{"matches":[{"vulnerability":{"id":"GHSA-4jrv-ppp4-jm57","dataSource":"https://github.com/advisories/GHSA-4jrv-ppp4-jm57","namespace":"github:language:java","severity":"High","urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-25647","https://github.com/google/gson/pull/1991","https://github.com/google/gson/pull/1991/commits","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327","https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html","https://www.debian.org/security/2022/dsa-5227","https://security.netapp.com/advisory/ntap-20220901-0009"],"description":"Deserialization of Untrusted Data in Gson","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":2.3,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-25647","epss":0.1223,"percentile":0.95924,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-25647","cwe":"CWE-502","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-25647","cwe":"CWE-502","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["2.8.9"],"state":"fixed","available":[{"version":"2.8.9","date":"2022-05-21","kind":"first-observed"}]},"advisories":[],"risk":9.2948},"relatedVulnerabilities":[{"id":"CVE-2022-25647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25647","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/google/gson/pull/1991","https://github.com/google/gson/pull/1991/commits","https://lists.debian.org/debian-lts-announce/2022/05/msg00015.html","https://lists.debian.org/debian-lts-announce/2022/09/msg00009.html","https://security.netapp.com/advisory/ntap-20220901-0009/","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLECODEGSON-1730327","https://www.debian.org/security/2022/dsa-5227","https://www.oracle.com/security-alerts/cpujul2022.html"],"description":"The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}},{"source":"report@snyk.io","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":2.3,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-25647","epss":0.1223,"percentile":0.95924,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-25647","cwe":"CWE-502","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-25647","cwe":"CWE-502","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.google.code.gson:gson","version":"2.8.5"}},"found":{"vulnerabilityID":"GHSA-4jrv-ppp4-jm57","versionConstraint":"<2.8.9 (unknown)"},"fix":{"suggestedVersion":"2.8.9"}}],"artifact":{"id":"ab7eba7e7e912f70","name":"gson","version":"2.8.5","type":"java-archive","locations":[{"path":"/zap/plugin/zest-beta-48.11.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/zest-beta-48.11.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:com.google.code.gson:gson:2.8.5:*:*:*:*:*:*:*","cpe:2.3:a:google:gson:2.8.5:*:*:*:*:*:*:*","cpe:2.3:a:code:gson:2.8.5:*:*:*:*:*:*:*","cpe:2.3:a:gson:gson:2.8.5:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.google.code.gson/gson@2.8.5","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/zest-beta-48.11.0.zap:com.google.code.gson:gson","pomArtifactID":"gson","pomGroupID":"com.google.code.gson","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2023-5217","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-5217","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)","cvss":[],"knownExploited":[{"cve":"CVE-2023-5217","vendorProject":"Google","product":"Chromium libvpx","dateAdded":"2023-10-02","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-10-23","knownRansomwareCampaignUse":"unknown","urls":["https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html","https://nvd.nist.gov/vuln/detail/CVE-2023-5217"],"cwes":["CWE-787"]}],"epss":[{"cve":"CVE-2023-5217","epss":0.49013,"percentile":0.98807,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5217","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-5217","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":5.250000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-5217","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5217","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2023/Oct/12","http://seclists.org/fulldisclosure/2023/Oct/16","http://www.openwall.com/lists/oss-security/2023/09/28/5","http://www.openwall.com/lists/oss-security/2023/09/28/6","http://www.openwall.com/lists/oss-security/2023/09/29/1","http://www.openwall.com/lists/oss-security/2023/09/29/11","http://www.openwall.com/lists/oss-security/2023/09/29/12","http://www.openwall.com/lists/oss-security/2023/09/29/14","http://www.openwall.com/lists/oss-security/2023/09/29/2","http://www.openwall.com/lists/oss-security/2023/09/29/7","http://www.openwall.com/lists/oss-security/2023/09/29/9","http://www.openwall.com/lists/oss-security/2023/09/30/1","http://www.openwall.com/lists/oss-security/2023/09/30/2","http://www.openwall.com/lists/oss-security/2023/09/30/3","http://www.openwall.com/lists/oss-security/2023/09/30/4","http://www.openwall.com/lists/oss-security/2023/09/30/5","http://www.openwall.com/lists/oss-security/2023/10/01/1","http://www.openwall.com/lists/oss-security/2023/10/01/2","http://www.openwall.com/lists/oss-security/2023/10/01/5","http://www.openwall.com/lists/oss-security/2023/10/02/6","http://www.openwall.com/lists/oss-security/2023/10/03/11","https://arstechnica.com/security/2023/09/new-0-day-in-chrome-and-firefox-is-likely-to-plague-other-software/","https://bugzilla.redhat.com/show_bug.cgi?id=2241191","https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html","https://crbug.com/1486441","https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590","https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282","https://github.com/webmproject/libvpx/releases/tag/v1.13.1","https://github.com/webmproject/libvpx/tags","https://lists.debian.org/debian-lts-announce/2023/09/msg00038.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00001.html","https://lists.debian.org/debian-lts-announce/2023/10/msg00015.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MFWDFJSSIFKWKNOCTQCFUNZWAXUCSS4/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/55YVCZNAVY3Y5E4DWPWMX2SPKZ2E5SOV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AY642Z6JZODQJE7Z62CFREVUHEGCXGPD/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BCVSHVX2RFBU3RMCUFSATVQEJUFD4Q63/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CWEJYS5NC7KVFYU3OAMPKQDYN6JQGVK6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TE7F54W5O5RS4ZMAAC7YK3CZWQXIDSKB/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/","https://pastebin.com/TdkC4pDv","https://security-tracker.debian.org/tracker/CVE-2023-5217","https://security.gentoo.org/glsa/202310-04","https://security.gentoo.org/glsa/202401-34","https://stackdiary.com/google-discloses-a-webm-vp8-bug-tracked-as-cve-2023-5217/","https://support.apple.com/kb/HT213961","https://support.apple.com/kb/HT213972","https://twitter.com/maddiestone/status/1707163313711497266","https://www.debian.org/security/2023/dsa-5508","https://www.debian.org/security/2023/dsa-5509","https://www.debian.org/security/2023/dsa-5510","https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/","https://www.openwall.com/lists/oss-security/2023/09/28/5","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-5217"],"description":"Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"knownExploited":[{"cve":"CVE-2023-5217","vendorProject":"Google","product":"Chromium libvpx","dateAdded":"2023-10-02","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-10-23","knownRansomwareCampaignUse":"unknown","urls":["https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html","https://nvd.nist.gov/vuln/detail/CVE-2023-5217"],"cwes":["CWE-787"]}],"epss":[{"cve":"CVE-2023-5217","epss":0.49013,"percentile":0.98807,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5217","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-5217","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-5217","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"GHSA-7r82-7xv7-xcpj","dataSource":"https://github.com/advisories/GHSA-7r82-7xv7-xcpj","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-13956","https://lists.apache.org/thread.html/r043a75acdeb52b15dd5e9524cdadef4202e6a5228644206acf9363f9@%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/r12cb62751b35bdcda0ae2a08b67877d665a1f4d41eee0fa7367169e0@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r2dc7930b43eadc78220d269b79e13ecd387e4bee52db67b2f47d4303@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/r34178ab6ef106bc940665fd3f4ba5026fac3603b3fa2aefafa0b619d@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r5de3d3808e7b5028df966e45115e006456c4e8931dc1e29036f17927@%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/r5fec9c1d67f928179adf484b01e7becd7c0a6fdfe3a08f92ea743b90@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r63296c45d5d84447babaf39bd1487329d8a80d8d563e67a4b6f3d8a7@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r6dab7da30f8bf075f79ee189e33b45a197502e2676481bb8787fc0d7%40%3Cdev.hc.apache.org%3E","https://lists.apache.org/thread.html/rae14ae25ff4a60251e3ba2629c082c5ba3851dfd4d21218b99b56652@%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/rb33212dab7beccaf1ffef9b88610047c644f644c7a0ebdc44d77e381@%3Ccommits.turbine.apache.org%3E","https://lists.apache.org/thread.html/rb725052404fabffbe093c83b2c46f3f87e12c3193a82379afbc529f8@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/rcced7ed3237c29cd19c1e9bf465d0038b8b2e967b99fc283db7ca553@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rcd9ad5dda60c82ab0d0c9bd3e9cb1dc740804451fc20c7f451ef5cc4@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rd5ab56beb2ac6879f6ab427bc4e5f7691aed8362d17b713f61779858@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/re504acd4d63b8df2a7353658f45c9a3137e5f80e41cf7de50058b2c1@%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/rf7ca60f78f05b772cc07d27e31bcd112f9910a05caf9095e38ee150f@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rfc00884c7b7ca878297bffe45fcb742c362b00b26ba37070706d44c3@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r03bbc318c81be21f5c8a9b85e34f2ecc741aa804a8e43b0ef2c37749@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r8aa1e5c343b89aec5b69961471950e862f15246cb6392910161c389b@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/ra539f20ef0fb0c27ee39945b5f56bf162e5c13d1c60f7344dab8de3b@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r06cf3ca5c8ceb94b39cd24a73d4e96153b485a7dac88444dd876accb@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r2a03dc210231d7e852ef73015f71792ac0fcaca6cccc024c522ef17d@%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/r34efec51cb817397ccf9f86e25a75676d435ba5f83ee7b2eabdad707@%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/r3f740e4c38bba1face49078aa5cbeeb558c27be601cc9712ad2dcd1e@%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/r549ac8c159bf0c568c19670bedeb8d7c0074beded951d34b1c1d0d05@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r55b2a1d1e9b1ec9db792b93da8f0f99a4fd5a5310b02673359d9b4d1@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r6eb2dae157dbc9af1f30d1f64e9c60d4ebef618f3dce4a0e32d6ea4d@%3Ccommits.drill.apache.org%3E","https://lists.apache.org/thread.html/r70c429923100c5a4fae8e5bc71c8a2d39af3de4888f50a0ac3755e6f@%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/r9e52a6c72c8365000ecd035e48cc9fee5a677a150350d4420c46443d@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/rad6222134183046f3928f733bf680919e0c390739bfbfe6c90049673@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rb4ba262d6f08ab9cf8b1ebbcd9b00b0368ffe90dad7ad7918b4b56fc@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/rc3739e0ad4bcf1888c6925233bfc37dd71156bbc8416604833095c42@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/rea3dbf633dde5008d38bf6600a3738b9216e733e03f9ff7becf79625@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/reef569c2419705754a3acf42b5f19b2a158153cef0e448158bc54917@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/rfb35f6db9ba1f1e061b63769a4eff5abadcc254ebfefc280e5a0dcf1@%3Ccommits.creadur.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/rc990e2462ec32b09523deafb2c73606208599e196fa2d7f50bdbc587@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r132e4c6a560cfc519caa1aaee63bdd4036327610eadbd89f76dd5457@%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r6a3cda38d050ebe13c1bc9a28d0a8ec38945095d07eca49046bcb89f@%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/rc505fee574fe8d18f9b0c655a4d120b0ae21bb6a73b96003e1d9be35@%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/r5b55f65c123a7481104d663a915ec45a0d103e6aaa03f42ed1c07a89@%3Cdev.jackrabbit.apache.org%3E","https://lists.apache.org/thread.html/rc0863892ccfd9fd0d0ae10091f24ee769fb39b8957fe4ebabfc11f17@%3Cdev.jackrabbit.apache.org%3E","https://lists.apache.org/thread.html/rfbedcb586a1e7dfce87ee03c720e583fc2ceeafa05f35c542cecc624@%3Cissues.solr.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://lists.apache.org/thread.html/r87ddc09295c27f25471269ad0a79433a91224045988b88f0413a97ec@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf03228972e56cb4a03e6d9558188c2938078cf3ceb23a3fead87c9ca@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r2835543ef0f91adcc47da72389b816e36936f584c7be584d2314fac3@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rc5c6ccb86d2afe46bbd4b71573f0448dc1f87bbcd5a0d8c7f8f904b2@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rf43d17ed0d1fb4fb79036b582810ef60b18b1ef3add0d5dea825af1e@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r6d672b46622842e565e00f6ef6bef83eb55d8792aac2bee75bff9a2a@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r3cecd59fba74404cbf4eb430135e1080897fb376f111406a78bed13a@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/ree942561f4620313c75982a4e5f3b74fe6f7062b073210779648eec2@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rf4db88c22e1be9eb60c7dc623d0528642c045fb196a24774ac2fa3a3@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r0bebe6f9808ac7bdf572873b4fa96a29c6398c90dab29f131f3ebffe@%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/r4850b3fbaea02fde2886e461005e4af8d37c80a48b3ce2a6edca0e30@%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/ra8bc6b61c5df301a6fe5a716315528ecd17ccb8a7f907e24a47a1a5e@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r0a75b8f0f72f3e18442dc56d33f3827b905f2fe5b7ba48997436f5d1@%3Cissues.solr.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2021.html","https://lists.apache.org/thread.html/r69a94e2f302d1b778bdfefe90fcb4b8c50b226438c3c8c1d0de85a19@%3Cdev.ranger.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2022.html","https://security.netapp.com/advisory/ntap-20220210-0002/","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"Cross-site scripting in Apache HttpClient","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-13956","epss":0.09032,"percentile":0.94959,"date":"2026-09-09"}],"fix":{"versions":["4.5.13"],"state":"fixed","available":[{"version":"4.5.13","date":"2021-06-04","kind":"first-observed"}]},"advisories":[],"risk":4.65148},"relatedVulnerabilities":[{"id":"CVE-2020-13956","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-13956","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.apache.org/thread.html/r03bbc318c81be21f5c8a9b85e34f2ecc741aa804a8e43b0ef2c37749%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r043a75acdeb52b15dd5e9524cdadef4202e6a5228644206acf9363f9%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/r06cf3ca5c8ceb94b39cd24a73d4e96153b485a7dac88444dd876accb%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r0a75b8f0f72f3e18442dc56d33f3827b905f2fe5b7ba48997436f5d1%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/r0bebe6f9808ac7bdf572873b4fa96a29c6398c90dab29f131f3ebffe%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/r12cb62751b35bdcda0ae2a08b67877d665a1f4d41eee0fa7367169e0%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r132e4c6a560cfc519caa1aaee63bdd4036327610eadbd89f76dd5457%40%3Cdev.creadur.apache.org%3E","https://lists.apache.org/thread.html/r2835543ef0f91adcc47da72389b816e36936f584c7be584d2314fac3%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r2a03dc210231d7e852ef73015f71792ac0fcaca6cccc024c522ef17d%40%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/r2dc7930b43eadc78220d269b79e13ecd387e4bee52db67b2f47d4303%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/r34178ab6ef106bc940665fd3f4ba5026fac3603b3fa2aefafa0b619d%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r34efec51cb817397ccf9f86e25a75676d435ba5f83ee7b2eabdad707%40%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/r3cecd59fba74404cbf4eb430135e1080897fb376f111406a78bed13a%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r3f740e4c38bba1face49078aa5cbeeb558c27be601cc9712ad2dcd1e%40%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/r4850b3fbaea02fde2886e461005e4af8d37c80a48b3ce2a6edca0e30%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/r549ac8c159bf0c568c19670bedeb8d7c0074beded951d34b1c1d0d05%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r55b2a1d1e9b1ec9db792b93da8f0f99a4fd5a5310b02673359d9b4d1%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r5b55f65c123a7481104d663a915ec45a0d103e6aaa03f42ed1c07a89%40%3Cdev.jackrabbit.apache.org%3E","https://lists.apache.org/thread.html/r5de3d3808e7b5028df966e45115e006456c4e8931dc1e29036f17927%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/r5fec9c1d67f928179adf484b01e7becd7c0a6fdfe3a08f92ea743b90%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r63296c45d5d84447babaf39bd1487329d8a80d8d563e67a4b6f3d8a7%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r69a94e2f302d1b778bdfefe90fcb4b8c50b226438c3c8c1d0de85a19%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r6a3cda38d050ebe13c1bc9a28d0a8ec38945095d07eca49046bcb89f%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/r6d672b46622842e565e00f6ef6bef83eb55d8792aac2bee75bff9a2a%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/r6dab7da30f8bf075f79ee189e33b45a197502e2676481bb8787fc0d7%40%3Cdev.hc.apache.org%3E","https://lists.apache.org/thread.html/r6eb2dae157dbc9af1f30d1f64e9c60d4ebef618f3dce4a0e32d6ea4d%40%3Ccommits.drill.apache.org%3E","https://lists.apache.org/thread.html/r70c429923100c5a4fae8e5bc71c8a2d39af3de4888f50a0ac3755e6f%40%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/r87ddc09295c27f25471269ad0a79433a91224045988b88f0413a97ec%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/r8aa1e5c343b89aec5b69961471950e862f15246cb6392910161c389b%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/r9e52a6c72c8365000ecd035e48cc9fee5a677a150350d4420c46443d%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/ra539f20ef0fb0c27ee39945b5f56bf162e5c13d1c60f7344dab8de3b%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/ra8bc6b61c5df301a6fe5a716315528ecd17ccb8a7f907e24a47a1a5e%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rad6222134183046f3928f733bf680919e0c390739bfbfe6c90049673%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rae14ae25ff4a60251e3ba2629c082c5ba3851dfd4d21218b99b56652%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/rb33212dab7beccaf1ffef9b88610047c644f644c7a0ebdc44d77e381%40%3Ccommits.turbine.apache.org%3E","https://lists.apache.org/thread.html/rb4ba262d6f08ab9cf8b1ebbcd9b00b0368ffe90dad7ad7918b4b56fc%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/rb725052404fabffbe093c83b2c46f3f87e12c3193a82379afbc529f8%40%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/rc0863892ccfd9fd0d0ae10091f24ee769fb39b8957fe4ebabfc11f17%40%3Cdev.jackrabbit.apache.org%3E","https://lists.apache.org/thread.html/rc3739e0ad4bcf1888c6925233bfc37dd71156bbc8416604833095c42%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/rc505fee574fe8d18f9b0c655a4d120b0ae21bb6a73b96003e1d9be35%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/rc5c6ccb86d2afe46bbd4b71573f0448dc1f87bbcd5a0d8c7f8f904b2%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rc990e2462ec32b09523deafb2c73606208599e196fa2d7f50bdbc587%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/rcced7ed3237c29cd19c1e9bf465d0038b8b2e967b99fc283db7ca553%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rcd9ad5dda60c82ab0d0c9bd3e9cb1dc740804451fc20c7f451ef5cc4%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rd5ab56beb2ac6879f6ab427bc4e5f7691aed8362d17b713f61779858%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/re504acd4d63b8df2a7353658f45c9a3137e5f80e41cf7de50058b2c1%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/rea3dbf633dde5008d38bf6600a3738b9216e733e03f9ff7becf79625%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ree942561f4620313c75982a4e5f3b74fe6f7062b073210779648eec2%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/reef569c2419705754a3acf42b5f19b2a158153cef0e448158bc54917%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/rf03228972e56cb4a03e6d9558188c2938078cf3ceb23a3fead87c9ca%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf43d17ed0d1fb4fb79036b582810ef60b18b1ef3add0d5dea825af1e%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rf4db88c22e1be9eb60c7dc623d0528642c045fb196a24774ac2fa3a3%40%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/rf7ca60f78f05b772cc07d27e31bcd112f9910a05caf9095e38ee150f%40%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rfb35f6db9ba1f1e061b63769a4eff5abadcc254ebfefc280e5a0dcf1%40%3Ccommits.creadur.apache.org%3E","https://lists.apache.org/thread.html/rfbedcb586a1e7dfce87ee03c720e583fc2ceeafa05f35c542cecc624%40%3Cissues.solr.apache.org%3E","https://lists.apache.org/thread.html/rfc00884c7b7ca878297bffe45fcb742c362b00b26ba37070706d44c3%40%3Cissues.hive.apache.org%3E","https://security.netapp.com/advisory/ntap-20220210-0002/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://priyankn.github.io/2021-02-26-CVE-2020-13956/"],"description":"Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-13956","epss":0.09032,"percentile":0.94959,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.httpcomponents:httpclient","version":"4.5.8"}},"found":{"vulnerabilityID":"GHSA-7r82-7xv7-xcpj","versionConstraint":"<4.5.13 (unknown)"},"fix":{"suggestedVersion":"4.5.13"}}],"artifact":{"id":"fc683514f1f41640","name":"httpclient","version":"4.5.8","type":"java-archive","locations":[{"path":"/zap/plugin/zest-beta-48.11.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/zest-beta-48.11.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:apache:httpclient:4.5.8:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.httpcomponents/httpclient@4.5.8","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/zest-beta-48.11.0.zap:org.apache.httpcomponents:httpclient","pomArtifactID":"httpclient","pomGroupID":"org.apache.httpcomponents","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2011-3389","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.","cvss":[],"epss":[{"cve":"CVE-2011-3389","epss":0.73327,"percentile":0.99427,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":3.66635},"relatedVulnerabilities":[{"id":"CVE-2011-3389","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","namespace":"nvd:cpe","severity":"Medium","urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-3389","epss":0.73327,"percentile":0.99427,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnutls28","version":"3.7.9-2+deb12u7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d1631d475c37518a","name":"libgnutls30","version":"3.7.9-2+deb12u7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libgnutls30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:bb7e5c24b3e27bbba5671dd710d159a0066833bda4caa1d55d8027ffed539337"],"cpes":["cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u7?arch=amd64&distro=debian-12.15&upstream=gnutls28","upstreams":[{"name":"gnutls28"}]}},{"vulnerability":{"id":"CVE-2023-45853","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45853","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45853","epss":0.03179,"percentile":0.87286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45853","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-45853","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":2.9882600000000004},"relatedVulnerabilities":[{"id":"CVE-2023-45853","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45853","namespace":"nvd:cpe","severity":"Critical","urls":["http://www.openwall.com/lists/oss-security/2023/10/20/9","http://www.openwall.com/lists/oss-security/2024/01/24/10","https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356","https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61","https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4","https://github.com/madler/zlib/pull/843","https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html","https://pypi.org/project/pyminizip/#history","https://security.gentoo.org/glsa/202401-18","https://security.netapp.com/advisory/ntap-20231130-0009/","https://www.winimage.com/zLibDll/minizip.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-470355.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"description":"MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45853","epss":0.03179,"percentile":0.87286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45853","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-45853","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45853","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3f28e512f3f6e928","name":"zlib1g-dev","version":"1:1.2.13.dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/zlib1g-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Zlib"],"cpes":["cpe:2.3:a:zlib1g-dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g-dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/zlib1g-dev@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","upstreams":[{"name":"zlib"}]}},{"vulnerability":{"id":"GHSA-4g8c-wm8x-jfhw","dataSource":"https://github.com/advisories/GHSA-4g8c-wm8x-jfhw","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-4g8c-wm8x-jfhw","https://github.com/netty/netty/commit/87f40725155b2f89adfde68c7732f97c153676c4","https://nvd.nist.gov/vuln/detail/CVE-2025-24970","https://security.netapp.com/advisory/ntap-20250221-0005","https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-detection","https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-mitigation"],"description":"SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-24970","epss":0.02192,"percentile":0.81373,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-24970","cwe":"CWE-20","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.118.Final"],"state":"fixed","available":[{"version":"4.1.118.Final","date":"2025-02-11","kind":"first-observed"}]},"advisories":[],"risk":1.644},"relatedVulnerabilities":[{"id":"CVE-2025-24970","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-24970","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/87f40725155b2f89adfde68c7732f97c153676c4","https://github.com/netty/netty/security/advisories/GHSA-4g8c-wm8x-jfhw","https://security.netapp.com/advisory/ntap-20250221-0005/","https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-detection","https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-mitigation"],"description":"Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-24970","epss":0.02192,"percentile":0.81373,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-24970","cwe":"CWE-20","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-4g8c-wm8x-jfhw","versionConstraint":">=4.1.91.Final,<=4.1.117.Final (unknown)"},"fix":{"suggestedVersion":"4.1.118.Final"}}],"artifact":{"id":"ab10619bb861593f","name":"netty-handler","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2023-2953","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-2953","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-2953","epss":0.01947,"percentile":0.78975,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"nvd@nist.gov","type":"Secondary"},{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.46025},"relatedVulnerabilities":[{"id":"CVE-2023-2953","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2953","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2023/Jul/47","http://seclists.org/fulldisclosure/2023/Jul/48","http://seclists.org/fulldisclosure/2023/Jul/52","https://access.redhat.com/security/cve/CVE-2023-2953","https://bugs.openldap.org/show_bug.cgi?id=9904","https://security.netapp.com/advisory/ntap-20230703-0005/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845"],"description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-2953","epss":0.01947,"percentile":0.78975,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"nvd@nist.gov","type":"Secondary"},{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-2953","versionConstraint":"none (unknown)"}}],"artifact":{"id":"692b9197d4b21a92","name":"libldap-2.5-0","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2023-2953","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-2953","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-2953","epss":0.01947,"percentile":0.78975,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"nvd@nist.gov","type":"Secondary"},{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.46025},"relatedVulnerabilities":[{"id":"CVE-2023-2953","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2953","namespace":"nvd:cpe","severity":"High","urls":["http://seclists.org/fulldisclosure/2023/Jul/47","http://seclists.org/fulldisclosure/2023/Jul/48","http://seclists.org/fulldisclosure/2023/Jul/52","https://access.redhat.com/security/cve/CVE-2023-2953","https://bugs.openldap.org/show_bug.cgi?id=9904","https://security.netapp.com/advisory/ntap-20230703-0005/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845"],"description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-2953","epss":0.01947,"percentile":0.78975,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"nvd@nist.gov","type":"Secondary"},{"cve":"CVE-2023-2953","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-2953","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dd3946a6b1d2298d","name":"libldap-common","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-common@2.5.13%2Bdfsg-5?arch=all&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2023-52355","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52355","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52355","epss":0.01829,"percentile":0.77557,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52355","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-52355","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.37175},"relatedVulnerabilities":[{"id":"CVE-2023-52355","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52355","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2025:20801","https://access.redhat.com/errata/RHSA-2025:21994","https://access.redhat.com/errata/RHSA-2025:23078","https://access.redhat.com/errata/RHSA-2025:23079","https://access.redhat.com/errata/RHSA-2025:23080","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:43537","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/security/cve/CVE-2023-52355","https://bugzilla.redhat.com/show_bug.cgi?id=2251326","https://gitlab.com/libtiff/libtiff/-/issues/621"],"description":"An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52355","epss":0.01829,"percentile":0.77557,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52355","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-52355","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52355","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2023-25193","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-25193","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-25193","epss":0.01812,"percentile":0.77331,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-25193","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-25193","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.3590000000000002},"relatedVulnerabilities":[{"id":"CVE-2023-25193","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-25193","namespace":"nvd:cpe","severity":"High","urls":["https://chromium.googlesource.com/chromium/src/+/e1f324aa681af54101c1f2d173d92adb80e37088/DEPS#361","https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh","https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3/","https://security.netapp.com/advisory/ntap-20230725-0006/","https://openjdk.org/groups/vulnerability/advisories/2023-07-18","https://www.oracle.com/security-alerts/cpujul2023.html"],"description":"hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-25193","epss":0.01812,"percentile":0.77331,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-25193","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-25193","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"harfbuzz","version":"6.0.0+dfsg-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-25193","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e593bea3ea25c1a5","name":"libharfbuzz0b","version":"6.0.0+dfsg-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libharfbuzz0b/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libharfbuzz0b/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libharfbuzz0b:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libharfbuzz0b:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","CC0-1.0","Expat","FSFAP","FSFUL","FSFULLR","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","MIT","Monotype","OFL-1.1","UFL-1.0","Unicode"],"cpes":["cpe:2.3:a:libharfbuzz0b:libharfbuzz0b:6.0.0\\+dfsg-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libharfbuzz0b@6.0.0%2Bdfsg-3?arch=amd64&distro=debian-12.15&upstream=harfbuzz","upstreams":[{"name":"harfbuzz"}]}},{"vulnerability":{"id":"GHSA-j288-q9x7-2f5v","dataSource":"https://github.com/advisories/GHSA-j288-q9x7-2f5v","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48924","https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html","http://www.openwall.com/lists/oss-security/2025/07/11/1"],"description":"Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-48924","epss":0.0227,"percentile":0.82016,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":1.30525},"relatedVulnerabilities":[{"id":"CVE-2025-48924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48924","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","http://www.openwall.com/lists/oss-security/2025/07/11/1","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html"],"description":"Uncontrolled Recursion vulnerability in Apache Commons Lang.\n\nThis issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.\n\nThe methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a \nStackOverflowError could cause an application to stop.\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-48924","epss":0.0227,"percentile":0.82016,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"commons-lang:commons-lang","version":"2.6"}},"found":{"vulnerabilityID":"GHSA-j288-q9x7-2f5v","versionConstraint":">=2.0,<=2.6 (unknown)"}}],"artifact":{"id":"448d1163210239cd","name":"commons-lang","version":"2.6","type":"java-archive","locations":[{"path":"/zap/lib/commons-lang-2.6.jar","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/lib/commons-lang-2.6.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:commons-lang:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_lang:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:2.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:lang:2.6:*:*:*:*:*:*:*"],"purl":"pkg:maven/commons-lang/commons-lang@2.6","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/lib/commons-lang-2.6.jar","pomArtifactID":"commons-lang","pomGroupID":"commons-lang","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"0ce1edb914c94ebc388f086c6827e8bdeec71ac2"}]}}},{"vulnerability":{"id":"GHSA-j288-q9x7-2f5v","dataSource":"https://github.com/advisories/GHSA-j288-q9x7-2f5v","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48924","https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html","http://www.openwall.com/lists/oss-security/2025/07/11/1"],"description":"Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-48924","epss":0.0227,"percentile":0.82016,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["3.18.0"],"state":"fixed","available":[{"version":"3.18.0","date":"2025-07-12","kind":"first-observed"}]},"advisories":[],"risk":1.30525},"relatedVulnerabilities":[{"id":"CVE-2025-48924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48924","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","http://www.openwall.com/lists/oss-security/2025/07/11/1","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html"],"description":"Uncontrolled Recursion vulnerability in Apache Commons Lang.\n\nThis issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.\n\nThe methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a \nStackOverflowError could cause an application to stop.\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-48924","epss":0.0227,"percentile":0.82016,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.commons:commons-lang3","version":"3.12.0"}},"found":{"vulnerabilityID":"GHSA-j288-q9x7-2f5v","versionConstraint":">=3.0,<3.18.0 (unknown)"},"fix":{"suggestedVersion":"3.18.0"}}],"artifact":{"id":"69184cfde01578d7","name":"commons-lang3","version":"3.12.0","type":"java-archive","locations":[{"path":"/zap/webswing/webswing-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/webswing-server.war:WEB-INF/lib-ext/commons-lang3-3.12.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:commons-lang3:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_lang3:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:lang3:3.12.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.commons/commons-lang3@3.12.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/webswing-server.war:WEB-INF/lib-ext/commons-lang3-3.12.0.jar","pomArtifactID":"commons-lang3","pomGroupID":"org.apache.commons","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"c6842c86792ff03b9f1d1fe2aab8dc23aa6c6f0e"}]}}},{"vulnerability":{"id":"CVE-2026-8461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8461","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.   This vulnerability is associated with the file libavcodec/magicyuv.C.    This issue affects FFmpeg before version 8.1.2.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8461","epss":0.01572,"percentile":0.73918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"reefs@jfrog.com","type":"Secondary"},{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":1.2811800000000002},"relatedVulnerabilities":[{"id":"CVE-2026-8461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"reefs@jfrog.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8461","epss":0.01572,"percentile":0.73918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"reefs@jfrog.com","type":"Secondary"},{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-8461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8461","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.   This vulnerability is associated with the file libavcodec/magicyuv.C.    This issue affects FFmpeg before version 8.1.2.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8461","epss":0.01572,"percentile":0.73918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"reefs@jfrog.com","type":"Secondary"},{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":1.2811800000000002},"relatedVulnerabilities":[{"id":"CVE-2026-8461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"reefs@jfrog.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8461","epss":0.01572,"percentile":0.73918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"reefs@jfrog.com","type":"Secondary"},{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-8461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8461","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.   This vulnerability is associated with the file libavcodec/magicyuv.C.    This issue affects FFmpeg before version 8.1.2.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8461","epss":0.01572,"percentile":0.73918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"reefs@jfrog.com","type":"Secondary"},{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":1.2811800000000002},"relatedVulnerabilities":[{"id":"CVE-2026-8461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"reefs@jfrog.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8461","epss":0.01572,"percentile":0.73918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"reefs@jfrog.com","type":"Secondary"},{"cve":"CVE-2026-8461","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2023-6879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6879","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6879","epss":0.01175,"percentile":0.65681,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6879","cwe":"CWE-20","source":"cve-coordination@google.com","type":"Secondary"},{"cve":"CVE-2023-6879","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.1045},"relatedVulnerabilities":[{"id":"CVE-2023-6879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6879","namespace":"nvd:cpe","severity":"Critical","urls":["https://aomedia.googlesource.com/aom/+/refs/tags/v3.7.1","https://crbug.com/aomedia/3491","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYONA2XSNFMXLAW4IHLFI5UVV3QRNG5K/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D6C2HN4T2S6GYNTAUXLH45LQZHK7QPHP/"],"description":"Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve-coordination@google.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9,"exploitabilityScore":2.3,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6879","epss":0.01175,"percentile":0.65681,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6879","cwe":"CWE-20","source":"cve-coordination@google.com","type":"Secondary"},{"cve":"CVE-2023-6879","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"aom","version":"3.6.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9e3b0cc1c76e74b4","name":"libaom3","version":"3.6.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libaom3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libaom3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libaom3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libaom3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","BSD-2-clause","BSD-3-clause","Expat","ISC","public-domain-md5"],"cpes":["cpe:2.3:a:libaom3:libaom3:3.6.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libaom3@3.6.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=aom","upstreams":[{"name":"aom"}]}},{"vulnerability":{"id":"CVE-2019-6110","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6110","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.","cvss":[],"epss":[{"cve":"CVE-2019-6110","epss":0.20906,"percentile":0.97408,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2019-6110","cwe":"CWE-838","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":1.0453000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-6110","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6110","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf","https://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.c","https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.c","https://security.gentoo.org/glsa/201903-16","https://security.netapp.com/advisory/ntap-20190213-0001/","https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt","https://www.exploit-db.com/exploits/46193/"],"description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":1.7,"impactScore":5.2},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"exploitabilityScore":5,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":1.7,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-6110","epss":0.20906,"percentile":0.97408,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2019-6110","cwe":"CWE-838","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-6110","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2023-6277","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6277","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6277","epss":0.0181,"percentile":0.77304,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-6277","cwe":"CWE-400","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.04075},"relatedVulnerabilities":[{"id":"CVE-2023-6277","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6277","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-6277","https://bugzilla.redhat.com/show_bug.cgi?id=2251311","https://gitlab.com/libtiff/libtiff/-/issues/614","https://gitlab.com/libtiff/libtiff/-/merge_requests/545","http://seclists.org/fulldisclosure/2024/Jul/16","http://seclists.org/fulldisclosure/2024/Jul/17","http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://seclists.org/fulldisclosure/2024/Jul/21","http://seclists.org/fulldisclosure/2024/Jul/22","http://seclists.org/fulldisclosure/2024/Jul/23","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJIN6DTSL3VODZUGWEUXLEL5DR53EZMV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7ZGN2MZXJ6E57W3L4YBM3ZPAU3T7T5C/","https://security.netapp.com/advisory/ntap-20240119-0002/","https://support.apple.com/kb/HT214116","https://support.apple.com/kb/HT214117","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120","https://support.apple.com/kb/HT214122","https://support.apple.com/kb/HT214123","https://support.apple.com/kb/HT214124"],"description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6277","epss":0.0181,"percentile":0.77304,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-6277","cwe":"CWE-400","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6277","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-63076","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63076","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.  Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.  CWE: CWE-476: NULL Pointer Dereference  Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.  This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63076","epss":0.0133,"percentile":0.69351,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.9974999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-63076","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63076","epss":0.0133,"percentile":0.69351,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f55823b1f5c2e201","name":"libssl3","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","upstreams":[{"name":"openssl"}]}},{"vulnerability":{"id":"CVE-2026-63076","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63076","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.  Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.  CWE: CWE-476: NULL Pointer Dereference  Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.  This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63076","epss":0.0133,"percentile":0.69351,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.9974999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-63076","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63076","epss":0.0133,"percentile":0.69351,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7345802bd2ec0962","name":"openssl","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-59375","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59375","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59375","epss":0.01315,"percentile":0.69037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.98625},"relatedVulnerabilities":[{"id":"CVE-2025-59375","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59375","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/blob/676a4c531ec768732fac215da9730b5f50fbd2bf/expat/Changes#L45-L74","https://github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changes","https://github.com/libexpat/libexpat/issues/1018","https://github.com/libexpat/libexpat/pull/1034","https://issues.oss-fuzz.com/issues/439133977","http://www.openwall.com/lists/oss-security/2025/09/16/2","http://www.openwall.com/lists/oss-security/2026/05/01/5","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html"],"description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59375","epss":0.01315,"percentile":0.69037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59375","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-59375","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59375","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59375","epss":0.01315,"percentile":0.69037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.98625},"relatedVulnerabilities":[{"id":"CVE-2025-59375","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59375","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/blob/676a4c531ec768732fac215da9730b5f50fbd2bf/expat/Changes#L45-L74","https://github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changes","https://github.com/libexpat/libexpat/issues/1018","https://github.com/libexpat/libexpat/pull/1034","https://issues.oss-fuzz.com/issues/439133977","http://www.openwall.com/lists/oss-security/2025/09/16/2","http://www.openwall.com/lists/oss-security/2026/05/01/5","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html"],"description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59375","epss":0.01315,"percentile":0.69037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59375","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"GHSA-355h-qmc2-wpwf","dataSource":"https://github.com/advisories/GHSA-355h-qmc2-wpwf","namespace":"github:language:java","severity":"High","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://nvd.nist.gov/vuln/detail/CVE-2026-2332","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://w4ke.info/2025/06/18/funky-chunks.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://access.redhat.com/security/cve/CVE-2026-2332","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:10175"],"description":"Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-2332","epss":0.01305,"percentile":0.68818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["9.4.60"],"state":"fixed","available":[{"version":"9.4.60","date":"2026-04-15","kind":"first-observed"}]},"advisories":[],"risk":0.972225},"relatedVulnerabilities":[{"id":"CVE-2026-2332","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2332","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2026-2332","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json"],"description":"In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-2332","epss":0.01305,"percentile":0.68818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.56.v20240826"}},"found":{"vulnerabilityID":"GHSA-355h-qmc2-wpwf","versionConstraint":">=9.4.0,<=9.4.59 (unknown)"},"fix":{"suggestedVersion":"9.4.60"}}],"artifact":{"id":"1240a4d50758cd81","name":"jetty-http","version":"9.4.56.v20240826","type":"java-archive","locations":[{"path":"/zap/webswing/server/webswing-jetty-launcher.jar","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/server/webswing-jetty-launcher.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.56.v20240826","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/server/webswing-jetty-launcher.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-355h-qmc2-wpwf","dataSource":"https://github.com/advisories/GHSA-355h-qmc2-wpwf","namespace":"github:language:java","severity":"High","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://nvd.nist.gov/vuln/detail/CVE-2026-2332","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://w4ke.info/2025/06/18/funky-chunks.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://access.redhat.com/security/cve/CVE-2026-2332","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:10175"],"description":"Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-2332","epss":0.01305,"percentile":0.68818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["9.4.60"],"state":"fixed","available":[{"version":"9.4.60","date":"2026-04-15","kind":"first-observed"}]},"advisories":[],"risk":0.972225},"relatedVulnerabilities":[{"id":"CVE-2026-2332","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2332","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2026-2332","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json"],"description":"In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-2332","epss":0.01305,"percentile":0.68818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.57.v20241219"}},"found":{"vulnerabilityID":"GHSA-355h-qmc2-wpwf","versionConstraint":">=9.4.0,<=9.4.59 (unknown)"},"fix":{"suggestedVersion":"9.4.60"}}],"artifact":{"id":"c9700e6689975883","name":"jetty-http","version":"9.4.57.v20241219","type":"java-archive","locations":[{"path":"/zap/plugin/selenium-release-15.43.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/selenium-release-15.43.0.zap:libs/htmlunit-websocket-client-4.14.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.57.v20241219","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/selenium-release-15.43.0.zap:libs/htmlunit-websocket-client-4.14.0.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-355h-qmc2-wpwf","dataSource":"https://github.com/advisories/GHSA-355h-qmc2-wpwf","namespace":"github:language:java","severity":"High","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://nvd.nist.gov/vuln/detail/CVE-2026-2332","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://w4ke.info/2025/06/18/funky-chunks.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://access.redhat.com/security/cve/CVE-2026-2332","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:10175"],"description":"Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-2332","epss":0.01305,"percentile":0.68818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["9.4.60"],"state":"fixed","available":[{"version":"9.4.60","date":"2026-04-15","kind":"first-observed"}]},"advisories":[],"risk":0.972225},"relatedVulnerabilities":[{"id":"CVE-2026-2332","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2332","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2026-2332","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json"],"description":"In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-2332","epss":0.01305,"percentile":0.68818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2026-2332","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.57.v20241219"}},"found":{"vulnerabilityID":"GHSA-355h-qmc2-wpwf","versionConstraint":">=9.4.0,<=9.4.59 (unknown)"},"fix":{"suggestedVersion":"9.4.60"}}],"artifact":{"id":"12be712711d3c78e","name":"jetty-http","version":"9.4.57.v20241219","type":"java-archive","locations":[{"path":"/zap/plugin/selenium-release-15.53.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/selenium-release-15.53.0.zap:libs/htmlunit-websocket-client-4.14.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.57.v20241219","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/selenium-release-15.53.0.zap:libs/htmlunit-websocket-client-4.14.0.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-w9fj-cfpg-grvv","dataSource":"https://github.com/advisories/GHSA-w9fj-cfpg-grvv","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-w9fj-cfpg-grvv","https://nvd.nist.gov/vuln/detail/CVE-2026-33871"],"description":"Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-33871","epss":0.01125,"percentile":0.64331,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-33871","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-33871","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.132.Final"],"state":"fixed","available":[{"version":"4.1.132.Final","date":"2026-03-27","kind":"first-observed"}]},"advisories":[],"risk":0.9112499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-33871","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33871","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-w9fj-cfpg-grvv","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:17789","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:22619","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:7109","https://access.redhat.com/errata/RHSA-2026:7380","https://access.redhat.com/errata/RHSA-2026:8159","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-33871","https://bugzilla.redhat.com/show_bug.cgi?id=2452456","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33871.json"],"description":"Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-33871","epss":0.01125,"percentile":0.64331,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-33871","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-33871","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-w9fj-cfpg-grvv","versionConstraint":"<4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.132.Final"}}],"artifact":{"id":"5895f3b705a95bee","name":"netty-codec-http2","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2025-13151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-13151","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-13151","epss":0.01149,"percentile":0.64944,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.86175},"relatedVulnerabilities":[{"id":"CVE-2025-13151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13151","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.com/gnutls/libtasn1","https://gitlab.com/gnutls/libtasn1/-/merge_requests/121","http://www.openwall.com/lists/oss-security/2026/01/08/5","https://www.kb.cert.org/vuls/id/271649"],"description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-13151","epss":0.01149,"percentile":0.64944,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libtasn1-6","version":"4.19.0-2+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-13151","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9e40126b989ece04","name":"libtasn1-6","version":"4.19.0-2+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtasn1-6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libtasn1-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:572ad60ad184d8f52c6dc66d83a61a68f137db560b3452ce00588c9ecf128a65"],"cpes":["cpe:2.3:a:libtasn1-6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1-6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtasn1-6@4.19.0-2%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-10536","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.57281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.83754},"relatedVulnerabilities":[{"id":"CVE-2026-10536","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.57281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-10536","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.57281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.83754},"relatedVulnerabilities":[{"id":"CVE-2026-10536","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.57281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-10536","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.57281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.83754},"relatedVulnerabilities":[{"id":"CVE-2026-10536","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10536","epss":0.00891,"percentile":0.57281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"GHSA-prj3-ccx8-p6x4","dataSource":"https://github.com/advisories/GHSA-prj3-ccx8-p6x4","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-prj3-ccx8-p6x4","https://nvd.nist.gov/vuln/detail/CVE-2025-55163","https://github.com/grpc/grpc-java/commit/6462ef9a11980e168c21d90bbc7245c728fd1a7a","https://github.com/netty/netty/commit/be53dc3c9acd9af2e20d0c3c07cd77115a594cf1","https://www.kb.cert.org/vuls/id/767506","http://www.openwall.com/lists/oss-security/2025/08/16/1"],"description":"Netty affected by MadeYouReset HTTP/2 DDoS vulnerability","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-55163","epss":0.01049,"percentile":0.62217,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-55163","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.124.Final"],"state":"fixed","available":[{"version":"4.1.124.Final","date":"2025-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.8051075},"relatedVulnerabilities":[{"id":"CVE-2025-55163","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55163","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-prj3-ccx8-p6x4","http://www.openwall.com/lists/oss-security/2025/08/16/1","https://www.kb.cert.org/vuls/id/767506"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-55163","epss":0.01049,"percentile":0.62217,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-55163","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-prj3-ccx8-p6x4","versionConstraint":"<=4.1.123.Final (unknown)"},"fix":{"suggestedVersion":"4.1.124.Final"}}],"artifact":{"id":"5895f3b705a95bee","name":"netty-codec-http2","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-3qp7-7mw8-wx86","dataSource":"https://github.com/advisories/GHSA-3qp7-7mw8-wx86","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-44249"],"description":"Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-44249","epss":0.01025,"percentile":0.61521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-44249","cwe":"CWE-284","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-44249","cwe":"CWE-697","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-44249","cwe":"CWE-1287","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-09","kind":"first-observed"}]},"advisories":[],"risk":0.7995},"relatedVulnerabilities":[{"id":"CVE-2026-44249","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44249","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-44249","https://bugzilla.redhat.com/show_bug.cgi?id=2488081","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json"],"description":"Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-44249","epss":0.01025,"percentile":0.61521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-44249","cwe":"CWE-284","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-44249","cwe":"CWE-697","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-44249","cwe":"CWE-1287","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-3qp7-7mw8-wx86","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"ab10619bb861593f","name":"netty-handler","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-3qp7-7mw8-wx86","dataSource":"https://github.com/advisories/GHSA-3qp7-7mw8-wx86","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-44249"],"description":"Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-44249","epss":0.01025,"percentile":0.61521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-44249","cwe":"CWE-284","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-44249","cwe":"CWE-697","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-44249","cwe":"CWE-1287","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-09","kind":"first-observed"}]},"advisories":[],"risk":0.7995},"relatedVulnerabilities":[{"id":"CVE-2026-44249","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44249","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-44249","https://bugzilla.redhat.com/show_bug.cgi?id=2488081","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json"],"description":"Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-44249","epss":0.01025,"percentile":0.61521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-44249","cwe":"CWE-284","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-44249","cwe":"CWE-697","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-44249","cwe":"CWE-1287","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-3qp7-7mw8-wx86","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"bf14062c190d1eea","name":"netty-handler","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-f6hv-jmp6-3vwv","dataSource":"https://github.com/advisories/GHSA-f6hv-jmp6-3vwv","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv","https://nvd.nist.gov/vuln/detail/CVE-2026-42587"],"description":"Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42587","epss":0.0099,"percentile":0.60446,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42587","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42587","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.133.Final"],"state":"fixed","available":[{"version":"4.1.133.Final","date":"2026-05-07","kind":"first-observed"}]},"advisories":[],"risk":0.7425000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-42587","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42587","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-42587","https://bugzilla.redhat.com/show_bug.cgi?id=2477220","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42587.json"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42587","epss":0.0099,"percentile":0.60446,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42587","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42587","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-f6hv-jmp6-3vwv","versionConstraint":"<=4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.133.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-f6hv-jmp6-3vwv","dataSource":"https://github.com/advisories/GHSA-f6hv-jmp6-3vwv","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv","https://nvd.nist.gov/vuln/detail/CVE-2026-42587"],"description":"Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42587","epss":0.0099,"percentile":0.60446,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42587","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42587","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.133.Final"],"state":"fixed","available":[{"version":"4.1.133.Final","date":"2026-05-07","kind":"first-observed"}]},"advisories":[],"risk":0.7425000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-42587","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42587","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-42587","https://bugzilla.redhat.com/show_bug.cgi?id=2477220","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42587.json"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42587","epss":0.0099,"percentile":0.60446,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42587","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42587","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-f6hv-jmp6-3vwv","versionConstraint":"<=4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.133.Final"}}],"artifact":{"id":"5895f3b705a95bee","name":"netty-codec-http2","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-19931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19931","epss":0.00788,"percentile":0.54044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.74072},"relatedVulnerabilities":[{"id":"CVE-2026-19931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19931","epss":0.00788,"percentile":0.54044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-19931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19931","epss":0.00788,"percentile":0.54044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.74072},"relatedVulnerabilities":[{"id":"CVE-2026-19931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19931","epss":0.00788,"percentile":0.54044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-19931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19931","epss":0.00788,"percentile":0.54044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.74072},"relatedVulnerabilities":[{"id":"CVE-2026-19931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19931","epss":0.00788,"percentile":0.54044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"GHSA-p93r-85wp-75v3","dataSource":"https://github.com/advisories/GHSA-p93r-85wp-75v3","namespace":"github:language:java","severity":"High","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-5598","https://github.com/bcgit/bc-java/commit/8692e6b2b191fc4aafa32545c7a78bdb9bf110c5","https://github.com/bcgit/bc-java/commit/94abbd56413dfdac651fd878bc60253871ef5e87","https://github.com/bcgit/bc-java/wiki/CVE-2026-5598","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905598"],"description":"Bouncy Castle Has Covert Timing Channel Vulnerability","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/S:P/AU:Y/U:Red","metrics":{"baseScore":8.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5598","epss":0.00899,"percentile":0.57515,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5598","cwe":"CWE-385","source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary"},{"cve":"CVE-2026-5598","cwe":"CWE-385","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["1.84"],"state":"fixed","available":[{"version":"1.84","date":"2026-04-26","kind":"first-observed"}]},"advisories":[],"risk":0.7371800000000001},"relatedVulnerabilities":[{"id":"CVE-2026-5598","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5598","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/bcgit/bc-java/commit/8692e6b2b191fc4aafa32545c7a78bdb9bf110c5","https://github.com/bcgit/bc-java/commit/94abbd56413dfdac651fd878bc60253871ef5e87","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905598","https://access.redhat.com/errata/RHSA-2026:12267","https://access.redhat.com/errata/RHSA-2026:12269","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/security/cve/CVE-2026-5598","https://bugzilla.redhat.com/show_bug.cgi?id=2458635","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5598.json"],"description":"Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).\n\n This vulnerability is associated with program files FrodoEngine.Java.\n\n\n\nThis issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Red","metrics":{"baseScore":8.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5598","epss":0.00899,"percentile":0.57515,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5598","cwe":"CWE-385","source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary"},{"cve":"CVE-2026-5598","cwe":"CWE-385","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.83"}},"found":{"vulnerabilityID":"GHSA-p93r-85wp-75v3","versionConstraint":">=1.82,<1.84 (unknown)"},"fix":{"suggestedVersion":"1.84"}}],"artifact":{"id":"a6a20590309f15f0","name":"bcprov-jdk18on","version":"1.83","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap:libs/bcprov-jdk18on-1.83.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.83:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.83","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:libs/bcprov-jdk18on-1.83.jar","pomArtifactID":"bcprov-jdk18on","pomGroupID":"org.bouncycastle","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"310e719f391bd9f4ee5103ca299c172643efb595"}]}}},{"vulnerability":{"id":"CVE-2024-31578","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-31578","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-31578","epss":0.00968,"percentile":0.59784,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-31578","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.7259999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-31578","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-31578","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/1047524396/45400cce5859d78dcd3a62010df8d179","https://github.com/ffmpeg/ffmpeg/commit/3bb00c0a420c3ce83c6fafee30270d69622ccad7","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://lists.debian.org/debian-lts-announce/2024/10/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"description":"FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-31578","epss":0.00968,"percentile":0.59784,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-31578","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-31578","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2024-31578","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-31578","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-31578","epss":0.00968,"percentile":0.59784,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-31578","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.7259999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-31578","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-31578","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/1047524396/45400cce5859d78dcd3a62010df8d179","https://github.com/ffmpeg/ffmpeg/commit/3bb00c0a420c3ce83c6fafee30270d69622ccad7","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://lists.debian.org/debian-lts-announce/2024/10/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"description":"FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-31578","epss":0.00968,"percentile":0.59784,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-31578","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-31578","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2024-31578","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-31578","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-31578","epss":0.00968,"percentile":0.59784,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-31578","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.7259999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-31578","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-31578","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/1047524396/45400cce5859d78dcd3a62010df8d179","https://github.com/ffmpeg/ffmpeg/commit/3bb00c0a420c3ce83c6fafee30270d69622ccad7","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://lists.debian.org/debian-lts-announce/2024/10/msg00019.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"description":"FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-31578","epss":0.00968,"percentile":0.59784,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-31578","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-31578","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"GHSA-5jpm-x58v-624v","dataSource":"https://github.com/advisories/GHSA-5jpm-x58v-624v","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-5jpm-x58v-624v","https://github.com/netty/netty/commit/0d0c6ed782d13d423586ad0c71737b2c7d02058c","https://gist.github.com/vietj/f558b8ea81ec6505f1e9a6ca283c9ae3","https://github.com/vietj/netty/tree/post-request-decoder","https://nvd.nist.gov/vuln/detail/CVE-2024-29025","https://lists.debian.org/debian-lts-announce/2024/06/msg00015.html"],"description":"Netty's HttpPostRequestDecoder can OOM","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-29025","epss":0.0138,"percentile":0.70466,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-29025","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.108.Final"],"state":"fixed","available":[{"version":"4.1.108.Final","date":"2024-03-26","kind":"first-observed"}]},"advisories":[],"risk":0.7107},"relatedVulnerabilities":[{"id":"CVE-2024-29025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-29025","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/vietj/f558b8ea81ec6505f1e9a6ca283c9ae3","https://github.com/netty/netty/commit/0d0c6ed782d13d423586ad0c71737b2c7d02058c","https://github.com/netty/netty/security/advisories/GHSA-5jpm-x58v-624v","https://lists.debian.org/debian-lts-announce/2024/06/msg00015.html"],"description":"Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-29025","epss":0.0138,"percentile":0.70466,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-29025","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-5jpm-x58v-624v","versionConstraint":"<4.1.108.Final (unknown)"},"fix":{"suggestedVersion":"4.1.108.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-rmj7-2vxq-3g9f","dataSource":"https://github.com/advisories/GHSA-rmj7-2vxq-3g9f","namespace":"github:language:java","severity":"High","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://nvd.nist.gov/vuln/detail/CVE-2026-54513","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260"],"description":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54513","epss":0.00892,"percentile":0.57301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-54513","cwe":"CWE-184","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-06-24","kind":"first-observed"}]},"advisories":[],"risk":0.6957600000000002},"relatedVulnerabilities":[{"id":"CVE-2026-54513","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54513","epss":0.00892,"percentile":0.57301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-54513","cwe":"CWE-184","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.1"}},"found":{"vulnerabilityID":"GHSA-rmj7-2vxq-3g9f","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"a302f39326030e6b","name":"jackson-databind","version":"2.19.1","type":"java-archive","locations":[{"path":"/zap/plugin/database-alpha-0.9.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"e8cb8e76faea3e0791165f5d3614fc45933b2ee0"}]}}},{"vulnerability":{"id":"GHSA-rmj7-2vxq-3g9f","dataSource":"https://github.com/advisories/GHSA-rmj7-2vxq-3g9f","namespace":"github:language:java","severity":"High","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://nvd.nist.gov/vuln/detail/CVE-2026-54513","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260"],"description":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54513","epss":0.00892,"percentile":0.57301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-54513","cwe":"CWE-184","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-06-24","kind":"first-observed"}]},"advisories":[],"risk":0.6957600000000002},"relatedVulnerabilities":[{"id":"CVE-2026-54513","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54513","epss":0.00892,"percentile":0.57301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-54513","cwe":"CWE-184","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.1"}},"found":{"vulnerabilityID":"GHSA-rmj7-2vxq-3g9f","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"36f0584e521d794e","name":"jackson-databind","version":"2.20.1","type":"java-archive","locations":[{"path":"/zap/plugin/commonlib-release-1.39.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/commonlib-release-1.39.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":["The Apache Software License, Version 2.0"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/commonlib-release-1.39.0.zap:com.fasterxml.jackson.core:jackson-databind","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-64831","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64831","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64831","epss":0.00851,"percentile":0.56037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.68931},"relatedVulnerabilities":[{"id":"CVE-2026-64831","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64831","epss":0.00851,"percentile":0.56037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64831","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64831","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64831","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64831","epss":0.00851,"percentile":0.56037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.68931},"relatedVulnerabilities":[{"id":"CVE-2026-64831","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64831","epss":0.00851,"percentile":0.56037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64831","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64831","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64831","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64831","epss":0.00851,"percentile":0.56037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.68931},"relatedVulnerabilities":[{"id":"CVE-2026-64831","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64831","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder"],"description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64831","epss":0.00851,"percentile":0.56037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64831","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64831","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"GHSA-j3rv-43j4-c7qm","dataSource":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm","namespace":"github:language:java","severity":"High","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://nvd.nist.gov/vuln/detail/CVE-2026-54512"],"description":"jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54512","epss":0.00873,"percentile":0.56762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-54512","cwe":"CWE-502","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-06-24","kind":"first-observed"}]},"advisories":[],"risk":0.68094},"relatedVulnerabilities":[{"id":"CVE-2026-54512","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54512","epss":0.00873,"percentile":0.56762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-54512","cwe":"CWE-502","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.1"}},"found":{"vulnerabilityID":"GHSA-j3rv-43j4-c7qm","versionConstraint":">=2.19.0,<=2.21.3 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"a302f39326030e6b","name":"jackson-databind","version":"2.19.1","type":"java-archive","locations":[{"path":"/zap/plugin/database-alpha-0.9.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"e8cb8e76faea3e0791165f5d3614fc45933b2ee0"}]}}},{"vulnerability":{"id":"GHSA-j3rv-43j4-c7qm","dataSource":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm","namespace":"github:language:java","severity":"High","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://nvd.nist.gov/vuln/detail/CVE-2026-54512"],"description":"jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54512","epss":0.00873,"percentile":0.56762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-54512","cwe":"CWE-502","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-06-24","kind":"first-observed"}]},"advisories":[],"risk":0.68094},"relatedVulnerabilities":[{"id":"CVE-2026-54512","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54512","epss":0.00873,"percentile":0.56762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-54512","cwe":"CWE-502","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.1"}},"found":{"vulnerabilityID":"GHSA-j3rv-43j4-c7qm","versionConstraint":">=2.19.0,<=2.21.3 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"36f0584e521d794e","name":"jackson-databind","version":"2.20.1","type":"java-archive","locations":[{"path":"/zap/plugin/commonlib-release-1.39.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/commonlib-release-1.39.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":["The Apache Software License, Version 2.0"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/commonlib-release-1.39.0.zap:com.fasterxml.jackson.core:jackson-databind","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-hf6x-8p5f-cgmf","dataSource":"https://github.com/advisories/GHSA-hf6x-8p5f-cgmf","namespace":"github:language:java","severity":"High","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54399","https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4","https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e","https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"],"description":"Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54399","epss":0.0087,"percentile":0.56634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["5.4.3"],"state":"fixed","available":[{"version":"5.4.3","date":"2026-08-13","kind":"first-observed"}]},"advisories":[],"risk":0.6525},"relatedVulnerabilities":[{"id":"CVE-2026-54399","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54399","namespace":"nvd:cpe","severity":"High","urls":["https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4"],"description":"Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54399","epss":0.0087,"percentile":0.56634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.httpcomponents.core5:httpcore5","version":"5.2"}},"found":{"vulnerabilityID":"GHSA-hf6x-8p5f-cgmf","versionConstraint":"<5.4.3 (unknown)"},"fix":{"suggestedVersion":"5.4.3"}}],"artifact":{"id":"c4507c0380e6f119","name":"httpcore5","version":"5.2","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap:libs/httpcore5-5.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["Apache-2.0"],"cpes":["cpe:2.3:a:apache:httpcore5:5.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:core5:5.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:libs/httpcore5-5.2.jar","pomArtifactID":"httpcore5","pomGroupID":"org.apache.httpcomponents.core5","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"ab7d251b8dfa3f2878f1eefbcca0e1fc0ebeba27"}]}}},{"vulnerability":{"id":"GHSA-hf6x-8p5f-cgmf","dataSource":"https://github.com/advisories/GHSA-hf6x-8p5f-cgmf","namespace":"github:language:java","severity":"High","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54399","https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4","https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e","https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"],"description":"Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54399","epss":0.0087,"percentile":0.56634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["5.4.3"],"state":"fixed","available":[{"version":"5.4.3","date":"2026-08-13","kind":"first-observed"}]},"advisories":[],"risk":0.6525},"relatedVulnerabilities":[{"id":"CVE-2026-54399","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54399","namespace":"nvd:cpe","severity":"High","urls":["https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4"],"description":"Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54399","epss":0.0087,"percentile":0.56634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.httpcomponents.core5:httpcore5","version":"5.2"}},"found":{"vulnerabilityID":"GHSA-hf6x-8p5f-cgmf","versionConstraint":"<5.4.3 (unknown)"},"fix":{"suggestedVersion":"5.4.3"}}],"artifact":{"id":"dd786a6159fa76f8","name":"httpcore5","version":"5.2","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap:libs/httpcore5-5.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["Apache-2.0"],"cpes":["cpe:2.3:a:apache:httpcore5:5.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:core5:5.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:libs/httpcore5-5.2.jar","pomArtifactID":"httpcore5","pomGroupID":"org.apache.httpcomponents.core5","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"ab7d251b8dfa3f2878f1eefbcca0e1fc0ebeba27"}]}}},{"vulnerability":{"id":"GHSA-v3jc-474w-2wm6","dataSource":"https://github.com/advisories/GHSA-v3jc-474w-2wm6","namespace":"github:language:java","severity":"High","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54428","https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3","https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e","https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"],"description":"Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54428","epss":0.0087,"percentile":0.56634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-54428","cwe":"CWE-770","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["5.4.3"],"state":"fixed","available":[{"version":"5.4.3","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.6525},"relatedVulnerabilities":[{"id":"CVE-2026-54428","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54428","namespace":"nvd:cpe","severity":"High","urls":["https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3"],"description":"Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54428","epss":0.0087,"percentile":0.56634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-54428","cwe":"CWE-770","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.httpcomponents.core5:httpcore5-h2","version":"5.2"}},"found":{"vulnerabilityID":"GHSA-v3jc-474w-2wm6","versionConstraint":"<5.4.3 (unknown)"},"fix":{"suggestedVersion":"5.4.3"}}],"artifact":{"id":"a8e5ff1419dd19fc","name":"httpcore5-h2","version":"5.2","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap:libs/httpcore5-h2-5.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["Apache-2.0"],"cpes":["cpe:2.3:a:apache:httpcore5-h2:5.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:httpcore5_h2:5.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:libs/httpcore5-h2-5.2.jar","pomArtifactID":"httpcore5-h2","pomGroupID":"org.apache.httpcomponents.core5","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"698bd8c759ccc7fd7398f3179ff45d0e5a7ccc16"}]}}},{"vulnerability":{"id":"GHSA-v3jc-474w-2wm6","dataSource":"https://github.com/advisories/GHSA-v3jc-474w-2wm6","namespace":"github:language:java","severity":"High","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54428","https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3","https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e","https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"],"description":"Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54428","epss":0.0087,"percentile":0.56634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-54428","cwe":"CWE-770","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["5.4.3"],"state":"fixed","available":[{"version":"5.4.3","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.6525},"relatedVulnerabilities":[{"id":"CVE-2026-54428","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54428","namespace":"nvd:cpe","severity":"High","urls":["https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3"],"description":"Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54428","epss":0.0087,"percentile":0.56634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-54428","cwe":"CWE-770","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.httpcomponents.core5:httpcore5-h2","version":"5.2"}},"found":{"vulnerabilityID":"GHSA-v3jc-474w-2wm6","versionConstraint":"<5.4.3 (unknown)"},"fix":{"suggestedVersion":"5.4.3"}}],"artifact":{"id":"5704f6484b82d248","name":"httpcore5-h2","version":"5.2","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap:libs/httpcore5-h2-5.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["Apache-2.0"],"cpes":["cpe:2.3:a:apache:httpcore5-h2:5.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:httpcore5_h2:5.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:libs/httpcore5-h2-5.2.jar","pomArtifactID":"httpcore5-h2","pomGroupID":"org.apache.httpcomponents.core5","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"698bd8c759ccc7fd7398f3179ff45d0e5a7ccc16"}]}}},{"vulnerability":{"id":"CVE-2020-15778","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15778","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\"","cvss":[],"epss":[{"cve":"CVE-2020-15778","epss":0.12996,"percentile":0.96086,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2020-15778","cwe":"CWE-78","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.6498},"relatedVulnerabilities":[{"id":"CVE-2020-15778","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15778","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2024:3166","https://github.com/cpandya2909/CVE-2020-15778/","https://news.ycombinator.com/item?id=25005567","https://security.gentoo.org/glsa/202212-06","https://security.netapp.com/advisory/ntap-20200731-0007/","https://www.openssh.com/security.html"],"description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"exploitabilityScore":1.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-15778","epss":0.12996,"percentile":0.96086,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2020-15778","cwe":"CWE-78","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-15778","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2026-11856","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.00688,"percentile":0.50612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.6467200000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11856","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.00688,"percentile":0.50612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-11856","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.00688,"percentile":0.50612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.6467200000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11856","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.00688,"percentile":0.50612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-11856","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the  `Authorization:` header field meant for `hostA`, to `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.00688,"percentile":0.50612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.6467200000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11856","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the  `Authorization:` header field meant for `hostA`,\nto `hostB`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11856","epss":0.00688,"percentile":0.50612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"GHSA-x4gw-5cx5-pgmh","dataSource":"https://github.com/advisories/GHSA-x4gw-5cx5-pgmh","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-45416"],"description":"Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45416","epss":0.00856,"percentile":0.56231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45416","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-45416","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-09","kind":"first-observed"}]},"advisories":[],"risk":0.642},"relatedVulnerabilities":[{"id":"CVE-2026-45416","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45416","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-45416","https://bugzilla.redhat.com/show_bug.cgi?id=2488391","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45416.json"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45416","epss":0.00856,"percentile":0.56231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45416","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-45416","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-x4gw-5cx5-pgmh","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"ab10619bb861593f","name":"netty-handler","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-x4gw-5cx5-pgmh","dataSource":"https://github.com/advisories/GHSA-x4gw-5cx5-pgmh","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-45416"],"description":"Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45416","epss":0.00856,"percentile":0.56231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45416","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-45416","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-09","kind":"first-observed"}]},"advisories":[],"risk":0.642},"relatedVulnerabilities":[{"id":"CVE-2026-45416","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45416","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-45416","https://bugzilla.redhat.com/show_bug.cgi?id=2488391","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45416.json"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45416","epss":0.00856,"percentile":0.56231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45416","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-45416","cwe":"CWE-770","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-x4gw-5cx5-pgmh","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"bf14062c190d1eea","name":"netty-handler","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2019-6462","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6462","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.","cvss":[],"epss":[{"cve":"CVE-2019-6462","epss":0.02124,"percentile":0.808,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.6371999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-6462","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6462","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/353","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-6462","epss":0.02124,"percentile":0.808,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-6462","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be12828c4e3c1a16","name":"libcairo-gobject2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo-gobject2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2019-6462","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6462","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.","cvss":[],"epss":[{"cve":"CVE-2019-6462","epss":0.02124,"percentile":0.808,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.6371999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-6462","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6462","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/353","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-6462","epss":0.02124,"percentile":0.808,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6462","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-6462","versionConstraint":"none (unknown)"}}],"artifact":{"id":"28d5ccf8758a4075","name":"libcairo2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo2:libcairo2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2019-6461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6461","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.","cvss":[],"epss":[{"cve":"CVE-2019-6461","epss":0.021,"percentile":0.80595,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.63},"relatedVulnerabilities":[{"id":"CVE-2019-6461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6461","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/352","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-6461","epss":0.021,"percentile":0.80595,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-6461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be12828c4e3c1a16","name":"libcairo-gobject2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo-gobject2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2019-6461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6461","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.","cvss":[],"epss":[{"cve":"CVE-2019-6461","epss":0.021,"percentile":0.80595,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.63},"relatedVulnerabilities":[{"id":"CVE-2019-6461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6461","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/TeamSeri0us/pocs/tree/master/gerbv","https://gitlab.freedesktop.org/cairo/cairo/issues/352","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-6461","epss":0.021,"percentile":0.80595,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6461","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-6461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"28d5ccf8758a4075","name":"libcairo2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo2:libcairo2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2024-10524","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10524","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.","cvss":[{"source":"reefs@jfrog.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":3.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10524","epss":0.01071,"percentile":0.62844,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","source":"reefs@jfrog.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.615825},"relatedVulnerabilities":[{"id":"CVE-2024-10524","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10524","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778","https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/","https://seclists.org/oss-sec/2024/q4/107","http://www.openwall.com/lists/oss-security/2024/11/18/6","https://security.netapp.com/advisory/ntap-20250321-0007/"],"description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.","cvss":[{"source":"reefs@jfrog.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":3.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10524","epss":0.01071,"percentile":0.62844,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","source":"reefs@jfrog.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-10524","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ef5a5a7d880f3e73","name":"wget","version":"1.21.3-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.list"}],"language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2021-31879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-31879","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-31879","epss":0.01104,"percentile":0.63779,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.6127199999999999},"relatedVulnerabilities":[{"id":"CVE-2021-31879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31879","namespace":"nvd:cpe","severity":"Medium","urls":["https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html","https://security.netapp.com/advisory/ntap-20210618-0002/"],"description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"exploitabilityScore":8.6,"impactScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-31879","epss":0.01104,"percentile":0.63779,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-31879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ef5a5a7d880f3e73","name":"wget","version":"1.21.3-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.list"}],"language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"GHSA-3pxv-7cmr-fjr4","dataSource":"https://github.com/advisories/GHSA-3pxv-7cmr-fjr4","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34480","https://github.com/apache/logging-log4j2/pull/4077","https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","https://logging.apache.org/security.html#CVE-2026-34480","http://www.openwall.com/lists/oss-security/2026/04/10/9"],"description":"Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34480","epss":0.00972,"percentile":0.59901,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34480","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["2.25.4"],"state":"fixed","available":[{"version":"2.25.4","date":"2026-04-11","kind":"first-observed"}]},"advisories":[],"risk":0.57834},"relatedVulnerabilities":[{"id":"CVE-2026-34480","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34480","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/apache/logging-log4j2/pull/4077","https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","https://logging.apache.org/security.html#CVE-2026-34480","http://www.openwall.com/lists/oss-security/2026/04/10/9"],"description":"Apache Log4j Core's  XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the  XML 1.0 specification https://www.w3.org/TR/xml/#charsets  producing invalid XML output whenever a log message or MDC value contains such characters.\n\nThe impact depends on the StAX implementation in use:\n\n  *  JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records.\n  *  Alternative StAX implementations (e.g.,  Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger.\n\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34480","epss":0.00972,"percentile":0.59901,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34480","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.20.0"}},"found":{"vulnerabilityID":"GHSA-3pxv-7cmr-fjr4","versionConstraint":">=2.0-alpha1,<2.25.4 (unknown)"},"fix":{"suggestedVersion":"2.25.4"}}],"artifact":{"id":"89dc48ff2ee6f684","name":"log4j-core","version":"2.20.0","type":"java-archive","locations":[{"path":"/zap/webswing/admin/webswing-admin-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/admin/webswing-admin-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:log4j-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.20.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.20.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/admin/webswing-admin-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"eb2a9a47b1396e00b5eee1264296729a70565cc0"}]}}},{"vulnerability":{"id":"GHSA-3pxv-7cmr-fjr4","dataSource":"https://github.com/advisories/GHSA-3pxv-7cmr-fjr4","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34480","https://github.com/apache/logging-log4j2/pull/4077","https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","https://logging.apache.org/security.html#CVE-2026-34480","http://www.openwall.com/lists/oss-security/2026/04/10/9"],"description":"Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34480","epss":0.00972,"percentile":0.59901,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34480","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["2.25.4"],"state":"fixed","available":[{"version":"2.25.4","date":"2026-04-11","kind":"first-observed"}]},"advisories":[],"risk":0.57834},"relatedVulnerabilities":[{"id":"CVE-2026-34480","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34480","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/apache/logging-log4j2/pull/4077","https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","https://logging.apache.org/security.html#CVE-2026-34480","http://www.openwall.com/lists/oss-security/2026/04/10/9"],"description":"Apache Log4j Core's  XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the  XML 1.0 specification https://www.w3.org/TR/xml/#charsets  producing invalid XML output whenever a log message or MDC value contains such characters.\n\nThe impact depends on the StAX implementation in use:\n\n  *  JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records.\n  *  Alternative StAX implementations (e.g.,  Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger.\n\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34480","epss":0.00972,"percentile":0.59901,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34480","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.20.0"}},"found":{"vulnerabilityID":"GHSA-3pxv-7cmr-fjr4","versionConstraint":">=2.0-alpha1,<2.25.4 (unknown)"},"fix":{"suggestedVersion":"2.25.4"}}],"artifact":{"id":"0b7b26b2a9f8e3ea","name":"log4j-core","version":"2.20.0","type":"java-archive","locations":[{"path":"/zap/webswing/webswing-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/webswing-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:log4j-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.20.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.20.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/webswing-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"eb2a9a47b1396e00b5eee1264296729a70565cc0"}]}}},{"vulnerability":{"id":"GHSA-3pxv-7cmr-fjr4","dataSource":"https://github.com/advisories/GHSA-3pxv-7cmr-fjr4","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34480","https://github.com/apache/logging-log4j2/pull/4077","https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","https://logging.apache.org/security.html#CVE-2026-34480","http://www.openwall.com/lists/oss-security/2026/04/10/9"],"description":"Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34480","epss":0.00972,"percentile":0.59901,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34480","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["2.25.4"],"state":"fixed","available":[{"version":"2.25.4","date":"2026-04-11","kind":"first-observed"}]},"advisories":[],"risk":0.57834},"relatedVulnerabilities":[{"id":"CVE-2026-34480","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34480","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/apache/logging-log4j2/pull/4077","https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","https://logging.apache.org/security.html#CVE-2026-34480","http://www.openwall.com/lists/oss-security/2026/04/10/9"],"description":"Apache Log4j Core's  XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the  XML 1.0 specification https://www.w3.org/TR/xml/#charsets  producing invalid XML output whenever a log message or MDC value contains such characters.\n\nThe impact depends on the StAX implementation in use:\n\n  *  JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records.\n  *  Alternative StAX implementations (e.g.,  Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger.\n\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34480","epss":0.00972,"percentile":0.59901,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34480","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.25.2"}},"found":{"vulnerabilityID":"GHSA-3pxv-7cmr-fjr4","versionConstraint":">=2.0-alpha1,<2.25.4 (unknown)"},"fix":{"suggestedVersion":"2.25.4"}}],"artifact":{"id":"a9ba8caf0d394805","name":"log4j-core","version":"2.25.2","type":"java-archive","locations":[{"path":"/zap/lib/log4j-core-2.25.2.jar","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/lib/log4j-core-2.25.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"cpes":["cpe:2.3:a:apache:log4j-core:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.25.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.25.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/lib/log4j-core-2.25.2.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"d4d0ad2e51e03e531f784891fbfff1bae1e13a12"}]}}},{"vulnerability":{"id":"GHSA-445c-vh5m-36rj","dataSource":"https://github.com/advisories/GHSA-445c-vh5m-36rj","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34478","https://github.com/apache/logging-log4j2/pull/4074","https://lists.apache.org/thread/3k1clr2l6vkdnl4cbhjrnt1nyjvb5gwt","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout","https://logging.apache.org/security.html#CVE-2026-34478","http://www.openwall.com/lists/oss-security/2026/04/10/7"],"description":"Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34478","epss":0.00972,"percentile":0.59901,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34478","cwe":"CWE-117","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-34478","cwe":"CWE-684","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["2.25.4"],"state":"fixed","available":[{"version":"2.25.4","date":"2026-04-14","kind":"first-observed"}]},"advisories":[],"risk":0.57834},"relatedVulnerabilities":[{"id":"CVE-2026-34478","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34478","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/apache/logging-log4j2/pull/4074","https://lists.apache.org/thread/3k1clr2l6vkdnl4cbhjrnt1nyjvb5gwt","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout","https://logging.apache.org/security.html#CVE-2026-34478","http://www.openwall.com/lists/oss-security/2026/04/10/7"],"description":"Apache Log4j Core's  Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.\n\nTwo distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:\n\n  *  The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output.\n  *  The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping.\n\n\nUsers of the SyslogAppender are not affected, as its configuration attributes were not modified.\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34478","epss":0.00972,"percentile":0.59901,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34478","cwe":"CWE-117","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-34478","cwe":"CWE-684","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.25.2"}},"found":{"vulnerabilityID":"GHSA-445c-vh5m-36rj","versionConstraint":">=2.21.0,<2.25.4 (unknown)"},"fix":{"suggestedVersion":"2.25.4"}}],"artifact":{"id":"a9ba8caf0d394805","name":"log4j-core","version":"2.25.2","type":"java-archive","locations":[{"path":"/zap/lib/log4j-core-2.25.2.jar","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/lib/log4j-core-2.25.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"cpes":["cpe:2.3:a:apache:log4j-core:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.25.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.25.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/lib/log4j-core-2.25.2.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"d4d0ad2e51e03e531f784891fbfff1bae1e13a12"}]}}},{"vulnerability":{"id":"GHSA-57rv-r2g8-2cj3","dataSource":"https://github.com/advisories/GHSA-57rv-r2g8-2cj3","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-57rv-r2g8-2cj3","https://nvd.nist.gov/vuln/detail/CVE-2026-42584"],"description":"Netty has HttpClientCodec response desynchronization","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42584","epss":0.00779,"percentile":0.53742,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42584","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42584","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.133.Final"],"state":"fixed","available":[{"version":"4.1.133.Final","date":"2026-05-07","kind":"first-observed"}]},"advisories":[],"risk":0.57646},"relatedVulnerabilities":[{"id":"CVE-2026-42584","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42584","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/netty/netty/security/advisories/GHSA-57rv-r2g8-2cj3","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-42584","https://bugzilla.redhat.com/show_bug.cgi?id=2477224","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42584.json"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42584","epss":0.00779,"percentile":0.53742,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42584","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42584","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-57rv-r2g8-2cj3","versionConstraint":"<=4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.133.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2023-39616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39616","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39616","epss":0.00738,"percentile":0.52389,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39616","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5535},"relatedVulnerabilities":[{"id":"CVE-2023-39616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39616","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.chromium.org/p/aomedia/issues/detail?id=3372#c3"],"description":"AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39616","epss":0.00738,"percentile":0.52389,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39616","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"aom","version":"3.6.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-39616","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9e3b0cc1c76e74b4","name":"libaom3","version":"3.6.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libaom3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libaom3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libaom3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libaom3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","BSD-2-clause","BSD-3-clause","Expat","ISC","public-domain-md5"],"cpes":["cpe:2.3:a:libaom3:libaom3:3.6.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libaom3@3.6.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=aom","upstreams":[{"name":"aom"}]}},{"vulnerability":{"id":"CVE-2023-50495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","epss":0.00962,"percentile":0.59549,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.55315},"relatedVulnerabilities":[{"id":"CVE-2023-50495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","epss":0.00962,"percentile":0.59549,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3a2ba7a41a0529","name":"libncursesw6","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2023-50495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","epss":0.00962,"percentile":0.59549,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.55315},"relatedVulnerabilities":[{"id":"CVE-2023-50495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","epss":0.00962,"percentile":0.59549,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6231fb14cfeaaac","name":"libtinfo6","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2023-50495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","epss":0.00962,"percentile":0.59549,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.55315},"relatedVulnerabilities":[{"id":"CVE-2023-50495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","epss":0.00962,"percentile":0.59549,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec73073218fd031a","name":"ncurses-base","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2023-50495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","epss":0.00962,"percentile":0.59549,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.55315},"relatedVulnerabilities":[{"id":"CVE-2023-50495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","epss":0.00962,"percentile":0.59549,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c5b18ac268f2ccdf","name":"ncurses-bin","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2026-18924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18924","epss":0.00608,"percentile":0.47103,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5502400000000001},"relatedVulnerabilities":[{"id":"CVE-2026-18924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18924","epss":0.00608,"percentile":0.47103,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-18924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18924","epss":0.00608,"percentile":0.47103,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5502400000000001},"relatedVulnerabilities":[{"id":"CVE-2026-18924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18924","epss":0.00608,"percentile":0.47103,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-18924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18924","epss":0.00608,"percentile":0.47103,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5502400000000001},"relatedVulnerabilities":[{"id":"CVE-2026-18924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18924","epss":0.00608,"percentile":0.47103,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"GHSA-pvp8-3xj6-8c6x","dataSource":"https://github.com/advisories/GHSA-pvp8-3xj6-8c6x","namespace":"github:language:java","severity":"Low","urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-46392","https://lists.apache.org/thread/y1pl0mn3opz6kwkm873zshjdxq3dwq5s","https://www.cve.org/CVERecord?id=CVE-2024-29131","https://www.cve.org/CVERecord?id=CVE-2024-29133"],"description":"Apache Commons Configuration Uncontrolled Resource Consumption","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":2.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-46392","epss":0.01929,"percentile":0.78763,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-46392","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.5497650000000001},"relatedVulnerabilities":[{"id":"CVE-2025-46392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-46392","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.apache.org/thread/y1pl0mn3opz6kwkm873zshjdxq3dwq5s","https://www.cve.org/CVERecord?id=CVE-2024-29131","https://www.cve.org/CVERecord?id=CVE-2024-29133"],"description":"Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x.\n\nThere are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenario's where you only load trusted configurations. \n\n\nUsers that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-46392","epss":0.01929,"percentile":0.78763,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-46392","cwe":"CWE-400","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"commons-configuration:commons-configuration","version":"1.10"}},"found":{"vulnerabilityID":"GHSA-pvp8-3xj6-8c6x","versionConstraint":"<=1.10 (unknown)"}}],"artifact":{"id":"518b4edcad81cd57","name":"commons-configuration","version":"1.10","type":"java-archive","locations":[{"path":"/zap/lib/commons-configuration-1.10.jar","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/lib/commons-configuration-1.10.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:commons-configuration:1.10:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_configuration:1.10:*:*:*:*:*:*:*","cpe:2.3:a:apache:configuration:1.10:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:1.10:*:*:*:*:*:*:*"],"purl":"pkg:maven/commons-configuration/commons-configuration@1.10","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/lib/commons-configuration-1.10.jar","pomArtifactID":"commons-configuration","pomGroupID":"commons-configuration","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"2b36e4adfb66d966c5aef2d73deb6be716389dc9"}]}}},{"vulnerability":{"id":"CVE-2017-7475","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.","cvss":[],"epss":[{"cve":"CVE-2017-7475","epss":0.01824,"percentile":0.77499,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5471999999999999},"relatedVulnerabilities":[{"id":"CVE-2017-7475","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-7475","epss":0.01824,"percentile":0.77499,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be12828c4e3c1a16","name":"libcairo-gobject2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo-gobject2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2017-7475","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-7475","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.","cvss":[],"epss":[{"cve":"CVE-2017-7475","epss":0.01824,"percentile":0.77499,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5471999999999999},"relatedVulnerabilities":[{"id":"CVE-2017-7475","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-7475","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/oss-sec/2017/q2/151","https://bugs.freedesktop.org/show_bug.cgi?id=100763","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7475","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-7475","epss":0.01824,"percentile":0.77499,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-7475","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-7475","versionConstraint":"none (unknown)"}}],"artifact":{"id":"28d5ccf8758a4075","name":"libcairo2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo2:libcairo2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2026-74943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74943","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74943","epss":0.0057,"percentile":0.45236,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74943","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-74943","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.5358},"relatedVulnerabilities":[{"id":"CVE-2026-74943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74943","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2057308","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74943","epss":0.0057,"percentile":0.45236,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74943","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-74943","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74943","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-63382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63382","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can select only the first header, evhttp_check_transfer_encoding_ was absent so the previous whole-string comparison fails to recognize valid lists ending in chunked, and evhttp_handle_chunked_read uses EVBUFFER_EOL_CRLF rather than EVBUFFER_EOL_CRLF_STRICT, accepting bare LF chunk terminators. When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63382","epss":0.00587,"percentile":0.4612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63382","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.5341699999999999},"relatedVulnerabilities":[{"id":"CVE-2026-63382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63382","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6","https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e","https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660","https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0","https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j"],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can select only the first header, evhttp_check_transfer_encoding_ was absent so the previous whole-string comparison fails to recognize valid lists ending in chunked, and evhttp_handle_chunked_read uses EVBUFFER_EOL_CRLF rather than EVBUFFER_EOL_CRLF_STRICT, accepting bare LF chunk terminators. When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63382","epss":0.00587,"percentile":0.4612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63382","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libevent","version":"2.1.12-stable-8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3bff02d75bb58680","name":"libevent-2.1-7","version":"2.1.12-stable-8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libevent-2.1-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libevent-2.1-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSL","Expat","FSFUL","FSFULLR","FSFULLR-No-Warranty","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","curl"],"cpes":["cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1-7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libevent-2.1-7@2.1.12-stable-8?arch=amd64&distro=debian-12.15&upstream=libevent","upstreams":[{"name":"libevent"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5337999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5337999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5337999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5337999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5337999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5337999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-9669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5337999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-9669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9669","epss":0.0068,"percentile":0.50301,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-16389","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16389","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16389","epss":0.00565,"percentile":0.45042,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16389","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["2:3.87.1-1+deb12u4"],"state":"fixed","available":[{"version":"2:3.87.1-1+deb12u4","date":"2026-08-11","kind":"first-observed"}]},"advisories":[],"risk":0.5311},"relatedVulnerabilities":[{"id":"CVE-2026-16389","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16389","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2043887","https://www.mozilla.org/security/advisories/mfsa2026-68/","https://www.mozilla.org/security/advisories/mfsa2026-71/","https://lists.debian.org/debian-lts-announce/2026/08/msg00019.html"],"description":"Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16389","epss":0.00565,"percentile":0.45042,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16389","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nss","version":"2:3.87.1-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16389","versionConstraint":"< 2:3.87.1-1+deb12u4 (deb)"},"fix":{"suggestedVersion":"2:3.87.1-1+deb12u4"}}],"artifact":{"id":"3325a62774655e15","name":"libnss3","version":"2:3.87.1-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3","MPL-2.0","Zlib","public-domain"],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.87.1-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.87.1-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2026-27601","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27601","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastructure, for example using JSON.parse, with no enforced depth limit. The datastructure thus created must be passed to _.flatten or _.isEqual. In the case of _.flatten, the vulnerability can only be exploited if it is possible for a remote client to prepare a datastructure that consists of arrays at all levels AND if no finite depth limit is passed as the second argument to _.flatten. In the case of _.isEqual, the vulnerability can only be exploited if there exists a code path in which two distinct datastructures that were submitted by the same remote client are compared using _.isEqual. For example, if a client submits data that are stored in a database, and the same client can later submit another datastructure that is then compared to the data that were saved in the database previously, OR if a client submits a single request, but its data are parsed twice, creating two non-identical but equivalent datastructures that are then compared. Exceptions originating from the call to _.flatten or _.isEqual, as a result of a stack overflow, are not being caught. This vulnerability is fixed in 1.13.8.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27601","epss":0.0096,"percentile":0.59455,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27601","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5232},"relatedVulnerabilities":[{"id":"CVE-2026-27601","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27601","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jashkenas/underscore/commit/411e222eb0ca5d570cc4f6315c02c05b830ed2b4","https://github.com/jashkenas/underscore/commit/a6e23ae9647461ec33ad9f92a2ecfc220eea0a84","https://github.com/jashkenas/underscore/security/advisories/GHSA-qpx9-hpmf-5gmw"],"description":"Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastructure, for example using JSON.parse, with no enforced depth limit. The datastructure thus created must be passed to _.flatten or _.isEqual. In the case of _.flatten, the vulnerability can only be exploited if it is possible for a remote client to prepare a datastructure that consists of arrays at all levels AND if no finite depth limit is passed as the second argument to _.flatten. In the case of _.isEqual, the vulnerability can only be exploited if there exists a code path in which two distinct datastructures that were submitted by the same remote client are compared using _.isEqual. For example, if a client submits data that are stored in a database, and the same client can later submit another datastructure that is then compared to the data that were saved in the database previously, OR if a client submits a single request, but its data are parsed twice, creating two non-identical but equivalent datastructures that are then compared. Exceptions originating from the call to _.flatten or _.isEqual, as a result of a stack overflow, are not being caught. This vulnerability is fixed in 1.13.8.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27601","epss":0.0096,"percentile":0.59455,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27601","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"underscore","version":"1.13.4~dfsg+~1.11.4-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27601","versionConstraint":"none (unknown)"}}],"artifact":{"id":"16597d15e0c46e47","name":"libjs-underscore","version":"1.13.4~dfsg+~1.11.4-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjs-underscore/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjs-underscore/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjs-underscore.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjs-underscore.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjs-underscore.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjs-underscore.list"}],"language":"","licenses":["BSD-3-clause","Expat","GPL-3","GPL-3+"],"cpes":["cpe:2.3:a:libjs-underscore:libjs-underscore:1.13.4\\~dfsg\\+\\~1.11.4-3:*:*:*:*:*:*:*","cpe:2.3:a:libjs-underscore:libjs_underscore:1.13.4\\~dfsg\\+\\~1.11.4-3:*:*:*:*:*:*:*","cpe:2.3:a:libjs_underscore:libjs-underscore:1.13.4\\~dfsg\\+\\~1.11.4-3:*:*:*:*:*:*:*","cpe:2.3:a:libjs_underscore:libjs_underscore:1.13.4\\~dfsg\\+\\~1.11.4-3:*:*:*:*:*:*:*","cpe:2.3:a:libjs:libjs-underscore:1.13.4\\~dfsg\\+\\~1.11.4-3:*:*:*:*:*:*:*","cpe:2.3:a:libjs:libjs_underscore:1.13.4\\~dfsg\\+\\~1.11.4-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjs-underscore@1.13.4~dfsg%2B~1.11.4-3?arch=all&distro=debian-12.15&upstream=underscore","upstreams":[{"name":"underscore"}]}},{"vulnerability":{"id":"CVE-2019-6988","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6988","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.","cvss":[],"epss":[{"cve":"CVE-2019-6988","epss":0.01724,"percentile":0.7615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5172},"relatedVulnerabilities":[{"id":"CVE-2019-6988","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6988","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106785","https://github.com/uclouvain/openjpeg/issues/1178"],"description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-6988","epss":0.01724,"percentile":0.7615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-6988","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-8924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.0056,"percentile":0.44758,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5068},"relatedVulnerabilities":[{"id":"CVE-2026-8924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.0056,"percentile":0.44758,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.0056,"percentile":0.44758,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5068},"relatedVulnerabilities":[{"id":"CVE-2026-8924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.0056,"percentile":0.44758,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.0056,"percentile":0.44758,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5068},"relatedVulnerabilities":[{"id":"CVE-2026-8924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n'super cookies' that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8924","epss":0.0056,"percentile":0.44758,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.504},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.504},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.504},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.504},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.504},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.504},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-7210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.504},"relatedVulnerabilities":[{"id":"CVE-2026-7210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7210","epss":0.00672,"percentile":0.49929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-74990","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74990","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74990","epss":0.00534,"percentile":0.43343,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74990","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.5019600000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74990","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74990","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045762%2C2052401%2C2058208","https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045774%2C2048490%2C2050864%2C2053159%2C2053260%2C2053261%2C2053582%2C2053599%2C2053607%2C2053608%2C2053853%2C2054626%2C2054627%2C2054635%2C2054677%2C2054740%2C2054832%2C2056792%2C2057098%2C2057100%2C2057101%2C2057103%2C2057117%2C2057118%2C2058048%2C2058049%2C2058622%2C2058623%2C2058665%2C2058666%2C2059121%2C2059164%2C2059188","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74990","epss":0.00534,"percentile":0.43343,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74990","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74990","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-58015","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58015","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58015","epss":0.00661,"percentile":0.49511,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.49575},"relatedVulnerabilities":[{"id":"CVE-2026-58015","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58015","epss":0.00661,"percentile":0.49511,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58015","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58015","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58015","epss":0.00661,"percentile":0.49511,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.49575},"relatedVulnerabilities":[{"id":"CVE-2026-58015","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58015","epss":0.00661,"percentile":0.49511,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-58015","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"GHSA-jppx-w49h-x2qq","dataSource":"https://github.com/advisories/GHSA-jppx-w49h-x2qq","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq","https://nvd.nist.gov/vuln/detail/CVE-2026-56745","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56745","epss":0.00612,"percentile":0.47269,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.49571999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-56745","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56745","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"],"description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56745","epss":0.00612,"percentile":0.47269,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-jppx-w49h-x2qq","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-jppx-w49h-x2qq","dataSource":"https://github.com/advisories/GHSA-jppx-w49h-x2qq","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq","https://nvd.nist.gov/vuln/detail/CVE-2026-56745","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56745","epss":0.00612,"percentile":0.47269,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.49571999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-56745","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56745","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"],"description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56745","epss":0.00612,"percentile":0.47269,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-jppx-w49h-x2qq","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-58016","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58016","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58016","epss":0.00545,"percentile":0.43968,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.493225},"relatedVulnerabilities":[{"id":"CVE-2026-58016","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","namespace":"nvd:cpe","severity":"Critical","urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58016","epss":0.00545,"percentile":0.43968,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58016","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58016","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58016","epss":0.00545,"percentile":0.43968,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.493225},"relatedVulnerabilities":[{"id":"CVE-2026-58016","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","namespace":"nvd:cpe","severity":"Critical","urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58016","epss":0.00545,"percentile":0.43968,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-74987","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74987","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74987","epss":0.00523,"percentile":0.4268,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74987","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.49162000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-74987","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74987","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/buglist.cgi?bug_id=1500946%2C1788109%2C2045379%2C2045380%2C2049339%2C2049393%2C2053580%2C2054662%2C2054665%2C2054673%2C2054785%2C2058645","https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048797%2C2050536%2C2053272%2C2053579%2C2057115%2C2057116%2C2057130%2C2057991%2C2057995%2C2058002%2C2058008%2C2058032%2C2058102%2C2058667","https://bugzilla.mozilla.org/show_bug.cgi?id=2059424","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74987","epss":0.00523,"percentile":0.4268,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74987","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74987","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"GHSA-qh8g-58pp-2wxh","dataSource":"https://github.com/advisories/GHSA-qh8g-58pp-2wxh","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://nvd.nist.gov/vuln/detail/CVE-2024-6763","https://github.com/jetty/jetty.project/pull/12012","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005"],"description":"Eclipse Jetty URI parsing of invalid authority","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-6763","epss":0.00965,"percentile":0.59623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["12.0.12"],"state":"fixed","available":[{"version":"12.0.12","date":"2024-10-15","kind":"first-observed"}]},"advisories":[],"risk":0.48250000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-6763","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-6763","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jetty/jetty.project/pull/12012","https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005/"],"description":"Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.\n\nThe HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI\n differs from the common browsers in how it handles a URI that would be \nconsidered invalid if fully validated against the RRC.  Specifically HttpURI\n and the browser may differ on the value of the host extracted from an \ninvalid URI and thus a combination of Jetty and a vulnerable browser may\n be vulnerable to a open redirect attack or to a SSRF attack if the URI \nis used after passing validation checks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-6763","epss":0.00965,"percentile":0.59623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.56.v20240826"}},"found":{"vulnerabilityID":"GHSA-qh8g-58pp-2wxh","versionConstraint":">=7.0.0,<=12.0.11 (unknown)"},"fix":{"suggestedVersion":"12.0.12"}}],"artifact":{"id":"1240a4d50758cd81","name":"jetty-http","version":"9.4.56.v20240826","type":"java-archive","locations":[{"path":"/zap/webswing/server/webswing-jetty-launcher.jar","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/server/webswing-jetty-launcher.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.56.v20240826","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/server/webswing-jetty-launcher.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-qh8g-58pp-2wxh","dataSource":"https://github.com/advisories/GHSA-qh8g-58pp-2wxh","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://nvd.nist.gov/vuln/detail/CVE-2024-6763","https://github.com/jetty/jetty.project/pull/12012","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005"],"description":"Eclipse Jetty URI parsing of invalid authority","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-6763","epss":0.00965,"percentile":0.59623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["12.0.12"],"state":"fixed","available":[{"version":"12.0.12","date":"2024-10-15","kind":"first-observed"}]},"advisories":[],"risk":0.48250000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-6763","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-6763","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jetty/jetty.project/pull/12012","https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005/"],"description":"Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.\n\nThe HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI\n differs from the common browsers in how it handles a URI that would be \nconsidered invalid if fully validated against the RRC.  Specifically HttpURI\n and the browser may differ on the value of the host extracted from an \ninvalid URI and thus a combination of Jetty and a vulnerable browser may\n be vulnerable to a open redirect attack or to a SSRF attack if the URI \nis used after passing validation checks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-6763","epss":0.00965,"percentile":0.59623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.57.v20241219"}},"found":{"vulnerabilityID":"GHSA-qh8g-58pp-2wxh","versionConstraint":">=7.0.0,<=12.0.11 (unknown)"},"fix":{"suggestedVersion":"12.0.12"}}],"artifact":{"id":"12be712711d3c78e","name":"jetty-http","version":"9.4.57.v20241219","type":"java-archive","locations":[{"path":"/zap/plugin/selenium-release-15.53.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/selenium-release-15.53.0.zap:libs/htmlunit-websocket-client-4.14.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.57.v20241219","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/selenium-release-15.53.0.zap:libs/htmlunit-websocket-client-4.14.0.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-qh8g-58pp-2wxh","dataSource":"https://github.com/advisories/GHSA-qh8g-58pp-2wxh","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://nvd.nist.gov/vuln/detail/CVE-2024-6763","https://github.com/jetty/jetty.project/pull/12012","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005"],"description":"Eclipse Jetty URI parsing of invalid authority","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-6763","epss":0.00965,"percentile":0.59623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["12.0.12"],"state":"fixed","available":[{"version":"12.0.12","date":"2024-10-15","kind":"first-observed"}]},"advisories":[],"risk":0.48250000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-6763","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-6763","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jetty/jetty.project/pull/12012","https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005/"],"description":"Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.\n\nThe HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI\n differs from the common browsers in how it handles a URI that would be \nconsidered invalid if fully validated against the RRC.  Specifically HttpURI\n and the browser may differ on the value of the host extracted from an \ninvalid URI and thus a combination of Jetty and a vulnerable browser may\n be vulnerable to a open redirect attack or to a SSRF attack if the URI \nis used after passing validation checks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-6763","epss":0.00965,"percentile":0.59623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.57.v20241219"}},"found":{"vulnerabilityID":"GHSA-qh8g-58pp-2wxh","versionConstraint":">=7.0.0,<=12.0.11 (unknown)"},"fix":{"suggestedVersion":"12.0.12"}}],"artifact":{"id":"c9700e6689975883","name":"jetty-http","version":"9.4.57.v20241219","type":"java-archive","locations":[{"path":"/zap/plugin/selenium-release-15.43.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/selenium-release-15.43.0.zap:libs/htmlunit-websocket-client-4.14.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.57.v20241219","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/selenium-release-15.43.0.zap:libs/htmlunit-websocket-client-4.14.0.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-pwqr-wmgm-9rr8","dataSource":"https://github.com/advisories/GHSA-pwqr-wmgm-9rr8","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-pwqr-wmgm-9rr8","https://w4ke.info/2025/06/18/funky-chunks.html","https://w4ke.info/2025/10/29/funky-chunks-2.html","https://www.rfc-editor.org/rfc/rfc9110","https://nvd.nist.gov/vuln/detail/CVE-2026-33870"],"description":"Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-33870","epss":0.0064,"percentile":0.48592,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-33870","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-33870","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.132.Final"],"state":"fixed","available":[{"version":"4.1.132.Final","date":"2026-03-27","kind":"first-observed"}]},"advisories":[],"risk":0.48000000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-33870","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33870","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-pwqr-wmgm-9rr8","https://w4ke.info/2025/06/18/funky-chunks.html","https://w4ke.info/2025/10/29/funky-chunks-2.html","https://www.rfc-editor.org/rfc/rfc9110","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:17789","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:22619","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:7109","https://access.redhat.com/errata/RHSA-2026:7380","https://access.redhat.com/errata/RHSA-2026:8159","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-33870","https://bugzilla.redhat.com/show_bug.cgi?id=2452453","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33870.json"],"description":"Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-33870","epss":0.0064,"percentile":0.48592,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-33870","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-33870","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-pwqr-wmgm-9rr8","versionConstraint":"<4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.132.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-15308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47774999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-15308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47774999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-15308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47774999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-15308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47774999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-15308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47774999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-15308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-15308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47774999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-15308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47774999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-15308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15308","epss":0.00637,"percentile":0.48445,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-66046","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66046","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66046","epss":0.00586,"percentile":0.46064,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.4746599999999999},"relatedVulnerabilities":[{"id":"CVE-2026-66046","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66046","epss":0.00586,"percentile":0.46064,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-66046","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66046","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66046","epss":0.00586,"percentile":0.46064,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.4746599999999999},"relatedVulnerabilities":[{"id":"CVE-2026-66046","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66046","epss":0.00586,"percentile":0.46064,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2023-5388","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-5388","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-5388","epss":0.00822,"percentile":0.55147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5388","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47264999999999996},"relatedVulnerabilities":[{"id":"CVE-2023-5388","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5388","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=1780432","https://lists.debian.org/debian-lts-announce/2024/03/msg00022.html","https://lists.debian.org/debian-lts-announce/2024/03/msg00028.html","https://www.mozilla.org/security/advisories/mfsa2024-12/","https://www.mozilla.org/security/advisories/mfsa2024-13/","https://www.mozilla.org/security/advisories/mfsa2024-14/","https://lists.debian.org/debian-lts-announce/2024/03/msg00010.html"],"description":"NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-5388","epss":0.00822,"percentile":0.55147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5388","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nss","version":"2:3.87.1-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-5388","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3325a62774655e15","name":"libnss3","version":"2:3.87.1-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3","MPL-2.0","Zlib","public-domain"],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.87.1-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.87.1-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2026-5450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47188},"relatedVulnerabilities":[{"id":"CVE-2026-5450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","namespace":"nvd:cpe","severity":"Critical","urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47188},"relatedVulnerabilities":[{"id":"CVE-2026-5450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","namespace":"nvd:cpe","severity":"Critical","urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47188},"relatedVulnerabilities":[{"id":"CVE-2026-5450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","namespace":"nvd:cpe","severity":"Critical","urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47188},"relatedVulnerabilities":[{"id":"CVE-2026-5450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","namespace":"nvd:cpe","severity":"Critical","urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.47188},"relatedVulnerabilities":[{"id":"CVE-2026-5450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","namespace":"nvd:cpe","severity":"Critical","urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5450","epss":0.00502,"percentile":0.41338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-5450","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"GHSA-vc5p-v9hr-52mj","dataSource":"https://github.com/advisories/GHSA-vc5p-v9hr-52mj","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-68161","https://github.com/apache/logging-log4j2/pull/4002","https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName","https://logging.apache.org/security.html#CVE-2025-68161","https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578","http://www.openwall.com/lists/oss-security/2025/12/18/1"],"description":"Apache Log4j does not verify the TLS hostname in its Socket Appender","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68161","epss":0.00816,"percentile":0.54948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68161","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2025-68161","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["2.25.3"],"state":"fixed","available":[{"version":"2.25.3","date":"2025-12-20","kind":"first-observed"}]},"advisories":[],"risk":0.46103999999999995},"relatedVulnerabilities":[{"id":"CVE-2025-68161","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68161","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4002","https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName","https://logging.apache.org/security.html#CVE-2025-68161","http://www.openwall.com/lists/oss-security/2025/12/18/1","https://lists.debian.org/debian-lts-announce/2026/01/msg00015.html"],"description":"The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the  verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName  configuration attribute or the  log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName  system property is set to true.\n\nThis issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions:\n\n  *  The attacker is able to intercept or redirect network traffic between the client and the log receiver.\n  *  The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured).\n\n\nUsers are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue.\n\nAs an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"exploitabilityScore":2.3,"impactScore":2.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68161","epss":0.00816,"percentile":0.54948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68161","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2025-68161","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.20.0"}},"found":{"vulnerabilityID":"GHSA-vc5p-v9hr-52mj","versionConstraint":">=2.0-beta9,<2.25.3 (unknown)"},"fix":{"suggestedVersion":"2.25.3"}}],"artifact":{"id":"0b7b26b2a9f8e3ea","name":"log4j-core","version":"2.20.0","type":"java-archive","locations":[{"path":"/zap/webswing/webswing-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/webswing-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:log4j-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.20.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.20.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/webswing-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"eb2a9a47b1396e00b5eee1264296729a70565cc0"}]}}},{"vulnerability":{"id":"GHSA-vc5p-v9hr-52mj","dataSource":"https://github.com/advisories/GHSA-vc5p-v9hr-52mj","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-68161","https://github.com/apache/logging-log4j2/pull/4002","https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName","https://logging.apache.org/security.html#CVE-2025-68161","https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578","http://www.openwall.com/lists/oss-security/2025/12/18/1"],"description":"Apache Log4j does not verify the TLS hostname in its Socket Appender","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68161","epss":0.00816,"percentile":0.54948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68161","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2025-68161","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["2.25.3"],"state":"fixed","available":[{"version":"2.25.3","date":"2025-12-20","kind":"first-observed"}]},"advisories":[],"risk":0.46103999999999995},"relatedVulnerabilities":[{"id":"CVE-2025-68161","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68161","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4002","https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName","https://logging.apache.org/security.html#CVE-2025-68161","http://www.openwall.com/lists/oss-security/2025/12/18/1","https://lists.debian.org/debian-lts-announce/2026/01/msg00015.html"],"description":"The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the  verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName  configuration attribute or the  log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName  system property is set to true.\n\nThis issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions:\n\n  *  The attacker is able to intercept or redirect network traffic between the client and the log receiver.\n  *  The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured).\n\n\nUsers are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue.\n\nAs an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"exploitabilityScore":2.3,"impactScore":2.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68161","epss":0.00816,"percentile":0.54948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68161","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2025-68161","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.20.0"}},"found":{"vulnerabilityID":"GHSA-vc5p-v9hr-52mj","versionConstraint":">=2.0-beta9,<2.25.3 (unknown)"},"fix":{"suggestedVersion":"2.25.3"}}],"artifact":{"id":"89dc48ff2ee6f684","name":"log4j-core","version":"2.20.0","type":"java-archive","locations":[{"path":"/zap/webswing/admin/webswing-admin-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/admin/webswing-admin-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:log4j-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.20.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.20.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/admin/webswing-admin-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"eb2a9a47b1396e00b5eee1264296729a70565cc0"}]}}},{"vulnerability":{"id":"GHSA-vc5p-v9hr-52mj","dataSource":"https://github.com/advisories/GHSA-vc5p-v9hr-52mj","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-68161","https://github.com/apache/logging-log4j2/pull/4002","https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName","https://logging.apache.org/security.html#CVE-2025-68161","https://github.com/apache/logging-log4j2/commit/3b93748497e1adbbd027fda8a5e7268ec5d0d578","http://www.openwall.com/lists/oss-security/2025/12/18/1"],"description":"Apache Log4j does not verify the TLS hostname in its Socket Appender","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68161","epss":0.00816,"percentile":0.54948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68161","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2025-68161","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["2.25.3"],"state":"fixed","available":[{"version":"2.25.3","date":"2025-12-20","kind":"first-observed"}]},"advisories":[],"risk":0.46103999999999995},"relatedVulnerabilities":[{"id":"CVE-2025-68161","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68161","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4002","https://lists.apache.org/thread/xr33kyxq3sl67lwb61ggvm1fzc8k7dvx","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName","https://logging.apache.org/security.html#CVE-2025-68161","http://www.openwall.com/lists/oss-security/2025/12/18/1","https://lists.debian.org/debian-lts-announce/2026/01/msg00015.html"],"description":"The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the  verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName  configuration attribute or the  log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName  system property is set to true.\n\nThis issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions:\n\n  *  The attacker is able to intercept or redirect network traffic between the client and the log receiver.\n  *  The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured).\n\n\nUsers are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue.\n\nAs an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"exploitabilityScore":2.3,"impactScore":2.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68161","epss":0.00816,"percentile":0.54948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68161","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2025-68161","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.25.2"}},"found":{"vulnerabilityID":"GHSA-vc5p-v9hr-52mj","versionConstraint":">=2.0-beta9,<2.25.3 (unknown)"},"fix":{"suggestedVersion":"2.25.3"}}],"artifact":{"id":"a9ba8caf0d394805","name":"log4j-core","version":"2.25.2","type":"java-archive","locations":[{"path":"/zap/lib/log4j-core-2.25.2.jar","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/lib/log4j-core-2.25.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"cpes":["cpe:2.3:a:apache:log4j-core:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.25.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.25.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/lib/log4j-core-2.25.2.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"d4d0ad2e51e03e531f784891fbfff1bae1e13a12"}]}}},{"vulnerability":{"id":"GHSA-qv9r-c865-cp47","dataSource":"https://github.com/advisories/GHSA-qv9r-c865-cp47","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-49844","https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844","https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300","https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82","https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5","https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"],"description":"Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49844","epss":0.00813,"percentile":0.54846,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["2.25.5"],"state":"fixed","available":[{"version":"2.25.5","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.459345},"relatedVulnerabilities":[{"id":"CVE-2026-49844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49844","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844"],"description":"Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49844","epss":0.00813,"percentile":0.54846,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-api","version":"2.20.0"}},"found":{"vulnerabilityID":"GHSA-qv9r-c865-cp47","versionConstraint":">=2.13.1,<2.25.5 (unknown)"},"fix":{"suggestedVersion":"2.25.5"}}],"artifact":{"id":"c6352d2233d82924","name":"log4j-api","version":"2.20.0","type":"java-archive","locations":[{"path":"/zap/webswing/webswing-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/webswing-server.war:WEB-INF/lib/log4j-api-2.20.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:log4j-api:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_api:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:api:2.20.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-api@2.20.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/webswing-server.war:WEB-INF/lib/log4j-api-2.20.0.jar","pomArtifactID":"log4j-api","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"1fe6082e660daf07c689a89c94dc0f49c26b44bb"}]}}},{"vulnerability":{"id":"GHSA-qv9r-c865-cp47","dataSource":"https://github.com/advisories/GHSA-qv9r-c865-cp47","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-49844","https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844","https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300","https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82","https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5","https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"],"description":"Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49844","epss":0.00813,"percentile":0.54846,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["2.25.5"],"state":"fixed","available":[{"version":"2.25.5","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.459345},"relatedVulnerabilities":[{"id":"CVE-2026-49844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49844","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844"],"description":"Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49844","epss":0.00813,"percentile":0.54846,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-api","version":"2.20.0"}},"found":{"vulnerabilityID":"GHSA-qv9r-c865-cp47","versionConstraint":">=2.13.1,<2.25.5 (unknown)"},"fix":{"suggestedVersion":"2.25.5"}}],"artifact":{"id":"e368e8453a6e6b15","name":"log4j-api","version":"2.20.0","type":"java-archive","locations":[{"path":"/zap/webswing/admin/webswing-admin-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/admin/webswing-admin-server.war:WEB-INF/lib/log4j-api-2.20.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:log4j-api:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_api:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:api:2.20.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-api@2.20.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/admin/webswing-admin-server.war:WEB-INF/lib/log4j-api-2.20.0.jar","pomArtifactID":"log4j-api","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"1fe6082e660daf07c689a89c94dc0f49c26b44bb"}]}}},{"vulnerability":{"id":"GHSA-qv9r-c865-cp47","dataSource":"https://github.com/advisories/GHSA-qv9r-c865-cp47","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-49844","https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844","https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300","https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82","https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5","https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"],"description":"Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49844","epss":0.00813,"percentile":0.54846,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["2.25.5"],"state":"fixed","available":[{"version":"2.25.5","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.459345},"relatedVulnerabilities":[{"id":"CVE-2026-49844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49844","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844"],"description":"Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49844","epss":0.00813,"percentile":0.54846,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-api","version":"2.25.2"}},"found":{"vulnerabilityID":"GHSA-qv9r-c865-cp47","versionConstraint":">=2.13.1,<2.25.5 (unknown)"},"fix":{"suggestedVersion":"2.25.5"}}],"artifact":{"id":"13ffd55eccdec7fb","name":"log4j-api","version":"2.25.2","type":"java-archive","locations":[{"path":"/zap/lib/log4j-api-2.25.2.jar","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/lib/log4j-api-2.25.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"cpes":["cpe:2.3:a:apache:log4j-api:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_api:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:api:2.25.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-api@2.25.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/lib/log4j-api-2.25.2.jar","pomArtifactID":"log4j-api","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"292c1a2b1702f1e1e3adb13e1c57e5bff60335ff"}]}}},{"vulnerability":{"id":"CVE-2026-63072","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63072","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.  Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.  The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.  FIPS impact: no  As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63072","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.45899999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-63072","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63072","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f55823b1f5c2e201","name":"libssl3","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","upstreams":[{"name":"openssl"}]}},{"vulnerability":{"id":"CVE-2026-63072","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63072","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.  Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.  The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.  FIPS impact: no  As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63072","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.45899999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-63072","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63072","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7345802bd2ec0962","name":"openssl","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8927","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.005,"percentile":0.41228,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.4525},"relatedVulnerabilities":[{"id":"CVE-2026-8927","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.005,"percentile":0.41228,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8927","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.005,"percentile":0.41228,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.4525},"relatedVulnerabilities":[{"id":"CVE-2026-8927","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.005,"percentile":0.41228,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8927","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.005,"percentile":0.41228,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.4525},"relatedVulnerabilities":[{"id":"CVE-2026-8927","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","namespace":"nvd:cpe","severity":"Critical","urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8927","epss":0.005,"percentile":0.41228,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2023-5574","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-5574","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-5574","epss":0.00621,"percentile":0.47738,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5574","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-5574","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.45022500000000004},"relatedVulnerabilities":[{"id":"CVE-2023-5574","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5574","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2024:2298","https://access.redhat.com/security/cve/CVE-2023-5574","https://bugzilla.redhat.com/show_bug.cgi?id=2244735","https://lists.x.org/archives/xorg-announce/2023-October/003430.html","https://security.netapp.com/advisory/ntap-20231130-0004/"],"description":"A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-5574","epss":0.00621,"percentile":0.47738,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5574","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-5574","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-5574","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2023-5574","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-5574","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-5574","epss":0.00621,"percentile":0.47738,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5574","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-5574","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.45022500000000004},"relatedVulnerabilities":[{"id":"CVE-2023-5574","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5574","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2024:2298","https://access.redhat.com/security/cve/CVE-2023-5574","https://bugzilla.redhat.com/show_bug.cgi?id=2244735","https://lists.x.org/archives/xorg-announce/2023-October/003430.html","https://security.netapp.com/advisory/ntap-20231130-0004/"],"description":"A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-5574","epss":0.00621,"percentile":0.47738,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5574","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-5574","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-5574","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-74964","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74964","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74964","epss":0.00466,"percentile":0.38908,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74964","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.43804000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-74964","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74964","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2053327","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74964","epss":0.00466,"percentile":0.38908,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74964","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74964","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-75874","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75874","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75874","epss":0.00455,"percentile":0.3823,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75874","cwe":"CWE-693","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.43225},"relatedVulnerabilities":[{"id":"CVE-2026-75874","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75874","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2039972","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-83/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75874","epss":0.00455,"percentile":0.3823,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75874","cwe":"CWE-693","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75874","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2007-2768","dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2768","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.","cvss":[],"epss":[{"cve":"CVE-2007-2768","epss":0.08615,"percentile":0.9476,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.4307500000000001},"relatedVulnerabilities":[{"id":"CVE-2007-2768","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2768","namespace":"nvd:cpe","severity":"Medium","urls":["http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0635.html","http://www.osvdb.org/34601","https://security.netapp.com/advisory/ntap-20191107-0002/"],"description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2007-2768","epss":0.08615,"percentile":0.9476,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2007-2768","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2025-69534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.42450000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-69534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.42450000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-69534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.42450000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-69534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.42450000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-69534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.42450000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.42450000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-69534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.42450000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69534","epss":0.00566,"percentile":0.45109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2025-69534","cwe":"CWE-617","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-7598","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7598","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7598","epss":0.00466,"percentile":0.38923,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7598","cwe":"CWE-189","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-7598","cwe":"CWE-190","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-7598","cwe":"CWE-190","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["1.10.0-3+deb12u1"],"state":"fixed","available":[{"version":"1.10.0-3+deb12u1","date":"2026-09-06","kind":"first-observed"}]},"advisories":[],"risk":0.42173000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-7598","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7598","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/libssh2/libssh2/","https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1","https://github.com/libssh2/libssh2/pull/1858","https://vuldb.com/submit/805564","https://vuldb.com/vuln/360555","https://vuldb.com/vuln/360555/cti","https://access.redhat.com/errata/RHSA-2026:16736","https://access.redhat.com/errata/RHSA-2026:61752","https://access.redhat.com/errata/RHSA-2026:7021","https://access.redhat.com/security/cve/CVE-2026-7598","https://bugzilla.redhat.com/show_bug.cgi?id=2464597","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7598.json"],"description":"A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7598","epss":0.00466,"percentile":0.38923,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7598","cwe":"CWE-189","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-7598","cwe":"CWE-190","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-7598","cwe":"CWE-190","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libssh2","version":"1.10.0-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7598","versionConstraint":"< 1.10.0-3+deb12u1 (deb)"},"fix":{"suggestedVersion":"1.10.0-3+deb12u1"}}],"artifact":{"id":"865a7a71606e882c","name":"libssh2-1","version":"1.10.0-3+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssh2-1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD3"],"cpes":["cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12.15&upstream=libssh2%401.10.0-3","upstreams":[{"name":"libssh2","version":"1.10.0-3"}]}},{"vulnerability":{"id":"CVE-2018-6951","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6951","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue.","cvss":[],"epss":[{"cve":"CVE-2018-6951","epss":0.08427,"percentile":0.94658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.42135},"relatedVulnerabilities":[{"id":"CVE-2018-6951","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6951","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/103044","https://git.savannah.gnu.org/cgit/patch.git/commit/?id=f290f48a621867084884bfff87f8093c15195e6a","https://savannah.gnu.org/bugs/index.php?53132","https://security.gentoo.org/glsa/201904-17","https://usn.ubuntu.com/3624-1/"],"description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-6951","epss":0.08427,"percentile":0.94658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-6951","versionConstraint":"none (unknown)"}}],"artifact":{"id":"acc529981c64331f","name":"patch","version":"2.7.6-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.list"}],"language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-32740","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32740","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32740","epss":0.00514,"percentile":0.42071,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32740","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32740","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.41891},"relatedVulnerabilities":[{"id":"CVE-2026-32740","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32740","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-frfr-f3vg-2g6j","https://access.redhat.com/security/cve/CVE-2026-32740","https://bugzilla.redhat.com/show_bug.cgi?id=2479969","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32740.json"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32740","epss":0.00514,"percentile":0.42071,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32740","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32740","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32740","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-66040","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66040","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66040","epss":0.00513,"percentile":0.42052,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.418095},"relatedVulnerabilities":[{"id":"CVE-2026-66040","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66040","epss":0.00513,"percentile":0.42052,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66040","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66040","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66040","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66040","epss":0.00513,"percentile":0.42052,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.418095},"relatedVulnerabilities":[{"id":"CVE-2026-66040","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66040","epss":0.00513,"percentile":0.42052,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66040","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66040","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66040","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66040","epss":0.00513,"percentile":0.42052,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.418095},"relatedVulnerabilities":[{"id":"CVE-2026-66040","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66040","epss":0.00513,"percentile":0.42052,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66040","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-50142","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50142","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_boxes.cc, Box_stsz::parse() applies max_sequence_frames only to variable-size samples, so fixed-size mode accepts an attacker-controlled sample_count without a bound. In libheif/sequences/track.cc, Track::load() also adds current_sample_idx and samples_per_chunk in 32-bit arithmetic, allowing the consistency check to be bypassed by wraparound. The resulting values reach the Chunk::Chunk() allocation path, which can consume gigabytes of memory and crash or stall the process through memory exhaustion. This issue is fixed in version 1.23.0.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50142","epss":0.00556,"percentile":0.44528,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50142","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-50142","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.41700000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-50142","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50142","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/commit/a6caa38f7a70d66dc9caec2a7bfe20935b32c622","https://github.com/strukturag/libheif/releases/tag/v1.23.0","https://github.com/strukturag/libheif/security/advisories/GHSA-jvmp-j3cw-84mh"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_boxes.cc, Box_stsz::parse() applies max_sequence_frames only to variable-size samples, so fixed-size mode accepts an attacker-controlled sample_count without a bound. In libheif/sequences/track.cc, Track::load() also adds current_sample_idx and samples_per_chunk in 32-bit arithmetic, allowing the consistency check to be bypassed by wraparound. The resulting values reach the Chunk::Chunk() allocation path, which can consume gigabytes of memory and crash or stall the process through memory exhaustion. This issue is fixed in version 1.23.0.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50142","epss":0.00556,"percentile":0.44528,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50142","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-50142","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50142","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-8376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00443,"percentile":0.37336,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.41642},"relatedVulnerabilities":[{"id":"CVE-2026-8376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00443,"percentile":0.37336,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-8376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00443,"percentile":0.37336,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.41642},"relatedVulnerabilities":[{"id":"CVE-2026-8376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00443,"percentile":0.37336,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00443,"percentile":0.37336,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.41642},"relatedVulnerabilities":[{"id":"CVE-2026-8376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00443,"percentile":0.37336,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-8376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00443,"percentile":0.37336,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.41642},"relatedVulnerabilities":[{"id":"CVE-2026-8376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8376","epss":0.00443,"percentile":0.37336,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2018-6952","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6952","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.","cvss":[],"epss":[{"cve":"CVE-2018-6952","epss":0.0819,"percentile":0.94525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.40950000000000003},"relatedVulnerabilities":[{"id":"CVE-2018-6952","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6952","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/103047","https://access.redhat.com/errata/RHSA-2019:2033","https://savannah.gnu.org/bugs/index.php?53133","https://security.gentoo.org/glsa/201904-17"],"description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-6952","epss":0.0819,"percentile":0.94525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-6952","versionConstraint":"none (unknown)"}}],"artifact":{"id":"acc529981c64331f","name":"patch","version":"2.7.6-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.list"}],"language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-64834","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64834","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64834","epss":0.00503,"percentile":0.41353,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.40742999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-64834","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64834","epss":0.00503,"percentile":0.41353,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64834","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64834","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64834","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64834","epss":0.00503,"percentile":0.41353,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.40742999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-64834","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64834","epss":0.00503,"percentile":0.41353,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64834","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64834","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64834","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64834","epss":0.00503,"percentile":0.41353,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.40742999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-64834","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64834","epss":0.00503,"percentile":0.41353,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64834","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2023-32570","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-32570","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-32570","epss":0.00743,"percentile":0.52581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-32570","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-32570","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.40493500000000004},"relatedVulnerabilities":[{"id":"CVE-2023-32570","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-32570","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.videolan.org/videolan/dav1d/-/commit/cf617fdae0b9bfabd27282854c8e81450d955efa","https://code.videolan.org/videolan/dav1d/-/tags/1.2.0","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WGSO7UMOF4MVLQ5H6KIV7OG6ONS377B/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXZ6CUNJFDJLCFOZHY2TIGMCAEITLCRP/","https://security.gentoo.org/glsa/202310-05"],"description":"VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-32570","epss":0.00743,"percentile":0.52581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-32570","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-32570","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"dav1d","version":"1.0.0-2+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-32570","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d96162e7206cebef","name":"libdav1d6","version":"1.0.0-2+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libdav1d6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libdav1d6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libdav1d6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libdav1d6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","ISC","public-domain"],"cpes":["cpe:2.3:a:libdav1d6:libdav1d6:1.0.0-2\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libdav1d6@1.0.0-2%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=dav1d","upstreams":[{"name":"dav1d"}]}},{"vulnerability":{"id":"CVE-2026-58013","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58013","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58013","epss":0.00501,"percentile":0.41254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3932849999999999},"relatedVulnerabilities":[{"id":"CVE-2026-58013","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58013","epss":0.00501,"percentile":0.41254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58013","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58013","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58013","epss":0.00501,"percentile":0.41254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3932849999999999},"relatedVulnerabilities":[{"id":"CVE-2026-58013","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58013","epss":0.00501,"percentile":0.41254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-6253","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00719,"percentile":0.51754,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.39185500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-6253","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00719,"percentile":0.51754,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6253","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00719,"percentile":0.51754,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.39185500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-6253","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00719,"percentile":0.51754,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6253","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00719,"percentile":0.51754,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.39185500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-6253","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6253","epss":0.00719,"percentile":0.51754,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"GHSA-2fvj-hgj9-j2gr","dataSource":"https://github.com/advisories/GHSA-2fvj-hgj9-j2gr","namespace":"github:language:java","severity":"High","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr","https://github.com/jetty/jetty.project/issues/15136","https://github.com/jetty/jetty.project/pull/15160","https://github.com/jetty/jetty.project/pull/15183","https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d","https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d","https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36","https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"],"description":"Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10050","epss":0.00483,"percentile":0.40113,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-10050","cwe":"CWE-173","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2026-10050","cwe":"CWE-303","source":"emo@eclipse.org","type":"Secondary"}],"fix":{"versions":["9.4.63"],"state":"fixed","available":[{"version":"9.4.63","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.39122999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-10050","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10050","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"],"description":"In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-10050","epss":0.00483,"percentile":0.40113,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-10050","cwe":"CWE-173","source":"emo@eclipse.org","type":"Secondary"},{"cve":"CVE-2026-10050","cwe":"CWE-303","source":"emo@eclipse.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-security","version":"9.4.56.v20240826"}},"found":{"vulnerabilityID":"GHSA-2fvj-hgj9-j2gr","versionConstraint":">=9.4.0.v20161208,<=9.4.58.v20250814 (unknown)"},"fix":{"suggestedVersion":"9.4.63"}}],"artifact":{"id":"569fe536bec484f7","name":"jetty-security","version":"9.4.56.v20240826","type":"java-archive","locations":[{"path":"/zap/webswing/server/webswing-jetty-launcher.jar","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/server/webswing-jetty-launcher.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty-security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty_security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty-security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty_security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_security:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-security@9.4.56.v20240826","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/server/webswing-jetty-launcher.jar:org.eclipse.jetty:jetty-security","pomArtifactID":"jetty-security","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-13221","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00432,"percentile":0.36461,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.39096000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-13221","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00432,"percentile":0.36461,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-13221","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00432,"percentile":0.36461,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.39096000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-13221","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00432,"percentile":0.36461,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-13221","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00432,"percentile":0.36461,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.39096000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-13221","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00432,"percentile":0.36461,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-13221","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00432,"percentile":0.36461,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.39096000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-13221","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13221","epss":0.00432,"percentile":0.36461,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-42496","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.36247,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38915},"relatedVulnerabilities":[{"id":"CVE-2026-42496","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.36247,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-42496","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.36247,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38915},"relatedVulnerabilities":[{"id":"CVE-2026-42496","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.36247,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-42496","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.36247,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38915},"relatedVulnerabilities":[{"id":"CVE-2026-42496","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.36247,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-42496","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.36247,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38915},"relatedVulnerabilities":[{"id":"CVE-2026-42496","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42496","epss":0.0043,"percentile":0.36247,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42496","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-74940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74940","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74940","epss":0.00412,"percentile":0.34649,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74940","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-74940","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.38728000000000007},"relatedVulnerabilities":[{"id":"CVE-2026-74940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74940","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2054842","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74940","epss":0.00412,"percentile":0.34649,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74940","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-74940","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74940","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-54874","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54874","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.  Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.  CWE: CWE-405: Asymmetric Resource Consumption (Amplification)  Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.  Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.  An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.  FIPS impact: no  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.  OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.  Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr  This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.  -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54874","epss":0.00516,"percentile":0.42237,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.38699999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-54874","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54874","epss":0.00516,"percentile":0.42237,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f55823b1f5c2e201","name":"libssl3","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","upstreams":[{"name":"openssl"}]}},{"vulnerability":{"id":"CVE-2026-54874","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54874","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.  Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.  CWE: CWE-405: Asymmetric Resource Consumption (Amplification)  Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.  Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.  An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.  FIPS impact: no  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.  OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.  Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr  This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.  -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54874","epss":0.00516,"percentile":0.42237,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.38699999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-54874","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54874","epss":0.00516,"percentile":0.42237,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7345802bd2ec0962","name":"openssl","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-58010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58010","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58010","epss":0.00491,"percentile":0.40625,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38543499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-58010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58010","epss":0.00491,"percentile":0.40625,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58010","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58010","epss":0.00491,"percentile":0.40625,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38543499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-58010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58010","epss":0.00491,"percentile":0.40625,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58012","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58012","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58012","epss":0.00491,"percentile":0.40624,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38543499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-58012","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58012","epss":0.00491,"percentile":0.40624,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58012","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58012","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58012","epss":0.00491,"percentile":0.40624,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.38543499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-58012","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58012","epss":0.00491,"percentile":0.40624,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-13608","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13608","epss":0.00509,"percentile":0.41806,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.379205},"relatedVulnerabilities":[{"id":"CVE-2026-13608","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13608","epss":0.00509,"percentile":0.41806,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-13608","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13608","epss":0.00509,"percentile":0.41806,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.379205},"relatedVulnerabilities":[{"id":"CVE-2026-13608","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13608","epss":0.00509,"percentile":0.41806,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-13608","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13608","epss":0.00509,"percentile":0.41806,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.379205},"relatedVulnerabilities":[{"id":"CVE-2026-13608","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13608","epss":0.00509,"percentile":0.41806,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-52490","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52490","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52490","epss":0.00403,"percentile":0.33841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.37882},"relatedVulnerabilities":[{"id":"CVE-2026-52490","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52490","namespace":"nvd:cpe","severity":"Critical","urls":["https://gist.github.com/okyfh/122c2d72e991a78c8af80a3af3be8671","https://gitlab.com/libtiff/libtiff/-/work_items/846"],"description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52490","epss":0.00403,"percentile":0.33841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52490","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-74936","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74936","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74936","epss":0.00403,"percentile":0.33773,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74936","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-74936","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.37882},"relatedVulnerabilities":[{"id":"CVE-2026-74936","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74936","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2052688","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74936","epss":0.00403,"percentile":0.33773,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74936","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-74936","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74936","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74944","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74944","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74944","epss":0.00403,"percentile":0.33773,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74944","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-74944","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.37882},"relatedVulnerabilities":[{"id":"CVE-2026-74944","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74944","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2057778","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74944","epss":0.00403,"percentile":0.33773,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74944","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-74944","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74944","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-34980","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34980","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34980","epss":0.00502,"percentile":0.41311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34980","cwe":"CWE-20","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3765},"relatedVulnerabilities":[{"id":"CVE-2026-34980","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34980","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34980","epss":0.00502,"percentile":0.41311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34980","cwe":"CWE-20","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-34980","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2025-15661","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15661","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15661","epss":0.00648,"percentile":0.48955,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15661","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":["1.10.0-3+deb12u1"],"state":"fixed","available":[{"version":"1.10.0-3+deb12u1","date":"2026-09-06","kind":"first-observed"}]},"advisories":[],"risk":0.3726},"relatedVulnerabilities":[{"id":"CVE-2025-15661","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15661","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d","https://github.com/libssh2/libssh2/pull/1705","https://github.com/libssh2/libssh2/pull/1717","https://www.vulncheck.com/advisories/libssh2-heap-buffer-over-read-via-sftp-symlink-in-sftp-c"],"description":"libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15661","epss":0.00648,"percentile":0.48955,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15661","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libssh2","version":"1.10.0-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15661","versionConstraint":"< 1.10.0-3+deb12u1 (deb)"},"fix":{"suggestedVersion":"1.10.0-3+deb12u1"}}],"artifact":{"id":"865a7a71606e882c","name":"libssh2-1","version":"1.10.0-3+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssh2-1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD3"],"cpes":["cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12.15&upstream=libssh2%401.10.0-3","upstreams":[{"name":"libssh2","version":"1.10.0-3"}]}},{"vulnerability":{"id":"CVE-2026-75143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75143","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75143","epss":0.00405,"percentile":0.34011,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75143","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.370575},"relatedVulnerabilities":[{"id":"CVE-2026-75143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75143","namespace":"nvd:cpe","severity":"Critical","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24089","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-rist-protocol-reader"],"description":"FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75143","epss":0.00405,"percentile":0.34011,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75143","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75143","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75143","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75143","epss":0.00405,"percentile":0.34011,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75143","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.370575},"relatedVulnerabilities":[{"id":"CVE-2026-75143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75143","namespace":"nvd:cpe","severity":"Critical","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24089","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-rist-protocol-reader"],"description":"FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75143","epss":0.00405,"percentile":0.34011,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75143","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75143","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75143","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75143","epss":0.00405,"percentile":0.34011,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75143","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.370575},"relatedVulnerabilities":[{"id":"CVE-2026-75143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75143","namespace":"nvd:cpe","severity":"Critical","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24089","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-rist-protocol-reader"],"description":"FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75143","epss":0.00405,"percentile":0.34011,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75143","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75143","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-47247","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47247","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47247","epss":0.00494,"percentile":0.40862,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47247","cwe":"CWE-200","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-47247","cwe":"CWE-226","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-47247","cwe":"CWE-682","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-47247","cwe":"CWE-908","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3705},"relatedVulnerabilities":[{"id":"CVE-2026-47247","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47247","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/security/advisories/GHSA-2vh6-whr3-cmq3"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47247","epss":0.00494,"percentile":0.40862,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47247","cwe":"CWE-200","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-47247","cwe":"CWE-226","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-47247","cwe":"CWE-682","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-47247","cwe":"CWE-908","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-47247","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-63385","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63385","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63385","epss":0.00403,"percentile":0.33834,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63385","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.36672999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-63385","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63385","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0","https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2","https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2"],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63385","epss":0.00403,"percentile":0.33834,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63385","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libevent","version":"2.1.12-stable-8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63385","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3bff02d75bb58680","name":"libevent-2.1-7","version":"2.1.12-stable-8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libevent-2.1-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libevent-2.1-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSL","Expat","FSFUL","FSFULLR","FSFULLR-No-Warranty","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","curl"],"cpes":["cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1-7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libevent-2.1-7@2.1.12-stable-8?arch=amd64&distro=debian-12.15&upstream=libevent","upstreams":[{"name":"libevent"}]}},{"vulnerability":{"id":"CVE-2026-62292","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-62292","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised tile with heif_image_handle_decode_image_tile(). In libheif/codecs/uncompressed/unc_decoder.cc, unc_decoder::fetch_tile_data() computes a large tile offset and unc_decoder::get_compressed_image_data_uncompressed() validates it with range_start_offset plus range_size. For the last advertised tile (4095, 4095), the addition can wrap to zero, bypass the bounds check, and pass an invalid source pointer and a one-terabyte length to memcpy. The observed result is an out-of-bounds read and process crash; opening the file alone does not trigger the issue because tile decoding is required. This issue is fixed in version 1.23.1.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-62292","epss":0.0045,"percentile":0.3787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-62292","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.36449999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-62292","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-62292","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/commit/089a809bf6bed1abae102d5e97b6bb8c4f53b515","https://github.com/strukturag/libheif/releases/tag/v1.23.1","https://github.com/strukturag/libheif/security/advisories/GHSA-73p7-m7gg-w2jv"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised tile with heif_image_handle_decode_image_tile(). In libheif/codecs/uncompressed/unc_decoder.cc, unc_decoder::fetch_tile_data() computes a large tile offset and unc_decoder::get_compressed_image_data_uncompressed() validates it with range_start_offset plus range_size. For the last advertised tile (4095, 4095), the addition can wrap to zero, bypass the bounds check, and pass an invalid source pointer and a one-terabyte length to memcpy. The observed result is an out-of-bounds read and process crash; opening the file alone does not trigger the issue because tile decoding is required. This issue is fixed in version 1.23.1.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-62292","epss":0.0045,"percentile":0.3787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-62292","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-62292","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-66032","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66032","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66032","epss":0.00448,"percentile":0.37745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66032","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":["1.10.0-3+deb12u1"],"state":"fixed","available":[{"version":"1.10.0-3+deb12u1","date":"2026-09-06","kind":"first-observed"}]},"advisories":[],"risk":0.3628799999999999},"relatedVulnerabilities":[{"id":"CVE-2026-66032","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66032","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0","https://github.com/libssh2/libssh2/pull/2180","https://www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-open"],"description":"libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66032","epss":0.00448,"percentile":0.37745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66032","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libssh2","version":"1.10.0-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66032","versionConstraint":"< 1.10.0-3+deb12u1 (deb)"},"fix":{"suggestedVersion":"1.10.0-3+deb12u1"}}],"artifact":{"id":"865a7a71606e882c","name":"libssh2-1","version":"1.10.0-3+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssh2-1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD3"],"cpes":["cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12.15&upstream=libssh2%401.10.0-3","upstreams":[{"name":"libssh2","version":"1.10.0-3"}]}},{"vulnerability":{"id":"GHSA-wg6q-6289-32hp","dataSource":"https://github.com/advisories/GHSA-wg6q-6289-32hp","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-5588","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905588","https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057"],"description":"Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5588","epss":0.0064,"percentile":0.48592,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5588","cwe":"CWE-327","source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary"},{"cve":"CVE-2026-5588","cwe":"CWE-347","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["1.84"],"state":"fixed","available":[{"version":"1.84","date":"2026-04-17","kind":"first-observed"}]},"advisories":[],"risk":0.3616},"relatedVulnerabilities":[{"id":"CVE-2026-5588","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5588","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905588","https://access.redhat.com/errata/RHSA-2026:11720","https://access.redhat.com/errata/RHSA-2026:11721","https://access.redhat.com/errata/RHSA-2026:13631","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2026-5588","https://bugzilla.redhat.com/show_bug.cgi?id=2458634","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5588.json"],"description":"Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules).\n\n This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java.\n\n\n\nThis issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5588","epss":0.0064,"percentile":0.48592,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5588","cwe":"CWE-327","source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary"},{"cve":"CVE-2026-5588","cwe":"CWE-347","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.bouncycastle:bcpkix-jdk18on","version":"1.83"}},"found":{"vulnerabilityID":"GHSA-wg6q-6289-32hp","versionConstraint":">=1.49,<1.84 (unknown)"},"fix":{"suggestedVersion":"1.84"}}],"artifact":{"id":"0dd075f163666c24","name":"bcpkix-jdk18on","version":"1.83","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap:libs/bcpkix-jdk18on-1.83.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.bouncycastle:bcpkix-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcpkix_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcpkix-jdk18on:bcpkix-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcpkix-jdk18on:bcpkix_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcpkix_jdk18on:bcpkix-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcpkix_jdk18on:bcpkix_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcpkix-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcpkix_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcpkix:bcpkix-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcpkix:bcpkix_jdk18on:1.83:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.bouncycastle/bcpkix-jdk18on@1.83","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:libs/bcpkix-jdk18on-1.83.jar","pomArtifactID":"bcpkix-jdk18on","pomGroupID":"org.bouncycastle","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"3f4300d0441459bfa64a481c80062b002ff0cf65"}]}}},{"vulnerability":{"id":"CVE-2026-3644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3644","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35850000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-3644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3644","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35850000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-3644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3644","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35850000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-3644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3644","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35850000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-3644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3644","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35850000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-3644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3644","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35850000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-3644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3644","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.35850000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-3644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3644","epss":0.00478,"percentile":0.39805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-3644","cwe":"CWE-116","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"GHSA-3p8m-j85q-pgmj","dataSource":"https://github.com/advisories/GHSA-3p8m-j85q-pgmj","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-3p8m-j85q-pgmj","https://github.com/netty/netty/commit/9d804c54ce962408ae6418255a83a13924f7145d","https://nvd.nist.gov/vuln/detail/CVE-2025-58057"],"description":"Netty's decoders vulnerable to DoS via zip bomb style attack","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58057","epss":0.00601,"percentile":0.46775,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-58057","cwe":"CWE-409","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.125.Final"],"state":"fixed","available":[{"version":"4.1.125.Final","date":"2025-09-04","kind":"first-observed"}]},"advisories":[],"risk":0.35759499999999994},"relatedVulnerabilities":[{"id":"CVE-2025-58057","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58057","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/9d804c54ce962408ae6418255a83a13924f7145d","https://github.com/netty/netty/security/advisories/GHSA-3p8m-j85q-pgmj"],"description":"Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58057","epss":0.00601,"percentile":0.46775,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-58057","cwe":"CWE-409","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-3p8m-j85q-pgmj","versionConstraint":"<4.1.125.Final (unknown)"},"fix":{"suggestedVersion":"4.1.125.Final"}}],"artifact":{"id":"3dc400e13c062728","name":"netty-codec","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec","pomArtifactID":"netty-codec","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-58011","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58011","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58011","epss":0.00474,"percentile":0.39484,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3555},"relatedVulnerabilities":[{"id":"CVE-2026-58011","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58011","epss":0.00474,"percentile":0.39484,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58011","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58011","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58011","epss":0.00474,"percentile":0.39484,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3555},"relatedVulnerabilities":[{"id":"CVE-2026-58011","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58011","epss":0.00474,"percentile":0.39484,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-84143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84143","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84143","epss":0.00378,"percentile":0.31074,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84143","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-84143","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.35532},"relatedVulnerabilities":[{"id":"CVE-2026-84143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84143","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048793%2C2054645%2C2057114%2C2059109%2C2061287","https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054631%2C2054657%2C2055007%2C2055681%2C2057107%2C2058087%2C2058088%2C2058090%2C2058095%2C2058101%2C2059183%2C2059185%2C2061301%2C2061325","https://bugzilla.mozilla.org/show_bug.cgi?id=2057108","https://www.mozilla.org/security/advisories/mfsa2026-82/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-86/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84143","epss":0.00378,"percentile":0.31074,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84143","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-84143","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84143","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-56211","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56211","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.7,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56211","epss":0.00482,"percentile":0.40036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56211","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-56211","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["3.6.0-1+deb12u3"],"state":"fixed","available":[{"version":"3.6.0-1+deb12u3","date":"2026-09-07","kind":"first-observed"}]},"advisories":[],"risk":0.35185999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-56211","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56211","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:30814","https://access.redhat.com/errata/RHSA-2026:42875","https://access.redhat.com/errata/RHSA-2026:51100","https://access.redhat.com/errata/RHSA-2026:51146","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61627","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/security/cve/CVE-2026-56211","https://aomedia.googlesource.com/aom/+/a93ba0ffaa","https://bugzilla.redhat.com/show_bug.cgi?id=2490802","https://issues.chromium.org/issues/503993985","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56211.json"],"description":"A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.7,"impactScore":5.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.7,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56211","epss":0.00482,"percentile":0.40036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56211","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-56211","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"aom","version":"3.6.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56211","versionConstraint":"< 3.6.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"3.6.0-1+deb12u3"}}],"artifact":{"id":"9e3b0cc1c76e74b4","name":"libaom3","version":"3.6.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libaom3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libaom3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libaom3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libaom3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","BSD-2-clause","BSD-3-clause","Expat","ISC","public-domain-md5"],"cpes":["cpe:2.3:a:libaom3:libaom3:3.6.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libaom3@3.6.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=aom","upstreams":[{"name":"aom"}]}},{"vulnerability":{"id":"CVE-2017-17740","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.","cvss":[],"epss":[{"cve":"CVE-2017-17740","epss":0.07022,"percentile":0.93779,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3511},"relatedVulnerabilities":[{"id":"CVE-2017-17740","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","namespace":"nvd:cpe","severity":"High","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-17740","epss":0.07022,"percentile":0.93779,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"}}],"artifact":{"id":"692b9197d4b21a92","name":"libldap-2.5-0","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2017-17740","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.","cvss":[],"epss":[{"cve":"CVE-2017-17740","epss":0.07022,"percentile":0.93779,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3511},"relatedVulnerabilities":[{"id":"CVE-2017-17740","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","namespace":"nvd:cpe","severity":"High","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-17740","epss":0.07022,"percentile":0.93779,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dd3946a6b1d2298d","name":"libldap-common","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-common@2.5.13%2Bdfsg-5?arch=all&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.349325},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.349325},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.349325},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.349325},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.349325},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.349325},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.349325},"relatedVulnerabilities":[{"id":"CVE-2026-11972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11972","epss":0.00445,"percentile":0.37489,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-606","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11972","cwe":"CWE-770","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-85091","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-85091","epss":0.00442,"percentile":0.3727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.34918000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-85091","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-85091","epss":0.00442,"percentile":0.3727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"}}],"artifact":{"id":"077923f667034501","name":"zlib1g","version":"1:1.2.13.dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Zlib"],"cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","upstreams":[{"name":"zlib"}]}},{"vulnerability":{"id":"CVE-2026-85091","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-85091","epss":0.00442,"percentile":0.3727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.34918000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-85091","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-85091","epss":0.00442,"percentile":0.3727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3f28e512f3f6e928","name":"zlib1g-dev","version":"1:1.2.13.dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/zlib1g-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Zlib"],"cpes":["cpe:2.3:a:zlib1g-dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g-dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/zlib1g-dev@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","upstreams":[{"name":"zlib"}]}},{"vulnerability":{"id":"GHSA-mj4r-2hfc-f8p6","dataSource":"https://github.com/advisories/GHSA-mj4r-2hfc-f8p6","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-mj4r-2hfc-f8p6","https://nvd.nist.gov/vuln/detail/CVE-2026-42583"],"description":"Netty Lz4FrameDecoder is vulnerable to resource exhaustion","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42583","epss":0.00461,"percentile":0.38612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42583","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42583","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.133.Final"],"state":"fixed","available":[{"version":"4.1.133.Final","date":"2026-05-07","kind":"first-observed"}]},"advisories":[],"risk":0.34575000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-42583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42583","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-mj4r-2hfc-f8p6"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42583","epss":0.00461,"percentile":0.38612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42583","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42583","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-mj4r-2hfc-f8p6","versionConstraint":"<=4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.133.Final"}}],"artifact":{"id":"3dc400e13c062728","name":"netty-codec","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec","pomArtifactID":"netty-codec","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-45186","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45186","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45186","epss":0.0046,"percentile":0.3854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.345},"relatedVulnerabilities":[{"id":"CVE-2026-45186","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45186","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1216","http://www.openwall.com/lists/oss-security/2026/05/11/16","https://access.redhat.com/errata/RHSA-2026:22715","https://access.redhat.com/errata/RHSA-2026:22721","https://access.redhat.com/errata/RHSA-2026:23230","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:27201","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-45186","https://bugzilla.redhat.com/show_bug.cgi?id=2468575","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json"],"description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45186","epss":0.0046,"percentile":0.3854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45186","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-45186","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45186","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45186","epss":0.0046,"percentile":0.3854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.345},"relatedVulnerabilities":[{"id":"CVE-2026-45186","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45186","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1216","http://www.openwall.com/lists/oss-security/2026/05/11/16","https://access.redhat.com/errata/RHSA-2026:22715","https://access.redhat.com/errata/RHSA-2026:22721","https://access.redhat.com/errata/RHSA-2026:23230","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:27201","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-45186","https://bugzilla.redhat.com/show_bug.cgi?id=2468575","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json"],"description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45186","epss":0.0046,"percentile":0.3854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2026-45186","cwe":"CWE-407","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45186","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2024-52616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00666,"percentile":0.49722,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.34299},"relatedVulnerabilities":[{"id":"CVE-2024-52616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00666,"percentile":0.49722,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c21957a0053108b1","name":"libavahi-client3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2024-52616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00666,"percentile":0.49722,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.34299},"relatedVulnerabilities":[{"id":"CVE-2024-52616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00666,"percentile":0.49722,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"}}],"artifact":{"id":"934d69cf9aa71068","name":"libavahi-common-data","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2024-52616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00666,"percentile":0.49722,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.34299},"relatedVulnerabilities":[{"id":"CVE-2024-52616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52616","epss":0.00666,"percentile":0.49722,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d355b05e7a15b748","name":"libavahi-common3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"GHSA-c653-97m9-rcg9","dataSource":"https://github.com/advisories/GHSA-c653-97m9-rcg9","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://nvd.nist.gov/vuln/detail/CVE-2026-50010","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"description":"Netty: Wrapping plain trust manager silently disables hostname verification","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50010","epss":0.00456,"percentile":0.38308,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50010","cwe":"CWE-347","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-50010","cwe":"CWE-347","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-16","kind":"first-observed"}]},"advisories":[],"risk":0.34199999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-50010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50010","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-50010","https://bugzilla.redhat.com/show_bug.cgi?id=2488429","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50010.json"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50010","epss":0.00456,"percentile":0.38308,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50010","cwe":"CWE-347","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-50010","cwe":"CWE-347","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-c653-97m9-rcg9","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"ab10619bb861593f","name":"netty-handler","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-c653-97m9-rcg9","dataSource":"https://github.com/advisories/GHSA-c653-97m9-rcg9","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://nvd.nist.gov/vuln/detail/CVE-2026-50010","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"description":"Netty: Wrapping plain trust manager silently disables hostname verification","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50010","epss":0.00456,"percentile":0.38308,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50010","cwe":"CWE-347","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-50010","cwe":"CWE-347","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-16","kind":"first-observed"}]},"advisories":[],"risk":0.34199999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-50010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50010","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-50010","https://bugzilla.redhat.com/show_bug.cgi?id=2488429","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50010.json"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50010","epss":0.00456,"percentile":0.38308,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50010","cwe":"CWE-347","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-50010","cwe":"CWE-347","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-c653-97m9-rcg9","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"bf14062c190d1eea","name":"netty-handler","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2025-69720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00447,"percentile":0.37674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.341955},"relatedVulnerabilities":[{"id":"CVE-2025-69720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00447,"percentile":0.37674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3a2ba7a41a0529","name":"libncursesw6","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-69720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00447,"percentile":0.37674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.341955},"relatedVulnerabilities":[{"id":"CVE-2025-69720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00447,"percentile":0.37674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6231fb14cfeaaac","name":"libtinfo6","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-69720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00447,"percentile":0.37674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.341955},"relatedVulnerabilities":[{"id":"CVE-2025-69720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00447,"percentile":0.37674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec73073218fd031a","name":"ncurses-base","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-69720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00447,"percentile":0.37674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.341955},"relatedVulnerabilities":[{"id":"CVE-2025-69720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69720","epss":0.00447,"percentile":0.37674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"},{"cve":"CVE-2025-69720","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c5b18ac268f2ccdf","name":"ncurses-bin","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2026-82209","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-82209","epss":0.00435,"percentile":0.36683,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3414749999999999},"relatedVulnerabilities":[{"id":"CVE-2026-82209","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-82209","epss":0.00435,"percentile":0.36683,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-82209","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-82209","epss":0.00435,"percentile":0.36683,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3414749999999999},"relatedVulnerabilities":[{"id":"CVE-2026-82209","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-82209","epss":0.00435,"percentile":0.36683,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-82209","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-82209","epss":0.00435,"percentile":0.36683,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3414749999999999},"relatedVulnerabilities":[{"id":"CVE-2026-82209","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-82209","epss":0.00435,"percentile":0.36683,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"GHSA-xxqh-mfjm-7mv9","dataSource":"https://github.com/advisories/GHSA-xxqh-mfjm-7mv9","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-xxqh-mfjm-7mv9","https://nvd.nist.gov/vuln/detail/CVE-2026-42581"],"description":"Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":5.8,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42581","epss":0.0063,"percentile":0.48146,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42581","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42581","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.133.Final"],"state":"fixed","available":[{"version":"4.1.133.Final","date":"2026-05-07","kind":"first-observed"}]},"advisories":[],"risk":0.3402},"relatedVulnerabilities":[{"id":"CVE-2026-42581","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42581","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/netty/netty/security/advisories/GHSA-xxqh-mfjm-7mv9","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-42581","https://bugzilla.redhat.com/show_bug.cgi?id=2477232","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42581.json"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"exploitabilityScore":3.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":5.8,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42581","epss":0.0063,"percentile":0.48146,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42581","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42581","cwe":"CWE-444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-xxqh-mfjm-7mv9","versionConstraint":"<=4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.133.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-12087","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00374,"percentile":0.30745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33847},"relatedVulnerabilities":[{"id":"CVE-2026-12087","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00374,"percentile":0.30745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-12087","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00374,"percentile":0.30745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33847},"relatedVulnerabilities":[{"id":"CVE-2026-12087","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00374,"percentile":0.30745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-12087","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00374,"percentile":0.30745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33847},"relatedVulnerabilities":[{"id":"CVE-2026-12087","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00374,"percentile":0.30745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-12087","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00374,"percentile":0.30745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33847},"relatedVulnerabilities":[{"id":"CVE-2026-12087","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12087","epss":0.00374,"percentile":0.30745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-12087","cwe":"CWE-805","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-9538","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00448,"percentile":0.37761,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33599999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-9538","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00448,"percentile":0.37761,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-9538","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00448,"percentile":0.37761,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33599999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-9538","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00448,"percentile":0.37761,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-9538","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00448,"percentile":0.37761,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33599999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-9538","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00448,"percentile":0.37761,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-9538","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00448,"percentile":0.37761,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33599999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-9538","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9538","epss":0.00448,"percentile":0.37761,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-57433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00357,"percentile":0.28943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33558},"relatedVulnerabilities":[{"id":"CVE-2026-57433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00357,"percentile":0.28943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-57433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00357,"percentile":0.28943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33558},"relatedVulnerabilities":[{"id":"CVE-2026-57433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00357,"percentile":0.28943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-57433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00357,"percentile":0.28943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33558},"relatedVulnerabilities":[{"id":"CVE-2026-57433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00357,"percentile":0.28943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-57433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00357,"percentile":0.28943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33558},"relatedVulnerabilities":[{"id":"CVE-2026-57433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57433","epss":0.00357,"percentile":0.28943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-6653","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6653","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6653","epss":0.00355,"percentile":0.28769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","source":"security@ubuntu.com","type":"Secondary"},{"cve":"CVE-2026-6653","cwe":"CWE-611","source":"security@ubuntu.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33370000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-6653","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6653","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"],"description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"security@ubuntu.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6653","epss":0.00355,"percentile":0.28769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","source":"security@ubuntu.com","type":"Secondary"},{"cve":"CVE-2026-6653","cwe":"CWE-611","source":"security@ubuntu.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6653","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-58014","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58014","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58014","epss":0.00414,"percentile":0.34799,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3332699999999999},"relatedVulnerabilities":[{"id":"CVE-2026-58014","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58014","epss":0.00414,"percentile":0.34799,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58014","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58014","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58014","epss":0.00414,"percentile":0.34799,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3332699999999999},"relatedVulnerabilities":[{"id":"CVE-2026-58014","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58014","epss":0.00414,"percentile":0.34799,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-58050","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58050","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58050","epss":0.00444,"percentile":0.37454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58050","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":["1.10.0-3+deb12u1"],"state":"fixed","available":[{"version":"1.10.0-3+deb12u1","date":"2026-09-06","kind":"first-observed"}]},"advisories":[],"risk":0.3330000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-58050","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58050","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc","https://github.com/libssh2/libssh2/blob/master/src/publickey.c","https://www.vulncheck.com/advisories/libssh2-integer-overflow-in-publickey-subsystem-attribute-allocation"],"description":"libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"exploitabilityScore":2.3,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58050","epss":0.00444,"percentile":0.37454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58050","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libssh2","version":"1.10.0-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58050","versionConstraint":"< 1.10.0-3+deb12u1 (deb)"},"fix":{"suggestedVersion":"1.10.0-3+deb12u1"}}],"artifact":{"id":"865a7a71606e882c","name":"libssh2-1","version":"1.10.0-3+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssh2-1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD3"],"cpes":["cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12.15&upstream=libssh2%401.10.0-3","upstreams":[{"name":"libssh2","version":"1.10.0-3"}]}},{"vulnerability":{"id":"GHSA-93wv-jw9v-4972","dataSource":"https://github.com/advisories/GHSA-93wv-jw9v-4972","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972","https://nvd.nist.gov/vuln/detail/CVE-2026-56819","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56819","epss":0.00443,"percentile":0.37352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56819","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-56819","cwe":"CWE-401","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-08-01","kind":"first-observed"}]},"advisories":[],"risk":0.33225},"relatedVulnerabilities":[{"id":"CVE-2026-56819","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56819","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"],"description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56819","epss":0.00443,"percentile":0.37352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56819","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-56819","cwe":"CWE-401","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-93wv-jw9v-4972","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"5895f3b705a95bee","name":"netty-codec-http2","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-93wv-jw9v-4972","dataSource":"https://github.com/advisories/GHSA-93wv-jw9v-4972","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972","https://nvd.nist.gov/vuln/detail/CVE-2026-56819","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56819","epss":0.00443,"percentile":0.37352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56819","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-56819","cwe":"CWE-401","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-08-01","kind":"first-observed"}]},"advisories":[],"risk":0.33225},"relatedVulnerabilities":[{"id":"CVE-2026-56819","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56819","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"],"description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56819","epss":0.00443,"percentile":0.37352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56819","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-56819","cwe":"CWE-401","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-93wv-jw9v-4972","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"c9e87a7d2efc8ca7","name":"netty-codec-http2","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2023-6135","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6135","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Multiple NSS NIST curves were susceptible to a side-channel attack known as \"Minerva\". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6135","epss":0.00714,"percentile":0.51541,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6135","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3320099999999999},"relatedVulnerabilities":[{"id":"CVE-2023-6135","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6135","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=1853908","https://security.gentoo.org/glsa/202401-10","https://www.mozilla.org/security/advisories/mfsa2023-56/"],"description":"Multiple NSS NIST curves were susceptible to a side-channel attack known as \"Minerva\". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6135","epss":0.00714,"percentile":0.51541,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6135","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nss","version":"2:3.87.1-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6135","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3325a62774655e15","name":"libnss3","version":"2:3.87.1-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3","MPL-2.0","Zlib","public-domain"],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.87.1-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.87.1-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2026-60000","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60000","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60000","epss":0.00441,"percentile":0.37153,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.33075},"relatedVulnerabilities":[{"id":"CVE-2026-60000","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","namespace":"nvd:cpe","severity":"High","urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60000","epss":0.00441,"percentile":0.37153,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"GHSA-6jqx-86gh-f27w","dataSource":"https://github.com/advisories/GHSA-6jqx-86gh-f27w","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w","https://nvd.nist.gov/vuln/detail/CVE-2026-55831","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty SPDY SETTINGS frame count materializes unbounded settings map","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55831","epss":0.00439,"percentile":0.3704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-55831","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.32925},"relatedVulnerabilities":[{"id":"CVE-2026-55831","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55831","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55831","epss":0.00439,"percentile":0.3704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-55831","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-6jqx-86gh-f27w","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-6jqx-86gh-f27w","dataSource":"https://github.com/advisories/GHSA-6jqx-86gh-f27w","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w","https://nvd.nist.gov/vuln/detail/CVE-2026-55831","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty SPDY SETTINGS frame count materializes unbounded settings map","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55831","epss":0.00439,"percentile":0.3704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-55831","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.32925},"relatedVulnerabilities":[{"id":"CVE-2026-55831","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55831","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55831","epss":0.00439,"percentile":0.3704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-55831","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-6jqx-86gh-f27w","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-66036","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66036","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66036","epss":0.00401,"percentile":0.33533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.326815},"relatedVulnerabilities":[{"id":"CVE-2026-66036","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66036","epss":0.00401,"percentile":0.33533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66036","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66036","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66036","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66036","epss":0.00401,"percentile":0.33533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.326815},"relatedVulnerabilities":[{"id":"CVE-2026-66036","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66036","epss":0.00401,"percentile":0.33533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66036","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66036","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66036","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66036","epss":0.00401,"percentile":0.33533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.326815},"relatedVulnerabilities":[{"id":"CVE-2026-66036","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66036","epss":0.00401,"percentile":0.33533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66036","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2023-39329","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39329","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39329","epss":0.00559,"percentile":0.44721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.321425},"relatedVulnerabilities":[{"id":"CVE-2023-39329","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39329","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39329","https://bugzilla.redhat.com/show_bug.cgi?id=2295816"],"description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39329","epss":0.00559,"percentile":0.44721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-39329","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-12912","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12912","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.4,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12912","epss":0.00433,"percentile":0.36484,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-12912","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3204199999999999},"relatedVulnerabilities":[{"id":"CVE-2026-12912","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12912","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:34890","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:42668","https://access.redhat.com/errata/RHSA-2026:47183","https://access.redhat.com/errata/RHSA-2026:47184","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:50774","https://access.redhat.com/errata/RHSA-2026:54638","https://access.redhat.com/errata/RHSA-2026:54640","https://access.redhat.com/errata/RHSA-2026:54642","https://access.redhat.com/errata/RHSA-2026:58545","https://access.redhat.com/errata/RHSA-2026:58553","https://access.redhat.com/errata/RHSA-2026:58554","https://access.redhat.com/errata/RHSA-2026:58556","https://access.redhat.com/errata/RHSA-2026:61657","https://access.redhat.com/security/cve/CVE-2026-12912","https://bugzilla.redhat.com/show_bug.cgi?id=2492871","https://gitlab.com/libtiff/libtiff/-/merge_requests/873","https://gitlab.com/libtiff/libtiff/-/work_items/824","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json"],"description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.4,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.4,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12912","epss":0.00433,"percentile":0.36484,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-12912","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12912","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-38076","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-38076","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38076","epss":0.00426,"percentile":0.35924,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38076","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3195},"relatedVulnerabilities":[{"id":"CVE-2026-38076","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-38076","namespace":"nvd:cpe","severity":"High","urls":["http://artifex.com","https://gist.github.com/dkjsone/c237b83ffa9ebd7028b5db7f410fcf78","https://github.com/ArtifexSoftware/jbig2dec"],"description":"An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38076","epss":0.00426,"percentile":0.35924,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38076","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jbig2dec","version":"0.19-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-38076","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4d5d6351b6af6711","name":"libjbig2dec0","version":"0.19-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjbig2dec0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjbig2dec0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjbig2dec0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjbig2dec0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AGPL-3+","BSD-2-clause","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","pubic-domain","public-domain"],"cpes":["cpe:2.3:a:libjbig2dec0:libjbig2dec0:0.19-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjbig2dec0@0.19-3?arch=amd64&distro=debian-12.15&upstream=jbig2dec","upstreams":[{"name":"jbig2dec"}]}},{"vulnerability":{"id":"GHSA-h383-gmxw-35v2","dataSource":"https://github.com/advisories/GHSA-h383-gmxw-35v2","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34479","https://github.com/apache/logging-log4j2/pull/4078","https://lists.apache.org/thread/gd0hp6mj17rn3kj279vgy4p7kd4zz5on","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html","https://logging.apache.org/security.html#CVE-2026-34479","http://www.openwall.com/lists/oss-security/2026/04/10/8"],"description":"Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34479","epss":0.00535,"percentile":0.43407,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34479","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["2.25.4"],"state":"fixed","available":[{"version":"2.25.4","date":"2026-04-14","kind":"first-observed"}]},"advisories":[],"risk":0.31832499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-34479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34479","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/apache/logging-log4j2/pull/4078","https://lists.apache.org/thread/gd0hp6mj17rn3kj279vgy4p7kd4zz5on","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html","https://logging.apache.org/security.html#CVE-2026-34479","http://www.openwall.com/lists/oss-security/2026/04/10/8"],"description":"The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.\n\nTwo groups of users are affected:\n\n  *  Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file.\n  *  Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class.\n\n\nUsers are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue.\n\nNote: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the  Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34479","epss":0.00535,"percentile":0.43407,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34479","cwe":"CWE-116","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-1.2-api","version":"2.25.2"}},"found":{"vulnerabilityID":"GHSA-h383-gmxw-35v2","versionConstraint":">=2.7,<2.25.4 (unknown)"},"fix":{"suggestedVersion":"2.25.4"}}],"artifact":{"id":"744d1742067b61d7","name":"log4j-1.2-api","version":"2.25.2","type":"java-archive","locations":[{"path":"/zap/lib/log4j-1.2-api-2.25.2.jar","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/lib/log4j-1.2-api-2.25.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"cpes":["cpe:2.3:a:apache:log4j-1.2-api:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_1.2_api:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:logging:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:api:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:1:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:2:2.25.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-1.2-api@2.25.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/lib/log4j-1.2-api-2.25.2.jar","pomArtifactID":"log4j-1.2-api","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"d937f5ea23f027563332126b3c96f970ed9536bb"}]}}},{"vulnerability":{"id":"CVE-2026-56208","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56208","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56208","epss":0.00421,"percentile":0.35529,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56208","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-56208","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["3.6.0-1+deb12u3"],"state":"fixed","available":[{"version":"3.6.0-1+deb12u3","date":"2026-09-07","kind":"first-observed"}]},"advisories":[],"risk":0.317855},"relatedVulnerabilities":[{"id":"CVE-2026-56208","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56208","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:30814","https://access.redhat.com/errata/RHSA-2026:42875","https://access.redhat.com/errata/RHSA-2026:47104","https://access.redhat.com/errata/RHSA-2026:47105","https://access.redhat.com/errata/RHSA-2026:51100","https://access.redhat.com/errata/RHSA-2026:51146","https://access.redhat.com/errata/RHSA-2026:54180","https://access.redhat.com/errata/RHSA-2026:54181","https://access.redhat.com/errata/RHSA-2026:54182","https://access.redhat.com/errata/RHSA-2026:54185","https://access.redhat.com/errata/RHSA-2026:54248","https://access.redhat.com/errata/RHSA-2026:54249","https://access.redhat.com/errata/RHSA-2026:54259","https://access.redhat.com/errata/RHSA-2026:54339","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61627","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/security/cve/CVE-2026-56208","https://aomedia.googlesource.com/aom/+/243f8ae84b","https://bugzilla.redhat.com/show_bug.cgi?id=2490799","https://issues.chromium.org/issues/504317456","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56208.json"],"description":"A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56208","epss":0.00421,"percentile":0.35529,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56208","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-56208","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"aom","version":"3.6.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56208","versionConstraint":"< 3.6.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"3.6.0-1+deb12u3"}}],"artifact":{"id":"9e3b0cc1c76e74b4","name":"libaom3","version":"3.6.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libaom3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libaom3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libaom3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libaom3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","BSD-2-clause","BSD-3-clause","Expat","ISC","public-domain-md5"],"cpes":["cpe:2.3:a:libaom3:libaom3:3.6.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libaom3@3.6.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=aom","upstreams":[{"name":"aom"}]}},{"vulnerability":{"id":"GHSA-c2gf-v879-257j","dataSource":"https://github.com/advisories/GHSA-c2gf-v879-257j","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j","https://nvd.nist.gov/vuln/detail/CVE-2026-48043","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/security/cve/CVE-2026-48043","https://bugzilla.redhat.com/show_bug.cgi?id=2488442","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126"],"description":"netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48043","epss":0.00617,"percentile":0.47514,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48043","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48043","cwe":"CWE-401","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48043","cwe":"CWE-772","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-11","kind":"first-observed"}]},"advisories":[],"risk":0.317755},"relatedVulnerabilities":[{"id":"CVE-2026-48043","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48043","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-48043","https://bugzilla.redhat.com/show_bug.cgi?id=2488442","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json"],"description":"Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48043","epss":0.00617,"percentile":0.47514,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48043","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48043","cwe":"CWE-401","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48043","cwe":"CWE-772","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-c2gf-v879-257j","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"5895f3b705a95bee","name":"netty-codec-http2","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-c2gf-v879-257j","dataSource":"https://github.com/advisories/GHSA-c2gf-v879-257j","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j","https://nvd.nist.gov/vuln/detail/CVE-2026-48043","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/security/cve/CVE-2026-48043","https://bugzilla.redhat.com/show_bug.cgi?id=2488442","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126"],"description":"netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48043","epss":0.00617,"percentile":0.47514,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48043","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48043","cwe":"CWE-401","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48043","cwe":"CWE-772","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-11","kind":"first-observed"}]},"advisories":[],"risk":0.317755},"relatedVulnerabilities":[{"id":"CVE-2026-48043","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48043","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-48043","https://bugzilla.redhat.com/show_bug.cgi?id=2488442","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json"],"description":"Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48043","epss":0.00617,"percentile":0.47514,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48043","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48043","cwe":"CWE-401","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48043","cwe":"CWE-772","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-c2gf-v879-257j","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"c9e87a7d2efc8ca7","name":"netty-codec-http2","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-mvh2-crg5-v77c","dataSource":"https://github.com/advisories/GHSA-mvh2-crg5-v77c","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c","https://nvd.nist.gov/vuln/detail/CVE-2026-55833","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55833","epss":0.00423,"percentile":0.35697,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.31725},"relatedVulnerabilities":[{"id":"CVE-2026-55833","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55833","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55833","epss":0.00423,"percentile":0.35697,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-mvh2-crg5-v77c","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-mvh2-crg5-v77c","dataSource":"https://github.com/advisories/GHSA-mvh2-crg5-v77c","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c","https://nvd.nist.gov/vuln/detail/CVE-2026-55833","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55833","epss":0.00423,"percentile":0.35697,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.31725},"relatedVulnerabilities":[{"id":"CVE-2026-55833","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55833","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55833","epss":0.00423,"percentile":0.35697,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-mvh2-crg5-v77c","versionConstraint":">=4.1.0.Final,<=4.1.135.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-42497","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.35095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31275000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-42497","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.35095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-42497","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.35095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31275000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-42497","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.35095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-42497","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.35095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31275000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-42497","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.35095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-42497","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.35095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31275000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-42497","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42497","epss":0.00417,"percentile":0.35095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-42497","cwe":"CWE-732","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-8458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.43845,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.312225},"relatedVulnerabilities":[{"id":"CVE-2026-8458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.43845,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.43845,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.312225},"relatedVulnerabilities":[{"id":"CVE-2026-8458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.43845,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.43845,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.312225},"relatedVulnerabilities":[{"id":"CVE-2026-8458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n'services'.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8458","epss":0.00543,"percentile":0.43845,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-41992","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41992","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41992","epss":0.00415,"percentile":0.34956,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.31124999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-41992","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41992","namespace":"nvd:cpe","severity":"High","urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=e7378c2d421be6a286922374425680bbe9ad8b7d","https://www.gnu.org/software/gzip/","http://www.openwall.com/lists/oss-security/2026/08/23/1","http://www.openwall.com/lists/oss-security/2026/08/25/1","http://www.openwall.com/lists/oss-security/2026/08/27/2"],"description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41992","epss":0.00415,"percentile":0.34956,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gzip","version":"1.12-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-41992","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aa527ab8cb576b14","name":"gzip","version":"1.12-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gzip.list"}],"language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"cpes":["cpe:2.3:a:gzip:gzip:1.12-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gzip@1.12-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-63384","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63384","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63384","epss":0.00384,"percentile":0.31769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63384","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.31104},"relatedVulnerabilities":[{"id":"CVE-2026-63384","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63384","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda","https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416","https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8"],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63384","epss":0.00384,"percentile":0.31769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63384","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libevent","version":"2.1.12-stable-8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63384","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3bff02d75bb58680","name":"libevent-2.1-7","version":"2.1.12-stable-8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libevent-2.1-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libevent-2.1-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSL","Expat","FSFUL","FSFULLR","FSFULLR-No-Warranty","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","curl"],"cpes":["cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1-7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libevent-2.1-7@2.1.12-stable-8?arch=amd64&distro=debian-12.15&upstream=libevent","upstreams":[{"name":"libevent"}]}},{"vulnerability":{"id":"CVE-2026-63383","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63383","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63383","epss":0.00384,"percentile":0.31768,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63383","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.31104},"relatedVulnerabilities":[{"id":"CVE-2026-63383","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63383","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321","https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb","https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6"],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63383","epss":0.00384,"percentile":0.31768,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63383","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libevent","version":"2.1.12-stable-8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63383","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3bff02d75bb58680","name":"libevent-2.1-7","version":"2.1.12-stable-8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libevent-2.1-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libevent-2.1-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSL","Expat","FSFUL","FSFULLR","FSFULLR-No-Warranty","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","curl"],"cpes":["cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1-7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libevent-2.1-7@2.1.12-stable-8?arch=amd64&distro=debian-12.15&upstream=libevent","upstreams":[{"name":"libevent"}]}},{"vulnerability":{"id":"CVE-2026-74959","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74959","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74959","epss":0.00342,"percentile":0.27269,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74959","cwe":"CWE-693","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.30951},"relatedVulnerabilities":[{"id":"CVE-2026-74959","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74959","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2047853","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74959","epss":0.00342,"percentile":0.27269,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74959","cwe":"CWE-693","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74959","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"GHSA-5mg8-w23w-74h3","dataSource":"https://github.com/advisories/GHSA-5mg8-w23w-74h3","namespace":"github:language:java","severity":"Low","urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-8908","https://github.com/google/guava/issues/4011","https://github.com/google/guava/commit/fec0dbc4634006a6162cfd4d0d09c962073ddf40","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e@%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6@%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222@%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf@%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3@%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a@%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604@%3Ctorque-dev.db.apache.org%3E","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594@%3Cdev.myfaces.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95@%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/r037fed1d0ebde50c9caf8d99815db3093c344c3f651c5a49a09824ce@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a@%3Cdev.drill.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27@%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f@%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e@%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625@%3Cissues.geode.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf@%3Cdev.pig.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95%40%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf%40%3Cdev.pig.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594%40%3Cdev.myfaces.apache.org%3E","https://github.com/google/guava/issues/4011#issuecomment-1578991974","https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284","https://security.netapp.com/advisory/ntap-20220210-0003"],"description":"Information Disclosure in Guava","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-8908","epss":0.00976,"percentile":0.6003,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-8908","cwe":"CWE-378","source":"cve-coordination@google.com","type":"Secondary"},{"cve":"CVE-2020-8908","cwe":"CWE-732","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["32.0.0-android"],"state":"fixed","available":[{"version":"32.0.0-android","date":"2023-11-10","kind":"first-observed"}]},"advisories":[],"risk":0.30743999999999994},"relatedVulnerabilities":[{"id":"CVE-2020-8908","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8908","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/google/guava/commit/fec0dbc4634006a6162cfd4d0d09c962073ddf40","https://github.com/google/guava/issues/4011","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95%40%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf%40%3Cdev.pig.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594%40%3Cdev.myfaces.apache.org%3E","https://security.netapp.com/advisory/ntap-20220210-0003/","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"description":"A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}},{"source":"cve-coordination@google.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-8908","epss":0.00976,"percentile":0.6003,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-8908","cwe":"CWE-378","source":"cve-coordination@google.com","type":"Secondary"},{"cve":"CVE-2020-8908","cwe":"CWE-732","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.google.guava:guava","version":"30.1-jre"}},"found":{"vulnerabilityID":"GHSA-5mg8-w23w-74h3","versionConstraint":"<32.0.0-android (unknown)"},"fix":{"suggestedVersion":"32.0.0-android"}}],"artifact":{"id":"6fadb4e96c532103","name":"guava","version":"30.1-jre","type":"java-archive","locations":[{"path":"/zap/plugin/spiderAjax-release-23.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/spiderAjax-release-23.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:com.google.guava:guava:30.1-jre:*:*:*:*:*:*:*","cpe:2.3:a:google:guava:30.1-jre:*:*:*:*:*:*:*","cpe:2.3:a:guava:guava:30.1-jre:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.google.guava/guava@30.1-jre","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/spiderAjax-release-23.29.0.zap:com.google.guava:guava","pomArtifactID":"guava","pomGroupID":"com.google.guava","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-5mg8-w23w-74h3","dataSource":"https://github.com/advisories/GHSA-5mg8-w23w-74h3","namespace":"github:language:java","severity":"Low","urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-8908","https://github.com/google/guava/issues/4011","https://github.com/google/guava/commit/fec0dbc4634006a6162cfd4d0d09c962073ddf40","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e@%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6@%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222@%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf@%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3@%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a@%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604@%3Ctorque-dev.db.apache.org%3E","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594@%3Cdev.myfaces.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95@%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/r037fed1d0ebde50c9caf8d99815db3093c344c3f651c5a49a09824ce@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a@%3Cdev.drill.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27@%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f@%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e@%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625@%3Cissues.geode.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf@%3Cdev.pig.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95%40%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf%40%3Cdev.pig.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594%40%3Cdev.myfaces.apache.org%3E","https://github.com/google/guava/issues/4011#issuecomment-1578991974","https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284","https://security.netapp.com/advisory/ntap-20220210-0003"],"description":"Information Disclosure in Guava","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-8908","epss":0.00976,"percentile":0.6003,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-8908","cwe":"CWE-378","source":"cve-coordination@google.com","type":"Secondary"},{"cve":"CVE-2020-8908","cwe":"CWE-732","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["32.0.0-android"],"state":"fixed","available":[{"version":"32.0.0-android","date":"2023-11-10","kind":"first-observed"}]},"advisories":[],"risk":0.30743999999999994},"relatedVulnerabilities":[{"id":"CVE-2020-8908","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8908","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/google/guava/commit/fec0dbc4634006a6162cfd4d0d09c962073ddf40","https://github.com/google/guava/issues/4011","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95%40%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf%40%3Cdev.pig.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594%40%3Cdev.myfaces.apache.org%3E","https://security.netapp.com/advisory/ntap-20220210-0003/","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"description":"A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}},{"source":"cve-coordination@google.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-8908","epss":0.00976,"percentile":0.6003,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-8908","cwe":"CWE-378","source":"cve-coordination@google.com","type":"Secondary"},{"cve":"CVE-2020-8908","cwe":"CWE-732","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.google.guava:guava","version":"31.0.1-jre"}},"found":{"vulnerabilityID":"GHSA-5mg8-w23w-74h3","versionConstraint":"<32.0.0-android (unknown)"},"fix":{"suggestedVersion":"32.0.0-android"}}],"artifact":{"id":"b4694958ecf60e48","name":"guava","version":"31.0.1-jre","type":"java-archive","locations":[{"path":"/zap/plugin/spiderAjax-release-23.32.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/spiderAjax-release-23.32.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:com.google.guava:guava:31.0.1-jre:*:*:*:*:*:*:*","cpe:2.3:a:google:guava:31.0.1-jre:*:*:*:*:*:*:*","cpe:2.3:a:guava:guava:31.0.1-jre:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.google.guava/guava@31.0.1-jre","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/spiderAjax-release-23.32.0.zap:com.google.guava:guava","pomArtifactID":"guava","pomGroupID":"com.google.guava","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2023-49528","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-49528","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-49528","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-49528","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3069},"relatedVulnerabilities":[{"id":"CVE-2023-49528","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49528","namespace":"nvd:cpe","severity":"High","urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10691","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"description":"Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-49528","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-49528","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-49528","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2023-49528","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-49528","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-49528","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-49528","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3069},"relatedVulnerabilities":[{"id":"CVE-2023-49528","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49528","namespace":"nvd:cpe","severity":"High","urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10691","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"description":"Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-49528","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-49528","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-49528","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2023-49528","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-49528","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-49528","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-49528","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3069},"relatedVulnerabilities":[{"id":"CVE-2023-49528","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49528","namespace":"nvd:cpe","severity":"High","urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10691","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"description":"Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-49528","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-49528","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-49528","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66034","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66034","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66034","epss":0.00402,"percentile":0.33711,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66034","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-66034","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":["1.10.0-3+deb12u1"],"state":"fixed","available":[{"version":"1.10.0-3+deb12u1","date":"2026-09-06","kind":"first-observed"}]},"advisories":[],"risk":0.30552},"relatedVulnerabilities":[{"id":"CVE-2026-66034","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66034","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9","https://github.com/libssh2/libssh2/pull/2202","https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem"],"description":"libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66034","epss":0.00402,"percentile":0.33711,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66034","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-66034","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libssh2","version":"1.10.0-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66034","versionConstraint":"< 1.10.0-3+deb12u1 (deb)"},"fix":{"suggestedVersion":"1.10.0-3+deb12u1"}}],"artifact":{"id":"865a7a71606e882c","name":"libssh2-1","version":"1.10.0-3+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssh2-1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD3"],"cpes":["cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12.15&upstream=libssh2%401.10.0-3","upstreams":[{"name":"libssh2","version":"1.10.0-3"}]}},{"vulnerability":{"id":"CVE-2026-42767","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42767","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42767","epss":0.00557,"percentile":0.44583,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30356500000000003},"relatedVulnerabilities":[{"id":"CVE-2026-42767","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42767","epss":0.00557,"percentile":0.44583,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42767","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f55823b1f5c2e201","name":"libssl3","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","upstreams":[{"name":"openssl"}]}},{"vulnerability":{"id":"CVE-2026-42767","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42767","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42767","epss":0.00557,"percentile":0.44583,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30356500000000003},"relatedVulnerabilities":[{"id":"CVE-2026-42767","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42767","epss":0.00557,"percentile":0.44583,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42767","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7345802bd2ec0962","name":"openssl","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-80230","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80230","epss":0.00401,"percentile":0.33593,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30074999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-80230","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80230","epss":0.00401,"percentile":0.33593,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-80230","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80230","epss":0.00401,"percentile":0.33593,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30074999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-80230","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80230","epss":0.00401,"percentile":0.33593,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-80230","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80230","epss":0.00401,"percentile":0.33593,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30074999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-80230","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80230","epss":0.00401,"percentile":0.33593,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-1502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.30067},"relatedVulnerabilities":[{"id":"CVE-2026-1502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1502","epss":0.00562,"percentile":0.44904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-12064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00399,"percentile":0.33421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.29924999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-12064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00399,"percentile":0.33421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-12064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00399,"percentile":0.33421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.29924999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-12064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00399,"percentile":0.33421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-12064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00399,"percentile":0.33421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.29924999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-12064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12064","epss":0.00399,"percentile":0.33421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-41080","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41080","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41080","epss":0.00398,"percentile":0.33254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.2985},"relatedVulnerabilities":[{"id":"CVE-2026-41080","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","namespace":"nvd:cpe","severity":"High","urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41080","epss":0.00398,"percentile":0.33254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-41080","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41080","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41080","epss":0.00398,"percentile":0.33254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.2985},"relatedVulnerabilities":[{"id":"CVE-2026-41080","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","namespace":"nvd:cpe","severity":"High","urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41080","epss":0.00398,"percentile":0.33254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-8932","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.297},"relatedVulnerabilities":[{"id":"CVE-2026-8932","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8932","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.297},"relatedVulnerabilities":[{"id":"CVE-2026-8932","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8932","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.297},"relatedVulnerabilities":[{"id":"CVE-2026-8932","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8932","epss":0.00396,"percentile":0.33079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-84119","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84119","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"exploitabilityScore":2.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84119","epss":0.00319,"percentile":0.24652,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84119","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.29667},"relatedVulnerabilities":[{"id":"CVE-2026-84119","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84119","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2057817","https://www.mozilla.org/security/advisories/mfsa2026-82/","https://www.mozilla.org/security/advisories/mfsa2026-83/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-86/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"exploitabilityScore":2.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84119","epss":0.00319,"percentile":0.24652,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84119","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84119","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-84121","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84121","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"exploitabilityScore":2.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84121","epss":0.00319,"percentile":0.24652,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84121","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.29667},"relatedVulnerabilities":[{"id":"CVE-2026-84121","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84121","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2059018","https://www.mozilla.org/security/advisories/mfsa2026-82/","https://www.mozilla.org/security/advisories/mfsa2026-83/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-86/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"exploitabilityScore":2.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84121","epss":0.00319,"percentile":0.24652,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84121","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84121","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-86145","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86145","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86145","epss":0.00373,"percentile":0.30575,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["10.42-1+deb12u1"],"state":"fixed","available":[{"version":"10.42-1+deb12u1","date":"2026-09-06","kind":"first-observed"}]},"advisories":[],"risk":0.292805},"relatedVulnerabilities":[{"id":"CVE-2026-86145","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86145","epss":0.00373,"percentile":0.30575,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pcre2","version":"10.42-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"< 10.42-1+deb12u1 (deb)"},"fix":{"suggestedVersion":"10.42-1+deb12u1"}}],"artifact":{"id":"fdd1d61b217ae9fe","name":"libpcre2-8-0","version":"10.42-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpcre2-8-0@10.42-1?arch=amd64&distro=debian-12.15&upstream=pcre2","upstreams":[{"name":"pcre2"}]}},{"vulnerability":{"id":"CVE-2026-63379","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63379","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An unauthenticated remote attacker can place security-sensitive fields in trailers so that an upstream proxy and the libevent application interpret different effective headers, enabling header smuggling, authorization bypass, proxy-header spoofing, or cache poisoning. The fix parses trailers into a temporary header list and discards them instead of merging them into req->input_headers. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63379","epss":0.00518,"percentile":0.42402,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63379","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29266999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-63379","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63379","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libevent/libevent/commit/87e8e44fa774e9677b089b1a5114ee68aefa1636","https://github.com/libevent/libevent/commit/b847071141b3827900d536594ec9045eb0a4c485","https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","https://github.com/libevent/libevent/security/advisories/GHSA-2gmv-p5m7-98p6"],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An unauthenticated remote attacker can place security-sensitive fields in trailers so that an upstream proxy and the libevent application interpret different effective headers, enabling header smuggling, authorization bypass, proxy-header spoofing, or cache poisoning. The fix parses trailers into a temporary header list and discards them instead of merging them into req->input_headers. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63379","epss":0.00518,"percentile":0.42402,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63379","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libevent","version":"2.1.12-stable-8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63379","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3bff02d75bb58680","name":"libevent-2.1-7","version":"2.1.12-stable-8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libevent-2.1-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libevent-2.1-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSL","Expat","FSFUL","FSFULLR","FSFULLR-No-Warranty","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","curl"],"cpes":["cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1-7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libevent-2.1-7@2.1.12-stable-8?arch=amd64&distro=debian-12.15&upstream=libevent","upstreams":[{"name":"libevent"}]}},{"vulnerability":{"id":"CVE-2026-64833","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64833","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64833","epss":0.00396,"percentile":0.33019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28908},"relatedVulnerabilities":[{"id":"CVE-2026-64833","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64833","epss":0.00396,"percentile":0.33019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64833","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64833","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64833","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64833","epss":0.00396,"percentile":0.33019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28908},"relatedVulnerabilities":[{"id":"CVE-2026-64833","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64833","epss":0.00396,"percentile":0.33019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64833","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64833","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64833","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64833","epss":0.00396,"percentile":0.33019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28908},"relatedVulnerabilities":[{"id":"CVE-2026-64833","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64833","epss":0.00396,"percentile":0.33019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64833","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2024-52615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00561,"percentile":0.44842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.28891500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-52615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00561,"percentile":0.44842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c21957a0053108b1","name":"libavahi-client3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2024-52615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00561,"percentile":0.44842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.28891500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-52615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00561,"percentile":0.44842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"934d69cf9aa71068","name":"libavahi-common-data","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2024-52615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00561,"percentile":0.44842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.28891500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-52615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52615","epss":0.00561,"percentile":0.44842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d355b05e7a15b748","name":"libavahi-common3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2008-3234","dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-3234","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.","cvss":[],"epss":[{"cve":"CVE-2008-3234","epss":0.05773,"percentile":0.92633,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28865},"relatedVulnerabilities":[{"id":"CVE-2008-3234","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-3234","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/30276","https://exchange.xforce.ibmcloud.com/vulnerabilities/44037","https://www.exploit-db.com/exploits/6094"],"description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"exploitabilityScore":8,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2008-3234","epss":0.05773,"percentile":0.92633,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2008-3234","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2018-20796","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28785000000000005},"relatedVulnerabilities":[{"id":"CVE-2018-20796","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2018-20796","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28785000000000005},"relatedVulnerabilities":[{"id":"CVE-2018-20796","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2018-20796","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28785000000000005},"relatedVulnerabilities":[{"id":"CVE-2018-20796","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2018-20796","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28785000000000005},"relatedVulnerabilities":[{"id":"CVE-2018-20796","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2018-20796","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28785000000000005},"relatedVulnerabilities":[{"id":"CVE-2018-20796","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20796","epss":0.05757,"percentile":0.92614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"GHSA-c4c3-7fpv-j4q5","dataSource":"https://github.com/advisories/GHSA-c4c3-7fpv-j4q5","namespace":"github:language:java","severity":"Critical","urls":["https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5","https://nvd.nist.gov/vuln/detail/CVE-2026-75595","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"description":"Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75595","epss":0.00317,"percentile":0.24433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.137.Final"],"state":"fixed","available":[{"version":"4.1.137.Final","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.286885},"relatedVulnerabilities":[{"id":"CVE-2026-75595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75595","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75595","epss":0.00317,"percentile":0.24433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-c4c3-7fpv-j4q5","versionConstraint":"<=4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.137.Final"}}],"artifact":{"id":"ab10619bb861593f","name":"netty-handler","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-c4c3-7fpv-j4q5","dataSource":"https://github.com/advisories/GHSA-c4c3-7fpv-j4q5","namespace":"github:language:java","severity":"Critical","urls":["https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5","https://nvd.nist.gov/vuln/detail/CVE-2026-75595","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"description":"Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75595","epss":0.00317,"percentile":0.24433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.137.Final"],"state":"fixed","available":[{"version":"4.1.137.Final","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.286885},"relatedVulnerabilities":[{"id":"CVE-2026-75595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75595","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75595","epss":0.00317,"percentile":0.24433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-c4c3-7fpv-j4q5","versionConstraint":"<=4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.137.Final"}}],"artifact":{"id":"bf14062c190d1eea","name":"netty-handler","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-574f-3g2m-x479","dataSource":"https://github.com/advisories/GHSA-574f-3g2m-x479","namespace":"github:language:java","severity":"Critical","urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-14813","https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3","https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json","https://bugzilla.redhat.com/show_bug.cgi?id=2458640","https://access.redhat.com/security/cve/CVE-2025-14813","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:13631","https://access.redhat.com/errata/RHSA-2026:11721","https://access.redhat.com/errata/RHSA-2026:11720"],"description":"Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/RE:M/U:Red","metrics":{"baseScore":9.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14813","epss":0.00313,"percentile":0.23945,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14813","cwe":"CWE-327","source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary"},{"cve":"CVE-2025-14813","cwe":"CWE-327","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["1.84"],"state":"fixed","available":[{"version":"1.84","date":"2026-07-01","kind":"first-observed"}]},"advisories":[],"risk":0.286395},"relatedVulnerabilities":[{"id":"CVE-2025-14813","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14813","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3","https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813","https://access.redhat.com/errata/RHSA-2026:11720","https://access.redhat.com/errata/RHSA-2026:11721","https://access.redhat.com/errata/RHSA-2026:13631","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2025-14813","https://bugzilla.redhat.com/show_bug.cgi?id=2458640","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json"],"description":": Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).\n\n This vulnerability is associated with program files G3413CTRBlockCipher.\n\n\n\nThis issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red","metrics":{"baseScore":9.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14813","epss":0.00313,"percentile":0.23945,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14813","cwe":"CWE-327","source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary"},{"cve":"CVE-2025-14813","cwe":"CWE-327","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.83"}},"found":{"vulnerabilityID":"GHSA-574f-3g2m-x479","versionConstraint":">=1.82,<=1.83 (unknown)"},"fix":{"suggestedVersion":"1.84"}}],"artifact":{"id":"a6a20590309f15f0","name":"bcprov-jdk18on","version":"1.83","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap:libs/bcprov-jdk18on-1.83.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.83:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.83","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:libs/bcprov-jdk18on-1.83.jar","pomArtifactID":"bcprov-jdk18on","pomGroupID":"org.bouncycastle","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"310e719f391bd9f4ee5103ca299c172643efb595"}]}}},{"vulnerability":{"id":"CVE-2026-58469","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58469","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58469","epss":0.00351,"percentile":0.28268,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58469","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.28431},"relatedVulnerabilities":[{"id":"CVE-2026-58469","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58469","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing"],"description":"GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58469","epss":0.00351,"percentile":0.28268,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58469","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58469","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ef5a5a7d880f3e73","name":"wget","version":"1.21.3-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.list"}],"language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-48959","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.30658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27974999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-48959","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.30658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-48959","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.30658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27974999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-48959","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.30658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-48959","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.30658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27974999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-48959","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.30658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-48959","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.30658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27974999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-48959","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48959","epss":0.00373,"percentile":0.30658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-17084","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27885000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-17084","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-17084","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27885000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-17084","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-17084","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27885000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-17084","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-17084","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27885000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-17084","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-17084","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27885000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-17084","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-17084","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27885000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-17084","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-17084","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27885000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-17084","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-17084","epss":0.00507,"percentile":0.41648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-84145","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84145","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84145","epss":0.0037,"percentile":0.30307,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84145","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.2775},"relatedVulnerabilities":[{"id":"CVE-2026-84145","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84145","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054640%2C2054650%2C2054652%2C2055693%2C2055705%2C2058051%2C2058652%2C2058660%2C2059027%2C2061220%2C2061242%2C2061285%2C2061300%2C2061316%2C2061397","https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058001%2C2059139%2C2062400%2C2062419","https://bugzilla.mozilla.org/show_bug.cgi?id=2055678","https://www.mozilla.org/security/advisories/mfsa2026-82/","https://www.mozilla.org/security/advisories/mfsa2026-83/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-86/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84145","epss":0.0037,"percentile":0.30307,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84145","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84145","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-64830","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64830","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64830","epss":0.00342,"percentile":0.27346,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27701999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-64830","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64830","epss":0.00342,"percentile":0.27346,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64830","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64830","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64830","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64830","epss":0.00342,"percentile":0.27346,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27701999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-64830","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64830","epss":0.00342,"percentile":0.27346,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64830","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64830","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64830","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64830","epss":0.00342,"percentile":0.27346,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27701999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-64830","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64830","epss":0.00342,"percentile":0.27346,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64830","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-5928","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27675},"relatedVulnerabilities":[{"id":"CVE-2026-5928","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5928","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27675},"relatedVulnerabilities":[{"id":"CVE-2026-5928","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5928","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27675},"relatedVulnerabilities":[{"id":"CVE-2026-5928","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5928","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27675},"relatedVulnerabilities":[{"id":"CVE-2026-5928","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5928","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27675},"relatedVulnerabilities":[{"id":"CVE-2026-5928","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5928","epss":0.00369,"percentile":0.30174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"GHSA-c3fc-8qff-9hwx","dataSource":"https://github.com/advisories/GHSA-c3fc-8qff-9hwx","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-0636","https://github.com/bcgit/bc-java/commit/d20cdb8430e09224114fec0179a71859929fcbde","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%900636"],"description":"Bouncy Castle has an LDAP injection","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/RE:M/U:Amber","metrics":{"baseScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0636","epss":0.00527,"percentile":0.42957,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0636","cwe":"CWE-90","source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary"},{"cve":"CVE-2026-0636","cwe":"CWE-90","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["1.84"],"state":"fixed","available":[{"version":"1.84","date":"2026-04-18","kind":"first-observed"}]},"advisories":[],"risk":0.276675},"relatedVulnerabilities":[{"id":"CVE-2026-0636","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0636","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/bcgit/bc-java/commit/d20cdb8430e09224114fec0179a71859929fcbde","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%900636","https://access.redhat.com/errata/RHSA-2026:11720","https://access.redhat.com/errata/RHSA-2026:11721","https://access.redhat.com/errata/RHSA-2026:13631","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2026-0636","https://bugzilla.redhat.com/show_bug.cgi?id=2458641","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0636.json"],"description":"Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).\n\n This vulnerability is associated with program files LDAPStoreHelper.\n\n\n\nThis issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:Amber","metrics":{"baseScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0636","epss":0.00527,"percentile":0.42957,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0636","cwe":"CWE-90","source":"91579145-5d7b-4cc5-b925-a0262ff19630","type":"Secondary"},{"cve":"CVE-2026-0636","cwe":"CWE-90","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.83"}},"found":{"vulnerabilityID":"GHSA-c3fc-8qff-9hwx","versionConstraint":">=1.74,<1.84 (unknown)"},"fix":{"suggestedVersion":"1.84"}}],"artifact":{"id":"a6a20590309f15f0","name":"bcprov-jdk18on","version":"1.83","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap:libs/bcprov-jdk18on-1.83.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.83:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.83:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.83","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:libs/bcprov-jdk18on-1.83.jar","pomArtifactID":"bcprov-jdk18on","pomGroupID":"org.bouncycastle","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"310e719f391bd9f4ee5103ca299c172643efb595"}]}}},{"vulnerability":{"id":"CVE-2026-60002","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60002","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"exploitabilityScore":3.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60002","epss":0.003,"percentile":0.2242,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.276},"relatedVulnerabilities":[{"id":"CVE-2026-60002","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","namespace":"nvd:cpe","severity":"Critical","urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"exploitabilityScore":3.9,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"exploitabilityScore":2.3,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60002","epss":0.003,"percentile":0.2242,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27458999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27458999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27458999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27458999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27458999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27458999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27458999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3276","epss":0.00486,"percentile":0.40302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.274495},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.274495},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.274495},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.274495},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.274495},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.274495},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-12781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.274495},"relatedVulnerabilities":[{"id":"CVE-2025-12781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12781","epss":0.00533,"percentile":0.43273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-70103","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-70103","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-70103","epss":0.00367,"percentile":0.30005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-70103","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27158},"relatedVulnerabilities":[{"id":"CVE-2025-70103","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-70103","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libjxl/libjxl/issues/4337","https://github.com/libjxl/libjxl/pull/4338","https://github.com/sigdevel/pocs/blob/main/res/libjxl/2025/2","https://infosec.exchange/@sigdevel/116642233929409910","http://www.openwall.com/lists/oss-security/2026/05/30/7"],"description":"Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-70103","epss":0.00367,"percentile":0.30005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-70103","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jpeg-xl","version":"0.7.0-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-70103","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b6ad6e0f23e0de4d","name":"libjxl0.7","version":"0.7.0-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjxl0.7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjxl0.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause-Google","ISC-License"],"cpes":["cpe:2.3:a:libjxl0.7:libjxl0.7:0.7.0-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjxl0.7@0.7.0-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=jpeg-xl","upstreams":[{"name":"jpeg-xl"}]}},{"vulnerability":{"id":"CVE-2026-64832","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64832","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64832","epss":0.00335,"percentile":0.26454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27135},"relatedVulnerabilities":[{"id":"CVE-2026-64832","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64832","epss":0.00335,"percentile":0.26454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64832","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64832","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64832","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64832","epss":0.00335,"percentile":0.26454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27135},"relatedVulnerabilities":[{"id":"CVE-2026-64832","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64832","epss":0.00335,"percentile":0.26454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64832","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64832","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64832","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64832","epss":0.00335,"percentile":0.26454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.27135},"relatedVulnerabilities":[{"id":"CVE-2026-64832","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64832","epss":0.00335,"percentile":0.26454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64832","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2025-61915","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61915","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61915","epss":0.00462,"percentile":0.38712,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61915","cwe":"CWE-124","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2025-61915","cwe":"CWE-129","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.27026999999999995},"relatedVulnerabilities":[{"id":"CVE-2025-61915","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61915","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/OpenPrinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","https://github.com/OpenPrinting/cups/releases/tag/v2.4.15","https://github.com/OpenPrinting/cups/security/advisories/GHSA-hxm8-vfpq-jrfc","http://www.openwall.com/lists/oss-security/2025/11/27/5"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61915","epss":0.00462,"percentile":0.38712,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61915","cwe":"CWE-124","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2025-61915","cwe":"CWE-129","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-61915","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2017-16232","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-16232","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue","cvss":[],"epss":[{"cve":"CVE-2017-16232","epss":0.05367,"percentile":0.92164,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26835000000000003},"relatedVulnerabilities":[{"id":"CVE-2017-16232","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16232","namespace":"nvd:cpe","severity":"High","urls":["http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html","http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html","http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html","http://seclists.org/fulldisclosure/2018/Dec/32","http://seclists.org/fulldisclosure/2018/Dec/47","http://www.openwall.com/lists/oss-security/2017/11/01/11","http://www.openwall.com/lists/oss-security/2017/11/01/3","http://www.openwall.com/lists/oss-security/2017/11/01/7","http://www.openwall.com/lists/oss-security/2017/11/01/8","http://www.securityfocus.com/bid/101696"],"description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-16232","epss":0.05367,"percentile":0.92164,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-16232","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-74946","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74946","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74946","epss":0.00328,"percentile":0.2571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74946","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.26732},"relatedVulnerabilities":[{"id":"CVE-2026-74946","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74946","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2059997","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74946","epss":0.00328,"percentile":0.2571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74946","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74946","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-84131","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84131","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84131","epss":0.00328,"percentile":0.2571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84131","cwe":"CWE-763","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.26732},"relatedVulnerabilities":[{"id":"CVE-2026-84131","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84131","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2060008","https://www.mozilla.org/security/advisories/mfsa2026-82/","https://www.mozilla.org/security/advisories/mfsa2026-83/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-86/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84131","epss":0.00328,"percentile":0.2571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84131","cwe":"CWE-763","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84131","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6429","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.42448,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.267285},"relatedVulnerabilities":[{"id":"CVE-2026-6429","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.42448,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6429","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.42448,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.267285},"relatedVulnerabilities":[{"id":"CVE-2026-6429","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.42448,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6429","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.42448,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.267285},"relatedVulnerabilities":[{"id":"CVE-2026-6429","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6429","epss":0.00519,"percentile":0.42448,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2016-20012","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-20012","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product","cvss":[],"epss":[{"cve":"CVE-2016-20012","epss":0.05326,"percentile":0.92118,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2016-20012","cwe":"CWE-203","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26630000000000004},"relatedVulnerabilities":[{"id":"CVE-2016-20012","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20012","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/openssh/openssh-portable/blob/d0fffc88c8fe90c1815c6f4097bc8cbcabc0f3dd/auth2-pubkey.c#L261-L265","https://github.com/openssh/openssh-portable/pull/270","https://github.com/openssh/openssh-portable/pull/270#issuecomment-920577097","https://github.com/openssh/openssh-portable/pull/270#issuecomment-943909185","https://rushter.com/blog/public-ssh-keys/","https://security.netapp.com/advisory/ntap-20211014-0005/","https://utcc.utoronto.ca/~cks/space/blog/tech/SSHKeysAreInfoLeak","https://www.openwall.com/lists/oss-security/2018/08/24/1"],"description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-20012","epss":0.05326,"percentile":0.92118,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2016-20012","cwe":"CWE-203","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-20012","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2026-63074","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63074","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.  Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack.  This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.     The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63074","epss":0.00488,"percentile":0.40431,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26596000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-63074","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63074","epss":0.00488,"percentile":0.40431,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f55823b1f5c2e201","name":"libssl3","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","upstreams":[{"name":"openssl"}]}},{"vulnerability":{"id":"CVE-2026-63074","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63074","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.  Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack.  This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.     The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63074","epss":0.00488,"percentile":0.40431,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26596000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-63074","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63074","epss":0.00488,"percentile":0.40431,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7345802bd2ec0962","name":"openssl","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-64835","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64835","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64835","epss":0.00328,"percentile":0.25632,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26567999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-64835","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64835","epss":0.00328,"percentile":0.25632,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64835","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64835","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64835","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64835","epss":0.00328,"percentile":0.25632,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26567999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-64835","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64835","epss":0.00328,"percentile":0.25632,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64835","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-64835","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64835","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64835","epss":0.00328,"percentile":0.25632,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26567999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-64835","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64835","epss":0.00328,"percentile":0.25632,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64835","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2015-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.","cvss":[],"epss":[{"cve":"CVE-2015-3276","epss":0.05269,"percentile":0.92059,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26345},"relatedVulnerabilities":[{"id":"CVE-2015-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","namespace":"nvd:cpe","severity":"High","urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","epss":0.05269,"percentile":0.92059,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"692b9197d4b21a92","name":"libldap-2.5-0","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2015-3276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.","cvss":[],"epss":[{"cve":"CVE-2015-3276","epss":0.05269,"percentile":0.92059,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26345},"relatedVulnerabilities":[{"id":"CVE-2015-3276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","namespace":"nvd:cpe","severity":"High","urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","epss":0.05269,"percentile":0.92059,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dd3946a6b1d2298d","name":"libldap-common","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-common@2.5.13%2Bdfsg-5?arch=all&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2026-74941","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74941","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74941","epss":0.00323,"percentile":0.25075,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74941","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.263245},"relatedVulnerabilities":[{"id":"CVE-2026-74941","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74941","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2055056","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74941","epss":0.00323,"percentile":0.25075,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74941","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74941","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-33164","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-33164","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-33164","epss":0.00349,"percentile":0.28044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-33164","cwe":"CWE-122","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-33164","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26175},"relatedVulnerabilities":[{"id":"CVE-2026-33164","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33164","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libde265/releases/tag/v1.0.17","https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r"],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-33164","epss":0.00349,"percentile":0.28044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-33164","cwe":"CWE-122","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-33164","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-33164","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2024-38950","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38950","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38950","epss":0.00453,"percentile":0.38092,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38950","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.260475},"relatedVulnerabilities":[{"id":"CVE-2024-38950","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38950","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libde265/issues/460","https://github.com/zhangteng0526/CVE-information/blob/main/CVE-2024-38950"],"description":"Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38950","epss":0.00453,"percentile":0.38092,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38950","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38950","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-74969","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74969","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74969","epss":0.00319,"percentile":0.24653,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74969","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.259985},"relatedVulnerabilities":[{"id":"CVE-2026-74969","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74969","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2056065","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74969","epss":0.00319,"percentile":0.24653,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74969","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74969","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74983","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74983","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74983","epss":0.00328,"percentile":0.25642,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74983","cwe":"CWE-693","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.25584},"relatedVulnerabilities":[{"id":"CVE-2026-74983","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74983","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2051897","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74983","epss":0.00328,"percentile":0.25642,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74983","cwe":"CWE-693","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74983","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-8869","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8869","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a \"fixed\" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706.  Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the \"vulnerable\" fallback code.  Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8869","epss":0.00469,"percentile":0.39163,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.255605},"relatedVulnerabilities":[{"id":"CVE-2025-8869","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8869","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pypa/pip/pull/13550","https://mail.python.org/archives/list/security-announce@python.org/thread/IF5A3GCJY3VH7BVHJKOWOJFKTW7VFQEN/","https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html"],"description":"When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706.\nNote that upgrading pip to a \"fixed\" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706.\n\nNote that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706\nand therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706\nthen pip doesn't use the \"vulnerable\" fallback code.\n\nMitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12),\napplying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8869","epss":0.00469,"percentile":0.39163,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python-pip","version":"23.0.1+dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8869","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5929913cf46d2db3","name":"python3-pip","version":"23.0.1+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3-pip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.list"},{"path":"/var/lib/dpkg/info/python3-pip.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.postinst"},{"path":"/var/lib/dpkg/info/python3-pip.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"cpes":["cpe:2.3:a:python3-pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-pip@23.0.1%2Bdfsg-1?arch=all&distro=debian-12.15&upstream=python-pip","upstreams":[{"name":"python-pip"}]}},{"vulnerability":{"id":"CVE-2026-56209","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56209","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56209","epss":0.0035,"percentile":0.28167,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56209","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-56209","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["3.6.0-1+deb12u3"],"state":"fixed","available":[{"version":"3.6.0-1+deb12u3","date":"2026-09-07","kind":"first-observed"}]},"advisories":[],"risk":0.2555},"relatedVulnerabilities":[{"id":"CVE-2026-56209","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56209","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:30814","https://access.redhat.com/errata/RHSA-2026:42875","https://access.redhat.com/errata/RHSA-2026:51100","https://access.redhat.com/errata/RHSA-2026:51146","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61627","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/security/cve/CVE-2026-56209","https://aomedia.googlesource.com/aom/+/a93ba0ffaa","https://bugzilla.redhat.com/show_bug.cgi?id=2490800","https://issues.chromium.org/issues/503993984","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56209.json"],"description":"An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56209","epss":0.0035,"percentile":0.28167,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56209","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-56209","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"aom","version":"3.6.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56209","versionConstraint":"< 3.6.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"3.6.0-1+deb12u3"}}],"artifact":{"id":"9e3b0cc1c76e74b4","name":"libaom3","version":"3.6.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libaom3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libaom3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libaom3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libaom3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","BSD-2-clause","BSD-3-clause","Expat","ISC","public-domain-md5"],"cpes":["cpe:2.3:a:libaom3:libaom3:3.6.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libaom3@3.6.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=aom","upstreams":[{"name":"aom"}]}},{"vulnerability":{"id":"CVE-2026-45382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45382","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = ctbY * ctbsWidth + ctbX` is computed from PPS-supplied `colBd[]`/`rowBd[]` arrays without validating the result against `CtbAddrRStoTS.size() == sps->PicSizeInCtbsY`. A malformed PPS that passes `set_derived_values` but encodes geometry inconsistent with the SPS produces a `ctbAddrRS` past the allocation, causing a 4-byte heap-buffer-overflow READ. Version 1.0.19 fixes the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45382","epss":0.00428,"percentile":0.36068,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45382","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25466},"relatedVulnerabilities":[{"id":"CVE-2026-45382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45382","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libde265/security/advisories/GHSA-hwhx-x2mq-ccr9"],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = ctbY * ctbsWidth + ctbX` is computed from PPS-supplied `colBd[]`/`rowBd[]` arrays without validating the result against `CtbAddrRStoTS.size() == sps->PicSizeInCtbsY`. A malformed PPS that passes `set_derived_values` but encodes geometry inconsistent with the SPS produces a `ctbAddrRS` past the allocation, causing a 4-byte heap-buffer-overflow READ. Version 1.0.19 fixes the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45382","epss":0.00428,"percentile":0.36068,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45382","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-74949","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74949","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74949","epss":0.00312,"percentile":0.23815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74949","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.25428},"relatedVulnerabilities":[{"id":"CVE-2026-74949","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74949","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2060245","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74949","epss":0.00312,"percentile":0.23815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74949","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74949","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2024-38949","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38949","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38949","epss":0.00441,"percentile":0.3715,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38949","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.253575},"relatedVulnerabilities":[{"id":"CVE-2024-38949","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38949","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libde265/issues/460","https://github.com/zhangteng0526/CVE-information/blob/main/CVE-2024-38949"],"description":"Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38949","epss":0.00441,"percentile":0.3715,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38949","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38949","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-45383","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45383","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `libde265/decctx.cc`. When decoding a WPP (Wavefront Parallel Processing) HEVC slice, `ctbAddrRS` is computed as `ctbRow * ctbsWidth` inside the entry-point loop. If the PPS/SPS headers are crafted so that this value exceeds `pps.CtbAddrRStoTS.size()`, the subsequent array access `pps.CtbAddrRStoTS[ctbAddrRS]` reads past the end of the allocated vector, triggering a heap-buffer-overflow confirmed by AddressSanitizer. Version 1.0.19 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45383","epss":0.00426,"percentile":0.35887,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45383","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25347},"relatedVulnerabilities":[{"id":"CVE-2026-45383","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45383","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libde265/security/advisories/GHSA-wg9q-ppqw-6q38"],"description":"libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `libde265/decctx.cc`. When decoding a WPP (Wavefront Parallel Processing) HEVC slice, `ctbAddrRS` is computed as `ctbRow * ctbsWidth` inside the entry-point loop. If the PPS/SPS headers are crafted so that this value exceeds `pps.CtbAddrRStoTS.size()`, the subsequent array access `pps.CtbAddrRStoTS[ctbAddrRS]` reads past the end of the allocated vector, triggering a heap-buffer-overflow confirmed by AddressSanitizer. Version 1.0.19 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45383","epss":0.00426,"percentile":0.35887,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45383","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45383","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-74935","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74935","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74935","epss":0.0031,"percentile":0.23577,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74935","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.25265},"relatedVulnerabilities":[{"id":"CVE-2026-74935","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74935","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2051013","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74935","epss":0.0031,"percentile":0.23577,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74935","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74935","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2024-7531","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-7531","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-7531","epss":0.00437,"percentile":0.36887,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-7531","cwe":"CWE-367","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.25127499999999997},"relatedVulnerabilities":[{"id":"CVE-2024-7531","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7531","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=1905691","https://www.mozilla.org/security/advisories/mfsa2024-33/","https://www.mozilla.org/security/advisories/mfsa2024-34/","https://www.mozilla.org/security/advisories/mfsa2024-35/"],"description":"Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"exploitabilityScore":2.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-7531","epss":0.00437,"percentile":0.36887,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-7531","cwe":"CWE-367","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nss","version":"2:3.87.1-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-7531","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3325a62774655e15","name":"libnss3","version":"2:3.87.1-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3","MPL-2.0","Zlib","public-domain"],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.87.1-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.87.1-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2026-6385","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6385","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6385","epss":0.00437,"percentile":0.36851,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6385","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.25127499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-6385","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6385","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6385","https://bugzilla.redhat.com/show_bug.cgi?id=2458764"],"description":"A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6385","epss":0.00437,"percentile":0.36851,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6385","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6385","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-6385","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6385","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6385","epss":0.00437,"percentile":0.36851,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6385","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.25127499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-6385","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6385","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6385","https://bugzilla.redhat.com/show_bug.cgi?id=2458764"],"description":"A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6385","epss":0.00437,"percentile":0.36851,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6385","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6385","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-6385","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6385","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6385","epss":0.00437,"percentile":0.36851,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6385","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.25127499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-6385","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6385","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6385","https://bugzilla.redhat.com/show_bug.cgi?id=2458764"],"description":"A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6385","epss":0.00437,"percentile":0.36851,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6385","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6385","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-32741","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32741","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file (attacker-controlled), while the destination buffer is sized based on the declared image dimensions. Because no upper-bound check exists on the data length, a crafted file whose iloc extent exceeds the pixel buffer allocation overflows the heap. The vulnerable single-memcpy branch is reached when the mskC property specifies bits_per_pixel = 8 and the ispe property declares an even width ≥ 64 (so that stride == width), with no changes to default security limits or external codec plugins required. This issue has been fixed in version 1.22.0.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32741","epss":0.00343,"percentile":0.27436,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32741","cwe":"CWE-122","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32741","cwe":"CWE-120","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25039},"relatedVulnerabilities":[{"id":"CVE-2026-32741","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32741","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-j3w5-7whq-p37q","https://access.redhat.com/security/cve/CVE-2026-32741","https://bugzilla.redhat.com/show_bug.cgi?id=2480002","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32741.json"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file (attacker-controlled), while the destination buffer is sized based on the declared image dimensions. Because no upper-bound check exists on the data length, a crafted file whose iloc extent exceeds the pixel buffer allocation overflows the heap. The vulnerable single-memcpy branch is reached when the mskC property specifies bits_per_pixel = 8 and the ispe property declares an even width ≥ 64 (so that stride == width), with no changes to default security limits or external codec plugins required. This issue has been fixed in version 1.22.0.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32741","epss":0.00343,"percentile":0.27436,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32741","cwe":"CWE-122","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32741","cwe":"CWE-120","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32741","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-63387","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63387","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"exploitabilityScore":2.3,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63387","epss":0.00345,"percentile":0.27614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63387","cwe":"CWE-121","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-63387","cwe":"CWE-193","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-63387","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.250125},"relatedVulnerabilities":[{"id":"CVE-2026-63387","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63387","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47"],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"exploitabilityScore":2.3,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63387","epss":0.00345,"percentile":0.27614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63387","cwe":"CWE-121","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-63387","cwe":"CWE-193","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-63387","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libevent","version":"2.1.12-stable-8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63387","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3bff02d75bb58680","name":"libevent-2.1-7","version":"2.1.12-stable-8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libevent-2.1-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libevent-2.1-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSL","Expat","FSFUL","FSFULLR","FSFULLR-No-Warranty","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","curl"],"cpes":["cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1-7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libevent-2.1-7@2.1.12-stable-8?arch=amd64&distro=debian-12.15&upstream=libevent","upstreams":[{"name":"libevent"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24906500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24906500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24906500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24906500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24906500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24906500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-8328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24906500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-8328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8328","epss":0.00457,"percentile":0.38376,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-74945","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74945","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74945","epss":0.00433,"percentile":0.36534,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74945","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.24897499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-74945","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74945","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2057808","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74945","epss":0.00433,"percentile":0.36534,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74945","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74945","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"GHSA-hjcp-jmpx-g3qm","dataSource":"https://github.com/advisories/GHSA-hjcp-jmpx-g3qm","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-64607","https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94","https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"description":"Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64607","epss":0.00482,"percentile":0.40066,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["5.6.3"],"state":"fixed","available":[{"version":"5.6.3","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.24822999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-64607","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64607","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"description":"HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64607","epss":0.00482,"percentile":0.40066,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.httpcomponents.client5:httpclient5","version":"5.2.1"}},"found":{"vulnerabilityID":"GHSA-hjcp-jmpx-g3qm","versionConstraint":">=5.0-alpha1,<5.6.3 (unknown)"},"fix":{"suggestedVersion":"5.6.3"}}],"artifact":{"id":"8cbbe3564cf11b47","name":"httpclient5","version":"5.2.1","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap:libs/httpclient5-5.2.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["Apache-2.0"],"cpes":["cpe:2.3:a:apache:httpclient5:5.2.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:client5:5.2.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.2.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:libs/httpclient5-5.2.1.jar","pomArtifactID":"httpclient5","pomGroupID":"org.apache.httpcomponents.client5","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"0c900514d3446d9ce5d9dbd90c21192048125440"}]}}},{"vulnerability":{"id":"GHSA-hjcp-jmpx-g3qm","dataSource":"https://github.com/advisories/GHSA-hjcp-jmpx-g3qm","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-64607","https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94","https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"description":"Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64607","epss":0.00482,"percentile":0.40066,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","source":"security@apache.org","type":"Secondary"}],"fix":{"versions":["5.6.3"],"state":"fixed","available":[{"version":"5.6.3","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.24822999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-64607","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64607","namespace":"nvd:cpe","severity":"Medium","urls":["https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"description":"HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64607","epss":0.00482,"percentile":0.40066,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","source":"security@apache.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.httpcomponents.client5:httpclient5","version":"5.2.1"}},"found":{"vulnerabilityID":"GHSA-hjcp-jmpx-g3qm","versionConstraint":">=5.0-alpha1,<5.6.3 (unknown)"},"fix":{"suggestedVersion":"5.6.3"}}],"artifact":{"id":"72713b9e650373bb","name":"httpclient5","version":"5.2.1","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap:libs/httpclient5-5.2.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["Apache-2.0"],"cpes":["cpe:2.3:a:apache:httpclient5:5.2.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:client5:5.2.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.2.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:libs/httpclient5-5.2.1.jar","pomArtifactID":"httpclient5","pomGroupID":"org.apache.httpcomponents.client5","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"0c900514d3446d9ce5d9dbd90c21192048125440"}]}}},{"vulnerability":{"id":"CVE-2026-74939","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74939","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74939","epss":0.00304,"percentile":0.22871,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74939","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.24776000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-74939","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74939","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2054416","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74939","epss":0.00304,"percentile":0.22871,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74939","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74939","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74942","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74942","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74942","epss":0.00304,"percentile":0.22871,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74942","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.24776000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-74942","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74942","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2056571","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74942","epss":0.00304,"percentile":0.22871,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74942","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74942","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2022-49737","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-49737","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":1.8,"impactScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-49737","epss":0.00326,"percentile":0.25473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-49737","cwe":"CWE-413","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.24775999999999998},"relatedVulnerabilities":[{"id":"CVE-2022-49737","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-49737","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=1081338;filename=dix-Hold-input-lock-for-AttachDevice.patch;msg=5","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1081338","https://gitlab.freedesktop.org/xorg/xserver/-/commit/dc7cb45482cea6ccec22d117ca0b489500b4d0a0","https://gitlab.freedesktop.org/xorg/xserver/-/issues/1260"],"description":"In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":1.8,"impactScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-49737","epss":0.00326,"percentile":0.25473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-49737","cwe":"CWE-413","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-49737","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2022-49737","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-49737","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":1.8,"impactScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-49737","epss":0.00326,"percentile":0.25473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-49737","cwe":"CWE-413","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.24775999999999998},"relatedVulnerabilities":[{"id":"CVE-2022-49737","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-49737","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=1081338;filename=dix-Hold-input-lock-for-AttachDevice.patch;msg=5","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1081338","https://gitlab.freedesktop.org/xorg/xserver/-/commit/dc7cb45482cea6ccec22d117ca0b489500b4d0a0","https://gitlab.freedesktop.org/xorg/xserver/-/issues/1260"],"description":"In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":1.8,"impactScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-49737","epss":0.00326,"percentile":0.25473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-49737","cwe":"CWE-413","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-49737","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-38347","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-38347","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38347","epss":0.00329,"percentile":0.25772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38347","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24675},"relatedVulnerabilities":[{"id":"CVE-2026-38347","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-38347","namespace":"nvd:cpe","severity":"High","urls":["https://trac.ffmpeg.org/ticket/11692"],"description":"A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38347","epss":0.00329,"percentile":0.25772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38347","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-38347","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-38347","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-38347","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38347","epss":0.00329,"percentile":0.25772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38347","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24675},"relatedVulnerabilities":[{"id":"CVE-2026-38347","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-38347","namespace":"nvd:cpe","severity":"High","urls":["https://trac.ffmpeg.org/ticket/11692"],"description":"A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38347","epss":0.00329,"percentile":0.25772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38347","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-38347","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-38347","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-38347","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38347","epss":0.00329,"percentile":0.25772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38347","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24675},"relatedVulnerabilities":[{"id":"CVE-2026-38347","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-38347","namespace":"nvd:cpe","severity":"High","urls":["https://trac.ffmpeg.org/ticket/11692"],"description":"A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38347","epss":0.00329,"percentile":0.25772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38347","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-38347","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-49295","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-49295","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predicted short-term reference picture set entries. Individual list sizes are validated, but the combined count after predicted RPS construction can exceed the 16-entry `PocStFoll` array, writing at index 16. Version 1.0.20 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49295","epss":0.00338,"percentile":0.26816,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49295","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24674000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-49295","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49295","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652b","https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594"],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predicted short-term reference picture set entries. Individual list sizes are validated, but the combined count after predicted RPS construction can exceed the 16-entry `PocStFoll` array, writing at index 16. Version 1.0.20 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49295","epss":0.00338,"percentile":0.26816,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49295","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-49295","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-49346","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-49346","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent `fill_image()` call computes the real size using `size_t`, writing ~4 GB into the undersized heap buffer. Version 1.1.0 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49346","epss":0.00338,"percentile":0.26815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49346","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24674000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-49346","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49346","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libde265/commit/8a1b5cf212f78e1c77cb46eb5d56e492a9336eb8","https://github.com/strukturag/libde265/security/advisories/GHSA-vv8h-932h-7r86"],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent `fill_image()` call computes the real size using `size_t`, writing ~4 GB into the undersized heap buffer. Version 1.1.0 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49346","epss":0.00338,"percentile":0.26815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49346","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-49346","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2023-39327","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39327","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39327","epss":0.00528,"percentile":0.42969,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24552},"relatedVulnerabilities":[{"id":"CVE-2023-39327","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39327","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39327","https://bugzilla.redhat.com/show_bug.cgi?id=2295812"],"description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39327","epss":0.00528,"percentile":0.42969,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-39327","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2010-4651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4651","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.","cvss":[],"epss":[{"cve":"CVE-2010-4651","epss":0.04874,"percentile":0.91518,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2437},"relatedVulnerabilities":[{"id":"CVE-2010-4651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4651","namespace":"nvd:cpe","severity":"Medium","urls":["http://git.savannah.gnu.org/cgit/patch.git/commit/?id=685a78b6052f4df6eac6d625a545cfb54a6ac0e1","http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055241.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055246.html","http://lists.gnu.org/archive/html/bug-patch/2010-12/msg00000.html","http://openwall.com/lists/oss-security/2011/01/05/10","http://openwall.com/lists/oss-security/2011/01/06/19","http://openwall.com/lists/oss-security/2011/01/06/20","http://openwall.com/lists/oss-security/2011/01/06/21","http://secunia.com/advisories/43663","http://secunia.com/advisories/43677","http://support.apple.com/kb/HT4723","http://www.securityfocus.com/bid/46768","http://www.vupen.com/english/advisories/2011/0600","https://bugzilla.redhat.com/show_bug.cgi?id=667529"],"description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"exploitabilityScore":8.6,"impactScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4651","epss":0.04874,"percentile":0.91518,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2010-4651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"acc529981c64331f","name":"patch","version":"2.7.6-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.list"}],"language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-38350","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-38350","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38350","epss":0.00324,"percentile":0.25209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38350","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.243},"relatedVulnerabilities":[{"id":"CVE-2026-38350","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-38350","namespace":"nvd:cpe","severity":"High","urls":["https://trac.ffmpeg.org/ticket/11686"],"description":"An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38350","epss":0.00324,"percentile":0.25209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38350","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-38350","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-38350","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-38350","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38350","epss":0.00324,"percentile":0.25209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38350","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.243},"relatedVulnerabilities":[{"id":"CVE-2026-38350","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-38350","namespace":"nvd:cpe","severity":"High","urls":["https://trac.ffmpeg.org/ticket/11686"],"description":"An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38350","epss":0.00324,"percentile":0.25209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38350","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-38350","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-38350","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-38350","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38350","epss":0.00324,"percentile":0.25209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38350","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.243},"relatedVulnerabilities":[{"id":"CVE-2026-38350","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-38350","namespace":"nvd:cpe","severity":"High","urls":["https://trac.ffmpeg.org/ticket/11686"],"description":"An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-38350","epss":0.00324,"percentile":0.25209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-38350","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-38350","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2025-68431","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68431","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68431","epss":0.00332,"percentile":0.26171,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68431","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2025-68431","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24236000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-68431","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68431","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/commit/b8c12a7b70f46c9516711a988483bed377b78d46","https://github.com/strukturag/libheif/releases/tag/v1.21.0","https://github.com/strukturag/libheif/security/advisories/GHSA-j87x-4gmq-cqfq"],"description":"libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68431","epss":0.00332,"percentile":0.26171,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68431","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2025-68431","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68431","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-16371","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16371","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, Thunderbird 140.13, Firefox ESR 140.15, and Thunderbird 140.15.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16371","epss":0.00297,"percentile":0.22125,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16371","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.242055},"relatedVulnerabilities":[{"id":"CVE-2026-16371","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16371","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2008369","https://www.mozilla.org/security/advisories/mfsa2026-68/","https://www.mozilla.org/security/advisories/mfsa2026-70/","https://www.mozilla.org/security/advisories/mfsa2026-71/","https://www.mozilla.org/security/advisories/mfsa2026-72/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-87/"],"description":"Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, Thunderbird 140.13, Firefox ESR 140.15, and Thunderbird 140.15.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16371","epss":0.00297,"percentile":0.22125,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16371","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16371","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74965","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74965","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74965","epss":0.00297,"percentile":0.22125,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74965","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.242055},"relatedVulnerabilities":[{"id":"CVE-2026-74965","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74965","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2053455","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74965","epss":0.00297,"percentile":0.22125,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74965","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74965","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74953","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74953","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74953","epss":0.00297,"percentile":0.22124,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74953","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.242055},"relatedVulnerabilities":[{"id":"CVE-2026-74953","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74953","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2022382","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74953","epss":0.00297,"percentile":0.22124,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74953","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74953","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8286","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.00309,"percentile":0.2352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24101999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-8286","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.00309,"percentile":0.2352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-8286","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.00309,"percentile":0.2352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24101999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-8286","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.00309,"percentile":0.2352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-8286","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.00309,"percentile":0.2352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24101999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-8286","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8286","epss":0.00309,"percentile":0.2352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2024-36615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36615","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36615","epss":0.00442,"percentile":0.37252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36615","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24089000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-36615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36615","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/1047524396/c44e5eaafa8f408eea0c9411205990fb","https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c#L1738","https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61"],"description":"FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36615","epss":0.00442,"percentile":0.37252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36615","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2024-36615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36615","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36615","epss":0.00442,"percentile":0.37252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36615","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24089000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-36615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36615","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/1047524396/c44e5eaafa8f408eea0c9411205990fb","https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c#L1738","https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61"],"description":"FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36615","epss":0.00442,"percentile":0.37252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36615","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2024-36615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36615","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36615","epss":0.00442,"percentile":0.37252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36615","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24089000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-36615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36615","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/1047524396/c44e5eaafa8f408eea0c9411205990fb","https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c#L1738","https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61"],"description":"FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36615","epss":0.00442,"percentile":0.37252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36615","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-5545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.34766,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23804999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-5545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.34766,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-5545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.34766,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23804999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-5545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.34766,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-5545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.34766,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23804999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-5545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5545","epss":0.00414,"percentile":0.34766,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-613","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-68471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00411,"percentile":0.3454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23632499999999998},"relatedVulnerabilities":[{"id":"CVE-2025-68471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00411,"percentile":0.3454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c21957a0053108b1","name":"libavahi-client3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00411,"percentile":0.3454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23632499999999998},"relatedVulnerabilities":[{"id":"CVE-2025-68471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00411,"percentile":0.3454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"}}],"artifact":{"id":"934d69cf9aa71068","name":"libavahi-common-data","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00411,"percentile":0.3454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23632499999999998},"relatedVulnerabilities":[{"id":"CVE-2025-68471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68471","epss":0.00411,"percentile":0.3454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d355b05e7a15b748","name":"libavahi-common3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-32882","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32882","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32882","epss":0.00323,"percentile":0.25122,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32882","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32882","cwe":"CWE-125","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23578999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-32882","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32882","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46","https://access.redhat.com/security/cve/CVE-2026-32882","https://bugzilla.redhat.com/show_bug.cgi?id=2480000","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32882.json"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32882","epss":0.00323,"percentile":0.25122,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32882","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32882","cwe":"CWE-125","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32882","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-41071","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41071","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares more samples than the chunks cover, the loop increments current_chunk past chunks.size(), causing an out-of-bounds read on the chunks vector. The vulnerability is triggered during file parsing (heif_context_read_from_file) without any additional user interaction. Any application using libheif to open untrusted HEIF files is affected. This issue has been fixed in version 1.22.0.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41071","epss":0.00302,"percentile":0.22615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41071","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23556000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-41071","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41071","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-xj92-xjff-h8w3"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares more samples than the chunks cover, the loop increments current_chunk past chunks.size(), causing an out-of-bounds read on the chunks vector. The vulnerability is triggered during file parsing (heif_context_read_from_file) without any additional user interaction. Any application using libheif to open untrusted HEIF files is affected. This issue has been fixed in version 1.22.0.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41071","epss":0.00302,"percentile":0.22615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41071","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-41071","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-66039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66039","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66039","epss":0.00307,"percentile":0.23217,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-66039","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.234855},"relatedVulnerabilities":[{"id":"CVE-2026-66039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66039","epss":0.00307,"percentile":0.23217,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-66039","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66039","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66039","epss":0.00307,"percentile":0.23217,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-66039","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.234855},"relatedVulnerabilities":[{"id":"CVE-2026-66039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66039","epss":0.00307,"percentile":0.23217,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-66039","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66039","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66039","epss":0.00307,"percentile":0.23217,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-66039","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.234855},"relatedVulnerabilities":[{"id":"CVE-2026-66039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66039","epss":0.00307,"percentile":0.23217,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-66039","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-74957","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74957","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74957","epss":0.003,"percentile":0.22488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74957","cwe":"CWE-693","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.234},"relatedVulnerabilities":[{"id":"CVE-2026-74957","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74957","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2041906","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74957","epss":0.003,"percentile":0.22488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74957","cwe":"CWE-693","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74957","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-65703","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65703","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65703","epss":0.00292,"percentile":0.21545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2336},"relatedVulnerabilities":[{"id":"CVE-2026-65703","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65703","epss":0.00292,"percentile":0.21545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65703","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65703","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65703","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65703","epss":0.00292,"percentile":0.21545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2336},"relatedVulnerabilities":[{"id":"CVE-2026-65703","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65703","epss":0.00292,"percentile":0.21545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65703","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65703","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65703","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65703","epss":0.00292,"percentile":0.21545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2336},"relatedVulnerabilities":[{"id":"CVE-2026-65703","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65703","epss":0.00292,"percentile":0.21545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65703","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-34978","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34978","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34978","epss":0.00406,"percentile":0.34084,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34978","cwe":"CWE-22","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.23345},"relatedVulnerabilities":[{"id":"CVE-2026-34978","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34978","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcr"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34978","epss":0.00406,"percentile":0.34084,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34978","cwe":"CWE-22","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-34978","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"GHSA-6hg6-v5c8-fphq","dataSource":"https://github.com/advisories/GHSA-6hg6-v5c8-fphq","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34477","https://github.com/apache/logging-log4j2/pull/4075","https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/security.html#CVE-2026-34477"],"description":"Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34477","epss":0.0041,"percentile":0.34433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34477","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-34477","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["2.25.4"],"state":"fixed","available":[{"version":"2.25.4","date":"2026-04-14","kind":"first-observed"}]},"advisories":[],"risk":0.23165},"relatedVulnerabilities":[{"id":"CVE-2026-34477","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34477","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4075","https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/security.html#CVE-2026-34477"],"description":"The fix for  CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161  was incomplete: it addressed hostname verification only when enabled via the  log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName  system property, but not when configured through the  verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName  attribute of the <Ssl> element.\n\nAlthough the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value.\n\nA network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met:\n\n  *  An SMTP, Socket, or Syslog appender is in use.\n  *  TLS is configured via a nested <Ssl> element.\n  *  The attacker can present a certificate issued by a CA trusted by the appender's configured trust store, or by the default Java trust store if none is configured.\nThis issue does not affect users of the HTTP appender, which uses a separate  verifyHostname https://logging.apache.org/log4j/2.x/manual/appenders/network.html#HttpAppender-attr-verifyHostName  attribute that was not subject to this bug and verifies host names by default.\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34477","epss":0.0041,"percentile":0.34433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34477","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-34477","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.20.0"}},"found":{"vulnerabilityID":"GHSA-6hg6-v5c8-fphq","versionConstraint":">=2.12.0,<2.25.4 (unknown)"},"fix":{"suggestedVersion":"2.25.4"}}],"artifact":{"id":"0b7b26b2a9f8e3ea","name":"log4j-core","version":"2.20.0","type":"java-archive","locations":[{"path":"/zap/webswing/webswing-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/webswing-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:log4j-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.20.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.20.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/webswing-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"eb2a9a47b1396e00b5eee1264296729a70565cc0"}]}}},{"vulnerability":{"id":"GHSA-6hg6-v5c8-fphq","dataSource":"https://github.com/advisories/GHSA-6hg6-v5c8-fphq","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34477","https://github.com/apache/logging-log4j2/pull/4075","https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/security.html#CVE-2026-34477"],"description":"Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34477","epss":0.0041,"percentile":0.34433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34477","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-34477","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["2.25.4"],"state":"fixed","available":[{"version":"2.25.4","date":"2026-04-14","kind":"first-observed"}]},"advisories":[],"risk":0.23165},"relatedVulnerabilities":[{"id":"CVE-2026-34477","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34477","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4075","https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/security.html#CVE-2026-34477"],"description":"The fix for  CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161  was incomplete: it addressed hostname verification only when enabled via the  log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName  system property, but not when configured through the  verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName  attribute of the <Ssl> element.\n\nAlthough the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value.\n\nA network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met:\n\n  *  An SMTP, Socket, or Syslog appender is in use.\n  *  TLS is configured via a nested <Ssl> element.\n  *  The attacker can present a certificate issued by a CA trusted by the appender's configured trust store, or by the default Java trust store if none is configured.\nThis issue does not affect users of the HTTP appender, which uses a separate  verifyHostname https://logging.apache.org/log4j/2.x/manual/appenders/network.html#HttpAppender-attr-verifyHostName  attribute that was not subject to this bug and verifies host names by default.\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34477","epss":0.0041,"percentile":0.34433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34477","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-34477","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.20.0"}},"found":{"vulnerabilityID":"GHSA-6hg6-v5c8-fphq","versionConstraint":">=2.12.0,<2.25.4 (unknown)"},"fix":{"suggestedVersion":"2.25.4"}}],"artifact":{"id":"89dc48ff2ee6f684","name":"log4j-core","version":"2.20.0","type":"java-archive","locations":[{"path":"/zap/webswing/admin/webswing-admin-server.war","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/admin/webswing-admin-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:apache:log4j-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.20.0:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.20.0","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/admin/webswing-admin-server.war:WEB-INF/lib/log4j-core-2.20.0.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"eb2a9a47b1396e00b5eee1264296729a70565cc0"}]}}},{"vulnerability":{"id":"GHSA-6hg6-v5c8-fphq","dataSource":"https://github.com/advisories/GHSA-6hg6-v5c8-fphq","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34477","https://github.com/apache/logging-log4j2/pull/4075","https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/security.html#CVE-2026-34477"],"description":"Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34477","epss":0.0041,"percentile":0.34433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34477","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-34477","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["2.25.4"],"state":"fixed","available":[{"version":"2.25.4","date":"2026-04-14","kind":"first-observed"}]},"advisories":[],"risk":0.23165},"relatedVulnerabilities":[{"id":"CVE-2026-34477","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34477","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/apache/logging-log4j2/pull/4075","https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/security.html#CVE-2026-34477"],"description":"The fix for  CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161  was incomplete: it addressed hostname verification only when enabled via the  log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName  system property, but not when configured through the  verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName  attribute of the <Ssl> element.\n\nAlthough the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value.\n\nA network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met:\n\n  *  An SMTP, Socket, or Syslog appender is in use.\n  *  TLS is configured via a nested <Ssl> element.\n  *  The attacker can present a certificate issued by a CA trusted by the appender's configured trust store, or by the default Java trust store if none is configured.\nThis issue does not affect users of the HTTP appender, which uses a separate  verifyHostname https://logging.apache.org/log4j/2.x/manual/appenders/network.html#HttpAppender-attr-verifyHostName  attribute that was not subject to this bug and verifies host names by default.\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@apache.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34477","epss":0.0041,"percentile":0.34433,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34477","cwe":"CWE-297","source":"security@apache.org","type":"Secondary"},{"cve":"CVE-2026-34477","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.25.2"}},"found":{"vulnerabilityID":"GHSA-6hg6-v5c8-fphq","versionConstraint":">=2.12.0,<2.25.4 (unknown)"},"fix":{"suggestedVersion":"2.25.4"}}],"artifact":{"id":"a9ba8caf0d394805","name":"log4j-core","version":"2.25.2","type":"java-archive","locations":[{"path":"/zap/lib/log4j-core-2.25.2.jar","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/lib/log4j-core-2.25.2.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"cpes":["cpe:2.3:a:apache:log4j-core:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.25.2:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.25.2","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/lib/log4j-core-2.25.2.jar","pomArtifactID":"log4j-core","pomGroupID":"org.apache.logging.log4j","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"d4d0ad2e51e03e531f784891fbfff1bae1e13a12"}]}}},{"vulnerability":{"id":"CVE-2026-19672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19672","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The tarfile module's tar and data  extraction filters created directories outside the destination for  members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.  Only  empty directories are created outside the destination. Member contents  are still extracted inside it. To return to the destination the member's  name must contain the destination directory's own final component, so  extraction into a secure randomised directory is not affected.  This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23108499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-19672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-19672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19672","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The tarfile module's tar and data  extraction filters created directories outside the destination for  members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.  Only  empty directories are created outside the destination. Member contents  are still extracted inside it. To return to the destination the member's  name must contain the destination directory's own final component, so  extraction into a secure randomised directory is not affected.  This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23108499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-19672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-19672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19672","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The tarfile module's tar and data  extraction filters created directories outside the destination for  members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.  Only  empty directories are created outside the destination. Member contents  are still extracted inside it. To return to the destination the member's  name must contain the destination directory's own final component, so  extraction into a secure randomised directory is not affected.  This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23108499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-19672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-19672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19672","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The tarfile module's tar and data  extraction filters created directories outside the destination for  members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.  Only  empty directories are created outside the destination. Member contents  are still extracted inside it. To return to the destination the member's  name must contain the destination directory's own final component, so  extraction into a secure randomised directory is not affected.  This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23108499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-19672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-19672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19672","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The tarfile module's tar and data  extraction filters created directories outside the destination for  members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.  Only  empty directories are created outside the destination. Member contents  are still extracted inside it. To return to the destination the member's  name must contain the destination directory's own final component, so  extraction into a secure randomised directory is not affected.  This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23108499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-19672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-19672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19672","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The tarfile module's tar and data  extraction filters created directories outside the destination for  members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.  Only  empty directories are created outside the destination. Member contents  are still extracted inside it. To return to the destination the member's  name must contain the destination directory's own final component, so  extraction into a secure randomised directory is not affected.  This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23108499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-19672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-19672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19672","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The tarfile module's tar and data  extraction filters created directories outside the destination for  members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.  Only  empty directories are created outside the destination. Member contents  are still extracted inside it. To return to the destination the member's  name must contain the destination directory's own final component, so  extraction into a secure randomised directory is not affected.  This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23108499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-19672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19672","epss":0.00409,"percentile":0.34311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-22693","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-22693","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-22693","epss":0.00442,"percentile":0.37228,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-22693","cwe":"CWE-476","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22763000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-22693","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22693","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/harfbuzz/harfbuzz/commit/1265ff8d990284f04d8768f35b0e20ae5f60daae","https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-xvjr-f2r9-c7ww","http://www.openwall.com/lists/oss-security/2026/01/11/1","http://www.openwall.com/lists/oss-security/2026/01/12/1"],"description":"HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-22693","epss":0.00442,"percentile":0.37228,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-22693","cwe":"CWE-476","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"harfbuzz","version":"6.0.0+dfsg-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-22693","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e593bea3ea25c1a5","name":"libharfbuzz0b","version":"6.0.0+dfsg-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libharfbuzz0b/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libharfbuzz0b/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libharfbuzz0b:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libharfbuzz0b:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","CC0-1.0","Expat","FSFAP","FSFUL","FSFULLR","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","MIT","Monotype","OFL-1.1","UFL-1.0","Unicode"],"cpes":["cpe:2.3:a:libharfbuzz0b:libharfbuzz0b:6.0.0\\+dfsg-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libharfbuzz0b@6.0.0%2Bdfsg-3?arch=amd64&distro=debian-12.15&upstream=harfbuzz","upstreams":[{"name":"harfbuzz"}]}},{"vulnerability":{"id":"CVE-2026-16365","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16365","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird 140.15.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16365","epss":0.00278,"percentile":0.20071,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16365","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16365","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.22657000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-16365","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16365","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2049149","https://www.mozilla.org/security/advisories/mfsa2026-68/","https://www.mozilla.org/security/advisories/mfsa2026-71/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-87/"],"description":"Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird 140.15.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16365","epss":0.00278,"percentile":0.20071,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16365","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16365","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16365","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-56210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56210","epss":0.00308,"percentile":0.23377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56210","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-56210","cwe":"CWE-125","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["3.6.0-1+deb12u3"],"state":"fixed","available":[{"version":"3.6.0-1+deb12u3","date":"2026-09-07","kind":"first-observed"}]},"advisories":[],"risk":0.22483999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-56210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56210","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:30814","https://access.redhat.com/errata/RHSA-2026:42875","https://access.redhat.com/errata/RHSA-2026:51100","https://access.redhat.com/errata/RHSA-2026:51146","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61627","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/security/cve/CVE-2026-56210","https://aomedia.googlesource.com/aom/+/a93ba0ffaa","https://bugzilla.redhat.com/show_bug.cgi?id=2490801","https://issues.chromium.org/issues/503975732","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56210.json"],"description":"A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56210","epss":0.00308,"percentile":0.23377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56210","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-56210","cwe":"CWE-125","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"aom","version":"3.6.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56210","versionConstraint":"< 3.6.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"3.6.0-1+deb12u3"}}],"artifact":{"id":"9e3b0cc1c76e74b4","name":"libaom3","version":"3.6.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libaom3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libaom3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libaom3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libaom3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","BSD-2-clause","BSD-3-clause","Expat","ISC","public-domain-md5"],"cpes":["cpe:2.3:a:libaom3:libaom3:3.6.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libaom3@3.6.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=aom","upstreams":[{"name":"aom"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22454000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-3184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3184","epss":0.00436,"percentile":0.36809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-15806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22385},"relatedVulnerabilities":[{"id":"CVE-2026-15806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22385},"relatedVulnerabilities":[{"id":"CVE-2026-15806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22385},"relatedVulnerabilities":[{"id":"CVE-2026-15806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22385},"relatedVulnerabilities":[{"id":"CVE-2026-15806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22385},"relatedVulnerabilities":[{"id":"CVE-2026-15806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-15806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22385},"relatedVulnerabilities":[{"id":"CVE-2026-15806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22385},"relatedVulnerabilities":[{"id":"CVE-2026-15806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15806","epss":0.00407,"percentile":0.34161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-15806","cwe":"CWE-522","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-48962","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.2154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22337999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-48962","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.2154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-48962","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.2154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22337999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-48962","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.2154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-48962","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.2154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22337999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-48962","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.2154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-48962","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.2154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22337999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-48962","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48962","epss":0.00292,"percentile":0.2154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-48962","cwe":"CWE-94","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2025-68468","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00386,"percentile":0.31978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22195},"relatedVulnerabilities":[{"id":"CVE-2025-68468","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00386,"percentile":0.31978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c21957a0053108b1","name":"libavahi-client3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68468","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00386,"percentile":0.31978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22195},"relatedVulnerabilities":[{"id":"CVE-2025-68468","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00386,"percentile":0.31978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"}}],"artifact":{"id":"934d69cf9aa71068","name":"libavahi-common-data","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68468","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00386,"percentile":0.31978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22195},"relatedVulnerabilities":[{"id":"CVE-2025-68468","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68468","epss":0.00386,"percentile":0.31978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d355b05e7a15b748","name":"libavahi-common3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-48029","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48029","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48029","epss":0.00304,"percentile":0.22923,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48029","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48029","cwe":"CWE-191","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22192},"relatedVulnerabilities":[{"id":"CVE-2026-48029","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48029","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/commit/e523ec0bf379110b7c33d4c159f8b1202d332157","https://github.com/strukturag/libheif/security/advisories/GHSA-6x5f-qchq-cxqv"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48029","epss":0.00304,"percentile":0.22923,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48029","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-48029","cwe":"CWE-191","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48029","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-6276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00295,"percentile":0.21888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22125},"relatedVulnerabilities":[{"id":"CVE-2026-6276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00295,"percentile":0.21888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00295,"percentile":0.21888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22125},"relatedVulnerabilities":[{"id":"CVE-2026-6276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00295,"percentile":0.21888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-6276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00295,"percentile":0.21888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22125},"relatedVulnerabilities":[{"id":"CVE-2026-6276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6276","epss":0.00295,"percentile":0.21888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-319","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-34990","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34990","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34990","epss":0.00289,"percentile":0.21314,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34990","cwe":"CWE-287","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.22108500000000003},"relatedVulnerabilities":[{"id":"CVE-2026-34990","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34990","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34990","epss":0.00289,"percentile":0.21314,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34990","cwe":"CWE-287","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-34990","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2026-58051","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58051","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58051","epss":0.00277,"percentile":0.19935,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58051","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":["1.10.0-3+deb12u1"],"state":"fixed","available":[{"version":"1.10.0-3+deb12u1","date":"2026-09-06","kind":"first-observed"}]},"advisories":[],"risk":0.21883000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-58051","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58051","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc","https://github.com/libssh2/libssh2/blob/master/src/publickey.c","https://www.vulncheck.com/advisories/libssh2-free-of-uninitialized-pointer-in-publickey-list-cleanup"],"description":"libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58051","epss":0.00277,"percentile":0.19935,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58051","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libssh2","version":"1.10.0-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58051","versionConstraint":"< 1.10.0-3+deb12u1 (deb)"},"fix":{"suggestedVersion":"1.10.0-3+deb12u1"}}],"artifact":{"id":"865a7a71606e882c","name":"libssh2-1","version":"1.10.0-3+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssh2-1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssh2-1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD3"],"cpes":["cpe:2.3:a:libssh2-1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1:1.10.0-3\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1:1.10.0-3\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssh2-1@1.10.0-3%2Bb1?arch=amd64&distro=debian-12.15&upstream=libssh2%401.10.0-3","upstreams":[{"name":"libssh2","version":"1.10.0-3"}]}},{"vulnerability":{"id":"GHSA-6cqp-g7gg-8hr5","dataSource":"https://github.com/advisories/GHSA-6cqp-g7gg-8hr5","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5","https://nvd.nist.gov/vuln/detail/CVE-2026-56746","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: Security Control Bypass via CORS Short-Circuit Failure","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56746","epss":0.00379,"percentile":0.31241,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.21792499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-56746","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56746","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"],"description":"Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56746","epss":0.00379,"percentile":0.31241,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-6cqp-g7gg-8hr5","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-6cqp-g7gg-8hr5","dataSource":"https://github.com/advisories/GHSA-6cqp-g7gg-8hr5","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5","https://nvd.nist.gov/vuln/detail/CVE-2026-56746","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: Security Control Bypass via CORS Short-Circuit Failure","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56746","epss":0.00379,"percentile":0.31241,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.21792499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-56746","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56746","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"],"description":"Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56746","epss":0.00379,"percentile":0.31241,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-6cqp-g7gg-8hr5","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-58049","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58049","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58049","epss":0.00286,"percentile":0.20936,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21593000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-58049","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58049","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/FFmpeg/FFmpeg/blob/master/libavcodec/rasc.c","https://github.com/bikini/exploitarium/tree/main/ffmpeg-rasc-dlta-calc-poc","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-rasc-decoder-decode-dlta","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/errata/RHSA-2026:51180","https://access.redhat.com/errata/RHSA-2026:52832","https://access.redhat.com/errata/RHSA-2026:52833","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61627","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/security/cve/CVE-2026-58049","https://bugzilla.redhat.com/show_bug.cgi?id=2493952","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58049.json"],"description":"FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58049","epss":0.00286,"percentile":0.20936,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58049","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-58049","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58049","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58049","epss":0.00286,"percentile":0.20936,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21593000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-58049","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58049","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/FFmpeg/FFmpeg/blob/master/libavcodec/rasc.c","https://github.com/bikini/exploitarium/tree/main/ffmpeg-rasc-dlta-calc-poc","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-rasc-decoder-decode-dlta","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/errata/RHSA-2026:51180","https://access.redhat.com/errata/RHSA-2026:52832","https://access.redhat.com/errata/RHSA-2026:52833","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61627","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/security/cve/CVE-2026-58049","https://bugzilla.redhat.com/show_bug.cgi?id=2493952","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58049.json"],"description":"FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58049","epss":0.00286,"percentile":0.20936,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58049","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-58049","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58049","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58049","epss":0.00286,"percentile":0.20936,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21593000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-58049","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58049","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/FFmpeg/FFmpeg/blob/master/libavcodec/rasc.c","https://github.com/bikini/exploitarium/tree/main/ffmpeg-rasc-dlta-calc-poc","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-rasc-decoder-decode-dlta","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/errata/RHSA-2026:51180","https://access.redhat.com/errata/RHSA-2026:52832","https://access.redhat.com/errata/RHSA-2026:52833","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61627","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:61629","https://access.redhat.com/security/cve/CVE-2026-58049","https://bugzilla.redhat.com/show_bug.cgi?id=2493952","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58049.json"],"description":"FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58049","epss":0.00286,"percentile":0.20936,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-58049","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58049","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-19487","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19487","epss":0.00418,"percentile":0.3521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21527},"relatedVulnerabilities":[{"id":"CVE-2026-19487","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19487","epss":0.00418,"percentile":0.3521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-19487","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19487","epss":0.00418,"percentile":0.3521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21527},"relatedVulnerabilities":[{"id":"CVE-2026-19487","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19487","epss":0.00418,"percentile":0.3521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-19487","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19487","epss":0.00418,"percentile":0.3521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21527},"relatedVulnerabilities":[{"id":"CVE-2026-19487","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19487","epss":0.00418,"percentile":0.3521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-19487","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19487","epss":0.00418,"percentile":0.3521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21527},"relatedVulnerabilities":[{"id":"CVE-2026-19487","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19487","epss":0.00418,"percentile":0.3521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2023-45221","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45221","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Improper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45221","epss":0.00281,"percentile":0.20449,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45221","cwe":"CWE-119","source":"secure@intel.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.214965},"relatedVulnerabilities":[{"id":"CVE-2023-45221","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45221","namespace":"nvd:cpe","severity":"High","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html"],"description":"Improper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"exploitabilityScore":1.4,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45221","epss":0.00281,"percentile":0.20449,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45221","cwe":"CWE-119","source":"secure@intel.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45221","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2025-7458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7458","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7458","epss":0.00237,"percentile":0.14694,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7458","cwe":"CWE-190","source":"cve-coordination@google.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.21448500000000004},"relatedVulnerabilities":[{"id":"CVE-2025-7458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7458","namespace":"nvd:cpe","severity":"Critical","urls":["https://sqlite.org/forum/forumpost/16ce2bb7a639e29b","https://sqlite.org/src/info/12ad822d9b827777"],"description":"An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"cve-coordination@google.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7458","epss":0.00237,"percentile":0.14694,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7458","cwe":"CWE-190","source":"cve-coordination@google.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"GHSA-xq3w-v528-46rv","dataSource":"https://github.com/advisories/GHSA-xq3w-v528-46rv","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-xq3w-v528-46rv","https://nvd.nist.gov/vuln/detail/CVE-2024-47535","https://github.com/netty/netty/commit/fbf7a704a82e7449b48bd0bbb679f5661c6d61a3"],"description":"Denial of Service attack on windows app using netty","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":5.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47535","epss":0.00408,"percentile":0.34266,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47535","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.115.Final"],"state":"fixed","available":[{"version":"4.1.115.Final","date":"2025-02-19","kind":"first-observed"}]},"advisories":[],"risk":0.21318},"relatedVulnerabilities":[{"id":"CVE-2024-47535","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47535","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/commit/fbf7a704a82e7449b48bd0bbb679f5661c6d61a3","https://github.com/netty/netty/security/advisories/GHSA-xq3w-v528-46rv"],"description":"Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47535","epss":0.00408,"percentile":0.34266,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47535","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-common","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-xq3w-v528-46rv","versionConstraint":"<=4.1.114.Final (unknown)"},"fix":{"suggestedVersion":"4.1.115.Final"}}],"artifact":{"id":"25deed0cb1aa906b","name":"netty-common","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-common:netty-common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-common:netty_common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_common:netty-common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_common:netty_common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_common:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-common@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-common","pomArtifactID":"netty-common","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-558v-64gr-wgg4","dataSource":"https://github.com/advisories/GHSA-558v-64gr-wgg4","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59901","epss":0.00263,"percentile":0.18081,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.21303},"relatedVulnerabilities":[{"id":"CVE-2026-59901","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59901","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59901","epss":0.00263,"percentile":0.18081,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-558v-64gr-wgg4","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"3dc400e13c062728","name":"netty-codec","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec","pomArtifactID":"netty-codec","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-558v-64gr-wgg4","dataSource":"https://github.com/advisories/GHSA-558v-64gr-wgg4","namespace":"github:language:java","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59901","epss":0.00263,"percentile":0.18081,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.21303},"relatedVulnerabilities":[{"id":"CVE-2026-59901","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59901","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59901","epss":0.00263,"percentile":0.18081,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-558v-64gr-wgg4","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"2e44eee37c37e0b2","name":"netty-codec","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec:netty-codec:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec","pomArtifactID":"netty-codec","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-41079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41079","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41079","epss":0.00409,"percentile":0.34283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41079","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-41079","cwe":"CWE-200","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21267999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-41079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41079","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080","https://github.com/OpenPrinting/cups/commit/d7fe0f521ff3b24676511e747b058362b9a20737","https://github.com/OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrv"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41079","epss":0.00409,"percentile":0.34283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41079","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-41079","cwe":"CWE-200","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-41079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2025-22921","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22921","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22921","epss":0.00365,"percentile":0.29762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20987499999999998},"relatedVulnerabilities":[{"id":"CVE-2025-22921","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","namespace":"nvd:cpe","severity":"Medium","urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22921","epss":0.00365,"percentile":0.29762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22921","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2025-22921","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22921","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22921","epss":0.00365,"percentile":0.29762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20987499999999998},"relatedVulnerabilities":[{"id":"CVE-2025-22921","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","namespace":"nvd:cpe","severity":"Medium","urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22921","epss":0.00365,"percentile":0.29762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22921","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2025-22921","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22921","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22921","epss":0.00365,"percentile":0.29762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20987499999999998},"relatedVulnerabilities":[{"id":"CVE-2025-22921","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22921","namespace":"nvd:cpe","severity":"Medium","urls":["https://trac.ffmpeg.org/ticket/11393","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"description":"FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22921","epss":0.00365,"percentile":0.29762,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22921","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22921","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"GHSA-m4cv-j2px-7723","dataSource":"https://github.com/advisories/GHSA-m4cv-j2px-7723","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-m4cv-j2px-7723","https://nvd.nist.gov/vuln/detail/CVE-2026-42580"],"description":"Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42580","epss":0.00364,"percentile":0.29689,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42580","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42580","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.133.Final"],"state":"fixed","available":[{"version":"4.1.133.Final","date":"2026-05-07","kind":"first-observed"}]},"advisories":[],"risk":0.20929999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-42580","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42580","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-m4cv-j2px-7723"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42580","epss":0.00364,"percentile":0.29689,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42580","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-42580","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-m4cv-j2px-7723","versionConstraint":"<=4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.133.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-fccg-mwvh-qqg4","dataSource":"https://github.com/advisories/GHSA-fccg-mwvh-qqg4","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4","https://nvd.nist.gov/vuln/detail/CVE-2026-75596","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"description":"Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75596","epss":0.00351,"percentile":0.28236,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.137.Final"],"state":"fixed","available":[{"version":"4.1.137.Final","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.208845},"relatedVulnerabilities":[{"id":"CVE-2026-75596","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75596","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75596","epss":0.00351,"percentile":0.28236,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-fccg-mwvh-qqg4","versionConstraint":"<=4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.137.Final"}}],"artifact":{"id":"ab10619bb861593f","name":"netty-handler","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-fccg-mwvh-qqg4","dataSource":"https://github.com/advisories/GHSA-fccg-mwvh-qqg4","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4","https://nvd.nist.gov/vuln/detail/CVE-2026-75596","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"description":"Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75596","epss":0.00351,"percentile":0.28236,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.137.Final"],"state":"fixed","available":[{"version":"4.1.137.Final","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.208845},"relatedVulnerabilities":[{"id":"CVE-2026-75596","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75596","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75596","epss":0.00351,"percentile":0.28236,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-handler","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-fccg-mwvh-qqg4","versionConstraint":"<=4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.137.Final"}}],"artifact":{"id":"bf14062c190d1eea","name":"netty-handler","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-handler@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-handler","pomArtifactID":"netty-handler","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20819000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20819000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20819000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20819000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20819000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20819000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20819000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-15366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15366","epss":0.00382,"percentile":0.31552,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20584999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-6238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","namespace":"nvd:cpe","severity":"Medium","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20584999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-6238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","namespace":"nvd:cpe","severity":"Medium","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20584999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-6238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","namespace":"nvd:cpe","severity":"Medium","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20584999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-6238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","namespace":"nvd:cpe","severity":"Medium","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20584999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-6238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","namespace":"nvd:cpe","severity":"Medium","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6238","epss":0.00358,"percentile":0.29076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-55999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-55999","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Local attackers with a X connection able to provide PCX fonts to the X  server xorg-server before 21.2.24 and xwayland before 24.1.13 could  cause a heap buffer overflow via SetFont due to missing glyph boundary checks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55999","epss":0.00269,"percentile":0.18941,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55999","cwe":"CWE-122","source":"meissner@suse.de","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.205785},"relatedVulnerabilities":[{"id":"CVE-2026-55999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55999","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/xorg/xserver/-/commit/fbf7bac22e2c6bd627fb042742a23318263edae1","https://www.openwall.com/lists/oss-security/2026/07/08/2"],"description":"Local attackers with a X connection able to provide PCX fonts to the X \nserver xorg-server before 21.2.24 and xwayland before 24.1.13 could \ncause a heap buffer overflow via SetFont due to missing glyph boundary checks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"meissner@suse.de","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"exploitabilityScore":1.8,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55999","epss":0.00269,"percentile":0.18941,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55999","cwe":"CWE-122","source":"meissner@suse.de","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-55999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-55999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-55999","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Local attackers with a X connection able to provide PCX fonts to the X  server xorg-server before 21.2.24 and xwayland before 24.1.13 could  cause a heap buffer overflow via SetFont due to missing glyph boundary checks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55999","epss":0.00269,"percentile":0.18941,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55999","cwe":"CWE-122","source":"meissner@suse.de","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.205785},"relatedVulnerabilities":[{"id":"CVE-2026-55999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55999","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/xorg/xserver/-/commit/fbf7bac22e2c6bd627fb042742a23318263edae1","https://www.openwall.com/lists/oss-security/2026/07/08/2"],"description":"Local attackers with a X connection able to provide PCX fonts to the X \nserver xorg-server before 21.2.24 and xwayland before 24.1.13 could \ncause a heap buffer overflow via SetFont due to missing glyph boundary checks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"meissner@suse.de","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"exploitabilityScore":1.8,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55999","epss":0.00269,"percentile":0.18941,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55999","cwe":"CWE-122","source":"meissner@suse.de","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-55999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"GHSA-389x-839f-4rhx","dataSource":"https://github.com/advisories/GHSA-389x-839f-4rhx","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-389x-839f-4rhx","https://github.com/netty/netty/commit/d1fbda62d3a47835d3fb35db8bd42ecc205a5386","https://nvd.nist.gov/vuln/detail/CVE-2025-25193","https://security.netapp.com/advisory/ntap-20250221-0006"],"description":"Denial of Service attack on windows app using Netty","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-25193","epss":0.00391,"percentile":0.32515,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-25193","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.118.Final"],"state":"fixed","available":[{"version":"4.1.118.Final","date":"2025-02-20","kind":"first-observed"}]},"advisories":[],"risk":0.20527500000000004},"relatedVulnerabilities":[{"id":"CVE-2025-25193","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-25193","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/commit/d1fbda62d3a47835d3fb35db8bd42ecc205a5386","https://github.com/netty/netty/security/advisories/GHSA-389x-839f-4rhx","https://security.netapp.com/advisory/ntap-20250221-0006/"],"description":"Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-25193","epss":0.00391,"percentile":0.32515,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-25193","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-common","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-389x-839f-4rhx","versionConstraint":"<4.1.118.Final (unknown)"},"fix":{"suggestedVersion":"4.1.118.Final"}}],"artifact":{"id":"25deed0cb1aa906b","name":"netty-common","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-common:netty-common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-common:netty_common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_common:netty-common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_common:netty_common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-common:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_common:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-common@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-common","pomArtifactID":"netty-common","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2025-7709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7709","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.","cvss":[{"source":"cve-coordination@google.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7709","epss":0.00345,"percentile":0.27591,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7709","cwe":"CWE-190","source":"cve-coordination@google.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.20527499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-7709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7709","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g","http://www.openwall.com/lists/oss-security/2025/09/06/2","http://www.openwall.com/lists/oss-security/2025/11/18/10"],"description":"An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.","cvss":[{"source":"cve-coordination@google.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7709","epss":0.00345,"percentile":0.27591,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7709","cwe":"CWE-190","source":"cve-coordination@google.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"GHSA-fghv-69vj-qj49","dataSource":"https://github.com/advisories/GHSA-fghv-69vj-qj49","namespace":"github:language:java","severity":"Low","urls":["https://github.com/netty/netty/security/advisories/GHSA-fghv-69vj-qj49","https://github.com/JLLeitschuh/unCVEed/issues/1","https://github.com/netty/netty/issues/15522","https://github.com/netty/netty/pull/15611","https://github.com/netty/netty/commit/edb55fd8e0a3bcbd85881e423464f585183d1284","https://w4ke.info/2025/06/18/funky-chunks.html","https://github.com/github/advisory-database/pull/6092","https://nvd.nist.gov/vuln/detail/CVE-2025-58056","https://datatracker.ietf.org/doc/html/rfc9112#name-chunked-transfer-coding"],"description":"Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions","cvss":[],"epss":[{"cve":"CVE-2025-58056","epss":0.00677,"percentile":0.50154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-58056","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.125.Final"],"state":"fixed","available":[{"version":"4.1.125.Final","date":"2025-09-06","kind":"first-observed"}]},"advisories":[],"risk":0.20309999999999997},"relatedVulnerabilities":[{"id":"CVE-2025-58056","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58056","namespace":"nvd:cpe","severity":"High","urls":["https://datatracker.ietf.org/doc/html/rfc9112#name-chunked-transfer-coding","https://github.com/JLLeitschuh/unCVEed/issues/1","https://github.com/netty/netty/commit/edb55fd8e0a3bcbd85881e423464f585183d1284","https://github.com/netty/netty/issues/15522","https://github.com/netty/netty/pull/15611","https://github.com/netty/netty/security/advisories/GHSA-fghv-69vj-qj49","https://w4ke.info/2025/06/18/funky-chunks.html"],"description":"Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58056","epss":0.00677,"percentile":0.50154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-58056","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-fghv-69vj-qj49","versionConstraint":"<4.1.125.Final (unknown)"},"fix":{"suggestedVersion":"4.1.125.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2005-2541","dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-2541","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.","cvss":[],"epss":[{"cve":"CVE-2005-2541","epss":0.03992,"percentile":0.89891,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1996},"relatedVulnerabilities":[{"id":"CVE-2005-2541","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","namespace":"nvd:cpe","severity":"High","urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"exploitabilityScore":10,"impactScore":10.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2005-2541","epss":0.03992,"percentile":0.89891,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f8ad3f5238dbcf6a","name":"tar","version":"1.34+dfsg-1.2+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"GHSA-q4f6-jm68-57ww","dataSource":"https://github.com/advisories/GHSA-q4f6-jm68-57ww","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59899","epss":0.00335,"percentile":0.26441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.19932499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-59899","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59899","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59899","epss":0.00335,"percentile":0.26441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-q4f6-jm68-57ww","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-q4f6-jm68-57ww","dataSource":"https://github.com/advisories/GHSA-q4f6-jm68-57ww","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59899","epss":0.00335,"percentile":0.26441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.19932499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-59899","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59899","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59899","epss":0.00335,"percentile":0.26441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-q4f6-jm68-57ww","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2023-6601","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6601","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6601","epss":0.00405,"percentile":0.33982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","source":"patrick@puiterwijk.org","type":"Secondary"},{"cve":"CVE-2023-6601","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.196425},"relatedVulnerabilities":[{"id":"CVE-2023-6601","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"patrick@puiterwijk.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6601","epss":0.00405,"percentile":0.33982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","source":"patrick@puiterwijk.org","type":"Secondary"},{"cve":"CVE-2023-6601","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6601","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2023-6601","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6601","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6601","epss":0.00405,"percentile":0.33982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","source":"patrick@puiterwijk.org","type":"Secondary"},{"cve":"CVE-2023-6601","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.196425},"relatedVulnerabilities":[{"id":"CVE-2023-6601","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"patrick@puiterwijk.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6601","epss":0.00405,"percentile":0.33982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","source":"patrick@puiterwijk.org","type":"Secondary"},{"cve":"CVE-2023-6601","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6601","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2023-6601","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6601","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6601","epss":0.00405,"percentile":0.33982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","source":"patrick@puiterwijk.org","type":"Secondary"},{"cve":"CVE-2023-6601","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.196425},"relatedVulnerabilities":[{"id":"CVE-2023-6601","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"patrick@puiterwijk.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6601","epss":0.00405,"percentile":0.33982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","source":"patrick@puiterwijk.org","type":"Secondary"},{"cve":"CVE-2023-6601","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6601","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-5704","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5704","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5704","epss":0.00372,"percentile":0.30542,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1953},"relatedVulnerabilities":[{"id":"CVE-2026-5704","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5704","epss":0.00372,"percentile":0.30542,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f8ad3f5238dbcf6a","name":"tar","version":"1.34+dfsg-1.2+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-34979","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34979","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34979","epss":0.00379,"percentile":0.31239,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34979","cwe":"CWE-122","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.195185},"relatedVulnerabilities":[{"id":"CVE-2026-34979","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34979","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fh"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34979","epss":0.00379,"percentile":0.31239,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34979","cwe":"CWE-122","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-34979","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2026-75146","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75146","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75146","epss":0.00261,"percentile":0.17888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75146","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19183499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-75146","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75146","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24093","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-in-dash-demuxer-via-dashdec-c"],"description":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75146","epss":0.00261,"percentile":0.17888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75146","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75146","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75146","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75146","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75146","epss":0.00261,"percentile":0.17888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75146","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19183499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-75146","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75146","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24093","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-in-dash-demuxer-via-dashdec-c"],"description":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75146","epss":0.00261,"percentile":0.17888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75146","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75146","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75146","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75146","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75146","epss":0.00261,"percentile":0.17888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75146","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19183499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-75146","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75146","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24093","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-in-dash-demuxer-via-dashdec-c"],"description":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75146","epss":0.00261,"percentile":0.17888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75146","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75146","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-54411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.0032,"percentile":0.248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1904},"relatedVulnerabilities":[{"id":"CVE-2026-54411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.0032,"percentile":0.248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4cab7ef7de016d31","name":"libpam-modules","version":"1.5.2-6+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-modules@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2026-54411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.0032,"percentile":0.248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1904},"relatedVulnerabilities":[{"id":"CVE-2026-54411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.0032,"percentile":0.248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"372dffabd059479c","name":"libpam-modules-bin","version":"1.5.2-6+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-modules-bin@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2026-54411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.0032,"percentile":0.248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1904},"relatedVulnerabilities":[{"id":"CVE-2026-54411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.0032,"percentile":0.248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ca1034d5d24bcf54","name":"libpam-runtime","version":"1.5.2-6+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-runtime@1.5.2-6%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2026-54411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.0032,"percentile":0.248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1904},"relatedVulnerabilities":[{"id":"CVE-2026-54411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.","cvss":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54411","epss":0.0032,"percentile":0.248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"}}],"artifact":{"id":"87d8465053cf56c8","name":"libpam0g","version":"1.5.2-6+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam0g@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"GHSA-hgj6-7826-r7m5","dataSource":"https://github.com/advisories/GHSA-hgj6-7826-r7m5","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://nvd.nist.gov/vuln/detail/CVE-2026-54514"],"description":"jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54514","epss":0.00368,"percentile":0.30042,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-06-24","kind":"first-observed"}]},"advisories":[],"risk":0.18952000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-54514","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54514","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54514","epss":0.00368,"percentile":0.30042,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.1"}},"found":{"vulnerabilityID":"GHSA-hgj6-7826-r7m5","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"a302f39326030e6b","name":"jackson-databind","version":"2.19.1","type":"java-archive","locations":[{"path":"/zap/plugin/database-alpha-0.9.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"e8cb8e76faea3e0791165f5d3614fc45933b2ee0"}]}}},{"vulnerability":{"id":"GHSA-hgj6-7826-r7m5","dataSource":"https://github.com/advisories/GHSA-hgj6-7826-r7m5","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://nvd.nist.gov/vuln/detail/CVE-2026-54514"],"description":"jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54514","epss":0.00368,"percentile":0.30042,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-06-24","kind":"first-observed"}]},"advisories":[],"risk":0.18952000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-54514","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54514","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54514","epss":0.00368,"percentile":0.30042,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.1"}},"found":{"vulnerabilityID":"GHSA-hgj6-7826-r7m5","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"36f0584e521d794e","name":"jackson-databind","version":"2.20.1","type":"java-archive","locations":[{"path":"/zap/plugin/commonlib-release-1.39.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/commonlib-release-1.39.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":["The Apache Software License, Version 2.0"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/commonlib-release-1.39.0.zap:com.fasterxml.jackson.core:jackson-databind","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-75803","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75803","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.  Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.  CWE: CWE-354 (Improper Validation of Integrity Check Value)  Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.  FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75803","epss":0.00207,"percentile":0.10845,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.187335},"relatedVulnerabilities":[{"id":"CVE-2026-75803","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75803","epss":0.00207,"percentile":0.10845,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f55823b1f5c2e201","name":"libssl3","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","upstreams":[{"name":"openssl"}]}},{"vulnerability":{"id":"CVE-2026-75803","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75803","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.  Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.  CWE: CWE-354 (Improper Validation of Integrity Check Value)  Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.  FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75803","epss":0.00207,"percentile":0.10845,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","source":"openssl-security@openssl.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.187335},"relatedVulnerabilities":[{"id":"CVE-2026-75803","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","namespace":"nvd:cpe","severity":"Critical","urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75803","epss":0.00207,"percentile":0.10845,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","source":"openssl-security@openssl.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7345802bd2ec0962","name":"openssl","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"GHSA-84h7-rjj3-6jx4","dataSource":"https://github.com/advisories/GHSA-84h7-rjj3-6jx4","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-84h7-rjj3-6jx4","https://github.com/netty/netty/commit/77e81f1e5944d98b3acf887d3aa443b252752e94","https://nvd.nist.gov/vuln/detail/CVE-2025-67735"],"description":"Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-67735","epss":0.00325,"percentile":0.25358,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-67735","cwe":"CWE-93","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.129.Final"],"state":"fixed","available":[{"version":"4.1.129.Final","date":"2025-12-16","kind":"first-observed"}]},"advisories":[],"risk":0.18687499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-67735","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-67735","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-84h7-rjj3-6jx4"],"description":"Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-67735","epss":0.00325,"percentile":0.25358,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-67735","cwe":"CWE-93","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-84h7-rjj3-6jx4","versionConstraint":"<4.1.129.Final (unknown)"},"fix":{"suggestedVersion":"4.1.129.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2014-8166","dataSource":"https://security-tracker.debian.org/tracker/CVE-2014-8166","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.","cvss":[],"epss":[{"cve":"CVE-2014-8166","epss":0.03703,"percentile":0.89073,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2014-8166","cwe":"CWE-20","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18515},"relatedVulnerabilities":[{"id":"CVE-2014-8166","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-8166","namespace":"nvd:cpe","severity":"High","urls":["http://www.openwall.com/lists/oss-security/2015/03/24/15","http://www.openwall.com/lists/oss-security/2015/03/24/2","http://www.securityfocus.com/bid/73300","https://bugzilla.redhat.com/show_bug.cgi?id=1084577"],"description":"The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2014-8166","epss":0.03703,"percentile":0.89073,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2014-8166","cwe":"CWE-20","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2014-8166","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"GHSA-72hv-8253-57qq","dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18401","epss":0.0031,"percentile":0.23542,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","type":"Secondary"}],"fix":{"versions":["2.21.1"],"state":"fixed","available":[{"version":"2.21.1","date":"2026-02-28","kind":"first-observed"}]},"advisories":[],"risk":0.18444999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-18401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0.","cvss":[{"source":"36c7be3b-2937-45df-85ea-ca7133ea542c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18401","epss":0.0031,"percentile":0.23542,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.19.1"}},"found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.19.0,<2.21.1 (unknown)"},"fix":{"suggestedVersion":"2.21.1"}}],"artifact":{"id":"525302ab25309ad8","name":"jackson-core","version":"2.19.1","type":"java-archive","locations":[{"path":"/zap/plugin/database-alpha-0.9.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-core-2.19.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.19.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.19.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-core-2.19.1.jar","pomArtifactID":"jackson-core","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"6e5a8cb8a6cada322497cefb7726657d98aaee15"}]}}},{"vulnerability":{"id":"GHSA-72hv-8253-57qq","dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18401","epss":0.0031,"percentile":0.23542,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","type":"Secondary"}],"fix":{"versions":["2.21.1"],"state":"fixed","available":[{"version":"2.21.1","date":"2026-02-28","kind":"first-observed"}]},"advisories":[],"risk":0.18444999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-18401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0.","cvss":[{"source":"36c7be3b-2937-45df-85ea-ca7133ea542c","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18401","epss":0.0031,"percentile":0.23542,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.20.1"}},"found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.19.0,<2.21.1 (unknown)"},"fix":{"suggestedVersion":"2.21.1"}}],"artifact":{"id":"aea317631b68845c","name":"jackson-core","version":"2.20.1","type":"java-archive","locations":[{"path":"/zap/plugin/commonlib-release-1.39.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/commonlib-release-1.39.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":["The Apache Software License, Version 2.0"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.20.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.20.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/commonlib-release-1.39.0.zap:com.fasterxml.jackson.core:jackson-core","pomArtifactID":"jackson-core","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-74976","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74976","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74976","epss":0.0032,"percentile":0.24746,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74976","cwe":"CWE-843","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.184},"relatedVulnerabilities":[{"id":"CVE-2026-74976","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74976","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=1952164","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74976","epss":0.0032,"percentile":0.24746,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74976","cwe":"CWE-843","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74976","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-32739","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32739","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32739","epss":0.0032,"percentile":0.24743,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32739","cwe":"CWE-835","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.184},"relatedVulnerabilities":[{"id":"CVE-2026-32739","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32739","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-j9g7-q9hv-gq8c"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32739","epss":0.0032,"percentile":0.24743,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32739","cwe":"CWE-835","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32739","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-61308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61308","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":2.3,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-61308","epss":0.0031,"percentile":0.23568,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-61308","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.18289999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-61308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61308","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":2.3,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-61308","epss":0.0031,"percentile":0.23568,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-61308","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-61308","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"945387ec24991974","name":"openjdk-17-jdk","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jdk/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jdk:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jdk:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jdk@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-61308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61308","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":2.3,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-61308","epss":0.0031,"percentile":0.23568,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-61308","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.18289999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-61308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61308","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":2.3,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-61308","epss":0.0031,"percentile":0.23568,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-61308","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-61308","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"8fadba790d3a033a","name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jdk-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jdk-headless:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jdk-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jdk-headless:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk-headless:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk_headless:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk_headless:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jdk-headless@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-61308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61308","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":2.3,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-61308","epss":0.0031,"percentile":0.23568,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-61308","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.18289999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-61308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61308","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":2.3,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-61308","epss":0.0031,"percentile":0.23568,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-61308","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-61308","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"a3f55d1528694a0b","name":"openjdk-17-jre","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jre/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jre:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jre@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-61308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61308","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":2.3,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-61308","epss":0.0031,"percentile":0.23568,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-61308","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.18289999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-61308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61308","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"exploitabilityScore":2.3,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-61308","epss":0.0031,"percentile":0.23568,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-61308","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-61308","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"a98c024490217f82","name":"openjdk-17-jre-headless","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jre-headless:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre-headless:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre_headless:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre_headless:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jre-headless@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.18203000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.18203000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.18203000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.18203000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.18203000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.18203000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-15367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.18203000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-15367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15367","epss":0.00334,"percentile":0.26405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-74948","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74948","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74948","epss":0.00314,"percentile":0.2402,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74948","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.18055},"relatedVulnerabilities":[{"id":"CVE-2026-74948","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74948","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2060106","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74948","epss":0.00314,"percentile":0.2402,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74948","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74948","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-7017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.00247,"percentile":0.15994,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18031},"relatedVulnerabilities":[{"id":"CVE-2026-7017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.00247,"percentile":0.15994,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-7017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.00247,"percentile":0.15994,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18031},"relatedVulnerabilities":[{"id":"CVE-2026-7017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.00247,"percentile":0.15994,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-7017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.00247,"percentile":0.15994,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18031},"relatedVulnerabilities":[{"id":"CVE-2026-7017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.00247,"percentile":0.15994,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-7017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.00247,"percentile":0.15994,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18031},"relatedVulnerabilities":[{"id":"CVE-2026-7017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7017","epss":0.00247,"percentile":0.15994,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-4873","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.179305},"relatedVulnerabilities":[{"id":"CVE-2026-4873","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-4873","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.179305},"relatedVulnerabilities":[{"id":"CVE-2026-4873","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-4873","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.179305},"relatedVulnerabilities":[{"id":"CVE-2026-4873","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4873","epss":0.00329,"percentile":0.25726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-4873","cwe":"CWE-319","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-27447","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27447","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":2.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27447","epss":0.00317,"percentile":0.24385,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27447","cwe":"CWE-863","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.179105},"relatedVulnerabilities":[{"id":"CVE-2026-27447","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27447","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/OpenPrinting/cups/commit/88516bf6d9e34cef7a64a704b856b837f70cd220","https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":2.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":4.8,"exploitabilityScore":0.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27447","epss":0.00317,"percentile":0.24385,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27447","cwe":"CWE-863","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27447","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2026-16118","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16118","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16118","epss":0.00245,"percentile":0.15743,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16118","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17884999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-16118","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16118","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:64799","https://access.redhat.com/errata/RHSA-2026:64800","https://access.redhat.com/security/cve/CVE-2026-16118","https://bugzilla.redhat.com/show_bug.cgi?id=2501732","https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41"],"description":"A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16118","epss":0.00245,"percentile":0.15743,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16118","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16118","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-16118","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16118","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16118","epss":0.00245,"percentile":0.15743,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16118","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17884999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-16118","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16118","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:64799","https://access.redhat.com/errata/RHSA-2026:64800","https://access.redhat.com/security/cve/CVE-2026-16118","https://bugzilla.redhat.com/show_bug.cgi?id=2501732","https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41"],"description":"A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16118","epss":0.00245,"percentile":0.15743,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16118","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16118","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-32814","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32814","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitialized heap memory information leak. The canvas is allocated via create_clone_image_at_new_size() → plane.alloc() → new (std::nothrow) uint8_t[allocation_size] which does not zero the memory; only the alpha plane is explicitly initialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever was previously at that heap address. The failed tile's region of the canvas is never written. It retains uninitialized heap data that is delivered to the caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane = 12,288+ bytes total). Any application using libheif to decode grid-based HEIF/AVIF files with default settings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of heap memory to appear as pixel values in the decoded image, and the calling application receives heif_error_Ok, so it has no indication the output contains heap garbage. In server-side image processing, an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social media) can leak cross-user data such as auth tokens, database results, and other users' image data. This issue has been fixed in version 1.22.0.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32814","epss":0.00311,"percentile":0.23705,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32814","cwe":"CWE-200","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32814","cwe":"CWE-908","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17882499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-32814","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32814","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-4m8r-34pg-rvwc"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitialized heap memory information leak. The canvas is allocated via create_clone_image_at_new_size() → plane.alloc() → new (std::nothrow) uint8_t[allocation_size] which does not zero the memory; only the alpha plane is explicitly initialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever was previously at that heap address. The failed tile's region of the canvas is never written. It retains uninitialized heap data that is delivered to the caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane = 12,288+ bytes total). Any application using libheif to decode grid-based HEIF/AVIF files with default settings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of heap memory to appear as pixel values in the decoded image, and the calling application receives heif_error_Ok, so it has no indication the output contains heap garbage. In server-side image processing, an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social media) can leak cross-user data such as auth tokens, database results, and other users' image data. This issue has been fixed in version 1.22.0.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32814","epss":0.00311,"percentile":0.23705,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32814","cwe":"CWE-200","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32814","cwe":"CWE-908","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32814","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2018-15919","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15919","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'","cvss":[],"epss":[{"cve":"CVE-2018-15919","epss":0.03557,"percentile":0.8862,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15919","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-15919","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17784999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-15919","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15919","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/oss-sec/2018/q3/180","http://www.securityfocus.com/bid/105163","https://security.netapp.com/advisory/ntap-20181221-0001/"],"description":"Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-15919","epss":0.03557,"percentile":0.8862,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15919","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-15919","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-15919","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54515","epss":0.00345,"percentile":0.27654,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["2.21.5"],"state":"fixed","available":[{"version":"2.21.5","date":"2026-06-24","kind":"first-observed"}]},"advisories":[],"risk":0.177675},"relatedVulnerabilities":[{"id":"CVE-2026-54515","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54515","epss":0.00345,"percentile":0.27654,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.1"}},"found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.19.0,<2.21.5 (unknown)"},"fix":{"suggestedVersion":"2.21.5"}}],"artifact":{"id":"a302f39326030e6b","name":"jackson-databind","version":"2.19.1","type":"java-archive","locations":[{"path":"/zap/plugin/database-alpha-0.9.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"e8cb8e76faea3e0791165f5d3614fc45933b2ee0"}]}}},{"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54515","epss":0.00345,"percentile":0.27654,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["2.21.5"],"state":"fixed","available":[{"version":"2.21.5","date":"2026-06-24","kind":"first-observed"}]},"advisories":[],"risk":0.177675},"relatedVulnerabilities":[{"id":"CVE-2026-54515","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54515","epss":0.00345,"percentile":0.27654,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.1"}},"found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.19.0,<2.21.5 (unknown)"},"fix":{"suggestedVersion":"2.21.5"}}],"artifact":{"id":"36f0584e521d794e","name":"jackson-databind","version":"2.20.1","type":"java-archive","locations":[{"path":"/zap/plugin/commonlib-release-1.39.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/commonlib-release-1.39.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":["The Apache Software License, Version 2.0"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/commonlib-release-1.39.0.zap:com.fasterxml.jackson.core:jackson-databind","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-3pjw-73gf-8qr5","dataSource":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://nvd.nist.gov/vuln/detail/CVE-2026-59888","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"description":"jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59888","epss":0.00309,"percentile":0.23498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-07-22","kind":"first-observed"}]},"advisories":[],"risk":0.17767499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-59888","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59888","epss":0.00309,"percentile":0.23498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.1"}},"found":{"vulnerabilityID":"GHSA-3pjw-73gf-8qr5","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"a302f39326030e6b","name":"jackson-databind","version":"2.19.1","type":"java-archive","locations":[{"path":"/zap/plugin/database-alpha-0.9.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-databind-2.19.1.jar","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"e8cb8e76faea3e0791165f5d3614fc45933b2ee0"}]}}},{"vulnerability":{"id":"GHSA-3pjw-73gf-8qr5","dataSource":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://nvd.nist.gov/vuln/detail/CVE-2026-59888","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"description":"jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59888","epss":0.00309,"percentile":0.23498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-07-22","kind":"first-observed"}]},"advisories":[],"risk":0.17767499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-59888","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"],"description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59888","epss":0.00309,"percentile":0.23498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.1"}},"found":{"vulnerabilityID":"GHSA-3pjw-73gf-8qr5","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"36f0584e521d794e","name":"jackson-databind","version":"2.20.1","type":"java-archive","locations":[{"path":"/zap/plugin/commonlib-release-1.39.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/commonlib-release-1.39.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":["The Apache Software License, Version 2.0"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/commonlib-release-1.39.0.zap:com.fasterxml.jackson.core:jackson-databind","pomArtifactID":"jackson-databind","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-5435","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17538},"relatedVulnerabilities":[{"id":"CVE-2026-5435","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","namespace":"nvd:cpe","severity":"High","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5435","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17538},"relatedVulnerabilities":[{"id":"CVE-2026-5435","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","namespace":"nvd:cpe","severity":"High","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5435","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17538},"relatedVulnerabilities":[{"id":"CVE-2026-5435","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","namespace":"nvd:cpe","severity":"High","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5435","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17538},"relatedVulnerabilities":[{"id":"CVE-2026-5435","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","namespace":"nvd:cpe","severity":"High","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-5435","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.17538},"relatedVulnerabilities":[{"id":"CVE-2026-5435","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","namespace":"nvd:cpe","severity":"High","urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5435","epss":0.00237,"percentile":0.14682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-32738","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32738","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an empty chunk and resulting in a denial of service. When any sample is accessed, the library reads from index 0 of an empty std::vector, causing a guaranteed SEGV (null-page read). The file parses successfully without producing an error; the crash occurs on the first frame access. This issue has been fixed in version 1.22.0.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32738","epss":0.00301,"percentile":0.22608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32738","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32738","cwe":"CWE-476","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17307499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-32738","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32738","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/security/advisories/GHSA-7f2h-cmpf-v9ww"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an empty chunk and resulting in a denial of service. When any sample is accessed, the library reads from index 0 of an empty std::vector, causing a guaranteed SEGV (null-page read). The file parses successfully without producing an error; the crash occurs on the first frame access. This issue has been fixed in version 1.22.0.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32738","epss":0.00301,"percentile":0.22608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32738","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-32738","cwe":"CWE-476","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32738","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-56000","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56000","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56000","epss":0.00222,"percentile":0.12703,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56000","cwe":"CWE-416","source":"meissner@suse.de","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16983000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-56000","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56000","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/xorg/xserver/-/commit/2779affbdb4354e894f490e56f962527d6125043","https://www.openwall.com/lists/oss-security/2026/07/08/2"],"description":"Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"meissner@suse.de","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56000","epss":0.00222,"percentile":0.12703,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56000","cwe":"CWE-416","source":"meissner@suse.de","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56000","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-56000","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56000","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56000","epss":0.00222,"percentile":0.12703,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56000","cwe":"CWE-416","source":"meissner@suse.de","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16983000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-56000","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56000","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/xorg/xserver/-/commit/2779affbdb4354e894f490e56f962527d6125043","https://www.openwall.com/lists/oss-security/2026/07/08/2"],"description":"Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"meissner@suse.de","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56000","epss":0.00222,"percentile":0.12703,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56000","cwe":"CWE-416","source":"meissner@suse.de","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56000","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-13858","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13858","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium)","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13858","epss":0.00293,"percentile":0.21727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13858","cwe":"CWE-125","source":"chrome-cve-admin@google.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16847499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-13858","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13858","namespace":"nvd:cpe","severity":"Medium","urls":["https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/507090179"],"description":"Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium)","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13858","epss":0.00293,"percentile":0.21727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13858","cwe":"CWE-125","source":"chrome-cve-admin@google.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13858","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-13858","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13858","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium)","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13858","epss":0.00293,"percentile":0.21727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13858","cwe":"CWE-125","source":"chrome-cve-admin@google.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16847499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-13858","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13858","namespace":"nvd:cpe","severity":"Medium","urls":["https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/507090179"],"description":"Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium)","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13858","epss":0.00293,"percentile":0.21727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13858","cwe":"CWE-125","source":"chrome-cve-admin@google.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13858","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-13858","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13858","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium)","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13858","epss":0.00293,"percentile":0.21727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13858","cwe":"CWE-125","source":"chrome-cve-admin@google.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16847499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-13858","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13858","namespace":"nvd:cpe","severity":"Medium","urls":["https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html","https://issues.chromium.org/issues/507090179"],"description":"Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium)","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13858","epss":0.00293,"percentile":0.21727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13858","cwe":"CWE-125","source":"chrome-cve-admin@google.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13858","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-8643","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8643","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8643","epss":0.0032,"percentile":0.24729,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-8643","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.168},"relatedVulnerabilities":[{"id":"CVE-2026-8643","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8643","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pypa/pip/pull/14000","https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/","http://www.openwall.com/lists/oss-security/2026/06/01/5","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:34456","https://access.redhat.com/errata/RHSA-2026:34739","https://access.redhat.com/errata/RHSA-2026:34740","https://access.redhat.com/errata/RHSA-2026:34741","https://access.redhat.com/errata/RHSA-2026:34748","https://access.redhat.com/errata/RHSA-2026:34749","https://access.redhat.com/errata/RHSA-2026:34750","https://access.redhat.com/errata/RHSA-2026:34752","https://access.redhat.com/errata/RHSA-2026:34756","https://access.redhat.com/errata/RHSA-2026:34758","https://access.redhat.com/errata/RHSA-2026:34760","https://access.redhat.com/errata/RHSA-2026:34765","https://access.redhat.com/errata/RHSA-2026:34772","https://access.redhat.com/errata/RHSA-2026:34773","https://access.redhat.com/errata/RHSA-2026:34774","https://access.redhat.com/errata/RHSA-2026:34775","https://access.redhat.com/errata/RHSA-2026:34776","https://access.redhat.com/errata/RHSA-2026:34777","https://access.redhat.com/errata/RHSA-2026:34778","https://access.redhat.com/errata/RHSA-2026:34780","https://access.redhat.com/errata/RHSA-2026:34891","https://access.redhat.com/errata/RHSA-2026:36193","https://access.redhat.com/errata/RHSA-2026:36315","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37283","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42144","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:50479","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:56347","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/security/cve/CVE-2026-8643","https://bugzilla.redhat.com/show_bug.cgi?id=2460927","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"],"description":"pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-8643","epss":0.0032,"percentile":0.24729,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-8643","cwe":"CWE-22","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python-pip","version":"23.0.1+dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-8643","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5929913cf46d2db3","name":"python3-pip","version":"23.0.1+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3-pip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.list"},{"path":"/var/lib/dpkg/info/python3-pip.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.postinst"},{"path":"/var/lib/dpkg/info/python3-pip.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"cpes":["cpe:2.3:a:python3-pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-pip@23.0.1%2Bdfsg-1?arch=all&distro=debian-12.15&upstream=python-pip","upstreams":[{"name":"python-pip"}]}},{"vulnerability":{"id":"CVE-2026-13346","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13346","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.     This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13346","epss":0.00292,"percentile":0.2161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.16789999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-13346","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13346","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pypa/pip/pull/14110","https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/","http://www.openwall.com/lists/oss-security/2026/07/29/7"],"description":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13346","epss":0.00292,"percentile":0.2161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python-pip","version":"23.0.1+dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13346","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5929913cf46d2db3","name":"python3-pip","version":"23.0.1+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3-pip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.list"},{"path":"/var/lib/dpkg/info/python3-pip.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.postinst"},{"path":"/var/lib/dpkg/info/python3-pip.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"cpes":["cpe:2.3:a:python3-pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-pip@23.0.1%2Bdfsg-1?arch=all&distro=debian-12.15&upstream=python-pip","upstreams":[{"name":"python-pip"}]}},{"vulnerability":{"id":"CVE-2026-57432","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00211,"percentile":0.11319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.167745},"relatedVulnerabilities":[{"id":"CVE-2026-57432","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00211,"percentile":0.11319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-57432","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00211,"percentile":0.11319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.167745},"relatedVulnerabilities":[{"id":"CVE-2026-57432","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00211,"percentile":0.11319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-57432","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00211,"percentile":0.11319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.167745},"relatedVulnerabilities":[{"id":"CVE-2026-57432","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00211,"percentile":0.11319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-57432","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00211,"percentile":0.11319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.167745},"relatedVulnerabilities":[{"id":"CVE-2026-57432","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57432","epss":0.00211,"percentile":0.11319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-57432","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"GHSA-563q-j3cm-6jxm","dataSource":"https://github.com/advisories/GHSA-563q-j3cm-6jxm","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm","https://nvd.nist.gov/vuln/detail/CVE-2026-50560","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings"],"description":"Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50560","epss":0.00302,"percentile":0.22618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50560","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-16","kind":"first-observed"}]},"advisories":[],"risk":0.16760999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-50560","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50560","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm","https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50560","epss":0.00302,"percentile":0.22618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50560","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-563q-j3cm-6jxm","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"5895f3b705a95bee","name":"netty-codec-http2","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-563q-j3cm-6jxm","dataSource":"https://github.com/advisories/GHSA-563q-j3cm-6jxm","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm","https://nvd.nist.gov/vuln/detail/CVE-2026-50560","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings"],"description":"Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50560","epss":0.00302,"percentile":0.22618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50560","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-16","kind":"first-observed"}]},"advisories":[],"risk":0.16760999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-50560","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50560","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm","https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50560","epss":0.00302,"percentile":0.22618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50560","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-563q-j3cm-6jxm","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"c9e87a7d2efc8ca7","name":"netty-codec-http2","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-60001","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60001","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60001","epss":0.00291,"percentile":0.21438,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.16732499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-60001","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","namespace":"nvd:cpe","severity":"Medium","urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60001","epss":0.00291,"percentile":0.21438,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2018-15863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15863","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with a no-op modmask expression.","cvss":[],"epss":[{"cve":"CVE-2018-15863","epss":0.00539,"percentile":0.43641,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15863","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16169999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-15863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15863","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2019:2079","https://github.com/xkbcommon/libxkbcommon/commit/96df3106d49438e442510c59acad306e94f3db4d","https://lists.freedesktop.org/archives/wayland-devel/2018-August/039243.html","https://security.gentoo.org/glsa/201810-05","https://usn.ubuntu.com/3786-1/","https://usn.ubuntu.com/3786-2/"],"description":"Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with a no-op modmask expression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-15863","epss":0.00539,"percentile":0.43641,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15863","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"x11-xkb-utils","version":"7.7+7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-15863","versionConstraint":"none (unknown)"}}],"artifact":{"id":"649f1ef760dcdc10","name":"x11-xkb-utils","version":"7.7+7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/x11-xkb-utils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/x11-xkb-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/x11-xkb-utils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/x11-xkb-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/x11-xkb-utils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/x11-xkb-utils.list"}],"language":"","licenses":["sha256:bf23f1dfd52e0f7526b83496effacba1e3f29a38adaf119091efad060f8836b1"],"cpes":["cpe:2.3:a:x11-xkb-utils:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb-utils:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb_utils:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb_utils:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/x11-xkb-utils@7.7%2B7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-15853","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15853","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.","cvss":[],"epss":[{"cve":"CVE-2018-15853","epss":0.00539,"percentile":0.4364,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15853","cwe":"CWE-400","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16169999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-15853","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15853","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2019:2079","https://github.com/xkbcommon/libxkbcommon/commit/1f9d1248c07cda8aaff762429c0dce146de8632a","https://lists.freedesktop.org/archives/wayland-devel/2018-August/039232.html","https://security.gentoo.org/glsa/201810-05","https://usn.ubuntu.com/3786-1/","https://usn.ubuntu.com/3786-2/"],"description":"Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-15853","epss":0.00539,"percentile":0.4364,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15853","cwe":"CWE-400","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"x11-xkb-utils","version":"7.7+7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-15853","versionConstraint":"none (unknown)"}}],"artifact":{"id":"649f1ef760dcdc10","name":"x11-xkb-utils","version":"7.7+7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/x11-xkb-utils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/x11-xkb-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/x11-xkb-utils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/x11-xkb-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/x11-xkb-utils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/x11-xkb-utils.list"}],"language":"","licenses":["sha256:bf23f1dfd52e0f7526b83496effacba1e3f29a38adaf119091efad060f8836b1"],"cpes":["cpe:2.3:a:x11-xkb-utils:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb-utils:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb_utils:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb_utils:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/x11-xkb-utils@7.7%2B7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-15859","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15859","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because lookup failures are mishandled.","cvss":[],"epss":[{"cve":"CVE-2018-15859","epss":0.00539,"percentile":0.4364,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15859","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16169999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-15859","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15859","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2019:2079","https://github.com/xkbcommon/libxkbcommon/commit/bb4909d2d8fa6b08155e449986a478101e2b2634","https://lists.freedesktop.org/archives/wayland-devel/2018-August/039243.html","https://security.gentoo.org/glsa/201810-05","https://usn.ubuntu.com/3786-1/","https://usn.ubuntu.com/3786-2/"],"description":"Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because lookup failures are mishandled.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-15859","epss":0.00539,"percentile":0.4364,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15859","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"x11-xkb-utils","version":"7.7+7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-15859","versionConstraint":"none (unknown)"}}],"artifact":{"id":"649f1ef760dcdc10","name":"x11-xkb-utils","version":"7.7+7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/x11-xkb-utils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/x11-xkb-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/x11-xkb-utils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/x11-xkb-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/x11-xkb-utils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/x11-xkb-utils.list"}],"language":"","licenses":["sha256:bf23f1dfd52e0f7526b83496effacba1e3f29a38adaf119091efad060f8836b1"],"cpes":["cpe:2.3:a:x11-xkb-utils:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb-utils:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb_utils:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb_utils:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/x11-xkb-utils@7.7%2B7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-15861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15861","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file that triggers an xkb_intern_atom failure.","cvss":[],"epss":[{"cve":"CVE-2018-15861","epss":0.00539,"percentile":0.4364,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15861","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16169999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-15861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15861","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2019:2079","https://github.com/xkbcommon/libxkbcommon/commit/38e1766bc6e20108948aec8a0b222a4bad0254e9","https://lists.freedesktop.org/archives/wayland-devel/2018-August/039243.html","https://security.gentoo.org/glsa/201810-05","https://usn.ubuntu.com/3786-1/","https://usn.ubuntu.com/3786-2/"],"description":"Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file that triggers an xkb_intern_atom failure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-15861","epss":0.00539,"percentile":0.4364,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-15861","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"x11-xkb-utils","version":"7.7+7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-15861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"649f1ef760dcdc10","name":"x11-xkb-utils","version":"7.7+7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/x11-xkb-utils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/x11-xkb-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/x11-xkb-utils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/x11-xkb-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/x11-xkb-utils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/x11-xkb-utils.list"}],"language":"","licenses":["sha256:bf23f1dfd52e0f7526b83496effacba1e3f29a38adaf119091efad060f8836b1"],"cpes":["cpe:2.3:a:x11-xkb-utils:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb-utils:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb_utils:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb_utils:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11-xkb:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11_xkb:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11:x11-xkb-utils:7.7\\+7:*:*:*:*:*:*:*","cpe:2.3:a:x11:x11_xkb_utils:7.7\\+7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/x11-xkb-utils@7.7%2B7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-70632","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70632","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70632","epss":0.00202,"percentile":0.10194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16160000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-70632","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70632","epss":0.00202,"percentile":0.10194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70632","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70632","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70632","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70632","epss":0.00202,"percentile":0.10194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16160000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-70632","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70632","epss":0.00202,"percentile":0.10194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70632","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70632","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70632","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70632","epss":0.00202,"percentile":0.10194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16160000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-70632","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70632","epss":0.00202,"percentile":0.10194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70632","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-58471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58471","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58471","epss":0.00221,"percentile":0.12608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58471","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.16133},"relatedVulnerabilities":[{"id":"CVE-2026-58471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58471","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"],"description":"GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":1.7,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58471","epss":0.00221,"percentile":0.12608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58471","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58471","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ef5a5a7d880f3e73","name":"wget","version":"1.21.3-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.list"}],"language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-58472","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58472","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58472","epss":0.00221,"percentile":0.12608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58472","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.16133},"relatedVulnerabilities":[{"id":"CVE-2026-58472","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58472","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"],"description":"GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":1.7,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58472","epss":0.00221,"percentile":0.12608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58472","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58472","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ef5a5a7d880f3e73","name":"wget","version":"1.21.3-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.list"}],"language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2019-1010022","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16115000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","namespace":"nvd:cpe","severity":"Critical","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010022","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16115000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","namespace":"nvd:cpe","severity":"Critical","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010022","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16115000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","namespace":"nvd:cpe","severity":"Critical","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010022","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16115000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","namespace":"nvd:cpe","severity":"Critical","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010022","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16115000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","namespace":"nvd:cpe","severity":"Critical","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010022","epss":0.03223,"percentile":0.8748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"GHSA-7p3p-8qv8-m2vh","dataSource":"https://github.com/advisories/GHSA-7p3p-8qv8-m2vh","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-7p3p-8qv8-m2vh","https://nvd.nist.gov/vuln/detail/CVE-2026-6790","https://github.com/jetty/jetty.project/issues/14870","https://github.com/jetty/jetty.project/pull/14871","https://github.com/jetty/jetty.project/pull/14897","https://github.com/jetty/jetty.project/pull/14970","https://github.com/jetty/jetty.project/commit/3e5a4daec196859b8886b6f67b1157dab47cdb6f","https://github.com/jetty/jetty.project/commit/67ba9e6b39661810123680d9c894e99a7940c73d","https://github.com/jetty/jetty.project/commit/cbca3076f7c914a232e7a8b22fa95fbf7e67a6cc","https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35","https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"],"description":"Eclipse Jetty: HTTP Authority/Host mismatch","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6790","epss":0.0031,"percentile":0.23617,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6790","cwe":"CWE-20","source":"emo@eclipse.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15965000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-6790","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6790","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"],"description":"In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present).\n\n\n\n\nThis was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112).\n\n\n\n\nThis mismatch can cause a number of problems that may be classified as vulnerabilities such as:\n\n\n\n  *  \n        \n      URI constructions (for example, for redirects -- this is typical for login pages)\n\n  *  \n        \n      Virtual host selection\n\n  *  \n        \n      Reverse proxying\n\n  *  \n        \n      Misleading logs\n\n  *  \n        \n      Etc.\n\n\n\n\n\n\nGiven that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant.","cvss":[{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6790","epss":0.0031,"percentile":0.23617,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6790","cwe":"CWE-20","source":"emo@eclipse.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-server","version":"9.4.56.v20240826"}},"found":{"vulnerabilityID":"GHSA-7p3p-8qv8-m2vh","versionConstraint":">=9.4.0.v20161208,<=9.4.58.v20250814 (unknown)"}}],"artifact":{"id":"2e8147393dc910c0","name":"jetty-server","version":"9.4.56.v20240826","type":"java-archive","locations":[{"path":"/zap/webswing/server/webswing-jetty-launcher.jar","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/server/webswing-jetty-launcher.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty-server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty_server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty-server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty_server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_server:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-server@9.4.56.v20240826","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/server/webswing-jetty-launcher.jar:org.eclipse.jetty:jetty-server","pomArtifactID":"jetty-server","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2019-1010024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15965000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15965000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15965000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15965000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15965000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010024","epss":0.03193,"percentile":0.87344,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"GHSA-v8h7-rr48-vmmv","dataSource":"https://github.com/advisories/GHSA-v8h7-rr48-vmmv","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-v8h7-rr48-vmmv","https://nvd.nist.gov/vuln/detail/CVE-2026-41417"],"description":"Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41417","epss":0.00307,"percentile":0.23177,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41417","cwe":"CWE-93","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-41417","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.133.Final"],"state":"fixed","available":[{"version":"4.1.133.Final","date":"2026-05-06","kind":"first-observed"}]},"advisories":[],"risk":0.158105},"relatedVulnerabilities":[{"id":"CVE-2026-41417","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41417","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-v8h7-rr48-vmmv"],"description":"Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41417","epss":0.00307,"percentile":0.23177,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41417","cwe":"CWE-93","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-41417","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-v8h7-rr48-vmmv","versionConstraint":"<=4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.133.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2024-7883","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-7883","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When using Arm Cortex-M Security Extensions (CMSE), Secure stack  contents can be leaked to Non-secure state via floating-point registers  when a Secure to Non-secure function call is made that returns a  floating-point value and when this is the first use of floating-point  since entering Secure state. This allows an attacker to read a limited  quantity of Secure stack contents with an impact on confidentiality.  This issue is specific to code generated using LLVM-based compilers.","cvss":[{"source":"arm-security@arm.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-7883","epss":0.00468,"percentile":0.39068,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-7883","cwe":"CWE-226","source":"arm-security@arm.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.15677999999999997},"relatedVulnerabilities":[{"id":"CVE-2024-7883","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7883","namespace":"nvd:cpe","severity":"Low","urls":["https://developer.arm.com/Arm%20Security%20Center/Cortex-M%20Security%20Extensions%20Vulnerability"],"description":"When using Arm Cortex-M Security Extensions (CMSE), Secure stack \ncontents can be leaked to Non-secure state via floating-point registers \nwhen a Secure to Non-secure function call is made that returns a \nfloating-point value and when this is the first use of floating-point \nsince entering Secure state. This allows an attacker to read a limited \nquantity of Secure stack contents with an impact on confidentiality. \nThis issue is specific to code generated using LLVM-based compilers.","cvss":[{"source":"arm-security@arm.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-7883","epss":0.00468,"percentile":0.39068,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-7883","cwe":"CWE-226","source":"arm-security@arm.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-7883","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2025-10256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10256","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10256","epss":0.00298,"percentile":0.22285,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","source":"patrick@puiterwijk.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.15645},"relatedVulnerabilities":[{"id":"CVE-2025-10256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"patrick@puiterwijk.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10256","epss":0.00298,"percentile":0.22285,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","source":"patrick@puiterwijk.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-10256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2025-10256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10256","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10256","epss":0.00298,"percentile":0.22285,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","source":"patrick@puiterwijk.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.15645},"relatedVulnerabilities":[{"id":"CVE-2025-10256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"patrick@puiterwijk.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10256","epss":0.00298,"percentile":0.22285,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","source":"patrick@puiterwijk.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-10256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2025-10256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10256","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10256","epss":0.00298,"percentile":0.22285,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","source":"patrick@puiterwijk.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.15645},"relatedVulnerabilities":[{"id":"CVE-2025-10256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"patrick@puiterwijk.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10256","epss":0.00298,"percentile":0.22285,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","source":"patrick@puiterwijk.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-10256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2016-9114","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9114","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.","cvss":[],"epss":[{"cve":"CVE-2016-9114","epss":0.03077,"percentile":0.86871,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9114","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15385},"relatedVulnerabilities":[{"id":"CVE-2016-9114","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9114","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/93979","https://github.com/uclouvain/openjpeg/issues/857","https://security.gentoo.org/glsa/201710-26"],"description":"There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9114","epss":0.03077,"percentile":0.86871,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9114","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-9114","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2016-9113","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9113","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.","cvss":[],"epss":[{"cve":"CVE-2016-9113","epss":0.0305,"percentile":0.86769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9113","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1525},"relatedVulnerabilities":[{"id":"CVE-2016-9113","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9113","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/93980","https://github.com/uclouvain/openjpeg/issues/856","https://security.gentoo.org/glsa/201710-26"],"description":"There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9113","epss":0.0305,"percentile":0.86769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9113","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-9113","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-47178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47178","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47178","epss":0.00199,"percentile":0.09778,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47178","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.152235},"relatedVulnerabilities":[{"id":"CVE-2026-47178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47178","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/security/advisories/GHSA-5x55-x5pf-9c6g"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47178","epss":0.00199,"percentile":0.09778,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47178","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-47178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2019-1010023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1522},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1522},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1522},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1522},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1522},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","epss":0.03044,"percentile":0.86734,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-49337","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-49337","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49337","epss":0.00327,"percentile":0.25591,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49337","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.152055},"relatedVulnerabilities":[{"id":"CVE-2026-49337","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49337","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9","https://github.com/strukturag/libde265/security/advisories/GHSA-g5hj-rf9f-7vxm"],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object\nthat has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49337","epss":0.00327,"percentile":0.25591,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49337","cwe":"CWE-770","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-49337","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"GHSA-5x3r-wrvg-rp6q","dataSource":"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-47244"],"description":"Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47244","epss":0.00292,"percentile":0.21547,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47244","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-09","kind":"first-observed"}]},"advisories":[],"risk":0.15038},"relatedVulnerabilities":[{"id":"CVE-2026-47244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47244","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47244","epss":0.00292,"percentile":0.21547,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47244","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-5x3r-wrvg-rp6q","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"5895f3b705a95bee","name":"netty-codec-http2","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-5x3r-wrvg-rp6q","dataSource":"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-47244"],"description":"Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47244","epss":0.00292,"percentile":0.21547,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47244","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-09","kind":"first-observed"}]},"advisories":[],"risk":0.15038},"relatedVulnerabilities":[{"id":"CVE-2026-47244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47244","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47244","epss":0.00292,"percentile":0.21547,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47244","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-5x3r-wrvg-rp6q","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"c9e87a7d2efc8ca7","name":"netty-codec-http2","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-25210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-25210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25210","epss":0.00196,"percentile":0.09446,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-25210","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14994},"relatedVulnerabilities":[{"id":"CVE-2026-25210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1075","https://github.com/libexpat/libexpat/pull/1075/commits/9c2d990389e6abe2e44527eeaa8b39f16fe859c7","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25210","epss":0.00196,"percentile":0.09446,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-25210","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-25210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-25210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-25210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25210","epss":0.00196,"percentile":0.09446,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-25210","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14994},"relatedVulnerabilities":[{"id":"CVE-2026-25210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25210","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1075","https://github.com/libexpat/libexpat/pull/1075/commits/9c2d990389e6abe2e44527eeaa8b39f16fe859c7","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25210","epss":0.00196,"percentile":0.09446,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-25210","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-25210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2023-5752","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-5752","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When installing a package from a Mercurial VCS URL  (ie \"pip install  hg+...\") with pip prior to v23.3, the specified Mercurial revision could  be used to inject arbitrary configuration options to the \"hg clone\"  call (ie \"--config\"). Controlling the Mercurial configuration can modify  how and which repository is installed. This vulnerability does not  affect users who aren't installing from Mercurial.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-5752","epss":0.00476,"percentile":0.39641,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5752","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2023-5752","cwe":"CWE-77","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14994},"relatedVulnerabilities":[{"id":"CVE-2023-5752","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5752","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/pypa/pip/pull/12306","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/622OZXWG72ISQPLM5Y57YCVIMWHD4C3U/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/65UKKF5LBHEFDCUSPBHUN4IHYX7SRMHH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FXUVMJM25PUAZRQZBF54OFVKTY3MINPW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KFC2SPFG5FLCZBYY2K3T5MFW2D22NG6E/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YBSB3SUPQ3VIFYUMHPO3MEQI4BJAXKCZ/","https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL/","https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html"],"description":"When installing a package from a Mercurial VCS URL  (ie \"pip install \nhg+...\") with pip prior to v23.3, the specified Mercurial revision could\n be used to inject arbitrary configuration options to the \"hg clone\" \ncall (ie \"--config\"). Controlling the Mercurial configuration can modify\n how and which repository is installed. This vulnerability does not \naffect users who aren't installing from Mercurial.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-5752","epss":0.00476,"percentile":0.39641,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-5752","cwe":"CWE-77","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2023-5752","cwe":"CWE-77","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python-pip","version":"23.0.1+dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-5752","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5929913cf46d2db3","name":"python3-pip","version":"23.0.1+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3-pip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.list"},{"path":"/var/lib/dpkg/info/python3-pip.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.postinst"},{"path":"/var/lib/dpkg/info/python3-pip.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"cpes":["cpe:2.3:a:python3-pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-pip@23.0.1%2Bdfsg-1?arch=all&distro=debian-12.15&upstream=python-pip","upstreams":[{"name":"python-pip"}]}},{"vulnerability":{"id":"CVE-2026-65706","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65706","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65706","epss":0.00187,"percentile":0.0844,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65706","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.14959999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-65706","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65706","epss":0.00187,"percentile":0.0844,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65706","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65706","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65706","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65706","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65706","epss":0.00187,"percentile":0.0844,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65706","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.14959999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-65706","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65706","epss":0.00187,"percentile":0.0844,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65706","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65706","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65706","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65706","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65706","epss":0.00187,"percentile":0.0844,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65706","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.14959999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-65706","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65706","epss":0.00187,"percentile":0.0844,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65706","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65706","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-1965","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.148925},"relatedVulnerabilities":[{"id":"CVE-2026-1965","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-1965","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.148925},"relatedVulnerabilities":[{"id":"CVE-2026-1965","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-1965","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it just sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.148925},"relatedVulnerabilities":[{"id":"CVE-2026-1965","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it just sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with  `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1965","epss":0.00259,"percentile":0.17581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2017-9937","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-9937","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.","cvss":[],"epss":[{"cve":"CVE-2017-9937","epss":0.02962,"percentile":0.86396,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-9937","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1481},"relatedVulnerabilities":[{"id":"CVE-2017-9937","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9937","namespace":"nvd:cpe","severity":"Medium","urls":["http://bugzilla.maptools.org/show_bug.cgi?id=2707","http://www.securityfocus.com/bid/99304","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-9937","epss":0.02962,"percentile":0.86396,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-9937","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jbigkit","version":"2.1-6.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-9937","versionConstraint":"none (unknown)"}}],"artifact":{"id":"63933a9eb4c88edb","name":"libjbig0","version":"2.1-6.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjbig0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjbig0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjbig0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjbig0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+"],"cpes":["cpe:2.3:a:libjbig0:libjbig0:2.1-6.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjbig0@2.1-6.1?arch=amd64&distro=debian-12.15&upstream=jbigkit","upstreams":[{"name":"jbigkit"}]}},{"vulnerability":{"id":"CVE-2008-1688","dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-1688","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option.  NOTE: it is not clear when this issue crosses privilege boundaries.","cvss":[],"epss":[{"cve":"CVE-2008-1688","epss":0.02957,"percentile":0.86367,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.14785},"relatedVulnerabilities":[{"id":"CVE-2008-1688","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-1688","namespace":"nvd:cpe","severity":"High","urls":["http://osvdb.org/44272","http://secunia.com/advisories/29671","http://secunia.com/advisories/29729","http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.510612","http://www.openwall.com/lists/oss-security/2008/04/07/1","http://www.openwall.com/lists/oss-security/2008/04/07/3","http://www.securityfocus.com/bid/28688","http://www.vupen.com/english/advisories/2008/1151/references","https://exchange.xforce.ibmcloud.com/vulnerabilities/41704"],"description":"Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option.  NOTE: it is not clear when this issue crosses privilege boundaries.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2008-1688","epss":0.02957,"percentile":0.86367,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"m4","version":"1.4.19-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2008-1688","versionConstraint":"none (unknown)"}}],"artifact":{"id":"10552197950b5e5a","name":"m4","version":"1.4.19-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/m4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/m4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/m4.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/m4.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/m4.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/m4.list"}],"language":"","licenses":["sha256:9438e0cbd4cf2121d2a9b61f42b1aaf765788dc3454983c55f2107cfe504f11c"],"cpes":["cpe:2.3:a:m4:m4:1.4.19-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/m4@1.4.19-3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-24401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00256,"percentile":0.17272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1472},"relatedVulnerabilities":[{"id":"CVE-2026-24401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00256,"percentile":0.17272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c21957a0053108b1","name":"libavahi-client3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-24401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00256,"percentile":0.17272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1472},"relatedVulnerabilities":[{"id":"CVE-2026-24401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00256,"percentile":0.17272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"934d69cf9aa71068","name":"libavahi-common-data","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-24401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00256,"percentile":0.17272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1472},"relatedVulnerabilities":[{"id":"CVE-2026-24401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24401","epss":0.00256,"percentile":0.17272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d355b05e7a15b748","name":"libavahi-common3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-58470","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58470","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58470","epss":0.00247,"percentile":0.15986,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58470","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14696499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-58470","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58470","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf","https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"],"description":"GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58470","epss":0.00247,"percentile":0.15986,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58470","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58470","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ef5a5a7d880f3e73","name":"wget","version":"1.21.3-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.list"}],"language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-41069","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41069","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41069","epss":0.00253,"percentile":0.16748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41069","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-41069","cwe":"CWE-476","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.145475},"relatedVulnerabilities":[{"id":"CVE-2026-41069","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41069","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/releases/tag/v1.22.0","https://github.com/strukturag/libheif/security/advisories/GHSA-p82x-fpmv-576r"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41069","epss":0.00253,"percentile":0.16748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41069","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-41069","cwe":"CWE-476","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-41069","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-70907","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70907","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70907","epss":0.00278,"percentile":0.20077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70907","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.14317},"relatedVulnerabilities":[{"id":"CVE-2026-70907","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70907","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70907","epss":0.00278,"percentile":0.20077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70907","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70907","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"945387ec24991974","name":"openjdk-17-jdk","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jdk/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jdk:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jdk:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jdk@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-70907","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70907","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70907","epss":0.00278,"percentile":0.20077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70907","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.14317},"relatedVulnerabilities":[{"id":"CVE-2026-70907","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70907","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70907","epss":0.00278,"percentile":0.20077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70907","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70907","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"8fadba790d3a033a","name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jdk-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jdk-headless:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jdk-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jdk-headless:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk-headless:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk_headless:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk_headless:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jdk-headless@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-70907","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70907","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70907","epss":0.00278,"percentile":0.20077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70907","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.14317},"relatedVulnerabilities":[{"id":"CVE-2026-70907","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70907","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70907","epss":0.00278,"percentile":0.20077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70907","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70907","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"a3f55d1528694a0b","name":"openjdk-17-jre","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jre/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jre:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jre@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-70907","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70907","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70907","epss":0.00278,"percentile":0.20077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70907","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.14317},"relatedVulnerabilities":[{"id":"CVE-2026-70907","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70907","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70907","epss":0.00278,"percentile":0.20077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70907","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70907","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"a98c024490217f82","name":"openjdk-17-jre-headless","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jre-headless:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre-headless:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre_headless:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre_headless:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jre-headless@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-58055","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58055","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58055","epss":0.00253,"percentile":0.16791,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.142945},"relatedVulnerabilities":[{"id":"CVE-2026-58055","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.3,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-58055","epss":0.00253,"percentile":0.16791,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nghttp2","version":"1.52.0-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-58055","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b906ffcf4bbc48dd","name":"libnghttp2-14","version":"1.52.0-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","all-permissive"],"cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnghttp2-14@1.52.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nghttp2","upstreams":[{"name":"nghttp2"}]}},{"vulnerability":{"id":"GHSA-38f8-5428-x5cv","dataSource":"https://github.com/advisories/GHSA-38f8-5428-x5cv","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-38f8-5428-x5cv","https://datatracker.ietf.org/doc/html/rfc9112#name-message-body-length","https://nvd.nist.gov/vuln/detail/CVE-2026-42585"],"description":"Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42585","epss":0.00248,"percentile":0.16105,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42585","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.133.Final"],"state":"fixed","available":[{"version":"4.1.133.Final","date":"2026-05-07","kind":"first-observed"}]},"advisories":[],"risk":0.1426},"relatedVulnerabilities":[{"id":"CVE-2026-42585","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42585","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/security/advisories/GHSA-38f8-5428-x5cv"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42585","epss":0.00248,"percentile":0.16105,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42585","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-38f8-5428-x5cv","versionConstraint":"<=4.1.132.Final (unknown)"},"fix":{"suggestedVersion":"4.1.133.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-55654","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-55654","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55654","epss":0.00424,"percentile":0.35781,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55654","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14203999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-55654","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55654","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/errata/RHSA-2026:36759","https://access.redhat.com/errata/RHSA-2026:47756","https://access.redhat.com/errata/RHSA-2026:47757","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-55654","https://bugzilla.redhat.com/show_bug.cgi?id=2462493"],"description":"A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-55654","epss":0.00424,"percentile":0.35781,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-55654","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-55654","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"GHSA-8c42-7qj2-3j46","dataSource":"https://github.com/advisories/GHSA-8c42-7qj2-3j46","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"description":"Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59903","epss":0.00245,"percentile":0.15704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.137.Final"],"state":"fixed","available":[{"version":"4.1.137.Final","date":"2026-08-18","kind":"first-observed"}]},"advisories":[],"risk":0.14087499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-59903","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59903","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59903","epss":0.00245,"percentile":0.15704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-8c42-7qj2-3j46","versionConstraint":"<=4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.137.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-8c42-7qj2-3j46","dataSource":"https://github.com/advisories/GHSA-8c42-7qj2-3j46","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"description":"Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59903","epss":0.00245,"percentile":0.15704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.137.Final"],"state":"fixed","available":[{"version":"4.1.137.Final","date":"2026-08-18","kind":"first-observed"}]},"advisories":[],"risk":0.14087499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-59903","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59903","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59903","epss":0.00245,"percentile":0.15704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-8c42-7qj2-3j46","versionConstraint":"<=4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.137.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-76642","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1408},"relatedVulnerabilities":[{"id":"CVE-2026-76642","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76642","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"GHSA-4mp9-239f-g9hg","dataSource":"https://github.com/advisories/GHSA-4mp9-239f-g9hg","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59898","epss":0.00249,"percentile":0.16264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.14068499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-59898","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59898","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"],"description":"Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59898","epss":0.00249,"percentile":0.16264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-4mp9-239f-g9hg","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-4mp9-239f-g9hg","dataSource":"https://github.com/advisories/GHSA-4mp9-239f-g9hg","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59898","epss":0.00249,"percentile":0.16264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.14068499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-59898","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59898","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"],"description":"Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59898","epss":0.00249,"percentile":0.16264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-4mp9-239f-g9hg","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-62289","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-62289","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-62289","epss":0.00302,"percentile":0.22661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-62289","cwe":"CWE-191","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-62289","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.14043},"relatedVulnerabilities":[{"id":"CVE-2026-62289","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-62289","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/commit/f01870c1d7323a3003796d58eba7fff502be994c","https://github.com/strukturag/libheif/releases/tag/v1.23.1","https://github.com/strukturag/libheif/security/advisories/GHSA-jc8f-p23p-5hjg"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-62289","epss":0.00302,"percentile":0.22661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-62289","cwe":"CWE-191","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-62289","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-62289","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-11822","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11822","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11822","epss":0.00175,"percentile":0.07168,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14},"relatedVulnerabilities":[{"id":"CVE-2026-11822","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","namespace":"nvd:cpe","severity":"High","urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11822","epss":0.00175,"percentile":0.07168,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"CVE-2026-11824","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11824","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11824","epss":0.00175,"percentile":0.07168,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.14},"relatedVulnerabilities":[{"id":"CVE-2026-11824","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11824","namespace":"nvd:cpe","severity":"High","urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate"],"description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11824","epss":0.00175,"percentile":0.07168,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11824","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"CVE-2024-56433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":1.1,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56433","epss":0.00423,"percentile":0.35657,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.13959},"relatedVulnerabilities":[{"id":"CVE-2024-56433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":1.1,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56433","epss":0.00423,"percentile":0.35657,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d5e0daed57b0ef5c","name":"login","version":"1:4.13+dfsg1-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","upstreams":[{"name":"shadow"}]}},{"vulnerability":{"id":"CVE-2024-56433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":1.1,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56433","epss":0.00423,"percentile":0.35657,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.13959},"relatedVulnerabilities":[{"id":"CVE-2024-56433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":1.1,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56433","epss":0.00423,"percentile":0.35657,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1853000d374a22b0","name":"passwd","version":"1:4.13+dfsg1-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/passwd@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","upstreams":[{"name":"shadow"}]}},{"vulnerability":{"id":"CVE-2026-66038","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66038","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66038","epss":0.00242,"percentile":0.15345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13914999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-66038","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66038","epss":0.00242,"percentile":0.15345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66038","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66038","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66038","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66038","epss":0.00242,"percentile":0.15345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13914999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-66038","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66038","epss":0.00242,"percentile":0.15345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66038","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66038","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66038","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66038","epss":0.00242,"percentile":0.15345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13914999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-66038","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66038","epss":0.00242,"percentile":0.15345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66038","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65705","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65705","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65705","epss":0.00187,"percentile":0.08441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65705","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13838},"relatedVulnerabilities":[{"id":"CVE-2026-65705","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65705","epss":0.00187,"percentile":0.08441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65705","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65705","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65705","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65705","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65705","epss":0.00187,"percentile":0.08441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65705","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13838},"relatedVulnerabilities":[{"id":"CVE-2026-65705","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65705","epss":0.00187,"percentile":0.08441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65705","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65705","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65705","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65705","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65705","epss":0.00187,"percentile":0.08441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65705","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13838},"relatedVulnerabilities":[{"id":"CVE-2026-65705","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65705","epss":0.00187,"percentile":0.08441,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65705","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65705","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"GHSA-c69g-56f8-xwqj","dataSource":"https://github.com/advisories/GHSA-c69g-56f8-xwqj","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59900","epss":0.00232,"percentile":0.14089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59900","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.13804},"relatedVulnerabilities":[{"id":"CVE-2026-59900","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59900","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59900","epss":0.00232,"percentile":0.14089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59900","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-c69g-56f8-xwqj","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"5895f3b705a95bee","name":"netty-codec-http2","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-c69g-56f8-xwqj","dataSource":"https://github.com/advisories/GHSA-c69g-56f8-xwqj","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59900","epss":0.00232,"percentile":0.14089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59900","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.13804},"relatedVulnerabilities":[{"id":"CVE-2026-59900","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59900","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59900","epss":0.00232,"percentile":0.14089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59900","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http2","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-c69g-56f8-xwqj","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"c9e87a7d2efc8ca7","name":"netty-codec-http2","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http2@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http2","pomArtifactID":"netty-codec-http2","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2023-47169","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-47169","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-47169","epss":0.00261,"percentile":0.17834,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-47169","cwe":"CWE-92","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-47169","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.137025},"relatedVulnerabilities":[{"id":"CVE-2023-47169","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-47169","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html"],"description":"Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-47169","epss":0.00261,"percentile":0.17834,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-47169","cwe":"CWE-92","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-47169","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-47169","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2012-2663","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-2663","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets.  NOTE: the CVE-2012-6638 fix makes this issue less relevant.","cvss":[],"epss":[{"cve":"CVE-2012-2663","epss":0.02737,"percentile":0.85244,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13685},"relatedVulnerabilities":[{"id":"CVE-2012-2663","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-2663","namespace":"nvd:cpe","severity":"High","urls":["http://www.spinics.net/lists/netfilter-devel/msg21248.html","https://bugzilla.redhat.com/show_bug.cgi?id=826702"],"description":"extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets.  NOTE: the CVE-2012-6638 fix makes this issue less relevant.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-2663","epss":0.02737,"percentile":0.85244,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"iptables","version":"1.8.9-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2012-2663","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a9652fb3f0d50205","name":"libip4tc2","version":"1.8.9-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libip4tc2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libip4tc2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libip4tc2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libip4tc2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","GPL-2","GPL-2+","custom"],"cpes":["cpe:2.3:a:libip4tc2:libip4tc2:1.8.9-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libip4tc2@1.8.9-2?arch=amd64&distro=debian-12.15&upstream=iptables","upstreams":[{"name":"iptables"}]}},{"vulnerability":{"id":"CVE-2018-20712","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13424999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-20712","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-20712","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13424999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-20712","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20712","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13424999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-20712","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20712","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13424999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-20712","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20712","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13424999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-20712","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20712","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13424999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-20712","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20712","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13424999999999998},"relatedVulnerabilities":[{"id":"CVE-2018-20712","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20712","epss":0.02685,"percentile":0.84952,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2006-4447","dataSource":"https://security-tracker.debian.org/tracker/CVE-2006-4447","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.","cvss":[],"epss":[{"cve":"CVE-2006-4447","epss":0.00447,"percentile":0.3766,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2006-4447","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1341},"relatedVulnerabilities":[{"id":"CVE-2006-4447","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2006-4447","namespace":"nvd:cpe","severity":"High","urls":["http://lists.freedesktop.org/archives/xorg/2006-June/016146.html","http://mail.gnome.org/archives/beast/2006-December/msg00025.html","http://secunia.com/advisories/21650","http://secunia.com/advisories/21660","http://secunia.com/advisories/21693","http://secunia.com/advisories/22332","http://secunia.com/advisories/25032","http://secunia.com/advisories/25059","http://security.gentoo.org/glsa/glsa-200608-25.xml","http://security.gentoo.org/glsa/glsa-200704-22.xml","http://www.debian.org/security/2006/dsa-1193","http://www.kb.cert.org/vuls/id/300368","http://www.mandriva.com/security/advisories?name=MDKSA-2006:160","http://www.securityfocus.com/bid/19742","http://www.securityfocus.com/bid/23697","http://www.vupen.com/english/advisories/2006/3409","http://www.vupen.com/english/advisories/2007/0409"],"description":"X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"exploitabilityScore":4,"impactScore":10.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2006-4447","epss":0.00447,"percentile":0.3766,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2006-4447","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xterm","version":"379-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2006-4447","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d0240bda9c48e21b","name":"xterm","version":"379-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xterm/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xterm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xterm.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xterm.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xterm.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.list"},{"path":"/var/lib/dpkg/info/xterm.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.postinst"},{"path":"/var/lib/dpkg/info/xterm.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.prerm"}],"language":"","licenses":["sha256:98e53d6eb11a468e199838883c5c0a756d12a3ece6e89b0ae4b98af77ee6e728"],"cpes":["cpe:2.3:a:xterm:xterm:379-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xterm@379-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2019-15680","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-15680","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.","cvss":[],"epss":[{"cve":"CVE-2019-15680","epss":0.02669,"percentile":0.84854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-15680","cwe":"CWE-476","source":"vulnerability@kaspersky.com","type":"Secondary"},{"cve":"CVE-2019-15680","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13344999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-15680","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-15680","namespace":"nvd:cpe","severity":"High","urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-478893.pdf","https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html","https://us-cert.cisa.gov/ics/advisories/icsa-20-343-08","https://usn.ubuntu.com/4407-1/","https://www.openwall.com/lists/oss-security/2018/12/10/5"],"description":"TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-15680","epss":0.02669,"percentile":0.84854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-15680","cwe":"CWE-476","source":"vulnerability@kaspersky.com","type":"Secondary"},{"cve":"CVE-2019-15680","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libvncserver","version":"0.9.14+dfsg-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-15680","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1016dfc48f06010d","name":"libvncclient1","version":"0.9.14+dfsg-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libvncclient1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libvncclient1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libvncclient1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libvncclient1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AT&T","BSD-3","Expat","GPL-2","GPL-2+","GPL-3","X-Consortium","wxWin"],"cpes":["cpe:2.3:a:libvncclient1:libvncclient1:0.9.14\\+dfsg-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libvncclient1@0.9.14%2Bdfsg-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libvncserver","upstreams":[{"name":"libvncserver"}]}},{"vulnerability":{"id":"CVE-2019-15680","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-15680","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.","cvss":[],"epss":[{"cve":"CVE-2019-15680","epss":0.02669,"percentile":0.84854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-15680","cwe":"CWE-476","source":"vulnerability@kaspersky.com","type":"Secondary"},{"cve":"CVE-2019-15680","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13344999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-15680","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-15680","namespace":"nvd:cpe","severity":"High","urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-478893.pdf","https://lists.debian.org/debian-lts-announce/2019/12/msg00028.html","https://us-cert.cisa.gov/ics/advisories/icsa-20-343-08","https://usn.ubuntu.com/4407-1/","https://www.openwall.com/lists/oss-security/2018/12/10/5"],"description":"TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-15680","epss":0.02669,"percentile":0.84854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-15680","cwe":"CWE-476","source":"vulnerability@kaspersky.com","type":"Secondary"},{"cve":"CVE-2019-15680","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libvncserver","version":"0.9.14+dfsg-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-15680","versionConstraint":"none (unknown)"}}],"artifact":{"id":"20d4e6f5042df6ab","name":"libvncserver1","version":"0.9.14+dfsg-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libvncserver1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libvncserver1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libvncserver1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libvncserver1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AT&T","BSD-3","Expat","GPL-2","GPL-2+","GPL-3","X-Consortium","wxWin"],"cpes":["cpe:2.3:a:libvncserver1:libvncserver1:0.9.14\\+dfsg-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libvncserver1@0.9.14%2Bdfsg-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libvncserver","upstreams":[{"name":"libvncserver"}]}},{"vulnerability":{"id":"CVE-2026-18393","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18393","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.4,"exploitabilityScore":1.2,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18393","epss":0.00255,"percentile":0.17032,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18393","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13260000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18393","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18393","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-18393","https://bugzilla.redhat.com/show_bug.cgi?id=2520309","https://github.com/FFmpeg/FFmpeg/commit/242ff799c75f20bade946314c8d741d0887ee11c","https://patchwork.ffmpeg.org/project/ffmpeg/patch/177767065817.63.1948165304485903849@29965ddac10e/"],"description":"A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond\nthe bounds of a heap-allocated buffer when processing crafted TDSC cursor\ndata. A remote attacker could exploit this by supplying a specially crafted\nvideo file, potentially leading to a denial of service or arbitrary code\nexecution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.4,"exploitabilityScore":1.2,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18393","epss":0.00255,"percentile":0.17032,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18393","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18393","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-18393","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18393","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.4,"exploitabilityScore":1.2,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18393","epss":0.00255,"percentile":0.17032,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18393","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13260000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18393","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18393","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-18393","https://bugzilla.redhat.com/show_bug.cgi?id=2520309","https://github.com/FFmpeg/FFmpeg/commit/242ff799c75f20bade946314c8d741d0887ee11c","https://patchwork.ffmpeg.org/project/ffmpeg/patch/177767065817.63.1948165304485903849@29965ddac10e/"],"description":"A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond\nthe bounds of a heap-allocated buffer when processing crafted TDSC cursor\ndata. A remote attacker could exploit this by supplying a specially crafted\nvideo file, potentially leading to a denial of service or arbitrary code\nexecution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.4,"exploitabilityScore":1.2,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18393","epss":0.00255,"percentile":0.17032,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18393","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18393","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-18393","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18393","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.4,"exploitabilityScore":1.2,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18393","epss":0.00255,"percentile":0.17032,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18393","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13260000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18393","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18393","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-18393","https://bugzilla.redhat.com/show_bug.cgi?id=2520309","https://github.com/FFmpeg/FFmpeg/commit/242ff799c75f20bade946314c8d741d0887ee11c","https://patchwork.ffmpeg.org/project/ffmpeg/patch/177767065817.63.1948165304485903849@29965ddac10e/"],"description":"A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond\nthe bounds of a heap-allocated buffer when processing crafted TDSC cursor\ndata. A remote attacker could exploit this by supplying a specially crafted\nvideo file, potentially leading to a denial of service or arbitrary code\nexecution.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.4,"exploitabilityScore":1.2,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18393","epss":0.00255,"percentile":0.17032,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18393","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18393","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2018-16376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-16376","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.","cvss":[],"epss":[{"cve":"CVE-2018-16376","epss":0.02647,"percentile":0.84704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-16376","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13235},"relatedVulnerabilities":[{"id":"CVE-2018-16376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16376","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/105262","https://github.com/uclouvain/openjpeg/issues/1127"],"description":"An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-16376","epss":0.02647,"percentile":0.84704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-16376","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-16376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2022-24975","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24975","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.","cvss":[],"epss":[{"cve":"CVE-2022-24975","epss":0.02645,"percentile":0.84697,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13225},"relatedVulnerabilities":[{"id":"CVE-2022-24975","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24975","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191","https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g/","https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/","https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/"],"description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-24975","epss":0.02645,"percentile":0.84697,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"git","version":"1:2.39.5-0+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-24975","versionConstraint":"none (unknown)"}}],"artifact":{"id":"58f3a3d22240a914","name":"git","version":"1:2.39.5-0+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.prerm"}],"language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"cpes":["cpe:2.3:a:git:git:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/git@1%3A2.39.5-0%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2022-24975","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24975","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.","cvss":[],"epss":[{"cve":"CVE-2022-24975","epss":0.02645,"percentile":0.84697,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13225},"relatedVulnerabilities":[{"id":"CVE-2022-24975","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24975","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191","https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g/","https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/","https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/"],"description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-24975","epss":0.02645,"percentile":0.84697,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"git","version":"1:2.39.5-0+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-24975","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d2fedb9664730c69","name":"git-man","version":"1:2.39.5-0+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git-man.list"}],"language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"cpes":["cpe:2.3:a:git-man:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/git-man@1%3A2.39.5-0%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=git","upstreams":[{"name":"git"}]}},{"vulnerability":{"id":"GHSA-gcjf-9mgh-3p7g","dataSource":"https://github.com/advisories/GHSA-gcjf-9mgh-3p7g","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"exploitabilityScore":2.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59921","epss":0.00247,"percentile":0.15948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.132145},"relatedVulnerabilities":[{"id":"CVE-2026-59921","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59921","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"exploitabilityScore":2.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59921","epss":0.00247,"percentile":0.15948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-gcjf-9mgh-3p7g","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-gcjf-9mgh-3p7g","dataSource":"https://github.com/advisories/GHSA-gcjf-9mgh-3p7g","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"description":"Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"exploitabilityScore":2.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59921","epss":0.00247,"percentile":0.15948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.136.Final"],"state":"fixed","available":[{"version":"4.1.136.Final","date":"2026-07-23","kind":"first-observed"}]},"advisories":[],"risk":0.132145},"relatedVulnerabilities":[{"id":"CVE-2026-59921","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59921","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"],"description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"exploitabilityScore":2.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59921","epss":0.00247,"percentile":0.15948,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-gcjf-9mgh-3p7g","versionConstraint":"<4.1.136.Final (unknown)"},"fix":{"suggestedVersion":"4.1.136.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-65704","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65704","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65704","epss":0.00178,"percentile":0.07506,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65704","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13172},"relatedVulnerabilities":[{"id":"CVE-2026-65704","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65704","epss":0.00178,"percentile":0.07506,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65704","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65704","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65704","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65704","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65704","epss":0.00178,"percentile":0.07506,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65704","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13172},"relatedVulnerabilities":[{"id":"CVE-2026-65704","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65704","epss":0.00178,"percentile":0.07506,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65704","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65704","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-65704","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-65704","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65704","epss":0.00178,"percentile":0.07506,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65704","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13172},"relatedVulnerabilities":[{"id":"CVE-2026-65704","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65704","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-via-ty-demuxer-and-shorten-decoder"],"description":"FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-65704","epss":0.00178,"percentile":0.07506,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-65704","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-65704","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-65704","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2010-4756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13055000000000003},"relatedVulnerabilities":[{"id":"CVE-2010-4756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","namespace":"nvd:cpe","severity":"Medium","urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2010-4756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13055000000000003},"relatedVulnerabilities":[{"id":"CVE-2010-4756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","namespace":"nvd:cpe","severity":"Medium","urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2010-4756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13055000000000003},"relatedVulnerabilities":[{"id":"CVE-2010-4756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","namespace":"nvd:cpe","severity":"Medium","urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2010-4756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13055000000000003},"relatedVulnerabilities":[{"id":"CVE-2010-4756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","namespace":"nvd:cpe","severity":"Medium","urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2010-4756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13055000000000003},"relatedVulnerabilities":[{"id":"CVE-2010-4756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","namespace":"nvd:cpe","severity":"Medium","urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4756","epss":0.02611,"percentile":0.84488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-7010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13329,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13052499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-7010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13329,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-7010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13329,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13052499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-7010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13329,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-7010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13329,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13052499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-7010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13329,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-7010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13329,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13052499999999997},"relatedVulnerabilities":[{"id":"CVE-2026-7010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-7010","epss":0.00227,"percentile":0.13329,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"GHSA-7g45-4rm6-3mm3","dataSource":"https://github.com/advisories/GHSA-7g45-4rm6-3mm3","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-2976","https://github.com/google/guava/issues/2575","https://github.com/google/guava/issues/6532","https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284","https://github.com/google/guava/releases/tag/v32.0.0","https://security.netapp.com/advisory/ntap-20230818-0008","https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html","https://security.netapp.com/advisory/ntap-20241108-0002"],"description":"Guava vulnerable to insecure use of temporary directory","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-2976","epss":0.00248,"percentile":0.16056,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-2976","cwe":"CWE-552","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-2976","cwe":"CWE-552","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["32.0.0-android"],"state":"fixed","available":[{"version":"32.0.0-android","date":"2023-11-10","kind":"first-observed"}]},"advisories":[],"risk":0.1302},"relatedVulnerabilities":[{"id":"CVE-2023-2976","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2976","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/google/guava/issues/2575","https://security.netapp.com/advisory/ntap-20230818-0008/","https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.\n\nEven though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve-coordination@google.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-2976","epss":0.00248,"percentile":0.16056,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-2976","cwe":"CWE-552","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-2976","cwe":"CWE-552","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.google.guava:guava","version":"30.1-jre"}},"found":{"vulnerabilityID":"GHSA-7g45-4rm6-3mm3","versionConstraint":">=1.0,<32.0.0-android (unknown)"},"fix":{"suggestedVersion":"32.0.0-android"}}],"artifact":{"id":"6fadb4e96c532103","name":"guava","version":"30.1-jre","type":"java-archive","locations":[{"path":"/zap/plugin/spiderAjax-release-23.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/spiderAjax-release-23.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:com.google.guava:guava:30.1-jre:*:*:*:*:*:*:*","cpe:2.3:a:google:guava:30.1-jre:*:*:*:*:*:*:*","cpe:2.3:a:guava:guava:30.1-jre:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.google.guava/guava@30.1-jre","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/spiderAjax-release-23.29.0.zap:com.google.guava:guava","pomArtifactID":"guava","pomGroupID":"com.google.guava","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-7g45-4rm6-3mm3","dataSource":"https://github.com/advisories/GHSA-7g45-4rm6-3mm3","namespace":"github:language:java","severity":"Medium","urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-2976","https://github.com/google/guava/issues/2575","https://github.com/google/guava/issues/6532","https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284","https://github.com/google/guava/releases/tag/v32.0.0","https://security.netapp.com/advisory/ntap-20230818-0008","https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html","https://security.netapp.com/advisory/ntap-20241108-0002"],"description":"Guava vulnerable to insecure use of temporary directory","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-2976","epss":0.00248,"percentile":0.16056,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-2976","cwe":"CWE-552","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-2976","cwe":"CWE-552","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["32.0.0-android"],"state":"fixed","available":[{"version":"32.0.0-android","date":"2023-11-10","kind":"first-observed"}]},"advisories":[],"risk":0.1302},"relatedVulnerabilities":[{"id":"CVE-2023-2976","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2976","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/google/guava/issues/2575","https://security.netapp.com/advisory/ntap-20230818-0008/","https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html","https://security.netapp.com/advisory/ntap-20241108-0002/"],"description":"Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.\n\nEven though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve-coordination@google.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-2976","epss":0.00248,"percentile":0.16056,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-2976","cwe":"CWE-552","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-2976","cwe":"CWE-552","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.google.guava:guava","version":"31.0.1-jre"}},"found":{"vulnerabilityID":"GHSA-7g45-4rm6-3mm3","versionConstraint":">=1.0,<32.0.0-android (unknown)"},"fix":{"suggestedVersion":"32.0.0-android"}}],"artifact":{"id":"b4694958ecf60e48","name":"guava","version":"31.0.1-jre","type":"java-archive","locations":[{"path":"/zap/plugin/spiderAjax-release-23.32.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/spiderAjax-release-23.32.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:com.google.guava:guava:31.0.1-jre:*:*:*:*:*:*:*","cpe:2.3:a:google:guava:31.0.1-jre:*:*:*:*:*:*:*","cpe:2.3:a:guava:guava:31.0.1-jre:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.google.guava/guava@31.0.1-jre","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/spiderAjax-release-23.32.0.zap:com.google.guava:guava","pomArtifactID":"guava","pomGroupID":"com.google.guava","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-59995","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59995","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59995","epss":0.0025,"percentile":0.16391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.13},"relatedVulnerabilities":[{"id":"CVE-2026-59995","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","namespace":"nvd:cpe","severity":"Medium","urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"exploitabilityScore":1.7,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59995","epss":0.0025,"percentile":0.16391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2026-59996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59996","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59996","epss":0.0025,"percentile":0.16391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.13},"relatedVulnerabilities":[{"id":"CVE-2026-59996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","namespace":"nvd:cpe","severity":"Medium","urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"exploitabilityScore":1.7,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59996","epss":0.0025,"percentile":0.16391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2024-10041","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10041","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.128525},"relatedVulnerabilities":[{"id":"CVE-2024-10041","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10041","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4cab7ef7de016d31","name":"libpam-modules","version":"1.5.2-6+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-modules@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2024-10041","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10041","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.128525},"relatedVulnerabilities":[{"id":"CVE-2024-10041","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10041","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"}}],"artifact":{"id":"372dffabd059479c","name":"libpam-modules-bin","version":"1.5.2-6+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-modules-bin@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2024-10041","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10041","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.128525},"relatedVulnerabilities":[{"id":"CVE-2024-10041","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10041","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ca1034d5d24bcf54","name":"libpam-runtime","version":"1.5.2-6+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-runtime@1.5.2-6%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2024-10041","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10041","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.128525},"relatedVulnerabilities":[{"id":"CVE-2024-10041","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-10041","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-10041","cwe":"CWE-922","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"}}],"artifact":{"id":"87d8465053cf56c8","name":"libpam0g","version":"1.5.2-6+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam0g@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","upstreams":[{"name":"pam"}]}},{"vulnerability":{"id":"CVE-2016-2781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-2781","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.","cvss":[],"epss":[{"cve":"CVE-2016-2781","epss":0.00428,"percentile":0.36088,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2016-2781","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1284},"relatedVulnerabilities":[{"id":"CVE-2016-2781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.1,"impactScore":4},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"exploitabilityScore":1.5,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-2781","epss":0.00428,"percentile":0.36088,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2016-2781","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eca37691b87c0860","name":"coreutils","version":"9.1-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74962","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74962","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74962","epss":0.00164,"percentile":0.05877,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74962","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.12792},"relatedVulnerabilities":[{"id":"CVE-2026-74962","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74962","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2050425","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74962","epss":0.00164,"percentile":0.05877,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74962","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74962","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74960","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74960","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74960","epss":0.00164,"percentile":0.05876,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74960","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-74960","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.12792},"relatedVulnerabilities":[{"id":"CVE-2026-74960","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74960","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2049148","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74960","epss":0.00164,"percentile":0.05876,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74960","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-74960","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74960","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12709499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-6019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12709499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-6019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12709499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-6019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12709499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-6019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12709499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-6019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12709499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-6019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12709499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-6019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"exploitabilityScore":2.9,"impactScore":2.8},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6019","epss":0.00229,"percentile":0.13682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-6019","cwe":"CWE-116","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2023-39328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39328","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39328","epss":0.00242,"percentile":0.15383,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39328","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12705},"relatedVulnerabilities":[{"id":"CVE-2023-39328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39328","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-39328","https://bugzilla.redhat.com/show_bug.cgi?id=2219236","https://github.com/uclouvain/openjpeg/issues/1476","https://github.com/uclouvain/openjpeg/pull/1470","https://github.com/uclouvain/openjpeg/pull/1471"],"description":"A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39328","epss":0.00242,"percentile":0.15383,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39328","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-39328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-50259","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50259","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50259","epss":0.00165,"percentile":0.05983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50259","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50259","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.126225},"relatedVulnerabilities":[{"id":"CVE-2026-50259","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50259","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50259","https://bugzilla.redhat.com/show_bug.cgi?id=2485384","https://gitlab.freedesktop.org/xorg/xserver/-/commit/867b59b33bee669cb412f1314e47c52eacf6e00b","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50259.json"],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50259","epss":0.00165,"percentile":0.05983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50259","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50259","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50259","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50259","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50259","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50259","epss":0.00165,"percentile":0.05983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50259","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50259","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.126225},"relatedVulnerabilities":[{"id":"CVE-2026-50259","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50259","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50259","https://bugzilla.redhat.com/show_bug.cgi?id=2485384","https://gitlab.freedesktop.org/xorg/xserver/-/commit/867b59b33bee669cb412f1314e47c52eacf6e00b","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50259.json"],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50259","epss":0.00165,"percentile":0.05983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50259","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50259","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50259","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2020-15719","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.","cvss":[],"epss":[{"cve":"CVE-2020-15719","epss":0.02515,"percentile":0.83854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12575},"relatedVulnerabilities":[{"id":"CVE-2020-15719","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"exploitabilityScore":1.7,"impactScore":2.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"exploitabilityScore":5,"impactScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-15719","epss":0.02515,"percentile":0.83854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"}}],"artifact":{"id":"692b9197d4b21a92","name":"libldap-2.5-0","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2020-15719","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.","cvss":[],"epss":[{"cve":"CVE-2020-15719","epss":0.02515,"percentile":0.83854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12575},"relatedVulnerabilities":[{"id":"CVE-2020-15719","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"exploitabilityScore":1.7,"impactScore":2.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"exploitabilityScore":5,"impactScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-15719","epss":0.02515,"percentile":0.83854,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dd3946a6b1d2298d","name":"libldap-common","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-common@2.5.13%2Bdfsg-5?arch=all&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2023-48368","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-48368","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-48368","epss":0.00239,"percentile":0.14917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-48368","cwe":"CWE-20","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-48368","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12547500000000003},"relatedVulnerabilities":[{"id":"CVE-2023-48368","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-48368","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html"],"description":"Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-48368","epss":0.00239,"percentile":0.14917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-48368","cwe":"CWE-20","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-48368","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-48368","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2024-35369","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35369","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35369","epss":0.00237,"percentile":0.1472,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35369","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12442500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-35369","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35369","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/1047524396/455093807666f2e351d674750c8cd0b8","https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavcodec/speexdec.c#L1423","https://github.com/ffmpeg/ffmpeg/commit/0895ef0d6d6406ee6cd158fc4d47d80f201b8e9c"],"description":"In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35369","epss":0.00237,"percentile":0.1472,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35369","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35369","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2024-35369","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35369","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35369","epss":0.00237,"percentile":0.1472,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35369","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12442500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-35369","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35369","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/1047524396/455093807666f2e351d674750c8cd0b8","https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavcodec/speexdec.c#L1423","https://github.com/ffmpeg/ffmpeg/commit/0895ef0d6d6406ee6cd158fc4d47d80f201b8e9c"],"description":"In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35369","epss":0.00237,"percentile":0.1472,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35369","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35369","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2024-35369","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35369","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35369","epss":0.00237,"percentile":0.1472,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35369","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12442500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-35369","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35369","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/1047524396/455093807666f2e351d674750c8cd0b8","https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavcodec/speexdec.c#L1423","https://github.com/ffmpeg/ffmpeg/commit/0895ef0d6d6406ee6cd158fc4d47d80f201b8e9c"],"description":"In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35369","epss":0.00237,"percentile":0.1472,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35369","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35369","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2007-2243","dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2243","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.","cvss":[],"epss":[{"cve":"CVE-2007-2243","epss":0.02472,"percentile":0.83553,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-2243","cwe":"CWE-287","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12360000000000002},"relatedVulnerabilities":[{"id":"CVE-2007-2243","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2243","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053906.html","http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053951.html","http://securityreason.com/securityalert/2631","http://www.osvdb.org/34600","http://www.securityfocus.com/bid/23601","https://exchange.xforce.ibmcloud.com/vulnerabilities/33794","https://security.netapp.com/advisory/ntap-20191107-0003/"],"description":"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2007-2243","epss":0.02472,"percentile":0.83553,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-2243","cwe":"CWE-287","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2007-2243","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2026-50258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50258","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50258","epss":0.00161,"percentile":0.05634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50258","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50258","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.12316500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50258","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50258","https://bugzilla.redhat.com/show_bug.cgi?id=2485383","https://gitlab.freedesktop.org/xorg/xserver/-/commit/543e108516428fc8c3bea91d6563ad266f9a801e","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50258.json"],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50258","epss":0.00161,"percentile":0.05634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50258","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50258","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50258","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50258","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50258","epss":0.00161,"percentile":0.05634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50258","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50258","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.12316500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50258","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50258","https://bugzilla.redhat.com/show_bug.cgi?id=2485383","https://gitlab.freedesktop.org/xorg/xserver/-/commit/543e108516428fc8c3bea91d6563ad266f9a801e","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50258.json"],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50258","epss":0.00161,"percentile":0.05634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50258","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50258","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50258","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2008-1687","dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-1687","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.","cvss":[],"epss":[{"cve":"CVE-2008-1687","epss":0.0245,"percentile":0.83407,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2008-1687","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12250000000000001},"relatedVulnerabilities":[{"id":"CVE-2008-1687","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-1687","namespace":"nvd:cpe","severity":"High","urls":["http://secunia.com/advisories/29671","http://secunia.com/advisories/29729","http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.510612","http://www.openwall.com/lists/oss-security/2008/04/07/1","http://www.openwall.com/lists/oss-security/2008/04/07/12","http://www.openwall.com/lists/oss-security/2008/04/07/3","http://www.openwall.com/lists/oss-security/2008/04/07/4","http://www.securityfocus.com/bid/28688","http://www.vupen.com/english/advisories/2008/1151/references","https://exchange.xforce.ibmcloud.com/vulnerabilities/41706"],"description":"The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2008-1687","epss":0.0245,"percentile":0.83407,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2008-1687","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"m4","version":"1.4.19-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2008-1687","versionConstraint":"none (unknown)"}}],"artifact":{"id":"10552197950b5e5a","name":"m4","version":"1.4.19-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/m4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/m4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/m4.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/m4.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/m4.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/m4.list"}],"language":"","licenses":["sha256:9438e0cbd4cf2121d2a9b61f42b1aaf765788dc3454983c55f2107cfe504f11c"],"cpes":["cpe:2.3:a:m4:m4:1.4.19-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/m4@1.4.19-3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-16768","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16768","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16768","epss":0.00237,"percentile":0.14631,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16768","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12205500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-16768","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16768","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-16768","https://bugzilla.redhat.com/show_bug.cgi?id=2506437","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302"],"description":"A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16768","epss":0.00237,"percentile":0.14631,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16768","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16768","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e384004f37f8d5e","name":"libgdk-pixbuf-2.0-0","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf-2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf-2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf-2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf-2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf-2.0-0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0-0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0_0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0_0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf-2.0-0@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2026-16768","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16768","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16768","epss":0.00237,"percentile":0.14631,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16768","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12205500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-16768","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16768","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-16768","https://bugzilla.redhat.com/show_bug.cgi?id=2506437","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302"],"description":"A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16768","epss":0.00237,"percentile":0.14631,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16768","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16768","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b205c783e97c36c6","name":"libgdk-pixbuf2.0-bin","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf2.0-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.list"}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf2.0-bin:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0-bin:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_bin:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_bin:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf2.0-bin@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2026-16768","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16768","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16768","epss":0.00237,"percentile":0.14631,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16768","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12205500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-16768","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16768","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-16768","https://bugzilla.redhat.com/show_bug.cgi?id=2506437","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302"],"description":"A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16768","epss":0.00237,"percentile":0.14631,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16768","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16768","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5a58bb7174f44032","name":"libgdk-pixbuf2.0-common","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf2.0-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf2.0-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.list"}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf2.0-common:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0-common:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_common:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_common:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf2.0-common@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=all&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2026-74971","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74971","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74971","epss":0.00261,"percentile":0.1782,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74971","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.12136499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74971","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74971","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2057204","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74971","epss":0.00261,"percentile":0.1782,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74971","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74971","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74972","epss":0.00261,"percentile":0.1782,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74972","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.12136499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74972","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2059053","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74972","epss":0.00261,"percentile":0.1782,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74972","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74972","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2019-9192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12135000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-9192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-9192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12135000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-9192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-9192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12135000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-9192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-9192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12135000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-9192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-9192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12135000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-9192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-9192","epss":0.02427,"percentile":0.8324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6791","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12063999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-6791","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6791","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12063999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-6791","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6791","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12063999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-6791","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6791","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12063999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-6791","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6791","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12063999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-6791","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6791","epss":0.00208,"percentile":0.10947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-50256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50256","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50256","epss":0.00157,"percentile":0.05214,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50256","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50256","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.12010499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-50256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50256","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50256","https://bugzilla.redhat.com/show_bug.cgi?id=2485380","https://gitlab.freedesktop.org/xorg/xserver/-/commit/bb5158f962dc935e58ef8b4b5fcb31be201a6e07","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50256.json"],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50256","epss":0.00157,"percentile":0.05214,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50256","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50256","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50256","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50256","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50256","epss":0.00157,"percentile":0.05214,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50256","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50256","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.12010499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-50256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50256","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50256","https://bugzilla.redhat.com/show_bug.cgi?id=2485380","https://gitlab.freedesktop.org/xorg/xserver/-/commit/bb5158f962dc935e58ef8b4b5fcb31be201a6e07","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50256.json"],"description":"A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50256","epss":0.00157,"percentile":0.05214,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50256","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50256","cwe":"CWE-121","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50256","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-82522","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82522","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers can supply a crafted JPEG XL file causing the decoder to parse attacker-controlled codestream bytes as phantom box headers, enabling injection of arbitrary metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-bounds reads.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-82522","epss":0.00233,"percentile":0.14204,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-82522","cwe":"CWE-681","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11999499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-82522","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82522","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libjxl/libjxl/commit/22ad80af1454f0444ea34115e49ed40517147d68","https://github.com/libjxl/libjxl/pull/4885","https://github.com/libjxl/libjxl/releases/tag/v0.12.0","https://www.vulncheck.com/advisories/libjxl-container-box-parser-integer-underflow-via-32-bit-size-truncation"],"description":"libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers can supply a crafted JPEG XL file causing the decoder to parse attacker-controlled codestream bytes as phantom box headers, enabling injection of arbitrary metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-bounds reads.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-82522","epss":0.00233,"percentile":0.14204,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-82522","cwe":"CWE-681","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jpeg-xl","version":"0.7.0-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-82522","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b6ad6e0f23e0de4d","name":"libjxl0.7","version":"0.7.0-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjxl0.7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjxl0.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause-Google","ISC-License"],"cpes":["cpe:2.3:a:libjxl0.7:libjxl0.7:0.7.0-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjxl0.7@0.7.0-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=jpeg-xl","upstreams":[{"name":"jpeg-xl"}]}},{"vulnerability":{"id":"CVE-2025-58436","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-58436","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58436","epss":0.00228,"percentile":0.13603,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-58436","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.11969999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-58436","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58436","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/OpenPrinting/cups/commit/40008d76a001babbb9beb9d9d74b01a86fb6ddb4","https://github.com/OpenPrinting/cups/releases/tag/v2.4.15","https://github.com/OpenPrinting/cups/security/advisories/GHSA-8wpw-vfgm-qrrr","http://www.openwall.com/lists/oss-security/2025/11/27/4"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"exploitabilityScore":1.5,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58436","epss":0.00228,"percentile":0.13603,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-58436","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-58436","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2015-9019","dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-9019","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.","cvss":[],"epss":[{"cve":"CVE-2015-9019","epss":0.02393,"percentile":0.82977,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2015-9019","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11965},"relatedVulnerabilities":[{"id":"CVE-2015-9019","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-9019","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.gnome.org/show_bug.cgi?id=758400","https://bugzilla.suse.com/show_bug.cgi?id=934119"],"description":"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-9019","epss":0.02393,"percentile":0.82977,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2015-9019","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxslt","version":"1.1.35-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2015-9019","versionConstraint":"none (unknown)"}}],"artifact":{"id":"127f2ae91adc51ae","name":"libxslt1.1","version":"1.1.35-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxslt1.1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxslt1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:4b82c8dd6e55001a5921bea1d6db20be5c51e5976d892e870324026c23f37b6f"],"cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.35-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxslt1.1@1.1.35-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=libxslt","upstreams":[{"name":"libxslt"}]}},{"vulnerability":{"id":"GHSA-hvcg-qmg6-jm4c","dataSource":"https://github.com/advisories/GHSA-hvcg-qmg6-jm4c","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-hvcg-qmg6-jm4c","https://nvd.nist.gov/vuln/detail/CVE-2026-50020","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"description":"Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50020","epss":0.00232,"percentile":0.14089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50020","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-16","kind":"first-observed"}]},"advisories":[],"risk":0.11948},"relatedVulnerabilities":[{"id":"CVE-2026-50020","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50020","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-hvcg-qmg6-jm4c"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50020","epss":0.00232,"percentile":0.14089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50020","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.100.Final"}},"found":{"vulnerabilityID":"GHSA-hvcg-qmg6-jm4c","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"4cc97727749401f1","name":"netty-codec-http","version":"4.1.100.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.25.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.25.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.100.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.100.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.100.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.25.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-hvcg-qmg6-jm4c","dataSource":"https://github.com/advisories/GHSA-hvcg-qmg6-jm4c","namespace":"github:language:java","severity":"Medium","urls":["https://github.com/netty/netty/security/advisories/GHSA-hvcg-qmg6-jm4c","https://nvd.nist.gov/vuln/detail/CVE-2026-50020","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"description":"Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50020","epss":0.00232,"percentile":0.14089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50020","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":["4.1.135.Final"],"state":"fixed","available":[{"version":"4.1.135.Final","date":"2026-06-16","kind":"first-observed"}]},"advisories":[],"risk":0.11948},"relatedVulnerabilities":[{"id":"CVE-2026-50020","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50020","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-hvcg-qmg6-jm4c"],"description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50020","epss":0.00232,"percentile":0.14089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50020","cwe":"CWE-444","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"io.netty:netty-codec-http","version":"4.1.134.Final"}},"found":{"vulnerabilityID":"GHSA-hvcg-qmg6-jm4c","versionConstraint":"<=4.1.134.Final (unknown)"},"fix":{"suggestedVersion":"4.1.135.Final"}}],"artifact":{"id":"ba26d62854f08a75","name":"netty-codec-http","version":"4.1.134.Final","type":"java-archive","locations":[{"path":"/zap/plugin/network-beta-0.29.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/network-beta-0.29.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:netty-codec-http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.1.134.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.1.134.Final:*:*:*:*:*:*:*"],"purl":"pkg:maven/io.netty/netty-codec-http@4.1.134.Final","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/network-beta-0.29.0.zap:io.netty:netty-codec-http","pomArtifactID":"netty-codec-http","pomGroupID":"io.netty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-59999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59999","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59999","epss":0.00159,"percentile":0.05416,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.11925},"relatedVulnerabilities":[{"id":"CVE-2026-59999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","namespace":"nvd:cpe","severity":"High","urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59999","epss":0.00159,"percentile":0.05416,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2026-52584","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52584","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52584","epss":0.00163,"percentile":0.05841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52584","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11899},"relatedVulnerabilities":[{"id":"CVE-2026-52584","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52584","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libjxl/libjxl/issues/4803","https://github.com/libjxl/libjxl/pull/4804"],"description":"Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52584","epss":0.00163,"percentile":0.05841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52584","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jpeg-xl","version":"0.7.0-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52584","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b6ad6e0f23e0de4d","name":"libjxl0.7","version":"0.7.0-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjxl0.7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjxl0.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause-Google","ISC-License"],"cpes":["cpe:2.3:a:libjxl0.7:libjxl0.7:0.7.0-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjxl0.7@0.7.0-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=jpeg-xl","upstreams":[{"name":"jpeg-xl"}]}},{"vulnerability":{"id":"CVE-2026-74934","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74934","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74934","epss":0.00158,"percentile":0.05273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74934","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-74934","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-74934","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.11850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74934","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74934","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2050584","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74934","epss":0.00158,"percentile":0.05273,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74934","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-74934","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-74934","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74934","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-50260","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50260","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50260","epss":0.00154,"percentile":0.04842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50260","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50260","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.11780999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-50260","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50260","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50260","https://bugzilla.redhat.com/show_bug.cgi?id=2485385","https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50260.json"],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50260","epss":0.00154,"percentile":0.04842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50260","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50260","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50260","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50261","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50261","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50261","epss":0.00154,"percentile":0.04842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50261","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50261","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.11780999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-50261","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50261","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50261","https://bugzilla.redhat.com/show_bug.cgi?id=2485386","https://gitlab.freedesktop.org/xorg/xserver/-/commit/bdd7bf57af208b1ddf57d4683d67104443b44812","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50261.json"],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50261","epss":0.00154,"percentile":0.04842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50261","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50261","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50261","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50260","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50260","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50260","epss":0.00154,"percentile":0.04842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50260","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50260","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.11780999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-50260","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50260","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50260","https://bugzilla.redhat.com/show_bug.cgi?id=2485385","https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50260.json"],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50260","epss":0.00154,"percentile":0.04842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50260","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50260","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50260","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50261","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50261","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50261","epss":0.00154,"percentile":0.04842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50261","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50261","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.11780999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-50261","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50261","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50261","https://bugzilla.redhat.com/show_bug.cgi?id=2485386","https://gitlab.freedesktop.org/xorg/xserver/-/commit/bdd7bf57af208b1ddf57d4683d67104443b44812","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50261.json"],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50261","epss":0.00154,"percentile":0.04842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50261","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50261","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50261","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-70628","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70628","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70628","epss":0.00145,"percentile":0.041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-70628","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.116},"relatedVulnerabilities":[{"id":"CVE-2026-70628","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70628","epss":0.00145,"percentile":0.041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-70628","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70628","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70628","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70628","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70628","epss":0.00145,"percentile":0.041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-70628","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.116},"relatedVulnerabilities":[{"id":"CVE-2026-70628","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70628","epss":0.00145,"percentile":0.041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-70628","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70628","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70628","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70628","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70628","epss":0.00145,"percentile":0.041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-70628","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.116},"relatedVulnerabilities":[{"id":"CVE-2026-70628","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897","https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70628","epss":0.00145,"percentile":0.041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70628","cwe":"CWE-190","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-70628","cwe":"CWE-787","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70628","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-33165","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-33165","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHeaderIndex to index past the allocated image metadata array and write 2 bytes past the end of a heap allocation. This issue has been patched in version 1.0.17.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-33165","epss":0.00232,"percentile":0.14003,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-33165","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.116},"relatedVulnerabilities":[{"id":"CVE-2026-33165","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33165","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libde265/commit/c7891e412106130b83f8e8ea8b7f907e9449b658","https://github.com/strukturag/libde265/releases/tag/v1.0.17","https://github.com/strukturag/libde265/security/advisories/GHSA-653q-9f73-8hvg"],"description":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHeaderIndex to index past the allocated image metadata array and write 2 bytes past the end of a heap allocation. This issue has been patched in version 1.0.17.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-33165","epss":0.00232,"percentile":0.14003,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-33165","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-33165","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-15588","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15588","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15588","epss":0.00225,"percentile":0.13072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.11587499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-15588","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15588","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:39985","https://access.redhat.com/errata/RHSA-2026:40485","https://access.redhat.com/errata/RHSA-2026:42329","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-15588","https://bugzilla.redhat.com/show_bug.cgi?id=2499675","https://gitlab.gnome.org/GNOME/glib/-/issues/3985"],"description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15588","epss":0.00225,"percentile":0.13072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15588","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-15588","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15588","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15588","epss":0.00225,"percentile":0.13072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.11587499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-15588","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15588","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:39985","https://access.redhat.com/errata/RHSA-2026:40485","https://access.redhat.com/errata/RHSA-2026:42329","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/security/cve/CVE-2026-15588","https://bugzilla.redhat.com/show_bug.cgi?id=2499675","https://gitlab.gnome.org/GNOME/glib/-/issues/3985"],"description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15588","epss":0.00225,"percentile":0.13072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15588","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-27171","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27171","epss":0.00218,"percentile":0.12242,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.11445000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-27171","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","namespace":"nvd:cpe","severity":"Medium","urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27171","epss":0.00218,"percentile":0.12242,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"}}],"artifact":{"id":"077923f667034501","name":"zlib1g","version":"1:1.2.13.dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Zlib"],"cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","upstreams":[{"name":"zlib"}]}},{"vulnerability":{"id":"CVE-2026-27171","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27171","epss":0.00218,"percentile":0.12242,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.11445000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-27171","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","namespace":"nvd:cpe","severity":"Medium","urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27171","epss":0.00218,"percentile":0.12242,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3f28e512f3f6e928","name":"zlib1g-dev","version":"1:1.2.13.dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/zlib1g-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/zlib1g-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Zlib"],"cpes":["cpe:2.3:a:zlib1g-dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g-dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g_dev:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g-dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:zlib1g:zlib1g_dev:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/zlib1g-dev@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","upstreams":[{"name":"zlib"}]}},{"vulnerability":{"id":"CVE-2026-49271","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-49271","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49271","epss":0.00199,"percentile":0.09837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49271","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11442499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-49271","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49271","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/security/advisories/GHSA-r7qj-cg5r-r6vf"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-49271","epss":0.00199,"percentile":0.09837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-49271","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-49271","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-84120","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84120","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84120","epss":0.00219,"percentile":0.12308,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84120","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.11388000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-84120","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84120","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2058911","https://www.mozilla.org/security/advisories/mfsa2026-82/","https://www.mozilla.org/security/advisories/mfsa2026-83/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-86/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84120","epss":0.00219,"percentile":0.12308,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84120","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84120","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-32777","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32777","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32777","epss":0.00216,"percentile":0.12006,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2026-32777","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32777","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/issues/1161","https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1162","https://issues.oss-fuzz.com/issues/486993411","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32777","epss":0.00216,"percentile":0.12006,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32777","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-32777","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32777","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32777","epss":0.00216,"percentile":0.12006,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2026-32777","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32777","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/issues/1161","https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1162","https://issues.oss-fuzz.com/issues/486993411","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32777","epss":0.00216,"percentile":0.12006,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32777","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2019-1010025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11334999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","namespace":"nvd:cpe","severity":"Medium","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11334999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","namespace":"nvd:cpe","severity":"Medium","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11334999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","namespace":"nvd:cpe","severity":"Medium","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11334999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","namespace":"nvd:cpe","severity":"Medium","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2019-1010025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11334999999999999},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","namespace":"nvd:cpe","severity":"Medium","urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010025","epss":0.02267,"percentile":0.81989,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-50264","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50264","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50264","epss":0.00148,"percentile":0.0435,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50264","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50264","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.11322000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-50264","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50264","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/security/cve/CVE-2026-50264","https://bugzilla.redhat.com/show_bug.cgi?id=2485389","https://gitlab.freedesktop.org/xorg/xserver/-/commit/339c279514326134b0878fc23ce6e9520440ce7f","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50264.json"],"description":"An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50264","epss":0.00148,"percentile":0.0435,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50264","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50264","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50264","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50264","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50264","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50264","epss":0.00148,"percentile":0.0435,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50264","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50264","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.11322000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-50264","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50264","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/security/cve/CVE-2026-50264","https://bugzilla.redhat.com/show_bug.cgi?id=2485389","https://gitlab.freedesktop.org/xorg/xserver/-/commit/339c279514326134b0878fc23ce6e9520440ce7f","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50264.json"],"description":"An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50264","epss":0.00148,"percentile":0.0435,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50264","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50264","cwe":"CWE-787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50264","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-63388","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63388","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63388","epss":0.00142,"percentile":0.03805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63388","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-63388","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11289000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-63388","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63388","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9","https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72","https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338"],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63388","epss":0.00142,"percentile":0.03805,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63388","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-63388","cwe":"CWE-787","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libevent","version":"2.1.12-stable-8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63388","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3bff02d75bb58680","name":"libevent-2.1-7","version":"2.1.12-stable-8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libevent-2.1-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libevent-2.1-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSL","Expat","FSFUL","FSFULLR","FSFULLR-No-Warranty","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","curl"],"cpes":["cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1-7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libevent-2.1-7@2.1.12-stable-8?arch=amd64&distro=debian-12.15&upstream=libevent","upstreams":[{"name":"libevent"}]}},{"vulnerability":{"id":"CVE-2020-23922","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-23922","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.","cvss":[],"epss":[{"cve":"CVE-2020-23922","epss":0.02237,"percentile":0.81769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-23922","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11185000000000002},"relatedVulnerabilities":[{"id":"CVE-2020-23922","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-23922","namespace":"nvd:cpe","severity":"High","urls":["https://cwe.mitre.org/data/definitions/126.html","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E","https://sourceforge.net/p/giflib/bugs/151/"],"description":"An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","metrics":{"baseScore":5.8,"exploitabilityScore":8.6,"impactScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-23922","epss":0.02237,"percentile":0.81769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-23922","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"giflib","version":"5.2.1-2.5+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-23922","versionConstraint":"none (unknown)"}}],"artifact":{"id":"71a582f5b3d629e1","name":"libgif7","version":"5.2.1-2.5+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgif7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgif7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgif7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgif7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT"],"cpes":["cpe:2.3:a:libgif7:libgif7:5.2.1-2.5\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgif7@5.2.1-2.5%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=giflib","upstreams":[{"name":"giflib"}]}},{"vulnerability":{"id":"CVE-2016-9116","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9116","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[],"epss":[{"cve":"CVE-2016-9116","epss":0.02236,"percentile":0.81763,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9116","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11180000000000001},"relatedVulnerabilities":[{"id":"CVE-2016-9116","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9116","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/93975","https://github.com/uclouvain/openjpeg/issues/859","https://security.gentoo.org/glsa/201710-26"],"description":"NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9116","epss":0.02236,"percentile":0.81763,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9116","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-9116","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-54369","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54369","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54369","epss":0.00153,"percentile":0.04764,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-54369","cwe":"CWE-59","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.11168999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-54369","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","namespace":"nvd:cpe","severity":"High","urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54369","epss":0.00153,"percentile":0.04764,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-54369","cwe":"CWE-59","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"acl","version":"2.3.1-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d047530090108251","name":"libacl1","version":"2.3.1-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"cpes":["cpe:2.3:a:libacl1:libacl1:2.3.1-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libacl1@2.3.1-3?arch=amd64&distro=debian-12.15&upstream=acl","upstreams":[{"name":"acl"}]}},{"vulnerability":{"id":"CVE-2026-47709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47709","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug builds this trips the `ispe && uncC` assertion in `ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan build, the same file causes a null pointer read at address `0xa8`. Version 1.22.0 fixes the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47709","epss":0.00212,"percentile":0.11508,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47709","cwe":"CWE-476","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11130000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-47709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47709","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/issues/1802","https://github.com/strukturag/libheif/pull/1806","https://github.com/strukturag/libheif/security/advisories/GHSA-4h72-vqgp-9376"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug builds this trips the `ispe && uncC` assertion in `ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan build, the same file causes a null pointer read at address `0xa8`. Version 1.22.0 fixes the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47709","epss":0.00212,"percentile":0.11508,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47709","cwe":"CWE-476","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-47709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-84122","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84122","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84122","epss":0.00214,"percentile":0.11671,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84122","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.11127999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-84122","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84122","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2059965","https://www.mozilla.org/security/advisories/mfsa2026-82/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-86/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84122","epss":0.00214,"percentile":0.11671,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84122","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84122","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2016-9117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9117","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[],"epss":[{"cve":"CVE-2016-9117","epss":0.02216,"percentile":0.81597,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9117","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11080000000000001},"relatedVulnerabilities":[{"id":"CVE-2016-9117","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9117","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/93783","https://github.com/uclouvain/openjpeg/issues/860","https://security.gentoo.org/glsa/201710-26"],"description":"NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9117","epss":0.02216,"percentile":0.81597,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9117","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-9117","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-66037","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66037","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66037","epss":0.00211,"percentile":0.11299,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2026-66037","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66037","epss":0.00211,"percentile":0.11299,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66037","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66037","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66037","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66037","epss":0.00211,"percentile":0.11299,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2026-66037","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66037","epss":0.00211,"percentile":0.11299,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66037","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-66037","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66037","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66037","epss":0.00211,"percentile":0.11299,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2026-66037","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-66037","epss":0.00211,"percentile":0.11299,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-66037","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75141","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75141","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75141","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75141","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24088","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-in-hvcc-box-writer-via-hevc-muxing"],"description":"FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75141","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75141","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75142","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75142","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75142","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75142","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75142","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75142","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24087","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-mpeg-ps-muxer-via-mpegenc-c"],"description":"FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75142","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75142","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75142","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75144","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted input is packetized for RTP output.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75144","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75144","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75144","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9b451e01c376398818","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24091","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-in-vc-2-dirac-rtp-packetizer"],"description":"FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted input is packetized for RTP output.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75144","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75144","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75144","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75141","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75141","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75141","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75141","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24088","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-in-hvcc-box-writer-via-hevc-muxing"],"description":"FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75141","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75141","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75142","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75142","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75142","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75142","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75142","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75142","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24087","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-mpeg-ps-muxer-via-mpegenc-c"],"description":"FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75142","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75142","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75142","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75144","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted input is packetized for RTP output.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75144","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75144","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75144","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9b451e01c376398818","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24091","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-in-vc-2-dirac-rtp-packetizer"],"description":"FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted input is packetized for RTP output.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75144","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75144","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75144","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75141","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75141","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75141","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75141","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24088","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-in-hvcc-box-writer-via-hevc-muxing"],"description":"FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75141","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75141","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75142","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75142","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75142","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75142","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75142","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75142","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24087","https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-mpeg-ps-muxer-via-mpegenc-c"],"description":"FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75142","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75142","cwe":"CWE-121","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75142","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-75144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75144","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted input is packetized for RTP output.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75144","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75144","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1096},"relatedVulnerabilities":[{"id":"CVE-2026-75144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75144","namespace":"nvd:cpe","severity":"High","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9b451e01c376398818","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24091","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-in-vc-2-dirac-rtp-packetizer"],"description":"FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted input is packetized for RTP output.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-75144","epss":0.00137,"percentile":0.03448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-75144","cwe":"CWE-122","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-75144","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-72522","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72522","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72522","epss":0.00194,"percentile":0.0917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-72522","cwe":"CWE-125","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.10864000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72522","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72522","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2053153","https://github.com/libexpat/libexpat/pull/1296","http://www.openwall.com/lists/oss-security/2026/08/11/5"],"description":"libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72522","epss":0.00194,"percentile":0.0917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-72522","cwe":"CWE-125","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72522","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-72522","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72522","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72522","epss":0.00194,"percentile":0.0917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-72522","cwe":"CWE-125","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.10864000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72522","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72522","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2053153","https://github.com/libexpat/libexpat/pull/1296","http://www.openwall.com/lists/oss-security/2026/08/11/5"],"description":"libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72522","epss":0.00194,"percentile":0.0917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-72522","cwe":"CWE-125","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72522","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-50257","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50257","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50257","epss":0.00142,"percentile":0.03826,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50257","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50257","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.10863},"relatedVulnerabilities":[{"id":"CVE-2026-50257","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50257","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50257","https://bugzilla.redhat.com/show_bug.cgi?id=2485382","https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50257.json"],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50257","epss":0.00142,"percentile":0.03826,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50257","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50257","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50257","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50257","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50257","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50257","epss":0.00142,"percentile":0.03826,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50257","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50257","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.10863},"relatedVulnerabilities":[{"id":"CVE-2026-50257","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50257","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50257","https://bugzilla.redhat.com/show_bug.cgi?id=2485382","https://gitlab.freedesktop.org/xorg/xserver/-/commit/f5abfb61994471023d8c6470428c8e30c411cc0b","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50257.json"],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50257","epss":0.00142,"percentile":0.03826,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50257","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-50257","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50257","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2019-12383","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-12383","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a \"Don't send my language\" setting.","cvss":[],"epss":[{"cve":"CVE-2019-12383","epss":0.02164,"percentile":0.81147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12383","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1082},"relatedVulnerabilities":[{"id":"CVE-2019-12383","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12383","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/108484","https://gitweb.torproject.org/tor-browser.git/commit/?id=cbb04b72c68272c2de42f157d40cd7d29a6b7b55","https://hackerone.com/reports/282748","https://trac.torproject.org/projects/tor/ticket/24056"],"description":"Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a \"Don't send my language\" setting.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-12383","epss":0.02164,"percentile":0.81147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12383","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-12383","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2016-10505","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-10505","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.","cvss":[],"epss":[{"cve":"CVE-2016-10505","epss":0.02149,"percentile":0.81027,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-10505","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10744999999999999},"relatedVulnerabilities":[{"id":"CVE-2016-10505","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-10505","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/uclouvain/openjpeg/issues/776","https://github.com/uclouvain/openjpeg/issues/784","https://github.com/uclouvain/openjpeg/issues/785","https://github.com/uclouvain/openjpeg/issues/792","https://security.gentoo.org/glsa/201710-26"],"description":"NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-10505","epss":0.02149,"percentile":0.81027,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-10505","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-10505","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-34933","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34933","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10315,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2026-34933","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34933","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/625ca0fac19229f6dfa3a6c6b698ae657187e50c","https://github.com/avahi/avahi/pull/891","https://github.com/avahi/avahi/security/advisories/GHSA-w65r-6gxh-vhvc","http://www.openwall.com/lists/oss-security/2026/04/11/9"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10315,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-34933","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c21957a0053108b1","name":"libavahi-client3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-34933","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34933","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10315,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2026-34933","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34933","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/625ca0fac19229f6dfa3a6c6b698ae657187e50c","https://github.com/avahi/avahi/pull/891","https://github.com/avahi/avahi/security/advisories/GHSA-w65r-6gxh-vhvc","http://www.openwall.com/lists/oss-security/2026/04/11/9"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10315,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-34933","versionConstraint":"none (unknown)"}}],"artifact":{"id":"934d69cf9aa71068","name":"libavahi-common-data","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-34933","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34933","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10315,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2026-34933","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34933","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/625ca0fac19229f6dfa3a6c6b698ae657187e50c","https://github.com/avahi/avahi/pull/891","https://github.com/avahi/avahi/security/advisories/GHSA-w65r-6gxh-vhvc","http://www.openwall.com/lists/oss-security/2026/04/11/9"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-34933","epss":0.00203,"percentile":0.10315,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-34933","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-34933","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d355b05e7a15b748","name":"libavahi-common3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-66382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66382","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66382","epss":0.00203,"percentile":0.10286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2025-66382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66382","epss":0.00203,"percentile":0.10286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-66382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66382","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66382","epss":0.00203,"percentile":0.10286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2025-66382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66382","epss":0.00203,"percentile":0.10286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2016-9115","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9115","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[],"epss":[{"cve":"CVE-2016-9115","epss":0.02128,"percentile":0.80834,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9115","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10640000000000001},"relatedVulnerabilities":[{"id":"CVE-2016-9115","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9115","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/93977","https://github.com/uclouvain/openjpeg/issues/858","https://security.gentoo.org/glsa/201710-26"],"description":"Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9115","epss":0.02128,"percentile":0.80834,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9115","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-9115","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-86140","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86140","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86140","epss":0.00136,"percentile":0.03337,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10540000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-86140","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86140","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86140","epss":0.00136,"percentile":0.03337,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86140","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-47254","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47254","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks.size()`) into `m_presentation_timeline` when the number of chunks defined in the `stco` box is less than the number of samples in `stsz`. A subsequent call to `heif_track_get_next_raw_sequence_sample()` reads `m_chunks[chunk_idx]` with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47254","epss":0.00189,"percentile":0.08582,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47254","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10489499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-47254","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47254","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/security/advisories/GHSA-wqjg-4x9g-6cvg"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks.size()`) into `m_presentation_timeline` when the number of chunks defined in the `stco` box is less than the number of samples in `stsz`. A subsequent call to `heif_track_get_next_raw_sequence_sample()` reads `m_chunks[chunk_idx]` with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47254","epss":0.00189,"percentile":0.08582,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47254","cwe":"CWE-125","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-47254","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-59998","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59998","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59998","epss":0.0018,"percentile":0.07614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1035},"relatedVulnerabilities":[{"id":"CVE-2026-59998","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","namespace":"nvd:cpe","severity":"Medium","urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"exploitabilityScore":2.3,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59998","epss":0.0018,"percentile":0.07614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2026-3446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10339999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-3446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10339999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-3446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10339999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-3446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10339999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-3446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10339999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-3446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10339999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-3446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10339999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-3446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3446","epss":0.00188,"percentile":0.08561,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3fb79a418234f4d0","name":"krb5-locales","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/krb5-locales@1.20.1-2%2Bdeb12u5?arch=all&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9db16cb04ae3b83d","name":"libgssapi-krb5-2","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fb1c9cf5b43a5af0","name":"libk5crypto3","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"52548f50c4ff26c7","name":"libkrb5-3","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2018-5709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10335000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-5709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-5709","epss":0.02067,"percentile":0.80253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"309b5ab55a11c7d0","name":"libkrb5support0","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2020-14145","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-14145","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.","cvss":[],"epss":[{"cve":"CVE-2020-14145","epss":0.02057,"percentile":0.80146,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-14145","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2020-14145","cwe":"CWE-203","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10285000000000001},"relatedVulnerabilities":[{"id":"CVE-2020-14145","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14145","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2020/12/02/1","https://anongit.mindrot.org/openssh.git/commit/?id=b3855ff053f5078ec3d3c653cdaedefaa5fc362d","https://docs.ssh-mitm.at/CVE-2020-14145.html","https://github.com/openssh/openssh-portable/compare/V_8_3_P1...V_8_4_P1","https://github.com/ssh-mitm/ssh-mitm/blob/master/ssh_proxy_server/plugins/session/cve202014145.py","https://security.gentoo.org/glsa/202105-35","https://security.netapp.com/advisory/ntap-20200709-0004/","https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients/"],"description":"The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14145","epss":0.02057,"percentile":0.80146,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-14145","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2020-14145","cwe":"CWE-203","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-14145","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2012-0039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-0039","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.","cvss":[],"epss":[{"cve":"CVE-2012-0039","epss":0.02043,"percentile":0.79999,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2012-0039","cwe":"CWE-310","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10215},"relatedVulnerabilities":[{"id":"CVE-2012-0039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-0039","namespace":"nvd:cpe","severity":"Medium","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044","http://mail.gnome.org/archives/gtk-devel-list/2003-May/msg00111.html","http://openwall.com/lists/oss-security/2012/01/10/12","https://bugzilla.redhat.com/show_bug.cgi?id=772720"],"description":"GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-0039","epss":0.02043,"percentile":0.79999,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2012-0039","cwe":"CWE-310","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2012-0039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2012-0039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-0039","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.","cvss":[],"epss":[{"cve":"CVE-2012-0039","epss":0.02043,"percentile":0.79999,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2012-0039","cwe":"CWE-310","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10215},"relatedVulnerabilities":[{"id":"CVE-2012-0039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-0039","namespace":"nvd:cpe","severity":"Medium","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044","http://mail.gnome.org/archives/gtk-devel-list/2003-May/msg00111.html","http://openwall.com/lists/oss-security/2012/01/10/12","https://bugzilla.redhat.com/show_bug.cgi?id=772720"],"description":"GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-0039","epss":0.02043,"percentile":0.79999,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2012-0039","cwe":"CWE-310","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2012-0039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-56412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56412","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56412","epss":0.00186,"percentile":0.08256,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.10137000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-56412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56412","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1278"],"description":"libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56412","epss":0.00186,"percentile":0.08256,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56412","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56412","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56412","epss":0.00186,"percentile":0.08256,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.10137000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-56412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56412","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1278"],"description":"libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56412","epss":0.00186,"percentile":0.08256,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56412","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-1703","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1703","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1703","epss":0.00405,"percentile":0.34013,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1703","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.10124999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-1703","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1703","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735","https://github.com/pypa/pip/pull/13777","https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ/"],"description":"When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-1703","epss":0.00405,"percentile":0.34013,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-1703","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python-pip","version":"23.0.1+dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-1703","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5929913cf46d2db3","name":"python3-pip","version":"23.0.1+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3-pip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.list"},{"path":"/var/lib/dpkg/info/python3-pip.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.postinst"},{"path":"/var/lib/dpkg/info/python3-pip.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"cpes":["cpe:2.3:a:python3-pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-pip@23.0.1%2Bdfsg-1?arch=all&distro=debian-12.15&upstream=python-pip","upstreams":[{"name":"python-pip"}]}},{"vulnerability":{"id":"CVE-2016-9580","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9580","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.","cvss":[],"epss":[{"cve":"CVE-2016-9580","epss":0.0202,"percentile":0.79772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9580","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9580","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9580","cwe":"CWE-190","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.101},"relatedVulnerabilities":[{"id":"CVE-2016-9580","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9580","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/94822","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9580","https://github.com/szukw000/openjpeg/commit/cadff5fb6e73398de26a92e96d3d7cac893af255","https://github.com/uclouvain/openjpeg/issues/871","https://security.gentoo.org/glsa/201710-26"],"description":"An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9580","epss":0.0202,"percentile":0.79772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9580","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9580","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9580","cwe":"CWE-190","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-9580","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2024-28757","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-28757","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).","cvss":[],"epss":[{"cve":"CVE-2024-28757","epss":0.02006,"percentile":0.79647,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-28757","cwe":"CWE-776","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-28757","cwe":"CWE-776","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10030000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-28757","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28757","namespace":"nvd:cpe","severity":"High","urls":["http://www.openwall.com/lists/oss-security/2024/03/15/1","https://github.com/libexpat/libexpat/issues/839","https://github.com/libexpat/libexpat/pull/842","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/","https://security.netapp.com/advisory/ntap-20240322-0001/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/"],"description":"libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-28757","epss":0.02006,"percentile":0.79647,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-28757","cwe":"CWE-776","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-28757","cwe":"CWE-776","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-28757","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2024-28757","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-28757","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).","cvss":[],"epss":[{"cve":"CVE-2024-28757","epss":0.02006,"percentile":0.79647,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-28757","cwe":"CWE-776","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-28757","cwe":"CWE-776","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10030000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-28757","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28757","namespace":"nvd:cpe","severity":"High","urls":["http://www.openwall.com/lists/oss-security/2024/03/15/1","https://github.com/libexpat/libexpat/issues/839","https://github.com/libexpat/libexpat/pull/842","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/","https://security.netapp.com/advisory/ntap-20240322-0001/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/"],"description":"libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-28757","epss":0.02006,"percentile":0.79647,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-28757","cwe":"CWE-776","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-28757","cwe":"CWE-776","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-28757","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-39316","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-39316","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are automatically deleted. cupsdDeleteTemporaryPrinters() in scheduler/printers.c calls cupsdDeletePrinter() without first expiring subscriptions that reference the printer, leaving cupsd_subscription_t.dest as a dangling pointer to freed heap memory. The dangling pointer is subsequently dereferenced at multiple code sites, causing a crash (denial of service) of the cupsd daemon. With heap grooming, this can be leveraged for code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39316","epss":0.00178,"percentile":0.07419,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-39316","cwe":"CWE-416","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09967999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-39316","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39316","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rg"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are automatically deleted. cupsdDeleteTemporaryPrinters() in scheduler/printers.c calls cupsdDeletePrinter() without first expiring subscriptions that reference the printer, leaving cupsd_subscription_t.dest as a dangling pointer to freed heap memory. The dangling pointer is subsequently dereferenced at multiple code sites, causing a crash (denial of service) of the cupsd daemon. With heap grooming, this can be leveraged for code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39316","epss":0.00178,"percentile":0.07419,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-39316","cwe":"CWE-416","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-39316","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2026-50219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50219","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50219","epss":0.00181,"percentile":0.07788,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50219","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.09864500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50219","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1246"],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50219","epss":0.00181,"percentile":0.07788,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50219","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50219","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-50219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50219","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50219","epss":0.00181,"percentile":0.07788,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50219","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.09864500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50219","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1246"],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50219","epss":0.00181,"percentile":0.07788,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50219","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50219","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2016-9581","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9581","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.","cvss":[],"epss":[{"cve":"CVE-2016-9581","epss":0.01969,"percentile":0.792,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9581","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9581","cwe":"CWE-835","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9581","cwe":"CWE-119","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09845},"relatedVulnerabilities":[{"id":"CVE-2016-9581","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9581","namespace":"nvd:cpe","severity":"High","urls":["http://www.securityfocus.com/bid/94822","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9581","https://github.com/szukw000/openjpeg/commit/cadff5fb6e73398de26a92e96d3d7cac893af255","https://github.com/uclouvain/openjpeg/issues/872","https://security.gentoo.org/glsa/201710-26"],"description":"An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-9581","epss":0.01969,"percentile":0.792,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-9581","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9581","cwe":"CWE-835","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2016-9581","cwe":"CWE-119","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjpeg2","version":"2.5.0-2+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-9581","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b280459d31091296","name":"libopenjp2-7","version":"2.5.0-2+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libopenjp2-7@2.5.0-2%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=openjpeg2","upstreams":[{"name":"openjpeg2"}]}},{"vulnerability":{"id":"CVE-2026-39113","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-39113","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int64(), sqlite3_malloc(int), uncompress() components","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39113","epss":0.00211,"percentile":0.11326,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-39113","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09494999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-39113","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39113","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/20000419/CVE-2026-39113","https://github.com/sqlite/sqlite/blob/169f68ed88b34cb68f720191c64c058f2ccec508/ext/misc/sqlar.c","https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508","https://www.sqlite.org/","https://www.sqlite.org/sqlar.html"],"description":"Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int64(), sqlite3_malloc(int), uncompress() components","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39113","epss":0.00211,"percentile":0.11326,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-39113","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-39113","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"CVE-2023-22656","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-22656","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.9,"exploitabilityScore":1.4,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-22656","epss":0.00275,"percentile":0.19712,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-22656","cwe":"CWE-125","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-22656","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09487499999999999},"relatedVulnerabilities":[{"id":"CVE-2023-22656","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-22656","namespace":"nvd:cpe","severity":"Low","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html"],"description":"Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.9,"exploitabilityScore":1.4,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-22656","epss":0.00275,"percentile":0.19712,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-22656","cwe":"CWE-125","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-22656","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-22656","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c185e9c791136aa6","name":"dirmngr","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:dirmngr:dirmngr:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dirmngr@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e92d6b046326efbc","name":"gnupg","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg:gnupg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"976c5c43a7fe516a","name":"gnupg-l10n","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-l10n@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4d2b57169c4709a4","name":"gnupg-utils","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-utils@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1b50350895a48a3b","name":"gpg","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg:gpg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"01ceda49a85ecdc9","name":"gpg-agent","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-agent@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2ce7ba29a10f5f2d","name":"gpg-wks-client","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-wks-client@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5c929b5e7563826e","name":"gpg-wks-server","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-server/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-wks-server/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-server.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-server.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-wks-server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-wks-server@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"45da524630bb2133","name":"gpgconf","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgconf:gpgconf:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgconf@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b982b129e67b17ad","name":"gpgsm","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgsm:gpgsm:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgsm@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-30258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2025-30258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","namespace":"nvd:cpe","severity":"Medium","urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-30258","epss":0.00192,"percentile":0.08971,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bab4532a87a829c8","name":"gpgv","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-18090","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18090","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.","cvss":[{"source":"secalert@redhat.com","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18090","epss":0.00167,"percentile":0.06252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18090","cwe":"CWE-125","source":"secalert@redhat.com","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09268499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-18090","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18090","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-18090","https://bugzilla.redhat.com/show_bug.cgi?id=2517751","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/308"],"description":"A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.","cvss":[{"source":"secalert@redhat.com","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18090","epss":0.00167,"percentile":0.06252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18090","cwe":"CWE-125","source":"secalert@redhat.com","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18090","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e384004f37f8d5e","name":"libgdk-pixbuf-2.0-0","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf-2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf-2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf-2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf-2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf-2.0-0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0-0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0_0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0_0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf-2.0-0@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2026-18090","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18090","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.","cvss":[{"source":"secalert@redhat.com","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18090","epss":0.00167,"percentile":0.06252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18090","cwe":"CWE-125","source":"secalert@redhat.com","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09268499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-18090","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18090","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-18090","https://bugzilla.redhat.com/show_bug.cgi?id=2517751","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/308"],"description":"A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.","cvss":[{"source":"secalert@redhat.com","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18090","epss":0.00167,"percentile":0.06252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18090","cwe":"CWE-125","source":"secalert@redhat.com","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18090","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b205c783e97c36c6","name":"libgdk-pixbuf2.0-bin","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf2.0-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.list"}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf2.0-bin:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0-bin:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_bin:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_bin:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf2.0-bin@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2026-18090","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18090","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.","cvss":[{"source":"secalert@redhat.com","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18090","epss":0.00167,"percentile":0.06252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18090","cwe":"CWE-125","source":"secalert@redhat.com","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09268499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-18090","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18090","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-18090","https://bugzilla.redhat.com/show_bug.cgi?id=2517751","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/308"],"description":"A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.","cvss":[{"source":"secalert@redhat.com","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18090","epss":0.00167,"percentile":0.06252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18090","cwe":"CWE-125","source":"secalert@redhat.com","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18090","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5a58bb7174f44032","name":"libgdk-pixbuf2.0-common","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf2.0-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf2.0-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.list"}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf2.0-common:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0-common:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_common:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_common:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf2.0-common@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=all&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2022-1210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-1210","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2022-1210","epss":0.01851,"percentile":0.77847,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-1210","cwe":"CWE-400","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2022-1210","cwe":"CWE-404","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09255},"relatedVulnerabilities":[{"id":"CVE-2022-1210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1210","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.com/libtiff/libtiff/-/issues/402","https://gitlab.com/libtiff/libtiff/uploads/c3da94e53cf1e1e8e6d4d3780dc8c42f/example.tiff","https://security.gentoo.org/glsa/202210-10","https://security.netapp.com/advisory/ntap-20220513-0005/","https://vuldb.com/?id.196363"],"description":"A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-1210","epss":0.01851,"percentile":0.77847,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-1210","cwe":"CWE-400","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2022-1210","cwe":"CWE-404","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-1210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-6879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09225},"relatedVulnerabilities":[{"id":"CVE-2026-6879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09225},"relatedVulnerabilities":[{"id":"CVE-2026-6879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09225},"relatedVulnerabilities":[{"id":"CVE-2026-6879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09225},"relatedVulnerabilities":[{"id":"CVE-2026-6879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09225},"relatedVulnerabilities":[{"id":"CVE-2026-6879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09225},"relatedVulnerabilities":[{"id":"CVE-2026-6879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-6879","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09225},"relatedVulnerabilities":[{"id":"CVE-2026-6879","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6879","epss":0.00369,"percentile":0.30134,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2018-10126","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10126","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.","cvss":[],"epss":[{"cve":"CVE-2018-10126","epss":0.01841,"percentile":0.77712,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09204999999999999},"relatedVulnerabilities":[{"id":"CVE-2018-10126","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10126","namespace":"nvd:cpe","severity":"Medium","urls":["http://bugzilla.maptools.org/show_bug.cgi?id=2786","https://gitlab.com/libtiff/libtiff/-/issues/128","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-10126","epss":0.01841,"percentile":0.77712,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-10126","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-59529","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00175,"percentile":0.07123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09187500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-59529","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00175,"percentile":0.07123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c21957a0053108b1","name":"libavahi-client3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-59529","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00175,"percentile":0.07123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09187500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-59529","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00175,"percentile":0.07123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"}}],"artifact":{"id":"934d69cf9aa71068","name":"libavahi-common-data","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-59529","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00175,"percentile":0.07123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09187500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-59529","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59529","epss":0.00175,"percentile":0.07123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d355b05e7a15b748","name":"libavahi-common3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-59997","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59997","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59997","epss":0.00175,"percentile":0.07078,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.091},"relatedVulnerabilities":[{"id":"CVE-2026-59997","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","namespace":"nvd:cpe","severity":"Medium","urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"exploitabilityScore":1.7,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-59997","epss":0.00175,"percentile":0.07078,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2025-10911","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10911","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10911","epss":0.00173,"percentile":0.06828,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-10911","cwe":"CWE-825","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.090825},"relatedVulnerabilities":[{"id":"CVE-2025-10911","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10911","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:11015","https://access.redhat.com/errata/RHSA-2026:26355","https://access.redhat.com/errata/RHSA-2026:28243","https://access.redhat.com/errata/RHSA-2026:28584","https://access.redhat.com/errata/RHSA-2026:29807","https://access.redhat.com/errata/RHSA-2026:29809","https://access.redhat.com/errata/RHSA-2026:29811","https://access.redhat.com/errata/RHSA-2026:29814","https://access.redhat.com/errata/RHSA-2026:29975","https://access.redhat.com/errata/RHSA-2026:29976","https://access.redhat.com/errata/RHSA-2026:30847","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2025-10911","https://bugzilla.redhat.com/show_bug.cgi?id=2397838","https://gitlab.gnome.org/GNOME/libxslt/-/issues/144","https://gitlab.gnome.org/GNOME/libxslt/-/merge_requests/77"],"description":"A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10911","epss":0.00173,"percentile":0.06828,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-10911","cwe":"CWE-825","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxslt","version":"1.1.35-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-10911","versionConstraint":"none (unknown)"}}],"artifact":{"id":"127f2ae91adc51ae","name":"libxslt1.1","version":"1.1.35-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxslt1.1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxslt1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:4b82c8dd6e55001a5921bea1d6db20be5c51e5976d892e870324026c23f37b6f"],"cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.35-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxslt1.1@1.1.35-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=libxslt","upstreams":[{"name":"libxslt"}]}},{"vulnerability":{"id":"CVE-2026-41991","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41991","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.  This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41991","epss":0.00186,"percentile":0.08314,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09021000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-41991","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41991","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269","https://www.gnu.org/software/gzip/"],"description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-41991","epss":0.00186,"percentile":0.08314,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gzip","version":"1.12-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-41991","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aa527ab8cb576b14","name":"gzip","version":"1.12-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gzip.list"}],"language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"cpes":["cpe:2.3:a:gzip:gzip:1.12-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gzip@1.12-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-56131","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56131","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56131","epss":0.00182,"percentile":0.07884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.09008999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-56131","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56131","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1267"],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56131","epss":0.00182,"percentile":0.07884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56131","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56131","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56131","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56131","epss":0.00182,"percentile":0.07884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.09008999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-56131","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56131","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1267"],"description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56131","epss":0.00182,"percentile":0.07884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56131","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-78409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-78409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78409","epss":0.00124,"percentile":0.02421,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-32778","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32778","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32778","epss":0.00171,"percentile":0.06643,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.089775},"relatedVulnerabilities":[{"id":"CVE-2026-32778","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32778","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1163","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32778","epss":0.00171,"percentile":0.06643,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32778","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-32778","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32778","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32778","epss":0.00171,"percentile":0.06643,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.089775},"relatedVulnerabilities":[{"id":"CVE-2026-32778","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32778","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1163","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32778","epss":0.00171,"percentile":0.06643,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32778","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-6141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00183,"percentile":0.07962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08967},"relatedVulnerabilities":[{"id":"CVE-2025-6141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","namespace":"nvd:cpe","severity":"Medium","urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00183,"percentile":0.07962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3a2ba7a41a0529","name":"libncursesw6","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-6141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00183,"percentile":0.07962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08967},"relatedVulnerabilities":[{"id":"CVE-2025-6141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","namespace":"nvd:cpe","severity":"Medium","urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00183,"percentile":0.07962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6231fb14cfeaaac","name":"libtinfo6","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-6141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00183,"percentile":0.07962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08967},"relatedVulnerabilities":[{"id":"CVE-2025-6141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","namespace":"nvd:cpe","severity":"Medium","urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00183,"percentile":0.07962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec73073218fd031a","name":"ncurses-base","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2025-6141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00183,"percentile":0.07962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08967},"relatedVulnerabilities":[{"id":"CVE-2025-6141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","namespace":"nvd:cpe","severity":"Medium","urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-6141","epss":0.00183,"percentile":0.07962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-6141","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c5b18ac268f2ccdf","name":"ncurses-bin","version":"6.4-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","upstreams":[{"name":"ncurses"}]}},{"vulnerability":{"id":"CVE-2026-15146","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15146","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15146","epss":0.00164,"percentile":0.05947,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08938},"relatedVulnerabilities":[{"id":"CVE-2026-15146","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15146","namespace":"nvd:cpe","severity":"Medium","urls":["https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b","https://kb.cert.org/vuls/id/564823","https://www.kb.cert.org/vuls/id/564823"],"description":"GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"exploitabilityScore":2.6,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15146","epss":0.00164,"percentile":0.05947,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15146","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ef5a5a7d880f3e73","name":"wget","version":"1.21.3-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.list"}],"language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-60589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60589","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60589","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60589","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.08877499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-60589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60589","namespace":"nvd:cpe","severity":"Low","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60589","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60589","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-60589","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"945387ec24991974","name":"openjdk-17-jdk","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jdk/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jdk:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jdk:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jdk:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jdk@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-60589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60589","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60589","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60589","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.08877499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-60589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60589","namespace":"nvd:cpe","severity":"Low","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60589","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60589","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-60589","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"8fadba790d3a033a","name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jdk-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jdk-headless:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jdk-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jdk-headless:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk-headless:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk_headless:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk_headless:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jdk-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jdk_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jdk-headless@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-60589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60589","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60589","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60589","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.08877499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-60589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60589","namespace":"nvd:cpe","severity":"Low","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60589","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60589","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-60589","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"a3f55d1528694a0b","name":"openjdk-17-jre","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jre/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jre:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jre:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jre@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-60589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60589","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60589","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60589","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["17.0.20.1+1-1~deb12u1"],"state":"fixed","available":[{"version":"17.0.20.1+1-1~deb12u1","date":"2026-08-27","kind":"first-observed"}]},"advisories":[],"risk":0.08877499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-60589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60589","namespace":"nvd:cpe","severity":"Low","urls":["https://www.oracle.com/security-alerts/cspuaug2026.html","https://openjdk.org/groups/vulnerability/advisories/2026-08-18"],"description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","cvss":[{"source":"secalert_us@oracle.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-60589","epss":0.00265,"percentile":0.18345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-60589","cwe":"CWE-200","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openjdk-17","version":"17.0.20+8-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-60589","versionConstraint":"< 17.0.20.1+1-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"17.0.20.1+1-1~deb12u1"}}],"artifact":{"id":"a98c024490217f82","name":"openjdk-17-jre-headless","version":"17.0.20+8-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openjdk-17-jre-headless/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openjdk-17-jre-headless/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openjdk-17-jre-headless:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-C3","GPL-2","LGPL","MIT"],"cpes":["cpe:2.3:a:openjdk-17-jre-headless:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre-headless:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre_headless:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre_headless:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17-jre:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17_jre:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk-17:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk_17:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk-17-jre-headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:openjdk:openjdk_17_jre_headless:17.0.20\\+8-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openjdk-17-jre-headless@17.0.20%2B8-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openjdk-17","upstreams":[{"name":"openjdk-17"}]}},{"vulnerability":{"id":"CVE-2026-84124","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84124","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84124","epss":0.0017,"percentile":0.06623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84124","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.15.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.15.0esr-1~deb12u1","date":"2026-09-05","kind":"first-observed"}]},"advisories":[],"risk":0.0884},"relatedVulnerabilities":[{"id":"CVE-2026-84124","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84124","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2061110","https://www.mozilla.org/security/advisories/mfsa2026-82/","https://www.mozilla.org/security/advisories/mfsa2026-84/","https://www.mozilla.org/security/advisories/mfsa2026-85/","https://www.mozilla.org/security/advisories/mfsa2026-86/","https://www.mozilla.org/security/advisories/mfsa2026-87/","https://www.mozilla.org/security/advisories/mfsa2026-88/"],"description":"Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-84124","epss":0.0017,"percentile":0.06623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-84124","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84124","versionConstraint":"< 140.15.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.15.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-6829","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6829","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.","cvss":[],"epss":[{"cve":"CVE-2018-6829","epss":0.01762,"percentile":0.76679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08810000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-6829","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6829","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/weikengchen/attack-on-libgcrypt-elgamal","https://github.com/weikengchen/attack-on-libgcrypt-elgamal/wiki","https://lists.gnupg.org/pipermail/gcrypt-devel/2018-February/004394.html","https://www.oracle.com/security-alerts/cpujan2020.html"],"description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-6829","epss":0.01762,"percentile":0.76679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libgcrypt20","version":"1.10.1-3+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-6829","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df01c68aff59530a","name":"libgcrypt20","version":"1.10.1-3+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:95db2f9da663f2bfe2aabe9c72fce9d6c9ae767b912f397d7823f50bd55a1a7d"],"cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgcrypt20@1.10.1-3%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-31486","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31486","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.","cvss":[],"epss":[{"cve":"CVE-2023-31486","epss":0.01742,"percentile":0.76393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08710000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-31486","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31486","namespace":"nvd:cpe","severity":"High","urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/chansen/p5-http-tiny/pull/153","https://hackeriet.github.io/cpan-http-tiny-overview/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://www.openwall.com/lists/oss-security/2023/05/03/4","https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/","https://security.netapp.com/advisory/ntap-20241129-0011/"],"description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31486","epss":0.01742,"percentile":0.76393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31486","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2023-31486","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31486","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.","cvss":[],"epss":[{"cve":"CVE-2023-31486","epss":0.01742,"percentile":0.76393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08710000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-31486","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31486","namespace":"nvd:cpe","severity":"High","urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/chansen/p5-http-tiny/pull/153","https://hackeriet.github.io/cpan-http-tiny-overview/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://www.openwall.com/lists/oss-security/2023/05/03/4","https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/","https://security.netapp.com/advisory/ntap-20241129-0011/"],"description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31486","epss":0.01742,"percentile":0.76393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31486","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-31486","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31486","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.","cvss":[],"epss":[{"cve":"CVE-2023-31486","epss":0.01742,"percentile":0.76393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08710000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-31486","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31486","namespace":"nvd:cpe","severity":"High","urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/chansen/p5-http-tiny/pull/153","https://hackeriet.github.io/cpan-http-tiny-overview/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://www.openwall.com/lists/oss-security/2023/05/03/4","https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/","https://security.netapp.com/advisory/ntap-20241129-0011/"],"description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31486","epss":0.01742,"percentile":0.76393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31486","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2023-31486","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31486","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.","cvss":[],"epss":[{"cve":"CVE-2023-31486","epss":0.01742,"percentile":0.76393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08710000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-31486","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31486","namespace":"nvd:cpe","severity":"High","urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/chansen/p5-http-tiny/pull/153","https://hackeriet.github.io/cpan-http-tiny-overview/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://www.openwall.com/lists/oss-security/2023/05/03/4","https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/","https://security.netapp.com/advisory/ntap-20241129-0011/"],"description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31486","epss":0.01742,"percentile":0.76393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31486","cwe":"CWE-295","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31486","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-78408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08700999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-78408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"exploitabilityScore":1.5,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78408","epss":0.00113,"percentile":0.0158,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-25068","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-25068","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25068","epss":0.00181,"percentile":0.07835,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-25068","cwe":"CWE-129","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08688},"relatedVulnerabilities":[{"id":"CVE-2026-25068","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25068","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40","https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow","https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"],"description":"alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25068","epss":0.00181,"percentile":0.07835,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-25068","cwe":"CWE-129","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"alsa-lib","version":"1.2.8-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-25068","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8c2bbfcb9ac36bec","name":"libasound2","version":"1.2.8-1+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasound2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libasound2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasound2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libasound2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["LGPL-2.1","LPGL-2.1+"],"cpes":["cpe:2.3:a:libasound2:libasound2:1.2.8-1\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libasound2@1.2.8-1%2Bb1?arch=amd64&distro=debian-12.15&upstream=alsa-lib%401.2.8-1","upstreams":[{"name":"alsa-lib","version":"1.2.8-1"}]}},{"vulnerability":{"id":"CVE-2026-25068","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-25068","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25068","epss":0.00181,"percentile":0.07835,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-25068","cwe":"CWE-129","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08688},"relatedVulnerabilities":[{"id":"CVE-2026-25068","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25068","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40","https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow","https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"],"description":"alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-25068","epss":0.00181,"percentile":0.07835,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-25068","cwe":"CWE-129","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"alsa-lib","version":"1.2.8-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-25068","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9395795765e6df6","name":"libasound2-data","version":"1.2.8-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasound2-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libasound2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasound2-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libasound2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasound2-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libasound2-data.list"}],"language":"","licenses":["LGPL-2.1","LPGL-2.1+"],"cpes":["cpe:2.3:a:libasound2-data:libasound2-data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2-data:libasound2_data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2_data:libasound2-data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2_data:libasound2_data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2:libasound2-data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2:libasound2_data:1.2.8-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libasound2-data@1.2.8-1?arch=all&distro=debian-12.15&upstream=alsa-lib","upstreams":[{"name":"alsa-lib"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-13595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08652000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13595","epss":0.00168,"percentile":0.06354,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-39314","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-39314","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local user to crash the cupsd root process by supplying a negative job-password-supported IPP attribute. The bounds check only caps the upper bound, so a negative value passes validation, is cast to size_t (wrapping to ~2^64), and is used as the length argument to memset() on a 33-byte stack buffer. This causes an immediate SIGSEGV in the cupsd root process. Combined with systemd's Restart=on-failure, an attacker can repeat the crash for sustained denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39314","epss":0.00154,"percentile":0.04849,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-39314","cwe":"CWE-191","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08624},"relatedVulnerabilities":[{"id":"CVE-2026-39314","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39314","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-pp8w-2g52-7vj7"],"description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local user to crash the cupsd root process by supplying a negative job-password-supported IPP attribute. The bounds check only caps the upper bound, so a negative value passes validation, is cast to size_t (wrapping to ~2^64), and is used as the length argument to memset() on a 33-byte stack buffer. This causes an immediate SIGSEGV in the cupsd root process. Combined with systemd's Restart=on-failure, an attacker can repeat the crash for sustained denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39314","epss":0.00154,"percentile":0.04849,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-39314","cwe":"CWE-191","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-39314","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2026-15534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":1.5,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15534","epss":0.00161,"percentile":0.0565,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-787","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.086135},"relatedVulnerabilities":[{"id":"CVE-2026-15534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":1.5,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15534","epss":0.00161,"percentile":0.0565,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-787","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-15534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":1.5,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15534","epss":0.00161,"percentile":0.0565,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-787","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.086135},"relatedVulnerabilities":[{"id":"CVE-2026-15534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":1.5,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15534","epss":0.00161,"percentile":0.0565,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-787","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-15534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":1.5,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15534","epss":0.00161,"percentile":0.0565,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-787","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.086135},"relatedVulnerabilities":[{"id":"CVE-2026-15534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":1.5,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15534","epss":0.00161,"percentile":0.0565,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-787","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-15534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":1.5,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15534","epss":0.00161,"percentile":0.0565,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-787","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.086135},"relatedVulnerabilities":[{"id":"CVE-2026-15534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":1.5,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15534","epss":0.00161,"percentile":0.0565,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-190","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"},{"cve":"CVE-2026-15534","cwe":"CWE-787","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-32776","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32776","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32776","epss":0.00164,"percentile":0.05916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0861},"relatedVulnerabilities":[{"id":"CVE-2026-32776","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32776","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1158","https://github.com/libexpat/libexpat/pull/1159","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32776","epss":0.00164,"percentile":0.05916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32776","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-32776","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32776","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32776","epss":0.00164,"percentile":0.05916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0861},"relatedVulnerabilities":[{"id":"CVE-2026-32776","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32776","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1158","https://github.com/libexpat/libexpat/pull/1159","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-32776","epss":0.00164,"percentile":0.05916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-32776","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2021-40633","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-40633","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.","cvss":[],"epss":[{"cve":"CVE-2021-40633","epss":0.01717,"percentile":0.76065,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-40633","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08585000000000001},"relatedVulnerabilities":[{"id":"CVE-2021-40633","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-40633","namespace":"nvd:cpe","severity":"High","urls":["https://sourceforge.net/p/giflib/bugs/157/"],"description":"A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-40633","epss":0.01717,"percentile":0.76065,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-40633","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"giflib","version":"5.2.1-2.5+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-40633","versionConstraint":"none (unknown)"}}],"artifact":{"id":"71a582f5b3d629e1","name":"libgif7","version":"5.2.1-2.5+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgif7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgif7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgif7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgif7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT"],"cpes":["cpe:2.3:a:libgif7:libgif7:5.2.1-2.5\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgif7@5.2.1-2.5%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=giflib","upstreams":[{"name":"giflib"}]}},{"vulnerability":{"id":"CVE-2024-2379","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-2379","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.","cvss":[],"epss":[{"cve":"CVE-2024-2379","epss":0.01709,"percentile":0.75959,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2379","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08545000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-2379","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2379","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://www.openwall.com/lists/oss-security/2024/03/27/2","https://curl.se/docs/CVE-2024-2379.html","https://curl.se/docs/CVE-2024-2379.json","https://hackerone.com/reports/2410774","https://security.netapp.com/advisory/ntap-20240531-0001/","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120"],"description":"libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"exploitabilityScore":2.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-2379","epss":0.01709,"percentile":0.75959,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2379","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-2379","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2024-2379","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-2379","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.","cvss":[],"epss":[{"cve":"CVE-2024-2379","epss":0.01709,"percentile":0.75959,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2379","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08545000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-2379","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2379","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://www.openwall.com/lists/oss-security/2024/03/27/2","https://curl.se/docs/CVE-2024-2379.html","https://curl.se/docs/CVE-2024-2379.json","https://hackerone.com/reports/2410774","https://security.netapp.com/advisory/ntap-20240531-0001/","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120"],"description":"libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"exploitabilityScore":2.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-2379","epss":0.01709,"percentile":0.75959,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2379","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-2379","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2024-2379","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-2379","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.","cvss":[],"epss":[{"cve":"CVE-2024-2379","epss":0.01709,"percentile":0.75959,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2379","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08545000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-2379","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2379","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://www.openwall.com/lists/oss-security/2024/03/27/2","https://curl.se/docs/CVE-2024-2379.html","https://curl.se/docs/CVE-2024-2379.json","https://hackerone.com/reports/2410774","https://security.netapp.com/advisory/ntap-20240531-0001/","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120"],"description":"libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"exploitabilityScore":2.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-2379","epss":0.01709,"percentile":0.75959,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2379","cwe":"CWE-295","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-2379","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-86144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86144","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":1.5,"impactScore":3.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86144","epss":0.00161,"percentile":0.05648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08533},"relatedVulnerabilities":[{"id":"CVE-2026-86144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86144","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":1.5,"impactScore":3.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86144","epss":0.00161,"percentile":0.05648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86144","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-15310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08415},"relatedVulnerabilities":[{"id":"CVE-2026-15310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08415},"relatedVulnerabilities":[{"id":"CVE-2026-15310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08415},"relatedVulnerabilities":[{"id":"CVE-2026-15310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08415},"relatedVulnerabilities":[{"id":"CVE-2026-15310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08415},"relatedVulnerabilities":[{"id":"CVE-2026-15310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-15310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08415},"relatedVulnerabilities":[{"id":"CVE-2026-15310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-15310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08415},"relatedVulnerabilities":[{"id":"CVE-2026-15310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15310","epss":0.0033,"percentile":0.25912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-50812","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50812","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50812","epss":0.0016,"percentile":0.05505,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-50812","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50812","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91","https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d","https://sqlite.org/src/info/e807d4e3798efd53"],"description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50812","epss":0.0016,"percentile":0.05505,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50812","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"CVE-2026-50813","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50813","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50813","epss":0.00159,"percentile":0.05356,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50813","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08347500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50813","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50813","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/junius-sec/f8acb66bafb80134c8e1a1c8c7c9f4f4","https://github.com/sqlite/sqlite/commit/c597ed79d1bd03f57198d10d1f431adda293cf2e","https://sqlite.org/src/info/869a51ae84df"],"description":"An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50813","epss":0.00159,"percentile":0.05356,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50813","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50813","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"CVE-2026-56403","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56403","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in storeAtts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56403","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56403","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.0833},"relatedVulnerabilities":[{"id":"CVE-2026-56403","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56403","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1232"],"description":"libexpat before 2.8.2 has an integer overflow in storeAtts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56403","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56403","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56403","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56404","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56404","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in addBinding.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56404","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.0833},"relatedVulnerabilities":[{"id":"CVE-2026-56404","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56404","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1249"],"description":"libexpat before 2.8.2 has an integer overflow in addBinding.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56404","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56404","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56405","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56405","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in getAttributeId.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56405","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.0833},"relatedVulnerabilities":[{"id":"CVE-2026-56405","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56405","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1251"],"description":"libexpat before 2.8.2 has an integer overflow in getAttributeId.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56405","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56405","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56408","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in copyString.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56408","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56408","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.0833},"relatedVulnerabilities":[{"id":"CVE-2026-56408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56408","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817"],"description":"libexpat before 2.8.2 has an integer overflow in copyString.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56408","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56408","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56408","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56403","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56403","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in storeAtts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56403","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56403","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.0833},"relatedVulnerabilities":[{"id":"CVE-2026-56403","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56403","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1232"],"description":"libexpat before 2.8.2 has an integer overflow in storeAtts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56403","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56403","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56403","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56404","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56404","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in addBinding.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56404","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.0833},"relatedVulnerabilities":[{"id":"CVE-2026-56404","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56404","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1249"],"description":"libexpat before 2.8.2 has an integer overflow in addBinding.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56404","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56404","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56405","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56405","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in getAttributeId.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56405","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.0833},"relatedVulnerabilities":[{"id":"CVE-2026-56405","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56405","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1251"],"description":"libexpat before 2.8.2 has an integer overflow in getAttributeId.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56405","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56405","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56408","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in copyString.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56408","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56408","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.0833},"relatedVulnerabilities":[{"id":"CVE-2026-56408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56408","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817"],"description":"libexpat before 2.8.2 has an integer overflow in copyString.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56408","epss":0.0014,"percentile":0.03679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56408","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56408","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-68276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.00158,"percentile":0.05342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08295000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-68276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688","https://github.com/avahi/avahi/pull/806","https://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling\nthe RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.00158,"percentile":0.05342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c21957a0053108b1","name":"libavahi-client3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-client3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.00158,"percentile":0.05342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08295000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-68276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688","https://github.com/avahi/avahi/pull/806","https://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling\nthe RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.00158,"percentile":0.05342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"934d69cf9aa71068","name":"libavahi-common-data","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common-data@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2025-68276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.00158,"percentile":0.05342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08295000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-68276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68276","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688","https://github.com/avahi/avahi/pull/806","https://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc"],"description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling\nthe RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68276","epss":0.00158,"percentile":0.05342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68276","cwe":"CWE-617","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"avahi","version":"0.8-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d355b05e7a15b748","name":"libavahi-common3","version":"0.8-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavahi-common3@0.8-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=avahi","upstreams":[{"name":"avahi"}]}},{"vulnerability":{"id":"CVE-2026-13757","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13757","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13757","epss":0.00148,"percentile":0.04341,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08288000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-13757","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/errata/RHSA-2026:49667","https://access.redhat.com/errata/RHSA-2026:49668","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-13757","epss":0.00148,"percentile":0.04341,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"p11-kit","version":"0.24.1-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0027543880aaec84","name":"libp11-kit0","version":"0.24.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-Clause","ISC","ISC+IBM","LGPL-2.1","LGPL-2.1+","permissive-like-automake-output","same-as-rest-of-p11kit"],"cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libp11-kit0@0.24.1-2?arch=amd64&distro=debian-12.15&upstream=p11-kit","upstreams":[{"name":"p11-kit"}]}},{"vulnerability":{"id":"CVE-2026-56407","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56407","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56407","epss":0.00139,"percentile":0.03601,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.082705},"relatedVulnerabilities":[{"id":"CVE-2026-56407","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56407","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1262"],"description":"libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56407","epss":0.00139,"percentile":0.03601,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56407","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56407","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56407","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56407","epss":0.00139,"percentile":0.03601,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.082705},"relatedVulnerabilities":[{"id":"CVE-2026-56407","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56407","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1262"],"description":"libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56407","epss":0.00139,"percentile":0.03601,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56407","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56406","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56406","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56406","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.082705},"relatedVulnerabilities":[{"id":"CVE-2026-56406","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56406","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1255"],"description":"libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56406","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56406","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56410","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56410","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56410","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.082705},"relatedVulnerabilities":[{"id":"CVE-2026-56410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56410","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1252"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56410","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56410","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56410","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56411","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56411","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56411","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.082705},"relatedVulnerabilities":[{"id":"CVE-2026-56411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56411","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1263"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56411","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56411","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56411","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56406","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56406","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56406","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.082705},"relatedVulnerabilities":[{"id":"CVE-2026-56406","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56406","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1255"],"description":"libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56406","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56406","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56410","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56410","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56410","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.082705},"relatedVulnerabilities":[{"id":"CVE-2026-56410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56410","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1252"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56410","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56410","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56410","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56411","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56411","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56411","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.082705},"relatedVulnerabilities":[{"id":"CVE-2026-56411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56411","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1263"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56411","epss":0.00139,"percentile":0.036,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56411","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56411","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2023-47282","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-47282","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Out-of-bounds write in Intel(R) Media SDK all versions and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"exploitabilityScore":1.4,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-47282","epss":0.00238,"percentile":0.14832,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-47282","cwe":"CWE-787","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-47282","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08210999999999999},"relatedVulnerabilities":[{"id":"CVE-2023-47282","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-47282","namespace":"nvd:cpe","severity":"Low","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html"],"description":"Out-of-bounds write in Intel(R) Media SDK all versions and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"exploitabilityScore":1.4,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-47282","epss":0.00238,"percentile":0.14832,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-47282","cwe":"CWE-787","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-47282","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-47282","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2021-35331","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-35331","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding","cvss":[],"epss":[{"cve":"CVE-2021-35331","epss":0.01639,"percentile":0.74933,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-35331","cwe":"CWE-134","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08195},"relatedVulnerabilities":[{"id":"CVE-2021-35331","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35331","namespace":"nvd:cpe","severity":"High","urls":["https://core.tcl-lang.org/tcl/info/28ef6c0c741408a2","https://core.tcl-lang.org/tcl/info/bad6cc213dfe8280","https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222","https://sqlite.org/forum/info/7dcd751996c93ec9"],"description":"In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35331","epss":0.01639,"percentile":0.74933,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-35331","cwe":"CWE-134","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tcl8.6","version":"8.6.13+dfsg-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-35331","versionConstraint":"none (unknown)"}}],"artifact":{"id":"033488132d11e065","name":"libtcl8.6","version":"8.6.13+dfsg-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtcl8.6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtcl8.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtcl8.6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtcl8.6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:e925aa8863f0c9eda3625ce2cb16c0d5017fca248c5bd6af97006df5d9c6199c"],"cpes":["cpe:2.3:a:libtcl8.6:libtcl8.6:8.6.13\\+dfsg-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtcl8.6@8.6.13%2Bdfsg-2?arch=amd64&distro=debian-12.15&upstream=tcl8.6","upstreams":[{"name":"tcl8.6"}]}},{"vulnerability":{"id":"CVE-2021-35331","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-35331","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding","cvss":[],"epss":[{"cve":"CVE-2021-35331","epss":0.01639,"percentile":0.74933,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-35331","cwe":"CWE-134","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08195},"relatedVulnerabilities":[{"id":"CVE-2021-35331","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-35331","namespace":"nvd:cpe","severity":"High","urls":["https://core.tcl-lang.org/tcl/info/28ef6c0c741408a2","https://core.tcl-lang.org/tcl/info/bad6cc213dfe8280","https://github.com/tcltk/tcl/commit/4705dbdde2f32ff90420765cd93e7ac71d81a222","https://sqlite.org/forum/info/7dcd751996c93ec9"],"description":"In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-35331","epss":0.01639,"percentile":0.74933,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-35331","cwe":"CWE-134","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tcl8.6","version":"8.6.13+dfsg-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-35331","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0b40383f10e43009","name":"tcl8.6","version":"8.6.13+dfsg-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tcl8.6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/tcl8.6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tcl8.6.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/tcl8.6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tcl8.6.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/tcl8.6.list"},{"path":"/var/lib/dpkg/info/tcl8.6.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/tcl8.6.prerm"}],"language":"","licenses":["sha256:e925aa8863f0c9eda3625ce2cb16c0d5017fca248c5bd6af97006df5d9c6199c"],"cpes":["cpe:2.3:a:tcl8.6:tcl8.6:8.6.13\\+dfsg-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/tcl8.6@8.6.13%2Bdfsg-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-76957","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76957","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76957","epss":0.00107,"percentile":0.0123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.081855},"relatedVulnerabilities":[{"id":"CVE-2026-76957","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76957","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1322","https://github.com/libexpat/libexpat/pull/1329"],"description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76957","epss":0.00107,"percentile":0.0123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76957","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-76957","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76957","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76957","epss":0.00107,"percentile":0.0123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.081855},"relatedVulnerabilities":[{"id":"CVE-2026-76957","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76957","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libexpat/libexpat/pull/1322","https://github.com/libexpat/libexpat/pull/1329"],"description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-76957","epss":0.00107,"percentile":0.0123,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-76957","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2018-20673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20673","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08185},"relatedVulnerabilities":[{"id":"CVE-2018-20673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20673","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106454","https://sourceware.org/bugzilla/show_bug.cgi?id=24039"],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-20673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20673","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08185},"relatedVulnerabilities":[{"id":"CVE-2018-20673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20673","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106454","https://sourceware.org/bugzilla/show_bug.cgi?id=24039"],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20673","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08185},"relatedVulnerabilities":[{"id":"CVE-2018-20673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20673","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106454","https://sourceware.org/bugzilla/show_bug.cgi?id=24039"],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20673","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08185},"relatedVulnerabilities":[{"id":"CVE-2018-20673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20673","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106454","https://sourceware.org/bugzilla/show_bug.cgi?id=24039"],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20673","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08185},"relatedVulnerabilities":[{"id":"CVE-2018-20673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20673","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106454","https://sourceware.org/bugzilla/show_bug.cgi?id=24039"],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20673","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08185},"relatedVulnerabilities":[{"id":"CVE-2018-20673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20673","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106454","https://sourceware.org/bugzilla/show_bug.cgi?id=24039"],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-20673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20673","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08185},"relatedVulnerabilities":[{"id":"CVE-2018-20673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20673","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/106454","https://sourceware.org/bugzilla/show_bug.cgi?id=24039"],"description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for \"Create an array for saving the template argument values\") that can trigger a heap-based buffer overflow, as demonstrated by nm.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20673","epss":0.01637,"percentile":0.74905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-20673","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2018-20673","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-20673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2021-45346","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-45346","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.","cvss":[],"epss":[{"cve":"CVE-2021-45346","epss":0.01614,"percentile":0.74541,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-45346","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08070000000000001},"relatedVulnerabilities":[{"id":"CVE-2021-45346","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-45346","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/guyinatuxedo/sqlite3_record_leaking","https://security.netapp.com/advisory/ntap-20220303-0001/","https://sqlite.org/forum/forumpost/056d557c2f8c452ed5","https://sqlite.org/forum/forumpost/53de8864ba114bf6","https://www.sqlite.org/cves.html#status_of_recent_sqlite_cves"],"description":"A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","metrics":{"baseScore":4,"exploitabilityScore":8,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-45346","epss":0.01614,"percentile":0.74541,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-45346","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-45346","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"CVE-2023-4016","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-4016","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-4016","epss":0.00256,"percentile":0.1721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-4016","cwe":"CWE-122","source":"trellixpsirt@trellix.com","type":"Secondary"},{"cve":"CVE-2023-4016","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08064},"relatedVulnerabilities":[{"id":"CVE-2023-4016","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4016","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/procps-ng/procps","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SUETRRT24OFGPYK6ACPM5VUGHNKH5CQ5/"],"description":"Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"trellixpsirt@trellix.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-4016","epss":0.00256,"percentile":0.1721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-4016","cwe":"CWE-122","source":"trellixpsirt@trellix.com","type":"Secondary"},{"cve":"CVE-2023-4016","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"procps","version":"2:4.0.2-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-4016","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5ac1d1a0947c5131","name":"libproc2-0","version":"2:4.0.2-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libproc2-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libproc2-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libproc2-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libproc2-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libproc2-0:libproc2-0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2-0:libproc2_0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2_0:libproc2-0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2_0:libproc2_0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2:libproc2-0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2:libproc2_0:2\\:4.0.2-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libproc2-0@2%3A4.0.2-3?arch=amd64&distro=debian-12.15&upstream=procps","upstreams":[{"name":"procps"}]}},{"vulnerability":{"id":"CVE-2023-4016","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-4016","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-4016","epss":0.00256,"percentile":0.1721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-4016","cwe":"CWE-122","source":"trellixpsirt@trellix.com","type":"Secondary"},{"cve":"CVE-2023-4016","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08064},"relatedVulnerabilities":[{"id":"CVE-2023-4016","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4016","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/procps-ng/procps","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SUETRRT24OFGPYK6ACPM5VUGHNKH5CQ5/"],"description":"Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"trellixpsirt@trellix.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-4016","epss":0.00256,"percentile":0.1721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-4016","cwe":"CWE-122","source":"trellixpsirt@trellix.com","type":"Secondary"},{"cve":"CVE-2023-4016","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"procps","version":"2:4.0.2-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-4016","versionConstraint":"none (unknown)"}}],"artifact":{"id":"145b97448d7e9318","name":"procps","version":"2:4.0.2-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/procps/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/procps/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/procps.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/procps.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/procps.list"},{"path":"/var/lib/dpkg/info/procps.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/procps.postinst"},{"path":"/var/lib/dpkg/info/procps.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/procps.postrm"},{"path":"/var/lib/dpkg/info/procps.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/procps.preinst"},{"path":"/var/lib/dpkg/info/procps.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/procps.prerm"}],"language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:procps:procps:2\\:4.0.2-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/procps@2%3A4.0.2-3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11731","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11731","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11731","epss":0.00264,"percentile":0.18252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11731","cwe":"CWE-843","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.08052},"relatedVulnerabilities":[{"id":"CVE-2025-11731","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11731","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/errata/RHSA-2026:11015","https://access.redhat.com/security/cve/CVE-2025-11731","https://bugzilla.redhat.com/show_bug.cgi?id=2403688","https://gitlab.gnome.org/GNOME/libxslt/-/issues/151","https://gitlab.gnome.org/GNOME/libxslt/-/merge_requests/78"],"description":"A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11731","epss":0.00264,"percentile":0.18252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11731","cwe":"CWE-843","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxslt","version":"1.1.35-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11731","versionConstraint":"none (unknown)"}}],"artifact":{"id":"127f2ae91adc51ae","name":"libxslt1.1","version":"1.1.35-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxslt1.1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxslt1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:4b82c8dd6e55001a5921bea1d6db20be5c51e5976d892e870324026c23f37b6f"],"cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.35-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxslt1.1@1.1.35-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=libxslt","upstreams":[{"name":"libxslt"}]}},{"vulnerability":{"id":"CVE-2026-74973","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74973","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"exploitabilityScore":1.7,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74973","epss":0.00175,"percentile":0.07185,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74973","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-74973","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-74973","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74973","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2060357","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"exploitabilityScore":1.7,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74973","epss":0.00175,"percentile":0.07185,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74973","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-74973","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74973","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-73282","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73282","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"exploitabilityScore":2.3,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-73282","epss":0.00163,"percentile":0.05792,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07987},"relatedVulnerabilities":[{"id":"CVE-2026-73282","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.openssh.org/releasenotes.html#10.5"],"description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"exploitabilityScore":2.3,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-73282","epss":0.00163,"percentile":0.05792,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2026-54371","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54371","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54371","epss":0.0014,"percentile":0.03706,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-54371","cwe":"CWE-59","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07909999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-54371","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","namespace":"nvd:cpe","severity":"Medium","urls":["https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","https://access.redhat.com/errata/RHSA-2026:34889","https://access.redhat.com/errata/RHSA-2026:56133","https://access.redhat.com/errata/RHSA-2026:59380","https://access.redhat.com/errata/RHSA-2026:60226","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/security/cve/CVE-2026-54371","https://bugzilla.redhat.com/show_bug.cgi?id=2490283","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"],"description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54371","epss":0.0014,"percentile":0.03706,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-54371","cwe":"CWE-59","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"attr","version":"1:2.5.1-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54371","versionConstraint":"none (unknown)"}}],"artifact":{"id":"722285f8005c2384","name":"libattr1","version":"1:2.5.1-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libattr1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libattr1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libattr1:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libattr1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"cpes":["cpe:2.3:a:libattr1:libattr1:1\\:2.5.1-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libattr1@1%3A2.5.1-4?arch=amd64&distro=debian-12.15&upstream=attr","upstreams":[{"name":"attr"}]}},{"vulnerability":{"id":"CVE-2026-86142","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86142","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86142","epss":0.00132,"percentile":0.03084,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07854},"relatedVulnerabilities":[{"id":"CVE-2026-86142","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86142","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"],"description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86142","epss":0.00132,"percentile":0.03084,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86142","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-70631","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70631","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70631","epss":0.00131,"percentile":0.03026,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07729},"relatedVulnerabilities":[{"id":"CVE-2026-70631","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70631","epss":0.00131,"percentile":0.03026,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70631","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70631","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70631","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70631","epss":0.00131,"percentile":0.03026,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07729},"relatedVulnerabilities":[{"id":"CVE-2026-70631","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70631","epss":0.00131,"percentile":0.03026,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70631","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70631","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70631","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70631","epss":0.00131,"percentile":0.03026,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07729},"relatedVulnerabilities":[{"id":"CVE-2026-70631","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70631","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-tiff-decoder"],"description":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70631","epss":0.00131,"percentile":0.03026,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70631","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70631","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-56409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56409","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":1.1,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56409","epss":0.00134,"percentile":0.03258,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56409","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.07705},"relatedVulnerabilities":[{"id":"CVE-2026-56409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56409","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1259"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":1.1,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56409","epss":0.00134,"percentile":0.03258,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56409","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56409","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56409","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":1.1,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56409","epss":0.00134,"percentile":0.03258,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56409","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":["2.5.0-1+deb12u3"],"state":"fixed","available":[{"version":"2.5.0-1+deb12u3","date":"2026-09-01","kind":"first-observed"}]},"advisories":[],"risk":0.07705},"relatedVulnerabilities":[{"id":"CVE-2026-56409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56409","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1259"],"description":"xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":1.1,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56409","epss":0.00134,"percentile":0.03258,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56409","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56409","versionConstraint":"< 2.5.0-1+deb12u3 (deb)"},"fix":{"suggestedVersion":"2.5.0-1+deb12u3"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-70629","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70629","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70629","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07611},"relatedVulnerabilities":[{"id":"CVE-2026-70629","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70629","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70629","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70630","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70630","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70630","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07611},"relatedVulnerabilities":[{"id":"CVE-2026-70630","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70630","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70630","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70629","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70629","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70629","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07611},"relatedVulnerabilities":[{"id":"CVE-2026-70629","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70629","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70629","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70630","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70630","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70630","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07611},"relatedVulnerabilities":[{"id":"CVE-2026-70630","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70630","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70630","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70629","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70629","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70629","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07611},"relatedVulnerabilities":[{"id":"CVE-2026-70629","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70629","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70629","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70629","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-70630","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70630","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70630","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07611},"relatedVulnerabilities":[{"id":"CVE-2026-70630","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70630","namespace":"nvd:cpe","severity":"Medium","urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896","https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-screenpresso-decoder"],"description":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-70630","epss":0.00129,"percentile":0.02819,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-70630","cwe":"CWE-908","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-70630","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-18374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07425},"relatedVulnerabilities":[{"id":"CVE-2026-18374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-18374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07425},"relatedVulnerabilities":[{"id":"CVE-2026-18374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-18374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07425},"relatedVulnerabilities":[{"id":"CVE-2026-18374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-18374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07425},"relatedVulnerabilities":[{"id":"CVE-2026-18374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-18374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07425},"relatedVulnerabilities":[{"id":"CVE-2026-18374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"exploitabilityScore":1.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18374","epss":0.0015,"percentile":0.04469,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"},{"cve":"CVE-2026-18374","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-50263","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50263","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50263","epss":0.00141,"percentile":0.03765,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50263","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.07402500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50263","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50263","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50263","https://bugzilla.redhat.com/show_bug.cgi?id=2485388","https://gitlab.freedesktop.org/xorg/xserver/-/commit/ecc634f1b2f7aa473d3a267eada98c4918bf9e05","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950"],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50263","epss":0.00141,"percentile":0.03765,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50263","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50263","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50263","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50263","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50263","epss":0.00141,"percentile":0.03765,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50263","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.07402500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-50263","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50263","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50263","https://bugzilla.redhat.com/show_bug.cgi?id=2485388","https://gitlab.freedesktop.org/xorg/xserver/-/commit/ecc634f1b2f7aa473d3a267eada98c4918bf9e05","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950"],"description":"A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50263","epss":0.00141,"percentile":0.03765,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50263","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50263","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2023-48727","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-48727","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"NULL pointer dereference in some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable information disclosure via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-48727","epss":0.00235,"percentile":0.14449,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-48727","cwe":"CWE-395","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-48727","cwe":"CWE-395","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.074025},"relatedVulnerabilities":[{"id":"CVE-2023-48727","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-48727","namespace":"nvd:cpe","severity":"Low","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html"],"description":"NULL pointer dereference in some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable information disclosure via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-48727","epss":0.00235,"percentile":0.14449,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-48727","cwe":"CWE-395","source":"secure@intel.com","type":"Secondary"},{"cve":"CVE-2023-48727","cwe":"CWE-395","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-48727","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2018-18064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-18064","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).","cvss":[],"epss":[{"cve":"CVE-2018-18064","epss":0.0148,"percentile":0.72361,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-18064","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07400000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-18064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-18064","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.freedesktop.org/cairo/cairo/issues/341","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-18064","epss":0.0148,"percentile":0.72361,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-18064","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-18064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be12828c4e3c1a16","name":"libcairo-gobject2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo-gobject2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2018-18064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-18064","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).","cvss":[],"epss":[{"cve":"CVE-2018-18064","epss":0.0148,"percentile":0.72361,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-18064","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07400000000000001},"relatedVulnerabilities":[{"id":"CVE-2018-18064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-18064","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.freedesktop.org/cairo/cairo/issues/341","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-18064","epss":0.0148,"percentile":0.72361,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-18064","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-18064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"28d5ccf8758a4075","name":"libcairo2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo2:libcairo2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-78410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07344},"relatedVulnerabilities":[{"id":"CVE-2026-78410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-78410","epss":0.00096,"percentile":0.00751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2023-51792","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-51792","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51792","epss":0.00232,"percentile":0.13998,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-51792","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07307999999999999},"relatedVulnerabilities":[{"id":"CVE-2023-51792","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-51792","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/strukturag/libde265","https://github.com/strukturag/libde265/issues/427","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"description":"Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-51792","epss":0.00232,"percentile":0.13998,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-51792","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-51792","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-86138","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86138","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86138","epss":0.0012,"percentile":0.02026,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07139999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-86138","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86138","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86138","epss":0.0012,"percentile":0.02026,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86138","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6357","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6357","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6357","epss":0.00138,"percentile":0.0355,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6357","cwe":"CWE-829","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07107},"relatedVulnerabilities":[{"id":"CVE-2026-6357","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6357","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pypa/pip/pull/13923","https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes","http://www.openwall.com/lists/oss-security/2026/04/27/7"],"description":"pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6357","epss":0.00138,"percentile":0.0355,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6357","cwe":"CWE-829","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python-pip","version":"23.0.1+dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6357","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5929913cf46d2db3","name":"python3-pip","version":"23.0.1+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3-pip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.list"},{"path":"/var/lib/dpkg/info/python3-pip.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.postinst"},{"path":"/var/lib/dpkg/info/python3-pip.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"cpes":["cpe:2.3:a:python3-pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-pip@23.0.1%2Bdfsg-1?arch=all&distro=debian-12.15&upstream=python-pip","upstreams":[{"name":"python-pip"}]}},{"vulnerability":{"id":"CVE-2026-86143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86143","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86143","epss":0.00119,"percentile":0.02002,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.070805},"relatedVulnerabilities":[{"id":"CVE-2026-86143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86143","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"],"description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86143","epss":0.00119,"percentile":0.02002,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86143","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74974","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74974","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74974","epss":0.00135,"percentile":0.03281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74974","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.0702},"relatedVulnerabilities":[{"id":"CVE-2026-74974","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74974","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2061794","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-75/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74974","epss":0.00135,"percentile":0.03281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74974","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74974","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2017-13716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13716","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06995},"relatedVulnerabilities":[{"id":"CVE-2017-13716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"exploitabilityScore":8.6,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2017-13716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13716","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06995},"relatedVulnerabilities":[{"id":"CVE-2017-13716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"exploitabilityScore":8.6,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2017-13716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13716","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06995},"relatedVulnerabilities":[{"id":"CVE-2017-13716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"exploitabilityScore":8.6,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2017-13716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13716","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06995},"relatedVulnerabilities":[{"id":"CVE-2017-13716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"exploitabilityScore":8.6,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2017-13716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13716","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06995},"relatedVulnerabilities":[{"id":"CVE-2017-13716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"exploitabilityScore":8.6,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2017-13716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13716","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06995},"relatedVulnerabilities":[{"id":"CVE-2017-13716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"exploitabilityScore":8.6,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2017-13716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13716","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06995},"relatedVulnerabilities":[{"id":"CVE-2017-13716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13716","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=22009"],"description":"The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"exploitabilityScore":8.6,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13716","epss":0.01399,"percentile":0.70837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13716","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13716","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-50262","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50262","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50262","epss":0.00132,"percentile":0.03136,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50262","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.0693},"relatedVulnerabilities":[{"id":"CVE-2026-50262","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50262","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50262","https://bugzilla.redhat.com/show_bug.cgi?id=2485387","https://gitlab.freedesktop.org/xorg/xserver/-/commit/6d459e4daf715bea8abdafa8fb130be2f8a1d145","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950"],"description":"An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50262","epss":0.00132,"percentile":0.03136,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50262","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50262","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"e42f5783fb468d08","name":"xserver-common","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xserver-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xserver-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xserver-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xserver-common.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xserver-common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver-common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver_common:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver-common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*","cpe:2.3:a:xserver:xserver_common:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xserver-common@2%3A21.1.7-3%2Bdeb12u12?arch=all&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-50262","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50262","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50262","epss":0.00132,"percentile":0.03136,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50262","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":["2:21.1.7-3+deb12u13"],"state":"fixed","available":[{"version":"2:21.1.7-3+deb12u13","date":"2026-08-14","kind":"first-observed"}]},"advisories":[],"risk":0.0693},"relatedVulnerabilities":[{"id":"CVE-2026-50262","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50262","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:26562","https://access.redhat.com/errata/RHSA-2026:26566","https://access.redhat.com/errata/RHSA-2026:26590","https://access.redhat.com/errata/RHSA-2026:26610","https://access.redhat.com/errata/RHSA-2026:26709","https://access.redhat.com/errata/RHSA-2026:28923","https://access.redhat.com/errata/RHSA-2026:29844","https://access.redhat.com/errata/RHSA-2026:36083","https://access.redhat.com/errata/RHSA-2026:36085","https://access.redhat.com/errata/RHSA-2026:36086","https://access.redhat.com/errata/RHSA-2026:36087","https://access.redhat.com/errata/RHSA-2026:36632","https://access.redhat.com/errata/RHSA-2026:36633","https://access.redhat.com/errata/RHSA-2026:36634","https://access.redhat.com/errata/RHSA-2026:36768","https://access.redhat.com/errata/RHSA-2026:36791","https://access.redhat.com/errata/RHSA-2026:36792","https://access.redhat.com/errata/RHSA-2026:36798","https://access.redhat.com/errata/RHSA-2026:38502","https://access.redhat.com/errata/RHSA-2026:38810","https://access.redhat.com/errata/RHSA-2026:46377","https://access.redhat.com/errata/RHSA-2026:46382","https://access.redhat.com/errata/RHSA-2026:46385","https://access.redhat.com/errata/RHSA-2026:46392","https://access.redhat.com/errata/RHSA-2026:46456","https://access.redhat.com/errata/RHSA-2026:46460","https://access.redhat.com/errata/RHSA-2026:46473","https://access.redhat.com/errata/RHSA-2026:49519","https://access.redhat.com/security/cve/CVE-2026-50262","https://bugzilla.redhat.com/show_bug.cgi?id=2485387","https://gitlab.freedesktop.org/xorg/xserver/-/commit/6d459e4daf715bea8abdafa8fb130be2f8a1d145","https://lists.x.org/archives/xorg-announce/2026-June/003702.html","https://redhat.atlassian.net/browse/PSIRTSUPT-16950"],"description":"An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-50262","epss":0.00132,"percentile":0.03136,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-50262","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xorg-server","version":"2:21.1.7-3+deb12u12"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-50262","versionConstraint":"< 2:21.1.7-3+deb12u13 (deb)"},"fix":{"suggestedVersion":"2:21.1.7-3+deb12u13"}}],"artifact":{"id":"b7cbe76e4089abe0","name":"xvfb","version":"2:21.1.7-3+deb12u12","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xvfb/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xvfb/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xvfb.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xvfb.list"}],"language":"","licenses":["sha256:4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f"],"cpes":["cpe:2.3:a:xvfb:xvfb:2\\:21.1.7-3\\+deb12u12:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xvfb@2%3A21.1.7-3%2Bdeb12u12?arch=amd64&distro=debian-12.15&upstream=xorg-server","upstreams":[{"name":"xorg-server"}]}},{"vulnerability":{"id":"CVE-2026-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3219","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3219","epss":0.00144,"percentile":0.04014,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3219","cwe":"CWE-434","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06912},"relatedVulnerabilities":[{"id":"CVE-2026-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3219","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pypa/pip/pull/13870","https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/","http://www.openwall.com/lists/oss-security/2026/04/20/8"],"description":"pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3219","epss":0.00144,"percentile":0.04014,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3219","cwe":"CWE-434","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python-pip","version":"23.0.1+dfsg-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5929913cf46d2db3","name":"python3-pip","version":"23.0.1+dfsg-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3-pip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.list"},{"path":"/var/lib/dpkg/info/python3-pip.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.postinst"},{"path":"/var/lib/dpkg/info/python3-pip.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3-pip.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"cpes":["cpe:2.3:a:python3-pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip:23.0.1\\+dfsg-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3-pip@23.0.1%2Bdfsg-1?arch=all&distro=debian-12.15&upstream=python-pip","upstreams":[{"name":"python-pip"}]}},{"vulnerability":{"id":"CVE-2025-1153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1153","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06785000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-1153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1153","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32603","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150","https://vuldb.com/?ctiid.295057","https://vuldb.com/?id.295057","https://vuldb.com/?submit.489991","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0005/"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1153","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06785000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-1153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1153","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32603","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150","https://vuldb.com/?ctiid.295057","https://vuldb.com/?id.295057","https://vuldb.com/?submit.489991","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0005/"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1153","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06785000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-1153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1153","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32603","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150","https://vuldb.com/?ctiid.295057","https://vuldb.com/?id.295057","https://vuldb.com/?submit.489991","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0005/"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1153","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06785000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-1153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1153","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32603","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150","https://vuldb.com/?ctiid.295057","https://vuldb.com/?id.295057","https://vuldb.com/?submit.489991","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0005/"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1153","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06785000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-1153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1153","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32603","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150","https://vuldb.com/?ctiid.295057","https://vuldb.com/?id.295057","https://vuldb.com/?submit.489991","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0005/"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1153","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06785000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-1153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1153","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32603","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150","https://vuldb.com/?ctiid.295057","https://vuldb.com/?id.295057","https://vuldb.com/?submit.489991","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0005/"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1153","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06785000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-1153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1153","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32603","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150","https://vuldb.com/?ctiid.295057","https://vuldb.com/?id.295057","https://vuldb.com/?submit.489991","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0005/"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1153","epss":0.01357,"percentile":0.70001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1153","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-4367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4367","epss":0.00129,"percentile":0.02841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4367","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06772500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-4367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4367","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:30354","https://access.redhat.com/errata/RHSA-2026:47072","https://access.redhat.com/security/cve/CVE-2026-4367","https://bugzilla.redhat.com/show_bug.cgi?id=2448984","https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd","https://seclists.org/oss-sec/2026/q2/192","http://www.openwall.com/lists/oss-security/2026/04/21/3"],"description":"A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4367","epss":0.00129,"percentile":0.02841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4367","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxpm","version":"1:3.5.12-1.1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"07bc70427a2415c9","name":"libxpm4","version":"1:3.5.12-1.1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxpm4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxpm4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxpm4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxpm4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libxpm4:libxpm4:1\\:3.5.12-1.1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxpm4@1%3A3.5.12-1.1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libxpm","upstreams":[{"name":"libxpm"}]}},{"vulnerability":{"id":"CVE-2025-15649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2025-15649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2025-15649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2025-15649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-15649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2025-15649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2025-15649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2025-15649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15649","epss":0.00127,"percentile":0.02676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-18508","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18508","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":1.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18508","epss":0.00141,"percentile":0.03751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06627},"relatedVulnerabilities":[{"id":"CVE-2026-18508","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":1.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18508","epss":0.00141,"percentile":0.03751,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f8ad3f5238dbcf6a","name":"tar","version":"1.34+dfsg-1.2+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-0864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-0864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-0864","epss":0.00126,"percentile":0.02613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-63381","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63381","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63381","epss":0.00121,"percentile":0.02174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63381","cwe":"CWE-908","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06534000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-63381","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63381","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libevent/libevent/commit/5cb95ba2f804f8aff46f88d58391c71e1251cd1c","https://github.com/libevent/libevent/commit/9db091b04f569be3a700fa9860ef02f90b830af9","https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable","https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha","https://github.com/libevent/libevent/security/advisories/GHSA-c2pj-cg4r-88c8"],"description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63381","epss":0.00121,"percentile":0.02174,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-63381","cwe":"CWE-908","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libevent","version":"2.1.12-stable-8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63381","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3bff02d75bb58680","name":"libevent-2.1-7","version":"2.1.12-stable-8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libevent-2.1-7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libevent-2.1-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libevent-2.1-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","BSL","Expat","FSFUL","FSFULLR","FSFULLR-No-Warranty","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","curl"],"cpes":["cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1-7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1_7:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent-2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent_2.1:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent-2.1-7:2.1.12-stable-8:*:*:*:*:*:*:*","cpe:2.3:a:libevent:libevent_2.1_7:2.1.12-stable-8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libevent-2.1-7@2.1.12-stable-8?arch=amd64&distro=debian-12.15&upstream=libevent","upstreams":[{"name":"libevent"}]}},{"vulnerability":{"id":"CVE-2026-54370","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54370","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54370","epss":0.00088,"percentile":0.00438,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06468},"relatedVulnerabilities":[{"id":"CVE-2026-54370","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","namespace":"nvd:cpe","severity":"High","urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-54370","epss":0.00088,"percentile":0.00438,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"acl","version":"2.3.1-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d047530090108251","name":"libacl1","version":"2.3.1-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"cpes":["cpe:2.3:a:libacl1:libacl1:2.3.1-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libacl1@2.3.1-3?arch=amd64&distro=debian-12.15&upstream=acl","upstreams":[{"name":"acl"}]}},{"vulnerability":{"id":"CVE-2026-74967","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74967","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74967","epss":0.00124,"percentile":0.02435,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74967","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.06448000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74967","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74967","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2055697","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74967","epss":0.00124,"percentile":0.02435,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74967","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74967","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-74963","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74963","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74963","epss":0.00124,"percentile":0.02434,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74963","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["140.14.0esr-1~deb12u1"],"state":"fixed","available":[{"version":"140.14.0esr-1~deb12u1","date":"2026-08-22","kind":"first-observed"}]},"advisories":[],"risk":0.06448000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74963","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74963","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2050482","https://www.mozilla.org/security/advisories/mfsa2026-74/","https://www.mozilla.org/security/advisories/mfsa2026-76/","https://www.mozilla.org/security/advisories/mfsa2026-77/","https://www.mozilla.org/security/advisories/mfsa2026-78/","https://www.mozilla.org/security/advisories/mfsa2026-79/","https://www.mozilla.org/security/advisories/mfsa2026-80/"],"description":"Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"exploitabilityScore":2.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74963","epss":0.00124,"percentile":0.02434,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-74963","cwe":"CWE-346","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"firefox-esr","version":"140.13.0esr-1~deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74963","versionConstraint":"< 140.14.0esr-1~deb12u1 (deb)"},"fix":{"suggestedVersion":"140.14.0esr-1~deb12u1"}}],"artifact":{"id":"2346d3265481a4fc","name":"firefox-esr","version":"140.13.0esr-1~deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/firefox-esr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/firefox-esr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/firefox-esr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.list"},{"path":"/var/lib/dpkg/info/firefox-esr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postinst"},{"path":"/var/lib/dpkg/info/firefox-esr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.postrm"},{"path":"/var/lib/dpkg/info/firefox-esr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.preinst"},{"path":"/var/lib/dpkg/info/firefox-esr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/firefox-esr.prerm"}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3","BSD-3-clause","BSD-4-clause","GPL-2","GPL-3","LGPL-2.1","MIT","MPL-1.1","MPL-2.0","other","public-domain"],"cpes":["cpe:2.3:a:firefox-esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox-esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox_esr:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox-esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:firefox:firefox_esr:140.13.0esr-1\\~deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/firefox-esr@140.13.0esr-1~deb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-86139","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86139","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86139","epss":0.00108,"percentile":0.01321,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86139","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06426},"relatedVulnerabilities":[{"id":"CVE-2026-86139","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86139","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"description":"In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86139","epss":0.00108,"percentile":0.01321,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86139","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86139","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-9996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-9996","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06425},"relatedVulnerabilities":[{"id":"CVE-2018-9996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-9996","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/103733","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85304"],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-9996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-9996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-9996","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06425},"relatedVulnerabilities":[{"id":"CVE-2018-9996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-9996","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/103733","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85304"],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-9996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-9996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-9996","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06425},"relatedVulnerabilities":[{"id":"CVE-2018-9996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-9996","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/103733","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85304"],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-9996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-9996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-9996","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06425},"relatedVulnerabilities":[{"id":"CVE-2018-9996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-9996","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/103733","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85304"],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-9996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-9996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-9996","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06425},"relatedVulnerabilities":[{"id":"CVE-2018-9996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-9996","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/103733","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85304"],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-9996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-9996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-9996","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06425},"relatedVulnerabilities":[{"id":"CVE-2018-9996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-9996","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/103733","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85304"],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-9996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2018-9996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-9996","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06425},"relatedVulnerabilities":[{"id":"CVE-2018-9996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-9996","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/103733","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85304"],"description":"An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-9996","epss":0.01285,"percentile":0.68393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-9996","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-9996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-0725","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0725","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.","cvss":[],"epss":[{"cve":"CVE-2025-0725","epss":0.01264,"percentile":0.67945,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0725","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0632},"relatedVulnerabilities":[{"id":"CVE-2025-0725","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0725","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2025-0725.html","https://curl.se/docs/CVE-2025-0725.json","https://hackerone.com/reports/2956023","http://www.openwall.com/lists/oss-security/2025/02/05/3","http://www.openwall.com/lists/oss-security/2025/02/06/2","http://www.openwall.com/lists/oss-security/2025/02/06/4","https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7","https://security.netapp.com/advisory/ntap-20250306-0009/"],"description":"When libcurl is asked to perform automatic gzip decompression of\ncontent-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option,\n**using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would\nmake libcurl perform a buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0725","epss":0.01264,"percentile":0.67945,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0725","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0725","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-0725","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0725","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.","cvss":[],"epss":[{"cve":"CVE-2025-0725","epss":0.01264,"percentile":0.67945,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0725","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0632},"relatedVulnerabilities":[{"id":"CVE-2025-0725","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0725","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2025-0725.html","https://curl.se/docs/CVE-2025-0725.json","https://hackerone.com/reports/2956023","http://www.openwall.com/lists/oss-security/2025/02/05/3","http://www.openwall.com/lists/oss-security/2025/02/06/2","http://www.openwall.com/lists/oss-security/2025/02/06/4","https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7","https://security.netapp.com/advisory/ntap-20250306-0009/"],"description":"When libcurl is asked to perform automatic gzip decompression of\ncontent-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option,\n**using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would\nmake libcurl perform a buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0725","epss":0.01264,"percentile":0.67945,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0725","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0725","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-0725","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0725","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.","cvss":[],"epss":[{"cve":"CVE-2025-0725","epss":0.01264,"percentile":0.67945,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0725","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0632},"relatedVulnerabilities":[{"id":"CVE-2025-0725","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0725","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2025-0725.html","https://curl.se/docs/CVE-2025-0725.json","https://hackerone.com/reports/2956023","http://www.openwall.com/lists/oss-security/2025/02/05/3","http://www.openwall.com/lists/oss-security/2025/02/06/2","http://www.openwall.com/lists/oss-security/2025/02/06/4","https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7","https://security.netapp.com/advisory/ntap-20250306-0009/"],"description":"When libcurl is asked to perform automatic gzip decompression of\ncontent-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option,\n**using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would\nmake libcurl perform a buffer overflow.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0725","epss":0.01264,"percentile":0.67945,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0725","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0725","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-50422","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-50422","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Cairo through 1.18.4, as used in Poppler through 25.08.0, has an \"unscaled->face == NULL\" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-50422","epss":0.00213,"percentile":0.11643,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-50422","cwe":"CWE-617","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.062835},"relatedVulnerabilities":[{"id":"CVE-2025-50422","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50422","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/Landw-hub/CVE-2025-50422","https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621","https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591","https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591#note_3045081"],"description":"Cairo through 1.18.4, as used in Poppler through 25.08.0, has an \"unscaled->face == NULL\" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-50422","epss":0.00213,"percentile":0.11643,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-50422","cwe":"CWE-617","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-50422","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be12828c4e3c1a16","name":"libcairo-gobject2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo-gobject2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo-gobject2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo-gobject2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo-gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo-gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo_gobject2:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo-gobject2:1.16.0-7:*:*:*:*:*:*:*","cpe:2.3:a:libcairo:libcairo_gobject2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo-gobject2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2025-50422","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-50422","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Cairo through 1.18.4, as used in Poppler through 25.08.0, has an \"unscaled->face == NULL\" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-50422","epss":0.00213,"percentile":0.11643,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-50422","cwe":"CWE-617","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.062835},"relatedVulnerabilities":[{"id":"CVE-2025-50422","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50422","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/Landw-hub/CVE-2025-50422","https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621","https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591","https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591#note_3045081"],"description":"Cairo through 1.18.4, as used in Poppler through 25.08.0, has an \"unscaled->face == NULL\" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-50422","epss":0.00213,"percentile":0.11643,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-50422","cwe":"CWE-617","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cairo","version":"1.16.0-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-50422","versionConstraint":"none (unknown)"}}],"artifact":{"id":"28d5ccf8758a4075","name":"libcairo2","version":"1.16.0-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcairo2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcairo2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcairo2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:408fb9e704e875cd42d432e7c9b3b378f568e3c89db2b5c5ef3d11c025319574"],"cpes":["cpe:2.3:a:libcairo2:libcairo2:1.16.0-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcairo2@1.16.0-7?arch=amd64&distro=debian-12.15&upstream=cairo","upstreams":[{"name":"cairo"}]}},{"vulnerability":{"id":"CVE-2022-28506","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-28506","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.","cvss":[],"epss":[{"cve":"CVE-2022-28506","epss":0.01253,"percentile":0.6768,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-28506","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06265},"relatedVulnerabilities":[{"id":"CVE-2022-28506","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-28506","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/verf1sh/Poc/blob/master/asan_report_giflib.png","https://github.com/verf1sh/Poc/blob/master/giflib_poc","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4CJSHXBD2RS5OJNWSHQZVMTQCCTIPYS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEAFUZXOOJJVFYRQM6IIJ7LMLEKCCESG/","https://sourceforge.net/p/giflib/bugs/159/"],"description":"There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-28506","epss":0.01253,"percentile":0.6768,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-28506","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"giflib","version":"5.2.1-2.5+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-28506","versionConstraint":"none (unknown)"}}],"artifact":{"id":"71a582f5b3d629e1","name":"libgif7","version":"5.2.1-2.5+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgif7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgif7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgif7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgif7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT"],"cpes":["cpe:2.3:a:libgif7:libgif7:5.2.1-2.5\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgif7@5.2.1-2.5%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=giflib","upstreams":[{"name":"giflib"}]}},{"vulnerability":{"id":"CVE-2026-15059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-15059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4a63521ec2fd3be","name":"libnss-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libnss-systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss-systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-15059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-15059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c085cdccd13efd58","name":"libpam-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpam-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libpam-systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-15059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-15059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f08c824a2d960023","name":"libsystemd-shared","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd-shared/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsystemd-shared/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd-shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd-shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd-shared@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-15059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-15059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fa8be228d5b7724c","name":"libsystemd0","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-15059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-15059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"55089f35a6363c37","name":"libudev1","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-15059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-15059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40fe219b13a5306","name":"systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd:systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-15059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-15059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8dbabe3bd671d120","name":"systemd-sysv","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-sysv@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-15059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-15059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15059","epss":0.00119,"percentile":0.01997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"},{"cve":"CVE-2026-15059","cwe":"CWE-59","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e4b498470090a3c","name":"systemd-timesyncd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-timesyncd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-timesyncd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.list"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postinst"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postrm"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.prerm"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-timesyncd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-42250","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67","cvss":[{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42250","epss":0.00126,"percentile":0.02637,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06174},"relatedVulnerabilities":[{"id":"CVE-2026-42250","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67","cvss":[{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42250","epss":0.00126,"percentile":0.02637,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bzip2","version":"1.0.8-5+b1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"}},{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bzip2","version":"1.0.8-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b42ef956bd40e9db","name":"bzip2","version":"1.0.8-5+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bzip2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/bzip2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bzip2.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/bzip2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bzip2.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/bzip2.list"}],"language":"","licenses":["BSD-variant","GPL-2"],"cpes":["cpe:2.3:a:bzip2:bzip2:1.0.8-5\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bzip2@1.0.8-5%2Bb1?arch=amd64&distro=debian-12.15&upstream=bzip2%401.0.8-5","upstreams":[{"name":"bzip2","version":"1.0.8-5"}]}},{"vulnerability":{"id":"CVE-2026-42250","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67","cvss":[{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42250","epss":0.00126,"percentile":0.02637,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.06174},"relatedVulnerabilities":[{"id":"CVE-2026-42250","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67","cvss":[{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42250","epss":0.00126,"percentile":0.02637,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bzip2","version":"1.0.8-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"}}],"artifact":{"id":"751ec9ae4280dd32","name":"libbz2-1.0","version":"1.0.8-5+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-variant","GPL-2"],"cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbz2-1.0@1.0.8-5%2Bb1?arch=amd64&distro=debian-12.15&upstream=bzip2%401.0.8-5","upstreams":[{"name":"bzip2","version":"1.0.8-5"}]}},{"vulnerability":{"id":"CVE-2026-56132","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56132","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56132","epss":0.00103,"percentile":0.01076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56132","cwe":"CWE-821","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.061285000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-56132","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56132","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1272"],"description":"In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56132","epss":0.00103,"percentile":0.01076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56132","cwe":"CWE-821","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56132","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-56132","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56132","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56132","epss":0.00103,"percentile":0.01076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56132","cwe":"CWE-821","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.061285000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-56132","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56132","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libexpat/libexpat/pull/1272"],"description":"In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"exploitabilityScore":1.5,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56132","epss":0.00103,"percentile":0.01076,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56132","cwe":"CWE-821","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56132","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-18938","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18938","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18938","epss":0.00107,"percentile":0.01243,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05992},"relatedVulnerabilities":[{"id":"CVE-2026-18938","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18938","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-18938","https://bugzilla.redhat.com/show_bug.cgi?id=2478995"],"description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18938","epss":0.00107,"percentile":0.01243,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"p11-kit","version":"0.24.1-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18938","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0027543880aaec84","name":"libp11-kit0","version":"0.24.1-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-Clause","ISC","ISC+IBM","LGPL-2.1","LGPL-2.1+","permissive-like-automake-output","same-as-rest-of-p11kit"],"cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libp11-kit0@0.24.1-2?arch=amd64&distro=debian-12.15&upstream=p11-kit","upstreams":[{"name":"p11-kit"}]}},{"vulnerability":{"id":"CVE-2011-3374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.66095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05955000000000001},"relatedVulnerabilities":[{"id":"CVE-2011-3374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.66095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"apt","version":"2.6.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cd0a6d87e2b9c130","name":"apt","version":"2.6.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/apt/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"language":"","licenses":["BSD-3-clause","Expat","GPL-2","GPL-2+"],"cpes":["cpe:2.3:a:apt:apt:2.6.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/apt@2.6.1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2011-3374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.66095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05955000000000001},"relatedVulnerabilities":[{"id":"CVE-2011-3374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-3374","epss":0.01191,"percentile":0.66095,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"apt","version":"2.6.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"91b1396a4c2e715d","name":"libapt-pkg6.0","version":"2.6.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-pkg6.0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libapt-pkg6.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-pkg6.0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libapt-pkg6.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","Expat","GPL-2","GPL-2+"],"cpes":["cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg6.0:libapt_pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg6.0:libapt-pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg6.0:libapt_pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg6.0:2.6.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libapt-pkg6.0@2.6.1?arch=amd64&distro=debian-12.15&upstream=apt","upstreams":[{"name":"apt"}]}},{"vulnerability":{"id":"CVE-2026-47714","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47714","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` are `unsigned int` (32-bit) values parsed from the HEIF file. Their product can exceed `UINT32_MAX`, wrapping to a small value before the division by 8. This causes an undersized buffer allocation, leading to out-of-bounds memory access when the mask data is later interpreted as a `width x height` bitmap. Version 1.22.0 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47714","epss":0.00107,"percentile":0.0124,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47714","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05938499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-47714","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47714","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/strukturag/libheif/security/advisories/GHSA-h4wm-6wwf-qvhx"],"description":"libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` are `unsigned int` (32-bit) values parsed from the HEIF file. Their product can exceed `UINT32_MAX`, wrapping to a small value before the division by 8. This causes an undersized buffer allocation, leading to out-of-bounds memory access when the mask data is later interpreted as a `width x height` bitmap. Version 1.22.0 patches the issue.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-47714","epss":0.00107,"percentile":0.0124,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-47714","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-47714","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-86469","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86469","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86469","epss":0.00113,"percentile":0.01606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.058195000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-86469","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86469","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-86469","https://bugzilla.redhat.com/show_bug.cgi?id=2473839","https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c","https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"],"description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86469","epss":0.00113,"percentile":0.01606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86469","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f7e49c1a6279cc8f","name":"libglib2.0-0","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-0@2.74.6-2%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2026-86469","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86469","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86469","epss":0.00113,"percentile":0.01606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.058195000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-86469","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86469","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-86469","https://bugzilla.redhat.com/show_bug.cgi?id=2473839","https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c","https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"],"description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86469","epss":0.00113,"percentile":0.01606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glib2.0","version":"2.74.6-2+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86469","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f3f80a402f7cbc1b","name":"libglib2.0-data","version":"2.74.6-2+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"language":"","licenses":["AFL-2.0","Apache-2.0","BSD-3-clause-pcre","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","Mingw-PD","Old-GLib-Tests-permissive","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6"],"cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.74.6-2\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglib2.0-data@2.74.6-2%2Bdeb12u9?arch=all&distro=debian-12.15&upstream=glib2.0","upstreams":[{"name":"glib2.0"}]}},{"vulnerability":{"id":"CVE-2024-21783","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-21783","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-21783","epss":0.00212,"percentile":0.11512,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-21783","cwe":"CWE-190","source":"secure@intel.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057240000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-21783","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-21783","namespace":"nvd:cpe","severity":"Low","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01131.html"],"description":"Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}},{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.8,"exploitabilityScore":1.4,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-21783","epss":0.00212,"percentile":0.11512,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-21783","cwe":"CWE-190","source":"secure@intel.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-21783","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-27456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.057229999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-27456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.","cvss":[{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-27456","epss":0.00118,"percentile":0.01922,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-269","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2026-27456","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2024-29511","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-29511","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.","cvss":[],"epss":[{"cve":"CVE-2024-29511","epss":0.01137,"percentile":0.64615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-29511","cwe":"CWE-489","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05685},"relatedVulnerabilities":[{"id":"CVE-2024-29511","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-29511","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=707510","https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=3d4cfdc1a44","https://www.openwall.com/lists/oss-security/2024/07/03/7"],"description":"Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-29511","epss":0.01137,"percentile":0.64615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-29511","cwe":"CWE-489","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-29511","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1a53878210d7ee72","name":"libgs-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs-common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2024-29511","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-29511","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.","cvss":[],"epss":[{"cve":"CVE-2024-29511","epss":0.01137,"percentile":0.64615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-29511","cwe":"CWE-489","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05685},"relatedVulnerabilities":[{"id":"CVE-2024-29511","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-29511","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=707510","https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=3d4cfdc1a44","https://www.openwall.com/lists/oss-security/2024/07/03/7"],"description":"Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-29511","epss":0.01137,"percentile":0.64615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-29511","cwe":"CWE-489","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-29511","versionConstraint":"none (unknown)"}}],"artifact":{"id":"097a7cb358060cf0","name":"libgs10","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10:libgs10:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10@10.0.0~dfsg-11%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2024-29511","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-29511","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.","cvss":[],"epss":[{"cve":"CVE-2024-29511","epss":0.01137,"percentile":0.64615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-29511","cwe":"CWE-489","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05685},"relatedVulnerabilities":[{"id":"CVE-2024-29511","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-29511","namespace":"nvd:cpe","severity":"High","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=707510","https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commitdiff%3Bh=3d4cfdc1a44","https://www.openwall.com/lists/oss-security/2024/07/03/7"],"description":"Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-29511","epss":0.01137,"percentile":0.64615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-29511","cwe":"CWE-489","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-29511","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1592f7455014590c","name":"libgs10-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3fb79a418234f4d0","name":"krb5-locales","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/krb5-locales@1.20.1-2%2Bdeb12u5?arch=all&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9db16cb04ae3b83d","name":"libgssapi-krb5-2","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fb1c9cf5b43a5af0","name":"libk5crypto3","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"52548f50c4ff26c7","name":"libkrb5-3","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056400000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-26461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26461","epss":0.01128,"percentile":0.644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"}}],"artifact":{"id":"309b5ab55a11c7d0","name":"libkrb5support0","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c185e9c791136aa6","name":"dirmngr","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:dirmngr:dirmngr:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dirmngr@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e92d6b046326efbc","name":"gnupg","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg:gnupg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"976c5c43a7fe516a","name":"gnupg-l10n","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-l10n@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4d2b57169c4709a4","name":"gnupg-utils","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-utils@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1b50350895a48a3b","name":"gpg","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg:gpg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"01ceda49a85ecdc9","name":"gpg-agent","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-agent@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2ce7ba29a10f5f2d","name":"gpg-wks-client","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-wks-client@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5c929b5e7563826e","name":"gpg-wks-server","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-server/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-wks-server/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-server.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-server.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-wks-server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-wks-server@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"45da524630bb2133","name":"gpgconf","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgconf:gpgconf:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgconf@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b982b129e67b17ad","name":"gpgsm","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgsm:gpgsm:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgsm@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-68972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-68972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","namespace":"nvd:cpe","severity":"Medium","urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":1.5,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68972","epss":0.00115,"percentile":0.01741,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bab4532a87a829c8","name":"gpgv","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2024-2236","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-2236","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.","cvss":[],"epss":[{"cve":"CVE-2024-2236","epss":0.01114,"percentile":0.64046,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.055700000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-2236","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2236","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:9404","https://access.redhat.com/errata/RHSA-2025:3530","https://access.redhat.com/errata/RHSA-2025:3534","https://access.redhat.com/security/cve/CVE-2024-2236","https://bugzilla.redhat.com/show_bug.cgi?id=2245218","https://bugzilla.redhat.com/show_bug.cgi?id=2268268"],"description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-2236","epss":0.01114,"percentile":0.64046,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libgcrypt20","version":"1.10.1-3+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-2236","versionConstraint":"none (unknown)"}}],"artifact":{"id":"df01c68aff59530a","name":"libgcrypt20","version":"1.10.1-3+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:95db2f9da663f2bfe2aabe9c72fce9d6c9ae767b912f397d7823f50bd55a1a7d"],"cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgcrypt20@1.10.1-3%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4a63521ec2fd3be","name":"libnss-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libnss-systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss-systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c085cdccd13efd58","name":"libpam-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpam-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libpam-systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f08c824a2d960023","name":"libsystemd-shared","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd-shared/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsystemd-shared/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd-shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd-shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd-shared@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fa8be228d5b7724c","name":"libsystemd0","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"55089f35a6363c37","name":"libudev1","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40fe219b13a5306","name":"systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd:systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8dbabe3bd671d120","name":"systemd-sysv","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-sysv@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-40228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05449499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-40228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40228","epss":0.00173,"percentile":0.06884,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e4b498470090a3c","name":"systemd-timesyncd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-timesyncd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-timesyncd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.list"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postinst"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postrm"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.prerm"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-timesyncd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-81893","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-81893","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.  Affected version >= 2.26.4","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-81893","epss":0.00112,"percentile":0.01538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-81893","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05432},"relatedVulnerabilities":[{"id":"CVE-2026-81893","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81893","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-81893","https://bugzilla.redhat.com/show_bug.cgi?id=2524834","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278"],"description":"A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.\n\nAffected version >= 2.26.4","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-81893","epss":0.00112,"percentile":0.01538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-81893","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-81893","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e384004f37f8d5e","name":"libgdk-pixbuf-2.0-0","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf-2.0-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf-2.0-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf-2.0-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf-2.0-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf-2.0-0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0-0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0_0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0_0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf-2.0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf_2.0:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf-2.0-0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf_2.0_0:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf-2.0-0@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2026-81893","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-81893","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.  Affected version >= 2.26.4","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-81893","epss":0.00112,"percentile":0.01538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-81893","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05432},"relatedVulnerabilities":[{"id":"CVE-2026-81893","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81893","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-81893","https://bugzilla.redhat.com/show_bug.cgi?id=2524834","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278"],"description":"A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.\n\nAffected version >= 2.26.4","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-81893","epss":0.00112,"percentile":0.01538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-81893","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-81893","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b205c783e97c36c6","name":"libgdk-pixbuf2.0-bin","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf2.0-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf2.0-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-bin.list"}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf2.0-bin:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0-bin:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_bin:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_bin:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf2.0-bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf2.0_bin:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf2.0-bin@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2026-81893","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-81893","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.  Affected version >= 2.26.4","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-81893","epss":0.00112,"percentile":0.01538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-81893","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05432},"relatedVulnerabilities":[{"id":"CVE-2026-81893","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81893","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-81893","https://bugzilla.redhat.com/show_bug.cgi?id=2524834","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01","https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278"],"description":"A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.\n\nAffected version >= 2.26.4","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-81893","epss":0.00112,"percentile":0.01538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-81893","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gdk-pixbuf","version":"2.42.10+dfsg-1+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-81893","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5a58bb7174f44032","name":"libgdk-pixbuf2.0-common","version":"2.42.10+dfsg-1+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgdk-pixbuf2.0-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgdk-pixbuf2.0-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgdk-pixbuf2.0-common.list"}],"language":"","licenses":["CC0-1.0","GPL-2","GPL-2+","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libgdk-pixbuf2.0-common:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0-common:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_common:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0_common:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk-pixbuf2.0:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk_pixbuf2.0:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk-pixbuf2.0-common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*","cpe:2.3:a:libgdk:libgdk_pixbuf2.0_common:2.42.10\\+dfsg-1\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgdk-pixbuf2.0-common@2.42.10%2Bdfsg-1%2Bdeb12u4?arch=all&distro=debian-12.15&upstream=gdk-pixbuf","upstreams":[{"name":"gdk-pixbuf"}]}},{"vulnerability":{"id":"CVE-2018-1000021","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-1000021","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).","cvss":[],"epss":[{"cve":"CVE-2018-1000021","epss":0.01074,"percentile":0.62929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.053700000000000005},"relatedVulnerabilities":[{"id":"CVE-2018-1000021","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000021","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.batterystapl.es/2018/01/security-implications-of-ansi-escape.html"],"description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-1000021","epss":0.01074,"percentile":0.62929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"git","version":"1:2.39.5-0+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-1000021","versionConstraint":"none (unknown)"}}],"artifact":{"id":"58f3a3d22240a914","name":"git","version":"1:2.39.5-0+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.prerm"}],"language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"cpes":["cpe:2.3:a:git:git:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/git@1%3A2.39.5-0%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2018-1000021","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-1000021","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).","cvss":[],"epss":[{"cve":"CVE-2018-1000021","epss":0.01074,"percentile":0.62929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.053700000000000005},"relatedVulnerabilities":[{"id":"CVE-2018-1000021","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000021","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.batterystapl.es/2018/01/security-implications-of-ansi-escape.html"],"description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-1000021","epss":0.01074,"percentile":0.62929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"git","version":"1:2.39.5-0+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-1000021","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d2fedb9664730c69","name":"git-man","version":"1:2.39.5-0+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git-man.list"}],"language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"cpes":["cpe:2.3:a:git-man:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/git-man@1%3A2.39.5-0%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=git","upstreams":[{"name":"git"}]}},{"vulnerability":{"id":"CVE-2021-36691","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-36691","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denial of service.","cvss":[],"epss":[{"cve":"CVE-2021-36691","epss":0.01071,"percentile":0.62864,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-36691","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05355000000000001},"relatedVulnerabilities":[{"id":"CVE-2021-36691","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36691","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/libjxl/libjxl/issues/422"],"description":"libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-36691","epss":0.01071,"percentile":0.62864,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-36691","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jpeg-xl","version":"0.7.0-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-36691","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b6ad6e0f23e0de4d","name":"libjxl0.7","version":"0.7.0-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjxl0.7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjxl0.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause-Google","ISC-License"],"cpes":["cpe:2.3:a:libjxl0.7:libjxl0.7:0.7.0-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjxl0.7@0.7.0-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=jpeg-xl","upstreams":[{"name":"jpeg-xl"}]}},{"vulnerability":{"id":"GHSA-wjpw-4j6x-6rwh","dataSource":"https://github.com/advisories/GHSA-wjpw-4j6x-6rwh","namespace":"github:language:java","severity":"Low","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh","https://nvd.nist.gov/vuln/detail/CVE-2025-11143","https://github.com/user-attachments/files/22222625/Java.Eclipse.Jetty.Report_.Incorrect.Parsing.Priority.of.the.IPv6.Hostname.Delimeter.pdf","https://github.com/user-attachments/files/22222626/Java.Eclipse.Jetty.Report_.The.Parsing.Priority.of.the.Delimiter.pdf","https://github.com/user-attachments/files/22222627/Java.Eclipse.Jetty.Report_.Parsing.Difference.Due.to.Deformed.Scheme.pdf","https://github.com/user-attachments/files/22222630/Java.Eclipse.Jetty.Report_.Improper.IPv4-mapped.IPv6.Parsing.pdf"],"description":"org.eclipse.jetty:jetty-http has different parsing of invalid URIs","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11143","epss":0.00159,"percentile":0.05347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","source":"emo@eclipse.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05326499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-11143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11143","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh"],"description":"The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11143","epss":0.00159,"percentile":0.05347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","source":"emo@eclipse.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.56.v20240826"}},"found":{"vulnerabilityID":"GHSA-wjpw-4j6x-6rwh","versionConstraint":">=9.4.0,<=9.4.58 (unknown)"}}],"artifact":{"id":"1240a4d50758cd81","name":"jetty-http","version":"9.4.56.v20240826","type":"java-archive","locations":[{"path":"/zap/webswing/server/webswing-jetty-launcher.jar","layerID":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","accessPath":"/zap/webswing/server/webswing-jetty-launcher.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.56.v20240826:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.56.v20240826:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.56.v20240826","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/webswing/server/webswing-jetty-launcher.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-wjpw-4j6x-6rwh","dataSource":"https://github.com/advisories/GHSA-wjpw-4j6x-6rwh","namespace":"github:language:java","severity":"Low","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh","https://nvd.nist.gov/vuln/detail/CVE-2025-11143","https://github.com/user-attachments/files/22222625/Java.Eclipse.Jetty.Report_.Incorrect.Parsing.Priority.of.the.IPv6.Hostname.Delimeter.pdf","https://github.com/user-attachments/files/22222626/Java.Eclipse.Jetty.Report_.The.Parsing.Priority.of.the.Delimiter.pdf","https://github.com/user-attachments/files/22222627/Java.Eclipse.Jetty.Report_.Parsing.Difference.Due.to.Deformed.Scheme.pdf","https://github.com/user-attachments/files/22222630/Java.Eclipse.Jetty.Report_.Improper.IPv4-mapped.IPv6.Parsing.pdf"],"description":"org.eclipse.jetty:jetty-http has different parsing of invalid URIs","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11143","epss":0.00159,"percentile":0.05347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","source":"emo@eclipse.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05326499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-11143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11143","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh"],"description":"The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11143","epss":0.00159,"percentile":0.05347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","source":"emo@eclipse.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.57.v20241219"}},"found":{"vulnerabilityID":"GHSA-wjpw-4j6x-6rwh","versionConstraint":">=9.4.0,<=9.4.58 (unknown)"}}],"artifact":{"id":"12be712711d3c78e","name":"jetty-http","version":"9.4.57.v20241219","type":"java-archive","locations":[{"path":"/zap/plugin/selenium-release-15.53.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/selenium-release-15.53.0.zap:libs/htmlunit-websocket-client-4.14.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.57.v20241219","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/selenium-release-15.53.0.zap:libs/htmlunit-websocket-client-4.14.0.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"GHSA-wjpw-4j6x-6rwh","dataSource":"https://github.com/advisories/GHSA-wjpw-4j6x-6rwh","namespace":"github:language:java","severity":"Low","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh","https://nvd.nist.gov/vuln/detail/CVE-2025-11143","https://github.com/user-attachments/files/22222625/Java.Eclipse.Jetty.Report_.Incorrect.Parsing.Priority.of.the.IPv6.Hostname.Delimeter.pdf","https://github.com/user-attachments/files/22222626/Java.Eclipse.Jetty.Report_.The.Parsing.Priority.of.the.Delimiter.pdf","https://github.com/user-attachments/files/22222627/Java.Eclipse.Jetty.Report_.Parsing.Difference.Due.to.Deformed.Scheme.pdf","https://github.com/user-attachments/files/22222630/Java.Eclipse.Jetty.Report_.Improper.IPv4-mapped.IPv6.Parsing.pdf"],"description":"org.eclipse.jetty:jetty-http has different parsing of invalid URIs","cvss":[{"type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11143","epss":0.00159,"percentile":0.05347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","source":"emo@eclipse.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05326499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-11143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11143","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh"],"description":"The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"emo@eclipse.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11143","epss":0.00159,"percentile":0.05347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","source":"emo@eclipse.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.57.v20241219"}},"found":{"vulnerabilityID":"GHSA-wjpw-4j6x-6rwh","versionConstraint":">=9.4.0,<=9.4.58 (unknown)"}}],"artifact":{"id":"c9700e6689975883","name":"jetty-http","version":"9.4.57.v20241219","type":"java-archive","locations":[{"path":"/zap/plugin/selenium-release-15.43.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/selenium-release-15.43.0.zap:libs/htmlunit-websocket-client-4.14.0.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":[],"cpes":["cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*"],"purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.57.v20241219","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/selenium-release-15.43.0.zap:libs/htmlunit-websocket-client-4.14.0.jar:org.eclipse.jetty:jetty-http","pomArtifactID":"jetty-http","pomGroupID":"org.eclipse.jetty","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2016-1585","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-1585","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In all versions of AppArmor mount rules are accidentally widened when compiled.","cvss":[],"epss":[{"cve":"CVE-2016-1585","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.051699999999999996},"relatedVulnerabilities":[{"id":"CVE-2016-1585","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-1585","namespace":"nvd:cpe","severity":"Critical","urls":["https://bugs.launchpad.net/apparmor/+bug/1597017","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"In all versions of AppArmor mount rules are accidentally widened when compiled.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"exploitabilityScore":10,"impactScore":6.5},"vendorMetadata":{}},{"source":"security@ubuntu.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":3.9,"exploitabilityScore":0.5,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-1585","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"apparmor","version":"3.0.8-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-1585","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d8977f5e58b612a","name":"libapparmor1","version":"3.0.8-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapparmor1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libapparmor1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapparmor1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libapparmor1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+"],"cpes":["cpe:2.3:a:libapparmor1:libapparmor1:3.0.8-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libapparmor1@3.0.8-3?arch=amd64&distro=debian-12.15&upstream=apparmor","upstreams":[{"name":"apparmor"}]}},{"vulnerability":{"id":"CVE-2023-45931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45931","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.051699999999999996},"relatedVulnerabilities":[{"id":"CVE-2023-45931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45931","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/mesa/mesa/-/issues/9859","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176813/Mesa-23.0.4-Null-Pointer.html","http://seclists.org/fulldisclosure/2024/Jan/59","http://seclists.org/fulldisclosure/2024/Jan/71"],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bcb26e78046666fd","name":"libgl1-mesa-dri","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgl1-mesa-dri/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgl1-mesa-dri/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgl1-mesa-dri:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgl1-mesa-dri:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libgl1-mesa-dri:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa-dri:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa_dri:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa_dri:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgl1-mesa-dri@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45931","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.051699999999999996},"relatedVulnerabilities":[{"id":"CVE-2023-45931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45931","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/mesa/mesa/-/issues/9859","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176813/Mesa-23.0.4-Null-Pointer.html","http://seclists.org/fulldisclosure/2024/Jan/59","http://seclists.org/fulldisclosure/2024/Jan/71"],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c6640a6d53117c22","name":"libglapi-mesa","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglapi-mesa/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglapi-mesa/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglapi-mesa:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglapi-mesa:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libglapi-mesa:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi-mesa:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi_mesa:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi_mesa:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglapi-mesa@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45931","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.051699999999999996},"relatedVulnerabilities":[{"id":"CVE-2023-45931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45931","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/mesa/mesa/-/issues/9859","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176813/Mesa-23.0.4-Null-Pointer.html","http://seclists.org/fulldisclosure/2024/Jan/59","http://seclists.org/fulldisclosure/2024/Jan/71"],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"779a1dd5fe6d386a","name":"libglx-mesa0","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglx-mesa0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglx-mesa0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglx-mesa0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglx-mesa0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libglx-mesa0:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx-mesa0:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx_mesa0:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx_mesa0:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglx-mesa0@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45931","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.051699999999999996},"relatedVulnerabilities":[{"id":"CVE-2023-45931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45931","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/mesa/mesa/-/issues/9859","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176813/Mesa-23.0.4-Null-Pointer.html","http://seclists.org/fulldisclosure/2024/Jan/59","http://seclists.org/fulldisclosure/2024/Jan/71"],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0b67d63ef680c3ac","name":"mesa-va-drivers","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mesa-va-drivers/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/mesa-va-drivers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mesa-va-drivers:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/mesa-va-drivers:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:mesa-va-drivers:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va-drivers:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va_drivers:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va_drivers:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mesa-va-drivers@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45931","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.051699999999999996},"relatedVulnerabilities":[{"id":"CVE-2023-45931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45931","namespace":"nvd:cpe","severity":"High","urls":["https://gitlab.freedesktop.org/mesa/mesa/-/issues/9859","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176813/Mesa-23.0.4-Null-Pointer.html","http://seclists.org/fulldisclosure/2024/Jan/59","http://seclists.org/fulldisclosure/2024/Jan/71"],"description":"Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45931","epss":0.01034,"percentile":0.61802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45931","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"68ea5f670263c4bf","name":"mesa-vdpau-drivers","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mesa-vdpau-drivers/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/mesa-vdpau-drivers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mesa-vdpau-drivers:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/mesa-vdpau-drivers:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:mesa-vdpau-drivers:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau-drivers:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau_drivers:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau_drivers:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mesa-vdpau-drivers@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2026-73281","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73281","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"exploitabilityScore":1.8,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-73281","epss":0.00158,"percentile":0.0532,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.05134999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-73281","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openssh.org/releasenotes.html#10.5"],"description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"exploitabilityScore":1.8,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-73281","epss":0.00158,"percentile":0.0532,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2024-31852","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-31852","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can sometimes be an exploitable error in the flow of control. This affects the ARM backend and can be demonstrated with Clang. NOTE: the vendor perspective is \"we don't have strong objections for a CVE to be created ... It does seem that the likelihood of this miscompile enabling an exploit remains very low, because the miscompile resulting in this JOP gadget is such that the function is most likely to crash on most valid inputs to the function. So, if this function is covered by any testing, the miscompile is most likely to be discovered before the binary is shipped to production.\"","cvss":[],"epss":[{"cve":"CVE-2024-31852","epss":0.00991,"percentile":0.60462,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.049550000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-31852","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-31852","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.chromium.org/p/llvm/issues/detail?id=69","https://github.com/llvm/llvm-project/issues/80287","https://github.com/llvmbot/llvm-project/commit/0e16af8e4cf3a66ad5d078d52744ae2776f9c4b2","https://llvm.org/docs/Security.html"],"description":"LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can sometimes be an exploitable error in the flow of control. This affects the ARM backend and can be demonstrated with Clang. NOTE: the vendor perspective is \"we don't have strong objections for a CVE to be created ... It does seem that the likelihood of this miscompile enabling an exploit remains very low, because the miscompile resulting in this JOP gadget is such that the function is most likely to crash on most valid inputs to the function. So, if this function is covered by any testing, the miscompile is most likely to be discovered before the binary is shipped to production.\"","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-31852","epss":0.00991,"percentile":0.60462,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-31852","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2024-13978","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-13978","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation appears to be difficult. The patch is named 2ebfffb0e8836bfb1cd7d85c059cd285c59761a4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-13978","epss":0.00191,"percentile":0.08858,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-13978","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2024-13978","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04775},"relatedVulnerabilities":[{"id":"CVE-2024-13978","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-13978","namespace":"nvd:cpe","severity":"Low","urls":["http://www.libtiff.org/","https://gitlab.com/libtiff/libtiff/-/commit/2ebfffb0e8836bfb1cd7d85c059cd285c59761a4","https://gitlab.com/libtiff/libtiff/-/issues/649","https://gitlab.com/libtiff/libtiff/-/merge_requests/667","https://vuldb.com/?ctiid.318355","https://vuldb.com/?id.318355","https://vuldb.com/?submit.624562","https://lists.debian.org/debian-lts-announce/2025/09/msg00031.html"],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation appears to be difficult. The patch is named 2ebfffb0e8836bfb1cd7d85c059cd285c59761a4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:H/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1,"exploitabilityScore":1.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-13978","epss":0.00191,"percentile":0.08858,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-13978","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2024-13978","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-13978","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-24515","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24515","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24515","epss":0.00173,"percentile":0.06876,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.047575000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-24515","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24515","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/libexpat/libexpat/pull/1131","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24515","epss":0.00173,"percentile":0.06876,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-24515","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2026-24515","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24515","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24515","epss":0.00173,"percentile":0.06876,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.047575000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-24515","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24515","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/libexpat/libexpat/pull/1131","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-24515","epss":0.00173,"percentile":0.06876,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-24515","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-12474","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12474","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory.  This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":1.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12474","epss":0.00101,"percentile":0.00975,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12474","cwe":"CWE-908","source":"cve-coordination@google.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.047470000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-12474","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12474","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/libjxl/libjxl/pull/4495"],"description":"A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory.\n\nThis can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":1.9,"impactScore":2.6},"vendorMetadata":{}},{"source":"cve-coordination@google.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-12474","epss":0.00101,"percentile":0.00975,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-12474","cwe":"CWE-908","source":"cve-coordination@google.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jpeg-xl","version":"0.7.0-10+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-12474","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b6ad6e0f23e0de4d","name":"libjxl0.7","version":"0.7.0-10+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjxl0.7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjxl0.7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjxl0.7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause-Google","ISC-License"],"cpes":["cpe:2.3:a:libjxl0.7:libjxl0.7:0.7.0-10\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjxl0.7@0.7.0-10%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=jpeg-xl","upstreams":[{"name":"jpeg-xl"}]}},{"vulnerability":{"id":"CVE-2007-5686","dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-5686","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.","cvss":[],"epss":[{"cve":"CVE-2007-5686","epss":0.00942,"percentile":0.58899,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0471},"relatedVulnerabilities":[{"id":"CVE-2007-5686","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5686","namespace":"nvd:cpe","severity":"Medium","urls":["http://secunia.com/advisories/27215","http://www.securityfocus.com/archive/1/482129/100/100/threaded","http://www.securityfocus.com/archive/1/482857/100/0/threaded","http://www.securityfocus.com/bid/26048","http://www.vupen.com/english/advisories/2007/3474","https://issues.rpath.com/browse/RPL-1825"],"description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2007-5686","epss":0.00942,"percentile":0.58899,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2007-5686","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d5e0daed57b0ef5c","name":"login","version":"1:4.13+dfsg1-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/login.prerm"}],"language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/login@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","upstreams":[{"name":"shadow"}]}},{"vulnerability":{"id":"CVE-2007-5686","dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-5686","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.","cvss":[],"epss":[{"cve":"CVE-2007-5686","epss":0.00942,"percentile":0.58899,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0471},"relatedVulnerabilities":[{"id":"CVE-2007-5686","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5686","namespace":"nvd:cpe","severity":"Medium","urls":["http://secunia.com/advisories/27215","http://www.securityfocus.com/archive/1/482129/100/100/threaded","http://www.securityfocus.com/archive/1/482857/100/0/threaded","http://www.securityfocus.com/bid/26048","http://www.vupen.com/english/advisories/2007/3474","https://issues.rpath.com/browse/RPL-1825"],"description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2007-5686","epss":0.00942,"percentile":0.58899,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2007-5686","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1853000d374a22b0","name":"passwd","version":"1:4.13+dfsg1-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/passwd@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","upstreams":[{"name":"shadow"}]}},{"vulnerability":{"id":"CVE-2025-29070","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-29070","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because \"this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation.\"","cvss":[],"epss":[{"cve":"CVE-2025-29070","epss":0.00938,"percentile":0.58796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-29070","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.046900000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-29070","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-29070","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/mm2/Little-CMS/issues/475","https://github.com/mm2/Little-CMS/issues/475#issuecomment-2696785063"],"description":"A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because \"this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation.\"","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-29070","epss":0.00938,"percentile":0.58796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-29070","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"lcms2","version":"2.14-2+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-29070","versionConstraint":"none (unknown)"}}],"artifact":{"id":"575a9480952e6fa7","name":"liblcms2-2","version":"2.14-2+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblcms2-2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/liblcms2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblcms2-2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/liblcms2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","GPL-3","IJG","MIT"],"cpes":["cpe:2.3:a:liblcms2-2:liblcms2-2:2.14-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2-2:liblcms2_2:2.14-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2_2:liblcms2-2:2.14-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2_2:liblcms2_2:2.14-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2:liblcms2-2:2.14-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:liblcms2:liblcms2_2:2.14-2\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblcms2-2@2.14-2%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=lcms2","upstreams":[{"name":"lcms2"}]}},{"vulnerability":{"id":"CVE-2023-45924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45924","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45924","epss":0.0092,"percentile":0.58176,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45924","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2023-45924","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.046},"relatedVulnerabilities":[{"id":"CVE-2023-45924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45924","namespace":"nvd:cpe","severity":"Critical","urls":["http://seclists.org/fulldisclosure/2024/Jan/52","https://gitlab.freedesktop.org/glvnd/libglvnd/-/issues/242","https://gitlab.freedesktop.org/glvnd/libglvnd/-/merge_requests/295","http://packetstormsecurity.com/files/176807/libglvnd-bb06db5a-Buffer-Overflow-Null-Pointer.html"],"description":"libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45924","epss":0.0092,"percentile":0.58176,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45924","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2023-45924","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libglvnd","version":"1.6.0-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"67ff0050dd08f9e7","name":"libgl1","version":"1.6.0-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgl1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgl1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-1-clause","GPL","GPL-3","GPL-3+","MIT"],"cpes":["cpe:2.3:a:libgl1:libgl1:1.6.0-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgl1@1.6.0-1?arch=amd64&distro=debian-12.15&upstream=libglvnd","upstreams":[{"name":"libglvnd"}]}},{"vulnerability":{"id":"CVE-2023-45924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45924","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45924","epss":0.0092,"percentile":0.58176,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45924","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2023-45924","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.046},"relatedVulnerabilities":[{"id":"CVE-2023-45924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45924","namespace":"nvd:cpe","severity":"Critical","urls":["http://seclists.org/fulldisclosure/2024/Jan/52","https://gitlab.freedesktop.org/glvnd/libglvnd/-/issues/242","https://gitlab.freedesktop.org/glvnd/libglvnd/-/merge_requests/295","http://packetstormsecurity.com/files/176807/libglvnd-bb06db5a-Buffer-Overflow-Null-Pointer.html"],"description":"libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45924","epss":0.0092,"percentile":0.58176,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45924","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2023-45924","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libglvnd","version":"1.6.0-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b9aae7cff2c05a77","name":"libglvnd0","version":"1.6.0-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglvnd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglvnd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglvnd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglvnd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-1-clause","GPL","GPL-3","GPL-3+","MIT"],"cpes":["cpe:2.3:a:libglvnd0:libglvnd0:1.6.0-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglvnd0@1.6.0-1?arch=amd64&distro=debian-12.15&upstream=libglvnd","upstreams":[{"name":"libglvnd"}]}},{"vulnerability":{"id":"CVE-2023-45924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45924","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45924","epss":0.0092,"percentile":0.58176,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45924","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2023-45924","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.046},"relatedVulnerabilities":[{"id":"CVE-2023-45924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45924","namespace":"nvd:cpe","severity":"Critical","urls":["http://seclists.org/fulldisclosure/2024/Jan/52","https://gitlab.freedesktop.org/glvnd/libglvnd/-/issues/242","https://gitlab.freedesktop.org/glvnd/libglvnd/-/merge_requests/295","http://packetstormsecurity.com/files/176807/libglvnd-bb06db5a-Buffer-Overflow-Null-Pointer.html"],"description":"libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45924","epss":0.0092,"percentile":0.58176,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45924","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2023-45924","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libglvnd","version":"1.6.0-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"95c1af9a421800b4","name":"libglx0","version":"1.6.0-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglx0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglx0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglx0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglx0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-1-clause","GPL","GPL-3","GPL-3+","MIT"],"cpes":["cpe:2.3:a:libglx0:libglx0:1.6.0-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglx0@1.6.0-1?arch=amd64&distro=debian-12.15&upstream=libglvnd","upstreams":[{"name":"libglvnd"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"47f6ae6b597dbb7b","name":"cpp-12","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/cpp-12.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/cpp-12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/cpp-12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-12.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/cpp-12.list"}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:cpp-12:cpp-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp-12:cpp_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp_12:cpp-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp_12:cpp_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/cpp-12@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6ff8ff63ca8b7466","name":"g++-12","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/g++-12.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/g++-12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/g++-12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-12.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/g++-12.list"}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:g\\+\\+-12:g\\+\\+-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-12:g\\+\\+_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_12:g\\+\\+-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_12:g\\+\\+_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/g%2B%2B-12@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5c074d6bc3f2ee94","name":"gcc-12","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/gcc-12.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gcc-12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/gcc-12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gcc-12.list"}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:gcc-12:gcc-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gcc-12@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"58c10ea7ffbc22a3","name":"gcc-12-base","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/gcc-12-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"45a0296b4a207092","name":"libasan8","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libasan8:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libasan8:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libasan8/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libasan8:libasan8:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libasan8@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"50514db327ffe1b7","name":"libatomic1","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libatomic1/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libatomic1:libatomic1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libatomic1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4d6867490f2ee31b","name":"libcc1-0","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libcc1-0/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libcc1-0:libcc1-0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1-0:libcc1_0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1-0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1_0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1-0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1_0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcc1-0@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0a2c9fc9336a4052","name":"libgcc-12-dev","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgcc-12-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgcc-12-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libgcc-12-dev/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libgcc-12-dev:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-12-dev:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_12_dev:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_12_dev:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-12:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-12:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_12:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_12:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgcc-12-dev@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9454a77b5ea4561d","name":"libgcc-s1","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5c053ad6c4a6e4ee","name":"libgomp1","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libgomp1/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libgomp1:libgomp1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgomp1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d691685b72bfc39","name":"libitm1","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libitm1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libitm1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libitm1/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libitm1:libitm1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libitm1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d282807e9bb10aec","name":"liblsan0","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/liblsan0/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:liblsan0:liblsan0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/liblsan0@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"25f43087fc45f095","name":"libquadmath0","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libquadmath0/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libquadmath0:libquadmath0:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libquadmath0@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"23363a8f5cb22d0c","name":"libstdc++-12-dev","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libstdc++-12-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libstdc++-12-dev:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libstdc++-12-dev/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libstdc\\+\\+-12-dev:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-12-dev:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_12_dev:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_12_dev:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-12:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-12:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_12:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_12:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+-12-dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+_12_dev:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libstdc%2B%2B-12-dev@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c2f4fec51904a8ce","name":"libstdc++6","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"84ebb3dcf8d53111","name":"libtsan2","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libtsan2/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libtsan2:libtsan2:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtsan2@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2022-27943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04530000000000001},"relatedVulnerabilities":[{"id":"CVE-2022-27943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","namespace":"nvd:cpe","severity":"Medium","urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27943","epss":0.00906,"percentile":0.57748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eab3329c061e989f","name":"libubsan1","version":"12.2.0-14+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libubsan1/copyright","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"cpes":["cpe:2.3:a:libubsan1:libubsan1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libubsan1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","upstreams":[{"name":"gcc-12"}]}},{"vulnerability":{"id":"CVE-2023-1972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-1972","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04475},"relatedVulnerabilities":[{"id":"CVE-2023-1972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-1972","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2185646","https://security.gentoo.org/glsa/202309-15","https://sourceware.org/bugzilla/show_bug.cgi?id=30285"],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-1972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-1972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-1972","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04475},"relatedVulnerabilities":[{"id":"CVE-2023-1972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-1972","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2185646","https://security.gentoo.org/glsa/202309-15","https://sourceware.org/bugzilla/show_bug.cgi?id=30285"],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-1972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-1972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-1972","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04475},"relatedVulnerabilities":[{"id":"CVE-2023-1972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-1972","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2185646","https://security.gentoo.org/glsa/202309-15","https://sourceware.org/bugzilla/show_bug.cgi?id=30285"],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-1972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-1972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-1972","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04475},"relatedVulnerabilities":[{"id":"CVE-2023-1972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-1972","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2185646","https://security.gentoo.org/glsa/202309-15","https://sourceware.org/bugzilla/show_bug.cgi?id=30285"],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-1972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-1972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-1972","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04475},"relatedVulnerabilities":[{"id":"CVE-2023-1972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-1972","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2185646","https://security.gentoo.org/glsa/202309-15","https://sourceware.org/bugzilla/show_bug.cgi?id=30285"],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-1972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-1972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-1972","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04475},"relatedVulnerabilities":[{"id":"CVE-2023-1972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-1972","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2185646","https://security.gentoo.org/glsa/202309-15","https://sourceware.org/bugzilla/show_bug.cgi?id=30285"],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-1972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-1972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-1972","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04475},"relatedVulnerabilities":[{"id":"CVE-2023-1972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-1972","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2185646","https://security.gentoo.org/glsa/202309-15","https://sourceware.org/bugzilla/show_bug.cgi?id=30285"],"description":"A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-1972","epss":0.00895,"percentile":0.57391,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1972","cwe":"CWE-119","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1972","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-1972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-40359","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-40359","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.","cvss":[],"epss":[{"cve":"CVE-2023-40359","epss":0.00855,"percentile":0.56197,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04275},"relatedVulnerabilities":[{"id":"CVE-2023-40359","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-40359","namespace":"nvd:cpe","severity":"Critical","urls":["https://invisible-island.net/xterm/xterm.log.html#xterm_380"],"description":"xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-40359","epss":0.00855,"percentile":0.56197,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xterm","version":"379-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-40359","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d0240bda9c48e21b","name":"xterm","version":"379-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xterm/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xterm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xterm.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xterm.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xterm.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.list"},{"path":"/var/lib/dpkg/info/xterm.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.postinst"},{"path":"/var/lib/dpkg/info/xterm.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xterm.prerm"}],"language":"","licenses":["sha256:98e53d6eb11a468e199838883c5c0a756d12a3ece6e89b0ae4b98af77ee6e728"],"cpes":["cpe:2.3:a:xterm:xterm:379-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xterm@379-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c185e9c791136aa6","name":"dirmngr","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:dirmngr:dirmngr:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dirmngr@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e92d6b046326efbc","name":"gnupg","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg:gnupg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"976c5c43a7fe516a","name":"gnupg-l10n","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-l10n@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4d2b57169c4709a4","name":"gnupg-utils","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-utils@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1b50350895a48a3b","name":"gpg","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg:gpg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"01ceda49a85ecdc9","name":"gpg-agent","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-agent@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2ce7ba29a10f5f2d","name":"gpg-wks-client","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-wks-client@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5c929b5e7563826e","name":"gpg-wks-server","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-server/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-wks-server/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-server.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-server.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-wks-server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-wks-server@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"45da524630bb2133","name":"gpgconf","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgconf:gpgconf:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgconf@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b982b129e67b17ad","name":"gpgsm","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgsm:gpgsm:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgsm@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.04189},"relatedVulnerabilities":[{"id":"CVE-2026-57062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","namespace":"nvd:cpe","severity":"Low","urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57062","epss":0.00142,"percentile":0.03872,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bab4532a87a829c8","name":"gpgv","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2026-57053","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57053","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57053","epss":0.00149,"percentile":0.04405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57053","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"},{"cve":"CVE-2026-57053","cwe":"CWE-1284","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.040975000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-57053","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57053","namespace":"nvd:cpe","severity":"Low","urls":["https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html","https://lists.gnu.org/archive/html/help-libidn/2026-06/msg00001.html"],"description":"GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4,"exploitabilityScore":1.5,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-57053","epss":0.00149,"percentile":0.04405,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-57053","cwe":"CWE-1284","source":"cve@mitre.org","type":"Primary"},{"cve":"CVE-2026-57053","cwe":"CWE-1284","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libidn","version":"1.41-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-57053","versionConstraint":"none (unknown)"}}],"artifact":{"id":"584c0ea61ff0a8df","name":"libidn12","version":"1.41-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libidn12/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libidn12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libidn12:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libidn12:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GAP","GFDL-1.3","GFDL-NIV-1.3+","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:libidn12:libidn12:1.41-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libidn12@1.41-1?arch=amd64&distro=debian-12.15&upstream=libidn","upstreams":[{"name":"libidn"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3fb79a418234f4d0","name":"krb5-locales","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/krb5-locales@1.20.1-2%2Bdeb12u5?arch=all&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9db16cb04ae3b83d","name":"libgssapi-krb5-2","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fb1c9cf5b43a5af0","name":"libk5crypto3","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"52548f50c4ff26c7","name":"libkrb5-3","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-26458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04075},"relatedVulnerabilities":[{"id":"CVE-2024-26458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26458","epss":0.00815,"percentile":0.5492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"309b5ab55a11c7d0","name":"libkrb5support0","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2025-1178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1178","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.040150000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-1178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1178","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15914","https://sourceware.org/bugzilla/show_bug.cgi?id=32638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=75086e9de1707281172cc77f178e7949a4414ed0","https://vuldb.com/?ctiid.295081","https://vuldb.com/?id.295081","https://vuldb.com/?submit.495369","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0008/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":2.3,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1178","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.040150000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-1178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1178","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15914","https://sourceware.org/bugzilla/show_bug.cgi?id=32638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=75086e9de1707281172cc77f178e7949a4414ed0","https://vuldb.com/?ctiid.295081","https://vuldb.com/?id.295081","https://vuldb.com/?submit.495369","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0008/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":2.3,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1178","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.040150000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-1178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1178","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15914","https://sourceware.org/bugzilla/show_bug.cgi?id=32638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=75086e9de1707281172cc77f178e7949a4414ed0","https://vuldb.com/?ctiid.295081","https://vuldb.com/?id.295081","https://vuldb.com/?submit.495369","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0008/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":2.3,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1178","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.040150000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-1178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1178","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15914","https://sourceware.org/bugzilla/show_bug.cgi?id=32638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=75086e9de1707281172cc77f178e7949a4414ed0","https://vuldb.com/?ctiid.295081","https://vuldb.com/?id.295081","https://vuldb.com/?submit.495369","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0008/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":2.3,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1178","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.040150000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-1178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1178","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15914","https://sourceware.org/bugzilla/show_bug.cgi?id=32638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=75086e9de1707281172cc77f178e7949a4414ed0","https://vuldb.com/?ctiid.295081","https://vuldb.com/?id.295081","https://vuldb.com/?submit.495369","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0008/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":2.3,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1178","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.040150000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-1178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1178","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15914","https://sourceware.org/bugzilla/show_bug.cgi?id=32638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=75086e9de1707281172cc77f178e7949a4414ed0","https://vuldb.com/?ctiid.295081","https://vuldb.com/?id.295081","https://vuldb.com/?submit.495369","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0008/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":2.3,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1178","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.040150000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-1178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1178","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15914","https://sourceware.org/bugzilla/show_bug.cgi?id=32638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=75086e9de1707281172cc77f178e7949a4414ed0","https://vuldb.com/?ctiid.295081","https://vuldb.com/?id.295081","https://vuldb.com/?submit.495369","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0008/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":2.3,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1178","epss":0.00803,"percentile":0.54533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1178","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-49463","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-49463","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.","cvss":[],"epss":[{"cve":"CVE-2023-49463","epss":0.00768,"percentile":0.53409,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.038400000000000004},"relatedVulnerabilities":[{"id":"CVE-2023-49463","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49463","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif","https://github.com/strukturag/libheif/issues/1042"],"description":"libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-49463","epss":0.00768,"percentile":0.53409,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-49463","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2023-46361","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-46361","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.","cvss":[],"epss":[{"cve":"CVE-2023-46361","epss":0.00753,"percentile":0.52903,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-46361","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03765},"relatedVulnerabilities":[{"id":"CVE-2023-46361","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-46361","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/Frank-Z7/z-vulnerabilitys/blob/main/jbig2dec-SEGV/jbig2dec-SEGV.md"],"description":"Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-46361","epss":0.00753,"percentile":0.52903,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-46361","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jbig2dec","version":"0.19-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-46361","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4d5d6351b6af6711","name":"libjbig2dec0","version":"0.19-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjbig2dec0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjbig2dec0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjbig2dec0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjbig2dec0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AGPL-3+","BSD-2-clause","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","pubic-domain","public-domain"],"cpes":["cpe:2.3:a:libjbig2dec0:libjbig2dec0:0.19-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjbig2dec0@0.19-3?arch=amd64&distro=debian-12.15&upstream=jbig2dec","upstreams":[{"name":"jbig2dec"}]}},{"vulnerability":{"id":"CVE-2026-18477","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18477","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18477","epss":0.0008,"percentile":0.00178,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0376},"relatedVulnerabilities":[{"id":"CVE-2026-18477","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18477","epss":0.0008,"percentile":0.00178,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f8ad3f5238dbcf6a","name":"tar","version":"1.34+dfsg-1.2+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2024-21808","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-21808","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-21808","epss":0.00188,"percentile":0.08574,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-21808","cwe":"CWE-92","source":"secure@intel.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0376},"relatedVulnerabilities":[{"id":"CVE-2024-21808","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-21808","namespace":"nvd:cpe","severity":"Low","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01131.html"],"description":"Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1},"vendorMetadata":{}},{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.2,"exploitabilityScore":0.8,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-21808","epss":0.00188,"percentile":0.08574,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-21808","cwe":"CWE-92","source":"secure@intel.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-21808","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0375},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0375},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0375},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0375},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0375},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0375},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-11940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330.","cvss":[],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0375},"relatedVulnerabilities":[{"id":"CVE-2026-11940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11940","epss":0.0075,"percentile":0.52802,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","source":"cna@python.org","type":"Secondary"},{"cve":"CVE-2026-11940","cwe":"CWE-59","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2021-32256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-32256","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.037450000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-32256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-32256","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070","https://security.netapp.com/advisory/ntap-20230824-0013/"],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-32256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2021-32256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-32256","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.037450000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-32256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-32256","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070","https://security.netapp.com/advisory/ntap-20230824-0013/"],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-32256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2021-32256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-32256","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.037450000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-32256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-32256","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070","https://security.netapp.com/advisory/ntap-20230824-0013/"],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-32256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2021-32256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-32256","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.037450000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-32256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-32256","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070","https://security.netapp.com/advisory/ntap-20230824-0013/"],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-32256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2021-32256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-32256","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.037450000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-32256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-32256","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070","https://security.netapp.com/advisory/ntap-20230824-0013/"],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-32256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2021-32256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-32256","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.037450000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-32256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-32256","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070","https://security.netapp.com/advisory/ntap-20230824-0013/"],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-32256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2021-32256","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-32256","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.037450000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-32256","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-32256","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070","https://security.netapp.com/advisory/ntap-20230824-0013/"],"description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-32256","epss":0.00749,"percentile":0.5276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-32256","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-32256","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-0840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03735},"relatedVulnerabilities":[{"id":"CVE-2025-0840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0840","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15882","https://sourceware.org/bugzilla/show_bug.cgi?id=32560","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893","https://vuldb.com/?ctiid.293997","https://vuldb.com/?id.293997","https://vuldb.com/?submit.485255","https://www.gnu.org/"],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-0840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03735},"relatedVulnerabilities":[{"id":"CVE-2025-0840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0840","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15882","https://sourceware.org/bugzilla/show_bug.cgi?id=32560","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893","https://vuldb.com/?ctiid.293997","https://vuldb.com/?id.293997","https://vuldb.com/?submit.485255","https://www.gnu.org/"],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-0840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03735},"relatedVulnerabilities":[{"id":"CVE-2025-0840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0840","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15882","https://sourceware.org/bugzilla/show_bug.cgi?id=32560","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893","https://vuldb.com/?ctiid.293997","https://vuldb.com/?id.293997","https://vuldb.com/?submit.485255","https://www.gnu.org/"],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-0840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03735},"relatedVulnerabilities":[{"id":"CVE-2025-0840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0840","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15882","https://sourceware.org/bugzilla/show_bug.cgi?id=32560","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893","https://vuldb.com/?ctiid.293997","https://vuldb.com/?id.293997","https://vuldb.com/?submit.485255","https://www.gnu.org/"],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-0840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03735},"relatedVulnerabilities":[{"id":"CVE-2025-0840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0840","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15882","https://sourceware.org/bugzilla/show_bug.cgi?id=32560","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893","https://vuldb.com/?ctiid.293997","https://vuldb.com/?id.293997","https://vuldb.com/?submit.485255","https://www.gnu.org/"],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-0840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03735},"relatedVulnerabilities":[{"id":"CVE-2025-0840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0840","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15882","https://sourceware.org/bugzilla/show_bug.cgi?id=32560","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893","https://vuldb.com/?ctiid.293997","https://vuldb.com/?id.293997","https://vuldb.com/?submit.485255","https://www.gnu.org/"],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-0840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-0840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03735},"relatedVulnerabilities":[{"id":"CVE-2025-0840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0840","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15882","https://sourceware.org/bugzilla/show_bug.cgi?id=32560","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=baac6c221e9d69335bf41366a1c7d87d8ab2f893","https://vuldb.com/?ctiid.293997","https://vuldb.com/?id.293997","https://vuldb.com/?submit.485255","https://www.gnu.org/"],"description":"A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-0840","epss":0.00747,"percentile":0.52702,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-0840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-0840","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-0840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-28051","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-28051","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Out-of-bounds read in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable information disclosure via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-28051","epss":0.00186,"percentile":0.08274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-28051","cwe":"CWE-125","source":"secure@intel.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.037200000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-28051","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28051","namespace":"nvd:cpe","severity":"Low","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01131.html"],"description":"Out-of-bounds read in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable information disclosure via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1},"vendorMetadata":{}},{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.2,"exploitabilityScore":0.8,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-28051","epss":0.00186,"percentile":0.08274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-28051","cwe":"CWE-125","source":"secure@intel.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-28051","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2017-11695","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11695","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[],"epss":[{"cve":"CVE-2017-11695","epss":0.00736,"percentile":0.52323,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-11695","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.036800000000000006},"relatedVulnerabilities":[{"id":"CVE-2017-11695","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11695","namespace":"nvd:cpe","severity":"High","urls":["http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html","http://seclists.org/fulldisclosure/2017/Aug/17","http://www.geeknik.net/9brdqk6xu","http://www.securityfocus.com/bid/100345","http://www.securitytracker.com/id/1039153","https://security.gentoo.org/glsa/202003-37"],"description":"Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-11695","epss":0.00736,"percentile":0.52323,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-11695","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nss","version":"2:3.87.1-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-11695","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3325a62774655e15","name":"libnss3","version":"2:3.87.1-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3","MPL-2.0","Zlib","public-domain"],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.87.1-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.87.1-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2017-11696","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11696","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[],"epss":[{"cve":"CVE-2017-11696","epss":0.00736,"percentile":0.52323,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-11696","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.036800000000000006},"relatedVulnerabilities":[{"id":"CVE-2017-11696","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11696","namespace":"nvd:cpe","severity":"High","urls":["http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html","http://seclists.org/fulldisclosure/2017/Aug/17","http://www.geeknik.net/9brdqk6xu","http://www.securityfocus.com/bid/100345","http://www.securitytracker.com/id/1039153","https://security.gentoo.org/glsa/202003-37"],"description":"Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-11696","epss":0.00736,"percentile":0.52323,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-11696","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nss","version":"2:3.87.1-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-11696","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3325a62774655e15","name":"libnss3","version":"2:3.87.1-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3","MPL-2.0","Zlib","public-domain"],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.87.1-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.87.1-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2017-11698","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11698","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[],"epss":[{"cve":"CVE-2017-11698","epss":0.00736,"percentile":0.52323,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-11698","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.036800000000000006},"relatedVulnerabilities":[{"id":"CVE-2017-11698","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11698","namespace":"nvd:cpe","severity":"High","urls":["http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html","http://seclists.org/fulldisclosure/2017/Aug/17","http://www.geeknik.net/9brdqk6xu","http://www.securityfocus.com/bid/100345","http://www.securitytracker.com/id/1039153","https://security.gentoo.org/glsa/202003-37"],"description":"Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-11698","epss":0.00736,"percentile":0.52323,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-11698","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nss","version":"2:3.87.1-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-11698","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3325a62774655e15","name":"libnss3","version":"2:3.87.1-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3","MPL-2.0","Zlib","public-domain"],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.87.1-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.87.1-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2025-1181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1181","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0359},"relatedVulnerabilities":[{"id":"CVE-2025-1181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1181","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15918","https://sourceware.org/bugzilla/show_bug.cgi?id=32643","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=931494c9a89558acb36a03a340c01726545eef24","https://vuldb.com/?ctiid.295084","https://vuldb.com/?id.295084","https://vuldb.com/?submit.495402","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250425-0007/"],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1181","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1181","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0359},"relatedVulnerabilities":[{"id":"CVE-2025-1181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1181","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15918","https://sourceware.org/bugzilla/show_bug.cgi?id=32643","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=931494c9a89558acb36a03a340c01726545eef24","https://vuldb.com/?ctiid.295084","https://vuldb.com/?id.295084","https://vuldb.com/?submit.495402","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250425-0007/"],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1181","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1181","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0359},"relatedVulnerabilities":[{"id":"CVE-2025-1181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1181","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15918","https://sourceware.org/bugzilla/show_bug.cgi?id=32643","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=931494c9a89558acb36a03a340c01726545eef24","https://vuldb.com/?ctiid.295084","https://vuldb.com/?id.295084","https://vuldb.com/?submit.495402","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250425-0007/"],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1181","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1181","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0359},"relatedVulnerabilities":[{"id":"CVE-2025-1181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1181","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15918","https://sourceware.org/bugzilla/show_bug.cgi?id=32643","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=931494c9a89558acb36a03a340c01726545eef24","https://vuldb.com/?ctiid.295084","https://vuldb.com/?id.295084","https://vuldb.com/?submit.495402","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250425-0007/"],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1181","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1181","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0359},"relatedVulnerabilities":[{"id":"CVE-2025-1181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1181","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15918","https://sourceware.org/bugzilla/show_bug.cgi?id=32643","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=931494c9a89558acb36a03a340c01726545eef24","https://vuldb.com/?ctiid.295084","https://vuldb.com/?id.295084","https://vuldb.com/?submit.495402","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250425-0007/"],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1181","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1181","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0359},"relatedVulnerabilities":[{"id":"CVE-2025-1181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1181","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15918","https://sourceware.org/bugzilla/show_bug.cgi?id=32643","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=931494c9a89558acb36a03a340c01726545eef24","https://vuldb.com/?ctiid.295084","https://vuldb.com/?id.295084","https://vuldb.com/?submit.495402","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250425-0007/"],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1181","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1181","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0359},"relatedVulnerabilities":[{"id":"CVE-2025-1181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1181","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15918","https://sourceware.org/bugzilla/show_bug.cgi?id=32643","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=931494c9a89558acb36a03a340c01726545eef24","https://vuldb.com/?ctiid.295084","https://vuldb.com/?id.295084","https://vuldb.com/?submit.495402","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250425-0007/"],"description":"A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1181","epss":0.00718,"percentile":0.51699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1181","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1181","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-28030","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-28030","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"NULL pointer dereference in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable denial of service via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-28030","epss":0.00178,"percentile":0.07418,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-28030","cwe":"CWE-395","source":"secure@intel.com","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0356},"relatedVulnerabilities":[{"id":"CVE-2024-28030","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28030","namespace":"nvd:cpe","severity":"Low","urls":["https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01131.html"],"description":"NULL pointer dereference in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable denial of service via local access.","cvss":[{"source":"secure@intel.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1},"vendorMetadata":{}},{"source":"secure@intel.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.2,"exploitabilityScore":0.8,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-28030","epss":0.00178,"percentile":0.07418,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-28030","cwe":"CWE-395","source":"secure@intel.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"intel-mediasdk","version":"22.5.4-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-28030","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5d758dc934bf2160","name":"libmfx1","version":"22.5.4-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmfx1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libmfx1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libmfx1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","MIT","NTP"],"cpes":["cpe:2.3:a:libmfx1:libmfx1:22.5.4-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmfx1@22.5.4-1?arch=amd64&distro=debian-12.15&upstream=intel-mediasdk","upstreams":[{"name":"intel-mediasdk"}]}},{"vulnerability":{"id":"CVE-2021-45261","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-45261","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.","cvss":[],"epss":[{"cve":"CVE-2021-45261","epss":0.00705,"percentile":0.51235,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-45261","cwe":"CWE-763","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.035250000000000004},"relatedVulnerabilities":[{"id":"CVE-2021-45261","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-45261","namespace":"nvd:cpe","severity":"Medium","urls":["https://savannah.gnu.org/bugs/?61685"],"description":"An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-45261","epss":0.00705,"percentile":0.51235,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-45261","cwe":"CWE-763","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-45261","versionConstraint":"none (unknown)"}}],"artifact":{"id":"acc529981c64331f","name":"patch","version":"2.7.6-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.list"}],"language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1180","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0349},"relatedVulnerabilities":[{"id":"CVE-2025-1180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1180","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15917","https://sourceware.org/bugzilla/show_bug.cgi?id=32642","https://vuldb.com/?ctiid.295083","https://vuldb.com/?id.295083","https://vuldb.com/?submit.495381","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1180","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1180","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0349},"relatedVulnerabilities":[{"id":"CVE-2025-1180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1180","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15917","https://sourceware.org/bugzilla/show_bug.cgi?id=32642","https://vuldb.com/?ctiid.295083","https://vuldb.com/?id.295083","https://vuldb.com/?submit.495381","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1180","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1180","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0349},"relatedVulnerabilities":[{"id":"CVE-2025-1180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1180","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15917","https://sourceware.org/bugzilla/show_bug.cgi?id=32642","https://vuldb.com/?ctiid.295083","https://vuldb.com/?id.295083","https://vuldb.com/?submit.495381","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1180","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1180","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0349},"relatedVulnerabilities":[{"id":"CVE-2025-1180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1180","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15917","https://sourceware.org/bugzilla/show_bug.cgi?id=32642","https://vuldb.com/?ctiid.295083","https://vuldb.com/?id.295083","https://vuldb.com/?submit.495381","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1180","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1180","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0349},"relatedVulnerabilities":[{"id":"CVE-2025-1180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1180","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15917","https://sourceware.org/bugzilla/show_bug.cgi?id=32642","https://vuldb.com/?ctiid.295083","https://vuldb.com/?id.295083","https://vuldb.com/?submit.495381","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1180","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1180","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0349},"relatedVulnerabilities":[{"id":"CVE-2025-1180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1180","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15917","https://sourceware.org/bugzilla/show_bug.cgi?id=32642","https://vuldb.com/?ctiid.295083","https://vuldb.com/?id.295083","https://vuldb.com/?submit.495381","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1180","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1180","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0349},"relatedVulnerabilities":[{"id":"CVE-2025-1180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1180","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15917","https://sourceware.org/bugzilla/show_bug.cgi?id=32642","https://vuldb.com/?ctiid.295083","https://vuldb.com/?id.295083","https://vuldb.com/?submit.495381","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1180","epss":0.00698,"percentile":0.50983,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1180","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1180","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-25269","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-25269","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.","cvss":[],"epss":[{"cve":"CVE-2024-25269","epss":0.00687,"percentile":0.50582,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25269","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.034350000000000006},"relatedVulnerabilities":[{"id":"CVE-2024-25269","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-25269","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/strukturag/libheif/issues/1073"],"description":"libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-25269","epss":0.00687,"percentile":0.50582,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25269","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-25269","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-86137","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86137","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86137","epss":0.00116,"percentile":0.01823,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","source":"cve@mitre.org","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03422},"relatedVulnerabilities":[{"id":"CVE-2026-86137","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86137","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099"],"description":"In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86137","epss":0.00116,"percentile":0.01823,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","source":"cve@mitre.org","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86137","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-86141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86141","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86141","epss":0.00116,"percentile":0.01823,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86141","cwe":"CWE-252","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03422},"relatedVulnerabilities":[{"id":"CVE-2026-86141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86141","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107"],"description":"xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"exploitabilityScore":1.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-86141","epss":0.00116,"percentile":0.01823,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-86141","cwe":"CWE-252","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-86141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1176","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0339},"relatedVulnerabilities":[{"id":"CVE-2025-1176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1176","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15913","https://sourceware.org/bugzilla/show_bug.cgi?id=32636","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f9978defb6fab0bd8583942d97c112b0932ac814","https://vuldb.com/?ctiid.295079","https://vuldb.com/?id.295079","https://vuldb.com/?submit.495329","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0007/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1176","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0339},"relatedVulnerabilities":[{"id":"CVE-2025-1176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1176","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15913","https://sourceware.org/bugzilla/show_bug.cgi?id=32636","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f9978defb6fab0bd8583942d97c112b0932ac814","https://vuldb.com/?ctiid.295079","https://vuldb.com/?id.295079","https://vuldb.com/?submit.495329","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0007/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1176","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0339},"relatedVulnerabilities":[{"id":"CVE-2025-1176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1176","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15913","https://sourceware.org/bugzilla/show_bug.cgi?id=32636","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f9978defb6fab0bd8583942d97c112b0932ac814","https://vuldb.com/?ctiid.295079","https://vuldb.com/?id.295079","https://vuldb.com/?submit.495329","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0007/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1176","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0339},"relatedVulnerabilities":[{"id":"CVE-2025-1176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1176","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15913","https://sourceware.org/bugzilla/show_bug.cgi?id=32636","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f9978defb6fab0bd8583942d97c112b0932ac814","https://vuldb.com/?ctiid.295079","https://vuldb.com/?id.295079","https://vuldb.com/?submit.495329","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0007/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1176","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0339},"relatedVulnerabilities":[{"id":"CVE-2025-1176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1176","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15913","https://sourceware.org/bugzilla/show_bug.cgi?id=32636","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f9978defb6fab0bd8583942d97c112b0932ac814","https://vuldb.com/?ctiid.295079","https://vuldb.com/?id.295079","https://vuldb.com/?submit.495329","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0007/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1176","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0339},"relatedVulnerabilities":[{"id":"CVE-2025-1176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1176","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15913","https://sourceware.org/bugzilla/show_bug.cgi?id=32636","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f9978defb6fab0bd8583942d97c112b0932ac814","https://vuldb.com/?ctiid.295079","https://vuldb.com/?id.295079","https://vuldb.com/?submit.495329","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0007/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1176","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0339},"relatedVulnerabilities":[{"id":"CVE-2025-1176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1176","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15913","https://sourceware.org/bugzilla/show_bug.cgi?id=32636","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f9978defb6fab0bd8583942d97c112b0932ac814","https://vuldb.com/?ctiid.295079","https://vuldb.com/?id.295079","https://vuldb.com/?submit.495329","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250411-0007/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1176","epss":0.00678,"percentile":0.50221,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1176","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-25467","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-25467","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.","cvss":[],"epss":[{"cve":"CVE-2025-25467","epss":0.00672,"percentile":0.49962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-25467","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.033600000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-25467","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-25467","namespace":"nvd:cpe","severity":"Critical","urls":["https://code.videolan.org/videolan/x264/-/issues/75"],"description":"Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-25467","epss":0.00672,"percentile":0.49962,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-25467","cwe":"CWE-94","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"x264","version":"2:0.164.3095+gitbaee400-3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-25467","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bb2a19a0fe1dc56","name":"libx264-164","version":"2:0.164.3095+gitbaee400-3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx264-164/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libx264-164/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx264-164:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libx264-164:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","Expat","GPL-2","GPL-2+","ISC","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libx264-164:libx264-164:2\\:0.164.3095\\+gitbaee400-3:*:*:*:*:*:*:*","cpe:2.3:a:libx264-164:libx264_164:2\\:0.164.3095\\+gitbaee400-3:*:*:*:*:*:*:*","cpe:2.3:a:libx264_164:libx264-164:2\\:0.164.3095\\+gitbaee400-3:*:*:*:*:*:*:*","cpe:2.3:a:libx264_164:libx264_164:2\\:0.164.3095\\+gitbaee400-3:*:*:*:*:*:*:*","cpe:2.3:a:libx264:libx264-164:2\\:0.164.3095\\+gitbaee400-3:*:*:*:*:*:*:*","cpe:2.3:a:libx264:libx264_164:2\\:0.164.3095\\+gitbaee400-3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libx264-164@2%3A0.164.3095%2Bgitbaee400-3?arch=amd64&distro=debian-12.15&upstream=x264","upstreams":[{"name":"x264"}]}},{"vulnerability":{"id":"CVE-2025-1147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1147","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03355},"relatedVulnerabilities":[{"id":"CVE-2025-1147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1147","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15881","https://sourceware.org/bugzilla/show_bug.cgi?id=32556","https://vuldb.com/?ctiid.295051","https://vuldb.com/?id.295051","https://vuldb.com/?submit.485254","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0003/"],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1147","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03355},"relatedVulnerabilities":[{"id":"CVE-2025-1147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1147","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15881","https://sourceware.org/bugzilla/show_bug.cgi?id=32556","https://vuldb.com/?ctiid.295051","https://vuldb.com/?id.295051","https://vuldb.com/?submit.485254","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0003/"],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1147","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03355},"relatedVulnerabilities":[{"id":"CVE-2025-1147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1147","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15881","https://sourceware.org/bugzilla/show_bug.cgi?id=32556","https://vuldb.com/?ctiid.295051","https://vuldb.com/?id.295051","https://vuldb.com/?submit.485254","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0003/"],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1147","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03355},"relatedVulnerabilities":[{"id":"CVE-2025-1147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1147","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15881","https://sourceware.org/bugzilla/show_bug.cgi?id=32556","https://vuldb.com/?ctiid.295051","https://vuldb.com/?id.295051","https://vuldb.com/?submit.485254","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0003/"],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1147","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03355},"relatedVulnerabilities":[{"id":"CVE-2025-1147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1147","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15881","https://sourceware.org/bugzilla/show_bug.cgi?id=32556","https://vuldb.com/?ctiid.295051","https://vuldb.com/?id.295051","https://vuldb.com/?submit.485254","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0003/"],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1147","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03355},"relatedVulnerabilities":[{"id":"CVE-2025-1147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1147","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15881","https://sourceware.org/bugzilla/show_bug.cgi?id=32556","https://vuldb.com/?ctiid.295051","https://vuldb.com/?id.295051","https://vuldb.com/?submit.485254","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0003/"],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1147","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03355},"relatedVulnerabilities":[{"id":"CVE-2025-1147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1147","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15881","https://sourceware.org/bugzilla/show_bug.cgi?id=32556","https://vuldb.com/?ctiid.295051","https://vuldb.com/?id.295051","https://vuldb.com/?submit.485254","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0003/"],"description":"A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1147","epss":0.00671,"percentile":0.4991,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1147","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1147","cwe":"CWE-120","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-16742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03334499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-16742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4a63521ec2fd3be","name":"libnss-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libnss-systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss-systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-16742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03334499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-16742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c085cdccd13efd58","name":"libpam-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpam-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libpam-systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-16742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03334499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-16742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f08c824a2d960023","name":"libsystemd-shared","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd-shared/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsystemd-shared/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd-shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd-shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd-shared@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-16742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03334499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-16742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fa8be228d5b7724c","name":"libsystemd0","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-16742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03334499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-16742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"55089f35a6363c37","name":"libudev1","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-16742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03334499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-16742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40fe219b13a5306","name":"systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd:systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-16742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03334499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-16742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8dbabe3bd671d120","name":"systemd-sysv","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-sysv@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-16742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.03334499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-16742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user","cvss":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16742","epss":0.00057,"percentile":0.00005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2026-16742","cwe":"CWE-347","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e4b498470090a3c","name":"systemd-timesyncd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-timesyncd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-timesyncd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.list"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postinst"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postrm"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.prerm"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-timesyncd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2025-1352","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1352","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1352","epss":0.00652,"percentile":0.49148,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1352","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.032600000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-1352","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1352","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15923","https://sourceware.org/bugzilla/show_bug.cgi?id=32650","https://sourceware.org/bugzilla/show_bug.cgi?id=32650#c2","https://vuldb.com/?ctiid.295960","https://vuldb.com/?id.295960","https://vuldb.com/?submit.495965","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1352","epss":0.00652,"percentile":0.49148,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1352","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1352","versionConstraint":"none (unknown)"}}],"artifact":{"id":"00b653c92ba9a809","name":"libelf1","version":"0.188-2.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","upstreams":[{"name":"elfutils"}]}},{"vulnerability":{"id":"CVE-2026-18503","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.032130000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-18503","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-18503","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.032130000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-18503","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-18503","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.032130000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-18503","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-18503","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.032130000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-18503","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-18503","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.032130000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-18503","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-18503","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.032130000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-18503","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-18503","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.032130000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-18503","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18503","epss":0.00119,"percentile":0.02005,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-1148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1148","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03205},"relatedVulnerabilities":[{"id":"CVE-2025-1148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1148","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295052","https://vuldb.com/?id.295052","https://vuldb.com/?submit.485747","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0004/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1148","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1148","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03205},"relatedVulnerabilities":[{"id":"CVE-2025-1148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1148","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295052","https://vuldb.com/?id.295052","https://vuldb.com/?submit.485747","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0004/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1148","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1148","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03205},"relatedVulnerabilities":[{"id":"CVE-2025-1148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1148","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295052","https://vuldb.com/?id.295052","https://vuldb.com/?submit.485747","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0004/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1148","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1148","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03205},"relatedVulnerabilities":[{"id":"CVE-2025-1148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1148","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295052","https://vuldb.com/?id.295052","https://vuldb.com/?submit.485747","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0004/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1148","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1148","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03205},"relatedVulnerabilities":[{"id":"CVE-2025-1148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1148","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295052","https://vuldb.com/?id.295052","https://vuldb.com/?submit.485747","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0004/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1148","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1148","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03205},"relatedVulnerabilities":[{"id":"CVE-2025-1148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1148","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295052","https://vuldb.com/?id.295052","https://vuldb.com/?submit.485747","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0004/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1148","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1148","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03205},"relatedVulnerabilities":[{"id":"CVE-2025-1148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1148","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295052","https://vuldb.com/?id.295052","https://vuldb.com/?submit.485747","https://www.gnu.org/","https://security.netapp.com/advisory/ntap-20250404-0004/"],"description":"A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1148","epss":0.00641,"percentile":0.48618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1148","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1148","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1152","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0308},"relatedVulnerabilities":[{"id":"CVE-2025-1152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1152","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0308},"relatedVulnerabilities":[{"id":"CVE-2025-1152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1152","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0308},"relatedVulnerabilities":[{"id":"CVE-2025-1152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1152","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0308},"relatedVulnerabilities":[{"id":"CVE-2025-1152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1152","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0308},"relatedVulnerabilities":[{"id":"CVE-2025-1152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1152","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0308},"relatedVulnerabilities":[{"id":"CVE-2025-1152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1152","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0308},"relatedVulnerabilities":[{"id":"CVE-2025-1152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1152","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295056","https://vuldb.com/?id.295056","https://www.gnu.org/"],"description":"A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"exploitabilityScore":2.3,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1152","epss":0.00616,"percentile":0.47482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1152","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2021-4217","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-4217","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.","cvss":[],"epss":[{"cve":"CVE-2021-4217","epss":0.00616,"percentile":0.47458,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-4217","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-4217","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0308},"relatedVulnerabilities":[{"id":"CVE-2021-4217","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4217","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2021-4217","https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1957077","https://bugzilla.redhat.com/show_bug.cgi?id=2044583"],"description":"A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-4217","epss":0.00616,"percentile":0.47458,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-4217","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-4217","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"unzip","version":"6.0-28"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-4217","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d86d104b2d6876f3","name":"unzip","version":"6.0-28","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/unzip/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/unzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/unzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/unzip.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/unzip.list"},{"path":"/var/lib/dpkg/info/unzip.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/unzip.postinst"},{"path":"/var/lib/dpkg/info/unzip.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/unzip.postrm"}],"language":"","licenses":["sha256:aacc60ee90cc889820675362044cce73adf6bd97ed39cf847bb902ccdf6a4b63"],"cpes":["cpe:2.3:a:unzip:unzip:6.0-28:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/unzip@6.0-28?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1150","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1150","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030600000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1150","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1150","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1150","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030600000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1150","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1150","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1150","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030600000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1150","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1150","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1150","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030600000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1150","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1150","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1150","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030600000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1150","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1150","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1150","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030600000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1150","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1150","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1150","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030600000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1150","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1150","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295054","https://vuldb.com/?id.295054","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1150","epss":0.00612,"percentile":0.47277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1150","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1150","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1151","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030350000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1151","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030350000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1151","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030350000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1151","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030350000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1151","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030350000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1151","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030350000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1151","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.030350000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1151","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295055","https://vuldb.com/?id.295055","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1151","epss":0.00607,"percentile":0.47039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1151","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1151","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1182","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029650000000000006},"relatedVulnerabilities":[{"id":"CVE-2025-1182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1182","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15919","https://sourceware.org/bugzilla/show_bug.cgi?id=32644","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b425859021d17adf62f06fb904797cf8642986ad","https://vuldb.com/?ctiid.295086","https://vuldb.com/?id.295086","https://vuldb.com/?submit.495407","https://www.gnu.org/"],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1182","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1182","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029650000000000006},"relatedVulnerabilities":[{"id":"CVE-2025-1182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1182","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15919","https://sourceware.org/bugzilla/show_bug.cgi?id=32644","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b425859021d17adf62f06fb904797cf8642986ad","https://vuldb.com/?ctiid.295086","https://vuldb.com/?id.295086","https://vuldb.com/?submit.495407","https://www.gnu.org/"],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1182","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1182","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029650000000000006},"relatedVulnerabilities":[{"id":"CVE-2025-1182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1182","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15919","https://sourceware.org/bugzilla/show_bug.cgi?id=32644","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b425859021d17adf62f06fb904797cf8642986ad","https://vuldb.com/?ctiid.295086","https://vuldb.com/?id.295086","https://vuldb.com/?submit.495407","https://www.gnu.org/"],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1182","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1182","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029650000000000006},"relatedVulnerabilities":[{"id":"CVE-2025-1182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1182","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15919","https://sourceware.org/bugzilla/show_bug.cgi?id=32644","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b425859021d17adf62f06fb904797cf8642986ad","https://vuldb.com/?ctiid.295086","https://vuldb.com/?id.295086","https://vuldb.com/?submit.495407","https://www.gnu.org/"],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1182","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1182","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029650000000000006},"relatedVulnerabilities":[{"id":"CVE-2025-1182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1182","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15919","https://sourceware.org/bugzilla/show_bug.cgi?id=32644","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b425859021d17adf62f06fb904797cf8642986ad","https://vuldb.com/?ctiid.295086","https://vuldb.com/?id.295086","https://vuldb.com/?submit.495407","https://www.gnu.org/"],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1182","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1182","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029650000000000006},"relatedVulnerabilities":[{"id":"CVE-2025-1182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1182","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15919","https://sourceware.org/bugzilla/show_bug.cgi?id=32644","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b425859021d17adf62f06fb904797cf8642986ad","https://vuldb.com/?ctiid.295086","https://vuldb.com/?id.295086","https://vuldb.com/?submit.495407","https://www.gnu.org/"],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1182","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1182","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029650000000000006},"relatedVulnerabilities":[{"id":"CVE-2025-1182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1182","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15919","https://sourceware.org/bugzilla/show_bug.cgi?id=32644","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b425859021d17adf62f06fb904797cf8642986ad","https://vuldb.com/?ctiid.295086","https://vuldb.com/?id.295086","https://vuldb.com/?submit.495407","https://www.gnu.org/"],"description":"A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1182","epss":0.00593,"percentile":0.46363,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1182","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1182","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-37769","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-37769","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.","cvss":[],"epss":[{"cve":"CVE-2023-37769","epss":0.00586,"percentile":0.46082,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-37769","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029300000000000003},"relatedVulnerabilities":[{"id":"CVE-2023-37769","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-37769","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.freedesktop.org/pixman/pixman/-/issues/76"],"description":"stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-37769","epss":0.00586,"percentile":0.46082,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-37769","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pixman","version":"0.42.2-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-37769","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e44f0bb190fc5866","name":"libpixman-1-0","version":"0.42.2-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpixman-1-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpixman-1-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpixman-1-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpixman-1-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:1b3fb5690861e15ca4fd6640fd4def4b2576617942eec04b6fcb7d8bc6c4c9da"],"cpes":["cpe:2.3:a:libpixman-1-0:libpixman-1-0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman-1-0:libpixman_1_0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman_1_0:libpixman-1-0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman_1_0:libpixman_1_0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman-1:libpixman-1-0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman-1:libpixman_1_0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman_1:libpixman-1-0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman_1:libpixman_1_0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman:libpixman-1-0:0.42.2-1:*:*:*:*:*:*:*","cpe:2.3:a:libpixman:libpixman_1_0:0.42.2-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpixman-1-0@0.42.2-1?arch=amd64&distro=debian-12.15&upstream=pixman","upstreams":[{"name":"pixman"}]}},{"vulnerability":{"id":"CVE-2025-1149","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1149","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0288},"relatedVulnerabilities":[{"id":"CVE-2025-1149","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1149","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1149","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0288},"relatedVulnerabilities":[{"id":"CVE-2025-1149","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1149","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1149","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0288},"relatedVulnerabilities":[{"id":"CVE-2025-1149","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1149","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1149","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0288},"relatedVulnerabilities":[{"id":"CVE-2025-1149","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1149","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1149","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0288},"relatedVulnerabilities":[{"id":"CVE-2025-1149","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1149","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1149","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0288},"relatedVulnerabilities":[{"id":"CVE-2025-1149","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1149","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1149","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0288},"relatedVulnerabilities":[{"id":"CVE-2025-1149","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1149","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15887","https://sourceware.org/bugzilla/show_bug.cgi?id=32576","https://vuldb.com/?ctiid.295053","https://vuldb.com/?id.295053","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: \"I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1149","epss":0.00576,"percentile":0.45563,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1149","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1149","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1149","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1179","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02835},"relatedVulnerabilities":[{"id":"CVE-2025-1179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1179","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15915","https://sourceware.org/bugzilla/show_bug.cgi?id=32640","https://sourceware.org/bugzilla/show_bug.cgi?id=32640#c1","https://vuldb.com/?ctiid.295082","https://vuldb.com/?id.295082","https://vuldb.com/?submit.495376","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1179","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02835},"relatedVulnerabilities":[{"id":"CVE-2025-1179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1179","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15915","https://sourceware.org/bugzilla/show_bug.cgi?id=32640","https://sourceware.org/bugzilla/show_bug.cgi?id=32640#c1","https://vuldb.com/?ctiid.295082","https://vuldb.com/?id.295082","https://vuldb.com/?submit.495376","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1179","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02835},"relatedVulnerabilities":[{"id":"CVE-2025-1179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1179","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15915","https://sourceware.org/bugzilla/show_bug.cgi?id=32640","https://sourceware.org/bugzilla/show_bug.cgi?id=32640#c1","https://vuldb.com/?ctiid.295082","https://vuldb.com/?id.295082","https://vuldb.com/?submit.495376","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1179","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02835},"relatedVulnerabilities":[{"id":"CVE-2025-1179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1179","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15915","https://sourceware.org/bugzilla/show_bug.cgi?id=32640","https://sourceware.org/bugzilla/show_bug.cgi?id=32640#c1","https://vuldb.com/?ctiid.295082","https://vuldb.com/?id.295082","https://vuldb.com/?submit.495376","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1179","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02835},"relatedVulnerabilities":[{"id":"CVE-2025-1179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1179","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15915","https://sourceware.org/bugzilla/show_bug.cgi?id=32640","https://sourceware.org/bugzilla/show_bug.cgi?id=32640#c1","https://vuldb.com/?ctiid.295082","https://vuldb.com/?id.295082","https://vuldb.com/?submit.495376","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1179","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02835},"relatedVulnerabilities":[{"id":"CVE-2025-1179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1179","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15915","https://sourceware.org/bugzilla/show_bug.cgi?id=32640","https://sourceware.org/bugzilla/show_bug.cgi?id=32640#c1","https://vuldb.com/?ctiid.295082","https://vuldb.com/?id.295082","https://vuldb.com/?submit.495376","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1179","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02835},"relatedVulnerabilities":[{"id":"CVE-2025-1179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1179","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15915","https://sourceware.org/bugzilla/show_bug.cgi?id=32640","https://sourceware.org/bugzilla/show_bug.cgi?id=32640#c1","https://vuldb.com/?ctiid.295082","https://vuldb.com/?id.295082","https://vuldb.com/?submit.495376","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that \"[t]his bug has been fixed at some point between the 2.43 and 2.44 releases\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"exploitabilityScore":1.7,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"exploitabilityScore":5,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1179","epss":0.00567,"percentile":0.45114,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1179","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6368","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.027285},"relatedVulnerabilities":[{"id":"CVE-2026-6368","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6368","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.027285},"relatedVulnerabilities":[{"id":"CVE-2026-6368","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6368","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.027285},"relatedVulnerabilities":[{"id":"CVE-2026-6368","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6368","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.027285},"relatedVulnerabilities":[{"id":"CVE-2026-6368","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-6368","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.027285},"relatedVulnerabilities":[{"id":"CVE-2026-6368","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","namespace":"nvd:cpe","severity":"Low","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.","cvss":[{"source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6368","epss":0.00107,"percentile":0.01252,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2025-15079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.","cvss":[],"epss":[{"cve":"CVE-2025-15079","epss":0.00537,"percentile":0.43535,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026850000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15079","epss":0.00537,"percentile":0.43535,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-15079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.","cvss":[],"epss":[{"cve":"CVE-2025-15079","epss":0.00537,"percentile":0.43535,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026850000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15079","epss":0.00537,"percentile":0.43535,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-15079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.","cvss":[],"epss":[{"cve":"CVE-2025-15079","epss":0.00537,"percentile":0.43535,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026850000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-15079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15079","epss":0.00537,"percentile":0.43535,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2023-45922","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45922","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0268},"relatedVulnerabilities":[{"id":"CVE-2023-45922","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45922","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/50","http://seclists.org/fulldisclosure/2024/Jan/71","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9857","http://packetstormsecurity.com/files/176805/Mesa-23.0.4-Buffer-Overflow-Null-Pointer.html"],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45922","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bcb26e78046666fd","name":"libgl1-mesa-dri","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgl1-mesa-dri/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgl1-mesa-dri/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgl1-mesa-dri:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgl1-mesa-dri:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libgl1-mesa-dri:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa-dri:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa_dri:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa_dri:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgl1-mesa-dri@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45922","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45922","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0268},"relatedVulnerabilities":[{"id":"CVE-2023-45922","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45922","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/50","http://seclists.org/fulldisclosure/2024/Jan/71","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9857","http://packetstormsecurity.com/files/176805/Mesa-23.0.4-Buffer-Overflow-Null-Pointer.html"],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45922","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c6640a6d53117c22","name":"libglapi-mesa","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglapi-mesa/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglapi-mesa/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglapi-mesa:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglapi-mesa:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libglapi-mesa:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi-mesa:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi_mesa:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi_mesa:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglapi-mesa@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45922","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45922","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0268},"relatedVulnerabilities":[{"id":"CVE-2023-45922","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45922","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/50","http://seclists.org/fulldisclosure/2024/Jan/71","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9857","http://packetstormsecurity.com/files/176805/Mesa-23.0.4-Buffer-Overflow-Null-Pointer.html"],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45922","versionConstraint":"none (unknown)"}}],"artifact":{"id":"779a1dd5fe6d386a","name":"libglx-mesa0","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglx-mesa0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglx-mesa0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglx-mesa0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglx-mesa0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libglx-mesa0:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx-mesa0:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx_mesa0:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx_mesa0:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglx-mesa0@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45922","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45922","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0268},"relatedVulnerabilities":[{"id":"CVE-2023-45922","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45922","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/50","http://seclists.org/fulldisclosure/2024/Jan/71","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9857","http://packetstormsecurity.com/files/176805/Mesa-23.0.4-Buffer-Overflow-Null-Pointer.html"],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45922","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0b67d63ef680c3ac","name":"mesa-va-drivers","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mesa-va-drivers/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/mesa-va-drivers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mesa-va-drivers:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/mesa-va-drivers:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:mesa-va-drivers:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va-drivers:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va_drivers:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va_drivers:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mesa-va-drivers@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45922","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45922","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0268},"relatedVulnerabilities":[{"id":"CVE-2023-45922","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45922","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/50","http://seclists.org/fulldisclosure/2024/Jan/71","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9857","http://packetstormsecurity.com/files/176805/Mesa-23.0.4-Buffer-Overflow-Null-Pointer.html"],"description":"glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45922","epss":0.00536,"percentile":0.43473,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45922","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45922","versionConstraint":"none (unknown)"}}],"artifact":{"id":"68ea5f670263c4bf","name":"mesa-vdpau-drivers","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mesa-vdpau-drivers/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/mesa-vdpau-drivers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mesa-vdpau-drivers:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/mesa-vdpau-drivers:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:mesa-vdpau-drivers:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau-drivers:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau_drivers:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau_drivers:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mesa-vdpau-drivers@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2021-4214","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-4214","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2021-4214","epss":0.00526,"percentile":0.42878,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-4214","cwe":"CWE-120","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-4214","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0263},"relatedVulnerabilities":[{"id":"CVE-2021-4214","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4214","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2021-4214","https://bugzilla.redhat.com/show_bug.cgi?id=2043393","https://github.com/glennrp/libpng/issues/302","https://security-tracker.debian.org/tracker/CVE-2021-4214","https://security.netapp.com/advisory/ntap-20221020-0001/"],"description":"A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-4214","epss":0.00526,"percentile":0.42878,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-4214","cwe":"CWE-120","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-4214","cwe":"CWE-787","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libpng1.6","version":"1.6.39-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-4214","versionConstraint":"none (unknown)"}}],"artifact":{"id":"042787cf6c096741","name":"libpng16-16","version":"1.6.39-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpng16-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"cpes":["cpe:2.3:a:libpng16-16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpng16-16@1.6.39-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=libpng1.6","upstreams":[{"name":"libpng1.6"}]}},{"vulnerability":{"id":"CVE-2017-11697","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11697","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.","cvss":[],"epss":[{"cve":"CVE-2017-11697","epss":0.00523,"percentile":0.42679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-11697","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02615},"relatedVulnerabilities":[{"id":"CVE-2017-11697","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11697","namespace":"nvd:cpe","severity":"High","urls":["http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html","http://seclists.org/fulldisclosure/2017/Aug/17","http://www.geeknik.net/9brdqk6xu","http://www.securityfocus.com/bid/100345","http://www.securitytracker.com/id/1039153","https://security.gentoo.org/glsa/202003-37"],"description":"The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-11697","epss":0.00523,"percentile":0.42679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-11697","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nss","version":"2:3.87.1-1+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-11697","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3325a62774655e15","name":"libnss3","version":"2:3.87.1-1+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3","MPL-2.0","Zlib","public-domain"],"cpes":["cpe:2.3:a:libnss3:libnss3:2\\:3.87.1-1\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss3@2%3A3.87.1-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nss","upstreams":[{"name":"nss"}]}},{"vulnerability":{"id":"CVE-2011-4116","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.42501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026},"relatedVulnerabilities":[{"id":"CVE-2011-4116","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","namespace":"nvd:cpe","severity":"Low","urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"exploitabilityScore":2.7,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.42501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2011-4116","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.42501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026},"relatedVulnerabilities":[{"id":"CVE-2011-4116","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","namespace":"nvd:cpe","severity":"Low","urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"exploitabilityScore":2.7,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.42501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2011-4116","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.42501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026},"relatedVulnerabilities":[{"id":"CVE-2011-4116","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","namespace":"nvd:cpe","severity":"Low","urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"exploitabilityScore":2.7,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.42501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2011-4116","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.42501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026},"relatedVulnerabilities":[{"id":"CVE-2011-4116","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","namespace":"nvd:cpe","severity":"Low","urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"exploitabilityScore":2.7,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-4116","epss":0.0052,"percentile":0.42501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2024-52005","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52005","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.","cvss":[],"epss":[{"cve":"CVE-2024-52005","epss":0.00513,"percentile":0.42012,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2024-52005","cwe":"CWE-150","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02565},"relatedVulnerabilities":[{"id":"CVE-2024-52005","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52005","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329","https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net"],"description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52005","epss":0.00513,"percentile":0.42012,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2024-52005","cwe":"CWE-150","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"git","version":"1:2.39.5-0+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52005","versionConstraint":"none (unknown)"}}],"artifact":{"id":"58f3a3d22240a914","name":"git","version":"1:2.39.5-0+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git.prerm"}],"language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"cpes":["cpe:2.3:a:git:git:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/git@1%3A2.39.5-0%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2024-52005","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52005","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.","cvss":[],"epss":[{"cve":"CVE-2024-52005","epss":0.00513,"percentile":0.42012,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2024-52005","cwe":"CWE-150","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02565},"relatedVulnerabilities":[{"id":"CVE-2024-52005","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52005","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329","https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net"],"description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52005","epss":0.00513,"percentile":0.42012,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","source":"security-advisories@github.com","type":"Secondary"},{"cve":"CVE-2024-52005","cwe":"CWE-150","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"git","version":"1:2.39.5-0+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52005","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d2fedb9664730c69","name":"git-man","version":"1:2.39.5-0+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/git-man.list"}],"language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"cpes":["cpe:2.3:a:git-man:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/git-man@1%3A2.39.5-0%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=git","upstreams":[{"name":"git"}]}},{"vulnerability":{"id":"CVE-2025-69650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69650","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025100000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69650","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69650","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69650","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025100000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69650","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69650","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69650","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025100000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69650","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69650","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69650","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025100000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69650","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69650","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69650","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025100000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69650","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69650","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69650","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025100000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69650","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69650","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69650","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025100000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-69650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69650","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69650","epss":0.00502,"percentile":0.41339,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-69650","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69650","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-73283","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73283","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-73283","epss":0.00091,"percentile":0.00528,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.025025000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-73283","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73283","namespace":"nvd:cpe","severity":"Low","urls":["https://www.openssh.org/releasenotes.html#10.5"],"description":"In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-73283","epss":0.00091,"percentile":0.00528,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-73283","cwe":"CWE-670","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-73283","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d82af4e74abd89bc","name":"openssh-client","version":"1:9.2p1-2+deb12u10","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","upstreams":[{"name":"openssh"}]}},{"vulnerability":{"id":"CVE-2025-15224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.","cvss":[],"epss":[{"cve":"CVE-2025-15224","epss":0.00486,"percentile":0.40294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0243},"relatedVulnerabilities":[{"id":"CVE-2025-15224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","namespace":"nvd:cpe","severity":"Low","urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15224","epss":0.00486,"percentile":0.40294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-15224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.","cvss":[],"epss":[{"cve":"CVE-2025-15224","epss":0.00486,"percentile":0.40294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0243},"relatedVulnerabilities":[{"id":"CVE-2025-15224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","namespace":"nvd:cpe","severity":"Low","urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15224","epss":0.00486,"percentile":0.40294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-15224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.","cvss":[],"epss":[{"cve":"CVE-2025-15224","epss":0.00486,"percentile":0.40294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0243},"relatedVulnerabilities":[{"id":"CVE-2025-15224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","namespace":"nvd:cpe","severity":"Low","urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"exploitabilityScore":1.7,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-15224","epss":0.00486,"percentile":0.40294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-15224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0234},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4a63521ec2fd3be","name":"libnss-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libnss-systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss-systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0234},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c085cdccd13efd58","name":"libpam-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpam-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libpam-systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0234},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f08c824a2d960023","name":"libsystemd-shared","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd-shared/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsystemd-shared/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd-shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd-shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd-shared@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0234},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fa8be228d5b7724c","name":"libsystemd0","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0234},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"55089f35a6363c37","name":"libudev1","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0234},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40fe219b13a5306","name":"systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd:systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0234},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8dbabe3bd671d120","name":"systemd-sysv","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-sysv@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2013-4392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0234},"relatedVulnerabilities":[{"id":"CVE-2013-4392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","namespace":"nvd:cpe","severity":"Low","urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":3.4,"impactScore":5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-4392","epss":0.00468,"percentile":0.39072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2013-4392","cwe":"CWE-59","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e4b498470090a3c","name":"systemd-timesyncd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-timesyncd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-timesyncd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.list"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postinst"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postrm"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.prerm"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-timesyncd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-30999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-30999","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[],"epss":[{"cve":"CVE-2026-30999","epss":0.00452,"percentile":0.3797,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0226},"relatedVulnerabilities":[{"id":"CVE-2026-30999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","namespace":"nvd:cpe","severity":"High","urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-30999","epss":0.00452,"percentile":0.3797,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-30999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f6f4254209010e58","name":"libavcodec59","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavcodec59/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavcodec59/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavcodec59:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavcodec59:libavcodec59:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavcodec59@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-30999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-30999","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[],"epss":[{"cve":"CVE-2026-30999","epss":0.00452,"percentile":0.3797,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0226},"relatedVulnerabilities":[{"id":"CVE-2026-30999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","namespace":"nvd:cpe","severity":"High","urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-30999","epss":0.00452,"percentile":0.3797,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-30999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"80795747554e31f8","name":"libavutil57","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavutil57/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libavutil57/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libavutil57:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libavutil57:libavutil57:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libavutil57@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2026-30999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-30999","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[],"epss":[{"cve":"CVE-2026-30999","epss":0.00452,"percentile":0.3797,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0226},"relatedVulnerabilities":[{"id":"CVE-2026-30999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","namespace":"nvd:cpe","severity":"High","urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-30999","epss":0.00452,"percentile":0.3797,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ffmpeg","version":"7:5.1.9-0+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-30999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"99546d72a5ab8c7e","name":"libswresample4","version":"7:5.1.9-0+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libswresample4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libswresample4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libswresample4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-1-clause","BSD-2-clause","BSD-3-clause","BSL","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","IJG","ISC","LGPL-2+","LGPL-2.1","LGPL-2.1+","Sundry","Zlib","man-page","public-domain"],"cpes":["cpe:2.3:a:libswresample4:libswresample4:7\\:5.1.9-0\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libswresample4@7%3A5.1.9-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=ffmpeg","upstreams":[{"name":"ffmpeg"}]}},{"vulnerability":{"id":"CVE-2024-23337","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-23337","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.","cvss":[],"epss":[{"cve":"CVE-2024-23337","epss":0.00441,"percentile":0.37152,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-23337","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02205},"relatedVulnerabilities":[{"id":"CVE-2024-23337","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-23337","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jqlang/jq/commit/de21386681c0df0104a99d9d09db23a9b2a78b1e","https://github.com/jqlang/jq/issues/3262","https://github.com/jqlang/jq/security/advisories/GHSA-2q6r-344g-cx46"],"description":"jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-23337","epss":0.00441,"percentile":0.37152,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-23337","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jq","version":"1.6-2.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-23337","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7197c1d5ef24996b","name":"jq","version":"1.6-2.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/jq.list"}],"language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"cpes":["cpe:2.3:a:jq:jq:1.6-2.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/jq@1.6-2.1%2Bdeb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2024-23337","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-23337","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.","cvss":[],"epss":[{"cve":"CVE-2024-23337","epss":0.00441,"percentile":0.37152,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-23337","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02205},"relatedVulnerabilities":[{"id":"CVE-2024-23337","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-23337","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jqlang/jq/commit/de21386681c0df0104a99d9d09db23a9b2a78b1e","https://github.com/jqlang/jq/issues/3262","https://github.com/jqlang/jq/security/advisories/GHSA-2q6r-344g-cx46"],"description":"jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-23337","epss":0.00441,"percentile":0.37152,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-23337","cwe":"CWE-190","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jq","version":"1.6-2.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-23337","versionConstraint":"none (unknown)"}}],"artifact":{"id":"87f3880f412f67fd","name":"libjq1","version":"1.6-2.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"cpes":["cpe:2.3:a:libjq1:libjq1:1.6-2.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjq1@1.6-2.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=jq","upstreams":[{"name":"jq"}]}},{"vulnerability":{"id":"CVE-2024-45993","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-45993","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.","cvss":[],"epss":[{"cve":"CVE-2024-45993","epss":0.00438,"percentile":0.36912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-45993","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-45993","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021900000000000003},"relatedVulnerabilities":[{"id":"CVE-2024-45993","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-45993","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.com/mthandazo/project-pov"],"description":"Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":3.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45993","epss":0.00438,"percentile":0.36912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-45993","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-45993","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"giflib","version":"5.2.1-2.5+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-45993","versionConstraint":"none (unknown)"}}],"artifact":{"id":"71a582f5b3d629e1","name":"libgif7","version":"5.2.1-2.5+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgif7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgif7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgif7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgif7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT"],"cpes":["cpe:2.3:a:libgif7:libgif7:5.2.1-2.5\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgif7@5.2.1-2.5%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=giflib","upstreams":[{"name":"giflib"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2022-0563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021350000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-0563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0563","epss":0.00427,"percentile":0.35982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0563","cwe":"CWE-209","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2023-48161","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-48161","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c","cvss":[],"epss":[{"cve":"CVE-2023-48161","epss":0.00425,"percentile":0.35861,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-48161","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02125},"relatedVulnerabilities":[{"id":"CVE-2023-48161","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-48161","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/tacetool/TACE#cve-2023-48161","https://sourceforge.net/p/giflib/bugs/167/"],"description":"Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-48161","epss":0.00425,"percentile":0.35861,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-48161","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"giflib","version":"5.2.1-2.5+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-48161","versionConstraint":"none (unknown)"}}],"artifact":{"id":"71a582f5b3d629e1","name":"libgif7","version":"5.2.1-2.5+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgif7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgif7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgif7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgif7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT"],"cpes":["cpe:2.3:a:libgif7:libgif7:5.2.1-2.5\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgif7@5.2.1-2.5%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=giflib","upstreams":[{"name":"giflib"}]}},{"vulnerability":{"id":"CVE-2002-1976","dataSource":"https://security-tracker.debian.org/tracker/CVE-2002-1976","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.","cvss":[],"epss":[{"cve":"CVE-2002-1976","epss":0.00405,"percentile":0.3398,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2002-1976","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.020249999999999997},"relatedVulnerabilities":[{"id":"CVE-2002-1976","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2002-1976","namespace":"nvd:cpe","severity":"Low","urls":["http://archives.neohapsis.com/archives/bugtraq/2002-07/0279.html","http://online.securityfocus.com/archive/1/284142","http://online.securityfocus.com/archive/1/284257","http://www.iss.net/security_center/static/9676.php","http://www.securityfocus.com/bid/5304"],"description":"ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2002-1976","epss":0.00405,"percentile":0.3398,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2002-1976","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"net-tools","version":"2.10-0.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2002-1976","versionConstraint":"none (unknown)"}}],"artifact":{"id":"26300d2a51d46caa","name":"net-tools","version":"2.10-0.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/net-tools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/net-tools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/net-tools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/net-tools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/net-tools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/net-tools.list"}],"language":"","licenses":["GPL-2","GPL-2+"],"cpes":["cpe:2.3:a:net-tools:net-tools:2.10-0.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:net-tools:net_tools:2.10-0.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:net_tools:net-tools:2.10-0.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:net_tools:net_tools:2.10-0.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:net:net-tools:2.10-0.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:net:net_tools:2.10-0.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/net-tools@2.10-0.1%2Bdeb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-27587","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-27587","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.","cvss":[],"epss":[{"cve":"CVE-2025-27587","epss":0.00403,"percentile":0.33831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-27587","cwe":"CWE-385","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.020149999999999998},"relatedVulnerabilities":[{"id":"CVE-2025-27587","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-27587","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/openssl/openssl/issues/24253","https://minerva.crocs.fi.muni.cz"],"description":"OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-27587","epss":0.00403,"percentile":0.33831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-27587","cwe":"CWE-385","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-27587","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f55823b1f5c2e201","name":"libssl3","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","upstreams":[{"name":"openssl"}]}},{"vulnerability":{"id":"CVE-2025-27587","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-27587","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.","cvss":[],"epss":[{"cve":"CVE-2025-27587","epss":0.00403,"percentile":0.33831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-27587","cwe":"CWE-385","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.020149999999999998},"relatedVulnerabilities":[{"id":"CVE-2025-27587","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-27587","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/openssl/openssl/issues/24253","https://minerva.crocs.fi.muni.cz"],"description":"OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-27587","epss":0.00403,"percentile":0.33831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-27587","cwe":"CWE-385","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-27587","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7345802bd2ec0962","name":"openssl","version":"3.0.20-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-6228","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6228","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.","cvss":[],"epss":[{"cve":"CVE-2023-6228","epss":0.00399,"percentile":0.33379,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6228","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-6228","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01995},"relatedVulnerabilities":[{"id":"CVE-2023-6228","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6228","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:2289","https://access.redhat.com/errata/RHSA-2024:5079","https://access.redhat.com/security/cve/CVE-2023-6228","https://bugzilla.redhat.com/show_bug.cgi?id=2240995"],"description":"An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.","cvss":[{"source":"nvd@nist.gov","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6228","epss":0.00399,"percentile":0.33379,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6228","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-6228","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6228","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-10966","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10966","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.  This prevents curl from detecting MITM attackers and more.","cvss":[],"epss":[{"cve":"CVE-2025-10966","epss":0.00399,"percentile":0.33329,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01995},"relatedVulnerabilities":[{"id":"CVE-2025-10966","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10966","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-10966.html","https://curl.se/docs/CVE-2025-10966.json","https://hackerone.com/reports/3355218","http://www.openwall.com/lists/oss-security/2025/11/05/2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10966","epss":0.00399,"percentile":0.33329,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-10966","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-10966","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10966","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.  This prevents curl from detecting MITM attackers and more.","cvss":[],"epss":[{"cve":"CVE-2025-10966","epss":0.00399,"percentile":0.33329,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01995},"relatedVulnerabilities":[{"id":"CVE-2025-10966","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10966","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-10966.html","https://curl.se/docs/CVE-2025-10966.json","https://hackerone.com/reports/3355218","http://www.openwall.com/lists/oss-security/2025/11/05/2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10966","epss":0.00399,"percentile":0.33329,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-10966","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-10966","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10966","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.  This prevents curl from detecting MITM attackers and more.","cvss":[],"epss":[{"cve":"CVE-2025-10966","epss":0.00399,"percentile":0.33329,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01995},"relatedVulnerabilities":[{"id":"CVE-2025-10966","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10966","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-10966.html","https://curl.se/docs/CVE-2025-10966.json","https://hackerone.com/reports/3355218","http://www.openwall.com/lists/oss-security/2025/11/05/2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"],"description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-10966","epss":0.00399,"percentile":0.33329,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-10966","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2023-45919","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45919","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.019400000000000004},"relatedVulnerabilities":[{"id":"CVE-2023-45919","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45919","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/47","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9858","http://packetstormsecurity.com/files/176802/Mesa-23.0.4-Buffer-Overflow.html"],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45919","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bcb26e78046666fd","name":"libgl1-mesa-dri","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgl1-mesa-dri/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgl1-mesa-dri/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgl1-mesa-dri:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgl1-mesa-dri:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libgl1-mesa-dri:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa-dri:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa_dri:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa_dri:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgl1-mesa-dri@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45919","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45919","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.019400000000000004},"relatedVulnerabilities":[{"id":"CVE-2023-45919","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45919","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/47","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9858","http://packetstormsecurity.com/files/176802/Mesa-23.0.4-Buffer-Overflow.html"],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45919","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c6640a6d53117c22","name":"libglapi-mesa","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglapi-mesa/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglapi-mesa/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglapi-mesa:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglapi-mesa:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libglapi-mesa:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi-mesa:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi_mesa:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi_mesa:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglapi-mesa@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45919","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45919","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.019400000000000004},"relatedVulnerabilities":[{"id":"CVE-2023-45919","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45919","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/47","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9858","http://packetstormsecurity.com/files/176802/Mesa-23.0.4-Buffer-Overflow.html"],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45919","versionConstraint":"none (unknown)"}}],"artifact":{"id":"779a1dd5fe6d386a","name":"libglx-mesa0","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglx-mesa0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglx-mesa0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglx-mesa0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglx-mesa0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libglx-mesa0:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx-mesa0:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx_mesa0:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx_mesa0:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglx-mesa0@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45919","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45919","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.019400000000000004},"relatedVulnerabilities":[{"id":"CVE-2023-45919","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45919","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/47","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9858","http://packetstormsecurity.com/files/176802/Mesa-23.0.4-Buffer-Overflow.html"],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45919","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0b67d63ef680c3ac","name":"mesa-va-drivers","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mesa-va-drivers/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/mesa-va-drivers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mesa-va-drivers:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/mesa-va-drivers:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:mesa-va-drivers:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va-drivers:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va_drivers:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va_drivers:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mesa-va-drivers@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45919","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45919","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.019400000000000004},"relatedVulnerabilities":[{"id":"CVE-2023-45919","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45919","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/47","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9858","http://packetstormsecurity.com/files/176802/Mesa-23.0.4-Buffer-Overflow.html"],"description":"Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45919","epss":0.00388,"percentile":0.32184,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45919","cwe":"CWE-126","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45919","versionConstraint":"none (unknown)"}}],"artifact":{"id":"68ea5f670263c4bf","name":"mesa-vdpau-drivers","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mesa-vdpau-drivers/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/mesa-vdpau-drivers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mesa-vdpau-drivers:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/mesa-vdpau-drivers:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:mesa-vdpau-drivers:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau-drivers:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau_drivers:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau_drivers:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mesa-vdpau-drivers@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2026-16599","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16599","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.   This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa","cvss":[],"epss":[{"cve":"CVE-2026-16599","epss":0.0038,"percentile":0.31319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","source":"cvd@cert.pl","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.019},"relatedVulnerabilities":[{"id":"CVE-2026-16599","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16599","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/08/CVE-2026-16599","https://gitlab.com/gnuwget/wget","https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"],"description":"GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa","cvss":[{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-16599","epss":0.0038,"percentile":0.31319,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","source":"cvd@cert.pl","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-16599","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ef5a5a7d880f3e73","name":"wget","version":"1.21.3-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/wget.list"}],"language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-52426","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52426","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.","cvss":[],"epss":[{"cve":"CVE-2023-52426","epss":0.00373,"percentile":0.3057,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52426","cwe":"CWE-776","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-52426","cwe":"CWE-776","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01865},"relatedVulnerabilities":[{"id":"CVE-2023-52426","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52426","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/776.html","https://github.com/libexpat/libexpat/commit/0f075ec8ecb5e43f8fdca5182f8cca4703da0404","https://github.com/libexpat/libexpat/pull/777","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV/","https://security.netapp.com/advisory/ntap-20240307-0005/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/"],"description":"libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52426","epss":0.00373,"percentile":0.3057,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52426","cwe":"CWE-776","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-52426","cwe":"CWE-776","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52426","versionConstraint":"none (unknown)"}}],"artifact":{"id":"66ec0b239b3dc1ac","name":"libexpat1","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2023-52426","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52426","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.","cvss":[],"epss":[{"cve":"CVE-2023-52426","epss":0.00373,"percentile":0.3057,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52426","cwe":"CWE-776","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-52426","cwe":"CWE-776","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01865},"relatedVulnerabilities":[{"id":"CVE-2023-52426","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52426","namespace":"nvd:cpe","severity":"Medium","urls":["https://cwe.mitre.org/data/definitions/776.html","https://github.com/libexpat/libexpat/commit/0f075ec8ecb5e43f8fdca5182f8cca4703da0404","https://github.com/libexpat/libexpat/pull/777","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV/","https://security.netapp.com/advisory/ntap-20240307-0005/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/"],"description":"libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52426","epss":0.00373,"percentile":0.3057,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52426","cwe":"CWE-776","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-52426","cwe":"CWE-776","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52426","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a7f5ffcb3e600344","name":"libexpat1-dev","version":"2.5.0-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libexpat1-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libexpat1-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["MIT"],"cpes":["cpe:2.3:a:libexpat1-dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1-dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1_dev:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1-dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libexpat1:libexpat1_dev:2.5.0-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libexpat1-dev@2.5.0-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=expat","upstreams":[{"name":"expat"}]}},{"vulnerability":{"id":"CVE-2025-66863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66863","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-66865","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66865","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66865","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-66863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66863","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66865","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66865","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66865","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66863","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66865","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66865","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66865","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66863","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66865","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66865","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66865","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66863","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66865","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66865","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66865","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66863","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66865","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66865","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66865","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66863","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66863","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash2.md"],"description":"An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66863","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66863","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66863","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66865","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66865","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.018400000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66865","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66865","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash4.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66865","epss":0.00368,"percentile":0.30033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66865","cwe":"CWE-121","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66865","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66862","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66862","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0181},"relatedVulnerabilities":[{"id":"CVE-2025-66862","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-66862","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66862","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0181},"relatedVulnerabilities":[{"id":"CVE-2025-66862","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66862","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66862","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0181},"relatedVulnerabilities":[{"id":"CVE-2025-66862","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66862","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66862","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0181},"relatedVulnerabilities":[{"id":"CVE-2025-66862","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66862","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66862","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0181},"relatedVulnerabilities":[{"id":"CVE-2025-66862","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66862","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66862","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0181},"relatedVulnerabilities":[{"id":"CVE-2025-66862","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66862","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66862","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0181},"relatedVulnerabilities":[{"id":"CVE-2025-66862","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66862","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash3.md"],"description":"A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66862","epss":0.00362,"percentile":0.29498,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66862","cwe":"CWE-122","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66862","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-1916","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-1916","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.","cvss":[],"epss":[{"cve":"CVE-2023-1916","epss":0.00361,"percentile":0.2937,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1916","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1916","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01805},"relatedVulnerabilities":[{"id":"CVE-2023-1916","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-1916","namespace":"nvd:cpe","severity":"Medium","urls":["https://gitlab.com/libtiff/libtiff/-/issues/536%2C","https://gitlab.com/libtiff/libtiff/-/issues/537","https://support.apple.com/kb/HT213844","https://gitlab.com/libtiff/libtiff/-/issues/536"],"description":"A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-1916","epss":0.00361,"percentile":0.2937,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-1916","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-1916","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-1916","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2017-14159","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-14159","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.","cvss":[],"epss":[{"cve":"CVE-2017-14159","epss":0.00349,"percentile":0.2808,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-14159","cwe":"CWE-665","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2017-14159","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-14159","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openldap.org/its/index.cgi?findid=8703","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-14159","epss":0.00349,"percentile":0.2808,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-14159","cwe":"CWE-665","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-14159","versionConstraint":"none (unknown)"}}],"artifact":{"id":"692b9197d4b21a92","name":"libldap-2.5-0","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2017-14159","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-14159","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.","cvss":[],"epss":[{"cve":"CVE-2017-14159","epss":0.00349,"percentile":0.2808,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-14159","cwe":"CWE-665","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2017-14159","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-14159","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openldap.org/its/index.cgi?findid=8703","https://www.oracle.com/security-alerts/cpuapr2022.html"],"description":"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-14159","epss":0.00349,"percentile":0.2808,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-14159","cwe":"CWE-665","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-14159","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dd3946a6b1d2298d","name":"libldap-common","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-common@2.5.13%2Bdfsg-5?arch=all&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4a63521ec2fd3be","name":"libnss-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libnss-systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss-systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c085cdccd13efd58","name":"libpam-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpam-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libpam-systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f08c824a2d960023","name":"libsystemd-shared","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd-shared/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsystemd-shared/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd-shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd-shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd-shared@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fa8be228d5b7724c","name":"libsystemd0","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"55089f35a6363c37","name":"libudev1","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40fe219b13a5306","name":"systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd:systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8dbabe3bd671d120","name":"systemd-sysv","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-sysv@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2023-31439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31439","epss":0.00349,"percentile":0.28079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e4b498470090a3c","name":"systemd-timesyncd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-timesyncd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-timesyncd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.list"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postinst"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postrm"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.prerm"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-timesyncd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-39742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39742","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.","cvss":[],"epss":[{"cve":"CVE-2023-39742","epss":0.00346,"percentile":0.2777,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39742","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0173},"relatedVulnerabilities":[{"id":"CVE-2023-39742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39742","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/huanglei3/ec9090096aa92445cf0a8baa8e929084","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O4RLSFGPBPR3FMIUJCWPGVIYIU35YGQX/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPNBOB65TEA4ZEPLVENI26BY4LEX7TEF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5WO6WL2TCGO6T4VKGACDIVSZI74WJAU/","https://sourceforge.net/p/giflib/bugs/166/"],"description":"giflib v5.2.1 was discovered to contain a segmentation fault via the component getarg.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39742","epss":0.00346,"percentile":0.2777,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39742","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"giflib","version":"5.2.1-2.5+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-39742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"71a582f5b3d629e1","name":"libgif7","version":"5.2.1-2.5+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgif7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgif7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgif7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgif7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT"],"cpes":["cpe:2.3:a:libgif7:libgif7:5.2.1-2.5\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgif7@5.2.1-2.5%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=giflib","upstreams":[{"name":"giflib"}]}},{"vulnerability":{"id":"CVE-2017-18018","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-18018","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.","cvss":[],"epss":[{"cve":"CVE-2017-18018","epss":0.00345,"percentile":0.27656,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-18018","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2017-18018","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01725},"relatedVulnerabilities":[{"id":"CVE-2017-18018","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18018","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.gnu.org/archive/html/coreutils/2017-12/msg00045.html"],"description":"In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-18018","epss":0.00345,"percentile":0.27656,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-18018","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2017-18018","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-18018","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eca37691b87c0860","name":"coreutils","version":"9.1-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1372","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1372","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 73db9d2021cab9e23fd734b0a76a612d52a6f1db. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1372","epss":0.00343,"percentile":0.27364,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1372","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1372","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1372","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01715},"relatedVulnerabilities":[{"id":"CVE-2025-1372","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1372","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15927","https://sourceware.org/bugzilla/show_bug.cgi?id=32656","https://sourceware.org/bugzilla/show_bug.cgi?id=32656#c3","https://sourceware.org/bugzilla/show_bug.cgi?id=32657","https://vuldb.com/?ctiid.295981","https://vuldb.com/?id.295981","https://vuldb.com/?submit.496485","https://www.gnu.org/"],"description":"A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 73db9d2021cab9e23fd734b0a76a612d52a6f1db. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1372","epss":0.00343,"percentile":0.27364,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1372","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1372","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1372","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1372","versionConstraint":"none (unknown)"}}],"artifact":{"id":"00b653c92ba9a809","name":"libelf1","version":"0.188-2.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","upstreams":[{"name":"elfutils"}]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01705},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4a63521ec2fd3be","name":"libnss-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libnss-systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss-systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01705},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c085cdccd13efd58","name":"libpam-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpam-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libpam-systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01705},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f08c824a2d960023","name":"libsystemd-shared","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd-shared/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsystemd-shared/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd-shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd-shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd-shared@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01705},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fa8be228d5b7724c","name":"libsystemd0","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01705},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"55089f35a6363c37","name":"libudev1","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01705},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40fe219b13a5306","name":"systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd:systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01705},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8dbabe3bd671d120","name":"systemd-sysv","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-sysv@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31437","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01705},"relatedVulnerabilities":[{"id":"CVE-2023-31437","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31437","epss":0.00341,"percentile":0.27231,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31437","cwe":"CWE-354","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e4b498470090a3c","name":"systemd-timesyncd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-timesyncd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-timesyncd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.list"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postinst"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postrm"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.prerm"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-timesyncd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2025-1365","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1365","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5e5c0394d82c53e97750fe7b18023e6f84157b81. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1365","epss":0.00339,"percentile":0.26897,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1365","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1365","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1365","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01695},"relatedVulnerabilities":[{"id":"CVE-2025-1365","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1365","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15925","https://sourceware.org/bugzilla/show_bug.cgi?id=32654","https://sourceware.org/bugzilla/show_bug.cgi?id=32654#c2","https://vuldb.com/?ctiid.295977","https://vuldb.com/?id.295977","https://vuldb.com/?submit.496483","https://www.gnu.org/"],"description":"A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5e5c0394d82c53e97750fe7b18023e6f84157b81. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1365","epss":0.00339,"percentile":0.26897,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1365","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1365","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1365","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1365","versionConstraint":"none (unknown)"}}],"artifact":{"id":"00b653c92ba9a809","name":"libelf1","version":"0.188-2.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","upstreams":[{"name":"elfutils"}]}},{"vulnerability":{"id":"CVE-2026-53910","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53910","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.   This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815   NOTE: The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.","cvss":[],"epss":[{"cve":"CVE-2026-53910","epss":0.00332,"percentile":0.26067,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.016600000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-53910","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53910","namespace":"nvd:cpe","severity":"Low","urls":["https://cert.pl/en/posts/2026/07/CVE-2026-53910","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815","https://git.savannah.gnu.org/cgit/diffutils.git/"],"description":"diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing. \nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\n\n\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 \n\nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.","cvss":[{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53910","epss":0.00332,"percentile":0.26067,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"diffutils","version":"1:3.8-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53910","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eae3581d3fe173ec","name":"diffutils","version":"1:3.8-4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/diffutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/diffutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/diffutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/diffutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/diffutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/diffutils.list"}],"language":"","licenses":["FSFAP","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3.0+","X11","public-domain"],"cpes":["cpe:2.3:a:diffutils:diffutils:1\\:3.8-4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/diffutils@1%3A3.8-4?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-38560","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-38560","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.","cvss":[],"epss":[{"cve":"CVE-2023-38560","epss":0.00329,"percentile":0.25796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.016450000000000003},"relatedVulnerabilities":[{"id":"CVE-2023-38560","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-38560","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-38560","https://bugs.ghostscript.com/show_bug.cgi?id=706898","https://bugzilla.redhat.com/show_bug.cgi?id=2224368","https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=b7eb1d0174c"],"description":"An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-38560","epss":0.00329,"percentile":0.25796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-38560","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1a53878210d7ee72","name":"libgs-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs-common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2023-38560","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-38560","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.","cvss":[],"epss":[{"cve":"CVE-2023-38560","epss":0.00329,"percentile":0.25796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.016450000000000003},"relatedVulnerabilities":[{"id":"CVE-2023-38560","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-38560","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-38560","https://bugs.ghostscript.com/show_bug.cgi?id=706898","https://bugzilla.redhat.com/show_bug.cgi?id=2224368","https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=b7eb1d0174c"],"description":"An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-38560","epss":0.00329,"percentile":0.25796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-38560","versionConstraint":"none (unknown)"}}],"artifact":{"id":"097a7cb358060cf0","name":"libgs10","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10:libgs10:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10@10.0.0~dfsg-11%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2023-38560","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-38560","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.","cvss":[],"epss":[{"cve":"CVE-2023-38560","epss":0.00329,"percentile":0.25796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.016450000000000003},"relatedVulnerabilities":[{"id":"CVE-2023-38560","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-38560","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-38560","https://bugs.ghostscript.com/show_bug.cgi?id=706898","https://bugzilla.redhat.com/show_bug.cgi?id=2224368","https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=b7eb1d0174c"],"description":"An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-38560","epss":0.00329,"percentile":0.25796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-38560","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-38560","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1592f7455014590c","name":"libgs10-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2023-26924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-26924","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes \"Language front-ends ... for which a malicious input file can cause undesirable behavior.\"","cvss":[],"epss":[{"cve":"CVE-2023-26924","epss":0.00328,"percentile":0.25641,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-26924","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0164},"relatedVulnerabilities":[{"id":"CVE-2023-26924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-26924","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/Colloportus0/fc16d10d74aedf89d5d1d020ebb89c0c","https://github.com/llvm/llvm-project/issues/60216","https://llvm.org/docs/Security.html#what-is-considered-a-security-issue"],"description":"LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes \"Language front-ends ... for which a malicious input file can cause undesirable behavior.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-26924","epss":0.00328,"percentile":0.25641,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-26924","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-26924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c4a63521ec2fd3be","name":"libnss-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnss-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libnss-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libnss-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libnss-systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss-systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss_systemd:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libnss:libnss_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libnss-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c085cdccd13efd58","name":"libpam-systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpam-systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpam-systemd:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libpam-systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_systemd:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpam-systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f08c824a2d960023","name":"libsystemd-shared","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd-shared/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsystemd-shared/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd-shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd-shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd-shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd_shared:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd-shared@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fa8be228d5b7724c","name":"libsystemd0","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"55089f35a6363c37","name":"libudev1","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c40fe219b13a5306","name":"systemd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd:systemd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8dbabe3bd671d120","name":"systemd-sysv","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-sysv/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-sysv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-sysv.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.list"},{"path":"/var/lib/dpkg/info/systemd-sysv.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-sysv.postinst"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_sysv:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_sysv:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-sysv@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2023-31438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2023-31438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":3.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31438","epss":0.00325,"percentile":0.2537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2e4b498470090a3c","name":"systemd-timesyncd","version":"252.39-1~deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-timesyncd/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/systemd-timesyncd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-timesyncd.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.list"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postinst"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.postrm"},{"path":"/var/lib/dpkg/info/systemd-timesyncd.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/systemd-timesyncd.prerm"}],"language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"cpes":["cpe:2.3:a:systemd-timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd-timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd_timesyncd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_timesyncd:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/systemd-timesyncd@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","upstreams":[{"name":"systemd"}]}},{"vulnerability":{"id":"CVE-2026-9547","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9547","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2026-9547","epss":0.00325,"percentile":0.25368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2026-9547","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9547","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9547.html","https://curl.se/docs/CVE-2026-9547.json","https://hackerone.com/reports/3751712"],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9547","epss":0.00325,"percentile":0.25368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9547","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-9547","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9547","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2026-9547","epss":0.00325,"percentile":0.25368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2026-9547","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9547","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9547.html","https://curl.se/docs/CVE-2026-9547.json","https://hackerone.com/reports/3751712"],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9547","epss":0.00325,"percentile":0.25368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9547","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2026-9547","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9547","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.","cvss":[],"epss":[{"cve":"CVE-2026-9547","epss":0.00325,"percentile":0.25368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01625},"relatedVulnerabilities":[{"id":"CVE-2026-9547","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9547","namespace":"nvd:cpe","severity":"High","urls":["https://curl.se/docs/CVE-2026-9547.html","https://curl.se/docs/CVE-2026-9547.json","https://hackerone.com/reports/3751712"],"description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"exploitabilityScore":2.3,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-9547","epss":0.00325,"percentile":0.25368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9547","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2017-15131","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-15131","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.","cvss":[],"epss":[{"cve":"CVE-2017-15131","epss":0.00321,"percentile":0.24866,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-15131","cwe":"CWE-284","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2017-15131","cwe":"CWE-276","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.016050000000000002},"relatedVulnerabilities":[{"id":"CVE-2017-15131","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-15131","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2018:0842","https://bugzilla.redhat.com/show_bug.cgi?id=1412762","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"description":"It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-15131","epss":0.00321,"percentile":0.24866,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-15131","cwe":"CWE-284","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2017-15131","cwe":"CWE-276","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"xdg-user-dirs","version":"0.18-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-15131","versionConstraint":"none (unknown)"}}],"artifact":{"id":"31bf5efa64b4314d","name":"xdg-user-dirs","version":"0.18-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xdg-user-dirs/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/xdg-user-dirs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-user-dirs.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xdg-user-dirs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-user-dirs.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xdg-user-dirs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-user-dirs.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xdg-user-dirs.list"},{"path":"/var/lib/dpkg/info/xdg-user-dirs.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xdg-user-dirs.postinst"},{"path":"/var/lib/dpkg/info/xdg-user-dirs.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xdg-user-dirs.postrm"},{"path":"/var/lib/dpkg/info/xdg-user-dirs.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xdg-user-dirs.preinst"},{"path":"/var/lib/dpkg/info/xdg-user-dirs.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/xdg-user-dirs.prerm"}],"language":"","licenses":["sha256:8fea73a6a82aa48f7b00aa9f88a6a36935528f60e2f79799e521754e1621bcf4"],"cpes":["cpe:2.3:a:xdg-user-dirs:xdg-user-dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg-user-dirs:xdg_user_dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg_user_dirs:xdg-user-dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg_user_dirs:xdg_user_dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg-user:xdg-user-dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg-user:xdg_user_dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg_user:xdg-user-dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg_user:xdg_user_dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg:xdg-user-dirs:0.18-1:*:*:*:*:*:*:*","cpe:2.3:a:xdg:xdg_user_dirs:0.18-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/xdg-user-dirs@0.18-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-1377","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1377","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1377","epss":0.00319,"percentile":0.24661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1377","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.015950000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1377","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1377","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15941","https://sourceware.org/bugzilla/show_bug.cgi?id=32673","https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2","https://vuldb.com/?ctiid.295985","https://vuldb.com/?id.295985","https://vuldb.com/?submit.497539","https://www.gnu.org/"],"description":"A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1377","epss":0.00319,"percentile":0.24661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1377","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1377","versionConstraint":"none (unknown)"}}],"artifact":{"id":"00b653c92ba9a809","name":"libelf1","version":"0.188-2.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","upstreams":[{"name":"elfutils"}]}},{"vulnerability":{"id":"CVE-2023-3164","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-3164","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.","cvss":[],"epss":[{"cve":"CVE-2023-3164","epss":0.00319,"percentile":0.24654,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-3164","cwe":"CWE-120","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-3164","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.015950000000000002},"relatedVulnerabilities":[{"id":"CVE-2023-3164","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3164","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-3164","https://bugzilla.redhat.com/show_bug.cgi?id=2213531","https://gitlab.com/libtiff/libtiff/-/issues/542"],"description":"A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-3164","epss":0.00319,"percentile":0.24654,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-3164","cwe":"CWE-120","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-3164","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-3164","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-48708","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-48708","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.","cvss":[],"epss":[{"cve":"CVE-2025-48708","epss":0.00316,"percentile":0.24275,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48708","cwe":"CWE-212","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-48708","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48708","namespace":"nvd:cpe","severity":"Low","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708446","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=b587663c623b4462f9e78686a31fd880207303ee","http://www.openwall.com/lists/oss-security/2025/05/23/2"],"description":"gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-48708","epss":0.00316,"percentile":0.24275,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48708","cwe":"CWE-212","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-48708","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1a53878210d7ee72","name":"libgs-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs-common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2025-48708","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-48708","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.","cvss":[],"epss":[{"cve":"CVE-2025-48708","epss":0.00316,"percentile":0.24275,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48708","cwe":"CWE-212","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-48708","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48708","namespace":"nvd:cpe","severity":"Low","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708446","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=b587663c623b4462f9e78686a31fd880207303ee","http://www.openwall.com/lists/oss-security/2025/05/23/2"],"description":"gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-48708","epss":0.00316,"percentile":0.24275,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48708","cwe":"CWE-212","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-48708","versionConstraint":"none (unknown)"}}],"artifact":{"id":"097a7cb358060cf0","name":"libgs10","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10:libgs10:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10@10.0.0~dfsg-11%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2025-48708","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-48708","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.","cvss":[],"epss":[{"cve":"CVE-2025-48708","epss":0.00316,"percentile":0.24275,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48708","cwe":"CWE-212","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-48708","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48708","namespace":"nvd:cpe","severity":"Low","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708446","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=b587663c623b4462f9e78686a31fd880207303ee","http://www.openwall.com/lists/oss-security/2025/05/23/2"],"description":"gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-48708","epss":0.00316,"percentile":0.24275,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-48708","cwe":"CWE-212","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-48708","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1592f7455014590c","name":"libgs10-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2025-66866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66866","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-66866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-66866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66866","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-66866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66866","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-66866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66866","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-66866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66866","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-66866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66866","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-66866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66866","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0158},"relatedVulnerabilities":[{"id":"CVE-2025-66866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66866","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash6.md"],"description":"An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66866","epss":0.00316,"percentile":0.2423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66866","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-25260","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-25260","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.","cvss":[],"epss":[{"cve":"CVE-2024-25260","epss":0.00307,"percentile":0.23164,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25260","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.015349999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-25260","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-25260","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/schsiung/fuzzer_issues/issues/1","https://sourceware.org/bugzilla/show_bug.cgi?id=31058","https://sourceware.org/elfutils/"],"description":"elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-25260","epss":0.00307,"percentile":0.23164,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25260","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-25260","versionConstraint":"none (unknown)"}}],"artifact":{"id":"00b653c92ba9a809","name":"libelf1","version":"0.188-2.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","upstreams":[{"name":"elfutils"}]}},{"vulnerability":{"id":"CVE-2025-1376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1376","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1376","epss":0.00303,"percentile":0.22736,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1376","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.015150000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-1376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1376","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15940","https://sourceware.org/bugzilla/show_bug.cgi?id=32672","https://sourceware.org/bugzilla/show_bug.cgi?id=32672#c3","https://vuldb.com/?ctiid.295984","https://vuldb.com/?id.295984","https://vuldb.com/?submit.497538","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:H/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1,"exploitabilityScore":1.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1376","epss":0.00303,"percentile":0.22736,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1376","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"00b653c92ba9a809","name":"libelf1","version":"0.188-2.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","upstreams":[{"name":"elfutils"}]}},{"vulnerability":{"id":"CVE-2025-70873","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-70873","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.","cvss":[],"epss":[{"cve":"CVE-2025-70873","epss":0.00301,"percentile":0.22536,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.015050000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-70873","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-70873","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054","https://sqlite.org/forum/forumpost/761eac3c82","https://sqlite.org/src/info/3d459f1fb1bd1b5e"],"description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-70873","epss":0.00301,"percentile":0.22536,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-70873","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"CVE-2026-18220","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18220","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.  A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().  Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.  Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014800000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18220","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18220","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-18220","https://bugzilla.redhat.com/show_bug.cgi?id=2507670"],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.\n\nA specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().\n\nAttack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.\n\nNote: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18220","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-18220","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18220","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.  A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().  Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.  Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014800000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18220","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18220","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-18220","https://bugzilla.redhat.com/show_bug.cgi?id=2507670"],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.\n\nA specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().\n\nAttack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.\n\nNote: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18220","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-18220","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18220","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.  A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().  Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.  Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014800000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18220","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18220","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-18220","https://bugzilla.redhat.com/show_bug.cgi?id=2507670"],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.\n\nA specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().\n\nAttack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.\n\nNote: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18220","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-18220","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18220","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.  A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().  Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.  Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014800000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18220","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18220","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-18220","https://bugzilla.redhat.com/show_bug.cgi?id=2507670"],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.\n\nA specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().\n\nAttack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.\n\nNote: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18220","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-18220","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18220","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.  A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().  Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.  Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014800000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18220","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18220","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-18220","https://bugzilla.redhat.com/show_bug.cgi?id=2507670"],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.\n\nA specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().\n\nAttack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.\n\nNote: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18220","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-18220","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18220","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.  A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().  Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.  Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014800000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18220","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18220","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-18220","https://bugzilla.redhat.com/show_bug.cgi?id=2507670"],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.\n\nA specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().\n\nAttack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.\n\nNote: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18220","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-18220","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18220","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.  A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().  Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.  Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014800000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-18220","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18220","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-18220","https://bugzilla.redhat.com/show_bug.cgi?id=2507670"],"description":"An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.\n\nA specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().\n\nAttack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.\n\nNote: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-18220","epss":0.00296,"percentile":0.22087,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-18220","cwe":"CWE-787","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-18220","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c185e9c791136aa6","name":"dirmngr","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:dirmngr:dirmngr:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dirmngr@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e92d6b046326efbc","name":"gnupg","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg:gnupg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"976c5c43a7fe516a","name":"gnupg-l10n","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-l10n@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"4d2b57169c4709a4","name":"gnupg-utils","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gnupg-utils@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1b50350895a48a3b","name":"gpg","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg:gpg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"01ceda49a85ecdc9","name":"gpg-agent","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-agent@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2ce7ba29a10f5f2d","name":"gpg-wks-client","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-wks-client@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"5c929b5e7563826e","name":"gpg-wks-server","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-server/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpg-wks-server/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-server.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpg-wks-server.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpg-wks-server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpg-wks-server@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"45da524630bb2133","name":"gpgconf","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgconf:gpgconf:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgconf@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b982b129e67b17ad","name":"gpgsm","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgsm:gpgsm:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgsm@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2022-3219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014650000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-3219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3219","epss":0.00293,"percentile":0.21661,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-3219","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bab4532a87a829c8","name":"gpgv","version":"2.2.40-1.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","upstreams":[{"name":"gnupg2"}]}},{"vulnerability":{"id":"CVE-2025-3198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-3198","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-3198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3198","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32716","https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d","https://vuldb.com/?ctiid.303151","https://vuldb.com/?id.303151","https://vuldb.com/?submit.545773","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-3198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-3198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-3198","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-3198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3198","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32716","https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d","https://vuldb.com/?ctiid.303151","https://vuldb.com/?id.303151","https://vuldb.com/?submit.545773","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-3198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-3198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-3198","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-3198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3198","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32716","https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d","https://vuldb.com/?ctiid.303151","https://vuldb.com/?id.303151","https://vuldb.com/?submit.545773","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-3198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-3198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-3198","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-3198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3198","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32716","https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d","https://vuldb.com/?ctiid.303151","https://vuldb.com/?id.303151","https://vuldb.com/?submit.545773","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-3198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-3198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-3198","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-3198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3198","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32716","https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d","https://vuldb.com/?ctiid.303151","https://vuldb.com/?id.303151","https://vuldb.com/?submit.545773","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-3198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-3198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-3198","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-3198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3198","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32716","https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d","https://vuldb.com/?ctiid.303151","https://vuldb.com/?id.303151","https://vuldb.com/?submit.545773","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-3198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-3198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-3198","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-3198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3198","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32716","https://sourceware.org/bugzilla/show_bug.cgi?id=32716#c0","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ba6ad3a18cb26b79e0e3b84c39f707535bbc344d","https://vuldb.com/?ctiid.303151","https://vuldb.com/?id.303151","https://vuldb.com/?submit.545773","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-3198","epss":0.00282,"percentile":0.20502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-3198","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-3198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5244","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5244","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16010","https://sourceware.org/bugzilla/show_bug.cgi?id=32858","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5","https://vuldb.com/?ctiid.310346","https://vuldb.com/?id.310346","https://vuldb.com/?submit.584634","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-5245","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5245","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5245","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5245","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16004","https://sourceware.org/bugzilla/show_bug.cgi?id=32829","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a","https://vuldb.com/?ctiid.310347","https://vuldb.com/?id.310347","https://vuldb.com/?submit.584635","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5245","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-5244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5244","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5244","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16010","https://sourceware.org/bugzilla/show_bug.cgi?id=32858","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5","https://vuldb.com/?ctiid.310346","https://vuldb.com/?id.310346","https://vuldb.com/?submit.584634","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5245","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5245","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5245","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5245","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16004","https://sourceware.org/bugzilla/show_bug.cgi?id=32829","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a","https://vuldb.com/?ctiid.310347","https://vuldb.com/?id.310347","https://vuldb.com/?submit.584635","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5245","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5244","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5244","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16010","https://sourceware.org/bugzilla/show_bug.cgi?id=32858","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5","https://vuldb.com/?ctiid.310346","https://vuldb.com/?id.310346","https://vuldb.com/?submit.584634","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5245","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5245","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5245","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5245","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16004","https://sourceware.org/bugzilla/show_bug.cgi?id=32829","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a","https://vuldb.com/?ctiid.310347","https://vuldb.com/?id.310347","https://vuldb.com/?submit.584635","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5245","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5244","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5244","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16010","https://sourceware.org/bugzilla/show_bug.cgi?id=32858","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5","https://vuldb.com/?ctiid.310346","https://vuldb.com/?id.310346","https://vuldb.com/?submit.584634","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5245","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5245","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5245","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5245","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16004","https://sourceware.org/bugzilla/show_bug.cgi?id=32829","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a","https://vuldb.com/?ctiid.310347","https://vuldb.com/?id.310347","https://vuldb.com/?submit.584635","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5245","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5244","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5244","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16010","https://sourceware.org/bugzilla/show_bug.cgi?id=32858","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5","https://vuldb.com/?ctiid.310346","https://vuldb.com/?id.310346","https://vuldb.com/?submit.584634","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5245","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5245","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5245","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5245","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16004","https://sourceware.org/bugzilla/show_bug.cgi?id=32829","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a","https://vuldb.com/?ctiid.310347","https://vuldb.com/?id.310347","https://vuldb.com/?submit.584635","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5245","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5244","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5244","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16010","https://sourceware.org/bugzilla/show_bug.cgi?id=32858","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5","https://vuldb.com/?ctiid.310346","https://vuldb.com/?id.310346","https://vuldb.com/?submit.584634","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5245","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5245","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5245","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5245","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16004","https://sourceware.org/bugzilla/show_bug.cgi?id=32829","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a","https://vuldb.com/?ctiid.310347","https://vuldb.com/?id.310347","https://vuldb.com/?submit.584635","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5245","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5244","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5244","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16010","https://sourceware.org/bugzilla/show_bug.cgi?id=32858","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d1458933830456e54223d9fc61f0d9b3a19256f5","https://vuldb.com/?ctiid.310346","https://vuldb.com/?id.310346","https://vuldb.com/?submit.584634","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5244","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5244","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5245","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5245","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01395},"relatedVulnerabilities":[{"id":"CVE-2025-5245","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5245","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16004","https://sourceware.org/bugzilla/show_bug.cgi?id=32829","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6c3458a8b7ee7d39f070c7b2350851cb2110c65a","https://vuldb.com/?ctiid.310347","https://vuldb.com/?id.310347","https://vuldb.com/?submit.584635","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5245","epss":0.00279,"percentile":0.20209,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5245","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5245","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-45913","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45913","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0139},"relatedVulnerabilities":[{"id":"CVE-2023-45913","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45913","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/28","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9856","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176800/Mesa-23.0.4-Null-Pointer.html"],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45913","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bcb26e78046666fd","name":"libgl1-mesa-dri","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgl1-mesa-dri/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgl1-mesa-dri/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgl1-mesa-dri:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgl1-mesa-dri:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libgl1-mesa-dri:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa-dri:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa_dri:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa_dri:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1-mesa:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1_mesa:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1:libgl1-mesa-dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libgl1:libgl1_mesa_dri:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgl1-mesa-dri@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45913","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45913","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0139},"relatedVulnerabilities":[{"id":"CVE-2023-45913","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45913","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/28","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9856","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176800/Mesa-23.0.4-Null-Pointer.html"],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45913","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c6640a6d53117c22","name":"libglapi-mesa","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglapi-mesa/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglapi-mesa/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglapi-mesa:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglapi-mesa:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libglapi-mesa:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi-mesa:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi_mesa:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi_mesa:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi:libglapi-mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglapi:libglapi_mesa:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglapi-mesa@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45913","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45913","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0139},"relatedVulnerabilities":[{"id":"CVE-2023-45913","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45913","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/28","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9856","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176800/Mesa-23.0.4-Null-Pointer.html"],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45913","versionConstraint":"none (unknown)"}}],"artifact":{"id":"779a1dd5fe6d386a","name":"libglx-mesa0","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglx-mesa0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libglx-mesa0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglx-mesa0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libglx-mesa0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:libglx-mesa0:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx-mesa0:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx_mesa0:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx_mesa0:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx:libglx-mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libglx:libglx_mesa0:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libglx-mesa0@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45913","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45913","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0139},"relatedVulnerabilities":[{"id":"CVE-2023-45913","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45913","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/28","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9856","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176800/Mesa-23.0.4-Null-Pointer.html"],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45913","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0b67d63ef680c3ac","name":"mesa-va-drivers","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mesa-va-drivers/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/mesa-va-drivers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mesa-va-drivers:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/mesa-va-drivers:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:mesa-va-drivers:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va-drivers:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va_drivers:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va_drivers:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-va:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_va:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa-va-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa_va_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mesa-va-drivers@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2023-45913","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-45913","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0139},"relatedVulnerabilities":[{"id":"CVE-2023-45913","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45913","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/fulldisclosure/2024/Jan/28","https://gitlab.freedesktop.org/mesa/mesa/-/issues/9856","https://seclists.org/fulldisclosure/2024/Jan/71","http://packetstormsecurity.com/files/176800/Mesa-23.0.4-Null-Pointer.html"],"description":"Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45913","epss":0.00278,"percentile":0.20129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-45913","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mesa","version":"22.3.6-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-45913","versionConstraint":"none (unknown)"}}],"artifact":{"id":"68ea5f670263c4bf","name":"mesa-vdpau-drivers","version":"22.3.6-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mesa-vdpau-drivers/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/mesa-vdpau-drivers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mesa-vdpau-drivers:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/mesa-vdpau-drivers:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-2-clause","BSD-3-google","BSL","GPL","Khronos","MIT","MLAA","SGI"],"cpes":["cpe:2.3:a:mesa-vdpau-drivers:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau-drivers:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau_drivers:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau_drivers:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa-vdpau:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa_vdpau:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa-vdpau-drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:mesa:mesa_vdpau_drivers:22.3.6-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mesa-vdpau-drivers@22.3.6-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=mesa","upstreams":[{"name":"mesa"}]}},{"vulnerability":{"id":"CVE-2025-8177","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8177","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.","cvss":[],"epss":[{"cve":"CVE-2025-8177","epss":0.00273,"percentile":0.19571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8177","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8177","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013649999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-8177","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8177","namespace":"nvd:cpe","severity":"High","urls":["http://www.libtiff.org/","https://gitlab.com/libtiff/libtiff/-/commit/e8c9d6c616b19438695fd829e58ae4fde5bfbc22","https://gitlab.com/libtiff/libtiff/-/issues/715","https://gitlab.com/libtiff/libtiff/-/merge_requests/737","https://vuldb.com/?ctiid.317591","https://vuldb.com/?id.317591","https://vuldb.com/?submit.621797"],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8177","epss":0.00273,"percentile":0.19571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8177","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8177","cwe":"CWE-120","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8177","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013550000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3fb79a418234f4d0","name":"krb5-locales","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-locales/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/krb5-locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/krb5-locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-locales.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/krb5-locales.list"}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:krb5-locales:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5-locales:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_locales:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_locales:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/krb5-locales@1.20.1-2%2Bdeb12u5?arch=all&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013550000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9db16cb04ae3b83d","name":"libgssapi-krb5-2","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013550000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fb1c9cf5b43a5af0","name":"libk5crypto3","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013550000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"52548f50c4ff26c7","name":"libkrb5-3","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2026-11850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013550000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":0.8,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11850","epss":0.00271,"percentile":0.1916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"309b5ab55a11c7d0","name":"libkrb5support0","version":"1.20.1-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","upstreams":[{"name":"krb5"}]}},{"vulnerability":{"id":"CVE-2024-53589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53589","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0135},"relatedVulnerabilities":[{"id":"CVE-2024-53589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53589","namespace":"nvd:cpe","severity":"High","urls":["https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow/","https://www.gnu.org/software/binutils/","https://security.netapp.com/advisory/ntap-20250314-0006/"],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53589","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2024-53589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53589","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0135},"relatedVulnerabilities":[{"id":"CVE-2024-53589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53589","namespace":"nvd:cpe","severity":"High","urls":["https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow/","https://www.gnu.org/software/binutils/","https://security.netapp.com/advisory/ntap-20250314-0006/"],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53589","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-53589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53589","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0135},"relatedVulnerabilities":[{"id":"CVE-2024-53589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53589","namespace":"nvd:cpe","severity":"High","urls":["https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow/","https://www.gnu.org/software/binutils/","https://security.netapp.com/advisory/ntap-20250314-0006/"],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53589","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-53589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53589","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0135},"relatedVulnerabilities":[{"id":"CVE-2024-53589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53589","namespace":"nvd:cpe","severity":"High","urls":["https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow/","https://www.gnu.org/software/binutils/","https://security.netapp.com/advisory/ntap-20250314-0006/"],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53589","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-53589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53589","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0135},"relatedVulnerabilities":[{"id":"CVE-2024-53589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53589","namespace":"nvd:cpe","severity":"High","urls":["https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow/","https://www.gnu.org/software/binutils/","https://security.netapp.com/advisory/ntap-20250314-0006/"],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53589","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-53589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53589","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0135},"relatedVulnerabilities":[{"id":"CVE-2024-53589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53589","namespace":"nvd:cpe","severity":"High","urls":["https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow/","https://www.gnu.org/software/binutils/","https://security.netapp.com/advisory/ntap-20250314-0006/"],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53589","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-53589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53589","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0135},"relatedVulnerabilities":[{"id":"CVE-2024-53589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53589","namespace":"nvd:cpe","severity":"High","urls":["https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow/","https://www.gnu.org/software/binutils/","https://security.netapp.com/advisory/ntap-20250314-0006/"],"description":"GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53589","epss":0.0027,"percentile":0.19022,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53589","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53589","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-5278","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5278","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.","cvss":[],"epss":[{"cve":"CVE-2025-5278","epss":0.00266,"percentile":0.18434,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013300000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-5278","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5278","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:28911","https://access.redhat.com/errata/RHSA-2026:33124","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:33612","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2025-5278","https://bugzilla.redhat.com/show_bug.cgi?id=2368764","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507","http://www.openwall.com/lists/oss-security/2025/05/27/2","http://www.openwall.com/lists/oss-security/2025/05/29/1","http://www.openwall.com/lists/oss-security/2025/05/29/2","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14","https://security-tracker.debian.org/tracker/CVE-2025-5278"],"description":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"exploitabilityScore":1.9,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-5278","epss":0.00266,"percentile":0.18434,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-5278","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eca37691b87c0860","name":"coreutils","version":"9.1-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-48961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0131},"relatedVulnerabilities":[{"id":"CVE-2026-48961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6896984bd13fb500","name":"libperl5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-48961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0131},"relatedVulnerabilities":[{"id":"CVE-2026-48961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"15c7b99e3a360b71","name":"perl","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-48961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0131},"relatedVulnerabilities":[{"id":"CVE-2026-48961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e272b8e8d5eb9292","name":"perl-base","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2026-48961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0131},"relatedVulnerabilities":[{"id":"CVE-2026-48961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":3.9,"impactScore":3.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-48961","epss":0.00262,"percentile":0.17916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"13b3922222ec533b","name":"perl-modules-5.36","version":"5.36.0-7+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","upstreams":[{"name":"perl"}]}},{"vulnerability":{"id":"CVE-2025-7545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7545","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01295},"relatedVulnerabilities":[{"id":"CVE-2025-7545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7545","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16117","https://sourceware.org/bugzilla/show_bug.cgi?id=33049","https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944","https://vuldb.com/?ctiid.316243","https://vuldb.com/?id.316243","https://vuldb.com/?submit.614355","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-7545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7545","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01295},"relatedVulnerabilities":[{"id":"CVE-2025-7545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7545","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16117","https://sourceware.org/bugzilla/show_bug.cgi?id=33049","https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944","https://vuldb.com/?ctiid.316243","https://vuldb.com/?id.316243","https://vuldb.com/?submit.614355","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7545","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01295},"relatedVulnerabilities":[{"id":"CVE-2025-7545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7545","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16117","https://sourceware.org/bugzilla/show_bug.cgi?id=33049","https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944","https://vuldb.com/?ctiid.316243","https://vuldb.com/?id.316243","https://vuldb.com/?submit.614355","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7545","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01295},"relatedVulnerabilities":[{"id":"CVE-2025-7545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7545","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16117","https://sourceware.org/bugzilla/show_bug.cgi?id=33049","https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944","https://vuldb.com/?ctiid.316243","https://vuldb.com/?id.316243","https://vuldb.com/?submit.614355","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7545","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01295},"relatedVulnerabilities":[{"id":"CVE-2025-7545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7545","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16117","https://sourceware.org/bugzilla/show_bug.cgi?id=33049","https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944","https://vuldb.com/?ctiid.316243","https://vuldb.com/?id.316243","https://vuldb.com/?submit.614355","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7545","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01295},"relatedVulnerabilities":[{"id":"CVE-2025-7545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7545","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16117","https://sourceware.org/bugzilla/show_bug.cgi?id=33049","https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944","https://vuldb.com/?ctiid.316243","https://vuldb.com/?id.316243","https://vuldb.com/?submit.614355","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7545","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7545","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01295},"relatedVulnerabilities":[{"id":"CVE-2025-7545","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7545","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16117","https://sourceware.org/bugzilla/show_bug.cgi?id=33049","https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944","https://vuldb.com/?ctiid.316243","https://vuldb.com/?id.316243","https://vuldb.com/?submit.614355","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7545","epss":0.00259,"percentile":0.17525,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7545","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7545","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7545","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69649","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69649","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33697","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66"],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69649","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69649","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33697","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66"],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69649","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69649","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33697","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66"],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69649","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69649","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33697","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66"],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69649","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69649","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33697","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66"],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69649","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69649","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33697","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66"],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69649","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69649","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33697","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=66a3492ce68e1ae45b2489bd9a815c39ea5d7f66"],"description":"GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69649","epss":0.00256,"percentile":0.17274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11839","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11839","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11839","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11839","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16344","https://sourceware.org/bugzilla/show_bug.cgi?id=33448","https://vuldb.com/?ctiid.328774","https://vuldb.com/?id.328774","https://vuldb.com/?submit.661279","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11839","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11840","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16351","https://sourceware.org/bugzilla/attachment.cgi?id=16357","https://sourceware.org/bugzilla/show_bug.cgi?id=33455","https://vuldb.com/?ctiid.328775","https://vuldb.com/?id.328775","https://vuldb.com/?submit.661281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11839","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11839","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11839","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11839","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16344","https://sourceware.org/bugzilla/show_bug.cgi?id=33448","https://vuldb.com/?ctiid.328774","https://vuldb.com/?id.328774","https://vuldb.com/?submit.661279","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11839","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11840","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16351","https://sourceware.org/bugzilla/attachment.cgi?id=16357","https://sourceware.org/bugzilla/show_bug.cgi?id=33455","https://vuldb.com/?ctiid.328775","https://vuldb.com/?id.328775","https://vuldb.com/?submit.661281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11839","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11839","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11839","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11839","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16344","https://sourceware.org/bugzilla/show_bug.cgi?id=33448","https://vuldb.com/?ctiid.328774","https://vuldb.com/?id.328774","https://vuldb.com/?submit.661279","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11839","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11840","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16351","https://sourceware.org/bugzilla/attachment.cgi?id=16357","https://sourceware.org/bugzilla/show_bug.cgi?id=33455","https://vuldb.com/?ctiid.328775","https://vuldb.com/?id.328775","https://vuldb.com/?submit.661281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11839","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11839","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11839","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11839","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16344","https://sourceware.org/bugzilla/show_bug.cgi?id=33448","https://vuldb.com/?ctiid.328774","https://vuldb.com/?id.328774","https://vuldb.com/?submit.661279","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11839","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11840","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16351","https://sourceware.org/bugzilla/attachment.cgi?id=16357","https://sourceware.org/bugzilla/show_bug.cgi?id=33455","https://vuldb.com/?ctiid.328775","https://vuldb.com/?id.328775","https://vuldb.com/?submit.661281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11839","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11839","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11839","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11839","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16344","https://sourceware.org/bugzilla/show_bug.cgi?id=33448","https://vuldb.com/?ctiid.328774","https://vuldb.com/?id.328774","https://vuldb.com/?submit.661279","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11839","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11840","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16351","https://sourceware.org/bugzilla/attachment.cgi?id=16357","https://sourceware.org/bugzilla/show_bug.cgi?id=33455","https://vuldb.com/?ctiid.328775","https://vuldb.com/?id.328775","https://vuldb.com/?submit.661281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11839","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11839","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11839","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11839","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16344","https://sourceware.org/bugzilla/show_bug.cgi?id=33448","https://vuldb.com/?ctiid.328774","https://vuldb.com/?id.328774","https://vuldb.com/?submit.661279","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11839","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11840","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16351","https://sourceware.org/bugzilla/attachment.cgi?id=16357","https://sourceware.org/bugzilla/show_bug.cgi?id=33455","https://vuldb.com/?ctiid.328775","https://vuldb.com/?id.328775","https://vuldb.com/?submit.661281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11839","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11839","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11839","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11839","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16344","https://sourceware.org/bugzilla/show_bug.cgi?id=33448","https://vuldb.com/?ctiid.328774","https://vuldb.com/?id.328774","https://vuldb.com/?submit.661279","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11839","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-253","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11839","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11839","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11840","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012800000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-11840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11840","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16351","https://sourceware.org/bugzilla/attachment.cgi?id=16357","https://sourceware.org/bugzilla/show_bug.cgi?id=33455","https://vuldb.com/?ctiid.328775","https://vuldb.com/?id.328775","https://vuldb.com/?submit.661281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11840","epss":0.00256,"percentile":0.17264,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11840","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11840","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11840","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11083","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11083","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16353","https://sourceware.org/bugzilla/show_bug.cgi?id=33457","https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490","https://vuldb.com/?ctiid.326124","https://vuldb.com/?id.326124","https://vuldb.com/?submit.661277","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11083","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11083","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16353","https://sourceware.org/bugzilla/show_bug.cgi?id=33457","https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490","https://vuldb.com/?ctiid.326124","https://vuldb.com/?id.326124","https://vuldb.com/?submit.661277","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11083","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11083","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16353","https://sourceware.org/bugzilla/show_bug.cgi?id=33457","https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490","https://vuldb.com/?ctiid.326124","https://vuldb.com/?id.326124","https://vuldb.com/?submit.661277","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11083","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11083","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16353","https://sourceware.org/bugzilla/show_bug.cgi?id=33457","https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490","https://vuldb.com/?ctiid.326124","https://vuldb.com/?id.326124","https://vuldb.com/?submit.661277","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11083","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11083","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16353","https://sourceware.org/bugzilla/show_bug.cgi?id=33457","https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490","https://vuldb.com/?ctiid.326124","https://vuldb.com/?id.326124","https://vuldb.com/?submit.661277","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11083","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11083","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16353","https://sourceware.org/bugzilla/show_bug.cgi?id=33457","https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490","https://vuldb.com/?ctiid.326124","https://vuldb.com/?id.326124","https://vuldb.com/?submit.661277","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11083","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11083","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16353","https://sourceware.org/bugzilla/show_bug.cgi?id=33457","https://sourceware.org/bugzilla/show_bug.cgi?id=33457#c1","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=9ca499644a21ceb3f946d1c179c38a83be084490","https://vuldb.com/?ctiid.326124","https://vuldb.com/?id.326124","https://vuldb.com/?submit.661277","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11083","epss":0.00255,"percentile":0.17059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11083","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11083","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3442","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3442","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-3442","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3442","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3442","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-3442","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3442","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3442","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-3442","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3442","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3442","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-3442","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3442","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3442","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-3442","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3442","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3442","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-3442","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3442","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3442","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012750000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-3442","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3442","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3442","https://bugzilla.redhat.com/show_bug.cgi?id=2443828"],"description":"A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3442","epss":0.00255,"percentile":0.17037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3442","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3442","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11082","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11082","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16358","https://sourceware.org/bugzilla/show_bug.cgi?id=33464","https://sourceware.org/bugzilla/show_bug.cgi?id=33464#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea1a0737c7692737a644af0486b71e4a392cbca8","https://vuldb.com/?ctiid.326123","https://vuldb.com/?id.326123","https://vuldb.com/?submit.661276","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11082","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11082","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16358","https://sourceware.org/bugzilla/show_bug.cgi?id=33464","https://sourceware.org/bugzilla/show_bug.cgi?id=33464#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea1a0737c7692737a644af0486b71e4a392cbca8","https://vuldb.com/?ctiid.326123","https://vuldb.com/?id.326123","https://vuldb.com/?submit.661276","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11082","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11082","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16358","https://sourceware.org/bugzilla/show_bug.cgi?id=33464","https://sourceware.org/bugzilla/show_bug.cgi?id=33464#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea1a0737c7692737a644af0486b71e4a392cbca8","https://vuldb.com/?ctiid.326123","https://vuldb.com/?id.326123","https://vuldb.com/?submit.661276","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11082","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11082","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16358","https://sourceware.org/bugzilla/show_bug.cgi?id=33464","https://sourceware.org/bugzilla/show_bug.cgi?id=33464#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea1a0737c7692737a644af0486b71e4a392cbca8","https://vuldb.com/?ctiid.326123","https://vuldb.com/?id.326123","https://vuldb.com/?submit.661276","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11082","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11082","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16358","https://sourceware.org/bugzilla/show_bug.cgi?id=33464","https://sourceware.org/bugzilla/show_bug.cgi?id=33464#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea1a0737c7692737a644af0486b71e4a392cbca8","https://vuldb.com/?ctiid.326123","https://vuldb.com/?id.326123","https://vuldb.com/?submit.661276","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11082","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11082","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16358","https://sourceware.org/bugzilla/show_bug.cgi?id=33464","https://sourceware.org/bugzilla/show_bug.cgi?id=33464#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea1a0737c7692737a644af0486b71e4a392cbca8","https://vuldb.com/?ctiid.326123","https://vuldb.com/?id.326123","https://vuldb.com/?submit.661276","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11082","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11082","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16358","https://sourceware.org/bugzilla/show_bug.cgi?id=33464","https://sourceware.org/bugzilla/show_bug.cgi?id=33464#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea1a0737c7692737a644af0486b71e4a392cbca8","https://vuldb.com/?ctiid.326123","https://vuldb.com/?id.326123","https://vuldb.com/?submit.661276","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with \"[f]ixed for 2.46\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11082","epss":0.00254,"percentile":0.16943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11082","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11082","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-57360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57360","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2024-57360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57360","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32467"],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2024-57360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57360","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2024-57360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57360","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32467"],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-57360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57360","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2024-57360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57360","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32467"],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-57360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57360","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2024-57360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57360","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32467"],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-57360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57360","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2024-57360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57360","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32467"],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-57360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57360","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2024-57360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57360","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32467"],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2024-57360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57360","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012700000000000003},"relatedVulnerabilities":[{"id":"CVE-2024-57360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57360","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32467"],"description":"https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57360","epss":0.00254,"percentile":0.16885,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57360","cwe":"CWE-284","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57360","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-61144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61144","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.","cvss":[],"epss":[{"cve":"CVE-2025-61144","epss":0.00253,"percentile":0.16717,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61144","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61144","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-61144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61144","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/optionGo/5ad17e96a0a40f03578dd6c9f8645952","https://gitlab.com/libtiff/libtiff/-/commit/09f53a86cf26dfd961925227e59e180db617f26d","https://gitlab.com/libtiff/libtiff/-/commit/88cf9dbb48f6e172629795ecffae35d5052f68aa","https://gitlab.com/libtiff/libtiff/-/issues/740","https://gitlab.com/libtiff/libtiff/-/merge_requests/757"],"description":"libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.4,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61144","epss":0.00253,"percentile":0.16717,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61144","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61144","cwe":"CWE-119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-61144","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-31344","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-31344","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C.  This issue affects giflib: through 5.2.2.","cvss":[],"epss":[{"cve":"CVE-2025-31344","epss":0.00249,"percentile":0.1627,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-31344","cwe":"CWE-122","source":"securities@openeuler.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012450000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-31344","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-31344","namespace":"nvd:cpe","severity":"High","urls":["https://gitee.com/src-openeuler/giflib/pulls/54","https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-1292","http://www.openwall.com/lists/oss-security/2025/04/07/3","http://www.openwall.com/lists/oss-security/2025/04/07/4","http://www.openwall.com/lists/oss-security/2025/04/07/5","http://www.openwall.com/lists/oss-security/2025/04/07/6","http://www.openwall.com/lists/oss-security/2025/04/08/1","http://www.openwall.com/lists/oss-security/2025/04/09/5","http://www.openwall.com/lists/oss-security/2025/04/09/7","http://www.openwall.com/lists/oss-security/2025/04/10/1"],"description":"Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C.\n\nThis issue affects giflib: through 5.2.2.","cvss":[{"source":"securities@openeuler.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":2.6,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-31344","epss":0.00249,"percentile":0.1627,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-31344","cwe":"CWE-122","source":"securities@openeuler.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"giflib","version":"5.2.1-2.5+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-31344","versionConstraint":"none (unknown)"}}],"artifact":{"id":"71a582f5b3d629e1","name":"libgif7","version":"5.2.1-2.5+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgif7/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgif7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgif7:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgif7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT"],"cpes":["cpe:2.3:a:libgif7:libgif7:5.2.1-2.5\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgif7@5.2.1-2.5%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=giflib","upstreams":[{"name":"giflib"}]}},{"vulnerability":{"id":"CVE-2025-8176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8176","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8176","epss":0.00243,"percentile":0.15465,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8176","cwe":"CWE-416","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01215},"relatedVulnerabilities":[{"id":"CVE-2025-8176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8176","namespace":"nvd:cpe","severity":"High","urls":["http://www.libtiff.org/","https://gitlab.com/libtiff/libtiff/-/commit/fe10872e53efba9cc36c66ac4ab3b41a839d5172","https://gitlab.com/libtiff/libtiff/-/issues/707","https://gitlab.com/libtiff/libtiff/-/merge_requests/727","https://vuldb.com/?ctiid.317590","https://vuldb.com/?id.317590","https://vuldb.com/?submit.621796"],"description":"A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8176","epss":0.00243,"percentile":0.15465,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8176","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8176","cwe":"CWE-416","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-69651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69651","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011999999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-69651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69651","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011999999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-69651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69651","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011999999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-69651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69651","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011999999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-69651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69651","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011999999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-69651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69651","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011999999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-69651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69651","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011999999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-69651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69651","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33698","https://sourceware.org/bugzilla/show_bug.cgi?id=33700","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=81e90cf63a10ad11772c2437c8f2a88f1a00c739","https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=ea4bc025abdba85a90e26e13f551c16a44bfa92","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=ea4bc025abdba85a90e26e13f551c16a44bfa921"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69651","epss":0.0024,"percentile":0.15099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69651","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11495","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11495","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11495","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11495","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11495","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11495","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11495","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-11495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11495","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16393","https://sourceware.org/bugzilla/show_bug.cgi?id=33502","https://sourceware.org/bugzilla/show_bug.cgi?id=33502#c3","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0","https://vuldb.com/?ctiid.327620","https://vuldb.com/?id.327620","https://vuldb.com/?submit.668290","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11495","epss":0.00238,"percentile":0.14863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11495","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11495","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11495","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-3479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-3479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","namespace":"nvd:cpe","severity":"Negligible","urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3479","epss":0.00238,"percentile":0.14831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2025-66864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66864","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-66864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66864","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66864","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66864","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66864","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66864","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66864","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011900000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-66864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66864","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash5.md"],"description":"An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66864","epss":0.00238,"percentile":0.14815,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66864","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0115},"relatedVulnerabilities":[{"id":"CVE-2025-8224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8224","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15680","https://sourceware.org/bugzilla/show_bug.cgi?id=32109","https://sourceware.org/bugzilla/show_bug.cgi?id=32109#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db856d41004301b3a56438efd957ef5cabb91530","https://vuldb.com/?ctiid.317812","https://vuldb.com/?id.317812","https://vuldb.com/?submit.621878","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-8224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0115},"relatedVulnerabilities":[{"id":"CVE-2025-8224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8224","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15680","https://sourceware.org/bugzilla/show_bug.cgi?id=32109","https://sourceware.org/bugzilla/show_bug.cgi?id=32109#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db856d41004301b3a56438efd957ef5cabb91530","https://vuldb.com/?ctiid.317812","https://vuldb.com/?id.317812","https://vuldb.com/?submit.621878","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0115},"relatedVulnerabilities":[{"id":"CVE-2025-8224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8224","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15680","https://sourceware.org/bugzilla/show_bug.cgi?id=32109","https://sourceware.org/bugzilla/show_bug.cgi?id=32109#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db856d41004301b3a56438efd957ef5cabb91530","https://vuldb.com/?ctiid.317812","https://vuldb.com/?id.317812","https://vuldb.com/?submit.621878","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0115},"relatedVulnerabilities":[{"id":"CVE-2025-8224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8224","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15680","https://sourceware.org/bugzilla/show_bug.cgi?id=32109","https://sourceware.org/bugzilla/show_bug.cgi?id=32109#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db856d41004301b3a56438efd957ef5cabb91530","https://vuldb.com/?ctiid.317812","https://vuldb.com/?id.317812","https://vuldb.com/?submit.621878","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0115},"relatedVulnerabilities":[{"id":"CVE-2025-8224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8224","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15680","https://sourceware.org/bugzilla/show_bug.cgi?id=32109","https://sourceware.org/bugzilla/show_bug.cgi?id=32109#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db856d41004301b3a56438efd957ef5cabb91530","https://vuldb.com/?ctiid.317812","https://vuldb.com/?id.317812","https://vuldb.com/?submit.621878","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0115},"relatedVulnerabilities":[{"id":"CVE-2025-8224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8224","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15680","https://sourceware.org/bugzilla/show_bug.cgi?id=32109","https://sourceware.org/bugzilla/show_bug.cgi?id=32109#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db856d41004301b3a56438efd957ef5cabb91530","https://vuldb.com/?ctiid.317812","https://vuldb.com/?id.317812","https://vuldb.com/?submit.621878","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8224","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0115},"relatedVulnerabilities":[{"id":"CVE-2025-8224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8224","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15680","https://sourceware.org/bugzilla/show_bug.cgi?id=32109","https://sourceware.org/bugzilla/show_bug.cgi?id=32109#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db856d41004301b3a56438efd957ef5cabb91530","https://vuldb.com/?ctiid.317812","https://vuldb.com/?id.317812","https://vuldb.com/?submit.621878","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8224","epss":0.0023,"percentile":0.13787,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8224","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-1371","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1371","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-1371","epss":0.00229,"percentile":0.13633,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1371","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1371","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1371","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01145},"relatedVulnerabilities":[{"id":"CVE-2025-1371","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1371","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15926","https://sourceware.org/bugzilla/show_bug.cgi?id=32655","https://sourceware.org/bugzilla/show_bug.cgi?id=32655#c2","https://vuldb.com/?ctiid.295978","https://vuldb.com/?id.295978","https://vuldb.com/?submit.496484","https://www.gnu.org/"],"description":"A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-1371","epss":0.00229,"percentile":0.13633,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-1371","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1371","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-1371","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-1371","versionConstraint":"none (unknown)"}}],"artifact":{"id":"00b653c92ba9a809","name":"libelf1","version":"0.188-2.1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","upstreams":[{"name":"elfutils"}]}},{"vulnerability":{"id":"CVE-2025-8225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8225","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01145},"relatedVulnerabilities":[{"id":"CVE-2025-8225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8225","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/gnutools/binutils-gdb/-/commit/e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4","https://vuldb.com/?ctiid.317813","https://vuldb.com/?id.317813","https://vuldb.com/?submit.621883","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-8225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8225","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01145},"relatedVulnerabilities":[{"id":"CVE-2025-8225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8225","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/gnutools/binutils-gdb/-/commit/e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4","https://vuldb.com/?ctiid.317813","https://vuldb.com/?id.317813","https://vuldb.com/?submit.621883","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8225","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01145},"relatedVulnerabilities":[{"id":"CVE-2025-8225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8225","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/gnutools/binutils-gdb/-/commit/e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4","https://vuldb.com/?ctiid.317813","https://vuldb.com/?id.317813","https://vuldb.com/?submit.621883","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8225","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01145},"relatedVulnerabilities":[{"id":"CVE-2025-8225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8225","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/gnutools/binutils-gdb/-/commit/e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4","https://vuldb.com/?ctiid.317813","https://vuldb.com/?id.317813","https://vuldb.com/?submit.621883","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8225","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01145},"relatedVulnerabilities":[{"id":"CVE-2025-8225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8225","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/gnutools/binutils-gdb/-/commit/e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4","https://vuldb.com/?ctiid.317813","https://vuldb.com/?id.317813","https://vuldb.com/?submit.621883","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8225","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01145},"relatedVulnerabilities":[{"id":"CVE-2025-8225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8225","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/gnutools/binutils-gdb/-/commit/e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4","https://vuldb.com/?ctiid.317813","https://vuldb.com/?id.317813","https://vuldb.com/?submit.621883","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8225","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01145},"relatedVulnerabilities":[{"id":"CVE-2025-8225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8225","namespace":"nvd:cpe","severity":"Low","urls":["https://gitlab.com/gnutools/binutils-gdb/-/commit/e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4","https://vuldb.com/?ctiid.317813","https://vuldb.com/?id.317813","https://vuldb.com/?submit.621883","https://www.gnu.org/"],"description":"A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8225","epss":0.00229,"percentile":0.13613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8225","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-29933","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-29933","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.","cvss":[],"epss":[{"cve":"CVE-2023-29933","epss":0.00221,"percentile":0.12586,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29933","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29933","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2023-29933","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29933","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/llvm/llvm-project/issues/59442"],"description":"llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-29933","epss":0.00221,"percentile":0.12586,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29933","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29933","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-29933","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2023-29935","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-29935","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && \"operation was already replaced.","cvss":[],"epss":[{"cve":"CVE-2023-29935","epss":0.00221,"percentile":0.12586,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29935","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29935","cwe":"CWE-617","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2023-29935","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29935","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/llvm/llvm-project/issues/59182"],"description":"llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && \"operation was already replaced.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-29935","epss":0.00221,"percentile":0.12586,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29935","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29935","cwe":"CWE-617","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-29935","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2023-29942","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-29942","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.","cvss":[],"epss":[{"cve":"CVE-2023-29942","epss":0.00221,"percentile":0.12586,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29942","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29942","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2023-29942","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29942","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/llvm/llvm-project/issues/59990"],"description":"llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-29942","epss":0.00221,"percentile":0.12586,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29942","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29942","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-29942","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2023-29932","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-29932","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.","cvss":[],"epss":[{"cve":"CVE-2023-29932","epss":0.00221,"percentile":0.12585,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29932","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29932","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2023-29932","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29932","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/llvm/llvm-project/issues/58745"],"description":"llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-29932","epss":0.00221,"percentile":0.12585,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29932","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29932","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-29932","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2023-29934","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-29934","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect().","cvss":[],"epss":[{"cve":"CVE-2023-29934","epss":0.00221,"percentile":0.12585,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29934","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29934","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2023-29934","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29934","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/llvm/llvm-project/issues/59136"],"description":"llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-29934","epss":0.00221,"percentile":0.12585,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29934","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29934","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-29934","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2025-11413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11413","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2025-11413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11413","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16362","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0","https://vuldb.com/?ctiid.327349","https://vuldb.com/?id.327349","https://vuldb.com/?submit.665587","https://vuldb.com/?submit.665590","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11413","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2025-11413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11413","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16362","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0","https://vuldb.com/?ctiid.327349","https://vuldb.com/?id.327349","https://vuldb.com/?submit.665587","https://vuldb.com/?submit.665590","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11413","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2025-11413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11413","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16362","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0","https://vuldb.com/?ctiid.327349","https://vuldb.com/?id.327349","https://vuldb.com/?submit.665587","https://vuldb.com/?submit.665590","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11413","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2025-11413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11413","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16362","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0","https://vuldb.com/?ctiid.327349","https://vuldb.com/?id.327349","https://vuldb.com/?submit.665587","https://vuldb.com/?submit.665590","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11413","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2025-11413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11413","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16362","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0","https://vuldb.com/?ctiid.327349","https://vuldb.com/?id.327349","https://vuldb.com/?submit.665587","https://vuldb.com/?submit.665590","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11413","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2025-11413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11413","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16362","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0","https://vuldb.com/?ctiid.327349","https://vuldb.com/?id.327349","https://vuldb.com/?submit.665587","https://vuldb.com/?submit.665590","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11413","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01105},"relatedVulnerabilities":[{"id":"CVE-2025-11413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11413","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16362","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33456#c10","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=72efdf166aa0ed72ecc69fc2349af6591a7a19c0","https://vuldb.com/?ctiid.327349","https://vuldb.com/?id.327349","https://vuldb.com/?submit.665587","https://vuldb.com/?submit.665590","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11413","epss":0.00221,"percentile":0.12569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11413","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11413","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2023-29939","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-29939","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr).","cvss":[],"epss":[{"cve":"CVE-2023-29939","epss":0.00218,"percentile":0.12166,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29939","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29939","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0109},"relatedVulnerabilities":[{"id":"CVE-2023-29939","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29939","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/llvm/llvm-project/issues/59983"],"description":"llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-29939","epss":0.00218,"percentile":0.12166,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29939","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29939","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-29939","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2025-9165","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-9165","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because \"this is a memory leak on a command line tool that is about to exit anyway\". In the reply the project maintainer declares this issue as \"a simple 'bug' when leaving the command line tool and (...) not a security issue at all\".","cvss":[],"epss":[{"cve":"CVE-2025-9165","epss":0.00217,"percentile":0.12157,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-9165","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-9165","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01085},"relatedVulnerabilities":[{"id":"CVE-2025-9165","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9165","namespace":"nvd:cpe","severity":"Low","urls":["http://www.libtiff.org/","https://drive.google.com/file/d/1FWhmkzksH8-qU0ZM6seBzGNB3aPnX3G8/view?usp=sharing","https://gitlab.com/libtiff/libtiff/-/commit/ed141286a37f6e5ddafb5069347ff5d587e7a4e0","https://gitlab.com/libtiff/libtiff/-/issues/728","https://gitlab.com/libtiff/libtiff/-/merge_requests/747","https://vuldb.com/?ctiid.320543","https://vuldb.com/?id.320543","https://vuldb.com/?submit.630506","https://vuldb.com/?submit.630507","https://gitlab.com/libtiff/libtiff/-/issues/728#note_2709263214"],"description":"A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because \"this is a memory leak on a command line tool that is about to exit anyway\". In the reply the project maintainer declares this issue as \"a simple 'bug' when leaving the command line tool and (...) not a security issue at all\".","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.1},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:H/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1,"exploitabilityScore":1.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-9165","epss":0.00217,"percentile":0.12157,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-9165","cwe":"CWE-401","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-9165","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-9165","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-29088","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-29088","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.","cvss":[],"epss":[{"cve":"CVE-2025-29088","epss":0.00217,"percentile":0.1211,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-29088","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01085},"relatedVulnerabilities":[{"id":"CVE-2025-29088","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-29088","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/ylwango613/d3883fb9f6ba8a78086356779ce88248","https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4","https://sqlite.org/forum/forumpost/48f365daec","https://sqlite.org/releaselog/3_49_1.html","https://www.sqlite.org/cves.html"],"description":"In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"exploitabilityScore":1.5,"impactScore":3.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-29088","epss":0.00217,"percentile":0.1211,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-29088","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-29088","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3705ae977c727f09","name":"libsqlite3-0","version":"3.40.1-2+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["GPL-2","GPL-2+","public-domain"],"cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","upstreams":[{"name":"sqlite3"}]}},{"vulnerability":{"id":"CVE-2023-29941","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-29941","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.","cvss":[],"epss":[{"cve":"CVE-2023-29941","epss":0.00215,"percentile":0.11889,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29941","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29941","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010750000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-29941","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29941","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/llvm/llvm-project/issues/59988","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWCCXDZP7H2JNFULSZZWXGAZHZUPN5DS/"],"description":"llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-29941","epss":0.00215,"percentile":0.11889,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-29941","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-29941","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"llvm-toolchain-15","version":"1:15.0.6-4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-29941","versionConstraint":"none (unknown)"}}],"artifact":{"id":"9da3ff34c9054159","name":"libllvm15","version":"1:15.0.6-4+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libllvm15/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libllvm15/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libllvm15:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["APACHE-2-LLVM-EXCEPTIONS","Apache-2.0","BSD-3-Clause","BSD-3-clause","MIT","Python","solar-public-domain"],"cpes":["cpe:2.3:a:libllvm15:libllvm15:1\\:15.0.6-4\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libllvm15@1%3A15.0.6-4%2Bb1?arch=amd64&distro=debian-12.15&upstream=llvm-toolchain-15%401%3A15.0.6-4","upstreams":[{"name":"llvm-toolchain-15","version":"1:15.0.6-4"}]}},{"vulnerability":{"id":"CVE-2025-11494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11494","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11494","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16389","https://sourceware.org/bugzilla/show_bug.cgi?id=33499","https://sourceware.org/bugzilla/show_bug.cgi?id=33499#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a","https://vuldb.com/?ctiid.327619","https://vuldb.com/?id.327619","https://vuldb.com/?submit.668281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11494","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11494","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11494","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16389","https://sourceware.org/bugzilla/show_bug.cgi?id=33499","https://sourceware.org/bugzilla/show_bug.cgi?id=33499#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a","https://vuldb.com/?ctiid.327619","https://vuldb.com/?id.327619","https://vuldb.com/?submit.668281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11494","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11494","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11494","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16389","https://sourceware.org/bugzilla/show_bug.cgi?id=33499","https://sourceware.org/bugzilla/show_bug.cgi?id=33499#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a","https://vuldb.com/?ctiid.327619","https://vuldb.com/?id.327619","https://vuldb.com/?submit.668281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11494","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11494","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11494","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16389","https://sourceware.org/bugzilla/show_bug.cgi?id=33499","https://sourceware.org/bugzilla/show_bug.cgi?id=33499#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a","https://vuldb.com/?ctiid.327619","https://vuldb.com/?id.327619","https://vuldb.com/?submit.668281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11494","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11494","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11494","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16389","https://sourceware.org/bugzilla/show_bug.cgi?id=33499","https://sourceware.org/bugzilla/show_bug.cgi?id=33499#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a","https://vuldb.com/?ctiid.327619","https://vuldb.com/?id.327619","https://vuldb.com/?submit.668281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11494","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11494","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11494","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16389","https://sourceware.org/bugzilla/show_bug.cgi?id=33499","https://sourceware.org/bugzilla/show_bug.cgi?id=33499#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a","https://vuldb.com/?ctiid.327619","https://vuldb.com/?id.327619","https://vuldb.com/?submit.668281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11494","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11494","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010750000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11494","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16389","https://sourceware.org/bugzilla/show_bug.cgi?id=33499","https://sourceware.org/bugzilla/show_bug.cgi?id=33499#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a","https://vuldb.com/?ctiid.327619","https://vuldb.com/?id.327619","https://vuldb.com/?submit.668281","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11494","epss":0.00215,"percentile":0.11856,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11494","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11494","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11494","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-9403","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-9403","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.","cvss":[],"epss":[{"cve":"CVE-2025-9403","epss":0.00211,"percentile":0.11342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01055},"relatedVulnerabilities":[{"id":"CVE-2025-9403","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9403","namespace":"nvd:cpe","severity":"Medium","urls":["https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing","https://github.com/jqlang/jq/issues/3393","https://vuldb.com/?ctiid.321239","https://vuldb.com/?id.321239","https://vuldb.com/?submit.633170"],"description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-9403","epss":0.00211,"percentile":0.11342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jq","version":"1.6-2.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-9403","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7197c1d5ef24996b","name":"jq","version":"1.6-2.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/jq.list"}],"language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"cpes":["cpe:2.3:a:jq:jq:1.6-2.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/jq@1.6-2.1%2Bdeb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-9403","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-9403","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.","cvss":[],"epss":[{"cve":"CVE-2025-9403","epss":0.00211,"percentile":0.11342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01055},"relatedVulnerabilities":[{"id":"CVE-2025-9403","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9403","namespace":"nvd:cpe","severity":"Medium","urls":["https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing","https://github.com/jqlang/jq/issues/3393","https://vuldb.com/?ctiid.321239","https://vuldb.com/?id.321239","https://vuldb.com/?submit.633170"],"description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-9403","epss":0.00211,"percentile":0.11342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jq","version":"1.6-2.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-9403","versionConstraint":"none (unknown)"}}],"artifact":{"id":"87f3880f412f67fd","name":"libjq1","version":"1.6-2.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"cpes":["cpe:2.3:a:libjq1:libjq1:1.6-2.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjq1@1.6-2.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=jq","upstreams":[{"name":"jq"}]}},{"vulnerability":{"id":"CVE-2025-11412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11412","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11412","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16378","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33452#c8","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc","https://vuldb.com/?ctiid.327348","https://vuldb.com/?id.327348","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11414","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11414","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16361","https://sourceware.org/bugzilla/show_bug.cgi?id=33450","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703","https://vuldb.com/?ctiid.327350","https://vuldb.com/?id.327350","https://vuldb.com/?submit.665591","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11414","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11412","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11412","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16378","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33452#c8","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc","https://vuldb.com/?ctiid.327348","https://vuldb.com/?id.327348","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11414","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11414","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16361","https://sourceware.org/bugzilla/show_bug.cgi?id=33450","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703","https://vuldb.com/?ctiid.327350","https://vuldb.com/?id.327350","https://vuldb.com/?submit.665591","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11414","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11412","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11412","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16378","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33452#c8","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc","https://vuldb.com/?ctiid.327348","https://vuldb.com/?id.327348","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11414","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11414","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16361","https://sourceware.org/bugzilla/show_bug.cgi?id=33450","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703","https://vuldb.com/?ctiid.327350","https://vuldb.com/?id.327350","https://vuldb.com/?submit.665591","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11414","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11412","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11412","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16378","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33452#c8","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc","https://vuldb.com/?ctiid.327348","https://vuldb.com/?id.327348","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11414","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11414","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16361","https://sourceware.org/bugzilla/show_bug.cgi?id=33450","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703","https://vuldb.com/?ctiid.327350","https://vuldb.com/?id.327350","https://vuldb.com/?submit.665591","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11414","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11412","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11412","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16378","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33452#c8","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc","https://vuldb.com/?ctiid.327348","https://vuldb.com/?id.327348","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11414","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11414","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16361","https://sourceware.org/bugzilla/show_bug.cgi?id=33450","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703","https://vuldb.com/?ctiid.327350","https://vuldb.com/?id.327350","https://vuldb.com/?submit.665591","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11414","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11412","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11412","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16378","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33452#c8","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc","https://vuldb.com/?ctiid.327348","https://vuldb.com/?id.327348","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11414","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11414","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16361","https://sourceware.org/bugzilla/show_bug.cgi?id=33450","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703","https://vuldb.com/?ctiid.327350","https://vuldb.com/?id.327350","https://vuldb.com/?submit.665591","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11414","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11412","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11412","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16378","https://sourceware.org/bugzilla/show_bug.cgi?id=33452","https://sourceware.org/bugzilla/show_bug.cgi?id=33452#c8","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=047435dd988a3975d40c6626a8f739a0b2e154bc","https://vuldb.com/?ctiid.327348","https://vuldb.com/?id.327348","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11412","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11412","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11412","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11414","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-11414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11414","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16361","https://sourceware.org/bugzilla/show_bug.cgi?id=33450","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aeaaa9af6359c8e394ce9cf24911fec4f4d23703","https://vuldb.com/?ctiid.327350","https://vuldb.com/?id.327350","https://vuldb.com/?submit.665591","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"description":"A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11414","epss":0.00205,"percentile":0.10551,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11414","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11414","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11414","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8961","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.","cvss":[],"epss":[{"cve":"CVE-2025-8961","epss":0.00205,"percentile":0.10522,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8961","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01025},"relatedVulnerabilities":[{"id":"CVE-2025-8961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8961","namespace":"nvd:cpe","severity":"Low","urls":["http://www.libtiff.org/","https://drive.google.com/file/d/15L4q2eD8GX3Aj3z6SWC3_FbqaM1ChUx2/view?usp=sharing","https://gitlab.com/libtiff/libtiff/-/issues/721","https://gitlab.com/libtiff/libtiff/-/issues/721#note_2670686960","https://vuldb.com/?ctiid.319955","https://vuldb.com/?id.319955","https://vuldb.com/?submit.627957"],"description":"A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8961","epss":0.00205,"percentile":0.10522,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8961","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-11081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11081","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010150000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11081","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/user-attachments/files/20623354/hdf5_crash_3.txt","https://sourceware.org/bugzilla/show_bug.cgi?id=33406","https://sourceware.org/bugzilla/show_bug.cgi?id=33406#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f87a66db645caf8cc0e6fc87b0c28c78a38af59b","https://vuldb.com/?ctiid.326122","https://vuldb.com/?id.326122","https://vuldb.com/?submit.661275","https://www.gnu.org/"],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-11081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11081","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010150000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11081","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/user-attachments/files/20623354/hdf5_crash_3.txt","https://sourceware.org/bugzilla/show_bug.cgi?id=33406","https://sourceware.org/bugzilla/show_bug.cgi?id=33406#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f87a66db645caf8cc0e6fc87b0c28c78a38af59b","https://vuldb.com/?ctiid.326122","https://vuldb.com/?id.326122","https://vuldb.com/?submit.661275","https://www.gnu.org/"],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11081","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010150000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11081","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/user-attachments/files/20623354/hdf5_crash_3.txt","https://sourceware.org/bugzilla/show_bug.cgi?id=33406","https://sourceware.org/bugzilla/show_bug.cgi?id=33406#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f87a66db645caf8cc0e6fc87b0c28c78a38af59b","https://vuldb.com/?ctiid.326122","https://vuldb.com/?id.326122","https://vuldb.com/?submit.661275","https://www.gnu.org/"],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11081","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010150000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11081","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/user-attachments/files/20623354/hdf5_crash_3.txt","https://sourceware.org/bugzilla/show_bug.cgi?id=33406","https://sourceware.org/bugzilla/show_bug.cgi?id=33406#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f87a66db645caf8cc0e6fc87b0c28c78a38af59b","https://vuldb.com/?ctiid.326122","https://vuldb.com/?id.326122","https://vuldb.com/?submit.661275","https://www.gnu.org/"],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11081","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010150000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11081","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/user-attachments/files/20623354/hdf5_crash_3.txt","https://sourceware.org/bugzilla/show_bug.cgi?id=33406","https://sourceware.org/bugzilla/show_bug.cgi?id=33406#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f87a66db645caf8cc0e6fc87b0c28c78a38af59b","https://vuldb.com/?ctiid.326122","https://vuldb.com/?id.326122","https://vuldb.com/?submit.661275","https://www.gnu.org/"],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11081","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010150000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11081","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/user-attachments/files/20623354/hdf5_crash_3.txt","https://sourceware.org/bugzilla/show_bug.cgi?id=33406","https://sourceware.org/bugzilla/show_bug.cgi?id=33406#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f87a66db645caf8cc0e6fc87b0c28c78a38af59b","https://vuldb.com/?ctiid.326122","https://vuldb.com/?id.326122","https://vuldb.com/?submit.661275","https://www.gnu.org/"],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-11081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-11081","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010150000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-11081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11081","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/user-attachments/files/20623354/hdf5_crash_3.txt","https://sourceware.org/bugzilla/show_bug.cgi?id=33406","https://sourceware.org/bugzilla/show_bug.cgi?id=33406#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f87a66db645caf8cc0e6fc87b0c28c78a38af59b","https://vuldb.com/?ctiid.326122","https://vuldb.com/?id.326122","https://vuldb.com/?submit.661275","https://www.gnu.org/"],"description":"A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-11081","epss":0.00203,"percentile":0.10335,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-11081","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-11081","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-11081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-59801","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59801","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.","cvss":[],"epss":[{"cve":"CVE-2025-59801","epss":0.00202,"percentile":0.10139,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59801","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-59801","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59801","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708819","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=99727069197d548a8db69ba5d63f766bff40eaab"],"description":"In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59801","epss":0.00202,"percentile":0.10139,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59801","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59801","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1a53878210d7ee72","name":"libgs-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs-common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2025-59801","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59801","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.","cvss":[],"epss":[{"cve":"CVE-2025-59801","epss":0.00202,"percentile":0.10139,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59801","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-59801","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59801","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708819","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=99727069197d548a8db69ba5d63f766bff40eaab"],"description":"In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59801","epss":0.00202,"percentile":0.10139,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59801","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59801","versionConstraint":"none (unknown)"}}],"artifact":{"id":"097a7cb358060cf0","name":"libgs10","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10:libgs10:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10@10.0.0~dfsg-11%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2025-59801","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59801","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.","cvss":[],"epss":[{"cve":"CVE-2025-59801","epss":0.00202,"percentile":0.10139,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59801","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.010100000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-59801","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59801","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708819","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=99727069197d548a8db69ba5d63f766bff40eaab"],"description":"In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.","cvss":[{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59801","epss":0.00202,"percentile":0.10139,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59801","cwe":"CWE-121","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59801","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1592f7455014590c","name":"libgs10-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-14104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009650000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-14104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14104","epss":0.00193,"percentile":0.09072,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2025-8534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8534","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that \"[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. \"rD\") option is used.\"","cvss":[],"epss":[{"cve":"CVE-2025-8534","epss":0.00186,"percentile":0.08327,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8534","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8534","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009300000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-8534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8534","namespace":"nvd:cpe","severity":"Low","urls":["http://www.libtiff.org/","https://drive.google.com/file/d/15JPA3kLYiYD-nRNJ8y8HmnYjhv9NE7k6/view?usp=drive_link","https://gitlab.com/libtiff/libtiff/-/commit/6ba36f159fd396ad11bf6b7874554197736ecc8b","https://gitlab.com/libtiff/libtiff/-/issues/718","https://gitlab.com/libtiff/libtiff/-/merge_requests/746","https://vuldb.com/?ctiid.318664","https://vuldb.com/?id.318664","https://vuldb.com/?submit.617831"],"description":"A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that \"[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. \"rD\") option is used.\"","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.1},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:H/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1,"exploitabilityScore":1.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8534","epss":0.00186,"percentile":0.08327,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8534","cwe":"CWE-404","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8534","cwe":"CWE-476","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8534","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-3441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3441","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00915},"relatedVulnerabilities":[{"id":"CVE-2026-3441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-3441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3441","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00915},"relatedVulnerabilities":[{"id":"CVE-2026-3441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3441","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00915},"relatedVulnerabilities":[{"id":"CVE-2026-3441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3441","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00915},"relatedVulnerabilities":[{"id":"CVE-2026-3441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3441","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00915},"relatedVulnerabilities":[{"id":"CVE-2026-3441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3441","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00915},"relatedVulnerabilities":[{"id":"CVE-2026-3441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3441","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00915},"relatedVulnerabilities":[{"id":"CVE-2026-3441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3441","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-3441","https://bugzilla.redhat.com/show_bug.cgi?id=2443826"],"description":"A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3441","epss":0.00183,"percentile":0.08034,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3441","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3441","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-8851","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8851","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-8851","epss":0.0018,"percentile":0.07618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8851","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8851","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.009000000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-8851","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8851","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.libtiff.org/","https://gitlab.com/libtiff/libtiff/-/commit/8a7a48d7a645992ca83062b3a1873c951661e2b3","https://vuldb.com/?ctiid.319382","https://vuldb.com/?id.319382","https://vuldb.com/?submit.624604"],"description":"A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8851","epss":0.0018,"percentile":0.07618,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-8851","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-8851","cwe":"CWE-121","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-8851","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-59800","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59800","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.","cvss":[],"epss":[{"cve":"CVE-2025-59800","epss":0.00178,"percentile":0.07457,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59800","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0089},"relatedVulnerabilities":[{"id":"CVE-2025-59800","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59800","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708602","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=176cf0188a2294bc307b8caec876f39412e58350"],"description":"In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59800","epss":0.00178,"percentile":0.07457,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59800","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59800","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1a53878210d7ee72","name":"libgs-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs-common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2025-59800","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59800","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.","cvss":[],"epss":[{"cve":"CVE-2025-59800","epss":0.00178,"percentile":0.07457,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59800","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0089},"relatedVulnerabilities":[{"id":"CVE-2025-59800","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59800","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708602","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=176cf0188a2294bc307b8caec876f39412e58350"],"description":"In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59800","epss":0.00178,"percentile":0.07457,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59800","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59800","versionConstraint":"none (unknown)"}}],"artifact":{"id":"097a7cb358060cf0","name":"libgs10","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10:libgs10:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10@10.0.0~dfsg-11%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2025-59800","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59800","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.","cvss":[],"epss":[{"cve":"CVE-2025-59800","epss":0.00178,"percentile":0.07457,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59800","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0089},"relatedVulnerabilities":[{"id":"CVE-2025-59800","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59800","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.ghostscript.com/show_bug.cgi?id=708602","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=176cf0188a2294bc307b8caec876f39412e58350"],"description":"In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cve@mitre.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.6,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-59800","epss":0.00178,"percentile":0.07457,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-59800","cwe":"CWE-190","source":"cve@mitre.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ghostscript","version":"10.0.0~dfsg-11+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-59800","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1592f7455014590c","name":"libgs10-common","version":"10.0.0~dfsg-11+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.0.0\\~dfsg-11\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgs10-common@10.0.0~dfsg-11%2Bdeb12u8?arch=all&distro=debian-12.15&upstream=ghostscript","upstreams":[{"name":"ghostscript"}]}},{"vulnerability":{"id":"CVE-2026-5673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5673","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.","cvss":[],"epss":[{"cve":"CVE-2026-5673","epss":0.00178,"percentile":0.07456,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5673","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0089},"relatedVulnerabilities":[{"id":"CVE-2026-5673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5673","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2026-5673","https://bugzilla.redhat.com/show_bug.cgi?id=2455340","https://github.com/xiph/theora/issues/24"],"description":"A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"exploitabilityScore":1.4,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-5673","epss":0.00178,"percentile":0.07456,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-5673","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libtheora","version":"1.1.1+dfsg.1-16.1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-5673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8b83c12ca9041a77","name":"libtheora0","version":"1.1.1+dfsg.1-16.1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtheora0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtheora0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtheora0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtheora0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause"],"cpes":["cpe:2.3:a:libtheora0:libtheora0:1.1.1\\+dfsg.1-16.1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtheora0@1.1.1%2Bdfsg.1-16.1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libtheora","upstreams":[{"name":"libtheora"}]}},{"vulnerability":{"id":"CVE-2025-69648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69648","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0088},"relatedVulnerabilities":[{"id":"CVE-2025-69648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69648","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0088},"relatedVulnerabilities":[{"id":"CVE-2025-69648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69648","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0088},"relatedVulnerabilities":[{"id":"CVE-2025-69648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69648","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0088},"relatedVulnerabilities":[{"id":"CVE-2025-69648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69648","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0088},"relatedVulnerabilities":[{"id":"CVE-2025-69648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69648","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0088},"relatedVulnerabilities":[{"id":"CVE-2025-69648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69648","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0088},"relatedVulnerabilities":[{"id":"CVE-2025-69648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69648","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33641","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69648","epss":0.00176,"percentile":0.0726,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69648","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7546","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7546","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00875},"relatedVulnerabilities":[{"id":"CVE-2025-7546","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7546","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16118","https://sourceware.org/bugzilla/show_bug.cgi?id=33050","https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6b","https://vuldb.com/?ctiid.316244","https://vuldb.com/?id.316244","https://vuldb.com/?submit.614375","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7546","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-7546","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7546","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00875},"relatedVulnerabilities":[{"id":"CVE-2025-7546","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7546","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16118","https://sourceware.org/bugzilla/show_bug.cgi?id=33050","https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6b","https://vuldb.com/?ctiid.316244","https://vuldb.com/?id.316244","https://vuldb.com/?submit.614375","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7546","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7546","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7546","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00875},"relatedVulnerabilities":[{"id":"CVE-2025-7546","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7546","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16118","https://sourceware.org/bugzilla/show_bug.cgi?id=33050","https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6b","https://vuldb.com/?ctiid.316244","https://vuldb.com/?id.316244","https://vuldb.com/?submit.614375","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7546","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7546","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7546","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00875},"relatedVulnerabilities":[{"id":"CVE-2025-7546","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7546","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16118","https://sourceware.org/bugzilla/show_bug.cgi?id=33050","https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6b","https://vuldb.com/?ctiid.316244","https://vuldb.com/?id.316244","https://vuldb.com/?submit.614375","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7546","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7546","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7546","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00875},"relatedVulnerabilities":[{"id":"CVE-2025-7546","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7546","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16118","https://sourceware.org/bugzilla/show_bug.cgi?id=33050","https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6b","https://vuldb.com/?ctiid.316244","https://vuldb.com/?id.316244","https://vuldb.com/?submit.614375","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7546","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7546","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7546","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00875},"relatedVulnerabilities":[{"id":"CVE-2025-7546","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7546","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16118","https://sourceware.org/bugzilla/show_bug.cgi?id=33050","https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6b","https://vuldb.com/?ctiid.316244","https://vuldb.com/?id.316244","https://vuldb.com/?submit.614375","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7546","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-7546","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7546","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00875},"relatedVulnerabilities":[{"id":"CVE-2025-7546","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7546","namespace":"nvd:cpe","severity":"High","urls":["https://sourceware.org/bugzilla/attachment.cgi?id=16118","https://sourceware.org/bugzilla/show_bug.cgi?id=33050","https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6b","https://vuldb.com/?ctiid.316244","https://vuldb.com/?id.316244","https://vuldb.com/?submit.614375","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"description":"A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-7546","epss":0.00175,"percentile":0.07169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-7546","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2025-7546","cwe":"CWE-787","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-7546","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69652","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69652","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00865},"relatedVulnerabilities":[{"id":"CVE-2025-69652","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69652","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69652","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00865},"relatedVulnerabilities":[{"id":"CVE-2025-69652","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69652","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69652","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00865},"relatedVulnerabilities":[{"id":"CVE-2025-69652","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69652","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69652","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00865},"relatedVulnerabilities":[{"id":"CVE-2025-69652","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69652","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69652","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00865},"relatedVulnerabilities":[{"id":"CVE-2025-69652","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69652","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69652","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00865},"relatedVulnerabilities":[{"id":"CVE-2025-69652","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69652","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69652","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00865},"relatedVulnerabilities":[{"id":"CVE-2025-69652","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69652","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33701","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=44b79abd0fa12e7947252eb4c6e5d16ed6033e01"],"description":"GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69652","epss":0.00173,"percentile":0.06843,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69652","cwe":"CWE-460","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69652","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6846","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00855},"relatedVulnerabilities":[{"id":"CVE-2026-6846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6846","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00855},"relatedVulnerabilities":[{"id":"CVE-2026-6846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6846","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00855},"relatedVulnerabilities":[{"id":"CVE-2026-6846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6846","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00855},"relatedVulnerabilities":[{"id":"CVE-2026-6846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6846","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00855},"relatedVulnerabilities":[{"id":"CVE-2026-6846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6846","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00855},"relatedVulnerabilities":[{"id":"CVE-2026-6846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6846","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00855},"relatedVulnerabilities":[{"id":"CVE-2026-6846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6846","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6846","https://bugzilla.redhat.com/show_bug.cgi?id=2460006","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6846.json"],"description":"A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6846","epss":0.00171,"percentile":0.06674,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2026-6846","cwe":"CWE-122","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-4647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-4647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-4647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-4647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-4647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-4647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-4647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-4647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-4647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-4647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-4647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-4647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-4647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-4647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4647","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:33527","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-4647","https://bugzilla.redhat.com/show_bug.cgi?id=2450302","https://sourceware.org/bugzilla/show_bug.cgi?id=33919"],"description":"A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-4647","epss":0.00168,"percentile":0.06368,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-4647","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-4647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-56288","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56288","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.    This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313","cvss":[],"epss":[{"cve":"CVE-2026-56288","epss":0.00168,"percentile":0.063,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56288","cwe":"CWE-476","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56288","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56288","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56288","https://cgit.git.savannah.gnu.org/cgit/patch.git/","https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313"],"description":"GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing.\nAn attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.\n\n\n\nThis issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56288","epss":0.00168,"percentile":0.063,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56288","cwe":"CWE-476","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56288","versionConstraint":"none (unknown)"}}],"artifact":{"id":"acc529981c64331f","name":"patch","version":"2.7.6-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.list"}],"language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-56289","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56289","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination.    This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9","cvss":[],"epss":[{"cve":"CVE-2026-56289","epss":0.00168,"percentile":0.063,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56289","cwe":"CWE-835","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-56289","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56289","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56288","https://cgit.git.savannah.gnu.org/cgit/patch.git/","https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9"],"description":"GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position.\nThis results in excessive CPU consumption and prevents the process from completing.\nAn attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination.\n\n\n\nThis issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56289","epss":0.00168,"percentile":0.063,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56289","cwe":"CWE-835","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"patch","version":"2.7.6-7"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56289","versionConstraint":"none (unknown)"}}],"artifact":{"id":"acc529981c64331f","name":"patch","version":"2.7.6-7","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/patch.list"}],"language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"cpes":["cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/patch@2.7.6-7?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69645","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69645","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008300000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69645","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69645","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69645","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008300000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69645","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69645","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69645","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008300000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69645","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69645","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69645","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008300000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69645","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69645","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69645","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008300000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69645","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69645","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69645","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008300000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69645","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69645","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69645","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.008300000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-69645","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69645","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33637","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cdb728d4da6184631989b192f1022c219dea7677"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69645","epss":0.00166,"percentile":0.06187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69645","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69645","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-40612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40612","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.","cvss":[],"epss":[{"cve":"CVE-2026-40612","epss":0.00161,"percentile":0.05606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00805},"relatedVulnerabilities":[{"id":"CVE-2026-40612","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40612","epss":0.00161,"percentile":0.05606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jq","version":"1.6-2.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7197c1d5ef24996b","name":"jq","version":"1.6-2.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/jq.list"}],"language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"cpes":["cpe:2.3:a:jq:jq:1.6-2.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/jq@1.6-2.1%2Bdeb12u2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-40612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40612","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.","cvss":[],"epss":[{"cve":"CVE-2026-40612","epss":0.00161,"percentile":0.05606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00805},"relatedVulnerabilities":[{"id":"CVE-2026-40612","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"security-advisories@github.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-40612","epss":0.00161,"percentile":0.05606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","source":"security-advisories@github.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"jq","version":"1.6-2.1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"none (unknown)"}}],"artifact":{"id":"87f3880f412f67fd","name":"libjq1","version":"1.6-2.1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"cpes":["cpe:2.3:a:libjq1:libjq1:1.6-2.1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libjq1@1.6-2.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=jq","upstreams":[{"name":"jq"}]}},{"vulnerability":{"id":"CVE-2025-61147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61147","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().","cvss":[],"epss":[{"cve":"CVE-2025-61147","epss":0.00159,"percentile":0.0537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61147","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00795},"relatedVulnerabilities":[{"id":"CVE-2025-61147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61147","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/optionGo/e6567a1c2bc4e0c9fee4e1e8be8d6af9","https://github.com/strukturag/libde265/commit/8b17e0930f77db07f55e0b89399a8f054ddbecf7","https://github.com/strukturag/libde265/issues/484"],"description":"strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61147","epss":0.00159,"percentile":0.0537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61147","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-61147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2025-69646","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69646","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00775},"relatedVulnerabilities":[{"id":"CVE-2025-69646","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69646","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69646","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00775},"relatedVulnerabilities":[{"id":"CVE-2025-69646","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69646","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69646","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00775},"relatedVulnerabilities":[{"id":"CVE-2025-69646","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69646","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69646","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00775},"relatedVulnerabilities":[{"id":"CVE-2025-69646","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69646","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69646","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00775},"relatedVulnerabilities":[{"id":"CVE-2025-69646","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69646","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69646","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00775},"relatedVulnerabilities":[{"id":"CVE-2025-69646","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69646","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69646","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00775},"relatedVulnerabilities":[{"id":"CVE-2025-69646","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69646","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33638","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=598704a00cbac5e85c2bedd363357b5bf6fcee33"],"description":"Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69646","epss":0.00155,"percentile":0.04953,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69646","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69646","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007600000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-69647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007600000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-69647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007600000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-69647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007600000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-69647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007600000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-69647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007600000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-69647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69647","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007600000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-69647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69647","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33640","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69647","epss":0.00152,"percentile":0.04658,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69647","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69647","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-11979","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11979","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.  This issue has been fixed in the commit c2e233fc.  NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.","cvss":[],"epss":[{"cve":"CVE-2026-11979","epss":0.00148,"percentile":0.04362,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11979","cwe":"CWE-121","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007400000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-11979","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11979","namespace":"nvd:cpe","severity":"High","urls":["https://cert.pl/en/posts/2026/06/CVE-2026-11979","https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"],"description":"libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-11979","epss":0.00148,"percentile":0.04362,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-11979","cwe":"CWE-121","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-11979","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dee83f732098ecac","name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["ISC","MIT-1"],"cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6c2b5da962774b6d","name":"libpython3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11:libpython3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"aca024efc3ad8df9","name":"libpython3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_dev:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1fa5bad162623b66","name":"libpython3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f5f8c195b69e3ce5","name":"libpython3.11-stdlib","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a09824e123a98184","name":"python3.11","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"82bac75dbb47c0c3","name":"python3.11-dev","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-dev.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-dev.list"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_dev:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_dev:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-dev@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-12003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.","cvss":[],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-12003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","namespace":"nvd:cpe","severity":"Medium","urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer.","cvss":[{"source":"cna@python.org","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-12003","epss":0.00147,"percentile":0.04282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","source":"cna@python.org","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"cc97519512dedbd9","name":"python3.11-minimal","version":"3.11.2-6+deb12u8","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","upstreams":[{"name":"python3.11"}]}},{"vulnerability":{"id":"CVE-2026-22185","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-22185","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.","cvss":[],"epss":[{"cve":"CVE-2026-22185","epss":0.00147,"percentile":0.04277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-22185","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-22185","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22185","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.openldap.org/show_bug.cgi?id=10421","https://seclists.org/fulldisclosure/2026/Jan/5","https://seclists.org/fulldisclosure/2026/Jan/8","https://www.openldap.org/","https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"],"description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-22185","epss":0.00147,"percentile":0.04277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-22185","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-22185","versionConstraint":"none (unknown)"}}],"artifact":{"id":"692b9197d4b21a92","name":"libldap-2.5-0","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2026-22185","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-22185","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.","cvss":[],"epss":[{"cve":"CVE-2026-22185","epss":0.00147,"percentile":0.04277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-22185","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-22185","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22185","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.openldap.org/show_bug.cgi?id=10421","https://seclists.org/fulldisclosure/2026/Jan/5","https://seclists.org/fulldisclosure/2026/Jan/8","https://www.openldap.org/","https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"],"description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-22185","epss":0.00147,"percentile":0.04277,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","source":"disclosure@vulncheck.com","type":"Secondary"},{"cve":"CVE-2026-22185","cwe":"CWE-191","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-22185","versionConstraint":"none (unknown)"}}],"artifact":{"id":"dd3946a6b1d2298d","name":"libldap-common","version":"2.5.13+dfsg-5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libldap-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-common.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libldap-common.list"}],"language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"cpes":["cpe:2.3:a:libldap-common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_common:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_common:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libldap-common@2.5.13%2Bdfsg-5?arch=all&distro=debian-12.15&upstream=openldap","upstreams":[{"name":"openldap"}]}},{"vulnerability":{"id":"CVE-2026-6845","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6845","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-6845","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6845","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6845","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-6845","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6845","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6845","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-6845","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6845","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6845","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-6845","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6845","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6845","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-6845","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6845","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6845","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-6845","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6845","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6845","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00735},"relatedVulnerabilities":[{"id":"CVE-2026-6845","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6845","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:34924","https://access.redhat.com/errata/RHSA-2026:39022","https://access.redhat.com/security/cve/CVE-2026-6845","https://bugzilla.redhat.com/show_bug.cgi?id=2460012"],"description":"A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6845","epss":0.00147,"percentile":0.04245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6845","cwe":"CWE-476","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6845","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-56392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56392","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.  When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.           This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d","cvss":[],"epss":[{"cve":"CVE-2026-56392","epss":0.00146,"percentile":0.04176,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0073},"relatedVulnerabilities":[{"id":"CVE-2026-56392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56392","epss":0.00146,"percentile":0.04176,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eca37691b87c0860","name":"coreutils","version":"9.1-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-28162","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-28162","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive","cvss":[],"epss":[{"cve":"CVE-2025-28162","epss":0.00144,"percentile":0.04007,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-28162","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.0072},"relatedVulnerabilities":[{"id":"CVE-2025-28162","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-28162","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/kittener/fbfdb9b5610c6b3db0d5dea045a07c60","https://github.com/pnggroup/libpng/issues/656"],"description":"Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-28162","epss":0.00144,"percentile":0.04007,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-28162","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libpng1.6","version":"1.6.39-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-28162","versionConstraint":"none (unknown)"}}],"artifact":{"id":"042787cf6c096741","name":"libpng16-16","version":"1.6.39-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpng16-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"cpes":["cpe:2.3:a:libpng16-16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpng16-16@1.6.39-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=libpng1.6","upstreams":[{"name":"libpng1.6"}]}},{"vulnerability":{"id":"CVE-2025-28164","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-28164","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.","cvss":[],"epss":[{"cve":"CVE-2025-28164","epss":0.00144,"percentile":0.04007,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-28164","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-28164","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0072},"relatedVulnerabilities":[{"id":"CVE-2025-28164","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-28164","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/kittener/506516f8c22178005b4379c8b2a7de20","https://github.com/pnggroup/libpng/issues/655"],"description":"Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-28164","epss":0.00144,"percentile":0.04007,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-28164","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-28164","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libpng1.6","version":"1.6.39-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-28164","versionConstraint":"none (unknown)"}}],"artifact":{"id":"042787cf6c096741","name":"libpng16-16","version":"1.6.39-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpng16-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"cpes":["cpe:2.3:a:libpng16-16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpng16-16@1.6.39-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=libpng1.6","upstreams":[{"name":"libpng1.6"}]}},{"vulnerability":{"id":"CVE-2025-66861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66861","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00715},"relatedVulnerabilities":[{"id":"CVE-2025-66861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-66861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66861","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00715},"relatedVulnerabilities":[{"id":"CVE-2025-66861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66861","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00715},"relatedVulnerabilities":[{"id":"CVE-2025-66861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66861","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00715},"relatedVulnerabilities":[{"id":"CVE-2025-66861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66861","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00715},"relatedVulnerabilities":[{"id":"CVE-2025-66861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66861","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00715},"relatedVulnerabilities":[{"id":"CVE-2025-66861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-66861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66861","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00715},"relatedVulnerabilities":[{"id":"CVE-2025-66861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66861","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/caozhzh/CRGF-Vul/blob/main/cxxfilt/crash1.md"],"description":"An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-66861","epss":0.00143,"percentile":0.03918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-66861","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-66861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-52491","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52491","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component","cvss":[],"epss":[{"cve":"CVE-2026-52491","epss":0.0014,"percentile":0.0371,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52491","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.007000000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-52491","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52491","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/okyfh/5cc53fa67d229017231cf18c91768bd9","https://gitlab.com/libtiff/libtiff/-/commit/9ce4d089bcf25496663776d9e6336738112f09a3"],"description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52491","epss":0.0014,"percentile":0.0371,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52491","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52491","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-56109","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56109","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.","cvss":[],"epss":[{"cve":"CVE-2026-56109","epss":0.00138,"percentile":0.03539,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56109","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0069},"relatedVulnerabilities":[{"id":"CVE-2026-56109","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56109","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0","https://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1","https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/","https://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"],"description":"The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56109","epss":0.00138,"percentile":0.03539,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56109","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"alsa-lib","version":"1.2.8-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56109","versionConstraint":"none (unknown)"}}],"artifact":{"id":"8c2bbfcb9ac36bec","name":"libasound2","version":"1.2.8-1+b1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasound2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libasound2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasound2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libasound2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["LGPL-2.1","LPGL-2.1+"],"cpes":["cpe:2.3:a:libasound2:libasound2:1.2.8-1\\+b1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libasound2@1.2.8-1%2Bb1?arch=amd64&distro=debian-12.15&upstream=alsa-lib%401.2.8-1","upstreams":[{"name":"alsa-lib","version":"1.2.8-1"}]}},{"vulnerability":{"id":"CVE-2026-56109","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56109","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.","cvss":[],"epss":[{"cve":"CVE-2026-56109","epss":0.00138,"percentile":0.03539,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56109","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0069},"relatedVulnerabilities":[{"id":"CVE-2026-56109","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56109","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0","https://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1","https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/","https://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"],"description":"The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.","cvss":[{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"vendorMetadata":{}},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56109","epss":0.00138,"percentile":0.03539,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56109","cwe":"CWE-415","source":"disclosure@vulncheck.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"alsa-lib","version":"1.2.8-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56109","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f9395795765e6df6","name":"libasound2-data","version":"1.2.8-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libasound2-data/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libasound2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasound2-data.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libasound2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasound2-data.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libasound2-data.list"}],"language":"","licenses":["LGPL-2.1","LPGL-2.1+"],"cpes":["cpe:2.3:a:libasound2-data:libasound2-data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2-data:libasound2_data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2_data:libasound2-data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2_data:libasound2_data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2:libasound2-data:1.2.8-1:*:*:*:*:*:*:*","cpe:2.3:a:libasound2:libasound2_data:1.2.8-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libasound2-data@1.2.8-1?arch=all&distro=debian-12.15&upstream=alsa-lib","upstreams":[{"name":"alsa-lib"}]}},{"vulnerability":{"id":"CVE-2026-56391","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56391","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value.  This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.  When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.   This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.","cvss":[],"epss":[{"cve":"CVE-2026-56391","epss":0.00131,"percentile":0.0305,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","source":"cvd@cert.pl","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00655},"relatedVulnerabilities":[{"id":"CVE-2026-56391","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","namespace":"nvd:cpe","severity":"Medium","urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"exploitabilityScore":1.9,"impactScore":4.3},"vendorMetadata":{}},{"source":"cvd@cert.pl","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-56391","epss":0.00131,"percentile":0.0305,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","source":"cvd@cert.pl","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-56391","versionConstraint":"none (unknown)"}}],"artifact":{"id":"eca37691b87c0860","name":"coreutils","version":"9.1-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-61145","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61145","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.","cvss":[],"epss":[{"cve":"CVE-2025-61145","epss":0.00131,"percentile":0.03048,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61145","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61145","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00655},"relatedVulnerabilities":[{"id":"CVE-2025-61145","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61145","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/optionGo/062f109569196dbffd8ac12020b42289","https://gitlab.com/libtiff/libtiff/-/issues/736","https://gitlab.com/libtiff/libtiff/-/merge_requests/753"],"description":"libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61145","epss":0.00131,"percentile":0.03048,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61145","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61145","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-61145","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-52492","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52492","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image","cvss":[],"epss":[{"cve":"CVE-2026-52492","epss":0.0013,"percentile":0.02978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52492","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0065},"relatedVulnerabilities":[{"id":"CVE-2026-52492","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52492","namespace":"nvd:cpe","severity":"High","urls":["https://gist.github.com/okyfh/fbc5a37cade358361d80f6a498560cfa","https://gitlab.com/libtiff/libtiff/-/commit/94affc5cf54111312f9891eb77accb93eebc28d7"],"description":"An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52492","epss":0.0013,"percentile":0.02978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52492","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52492","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2025-69644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69644","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2025-69644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-69644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69644","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2025-69644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69644","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2025-69644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69644","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2025-69644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69644","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2025-69644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69644","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2025-69644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-69644","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69644","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2025-69644","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69644","namespace":"nvd:cpe","severity":"Medium","urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33639","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=455446bbdc8675f34808187de2bbad4682016ff7"],"description":"An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"exploitabilityScore":1.4,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-69644","epss":0.00126,"percentile":0.02608,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-69644","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-69644","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-3713","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3713","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":[],"epss":[{"cve":"CVE-2026-3713","epss":0.00126,"percentile":0.02557,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3713","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-3713","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0063},"relatedVulnerabilities":[{"id":"CVE-2026-3713","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3713","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/biniamf/pocs/tree/main/pnm2png","https://github.com/pnggroup/libpng/","https://github.com/pnggroup/libpng/issues/794","https://vuldb.com/?ctiid.349658","https://vuldb.com/?id.349658","https://vuldb.com/?submit.761996"],"description":"A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"exploitabilityScore":1.9,"impactScore":3.4},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"exploitabilityScore":3.2,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3713","epss":0.00126,"percentile":0.02557,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3713","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-3713","cwe":"CWE-122","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libpng1.6","version":"1.6.39-2+deb12u5"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3713","versionConstraint":"none (unknown)"}}],"artifact":{"id":"042787cf6c096741","name":"libpng16-16","version":"1.6.39-2+deb12u5","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libpng16-16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libpng16-16:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"cpes":["cpe:2.3:a:libpng16-16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16:1.6.39-2\\+deb12u5:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libpng16-16@1.6.39-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=libpng1.6","upstreams":[{"name":"libpng1.6"}]}},{"vulnerability":{"id":"CVE-2026-3949","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3949","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.","cvss":[],"epss":[{"cve":"CVE-2026-3949","epss":0.00117,"percentile":0.01893,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3949","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-3949","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00585},"relatedVulnerabilities":[{"id":"CVE-2026-3949","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3949","namespace":"nvd:cpe","severity":"Low","urls":["https://github.com/biniamf/pocs/tree/main/libheif_vvdec","https://github.com/strukturag/libheif/","https://github.com/strukturag/libheif/commit/b97c8b5f198b27f375127cd597a35f2113544d03","https://github.com/strukturag/libheif/issues/1712","https://github.com/strukturag/libheif/issues/1712#issuecomment-3947938531","https://vuldb.com/?ctiid.350381","https://vuldb.com/?id.350381","https://vuldb.com/?submit.765979"],"description":"A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.","cvss":[{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"cna@vuldb.com","type":"Secondary","version":"2.0","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"exploitabilityScore":3.2,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-3949","epss":0.00117,"percentile":0.01893,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-3949","cwe":"CWE-119","source":"cna@vuldb.com","type":"Secondary"},{"cve":"CVE-2026-3949","cwe":"CWE-125","source":"cna@vuldb.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-3949","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-19548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19548","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:  1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging  The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.  An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.  The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2026-19548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-19548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19548","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:  1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging  The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.  An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.  The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2026-19548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-19548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19548","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:  1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging  The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.  An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.  The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2026-19548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-19548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19548","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:  1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging  The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.  An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.  The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2026-19548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-19548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19548","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:  1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging  The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.  An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.  The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2026-19548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-19548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19548","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:  1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging  The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.  An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.  The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2026-19548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-19548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19548","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:  1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging  The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.  An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.  The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2026-19548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19548","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19548","https://bugzilla.redhat.com/show_bug.cgi?id=2507832"],"description":"Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:\n\n1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)\n2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call\n3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging\n\nThe vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.\n\nAn attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.\n\nThe attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19548","epss":0.00116,"percentile":0.01818,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19548","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19548","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2025-14017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14017","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers.  Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.","cvss":[],"epss":[{"cve":"CVE-2025-14017","epss":0.00116,"percentile":0.01793,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2025-14017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14017","epss":0.00116,"percentile":0.01793,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ec8eb39ce089dc08","name":"curl","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/curl.list"}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2025-14017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14017","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers.  Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.","cvss":[],"epss":[{"cve":"CVE-2025-14017","epss":0.00116,"percentile":0.01793,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2025-14017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14017","epss":0.00116,"percentile":0.01793,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f49af56f3a8f57c1","name":"libcurl3-gnutls","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-14017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14017","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers.  Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.","cvss":[],"epss":[{"cve":"CVE-2025-14017","epss":0.00116,"percentile":0.01793,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0058},"relatedVulnerabilities":[{"id":"CVE-2025-14017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","namespace":"nvd:cpe","severity":"Medium","urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-14017","epss":0.00116,"percentile":0.01793,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-14017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"a6e2427d3e834f56","name":"libcurl4","version":"7.88.1-10+deb12u15","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","upstreams":[{"name":"curl"}]}},{"vulnerability":{"id":"CVE-2025-61143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61143","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.","cvss":[],"epss":[{"cve":"CVE-2025-61143","epss":0.00113,"percentile":0.01578,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61143","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61143","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00565},"relatedVulnerabilities":[{"id":"CVE-2025-61143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61143","namespace":"nvd:cpe","severity":"Medium","urls":["https://gist.github.com/optionGo/9c024cd8e7b131463b84dc60af9bb0aa","https://gitlab.com/libtiff/libtiff/-/issues/737","https://gitlab.com/libtiff/libtiff/-/merge_requests/755"],"description":"libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61143","epss":0.00113,"percentile":0.01578,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-61143","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-61143","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-61143","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-15003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2026-15003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"exploitabilityScore":1.4,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-15003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2026-15003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"exploitabilityScore":1.4,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-15003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2026-15003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"exploitabilityScore":1.4,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-15003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2026-15003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"exploitabilityScore":1.4,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-15003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2026-15003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"exploitabilityScore":1.4,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-15003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2026-15003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"exploitabilityScore":1.4,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-15003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15003","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0053},"relatedVulnerabilities":[{"id":"CVE-2026-15003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15003","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2026:47171","https://access.redhat.com/security/cve/CVE-2026-15003","https://bugzilla.redhat.com/show_bug.cgi?id=2497805","https://sourceware.org/bugzilla/show_bug.cgi?id=34053"],"description":"A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"exploitabilityScore":1.4,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15003","epss":0.00106,"percentile":0.0121,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-15003","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-15003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-19617","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19617","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.","cvss":[],"epss":[{"cve":"CVE-2026-19617","epss":0.00105,"percentile":0.0118,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19617","cwe":"CWE-770","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00525},"relatedVulnerabilities":[{"id":"CVE-2026-19617","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19617","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19617","https://bugzilla.redhat.com/show_bug.cgi?id=2514626"],"description":"A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19617","epss":0.00105,"percentile":0.0118,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19617","cwe":"CWE-770","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"lvm2","version":"2.03.16-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19617","versionConstraint":"none (unknown)"}}],"artifact":{"id":"bc637791db1d1ef3","name":"dmsetup","version":"2:1.02.185-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dmsetup/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/dmsetup/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dmsetup.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dmsetup.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dmsetup.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dmsetup.list"},{"path":"/var/lib/dpkg/info/dmsetup.postinst","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dmsetup.postinst"},{"path":"/var/lib/dpkg/info/dmsetup.triggers","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/dmsetup.triggers"}],"language":"","licenses":["BSD-2-Clause","GPL-2","GPL-2.0","GPL-2.0+","LGPL-2","LGPL-2.1"],"cpes":["cpe:2.3:a:dmsetup:dmsetup:2\\:1.02.185-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/dmsetup@2%3A1.02.185-2?arch=amd64&distro=debian-12.15&upstream=lvm2%402.03.16-2","upstreams":[{"name":"lvm2","version":"2.03.16-2"}]}},{"vulnerability":{"id":"CVE-2026-19617","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19617","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.","cvss":[],"epss":[{"cve":"CVE-2026-19617","epss":0.00105,"percentile":0.0118,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19617","cwe":"CWE-770","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.00525},"relatedVulnerabilities":[{"id":"CVE-2026-19617","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19617","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-19617","https://bugzilla.redhat.com/show_bug.cgi?id=2514626"],"description":"A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-19617","epss":0.00105,"percentile":0.0118,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-19617","cwe":"CWE-770","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"lvm2","version":"2.03.16-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19617","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d79caa349ecf8d26","name":"libdevmapper1.02.1","version":"2:1.02.185-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libdevmapper1.02.1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libdevmapper1.02.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libdevmapper1.02.1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libdevmapper1.02.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","GPL-2","GPL-2.0","GPL-2.0+","LGPL-2","LGPL-2.1"],"cpes":["cpe:2.3:a:libdevmapper1.02.1:libdevmapper1.02.1:2\\:1.02.185-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libdevmapper1.02.1@2%3A1.02.185-2?arch=amd64&distro=debian-12.15&upstream=lvm2%402.03.16-2","upstreams":[{"name":"lvm2","version":"2.03.16-2"}]}},{"vulnerability":{"id":"CVE-2026-6844","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6844","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0052},"relatedVulnerabilities":[{"id":"CVE-2026-6844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"}}],"artifact":{"id":"142b9fb5725bdc5a","name":"binutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils:binutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils@2.40-2?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-6844","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6844","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0052},"relatedVulnerabilities":[{"id":"CVE-2026-6844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2224ebf13f7b34f5","name":"binutils-common","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-common@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6844","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6844","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0052},"relatedVulnerabilities":[{"id":"CVE-2026-6844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7da2d1209865fe04","name":"binutils-x86-64-linux-gnu","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6844","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6844","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0052},"relatedVulnerabilities":[{"id":"CVE-2026-6844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"}}],"artifact":{"id":"1bf658472b38bf7b","name":"libbinutils","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libbinutils:libbinutils:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libbinutils@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6844","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6844","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0052},"relatedVulnerabilities":[{"id":"CVE-2026-6844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"}}],"artifact":{"id":"882c1aa85bf92608","name":"libctf-nobfd0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.40-2:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf-nobfd0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6844","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6844","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0052},"relatedVulnerabilities":[{"id":"CVE-2026-6844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f893e5b0c4f34ee1","name":"libctf0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libctf0:libctf0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libctf0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"CVE-2026-6844","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6844","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0052},"relatedVulnerabilities":[{"id":"CVE-2026-6844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6844","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-6844","https://bugzilla.redhat.com/show_bug.cgi?id=2460016"],"description":"A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the `readelf` utility becoming unresponsive or crashing, leading to a denial of service.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-6844","epss":0.00104,"percentile":0.01117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-6844","cwe":"CWE-400","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"binutils","version":"2.40-2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-6844","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7d90fc4b240ace2b","name":"libgprofng0","version":"2.40-2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:a81bdd422c2c015deca84bf6ad249bf0d7d19885fc01d1894463291b0b7313e1"],"cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.40-2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgprofng0@2.40-2?arch=amd64&distro=debian-12.15&upstream=binutils","upstreams":[{"name":"binutils"}]}},{"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","namespace":"github:language:java","severity":"High","urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8"],"description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-07-22","kind":"first-observed"}]},"advisories":[],"risk":0},"relatedVulnerabilities":[],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.19.1"}},"found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"525302ab25309ad8","name":"jackson-core","version":"2.19.1","type":"java-archive","locations":[{"path":"/zap/plugin/database-alpha-0.9.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-core-2.19.1.jar","annotations":{"evidence":"primary"}}],"language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.19.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.19.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.19.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/database-alpha-0.9.0.zap:libs/jackson-core-2.19.1.jar","pomArtifactID":"jackson-core","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":[{"algorithm":"sha1","value":"6e5a8cb8a6cada322497cefb7726657d98aaee15"}]}}},{"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","namespace":"github:language:java","severity":"High","urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8"],"description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)","cvss":[{"type":"Secondary","version":"4.0","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"vendorMetadata":{}}],"fix":{"versions":["2.21.4"],"state":"fixed","available":[{"version":"2.21.4","date":"2026-07-22","kind":"first-observed"}]},"advisories":[],"risk":0},"relatedVulnerabilities":[],"matchDetails":[{"type":"exact-direct-match","matcher":"java-matcher","searchedBy":{"language":"java","namespace":"github:language:java","package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.20.1"}},"found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"fix":{"suggestedVersion":"2.21.4"}}],"artifact":{"id":"aea317631b68845c","name":"jackson-core","version":"2.20.1","type":"java-archive","locations":[{"path":"/zap/plugin/commonlib-release-1.39.0.zap","layerID":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","accessPath":"/zap/plugin/commonlib-release-1.39.0.zap","annotations":{"evidence":"primary"}}],"language":"java","licenses":["The Apache Software License, Version 2.0"],"cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.20.1:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.20.1:*:*:*:*:*:*:*"],"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.20.1","upstreams":[],"metadataType":"JavaMetadata","metadata":{"virtualPath":"/zap/plugin/commonlib-release-1.39.0.zap:com.fasterxml.jackson.core:jackson-core","pomArtifactID":"jackson-core","pomGroupID":"com.fasterxml.jackson.core","manifestName":"","archiveDigests":null}}},{"vulnerability":{"id":"CVE-2026-87875","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87875","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87875","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-87875","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87875","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2026-87875","https://bugzilla.redhat.com/show_bug.cgi?id=2530994","https://github.com/OpenPrinting/cups/commit/0c6842fc615e8afa284136a092da8178abf5f142","https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4","https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq"],"description":"The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":2.9,"impactScore":1.5},"vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87875","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-87875","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2026-87876","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87876","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3,"exploitabilityScore":1.6,"impactScore":1.5},"vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87876","cwe":"CWE-178","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-87876","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87876","namespace":"nvd:cpe","severity":"Low","urls":["https://access.redhat.com/security/cve/CVE-2026-87876","https://bugzilla.redhat.com/show_bug.cgi?id=2530991","https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","https://github.com/OpenPrinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2"],"description":"Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.","cvss":[{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3,"exploitabilityScore":1.6,"impactScore":1.5},"vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87876","cwe":"CWE-178","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cups","version":"2.4.2-3+deb12u9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-87876","versionConstraint":"none (unknown)"}}],"artifact":{"id":"11d4c439dfa80a79","name":"libcups2","version":"2.4.2-3+deb12u9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libcups2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libcups2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"cpes":["cpe:2.3:a:libcups2:libcups2:2.4.2-3\\+deb12u9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libcups2@2.4.2-3%2Bdeb12u9?arch=amd64&distro=debian-12.15&upstream=cups","upstreams":[{"name":"cups"}]}},{"vulnerability":{"id":"CVE-2026-44950","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-44950","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-44950","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxfont","version":"1:2.0.6-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-44950","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7bc4b5cfb578d49a","name":"libxfont2","version":"1:2.0.6-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxfont2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxfont2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxfont2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxfont2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","BSD-4-Clause-UC","HPND","HPND-sell-variant","MIT"],"cpes":["cpe:2.3:a:libxfont2:libxfont2:1\\:2.0.6-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxfont2@1%3A2.0.6-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libxfont","upstreams":[{"name":"libxfont"}]}},{"vulnerability":{"id":"CVE-2026-59679","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59679","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-59679","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxfont","version":"1:2.0.6-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-59679","versionConstraint":"none (unknown)"}}],"artifact":{"id":"7bc4b5cfb578d49a","name":"libxfont2","version":"1:2.0.6-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxfont2/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libxfont2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxfont2:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libxfont2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-Clause","BSD-4-Clause-UC","HPND","HPND-sell-variant","MIT"],"cpes":["cpe:2.3:a:libxfont2:libxfont2:1\\:2.0.6-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libxfont2@1%3A2.0.6-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libxfont","upstreams":[{"name":"libxfont"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"f131145b816a43ee","name":"bsdutils","version":"1:2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"af35543f081d70bf","name":"libblkid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-19499","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19499","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19542","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19542","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-77117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-77117","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-80489","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80489","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"}}],"artifact":{"id":"0d487d9c5e9a860d","name":"libc-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19499","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19499","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19542","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19542","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-77117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-77117","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-80489","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80489","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"}}],"artifact":{"id":"05457b2d3472913c","name":"libc-dev-bin","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-dev-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19499","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19499","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19542","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19542","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-77117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-77117","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-80489","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80489","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"}}],"artifact":{"id":"548399149a687c60","name":"libc-devtools","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-devtools/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc-devtools/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-devtools.list","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc-devtools.list"}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc-devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_devtools:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_devtools:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc-devtools@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19499","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19499","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19542","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19542","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-77117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-77117","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-80489","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80489","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3d449c1cd40f62d0","name":"libc6","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19499","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19499","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-19542","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-19542","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-77117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-77117","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-80489","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80489","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"}}],"artifact":{"id":"be9fcdc16d52ab8f","name":"libc6-dev","version":"2.36-9+deb12u14","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libc6-dev@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","upstreams":[{"name":"glibc"}]}},{"vulnerability":{"id":"CVE-2026-54240","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54240","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-54240","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54240","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-54241","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54241","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-54241","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libde265","version":"1.0.11-1+deb12u2"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-54241","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e9e852b82b9bceda","name":"libde265-0","version":"1.0.11-1+deb12u2","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.11-1\\+deb12u2:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libde265-0@1.0.11-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=libde265","upstreams":[{"name":"libde265"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"c307e94620069e41","name":"libfdisk1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfdisk1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libfdisk1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libfdisk1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libfdisk1:libfdisk1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libfdisk1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-9672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9672","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":["2.3.3-9+deb12u1"],"state":"fixed","available":[{"version":"2.3.3-9+deb12u1","date":"2026-08-12","kind":"first-observed"}]},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-9672","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libgd2","version":"2.3.3-9"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-9672","versionConstraint":"< 2.3.3-9+deb12u1 (deb)"},"fix":{"suggestedVersion":"2.3.3-9+deb12u1"}}],"artifact":{"id":"b759e41eec98bfa7","name":"libgd3","version":"2.3.3-9","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgd3/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libgd3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgd3:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libgd3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["sha256:53c9aa3ebfa5ab3aa28a5467aca74c10446b2e7ed21d68bdc8cc372f32d551ee"],"cpes":["cpe:2.3:a:libgd3:libgd3:2.3.3-9:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libgd3@2.3.3-9?arch=amd64&distro=debian-12.15&upstream=libgd2","upstreams":[{"name":"libgd2"}]}},{"vulnerability":{"id":"CVE-2026-84450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84450","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-84450","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84450","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-84451","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84451","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-84451","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libheif","version":"1.15.1-1+deb12u1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-84451","versionConstraint":"none (unknown)"}}],"artifact":{"id":"6dec48f68a6dce02","name":"libheif1","version":"1.15.1-1+deb12u1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libheif1/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libheif1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libheif1:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libheif1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BOOST-1.0","BSD-3-clause","BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","MIT"],"cpes":["cpe:2.3:a:libheif1:libheif1:1.15.1-1\\+deb12u1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libheif1@1.15.1-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libheif","upstreams":[{"name":"libheif"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"3578a81ebb651f3d","name":"libmount1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"ecee94562f1ce06f","name":"libsmartcols1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-36849","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-36849","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-36849","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tiff","version":"4.5.0-6+deb12u4"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-36849","versionConstraint":"none (unknown)"}}],"artifact":{"id":"d41dc3f05b6fab73","name":"libtiff6","version":"4.5.0-6+deb12u4","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["Hylafax"],"cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.0-6\\+deb12u4:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libtiff6@4.5.0-6%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=tiff","upstreams":[{"name":"tiff"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2049f4c13963925a","name":"libuuid1","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"e75e0a2b6968d414","name":"mount","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/mount.list"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-direct-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"b11f4a313957922c","name":"util-linux","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","upstreams":[]}},{"vulnerability":{"id":"CVE-2026-53613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53613","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}},{"vulnerability":{"id":"CVE-2026-53615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-53615","dataSource":"nvd","namespace":"nvd:cpe","severity":"Unknown","urls":[],"cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"fc9180bcad1f4d49","name":"util-linux-extra","version":"2.38.1-5+deb12u3","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","upstreams":[{"name":"util-linux"}]}}],"ignoredMatches":[{"vulnerability":{"id":"CVE-2004-0230","dataSource":"https://security-tracker.debian.org/tracker/CVE-2004-0230","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.","cvss":[],"epss":[{"cve":"CVE-2004-0230","epss":0.80286,"percentile":0.99594,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2004-0230","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":4.0143},"relatedVulnerabilities":[{"id":"CVE-2004-0230","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2004-0230","namespace":"nvd:cpe","severity":"Medium","urls":["ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc","ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt","ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt","ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt","ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc","http://kb.juniper.net/JSA10638","http://marc.info/?l=bugtraq&m=108302060014745&w=2","http://marc.info/?l=bugtraq&m=108506952116653&w=2","http://secunia.com/advisories/11440","http://secunia.com/advisories/11458","http://secunia.com/advisories/22341","http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml","http://www.kb.cert.org/vuls/id/415294","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.osvdb.org/4030","http://www.securityfocus.com/archive/1/449179/100/0/threaded","http://www.securityfocus.com/bid/10183","http://www.uniras.gov.uk/vuls/2004/236929/index.htm","http://www.us-cert.gov/cas/techalerts/TA04-111A.html","http://www.vupen.com/english/advisories/2006/3983","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-019","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-064","https://exchange.xforce.ibmcloud.com/vulnerabilities/15886","https://kc.mcafee.com/corporate/index?page=content&id=SB10053","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2689","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A270","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3508","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4791","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5711"],"description":"TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2004-0230","epss":0.80286,"percentile":0.99594,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2004-0230","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2004-0230","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2005-3660","dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-3660","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and setting a large data transfer buffer, then preventing Linux from being able to finish the transfer by causing the process to become a zombie, or closing the file descriptor without closing an associated reference.","cvss":[],"epss":[{"cve":"CVE-2005-3660","epss":0.00402,"percentile":0.33634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2005-3660","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0201},"relatedVulnerabilities":[{"id":"CVE-2005-3660","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-3660","namespace":"nvd:cpe","severity":"Medium","urls":["http://secunia.com/advisories/18205","http://securityreason.com/securityalert/291","http://securitytracker.com/id?1015402","http://www.idefense.com/intelligence/vulnerabilities/display.php?id=362","http://www.securityfocus.com/bid/16041","http://www.vupen.com/english/advisories/2005/3076","https://exchange.xforce.ibmcloud.com/vulnerabilities/23835"],"description":"Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and setting a large data transfer buffer, then preventing Linux from being able to finish the transfer by causing the process to become a zombie, or closing the file descriptor without closing an associated reference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2005-3660","epss":0.00402,"percentile":0.33634,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2005-3660","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2005-3660","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2007-3719","dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-3719","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The process scheduler in the Linux kernel 2.6.16 gives preference to \"interactive\" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"","cvss":[],"epss":[{"cve":"CVE-2007-3719","epss":0.00313,"percentile":0.23998,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-3719","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01565},"relatedVulnerabilities":[{"id":"CVE-2007-3719","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3719","namespace":"nvd:cpe","severity":"Low","urls":["http://osvdb.org/37127","http://www.cs.huji.ac.il/~dants/papers/Cheat07Security.pdf"],"description":"The process scheduler in the Linux kernel 2.6.16 gives preference to \"interactive\" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in \"Secretly Monopolizing the CPU Without Superuser Privileges.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2007-3719","epss":0.00313,"percentile":0.23998,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2007-3719","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2007-3719","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2008-2544","dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-2544","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.","cvss":[],"epss":[{"cve":"CVE-2008-2544","epss":0.00306,"percentile":0.23097,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2008-2544","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.015300000000000001},"relatedVulnerabilities":[{"id":"CVE-2008-2544","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-2544","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=213135"],"description":"Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2008-2544","epss":0.00306,"percentile":0.23097,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2008-2544","cwe":"CWE-668","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2008-2544","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2008-4609","dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-4609","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.","cvss":[],"epss":[{"cve":"CVE-2008-4609","epss":0.32123,"percentile":0.98208,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2008-4609","cwe":"CWE-16","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":1.6061500000000002},"relatedVulnerabilities":[{"id":"CVE-2008-4609","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-4609","namespace":"nvd:cpe","severity":"High","urls":["http://blog.robertlee.name/2008/10/conjecture-speculation.html","http://insecure.org/stf/tcp-dos-attack-explained.html","http://lists.immunitysec.com/pipermail/dailydave/2008-October/005360.html","http://marc.info/?l=bugtraq&m=125856010926699&w=2","http://searchsecurity.techtarget.com.au/articles/27154-TCP-is-fundamentally-borked","http://www.cisco.com/en/US/products/products_security_advisory09186a0080af511d.shtml","http://www.cisco.com/en/US/products/products_security_response09186a0080a15120.html","http://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdf","http://www.mandriva.com/security/advisories?name=MDVSA-2013:150","http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html","http://www.outpost24.com/news/news-2008-10-02.html","http://www.us-cert.gov/cas/techalerts/TA09-251A.html","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-048","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6340","https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html"],"description":"The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"exploitabilityScore":8.6,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2008-4609","epss":0.32123,"percentile":0.98208,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2008-4609","cwe":"CWE-16","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2008-4609","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2010-4563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4563","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping.","cvss":[],"epss":[{"cve":"CVE-2010-4563","epss":0.03002,"percentile":0.86571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4563","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1501},"relatedVulnerabilities":[{"id":"CVE-2010-4563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4563","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/dailydave/2011/q2/25","http://seclists.org/fulldisclosure/2011/Apr/254"],"description":"The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"exploitabilityScore":10,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-4563","epss":0.03002,"percentile":0.86571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-4563","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2010-4563","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2010-5321","dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-5321","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6.x through 4.x allows local users to cause a denial of service (memory consumption) by leveraging /dev/video access for a series of mmap calls that require new allocations, a different vulnerability than CVE-2007-6761.  NOTE: as of 2016-06-18, this affects only 11 drivers that have not been updated to use videobuf2 instead of videobuf.","cvss":[],"epss":[{"cve":"CVE-2010-5321","epss":0.00401,"percentile":0.33602,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-5321","cwe":"CWE-772","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02005},"relatedVulnerabilities":[{"id":"CVE-2010-5321","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-5321","namespace":"nvd:cpe","severity":"Medium","urls":["http://linuxtv.org/irc/v4l/index.php?date=2010-07-29","http://www.openwall.com/lists/oss-security/2015/02/08/4","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827340","https://bugzilla.kernel.org/show_bug.cgi?id=120571","https://bugzilla.redhat.com/show_bug.cgi?id=620629"],"description":"Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6.x through 4.x allows local users to cause a denial of service (memory consumption) by leveraging /dev/video access for a series of mmap calls that require new allocations, a different vulnerability than CVE-2007-6761.  NOTE: as of 2016-06-18, this affects only 11 drivers that have not been updated to use videobuf2 instead of videobuf.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.3,"exploitabilityScore":0.7,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2010-5321","epss":0.00401,"percentile":0.33602,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2010-5321","cwe":"CWE-772","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2010-5321","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2011-4915","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4915","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.","cvss":[],"epss":[{"cve":"CVE-2011-4915","epss":0.00513,"percentile":0.42037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4915","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02565},"relatedVulnerabilities":[{"id":"CVE-2011-4915","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4915","namespace":"nvd:cpe","severity":"Medium","urls":["http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0499680a42141d86417a8fbaa8c8db806bea1201","http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a2ef990ab5a6705a356d146dd773a3b359787497","http://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-4915.html","http://www.openwall.com/lists/oss-security/2011/11/07/9","https://lkml.org/lkml/2011/11/7/340","https://seclists.org/oss-sec/2011/q4/571","https://security-tracker.debian.org/tracker/CVE-2011-4915","https://vigilance.fr/vulnerability/Linux-kernel-information-disclosure-about-keyboard-11131"],"description":"fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-4915","epss":0.00513,"percentile":0.42037,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4915","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-4915","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2011-4916","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4916","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.","cvss":[],"epss":[{"cve":"CVE-2011-4916","epss":0.00412,"percentile":0.34609,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4916","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2011-4916","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0206},"relatedVulnerabilities":[{"id":"CVE-2011-4916","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4916","namespace":"nvd:cpe","severity":"Medium","urls":["https://lkml.org/lkml/2011/11/7/355","https://www.openwall.com/lists/oss-security/2011/12/28/3"],"description":"Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-4916","epss":0.00412,"percentile":0.34609,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4916","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2011-4916","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-4916","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2011-4917","dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4917","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.","cvss":[],"epss":[{"cve":"CVE-2011-4917","epss":0.00483,"percentile":0.40077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4917","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02415},"relatedVulnerabilities":[{"id":"CVE-2011-4917","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4917","namespace":"nvd:cpe","severity":"Medium","urls":["https://lkml.org/lkml/2011/11/7/340","https://www.openwall.com/lists/oss-security/2011/12/28/4"],"description":"In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-4917","epss":0.00483,"percentile":0.40077,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2011-4917","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2011-4917","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2012-4542","dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-4542","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.","cvss":[],"epss":[{"cve":"CVE-2012-4542","epss":0.00349,"percentile":0.2809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2012-4542","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01745},"relatedVulnerabilities":[{"id":"CVE-2012-4542","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-4542","namespace":"nvd:cpe","severity":"Medium","urls":["http://marc.info/?l=linux-kernel&m=135903967015813&w=2","http://marc.info/?l=linux-kernel&m=135904012416042&w=2","http://rhn.redhat.com/errata/RHSA-2013-0496.html","http://rhn.redhat.com/errata/RHSA-2013-0579.html","http://rhn.redhat.com/errata/RHSA-2013-0882.html","http://rhn.redhat.com/errata/RHSA-2013-0928.html","https://bugzilla.redhat.com/show_bug.cgi?id=875360","https://oss.oracle.com/git/?p=redpatch.git%3Ba=commit%3Bh=76a274e17114abf1a77de6b651424648ce9e10c8"],"description":"block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-4542","epss":0.00349,"percentile":0.2809,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2012-4542","cwe":"CWE-264","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2012-4542","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2013-7445","dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-7445","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"exploitabilityScore":10,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-7445","epss":0.02728,"percentile":0.85195,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-7445","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":2.08692},"relatedVulnerabilities":[{"id":"CVE-2013-7445","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-7445","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.kernel.org/show_bug.cgi?id=60533"],"description":"The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"exploitabilityScore":10,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2013-7445","epss":0.02728,"percentile":0.85195,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2013-7445","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2013-7445","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2014-9892","dataSource":"https://security-tracker.debian.org/tracker/CVE-2014-9892","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28770164 and Qualcomm internal bug CR568717.","cvss":[],"epss":[{"cve":"CVE-2014-9892","epss":0.00499,"percentile":0.41155,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2014-9892","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02495},"relatedVulnerabilities":[{"id":"CVE-2014-9892","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9892","namespace":"nvd:cpe","severity":"Medium","urls":["http://source.android.com/security/bulletin/2016-08-01.html","http://www.securityfocus.com/bid/92222","https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=591b1f455c32206704cbcf426bb30911c260c33e"],"description":"The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28770164 and Qualcomm internal bug CR568717.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2014-9892","epss":0.00499,"percentile":0.41155,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2014-9892","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2014-9892","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2014-9900","dataSource":"https://security-tracker.debian.org/tracker/CVE-2014-9900","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.","cvss":[],"epss":[{"cve":"CVE-2014-9900","epss":0.00519,"percentile":0.42448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2014-9900","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02595},"relatedVulnerabilities":[{"id":"CVE-2014-9900","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9900","namespace":"nvd:cpe","severity":"Medium","urls":["http://source.android.com/security/bulletin/2016-08-01.html","http://www.securityfocus.com/bid/92222","https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=63c317dbee97983004dffdd9f742a20d17150071"],"description":"The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2014-9900","epss":0.00519,"percentile":0.42448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2014-9900","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2014-9900","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2015-2877","dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-2877","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack.  NOTE: the vendor states \"Basically if you care about this attack vector, disable deduplication.\" Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities","cvss":[],"epss":[{"cve":"CVE-2015-2877","epss":0.00942,"percentile":0.5889,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2015-2877","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0471},"relatedVulnerabilities":[{"id":"CVE-2015-2877","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-2877","namespace":"nvd:cpe","severity":"Low","urls":["http://www.antoniobarresi.com/files/cain_advisory.txt","http://www.kb.cert.org/vuls/id/935424","http://www.securityfocus.com/bid/76256","https://bugzilla.redhat.com/show_bug.cgi?id=1252096","https://www.kb.cert.org/vuls/id/BGAR-A2CNKG","https://www.kb.cert.org/vuls/id/BLUU-9ZAHZH","https://www.usenix.org/system/files/conference/woot15/woot15-paper-barresi.pdf"],"description":"Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack.  NOTE: the vendor states \"Basically if you care about this attack vector, disable deduplication.\" Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-2877","epss":0.00942,"percentile":0.5889,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2015-2877","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2015-2877","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2016-10723","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-10723","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that \"the underlying problem is non-trivial to handle.","cvss":[],"epss":[{"cve":"CVE-2016-10723","epss":0.00378,"percentile":0.31144,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-10723","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0189},"relatedVulnerabilities":[{"id":"CVE-2016-10723","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-10723","namespace":"nvd:cpe","severity":"Medium","urls":["https://patchwork.kernel.org/patch/10395909/","https://patchwork.kernel.org/patch/9842889/","https://www.spinics.net/lists/linux-mm/msg117896.html"],"description":"An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that \"the underlying problem is non-trivial to handle.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-10723","epss":0.00378,"percentile":0.31144,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-10723","cwe":"CWE-399","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-10723","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2016-8660","dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-8660","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a \"page lock order bug in the XFS seek hole/data implementation.\"","cvss":[],"epss":[{"cve":"CVE-2016-8660","epss":0.00339,"percentile":0.26911,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-8660","cwe":"CWE-19","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01695},"relatedVulnerabilities":[{"id":"CVE-2016-8660","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-8660","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2016/10/13/8","http://www.securityfocus.com/bid/93558","https://bugzilla.redhat.com/show_bug.cgi?id=1384851"],"description":"The XFS subsystem in the Linux kernel through 4.8.2 allows local users to cause a denial of service (fdatasync failure and system hang) by using the vfs syscall group in the trinity program, related to a \"page lock order bug in the XFS seek hole/data implementation.\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2016-8660","epss":0.00339,"percentile":0.26911,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2016-8660","cwe":"CWE-19","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2016-8660","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2017-0630","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-0630","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.","cvss":[],"epss":[{"cve":"CVE-2017-0630","epss":0.01444,"percentile":0.71665,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-0630","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0722},"relatedVulnerabilities":[{"id":"CVE-2017-0630","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-0630","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/98213","https://source.android.com/security/bulletin/2017-05-01"],"description":"An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.6,"exploitabilityScore":5,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-0630","epss":0.01444,"percentile":0.71665,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-0630","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-0630","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2017-13693","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13693","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.","cvss":[],"epss":[{"cve":"CVE-2017-13693","epss":0.00443,"percentile":0.37324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13693","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.022150000000000003},"relatedVulnerabilities":[{"id":"CVE-2017-13693","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13693","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/100502","https://github.com/acpica/acpica/pull/295","https://github.com/acpica/acpica/pull/295/commits/987a3b5cf7175916e2a4b6ea5b8e70f830dfe732","https://patchwork.kernel.org/patch/9919053/"],"description":"The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13693","epss":0.00443,"percentile":0.37324,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13693","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13693","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2017-13694","dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-13694","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.","cvss":[],"epss":[{"cve":"CVE-2017-13694","epss":0.00408,"percentile":0.34232,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13694","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0204},"relatedVulnerabilities":[{"id":"CVE-2017-13694","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-13694","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/100500","https://github.com/acpica/acpica/pull/278","https://github.com/acpica/acpica/pull/278/commits/4a0243ecb4c94e2d73510d096c5ea4d0711fc6c0","https://patchwork.kernel.org/patch/9806085/"],"description":"The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2017-13694","epss":0.00408,"percentile":0.34232,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2017-13694","cwe":"CWE-200","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2017-13694","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2018-1121","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-1121","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.","cvss":[],"epss":[{"cve":"CVE-2018-1121","epss":0.04189,"percentile":0.90325,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-1121","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2018-1121","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.20945},"relatedVulnerabilities":[{"id":"CVE-2018-1121","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1121","namespace":"nvd:cpe","severity":"Medium","urls":["http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1121","https://www.exploit-db.com/exploits/44806/","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"description":"procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"exploitabilityScore":8.6,"impactScore":2.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"exploitabilityScore":1.4,"impactScore":2.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-1121","epss":0.04189,"percentile":0.90325,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-1121","cwe":"CWE-367","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2018-1121","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-1121","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2018-12928","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-12928","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.","cvss":[],"epss":[{"cve":"CVE-2018-12928","epss":0.00427,"percentile":0.36007,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-12928","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.1281},"relatedVulnerabilities":[{"id":"CVE-2018-12928","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-12928","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/104593","https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763384","https://marc.info/?l=linux-fsdevel&m=152407263325766&w=2"],"description":"In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-12928","epss":0.00427,"percentile":0.36007,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-12928","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-12928","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2018-17977","dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-17977","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.","cvss":[],"epss":[{"cve":"CVE-2018-17977","epss":0.00379,"percentile":0.31253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-17977","cwe":"CWE-400","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01895},"relatedVulnerabilities":[{"id":"CVE-2018-17977","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-17977","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/105539","https://www.openwall.com/lists/oss-security/2018/10/05/5"],"description":"The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-17977","epss":0.00379,"percentile":0.31253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2018-17977","cwe":"CWE-400","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2018-17977","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-11191","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-11191","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat. NOTE: the software maintainer disputes that this is a vulnerability because ASLR for a.out format executables has never been supported","cvss":[],"epss":[{"cve":"CVE-2019-11191","epss":0.00499,"percentile":0.41166,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-11191","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.02495},"relatedVulnerabilities":[{"id":"CVE-2019-11191","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-11191","namespace":"nvd:cpe","severity":"Low","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html","http://www.openwall.com/lists/oss-security/2019/04/18/5","http://www.openwall.com/lists/oss-security/2019/05/22/7","http://www.securityfocus.com/bid/107887","https://usn.ubuntu.com/4006-1/","https://usn.ubuntu.com/4006-2/","https://usn.ubuntu.com/4007-1/","https://usn.ubuntu.com/4007-2/","https://usn.ubuntu.com/4008-1/","https://usn.ubuntu.com/4008-3/","https://www.openwall.com/lists/oss-security/2019/04/03/4","https://www.openwall.com/lists/oss-security/2019/04/03/4/1"],"description":"The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat. NOTE: the software maintainer disputes that this is a vulnerability because ASLR for a.out format executables has never been supported","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"exploitabilityScore":1.1,"impactScore":1.5},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":3.4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-11191","epss":0.00499,"percentile":0.41166,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-11191","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-11191","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-12378","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-12378","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This has been disputed as not an issue","cvss":[],"epss":[{"cve":"CVE-2019-12378","epss":0.00446,"percentile":0.37607,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12378","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.022300000000000004},"relatedVulnerabilities":[{"id":"CVE-2019-12378","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12378","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/108475","https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=95baa60a0da80a0143e3ddd4d3725758b4513825","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLGWJKLMTBBB53D5QLS4HOY2EH246WBE/","https://lkml.org/lkml/2019/5/25/229"],"description":"An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This has been disputed as not an issue","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-12378","epss":0.00446,"percentile":0.37607,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12378","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-12378","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-12379","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-12379","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in con_insert_unipair in drivers/tty/vt/consolemap.c in the Linux kernel through 5.1.5. There is a memory leak in a certain case of an ENOMEM outcome of kmalloc. NOTE: This id is disputed as not being an issue","cvss":[],"epss":[{"cve":"CVE-2019-12379","epss":0.00445,"percentile":0.37539,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12379","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.022250000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-12379","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12379","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/108478","https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty.git/commit/?h=tty-next&id=84ecc2f6eb1cb12e6d44818f94fa49b50f06e6ac","https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/tty.git/commit/?h=tty-testing&id=15b3cd8ef46ad1b100e0d3c7e38774f330726820","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLGWJKLMTBBB53D5QLS4HOY2EH246WBE/","https://security.netapp.com/advisory/ntap-20190710-0002/"],"description":"An issue was discovered in con_insert_unipair in drivers/tty/vt/consolemap.c in the Linux kernel through 5.1.5. There is a memory leak in a certain case of an ENOMEM outcome of kmalloc. NOTE: This id is disputed as not being an issue","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-12379","epss":0.00445,"percentile":0.37539,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12379","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-12379","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-12380","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-12380","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"**DISPUTED** An issue was discovered in the efi subsystem in the Linux kernel through 5.1.5. phys_efi_set_virtual_address_map in arch/x86/platform/efi/efi.c and efi_call_phys_prolog in arch/x86/platform/efi/efi_64.c mishandle memory allocation failures. NOTE: This id is disputed as not being an issue because “All the code touched by the referenced commit runs only at boot, before any user processes are started. Therefore, there is no possibility for an unprivileged user to control it.”.","cvss":[],"epss":[{"cve":"CVE-2019-12380","epss":0.00469,"percentile":0.39131,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12380","cwe":"CWE-388","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.023450000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-12380","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12380","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html","http://www.securityfocus.com/bid/108477","https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=4e78921ba4dd0aca1cc89168f45039add4183f8e","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLGWJKLMTBBB53D5QLS4HOY2EH246WBE/","https://security.netapp.com/advisory/ntap-20190710-0002/","https://usn.ubuntu.com/4414-1/","https://usn.ubuntu.com/4427-1/","https://usn.ubuntu.com/4439-1/"],"description":"**DISPUTED** An issue was discovered in the efi subsystem in the Linux kernel through 5.1.5. phys_efi_set_virtual_address_map in arch/x86/platform/efi/efi.c and efi_call_phys_prolog in arch/x86/platform/efi/efi_64.c mishandle memory allocation failures. NOTE: This id is disputed as not being an issue because “All the code touched by the referenced commit runs only at boot, before any user processes are started. Therefore, there is no possibility for an unprivileged user to control it.”.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-12380","epss":0.00469,"percentile":0.39131,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12380","cwe":"CWE-388","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-12380","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-12381","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-12381","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: this is disputed because new_ra is never used if it is NULL","cvss":[],"epss":[{"cve":"CVE-2019-12381","epss":0.00444,"percentile":0.37463,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12381","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.022200000000000004},"relatedVulnerabilities":[{"id":"CVE-2019-12381","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12381","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.securityfocus.com/bid/108473","https://bugzilla.redhat.com/show_bug.cgi?id=1715501","https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=425aa0e1d01513437668fa3d4a971168bbaa8515","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLGWJKLMTBBB53D5QLS4HOY2EH246WBE/","https://lkml.org/lkml/2019/5/25/230"],"description":"An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: this is disputed because new_ra is never used if it is NULL","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-12381","epss":0.00444,"percentile":0.37463,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12381","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-12381","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-12382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-12382","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: The vendor disputes this issues as not being a vulnerability because kstrdup() returning NULL is handled sufficiently and there is no chance for a NULL pointer dereference","cvss":[],"epss":[{"cve":"CVE-2019-12382","epss":0.00464,"percentile":0.3878,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12382","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0232},"relatedVulnerabilities":[{"id":"CVE-2019-12382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12382","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html","http://www.securityfocus.com/bid/108474","https://cgit.freedesktop.org/drm/drm-misc/commit/?id=9f1f1a2dab38d4ce87a13565cf4dc1b73bef3a5f","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLGWJKLMTBBB53D5QLS4HOY2EH246WBE/","https://lkml.org/lkml/2019/5/24/843","https://lore.kernel.org/lkml/87o93u7d3s.fsf%40intel.com/","https://salsa.debian.org/kernel-team/kernel-sec/blob/master/retired/CVE-2019-12382"],"description":"An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: The vendor disputes this issues as not being a vulnerability because kstrdup() returning NULL is handled sufficiently and there is no chance for a NULL pointer dereference","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-12382","epss":0.00464,"percentile":0.3878,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12382","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-12382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-12455","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-12455","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in sunxi_divs_clk_setup in drivers/clk/sunxi/clk-sunxi.c in the Linux kernel through 5.1.5. There is an unchecked kstrndup of derived_name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This id is disputed as not being an issue because “The memory allocation that was not checked is part of a code that only runs at boot time, before user processes are started. Therefore, there is no possibility for an unprivileged user to control it, and no denial of service.”","cvss":[],"epss":[{"cve":"CVE-2019-12455","epss":0.00421,"percentile":0.35504,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12455","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021050000000000003},"relatedVulnerabilities":[{"id":"CVE-2019-12455","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12455","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/pub/scm/linux/kernel/git/sunxi/linux.git/commit/?h=sunxi/clk-for-5.3&id=fcdf445ff42f036d22178b49cf64e92d527c1330","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/","https://security.netapp.com/advisory/ntap-20190710-0002/","https://www.mail-archive.com/linux-kernel%40vger.kernel.org/msg2010240.html"],"description":"An issue was discovered in sunxi_divs_clk_setup in drivers/clk/sunxi/clk-sunxi.c in the Linux kernel through 5.1.5. There is an unchecked kstrndup of derived_name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This id is disputed as not being an issue because “The memory allocation that was not checked is part of a code that only runs at boot time, before user processes are started. Therefore, there is no possibility for an unprivileged user to control it, and no denial of service.”","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-12455","epss":0.00421,"percentile":0.35504,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-12455","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-12455","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-12456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-12456","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux kernel through 5.1.5. It allows local users to cause a denial of service or possibly have unspecified other impact by changing the value of ioc_number between two kernel reads of that value, aka a \"double fetch\" vulnerability. NOTE: a third party reports that this is unexploitable because the doubly fetched value is not used","cvss":[],"epss":[{"cve":"CVE-2019-12456","epss":0.00406,"percentile":0.34056,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.020300000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-12456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12456","namespace":"nvd:cpe","severity":"High","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html","https://bugzilla.redhat.com/show_bug.cgi?id=1717182","https://git.kernel.org/pub/scm/linux/kernel/git/mkp/scsi.git/commit/?h=5.3/scsi-queue&id=86e5aca7fa2927060839f3e3b40c8bd65a7e8d1e","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MDURACJVGIBIYBSGDZJTRDPX46H5WPZW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OBJHGQXA4PQ5EOGCOXEH3KFDNVZ2I4X7/","https://lkml.org/lkml/2019/5/29/1164","https://support.f5.com/csp/article/K84310302","https://support.f5.com/csp/article/K84310302?utm_source=f5support&amp%3Butm_medium=RSS"],"description":"An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux kernel through 5.1.5. It allows local users to cause a denial of service or possibly have unspecified other impact by changing the value of ioc_number between two kernel reads of that value, aka a \"double fetch\" vulnerability. NOTE: a third party reports that this is unexploitable because the doubly fetched value is not used","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.0","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"exploitabilityScore":4,"impactScore":10.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-12456","epss":0.00406,"percentile":0.34056,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-12456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-15213","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-15213","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.6,"exploitabilityScore":1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-15213","epss":0.0063,"percentile":0.4811,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-15213","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2019-15213","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.3024},"relatedVulnerabilities":[{"id":"CVE-2019-15213","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-15213","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html","http://www.openwall.com/lists/oss-security/2019/08/20/2","https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3","https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6cf97230cd5f36b7665099083272595c55d72be7","https://security.netapp.com/advisory/ntap-20190905-0002/","https://syzkaller.appspot.com/bug?id=a53c9c9dd2981bfdbfbcbc1ddbd35595eda8bced"],"description":"An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.6,"exploitabilityScore":1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.9,"exploitabilityScore":4,"impactScore":6.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.6,"exploitabilityScore":1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-15213","epss":0.0063,"percentile":0.4811,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-15213","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2019-15213","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-15213","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-16089","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-16089","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An issue was discovered in the Linux kernel through 5.2.13. nbd_genl_status in drivers/block/nbd.c does not check the nla_nest_start_noflag return value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-16089","epss":0.00387,"percentile":0.32091,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16089","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.176085},"relatedVulnerabilities":[{"id":"CVE-2019-16089","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16089","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/patchwork/patch/1106884/","https://lore.kernel.org/patchwork/patch/1126650/","https://security.netapp.com/advisory/ntap-20191004-0001/","https://support.f5.com/csp/article/K03814795?utm_source=f5support&amp%3Butm_medium=RSS","https://usn.ubuntu.com/4414-1/","https://usn.ubuntu.com/4425-1/","https://usn.ubuntu.com/4439-1/","https://usn.ubuntu.com/4440-1/"],"description":"An issue was discovered in the Linux kernel through 5.2.13. nbd_genl_status in drivers/block/nbd.c does not check the nla_nest_start_noflag return value.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.7,"exploitabilityScore":3.4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-16089","epss":0.00387,"percentile":0.32091,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16089","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-16089","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-16229","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-16229","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deserving a CVE id","cvss":[],"epss":[{"cve":"CVE-2019-16229","epss":0.00421,"percentile":0.35517,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16229","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.021050000000000003},"relatedVulnerabilities":[{"id":"CVE-2019-16229","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16229","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.suse.com/show_bug.cgi?id=1150469#c3","https://lkml.org/lkml/2019/9/9/487","https://security.netapp.com/advisory/ntap-20191004-0001/","https://usn.ubuntu.com/4284-1/","https://usn.ubuntu.com/4285-1/","https://usn.ubuntu.com/4287-1/","https://usn.ubuntu.com/4287-2/"],"description":"drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deserving a CVE id","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.7,"exploitabilityScore":3.4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-16229","epss":0.00421,"percentile":0.35517,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16229","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-16229","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-16230","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-16230","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer states that the work queue allocation is happening during device initialization, which for a graphics card occurs during boot. It is not attacker controllable and OOM at that time is highly unlikely","cvss":[],"epss":[{"cve":"CVE-2019-16230","epss":0.00375,"percentile":0.30813,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16230","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2019-16230","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01875},"relatedVulnerabilities":[{"id":"CVE-2019-16230","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16230","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.suse.com/show_bug.cgi?id=1150468","https://lkml.org/lkml/2019/9/9/487","https://security.netapp.com/advisory/ntap-20191004-0001/"],"description":"drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer states that the work queue allocation is happening during device initialization, which for a graphics card occurs during boot. It is not attacker controllable and OOM at that time is highly unlikely","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.7,"exploitabilityScore":3.4,"impactScore":6.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-16230","epss":0.00375,"percentile":0.30813,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16230","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2019-16230","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-16230","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-16231","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-16231","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.","cvss":[],"epss":[{"cve":"CVE-2019-16231","epss":0.00422,"percentile":0.35606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16231","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0211},"relatedVulnerabilities":[{"id":"CVE-2019-16231","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16231","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00039.html","https://lkml.org/lkml/2019/9/9/487","https://security.netapp.com/advisory/ntap-20191004-0001/","https://usn.ubuntu.com/4225-1/","https://usn.ubuntu.com/4225-2/","https://usn.ubuntu.com/4226-1/","https://usn.ubuntu.com/4227-1/","https://usn.ubuntu.com/4227-2/"],"description":"drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.7,"exploitabilityScore":3.4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-16231","epss":0.00422,"percentile":0.35606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16231","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-16231","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-16232","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-16232","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.","cvss":[],"epss":[{"cve":"CVE-2019-16232","epss":0.00583,"percentile":0.45942,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16232","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.029150000000000002},"relatedVulnerabilities":[{"id":"CVE-2019-16232","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16232","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LYIFGYEDQXP5DVJQQUARQRK2PXKBKQGY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YWWOOJKZ4NQYN4RMFIVJ3ZIXKJJI3MKP/","https://lkml.org/lkml/2019/9/9/487","https://security.netapp.com/advisory/ntap-20191004-0001/","https://usn.ubuntu.com/4284-1/","https://usn.ubuntu.com/4285-1/","https://usn.ubuntu.com/4287-1/","https://usn.ubuntu.com/4287-2/"],"description":"drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.7,"exploitabilityScore":3.4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-16232","epss":0.00583,"percentile":0.45942,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16232","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-16232","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-16233","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-16233","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.","cvss":[],"epss":[{"cve":"CVE-2019-16233","epss":0.00381,"percentile":0.31387,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16233","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01905},"relatedVulnerabilities":[{"id":"CVE-2019-16233","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16233","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html","https://lkml.org/lkml/2019/9/9/487","https://security.netapp.com/advisory/ntap-20191004-0001/","https://usn.ubuntu.com/4226-1/","https://usn.ubuntu.com/4227-1/","https://usn.ubuntu.com/4227-2/","https://usn.ubuntu.com/4346-1/"],"description":"drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.7,"exploitabilityScore":3.4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-16233","epss":0.00381,"percentile":0.31387,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16233","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-16233","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-16234","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-16234","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.","cvss":[],"epss":[{"cve":"CVE-2019-16234","epss":0.00436,"percentile":0.36794,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16234","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0218},"relatedVulnerabilities":[{"id":"CVE-2019-16234","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-16234","namespace":"nvd:cpe","severity":"Medium","urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00064.html","http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html","https://lkml.org/lkml/2019/9/9/487","https://security.netapp.com/advisory/ntap-20191004-0001/","https://usn.ubuntu.com/4342-1/","https://usn.ubuntu.com/4344-1/","https://usn.ubuntu.com/4345-1/","https://usn.ubuntu.com/4346-1/"],"description":"drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.7,"exploitabilityScore":3.4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-16234","epss":0.00436,"percentile":0.36794,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-16234","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-16234","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-19070","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-19070","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third parties dispute the relevance of this because the system must have already been out of memory before the probe began","cvss":[],"epss":[{"cve":"CVE-2019-19070","epss":0.02848,"percentile":0.85867,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-19070","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1424},"relatedVulnerabilities":[{"id":"CVE-2019-19070","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19070","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.suse.com/show_bug.cgi?id=1157294","https://github.com/torvalds/linux/commit/d3b0ffa1d75d5305ebe34735598993afbb8a869d","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O3PSDE6PTOTVBK2YTKB2TFQP2SUBVSNF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PY7LJMSPAGRIKABJPDKQDTXYW3L5RX2T/"],"description":"A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third parties dispute the relevance of this because the system must have already been out of memory before the probe began","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"exploitabilityScore":10,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19070","epss":0.02848,"percentile":0.85867,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-19070","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-19070","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-19378","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-19378","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.","cvss":[],"epss":[{"cve":"CVE-2019-19378","epss":0.02354,"percentile":0.82706,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-19378","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2019-19378","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11770000000000001},"relatedVulnerabilities":[{"id":"CVE-2019-19378","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19378","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19378","https://security.netapp.com/advisory/ntap-20200103-0001/"],"description":"In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19378","epss":0.02354,"percentile":0.82706,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-19378","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2019-19378","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-19378","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-19449","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-19449","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19449","epss":0.02014,"percentile":0.79718,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-19449","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":1.5407100000000002},"relatedVulnerabilities":[{"id":"CVE-2019-19449","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19449","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19449","https://security.netapp.com/advisory/ntap-20200103-0001/"],"description":"In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"exploitabilityScore":8.6,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19449","epss":0.02014,"percentile":0.79718,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-19449","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-19449","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-19814","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-19814","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19814","epss":0.03297,"percentile":0.87767,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-19814","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":2.522205},"relatedVulnerabilities":[{"id":"CVE-2019-19814","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19814","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19814","https://security.netapp.com/advisory/ntap-20200103-0001/"],"description":"In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"exploitabilityScore":8.6,"impactScore":10.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19814","epss":0.03297,"percentile":0.87767,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-19814","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-19814","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2019-20794","dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-20794","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-20794","epss":0.00512,"percentile":0.41978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-20794","cwe":"CWE-772","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.24832},"relatedVulnerabilities":[{"id":"CVE-2019-20794","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20794","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2020/08/24/1","https://github.com/sargun/fuse-example","https://security.netapp.com/advisory/ntap-20200608-0001/","https://sourceforge.net/p/fuse/mailman/message/36598753/"],"description":"An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":4.7,"exploitabilityScore":3.4,"impactScore":6.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-20794","epss":0.00512,"percentile":0.41978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2019-20794","cwe":"CWE-772","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2019-20794","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2020-11725","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-11725","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later affects a private_size*count multiplication for unspecified \"interesting side effects.\" NOTE: kernel engineers dispute this finding, because it could be relevant only if new callers were added that were unfamiliar with the misuse of the info->owner field to represent data unrelated to the \"owner\" concept. The existing callers, SNDRV_CTL_IOCTL_ELEM_ADD and SNDRV_CTL_IOCTL_ELEM_REPLACE, have been designed to misuse the info->owner field in a safe way","cvss":[],"epss":[{"cve":"CVE-2020-11725","epss":0.00515,"percentile":0.4218,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-11725","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.025750000000000002},"relatedVulnerabilities":[{"id":"CVE-2020-11725","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-11725","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/torvalds/linux/blob/3b2549a3740efb8af0150415737067d87e466c5b/sound/core/control.c#L1434-L1474","https://lore.kernel.org/alsa-devel/s5h4ktmlfpx.wl-tiwai%40suse.de/","https://twitter.com/yabbadabbadrew/status/1248632267028582400"],"description":"snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later affects a private_size*count multiplication for unspecified \"interesting side effects.\" NOTE: kernel engineers dispute this finding, because it could be relevant only if new callers were added that were unfamiliar with the misuse of the info->owner field to represent data unrelated to the \"owner\" concept. The existing callers, SNDRV_CTL_IOCTL_ELEM_ADD and SNDRV_CTL_IOCTL_ELEM_REPLACE, have been designed to misuse the info->owner field in a safe way","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-11725","epss":0.00515,"percentile":0.4218,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-11725","cwe":"CWE-704","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-11725","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2020-14304","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-14304","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vulnerability is to confidentiality.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14304","epss":0.00358,"percentile":0.29107,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-14304","cwe":"CWE-460","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2020-14304","cwe":"CWE-755","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.16826},"relatedVulnerabilities":[{"id":"CVE-2020-14304","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14304","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960702","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14304"],"description":"A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vulnerability is to confidentiality.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"exploitabilityScore":4,"impactScore":2.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-14304","epss":0.00358,"percentile":0.29107,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-14304","cwe":"CWE-460","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2020-14304","cwe":"CWE-755","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-14304","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2020-35501","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-35501","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem","cvss":[],"epss":[{"cve":"CVE-2020-35501","epss":0.00241,"percentile":0.15276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-35501","cwe":"CWE-863","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2020-35501","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01205},"relatedVulnerabilities":[{"id":"CVE-2020-35501","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-35501","namespace":"nvd:cpe","severity":"Low","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1908577"],"description":"A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.4,"exploitabilityScore":0.8,"impactScore":2.6},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.6,"exploitabilityScore":4,"impactScore":5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-35501","epss":0.00241,"percentile":0.15276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-35501","cwe":"CWE-863","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2020-35501","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-35501","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2020-36694","dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-36694","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with the CAP_NET_ADMIN capability in an unprivileged namespace. NOTE: cc00bca was reverted in 5.12.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-36694","epss":0.00444,"percentile":0.3745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-36694","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2020-36694","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25974},"relatedVulnerabilities":[{"id":"CVE-2020-36694","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-36694","namespace":"nvd:cpe","severity":"Medium","urls":["https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10","https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12","https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cc00bcaa589914096edef7fb87ca5cee4a166b5c","https://security.netapp.com/advisory/ntap-20230622-0005/","https://syzkaller.appspot.com/bug?id=0c4fd9c6aa04ec116d01e915d3b186f71a212cb2"],"description":"An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with the CAP_NET_ADMIN capability in an unprivileged namespace. NOTE: cc00bca was reverted in 5.12.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2020-36694","epss":0.00444,"percentile":0.3745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2020-36694","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2020-36694","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2020-36694","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2021-26934","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-26934","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.","cvss":[],"epss":[{"cve":"CVE-2021-26934","epss":0.00346,"percentile":0.27744,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0173},"relatedVulnerabilities":[{"id":"CVE-2021-26934","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-26934","namespace":"nvd:cpe","severity":"High","urls":["http://xenbits.xen.org/xsa/advisory-363.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4GELN5E6MDR5KQBJF5M5COUUED3YFZTD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOAJBVAVR6RSCUCHNXPVSNRPSFM7INMP/","https://security.netapp.com/advisory/ntap-20210326-0001/"],"description":"An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"exploitabilityScore":4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-26934","epss":0.00346,"percentile":0.27744,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-26934","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2021-3714","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-3714","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.","cvss":[],"epss":[{"cve":"CVE-2021-3714","epss":0.01523,"percentile":0.73111,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-3714","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07615},"relatedVulnerabilities":[{"id":"CVE-2021-3714","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3714","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2021-3714","https://arxiv.org/abs/2111.08553","https://arxiv.org/pdf/2111.08553.pdf","https://bugzilla.redhat.com/show_bug.cgi?id=1931327"],"description":"A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and detect the change in access time from a networked service to determine if the page has been merged.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"exploitabilityScore":2.3,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-3714","epss":0.01523,"percentile":0.73111,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-3714","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-3714","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2021-3847","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-3847","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-3847","epss":0.00464,"percentile":0.38827,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-3847","cwe":"CWE-281","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-3847","cwe":"CWE-281","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.35496},"relatedVulnerabilities":[{"id":"CVE-2021-3847","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3847","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2009704","https://www.openwall.com/lists/oss-security/2021/10/14/3"],"description":"An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"exploitabilityScore":4,"impactScore":10.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-3847","epss":0.00464,"percentile":0.38827,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-3847","cwe":"CWE-281","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2021-3847","cwe":"CWE-281","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-3847","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2021-3864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-3864","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-3864","epss":0.00769,"percentile":0.5342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-3864","cwe":"CWE-284","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.5575249999999999},"relatedVulnerabilities":[{"id":"CVE-2021-3864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3864","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2021-3864","https://bugzilla.redhat.com/show_bug.cgi?id=2015046","https://lore.kernel.org/all/20211221021744.864115-1-longman%40redhat.com/","https://lore.kernel.org/all/20211226150310.GA992%401wt.eu/","https://lore.kernel.org/lkml/20211228170910.623156-1-wander%40redhat.com/","https://security-tracker.debian.org/tracker/CVE-2021-3864","https://www.openwall.com/lists/oss-security/2021/10/20/2"],"description":"A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2021-3864","epss":0.00769,"percentile":0.5342,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2021-3864","cwe":"CWE-284","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2021-3864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-0400","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0400","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.","cvss":[],"epss":[{"cve":"CVE-2022-0400","epss":0.01713,"percentile":0.76015,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0400","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0400","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08565},"relatedVulnerabilities":[{"id":"CVE-2022-0400","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0400","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2022-0400","https://bugzilla.redhat.com/show_bug.cgi?id=2040604","https://bugzilla.redhat.com/show_bug.cgi?id=2044575"],"description":"An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-0400","epss":0.01713,"percentile":0.76015,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-0400","cwe":"CWE-125","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-0400","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-0400","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-1247","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-1247","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls rose_del_node() and removes neighbours only if their “count” and “use” are zero.","cvss":[],"epss":[{"cve":"CVE-2022-1247","epss":0.00273,"percentile":0.19538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-1247","cwe":"CWE-362","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-1247","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.013649999999999999},"relatedVulnerabilities":[{"id":"CVE-2022-1247","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1247","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2022-1247","https://bugzilla.redhat.com/show_bug.cgi?id=2066799"],"description":"An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls rose_del_node() and removes neighbours only if their “count” and “use” are zero.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-1247","epss":0.00273,"percentile":0.19538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-1247","cwe":"CWE-362","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-1247","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-1247","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-25265","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-25265","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.","cvss":[],"epss":[{"cve":"CVE-2022-25265","epss":0.01054,"percentile":0.62377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-25265","cwe":"CWE-913","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.052700000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-25265","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25265","namespace":"nvd:cpe","severity":"High","urls":["https://github.com/torvalds/linux/blob/1c33bb0507508af24fd754dd7123bd8e997fab2f/arch/x86/include/asm/elf.h#L281-L294","https://github.com/x0reaxeax/exec-prot-bypass","https://security.netapp.com/advisory/ntap-20220318-0005/"],"description":"In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"nvd@nist.gov","type":"Primary","version":"2.0","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.4,"exploitabilityScore":3.4,"impactScore":6.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-25265","epss":0.01054,"percentile":0.62377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-25265","cwe":"CWE-913","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-25265","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-2961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-2961","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.","cvss":[],"epss":[{"cve":"CVE-2022-2961","epss":0.00317,"percentile":0.24402,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-2961","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-2961","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01585},"relatedVulnerabilities":[{"id":"CVE-2022-2961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2961","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/security/cve/CVE-2022-2961","https://security.netapp.com/advisory/ntap-20230214-0004/"],"description":"A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-2961","epss":0.00317,"percentile":0.24402,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-2961","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-2961","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-2961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-3238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3238","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.","cvss":[],"epss":[{"cve":"CVE-2022-3238","epss":0.00216,"percentile":0.11924,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3238","cwe":"CWE-459","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-3238","cwe":"CWE-415","source":"nvd@nist.gov","type":"Secondary"},{"cve":"CVE-2022-3238","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0108},"relatedVulnerabilities":[{"id":"CVE-2022-3238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3238","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2127927"],"description":"A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-3238","epss":0.00216,"percentile":0.11924,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-3238","cwe":"CWE-459","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-3238","cwe":"CWE-415","source":"nvd@nist.gov","type":"Secondary"},{"cve":"CVE-2022-3238","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-3238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-41848","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-41848","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioctl and mgslpc_detach.","cvss":[],"epss":[{"cve":"CVE-2022-41848","epss":0.00251,"percentile":0.165,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-41848","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-41848","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-41848","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2022-41848","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.012550000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-41848","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41848","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/drivers/char/pcmcia/synclink_cs.c","https://lore.kernel.org/lkml/20220919040251.GA302541%40ubuntu/T/#rc85e751f467b3e6f9ccef92cfa7fb8a6cc50c270"],"description":"drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioctl and mgslpc_detach.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.2,"exploitabilityScore":0.6,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.2,"exploitabilityScore":0.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-41848","epss":0.00251,"percentile":0.165,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-41848","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-41848","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-41848","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2022-41848","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-41848","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-44032","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-44032","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between cmm_open() and cm4000_detach().","cvss":[],"epss":[{"cve":"CVE-2022-44032","epss":0.00332,"percentile":0.26129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-44032","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-44032","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.016600000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-44032","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-44032","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9b12f050c76f090cc6d0aebe0ef76fed79ec3f15","https://lore.kernel.org/lkml/20220915020834.GA110086%40ubuntu/","https://lore.kernel.org/lkml/20220919040701.GA302806%40ubuntu/"],"description":"An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between cmm_open() and cm4000_detach().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"exploitabilityScore":0.6,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"exploitabilityScore":0.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-44032","epss":0.00332,"percentile":0.26129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-44032","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-44032","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-44032","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-44033","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-44033","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between cm4040_open() and reader_detach().","cvss":[],"epss":[{"cve":"CVE-2022-44033","epss":0.00332,"percentile":0.2613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-44033","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.016600000000000004},"relatedVulnerabilities":[{"id":"CVE-2022-44033","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-44033","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9b12f050c76f090cc6d0aebe0ef76fed79ec3f15","https://lore.kernel.org/lkml/20220915020834.GA110086%40ubuntu/","https://lore.kernel.org/lkml/20220919040457.GA302681%40ubuntu/"],"description":"An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between cm4040_open() and reader_detach().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"exploitabilityScore":0.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-44033","epss":0.00332,"percentile":0.2613,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-44033","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-44033","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-44034","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-44034","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between scr24x_open() and scr24x_remove().","cvss":[],"epss":[{"cve":"CVE-2022-44034","epss":0.00308,"percentile":0.23341,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-44034","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0154},"relatedVulnerabilities":[{"id":"CVE-2022-44034","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-44034","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9b12f050c76f090cc6d0aebe0ef76fed79ec3f15","https://lore.kernel.org/lkml/20220916050333.GA188358%40ubuntu/","https://lore.kernel.org/lkml/20220919101825.GA313940%40ubuntu/"],"description":"An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between scr24x_open() and scr24x_remove().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"exploitabilityScore":0.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-44034","epss":0.00308,"percentile":0.23341,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-44034","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-44034","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-4543","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-4543","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw named \"EntryBleed\" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.","cvss":[],"epss":[{"cve":"CVE-2022-4543","epss":0.00954,"percentile":0.5929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-4543","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-4543","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0477},"relatedVulnerabilities":[{"id":"CVE-2022-4543","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4543","namespace":"nvd:cpe","severity":"Medium","urls":["https://www.openwall.com/lists/oss-security/2022/12/16/3","https://www.willsroot.io/2022/12/entrybleed.html"],"description":"A flaw named \"EntryBleed\" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-4543","epss":0.00954,"percentile":0.5929,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-4543","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2022-4543","cwe":"CWE-203","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-4543","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-45884","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-45884","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.","cvss":[],"epss":[{"cve":"CVE-2022-45884","epss":0.00331,"percentile":0.2601,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-45884","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-45884","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.016550000000000002},"relatedVulnerabilities":[{"id":"CVE-2022-45884","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-45884","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=627bb528b086b4136315c25d6a447a98ea9448d3","https://lore.kernel.org/linux-media/20221115131822.6640-1-imv4bel%40gmail.com/","https://lore.kernel.org/linux-media/20221115131822.6640-4-imv4bel%40gmail.com/","https://security.netapp.com/advisory/ntap-20230113-0006/"],"description":"An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-45884","epss":0.00331,"percentile":0.2601,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-45884","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-45884","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-45884","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2022-45885","dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-45885","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.","cvss":[],"epss":[{"cve":"CVE-2022-45885","epss":0.0031,"percentile":0.23636,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-45885","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-45885","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-45885","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2022-45885","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0155},"relatedVulnerabilities":[{"id":"CVE-2022-45885","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-45885","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6769a0b7ee0c3b31e1b22c3fadff2bfb642de23f","https://lore.kernel.org/linux-media/20221115131822.6640-1-imv4bel%40gmail.com/","https://lore.kernel.org/linux-media/20221115131822.6640-2-imv4bel%40gmail.com/","https://security.netapp.com/advisory/ntap-20230113-0006/"],"description":"An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-45885","epss":0.0031,"percentile":0.23636,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2022-45885","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-45885","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2022-45885","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"},{"cve":"CVE-2022-45885","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2022-45885","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-0597","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-0597","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-0597","epss":0.00298,"percentile":0.22257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-0597","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-0597","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"},{"cve":"CVE-2023-0597","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15645},"relatedVulnerabilities":[{"id":"CVE-2023-0597","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0597","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2023/07/28/1","https://git.kernel.org/linus/97e3d26b5e5f371b3ee223d94dd123e6c442ba80","https://www.openwall.com/lists/oss-security/2023/07/28/1"],"description":"A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-0597","epss":0.00298,"percentile":0.22257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-0597","cwe":"CWE-200","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-0597","cwe":"CWE-401","source":"nvd@nist.gov","type":"Secondary"},{"cve":"CVE-2023-0597","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-0597","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-21264","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-21264","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-21264","epss":0.00141,"percentile":0.03767,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-21264","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08248499999999999},"relatedVulnerabilities":[{"id":"CVE-2023-21264","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-21264","namespace":"nvd:cpe","severity":"Medium","urls":["https://android.googlesource.com/kernel/common/+/53625a846a7b4","https://android.googlesource.com/kernel/common/+/b35a06182451f","https://source.android.com/security/bulletin/2023-08-01"],"description":"In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"exploitabilityScore":0.8,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-21264","epss":0.00141,"percentile":0.03767,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-21264","cwe":"CWE-119","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-21264","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-23005","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-23005","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-23005","epss":0.00268,"percentile":0.18873,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-23005","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-23005","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1407},"relatedVulnerabilities":[{"id":"CVE-2023-23005","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-23005","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.suse.com/show_bug.cgi?id=1208844#c2","https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2","https://github.com/torvalds/linux/commit/4a625ceee8a0ab0273534cb6b432ce6b331db5ee"],"description":"In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-23005","epss":0.00268,"percentile":0.18873,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-23005","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-23005","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-23005","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-23039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-23039","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().","cvss":[],"epss":[{"cve":"CVE-2023-23039","epss":0.00217,"percentile":0.12048,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-23039","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-23039","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01085},"relatedVulnerabilities":[{"id":"CVE-2023-23039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-23039","namespace":"nvd:cpe","severity":"Medium","urls":["https://lkml.org/lkml/2023/1/1/169"],"description":"An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":0.6,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":0.6,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-23039","epss":0.00217,"percentile":0.12048,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-23039","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-23039","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-23039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-26242","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-26242","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.","cvss":[],"epss":[{"cve":"CVE-2023-26242","epss":0.0024,"percentile":0.15082,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-26242","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-26242","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.011999999999999999},"relatedVulnerabilities":[{"id":"CVE-2023-26242","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-26242","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.suse.com/show_bug.cgi?id=1208518","https://patchwork.kernel.org/project/linux-fpga/patch/20230206054326.89323-1-k1rh4.lee%40gmail.com","https://security.netapp.com/advisory/ntap-20230406-0002/"],"description":"afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-26242","epss":0.0024,"percentile":0.15082,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-26242","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-26242","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-26242","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-31081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31081","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vidtv_mux_stop_thread. In vidtv_stop_streaming, after dvb->mux=NULL occurs, it executes vidtv_mux_stop_thread(dvb->mux).","cvss":[],"epss":[{"cve":"CVE-2023-31081","epss":0.00355,"percentile":0.28708,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31081","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31081","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.017750000000000002},"relatedVulnerabilities":[{"id":"CVE-2023-31081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31081","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.suse.com/show_bug.cgi?id=1210782","https://lore.kernel.org/all/CA+UBctDXyiosaiR7YNKCs8k0aWu4gU+YutRcnC+TDJkXpHjQag%40mail.gmail.com/","https://security.netapp.com/advisory/ntap-20230929-0003/"],"description":"An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vidtv_mux_stop_thread. In vidtv_stop_streaming, after dvb->mux=NULL occurs, it executes vidtv_mux_stop_thread(dvb->mux).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31081","epss":0.00355,"percentile":0.28708,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31081","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-31081","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-31082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31082","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31082","epss":0.0036,"percentile":0.29245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31082","cwe":"CWE-763","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.189},"relatedVulnerabilities":[{"id":"CVE-2023-31082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31082","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.suse.com/show_bug.cgi?id=1210781","https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A%40mail.gmail.com/","https://security.netapp.com/advisory/ntap-20230929-0003/"],"description":"An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31082","epss":0.0036,"percentile":0.29245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31082","cwe":"CWE-763","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-31085","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31085","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,mtd->erasesize), used indirectly by ctrl_cdev_ioctl, when mtd->erasesize is 0.","cvss":[],"epss":[{"cve":"CVE-2023-31085","epss":0.00379,"percentile":0.3124,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31085","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01895},"relatedVulnerabilities":[{"id":"CVE-2023-31085","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31085","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=017c73a34a661a861712f7cc1393a123e5b2208c","https://lore.kernel.org/all/687864524.118195.1681799447034.JavaMail.zimbra%40nod.at/","https://security.netapp.com/advisory/ntap-20230929-0003/"],"description":"An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,mtd->erasesize), used indirectly by ctrl_cdev_ioctl, when mtd->erasesize is 0.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-31085","epss":0.00379,"percentile":0.3124,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-31085","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-31085","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-3397","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-3397","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A race condition occurred between the functions lmLogClose and txEnd in JFS, in the Linux Kernel, executed in different threads. This flaw allows a local attacker with normal user privileges to crash the system or leak internal kernel information.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-3397","epss":0.0021,"percentile":0.11173,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-3397","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-3397","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11864999999999998},"relatedVulnerabilities":[{"id":"CVE-2023-3397","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3397","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-3397","https://bugzilla.redhat.com/show_bug.cgi?id=2217271","https://www.spinics.net/lists/kernel/msg4788636.html"],"description":"A race condition occurred between the functions lmLogClose and txEnd in JFS, in the Linux Kernel, executed in different threads. This flaw allows a local attacker with normal user privileges to crash the system or leak internal kernel information.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-3397","epss":0.0021,"percentile":0.11173,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-3397","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-3397","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-3397","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-3640","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-3640","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. This issue could allow a local user to gain access to some important data with memory in an expected location and potentially escalate their privileges on the system.","cvss":[],"epss":[{"cve":"CVE-2023-3640","epss":0.00761,"percentile":0.53163,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-3640","cwe":"CWE-385","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-3640","cwe":"CWE-203","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03805},"relatedVulnerabilities":[{"id":"CVE-2023-3640","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3640","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2023:6583","https://access.redhat.com/security/cve/CVE-2023-3640","https://bugzilla.redhat.com/show_bug.cgi?id=2217523"],"description":"A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in /arch/x86/mm/cpu_entry_area.c, which works through the init_cea_offsets() function when KASLR is enabled. However, despite this feature, there is still a risk of per-cpu entry area leaks. This issue could allow a local user to gain access to some important data with memory in an expected location and potentially escalate their privileges on the system.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-3640","epss":0.00761,"percentile":0.53163,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-3640","cwe":"CWE-385","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-3640","cwe":"CWE-203","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-3640","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-37454","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-37454","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective about this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-37454","epss":0.00361,"percentile":0.29385,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-37454","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.189525},"relatedVulnerabilities":[{"id":"CVE-2023-37454","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-37454","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-37454","https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6f861765464f43a71462d52026fbddfc858239a5","https://lore.kernel.org/all/00000000000056e02f05dfb6e11a%40google.com/T/","https://syzkaller.appspot.com/bug?extid=26873a72980f8fa8bc55","https://syzkaller.appspot.com/bug?extid=60864ed35b1073540d57","https://syzkaller.appspot.com/bug?extid=61564e5023b7229ec85d"],"description":"An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective about this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-37454","epss":0.00361,"percentile":0.29385,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-37454","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-37454","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-39191","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39191","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.","cvss":[],"epss":[{"cve":"CVE-2023-39191","epss":0.0052,"percentile":0.42522,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39191","cwe":"CWE-20","source":"secalert@redhat.com","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.026},"relatedVulnerabilities":[{"id":"CVE-2023-39191","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39191","namespace":"nvd:cpe","severity":"High","urls":["https://access.redhat.com/errata/RHSA-2023:6583","https://access.redhat.com/errata/RHSA-2024:0381","https://access.redhat.com/errata/RHSA-2024:0439","https://access.redhat.com/errata/RHSA-2024:0448","https://access.redhat.com/security/cve/CVE-2023-39191","https://bugzilla.redhat.com/show_bug.cgi?id=2226783","https://www.zerodayinitiative.com/advisories/ZDI-CAN-19399/"],"description":"An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39191","epss":0.0052,"percentile":0.42522,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-39191","cwe":"CWE-20","source":"secalert@redhat.com","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-39191","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-4133","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-4133","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of service condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-4133","epss":0.00231,"percentile":0.13888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-4133","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-4133","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12127500000000001},"relatedVulnerabilities":[{"id":"CVE-2023-4133","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4133","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:2394","https://access.redhat.com/errata/RHSA-2024:2950","https://access.redhat.com/errata/RHSA-2024:3138","https://access.redhat.com/security/cve/CVE-2023-4133","https://bugzilla.redhat.com/show_bug.cgi?id=2221702"],"description":"A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of service condition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-4133","epss":0.00231,"percentile":0.13888,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-4133","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-4133","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-4133","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-4134","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-4134","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service.","cvss":[],"epss":[{"cve":"CVE-2023-4134","epss":0.002,"percentile":0.09906,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-4134","cwe":"CWE-416","source":"patrick@puiterwijk.org","type":"Secondary"},{"cve":"CVE-2023-4134","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.01},"relatedVulnerabilities":[{"id":"CVE-2023-4134","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4134","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-4134","https://bugzilla.redhat.com/show_bug.cgi?id=2221700"],"description":"A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"patrick@puiterwijk.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-4134","epss":0.002,"percentile":0.09906,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-4134","cwe":"CWE-416","source":"patrick@puiterwijk.org","type":"Secondary"},{"cve":"CVE-2023-4134","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-4134","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52452","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52452","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix accesses to uninit stack slots  Privileged programs are supposed to be able to read uninitialized stack memory (ever since 6715df8d5) but, before this patch, these accesses were permitted inconsistently. In particular, accesses were permitted above state->allocated_stack, but not below it. In other words, if the stack was already \"large enough\", the access was permitted, but otherwise the access was rejected instead of being allowed to \"grow the stack\". This undesired rejection was happening in two places: - in check_stack_slot_within_bounds() - in check_stack_range_initialized() This patch arranges for these accesses to be permitted. A bunch of tests that were relying on the old rejection had to change; all of them were changed to add also run unprivileged, in which case the old behavior persists. One tests couldn't be updated - global_func16 - because it can't run unprivileged for other reasons.  This patch also fixes the tracking of the stack size for variable-offset reads. This second fix is bundled in the same commit as the first one because they're inter-related. Before this patch, writes to the stack using registers containing a variable offset (as opposed to registers with fixed, known values) were not properly contributing to the function's needed stack size. As a result, it was possible for a program to verify, but then to attempt to read out-of-bounds data at runtime because a too small stack had been allocated for it.  Each function tracks the size of the stack it needs in bpf_subprog_info.stack_depth, which is maintained by update_stack_depth(). For regular memory accesses, check_mem_access() was calling update_state_depth() but it was passing in only the fixed part of the offset register, ignoring the variable offset. This was incorrect; the minimum possible value of that register should be used instead.  This tracking is now fixed by centralizing the tracking of stack size in grow_stack_state(), and by lifting the calls to grow_stack_state() to check_stack_access_within_bounds() as suggested by Andrii. The code is now simpler and more convincingly tracks the correct maximum stack size. check_stack_range_initialized() can now rely on enough stack having been allocated for the access; this helps with the fix for the first issue.  A few tests were changed to also check the stack depth computation. The one that fails without this patch is verifier_var_off:stack_write_priv_vs_unpriv.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52452","epss":0.00239,"percentile":0.14898,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52452","cwe":"CWE-665","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18283500000000003},"relatedVulnerabilities":[{"id":"CVE-2023-52452","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52452","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0954982db8283016bf38e9db2da5adf47a102e19","https://git.kernel.org/stable/c/6b4a64bafd107e521c01eec3453ce94a3fb38529","https://git.kernel.org/stable/c/fbcf372c8eda2290470268e0afb5ab5d5f5d5fde"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix accesses to uninit stack slots\n\nPrivileged programs are supposed to be able to read uninitialized stack\nmemory (ever since 6715df8d5) but, before this patch, these accesses\nwere permitted inconsistently. In particular, accesses were permitted\nabove state->allocated_stack, but not below it. In other words, if the\nstack was already \"large enough\", the access was permitted, but\notherwise the access was rejected instead of being allowed to \"grow the\nstack\". This undesired rejection was happening in two places:\n- in check_stack_slot_within_bounds()\n- in check_stack_range_initialized()\nThis patch arranges for these accesses to be permitted. A bunch of tests\nthat were relying on the old rejection had to change; all of them were\nchanged to add also run unprivileged, in which case the old behavior\npersists. One tests couldn't be updated - global_func16 - because it\ncan't run unprivileged for other reasons.\n\nThis patch also fixes the tracking of the stack size for variable-offset\nreads. This second fix is bundled in the same commit as the first one\nbecause they're inter-related. Before this patch, writes to the stack\nusing registers containing a variable offset (as opposed to registers\nwith fixed, known values) were not properly contributing to the\nfunction's needed stack size. As a result, it was possible for a program\nto verify, but then to attempt to read out-of-bounds data at runtime\nbecause a too small stack had been allocated for it.\n\nEach function tracks the size of the stack it needs in\nbpf_subprog_info.stack_depth, which is maintained by\nupdate_stack_depth(). For regular memory accesses, check_mem_access()\nwas calling update_state_depth() but it was passing in only the fixed\npart of the offset register, ignoring the variable offset. This was\nincorrect; the minimum possible value of that register should be used\ninstead.\n\nThis tracking is now fixed by centralizing the tracking of stack size in\ngrow_stack_state(), and by lifting the calls to grow_stack_state() to\ncheck_stack_access_within_bounds() as suggested by Andrii. The code is\nnow simpler and more convincingly tracks the correct maximum stack size.\ncheck_stack_range_initialized() can now rely on enough stack having been\nallocated for the access; this helps with the fix for the first issue.\n\nA few tests were changed to also check the stack depth computation. The\none that fails without this patch is verifier_var_off:stack_write_priv_vs_unpriv.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52452","epss":0.00239,"percentile":0.14898,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52452","cwe":"CWE-665","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52452","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52586","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52586","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm/dpu: Add mutex lock in control vblank irq  Add a mutex lock to control vblank irq to synchronize vblank enable/disable operations happening from different threads to prevent race conditions while registering/unregistering the vblank irq callback.  v4: -Removed vblank_ctl_lock from dpu_encoder_virt, so it is only a     parameter of dpu_encoder_phys.     -Switch from atomic refcnt to a simple int counter as mutex has     now been added v3: Mistakenly did not change wording in last version. It is done now. v2: Slightly changed wording of commit message  Patchwork: https://patchwork.freedesktop.org/patch/571854/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52586","epss":0.00161,"percentile":0.05596,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52586","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11672500000000001},"relatedVulnerabilities":[{"id":"CVE-2023-52586","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52586","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/14f109bf74dd67e1d0469fed859c8e506b0df53f","https://git.kernel.org/stable/c/45284ff733e4caf6c118aae5131eb7e7cf3eea5a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: Add mutex lock in control vblank irq\n\nAdd a mutex lock to control vblank irq to synchronize vblank\nenable/disable operations happening from different threads to prevent\nrace conditions while registering/unregistering the vblank irq callback.\n\nv4: -Removed vblank_ctl_lock from dpu_encoder_virt, so it is only a\n    parameter of dpu_encoder_phys.\n    -Switch from atomic refcnt to a simple int counter as mutex has\n    now been added\nv3: Mistakenly did not change wording in last version. It is done now.\nv2: Slightly changed wording of commit message\n\nPatchwork: https://patchwork.freedesktop.org/patch/571854/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52586","epss":0.00161,"percentile":0.05596,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52586","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52586","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52590","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52590","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ocfs2: Avoid touching renamed directory if parent does not change  The VFS will not be locking moved directory if its parent does not change. Change ocfs2 rename code to avoid touching renamed directory if its parent does not change as without locking that can corrupt the filesystem.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52590","epss":0.00169,"percentile":0.06517,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52590","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08872500000000001},"relatedVulnerabilities":[{"id":"CVE-2023-52590","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52590","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/9d618d19b29c2943527e3a43da0a35aea91062fc","https://git.kernel.org/stable/c/de940cede3c41624e2de27f805b490999f419df9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: Avoid touching renamed directory if parent does not change\n\nThe VFS will not be locking moved directory if its parent does not\nchange. Change ocfs2 rename code to avoid touching renamed directory if\nits parent does not change as without locking that can corrupt the\nfilesystem.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52590","epss":0.00169,"percentile":0.06517,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52590","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52590","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52591","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52591","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  reiserfs: Avoid touching renamed directory if parent does not change  The VFS will not be locking moved directory if its parent does not change. Change reiserfs rename code to avoid touching renamed directory if its parent does not change as without locking that can corrupt the filesystem.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52591","epss":0.0024,"percentile":0.15015,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18359999999999999},"relatedVulnerabilities":[{"id":"CVE-2023-52591","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52591","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/17e1361cb91dc1325834da95d2ab532959d2debc","https://git.kernel.org/stable/c/49db9b1b86a82448dfaf3fcfefcf678dee56c8ed","https://git.kernel.org/stable/c/c04c162f82ac403917780eb6d1654694455d4e7c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nreiserfs: Avoid touching renamed directory if parent does not change\n\nThe VFS will not be locking moved directory if its parent does not\nchange. Change reiserfs rename code to avoid touching renamed directory\nif its parent does not change as without locking that can corrupt the\nfilesystem.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52591","epss":0.0024,"percentile":0.15015,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52591","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52624","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52624","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Wake DMCUB before executing GPINT commands  [Why] DMCUB can be in idle when we attempt to interface with the HW through the GPINT mailbox resulting in a system hang.  [How] Add dc_wake_and_execute_gpint() to wrap the wake, execute, sleep sequence.  If the GPINT executes successfully then DMCUB will be put back into sleep after the optional response is returned.  It functions similar to the inbox command interface.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52624","epss":0.00368,"percentile":0.30063,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52624","cwe":"CWE-77","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28152000000000005},"relatedVulnerabilities":[{"id":"CVE-2023-52624","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52624","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2ef98c6d753a744e333b7e34b9cf687040fba57d","https://git.kernel.org/stable/c/e5ffd1263dd5b44929c676171802e7b6af483f21"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Wake DMCUB before executing GPINT commands\n\n[Why]\nDMCUB can be in idle when we attempt to interface with the HW through\nthe GPINT mailbox resulting in a system hang.\n\n[How]\nAdd dc_wake_and_execute_gpint() to wrap the wake, execute, sleep\nsequence.\n\nIf the GPINT executes successfully then DMCUB will be put back into\nsleep after the optional response is returned.\n\nIt functions similar to the inbox command interface.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52624","epss":0.00368,"percentile":0.30063,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52624","cwe":"CWE-77","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52624","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52625","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52625","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Refactor DMCUB enter/exit idle interface  [Why] We can hang in place trying to send commands when the DMCUB isn't powered on.  [How] We need to exit out of the idle state prior to sending a command, but the process that performs the exit also invokes a command itself.  Fixing this issue involves the following:  1. Using a software state to track whether or not we need to start    the process to exit idle or notify idle.  It's possible for the hardware to have exited an idle state without driver knowledge, but entering one is always restricted to a driver allow - which makes the SW state vs HW state mismatch issue purely one of optimization, which should seldomly be hit, if at all.  2. Refactor any instances of exit/notify idle to use a single wrapper    that maintains this SW state.  This works simialr to dc_allow_idle_optimizations, but works at the DMCUB level and makes sure the state is marked prior to any notify/exit idle so we don't enter an infinite loop.  3. Make sure we exit out of idle prior to sending any commands or    waiting for DMCUB idle.  This patch takes care of 1/2. A future patch will take care of wrapping DMCUB command submission with calls to this new interface.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52625","epss":0.002,"percentile":0.0997,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10500000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-52625","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52625","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/820c3870c491946a78950cdf961bf40e28c1025f","https://git.kernel.org/stable/c/8e57c06bf4b0f51a4d6958e15e1a99c9520d00fa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Refactor DMCUB enter/exit idle interface\n\n[Why]\nWe can hang in place trying to send commands when the DMCUB isn't\npowered on.\n\n[How]\nWe need to exit out of the idle state prior to sending a command,\nbut the process that performs the exit also invokes a command itself.\n\nFixing this issue involves the following:\n\n1. Using a software state to track whether or not we need to start\n   the process to exit idle or notify idle.\n\nIt's possible for the hardware to have exited an idle state without\ndriver knowledge, but entering one is always restricted to a driver\nallow - which makes the SW state vs HW state mismatch issue purely one\nof optimization, which should seldomly be hit, if at all.\n\n2. Refactor any instances of exit/notify idle to use a single wrapper\n   that maintains this SW state.\n\nThis works simialr to dc_allow_idle_optimizations, but works at the\nDMCUB level and makes sure the state is marked prior to any notify/exit\nidle so we don't enter an infinite loop.\n\n3. Make sure we exit out of idle prior to sending any commands or\n   waiting for DMCUB idle.\n\nThis patch takes care of 1/2. A future patch will take care of wrapping\nDMCUB command submission with calls to this new interface.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52625","epss":0.002,"percentile":0.0997,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52625","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52629","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52629","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sh: push-switch: Reorder cleanup operations to avoid use-after-free bug  The original code puts flush_work() before timer_shutdown_sync() in switch_drv_remove(). Although we use flush_work() to stop the worker, it could be rescheduled in switch_timer(). As a result, a use-after-free bug can occur. The details are shown below:        (cpu 0)                    |      (cpu 1) switch_drv_remove()              |  flush_work()                    |   ...                            |  switch_timer // timer                                  |   schedule_work(&psw->work)  timer_shutdown_sync()           |  ...                             |  switch_work_handler // worker  kfree(psw) // free              |                                  |   psw->state = 0 // use  This patch puts timer_shutdown_sync() before flush_work() to mitigate the bugs. As a result, the worker and timer will be stopped safely before the deallocate operations.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52629","epss":0.00242,"percentile":0.15311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52629","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19238999999999998},"relatedVulnerabilities":[{"id":"CVE-2023-52629","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52629","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/246f80a0b17f8f582b2c0996db02998239057c65","https://git.kernel.org/stable/c/610dbd8ac271aa36080aac50b928d700ee3fe4de"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsh: push-switch: Reorder cleanup operations to avoid use-after-free bug\n\nThe original code puts flush_work() before timer_shutdown_sync()\nin switch_drv_remove(). Although we use flush_work() to stop\nthe worker, it could be rescheduled in switch_timer(). As a result,\na use-after-free bug can occur. The details are shown below:\n\n      (cpu 0)                    |      (cpu 1)\nswitch_drv_remove()              |\n flush_work()                    |\n  ...                            |  switch_timer // timer\n                                 |   schedule_work(&psw->work)\n timer_shutdown_sync()           |\n ...                             |  switch_work_handler // worker\n kfree(psw) // free              |\n                                 |   psw->state = 0 // use\n\nThis patch puts timer_shutdown_sync() before flush_work() to\nmitigate the bugs. As a result, the worker and timer will be\nstopped safely before the deallocate operations.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52629","epss":0.00242,"percentile":0.15311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52629","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52629","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52648","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vmwgfx: Unmap the surface before resetting it on a plane state  Switch to a new plane state requires unreferencing of all held surfaces. In the work required for mob cursors the mapped surfaces started being cached but the variable indicating whether the surface is currently mapped was not being reset. This leads to crashes as the duplicated state, incorrectly, indicates the that surface is mapped even when no surface is present. That's because after unreferencing the surface it's perfectly possible for the plane to be backed by a bo instead of a surface.  Reset the surface mapped flag when unreferencing the plane state surface to fix null derefs in cleanup. Fixes crashes in KDE KWin 6.0 on Wayland:  Oops: 0000 [#1] PREEMPT SMP PTI CPU: 4 PID: 2533 Comm: kwin_wayland Not tainted 6.7.0-rc3-vmwgfx #2 Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 RIP: 0010:vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx] Code: 00 00 00 75 3a 48 83 c4 10 5b 5d c3 cc cc cc cc 48 8b b3 a8 00 00 00 48 c7 c7 99 90 43 c0 e8 93 c5 db ca 48 8b 83 a8 00 00 00 <48> 8b 78 28 e8 e3 f> RSP: 0018:ffffb6b98216fa80 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff969d84cdcb00 RCX: 0000000000000027 RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff969e75f21600 RBP: ffff969d4143dc50 R08: 0000000000000000 R09: ffffb6b98216f920 R10: 0000000000000003 R11: ffff969e7feb3b10 R12: 0000000000000000 R13: 0000000000000000 R14: 000000000000027b R15: ffff969d49c9fc00 FS:  00007f1e8f1b4180(0000) GS:ffff969e75f00000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000028 CR3: 0000000104006004 CR4: 00000000003706f0 Call Trace:  <TASK>  ? __die+0x23/0x70  ? page_fault_oops+0x171/0x4e0  ? exc_page_fault+0x7f/0x180  ? asm_exc_page_fault+0x26/0x30  ? vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx]  drm_atomic_helper_cleanup_planes+0x9b/0xc0  commit_tail+0xd1/0x130  drm_atomic_helper_commit+0x11a/0x140  drm_atomic_commit+0x97/0xd0  ? __pfx___drm_printfn_info+0x10/0x10  drm_atomic_helper_update_plane+0xf5/0x160  drm_mode_cursor_universal+0x10e/0x270  drm_mode_cursor_common+0x102/0x230  ? __pfx_drm_mode_cursor2_ioctl+0x10/0x10  drm_ioctl_kernel+0xb2/0x110  drm_ioctl+0x26d/0x4b0  ? __pfx_drm_mode_cursor2_ioctl+0x10/0x10  ? __pfx_drm_ioctl+0x10/0x10  vmw_generic_ioctl+0xa4/0x110 [vmwgfx]  __x64_sys_ioctl+0x94/0xd0  do_syscall_64+0x61/0xe0  ? __x64_sys_ioctl+0xaf/0xd0  ? syscall_exit_to_user_mode+0x2b/0x40  ? do_syscall_64+0x70/0xe0  ? __x64_sys_ioctl+0xaf/0xd0  ? syscall_exit_to_user_mode+0x2b/0x40  ? do_syscall_64+0x70/0xe0  ? exc_page_fault+0x7f/0x180  entry_SYSCALL_64_after_hwframe+0x6e/0x76 RIP: 0033:0x7f1e93f279ed Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff f> RSP: 002b:00007ffca0faf600 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 000055db876ed2c0 RCX: 00007f1e93f279ed RDX: 00007ffca0faf6c0 RSI: 00000000c02464bb RDI: 0000000000000015 RBP: 00007ffca0faf650 R08: 000055db87184010 R09: 0000000000000007 R10: 000055db886471a0 R11: 0000000000000246 R12: 00007ffca0faf6c0 R13: 00000000c02464bb R14: 0000000000000015 R15: 00007ffca0faf790  </TASK> Modules linked in: snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_ine> CR2: 0000000000000028 ---[ end trace 0000000000000000 ]--- RIP: 0010:vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx] Code: 00 00 00 75 3a 48 83 c4 10 5b 5d c3 cc cc cc cc 48 8b b3 a8 00 00 00 48 c7 c7 99 90 43 c0 e8 93 c5 db ca 48 8b 83 a8 00 00 00 <48> 8b 78 28 e8 e3 f> RSP: 0018:ffffb6b98216fa80 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff969d84cdcb00 RCX: 0000000000000027 RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff969e75f21600 RBP: ffff969d4143 ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52648","epss":0.00225,"percentile":0.13151,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52648","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11812500000000001},"relatedVulnerabilities":[{"id":"CVE-2023-52648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52648","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0a23f95af7f28dae7c0f7c82578ca5e1a239d461","https://git.kernel.org/stable/c/105f72cc48c4c93f4578fcc61e06276471858e92","https://git.kernel.org/stable/c/27571c64f1855881753e6f33c3186573afbab7ba","https://git.kernel.org/stable/c/75baad63c033b3b900d822bffbc96c9d3649bc75"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Unmap the surface before resetting it on a plane state\n\nSwitch to a new plane state requires unreferencing of all held surfaces.\nIn the work required for mob cursors the mapped surfaces started being\ncached but the variable indicating whether the surface is currently\nmapped was not being reset. This leads to crashes as the duplicated\nstate, incorrectly, indicates the that surface is mapped even when\nno surface is present. That's because after unreferencing the surface\nit's perfectly possible for the plane to be backed by a bo instead of a\nsurface.\n\nReset the surface mapped flag when unreferencing the plane state surface\nto fix null derefs in cleanup. Fixes crashes in KDE KWin 6.0 on Wayland:\n\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 4 PID: 2533 Comm: kwin_wayland Not tainted 6.7.0-rc3-vmwgfx #2\nHardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020\nRIP: 0010:vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx]\nCode: 00 00 00 75 3a 48 83 c4 10 5b 5d c3 cc cc cc cc 48 8b b3 a8 00 00 00 48 c7 c7 99 90 43 c0 e8 93 c5 db ca 48 8b 83 a8 00 00 00 <48> 8b 78 28 e8 e3 f>\nRSP: 0018:ffffb6b98216fa80 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff969d84cdcb00 RCX: 0000000000000027\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff969e75f21600\nRBP: ffff969d4143dc50 R08: 0000000000000000 R09: ffffb6b98216f920\nR10: 0000000000000003 R11: ffff969e7feb3b10 R12: 0000000000000000\nR13: 0000000000000000 R14: 000000000000027b R15: ffff969d49c9fc00\nFS:  00007f1e8f1b4180(0000) GS:ffff969e75f00000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000028 CR3: 0000000104006004 CR4: 00000000003706f0\nCall Trace:\n <TASK>\n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? exc_page_fault+0x7f/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx]\n drm_atomic_helper_cleanup_planes+0x9b/0xc0\n commit_tail+0xd1/0x130\n drm_atomic_helper_commit+0x11a/0x140\n drm_atomic_commit+0x97/0xd0\n ? __pfx___drm_printfn_info+0x10/0x10\n drm_atomic_helper_update_plane+0xf5/0x160\n drm_mode_cursor_universal+0x10e/0x270\n drm_mode_cursor_common+0x102/0x230\n ? __pfx_drm_mode_cursor2_ioctl+0x10/0x10\n drm_ioctl_kernel+0xb2/0x110\n drm_ioctl+0x26d/0x4b0\n ? __pfx_drm_mode_cursor2_ioctl+0x10/0x10\n ? __pfx_drm_ioctl+0x10/0x10\n vmw_generic_ioctl+0xa4/0x110 [vmwgfx]\n __x64_sys_ioctl+0x94/0xd0\n do_syscall_64+0x61/0xe0\n ? __x64_sys_ioctl+0xaf/0xd0\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? do_syscall_64+0x70/0xe0\n ? __x64_sys_ioctl+0xaf/0xd0\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? do_syscall_64+0x70/0xe0\n ? exc_page_fault+0x7f/0x180\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\nRIP: 0033:0x7f1e93f279ed\nCode: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff f>\nRSP: 002b:00007ffca0faf600 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 000055db876ed2c0 RCX: 00007f1e93f279ed\nRDX: 00007ffca0faf6c0 RSI: 00000000c02464bb RDI: 0000000000000015\nRBP: 00007ffca0faf650 R08: 000055db87184010 R09: 0000000000000007\nR10: 000055db886471a0 R11: 0000000000000246 R12: 00007ffca0faf6c0\nR13: 00000000c02464bb R14: 0000000000000015 R15: 00007ffca0faf790\n </TASK>\nModules linked in: snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_ine>\nCR2: 0000000000000028\n---[ end trace 0000000000000000 ]---\nRIP: 0010:vmw_du_cursor_plane_cleanup_fb+0x124/0x140 [vmwgfx]\nCode: 00 00 00 75 3a 48 83 c4 10 5b 5d c3 cc cc cc cc 48 8b b3 a8 00 00 00 48 c7 c7 99 90 43 c0 e8 93 c5 db ca 48 8b 83 a8 00 00 00 <48> 8b 78 28 e8 e3 f>\nRSP: 0018:ffffb6b98216fa80 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff969d84cdcb00 RCX: 0000000000000027\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff969e75f21600\nRBP: ffff969d4143\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52648","epss":0.00225,"percentile":0.13151,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52648","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52653","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52653","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  SUNRPC: fix a memleak in gss_import_v2_context  The ctx->mech_used.data allocated by kmemdup is not freed in neither gss_import_v2_context nor it only caller gss_krb5_import_sec_context, which frees ctx on error.  Thus, this patch reform the last call of gss_import_v2_context to the gss_krb5_import_ctx_v2, preventing the memleak while keepping the return formation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52653","epss":0.00275,"percentile":0.19688,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52653","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.144375},"relatedVulnerabilities":[{"id":"CVE-2023-52653","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52653","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/47ac11db93e74ac49cd6c3fc69bcbc5964c4a8b4","https://git.kernel.org/stable/c/99044c01ed5329e73651c054d8a4baacdbb1a27c","https://git.kernel.org/stable/c/d111e30d9cd846bb368faf3637dc0f71fcbcf822","https://git.kernel.org/stable/c/e67b652d8e8591d3b1e569dbcdfcee15993e91fa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix a memleak in gss_import_v2_context\n\nThe ctx->mech_used.data allocated by kmemdup is not freed in neither\ngss_import_v2_context nor it only caller gss_krb5_import_sec_context,\nwhich frees ctx on error.\n\nThus, this patch reform the last call of gss_import_v2_context to the\ngss_krb5_import_ctx_v2, preventing the memleak while keepping the return\nformation.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52653","epss":0.00275,"percentile":0.19688,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52653","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52653","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52671","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52671","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix hang/underflow when transitioning to ODM4:1  [Why] Under some circumstances, disabling an OPTC and attempting to reclaim its OPP(s) for a different OPTC could cause a hang/underflow due to OPPs not being properly disconnected from the disabled OPTC.  [How] Ensure that all OPPs are unassigned from an OPTC when it gets disabled.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52671","epss":0.00222,"percentile":0.12734,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11655000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-52671","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52671","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4b6b479b2da6badff099b2e3abf0248936eefbf5","https://git.kernel.org/stable/c/ae62f1dde66a6f0eee98defc4c7a346bd5acd239","https://git.kernel.org/stable/c/e7b2b108cdeab76a7e7324459e50b0c1214c0386"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix hang/underflow when transitioning to ODM4:1\n\n[Why]\nUnder some circumstances, disabling an OPTC and attempting to reclaim\nits OPP(s) for a different OPTC could cause a hang/underflow due to OPPs\nnot being properly disconnected from the disabled OPTC.\n\n[How]\nEnsure that all OPPs are unassigned from an OPTC when it gets disabled.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52671","epss":0.00222,"percentile":0.12734,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52671","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52676","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52676","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Guard stack limits against 32bit overflow  This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current 32bit. The arithmetic implies adding together a 64-bit register with a int offset. The register was checked to be below 1<<29 when it was variable, but not when it was fixed. The offset either comes from an instruction (in which case it is 16 bit), from another register (in which case the caller checked it to be below 1<<29 [1]), or from the size of an argument to a kfunc (in which case it can be a u32 [2]). Between the register being inconsistently checked to be below 1<<29, and the offset being up to an u32, it appears that we were open to overflowing the `int`s which were currently used for arithmetic.  [1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498 [2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52676","epss":0.00236,"percentile":0.14564,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52676","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12390000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-52676","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52676","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1d38a9ee81570c4bd61f557832dead4d6f816760","https://git.kernel.org/stable/c/ad140fc856f0b1d5e2215bcb6d0cc247a86805a2","https://git.kernel.org/stable/c/e5ad9ecb84405637df82732ee02ad741a5f782a6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard stack limits against 32bit overflow\n\nThis patch promotes the arithmetic around checking stack bounds to be\ndone in the 64-bit domain, instead of the current 32bit. The arithmetic\nimplies adding together a 64-bit register with a int offset. The\nregister was checked to be below 1<<29 when it was variable, but not\nwhen it was fixed. The offset either comes from an instruction (in which\ncase it is 16 bit), from another register (in which case the caller\nchecked it to be below 1<<29 [1]), or from the size of an argument to a\nkfunc (in which case it can be a u32 [2]). Between the register being\ninconsistently checked to be below 1<<29, and the offset being up to an\nu32, it appears that we were open to overflowing the `int`s which were\ncurrently used for arithmetic.\n\n[1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498\n[2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52676","epss":0.00236,"percentile":0.14564,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52676","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52676","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52751","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52751","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix use-after-free in smb2_query_info_compound()  The following UAF was triggered when running fstests generic/072 with KASAN enabled against Windows Server 2022 and mount options 'multichannel,max_channels=2,vers=3.1.1,mfsymlinks,noperm'    BUG: KASAN: slab-use-after-free in smb2_query_info_compound+0x423/0x6d0 [cifs]   Read of size 8 at addr ffff888014941048 by task xfs_io/27534    CPU: 0 PID: 27534 Comm: xfs_io Not tainted 6.6.0-rc7 #1   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS   rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014   Call Trace:    dump_stack_lvl+0x4a/0x80    print_report+0xcf/0x650    ? srso_alias_return_thunk+0x5/0x7f    ? srso_alias_return_thunk+0x5/0x7f    ? __phys_addr+0x46/0x90    kasan_report+0xda/0x110    ? smb2_query_info_compound+0x423/0x6d0 [cifs]    ? smb2_query_info_compound+0x423/0x6d0 [cifs]    smb2_query_info_compound+0x423/0x6d0 [cifs]    ? __pfx_smb2_query_info_compound+0x10/0x10 [cifs]    ? srso_alias_return_thunk+0x5/0x7f    ? __stack_depot_save+0x39/0x480    ? kasan_save_stack+0x33/0x60    ? kasan_set_track+0x25/0x30    ? ____kasan_slab_free+0x126/0x170    smb2_queryfs+0xc2/0x2c0 [cifs]    ? __pfx_smb2_queryfs+0x10/0x10 [cifs]    ? __pfx___lock_acquire+0x10/0x10    smb311_queryfs+0x210/0x220 [cifs]    ? __pfx_smb311_queryfs+0x10/0x10 [cifs]    ? srso_alias_return_thunk+0x5/0x7f    ? __lock_acquire+0x480/0x26c0    ? lock_release+0x1ed/0x640    ? srso_alias_return_thunk+0x5/0x7f    ? do_raw_spin_unlock+0x9b/0x100    cifs_statfs+0x18c/0x4b0 [cifs]    statfs_by_dentry+0x9b/0xf0    fd_statfs+0x4e/0xb0    __do_sys_fstatfs+0x7f/0xe0    ? __pfx___do_sys_fstatfs+0x10/0x10    ? srso_alias_return_thunk+0x5/0x7f    ? lockdep_hardirqs_on_prepare+0x136/0x200    ? srso_alias_return_thunk+0x5/0x7f    do_syscall_64+0x3f/0x90    entry_SYSCALL_64_after_hwframe+0x6e/0xd8    Allocated by task 27534:    kasan_save_stack+0x33/0x60    kasan_set_track+0x25/0x30    __kasan_kmalloc+0x8f/0xa0    open_cached_dir+0x71b/0x1240 [cifs]    smb2_query_info_compound+0x5c3/0x6d0 [cifs]    smb2_queryfs+0xc2/0x2c0 [cifs]    smb311_queryfs+0x210/0x220 [cifs]    cifs_statfs+0x18c/0x4b0 [cifs]    statfs_by_dentry+0x9b/0xf0    fd_statfs+0x4e/0xb0    __do_sys_fstatfs+0x7f/0xe0    do_syscall_64+0x3f/0x90    entry_SYSCALL_64_after_hwframe+0x6e/0xd8    Freed by task 27534:    kasan_save_stack+0x33/0x60    kasan_set_track+0x25/0x30    kasan_save_free_info+0x2b/0x50    ____kasan_slab_free+0x126/0x170    slab_free_freelist_hook+0xd0/0x1e0    __kmem_cache_free+0x9d/0x1b0    open_cached_dir+0xff5/0x1240 [cifs]    smb2_query_info_compound+0x5c3/0x6d0 [cifs]    smb2_queryfs+0xc2/0x2c0 [cifs]  This is a race between open_cached_dir() and cached_dir_lease_break() where the cache entry for the open directory handle receives a lease break while creating it.  And before returning from open_cached_dir(), we put the last reference of the new @cfid because of !@cfid->has_lease.  Besides the UAF, while running xfstests a lot of missed lease breaks have been noticed in tests that run several concurrent statfs(2) calls on those cached fids    CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame...   CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1...   CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 00000000715bfe83 len 108   CIFS: VFS: Dump pending requests:   CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame...   CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1...   CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 000000005aa7316e len 108   ...  To fix both, in open_cached_dir() ensure that @cfid->has_lease is set right before sending out compounded request so that any potential lease break will be get processed by demultiplex thread while we're still caching @cfid.  And, if open failed for some reason, re-check @cfid->has_lease to decide whether or not put lease reference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52751","epss":0.00241,"percentile":0.15225,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52751","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18436499999999997},"relatedVulnerabilities":[{"id":"CVE-2023-52751","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52751","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5c86919455c1edec99ebd3338ad213b59271a71b","https://git.kernel.org/stable/c/6db94d08359c43f2c8fe372811cdee04564a41b9","https://git.kernel.org/stable/c/93877b9afc2994c89362007aac480a7b150f386f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in smb2_query_info_compound()\n\nThe following UAF was triggered when running fstests generic/072 with\nKASAN enabled against Windows Server 2022 and mount options\n'multichannel,max_channels=2,vers=3.1.1,mfsymlinks,noperm'\n\n  BUG: KASAN: slab-use-after-free in smb2_query_info_compound+0x423/0x6d0 [cifs]\n  Read of size 8 at addr ffff888014941048 by task xfs_io/27534\n\n  CPU: 0 PID: 27534 Comm: xfs_io Not tainted 6.6.0-rc7 #1\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS\n  rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014\n  Call Trace:\n   dump_stack_lvl+0x4a/0x80\n   print_report+0xcf/0x650\n   ? srso_alias_return_thunk+0x5/0x7f\n   ? srso_alias_return_thunk+0x5/0x7f\n   ? __phys_addr+0x46/0x90\n   kasan_report+0xda/0x110\n   ? smb2_query_info_compound+0x423/0x6d0 [cifs]\n   ? smb2_query_info_compound+0x423/0x6d0 [cifs]\n   smb2_query_info_compound+0x423/0x6d0 [cifs]\n   ? __pfx_smb2_query_info_compound+0x10/0x10 [cifs]\n   ? srso_alias_return_thunk+0x5/0x7f\n   ? __stack_depot_save+0x39/0x480\n   ? kasan_save_stack+0x33/0x60\n   ? kasan_set_track+0x25/0x30\n   ? ____kasan_slab_free+0x126/0x170\n   smb2_queryfs+0xc2/0x2c0 [cifs]\n   ? __pfx_smb2_queryfs+0x10/0x10 [cifs]\n   ? __pfx___lock_acquire+0x10/0x10\n   smb311_queryfs+0x210/0x220 [cifs]\n   ? __pfx_smb311_queryfs+0x10/0x10 [cifs]\n   ? srso_alias_return_thunk+0x5/0x7f\n   ? __lock_acquire+0x480/0x26c0\n   ? lock_release+0x1ed/0x640\n   ? srso_alias_return_thunk+0x5/0x7f\n   ? do_raw_spin_unlock+0x9b/0x100\n   cifs_statfs+0x18c/0x4b0 [cifs]\n   statfs_by_dentry+0x9b/0xf0\n   fd_statfs+0x4e/0xb0\n   __do_sys_fstatfs+0x7f/0xe0\n   ? __pfx___do_sys_fstatfs+0x10/0x10\n   ? srso_alias_return_thunk+0x5/0x7f\n   ? lockdep_hardirqs_on_prepare+0x136/0x200\n   ? srso_alias_return_thunk+0x5/0x7f\n   do_syscall_64+0x3f/0x90\n   entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n  Allocated by task 27534:\n   kasan_save_stack+0x33/0x60\n   kasan_set_track+0x25/0x30\n   __kasan_kmalloc+0x8f/0xa0\n   open_cached_dir+0x71b/0x1240 [cifs]\n   smb2_query_info_compound+0x5c3/0x6d0 [cifs]\n   smb2_queryfs+0xc2/0x2c0 [cifs]\n   smb311_queryfs+0x210/0x220 [cifs]\n   cifs_statfs+0x18c/0x4b0 [cifs]\n   statfs_by_dentry+0x9b/0xf0\n   fd_statfs+0x4e/0xb0\n   __do_sys_fstatfs+0x7f/0xe0\n   do_syscall_64+0x3f/0x90\n   entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n  Freed by task 27534:\n   kasan_save_stack+0x33/0x60\n   kasan_set_track+0x25/0x30\n   kasan_save_free_info+0x2b/0x50\n   ____kasan_slab_free+0x126/0x170\n   slab_free_freelist_hook+0xd0/0x1e0\n   __kmem_cache_free+0x9d/0x1b0\n   open_cached_dir+0xff5/0x1240 [cifs]\n   smb2_query_info_compound+0x5c3/0x6d0 [cifs]\n   smb2_queryfs+0xc2/0x2c0 [cifs]\n\nThis is a race between open_cached_dir() and cached_dir_lease_break()\nwhere the cache entry for the open directory handle receives a lease\nbreak while creating it.  And before returning from open_cached_dir(),\nwe put the last reference of the new @cfid because of\n!@cfid->has_lease.\n\nBesides the UAF, while running xfstests a lot of missed lease breaks\nhave been noticed in tests that run several concurrent statfs(2) calls\non those cached fids\n\n  CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame...\n  CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1...\n  CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 00000000715bfe83 len 108\n  CIFS: VFS: Dump pending requests:\n  CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame...\n  CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1...\n  CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 000000005aa7316e len 108\n  ...\n\nTo fix both, in open_cached_dir() ensure that @cfid->has_lease is set\nright before sending out compounded request so that any potential\nlease break will be get processed by demultiplex thread while we're\nstill caching @cfid.  And, if open failed for some reason, re-check\n@cfid->has_lease to decide whether or not put lease reference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52751","epss":0.00241,"percentile":0.15225,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52751","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52751","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52761","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52761","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  riscv: VMAP_STACK overflow detection thread-safe  commit 31da94c25aea (\"riscv: add VMAP_STACK overflow detection\") added support for CONFIG_VMAP_STACK. If overflow is detected, CPU switches to `shadow_stack` temporarily before switching finally to per-cpu `overflow_stack`.  If two CPUs/harts are racing and end up in over flowing kernel stack, one or both will end up corrupting each other state because `shadow_stack` is not per-cpu. This patch optimizes per-cpu overflow stack switch by directly picking per-cpu `overflow_stack` and gets rid of `shadow_stack`.  Following are the changes in this patch   - Defines an asm macro to obtain per-cpu symbols in destination    register.  - In entry.S, when overflow is detected, per-cpu overflow stack is    located using per-cpu asm macro. Computing per-cpu symbol requires    a temporary register. x31 is saved away into CSR_SCRATCH    (CSR_SCRATCH is anyways zero since we're in kernel).  Please see Links for additional relevant disccussion and alternative solution.  Tested by `echo EXHAUST_STACK > /sys/kernel/debug/provoke-crash/DIRECT` Kernel crash log below   Insufficient stack space to handle exception!/debug/provoke-crash/DIRECT  Task stack:     [0xff20000010a98000..0xff20000010a9c000]  Overflow stack: [0xff600001f7d98370..0xff600001f7d99370]  CPU: 1 PID: 205 Comm: bash Not tainted 6.1.0-rc2-00001-g328a1f96f7b9 #34  Hardware name: riscv-virtio,qemu (DT)  epc : __memset+0x60/0xfc   ra : recursive_loop+0x48/0xc6 [lkdtm]  epc : ffffffff808de0e4 ra : ffffffff0163a752 sp : ff20000010a97e80   gp : ffffffff815c0330 tp : ff600000820ea280 t0 : ff20000010a97e88   t1 : 000000000000002e t2 : 3233206874706564 s0 : ff20000010a982b0   s1 : 0000000000000012 a0 : ff20000010a97e88 a1 : 0000000000000000   a2 : 0000000000000400 a3 : ff20000010a98288 a4 : 0000000000000000   a5 : 0000000000000000 a6 : fffffffffffe43f0 a7 : 00007fffffffffff   s2 : ff20000010a97e88 s3 : ffffffff01644680 s4 : ff20000010a9be90   s5 : ff600000842ba6c0 s6 : 00aaaaaac29e42b0 s7 : 00fffffff0aa3684   s8 : 00aaaaaac2978040 s9 : 0000000000000065 s10: 00ffffff8a7cad10   s11: 00ffffff8a76a4e0 t3 : ffffffff815dbaf4 t4 : ffffffff815dbaf4   t5 : ffffffff815dbab8 t6 : ff20000010a9bb48  status: 0000000200000120 badaddr: ff20000010a97e88 cause: 000000000000000f  Kernel panic - not syncing: Kernel stack overflow  CPU: 1 PID: 205 Comm: bash Not tainted 6.1.0-rc2-00001-g328a1f96f7b9 #34  Hardware name: riscv-virtio,qemu (DT)  Call Trace:  [<ffffffff80006754>] dump_backtrace+0x30/0x38  [<ffffffff808de798>] show_stack+0x40/0x4c  [<ffffffff808ea2a8>] dump_stack_lvl+0x44/0x5c  [<ffffffff808ea2d8>] dump_stack+0x18/0x20  [<ffffffff808dec06>] panic+0x126/0x2fe  [<ffffffff800065ea>] walk_stackframe+0x0/0xf0  [<ffffffff0163a752>] recursive_loop+0x48/0xc6 [lkdtm]  SMP: stopping secondary CPUs  ---[ end Kernel panic - not syncing: Kernel stack overflow ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52761","epss":0.00267,"percentile":0.18719,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52761","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.140175},"relatedVulnerabilities":[{"id":"CVE-2023-52761","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52761","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1493baaf09e3c1899959c8a107cd1207e16d1788","https://git.kernel.org/stable/c/be97d0db5f44c0674480cb79ac6f5b0529b84c76","https://git.kernel.org/stable/c/eff53aea3855f71992c043cebb1c00988c17ee20"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: VMAP_STACK overflow detection thread-safe\n\ncommit 31da94c25aea (\"riscv: add VMAP_STACK overflow detection\") added\nsupport for CONFIG_VMAP_STACK. If overflow is detected, CPU switches to\n`shadow_stack` temporarily before switching finally to per-cpu\n`overflow_stack`.\n\nIf two CPUs/harts are racing and end up in over flowing kernel stack, one\nor both will end up corrupting each other state because `shadow_stack` is\nnot per-cpu. This patch optimizes per-cpu overflow stack switch by\ndirectly picking per-cpu `overflow_stack` and gets rid of `shadow_stack`.\n\nFollowing are the changes in this patch\n\n - Defines an asm macro to obtain per-cpu symbols in destination\n   register.\n - In entry.S, when overflow is detected, per-cpu overflow stack is\n   located using per-cpu asm macro. Computing per-cpu symbol requires\n   a temporary register. x31 is saved away into CSR_SCRATCH\n   (CSR_SCRATCH is anyways zero since we're in kernel).\n\nPlease see Links for additional relevant disccussion and alternative\nsolution.\n\nTested by `echo EXHAUST_STACK > /sys/kernel/debug/provoke-crash/DIRECT`\nKernel crash log below\n\n Insufficient stack space to handle exception!/debug/provoke-crash/DIRECT\n Task stack:     [0xff20000010a98000..0xff20000010a9c000]\n Overflow stack: [0xff600001f7d98370..0xff600001f7d99370]\n CPU: 1 PID: 205 Comm: bash Not tainted 6.1.0-rc2-00001-g328a1f96f7b9 #34\n Hardware name: riscv-virtio,qemu (DT)\n epc : __memset+0x60/0xfc\n  ra : recursive_loop+0x48/0xc6 [lkdtm]\n epc : ffffffff808de0e4 ra : ffffffff0163a752 sp : ff20000010a97e80\n  gp : ffffffff815c0330 tp : ff600000820ea280 t0 : ff20000010a97e88\n  t1 : 000000000000002e t2 : 3233206874706564 s0 : ff20000010a982b0\n  s1 : 0000000000000012 a0 : ff20000010a97e88 a1 : 0000000000000000\n  a2 : 0000000000000400 a3 : ff20000010a98288 a4 : 0000000000000000\n  a5 : 0000000000000000 a6 : fffffffffffe43f0 a7 : 00007fffffffffff\n  s2 : ff20000010a97e88 s3 : ffffffff01644680 s4 : ff20000010a9be90\n  s5 : ff600000842ba6c0 s6 : 00aaaaaac29e42b0 s7 : 00fffffff0aa3684\n  s8 : 00aaaaaac2978040 s9 : 0000000000000065 s10: 00ffffff8a7cad10\n  s11: 00ffffff8a76a4e0 t3 : ffffffff815dbaf4 t4 : ffffffff815dbaf4\n  t5 : ffffffff815dbab8 t6 : ff20000010a9bb48\n status: 0000000200000120 badaddr: ff20000010a97e88 cause: 000000000000000f\n Kernel panic - not syncing: Kernel stack overflow\n CPU: 1 PID: 205 Comm: bash Not tainted 6.1.0-rc2-00001-g328a1f96f7b9 #34\n Hardware name: riscv-virtio,qemu (DT)\n Call Trace:\n [<ffffffff80006754>] dump_backtrace+0x30/0x38\n [<ffffffff808de798>] show_stack+0x40/0x4c\n [<ffffffff808ea2a8>] dump_stack_lvl+0x44/0x5c\n [<ffffffff808ea2d8>] dump_stack+0x18/0x20\n [<ffffffff808dec06>] panic+0x126/0x2fe\n [<ffffffff800065ea>] walk_stackframe+0x0/0xf0\n [<ffffffff0163a752>] recursive_loop+0x48/0xc6 [lkdtm]\n SMP: stopping secondary CPUs\n ---[ end Kernel panic - not syncing: Kernel stack overflow ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52761","epss":0.00267,"percentile":0.18719,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52761","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52761","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52770","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52770","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: split initial and dynamic conditions for extent_cache  Let's allocate the extent_cache tree without dynamic conditions to avoid a missing condition causing a panic as below.   # create a file w/ a compressed flag  # disable the compression  # panic while updating extent_cache  F2FS-fs (dm-64): Swapfile: last extent is not aligned to section F2FS-fs (dm-64): Swapfile (3) is not align to section: 1) creat(), 2) ioctl(F2FS_IOC_SET_PIN_FILE), 3) fallocate(2097152 * N) Adding 124996k swap on ./swap-file.  Priority:0 extents:2 across:17179494468k ================================================================== BUG: KASAN: null-ptr-deref in instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline] BUG: KASAN: null-ptr-deref in atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline] BUG: KASAN: null-ptr-deref in queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline] BUG: KASAN: null-ptr-deref in __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline] BUG: KASAN: null-ptr-deref in _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295 Write of size 4 at addr 0000000000000030 by task syz-executor154/3327  CPU: 0 PID: 3327 Comm: syz-executor154 Tainted: G           O      5.10.185 #1 Hardware name: emulation qemu-x86/qemu-x86, BIOS 2023.01-21885-gb3cc1cd24d 01/01/2023 Call Trace:  __dump_stack out/common/lib/dump_stack.c:77 [inline]  dump_stack_lvl+0x17e/0x1c4 out/common/lib/dump_stack.c:118  __kasan_report+0x16c/0x260 out/common/mm/kasan/report.c:415  kasan_report+0x51/0x70 out/common/mm/kasan/report.c:428  kasan_check_range+0x2f3/0x340 out/common/mm/kasan/generic.c:186  __kasan_check_write+0x14/0x20 out/common/mm/kasan/shadow.c:37  instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline]  atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline]  queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline]  __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline]  _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295  __drop_extent_tree+0xdf/0x2f0 out/common/fs/f2fs/extent_cache.c:1155  f2fs_drop_extent_tree+0x17/0x30 out/common/fs/f2fs/extent_cache.c:1172  f2fs_insert_range out/common/fs/f2fs/file.c:1600 [inline]  f2fs_fallocate+0x19fd/0x1f40 out/common/fs/f2fs/file.c:1764  vfs_fallocate+0x514/0x9b0 out/common/fs/open.c:310  ksys_fallocate out/common/fs/open.c:333 [inline]  __do_sys_fallocate out/common/fs/open.c:341 [inline]  __se_sys_fallocate out/common/fs/open.c:339 [inline]  __x64_sys_fallocate+0xb8/0x100 out/common/fs/open.c:339  do_syscall_64+0x35/0x50 out/common/arch/x86/entry/common.c:46","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52770","epss":0.00236,"percentile":0.14496,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52770","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12390000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-52770","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52770","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/9de787139b0258a5dd1f498780c26d76b61d2958","https://git.kernel.org/stable/c/d83309e7e006cee8afca83523559017c824fbf7a","https://git.kernel.org/stable/c/f803982190f0265fd36cf84670aa6daefc2b0768"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: split initial and dynamic conditions for extent_cache\n\nLet's allocate the extent_cache tree without dynamic conditions to avoid a\nmissing condition causing a panic as below.\n\n # create a file w/ a compressed flag\n # disable the compression\n # panic while updating extent_cache\n\nF2FS-fs (dm-64): Swapfile: last extent is not aligned to section\nF2FS-fs (dm-64): Swapfile (3) is not align to section: 1) creat(), 2) ioctl(F2FS_IOC_SET_PIN_FILE), 3) fallocate(2097152 * N)\nAdding 124996k swap on ./swap-file.  Priority:0 extents:2 across:17179494468k\n==================================================================\nBUG: KASAN: null-ptr-deref in instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline]\nBUG: KASAN: null-ptr-deref in atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline]\nBUG: KASAN: null-ptr-deref in queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline]\nBUG: KASAN: null-ptr-deref in __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline]\nBUG: KASAN: null-ptr-deref in _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295\nWrite of size 4 at addr 0000000000000030 by task syz-executor154/3327\n\nCPU: 0 PID: 3327 Comm: syz-executor154 Tainted: G           O      5.10.185 #1\nHardware name: emulation qemu-x86/qemu-x86, BIOS 2023.01-21885-gb3cc1cd24d 01/01/2023\nCall Trace:\n __dump_stack out/common/lib/dump_stack.c:77 [inline]\n dump_stack_lvl+0x17e/0x1c4 out/common/lib/dump_stack.c:118\n __kasan_report+0x16c/0x260 out/common/mm/kasan/report.c:415\n kasan_report+0x51/0x70 out/common/mm/kasan/report.c:428\n kasan_check_range+0x2f3/0x340 out/common/mm/kasan/generic.c:186\n __kasan_check_write+0x14/0x20 out/common/mm/kasan/shadow.c:37\n instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline]\n atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline]\n queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline]\n __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline]\n _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295\n __drop_extent_tree+0xdf/0x2f0 out/common/fs/f2fs/extent_cache.c:1155\n f2fs_drop_extent_tree+0x17/0x30 out/common/fs/f2fs/extent_cache.c:1172\n f2fs_insert_range out/common/fs/f2fs/file.c:1600 [inline]\n f2fs_fallocate+0x19fd/0x1f40 out/common/fs/f2fs/file.c:1764\n vfs_fallocate+0x514/0x9b0 out/common/fs/open.c:310\n ksys_fallocate out/common/fs/open.c:333 [inline]\n __do_sys_fallocate out/common/fs/open.c:341 [inline]\n __se_sys_fallocate out/common/fs/open.c:339 [inline]\n __x64_sys_fallocate+0xb8/0x100 out/common/fs/open.c:339\n do_syscall_64+0x35/0x50 out/common/arch/x86/entry/common.c:46","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52770","epss":0.00236,"percentile":0.14496,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52770","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52770","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52771","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52771","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cxl/port: Fix delete_endpoint() vs parent unregistration race  The CXL subsystem, at cxl_mem ->probe() time, establishes a lineage of ports (struct cxl_port objects) between an endpoint and the root of a CXL topology. Each port including the endpoint port is attached to the cxl_port driver.  Given that setup, it follows that when either any port in that lineage goes through a cxl_port ->remove() event, or the memdev goes through a cxl_mem ->remove() event. The hierarchy below the removed port, or the entire hierarchy if the memdev is removed needs to come down.  The delete_endpoint() callback is careful to check whether it is being called to tear down the hierarchy, or if it is only being called to teardown the memdev because an ancestor port is going through ->remove().  That care needs to take the device_lock() of the endpoint's parent. Which requires 2 bugs to be fixed:  1/ A reference on the parent is needed to prevent use-after-free    scenarios like this signature:      BUG: spinlock bad magic on CPU#0, kworker/u56:0/11     Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20230524-3.fc38 05/24/2023     Workqueue: cxl_port detach_memdev [cxl_core]     RIP: 0010:spin_bug+0x65/0xa0     Call Trace:       do_raw_spin_lock+0x69/0xa0      __mutex_lock+0x695/0xb80      delete_endpoint+0xad/0x150 [cxl_core]      devres_release_all+0xb8/0x110      device_unbind_cleanup+0xe/0x70      device_release_driver_internal+0x1d2/0x210      detach_memdev+0x15/0x20 [cxl_core]      process_one_work+0x1e3/0x4c0      worker_thread+0x1dd/0x3d0  2/ In the case of RCH topologies, the parent device that needs to be    locked is not always @port->dev as returned by cxl_mem_find_port(), use    endpoint->dev.parent instead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52771","epss":0.00182,"percentile":0.07874,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52771","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08826999999999999},"relatedVulnerabilities":[{"id":"CVE-2023-52771","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52771","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/37179fcc916bce8c3cc7b36d67ef814cce55142b","https://git.kernel.org/stable/c/6b2e428e673b3f55965674a426c40922e91388aa","https://git.kernel.org/stable/c/8d2ad999ca3c64cb08cf6a58d227b9d9e746d708"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/port: Fix delete_endpoint() vs parent unregistration race\n\nThe CXL subsystem, at cxl_mem ->probe() time, establishes a lineage of\nports (struct cxl_port objects) between an endpoint and the root of a\nCXL topology. Each port including the endpoint port is attached to the\ncxl_port driver.\n\nGiven that setup, it follows that when either any port in that lineage\ngoes through a cxl_port ->remove() event, or the memdev goes through a\ncxl_mem ->remove() event. The hierarchy below the removed port, or the\nentire hierarchy if the memdev is removed needs to come down.\n\nThe delete_endpoint() callback is careful to check whether it is being\ncalled to tear down the hierarchy, or if it is only being called to\nteardown the memdev because an ancestor port is going through\n->remove().\n\nThat care needs to take the device_lock() of the endpoint's parent.\nWhich requires 2 bugs to be fixed:\n\n1/ A reference on the parent is needed to prevent use-after-free\n   scenarios like this signature:\n\n    BUG: spinlock bad magic on CPU#0, kworker/u56:0/11\n    Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20230524-3.fc38 05/24/2023\n    Workqueue: cxl_port detach_memdev [cxl_core]\n    RIP: 0010:spin_bug+0x65/0xa0\n    Call Trace:\n      do_raw_spin_lock+0x69/0xa0\n     __mutex_lock+0x695/0xb80\n     delete_endpoint+0xad/0x150 [cxl_core]\n     devres_release_all+0xb8/0x110\n     device_unbind_cleanup+0xe/0x70\n     device_release_driver_internal+0x1d2/0x210\n     detach_memdev+0x15/0x20 [cxl_core]\n     process_one_work+0x1e3/0x4c0\n     worker_thread+0x1dd/0x3d0\n\n2/ In the case of RCH topologies, the parent device that needs to be\n   locked is not always @port->dev as returned by cxl_mem_find_port(), use\n   endpoint->dev.parent instead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52771","epss":0.00182,"percentile":0.07874,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52771","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52771","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52797","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52797","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drivers: perf: Check find_first_bit() return value  We must check the return value of find_first_bit() before using the return value as an index array since it happens to overflow the array and then panic:  [  107.318430] Kernel BUG [#1] [  107.319434] CPU: 3 PID: 1238 Comm: kill Tainted: G            E      6.6.0-rc6ubuntu-defconfig #2 [  107.319465] Hardware name: riscv-virtio,qemu (DT) [  107.319551] epc : pmu_sbi_ovf_handler+0x3a4/0x3ae [  107.319840]  ra : pmu_sbi_ovf_handler+0x52/0x3ae [  107.319868] epc : ffffffff80a0a77c ra : ffffffff80a0a42a sp : ffffaf83fecda350 [  107.319884]  gp : ffffffff823961a8 tp : ffffaf8083db1dc0 t0 : ffffaf83fecda480 [  107.319899]  t1 : ffffffff80cafe62 t2 : 000000000000ff00 s0 : ffffaf83fecda520 [  107.319921]  s1 : ffffaf83fecda380 a0 : 00000018fca29df0 a1 : ffffffffffffffff [  107.319936]  a2 : 0000000001073734 a3 : 0000000000000004 a4 : 0000000000000000 [  107.319951]  a5 : 0000000000000040 a6 : 000000001d1c8774 a7 : 0000000000504d55 [  107.319965]  s2 : ffffffff82451f10 s3 : ffffffff82724e70 s4 : 000000000000003f [  107.319980]  s5 : 0000000000000011 s6 : ffffaf8083db27c0 s7 : 0000000000000000 [  107.319995]  s8 : 0000000000000001 s9 : 00007fffb45d6558 s10: 00007fffb45d81a0 [  107.320009]  s11: ffffaf7ffff60000 t3 : 0000000000000004 t4 : 0000000000000000 [  107.320023]  t5 : ffffaf7f80000000 t6 : ffffaf8000000000 [  107.320037] status: 0000000200000100 badaddr: 0000000000000000 cause: 0000000000000003 [  107.320081] [<ffffffff80a0a77c>] pmu_sbi_ovf_handler+0x3a4/0x3ae [  107.320112] [<ffffffff800b42d0>] handle_percpu_devid_irq+0x9e/0x1a0 [  107.320131] [<ffffffff800ad92c>] generic_handle_domain_irq+0x28/0x36 [  107.320148] [<ffffffff8065f9f8>] riscv_intc_irq+0x36/0x4e [  107.320166] [<ffffffff80caf4a0>] handle_riscv_irq+0x54/0x86 [  107.320189] [<ffffffff80cb0036>] do_irq+0x64/0x96 [  107.320271] Code: 85a6 855e b097 ff7f 80e7 9220 b709 9002 4501 bbd9 (9002) 6097 [  107.320585] ---[ end trace 0000000000000000 ]--- [  107.320704] Kernel panic - not syncing: Fatal exception in interrupt [  107.320775] SMP: stopping secondary CPUs [  107.321219] Kernel Offset: 0x0 from 0xffffffff80000000 [  107.333051] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52797","epss":0.0028,"percentile":0.20347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52797","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.147},"relatedVulnerabilities":[{"id":"CVE-2023-52797","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52797","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2c86b24095fcf72cf51bc72d12e4350163b4e11d","https://git.kernel.org/stable/c/45a0de41ec383c8b7c6d442734ba3852dd2fc4a7","https://git.kernel.org/stable/c/c6e316ac05532febb0c966fa9b55f5258ed037be"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: perf: Check find_first_bit() return value\n\nWe must check the return value of find_first_bit() before using the\nreturn value as an index array since it happens to overflow the array\nand then panic:\n\n[  107.318430] Kernel BUG [#1]\n[  107.319434] CPU: 3 PID: 1238 Comm: kill Tainted: G            E      6.6.0-rc6ubuntu-defconfig #2\n[  107.319465] Hardware name: riscv-virtio,qemu (DT)\n[  107.319551] epc : pmu_sbi_ovf_handler+0x3a4/0x3ae\n[  107.319840]  ra : pmu_sbi_ovf_handler+0x52/0x3ae\n[  107.319868] epc : ffffffff80a0a77c ra : ffffffff80a0a42a sp : ffffaf83fecda350\n[  107.319884]  gp : ffffffff823961a8 tp : ffffaf8083db1dc0 t0 : ffffaf83fecda480\n[  107.319899]  t1 : ffffffff80cafe62 t2 : 000000000000ff00 s0 : ffffaf83fecda520\n[  107.319921]  s1 : ffffaf83fecda380 a0 : 00000018fca29df0 a1 : ffffffffffffffff\n[  107.319936]  a2 : 0000000001073734 a3 : 0000000000000004 a4 : 0000000000000000\n[  107.319951]  a5 : 0000000000000040 a6 : 000000001d1c8774 a7 : 0000000000504d55\n[  107.319965]  s2 : ffffffff82451f10 s3 : ffffffff82724e70 s4 : 000000000000003f\n[  107.319980]  s5 : 0000000000000011 s6 : ffffaf8083db27c0 s7 : 0000000000000000\n[  107.319995]  s8 : 0000000000000001 s9 : 00007fffb45d6558 s10: 00007fffb45d81a0\n[  107.320009]  s11: ffffaf7ffff60000 t3 : 0000000000000004 t4 : 0000000000000000\n[  107.320023]  t5 : ffffaf7f80000000 t6 : ffffaf8000000000\n[  107.320037] status: 0000000200000100 badaddr: 0000000000000000 cause: 0000000000000003\n[  107.320081] [<ffffffff80a0a77c>] pmu_sbi_ovf_handler+0x3a4/0x3ae\n[  107.320112] [<ffffffff800b42d0>] handle_percpu_devid_irq+0x9e/0x1a0\n[  107.320131] [<ffffffff800ad92c>] generic_handle_domain_irq+0x28/0x36\n[  107.320148] [<ffffffff8065f9f8>] riscv_intc_irq+0x36/0x4e\n[  107.320166] [<ffffffff80caf4a0>] handle_riscv_irq+0x54/0x86\n[  107.320189] [<ffffffff80cb0036>] do_irq+0x64/0x96\n[  107.320271] Code: 85a6 855e b097 ff7f 80e7 9220 b709 9002 4501 bbd9 (9002) 6097\n[  107.320585] ---[ end trace 0000000000000000 ]---\n[  107.320704] Kernel panic - not syncing: Fatal exception in interrupt\n[  107.320775] SMP: stopping secondary CPUs\n[  107.321219] Kernel Offset: 0x0 from 0xffffffff80000000\n[  107.333051] ---[ end Kernel panic - not syncing: Fatal exception in interrupt ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52797","epss":0.0028,"percentile":0.20347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52797","cwe":"CWE-252","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52797","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52888","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52888","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: mediatek: vcodec: Only free buffer VA that is not NULL  In the MediaTek vcodec driver, while mtk_vcodec_mem_free() is mostly called only when the buffer to free exists, there are some instances that didn't do the check and triggered warnings in practice.  We believe those checks were forgotten unintentionally. Add the checks back to fix the warnings.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52888","epss":0.00239,"percentile":0.14903,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52888","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12547500000000003},"relatedVulnerabilities":[{"id":"CVE-2023-52888","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52888","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/303d01082edaf817ee2df53a40dca9da637a2c04","https://git.kernel.org/stable/c/5c217253c76c94f76d1df31d0bbdcb88dc07be91","https://git.kernel.org/stable/c/eb005c801ec70ff4307727bd3bd6e8280169ef32"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: Only free buffer VA that is not NULL\n\nIn the MediaTek vcodec driver, while mtk_vcodec_mem_free() is mostly\ncalled only when the buffer to free exists, there are some instances\nthat didn't do the check and triggered warnings in practice.\n\nWe believe those checks were forgotten unintentionally. Add the checks\nback to fix the warnings.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52888","epss":0.00239,"percentile":0.14903,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52888","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52888","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-52920","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52920","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: support non-r10 register spill/fill to/from stack in precision tracking  Use instruction (jump) history to record instructions that performed register spill/fill to/from stack, regardless if this was done through read-only r10 register, or any other register after copying r10 into it *and* potentially adjusting offset.  To make this work reliably, we push extra per-instruction flags into instruction history, encoding stack slot index (spi) and stack frame number in extra 10 bit flags we take away from prev_idx in instruction history. We don't touch idx field for maximum performance, as it's checked most frequently during backtracking.  This change removes basically the last remaining practical limitation of precision backtracking logic in BPF verifier. It fixes known deficiencies, but also opens up new opportunities to reduce number of verified states, explored in the subsequent patches.  There are only three differences in selftests' BPF object files according to veristat, all in the positive direction (less states).  File                                    Program        Insns (A)  Insns (B)  Insns  (DIFF)  States (A)  States (B)  States (DIFF) --------------------------------------  -------------  ---------  ---------  -------------  ----------  ----------  ------------- test_cls_redirect_dynptr.bpf.linked3.o  cls_redirect        2987       2864  -123 (-4.12%)         240         231    -9 (-3.75%) xdp_synproxy_kern.bpf.linked3.o         syncookie_tc       82848      82661  -187 (-0.23%)        5107        5073   -34 (-0.67%) xdp_synproxy_kern.bpf.linked3.o         syncookie_xdp      85116      84964  -152 (-0.18%)        5162        5130   -32 (-0.62%)  Note, I avoided renaming jmp_history to more generic insn_hist to minimize number of lines changed and potential merge conflicts between bpf and bpf-next trees.  Notice also cur_hist_entry pointer reset to NULL at the beginning of instruction verification loop. This pointer avoids the problem of relying on last jump history entry's insn_idx to determine whether we already have entry for current instruction or not. It can happen that we added jump history entry because current instruction is_jmp_point(), but also we need to add instruction flags for stack access. In this case, we don't want to entries, so we need to reuse last added entry, if it is present.  Relying on insn_idx comparison has the same ambiguity problem as the one that was fixed recently in [0], so we avoid that.    [0] https://patchwork.kernel.org/project/netdevbpf/patch/20231110002638.4168352-3-andrii@kernel.org/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52920","epss":0.00254,"percentile":0.16904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52920","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13335},"relatedVulnerabilities":[{"id":"CVE-2023-52920","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52920","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/199f0452873741fa4b8d4d88958e929030b2f92b","https://git.kernel.org/stable/c/41f6f64e6999a837048b1bd13a2f8742964eca6b","https://git.kernel.org/stable/c/e4da60feca4d35e1a9b03dc0affa3354f9ff45e4","https://git.kernel.org/stable/c/ecc2aeeaa08a355d84d3ca9c3d2512399a194f29"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: support non-r10 register spill/fill to/from stack in precision tracking\n\nUse instruction (jump) history to record instructions that performed\nregister spill/fill to/from stack, regardless if this was done through\nread-only r10 register, or any other register after copying r10 into it\n*and* potentially adjusting offset.\n\nTo make this work reliably, we push extra per-instruction flags into\ninstruction history, encoding stack slot index (spi) and stack frame\nnumber in extra 10 bit flags we take away from prev_idx in instruction\nhistory. We don't touch idx field for maximum performance, as it's\nchecked most frequently during backtracking.\n\nThis change removes basically the last remaining practical limitation of\nprecision backtracking logic in BPF verifier. It fixes known\ndeficiencies, but also opens up new opportunities to reduce number of\nverified states, explored in the subsequent patches.\n\nThere are only three differences in selftests' BPF object files\naccording to veristat, all in the positive direction (less states).\n\nFile                                    Program        Insns (A)  Insns (B)  Insns  (DIFF)  States (A)  States (B)  States (DIFF)\n--------------------------------------  -------------  ---------  ---------  -------------  ----------  ----------  -------------\ntest_cls_redirect_dynptr.bpf.linked3.o  cls_redirect        2987       2864  -123 (-4.12%)         240         231    -9 (-3.75%)\nxdp_synproxy_kern.bpf.linked3.o         syncookie_tc       82848      82661  -187 (-0.23%)        5107        5073   -34 (-0.67%)\nxdp_synproxy_kern.bpf.linked3.o         syncookie_xdp      85116      84964  -152 (-0.18%)        5162        5130   -32 (-0.62%)\n\nNote, I avoided renaming jmp_history to more generic insn_hist to\nminimize number of lines changed and potential merge conflicts between\nbpf and bpf-next trees.\n\nNotice also cur_hist_entry pointer reset to NULL at the beginning of\ninstruction verification loop. This pointer avoids the problem of\nrelying on last jump history entry's insn_idx to determine whether we\nalready have entry for current instruction or not. It can happen that we\nadded jump history entry because current instruction is_jmp_point(), but\nalso we need to add instruction flags for stack access. In this case, we\ndon't want to entries, so we need to reuse last added entry, if it is\npresent.\n\nRelying on insn_idx comparison has the same ambiguity problem as the one\nthat was fixed recently in [0], so we avoid that.\n\n  [0] https://patchwork.kernel.org/project/netdevbpf/patch/20231110002638.4168352-3-andrii@kernel.org/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-52920","epss":0.00254,"percentile":0.16904,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-52920","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-52920","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53149","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53149","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: avoid deadlock in fs reclaim with page writeback  Ext4 has a filesystem wide lock protecting ext4_writepages() calls to avoid races with switching of journalled data flag or inode format. This lock can however cause a deadlock like:  CPU0                            CPU1  ext4_writepages()   percpu_down_read(sbi->s_writepages_rwsem);                                 ext4_change_inode_journal_flag()                                   percpu_down_write(sbi->s_writepages_rwsem);                                     - blocks, all readers block from now on   ext4_do_writepages()     ext4_init_io_end()       kmem_cache_zalloc(io_end_cachep, GFP_KERNEL)         fs_reclaim frees dentry...           dentry_unlink_inode()             iput() - last ref =>               iput_final() - inode dirty =>                 write_inode_now()...                   ext4_writepages() tries to acquire sbi->s_writepages_rwsem                     and blocks forever  Make sure we cannot recurse into filesystem reclaim from writeback code to avoid the deadlock.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53149","epss":0.00117,"percentile":0.01837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53149","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.061425},"relatedVulnerabilities":[{"id":"CVE-2023-53149","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53149","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/00d873c17e29cc32d90ca852b82685f1673acaa5","https://git.kernel.org/stable/c/2ec97dc90df40c50e509809dc9a198638a7e18b6","https://git.kernel.org/stable/c/4b4340bf04ce9a52061f15000ecedd126abc093c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid deadlock in fs reclaim with page writeback\n\nExt4 has a filesystem wide lock protecting ext4_writepages() calls to\navoid races with switching of journalled data flag or inode format. This\nlock can however cause a deadlock like:\n\nCPU0                            CPU1\n\next4_writepages()\n  percpu_down_read(sbi->s_writepages_rwsem);\n                                ext4_change_inode_journal_flag()\n                                  percpu_down_write(sbi->s_writepages_rwsem);\n                                    - blocks, all readers block from now on\n  ext4_do_writepages()\n    ext4_init_io_end()\n      kmem_cache_zalloc(io_end_cachep, GFP_KERNEL)\n        fs_reclaim frees dentry...\n          dentry_unlink_inode()\n            iput() - last ref =>\n              iput_final() - inode dirty =>\n                write_inode_now()...\n                  ext4_writepages() tries to acquire sbi->s_writepages_rwsem\n                    and blocks forever\n\nMake sure we cannot recurse into filesystem reclaim from writeback code\nto avoid the deadlock.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53149","epss":0.00117,"percentile":0.01837,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53149","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53149","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53218","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53218","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Make it so that a waiting process can be aborted  When sendmsg() creates an rxrpc call, it queues it to wait for a connection and channel to be assigned and then waits before it can start shovelling data as the encrypted DATA packet content includes a summary of the connection parameters.  However, sendmsg() may get interrupted before a connection gets assigned and further sendmsg() calls will fail with EBUSY until an assignment is made.  Fix this so that the call can at least be aborted without failing on EBUSY.  We have to be careful here as sendmsg() mustn't be allowed to start the call timer if the call doesn't yet have a connection assigned as an oops may follow shortly thereafter.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53218","epss":0.00162,"percentile":0.05701,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12393},"relatedVulnerabilities":[{"id":"CVE-2023-53218","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53218","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0eb362d254814ce04848730bf32e75b8ee1a4d6c","https://git.kernel.org/stable/c/7161cf61c64e9e9413d790f2fa2b9dada71a2249","https://git.kernel.org/stable/c/876d96faacbc407daf4978d7ec95051b68f5344a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Make it so that a waiting process can be aborted\n\nWhen sendmsg() creates an rxrpc call, it queues it to wait for a connection\nand channel to be assigned and then waits before it can start shovelling\ndata as the encrypted DATA packet content includes a summary of the\nconnection parameters.\n\nHowever, sendmsg() may get interrupted before a connection gets assigned\nand further sendmsg() calls will fail with EBUSY until an assignment is\nmade.\n\nFix this so that the call can at least be aborted without failing on\nEBUSY.  We have to be careful here as sendmsg() mustn't be allowed to start\nthe call timer if the call doesn't yet have a connection assigned as an\noops may follow shortly thereafter.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53218","epss":0.00162,"percentile":0.05701,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53218","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53231","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53231","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  erofs: Fix detection of atomic context  Current check for atomic context is not sufficient as z_erofs_decompressqueue_endio can be called under rcu lock from blk_mq_flush_plug_list(). See the stacktrace [1]  In such case we should hand off the decompression work for async processing rather than trying to do sync decompression in current context. Patch fixes the detection by checking for rcu_read_lock_any_held() and while at it use more appropriate !in_task() check than in_atomic().  Background: Historically erofs would always schedule a kworker for decompression which would incur the scheduling cost regardless of the context. But z_erofs_decompressqueue_endio() may not always be in atomic context and we could actually benefit from doing the decompression in z_erofs_decompressqueue_endio() if we are in thread context, for example when running with dm-verity. This optimization was later added in patch [2] which has shown improvement in performance benchmarks.  ============================================== [1] Problem stacktrace [name:core&]BUG: sleeping function called from invalid context at kernel/locking/mutex.c:291 [name:core&]in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 1615, name: CpuMonitorServi [name:core&]preempt_count: 0, expected: 0 [name:core&]RCU nest depth: 1, expected: 0 CPU: 7 PID: 1615 Comm: CpuMonitorServi Tainted: G S      W  OE      6.1.25-android14-5-maybe-dirty-mainline #1 Hardware name: MT6897 (DT) Call trace:  dump_backtrace+0x108/0x15c  show_stack+0x20/0x30  dump_stack_lvl+0x6c/0x8c  dump_stack+0x20/0x48  __might_resched+0x1fc/0x308  __might_sleep+0x50/0x88  mutex_lock+0x2c/0x110  z_erofs_decompress_queue+0x11c/0xc10  z_erofs_decompress_kickoff+0x110/0x1a4  z_erofs_decompressqueue_endio+0x154/0x180  bio_endio+0x1b0/0x1d8  __dm_io_complete+0x22c/0x280  clone_endio+0xe4/0x280  bio_endio+0x1b0/0x1d8  blk_update_request+0x138/0x3a4  blk_mq_plug_issue_direct+0xd4/0x19c  blk_mq_flush_plug_list+0x2b0/0x354  __blk_flush_plug+0x110/0x160  blk_finish_plug+0x30/0x4c  read_pages+0x2fc/0x370  page_cache_ra_unbounded+0xa4/0x23c  page_cache_ra_order+0x290/0x320  do_sync_mmap_readahead+0x108/0x2c0  filemap_fault+0x19c/0x52c  __do_fault+0xc4/0x114  handle_mm_fault+0x5b4/0x1168  do_page_fault+0x338/0x4b4  do_translation_fault+0x40/0x60  do_mem_abort+0x60/0xc8  el0_da+0x4c/0xe0  el0t_64_sync_handler+0xd4/0xfc  el0t_64_sync+0x1a0/0x1a4  [2] Link: https://lore.kernel.org/all/20210317035448.13921-1-huangjianan@oppo.com/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53231","epss":0.00137,"percentile":0.03405,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07192499999999999},"relatedVulnerabilities":[{"id":"CVE-2023-53231","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53231","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/12d0a24afd9ea58e581ea64d64e066f2027b28d9","https://git.kernel.org/stable/c/597fb60c75132719687e173b75cab8f6eb1ca657"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: Fix detection of atomic context\n\nCurrent check for atomic context is not sufficient as\nz_erofs_decompressqueue_endio can be called under rcu lock\nfrom blk_mq_flush_plug_list(). See the stacktrace [1]\n\nIn such case we should hand off the decompression work for async\nprocessing rather than trying to do sync decompression in current\ncontext. Patch fixes the detection by checking for\nrcu_read_lock_any_held() and while at it use more appropriate\n!in_task() check than in_atomic().\n\nBackground: Historically erofs would always schedule a kworker for\ndecompression which would incur the scheduling cost regardless of\nthe context. But z_erofs_decompressqueue_endio() may not always\nbe in atomic context and we could actually benefit from doing the\ndecompression in z_erofs_decompressqueue_endio() if we are in\nthread context, for example when running with dm-verity.\nThis optimization was later added in patch [2] which has shown\nimprovement in performance benchmarks.\n\n==============================================\n[1] Problem stacktrace\n[name:core&]BUG: sleeping function called from invalid context at kernel/locking/mutex.c:291\n[name:core&]in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 1615, name: CpuMonitorServi\n[name:core&]preempt_count: 0, expected: 0\n[name:core&]RCU nest depth: 1, expected: 0\nCPU: 7 PID: 1615 Comm: CpuMonitorServi Tainted: G S      W  OE      6.1.25-android14-5-maybe-dirty-mainline #1\nHardware name: MT6897 (DT)\nCall trace:\n dump_backtrace+0x108/0x15c\n show_stack+0x20/0x30\n dump_stack_lvl+0x6c/0x8c\n dump_stack+0x20/0x48\n __might_resched+0x1fc/0x308\n __might_sleep+0x50/0x88\n mutex_lock+0x2c/0x110\n z_erofs_decompress_queue+0x11c/0xc10\n z_erofs_decompress_kickoff+0x110/0x1a4\n z_erofs_decompressqueue_endio+0x154/0x180\n bio_endio+0x1b0/0x1d8\n __dm_io_complete+0x22c/0x280\n clone_endio+0xe4/0x280\n bio_endio+0x1b0/0x1d8\n blk_update_request+0x138/0x3a4\n blk_mq_plug_issue_direct+0xd4/0x19c\n blk_mq_flush_plug_list+0x2b0/0x354\n __blk_flush_plug+0x110/0x160\n blk_finish_plug+0x30/0x4c\n read_pages+0x2fc/0x370\n page_cache_ra_unbounded+0xa4/0x23c\n page_cache_ra_order+0x290/0x320\n do_sync_mmap_readahead+0x108/0x2c0\n filemap_fault+0x19c/0x52c\n __do_fault+0xc4/0x114\n handle_mm_fault+0x5b4/0x1168\n do_page_fault+0x338/0x4b4\n do_translation_fault+0x40/0x60\n do_mem_abort+0x60/0xc8\n el0_da+0x4c/0xe0\n el0t_64_sync_handler+0xd4/0xfc\n el0t_64_sync+0x1a0/0x1a4\n\n[2] Link: https://lore.kernel.org/all/20210317035448.13921-1-huangjianan@oppo.com/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53231","epss":0.00137,"percentile":0.03405,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53231","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53261","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53261","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  coresight: Fix memory leak in acpi_buffer->pointer  There are memory leaks reported by kmemleak: ... unreferenced object 0xffff00213c141000 (size 1024):   comm \"systemd-udevd\", pid 2123, jiffies 4294909467 (age 6062.160s)   hex dump (first 32 bytes):     04 00 00 00 02 00 00 00 18 10 14 3c 21 00 ff ff  ...........<!...     00 00 00 00 00 00 00 00 03 00 00 00 10 00 00 00  ................   backtrace:     [<000000004b7c9001>] __kmem_cache_alloc_node+0x2f8/0x348     [<00000000b0fc7ceb>] __kmalloc+0x58/0x108     [<0000000064ff4695>] acpi_os_allocate+0x2c/0x68     [<000000007d57d116>] acpi_ut_initialize_buffer+0x54/0xe0     [<0000000024583908>] acpi_evaluate_object+0x388/0x438     [<0000000017b2e72b>] acpi_evaluate_object_typed+0xe8/0x240     [<000000005df0eac2>] coresight_get_platform_data+0x1b4/0x988 [coresight] ...  The ACPI buffer memory (buf.pointer) should be freed. But the buffer is also used after returning from acpi_get_dsd_graph(). Move the temporary variables buf to acpi_coresight_parse_graph(), and free it before the function return to prevent memory leak.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53261","epss":0.00127,"percentile":0.02713,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53261","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53261","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2023-53261","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53261","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1a9e02673e2550f5612099e64e8761f0c8fc0f50","https://git.kernel.org/stable/c/d1b60e7c9fee34eaedf1fc4e0471f75b33f83a4a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: Fix memory leak in acpi_buffer->pointer\n\nThere are memory leaks reported by kmemleak:\n...\nunreferenced object 0xffff00213c141000 (size 1024):\n  comm \"systemd-udevd\", pid 2123, jiffies 4294909467 (age 6062.160s)\n  hex dump (first 32 bytes):\n    04 00 00 00 02 00 00 00 18 10 14 3c 21 00 ff ff  ...........<!...\n    00 00 00 00 00 00 00 00 03 00 00 00 10 00 00 00  ................\n  backtrace:\n    [<000000004b7c9001>] __kmem_cache_alloc_node+0x2f8/0x348\n    [<00000000b0fc7ceb>] __kmalloc+0x58/0x108\n    [<0000000064ff4695>] acpi_os_allocate+0x2c/0x68\n    [<000000007d57d116>] acpi_ut_initialize_buffer+0x54/0xe0\n    [<0000000024583908>] acpi_evaluate_object+0x388/0x438\n    [<0000000017b2e72b>] acpi_evaluate_object_typed+0xe8/0x240\n    [<000000005df0eac2>] coresight_get_platform_data+0x1b4/0x988 [coresight]\n...\n\nThe ACPI buffer memory (buf.pointer) should be freed. But the buffer\nis also used after returning from acpi_get_dsd_graph().\nMove the temporary variables buf to acpi_coresight_parse_graph(),\nand free it before the function return to prevent memory leak.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53261","epss":0.00127,"percentile":0.02713,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53261","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53261","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53261","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53336","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53336","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings  When ipu_bridge_parse_rotation() and ipu_bridge_parse_orientation() run sensor->adev is not set yet.  So if either of the dev_warn() calls about unknown values are hit this will lead to a NULL pointer deref.  Set sensor->adev earlier, with a borrowed ref to avoid making unrolling on errors harder, to fix this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53336","epss":0.00201,"percentile":0.10004,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53336","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53336","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.105525},"relatedVulnerabilities":[{"id":"CVE-2023-53336","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53336","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/284be5693163343e1cf17c03917eecd1d6681bcf","https://git.kernel.org/stable/c/3de35e29cfddfe6bff762b15bcfe8d80bebac6cb","https://git.kernel.org/stable/c/e08b091e33ecf6e4cb2c0c5820a69abe7673280b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings\n\nWhen ipu_bridge_parse_rotation() and ipu_bridge_parse_orientation() run\nsensor->adev is not set yet.\n\nSo if either of the dev_warn() calls about unknown values are hit this\nwill lead to a NULL pointer deref.\n\nSet sensor->adev earlier, with a borrowed ref to avoid making unrolling\non errors harder, to fix this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53336","epss":0.00201,"percentile":0.10004,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53336","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53336","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53336","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53353","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53353","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  accel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release()  The memory manager IDR is currently destroyed when user releases the file descriptor. However, at this point the user context might be still held, and memory buffers might be still in use. Later on, calls to release those buffers will fail due to not finding their handles in the IDR, leading to a memory leak. To avoid this leak, split the IDR destruction from the memory manager fini, and postpone it to hpriv_release() when there is no user context and no buffers are used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53353","epss":0.00167,"percentile":0.06282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53353","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53353","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.087675},"relatedVulnerabilities":[{"id":"CVE-2023-53353","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53353","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2e8e9a895c4589f124a37fc84d123b5114406e94","https://git.kernel.org/stable/c/840de329ca99cafd0cdde9c6ac160b1330942aba"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/habanalabs: postpone mem_mgr IDR destruction to hpriv_release()\n\nThe memory manager IDR is currently destroyed when user releases the\nfile descriptor.\nHowever, at this point the user context might be still held, and memory\nbuffers might be still in use.\nLater on, calls to release those buffers will fail due to not finding\ntheir handles in the IDR, leading to a memory leak.\nTo avoid this leak, split the IDR destruction from the memory manager\nfini, and postpone it to hpriv_release() when there is no user context\nand no buffers are used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53353","epss":0.00167,"percentile":0.06282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53353","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53353","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53353","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53367","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  accel/habanalabs: fix mem leak in capture user mappings  This commit fixes a memory leak caused when clearing the user_mappings info when a new context is opened immediately after user_mapping is captured and a hard reset is performed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53367","epss":0.00167,"percentile":0.06281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53367","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53367","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.087675},"relatedVulnerabilities":[{"id":"CVE-2023-53367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53367","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/314a7ffd7c196b27eedd50cb7553029e17789b55","https://git.kernel.org/stable/c/973e0890e5264cb075ef668661cad06b67777121"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/habanalabs: fix mem leak in capture user mappings\n\nThis commit fixes a memory leak caused when clearing the user_mappings\ninfo when a new context is opened immediately after user_mapping is\ncaptured and a hard reset is performed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53367","epss":0.00167,"percentile":0.06281,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53367","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53367","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53367","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53394","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53394","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: xsk: Fix crash on regular rq reactivation  When the regular rq is reactivated after the XSK socket is closed it could be reading stale cqes which eventually corrupts the rq. This leads to no more traffic being received on the regular rq and a crash on the next close or deactivation of the rq.  Kal Cuttler Conely reported this issue as a crash on the release path when the xdpsock sample program is stopped (killed) and restarted in sequence while traffic is running.  This patch flushes all cqes when during the rq flush. The cqe flushing is done in the reset state of the rq. mlx5e_rq_to_ready code is moved into the flush function to allow for this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53394","epss":0.00134,"percentile":0.03263,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07035},"relatedVulnerabilities":[{"id":"CVE-2023-53394","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53394","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/02a84eb2af6bea7871cd34264fb27f141f005fd9","https://git.kernel.org/stable/c/39646d9bcd1a65d2396328026626859a1dab59d7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: xsk: Fix crash on regular rq reactivation\n\nWhen the regular rq is reactivated after the XSK socket is closed\nit could be reading stale cqes which eventually corrupts the rq.\nThis leads to no more traffic being received on the regular rq and a\ncrash on the next close or deactivation of the rq.\n\nKal Cuttler Conely reported this issue as a crash on the release\npath when the xdpsock sample program is stopped (killed) and restarted\nin sequence while traffic is running.\n\nThis patch flushes all cqes when during the rq flush. The cqe flushing\nis done in the reset state of the rq. mlx5e_rq_to_ready code is moved\ninto the flush function to allow for this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53394","epss":0.00134,"percentile":0.03263,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53394","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53429","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53429","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: don't check PageError in __extent_writepage  __extent_writepage currenly sets PageError whenever any error happens, and the also checks for PageError to decide if to call error handling. This leads to very unclear responsibility for cleaning up on errors. In the VM and generic writeback helpers the basic idea is that once I/O is fired off all error handling responsibility is delegated to the end I/O handler.  But if that end I/O handler sets the PageError bit, and the submitter checks it, the bit could in some cases leak into the submission context for fast enough I/O.  Fix this by simply not checking PageError and just using the local ret variable to check for submission errors.  This also fundamentally solves the long problem documented in a comment in __extent_writepage by never leaking the error bit into the submission context.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53429","epss":0.00134,"percentile":0.03262,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07035},"relatedVulnerabilities":[{"id":"CVE-2023-53429","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53429","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3e92499e3b004baffb479d61e191b41b604ece9a","https://git.kernel.org/stable/c/d40be032ecd8ee1ca033bee43c7755d21fb4d72a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't check PageError in __extent_writepage\n\n__extent_writepage currenly sets PageError whenever any error happens,\nand the also checks for PageError to decide if to call error handling.\nThis leads to very unclear responsibility for cleaning up on errors.\nIn the VM and generic writeback helpers the basic idea is that once\nI/O is fired off all error handling responsibility is delegated to the\nend I/O handler.  But if that end I/O handler sets the PageError bit,\nand the submitter checks it, the bit could in some cases leak into the\nsubmission context for fast enough I/O.\n\nFix this by simply not checking PageError and just using the local\nret variable to check for submission errors.  This also fundamentally\nsolves the long problem documented in a comment in __extent_writepage\nby never leaking the error bit into the submission context.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53429","epss":0.00134,"percentile":0.03262,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53429","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53447","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53447","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: don't reset unchangable mount option in f2fs_remount()  syzbot reports a bug as below:  general protection fault, probably for non-canonical address 0xdffffc0000000009: 0000 [#1] PREEMPT SMP KASAN RIP: 0010:__lock_acquire+0x69/0x2000 kernel/locking/lockdep.c:4942 Call Trace:  lock_acquire+0x1e3/0x520 kernel/locking/lockdep.c:5691  __raw_write_lock include/linux/rwlock_api_smp.h:209 [inline]  _raw_write_lock+0x2e/0x40 kernel/locking/spinlock.c:300  __drop_extent_tree+0x3ac/0x660 fs/f2fs/extent_cache.c:1100  f2fs_drop_extent_tree+0x17/0x30 fs/f2fs/extent_cache.c:1116  f2fs_insert_range+0x2d5/0x3c0 fs/f2fs/file.c:1664  f2fs_fallocate+0x4e4/0x6d0 fs/f2fs/file.c:1838  vfs_fallocate+0x54b/0x6b0 fs/open.c:324  ksys_fallocate fs/open.c:347 [inline]  __do_sys_fallocate fs/open.c:355 [inline]  __se_sys_fallocate fs/open.c:353 [inline]  __x64_sys_fallocate+0xbd/0x100 fs/open.c:353  do_syscall_x64 arch/x86/entry/common.c:50 [inline]  do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80  entry_SYSCALL_64_after_hwframe+0x63/0xcd  The root cause is race condition as below: - since it tries to remount rw filesystem, so that do_remount won't call sb_prepare_remount_readonly to block fallocate, there may be race condition in between remount and fallocate. - in f2fs_remount(), default_options() will reset mount option to default one, and then update it based on result of parse_options(), so there is a hole which race condition can happen.  Thread A\t\t\tThread B - f2fs_fill_super  - parse_options   - clear_opt(READ_EXTENT_CACHE)  - f2fs_remount  - default_options   - set_opt(READ_EXTENT_CACHE) \t\t\t\t- f2fs_fallocate \t\t\t\t - f2fs_insert_range \t\t\t\t  - f2fs_drop_extent_tree \t\t\t\t   - __drop_extent_tree \t\t\t\t    - __may_extent_tree \t\t\t\t     - test_opt(READ_EXTENT_CACHE) return true \t\t\t\t    - write_lock(&et->lock) access NULL pointer  - parse_options   - clear_opt(READ_EXTENT_CACHE)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53447","epss":0.00093,"percentile":0.00588,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53447","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53447","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.045105000000000006},"relatedVulnerabilities":[{"id":"CVE-2023-53447","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53447","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/115557cc226a927924f2d7d1980ccbf6e3b3bb36","https://git.kernel.org/stable/c/458c15dfbce62c35fefd9ca637b20a051309c9f1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: don't reset unchangable mount option in f2fs_remount()\n\nsyzbot reports a bug as below:\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000009: 0000 [#1] PREEMPT SMP KASAN\nRIP: 0010:__lock_acquire+0x69/0x2000 kernel/locking/lockdep.c:4942\nCall Trace:\n lock_acquire+0x1e3/0x520 kernel/locking/lockdep.c:5691\n __raw_write_lock include/linux/rwlock_api_smp.h:209 [inline]\n _raw_write_lock+0x2e/0x40 kernel/locking/spinlock.c:300\n __drop_extent_tree+0x3ac/0x660 fs/f2fs/extent_cache.c:1100\n f2fs_drop_extent_tree+0x17/0x30 fs/f2fs/extent_cache.c:1116\n f2fs_insert_range+0x2d5/0x3c0 fs/f2fs/file.c:1664\n f2fs_fallocate+0x4e4/0x6d0 fs/f2fs/file.c:1838\n vfs_fallocate+0x54b/0x6b0 fs/open.c:324\n ksys_fallocate fs/open.c:347 [inline]\n __do_sys_fallocate fs/open.c:355 [inline]\n __se_sys_fallocate fs/open.c:353 [inline]\n __x64_sys_fallocate+0xbd/0x100 fs/open.c:353\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe root cause is race condition as below:\n- since it tries to remount rw filesystem, so that do_remount won't\ncall sb_prepare_remount_readonly to block fallocate, there may be race\ncondition in between remount and fallocate.\n- in f2fs_remount(), default_options() will reset mount option to default\none, and then update it based on result of parse_options(), so there is\na hole which race condition can happen.\n\nThread A\t\t\tThread B\n- f2fs_fill_super\n - parse_options\n  - clear_opt(READ_EXTENT_CACHE)\n\n- f2fs_remount\n - default_options\n  - set_opt(READ_EXTENT_CACHE)\n\t\t\t\t- f2fs_fallocate\n\t\t\t\t - f2fs_insert_range\n\t\t\t\t  - f2fs_drop_extent_tree\n\t\t\t\t   - __drop_extent_tree\n\t\t\t\t    - __may_extent_tree\n\t\t\t\t     - test_opt(READ_EXTENT_CACHE) return true\n\t\t\t\t    - write_lock(&et->lock) access NULL pointer\n - parse_options\n  - clear_opt(READ_EXTENT_CACHE)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53447","epss":0.00093,"percentile":0.00588,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53447","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2023-53447","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53447","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53460","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53460","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw88: fix memory leak in rtw_usb_probe()  drivers/net/wireless/realtek/rtw88/usb.c:876 rtw_usb_probe() warn: 'hw' from ieee80211_alloc_hw() not released on lines: 811  Fix this by modifying return to a goto statement.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53460","epss":0.00137,"percentile":0.03415,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53460","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07192499999999999},"relatedVulnerabilities":[{"id":"CVE-2023-53460","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53460","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/48181d285623198c33bb9698992502687b258efa","https://git.kernel.org/stable/c/6cc92379b80af005e1f49ef6ef790cddc58cf0da"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: fix memory leak in rtw_usb_probe()\n\ndrivers/net/wireless/realtek/rtw88/usb.c:876 rtw_usb_probe()\nwarn: 'hw' from ieee80211_alloc_hw() not released on lines: 811\n\nFix this by modifying return to a goto statement.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53460","epss":0.00137,"percentile":0.03415,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53460","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53460","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53491","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53491","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  start_kernel: Add __no_stack_protector function attribute  Back during the discussion of commit a9a3ed1eff36 (\"x86: Fix early boot crash on gcc-10, third try\") we discussed the need for a function attribute to control the omission of stack protectors on a per-function basis; at the time Clang had support for no_stack_protector but GCC did not. This was fixed in gcc-11. Now that the function attribute is available, let's start using it.  Callers of boot_init_stack_canary need to use this function attribute unless they're compiled with -fno-stack-protector, otherwise the canary stored in the stack slot of the caller will differ upon the call to boot_init_stack_canary. This will lead to a call to __stack_chk_fail() then panic.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53491","epss":0.00297,"percentile":0.22154,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.155925},"relatedVulnerabilities":[{"id":"CVE-2023-53491","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53491","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/25e73018b4093e0cfbcec5dc4a4bb86d0b69ed56","https://git.kernel.org/stable/c/514ca14ed5444b911de59ed3381dfd195d99fe4b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstart_kernel: Add __no_stack_protector function attribute\n\nBack during the discussion of\ncommit a9a3ed1eff36 (\"x86: Fix early boot crash on gcc-10, third try\")\nwe discussed the need for a function attribute to control the omission\nof stack protectors on a per-function basis; at the time Clang had\nsupport for no_stack_protector but GCC did not. This was fixed in\ngcc-11. Now that the function attribute is available, let's start using\nit.\n\nCallers of boot_init_stack_canary need to use this function attribute\nunless they're compiled with -fno-stack-protector, otherwise the canary\nstored in the stack slot of the caller will differ upon the call to\nboot_init_stack_canary. This will lead to a call to __stack_chk_fail()\nthen panic.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53491","epss":0.00297,"percentile":0.22154,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53491","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53523","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53523","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: gs_usb: fix time stamp counter initialization  If the gs_usb device driver is unloaded (or unbound) before the interface is shut down, the USB stack first calls the struct usb_driver::disconnect and then the struct net_device_ops::ndo_stop callback.  In gs_usb_disconnect() all pending bulk URBs are killed, i.e. no more RX'ed CAN frames are send from the USB device to the host. Later in gs_can_close() a reset control message is send to each CAN channel to remove the controller from the CAN bus. In this race window the USB device can still receive CAN frames from the bus and internally queue them to be send to the host.  At least in the current version of the candlelight firmware, the queue of received CAN frames is not emptied during the reset command. After loading (or binding) the gs_usb driver, new URBs are submitted during the struct net_device_ops::ndo_open callback and the candlelight firmware starts sending its already queued CAN frames to the host.  However, this scenario was not considered when implementing the hardware timestamp function. The cycle counter/time counter infrastructure is set up (gs_usb_timestamp_init()) after the USBs are submitted, resulting in a NULL pointer dereference if timecounter_cyc2time() (via the call chain: gs_usb_receive_bulk_callback() -> gs_usb_set_timestamp() -> gs_usb_skb_set_timestamp()) is called too early.  Move the gs_usb_timestamp_init() function before the URBs are submitted to fix this problem.  For a comprehensive solution, we need to consider gs_usb devices with more than 1 channel. The cycle counter/time counter infrastructure is setup per channel, but the RX URBs are per device. Once gs_can_open() of _a_ channel has been called, and URBs have been submitted, the gs_usb_receive_bulk_callback() can be called for _all_ available channels, even for channels that are not running, yet. As cycle counter/time counter has not set up, this will again lead to a NULL pointer dereference.  Convert the cycle counter/time counter from a \"per channel\" to a \"per device\" functionality. Also set it up, before submitting any URBs to the device.  Further in gs_usb_receive_bulk_callback(), don't process any URBs for not started CAN channels, only resubmit the URB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53523","epss":0.00127,"percentile":0.02716,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53523","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2023-53523","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53523","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/210a8cffc9c1b044281c0a868485c870c9c11374","https://git.kernel.org/stable/c/5886e4d5ecec3e22844efed90b2dd383ef804b3a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: gs_usb: fix time stamp counter initialization\n\nIf the gs_usb device driver is unloaded (or unbound) before the\ninterface is shut down, the USB stack first calls the struct\nusb_driver::disconnect and then the struct net_device_ops::ndo_stop\ncallback.\n\nIn gs_usb_disconnect() all pending bulk URBs are killed, i.e. no more\nRX'ed CAN frames are send from the USB device to the host. Later in\ngs_can_close() a reset control message is send to each CAN channel to\nremove the controller from the CAN bus. In this race window the USB\ndevice can still receive CAN frames from the bus and internally queue\nthem to be send to the host.\n\nAt least in the current version of the candlelight firmware, the queue\nof received CAN frames is not emptied during the reset command. After\nloading (or binding) the gs_usb driver, new URBs are submitted during\nthe struct net_device_ops::ndo_open callback and the candlelight\nfirmware starts sending its already queued CAN frames to the host.\n\nHowever, this scenario was not considered when implementing the\nhardware timestamp function. The cycle counter/time counter\ninfrastructure is set up (gs_usb_timestamp_init()) after the USBs are\nsubmitted, resulting in a NULL pointer dereference if\ntimecounter_cyc2time() (via the call chain:\ngs_usb_receive_bulk_callback() -> gs_usb_set_timestamp() ->\ngs_usb_skb_set_timestamp()) is called too early.\n\nMove the gs_usb_timestamp_init() function before the URBs are\nsubmitted to fix this problem.\n\nFor a comprehensive solution, we need to consider gs_usb devices with\nmore than 1 channel. The cycle counter/time counter infrastructure is\nsetup per channel, but the RX URBs are per device. Once gs_can_open()\nof _a_ channel has been called, and URBs have been submitted, the\ngs_usb_receive_bulk_callback() can be called for _all_ available\nchannels, even for channels that are not running, yet. As cycle\ncounter/time counter has not set up, this will again lead to a NULL\npointer dereference.\n\nConvert the cycle counter/time counter from a \"per channel\" to a \"per\ndevice\" functionality. Also set it up, before submitting any URBs to\nthe device.\n\nFurther in gs_usb_receive_bulk_callback(), don't process any URBs for\nnot started CAN channels, only resubmit the URB.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53523","epss":0.00127,"percentile":0.02716,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53523","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53523","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53529","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53529","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw88: Fix memory leak in rtw88_usb  Kmemleak shows the following leak arising from routine in the usb probe routine:  unreferenced object 0xffff895cb29bba00 (size 512):   comm \"(udev-worker)\", pid 534, jiffies 4294903932 (age 102751.088s)   hex dump (first 32 bytes):     77 30 30 30 00 00 00 00 02 2f 2d 2b 30 00 00 00  w000...../-+0...     02 00 2a 28 00 00 00 00 ff 55 ff ff ff 00 00 00  ..*(.....U......   backtrace:     [<ffffffff9265fa36>] kmalloc_trace+0x26/0x90     [<ffffffffc17eec41>] rtw_usb_probe+0x2f1/0x680 [rtw_usb]     [<ffffffffc03e19fd>] usb_probe_interface+0xdd/0x2e0 [usbcore]     [<ffffffff92b4f2fe>] really_probe+0x18e/0x3d0     [<ffffffff92b4f5b8>] __driver_probe_device+0x78/0x160     [<ffffffff92b4f6bf>] driver_probe_device+0x1f/0x90     [<ffffffff92b4f8df>] __driver_attach+0xbf/0x1b0     [<ffffffff92b4d350>] bus_for_each_dev+0x70/0xc0     [<ffffffff92b4e51e>] bus_add_driver+0x10e/0x210     [<ffffffff92b50935>] driver_register+0x55/0xf0     [<ffffffffc03e0708>] usb_register_driver+0x88/0x140 [usbcore]     [<ffffffff92401153>] do_one_initcall+0x43/0x210     [<ffffffff9254f42a>] do_init_module+0x4a/0x200     [<ffffffff92551d1c>] __do_sys_finit_module+0xac/0x120     [<ffffffff92ee6626>] do_syscall_64+0x56/0x80     [<ffffffff9300006a>] entry_SYSCALL_64_after_hwframe+0x46/0xb0  The leak was verified to be real by unloading the driver, which resulted in a dangling pointer to the allocation.  The allocated memory is freed in rtw_usb_intf_deinit().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53529","epss":0.00127,"percentile":0.02715,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53529","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2023-53529","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53529","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/59a3a312009723e3e5082899655fdcc420e2b47a","https://git.kernel.org/stable/c/5bba1ad561a8b5bb14704d8f511cf10466336e3d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: Fix memory leak in rtw88_usb\n\nKmemleak shows the following leak arising from routine in the usb\nprobe routine:\n\nunreferenced object 0xffff895cb29bba00 (size 512):\n  comm \"(udev-worker)\", pid 534, jiffies 4294903932 (age 102751.088s)\n  hex dump (first 32 bytes):\n    77 30 30 30 00 00 00 00 02 2f 2d 2b 30 00 00 00  w000...../-+0...\n    02 00 2a 28 00 00 00 00 ff 55 ff ff ff 00 00 00  ..*(.....U......\n  backtrace:\n    [<ffffffff9265fa36>] kmalloc_trace+0x26/0x90\n    [<ffffffffc17eec41>] rtw_usb_probe+0x2f1/0x680 [rtw_usb]\n    [<ffffffffc03e19fd>] usb_probe_interface+0xdd/0x2e0 [usbcore]\n    [<ffffffff92b4f2fe>] really_probe+0x18e/0x3d0\n    [<ffffffff92b4f5b8>] __driver_probe_device+0x78/0x160\n    [<ffffffff92b4f6bf>] driver_probe_device+0x1f/0x90\n    [<ffffffff92b4f8df>] __driver_attach+0xbf/0x1b0\n    [<ffffffff92b4d350>] bus_for_each_dev+0x70/0xc0\n    [<ffffffff92b4e51e>] bus_add_driver+0x10e/0x210\n    [<ffffffff92b50935>] driver_register+0x55/0xf0\n    [<ffffffffc03e0708>] usb_register_driver+0x88/0x140 [usbcore]\n    [<ffffffff92401153>] do_one_initcall+0x43/0x210\n    [<ffffffff9254f42a>] do_init_module+0x4a/0x200\n    [<ffffffff92551d1c>] __do_sys_finit_module+0xac/0x120\n    [<ffffffff92ee6626>] do_syscall_64+0x56/0x80\n    [<ffffffff9300006a>] entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nThe leak was verified to be real by unloading the driver, which resulted\nin a dangling pointer to the allocation.\n\nThe allocated memory is freed in rtw_usb_intf_deinit().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53529","epss":0.00127,"percentile":0.02715,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53529","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53529","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53538","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53538","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: insert tree mod log move in push_node_left  There is a fairly unlikely race condition in tree mod log rewind that can result in a kernel panic which has the following trace:    [530.569] BTRFS critical (device sda3): unable to find logical 0 length 4096   [530.585] BTRFS critical (device sda3): unable to find logical 0 length 4096   [530.602] BUG: kernel NULL pointer dereference, address: 0000000000000002   [530.618] #PF: supervisor read access in kernel mode   [530.629] #PF: error_code(0x0000) - not-present page   [530.641] PGD 0 P4D 0   [530.647] Oops: 0000 [#1] SMP   [530.654] CPU: 30 PID: 398973 Comm: below Kdump: loaded Tainted: G S         O  K   5.12.0-0_fbk13_clang_7455_gb24de3bdb045 #1   [530.680] Hardware name: Quanta Mono Lake-M.2 SATA 1HY9U9Z001G/Mono Lake-M.2 SATA, BIOS F20_3A15 08/16/2017   [530.703] RIP: 0010:__btrfs_map_block+0xaa/0xd00   [530.755] RSP: 0018:ffffc9002c2f7600 EFLAGS: 00010246   [530.767] RAX: ffffffffffffffea RBX: ffff888292e41000 RCX: f2702d8b8be15100   [530.784] RDX: ffff88885fda6fb8 RSI: ffff88885fd973c8 RDI: ffff88885fd973c8   [530.800] RBP: ffff888292e410d0 R08: ffffffff82fd7fd0 R09: 00000000fffeffff   [530.816] R10: ffffffff82e57fd0 R11: ffffffff82e57d70 R12: 0000000000000000   [530.832] R13: 0000000000001000 R14: 0000000000001000 R15: ffffc9002c2f76f0   [530.848] FS:  00007f38d64af000(0000) GS:ffff88885fd80000(0000) knlGS:0000000000000000   [530.866] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   [530.880] CR2: 0000000000000002 CR3: 00000002b6770004 CR4: 00000000003706e0   [530.896] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000   [530.912] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400   [530.928] Call Trace:   [530.934]  ? btrfs_printk+0x13b/0x18c   [530.943]  ? btrfs_bio_counter_inc_blocked+0x3d/0x130   [530.955]  btrfs_map_bio+0x75/0x330   [530.963]  ? kmem_cache_alloc+0x12a/0x2d0   [530.973]  ? btrfs_submit_metadata_bio+0x63/0x100   [530.984]  btrfs_submit_metadata_bio+0xa4/0x100   [530.995]  submit_extent_page+0x30f/0x360   [531.004]  read_extent_buffer_pages+0x49e/0x6d0   [531.015]  ? submit_extent_page+0x360/0x360   [531.025]  btree_read_extent_buffer_pages+0x5f/0x150   [531.037]  read_tree_block+0x37/0x60   [531.046]  read_block_for_search+0x18b/0x410   [531.056]  btrfs_search_old_slot+0x198/0x2f0   [531.066]  resolve_indirect_ref+0xfe/0x6f0   [531.076]  ? ulist_alloc+0x31/0x60   [531.084]  ? kmem_cache_alloc_trace+0x12e/0x2b0   [531.095]  find_parent_nodes+0x720/0x1830   [531.105]  ? ulist_alloc+0x10/0x60   [531.113]  iterate_extent_inodes+0xea/0x370   [531.123]  ? btrfs_previous_extent_item+0x8f/0x110   [531.134]  ? btrfs_search_path_in_tree+0x240/0x240   [531.146]  iterate_inodes_from_logical+0x98/0xd0   [531.157]  ? btrfs_search_path_in_tree+0x240/0x240   [531.168]  btrfs_ioctl_logical_to_ino+0xd9/0x180   [531.179]  btrfs_ioctl+0xe2/0x2eb0  This occurs when logical inode resolution takes a tree mod log sequence number, and then while backref walking hits a rewind on a busy node which has the following sequence of tree mod log operations (numbers filled in from a specific example, but they are somewhat arbitrary)    REMOVE_WHILE_FREEING slot 532   REMOVE_WHILE_FREEING slot 531   REMOVE_WHILE_FREEING slot 530   ...   REMOVE_WHILE_FREEING slot 0   REMOVE slot 455   REMOVE slot 454   REMOVE slot 453   ...   REMOVE slot 0   ADD slot 455   ADD slot 454   ADD slot 453   ...   ADD slot 0   MOVE src slot 0 -> dst slot 456 nritems 533   REMOVE slot 455   REMOVE slot 454   REMOVE slot 453   ...   REMOVE slot 0  When this sequence gets applied via btrfs_tree_mod_log_rewind, it allocates a fresh rewind eb, and first inserts the correct key info for the 533 elements, then overwrites the first 456 of them, then decrements the count by 456 via the add ops, then rewinds the move by doing a memmove from 456:988->0:532. We have never written anything past 532, ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53538","epss":0.00137,"percentile":0.03417,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53538","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07192499999999999},"relatedVulnerabilities":[{"id":"CVE-2023-53538","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53538","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/11f14402fe3437852cb44945b3b9f1bdb4032956","https://git.kernel.org/stable/c/5cead5422a0e3d13b0bcee986c0f5c4ebb94100b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: insert tree mod log move in push_node_left\n\nThere is a fairly unlikely race condition in tree mod log rewind that\ncan result in a kernel panic which has the following trace:\n\n  [530.569] BTRFS critical (device sda3): unable to find logical 0 length 4096\n  [530.585] BTRFS critical (device sda3): unable to find logical 0 length 4096\n  [530.602] BUG: kernel NULL pointer dereference, address: 0000000000000002\n  [530.618] #PF: supervisor read access in kernel mode\n  [530.629] #PF: error_code(0x0000) - not-present page\n  [530.641] PGD 0 P4D 0\n  [530.647] Oops: 0000 [#1] SMP\n  [530.654] CPU: 30 PID: 398973 Comm: below Kdump: loaded Tainted: G S         O  K   5.12.0-0_fbk13_clang_7455_gb24de3bdb045 #1\n  [530.680] Hardware name: Quanta Mono Lake-M.2 SATA 1HY9U9Z001G/Mono Lake-M.2 SATA, BIOS F20_3A15 08/16/2017\n  [530.703] RIP: 0010:__btrfs_map_block+0xaa/0xd00\n  [530.755] RSP: 0018:ffffc9002c2f7600 EFLAGS: 00010246\n  [530.767] RAX: ffffffffffffffea RBX: ffff888292e41000 RCX: f2702d8b8be15100\n  [530.784] RDX: ffff88885fda6fb8 RSI: ffff88885fd973c8 RDI: ffff88885fd973c8\n  [530.800] RBP: ffff888292e410d0 R08: ffffffff82fd7fd0 R09: 00000000fffeffff\n  [530.816] R10: ffffffff82e57fd0 R11: ffffffff82e57d70 R12: 0000000000000000\n  [530.832] R13: 0000000000001000 R14: 0000000000001000 R15: ffffc9002c2f76f0\n  [530.848] FS:  00007f38d64af000(0000) GS:ffff88885fd80000(0000) knlGS:0000000000000000\n  [530.866] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  [530.880] CR2: 0000000000000002 CR3: 00000002b6770004 CR4: 00000000003706e0\n  [530.896] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n  [530.912] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n  [530.928] Call Trace:\n  [530.934]  ? btrfs_printk+0x13b/0x18c\n  [530.943]  ? btrfs_bio_counter_inc_blocked+0x3d/0x130\n  [530.955]  btrfs_map_bio+0x75/0x330\n  [530.963]  ? kmem_cache_alloc+0x12a/0x2d0\n  [530.973]  ? btrfs_submit_metadata_bio+0x63/0x100\n  [530.984]  btrfs_submit_metadata_bio+0xa4/0x100\n  [530.995]  submit_extent_page+0x30f/0x360\n  [531.004]  read_extent_buffer_pages+0x49e/0x6d0\n  [531.015]  ? submit_extent_page+0x360/0x360\n  [531.025]  btree_read_extent_buffer_pages+0x5f/0x150\n  [531.037]  read_tree_block+0x37/0x60\n  [531.046]  read_block_for_search+0x18b/0x410\n  [531.056]  btrfs_search_old_slot+0x198/0x2f0\n  [531.066]  resolve_indirect_ref+0xfe/0x6f0\n  [531.076]  ? ulist_alloc+0x31/0x60\n  [531.084]  ? kmem_cache_alloc_trace+0x12e/0x2b0\n  [531.095]  find_parent_nodes+0x720/0x1830\n  [531.105]  ? ulist_alloc+0x10/0x60\n  [531.113]  iterate_extent_inodes+0xea/0x370\n  [531.123]  ? btrfs_previous_extent_item+0x8f/0x110\n  [531.134]  ? btrfs_search_path_in_tree+0x240/0x240\n  [531.146]  iterate_inodes_from_logical+0x98/0xd0\n  [531.157]  ? btrfs_search_path_in_tree+0x240/0x240\n  [531.168]  btrfs_ioctl_logical_to_ino+0xd9/0x180\n  [531.179]  btrfs_ioctl+0xe2/0x2eb0\n\nThis occurs when logical inode resolution takes a tree mod log sequence\nnumber, and then while backref walking hits a rewind on a busy node\nwhich has the following sequence of tree mod log operations (numbers\nfilled in from a specific example, but they are somewhat arbitrary)\n\n  REMOVE_WHILE_FREEING slot 532\n  REMOVE_WHILE_FREEING slot 531\n  REMOVE_WHILE_FREEING slot 530\n  ...\n  REMOVE_WHILE_FREEING slot 0\n  REMOVE slot 455\n  REMOVE slot 454\n  REMOVE slot 453\n  ...\n  REMOVE slot 0\n  ADD slot 455\n  ADD slot 454\n  ADD slot 453\n  ...\n  ADD slot 0\n  MOVE src slot 0 -> dst slot 456 nritems 533\n  REMOVE slot 455\n  REMOVE slot 454\n  REMOVE slot 453\n  ...\n  REMOVE slot 0\n\nWhen this sequence gets applied via btrfs_tree_mod_log_rewind, it\nallocates a fresh rewind eb, and first inserts the correct key info for\nthe 533 elements, then overwrites the first 456 of them, then decrements\nthe count by 456 via the add ops, then rewinds the move by doing a\nmemmove from 456:988->0:532. We have never written anything past 532,\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53538","epss":0.00137,"percentile":0.03417,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53538","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53538","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53574","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53574","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw88: delete timer and free skb queue when unloading  Fix possible crash and memory leak on driver unload by deleting TX purge timer and freeing C2H queue in 'rtw_core_deinit()', shrink critical section in the latter by freeing COEX queue out of TX report lock scope.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53574","epss":0.00127,"percentile":0.02715,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53574","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2023-53574","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53574","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4128b00a6006870e117ab1841e58f369e9284ecb","https://git.kernel.org/stable/c/634fcbcaa4062db39aeb5ac6ed1bc1feb8dd5216"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: delete timer and free skb queue when unloading\n\nFix possible crash and memory leak on driver unload by deleting\nTX purge timer and freeing C2H queue in 'rtw_core_deinit()',\nshrink critical section in the latter by freeing COEX queue\nout of TX report lock scope.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53574","epss":0.00127,"percentile":0.02715,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53574","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53574","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53627","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53627","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list  When freeing slots in function slot_complete_v3_hw(), it is possible that sas_dev.list is being traversed elsewhere, and it may trigger a NULL pointer exception, such as follows:  ==>cq thread                    ==>scsi_eh_6                                  ==>scsi_error_handler() \t\t\t\t  ==>sas_eh_handle_sas_errors() \t\t\t\t    ==>sas_scsi_find_task() \t\t\t\t      ==>lldd_abort_task() ==>slot_complete_v3_hw()              ==>hisi_sas_abort_task()   ==>hisi_sas_slot_task_free()\t        ==>dereg_device_v3_hw()     ==>list_del_init()        \t\t  ==>list_for_each_entry_safe()  [ 7165.434918] sas: Enter sas_scsi_recover_host busy: 32 failed: 32 [ 7165.434926] sas: trying to find task 0x00000000769b5ba5 [ 7165.434927] sas: sas_scsi_find_task: aborting task 0x00000000769b5ba5 [ 7165.434940] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000769b5ba5) aborted [ 7165.434964] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000c9f7aa07) ignored [ 7165.434965] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000e2a1cf01) ignored [ 7165.434968] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [ 7165.434972] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(0000000022d52d93) ignored [ 7165.434975] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(0000000066a7516c) ignored [ 7165.434976] Mem abort info: [ 7165.434982]   ESR = 0x96000004 [ 7165.434991]   Exception class = DABT (current EL), IL = 32 bits [ 7165.434992]   SET = 0, FnV = 0 [ 7165.434993]   EA = 0, S1PTW = 0 [ 7165.434994] Data abort info: [ 7165.434994]   ISV = 0, ISS = 0x00000004 [ 7165.434995]   CM = 0, WnR = 0 [ 7165.434997] user pgtable: 4k pages, 48-bit VAs, pgdp = 00000000f29543f2 [ 7165.434998] [0000000000000000] pgd=0000000000000000 [ 7165.435003] Internal error: Oops: 96000004 [#1] SMP [ 7165.439863] Process scsi_eh_6 (pid: 4109, stack limit = 0x00000000c43818d5) [ 7165.468862] pstate: 00c00009 (nzcv daif +PAN +UAO) [ 7165.473637] pc : dereg_device_v3_hw+0x68/0xa8 [hisi_sas_v3_hw] [ 7165.479443] lr : dereg_device_v3_hw+0x2c/0xa8 [hisi_sas_v3_hw] [ 7165.485247] sp : ffff00001d623bc0 [ 7165.488546] x29: ffff00001d623bc0 x28: ffffa027d03b9508 [ 7165.493835] x27: ffff80278ed50af0 x26: ffffa027dd31e0a8 [ 7165.499123] x25: ffffa027d9b27f88 x24: ffffa027d9b209f8 [ 7165.504411] x23: ffffa027c45b0d60 x22: ffff80278ec07c00 [ 7165.509700] x21: 0000000000000008 x20: ffffa027d9b209f8 [ 7165.514988] x19: ffffa027d9b27f88 x18: ffffffffffffffff [ 7165.520276] x17: 0000000000000000 x16: 0000000000000000 [ 7165.525564] x15: ffff0000091d9708 x14: ffff0000093b7dc8 [ 7165.530852] x13: ffff0000093b7a23 x12: 6e7265746e692067 [ 7165.536140] x11: 0000000000000000 x10: 0000000000000bb0 [ 7165.541429] x9 : ffff00001d6238f0 x8 : ffffa027d877af00 [ 7165.546718] x7 : ffffa027d6329600 x6 : ffff7e809f58ca00 [ 7165.552006] x5 : 0000000000001f8a x4 : 000000000000088e [ 7165.557295] x3 : ffffa027d9b27fa8 x2 : 0000000000000000 [ 7165.562583] x1 : 0000000000000000 x0 : 000000003000188e [ 7165.567872] Call trace: [ 7165.570309]  dereg_device_v3_hw+0x68/0xa8 [hisi_sas_v3_hw] [ 7165.575775]  hisi_sas_abort_task+0x248/0x358 [hisi_sas_main] [ 7165.581415]  sas_eh_handle_sas_errors+0x258/0x8e0 [libsas] [ 7165.586876]  sas_scsi_recover_host+0x134/0x458 [libsas] [ 7165.592082]  scsi_error_handler+0xb4/0x488 [ 7165.596163]  kthread+0x134/0x138 [ 7165.599380]  ret_from_fork+0x10/0x18 [ 7165.602940] Code: d5033e9f b9000040 aa0103e2 eb03003f (f9400021) [ 7165.609004] kernel fault(0x1) notification starting on CPU 75 [ 7165.700728] ---[ end trace fc042cbbea224efc ]--- [ 7165.705326] Kernel panic - not syncing: Fatal exception  To fix the issue, grab sas_dev lock when traversing the members of sas_dev.list in dereg_device_v3_hw() and hisi_sas_release_tasks() to avoid concurrency of adding and deleting member. When  ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53627","epss":0.00186,"percentile":0.08302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53627","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09765},"relatedVulnerabilities":[{"id":"CVE-2023-53627","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53627","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6e2a40b3a332ea84079983be21c944de8ddbc4f3","https://git.kernel.org/stable/c/71fb36b5ff113a7674710b9d6063241eada84ff7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list\n\nWhen freeing slots in function slot_complete_v3_hw(), it is possible that\nsas_dev.list is being traversed elsewhere, and it may trigger a NULL\npointer exception, such as follows:\n\n==>cq thread                    ==>scsi_eh_6\n\n                                ==>scsi_error_handler()\n\t\t\t\t  ==>sas_eh_handle_sas_errors()\n\t\t\t\t    ==>sas_scsi_find_task()\n\t\t\t\t      ==>lldd_abort_task()\n==>slot_complete_v3_hw()              ==>hisi_sas_abort_task()\n  ==>hisi_sas_slot_task_free()\t        ==>dereg_device_v3_hw()\n    ==>list_del_init()        \t\t  ==>list_for_each_entry_safe()\n\n[ 7165.434918] sas: Enter sas_scsi_recover_host busy: 32 failed: 32\n[ 7165.434926] sas: trying to find task 0x00000000769b5ba5\n[ 7165.434927] sas: sas_scsi_find_task: aborting task 0x00000000769b5ba5\n[ 7165.434940] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000769b5ba5) aborted\n[ 7165.434964] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000c9f7aa07) ignored\n[ 7165.434965] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(00000000e2a1cf01) ignored\n[ 7165.434968] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[ 7165.434972] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(0000000022d52d93) ignored\n[ 7165.434975] hisi_sas_v3_hw 0000:b4:02.0: slot complete: task(0000000066a7516c) ignored\n[ 7165.434976] Mem abort info:\n[ 7165.434982]   ESR = 0x96000004\n[ 7165.434991]   Exception class = DABT (current EL), IL = 32 bits\n[ 7165.434992]   SET = 0, FnV = 0\n[ 7165.434993]   EA = 0, S1PTW = 0\n[ 7165.434994] Data abort info:\n[ 7165.434994]   ISV = 0, ISS = 0x00000004\n[ 7165.434995]   CM = 0, WnR = 0\n[ 7165.434997] user pgtable: 4k pages, 48-bit VAs, pgdp = 00000000f29543f2\n[ 7165.434998] [0000000000000000] pgd=0000000000000000\n[ 7165.435003] Internal error: Oops: 96000004 [#1] SMP\n[ 7165.439863] Process scsi_eh_6 (pid: 4109, stack limit = 0x00000000c43818d5)\n[ 7165.468862] pstate: 00c00009 (nzcv daif +PAN +UAO)\n[ 7165.473637] pc : dereg_device_v3_hw+0x68/0xa8 [hisi_sas_v3_hw]\n[ 7165.479443] lr : dereg_device_v3_hw+0x2c/0xa8 [hisi_sas_v3_hw]\n[ 7165.485247] sp : ffff00001d623bc0\n[ 7165.488546] x29: ffff00001d623bc0 x28: ffffa027d03b9508\n[ 7165.493835] x27: ffff80278ed50af0 x26: ffffa027dd31e0a8\n[ 7165.499123] x25: ffffa027d9b27f88 x24: ffffa027d9b209f8\n[ 7165.504411] x23: ffffa027c45b0d60 x22: ffff80278ec07c00\n[ 7165.509700] x21: 0000000000000008 x20: ffffa027d9b209f8\n[ 7165.514988] x19: ffffa027d9b27f88 x18: ffffffffffffffff\n[ 7165.520276] x17: 0000000000000000 x16: 0000000000000000\n[ 7165.525564] x15: ffff0000091d9708 x14: ffff0000093b7dc8\n[ 7165.530852] x13: ffff0000093b7a23 x12: 6e7265746e692067\n[ 7165.536140] x11: 0000000000000000 x10: 0000000000000bb0\n[ 7165.541429] x9 : ffff00001d6238f0 x8 : ffffa027d877af00\n[ 7165.546718] x7 : ffffa027d6329600 x6 : ffff7e809f58ca00\n[ 7165.552006] x5 : 0000000000001f8a x4 : 000000000000088e\n[ 7165.557295] x3 : ffffa027d9b27fa8 x2 : 0000000000000000\n[ 7165.562583] x1 : 0000000000000000 x0 : 000000003000188e\n[ 7165.567872] Call trace:\n[ 7165.570309]  dereg_device_v3_hw+0x68/0xa8 [hisi_sas_v3_hw]\n[ 7165.575775]  hisi_sas_abort_task+0x248/0x358 [hisi_sas_main]\n[ 7165.581415]  sas_eh_handle_sas_errors+0x258/0x8e0 [libsas]\n[ 7165.586876]  sas_scsi_recover_host+0x134/0x458 [libsas]\n[ 7165.592082]  scsi_error_handler+0xb4/0x488\n[ 7165.596163]  kthread+0x134/0x138\n[ 7165.599380]  ret_from_fork+0x10/0x18\n[ 7165.602940] Code: d5033e9f b9000040 aa0103e2 eb03003f (f9400021)\n[ 7165.609004] kernel fault(0x1) notification starting on CPU 75\n[ 7165.700728] ---[ end trace fc042cbbea224efc ]---\n[ 7165.705326] Kernel panic - not syncing: Fatal exception\n\nTo fix the issue, grab sas_dev lock when traversing the members of\nsas_dev.list in dereg_device_v3_hw() and hisi_sas_release_tasks() to avoid\nconcurrency of adding and deleting member. When \n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53627","epss":0.00186,"percentile":0.08302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-53627","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53627","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53706","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53706","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/vmemmap/devdax: fix kernel crash when probing devdax devices  commit 4917f55b4ef9 (\"mm/sparse-vmemmap: improve memory savings for compound devmaps\") added support for using optimized vmmemap for devdax devices.  But how vmemmap mappings are created are architecture specific.  For example, powerpc with hash translation doesn't have vmemmap mappings in init_mm page table instead they are bolted table entries in the hardware page table  vmemmap_populate_compound_pages() used by vmemmap optimization code is not aware of these architecture-specific mapping.  Hence allow architecture to opt for this feature.  I selected architectures supporting HUGETLB_PAGE_OPTIMIZE_VMEMMAP option as also supporting this feature.  This patch fixes the below crash on ppc64.  BUG: Unable to handle kernel data access on write at 0xc00c000100400038 Faulting instruction address: 0xc000000001269d90 Oops: Kernel access of bad area, sig: 11 [#1] LE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries Modules linked in: CPU: 7 PID: 1 Comm: swapper/0 Not tainted 6.3.0-rc5-150500.34-default+ #2 5c90a668b6bbd142599890245c2fb5de19d7d28a Hardware name: IBM,9009-42G POWER9 (raw) 0x4e0202 0xf000005 of:IBM,FW950.40 (VL950_099) hv:phyp pSeries NIP:  c000000001269d90 LR: c0000000004c57d4 CTR: 0000000000000000 REGS: c000000003632c30 TRAP: 0300   Not tainted  (6.3.0-rc5-150500.34-default+) MSR:  8000000000009033 <SF,EE,ME,IR,DR,RI,LE>  CR: 24842228  XER: 00000000 CFAR: c0000000004c57d0 DAR: c00c000100400038 DSISR: 42000000 IRQMASK: 0 .... NIP [c000000001269d90] __init_single_page.isra.74+0x14/0x4c LR [c0000000004c57d4] __init_zone_device_page+0x44/0xd0 Call Trace: [c000000003632ed0] [c000000003632f60] 0xc000000003632f60 (unreliable) [c000000003632f10] [c0000000004c5ca0] memmap_init_zone_device+0x170/0x250 [c000000003632fe0] [c0000000005575f8] memremap_pages+0x2c8/0x7f0 [c0000000036330c0] [c000000000557b5c] devm_memremap_pages+0x3c/0xa0 [c000000003633100] [c000000000d458a8] dev_dax_probe+0x108/0x3e0 [c0000000036331a0] [c000000000d41430] dax_bus_probe+0xb0/0x140 [c0000000036331d0] [c000000000cef27c] really_probe+0x19c/0x520 [c000000003633260] [c000000000cef6b4] __driver_probe_device+0xb4/0x230 [c0000000036332e0] [c000000000cef888] driver_probe_device+0x58/0x120 [c000000003633320] [c000000000cefa6c] __device_attach_driver+0x11c/0x1e0 [c0000000036333a0] [c000000000cebc58] bus_for_each_drv+0xa8/0x130 [c000000003633400] [c000000000ceefcc] __device_attach+0x15c/0x250 [c0000000036334a0] [c000000000ced458] bus_probe_device+0x108/0x110 [c0000000036334f0] [c000000000ce92dc] device_add+0x7fc/0xa10 [c0000000036335b0] [c000000000d447c8] devm_create_dev_dax+0x1d8/0x530 [c000000003633640] [c000000000d46b60] __dax_pmem_probe+0x200/0x270 [c0000000036337b0] [c000000000d46bf0] dax_pmem_probe+0x20/0x70 [c0000000036337d0] [c000000000d2279c] nvdimm_bus_probe+0xac/0x2b0 [c000000003633860] [c000000000cef27c] really_probe+0x19c/0x520 [c0000000036338f0] [c000000000cef6b4] __driver_probe_device+0xb4/0x230 [c000000003633970] [c000000000cef888] driver_probe_device+0x58/0x120 [c0000000036339b0] [c000000000cefd08] __driver_attach+0x1d8/0x240 [c000000003633a30] [c000000000cebb04] bus_for_each_dev+0xb4/0x130 [c000000003633a90] [c000000000cee564] driver_attach+0x34/0x50 [c000000003633ab0] [c000000000ced878] bus_add_driver+0x218/0x300 [c000000003633b40] [c000000000cf1144] driver_register+0xa4/0x1b0 [c000000003633bb0] [c000000000d21a0c] __nd_driver_register+0x5c/0x100 [c000000003633c10] [c00000000206a2e8] dax_pmem_init+0x34/0x48 [c000000003633c30] [c0000000000132d0] do_one_initcall+0x60/0x320 [c000000003633d00] [c0000000020051b0] kernel_init_freeable+0x360/0x400 [c000000003633de0] [c000000000013764] kernel_init+0x34/0x1d0 [c000000003633e50] [c00000000000de14] ret_from_kernel_thread+0x5c/0x64","cvss":[],"epss":[{"cve":"CVE-2023-53706","epss":0.00197,"percentile":0.09597,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0985},"relatedVulnerabilities":[{"id":"CVE-2023-53706","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53706","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/87349cf6818c4a0be00d49a13572f20a9e17887d","https://git.kernel.org/stable/c/87a7ae75d7383afa998f57656d1d14e2a730cc47","https://git.kernel.org/stable/c/8f4603588acf5807aa1f1b4b1ea2b0365acd71f0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmemmap/devdax: fix kernel crash when probing devdax devices\n\ncommit 4917f55b4ef9 (\"mm/sparse-vmemmap: improve memory savings for\ncompound devmaps\") added support for using optimized vmmemap for devdax\ndevices.  But how vmemmap mappings are created are architecture specific. \nFor example, powerpc with hash translation doesn't have vmemmap mappings\nin init_mm page table instead they are bolted table entries in the\nhardware page table\n\nvmemmap_populate_compound_pages() used by vmemmap optimization code is not\naware of these architecture-specific mapping.  Hence allow architecture to\nopt for this feature.  I selected architectures supporting\nHUGETLB_PAGE_OPTIMIZE_VMEMMAP option as also supporting this feature.\n\nThis patch fixes the below crash on ppc64.\n\nBUG: Unable to handle kernel data access on write at 0xc00c000100400038\nFaulting instruction address: 0xc000000001269d90\nOops: Kernel access of bad area, sig: 11 [#1]\nLE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries\nModules linked in:\nCPU: 7 PID: 1 Comm: swapper/0 Not tainted 6.3.0-rc5-150500.34-default+ #2 5c90a668b6bbd142599890245c2fb5de19d7d28a\nHardware name: IBM,9009-42G POWER9 (raw) 0x4e0202 0xf000005 of:IBM,FW950.40 (VL950_099) hv:phyp pSeries\nNIP:  c000000001269d90 LR: c0000000004c57d4 CTR: 0000000000000000\nREGS: c000000003632c30 TRAP: 0300   Not tainted  (6.3.0-rc5-150500.34-default+)\nMSR:  8000000000009033 <SF,EE,ME,IR,DR,RI,LE>  CR: 24842228  XER: 00000000\nCFAR: c0000000004c57d0 DAR: c00c000100400038 DSISR: 42000000 IRQMASK: 0\n....\nNIP [c000000001269d90] __init_single_page.isra.74+0x14/0x4c\nLR [c0000000004c57d4] __init_zone_device_page+0x44/0xd0\nCall Trace:\n[c000000003632ed0] [c000000003632f60] 0xc000000003632f60 (unreliable)\n[c000000003632f10] [c0000000004c5ca0] memmap_init_zone_device+0x170/0x250\n[c000000003632fe0] [c0000000005575f8] memremap_pages+0x2c8/0x7f0\n[c0000000036330c0] [c000000000557b5c] devm_memremap_pages+0x3c/0xa0\n[c000000003633100] [c000000000d458a8] dev_dax_probe+0x108/0x3e0\n[c0000000036331a0] [c000000000d41430] dax_bus_probe+0xb0/0x140\n[c0000000036331d0] [c000000000cef27c] really_probe+0x19c/0x520\n[c000000003633260] [c000000000cef6b4] __driver_probe_device+0xb4/0x230\n[c0000000036332e0] [c000000000cef888] driver_probe_device+0x58/0x120\n[c000000003633320] [c000000000cefa6c] __device_attach_driver+0x11c/0x1e0\n[c0000000036333a0] [c000000000cebc58] bus_for_each_drv+0xa8/0x130\n[c000000003633400] [c000000000ceefcc] __device_attach+0x15c/0x250\n[c0000000036334a0] [c000000000ced458] bus_probe_device+0x108/0x110\n[c0000000036334f0] [c000000000ce92dc] device_add+0x7fc/0xa10\n[c0000000036335b0] [c000000000d447c8] devm_create_dev_dax+0x1d8/0x530\n[c000000003633640] [c000000000d46b60] __dax_pmem_probe+0x200/0x270\n[c0000000036337b0] [c000000000d46bf0] dax_pmem_probe+0x20/0x70\n[c0000000036337d0] [c000000000d2279c] nvdimm_bus_probe+0xac/0x2b0\n[c000000003633860] [c000000000cef27c] really_probe+0x19c/0x520\n[c0000000036338f0] [c000000000cef6b4] __driver_probe_device+0xb4/0x230\n[c000000003633970] [c000000000cef888] driver_probe_device+0x58/0x120\n[c0000000036339b0] [c000000000cefd08] __driver_attach+0x1d8/0x240\n[c000000003633a30] [c000000000cebb04] bus_for_each_dev+0xb4/0x130\n[c000000003633a90] [c000000000cee564] driver_attach+0x34/0x50\n[c000000003633ab0] [c000000000ced878] bus_add_driver+0x218/0x300\n[c000000003633b40] [c000000000cf1144] driver_register+0xa4/0x1b0\n[c000000003633bb0] [c000000000d21a0c] __nd_driver_register+0x5c/0x100\n[c000000003633c10] [c00000000206a2e8] dax_pmem_init+0x34/0x48\n[c000000003633c30] [c0000000000132d0] do_one_initcall+0x60/0x320\n[c000000003633d00] [c0000000020051b0] kernel_init_freeable+0x360/0x400\n[c000000003633de0] [c000000000013764] kernel_init+0x34/0x1d0\n[c000000003633e50] [c00000000000de14] ret_from_kernel_thread+0x5c/0x64","cvss":[],"epss":[{"cve":"CVE-2023-53706","epss":0.00197,"percentile":0.09597,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53706","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53762","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53762","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync  Use-after-free can occur in hci_disconnect_all_sync if a connection is deleted by concurrent processing of a controller event.  To prevent this the code now tries to iterate over the list backwards to ensure the links are cleanup before its parents, also it no longer relies on a cursor, instead it always uses the last element since hci_abort_conn_sync is guaranteed to call hci_conn_del.  UAF crash log: ================================================================== BUG: KASAN: slab-use-after-free in hci_set_powered_sync (net/bluetooth/hci_sync.c:5424) [bluetooth] Read of size 8 at addr ffff888009d9c000 by task kworker/u9:0/124  CPU: 0 PID: 124 Comm: kworker/u9:0 Tainted: G        W 6.5.0-rc1+ #10 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-1.fc38 04/01/2014 Workqueue: hci0 hci_cmd_sync_work [bluetooth] Call Trace:  <TASK>  dump_stack_lvl+0x5b/0x90  print_report+0xcf/0x670  ? __virt_addr_valid+0xdd/0x160  ? hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]  kasan_report+0xa6/0xe0  ? hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]  ? __pfx_set_powered_sync+0x10/0x10 [bluetooth]  hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]  ? __pfx_hci_set_powered_sync+0x10/0x10 [bluetooth]  ? __pfx_lock_release+0x10/0x10  ? __pfx_set_powered_sync+0x10/0x10 [bluetooth]  hci_cmd_sync_work+0x137/0x220 [bluetooth]  process_one_work+0x526/0x9d0  ? __pfx_process_one_work+0x10/0x10  ? __pfx_do_raw_spin_lock+0x10/0x10  ? mark_held_locks+0x1a/0x90  worker_thread+0x92/0x630  ? __pfx_worker_thread+0x10/0x10  kthread+0x196/0x1e0  ? __pfx_kthread+0x10/0x10  ret_from_fork+0x2c/0x50  </TASK>  Allocated by task 1782:  kasan_save_stack+0x33/0x60  kasan_set_track+0x25/0x30  __kasan_kmalloc+0x8f/0xa0  hci_conn_add+0xa5/0xa80 [bluetooth]  hci_bind_cis+0x881/0x9b0 [bluetooth]  iso_connect_cis+0x121/0x520 [bluetooth]  iso_sock_connect+0x3f6/0x790 [bluetooth]  __sys_connect+0x109/0x130  __x64_sys_connect+0x40/0x50  do_syscall_64+0x60/0x90  entry_SYSCALL_64_after_hwframe+0x6e/0xd8  Freed by task 695:  kasan_save_stack+0x33/0x60  kasan_set_track+0x25/0x30  kasan_save_free_info+0x2b/0x50  __kasan_slab_free+0x10a/0x180  __kmem_cache_free+0x14d/0x2e0  device_release+0x5d/0xf0  kobject_put+0xdf/0x270  hci_disconn_complete_evt+0x274/0x3a0 [bluetooth]  hci_event_packet+0x579/0x7e0 [bluetooth]  hci_rx_work+0x287/0xaa0 [bluetooth]  process_one_work+0x526/0x9d0  worker_thread+0x92/0x630  kthread+0x196/0x1e0  ret_from_fork+0x2c/0x50 ==================================================================","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53762","epss":0.00245,"percentile":0.15759,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19967500000000002},"relatedVulnerabilities":[{"id":"CVE-2023-53762","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53762","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/94d9ba9f9888b748d4abd2aa1547af56ae85f772","https://git.kernel.org/stable/c/a30c074f0b5b7f909a15c978fbc96a29e2f94e42","https://git.kernel.org/stable/c/ba3ba53ce1f76fc372b8f918fece4f9b1e41acd4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync\n\nUse-after-free can occur in hci_disconnect_all_sync if a connection is\ndeleted by concurrent processing of a controller event.\n\nTo prevent this the code now tries to iterate over the list backwards\nto ensure the links are cleanup before its parents, also it no longer\nrelies on a cursor, instead it always uses the last element since\nhci_abort_conn_sync is guaranteed to call hci_conn_del.\n\nUAF crash log:\n==================================================================\nBUG: KASAN: slab-use-after-free in hci_set_powered_sync\n(net/bluetooth/hci_sync.c:5424) [bluetooth]\nRead of size 8 at addr ffff888009d9c000 by task kworker/u9:0/124\n\nCPU: 0 PID: 124 Comm: kworker/u9:0 Tainted: G        W\n6.5.0-rc1+ #10\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS\n1.16.2-1.fc38 04/01/2014\nWorkqueue: hci0 hci_cmd_sync_work [bluetooth]\nCall Trace:\n <TASK>\n dump_stack_lvl+0x5b/0x90\n print_report+0xcf/0x670\n ? __virt_addr_valid+0xdd/0x160\n ? hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]\n kasan_report+0xa6/0xe0\n ? hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]\n ? __pfx_set_powered_sync+0x10/0x10 [bluetooth]\n hci_set_powered_sync+0x2c9/0x4a0 [bluetooth]\n ? __pfx_hci_set_powered_sync+0x10/0x10 [bluetooth]\n ? __pfx_lock_release+0x10/0x10\n ? __pfx_set_powered_sync+0x10/0x10 [bluetooth]\n hci_cmd_sync_work+0x137/0x220 [bluetooth]\n process_one_work+0x526/0x9d0\n ? __pfx_process_one_work+0x10/0x10\n ? __pfx_do_raw_spin_lock+0x10/0x10\n ? mark_held_locks+0x1a/0x90\n worker_thread+0x92/0x630\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x196/0x1e0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2c/0x50\n </TASK>\n\nAllocated by task 1782:\n kasan_save_stack+0x33/0x60\n kasan_set_track+0x25/0x30\n __kasan_kmalloc+0x8f/0xa0\n hci_conn_add+0xa5/0xa80 [bluetooth]\n hci_bind_cis+0x881/0x9b0 [bluetooth]\n iso_connect_cis+0x121/0x520 [bluetooth]\n iso_sock_connect+0x3f6/0x790 [bluetooth]\n __sys_connect+0x109/0x130\n __x64_sys_connect+0x40/0x50\n do_syscall_64+0x60/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nFreed by task 695:\n kasan_save_stack+0x33/0x60\n kasan_set_track+0x25/0x30\n kasan_save_free_info+0x2b/0x50\n __kasan_slab_free+0x10a/0x180\n __kmem_cache_free+0x14d/0x2e0\n device_release+0x5d/0xf0\n kobject_put+0xdf/0x270\n hci_disconn_complete_evt+0x274/0x3a0 [bluetooth]\n hci_event_packet+0x579/0x7e0 [bluetooth]\n hci_rx_work+0x287/0xaa0 [bluetooth]\n process_one_work+0x526/0x9d0\n worker_thread+0x92/0x630\n kthread+0x196/0x1e0\n ret_from_fork+0x2c/0x50\n==================================================================","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53762","epss":0.00245,"percentile":0.15759,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53762","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53781","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smc: Fix use-after-free in tcp_write_timer_handler().  With Eric's ref tracker, syzbot finally found a repro for use-after-free in tcp_write_timer_handler() by kernel TCP sockets. [0]  If SMC creates a kernel socket in __smc_create(), the kernel socket is supposed to be freed in smc_clcsock_release() by calling sock_release() when we close() the parent SMC socket.  However, at the end of smc_clcsock_release(), the kernel socket's sk_state might not be TCP_CLOSE.  This means that we have not called inet_csk_destroy_sock() in __tcp_close() and have not stopped the TCP timers.  The kernel socket's TCP timers can be fired later, so we need to hold a refcnt for net as we do for MPTCP subflows in mptcp_subflow_create_socket().  [0]: leaked reference.  sk_alloc (./include/net/net_namespace.h:335 net/core/sock.c:2108)  inet_create (net/ipv4/af_inet.c:319 net/ipv4/af_inet.c:244)  __sock_create (net/socket.c:1546)  smc_create (net/smc/af_smc.c:3269 net/smc/af_smc.c:3284)  __sock_create (net/socket.c:1546)  __sys_socket (net/socket.c:1634 net/socket.c:1618 net/socket.c:1661)  __x64_sys_socket (net/socket.c:1672)  do_syscall_64 (arch/x86/entry/common.c:50 arch/x86/entry/common.c:80)  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:120) ================================================================== BUG: KASAN: slab-use-after-free in tcp_write_timer_handler (net/ipv4/tcp_timer.c:378 net/ipv4/tcp_timer.c:624 net/ipv4/tcp_timer.c:594) Read of size 1 at addr ffff888052b65e0d by task syzrepro/18091  CPU: 0 PID: 18091 Comm: syzrepro Tainted: G        W          6.3.0-rc4-01174-gb5d54eb5899a #7 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.0-1.amzn2022.0.1 04/01/2014 Call Trace:  <IRQ>  dump_stack_lvl (lib/dump_stack.c:107)  print_report (mm/kasan/report.c:320 mm/kasan/report.c:430)  kasan_report (mm/kasan/report.c:538)  tcp_write_timer_handler (net/ipv4/tcp_timer.c:378 net/ipv4/tcp_timer.c:624 net/ipv4/tcp_timer.c:594)  tcp_write_timer (./include/linux/spinlock.h:390 net/ipv4/tcp_timer.c:643)  call_timer_fn (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/timer.h:127 kernel/time/timer.c:1701)  __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2022)  run_timer_softirq (kernel/time/timer.c:2037)  __do_softirq (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/irq.h:142 kernel/softirq.c:572)  __irq_exit_rcu (kernel/softirq.c:445 kernel/softirq.c:650)  irq_exit_rcu (kernel/softirq.c:664)  sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1107 (discriminator 14))  </IRQ>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53781","epss":0.00144,"percentile":0.04026,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11016000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-53781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53781","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1cc41c8acfc1ee30b4868559058db97fa44b0137","https://git.kernel.org/stable/c/9744d2bf19762703704ecba885b7ac282c02eacf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmc: Fix use-after-free in tcp_write_timer_handler().\n\nWith Eric's ref tracker, syzbot finally found a repro for\nuse-after-free in tcp_write_timer_handler() by kernel TCP\nsockets. [0]\n\nIf SMC creates a kernel socket in __smc_create(), the kernel\nsocket is supposed to be freed in smc_clcsock_release() by\ncalling sock_release() when we close() the parent SMC socket.\n\nHowever, at the end of smc_clcsock_release(), the kernel\nsocket's sk_state might not be TCP_CLOSE.  This means that\nwe have not called inet_csk_destroy_sock() in __tcp_close()\nand have not stopped the TCP timers.\n\nThe kernel socket's TCP timers can be fired later, so we\nneed to hold a refcnt for net as we do for MPTCP subflows\nin mptcp_subflow_create_socket().\n\n[0]:\nleaked reference.\n sk_alloc (./include/net/net_namespace.h:335 net/core/sock.c:2108)\n inet_create (net/ipv4/af_inet.c:319 net/ipv4/af_inet.c:244)\n __sock_create (net/socket.c:1546)\n smc_create (net/smc/af_smc.c:3269 net/smc/af_smc.c:3284)\n __sock_create (net/socket.c:1546)\n __sys_socket (net/socket.c:1634 net/socket.c:1618 net/socket.c:1661)\n __x64_sys_socket (net/socket.c:1672)\n do_syscall_64 (arch/x86/entry/common.c:50 arch/x86/entry/common.c:80)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:120)\n==================================================================\nBUG: KASAN: slab-use-after-free in tcp_write_timer_handler (net/ipv4/tcp_timer.c:378 net/ipv4/tcp_timer.c:624 net/ipv4/tcp_timer.c:594)\nRead of size 1 at addr ffff888052b65e0d by task syzrepro/18091\n\nCPU: 0 PID: 18091 Comm: syzrepro Tainted: G        W          6.3.0-rc4-01174-gb5d54eb5899a #7\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.0-1.amzn2022.0.1 04/01/2014\nCall Trace:\n <IRQ>\n dump_stack_lvl (lib/dump_stack.c:107)\n print_report (mm/kasan/report.c:320 mm/kasan/report.c:430)\n kasan_report (mm/kasan/report.c:538)\n tcp_write_timer_handler (net/ipv4/tcp_timer.c:378 net/ipv4/tcp_timer.c:624 net/ipv4/tcp_timer.c:594)\n tcp_write_timer (./include/linux/spinlock.h:390 net/ipv4/tcp_timer.c:643)\n call_timer_fn (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/timer.h:127 kernel/time/timer.c:1701)\n __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2022)\n run_timer_softirq (kernel/time/timer.c:2037)\n __do_softirq (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/irq.h:142 kernel/softirq.c:572)\n __irq_exit_rcu (kernel/softirq.c:445 kernel/softirq.c:650)\n irq_exit_rcu (kernel/softirq.c:664)\n sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1107 (discriminator 14))\n </IRQ>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53781","epss":0.00144,"percentile":0.04026,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53823","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53823","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  block/rq_qos: protect rq_qos apis with a new lock  commit 50e34d78815e (\"block: disable the elevator int del_gendisk\") move rq_qos_exit() from disk_release() to del_gendisk(), this will introduce some problems:  1) If rq_qos_add() is triggered by enabling iocost/iolatency through    cgroupfs, then it can concurrent with del_gendisk(), it's not safe to    write 'q->rq_qos' concurrently.  2) Activate cgroup policy that is relied on rq_qos will call    rq_qos_add() and blkcg_activate_policy(), and if rq_qos_exit() is    called in the middle, null-ptr-dereference will be triggered in    blkcg_activate_policy().  3) blkg_conf_open_bdev() can call blkdev_get_no_open() first to find the    disk, then if rq_qos_exit() from del_gendisk() is done before    rq_qos_add(), then memory will be leaked.  This patch add a new disk level mutex 'rq_qos_mutex':  1) The lock will protect rq_qos_exit() directly.  2) For wbt that doesn't relied on blk-cgroup, rq_qos_add() can only be    called from disk initialization for now because wbt can't be    destructed until rq_qos_exit(), so it's safe not to protect wbt for    now. Hoever, in case that rq_qos dynamically destruction is supported    in the furture, this patch also protect rq_qos_add() from wbt_init()    directly, this is enough because blk-sysfs already synchronize    writers with disk removal.  3) For iocost and iolatency, in order to synchronize disk removal and    cgroup configuration, the lock is held after blkdev_get_no_open()    from blkg_conf_open_bdev(), and is released in blkg_conf_exit().    In order to fix the above memory leak, disk_live() is checked after    holding the new lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53823","epss":0.00183,"percentile":0.07989,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.139995},"relatedVulnerabilities":[{"id":"CVE-2023-53823","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53823","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/16398b4638b5cd8c1dc95fc940a1591a801d53ce","https://git.kernel.org/stable/c/a13bd91be22318768d55470cbc0b0f4488ef9edf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nblock/rq_qos: protect rq_qos apis with a new lock\n\ncommit 50e34d78815e (\"block: disable the elevator int del_gendisk\")\nmove rq_qos_exit() from disk_release() to del_gendisk(), this will\nintroduce some problems:\n\n1) If rq_qos_add() is triggered by enabling iocost/iolatency through\n   cgroupfs, then it can concurrent with del_gendisk(), it's not safe to\n   write 'q->rq_qos' concurrently.\n\n2) Activate cgroup policy that is relied on rq_qos will call\n   rq_qos_add() and blkcg_activate_policy(), and if rq_qos_exit() is\n   called in the middle, null-ptr-dereference will be triggered in\n   blkcg_activate_policy().\n\n3) blkg_conf_open_bdev() can call blkdev_get_no_open() first to find the\n   disk, then if rq_qos_exit() from del_gendisk() is done before\n   rq_qos_add(), then memory will be leaked.\n\nThis patch add a new disk level mutex 'rq_qos_mutex':\n\n1) The lock will protect rq_qos_exit() directly.\n\n2) For wbt that doesn't relied on blk-cgroup, rq_qos_add() can only be\n   called from disk initialization for now because wbt can't be\n   destructed until rq_qos_exit(), so it's safe not to protect wbt for\n   now. Hoever, in case that rq_qos dynamically destruction is supported\n   in the furture, this patch also protect rq_qos_add() from wbt_init()\n   directly, this is enough because blk-sysfs already synchronize\n   writers with disk removal.\n\n3) For iocost and iolatency, in order to synchronize disk removal and\n   cgroup configuration, the lock is held after blkdev_get_no_open()\n   from blkg_conf_open_bdev(), and is released in blkg_conf_exit().\n   In order to fix the above memory leak, disk_live() is checked after\n   holding the new lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53823","epss":0.00183,"percentile":0.07989,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53823","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53846","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to do sanity check on direct node in truncate_dnode()  syzbot reports below bug:  BUG: KASAN: slab-use-after-free in f2fs_truncate_data_blocks_range+0x122a/0x14c0 fs/f2fs/file.c:574 Read of size 4 at addr ffff88802a25c000 by task syz-executor148/5000  CPU: 1 PID: 5000 Comm: syz-executor148 Not tainted 6.4.0-rc7-syzkaller-00041-ge660abd551f1 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023 Call Trace:  <TASK>  __dump_stack lib/dump_stack.c:88 [inline]  dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106  print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351  print_report mm/kasan/report.c:462 [inline]  kasan_report+0x11c/0x130 mm/kasan/report.c:572  f2fs_truncate_data_blocks_range+0x122a/0x14c0 fs/f2fs/file.c:574  truncate_dnode+0x229/0x2e0 fs/f2fs/node.c:944  f2fs_truncate_inode_blocks+0x64b/0xde0 fs/f2fs/node.c:1154  f2fs_do_truncate_blocks+0x4ac/0xf30 fs/f2fs/file.c:721  f2fs_truncate_blocks+0x7b/0x300 fs/f2fs/file.c:749  f2fs_truncate.part.0+0x4a5/0x630 fs/f2fs/file.c:799  f2fs_truncate include/linux/fs.h:825 [inline]  f2fs_setattr+0x1738/0x2090 fs/f2fs/file.c:1006  notify_change+0xb2c/0x1180 fs/attr.c:483  do_truncate+0x143/0x200 fs/open.c:66  handle_truncate fs/namei.c:3295 [inline]  do_open fs/namei.c:3640 [inline]  path_openat+0x2083/0x2750 fs/namei.c:3791  do_filp_open+0x1ba/0x410 fs/namei.c:3818  do_sys_openat2+0x16d/0x4c0 fs/open.c:1356  do_sys_open fs/open.c:1372 [inline]  __do_sys_creat fs/open.c:1448 [inline]  __se_sys_creat fs/open.c:1442 [inline]  __x64_sys_creat+0xcd/0x120 fs/open.c:1442  do_syscall_x64 arch/x86/entry/common.c:50 [inline]  do_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80  entry_SYSCALL_64_after_hwframe+0x63/0xcd  The root cause is, inodeA references inodeB via inodeB's ino, once inodeA is truncated, it calls truncate_dnode() to truncate data blocks in inodeB's node page, it traverse mapping data from node->i.i_addr[0] to node->i.i_addr[ADDRS_PER_BLOCK() - 1], result in out-of-boundary access.  This patch fixes to add sanity check on dnode page in truncate_dnode(), so that, it can help to avoid triggering such issue, and once it encounters such issue, it will record newly introduced ERROR_INVALID_NODE_REFERENCE error into superblock, later fsck can detect such issue and try repairing.  Also, it removes f2fs_truncate_data_blocks() for cleanup due to the function has only one caller, and uses f2fs_truncate_data_blocks_range() instead.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53846","epss":0.0017,"percentile":0.06636,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13005},"relatedVulnerabilities":[{"id":"CVE-2023-53846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53846","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/a6ec83786ab9f13f25fb18166dee908845713a95","https://git.kernel.org/stable/c/af0f716ad3b039cab9d426da63a5ee6c88751185"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on direct node in truncate_dnode()\n\nsyzbot reports below bug:\n\nBUG: KASAN: slab-use-after-free in f2fs_truncate_data_blocks_range+0x122a/0x14c0 fs/f2fs/file.c:574\nRead of size 4 at addr ffff88802a25c000 by task syz-executor148/5000\n\nCPU: 1 PID: 5000 Comm: syz-executor148 Not tainted 6.4.0-rc7-syzkaller-00041-ge660abd551f1 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106\n print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351\n print_report mm/kasan/report.c:462 [inline]\n kasan_report+0x11c/0x130 mm/kasan/report.c:572\n f2fs_truncate_data_blocks_range+0x122a/0x14c0 fs/f2fs/file.c:574\n truncate_dnode+0x229/0x2e0 fs/f2fs/node.c:944\n f2fs_truncate_inode_blocks+0x64b/0xde0 fs/f2fs/node.c:1154\n f2fs_do_truncate_blocks+0x4ac/0xf30 fs/f2fs/file.c:721\n f2fs_truncate_blocks+0x7b/0x300 fs/f2fs/file.c:749\n f2fs_truncate.part.0+0x4a5/0x630 fs/f2fs/file.c:799\n f2fs_truncate include/linux/fs.h:825 [inline]\n f2fs_setattr+0x1738/0x2090 fs/f2fs/file.c:1006\n notify_change+0xb2c/0x1180 fs/attr.c:483\n do_truncate+0x143/0x200 fs/open.c:66\n handle_truncate fs/namei.c:3295 [inline]\n do_open fs/namei.c:3640 [inline]\n path_openat+0x2083/0x2750 fs/namei.c:3791\n do_filp_open+0x1ba/0x410 fs/namei.c:3818\n do_sys_openat2+0x16d/0x4c0 fs/open.c:1356\n do_sys_open fs/open.c:1372 [inline]\n __do_sys_creat fs/open.c:1448 [inline]\n __se_sys_creat fs/open.c:1442 [inline]\n __x64_sys_creat+0xcd/0x120 fs/open.c:1442\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe root cause is, inodeA references inodeB via inodeB's ino, once inodeA\nis truncated, it calls truncate_dnode() to truncate data blocks in inodeB's\nnode page, it traverse mapping data from node->i.i_addr[0] to\nnode->i.i_addr[ADDRS_PER_BLOCK() - 1], result in out-of-boundary access.\n\nThis patch fixes to add sanity check on dnode page in truncate_dnode(),\nso that, it can help to avoid triggering such issue, and once it encounters\nsuch issue, it will record newly introduced ERROR_INVALID_NODE_REFERENCE\nerror into superblock, later fsck can detect such issue and try repairing.\n\nAlso, it removes f2fs_truncate_data_blocks() for cleanup due to the\nfunction has only one caller, and uses f2fs_truncate_data_blocks_range()\ninstead.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53846","epss":0.0017,"percentile":0.06636,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53851","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53851","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm/dp: Drop aux devices together with DP controller  Using devres to depopulate the aux bus made sure that upon a probe deferral the EDP panel device would be destroyed and recreated upon next attempt.  But the struct device which the devres is tied to is the DPUs (drm_dev->dev), which may be happen after the DP controller is torn down.  Indications of this can be seen in the commonly seen EDID-hexdump full of zeros in the log, or the occasional/rare KASAN fault where the panel's attempt to read the EDID information causes a use after free on DP resources.  It's tempting to move the devres to the DP controller's struct device, but the resources used by the device(s) on the aux bus are explicitly torn down in the error path. The KASAN-reported use-after-free also remains, as the DP aux \"module\" explicitly frees its devres-allocated memory in this code path.  As such, explicitly depopulate the aux bus in the error path, and in the component unbind path, to avoid these issues.  Patchwork: https://patchwork.freedesktop.org/patch/542163/","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53851","epss":0.00192,"percentile":0.0892,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15264},"relatedVulnerabilities":[{"id":"CVE-2023-53851","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53851","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2fde37445807e6e6d7981402d0bf1be0e5d81291","https://git.kernel.org/stable/c/a7bfb2ad2184a1fba78be35209b6019aa8cc8d4d","https://git.kernel.org/stable/c/e09ed06938807cb113cddd0708ed74bd8cdaff33"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dp: Drop aux devices together with DP controller\n\nUsing devres to depopulate the aux bus made sure that upon a probe\ndeferral the EDP panel device would be destroyed and recreated upon next\nattempt.\n\nBut the struct device which the devres is tied to is the DPUs\n(drm_dev->dev), which may be happen after the DP controller is torn\ndown.\n\nIndications of this can be seen in the commonly seen EDID-hexdump full\nof zeros in the log, or the occasional/rare KASAN fault where the\npanel's attempt to read the EDID information causes a use after free on\nDP resources.\n\nIt's tempting to move the devres to the DP controller's struct device,\nbut the resources used by the device(s) on the aux bus are explicitly\ntorn down in the error path. The KASAN-reported use-after-free also\nremains, as the DP aux \"module\" explicitly frees its devres-allocated\nmemory in this code path.\n\nAs such, explicitly depopulate the aux bus in the error path, and in the\ncomponent unbind path, to avoid these issues.\n\nPatchwork: https://patchwork.freedesktop.org/patch/542163/","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-53851","epss":0.00192,"percentile":0.0892,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53851","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53857","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53857","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: bpf_sk_storage: Fix invalid wait context lockdep report  './test_progs -t test_local_storage' reported a splat:  [   27.137569] ============================= [   27.138122] [ BUG: Invalid wait context ] [   27.138650] 6.5.0-03980-gd11ae1b16b0a #247 Tainted: G           O [   27.139542] ----------------------------- [   27.140106] test_progs/1729 is trying to lock: [   27.140713] ffff8883ef047b88 (stock_lock){-.-.}-{3:3}, at: local_lock_acquire+0x9/0x130 [   27.141834] other info that might help us debug this: [   27.142437] context-{5:5} [   27.142856] 2 locks held by test_progs/1729: [   27.143352]  #0: ffffffff84bcd9c0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x4/0x40 [   27.144492]  #1: ffff888107deb2c0 (&storage->lock){..-.}-{2:2}, at: bpf_local_storage_update+0x39e/0x8e0 [   27.145855] stack backtrace: [   27.146274] CPU: 0 PID: 1729 Comm: test_progs Tainted: G           O       6.5.0-03980-gd11ae1b16b0a #247 [   27.147550] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014 [   27.149127] Call Trace: [   27.149490]  <TASK> [   27.149867]  dump_stack_lvl+0x130/0x1d0 [   27.152609]  dump_stack+0x14/0x20 [   27.153131]  __lock_acquire+0x1657/0x2220 [   27.153677]  lock_acquire+0x1b8/0x510 [   27.157908]  local_lock_acquire+0x29/0x130 [   27.159048]  obj_cgroup_charge+0xf4/0x3c0 [   27.160794]  slab_pre_alloc_hook+0x28e/0x2b0 [   27.161931]  __kmem_cache_alloc_node+0x51/0x210 [   27.163557]  __kmalloc+0xaa/0x210 [   27.164593]  bpf_map_kzalloc+0xbc/0x170 [   27.165147]  bpf_selem_alloc+0x130/0x510 [   27.166295]  bpf_local_storage_update+0x5aa/0x8e0 [   27.167042]  bpf_fd_sk_storage_update_elem+0xdb/0x1a0 [   27.169199]  bpf_map_update_value+0x415/0x4f0 [   27.169871]  map_update_elem+0x413/0x550 [   27.170330]  __sys_bpf+0x5e9/0x640 [   27.174065]  __x64_sys_bpf+0x80/0x90 [   27.174568]  do_syscall_64+0x48/0xa0 [   27.175201]  entry_SYSCALL_64_after_hwframe+0x6e/0xd8 [   27.175932] RIP: 0033:0x7effb40e41ad [   27.176357] Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d8 [   27.179028] RSP: 002b:00007ffe64c21fc8 EFLAGS: 00000202 ORIG_RAX: 0000000000000141 [   27.180088] RAX: ffffffffffffffda RBX: 00007ffe64c22768 RCX: 00007effb40e41ad [   27.181082] RDX: 0000000000000020 RSI: 00007ffe64c22008 RDI: 0000000000000002 [   27.182030] RBP: 00007ffe64c21ff0 R08: 0000000000000000 R09: 00007ffe64c22788 [   27.183038] R10: 0000000000000064 R11: 0000000000000202 R12: 0000000000000000 [   27.184006] R13: 00007ffe64c22788 R14: 00007effb42a1000 R15: 0000000000000000 [   27.184958]  </TASK>  It complains about acquiring a local_lock while holding a raw_spin_lock. It means it should not allocate memory while holding a raw_spin_lock since it is not safe for RT.  raw_spin_lock is needed because bpf_local_storage supports tracing context. In particular for task local storage, it is easy to get a \"current\" task PTR_TO_BTF_ID in tracing bpf prog. However, task (and cgroup) local storage has already been moved to bpf mem allocator which can be used after raw_spin_lock.  The splat is for the sk storage. For sk (and inode) storage, it has not been moved to bpf mem allocator. Using raw_spin_lock or not, kzalloc(GFP_ATOMIC) could theoretically be unsafe in tracing context. However, the local storage helper requires a verifier accepted sk pointer (PTR_TO_BTF_ID), it is hypothetical if that (mean running a bpf prog in a kzalloc unsafe context and also able to hold a verifier accepted sk pointer) could happen.  This patch avoids kzalloc after raw_spin_lock to silent the splat. There is an existing kzalloc before the raw_spin_lock. At that point, a kzalloc is very likely required because a lookup has just been done before. Thus, this patch always does the kzalloc before acq ---truncated---","cvss":[],"epss":[{"cve":"CVE-2023-53857","epss":0.0021,"percentile":0.11193,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2023-53857","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53857","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/300415caa373a07782fcbc2f8d9429bc2dc27a47","https://git.kernel.org/stable/c/a96a44aba556c42b432929d37d60158aca21ad4c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: bpf_sk_storage: Fix invalid wait context lockdep report\n\n'./test_progs -t test_local_storage' reported a splat:\n\n[   27.137569] =============================\n[   27.138122] [ BUG: Invalid wait context ]\n[   27.138650] 6.5.0-03980-gd11ae1b16b0a #247 Tainted: G           O\n[   27.139542] -----------------------------\n[   27.140106] test_progs/1729 is trying to lock:\n[   27.140713] ffff8883ef047b88 (stock_lock){-.-.}-{3:3}, at: local_lock_acquire+0x9/0x130\n[   27.141834] other info that might help us debug this:\n[   27.142437] context-{5:5}\n[   27.142856] 2 locks held by test_progs/1729:\n[   27.143352]  #0: ffffffff84bcd9c0 (rcu_read_lock){....}-{1:3}, at: rcu_lock_acquire+0x4/0x40\n[   27.144492]  #1: ffff888107deb2c0 (&storage->lock){..-.}-{2:2}, at: bpf_local_storage_update+0x39e/0x8e0\n[   27.145855] stack backtrace:\n[   27.146274] CPU: 0 PID: 1729 Comm: test_progs Tainted: G           O       6.5.0-03980-gd11ae1b16b0a #247\n[   27.147550] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014\n[   27.149127] Call Trace:\n[   27.149490]  <TASK>\n[   27.149867]  dump_stack_lvl+0x130/0x1d0\n[   27.152609]  dump_stack+0x14/0x20\n[   27.153131]  __lock_acquire+0x1657/0x2220\n[   27.153677]  lock_acquire+0x1b8/0x510\n[   27.157908]  local_lock_acquire+0x29/0x130\n[   27.159048]  obj_cgroup_charge+0xf4/0x3c0\n[   27.160794]  slab_pre_alloc_hook+0x28e/0x2b0\n[   27.161931]  __kmem_cache_alloc_node+0x51/0x210\n[   27.163557]  __kmalloc+0xaa/0x210\n[   27.164593]  bpf_map_kzalloc+0xbc/0x170\n[   27.165147]  bpf_selem_alloc+0x130/0x510\n[   27.166295]  bpf_local_storage_update+0x5aa/0x8e0\n[   27.167042]  bpf_fd_sk_storage_update_elem+0xdb/0x1a0\n[   27.169199]  bpf_map_update_value+0x415/0x4f0\n[   27.169871]  map_update_elem+0x413/0x550\n[   27.170330]  __sys_bpf+0x5e9/0x640\n[   27.174065]  __x64_sys_bpf+0x80/0x90\n[   27.174568]  do_syscall_64+0x48/0xa0\n[   27.175201]  entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n[   27.175932] RIP: 0033:0x7effb40e41ad\n[   27.176357] Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d8\n[   27.179028] RSP: 002b:00007ffe64c21fc8 EFLAGS: 00000202 ORIG_RAX: 0000000000000141\n[   27.180088] RAX: ffffffffffffffda RBX: 00007ffe64c22768 RCX: 00007effb40e41ad\n[   27.181082] RDX: 0000000000000020 RSI: 00007ffe64c22008 RDI: 0000000000000002\n[   27.182030] RBP: 00007ffe64c21ff0 R08: 0000000000000000 R09: 00007ffe64c22788\n[   27.183038] R10: 0000000000000064 R11: 0000000000000202 R12: 0000000000000000\n[   27.184006] R13: 00007ffe64c22788 R14: 00007effb42a1000 R15: 0000000000000000\n[   27.184958]  </TASK>\n\nIt complains about acquiring a local_lock while holding a raw_spin_lock.\nIt means it should not allocate memory while holding a raw_spin_lock\nsince it is not safe for RT.\n\nraw_spin_lock is needed because bpf_local_storage supports tracing\ncontext. In particular for task local storage, it is easy to\nget a \"current\" task PTR_TO_BTF_ID in tracing bpf prog.\nHowever, task (and cgroup) local storage has already been moved to\nbpf mem allocator which can be used after raw_spin_lock.\n\nThe splat is for the sk storage. For sk (and inode) storage,\nit has not been moved to bpf mem allocator. Using raw_spin_lock or not,\nkzalloc(GFP_ATOMIC) could theoretically be unsafe in tracing context.\nHowever, the local storage helper requires a verifier accepted\nsk pointer (PTR_TO_BTF_ID), it is hypothetical if that (mean running\na bpf prog in a kzalloc unsafe context and also able to hold a verifier\naccepted sk pointer) could happen.\n\nThis patch avoids kzalloc after raw_spin_lock to silent the splat.\nThere is an existing kzalloc before the raw_spin_lock. At that point,\na kzalloc is very likely required because a lookup has just been done\nbefore. Thus, this patch always does the kzalloc before acq\n---truncated---","cvss":[],"epss":[{"cve":"CVE-2023-53857","epss":0.0021,"percentile":0.11193,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53857","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-53999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-53999","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: TC, Fix internal port memory leak  The flow rule can be splited, and the extra post_act rules are added to post_act table. It's possible to trigger memleak when the rule forwards packets from internal port and over tunnel, in the case that, for example, CT 'new' state offload is allowed. As int_port object is assigned to the flow attribute of post_act rule, and its refcnt is incremented by mlx5e_tc_int_port_get(), but mlx5e_tc_int_port_put() is not called, the refcnt is never decremented, then int_port is never freed.  The kmemleak reports the following error: unreferenced object 0xffff888128204b80 (size 64):   comm \"handler20\", pid 50121, jiffies 4296973009 (age 642.932s)   hex dump (first 32 bytes):     01 00 00 00 19 00 00 00 03 f0 00 00 04 00 00 00  ................     98 77 67 41 81 88 ff ff 98 77 67 41 81 88 ff ff  .wgA.....wgA....   backtrace:     [<00000000e992680d>] kmalloc_trace+0x27/0x120     [<000000009e945a98>] mlx5e_tc_int_port_get+0x3f3/0xe20 [mlx5_core]     [<0000000035a537f0>] mlx5e_tc_add_fdb_flow+0x473/0xcf0 [mlx5_core]     [<0000000070c2cec6>] __mlx5e_add_fdb_flow+0x7cf/0xe90 [mlx5_core]     [<000000005cc84048>] mlx5e_configure_flower+0xd40/0x4c40 [mlx5_core]     [<000000004f8a2031>] mlx5e_rep_indr_offload.isra.0+0x10e/0x1c0 [mlx5_core]     [<000000007df797dc>] mlx5e_rep_indr_setup_tc_cb+0x90/0x130 [mlx5_core]     [<0000000016c15cc3>] tc_setup_cb_add+0x1cf/0x410     [<00000000a63305b4>] fl_hw_replace_filter+0x38f/0x670 [cls_flower]     [<000000008bc9e77c>] fl_change+0x1fd5/0x4430 [cls_flower]     [<00000000e7f766e4>] tc_new_tfilter+0x867/0x2010     [<00000000e101c0ef>] rtnetlink_rcv_msg+0x6fc/0x9f0     [<00000000e1111d44>] netlink_rcv_skb+0x12c/0x360     [<0000000082dd6c8b>] netlink_unicast+0x438/0x710     [<00000000fc568f70>] netlink_sendmsg+0x794/0xc50     [<0000000016e92590>] sock_sendmsg+0xc5/0x190  So fix this by moving int_port cleanup code to the flow attribute free helper, which is used by all the attribute free cases.","cvss":[],"epss":[{"cve":"CVE-2023-53999","epss":0.00185,"percentile":0.08196,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0925},"relatedVulnerabilities":[{"id":"CVE-2023-53999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-53999","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/ac5da544a3c2047cbfd715acd9cec8380d7fe5c6","https://git.kernel.org/stable/c/bc1918bac0f30e3f551ef5649b53062917db55fa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: TC, Fix internal port memory leak\n\nThe flow rule can be splited, and the extra post_act rules are added\nto post_act table. It's possible to trigger memleak when the rule\nforwards packets from internal port and over tunnel, in the case that,\nfor example, CT 'new' state offload is allowed. As int_port object is\nassigned to the flow attribute of post_act rule, and its refcnt is\nincremented by mlx5e_tc_int_port_get(), but mlx5e_tc_int_port_put() is\nnot called, the refcnt is never decremented, then int_port is never\nfreed.\n\nThe kmemleak reports the following error:\nunreferenced object 0xffff888128204b80 (size 64):\n  comm \"handler20\", pid 50121, jiffies 4296973009 (age 642.932s)\n  hex dump (first 32 bytes):\n    01 00 00 00 19 00 00 00 03 f0 00 00 04 00 00 00  ................\n    98 77 67 41 81 88 ff ff 98 77 67 41 81 88 ff ff  .wgA.....wgA....\n  backtrace:\n    [<00000000e992680d>] kmalloc_trace+0x27/0x120\n    [<000000009e945a98>] mlx5e_tc_int_port_get+0x3f3/0xe20 [mlx5_core]\n    [<0000000035a537f0>] mlx5e_tc_add_fdb_flow+0x473/0xcf0 [mlx5_core]\n    [<0000000070c2cec6>] __mlx5e_add_fdb_flow+0x7cf/0xe90 [mlx5_core]\n    [<000000005cc84048>] mlx5e_configure_flower+0xd40/0x4c40 [mlx5_core]\n    [<000000004f8a2031>] mlx5e_rep_indr_offload.isra.0+0x10e/0x1c0 [mlx5_core]\n    [<000000007df797dc>] mlx5e_rep_indr_setup_tc_cb+0x90/0x130 [mlx5_core]\n    [<0000000016c15cc3>] tc_setup_cb_add+0x1cf/0x410\n    [<00000000a63305b4>] fl_hw_replace_filter+0x38f/0x670 [cls_flower]\n    [<000000008bc9e77c>] fl_change+0x1fd5/0x4430 [cls_flower]\n    [<00000000e7f766e4>] tc_new_tfilter+0x867/0x2010\n    [<00000000e101c0ef>] rtnetlink_rcv_msg+0x6fc/0x9f0\n    [<00000000e1111d44>] netlink_rcv_skb+0x12c/0x360\n    [<0000000082dd6c8b>] netlink_unicast+0x438/0x710\n    [<00000000fc568f70>] netlink_sendmsg+0x794/0xc50\n    [<0000000016e92590>] sock_sendmsg+0xc5/0x190\n\nSo fix this by moving int_port cleanup code to the flow attribute\nfree helper, which is used by all the attribute free cases.","cvss":[],"epss":[{"cve":"CVE-2023-53999","epss":0.00185,"percentile":0.08196,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-53999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54013","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54013","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  interconnect: Fix locking for runpm vs reclaim  For cases where icc_bw_set() can be called in callbaths that could deadlock against shrinker/reclaim, such as runpm resume, we need to decouple the icc locking.  Introduce a new icc_bw_lock for cases where we need to serialize bw aggregation and update to decouple that from paths that require memory allocation such as node/link creation/ destruction.  Fixes this lockdep splat:     ======================================================    WARNING: possible circular locking dependency detected    6.2.0-rc8-debug+ #554 Not tainted    ------------------------------------------------------    ring0/132 is trying to acquire lock:    ffffff80871916d0 (&gmu->lock){+.+.}-{3:3}, at: a6xx_pm_resume+0xf0/0x234     but task is already holding lock:    ffffffdb5aee57e8 (dma_fence_map){++++}-{0:0}, at: msm_job_run+0x68/0x150     which lock already depends on the new lock.     the existing dependency chain (in reverse order) is:     -> #4 (dma_fence_map){++++}-{0:0}:           __dma_fence_might_wait+0x74/0xc0           dma_resv_lockdep+0x1f4/0x2f4           do_one_initcall+0x104/0x2bc           kernel_init_freeable+0x344/0x34c           kernel_init+0x30/0x134           ret_from_fork+0x10/0x20     -> #3 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}:           fs_reclaim_acquire+0x80/0xa8           slab_pre_alloc_hook.constprop.0+0x40/0x25c           __kmem_cache_alloc_node+0x60/0x1cc           __kmalloc+0xd8/0x100           topology_parse_cpu_capacity+0x8c/0x178           get_cpu_for_node+0x88/0xc4           parse_cluster+0x1b0/0x28c           parse_cluster+0x8c/0x28c           init_cpu_topology+0x168/0x188           smp_prepare_cpus+0x24/0xf8           kernel_init_freeable+0x18c/0x34c           kernel_init+0x30/0x134           ret_from_fork+0x10/0x20     -> #2 (fs_reclaim){+.+.}-{0:0}:           __fs_reclaim_acquire+0x3c/0x48           fs_reclaim_acquire+0x54/0xa8           slab_pre_alloc_hook.constprop.0+0x40/0x25c           __kmem_cache_alloc_node+0x60/0x1cc           __kmalloc+0xd8/0x100           kzalloc.constprop.0+0x14/0x20           icc_node_create_nolock+0x4c/0xc4           icc_node_create+0x38/0x58           qcom_icc_rpmh_probe+0x1b8/0x248           platform_probe+0x70/0xc4           really_probe+0x158/0x290           __driver_probe_device+0xc8/0xe0           driver_probe_device+0x44/0x100           __driver_attach+0xf8/0x108           bus_for_each_dev+0x78/0xc4           driver_attach+0x2c/0x38           bus_add_driver+0xd0/0x1d8           driver_register+0xbc/0xf8           __platform_driver_register+0x30/0x3c           qnoc_driver_init+0x24/0x30           do_one_initcall+0x104/0x2bc           kernel_init_freeable+0x344/0x34c           kernel_init+0x30/0x134           ret_from_fork+0x10/0x20     -> #1 (icc_lock){+.+.}-{3:3}:           __mutex_lock+0xcc/0x3c8           mutex_lock_nested+0x30/0x44           icc_set_bw+0x88/0x2b4           _set_opp_bw+0x8c/0xd8           _set_opp+0x19c/0x300           dev_pm_opp_set_opp+0x84/0x94           a6xx_gmu_resume+0x18c/0x804           a6xx_pm_resume+0xf8/0x234           adreno_runtime_resume+0x2c/0x38           pm_generic_runtime_resume+0x30/0x44           __rpm_callback+0x15c/0x174           rpm_callback+0x78/0x7c           rpm_resume+0x318/0x524           __pm_runtime_resume+0x78/0xbc           adreno_load_gpu+0xc4/0x17c           msm_open+0x50/0x120           drm_file_alloc+0x17c/0x228           drm_open_helper+0x74/0x118           drm_open+0xa0/0x144           drm_stub_open+0xd4/0xe4           chrdev_open+0x1b8/0x1e4           do_dentry_open+0x2f8/0x38c           vfs_open+0x34/0x40           path_openat+0x64c/0x7b4           do_filp_open+0x54/0xc4           do_sys_openat2+0x9c/0x100           do_sys_open+0x50/0x7c           __arm64_sys_openat+0x28/0x34           invoke_syscall+0x8c/0x128           el0_svc_common.constprop.0+0xa0/0x11c           do_el0_ ---truncated---","cvss":[],"epss":[{"cve":"CVE-2023-54013","epss":0.00189,"percentile":0.08661,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2023-54013","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54013","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2f3a124696d43de3c837f87a9f767c56ee86cf2a","https://git.kernel.org/stable/c/af42269c3523492d71ebbe11fefae2653e9cdc78"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ninterconnect: Fix locking for runpm vs reclaim\n\nFor cases where icc_bw_set() can be called in callbaths that could\ndeadlock against shrinker/reclaim, such as runpm resume, we need to\ndecouple the icc locking.  Introduce a new icc_bw_lock for cases where\nwe need to serialize bw aggregation and update to decouple that from\npaths that require memory allocation such as node/link creation/\ndestruction.\n\nFixes this lockdep splat:\n\n   ======================================================\n   WARNING: possible circular locking dependency detected\n   6.2.0-rc8-debug+ #554 Not tainted\n   ------------------------------------------------------\n   ring0/132 is trying to acquire lock:\n   ffffff80871916d0 (&gmu->lock){+.+.}-{3:3}, at: a6xx_pm_resume+0xf0/0x234\n\n   but task is already holding lock:\n   ffffffdb5aee57e8 (dma_fence_map){++++}-{0:0}, at: msm_job_run+0x68/0x150\n\n   which lock already depends on the new lock.\n\n   the existing dependency chain (in reverse order) is:\n\n   -> #4 (dma_fence_map){++++}-{0:0}:\n          __dma_fence_might_wait+0x74/0xc0\n          dma_resv_lockdep+0x1f4/0x2f4\n          do_one_initcall+0x104/0x2bc\n          kernel_init_freeable+0x344/0x34c\n          kernel_init+0x30/0x134\n          ret_from_fork+0x10/0x20\n\n   -> #3 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}:\n          fs_reclaim_acquire+0x80/0xa8\n          slab_pre_alloc_hook.constprop.0+0x40/0x25c\n          __kmem_cache_alloc_node+0x60/0x1cc\n          __kmalloc+0xd8/0x100\n          topology_parse_cpu_capacity+0x8c/0x178\n          get_cpu_for_node+0x88/0xc4\n          parse_cluster+0x1b0/0x28c\n          parse_cluster+0x8c/0x28c\n          init_cpu_topology+0x168/0x188\n          smp_prepare_cpus+0x24/0xf8\n          kernel_init_freeable+0x18c/0x34c\n          kernel_init+0x30/0x134\n          ret_from_fork+0x10/0x20\n\n   -> #2 (fs_reclaim){+.+.}-{0:0}:\n          __fs_reclaim_acquire+0x3c/0x48\n          fs_reclaim_acquire+0x54/0xa8\n          slab_pre_alloc_hook.constprop.0+0x40/0x25c\n          __kmem_cache_alloc_node+0x60/0x1cc\n          __kmalloc+0xd8/0x100\n          kzalloc.constprop.0+0x14/0x20\n          icc_node_create_nolock+0x4c/0xc4\n          icc_node_create+0x38/0x58\n          qcom_icc_rpmh_probe+0x1b8/0x248\n          platform_probe+0x70/0xc4\n          really_probe+0x158/0x290\n          __driver_probe_device+0xc8/0xe0\n          driver_probe_device+0x44/0x100\n          __driver_attach+0xf8/0x108\n          bus_for_each_dev+0x78/0xc4\n          driver_attach+0x2c/0x38\n          bus_add_driver+0xd0/0x1d8\n          driver_register+0xbc/0xf8\n          __platform_driver_register+0x30/0x3c\n          qnoc_driver_init+0x24/0x30\n          do_one_initcall+0x104/0x2bc\n          kernel_init_freeable+0x344/0x34c\n          kernel_init+0x30/0x134\n          ret_from_fork+0x10/0x20\n\n   -> #1 (icc_lock){+.+.}-{3:3}:\n          __mutex_lock+0xcc/0x3c8\n          mutex_lock_nested+0x30/0x44\n          icc_set_bw+0x88/0x2b4\n          _set_opp_bw+0x8c/0xd8\n          _set_opp+0x19c/0x300\n          dev_pm_opp_set_opp+0x84/0x94\n          a6xx_gmu_resume+0x18c/0x804\n          a6xx_pm_resume+0xf8/0x234\n          adreno_runtime_resume+0x2c/0x38\n          pm_generic_runtime_resume+0x30/0x44\n          __rpm_callback+0x15c/0x174\n          rpm_callback+0x78/0x7c\n          rpm_resume+0x318/0x524\n          __pm_runtime_resume+0x78/0xbc\n          adreno_load_gpu+0xc4/0x17c\n          msm_open+0x50/0x120\n          drm_file_alloc+0x17c/0x228\n          drm_open_helper+0x74/0x118\n          drm_open+0xa0/0x144\n          drm_stub_open+0xd4/0xe4\n          chrdev_open+0x1b8/0x1e4\n          do_dentry_open+0x2f8/0x38c\n          vfs_open+0x34/0x40\n          path_openat+0x64c/0x7b4\n          do_filp_open+0x54/0xc4\n          do_sys_openat2+0x9c/0x100\n          do_sys_open+0x50/0x7c\n          __arm64_sys_openat+0x28/0x34\n          invoke_syscall+0x8c/0x128\n          el0_svc_common.constprop.0+0xa0/0x11c\n          do_el0_\n---truncated---","cvss":[],"epss":[{"cve":"CVE-2023-54013","epss":0.00189,"percentile":0.08661,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54013","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54030","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54030","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  io_uring/net: don't overflow multishot recv  Don't allow overflowing multishot recv CQEs, it might get out of hand, hurt performance, and in the worst case scenario OOM the task.","cvss":[],"epss":[{"cve":"CVE-2023-54030","epss":0.00169,"percentile":0.06472,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0845},"relatedVulnerabilities":[{"id":"CVE-2023-54030","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54030","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1e2db9837be7d24a2a74eb3f3906d0872bee8907","https://git.kernel.org/stable/c/b2e74db55dd93d6db22a813c9a775b5dbf87c560"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/net: don't overflow multishot recv\n\nDon't allow overflowing multishot recv CQEs, it might get out of\nhand, hurt performance, and in the worst case scenario OOM the task.","cvss":[],"epss":[{"cve":"CVE-2023-54030","epss":0.00169,"percentile":0.06472,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54030","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54088","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54088","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  blk-cgroup: hold queue_lock when removing blkg->q_node  When blkg is removed from q->blkg_list from blkg_free_workfn(), queue_lock has to be held, otherwise, all kinds of bugs(list corruption, hard lockup, ..) can be triggered from blkg_destroy_all().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-54088","epss":0.0016,"percentile":0.05542,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12240000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-54088","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54088","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/083b58373463a6e5ee60ecb135269348f68ad7df","https://git.kernel.org/stable/c/b5dae1cd0d8368b4338430ff93403df67f0b8bcc","https://git.kernel.org/stable/c/c164c7bc9775be7bcc68754bb3431fce5823822e","https://git.kernel.org/stable/c/cd4ffdf56791eec95af01f06bee1ec7665ca75c4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: hold queue_lock when removing blkg->q_node\n\nWhen blkg is removed from q->blkg_list from blkg_free_workfn(), queue_lock\nhas to be held, otherwise, all kinds of bugs(list corruption, hard lockup,\n..) can be triggered from blkg_destroy_all().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-54088","epss":0.0016,"percentile":0.05542,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54088","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54107","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54107","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  blk-cgroup: dropping parent refcount after pd_free_fn() is done  Some cgroup policies will access parent pd through child pd even after pd_offline_fn() is done. If pd_free_fn() for parent is called before child, then UAF can be triggered. Hence it's better to guarantee the order of pd_free_fn().  Currently refcount of parent blkg is dropped in __blkg_release(), which is before pd_free_fn() is called in blkg_free_work_fn() while blkg_free_work_fn() is called asynchronously.  This patch make sure pd_free_fn() called from removing cgroup is ordered by delaying dropping parent refcount after calling pd_free_fn() for child.  BTW, pd_free_fn() will also be called from blkcg_deactivate_policy() from deleting device, and following patches will guarantee the order.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-54107","epss":0.00147,"percentile":0.04274,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.112455},"relatedVulnerabilities":[{"id":"CVE-2023-54107","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54107","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/c7241babf0855d8a6180cd1743ff0ec34de40b4e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: dropping parent refcount after pd_free_fn() is done\n\nSome cgroup policies will access parent pd through child pd even\nafter pd_offline_fn() is done. If pd_free_fn() for parent is called\nbefore child, then UAF can be triggered. Hence it's better to guarantee\nthe order of pd_free_fn().\n\nCurrently refcount of parent blkg is dropped in __blkg_release(), which\nis before pd_free_fn() is called in blkg_free_work_fn() while\nblkg_free_work_fn() is called asynchronously.\n\nThis patch make sure pd_free_fn() called from removing cgroup is ordered\nby delaying dropping parent refcount after calling pd_free_fn() for\nchild.\n\nBTW, pd_free_fn() will also be called from blkcg_deactivate_policy()\nfrom deleting device, and following patches will guarantee the order.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-54107","epss":0.00147,"percentile":0.04274,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54107","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54141","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: Add missing hw_ops->get_ring_selector() for IPQ5018  During sending data after clients connected, hw_ops->get_ring_selector() will be called. But for IPQ5018, this member isn't set, and the following NULL pointer exception will be occurred:  \t[   38.840478] 8<--- cut here --- \t[   38.840517] Unable to handle kernel NULL pointer dereference at virtual address 00000000 \t... \t[   38.923161] PC is at 0x0 \t[   38.927930] LR is at ath11k_dp_tx+0x70/0x730 [ath11k] \t... \t[   39.063264] Process hostapd (pid: 1034, stack limit = 0x801ceb3d) \t[   39.068994] Stack: (0x856a9a68 to 0x856aa000) \t... \t[   39.438467] [<7f323804>] (ath11k_dp_tx [ath11k]) from [<7f314e6c>] (ath11k_mac_op_tx+0x80/0x190 [ath11k]) \t[   39.446607] [<7f314e6c>] (ath11k_mac_op_tx [ath11k]) from [<7f17dbe0>] (ieee80211_handle_wake_tx_queue+0x7c/0xc0 [mac80211]) \t[   39.456162] [<7f17dbe0>] (ieee80211_handle_wake_tx_queue [mac80211]) from [<7f174450>] (ieee80211_probereq_get+0x584/0x704 [mac80211]) \t[   39.467443] [<7f174450>] (ieee80211_probereq_get [mac80211]) from [<7f178c40>] (ieee80211_tx_prepare_skb+0x1f8/0x248 [mac80211]) \t[   39.479334] [<7f178c40>] (ieee80211_tx_prepare_skb [mac80211]) from [<7f179e28>] (__ieee80211_subif_start_xmit+0x32c/0x3d4 [mac80211]) \t[   39.491053] [<7f179e28>] (__ieee80211_subif_start_xmit [mac80211]) from [<7f17af08>] (ieee80211_tx_control_port+0x19c/0x288 [mac80211]) \t[   39.502946] [<7f17af08>] (ieee80211_tx_control_port [mac80211]) from [<7f0fc704>] (nl80211_tx_control_port+0x174/0x1d4 [cfg80211]) \t[   39.515017] [<7f0fc704>] (nl80211_tx_control_port [cfg80211]) from [<808ceac4>] (genl_rcv_msg+0x154/0x340) \t[   39.526814] [<808ceac4>] (genl_rcv_msg) from [<808cdb74>] (netlink_rcv_skb+0xb8/0x11c) \t[   39.536446] [<808cdb74>] (netlink_rcv_skb) from [<808ce1d0>] (genl_rcv+0x28/0x34) \t[   39.544344] [<808ce1d0>] (genl_rcv) from [<808cd234>] (netlink_unicast+0x174/0x274) \t[   39.551895] [<808cd234>] (netlink_unicast) from [<808cd510>] (netlink_sendmsg+0x1dc/0x440) \t[   39.559362] [<808cd510>] (netlink_sendmsg) from [<808596e0>] (____sys_sendmsg+0x1a8/0x1fc) \t[   39.567697] [<808596e0>] (____sys_sendmsg) from [<8085b1a8>] (___sys_sendmsg+0xa4/0xdc) \t[   39.575941] [<8085b1a8>] (___sys_sendmsg) from [<8085b310>] (sys_sendmsg+0x44/0x74) \t[   39.583841] [<8085b310>] (sys_sendmsg) from [<80300060>] (ret_fast_syscall+0x0/0x40) \t... \t[   39.620734] Code: bad PC value \t[   39.625869] ---[ end trace 8aef983ad3cbc032 ]---","cvss":[],"epss":[{"cve":"CVE-2023-54141","epss":0.00204,"percentile":0.10387,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10200000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-54141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54141","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/c36289e3c5e83286974ef68c20c821fd5b63801c","https://git.kernel.org/stable/c/ce282d8de71f07f0056ea319541141152c65f552","https://git.kernel.org/stable/c/d1992d72a359732f143cc962917104d193705da7","https://git.kernel.org/stable/c/d49d420e4833fdf6d7c506de23884a0cb9b08e0a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: Add missing hw_ops->get_ring_selector() for IPQ5018\n\nDuring sending data after clients connected, hw_ops->get_ring_selector()\nwill be called. But for IPQ5018, this member isn't set, and the\nfollowing NULL pointer exception will be occurred:\n\n\t[   38.840478] 8<--- cut here ---\n\t[   38.840517] Unable to handle kernel NULL pointer dereference at virtual address 00000000\n\t...\n\t[   38.923161] PC is at 0x0\n\t[   38.927930] LR is at ath11k_dp_tx+0x70/0x730 [ath11k]\n\t...\n\t[   39.063264] Process hostapd (pid: 1034, stack limit = 0x801ceb3d)\n\t[   39.068994] Stack: (0x856a9a68 to 0x856aa000)\n\t...\n\t[   39.438467] [<7f323804>] (ath11k_dp_tx [ath11k]) from [<7f314e6c>] (ath11k_mac_op_tx+0x80/0x190 [ath11k])\n\t[   39.446607] [<7f314e6c>] (ath11k_mac_op_tx [ath11k]) from [<7f17dbe0>] (ieee80211_handle_wake_tx_queue+0x7c/0xc0 [mac80211])\n\t[   39.456162] [<7f17dbe0>] (ieee80211_handle_wake_tx_queue [mac80211]) from [<7f174450>] (ieee80211_probereq_get+0x584/0x704 [mac80211])\n\t[   39.467443] [<7f174450>] (ieee80211_probereq_get [mac80211]) from [<7f178c40>] (ieee80211_tx_prepare_skb+0x1f8/0x248 [mac80211])\n\t[   39.479334] [<7f178c40>] (ieee80211_tx_prepare_skb [mac80211]) from [<7f179e28>] (__ieee80211_subif_start_xmit+0x32c/0x3d4 [mac80211])\n\t[   39.491053] [<7f179e28>] (__ieee80211_subif_start_xmit [mac80211]) from [<7f17af08>] (ieee80211_tx_control_port+0x19c/0x288 [mac80211])\n\t[   39.502946] [<7f17af08>] (ieee80211_tx_control_port [mac80211]) from [<7f0fc704>] (nl80211_tx_control_port+0x174/0x1d4 [cfg80211])\n\t[   39.515017] [<7f0fc704>] (nl80211_tx_control_port [cfg80211]) from [<808ceac4>] (genl_rcv_msg+0x154/0x340)\n\t[   39.526814] [<808ceac4>] (genl_rcv_msg) from [<808cdb74>] (netlink_rcv_skb+0xb8/0x11c)\n\t[   39.536446] [<808cdb74>] (netlink_rcv_skb) from [<808ce1d0>] (genl_rcv+0x28/0x34)\n\t[   39.544344] [<808ce1d0>] (genl_rcv) from [<808cd234>] (netlink_unicast+0x174/0x274)\n\t[   39.551895] [<808cd234>] (netlink_unicast) from [<808cd510>] (netlink_sendmsg+0x1dc/0x440)\n\t[   39.559362] [<808cd510>] (netlink_sendmsg) from [<808596e0>] (____sys_sendmsg+0x1a8/0x1fc)\n\t[   39.567697] [<808596e0>] (____sys_sendmsg) from [<8085b1a8>] (___sys_sendmsg+0xa4/0xdc)\n\t[   39.575941] [<8085b1a8>] (___sys_sendmsg) from [<8085b310>] (sys_sendmsg+0x44/0x74)\n\t[   39.583841] [<8085b310>] (sys_sendmsg) from [<80300060>] (ret_fast_syscall+0x0/0x40)\n\t...\n\t[   39.620734] Code: bad PC value\n\t[   39.625869] ---[ end trace 8aef983ad3cbc032 ]---","cvss":[],"epss":[{"cve":"CVE-2023-54141","epss":0.00204,"percentile":0.10387,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54141","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54227","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54227","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  blk-mq: fix tags leak when shrink nr_hw_queues  Although we don't need to realloc set->tags[] when shrink nr_hw_queues, we need to free them. Or these tags will be leaked.  How to reproduce: 1. mount -t configfs configfs /mnt 2. modprobe null_blk nr_devices=0 submit_queues=8 3. mkdir /mnt/nullb/nullb0 4. echo 1 > /mnt/nullb/nullb0/power 5. echo 4 > /mnt/nullb/nullb0/submit_queues 6. rmdir /mnt/nullb/nullb0  In step 4, will alloc 9 tags (8 submit queues and 1 poll queue), then in step 5, new_nr_hw_queues = 5 (4 submit queues and 1 poll queue). At last in step 6, only these 5 tags are freed, the other 4 tags leaked.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-54227","epss":0.00403,"percentile":0.33736,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.30225},"relatedVulnerabilities":[{"id":"CVE-2023-54227","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54227","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/c0ef7493e68b8896806a2f598fcffbaa97333405","https://git.kernel.org/stable/c/e1dd7bc93029024af5688253b0c05181d6e01f8e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: fix tags leak when shrink nr_hw_queues\n\nAlthough we don't need to realloc set->tags[] when shrink nr_hw_queues,\nwe need to free them. Or these tags will be leaked.\n\nHow to reproduce:\n1. mount -t configfs configfs /mnt\n2. modprobe null_blk nr_devices=0 submit_queues=8\n3. mkdir /mnt/nullb/nullb0\n4. echo 1 > /mnt/nullb/nullb0/power\n5. echo 4 > /mnt/nullb/nullb0/submit_queues\n6. rmdir /mnt/nullb/nullb0\n\nIn step 4, will alloc 9 tags (8 submit queues and 1 poll queue), then\nin step 5, new_nr_hw_queues = 5 (4 submit queues and 1 poll queue).\nAt last in step 6, only these 5 tags are freed, the other 4 tags leaked.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-54227","epss":0.00403,"percentile":0.33736,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54227","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54233","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54233","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: SOF: avoid a NULL dereference with unsupported widgets  If an IPC4 topology contains an unsupported widget, its .module_info field won't be set, then sof_ipc4_route_setup() will cause a kernel Oops trying to dereference it. Add a check for such cases.","cvss":[],"epss":[{"cve":"CVE-2023-54233","epss":0.00181,"percentile":0.07789,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0905},"relatedVulnerabilities":[{"id":"CVE-2023-54233","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54233","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/170818974e9732506195c6302743856cc8bdfd6f","https://git.kernel.org/stable/c/e3720f92e0237921da537e47a0b24e27899203f8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: avoid a NULL dereference with unsupported widgets\n\nIf an IPC4 topology contains an unsupported widget, its .module_info\nfield won't be set, then sof_ipc4_route_setup() will cause a kernel\nOops trying to dereference it. Add a check for such cases.","cvss":[],"epss":[{"cve":"CVE-2023-54233","epss":0.00181,"percentile":0.07789,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54233","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54263","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54263","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/nouveau/kms/nv50-: init hpd_irq_lock for PIOR DP  Fixes OOPS on boards with ANX9805 DP encoders.","cvss":[],"epss":[{"cve":"CVE-2023-54263","epss":0.00195,"percentile":0.09335,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2023-54263","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54263","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/92d48ce21645267c574268678131cd2b648dad0f","https://git.kernel.org/stable/c/a63fa556ac5772d004025c1164b7bd5a8b95eaef","https://git.kernel.org/stable/c/ea293f823a8805735d9e00124df81a8f448ed1ae"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/kms/nv50-: init hpd_irq_lock for PIOR DP\n\nFixes OOPS on boards with ANX9805 DP encoders.","cvss":[],"epss":[{"cve":"CVE-2023-54263","epss":0.00195,"percentile":0.09335,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54263","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-54280","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-54280","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cifs: fix potential race when tree connecting ipc  Protect access of TCP_Server_Info::hostname when building the ipc tree name as it might get freed in cifsd thread and thus causing an use-after-free bug in __tree_connect_dfs_target().  Also, while at it, update status of IPC tcon on success and then avoid any extra tree connects.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-54280","epss":0.00503,"percentile":0.41407,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.47282},"relatedVulnerabilities":[{"id":"CVE-2023-54280","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-54280","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/536ec71ba060a02fabe8e22cecb82fe7b3a8708b","https://git.kernel.org/stable/c/553476df55a111e6a66ad9155256aec0ec1b7ad0","https://git.kernel.org/stable/c/ee20d7c6100752eaf2409d783f4f1449c29ea33d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix potential race when tree connecting ipc\n\nProtect access of TCP_Server_Info::hostname when building the ipc tree\nname as it might get freed in cifsd thread and thus causing an\nuse-after-free bug in __tree_connect_dfs_target().  Also, while at it,\nupdate status of IPC tcon on success and then avoid any extra tree\nconnects.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-54280","epss":0.00503,"percentile":0.41407,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-54280","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-6039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6039","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb/lan78xx in the Linux Kernel. This flaw allows a local attacker to crash the system when the LAN78XX USB device detaches.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6039","epss":0.00258,"percentile":0.17412,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6039","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-6039","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13545000000000001},"relatedVulnerabilities":[{"id":"CVE-2023-6039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6039","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2023-6039","https://bugzilla.redhat.com/show_bug.cgi?id=2248755","https://github.com/torvalds/linux/commit/1e7417c188d0a83fb385ba2dbe35fd2563f2b6f3"],"description":"A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb/lan78xx in the Linux Kernel. This flaw allows a local attacker to crash the system when the LAN78XX USB device detaches.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6039","epss":0.00258,"percentile":0.17412,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6039","cwe":"CWE-416","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-6039","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2023-6240","dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-6240","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6240","epss":0.00969,"percentile":0.59793,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6240","cwe":"CWE-203","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-6240","cwe":"CWE-203","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.557175},"relatedVulnerabilities":[{"id":"CVE-2023-6240","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6240","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/errata/RHSA-2024:1881","https://access.redhat.com/errata/RHSA-2024:1882","https://access.redhat.com/errata/RHSA-2024:2758","https://access.redhat.com/errata/RHSA-2024:3414","https://access.redhat.com/errata/RHSA-2024:3421","https://access.redhat.com/errata/RHSA-2024:3618","https://access.redhat.com/errata/RHSA-2024:3627","https://access.redhat.com/security/cve/CVE-2023-6240","https://bugzilla.redhat.com/show_bug.cgi?id=2250843","https://people.redhat.com/~hkario/marvin/","https://securitypitfalls.wordpress.com/2023/10/16/experiment-with-side-channel-attacks-yourself/","https://security.netapp.com/advisory/ntap-20240628-0002/"],"description":"A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.3,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-6240","epss":0.00969,"percentile":0.59793,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2023-6240","cwe":"CWE-203","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2023-6240","cwe":"CWE-203","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2023-6240","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-0564","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-0564","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is \"max page sharing=256\", it is possible for the attacker to time the unmap to merge with the victim's page. The unmapping time depends on whether it merges with the victim's page and additional physical pages are created beyond the KSM's \"max page share\". Through these operations, the attacker can leak the victim's page.","cvss":[],"epss":[{"cve":"CVE-2024-0564","epss":0.00623,"percentile":0.47822,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-0564","cwe":"CWE-203","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-0564","cwe":"CWE-203","source":"nvd@nist.gov","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.031150000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-0564","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0564","namespace":"nvd:cpe","severity":"Medium","urls":["https://access.redhat.com/security/cve/CVE-2024-0564","https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1680513","https://bugzilla.redhat.com/show_bug.cgi?id=2258514","https://link.springer.com/conference/wisa","https://wisa.or.kr/accepted"],"description":"A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is \"max page sharing=256\", it is possible for the attacker to time the unmap to merge with the victim's page. The unmapping time depends on whether it merges with the victim's page and additional physical pages are created beyond the KSM's \"max page share\". Through these operations, the attacker can leak the victim's page.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"exploitabilityScore":2.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"secalert@redhat.com","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"exploitabilityScore":1.7,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-0564","epss":0.00623,"percentile":0.47822,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-0564","cwe":"CWE-203","source":"secalert@redhat.com","type":"Secondary"},{"cve":"CVE-2024-0564","cwe":"CWE-203","source":"nvd@nist.gov","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-0564","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-14040","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-14040","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: nexthop: Increase weight to u16  In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. With high fan-out of the involved nodes, and overall high number of nodes, a (non-)ECMP weight ratio that we would like to configure does not fit into 8 bits. Instead of, say, 255:254, we might like to configure something like 1000:999. For these deployments, the 8-bit weight may not be enough.  To that end, in this patch increase the next hop weight from u8 to u16.  Increasing the width of an integral type can be tricky, because while the code still compiles, the types may not check out anymore, and numerical errors come up. To prevent this, the conversion was done in two steps. First the type was changed from u8 to a single-member structure, which invalidated all uses of the field. This allowed going through them one by one and audit for type correctness. Then the structure was replaced with a vanilla u16 again. This should ensure that no place was missed.  The UAPI for configuring nexthop group members is that an attribute NHA_GROUP carries an array of struct nexthop_grp entries:  \tstruct nexthop_grp { \t\t__u32\tid;\t  /* nexthop id - must exist */ \t\t__u8\tweight;   /* weight of this nexthop */ \t\t__u8\tresvd1; \t\t__u16\tresvd2; \t};  The field resvd1 is currently validated and required to be zero. We can lift this requirement and carry high-order bits of the weight in the reserved field:  \tstruct nexthop_grp { \t\t__u32\tid;\t  /* nexthop id - must exist */ \t\t__u8\tweight;   /* weight of this nexthop */ \t\t__u8\tweight_high; \t\t__u16\tresvd2; \t};  Keeping the fields split this way was chosen in case an existing userspace makes assumptions about the width of the weight field, and to sidestep any endianness issues.  The weight field is currently encoded as the weight value minus one, because weight of 0 is invalid. This same trick is impossible for the new weight_high field, because zero must mean actual zero. With this in place:  - Old userspace is guaranteed to carry weight_high of 0, therefore   configuring 8-bit weights as appropriate. When dumping nexthops with   16-bit weight, it would only show the lower 8 bits. But configuring such   nexthops implies existence of userspace aware of the extension in the   first place.  - New userspace talking to an old kernel will work as long as it only   attempts to configure 8-bit weights, where the high-order bits are zero.   Old kernel will bounce attempts at configuring >8-bit weights.  Renaming reserved fields as they are allocated for some purpose is commonly done in Linux. Whoever touches a reserved field is doing so at their own risk. nexthop_grp::resvd1 in particular is currently used by at least strace, however they carry an own copy of UAPI headers, and the conversion should be trivial. A helper is provided for decoding the weight out of the two fields. Forcing a conversion seems preferable to bending backwards and introducing anonymous unions or whatever.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-14040","epss":0.00114,"percentile":0.01681,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08721},"relatedVulnerabilities":[{"id":"CVE-2024-14040","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-14040","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/b72a6a7ab9573e06d5c2fcb92eaa28614a735bfd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nexthop: Increase weight to u16\n\nIn CLOS networks, as link failures occur at various points in the network,\nECMP weights of the involved nodes are adjusted to compensate. With high\nfan-out of the involved nodes, and overall high number of nodes,\na (non-)ECMP weight ratio that we would like to configure does not fit into\n8 bits. Instead of, say, 255:254, we might like to configure something like\n1000:999. For these deployments, the 8-bit weight may not be enough.\n\nTo that end, in this patch increase the next hop weight from u8 to u16.\n\nIncreasing the width of an integral type can be tricky, because while the\ncode still compiles, the types may not check out anymore, and numerical\nerrors come up. To prevent this, the conversion was done in two steps.\nFirst the type was changed from u8 to a single-member structure, which\ninvalidated all uses of the field. This allowed going through them one by\none and audit for type correctness. Then the structure was replaced with a\nvanilla u16 again. This should ensure that no place was missed.\n\nThe UAPI for configuring nexthop group members is that an attribute\nNHA_GROUP carries an array of struct nexthop_grp entries:\n\n\tstruct nexthop_grp {\n\t\t__u32\tid;\t  /* nexthop id - must exist */\n\t\t__u8\tweight;   /* weight of this nexthop */\n\t\t__u8\tresvd1;\n\t\t__u16\tresvd2;\n\t};\n\nThe field resvd1 is currently validated and required to be zero. We can\nlift this requirement and carry high-order bits of the weight in the\nreserved field:\n\n\tstruct nexthop_grp {\n\t\t__u32\tid;\t  /* nexthop id - must exist */\n\t\t__u8\tweight;   /* weight of this nexthop */\n\t\t__u8\tweight_high;\n\t\t__u16\tresvd2;\n\t};\n\nKeeping the fields split this way was chosen in case an existing userspace\nmakes assumptions about the width of the weight field, and to sidestep any\nendianness issues.\n\nThe weight field is currently encoded as the weight value minus one,\nbecause weight of 0 is invalid. This same trick is impossible for the new\nweight_high field, because zero must mean actual zero. With this in place:\n\n- Old userspace is guaranteed to carry weight_high of 0, therefore\n  configuring 8-bit weights as appropriate. When dumping nexthops with\n  16-bit weight, it would only show the lower 8 bits. But configuring such\n  nexthops implies existence of userspace aware of the extension in the\n  first place.\n\n- New userspace talking to an old kernel will work as long as it only\n  attempts to configure 8-bit weights, where the high-order bits are zero.\n  Old kernel will bounce attempts at configuring >8-bit weights.\n\nRenaming reserved fields as they are allocated for some purpose is commonly\ndone in Linux. Whoever touches a reserved field is doing so at their own\nrisk. nexthop_grp::resvd1 in particular is currently used by at least\nstrace, however they carry an own copy of UAPI headers, and the conversion\nshould be trivial. A helper is provided for decoding the weight out of the\ntwo fields. Forcing a conversion seems preferable to bending backwards and\nintroducing anonymous unions or whatever.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-14040","epss":0.00114,"percentile":0.01681,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-14040","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-21803","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-21803","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C.  This issue affects Linux kernel: from v2.6.12-rc2 before v6.8-rc1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-21803","epss":0.00495,"percentile":0.40912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-21803","cwe":"CWE-416","source":"security@openanolis.org","type":"Secondary"},{"cve":"CVE-2024-21803","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.37867500000000004},"relatedVulnerabilities":[{"id":"CVE-2024-21803","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-21803","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.openanolis.cn/show_bug.cgi?id=8081"],"description":"Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C.\n\nThis issue affects Linux kernel: from v2.6.12-rc2 before v6.8-rc1.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"security@openanolis.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L","metrics":{"baseScore":3.5,"exploitabilityScore":1.8,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-21803","epss":0.00495,"percentile":0.40912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-21803","cwe":"CWE-416","source":"security@openanolis.org","type":"Secondary"},{"cve":"CVE-2024-21803","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-21803","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-2193","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-2193","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":5.7,"exploitabilityScore":0.5,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-2193","epss":0.01268,"percentile":0.68023,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2193","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.6783800000000001},"relatedVulnerabilities":[{"id":"CVE-2024-2193","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2193","namespace":"nvd:cpe","severity":"Medium","urls":["http://www.openwall.com/lists/oss-security/2024/03/12/14","https://download.vusec.net/papers/ghostrace_sec24.pdf","https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=944d5fe50f3f03daacfea16300e656a1691c4a23","https://ibm.github.io/system-security-research-updates/2024/03/12/ghostrace","https://kb.cert.org/vuls/id/488902","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EIUICU6CVJUIB6BPJ7P5QTPQR5VOBHFK/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A/","https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7016.html","https://www.kb.cert.org/vuls/id/488902","https://www.vusec.net/projects/ghostrace/","https://xenbits.xen.org/xsa/advisory-453.html","http://xenbits.xen.org/xsa/advisory-453.html"],"description":"A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":5.7,"exploitabilityScore":0.5,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-2193","epss":0.01268,"percentile":0.68023,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-2193","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-2193","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-24864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-24864","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24864","epss":0.00181,"percentile":0.07749,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-24864","cwe":"CWE-362","source":"security@openanolis.org","type":"Secondary"},{"cve":"CVE-2024-24864","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-24864","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.087785},"relatedVulnerabilities":[{"id":"CVE-2024-24864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24864","namespace":"nvd:cpe","severity":"Medium","urls":["https://bugzilla.openanolis.cn/show_bug.cgi?id=8178"],"description":"A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"security@openanolis.org","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":0.9,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24864","epss":0.00181,"percentile":0.07749,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-24864","cwe":"CWE-362","source":"security@openanolis.org","type":"Secondary"},{"cve":"CVE-2024-24864","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-24864","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-24864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-25740","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-25740","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-25740","epss":0.00207,"percentile":0.10847,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25740","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-25740","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10867500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-25740","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-25740","namespace":"nvd:cpe","severity":"Medium","urls":["https://lore.kernel.org/lkml/0171b6cc-95ee-3538-913b-65a391a446b3%40huawei.com/T/"],"description":"A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-25740","epss":0.00207,"percentile":0.10847,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25740","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-25740","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-25740","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-25742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-25742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":1.1,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-25742","epss":0.0018,"percentile":0.07619,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25742","cwe":"CWE-828","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1035},"relatedVulnerabilities":[{"id":"CVE-2024-25742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-25742","namespace":"nvd:cpe","severity":"Medium","urls":["https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.9","https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e3ef461af35a8c74f2f4ce6616491ddb355a208f","https://github.com/torvalds/linux/commit/e3ef461af35a8c74f2f4ce6616491ddb355a208f","https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html"],"description":"In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.5,"exploitabilityScore":1.1,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-25742","epss":0.0018,"percentile":0.07619,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25742","cwe":"CWE-828","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-25742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-25743","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-25743","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-25743","epss":0.00247,"percentile":0.15981,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25743","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18031},"relatedVulnerabilities":[{"id":"CVE-2024-25743","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-25743","namespace":"nvd:cpe","severity":"High","urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2270836","https://bugzilla.suse.com/show_bug.cgi?id=1223307","https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html"],"description":"In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-25743","epss":0.00247,"percentile":0.15981,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-25743","cwe":"CWE-20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-25743","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26661","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26661","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add NULL test for 'timing generator' in 'dcn21_set_pipe()'  In \"u32 otg_inst = pipe_ctx->stream_res.tg->inst;\" pipe_ctx->stream_res.tg could be NULL, it is relying on the caller to ensure the tg is not NULL.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26661","epss":0.00225,"percentile":0.13135,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26661","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11812500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-26661","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26661","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/39f24c08363af1cd945abad84e3c87fd3e3c845a","https://git.kernel.org/stable/c/3f3c237a706580326d3b7a1b97697e5031ca4667","https://git.kernel.org/stable/c/66951d98d9bf45ba25acf37fe0747253fafdf298"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL test for 'timing generator' in 'dcn21_set_pipe()'\n\nIn \"u32 otg_inst = pipe_ctx->stream_res.tg->inst;\"\npipe_ctx->stream_res.tg could be NULL, it is relying on the caller to\nensure the tg is not NULL.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26661","epss":0.00225,"percentile":0.13135,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26661","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26661","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26662","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26662","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix 'panel_cntl' could be null in 'dcn21_set_backlight_level()'  'panel_cntl' structure used to control the display panel could be null, dereferencing it could lead to a null pointer access.  Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn21/dcn21_hwseq.c:269 dcn21_set_backlight_level() error: we previously assumed 'panel_cntl' could be null (see line 250)","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26662","epss":0.00225,"percentile":0.13133,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26662","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11812500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-26662","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26662","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0c863cab0e9173f8b6c7bc328bee3b8625f131b5","https://git.kernel.org/stable/c/2e150ccea13129eb048679114808eb9770443e4d","https://git.kernel.org/stable/c/e96fddb32931d007db12b1fce9b5e8e4c080401b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix 'panel_cntl' could be null in 'dcn21_set_backlight_level()'\n\n'panel_cntl' structure used to control the display panel could be null,\ndereferencing it could lead to a null pointer access.\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn21/dcn21_hwseq.c:269 dcn21_set_backlight_level() error: we previously assumed 'panel_cntl' could be null (see line 250)","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26662","epss":0.00225,"percentile":0.13133,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26662","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26662","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26669","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: flower: Fix chain template offload  When a qdisc is deleted from a net device the stack instructs the underlying driver to remove its flow offload callback from the associated filter block using the 'FLOW_BLOCK_UNBIND' command. The stack then continues to replay the removal of the filters in the block for this driver by iterating over the chains in the block and invoking the 'reoffload' operation of the classifier being used. In turn, the classifier in its 'reoffload' operation prepares and emits a 'FLOW_CLS_DESTROY' command for each filter.  However, the stack does not do the same for chain templates and the underlying driver never receives a 'FLOW_CLS_TMPLT_DESTROY' command when a qdisc is deleted. This results in a memory leak [1] which can be reproduced using [2].  Fix by introducing a 'tmplt_reoffload' operation and have the stack invoke it with the appropriate arguments as part of the replay. Implement the operation in the sole classifier that supports chain templates (flower) by emitting the 'FLOW_CLS_TMPLT_{CREATE,DESTROY}' command based on whether a flow offload callback is being bound to a filter block or being unbound from one.  As far as I can tell, the issue happens since cited commit which reordered tcf_block_offload_unbind() before tcf_block_flush_all_chains() in __tcf_block_put(). The order cannot be reversed as the filter block is expected to be freed after flushing all the chains.  [1] unreferenced object 0xffff888107e28800 (size 2048):   comm \"tc\", pid 1079, jiffies 4294958525 (age 3074.287s)   hex dump (first 32 bytes):     b1 a6 7c 11 81 88 ff ff e0 5b b3 10 81 88 ff ff  ..|......[......     01 00 00 00 00 00 00 00 e0 aa b0 84 ff ff ff ff  ................   backtrace:     [<ffffffff81c06a68>] __kmem_cache_alloc_node+0x1e8/0x320     [<ffffffff81ab374e>] __kmalloc+0x4e/0x90     [<ffffffff832aec6d>] mlxsw_sp_acl_ruleset_get+0x34d/0x7a0     [<ffffffff832bc195>] mlxsw_sp_flower_tmplt_create+0x145/0x180     [<ffffffff832b2e1a>] mlxsw_sp_flow_block_cb+0x1ea/0x280     [<ffffffff83a10613>] tc_setup_cb_call+0x183/0x340     [<ffffffff83a9f85a>] fl_tmplt_create+0x3da/0x4c0     [<ffffffff83a22435>] tc_ctl_chain+0xa15/0x1170     [<ffffffff838a863c>] rtnetlink_rcv_msg+0x3cc/0xed0     [<ffffffff83ac87f0>] netlink_rcv_skb+0x170/0x440     [<ffffffff83ac6270>] netlink_unicast+0x540/0x820     [<ffffffff83ac6e28>] netlink_sendmsg+0x8d8/0xda0     [<ffffffff83793def>] ____sys_sendmsg+0x30f/0xa80     [<ffffffff8379d29a>] ___sys_sendmsg+0x13a/0x1e0     [<ffffffff8379d50c>] __sys_sendmsg+0x11c/0x1f0     [<ffffffff843b9ce0>] do_syscall_64+0x40/0xe0 unreferenced object 0xffff88816d2c0400 (size 1024):   comm \"tc\", pid 1079, jiffies 4294958525 (age 3074.287s)   hex dump (first 32 bytes):     40 00 00 00 00 00 00 00 57 f6 38 be 00 00 00 00  @.......W.8.....     10 04 2c 6d 81 88 ff ff 10 04 2c 6d 81 88 ff ff  ..,m......,m....   backtrace:     [<ffffffff81c06a68>] __kmem_cache_alloc_node+0x1e8/0x320     [<ffffffff81ab36c1>] __kmalloc_node+0x51/0x90     [<ffffffff81a8ed96>] kvmalloc_node+0xa6/0x1f0     [<ffffffff82827d03>] bucket_table_alloc.isra.0+0x83/0x460     [<ffffffff82828d2b>] rhashtable_init+0x43b/0x7c0     [<ffffffff832aed48>] mlxsw_sp_acl_ruleset_get+0x428/0x7a0     [<ffffffff832bc195>] mlxsw_sp_flower_tmplt_create+0x145/0x180     [<ffffffff832b2e1a>] mlxsw_sp_flow_block_cb+0x1ea/0x280     [<ffffffff83a10613>] tc_setup_cb_call+0x183/0x340     [<ffffffff83a9f85a>] fl_tmplt_create+0x3da/0x4c0     [<ffffffff83a22435>] tc_ctl_chain+0xa15/0x1170     [<ffffffff838a863c>] rtnetlink_rcv_msg+0x3cc/0xed0     [<ffffffff83ac87f0>] netlink_rcv_skb+0x170/0x440     [<ffffffff83ac6270>] netlink_unicast+0x540/0x820     [<ffffffff83ac6e28>] netlink_sendmsg+0x8d8/0xda0     [<ffffffff83793def>] ____sys_sendmsg+0x30f/0xa80  [2]  # tc qdisc add dev swp1 clsact  # tc chain add dev swp1 ingress proto ip chain 1 flower dst_ip 0.0.0.0/32  # tc qdisc del dev ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26669","epss":0.00238,"percentile":0.14813,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26669","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17374},"relatedVulnerabilities":[{"id":"CVE-2024-26669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26669","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/32f2a0afa95fae0d1ceec2ff06e0e816939964b8","https://git.kernel.org/stable/c/9ed46144cff3598a5cf79955630e795ff9af5b97","https://git.kernel.org/stable/c/c04709b2cc99ae31c346f79f0211752d7b74df01"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: flower: Fix chain template offload\n\nWhen a qdisc is deleted from a net device the stack instructs the\nunderlying driver to remove its flow offload callback from the\nassociated filter block using the 'FLOW_BLOCK_UNBIND' command. The stack\nthen continues to replay the removal of the filters in the block for\nthis driver by iterating over the chains in the block and invoking the\n'reoffload' operation of the classifier being used. In turn, the\nclassifier in its 'reoffload' operation prepares and emits a\n'FLOW_CLS_DESTROY' command for each filter.\n\nHowever, the stack does not do the same for chain templates and the\nunderlying driver never receives a 'FLOW_CLS_TMPLT_DESTROY' command when\na qdisc is deleted. This results in a memory leak [1] which can be\nreproduced using [2].\n\nFix by introducing a 'tmplt_reoffload' operation and have the stack\ninvoke it with the appropriate arguments as part of the replay.\nImplement the operation in the sole classifier that supports chain\ntemplates (flower) by emitting the 'FLOW_CLS_TMPLT_{CREATE,DESTROY}'\ncommand based on whether a flow offload callback is being bound to a\nfilter block or being unbound from one.\n\nAs far as I can tell, the issue happens since cited commit which\nreordered tcf_block_offload_unbind() before tcf_block_flush_all_chains()\nin __tcf_block_put(). The order cannot be reversed as the filter block\nis expected to be freed after flushing all the chains.\n\n[1]\nunreferenced object 0xffff888107e28800 (size 2048):\n  comm \"tc\", pid 1079, jiffies 4294958525 (age 3074.287s)\n  hex dump (first 32 bytes):\n    b1 a6 7c 11 81 88 ff ff e0 5b b3 10 81 88 ff ff  ..|......[......\n    01 00 00 00 00 00 00 00 e0 aa b0 84 ff ff ff ff  ................\n  backtrace:\n    [<ffffffff81c06a68>] __kmem_cache_alloc_node+0x1e8/0x320\n    [<ffffffff81ab374e>] __kmalloc+0x4e/0x90\n    [<ffffffff832aec6d>] mlxsw_sp_acl_ruleset_get+0x34d/0x7a0\n    [<ffffffff832bc195>] mlxsw_sp_flower_tmplt_create+0x145/0x180\n    [<ffffffff832b2e1a>] mlxsw_sp_flow_block_cb+0x1ea/0x280\n    [<ffffffff83a10613>] tc_setup_cb_call+0x183/0x340\n    [<ffffffff83a9f85a>] fl_tmplt_create+0x3da/0x4c0\n    [<ffffffff83a22435>] tc_ctl_chain+0xa15/0x1170\n    [<ffffffff838a863c>] rtnetlink_rcv_msg+0x3cc/0xed0\n    [<ffffffff83ac87f0>] netlink_rcv_skb+0x170/0x440\n    [<ffffffff83ac6270>] netlink_unicast+0x540/0x820\n    [<ffffffff83ac6e28>] netlink_sendmsg+0x8d8/0xda0\n    [<ffffffff83793def>] ____sys_sendmsg+0x30f/0xa80\n    [<ffffffff8379d29a>] ___sys_sendmsg+0x13a/0x1e0\n    [<ffffffff8379d50c>] __sys_sendmsg+0x11c/0x1f0\n    [<ffffffff843b9ce0>] do_syscall_64+0x40/0xe0\nunreferenced object 0xffff88816d2c0400 (size 1024):\n  comm \"tc\", pid 1079, jiffies 4294958525 (age 3074.287s)\n  hex dump (first 32 bytes):\n    40 00 00 00 00 00 00 00 57 f6 38 be 00 00 00 00  @.......W.8.....\n    10 04 2c 6d 81 88 ff ff 10 04 2c 6d 81 88 ff ff  ..,m......,m....\n  backtrace:\n    [<ffffffff81c06a68>] __kmem_cache_alloc_node+0x1e8/0x320\n    [<ffffffff81ab36c1>] __kmalloc_node+0x51/0x90\n    [<ffffffff81a8ed96>] kvmalloc_node+0xa6/0x1f0\n    [<ffffffff82827d03>] bucket_table_alloc.isra.0+0x83/0x460\n    [<ffffffff82828d2b>] rhashtable_init+0x43b/0x7c0\n    [<ffffffff832aed48>] mlxsw_sp_acl_ruleset_get+0x428/0x7a0\n    [<ffffffff832bc195>] mlxsw_sp_flower_tmplt_create+0x145/0x180\n    [<ffffffff832b2e1a>] mlxsw_sp_flow_block_cb+0x1ea/0x280\n    [<ffffffff83a10613>] tc_setup_cb_call+0x183/0x340\n    [<ffffffff83a9f85a>] fl_tmplt_create+0x3da/0x4c0\n    [<ffffffff83a22435>] tc_ctl_chain+0xa15/0x1170\n    [<ffffffff838a863c>] rtnetlink_rcv_msg+0x3cc/0xed0\n    [<ffffffff83ac87f0>] netlink_rcv_skb+0x170/0x440\n    [<ffffffff83ac6270>] netlink_unicast+0x540/0x820\n    [<ffffffff83ac6e28>] netlink_sendmsg+0x8d8/0xda0\n    [<ffffffff83793def>] ____sys_sendmsg+0x30f/0xa80\n\n[2]\n # tc qdisc add dev swp1 clsact\n # tc chain add dev swp1 ingress proto ip chain 1 flower dst_ip 0.0.0.0/32\n # tc qdisc del dev\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26669","epss":0.00238,"percentile":0.14813,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26669","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26669","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26670","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26670","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  arm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD  Currently the ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround isn't quite right, as it is supposed to be applied after the last explicit memory access, but is immediately followed by an LDR.  The ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround is used to handle Cortex-A520 erratum 2966298 and Cortex-A510 erratum 3117295, which are described in:  * https://developer.arm.com/documentation/SDEN2444153/0600/?lang=en * https://developer.arm.com/documentation/SDEN1873361/1600/?lang=en  In both cases the workaround is described as:  | If pagetable isolation is disabled, the context switch logic in the | kernel can be updated to execute the following sequence on affected | cores before exiting to EL0, and after all explicit memory accesses: | | 1. A non-shareable TLBI to any context and/or address, including |    unused contexts or addresses, such as a `TLBI VALE1 Xzr`. | | 2. A DSB NSH to guarantee completion of the TLBI.  The important part being that the TLBI+DSB must be placed \"after all explicit memory accesses\".  Unfortunately, as-implemented, the TLBI+DSB is immediately followed by an LDR, as we have:  | alternative_if ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD | \ttlbi\tvale1, xzr | \tdsb\tnsh | alternative_else_nop_endif | alternative_if_not ARM64_UNMAP_KERNEL_AT_EL0 | \tldr\tlr, [sp, #S_LR] | \tadd\tsp, sp, #PT_REGS_SIZE\t\t// restore sp | \teret | alternative_else_nop_endif | | [ ... KPTI exception return path ... ]  This patch fixes this by reworking the logic to place the TLBI+DSB immediately before the ERET, after all explicit memory accesses.  The ERET is currently in a separate alternative block, and alternatives cannot be nested. To account for this, the alternative block for ARM64_UNMAP_KERNEL_AT_EL0 is replaced with a single alternative branch to skip the KPTI logic, with the new shape of the logic being:  | alternative_insn \"b .L_skip_tramp_exit_\\@\", nop, ARM64_UNMAP_KERNEL_AT_EL0 | \t[ ... KPTI exception return path ... ] | .L_skip_tramp_exit_\\@: | | \tldr\tlr, [sp, #S_LR] | \tadd\tsp, sp, #PT_REGS_SIZE\t\t// restore sp | | alternative_if ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD | \ttlbi\tvale1, xzr | \tdsb\tnsh | alternative_else_nop_endif | \teret  The new structure means that the workaround is only applied when KPTI is not in use; this is fine as noted in the documented implications of the erratum:  | Pagetable isolation between EL0 and higher level ELs prevents the | issue from occurring.  ... and as per the workaround description quoted above, the workaround is only necessary \"If pagetable isolation is disabled\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26670","epss":0.00225,"percentile":0.13138,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26670","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-26670","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11812500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-26670","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26670","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/58eb5c07f41704464b9acc09ab0707b6769db6c0","https://git.kernel.org/stable/c/832dd634bd1b4e3bbe9f10b9c9ba5db6f6f2b97f","https://git.kernel.org/stable/c/baa0aaac16432019651e0d60c41cd34a0c3c3477"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD\n\nCurrently the ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround isn't\nquite right, as it is supposed to be applied after the last explicit\nmemory access, but is immediately followed by an LDR.\n\nThe ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround is used to\nhandle Cortex-A520 erratum 2966298 and Cortex-A510 erratum 3117295,\nwhich are described in:\n\n* https://developer.arm.com/documentation/SDEN2444153/0600/?lang=en\n* https://developer.arm.com/documentation/SDEN1873361/1600/?lang=en\n\nIn both cases the workaround is described as:\n\n| If pagetable isolation is disabled, the context switch logic in the\n| kernel can be updated to execute the following sequence on affected\n| cores before exiting to EL0, and after all explicit memory accesses:\n|\n| 1. A non-shareable TLBI to any context and/or address, including\n|    unused contexts or addresses, such as a `TLBI VALE1 Xzr`.\n|\n| 2. A DSB NSH to guarantee completion of the TLBI.\n\nThe important part being that the TLBI+DSB must be placed \"after all\nexplicit memory accesses\".\n\nUnfortunately, as-implemented, the TLBI+DSB is immediately followed by\nan LDR, as we have:\n\n| alternative_if ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD\n| \ttlbi\tvale1, xzr\n| \tdsb\tnsh\n| alternative_else_nop_endif\n| alternative_if_not ARM64_UNMAP_KERNEL_AT_EL0\n| \tldr\tlr, [sp, #S_LR]\n| \tadd\tsp, sp, #PT_REGS_SIZE\t\t// restore sp\n| \teret\n| alternative_else_nop_endif\n|\n| [ ... KPTI exception return path ... ]\n\nThis patch fixes this by reworking the logic to place the TLBI+DSB\nimmediately before the ERET, after all explicit memory accesses.\n\nThe ERET is currently in a separate alternative block, and alternatives\ncannot be nested. To account for this, the alternative block for\nARM64_UNMAP_KERNEL_AT_EL0 is replaced with a single alternative branch\nto skip the KPTI logic, with the new shape of the logic being:\n\n| alternative_insn \"b .L_skip_tramp_exit_\\@\", nop, ARM64_UNMAP_KERNEL_AT_EL0\n| \t[ ... KPTI exception return path ... ]\n| .L_skip_tramp_exit_\\@:\n|\n| \tldr\tlr, [sp, #S_LR]\n| \tadd\tsp, sp, #PT_REGS_SIZE\t\t// restore sp\n|\n| alternative_if ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD\n| \ttlbi\tvale1, xzr\n| \tdsb\tnsh\n| alternative_else_nop_endif\n| \teret\n\nThe new structure means that the workaround is only applied when KPTI is\nnot in use; this is fine as noted in the documented implications of the\nerratum:\n\n| Pagetable isolation between EL0 and higher level ELs prevents the\n| issue from occurring.\n\n... and as per the workaround description quoted above, the workaround\nis only necessary \"If pagetable isolation is disabled\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26670","epss":0.00225,"percentile":0.13138,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26670","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-26670","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26670","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26672","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()'  Fixes the below:  drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c:377 amdgpu_mca_smu_get_mca_entry() warn: variable dereferenced before check 'mca_funcs' (see line 368)  357 int amdgpu_mca_smu_get_mca_entry(struct amdgpu_device *adev, \t\t\t\t     enum amdgpu_mca_error_type type, 358                                  int idx, struct mca_bank_entry *entry) 359 { 360         const struct amdgpu_mca_smu_funcs *mca_funcs = \t\t\t\t\t\tadev->mca.mca_funcs; 361         int count; 362 363         switch (type) { 364         case AMDGPU_MCA_ERROR_TYPE_UE: 365                 count = mca_funcs->max_ue_count;  mca_funcs is dereferenced here.  366                 break; 367         case AMDGPU_MCA_ERROR_TYPE_CE: 368                 count = mca_funcs->max_ce_count;  mca_funcs is dereferenced here.  369                 break; 370         default: 371                 return -EINVAL; 372         } 373 374         if (idx >= count) 375                 return -EINVAL; 376 377         if (mca_funcs && mca_funcs->mca_get_mca_entry) \t        ^^^^^^^^^  Checked too late!","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26672","epss":0.00217,"percentile":0.12119,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26672","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15841},"relatedVulnerabilities":[{"id":"CVE-2024-26672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26672","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4f32504a2f85a7b40fe149436881381f48e9c0c0","https://git.kernel.org/stable/c/7b5d58c07024516c0e81b95e98f37710cf402c53"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()'\n\nFixes the below:\n\ndrivers/gpu/drm/amd/amdgpu/amdgpu_mca.c:377 amdgpu_mca_smu_get_mca_entry() warn: variable dereferenced before check 'mca_funcs' (see line 368)\n\n357 int amdgpu_mca_smu_get_mca_entry(struct amdgpu_device *adev,\n\t\t\t\t     enum amdgpu_mca_error_type type,\n358                                  int idx, struct mca_bank_entry *entry)\n359 {\n360         const struct amdgpu_mca_smu_funcs *mca_funcs =\n\t\t\t\t\t\tadev->mca.mca_funcs;\n361         int count;\n362\n363         switch (type) {\n364         case AMDGPU_MCA_ERROR_TYPE_UE:\n365                 count = mca_funcs->max_ue_count;\n\nmca_funcs is dereferenced here.\n\n366                 break;\n367         case AMDGPU_MCA_ERROR_TYPE_CE:\n368                 count = mca_funcs->max_ce_count;\n\nmca_funcs is dereferenced here.\n\n369                 break;\n370         default:\n371                 return -EINVAL;\n372         }\n373\n374         if (idx >= count)\n375                 return -EINVAL;\n376\n377         if (mca_funcs && mca_funcs->mca_get_mca_entry)\n\t        ^^^^^^^^^\n\nChecked too late!","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26672","epss":0.00217,"percentile":0.12119,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26672","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26672","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26677","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26677","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix delayed ACKs to not set the reference serial number  Fix the construction of delayed ACKs to not set the reference serial number as they can't be used as an RTT reference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26677","epss":0.00241,"percentile":0.15238,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26677","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.126525},"relatedVulnerabilities":[{"id":"CVE-2024-26677","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26677","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/200cb50b9e154434470c8969d32474d38475acc2","https://git.kernel.org/stable/c/63719f490e6a89896e9a463d2b45e8203eab23ae","https://git.kernel.org/stable/c/e7870cf13d20f56bfc19f9c3e89707c69cf104ef"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix delayed ACKs to not set the reference serial number\n\nFix the construction of delayed ACKs to not set the reference serial number\nas they can't be used as an RTT reference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26677","epss":0.00241,"percentile":0.15238,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26677","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26677","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26691","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26691","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: arm64: Fix circular locking dependency  The rule inside kvm enforces that the vcpu->mutex is taken *inside* kvm->lock. The rule is violated by the pkvm_create_hyp_vm() which acquires the kvm->lock while already holding the vcpu->mutex lock from kvm_vcpu_ioctl(). Avoid the circular locking dependency altogether by protecting the hyp vm handle with the config_lock, much like we already do for other forms of VM-scoped data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26691","epss":0.00183,"percentile":0.07956,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26691","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09607500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-26691","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26691","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/10c02aad111df02088d1a81792a709f6a7eca6cc","https://git.kernel.org/stable/c/3ab1c40a1e915e350d9181a4603af393141970cc","https://git.kernel.org/stable/c/3d16cebf01127f459dcfeb79ed77bd68b124c228"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix circular locking dependency\n\nThe rule inside kvm enforces that the vcpu->mutex is taken *inside*\nkvm->lock. The rule is violated by the pkvm_create_hyp_vm() which acquires\nthe kvm->lock while already holding the vcpu->mutex lock from\nkvm_vcpu_ioctl(). Avoid the circular locking dependency altogether by\nprotecting the hyp vm handle with the config_lock, much like we already\ndo for other forms of VM-scoped data.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26691","epss":0.00183,"percentile":0.07956,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26691","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26691","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26740","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26740","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: act_mirred: use the backlog for mirred ingress  The test Davide added in commit ca22da2fbd69 (\"act_mirred: use the backlog for nested calls to mirred ingress\") hangs our testing VMs every 10 or so runs, with the familiar tcp_v4_rcv -> tcp_v4_rcv deadlock reported by lockdep.  The problem as previously described by Davide (see Link) is that if we reverse flow of traffic with the redirect (egress -> ingress) we may reach the same socket which generated the packet. And we may still be holding its socket lock. The common solution to such deadlocks is to put the packet in the Rx backlog, rather than run the Rx path inline. Do that for all egress -> ingress reversals, not just once we started to nest mirred calls.  In the past there was a concern that the backlog indirection will lead to loss of error reporting / less accurate stats. But the current workaround does not seem to address the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26740","epss":0.00181,"percentile":0.0779,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26740","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095025},"relatedVulnerabilities":[{"id":"CVE-2024-26740","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26740","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/52f671db18823089a02f07efc04efdb2272ddc17","https://git.kernel.org/stable/c/60ddea1600bc476e0f5e02bce0e29a460ccbf0be","https://git.kernel.org/stable/c/7c787888d164689da8b1b115f3ef562c1e843af4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_mirred: use the backlog for mirred ingress\n\nThe test Davide added in commit ca22da2fbd69 (\"act_mirred: use the backlog\nfor nested calls to mirred ingress\") hangs our testing VMs every 10 or so\nruns, with the familiar tcp_v4_rcv -> tcp_v4_rcv deadlock reported by\nlockdep.\n\nThe problem as previously described by Davide (see Link) is that\nif we reverse flow of traffic with the redirect (egress -> ingress)\nwe may reach the same socket which generated the packet. And we may\nstill be holding its socket lock. The common solution to such deadlocks\nis to put the packet in the Rx backlog, rather than run the Rx path\ninline. Do that for all egress -> ingress reversals, not just once\nwe started to nest mirred calls.\n\nIn the past there was a concern that the backlog indirection will\nlead to loss of error reporting / less accurate stats. But the current\nworkaround does not seem to address the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26740","epss":0.00181,"percentile":0.0779,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26740","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26740","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26756","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md: Don't register sync_thread for reshape directly  Currently, if reshape is interrupted, then reassemble the array will register sync_thread directly from pers->run(), in this case 'MD_RECOVERY_RUNNING' is set directly, however, there is no guarantee that md_do_sync() will be executed, hence stop_sync_thread() will hang because 'MD_RECOVERY_RUNNING' can't be cleared.  Last patch make sure that md_do_sync() will set MD_RECOVERY_DONE, however, following hang can still be triggered by dm-raid test shell/lvconvert-raid-reshape.sh occasionally:  [root@fedora ~]# cat /proc/1982/stack [<0>] stop_sync_thread+0x1ab/0x270 [md_mod] [<0>] md_frozen_sync_thread+0x5c/0xa0 [md_mod] [<0>] raid_presuspend+0x1e/0x70 [dm_raid] [<0>] dm_table_presuspend_targets+0x40/0xb0 [dm_mod] [<0>] __dm_destroy+0x2a5/0x310 [dm_mod] [<0>] dm_destroy+0x16/0x30 [dm_mod] [<0>] dev_remove+0x165/0x290 [dm_mod] [<0>] ctl_ioctl+0x4bb/0x7b0 [dm_mod] [<0>] dm_ctl_ioctl+0x11/0x20 [dm_mod] [<0>] vfs_ioctl+0x21/0x60 [<0>] __x64_sys_ioctl+0xb9/0xe0 [<0>] do_syscall_64+0xc6/0x230 [<0>] entry_SYSCALL_64_after_hwframe+0x6c/0x74  Meanwhile mddev->recovery is: MD_RECOVERY_RUNNING | MD_RECOVERY_INTR | MD_RECOVERY_RESHAPE | MD_RECOVERY_FROZEN  Fix this problem by remove the code to register sync_thread directly from raid10 and raid5. And let md_check_recovery() to register sync_thread.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26756","epss":0.00209,"percentile":0.11061,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26756","cwe":"CWE-459","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10972499999999999},"relatedVulnerabilities":[{"id":"CVE-2024-26756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26756","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/13b520fb62b772e408f9b79c5fe18ad414e90417","https://git.kernel.org/stable/c/ad39c08186f8a0f221337985036ba86731d6aafe"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd: Don't register sync_thread for reshape directly\n\nCurrently, if reshape is interrupted, then reassemble the array will\nregister sync_thread directly from pers->run(), in this case\n'MD_RECOVERY_RUNNING' is set directly, however, there is no guarantee\nthat md_do_sync() will be executed, hence stop_sync_thread() will hang\nbecause 'MD_RECOVERY_RUNNING' can't be cleared.\n\nLast patch make sure that md_do_sync() will set MD_RECOVERY_DONE,\nhowever, following hang can still be triggered by dm-raid test\nshell/lvconvert-raid-reshape.sh occasionally:\n\n[root@fedora ~]# cat /proc/1982/stack\n[<0>] stop_sync_thread+0x1ab/0x270 [md_mod]\n[<0>] md_frozen_sync_thread+0x5c/0xa0 [md_mod]\n[<0>] raid_presuspend+0x1e/0x70 [dm_raid]\n[<0>] dm_table_presuspend_targets+0x40/0xb0 [dm_mod]\n[<0>] __dm_destroy+0x2a5/0x310 [dm_mod]\n[<0>] dm_destroy+0x16/0x30 [dm_mod]\n[<0>] dev_remove+0x165/0x290 [dm_mod]\n[<0>] ctl_ioctl+0x4bb/0x7b0 [dm_mod]\n[<0>] dm_ctl_ioctl+0x11/0x20 [dm_mod]\n[<0>] vfs_ioctl+0x21/0x60\n[<0>] __x64_sys_ioctl+0xb9/0xe0\n[<0>] do_syscall_64+0xc6/0x230\n[<0>] entry_SYSCALL_64_after_hwframe+0x6c/0x74\n\nMeanwhile mddev->recovery is:\nMD_RECOVERY_RUNNING |\nMD_RECOVERY_INTR |\nMD_RECOVERY_RESHAPE |\nMD_RECOVERY_FROZEN\n\nFix this problem by remove the code to register sync_thread directly\nfrom raid10 and raid5. And let md_check_recovery() to register\nsync_thread.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26756","epss":0.00209,"percentile":0.11061,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26756","cwe":"CWE-459","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26756","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26757","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26757","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md: Don't ignore read-only array in md_check_recovery()  Usually if the array is not read-write, md_check_recovery() won't register new sync_thread in the first place. And if the array is read-write and sync_thread is registered, md_set_readonly() will unregister sync_thread before setting the array read-only. md/raid follow this behavior hence there is no problem.  After commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), following hang can be triggered by test shell/integrity-caching.sh:  1) array is read-only. dm-raid update super block: rs_update_sbs  ro = mddev->ro  mddev->ro = 0   -> set array read-write  md_update_sb  2) register new sync thread concurrently.  3) dm-raid set array back to read-only: rs_update_sbs  mddev->ro = ro  4) stop the array: raid_dtr  md_stop   stop_sync_thread     set_bit(MD_RECOVERY_INTR, &mddev->recovery);     md_wakeup_thread_directly(mddev->sync_thread);     wait_event(..., !test_bit(MD_RECOVERY_RUNNING, &mddev->recovery))  5) sync thread done:  md_do_sync  set_bit(MD_RECOVERY_DONE, &mddev->recovery);  md_wakeup_thread(mddev->thread);  6) daemon thread can't unregister sync thread:  md_check_recovery   if (!md_is_rdwr(mddev) &&       !test_bit(MD_RECOVERY_NEEDED, &mddev->recovery))    return;   -> -> MD_RECOVERY_RUNNING can't be cleared, hence step 4 hang;  The root cause is that dm-raid manipulate 'mddev->ro' by itself, however, dm-raid really should stop sync thread before setting the array read-only. Unfortunately, I need to read more code before I can refacter the handler of 'mddev->ro' in dm-raid, hence let's fix the problem the easy way for now to prevent dm-raid regression.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26757","epss":0.00209,"percentile":0.11086,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26757","cwe":"CWE-404","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10972499999999999},"relatedVulnerabilities":[{"id":"CVE-2024-26757","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26757","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2ea169c5a0b1134d573d07fc27a16f327ad0e7d3","https://git.kernel.org/stable/c/55a48ad2db64737f7ffc0407634218cc6e4c513b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd: Don't ignore read-only array in md_check_recovery()\n\nUsually if the array is not read-write, md_check_recovery() won't\nregister new sync_thread in the first place. And if the array is\nread-write and sync_thread is registered, md_set_readonly() will\nunregister sync_thread before setting the array read-only. md/raid\nfollow this behavior hence there is no problem.\n\nAfter commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), following\nhang can be triggered by test shell/integrity-caching.sh:\n\n1) array is read-only. dm-raid update super block:\nrs_update_sbs\n ro = mddev->ro\n mddev->ro = 0\n  -> set array read-write\n md_update_sb\n\n2) register new sync thread concurrently.\n\n3) dm-raid set array back to read-only:\nrs_update_sbs\n mddev->ro = ro\n\n4) stop the array:\nraid_dtr\n md_stop\n  stop_sync_thread\n    set_bit(MD_RECOVERY_INTR, &mddev->recovery);\n    md_wakeup_thread_directly(mddev->sync_thread);\n    wait_event(..., !test_bit(MD_RECOVERY_RUNNING, &mddev->recovery))\n\n5) sync thread done:\n md_do_sync\n set_bit(MD_RECOVERY_DONE, &mddev->recovery);\n md_wakeup_thread(mddev->thread);\n\n6) daemon thread can't unregister sync thread:\n md_check_recovery\n  if (!md_is_rdwr(mddev) &&\n      !test_bit(MD_RECOVERY_NEEDED, &mddev->recovery))\n   return;\n  -> -> MD_RECOVERY_RUNNING can't be cleared, hence step 4 hang;\n\nThe root cause is that dm-raid manipulate 'mddev->ro' by itself,\nhowever, dm-raid really should stop sync thread before setting the\narray read-only. Unfortunately, I need to read more code before I\ncan refacter the handler of 'mddev->ro' in dm-raid, hence let's fix\nthe problem the easy way for now to prevent dm-raid regression.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26757","epss":0.00209,"percentile":0.11086,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26757","cwe":"CWE-404","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26757","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26758","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26758","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md: Don't ignore suspended array in md_check_recovery()  mddev_suspend() never stop sync_thread, hence it doesn't make sense to ignore suspended array in md_check_recovery(), which might cause sync_thread can't be unregistered.  After commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), following hang can be triggered by test shell/integrity-caching.sh:  1) suspend the array: raid_postsuspend  mddev_suspend  2) stop the array: raid_dtr  md_stop   __md_stop_writes    stop_sync_thread     set_bit(MD_RECOVERY_INTR, &mddev->recovery);     md_wakeup_thread_directly(mddev->sync_thread);     wait_event(..., !test_bit(MD_RECOVERY_RUNNING, &mddev->recovery))  3) sync thread done: md_do_sync  set_bit(MD_RECOVERY_DONE, &mddev->recovery);  md_wakeup_thread(mddev->thread);  4) daemon thread can't unregister sync thread: md_check_recovery  if (mddev->suspended)    return; -> return directly  md_read_sync_thread  clear_bit(MD_RECOVERY_RUNNING, &mddev->recovery);  -> MD_RECOVERY_RUNNING can't be cleared, hence step 2 hang;  This problem is not just related to dm-raid, fix it by ignoring suspended array in md_check_recovery(). And follow up patches will improve dm-raid better to frozen sync thread during suspend.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26758","epss":0.00212,"percentile":0.1146,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26758","cwe":"CWE-129","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11130000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-26758","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26758","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1baae052cccd08daf9a9d64c3f959d8cdb689757","https://git.kernel.org/stable/c/a55f0d6179a19c6b982e2dc344d58c98647a3be0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd: Don't ignore suspended array in md_check_recovery()\n\nmddev_suspend() never stop sync_thread, hence it doesn't make sense to\nignore suspended array in md_check_recovery(), which might cause\nsync_thread can't be unregistered.\n\nAfter commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), following\nhang can be triggered by test shell/integrity-caching.sh:\n\n1) suspend the array:\nraid_postsuspend\n mddev_suspend\n\n2) stop the array:\nraid_dtr\n md_stop\n  __md_stop_writes\n   stop_sync_thread\n    set_bit(MD_RECOVERY_INTR, &mddev->recovery);\n    md_wakeup_thread_directly(mddev->sync_thread);\n    wait_event(..., !test_bit(MD_RECOVERY_RUNNING, &mddev->recovery))\n\n3) sync thread done:\nmd_do_sync\n set_bit(MD_RECOVERY_DONE, &mddev->recovery);\n md_wakeup_thread(mddev->thread);\n\n4) daemon thread can't unregister sync thread:\nmd_check_recovery\n if (mddev->suspended)\n   return; -> return directly\n md_read_sync_thread\n clear_bit(MD_RECOVERY_RUNNING, &mddev->recovery);\n -> MD_RECOVERY_RUNNING can't be cleared, hence step 2 hang;\n\nThis problem is not just related to dm-raid, fix it by ignoring\nsuspended array in md_check_recovery(). And follow up patches will\nimprove dm-raid better to frozen sync thread during suspend.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26758","epss":0.00212,"percentile":0.1146,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26758","cwe":"CWE-129","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26758","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26768","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26768","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Change acpi_core_pic[NR_CPUS] to acpi_core_pic[MAX_CORE_PIC]  With default config, the value of NR_CPUS is 64. When HW platform has more then 64 cpus, system will crash on these platforms. MAX_CORE_PIC is the maximum cpu number in MADT table (max physical number) which can exceed the supported maximum cpu number (NR_CPUS, max logical number), but kernel should not crash. Kernel should boot cpus with NR_CPUS, let the remainder cpus stay in BIOS.  The potential crash reason is that the array acpi_core_pic[NR_CPUS] can be overflowed when parsing MADT table, and it is obvious that CORE_PIC should be corresponding to physical core rather than logical core, so it is better to define the array as acpi_core_pic[MAX_CORE_PIC].  With the patch, system can boot up 64 vcpus with qemu parameter -smp 128, otherwise system will crash with the following message.  [    0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000420000004259, era == 90000000037a5f0c, ra == 90000000037a46ec [    0.000000] Oops[#1]: [    0.000000] CPU: 0 PID: 0 Comm: swapper Not tainted 6.8.0-rc2+ #192 [    0.000000] Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022 [    0.000000] pc 90000000037a5f0c ra 90000000037a46ec tp 9000000003c90000 sp 9000000003c93d60 [    0.000000] a0 0000000000000019 a1 9000000003d93bc0 a2 0000000000000000 a3 9000000003c93bd8 [    0.000000] a4 9000000003c93a74 a5 9000000083c93a67 a6 9000000003c938f0 a7 0000000000000005 [    0.000000] t0 0000420000004201 t1 0000000000000000 t2 0000000000000001 t3 0000000000000001 [    0.000000] t4 0000000000000003 t5 0000000000000000 t6 0000000000000030 t7 0000000000000063 [    0.000000] t8 0000000000000014 u0 ffffffffffffffff s9 0000000000000000 s0 9000000003caee98 [    0.000000] s1 90000000041b0480 s2 9000000003c93da0 s3 9000000003c93d98 s4 9000000003c93d90 [    0.000000] s5 9000000003caa000 s6 000000000a7fd000 s7 000000000f556b60 s8 000000000e0a4330 [    0.000000]    ra: 90000000037a46ec platform_init+0x214/0x250 [    0.000000]   ERA: 90000000037a5f0c efi_runtime_init+0x30/0x94 [    0.000000]  CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE) [    0.000000]  PRMD: 00000000 (PPLV0 -PIE -PWE) [    0.000000]  EUEN: 00000000 (-FPE -SXE -ASXE -BTE) [    0.000000]  ECFG: 00070800 (LIE=11 VS=7) [    0.000000] ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0) [    0.000000]  BADV: 0000420000004259 [    0.000000]  PRID: 0014c010 (Loongson-64bit, Loongson-3A5000) [    0.000000] Modules linked in: [    0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____)) [    0.000000] Stack : 9000000003c93a14 9000000003800898 90000000041844f8 90000000037a46ec [    0.000000]         000000000a7fd000 0000000008290000 0000000000000000 0000000000000000 [    0.000000]         0000000000000000 0000000000000000 00000000019d8000 000000000f556b60 [    0.000000]         000000000a7fd000 000000000f556b08 9000000003ca7700 9000000003800000 [    0.000000]         9000000003c93e50 9000000003800898 9000000003800108 90000000037a484c [    0.000000]         000000000e0a4330 000000000f556b60 000000000a7fd000 000000000f556b08 [    0.000000]         9000000003ca7700 9000000004184000 0000000000200000 000000000e02b018 [    0.000000]         000000000a7fd000 90000000037a0790 9000000003800108 0000000000000000 [    0.000000]         0000000000000000 000000000e0a4330 000000000f556b60 000000000a7fd000 [    0.000000]         000000000f556b08 000000000eaae298 000000000eaa5040 0000000000200000 [    0.000000]         ... [    0.000000] Call Trace: [    0.000000] [<90000000037a5f0c>] efi_runtime_init+0x30/0x94 [    0.000000] [<90000000037a46ec>] platform_init+0x214/0x250 [    0.000000] [<90000000037a484c>] setup_arch+0x124/0x45c [    0.000000] [<90000000037a0790>] start_kernel+0x90/0x670 [    0.000000] [<900000000378b0d8>] kernel_entry+0xd8/0xdc","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.1,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26768","epss":0.00598,"percentile":0.4665,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26768","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.34385},"relatedVulnerabilities":[{"id":"CVE-2024-26768","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26768","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0f6810e39898af2d2cabd9313e4dbc945fb5dfdd","https://git.kernel.org/stable/c/4551b30525cf3d2f026b92401ffe241eb04dfebe","https://git.kernel.org/stable/c/88e189bd16e5889e44a41b3309558ebab78b9280"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Change acpi_core_pic[NR_CPUS] to acpi_core_pic[MAX_CORE_PIC]\n\nWith default config, the value of NR_CPUS is 64. When HW platform has\nmore then 64 cpus, system will crash on these platforms. MAX_CORE_PIC\nis the maximum cpu number in MADT table (max physical number) which can\nexceed the supported maximum cpu number (NR_CPUS, max logical number),\nbut kernel should not crash. Kernel should boot cpus with NR_CPUS, let\nthe remainder cpus stay in BIOS.\n\nThe potential crash reason is that the array acpi_core_pic[NR_CPUS] can\nbe overflowed when parsing MADT table, and it is obvious that CORE_PIC\nshould be corresponding to physical core rather than logical core, so it\nis better to define the array as acpi_core_pic[MAX_CORE_PIC].\n\nWith the patch, system can boot up 64 vcpus with qemu parameter -smp 128,\notherwise system will crash with the following message.\n\n[    0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000420000004259, era == 90000000037a5f0c, ra == 90000000037a46ec\n[    0.000000] Oops[#1]:\n[    0.000000] CPU: 0 PID: 0 Comm: swapper Not tainted 6.8.0-rc2+ #192\n[    0.000000] Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022\n[    0.000000] pc 90000000037a5f0c ra 90000000037a46ec tp 9000000003c90000 sp 9000000003c93d60\n[    0.000000] a0 0000000000000019 a1 9000000003d93bc0 a2 0000000000000000 a3 9000000003c93bd8\n[    0.000000] a4 9000000003c93a74 a5 9000000083c93a67 a6 9000000003c938f0 a7 0000000000000005\n[    0.000000] t0 0000420000004201 t1 0000000000000000 t2 0000000000000001 t3 0000000000000001\n[    0.000000] t4 0000000000000003 t5 0000000000000000 t6 0000000000000030 t7 0000000000000063\n[    0.000000] t8 0000000000000014 u0 ffffffffffffffff s9 0000000000000000 s0 9000000003caee98\n[    0.000000] s1 90000000041b0480 s2 9000000003c93da0 s3 9000000003c93d98 s4 9000000003c93d90\n[    0.000000] s5 9000000003caa000 s6 000000000a7fd000 s7 000000000f556b60 s8 000000000e0a4330\n[    0.000000]    ra: 90000000037a46ec platform_init+0x214/0x250\n[    0.000000]   ERA: 90000000037a5f0c efi_runtime_init+0x30/0x94\n[    0.000000]  CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)\n[    0.000000]  PRMD: 00000000 (PPLV0 -PIE -PWE)\n[    0.000000]  EUEN: 00000000 (-FPE -SXE -ASXE -BTE)\n[    0.000000]  ECFG: 00070800 (LIE=11 VS=7)\n[    0.000000] ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0)\n[    0.000000]  BADV: 0000420000004259\n[    0.000000]  PRID: 0014c010 (Loongson-64bit, Loongson-3A5000)\n[    0.000000] Modules linked in:\n[    0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____))\n[    0.000000] Stack : 9000000003c93a14 9000000003800898 90000000041844f8 90000000037a46ec\n[    0.000000]         000000000a7fd000 0000000008290000 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 0000000000000000 00000000019d8000 000000000f556b60\n[    0.000000]         000000000a7fd000 000000000f556b08 9000000003ca7700 9000000003800000\n[    0.000000]         9000000003c93e50 9000000003800898 9000000003800108 90000000037a484c\n[    0.000000]         000000000e0a4330 000000000f556b60 000000000a7fd000 000000000f556b08\n[    0.000000]         9000000003ca7700 9000000004184000 0000000000200000 000000000e02b018\n[    0.000000]         000000000a7fd000 90000000037a0790 9000000003800108 0000000000000000\n[    0.000000]         0000000000000000 000000000e0a4330 000000000f556b60 000000000a7fd000\n[    0.000000]         000000000f556b08 000000000eaae298 000000000eaa5040 0000000000200000\n[    0.000000]         ...\n[    0.000000] Call Trace:\n[    0.000000] [<90000000037a5f0c>] efi_runtime_init+0x30/0x94\n[    0.000000] [<90000000037a46ec>] platform_init+0x214/0x250\n[    0.000000] [<90000000037a484c>] setup_arch+0x124/0x45c\n[    0.000000] [<90000000037a0790>] start_kernel+0x90/0x670\n[    0.000000] [<900000000378b0d8>] kernel_entry+0xd8/0xdc","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.1,"impactScore":4},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.2,"exploitabilityScore":1.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26768","epss":0.00598,"percentile":0.4665,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26768","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26768","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26799","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26799","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: qcom: Fix uninitialized pointer dmactl  In the case where __lpass_get_dmactl_handle is called and the driver id dai_id is invalid the pointer dmactl is not being assigned a value, and dmactl contains a garbage value since it has not been initialized and so the null check may not work. Fix this to initialize dmactl to NULL. One could argue that modern compilers will set this to zero, but it is useful to keep this initialized as per the same way in functions __lpass_platform_codec_intf_init and lpass_cdc_dma_daiops_hw_params.  Cleans up clang scan build warning: sound/soc/qcom/lpass-cdc-dma.c:275:7: warning: Branch condition evaluates to a garbage value [core.uninitialized.Branch]","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26799","epss":0.00239,"percentile":0.14889,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26799","cwe":"CWE-824","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13384000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-26799","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26799","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1382d8b55129875b2e07c4d2a7ebc790183769ee","https://git.kernel.org/stable/c/99adc8b4d2f38bf0d06483ec845bc48f60c3f8cf","https://git.kernel.org/stable/c/d5a7726e6ea62d447b79ab5baeb537ea6bdb225b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: Fix uninitialized pointer dmactl\n\nIn the case where __lpass_get_dmactl_handle is called and the driver\nid dai_id is invalid the pointer dmactl is not being assigned a value,\nand dmactl contains a garbage value since it has not been initialized\nand so the null check may not work. Fix this to initialize dmactl to\nNULL. One could argue that modern compilers will set this to zero, but\nit is useful to keep this initialized as per the same way in functions\n__lpass_platform_codec_intf_init and lpass_cdc_dma_daiops_hw_params.\n\nCleans up clang scan build warning:\nsound/soc/qcom/lpass-cdc-dma.c:275:7: warning: Branch condition\nevaluates to a garbage value [core.uninitialized.Branch]","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26799","epss":0.00239,"percentile":0.14889,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26799","cwe":"CWE-824","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26799","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26836","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26836","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  platform/x86: think-lmi: Fix password opcode ordering for workstations  The Lenovo workstations require the password opcode to be run before the attribute value is changed (if Admin password is enabled).  Tested on some Thinkpads to confirm they are OK with this order too.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26836","epss":0.00231,"percentile":0.13892,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.176715},"relatedVulnerabilities":[{"id":"CVE-2024-26836","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26836","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2bfbe1e0aed00ba51d58573c79452fada3f62ed4","https://git.kernel.org/stable/c/2deb10a99671afda30f834e95e5b992a805bba6a","https://git.kernel.org/stable/c/6f7d0f5fd8e440c3446560100ac4ff9a55eec340"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: think-lmi: Fix password opcode ordering for workstations\n\nThe Lenovo workstations require the password opcode to be run before\nthe attribute value is changed (if Admin password is enabled).\n\nTested on some Thinkpads to confirm they are OK with this order too.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26836","epss":0.00231,"percentile":0.13892,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26836","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26841","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26841","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Update cpu_sibling_map when disabling nonboot CPUs  Update cpu_sibling_map when disabling nonboot CPUs by defining & calling clear_cpu_sibling_map(), otherwise we get such errors on SMT systems:  jump label: negative count! WARNING: CPU: 6 PID: 45 at kernel/jump_label.c:263 __static_key_slow_dec_cpuslocked+0xec/0x100 CPU: 6 PID: 45 Comm: cpuhp/6 Not tainted 6.8.0-rc5+ #1340 pc 90000000004c302c ra 90000000004c302c tp 90000001005bc000 sp 90000001005bfd20 a0 000000000000001b a1 900000000224c278 a2 90000001005bfb58 a3 900000000224c280 a4 900000000224c278 a5 90000001005bfb50 a6 0000000000000001 a7 0000000000000001 t0 ce87a4763eb5234a t1 ce87a4763eb5234a t2 0000000000000000 t3 0000000000000000 t4 0000000000000006 t5 0000000000000000 t6 0000000000000064 t7 0000000000001964 t8 000000000009ebf6 u0 9000000001f2a068 s9 0000000000000000 s0 900000000246a2d8 s1 ffffffffffffffff s2 ffffffffffffffff s3 90000000021518c0 s4 0000000000000040 s5 9000000002151058 s6 9000000009828e40 s7 00000000000000b4 s8 0000000000000006    ra: 90000000004c302c __static_key_slow_dec_cpuslocked+0xec/0x100   ERA: 90000000004c302c __static_key_slow_dec_cpuslocked+0xec/0x100  CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)  PRMD: 00000004 (PPLV0 +PIE -PWE)  EUEN: 00000000 (-FPE -SXE -ASXE -BTE)  ECFG: 00071c1c (LIE=2-4,10-12 VS=7) ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0)  PRID: 0014d000 (Loongson-64bit, Loongson-3A6000-HV) CPU: 6 PID: 45 Comm: cpuhp/6 Not tainted 6.8.0-rc5+ #1340 Stack : 0000000000000000 900000000203f258 900000000179afc8 90000001005bc000         90000001005bf980 0000000000000000 90000001005bf988 9000000001fe0be0         900000000224c280 900000000224c278 90000001005bf8c0 0000000000000001         0000000000000001 ce87a4763eb5234a 0000000007f38000 90000001003f8cc0         0000000000000000 0000000000000006 0000000000000000 4c206e6f73676e6f         6f4c203a656d616e 000000000009ec99 0000000007f38000 0000000000000000         900000000214b000 9000000001fe0be0 0000000000000004 0000000000000000         0000000000000107 0000000000000009 ffffffffffafdabe 00000000000000b4         0000000000000006 90000000004c302c 9000000000224528 00005555939a0c7c         00000000000000b0 0000000000000004 0000000000000000 0000000000071c1c         ... Call Trace: [<9000000000224528>] show_stack+0x48/0x1a0 [<900000000179afc8>] dump_stack_lvl+0x78/0xa0 [<9000000000263ed0>] __warn+0x90/0x1a0 [<90000000017419b8>] report_bug+0x1b8/0x280 [<900000000179c564>] do_bp+0x264/0x420 [<90000000004c302c>] __static_key_slow_dec_cpuslocked+0xec/0x100 [<90000000002b4d7c>] sched_cpu_deactivate+0x2fc/0x300 [<9000000000266498>] cpuhp_invoke_callback+0x178/0x8a0 [<9000000000267f70>] cpuhp_thread_fun+0xf0/0x240 [<90000000002a117c>] smpboot_thread_fn+0x1dc/0x2e0 [<900000000029a720>] kthread+0x140/0x160 [<9000000000222288>] ret_from_kernel_thread+0xc/0xa4","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26841","epss":0.00224,"percentile":0.12979,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26841","cwe":"CWE-459","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1176},"relatedVulnerabilities":[{"id":"CVE-2024-26841","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26841","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0d862db64d26c2905ba1a6a8561466b215b664c2","https://git.kernel.org/stable/c/752cd08da320a667a833803a8fd6bb266114cce5","https://git.kernel.org/stable/c/b1ec3d6b86fdd057559a5908e6668279bf770e0e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Update cpu_sibling_map when disabling nonboot CPUs\n\nUpdate cpu_sibling_map when disabling nonboot CPUs by defining & calling\nclear_cpu_sibling_map(), otherwise we get such errors on SMT systems:\n\njump label: negative count!\nWARNING: CPU: 6 PID: 45 at kernel/jump_label.c:263 __static_key_slow_dec_cpuslocked+0xec/0x100\nCPU: 6 PID: 45 Comm: cpuhp/6 Not tainted 6.8.0-rc5+ #1340\npc 90000000004c302c ra 90000000004c302c tp 90000001005bc000 sp 90000001005bfd20\na0 000000000000001b a1 900000000224c278 a2 90000001005bfb58 a3 900000000224c280\na4 900000000224c278 a5 90000001005bfb50 a6 0000000000000001 a7 0000000000000001\nt0 ce87a4763eb5234a t1 ce87a4763eb5234a t2 0000000000000000 t3 0000000000000000\nt4 0000000000000006 t5 0000000000000000 t6 0000000000000064 t7 0000000000001964\nt8 000000000009ebf6 u0 9000000001f2a068 s9 0000000000000000 s0 900000000246a2d8\ns1 ffffffffffffffff s2 ffffffffffffffff s3 90000000021518c0 s4 0000000000000040\ns5 9000000002151058 s6 9000000009828e40 s7 00000000000000b4 s8 0000000000000006\n   ra: 90000000004c302c __static_key_slow_dec_cpuslocked+0xec/0x100\n  ERA: 90000000004c302c __static_key_slow_dec_cpuslocked+0xec/0x100\n CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)\n PRMD: 00000004 (PPLV0 +PIE -PWE)\n EUEN: 00000000 (-FPE -SXE -ASXE -BTE)\n ECFG: 00071c1c (LIE=2-4,10-12 VS=7)\nESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0)\n PRID: 0014d000 (Loongson-64bit, Loongson-3A6000-HV)\nCPU: 6 PID: 45 Comm: cpuhp/6 Not tainted 6.8.0-rc5+ #1340\nStack : 0000000000000000 900000000203f258 900000000179afc8 90000001005bc000\n        90000001005bf980 0000000000000000 90000001005bf988 9000000001fe0be0\n        900000000224c280 900000000224c278 90000001005bf8c0 0000000000000001\n        0000000000000001 ce87a4763eb5234a 0000000007f38000 90000001003f8cc0\n        0000000000000000 0000000000000006 0000000000000000 4c206e6f73676e6f\n        6f4c203a656d616e 000000000009ec99 0000000007f38000 0000000000000000\n        900000000214b000 9000000001fe0be0 0000000000000004 0000000000000000\n        0000000000000107 0000000000000009 ffffffffffafdabe 00000000000000b4\n        0000000000000006 90000000004c302c 9000000000224528 00005555939a0c7c\n        00000000000000b0 0000000000000004 0000000000000000 0000000000071c1c\n        ...\nCall Trace:\n[<9000000000224528>] show_stack+0x48/0x1a0\n[<900000000179afc8>] dump_stack_lvl+0x78/0xa0\n[<9000000000263ed0>] __warn+0x90/0x1a0\n[<90000000017419b8>] report_bug+0x1b8/0x280\n[<900000000179c564>] do_bp+0x264/0x420\n[<90000000004c302c>] __static_key_slow_dec_cpuslocked+0xec/0x100\n[<90000000002b4d7c>] sched_cpu_deactivate+0x2fc/0x300\n[<9000000000266498>] cpuhp_invoke_callback+0x178/0x8a0\n[<9000000000267f70>] cpuhp_thread_fun+0xf0/0x240\n[<90000000002a117c>] smpboot_thread_fn+0x1dc/0x2e0\n[<900000000029a720>] kthread+0x140/0x160\n[<9000000000222288>] ret_from_kernel_thread+0xc/0xa4","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26841","epss":0.00224,"percentile":0.12979,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26841","cwe":"CWE-459","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26841","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26866","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: lpspi: Avoid potential use-after-free in probe()  fsl_lpspi_probe() is allocating/disposing memory manually with spi_alloc_host()/spi_alloc_target(), but uses devm_spi_register_controller(). In case of error after the latter call the memory will be explicitly freed in the probe function by spi_controller_put() call, but used afterwards by \"devm\" management outside probe() (spi_unregister_controller() <- devm_spi_unregister() below).  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000070 ... Call trace:  kernfs_find_ns  kernfs_find_and_get_ns  sysfs_remove_group  sysfs_remove_groups  device_remove_attrs  device_del  spi_unregister_controller  devm_spi_unregister  release_nodes  devres_release_all  really_probe  driver_probe_device  __device_attach_driver  bus_for_each_drv  __device_attach  device_initial_probe  bus_probe_device  deferred_probe_work_func  process_one_work  worker_thread  kthread  ret_from_fork","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26866","epss":0.00216,"percentile":0.11963,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26866","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2024-26866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26866","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1543418e82789cc383cd36d41469983c64e3fc7f","https://git.kernel.org/stable/c/2ae0ab0143fcc06190713ed81a6486ed0ad3c861","https://git.kernel.org/stable/c/996ce839606afd0fef91355627868022aa73eb68","https://git.kernel.org/stable/c/da83ed350e4604b976e94239b08d8e2e7eaee7ea"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: lpspi: Avoid potential use-after-free in probe()\n\nfsl_lpspi_probe() is allocating/disposing memory manually with\nspi_alloc_host()/spi_alloc_target(), but uses\ndevm_spi_register_controller(). In case of error after the latter call the\nmemory will be explicitly freed in the probe function by\nspi_controller_put() call, but used afterwards by \"devm\" management outside\nprobe() (spi_unregister_controller() <- devm_spi_unregister() below).\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000070\n...\nCall trace:\n kernfs_find_ns\n kernfs_find_and_get_ns\n sysfs_remove_group\n sysfs_remove_groups\n device_remove_attrs\n device_del\n spi_unregister_controller\n devm_spi_unregister\n release_nodes\n devres_release_all\n really_probe\n driver_probe_device\n __device_attach_driver\n bus_for_each_drv\n __device_attach\n device_initial_probe\n bus_probe_device\n deferred_probe_work_func\n process_one_work\n worker_thread\n kthread\n ret_from_fork","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26866","epss":0.00216,"percentile":0.11963,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26866","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26869","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26869","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to truncate meta inode pages forcely  Below race case can cause data corruption:  Thread A\t\t\t\tGC thread \t\t\t\t\t- gc_data_segment \t\t\t\t\t - ra_data_block \t\t\t\t\t  - locked meta_inode page - f2fs_inplace_write_data  - invalidate_mapping_pages  : fail to invalidate meta_inode page    due to lock failure or dirty|writeback    status  - f2fs_submit_page_bio  : write last dirty data to old blkaddr \t\t\t\t\t - move_data_block \t\t\t\t\t  - load old data from meta_inode page \t\t\t\t\t  - f2fs_submit_page_write \t\t\t\t\t  : write old data to new blkaddr  Because invalidate_mapping_pages() will skip invalidating page which has unclear status including locked, dirty, writeback and so on, so we need to use truncate_inode_pages_range() instead of invalidate_mapping_pages() to make sure meta_inode page will be dropped.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26869","epss":0.0018,"percentile":0.07605,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26869","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0873},"relatedVulnerabilities":[{"id":"CVE-2024-26869","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26869","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/04226d8e3c4028dc451e9d8777356ec0f7919253","https://git.kernel.org/stable/c/77bfdb89cc222fc7bfe198eda77bdc427d5ac189","https://git.kernel.org/stable/c/9f0c4a46be1fe9b97dbe66d49204c1371e3ece65","https://git.kernel.org/stable/c/c92f2927df860a60ba815d3ee610a944b92a8694"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to truncate meta inode pages forcely\n\nBelow race case can cause data corruption:\n\nThread A\t\t\t\tGC thread\n\t\t\t\t\t- gc_data_segment\n\t\t\t\t\t - ra_data_block\n\t\t\t\t\t  - locked meta_inode page\n- f2fs_inplace_write_data\n - invalidate_mapping_pages\n : fail to invalidate meta_inode page\n   due to lock failure or dirty|writeback\n   status\n - f2fs_submit_page_bio\n : write last dirty data to old blkaddr\n\t\t\t\t\t - move_data_block\n\t\t\t\t\t  - load old data from meta_inode page\n\t\t\t\t\t  - f2fs_submit_page_write\n\t\t\t\t\t  : write old data to new blkaddr\n\nBecause invalidate_mapping_pages() will skip invalidating page which\nhas unclear status including locked, dirty, writeback and so on, so\nwe need to use truncate_inode_pages_range() instead of\ninvalidate_mapping_pages() to make sure meta_inode page will be dropped.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26869","epss":0.0018,"percentile":0.07605,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26869","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26869","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26876","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26876","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/bridge: adv7511: fix crash on irq during probe  Moved IRQ registration down to end of adv7511_probe().  If an IRQ already is pending during adv7511_probe (before adv7511_cec_init) then cec_received_msg_ts could crash using uninitialized data:      Unable to handle kernel read from unreadable memory at virtual address 00000000000003d5     Internal error: Oops: 96000004 [#1] PREEMPT_RT SMP     Call trace:      cec_received_msg_ts+0x48/0x990 [cec]      adv7511_cec_irq_process+0x1cc/0x308 [adv7511]      adv7511_irq_process+0xd8/0x120 [adv7511]      adv7511_irq_handler+0x1c/0x30 [adv7511]      irq_thread_fn+0x30/0xa0      irq_thread+0x14c/0x238      kthread+0x190/0x1a8","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26876","epss":0.00225,"percentile":0.13147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26876","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11812500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-26876","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26876","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/28a94271bd50e4cf498df0381f776f8ea40a289e","https://git.kernel.org/stable/c/50f4b57e9a9db4ede9294f39b9e75b5f26bae9b7","https://git.kernel.org/stable/c/955c1252930677762e0db2b6b9e36938c887445c","https://git.kernel.org/stable/c/aeedaee5ef5468caf59e2bb1265c2116e0c9a924"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: adv7511: fix crash on irq during probe\n\nMoved IRQ registration down to end of adv7511_probe().\n\nIf an IRQ already is pending during adv7511_probe\n(before adv7511_cec_init) then cec_received_msg_ts\ncould crash using uninitialized data:\n\n    Unable to handle kernel read from unreadable memory at virtual address 00000000000003d5\n    Internal error: Oops: 96000004 [#1] PREEMPT_RT SMP\n    Call trace:\n     cec_received_msg_ts+0x48/0x990 [cec]\n     adv7511_cec_irq_process+0x1cc/0x308 [adv7511]\n     adv7511_irq_process+0xd8/0x120 [adv7511]\n     adv7511_irq_handler+0x1c/0x30 [adv7511]\n     irq_thread_fn+0x30/0xa0\n     irq_thread+0x14c/0x238\n     kthread+0x190/0x1a8","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26876","epss":0.00225,"percentile":0.13147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26876","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26876","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26902","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26902","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf: RISCV: Fix panic on pmu overflow handler  (1 << idx) of int is not desired when setting bits in unsigned long overflowed_ctrs, use BIT() instead. This panic happens when running 'perf record -e branches' on sophgo sg2042.  [  273.311852] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000098 [  273.320851] Oops [#1] [  273.323179] Modules linked in: [  273.326303] CPU: 0 PID: 1475 Comm: perf Not tainted 6.6.0-rc3+ #9 [  273.332521] Hardware name: Sophgo Mango (DT) [  273.336878] epc : riscv_pmu_ctr_get_width_mask+0x8/0x62 [  273.342291]  ra : pmu_sbi_ovf_handler+0x2e0/0x34e [  273.347091] epc : ffffffff80aecd98 ra : ffffffff80aee056 sp : fffffff6e36928b0 [  273.354454]  gp : ffffffff821f82d0 tp : ffffffd90c353200 t0 : 0000002ade4f9978 [  273.361815]  t1 : 0000000000504d55 t2 : ffffffff8016cd8c s0 : fffffff6e3692a70 [  273.369180]  s1 : 0000000000000020 a0 : 0000000000000000 a1 : 00001a8e81800000 [  273.376540]  a2 : 0000003c00070198 a3 : 0000003c00db75a4 a4 : 0000000000000015 [  273.383901]  a5 : ffffffd7ff8804b0 a6 : 0000000000000015 a7 : 000000000000002a [  273.391327]  s2 : 000000000000ffff s3 : 0000000000000000 s4 : ffffffd7ff8803b0 [  273.398773]  s5 : 0000000000504d55 s6 : ffffffd905069800 s7 : ffffffff821fe210 [  273.406139]  s8 : 000000007fffffff s9 : ffffffd7ff8803b0 s10: ffffffd903f29098 [  273.413660]  s11: 0000000080000000 t3 : 0000000000000003 t4 : ffffffff8017a0ca [  273.421022]  t5 : ffffffff8023cfc2 t6 : ffffffd9040780e8 [  273.426437] status: 0000000200000100 badaddr: 0000000000000098 cause: 000000000000000d [  273.434512] [<ffffffff80aecd98>] riscv_pmu_ctr_get_width_mask+0x8/0x62 [  273.441169] [<ffffffff80076bd8>] handle_percpu_devid_irq+0x98/0x1ee [  273.447562] [<ffffffff80071158>] generic_handle_domain_irq+0x28/0x36 [  273.454151] [<ffffffff8047a99a>] riscv_intc_irq+0x36/0x4e [  273.459659] [<ffffffff80c944de>] handle_riscv_irq+0x4a/0x74 [  273.465442] [<ffffffff80c94c48>] do_irq+0x62/0x92 [  273.470360] Code: 0420 60a2 6402 5529 0141 8082 0013 0000 0013 0000 (6d5c) b783 [  273.477921] ---[ end trace 0000000000000000 ]--- [  273.482630] Kernel panic - not syncing: Fatal exception in interrupt","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26902","epss":0.00238,"percentile":0.14756,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26902","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12495000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-26902","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26902","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/34b567868777e9fd39ec5333969728a7f0cf179c","https://git.kernel.org/stable/c/3ede8e94de6b834b48b0643385e66363e7a04be9","https://git.kernel.org/stable/c/9f599ba3b9cc4bdb8ec1e3f0feddd41bf9d296d6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf: RISCV: Fix panic on pmu overflow handler\n\n(1 << idx) of int is not desired when setting bits in unsigned long\noverflowed_ctrs, use BIT() instead. This panic happens when running\n'perf record -e branches' on sophgo sg2042.\n\n[  273.311852] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000098\n[  273.320851] Oops [#1]\n[  273.323179] Modules linked in:\n[  273.326303] CPU: 0 PID: 1475 Comm: perf Not tainted 6.6.0-rc3+ #9\n[  273.332521] Hardware name: Sophgo Mango (DT)\n[  273.336878] epc : riscv_pmu_ctr_get_width_mask+0x8/0x62\n[  273.342291]  ra : pmu_sbi_ovf_handler+0x2e0/0x34e\n[  273.347091] epc : ffffffff80aecd98 ra : ffffffff80aee056 sp : fffffff6e36928b0\n[  273.354454]  gp : ffffffff821f82d0 tp : ffffffd90c353200 t0 : 0000002ade4f9978\n[  273.361815]  t1 : 0000000000504d55 t2 : ffffffff8016cd8c s0 : fffffff6e3692a70\n[  273.369180]  s1 : 0000000000000020 a0 : 0000000000000000 a1 : 00001a8e81800000\n[  273.376540]  a2 : 0000003c00070198 a3 : 0000003c00db75a4 a4 : 0000000000000015\n[  273.383901]  a5 : ffffffd7ff8804b0 a6 : 0000000000000015 a7 : 000000000000002a\n[  273.391327]  s2 : 000000000000ffff s3 : 0000000000000000 s4 : ffffffd7ff8803b0\n[  273.398773]  s5 : 0000000000504d55 s6 : ffffffd905069800 s7 : ffffffff821fe210\n[  273.406139]  s8 : 000000007fffffff s9 : ffffffd7ff8803b0 s10: ffffffd903f29098\n[  273.413660]  s11: 0000000080000000 t3 : 0000000000000003 t4 : ffffffff8017a0ca\n[  273.421022]  t5 : ffffffff8023cfc2 t6 : ffffffd9040780e8\n[  273.426437] status: 0000000200000100 badaddr: 0000000000000098 cause: 000000000000000d\n[  273.434512] [<ffffffff80aecd98>] riscv_pmu_ctr_get_width_mask+0x8/0x62\n[  273.441169] [<ffffffff80076bd8>] handle_percpu_devid_irq+0x98/0x1ee\n[  273.447562] [<ffffffff80071158>] generic_handle_domain_irq+0x28/0x36\n[  273.454151] [<ffffffff8047a99a>] riscv_intc_irq+0x36/0x4e\n[  273.459659] [<ffffffff80c944de>] handle_riscv_irq+0x4a/0x74\n[  273.465442] [<ffffffff80c94c48>] do_irq+0x62/0x92\n[  273.470360] Code: 0420 60a2 6402 5529 0141 8082 0013 0000 0013 0000 (6d5c) b783\n[  273.477921] ---[ end trace 0000000000000000 ]---\n[  273.482630] Kernel panic - not syncing: Fatal exception in interrupt","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26902","epss":0.00238,"percentile":0.14756,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26902","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26902","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26913","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26913","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix dcn35 8k30 Underflow/Corruption Issue  [why] odm calculation is missing for pipe split policy determination and cause Underflow/Corruption issue.  [how] Add the odm calculation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26913","epss":0.0025,"percentile":0.16365,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26913","cwe":"CWE-191","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19125},"relatedVulnerabilities":[{"id":"CVE-2024-26913","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26913","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/cdbe0be8874c63bca85b8c38e5b1eecbdd18df31","https://git.kernel.org/stable/c/faf51b201bc42adf500945732abb6220c707d6f3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix dcn35 8k30 Underflow/Corruption Issue\n\n[why]\nodm calculation is missing for pipe split policy determination\nand cause Underflow/Corruption issue.\n\n[how]\nAdd the odm calculation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26913","epss":0.0025,"percentile":0.16365,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26913","cwe":"CWE-191","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26913","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26914","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26914","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: fix incorrect mpc_combine array size  [why] MAX_SURFACES is per stream, while MAX_PLANES is per asic. The mpc_combine is an array that records all the planes per asic. Therefore MAX_PLANES should be used as the array size. Using MAX_SURFACES causes array overflow when there are more than 3 planes.  [how] Use the MAX_PLANES for the mpc_combine array size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26914","epss":0.00216,"percentile":0.12009,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26914","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16524},"relatedVulnerabilities":[{"id":"CVE-2024-26914","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26914","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0bd8ef618a42d7e6ea3f701065264e15678025e3","https://git.kernel.org/stable/c/39079fe8e660851abbafa90cd55cbf029210661f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix incorrect mpc_combine array size\n\n[why]\nMAX_SURFACES is per stream, while MAX_PLANES is per asic. The\nmpc_combine is an array that records all the planes per asic. Therefore\nMAX_PLANES should be used as the array size. Using MAX_SURFACES causes\narray overflow when there are more than 3 planes.\n\n[how]\nUse the MAX_PLANES for the mpc_combine array size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26914","epss":0.00216,"percentile":0.12009,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26914","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26914","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26944","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26944","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: zoned: fix use-after-free in do_zone_finish()  Shinichiro reported the following use-after-free triggered by the device replace operation in fstests btrfs/070.   BTRFS info (device nullb1): scrub: finished on devid 1 with status: 0  ==================================================================  BUG: KASAN: slab-use-after-free in do_zone_finish+0x91a/0xb90 [btrfs]  Read of size 8 at addr ffff8881543c8060 by task btrfs-cleaner/3494007   CPU: 0 PID: 3494007 Comm: btrfs-cleaner Tainted: G        W          6.8.0-rc5-kts #1  Hardware name: Supermicro Super Server/X11SPi-TF, BIOS 3.3 02/21/2020  Call Trace:   <TASK>   dump_stack_lvl+0x5b/0x90   print_report+0xcf/0x670   ? __virt_addr_valid+0x200/0x3e0   kasan_report+0xd8/0x110   ? do_zone_finish+0x91a/0xb90 [btrfs]   ? do_zone_finish+0x91a/0xb90 [btrfs]   do_zone_finish+0x91a/0xb90 [btrfs]   btrfs_delete_unused_bgs+0x5e1/0x1750 [btrfs]   ? __pfx_btrfs_delete_unused_bgs+0x10/0x10 [btrfs]   ? btrfs_put_root+0x2d/0x220 [btrfs]   ? btrfs_clean_one_deleted_snapshot+0x299/0x430 [btrfs]   cleaner_kthread+0x21e/0x380 [btrfs]   ? __pfx_cleaner_kthread+0x10/0x10 [btrfs]   kthread+0x2e3/0x3c0   ? __pfx_kthread+0x10/0x10   ret_from_fork+0x31/0x70   ? __pfx_kthread+0x10/0x10   ret_from_fork_asm+0x1b/0x30   </TASK>   Allocated by task 3493983:   kasan_save_stack+0x33/0x60   kasan_save_track+0x14/0x30   __kasan_kmalloc+0xaa/0xb0   btrfs_alloc_device+0xb3/0x4e0 [btrfs]   device_list_add.constprop.0+0x993/0x1630 [btrfs]   btrfs_scan_one_device+0x219/0x3d0 [btrfs]   btrfs_control_ioctl+0x26e/0x310 [btrfs]   __x64_sys_ioctl+0x134/0x1b0   do_syscall_64+0x99/0x190   entry_SYSCALL_64_after_hwframe+0x6e/0x76   Freed by task 3494056:   kasan_save_stack+0x33/0x60   kasan_save_track+0x14/0x30   kasan_save_free_info+0x3f/0x60   poison_slab_object+0x102/0x170   __kasan_slab_free+0x32/0x70   kfree+0x11b/0x320   btrfs_rm_dev_replace_free_srcdev+0xca/0x280 [btrfs]   btrfs_dev_replace_finishing+0xd7e/0x14f0 [btrfs]   btrfs_dev_replace_by_ioctl+0x1286/0x25a0 [btrfs]   btrfs_ioctl+0xb27/0x57d0 [btrfs]   __x64_sys_ioctl+0x134/0x1b0   do_syscall_64+0x99/0x190   entry_SYSCALL_64_after_hwframe+0x6e/0x76   The buggy address belongs to the object at ffff8881543c8000   which belongs to the cache kmalloc-1k of size 1024  The buggy address is located 96 bytes inside of   freed 1024-byte region [ffff8881543c8000, ffff8881543c8400)   The buggy address belongs to the physical page:  page:00000000fe2c1285 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1543c8  head:00000000fe2c1285 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0  flags: 0x17ffffc0000840(slab|head|node=0|zone=2|lastcpupid=0x1fffff)  page_type: 0xffffffff()  raw: 0017ffffc0000840 ffff888100042dc0 ffffea0019e8f200 dead000000000002  raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000  page dumped because: kasan: bad access detected   Memory state around the buggy address:   ffff8881543c7f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ffff8881543c7f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  >ffff8881543c8000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb                                                         ^   ffff8881543c8080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb   ffff8881543c8100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb  This UAF happens because we're accessing stale zone information of a already removed btrfs_device in do_zone_finish().  The sequence of events is as follows:  btrfs_dev_replace_start   btrfs_scrub_dev    btrfs_dev_replace_finishing     btrfs_dev_replace_update_device_in_mapping_tree <-- devices replaced     btrfs_rm_dev_replace_free_srcdev      btrfs_free_device                              <-- device freed  cleaner_kthread  btrfs_delete_unused_bgs   btrfs_zone_finish    do_zone_finish              <-- refers the freed device  The reason for this is that we're using a ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26944","epss":0.00227,"percentile":0.13359,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26944","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.173655},"relatedVulnerabilities":[{"id":"CVE-2024-26944","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26944","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1ec17ef59168a1a6f1105f5dc517f783839a5302","https://git.kernel.org/stable/c/34ca809e055eca5cfe63d9c7efbf80b7c21b4e57"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: fix use-after-free in do_zone_finish()\n\nShinichiro reported the following use-after-free triggered by the device\nreplace operation in fstests btrfs/070.\n\n BTRFS info (device nullb1): scrub: finished on devid 1 with status: 0\n ==================================================================\n BUG: KASAN: slab-use-after-free in do_zone_finish+0x91a/0xb90 [btrfs]\n Read of size 8 at addr ffff8881543c8060 by task btrfs-cleaner/3494007\n\n CPU: 0 PID: 3494007 Comm: btrfs-cleaner Tainted: G        W          6.8.0-rc5-kts #1\n Hardware name: Supermicro Super Server/X11SPi-TF, BIOS 3.3 02/21/2020\n Call Trace:\n  <TASK>\n  dump_stack_lvl+0x5b/0x90\n  print_report+0xcf/0x670\n  ? __virt_addr_valid+0x200/0x3e0\n  kasan_report+0xd8/0x110\n  ? do_zone_finish+0x91a/0xb90 [btrfs]\n  ? do_zone_finish+0x91a/0xb90 [btrfs]\n  do_zone_finish+0x91a/0xb90 [btrfs]\n  btrfs_delete_unused_bgs+0x5e1/0x1750 [btrfs]\n  ? __pfx_btrfs_delete_unused_bgs+0x10/0x10 [btrfs]\n  ? btrfs_put_root+0x2d/0x220 [btrfs]\n  ? btrfs_clean_one_deleted_snapshot+0x299/0x430 [btrfs]\n  cleaner_kthread+0x21e/0x380 [btrfs]\n  ? __pfx_cleaner_kthread+0x10/0x10 [btrfs]\n  kthread+0x2e3/0x3c0\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork+0x31/0x70\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork_asm+0x1b/0x30\n  </TASK>\n\n Allocated by task 3493983:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x14/0x30\n  __kasan_kmalloc+0xaa/0xb0\n  btrfs_alloc_device+0xb3/0x4e0 [btrfs]\n  device_list_add.constprop.0+0x993/0x1630 [btrfs]\n  btrfs_scan_one_device+0x219/0x3d0 [btrfs]\n  btrfs_control_ioctl+0x26e/0x310 [btrfs]\n  __x64_sys_ioctl+0x134/0x1b0\n  do_syscall_64+0x99/0x190\n  entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\n Freed by task 3494056:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x14/0x30\n  kasan_save_free_info+0x3f/0x60\n  poison_slab_object+0x102/0x170\n  __kasan_slab_free+0x32/0x70\n  kfree+0x11b/0x320\n  btrfs_rm_dev_replace_free_srcdev+0xca/0x280 [btrfs]\n  btrfs_dev_replace_finishing+0xd7e/0x14f0 [btrfs]\n  btrfs_dev_replace_by_ioctl+0x1286/0x25a0 [btrfs]\n  btrfs_ioctl+0xb27/0x57d0 [btrfs]\n  __x64_sys_ioctl+0x134/0x1b0\n  do_syscall_64+0x99/0x190\n  entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\n The buggy address belongs to the object at ffff8881543c8000\n  which belongs to the cache kmalloc-1k of size 1024\n The buggy address is located 96 bytes inside of\n  freed 1024-byte region [ffff8881543c8000, ffff8881543c8400)\n\n The buggy address belongs to the physical page:\n page:00000000fe2c1285 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1543c8\n head:00000000fe2c1285 order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n flags: 0x17ffffc0000840(slab|head|node=0|zone=2|lastcpupid=0x1fffff)\n page_type: 0xffffffff()\n raw: 0017ffffc0000840 ffff888100042dc0 ffffea0019e8f200 dead000000000002\n raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n  ffff8881543c7f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n  ffff8881543c7f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n >ffff8881543c8000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n                                                        ^\n  ffff8881543c8080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n  ffff8881543c8100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n\nThis UAF happens because we're accessing stale zone information of a\nalready removed btrfs_device in do_zone_finish().\n\nThe sequence of events is as follows:\n\nbtrfs_dev_replace_start\n  btrfs_scrub_dev\n   btrfs_dev_replace_finishing\n    btrfs_dev_replace_update_device_in_mapping_tree <-- devices replaced\n    btrfs_rm_dev_replace_free_srcdev\n     btrfs_free_device                              <-- device freed\n\ncleaner_kthread\n btrfs_delete_unused_bgs\n  btrfs_zone_finish\n   do_zone_finish              <-- refers the freed device\n\nThe reason for this is that we're using a\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26944","epss":0.00227,"percentile":0.13359,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26944","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26944","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26947","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26947","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses  Since commit a4d5613c4dc6 (\"arm: extend pfn_valid to take into account freed memory map alignment\") changes the semantics of pfn_valid() to check presence of the memory map for a PFN. A valid page for an address which is reserved but not mapped by the kernel[1], the system crashed during some uio test with the following memory layout:   node   0: [mem 0x00000000c0a00000-0x00000000cc8fffff]  node   0: [mem 0x00000000d0000000-0x00000000da1fffff]  the uio layout is：0xc0900000, 0x100000  the crash backtrace like:    Unable to handle kernel paging request at virtual address bff00000   [...]   CPU: 1 PID: 465 Comm: startapp.bin Tainted: G           O      5.10.0 #1   Hardware name: Generic DT based system   PC is at b15_flush_kern_dcache_area+0x24/0x3c   LR is at __sync_icache_dcache+0x6c/0x98   [...]    (b15_flush_kern_dcache_area) from (__sync_icache_dcache+0x6c/0x98)    (__sync_icache_dcache) from (set_pte_at+0x28/0x54)    (set_pte_at) from (remap_pfn_range+0x1a0/0x274)    (remap_pfn_range) from (uio_mmap+0x184/0x1b8 [uio])    (uio_mmap [uio]) from (__mmap_region+0x264/0x5f4)    (__mmap_region) from (__do_mmap_mm+0x3ec/0x440)    (__do_mmap_mm) from (do_mmap+0x50/0x58)    (do_mmap) from (vm_mmap_pgoff+0xfc/0x188)    (vm_mmap_pgoff) from (ksys_mmap_pgoff+0xac/0xc4)    (ksys_mmap_pgoff) from (ret_fast_syscall+0x0/0x5c)   Code: e0801001 e2423001 e1c00003 f57ff04f (ee070f3e)   ---[ end trace 09cf0734c3805d52 ]---   Kernel panic - not syncing: Fatal exception  So check if PG_reserved was set to solve this issue.  [1]: https://lore.kernel.org/lkml/Zbtdue57RO0QScJM@linux.ibm.com/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26947","epss":0.0023,"percentile":0.13729,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12075},"relatedVulnerabilities":[{"id":"CVE-2024-26947","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26947","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0c027c2bad7f5111c51a358b5d392e1a695dabff","https://git.kernel.org/stable/c/0c66c6f4e21cb22220cbd8821c5c73fc157d20dc","https://git.kernel.org/stable/c/9f7ddc222cae8254e93d5c169a8ae11a49d912a7","https://git.kernel.org/stable/c/fb3a122a978626b33de3367ee1762da934c0f512"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses\n\nSince commit a4d5613c4dc6 (\"arm: extend pfn_valid to take into account\nfreed memory map alignment\") changes the semantics of pfn_valid() to check\npresence of the memory map for a PFN. A valid page for an address which\nis reserved but not mapped by the kernel[1], the system crashed during\nsome uio test with the following memory layout:\n\n node   0: [mem 0x00000000c0a00000-0x00000000cc8fffff]\n node   0: [mem 0x00000000d0000000-0x00000000da1fffff]\n the uio layout is：0xc0900000, 0x100000\n\nthe crash backtrace like:\n\n  Unable to handle kernel paging request at virtual address bff00000\n  [...]\n  CPU: 1 PID: 465 Comm: startapp.bin Tainted: G           O      5.10.0 #1\n  Hardware name: Generic DT based system\n  PC is at b15_flush_kern_dcache_area+0x24/0x3c\n  LR is at __sync_icache_dcache+0x6c/0x98\n  [...]\n   (b15_flush_kern_dcache_area) from (__sync_icache_dcache+0x6c/0x98)\n   (__sync_icache_dcache) from (set_pte_at+0x28/0x54)\n   (set_pte_at) from (remap_pfn_range+0x1a0/0x274)\n   (remap_pfn_range) from (uio_mmap+0x184/0x1b8 [uio])\n   (uio_mmap [uio]) from (__mmap_region+0x264/0x5f4)\n   (__mmap_region) from (__do_mmap_mm+0x3ec/0x440)\n   (__do_mmap_mm) from (do_mmap+0x50/0x58)\n   (do_mmap) from (vm_mmap_pgoff+0xfc/0x188)\n   (vm_mmap_pgoff) from (ksys_mmap_pgoff+0xac/0xc4)\n   (ksys_mmap_pgoff) from (ret_fast_syscall+0x0/0x5c)\n  Code: e0801001 e2423001 e1c00003 f57ff04f (ee070f3e)\n  ---[ end trace 09cf0734c3805d52 ]---\n  Kernel panic - not syncing: Fatal exception\n\nSo check if PG_reserved was set to solve this issue.\n\n[1]: https://lore.kernel.org/lkml/Zbtdue57RO0QScJM@linux.ibm.com/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26947","epss":0.0023,"percentile":0.13729,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26947","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26948","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26948","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add a dc_state NULL check in dc_state_release  [How] Check wheather state is NULL before releasing it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26948","epss":0.00198,"percentile":0.09668,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26948","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10395},"relatedVulnerabilities":[{"id":"CVE-2024-26948","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26948","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/334b56cea5d9df5989be6cf1a5898114fa70ad98","https://git.kernel.org/stable/c/d37a08f840485995e3fb91dad95e441b9d28a269"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add a dc_state NULL check in dc_state_release\n\n[How]\nCheck wheather state is NULL before releasing it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26948","epss":0.00198,"percentile":0.09668,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26948","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26948","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26953","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26953","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: esp: fix bad handling of pages from page_pool  When the skb is reorganized during esp_output (!esp->inline), the pages coming from the original skb fragments are supposed to be released back to the system through put_page. But if the skb fragment pages are originating from a page_pool, calling put_page on them will trigger a page_pool leak which will eventually result in a crash.  This leak can be easily observed when using CONFIG_DEBUG_VM and doing ipsec + gre (non offloaded) forwarding:    BUG: Bad page state in process ksoftirqd/16  pfn:1451b6   page:00000000de2b8d32 refcount:0 mapcount:0 mapping:0000000000000000 index:0x1451b6000 pfn:0x1451b6   flags: 0x200000000000000(node=0|zone=2)   page_type: 0xffffffff()   raw: 0200000000000000 dead000000000040 ffff88810d23c000 0000000000000000   raw: 00000001451b6000 0000000000000001 00000000ffffffff 0000000000000000   page dumped because: page_pool leak   Modules linked in: ip_gre gre mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink iptable_nat nf_nat xt_addrtype br_netfilter rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core overlay zram zsmalloc fuse [last unloaded: mlx5_core]   CPU: 16 PID: 96 Comm: ksoftirqd/16 Not tainted 6.8.0-rc4+ #22   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014   Call Trace:    <TASK>    dump_stack_lvl+0x36/0x50    bad_page+0x70/0xf0    free_unref_page_prepare+0x27a/0x460    free_unref_page+0x38/0x120    esp_ssg_unref.isra.0+0x15f/0x200    esp_output_tail+0x66d/0x780    esp_xmit+0x2c5/0x360    validate_xmit_xfrm+0x313/0x370    ? validate_xmit_skb+0x1d/0x330    validate_xmit_skb_list+0x4c/0x70    sch_direct_xmit+0x23e/0x350    __dev_queue_xmit+0x337/0xba0    ? nf_hook_slow+0x3f/0xd0    ip_finish_output2+0x25e/0x580    iptunnel_xmit+0x19b/0x240    ip_tunnel_xmit+0x5fb/0xb60    ipgre_xmit+0x14d/0x280 [ip_gre]    dev_hard_start_xmit+0xc3/0x1c0    __dev_queue_xmit+0x208/0xba0    ? nf_hook_slow+0x3f/0xd0    ip_finish_output2+0x1ca/0x580    ip_sublist_rcv_finish+0x32/0x40    ip_sublist_rcv+0x1b2/0x1f0    ? ip_rcv_finish_core.constprop.0+0x460/0x460    ip_list_rcv+0x103/0x130    __netif_receive_skb_list_core+0x181/0x1e0    netif_receive_skb_list_internal+0x1b3/0x2c0    napi_gro_receive+0xc8/0x200    gro_cell_poll+0x52/0x90    __napi_poll+0x25/0x1a0    net_rx_action+0x28e/0x300    __do_softirq+0xc3/0x276    ? sort_range+0x20/0x20    run_ksoftirqd+0x1e/0x30    smpboot_thread_fn+0xa6/0x130    kthread+0xcd/0x100    ? kthread_complete_and_exit+0x20/0x20    ret_from_fork+0x31/0x50    ? kthread_complete_and_exit+0x20/0x20    ret_from_fork_asm+0x11/0x20    </TASK>  The suggested fix is to introduce a new wrapper (skb_page_unref) that covers page refcounting for page_pool pages as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26953","epss":0.00656,"percentile":0.49323,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3444},"relatedVulnerabilities":[{"id":"CVE-2024-26953","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26953","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1abb20a5f4b02fb3020f88456fc1e6069b3cdc45","https://git.kernel.org/stable/c/8291b4eac429c480386669444c6377573f5d8664","https://git.kernel.org/stable/c/c3198822c6cb9fb588e446540485669cc81c5d34","https://git.kernel.org/stable/c/f278ff9db67264715d0d50e3e75044f8b78990f4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: esp: fix bad handling of pages from page_pool\n\nWhen the skb is reorganized during esp_output (!esp->inline), the pages\ncoming from the original skb fragments are supposed to be released back\nto the system through put_page. But if the skb fragment pages are\noriginating from a page_pool, calling put_page on them will trigger a\npage_pool leak which will eventually result in a crash.\n\nThis leak can be easily observed when using CONFIG_DEBUG_VM and doing\nipsec + gre (non offloaded) forwarding:\n\n  BUG: Bad page state in process ksoftirqd/16  pfn:1451b6\n  page:00000000de2b8d32 refcount:0 mapcount:0 mapping:0000000000000000 index:0x1451b6000 pfn:0x1451b6\n  flags: 0x200000000000000(node=0|zone=2)\n  page_type: 0xffffffff()\n  raw: 0200000000000000 dead000000000040 ffff88810d23c000 0000000000000000\n  raw: 00000001451b6000 0000000000000001 00000000ffffffff 0000000000000000\n  page dumped because: page_pool leak\n  Modules linked in: ip_gre gre mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink iptable_nat nf_nat xt_addrtype br_netfilter rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core overlay zram zsmalloc fuse [last unloaded: mlx5_core]\n  CPU: 16 PID: 96 Comm: ksoftirqd/16 Not tainted 6.8.0-rc4+ #22\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x36/0x50\n   bad_page+0x70/0xf0\n   free_unref_page_prepare+0x27a/0x460\n   free_unref_page+0x38/0x120\n   esp_ssg_unref.isra.0+0x15f/0x200\n   esp_output_tail+0x66d/0x780\n   esp_xmit+0x2c5/0x360\n   validate_xmit_xfrm+0x313/0x370\n   ? validate_xmit_skb+0x1d/0x330\n   validate_xmit_skb_list+0x4c/0x70\n   sch_direct_xmit+0x23e/0x350\n   __dev_queue_xmit+0x337/0xba0\n   ? nf_hook_slow+0x3f/0xd0\n   ip_finish_output2+0x25e/0x580\n   iptunnel_xmit+0x19b/0x240\n   ip_tunnel_xmit+0x5fb/0xb60\n   ipgre_xmit+0x14d/0x280 [ip_gre]\n   dev_hard_start_xmit+0xc3/0x1c0\n   __dev_queue_xmit+0x208/0xba0\n   ? nf_hook_slow+0x3f/0xd0\n   ip_finish_output2+0x1ca/0x580\n   ip_sublist_rcv_finish+0x32/0x40\n   ip_sublist_rcv+0x1b2/0x1f0\n   ? ip_rcv_finish_core.constprop.0+0x460/0x460\n   ip_list_rcv+0x103/0x130\n   __netif_receive_skb_list_core+0x181/0x1e0\n   netif_receive_skb_list_internal+0x1b3/0x2c0\n   napi_gro_receive+0xc8/0x200\n   gro_cell_poll+0x52/0x90\n   __napi_poll+0x25/0x1a0\n   net_rx_action+0x28e/0x300\n   __do_softirq+0xc3/0x276\n   ? sort_range+0x20/0x20\n   run_ksoftirqd+0x1e/0x30\n   smpboot_thread_fn+0xa6/0x130\n   kthread+0xcd/0x100\n   ? kthread_complete_and_exit+0x20/0x20\n   ret_from_fork+0x31/0x50\n   ? kthread_complete_and_exit+0x20/0x20\n   ret_from_fork_asm+0x11/0x20\n   </TASK>\n\nThe suggested fix is to introduce a new wrapper (skb_page_unref) that\ncovers page refcounting for page_pool pages as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26953","epss":0.00656,"percentile":0.49323,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26953","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-26962","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26962","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm-raid456, md/raid456: fix a deadlock for dm-raid456 while io concurrent with reshape  For raid456, if reshape is still in progress, then IO across reshape position will wait for reshape to make progress. However, for dm-raid, in following cases reshape will never make progress hence IO will hang:  1) the array is read-only; 2) MD_RECOVERY_WAIT is set; 3) MD_RECOVERY_FROZEN is set;  After commit c467e97f079f (\"md/raid6: use valid sector values to determine if an I/O should wait on the reshape\") fix the problem that IO across reshape position doesn't wait for reshape, the dm-raid test shell/lvconvert-raid-reshape.sh start to hang:  [root@fedora ~]# cat /proc/979/stack [<0>] wait_woken+0x7d/0x90 [<0>] raid5_make_request+0x929/0x1d70 [raid456] [<0>] md_handle_request+0xc2/0x3b0 [md_mod] [<0>] raid_map+0x2c/0x50 [dm_raid] [<0>] __map_bio+0x251/0x380 [dm_mod] [<0>] dm_submit_bio+0x1f0/0x760 [dm_mod] [<0>] __submit_bio+0xc2/0x1c0 [<0>] submit_bio_noacct_nocheck+0x17f/0x450 [<0>] submit_bio_noacct+0x2bc/0x780 [<0>] submit_bio+0x70/0xc0 [<0>] mpage_readahead+0x169/0x1f0 [<0>] blkdev_readahead+0x18/0x30 [<0>] read_pages+0x7c/0x3b0 [<0>] page_cache_ra_unbounded+0x1ab/0x280 [<0>] force_page_cache_ra+0x9e/0x130 [<0>] page_cache_sync_ra+0x3b/0x110 [<0>] filemap_get_pages+0x143/0xa30 [<0>] filemap_read+0xdc/0x4b0 [<0>] blkdev_read_iter+0x75/0x200 [<0>] vfs_read+0x272/0x460 [<0>] ksys_read+0x7a/0x170 [<0>] __x64_sys_read+0x1c/0x30 [<0>] do_syscall_64+0xc6/0x230 [<0>] entry_SYSCALL_64_after_hwframe+0x6c/0x74  This is because reshape can't make progress.  For md/raid, the problem doesn't exist because register new sync_thread doesn't rely on the IO to be done any more:  1) If array is read-only, it can switch to read-write by ioctl/sysfs; 2) md/raid never set MD_RECOVERY_WAIT; 3) If MD_RECOVERY_FROZEN is set, mddev_suspend() doesn't hold    'reconfig_mutex', hence it can be cleared and reshape can continue by    sysfs api 'sync_action'.  However, I'm not sure yet how to avoid the problem in dm-raid yet. This patch on the one hand make sure raid_message() can't change sync_thread() through raid_message() after presuspend(), on the other hand detect the above 3 cases before wait for IO do be done in dm_suspend(), and let dm-raid requeue those IO.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26962","epss":0.00174,"percentile":0.06943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26962","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09135},"relatedVulnerabilities":[{"id":"CVE-2024-26962","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26962","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/41425f96d7aa59bc865f60f5dda3d7697b555677","https://git.kernel.org/stable/c/5943a34bf6bab5801e08a55f63e1b8d5bc90dae1","https://git.kernel.org/stable/c/a8d249d770cb357d16a2097b548d2e4c1c137304"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-raid456, md/raid456: fix a deadlock for dm-raid456 while io concurrent with reshape\n\nFor raid456, if reshape is still in progress, then IO across reshape\nposition will wait for reshape to make progress. However, for dm-raid,\nin following cases reshape will never make progress hence IO will hang:\n\n1) the array is read-only;\n2) MD_RECOVERY_WAIT is set;\n3) MD_RECOVERY_FROZEN is set;\n\nAfter commit c467e97f079f (\"md/raid6: use valid sector values to determine\nif an I/O should wait on the reshape\") fix the problem that IO across\nreshape position doesn't wait for reshape, the dm-raid test\nshell/lvconvert-raid-reshape.sh start to hang:\n\n[root@fedora ~]# cat /proc/979/stack\n[<0>] wait_woken+0x7d/0x90\n[<0>] raid5_make_request+0x929/0x1d70 [raid456]\n[<0>] md_handle_request+0xc2/0x3b0 [md_mod]\n[<0>] raid_map+0x2c/0x50 [dm_raid]\n[<0>] __map_bio+0x251/0x380 [dm_mod]\n[<0>] dm_submit_bio+0x1f0/0x760 [dm_mod]\n[<0>] __submit_bio+0xc2/0x1c0\n[<0>] submit_bio_noacct_nocheck+0x17f/0x450\n[<0>] submit_bio_noacct+0x2bc/0x780\n[<0>] submit_bio+0x70/0xc0\n[<0>] mpage_readahead+0x169/0x1f0\n[<0>] blkdev_readahead+0x18/0x30\n[<0>] read_pages+0x7c/0x3b0\n[<0>] page_cache_ra_unbounded+0x1ab/0x280\n[<0>] force_page_cache_ra+0x9e/0x130\n[<0>] page_cache_sync_ra+0x3b/0x110\n[<0>] filemap_get_pages+0x143/0xa30\n[<0>] filemap_read+0xdc/0x4b0\n[<0>] blkdev_read_iter+0x75/0x200\n[<0>] vfs_read+0x272/0x460\n[<0>] ksys_read+0x7a/0x170\n[<0>] __x64_sys_read+0x1c/0x30\n[<0>] do_syscall_64+0xc6/0x230\n[<0>] entry_SYSCALL_64_after_hwframe+0x6c/0x74\n\nThis is because reshape can't make progress.\n\nFor md/raid, the problem doesn't exist because register new sync_thread\ndoesn't rely on the IO to be done any more:\n\n1) If array is read-only, it can switch to read-write by ioctl/sysfs;\n2) md/raid never set MD_RECOVERY_WAIT;\n3) If MD_RECOVERY_FROZEN is set, mddev_suspend() doesn't hold\n   'reconfig_mutex', hence it can be cleared and reshape can continue by\n   sysfs api 'sync_action'.\n\nHowever, I'm not sure yet how to avoid the problem in dm-raid yet. This\npatch on the one hand make sure raid_message() can't change\nsync_thread() through raid_message() after presuspend(), on the other\nhand detect the above 3 cases before wait for IO do be done in\ndm_suspend(), and let dm-raid requeue those IO.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-26962","epss":0.00174,"percentile":0.06943,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-26962","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-26962","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-27010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-27010","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: Fix mirred deadlock on device recursion  When the mirred action is used on a classful egress qdisc and a packet is mirrored or redirected to self we hit a qdisc lock deadlock. See trace below.  [..... other info removed for brevity....] [   82.890906] [   82.890906] ============================================ [   82.890906] WARNING: possible recursive locking detected [   82.890906] 6.8.0-05205-g77fadd89fe2d-dirty #213 Tainted: G        W [   82.890906] -------------------------------------------- [   82.890906] ping/418 is trying to acquire lock: [   82.890906] ffff888006994110 (&sch->q.lock){+.-.}-{3:3}, at: __dev_queue_xmit+0x1778/0x3550 [   82.890906] [   82.890906] but task is already holding lock: [   82.890906] ffff888006994110 (&sch->q.lock){+.-.}-{3:3}, at: __dev_queue_xmit+0x1778/0x3550 [   82.890906] [   82.890906] other info that might help us debug this: [   82.890906]  Possible unsafe locking scenario: [   82.890906] [   82.890906]        CPU0 [   82.890906]        ---- [   82.890906]   lock(&sch->q.lock); [   82.890906]   lock(&sch->q.lock); [   82.890906] [   82.890906]  *** DEADLOCK *** [   82.890906] [..... other info removed for brevity....]  Example setup (eth0->eth0) to recreate tc qdisc add dev eth0 root handle 1: htb default 30 tc filter add dev eth0 handle 1: protocol ip prio 2 matchall \\      action mirred egress redirect dev eth0  Another example(eth0->eth1->eth0) to recreate tc qdisc add dev eth0 root handle 1: htb default 30 tc filter add dev eth0 handle 1: protocol ip prio 2 matchall \\      action mirred egress redirect dev eth1  tc qdisc add dev eth1 root handle 1: htb default 30 tc filter add dev eth1 handle 1: protocol ip prio 2 matchall \\      action mirred egress redirect dev eth0  We fix this by adding an owner field (CPU id) to struct Qdisc set after root qdisc is entered. When the softirq enters it a second time, if the qdisc owner is the same CPU, the packet is dropped to break the loop.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27010","epss":0.00176,"percentile":0.07269,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27010","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09240000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-27010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-27010","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0f022d32c3eca477fbf79a205243a6123ed0fe11","https://git.kernel.org/stable/c/524323f52cbfbac4fe3f8a33a8cc405fafba0d33","https://git.kernel.org/stable/c/e6b90468da4dae2281a6e381107f411efb48b0ef","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: Fix mirred deadlock on device recursion\n\nWhen the mirred action is used on a classful egress qdisc and a packet is\nmirrored or redirected to self we hit a qdisc lock deadlock.\nSee trace below.\n\n[..... other info removed for brevity....]\n[   82.890906]\n[   82.890906] ============================================\n[   82.890906] WARNING: possible recursive locking detected\n[   82.890906] 6.8.0-05205-g77fadd89fe2d-dirty #213 Tainted: G        W\n[   82.890906] --------------------------------------------\n[   82.890906] ping/418 is trying to acquire lock:\n[   82.890906] ffff888006994110 (&sch->q.lock){+.-.}-{3:3}, at:\n__dev_queue_xmit+0x1778/0x3550\n[   82.890906]\n[   82.890906] but task is already holding lock:\n[   82.890906] ffff888006994110 (&sch->q.lock){+.-.}-{3:3}, at:\n__dev_queue_xmit+0x1778/0x3550\n[   82.890906]\n[   82.890906] other info that might help us debug this:\n[   82.890906]  Possible unsafe locking scenario:\n[   82.890906]\n[   82.890906]        CPU0\n[   82.890906]        ----\n[   82.890906]   lock(&sch->q.lock);\n[   82.890906]   lock(&sch->q.lock);\n[   82.890906]\n[   82.890906]  *** DEADLOCK ***\n[   82.890906]\n[..... other info removed for brevity....]\n\nExample setup (eth0->eth0) to recreate\ntc qdisc add dev eth0 root handle 1: htb default 30\ntc filter add dev eth0 handle 1: protocol ip prio 2 matchall \\\n     action mirred egress redirect dev eth0\n\nAnother example(eth0->eth1->eth0) to recreate\ntc qdisc add dev eth0 root handle 1: htb default 30\ntc filter add dev eth0 handle 1: protocol ip prio 2 matchall \\\n     action mirred egress redirect dev eth1\n\ntc qdisc add dev eth1 root handle 1: htb default 30\ntc filter add dev eth1 handle 1: protocol ip prio 2 matchall \\\n     action mirred egress redirect dev eth0\n\nWe fix this by adding an owner field (CPU id) to struct Qdisc set after\nroot qdisc is entered. When the softirq enters it a second time, if the\nqdisc owner is the same CPU, the packet is dropped to break the loop.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27010","epss":0.00176,"percentile":0.07269,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27010","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-27010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-27011","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-27011","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: fix memleak in map from abort path  The delete set command does not rely on the transaction object for element removal, therefore, a combination of delete element + delete set from the abort path could result in restoring twice the refcount of the mapping.  Check for inactive element in the next generation for the delete element command in the abort path, skip restoring state if next generation bit has been already cleared. This is similar to the activate logic using the set walk iterator.  [ 6170.286929] ------------[ cut here ]------------ [ 6170.286939] WARNING: CPU: 6 PID: 790302 at net/netfilter/nf_tables_api.c:2086 nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.287071] Modules linked in: [...] [ 6170.287633] CPU: 6 PID: 790302 Comm: kworker/6:2 Not tainted 6.9.0-rc3+ #365 [ 6170.287768] RIP: 0010:nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.287886] Code: df 48 8d 7d 58 e8 69 2e 3b df 48 8b 7d 58 e8 80 1b 37 df 48 8d 7d 68 e8 57 2e 3b df 48 8b 7d 68 e8 6e 1b 37 df 48 89 ef eb c4 <0f> 0b 48 83 c4 08 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc 0f [ 6170.287895] RSP: 0018:ffff888134b8fd08 EFLAGS: 00010202 [ 6170.287904] RAX: 0000000000000001 RBX: ffff888125bffb28 RCX: dffffc0000000000 [ 6170.287912] RDX: 0000000000000003 RSI: ffffffffa20298ab RDI: ffff88811ebe4750 [ 6170.287919] RBP: ffff88811ebe4700 R08: ffff88838e812650 R09: fffffbfff0623a55 [ 6170.287926] R10: ffffffff8311d2af R11: 0000000000000001 R12: ffff888125bffb10 [ 6170.287933] R13: ffff888125bffb10 R14: dead000000000122 R15: dead000000000100 [ 6170.287940] FS:  0000000000000000(0000) GS:ffff888390b00000(0000) knlGS:0000000000000000 [ 6170.287948] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 6170.287955] CR2: 00007fd31fc00710 CR3: 0000000133f60004 CR4: 00000000001706f0 [ 6170.287962] Call Trace: [ 6170.287967]  <TASK> [ 6170.287973]  ? __warn+0x9f/0x1a0 [ 6170.287986]  ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.288092]  ? report_bug+0x1b1/0x1e0 [ 6170.287986]  ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.288092]  ? report_bug+0x1b1/0x1e0 [ 6170.288104]  ? handle_bug+0x3c/0x70 [ 6170.288112]  ? exc_invalid_op+0x17/0x40 [ 6170.288120]  ? asm_exc_invalid_op+0x1a/0x20 [ 6170.288132]  ? nf_tables_chain_destroy+0x2b/0x220 [nf_tables] [ 6170.288243]  ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables] [ 6170.288366]  ? nf_tables_chain_destroy+0x2b/0x220 [nf_tables] [ 6170.288483]  nf_tables_trans_destroy_work+0x588/0x590 [nf_tables]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27011","epss":0.00232,"percentile":0.14093,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27011","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1218},"relatedVulnerabilities":[{"id":"CVE-2024-27011","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-27011","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/49d0e656d19dfb2d4d7c230e4a720d37b3decff6","https://git.kernel.org/stable/c/86a1471d7cde792941109b93b558b5dc078b9ee9","https://git.kernel.org/stable/c/a1bd2a38a1c6388fc8556816dc203c3e9dc52237","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix memleak in map from abort path\n\nThe delete set command does not rely on the transaction object for\nelement removal, therefore, a combination of delete element + delete set\nfrom the abort path could result in restoring twice the refcount of the\nmapping.\n\nCheck for inactive element in the next generation for the delete element\ncommand in the abort path, skip restoring state if next generation bit\nhas been already cleared. This is similar to the activate logic using\nthe set walk iterator.\n\n[ 6170.286929] ------------[ cut here ]------------\n[ 6170.286939] WARNING: CPU: 6 PID: 790302 at net/netfilter/nf_tables_api.c:2086 nf_tables_chain_destroy+0x1f7/0x220 [nf_tables]\n[ 6170.287071] Modules linked in: [...]\n[ 6170.287633] CPU: 6 PID: 790302 Comm: kworker/6:2 Not tainted 6.9.0-rc3+ #365\n[ 6170.287768] RIP: 0010:nf_tables_chain_destroy+0x1f7/0x220 [nf_tables]\n[ 6170.287886] Code: df 48 8d 7d 58 e8 69 2e 3b df 48 8b 7d 58 e8 80 1b 37 df 48 8d 7d 68 e8 57 2e 3b df 48 8b 7d 68 e8 6e 1b 37 df 48 89 ef eb c4 <0f> 0b 48 83 c4 08 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc 0f\n[ 6170.287895] RSP: 0018:ffff888134b8fd08 EFLAGS: 00010202\n[ 6170.287904] RAX: 0000000000000001 RBX: ffff888125bffb28 RCX: dffffc0000000000\n[ 6170.287912] RDX: 0000000000000003 RSI: ffffffffa20298ab RDI: ffff88811ebe4750\n[ 6170.287919] RBP: ffff88811ebe4700 R08: ffff88838e812650 R09: fffffbfff0623a55\n[ 6170.287926] R10: ffffffff8311d2af R11: 0000000000000001 R12: ffff888125bffb10\n[ 6170.287933] R13: ffff888125bffb10 R14: dead000000000122 R15: dead000000000100\n[ 6170.287940] FS:  0000000000000000(0000) GS:ffff888390b00000(0000) knlGS:0000000000000000\n[ 6170.287948] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 6170.287955] CR2: 00007fd31fc00710 CR3: 0000000133f60004 CR4: 00000000001706f0\n[ 6170.287962] Call Trace:\n[ 6170.287967]  <TASK>\n[ 6170.287973]  ? __warn+0x9f/0x1a0\n[ 6170.287986]  ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables]\n[ 6170.288092]  ? report_bug+0x1b1/0x1e0\n[ 6170.287986]  ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables]\n[ 6170.288092]  ? report_bug+0x1b1/0x1e0\n[ 6170.288104]  ? handle_bug+0x3c/0x70\n[ 6170.288112]  ? exc_invalid_op+0x17/0x40\n[ 6170.288120]  ? asm_exc_invalid_op+0x1a/0x20\n[ 6170.288132]  ? nf_tables_chain_destroy+0x2b/0x220 [nf_tables]\n[ 6170.288243]  ? nf_tables_chain_destroy+0x1f7/0x220 [nf_tables]\n[ 6170.288366]  ? nf_tables_chain_destroy+0x2b/0x220 [nf_tables]\n[ 6170.288483]  nf_tables_trans_destroy_work+0x588/0x590 [nf_tables]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27011","epss":0.00232,"percentile":0.14093,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27011","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-27011","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-27041","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-27041","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: fix NULL checks for adev->dm.dc in amdgpu_dm_fini()  Since 'adev->dm.dc' in amdgpu_dm_fini() might turn out to be NULL before the call to dc_enable_dmub_notifications(), check beforehand to ensure there will not be a possible NULL-ptr-deref there.  Also, since commit 1e88eb1b2c25 (\"drm/amd/display: Drop CONFIG_DRM_AMD_DC_HDCP\") there are two separate checks for NULL in 'adev->dm.dc' before dc_deinit_callbacks() and dc_dmub_srv_destroy(). Clean up by combining them all under one 'if'.  Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27041","epss":0.00272,"percentile":0.19373,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27041","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1428},"relatedVulnerabilities":[{"id":"CVE-2024-27041","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-27041","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1c62697e4086de988b31124fb8c79c244ea05f2b","https://git.kernel.org/stable/c/2a3cfb9a24a28da9cc13d2c525a76548865e182c","https://git.kernel.org/stable/c/ca2eb375db76fd50f31afdd67d6ca4f833254957","https://git.kernel.org/stable/c/e040f1fbe9abae91b12b074cfc3bbb5367b79811"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix NULL checks for adev->dm.dc in amdgpu_dm_fini()\n\nSince 'adev->dm.dc' in amdgpu_dm_fini() might turn out to be NULL\nbefore the call to dc_enable_dmub_notifications(), check\nbeforehand to ensure there will not be a possible NULL-ptr-deref\nthere.\n\nAlso, since commit 1e88eb1b2c25 (\"drm/amd/display: Drop\nCONFIG_DRM_AMD_DC_HDCP\") there are two separate checks for NULL in\n'adev->dm.dc' before dc_deinit_callbacks() and dc_dmub_srv_destroy().\nClean up by combining them all under one 'if'.\n\nFound by Linux Verification Center (linuxtesting.org) with static\nanalysis tool SVACE.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27041","epss":0.00272,"percentile":0.19373,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27041","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-27041","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-27057","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-27057","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: SOF: ipc4-pcm: Workaround for crashed firmware on system suspend  When the system is suspended while audio is active, the sof_ipc4_pcm_hw_free() is invoked to reset the pipelines since during suspend the DSP is turned off, streams will be re-started after resume.  If the firmware crashes during while audio is running (or when we reset the stream before suspend) then the sof_ipc4_set_multi_pipeline_state() will fail with IPC error and the state change is interrupted. This will cause misalignment between the kernel and firmware state on next DSP boot resulting errors returned by firmware for IPC messages, eventually failing the audio resume. On stream close the errors are ignored so the kernel state will be corrected on the next DSP boot, so the second boot after the DSP panic.  If sof_ipc4_trigger_pipelines() is called from sof_ipc4_pcm_hw_free() then state parameter is SOF_IPC4_PIPE_RESET and only in this case.  Treat a forced pipeline reset similarly to how we treat a pcm_free by ignoring error on state sending to allow the kernel's state to be consistent with the state the firmware will have after the next boot.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27057","epss":0.00222,"percentile":0.12727,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11655000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-27057","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-27057","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3cac6eebea9b4bc5f041e157e45c76e212ad6759","https://git.kernel.org/stable/c/c40aad7c81e5fba34b70123ed7ce3397fa62a4d2","https://git.kernel.org/stable/c/d153e8b154f9746ac969c85a4e6474760453647c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-pcm: Workaround for crashed firmware on system suspend\n\nWhen the system is suspended while audio is active, the\nsof_ipc4_pcm_hw_free() is invoked to reset the pipelines since during\nsuspend the DSP is turned off, streams will be re-started after resume.\n\nIf the firmware crashes during while audio is running (or when we reset\nthe stream before suspend) then the sof_ipc4_set_multi_pipeline_state()\nwill fail with IPC error and the state change is interrupted.\nThis will cause misalignment between the kernel and firmware state on next\nDSP boot resulting errors returned by firmware for IPC messages, eventually\nfailing the audio resume.\nOn stream close the errors are ignored so the kernel state will be\ncorrected on the next DSP boot, so the second boot after the DSP panic.\n\nIf sof_ipc4_trigger_pipelines() is called from sof_ipc4_pcm_hw_free() then\nstate parameter is SOF_IPC4_PIPE_RESET and only in this case.\n\nTreat a forced pipeline reset similarly to how we treat a pcm_free by\nignoring error on state sending to allow the kernel's state to be\nconsistent with the state the firmware will have after the next boot.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27057","epss":0.00222,"percentile":0.12727,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-27057","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-27062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-27062","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nouveau: lock the client object tree.  It appears the client object tree has no locking unless I've missed something else. Fix races around adding/removing client objects, mostly vram bar mappings.   4562.099306] general protection fault, probably for non-canonical address 0x6677ed422bceb80c: 0000 [#1] PREEMPT SMP PTI [ 4562.099314] CPU: 2 PID: 23171 Comm: deqp-vk Not tainted 6.8.0-rc6+ #27 [ 4562.099324] Hardware name: Gigabyte Technology Co., Ltd. Z390 I AORUS PRO WIFI/Z390 I AORUS PRO WIFI-CF, BIOS F8 11/05/2021 [ 4562.099330] RIP: 0010:nvkm_object_search+0x1d/0x70 [nouveau] [ 4562.099503] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 48 89 f8 48 85 f6 74 39 48 8b 87 a0 00 00 00 48 85 c0 74 12 <48> 8b 48 f8 48 39 ce 73 15 48 8b 40 10 48 85 c0 75 ee 48 c7 c0 fe [ 4562.099506] RSP: 0000:ffffa94cc420bbf8 EFLAGS: 00010206 [ 4562.099512] RAX: 6677ed422bceb814 RBX: ffff98108791f400 RCX: ffff9810f26b8f58 [ 4562.099517] RDX: 0000000000000000 RSI: ffff9810f26b9158 RDI: ffff98108791f400 [ 4562.099519] RBP: ffff9810f26b9158 R08: 0000000000000000 R09: 0000000000000000 [ 4562.099521] R10: ffffa94cc420bc48 R11: 0000000000000001 R12: ffff9810f02a7cc0 [ 4562.099526] R13: 0000000000000000 R14: 00000000000000ff R15: 0000000000000007 [ 4562.099528] FS:  00007f629c5017c0(0000) GS:ffff98142c700000(0000) knlGS:0000000000000000 [ 4562.099534] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 4562.099536] CR2: 00007f629a882000 CR3: 000000017019e004 CR4: 00000000003706f0 [ 4562.099541] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 4562.099542] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 4562.099544] Call Trace: [ 4562.099555]  <TASK> [ 4562.099573]  ? die_addr+0x36/0x90 [ 4562.099583]  ? exc_general_protection+0x246/0x4a0 [ 4562.099593]  ? asm_exc_general_protection+0x26/0x30 [ 4562.099600]  ? nvkm_object_search+0x1d/0x70 [nouveau] [ 4562.099730]  nvkm_ioctl+0xa1/0x250 [nouveau] [ 4562.099861]  nvif_object_map_handle+0xc8/0x180 [nouveau] [ 4562.099986]  nouveau_ttm_io_mem_reserve+0x122/0x270 [nouveau] [ 4562.100156]  ? dma_resv_test_signaled+0x26/0xb0 [ 4562.100163]  ttm_bo_vm_fault_reserved+0x97/0x3c0 [ttm] [ 4562.100182]  ? __mutex_unlock_slowpath+0x2a/0x270 [ 4562.100189]  nouveau_ttm_fault+0x69/0xb0 [nouveau] [ 4562.100356]  __do_fault+0x32/0x150 [ 4562.100362]  do_fault+0x7c/0x560 [ 4562.100369]  __handle_mm_fault+0x800/0xc10 [ 4562.100382]  handle_mm_fault+0x17c/0x3e0 [ 4562.100388]  do_user_addr_fault+0x208/0x860 [ 4562.100395]  exc_page_fault+0x7f/0x200 [ 4562.100402]  asm_exc_page_fault+0x26/0x30 [ 4562.100412] RIP: 0033:0x9b9870 [ 4562.100419] Code: 85 a8 f7 ff ff 8b 8d 80 f7 ff ff 89 08 e9 18 f2 ff ff 0f 1f 84 00 00 00 00 00 44 89 32 e9 90 fa ff ff 0f 1f 84 00 00 00 00 00 <44> 89 32 e9 f8 f1 ff ff 0f 1f 84 00 00 00 00 00 66 44 89 32 e9 e7 [ 4562.100422] RSP: 002b:00007fff9ba2dc70 EFLAGS: 00010246 [ 4562.100426] RAX: 0000000000000004 RBX: 000000000dd65e10 RCX: 000000fff0000000 [ 4562.100428] RDX: 00007f629a882000 RSI: 00007f629a882000 RDI: 0000000000000066 [ 4562.100432] RBP: 00007fff9ba2e570 R08: 0000000000000000 R09: 0000000123ddf000 [ 4562.100434] R10: 0000000000000001 R11: 0000000000000246 R12: 000000007fffffff [ 4562.100436] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 [ 4562.100446]  </TASK> [ 4562.100448] Modules linked in: nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables libcrc32c nfnetlink cmac bnep sunrpc iwlmvm intel_rapl_msr intel_rapl_common snd_sof_pci_intel_cnl x86_pkg_temp_thermal intel_powerclamp snd_sof_intel_hda_common mac80211 coretemp snd_soc_acpi_intel_match kvm_intel snd_soc_acpi snd_soc_hdac_hda snd_sof_pci snd_sof_xtensa_dsp snd_sof_intel_hda_mlink  ---truncated---","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27062","epss":0.00181,"percentile":0.07783,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27062","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095025},"relatedVulnerabilities":[{"id":"CVE-2024-27062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-27062","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6887314f5356389fc219b8152e951ac084a10ef7","https://git.kernel.org/stable/c/96c8751844171af4b3898fee3857ee180586f589","https://git.kernel.org/stable/c/b7cc4ff787a572edf2c55caeffaa88cd801eb135"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau: lock the client object tree.\n\nIt appears the client object tree has no locking unless I've missed\nsomething else. Fix races around adding/removing client objects,\nmostly vram bar mappings.\n\n 4562.099306] general protection fault, probably for non-canonical address 0x6677ed422bceb80c: 0000 [#1] PREEMPT SMP PTI\n[ 4562.099314] CPU: 2 PID: 23171 Comm: deqp-vk Not tainted 6.8.0-rc6+ #27\n[ 4562.099324] Hardware name: Gigabyte Technology Co., Ltd. Z390 I AORUS PRO WIFI/Z390 I AORUS PRO WIFI-CF, BIOS F8 11/05/2021\n[ 4562.099330] RIP: 0010:nvkm_object_search+0x1d/0x70 [nouveau]\n[ 4562.099503] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 48 89 f8 48 85 f6 74 39 48 8b 87 a0 00 00 00 48 85 c0 74 12 <48> 8b 48 f8 48 39 ce 73 15 48 8b 40 10 48 85 c0 75 ee 48 c7 c0 fe\n[ 4562.099506] RSP: 0000:ffffa94cc420bbf8 EFLAGS: 00010206\n[ 4562.099512] RAX: 6677ed422bceb814 RBX: ffff98108791f400 RCX: ffff9810f26b8f58\n[ 4562.099517] RDX: 0000000000000000 RSI: ffff9810f26b9158 RDI: ffff98108791f400\n[ 4562.099519] RBP: ffff9810f26b9158 R08: 0000000000000000 R09: 0000000000000000\n[ 4562.099521] R10: ffffa94cc420bc48 R11: 0000000000000001 R12: ffff9810f02a7cc0\n[ 4562.099526] R13: 0000000000000000 R14: 00000000000000ff R15: 0000000000000007\n[ 4562.099528] FS:  00007f629c5017c0(0000) GS:ffff98142c700000(0000) knlGS:0000000000000000\n[ 4562.099534] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 4562.099536] CR2: 00007f629a882000 CR3: 000000017019e004 CR4: 00000000003706f0\n[ 4562.099541] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 4562.099542] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 4562.099544] Call Trace:\n[ 4562.099555]  <TASK>\n[ 4562.099573]  ? die_addr+0x36/0x90\n[ 4562.099583]  ? exc_general_protection+0x246/0x4a0\n[ 4562.099593]  ? asm_exc_general_protection+0x26/0x30\n[ 4562.099600]  ? nvkm_object_search+0x1d/0x70 [nouveau]\n[ 4562.099730]  nvkm_ioctl+0xa1/0x250 [nouveau]\n[ 4562.099861]  nvif_object_map_handle+0xc8/0x180 [nouveau]\n[ 4562.099986]  nouveau_ttm_io_mem_reserve+0x122/0x270 [nouveau]\n[ 4562.100156]  ? dma_resv_test_signaled+0x26/0xb0\n[ 4562.100163]  ttm_bo_vm_fault_reserved+0x97/0x3c0 [ttm]\n[ 4562.100182]  ? __mutex_unlock_slowpath+0x2a/0x270\n[ 4562.100189]  nouveau_ttm_fault+0x69/0xb0 [nouveau]\n[ 4562.100356]  __do_fault+0x32/0x150\n[ 4562.100362]  do_fault+0x7c/0x560\n[ 4562.100369]  __handle_mm_fault+0x800/0xc10\n[ 4562.100382]  handle_mm_fault+0x17c/0x3e0\n[ 4562.100388]  do_user_addr_fault+0x208/0x860\n[ 4562.100395]  exc_page_fault+0x7f/0x200\n[ 4562.100402]  asm_exc_page_fault+0x26/0x30\n[ 4562.100412] RIP: 0033:0x9b9870\n[ 4562.100419] Code: 85 a8 f7 ff ff 8b 8d 80 f7 ff ff 89 08 e9 18 f2 ff ff 0f 1f 84 00 00 00 00 00 44 89 32 e9 90 fa ff ff 0f 1f 84 00 00 00 00 00 <44> 89 32 e9 f8 f1 ff ff 0f 1f 84 00 00 00 00 00 66 44 89 32 e9 e7\n[ 4562.100422] RSP: 002b:00007fff9ba2dc70 EFLAGS: 00010246\n[ 4562.100426] RAX: 0000000000000004 RBX: 000000000dd65e10 RCX: 000000fff0000000\n[ 4562.100428] RDX: 00007f629a882000 RSI: 00007f629a882000 RDI: 0000000000000066\n[ 4562.100432] RBP: 00007fff9ba2e570 R08: 0000000000000000 R09: 0000000123ddf000\n[ 4562.100434] R10: 0000000000000001 R11: 0000000000000246 R12: 000000007fffffff\n[ 4562.100436] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n[ 4562.100446]  </TASK>\n[ 4562.100448] Modules linked in: nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables libcrc32c nfnetlink cmac bnep sunrpc iwlmvm intel_rapl_msr intel_rapl_common snd_sof_pci_intel_cnl x86_pkg_temp_thermal intel_powerclamp snd_sof_intel_hda_common mac80211 coretemp snd_soc_acpi_intel_match kvm_intel snd_soc_acpi snd_soc_hdac_hda snd_sof_pci snd_sof_xtensa_dsp snd_sof_intel_hda_mlink \n---truncated---","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27062","epss":0.00181,"percentile":0.07783,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27062","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-27062","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-27079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-27079","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/vt-d: Fix NULL domain on device release  In the kdump kernel, the IOMMU operates in deferred_attach mode. In this mode, info->domain may not yet be assigned by the time the release_device function is called. It leads to the following crash in the crash kernel:      BUG: kernel NULL pointer dereference, address: 000000000000003c     ...     RIP: 0010:do_raw_spin_lock+0xa/0xa0     ...     _raw_spin_lock_irqsave+0x1b/0x30     intel_iommu_release_device+0x96/0x170     iommu_deinit_device+0x39/0xf0     __iommu_group_remove_device+0xa0/0xd0     iommu_bus_notifier+0x55/0xb0     notifier_call_chain+0x5a/0xd0     blocking_notifier_call_chain+0x41/0x60     bus_notify+0x34/0x50     device_del+0x269/0x3d0     pci_remove_bus_device+0x77/0x100     p2sb_bar+0xae/0x1d0     ...     i801_probe+0x423/0x740  Use the release_domain mechanism to fix it. The scalable mode context entry which is not part of release domain should be cleared in release_device().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27079","epss":0.00242,"percentile":0.15374,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27079","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12705},"relatedVulnerabilities":[{"id":"CVE-2024-27079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-27079","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/333fe86968482ca701c609af590003bcea450e8f","https://git.kernel.org/stable/c/81e921fd321614c2ad8ac333b041aae1da7a1c6d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix NULL domain on device release\n\nIn the kdump kernel, the IOMMU operates in deferred_attach mode. In this\nmode, info->domain may not yet be assigned by the time the release_device\nfunction is called. It leads to the following crash in the crash kernel:\n\n    BUG: kernel NULL pointer dereference, address: 000000000000003c\n    ...\n    RIP: 0010:do_raw_spin_lock+0xa/0xa0\n    ...\n    _raw_spin_lock_irqsave+0x1b/0x30\n    intel_iommu_release_device+0x96/0x170\n    iommu_deinit_device+0x39/0xf0\n    __iommu_group_remove_device+0xa0/0xd0\n    iommu_bus_notifier+0x55/0xb0\n    notifier_call_chain+0x5a/0xd0\n    blocking_notifier_call_chain+0x41/0x60\n    bus_notify+0x34/0x50\n    device_del+0x269/0x3d0\n    pci_remove_bus_device+0x77/0x100\n    p2sb_bar+0xae/0x1d0\n    ...\n    i801_probe+0x423/0x740\n\nUse the release_domain mechanism to fix it. The scalable mode context\nentry which is not part of release domain should be cleared in\nrelease_device().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27079","epss":0.00242,"percentile":0.15374,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27079","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-27079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-27408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-27408","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup  The Linked list element and pointer are not stored in the same memory as the eDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27408","epss":0.00192,"percentile":0.0897,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27408","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09312},"relatedVulnerabilities":[{"id":"CVE-2024-27408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-27408","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/bbcc1c83f343e580c3aa1f2a8593343bf7b55bba","https://git.kernel.org/stable/c/d24fe6d5a1cfdddb7a9ef56736ec501c4d0a5fd3","https://git.kernel.org/stable/c/f396b4df27cfe01a99f4b41f584c49e56477be3a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup\n\nThe Linked list element and pointer are not stored in the same memory as\nthe eDMA controller register. If the doorbell register is toggled before\nthe full write of the linked list a race condition error will occur.\nIn remote setup we can only use a readl to the memory to assure the full\nwrite has occurred.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-27408","epss":0.00192,"percentile":0.0897,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-27408","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-27408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35784","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35784","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix deadlock with fiemap and extent locking  While working on the patchset to remove extent locking I got a lockdep splat with fiemap and pagefaulting with my new extent lock replacement lock.  This deadlock exists with our normal code, we just don't have lockdep annotations with the extent locking so we've never noticed it.  Since we're copying the fiemap extent to user space on every iteration we have the chance of pagefaulting.  Because we hold the extent lock for the entire range we could mkwrite into a range in the file that we have mmap'ed.  This would deadlock with the following stack trace  [<0>] lock_extent+0x28d/0x2f0 [<0>] btrfs_page_mkwrite+0x273/0x8a0 [<0>] do_page_mkwrite+0x50/0xb0 [<0>] do_fault+0xc1/0x7b0 [<0>] __handle_mm_fault+0x2fa/0x460 [<0>] handle_mm_fault+0xa4/0x330 [<0>] do_user_addr_fault+0x1f4/0x800 [<0>] exc_page_fault+0x7c/0x1e0 [<0>] asm_exc_page_fault+0x26/0x30 [<0>] rep_movs_alternative+0x33/0x70 [<0>] _copy_to_user+0x49/0x70 [<0>] fiemap_fill_next_extent+0xc8/0x120 [<0>] emit_fiemap_extent+0x4d/0xa0 [<0>] extent_fiemap+0x7f8/0xad0 [<0>] btrfs_fiemap+0x49/0x80 [<0>] __x64_sys_ioctl+0x3e1/0xb50 [<0>] do_syscall_64+0x94/0x1a0 [<0>] entry_SYSCALL_64_after_hwframe+0x6e/0x76  I wrote an fstest to reproduce this deadlock without my replacement lock and verified that the deadlock exists with our existing locking.  To fix this simply don't take the extent lock for the entire duration of the fiemap.  This is safe in general because we keep track of where we are when we're searching the tree, so if an ordered extent updates in the middle of our fiemap call we'll still emit the correct extents because we know what offset we were on before.  The only place we maintain the lock is searching delalloc.  Since the delalloc stuff can change during writeback we want to lock the extent range so we have a consistent view of delalloc at the time we're checking to see if we need to set the delalloc flag.  With this patch applied we no longer deadlock with my testcase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35784","epss":0.00173,"percentile":0.06916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35784","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.090825},"relatedVulnerabilities":[{"id":"CVE-2024-35784","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35784","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/89bca7fe6382d61e88c67a0b0e7bce315986fb8b","https://git.kernel.org/stable/c/b0ad381fa7690244802aed119b478b4bdafc31dd","https://git.kernel.org/stable/c/ded566b4637f1b6b4c9ba74e7d0b8493e93f19cf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock with fiemap and extent locking\n\nWhile working on the patchset to remove extent locking I got a lockdep\nsplat with fiemap and pagefaulting with my new extent lock replacement\nlock.\n\nThis deadlock exists with our normal code, we just don't have lockdep\nannotations with the extent locking so we've never noticed it.\n\nSince we're copying the fiemap extent to user space on every iteration\nwe have the chance of pagefaulting.  Because we hold the extent lock for\nthe entire range we could mkwrite into a range in the file that we have\nmmap'ed.  This would deadlock with the following stack trace\n\n[<0>] lock_extent+0x28d/0x2f0\n[<0>] btrfs_page_mkwrite+0x273/0x8a0\n[<0>] do_page_mkwrite+0x50/0xb0\n[<0>] do_fault+0xc1/0x7b0\n[<0>] __handle_mm_fault+0x2fa/0x460\n[<0>] handle_mm_fault+0xa4/0x330\n[<0>] do_user_addr_fault+0x1f4/0x800\n[<0>] exc_page_fault+0x7c/0x1e0\n[<0>] asm_exc_page_fault+0x26/0x30\n[<0>] rep_movs_alternative+0x33/0x70\n[<0>] _copy_to_user+0x49/0x70\n[<0>] fiemap_fill_next_extent+0xc8/0x120\n[<0>] emit_fiemap_extent+0x4d/0xa0\n[<0>] extent_fiemap+0x7f8/0xad0\n[<0>] btrfs_fiemap+0x49/0x80\n[<0>] __x64_sys_ioctl+0x3e1/0xb50\n[<0>] do_syscall_64+0x94/0x1a0\n[<0>] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nI wrote an fstest to reproduce this deadlock without my replacement lock\nand verified that the deadlock exists with our existing locking.\n\nTo fix this simply don't take the extent lock for the entire duration of\nthe fiemap.  This is safe in general because we keep track of where we\nare when we're searching the tree, so if an ordered extent updates in\nthe middle of our fiemap call we'll still emit the correct extents\nbecause we know what offset we were on before.\n\nThe only place we maintain the lock is searching delalloc.  Since the\ndelalloc stuff can change during writeback we want to lock the extent\nrange so we have a consistent view of delalloc at the time we're\nchecking to see if we need to set the delalloc flag.\n\nWith this patch applied we no longer deadlock with my testcase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35784","epss":0.00173,"percentile":0.06916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35784","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35784","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35794","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35794","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm-raid: really frozen sync_thread during suspend  1) commit f52f5c71f3d4 (\"md: fix stopping sync thread\") remove    MD_RECOVERY_FROZEN from __md_stop_writes() and doesn't realize that    dm-raid relies on __md_stop_writes() to frozen sync_thread    indirectly. Fix this problem by adding MD_RECOVERY_FROZEN in    md_stop_writes(), and since stop_sync_thread() is only used for    dm-raid in this case, also move stop_sync_thread() to    md_stop_writes(). 2) The flag MD_RECOVERY_FROZEN doesn't mean that sync thread is frozen,    it only prevent new sync_thread to start, and it can't stop the    running sync thread; In order to frozen sync_thread, after seting the    flag, stop_sync_thread() should be used. 3) The flag MD_RECOVERY_FROZEN doesn't mean that writes are stopped, use    it as condition for md_stop_writes() in raid_postsuspend() doesn't    look correct. Consider that reentrant stop_sync_thread() do nothing,    always call md_stop_writes() in raid_postsuspend(). 4) raid_message can set/clear the flag MD_RECOVERY_FROZEN at anytime,    and if MD_RECOVERY_FROZEN is cleared while the array is suspended,    new sync_thread can start unexpected. Fix this by disallow    raid_message() to change sync_thread status during suspend.  Note that after commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), the test shell/lvconvert-raid-reshape.sh start to hang in stop_sync_thread(), and with previous fixes, the test won't hang there anymore, however, the test will still fail and complain that ext4 is corrupted. And with this patch, the test won't hang due to stop_sync_thread() or fail due to ext4 is corrupted anymore. However, there is still a deadlock related to dm-raid456 that will be fixed in following patches.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35794","epss":0.00223,"percentile":0.12903,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11707500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-35794","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35794","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/16c4770c75b1223998adbeb7286f9a15c65fba73","https://git.kernel.org/stable/c/af916cb66a80597f3523bc85812e790bcdcfd62b","https://git.kernel.org/stable/c/eaa8fc9b092837cf2c754bde1a15d784ce9a85ab"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-raid: really frozen sync_thread during suspend\n\n1) commit f52f5c71f3d4 (\"md: fix stopping sync thread\") remove\n   MD_RECOVERY_FROZEN from __md_stop_writes() and doesn't realize that\n   dm-raid relies on __md_stop_writes() to frozen sync_thread\n   indirectly. Fix this problem by adding MD_RECOVERY_FROZEN in\n   md_stop_writes(), and since stop_sync_thread() is only used for\n   dm-raid in this case, also move stop_sync_thread() to\n   md_stop_writes().\n2) The flag MD_RECOVERY_FROZEN doesn't mean that sync thread is frozen,\n   it only prevent new sync_thread to start, and it can't stop the\n   running sync thread; In order to frozen sync_thread, after seting the\n   flag, stop_sync_thread() should be used.\n3) The flag MD_RECOVERY_FROZEN doesn't mean that writes are stopped, use\n   it as condition for md_stop_writes() in raid_postsuspend() doesn't\n   look correct. Consider that reentrant stop_sync_thread() do nothing,\n   always call md_stop_writes() in raid_postsuspend().\n4) raid_message can set/clear the flag MD_RECOVERY_FROZEN at anytime,\n   and if MD_RECOVERY_FROZEN is cleared while the array is suspended,\n   new sync_thread can start unexpected. Fix this by disallow\n   raid_message() to change sync_thread status during suspend.\n\nNote that after commit f52f5c71f3d4 (\"md: fix stopping sync thread\"), the\ntest shell/lvconvert-raid-reshape.sh start to hang in stop_sync_thread(),\nand with previous fixes, the test won't hang there anymore, however, the\ntest will still fail and complain that ext4 is corrupted. And with this\npatch, the test won't hang due to stop_sync_thread() or fail due to ext4\nis corrupted anymore. However, there is still a deadlock related to\ndm-raid456 that will be fixed in following patches.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35794","epss":0.00223,"percentile":0.12903,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35794","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35799","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35799","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Prevent crash when disable stream  [Why] Disabling stream encoder invokes a function that no longer exists.  [How] Check if the function declaration is NULL in disable stream encoder.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35799","epss":0.00229,"percentile":0.13633,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35799","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.120225},"relatedVulnerabilities":[{"id":"CVE-2024-35799","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35799","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2b17133a0a2e0e111803124dad09e803718d4a48","https://git.kernel.org/stable/c/4356a2c3f296503c8b420ae8adece053960a9f06","https://git.kernel.org/stable/c/59772327d439874095516673b4b30c48bd83ca38","https://git.kernel.org/stable/c/72d72e8fddbcd6c98e1b02d32cf6f2b04e10bd1c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Prevent crash when disable stream\n\n[Why]\nDisabling stream encoder invokes a function that no longer exists.\n\n[How]\nCheck if the function declaration is NULL in disable stream encoder.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"exploitabilityScore":2.6,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35799","epss":0.00229,"percentile":0.13633,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35799","cwe":"CWE-400","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35799","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35808","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35808","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md/dm-raid: don't call md_reap_sync_thread() directly  Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'.  However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b (\"md: refactor idle/frozen_sync_thread() to fix deadlock\").  Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35808","epss":0.0018,"percentile":0.07746,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35808","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2024-35808","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35808","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/347dcdc15a1706f61aa545ae498ededdf31aeebc","https://git.kernel.org/stable/c/9e59b8d76ff511505eb0dd1478329f09e0f04669","https://git.kernel.org/stable/c/cd32b27a66db8776d8b8e82ec7d7dde97a8693b0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/dm-raid: don't call md_reap_sync_thread() directly\n\nCurrently md_reap_sync_thread() is called from raid_message() directly\nwithout holding 'reconfig_mutex', this is definitely unsafe because\nmd_reap_sync_thread() can change many fields that is protected by\n'reconfig_mutex'.\n\nHowever, hold 'reconfig_mutex' here is still problematic because this\nwill cause deadlock, for example, commit 130443d60b1b (\"md: refactor\nidle/frozen_sync_thread() to fix deadlock\").\n\nFix this problem by using stop_sync_thread() to unregister sync_thread,\nlike md/raid did.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35808","epss":0.0018,"percentile":0.07746,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35808","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35808","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35843","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35843","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/vt-d: Use device rbtree in iopf reporting path  The existing I/O page fault handler currently locates the PCI device by calling pci_get_domain_bus_and_slot(). This function searches the list of all PCI devices until the desired device is found. To improve lookup efficiency, replace it with device_rbtree_find() to search the device within the probed device rbtree.  The I/O page fault is initiated by the device, which does not have any synchronization mechanism with the software to ensure that the device stays in the probed device tree. Theoretically, a device could be released by the IOMMU subsystem after device_rbtree_find() and before iopf_get_dev_fault_param(), which would cause a use-after-free problem.  Add a mutex to synchronize the I/O page fault reporting path and the IOMMU release device path. This lock doesn't introduce any performance overhead, as the conflict between I/O page fault reporting and device releasing is very rare.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35843","epss":0.00216,"percentile":0.12039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35843","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12744},"relatedVulnerabilities":[{"id":"CVE-2024-35843","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35843","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3d39238991e745c5df85785604f037f35d9d1b15","https://git.kernel.org/stable/c/def054b01a867822254e1dda13d587f5c7a99e2a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Use device rbtree in iopf reporting path\n\nThe existing I/O page fault handler currently locates the PCI device by\ncalling pci_get_domain_bus_and_slot(). This function searches the list\nof all PCI devices until the desired device is found. To improve lookup\nefficiency, replace it with device_rbtree_find() to search the device\nwithin the probed device rbtree.\n\nThe I/O page fault is initiated by the device, which does not have any\nsynchronization mechanism with the software to ensure that the device\nstays in the probed device tree. Theoretically, a device could be released\nby the IOMMU subsystem after device_rbtree_find() and before\niopf_get_dev_fault_param(), which would cause a use-after-free problem.\n\nAdd a mutex to synchronize the I/O page fault reporting path and the IOMMU\nrelease device path. This lock doesn't introduce any performance overhead,\nas the conflict between I/O page fault reporting and device releasing is\nvery rare.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"exploitabilityScore":2.6,"impactScore":4.3},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35843","epss":0.00216,"percentile":0.12039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35843","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35843","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35860","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35860","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: support deferring bpf_link dealloc to after RCU grace period  BPF link for some program types is passed as a \"context\" which can be used by those BPF programs to look up additional information. E.g., for multi-kprobes and multi-uprobes, link is used to fetch BPF cookie values.  Because of this runtime dependency, when bpf_link refcnt drops to zero there could still be active BPF programs running accessing link data.  This patch adds generic support to defer bpf_link dealloc callback to after RCU GP, if requested. This is done by exposing two different deallocation callbacks, one synchronous and one deferred. If deferred one is provided, bpf_link_free() will schedule dealloc_deferred() callback to happen after RCU GP.  BPF is using two flavors of RCU: \"classic\" non-sleepable one and RCU tasks trace one. The latter is used when sleepable BPF programs are used. bpf_link_free() accommodates that by checking underlying BPF program's sleepable flag, and goes either through normal RCU GP only for non-sleepable, or through RCU tasks trace GP *and* then normal RCU GP (taking into account rcu_trace_implies_rcu_gp() optimization), if BPF program is sleepable.  We use this for multi-kprobe and multi-uprobe links, which dereference link during program run. We also preventively switch raw_tp link to use deferred dealloc callback, as upcoming changes in bpf-next tree expose raw_tp link data (specifically, cookie value) to BPF program at runtime as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35860","epss":0.00236,"percentile":0.14562,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12390000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-35860","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35860","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce","https://git.kernel.org/stable/c/5d8d447777564b35f67000e7838e7ccb64d525c8","https://git.kernel.org/stable/c/876941f533e7b47fc69977fc4551c02f2d18af97"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: support deferring bpf_link dealloc to after RCU grace period\n\nBPF link for some program types is passed as a \"context\" which can be\nused by those BPF programs to look up additional information. E.g., for\nmulti-kprobes and multi-uprobes, link is used to fetch BPF cookie values.\n\nBecause of this runtime dependency, when bpf_link refcnt drops to zero\nthere could still be active BPF programs running accessing link data.\n\nThis patch adds generic support to defer bpf_link dealloc callback to\nafter RCU GP, if requested. This is done by exposing two different\ndeallocation callbacks, one synchronous and one deferred. If deferred\none is provided, bpf_link_free() will schedule dealloc_deferred()\ncallback to happen after RCU GP.\n\nBPF is using two flavors of RCU: \"classic\" non-sleepable one and RCU\ntasks trace one. The latter is used when sleepable BPF programs are\nused. bpf_link_free() accommodates that by checking underlying BPF\nprogram's sleepable flag, and goes either through normal RCU GP only for\nnon-sleepable, or through RCU tasks trace GP *and* then normal RCU GP\n(taking into account rcu_trace_implies_rcu_gp() optimization), if BPF\nprogram is sleepable.\n\nWe use this for multi-kprobe and multi-uprobe links, which dereference\nlink during program run. We also preventively switch raw_tp link to use\ndeferred dealloc callback, as upcoming changes in bpf-next tree expose\nraw_tp link data (specifically, cookie value) to BPF program at runtime\nas well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35860","epss":0.00236,"percentile":0.14562,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35860","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35887","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35887","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ax25: fix use-after-free bugs caused by ax25_ds_del_timer  When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_timer. When the timer handler is running, the ax25_ds_del_timer() that calls del_timer() in it will return directly. As a result, the use-after-free bugs could happen, one of the scenarios is shown below:        (Thread 1)          |      (Thread 2)                           | ax25_ds_timeout() ax25_dev_device_down()    |   ax25_ds_del_timer()     |     del_timer()           |   ax25_dev_put() //FREE   |                           |  ax25_dev-> //USE  In order to mitigate bugs, when the device is detaching, use timer_shutdown_sync() to stop the timer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35887","epss":0.00341,"percentile":0.27235,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35887","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.260865},"relatedVulnerabilities":[{"id":"CVE-2024-35887","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35887","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/74204bf9050f7627aead9875fe4e07ba125cb19b","https://git.kernel.org/stable/c/c6a368f9c7af4c14b14d390c2543af8001c9bdb9","https://git.kernel.org/stable/c/fd819ad3ecf6f3c232a06b27423ce9ed8c20da89"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nax25: fix use-after-free bugs caused by ax25_ds_del_timer\n\nWhen the ax25 device is detaching, the ax25_dev_device_down()\ncalls ax25_ds_del_timer() to cleanup the slave_timer. When\nthe timer handler is running, the ax25_ds_del_timer() that\ncalls del_timer() in it will return directly. As a result,\nthe use-after-free bugs could happen, one of the scenarios\nis shown below:\n\n      (Thread 1)          |      (Thread 2)\n                          | ax25_ds_timeout()\nax25_dev_device_down()    |\n  ax25_ds_del_timer()     |\n    del_timer()           |\n  ax25_dev_put() //FREE   |\n                          |  ax25_dev-> //USE\n\nIn order to mitigate bugs, when the device is detaching, use\ntimer_shutdown_sync() to stop the timer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35887","epss":0.00341,"percentile":0.27235,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35887","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35887","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35904","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35904","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: avoid dereference of garbage after mount failure  In case kern_mount() fails and returns an error pointer return in the error branch instead of continuing and dereferencing the error pointer.  While on it drop the never read static variable selinuxfs_mount.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35904","epss":0.00228,"percentile":0.1347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35904","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11969999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-35904","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35904","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/37801a36b4d68892ce807264f784d818f8d0d39b","https://git.kernel.org/stable/c/477ed6789eb9f3f4d3568bb977f90c863c12724e","https://git.kernel.org/stable/c/68784a5d01b8868ff85a7926676b6729715fff3c","http://www.openwall.com/lists/oss-security/2024/05/30/1","http://www.openwall.com/lists/oss-security/2024/05/30/2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: avoid dereference of garbage after mount failure\n\nIn case kern_mount() fails and returns an error pointer return in the\nerror branch instead of continuing and dereferencing the error pointer.\n\nWhile on it drop the never read static variable selinuxfs_mount.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35904","epss":0.00228,"percentile":0.1347,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35904","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35904","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35924","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35924","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: typec: ucsi: Limit read size on v1.2  Between UCSI 1.2 and UCSI 2.0, the size of the MESSAGE_IN region was increased from 16 to 256. In order to avoid overflowing reads for older systems, add a mechanism to use the read UCSI version to truncate read sizes on UCSI v1.2.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35924","epss":0.00219,"percentile":0.12369,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11497500000000002},"relatedVulnerabilities":[{"id":"CVE-2024-35924","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35924","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0defcaa09d3b21e8387829ee3a652c43fa91e13f","https://git.kernel.org/stable/c/266f403ec47573046dee4bcebda82777ce702c40","https://git.kernel.org/stable/c/b3db266fb031fba88c423d4bb8983a73a3db6527"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Limit read size on v1.2\n\nBetween UCSI 1.2 and UCSI 2.0, the size of the MESSAGE_IN region was\nincreased from 16 to 256. In order to avoid overflowing reads for older\nsystems, add a mechanism to use the read UCSI version to truncate read\nsizes on UCSI v1.2.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35924","epss":0.00219,"percentile":0.12369,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35924","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35931","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35931","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Skip do PCI error slot reset during RAS recovery  Why:     The PCI error slot reset maybe triggered after inject ue to UMC multi times, this     caused system hang.     [  557.371857] amdgpu 0000:af:00.0: amdgpu: GPU reset succeeded, trying to resume     [  557.373718] [drm] PCIE GART of 512M enabled.     [  557.373722] [drm] PTB located at 0x0000031FED700000     [  557.373788] [drm] VRAM is lost due to GPU reset!     [  557.373789] [drm] PSP is resuming...     [  557.547012] mlx5_core 0000:55:00.0: mlx5_pci_err_detected Device state = 1 pci_status: 0. Exit, result = 3, need reset     [  557.547067] [drm] PCI error: detected callback, state(1)!!     [  557.547069] [drm] No support for XGMI hive yet...     [  557.548125] mlx5_core 0000:55:00.0: mlx5_pci_slot_reset Device state = 1 pci_status: 0. Enter     [  557.607763] mlx5_core 0000:55:00.0: wait vital counter value 0x16b5b after 1 iterations     [  557.607777] mlx5_core 0000:55:00.0: mlx5_pci_slot_reset Device state = 1 pci_status: 1. Exit, err = 0, result = 5, recovered     [  557.610492] [drm] PCI error: slot reset callback!!     ...     [  560.689382] amdgpu 0000:3f:00.0: amdgpu: GPU reset(2) succeeded!     [  560.689546] amdgpu 0000:5a:00.0: amdgpu: GPU reset(2) succeeded!     [  560.689562] general protection fault, probably for non-canonical address 0x5f080b54534f611f: 0000 [#1] SMP NOPTI     [  560.701008] CPU: 16 PID: 2361 Comm: kworker/u448:9 Tainted: G           OE     5.15.0-91-generic #101-Ubuntu     [  560.712057] Hardware name: Microsoft C278A/C278A, BIOS C2789.5.BS.1C11.AG.1 11/08/2023     [  560.720959] Workqueue: amdgpu-reset-hive amdgpu_ras_do_recovery [amdgpu]     [  560.728887] RIP: 0010:amdgpu_device_gpu_recover.cold+0xbf1/0xcf5 [amdgpu]     [  560.736891] Code: ff 41 89 c6 e9 1b ff ff ff 44 0f b6 45 b0 e9 4f ff ff ff be 01 00 00 00 4c 89 e7 e8 76 c9 8b ff 44 0f b6 45 b0 e9 3c fd ff ff <48> 83 ba 18 02 00 00 00 0f 84 6a f8 ff ff 48 8d 7a 78 be 01 00 00     [  560.757967] RSP: 0018:ffa0000032e53d80 EFLAGS: 00010202     [  560.763848] RAX: ffa00000001dfd10 RBX: ffa0000000197090 RCX: ffa0000032e53db0     [  560.771856] RDX: 5f080b54534f5f07 RSI: 0000000000000000 RDI: ff11000128100010     [  560.779867] RBP: ffa0000032e53df0 R08: 0000000000000000 R09: ffffffffffe77f08     [  560.787879] R10: 0000000000ffff0a R11: 0000000000000001 R12: 0000000000000000     [  560.795889] R13: ffa0000032e53e00 R14: 0000000000000000 R15: 0000000000000000     [  560.803889] FS:  0000000000000000(0000) GS:ff11007e7e800000(0000) knlGS:0000000000000000     [  560.812973] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033     [  560.819422] CR2: 000055a04c118e68 CR3: 0000000007410005 CR4: 0000000000771ee0     [  560.827433] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000     [  560.835433] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400     [  560.843444] PKRU: 55555554     [  560.846480] Call Trace:     [  560.849225]  <TASK>     [  560.851580]  ? show_trace_log_lvl+0x1d6/0x2ea     [  560.856488]  ? show_trace_log_lvl+0x1d6/0x2ea     [  560.861379]  ? amdgpu_ras_do_recovery+0x1b2/0x210 [amdgpu]     [  560.867778]  ? show_regs.part.0+0x23/0x29     [  560.872293]  ? __die_body.cold+0x8/0xd     [  560.876502]  ? die_addr+0x3e/0x60     [  560.880238]  ? exc_general_protection+0x1c5/0x410     [  560.885532]  ? asm_exc_general_protection+0x27/0x30     [  560.891025]  ? amdgpu_device_gpu_recover.cold+0xbf1/0xcf5 [amdgpu]     [  560.898323]  amdgpu_ras_do_recovery+0x1b2/0x210 [amdgpu]     [  560.904520]  process_one_work+0x228/0x3d0 How:     In RAS recovery, mode-1 reset is issued from RAS fatal error handling and expected     all the nodes in a hive to be reset. no need to issue another mode-1 during this procedure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35931","epss":0.00195,"percentile":0.09371,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.102375},"relatedVulnerabilities":[{"id":"CVE-2024-35931","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35931","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/395ca1031acf89d8ecb26127c544a71688d96f35","https://git.kernel.org/stable/c/601429cca96b4af3be44172c3b64e4228515dbe1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Skip do PCI error slot reset during RAS recovery\n\nWhy:\n    The PCI error slot reset maybe triggered after inject ue to UMC multi times, this\n    caused system hang.\n    [  557.371857] amdgpu 0000:af:00.0: amdgpu: GPU reset succeeded, trying to resume\n    [  557.373718] [drm] PCIE GART of 512M enabled.\n    [  557.373722] [drm] PTB located at 0x0000031FED700000\n    [  557.373788] [drm] VRAM is lost due to GPU reset!\n    [  557.373789] [drm] PSP is resuming...\n    [  557.547012] mlx5_core 0000:55:00.0: mlx5_pci_err_detected Device state = 1 pci_status: 0. Exit, result = 3, need reset\n    [  557.547067] [drm] PCI error: detected callback, state(1)!!\n    [  557.547069] [drm] No support for XGMI hive yet...\n    [  557.548125] mlx5_core 0000:55:00.0: mlx5_pci_slot_reset Device state = 1 pci_status: 0. Enter\n    [  557.607763] mlx5_core 0000:55:00.0: wait vital counter value 0x16b5b after 1 iterations\n    [  557.607777] mlx5_core 0000:55:00.0: mlx5_pci_slot_reset Device state = 1 pci_status: 1. Exit, err = 0, result = 5, recovered\n    [  557.610492] [drm] PCI error: slot reset callback!!\n    ...\n    [  560.689382] amdgpu 0000:3f:00.0: amdgpu: GPU reset(2) succeeded!\n    [  560.689546] amdgpu 0000:5a:00.0: amdgpu: GPU reset(2) succeeded!\n    [  560.689562] general protection fault, probably for non-canonical address 0x5f080b54534f611f: 0000 [#1] SMP NOPTI\n    [  560.701008] CPU: 16 PID: 2361 Comm: kworker/u448:9 Tainted: G           OE     5.15.0-91-generic #101-Ubuntu\n    [  560.712057] Hardware name: Microsoft C278A/C278A, BIOS C2789.5.BS.1C11.AG.1 11/08/2023\n    [  560.720959] Workqueue: amdgpu-reset-hive amdgpu_ras_do_recovery [amdgpu]\n    [  560.728887] RIP: 0010:amdgpu_device_gpu_recover.cold+0xbf1/0xcf5 [amdgpu]\n    [  560.736891] Code: ff 41 89 c6 e9 1b ff ff ff 44 0f b6 45 b0 e9 4f ff ff ff be 01 00 00 00 4c 89 e7 e8 76 c9 8b ff 44 0f b6 45 b0 e9 3c fd ff ff <48> 83 ba 18 02 00 00 00 0f 84 6a f8 ff ff 48 8d 7a 78 be 01 00 00\n    [  560.757967] RSP: 0018:ffa0000032e53d80 EFLAGS: 00010202\n    [  560.763848] RAX: ffa00000001dfd10 RBX: ffa0000000197090 RCX: ffa0000032e53db0\n    [  560.771856] RDX: 5f080b54534f5f07 RSI: 0000000000000000 RDI: ff11000128100010\n    [  560.779867] RBP: ffa0000032e53df0 R08: 0000000000000000 R09: ffffffffffe77f08\n    [  560.787879] R10: 0000000000ffff0a R11: 0000000000000001 R12: 0000000000000000\n    [  560.795889] R13: ffa0000032e53e00 R14: 0000000000000000 R15: 0000000000000000\n    [  560.803889] FS:  0000000000000000(0000) GS:ff11007e7e800000(0000) knlGS:0000000000000000\n    [  560.812973] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n    [  560.819422] CR2: 000055a04c118e68 CR3: 0000000007410005 CR4: 0000000000771ee0\n    [  560.827433] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n    [  560.835433] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n    [  560.843444] PKRU: 55555554\n    [  560.846480] Call Trace:\n    [  560.849225]  <TASK>\n    [  560.851580]  ? show_trace_log_lvl+0x1d6/0x2ea\n    [  560.856488]  ? show_trace_log_lvl+0x1d6/0x2ea\n    [  560.861379]  ? amdgpu_ras_do_recovery+0x1b2/0x210 [amdgpu]\n    [  560.867778]  ? show_regs.part.0+0x23/0x29\n    [  560.872293]  ? __die_body.cold+0x8/0xd\n    [  560.876502]  ? die_addr+0x3e/0x60\n    [  560.880238]  ? exc_general_protection+0x1c5/0x410\n    [  560.885532]  ? asm_exc_general_protection+0x27/0x30\n    [  560.891025]  ? amdgpu_device_gpu_recover.cold+0xbf1/0xcf5 [amdgpu]\n    [  560.898323]  amdgpu_ras_do_recovery+0x1b2/0x210 [amdgpu]\n    [  560.904520]  process_one_work+0x228/0x3d0\nHow:\n    In RAS recovery, mode-1 reset is issued from RAS fatal error handling and expected\n    all the nodes in a hive to be reset. no need to issue another mode-1 during this procedure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35931","epss":0.00195,"percentile":0.09371,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35931","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35942","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35942","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pmdomain: imx8mp-blk-ctrl: imx8mp_blk: Add fdcc clock to hdmimix domain  According to i.MX8MP RM and HDMI ADD, the fdcc clock is part of hdmi rx verification IP that should not enable for HDMI TX. But actually if the clock is disabled before HDMI/LCDIF probe, LCDIF will not get pixel clock from HDMI PHY and print the error logs:  [CRTC:39:crtc-2] vblank wait timed out WARNING: CPU: 2 PID: 9 at drivers/gpu/drm/drm_atomic_helper.c:1634 drm_atomic_helper_wait_for_vblanks.part.0+0x23c/0x260  Add fdcc clock to LCDIF and HDMI TX power domains to fix the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35942","epss":0.00211,"percentile":0.11418,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2024-35942","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35942","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/697624ee8ad557ab5417f985d2c804241a7ad30d","https://git.kernel.org/stable/c/9d3f959b426635c4da50dfc7b1306afd84d23e7c","https://git.kernel.org/stable/c/b13c0d871cd878ff53d25507ca535f59ed1f6a2a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx8mp-blk-ctrl: imx8mp_blk: Add fdcc clock to hdmimix domain\n\nAccording to i.MX8MP RM and HDMI ADD, the fdcc clock is part of\nhdmi rx verification IP that should not enable for HDMI TX.\nBut actually if the clock is disabled before HDMI/LCDIF probe,\nLCDIF will not get pixel clock from HDMI PHY and print the error\nlogs:\n\n[CRTC:39:crtc-2] vblank wait timed out\nWARNING: CPU: 2 PID: 9 at drivers/gpu/drm/drm_atomic_helper.c:1634 drm_atomic_helper_wait_for_vblanks.part.0+0x23c/0x260\n\nAdd fdcc clock to LCDIF and HDMI TX power domains to fix the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35942","epss":0.00211,"percentile":0.11418,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35942","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35945","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35945","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: phy: phy_device: Prevent nullptr exceptions on ISR  If phydev->irq is set unconditionally, check for valid interrupt handler or fall back to polling mode to prevent nullptr exceptions in interrupt service routine.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35945","epss":0.00213,"percentile":0.11625,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35945","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11182500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-35945","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35945","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3419ee39e3d3162ab2ec9942bb537613ed5b6311","https://git.kernel.org/stable/c/61c81872815f46006982bb80460c0c80a949b35b","https://git.kernel.org/stable/c/7a71f61ebf95cedd3f245db6da397822971d8db5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: phy_device: Prevent nullptr exceptions on ISR\n\nIf phydev->irq is set unconditionally, check\nfor valid interrupt handler or fall back to polling mode to prevent\nnullptr exceptions in interrupt service routine.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35945","epss":0.00213,"percentile":0.11625,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35945","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35945","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35946","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35946","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw89: fix null pointer access when abort scan  During cancel scan we might use vif that weren't scanning. Fix this by using the actual scanning vif.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35946","epss":0.00213,"percentile":0.11625,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35946","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11182500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-35946","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35946","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4f11c741908dab7dd48fa5a986b210d4fc74ca8d","https://git.kernel.org/stable/c/7e11a2966f51695c0af0b1f976a32d64dee243b2","https://git.kernel.org/stable/c/b34d64e9aa5505e3c84570aed5c757f1839573e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: fix null pointer access when abort scan\n\nDuring cancel scan we might use vif that weren't scanning.\nFix this by using the actual scanning vif.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35946","epss":0.00213,"percentile":0.11625,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-35946","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35946","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35951","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35951","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr()  Subject: [PATCH] drm/panfrost: Fix the error path in  panfrost_mmu_map_fault_addr()  If some the pages or sgt allocation failed, we shouldn't release the pages ref we got earlier, otherwise we will end up with unbalanced get/put_pages() calls. We should instead leave everything in place and let the BO release function deal with extra cleanup when the object is destroyed, or let the fault handler try again next time it's called.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35951","epss":0.00246,"percentile":0.15841,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12915000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-35951","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35951","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1fc9af813b25e146d3607669247d0f970f5a87c3","https://git.kernel.org/stable/c/31806711e8a4b75e09b1c43652f2a6420e6e1002","https://git.kernel.org/stable/c/e18070c622c63f0cab170348e320454728c277aa","http://www.openwall.com/lists/oss-security/2024/05/30/1","http://www.openwall.com/lists/oss-security/2024/05/30/2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr()\n\nSubject: [PATCH] drm/panfrost: Fix the error path in\n panfrost_mmu_map_fault_addr()\n\nIf some the pages or sgt allocation failed, we shouldn't release the\npages ref we got earlier, otherwise we will end up with unbalanced\nget/put_pages() calls. We should instead leave everything in place\nand let the BO release function deal with extra cleanup when the object\nis destroyed, or let the fault handler try again next time it's called.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35951","epss":0.00246,"percentile":0.15841,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35951","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-35961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-35961","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5: Register devlink first under devlink lock  In case device is having a non fatal FW error during probe, the driver will report the error to user via devlink. This will trigger a WARN_ON, since mlx5 is calling devlink_register() last. In order to avoid the WARN_ON[1], change mlx5 to invoke devl_register() first under devlink lock.  [1] WARNING: CPU: 5 PID: 227 at net/devlink/health.c:483 devlink_recover_notify.constprop.0+0xb8/0xc0 CPU: 5 PID: 227 Comm: kworker/u16:3 Not tainted 6.4.0-rc5_for_upstream_min_debug_2023_06_12_12_38 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 Workqueue: mlx5_health0000:08:00.0 mlx5_fw_reporter_err_work [mlx5_core] RIP: 0010:devlink_recover_notify.constprop.0+0xb8/0xc0 Call Trace:  <TASK>  ? __warn+0x79/0x120  ? devlink_recover_notify.constprop.0+0xb8/0xc0  ? report_bug+0x17c/0x190  ? handle_bug+0x3c/0x60  ? exc_invalid_op+0x14/0x70  ? asm_exc_invalid_op+0x16/0x20  ? devlink_recover_notify.constprop.0+0xb8/0xc0  devlink_health_report+0x4a/0x1c0  mlx5_fw_reporter_err_work+0xa4/0xd0 [mlx5_core]  process_one_work+0x1bb/0x3c0  ? process_one_work+0x3c0/0x3c0  worker_thread+0x4d/0x3c0  ? process_one_work+0x3c0/0x3c0  kthread+0xc6/0xf0  ? kthread_complete_and_exit+0x20/0x20  ret_from_fork+0x1f/0x30  </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35961","epss":0.00227,"percentile":0.13377,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11917499999999999},"relatedVulnerabilities":[{"id":"CVE-2024-35961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35961","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/8c91c60858473731bcdaf04fda99fcbcf84420d4","https://git.kernel.org/stable/c/967caa3d37c078e5b95a32094657e6a4cad145f0","https://git.kernel.org/stable/c/c6e77aa9dd82bc18a89bf49418f8f7e961cfccc8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Register devlink first under devlink lock\n\nIn case device is having a non fatal FW error during probe, the\ndriver will report the error to user via devlink. This will trigger\na WARN_ON, since mlx5 is calling devlink_register() last.\nIn order to avoid the WARN_ON[1], change mlx5 to invoke devl_register()\nfirst under devlink lock.\n\n[1]\nWARNING: CPU: 5 PID: 227 at net/devlink/health.c:483 devlink_recover_notify.constprop.0+0xb8/0xc0\nCPU: 5 PID: 227 Comm: kworker/u16:3 Not tainted 6.4.0-rc5_for_upstream_min_debug_2023_06_12_12_38 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nWorkqueue: mlx5_health0000:08:00.0 mlx5_fw_reporter_err_work [mlx5_core]\nRIP: 0010:devlink_recover_notify.constprop.0+0xb8/0xc0\nCall Trace:\n <TASK>\n ? __warn+0x79/0x120\n ? devlink_recover_notify.constprop.0+0xb8/0xc0\n ? report_bug+0x17c/0x190\n ? handle_bug+0x3c/0x60\n ? exc_invalid_op+0x14/0x70\n ? asm_exc_invalid_op+0x16/0x20\n ? devlink_recover_notify.constprop.0+0xb8/0xc0\n devlink_health_report+0x4a/0x1c0\n mlx5_fw_reporter_err_work+0xa4/0xd0 [mlx5_core]\n process_one_work+0x1bb/0x3c0\n ? process_one_work+0x3c0/0x3c0\n worker_thread+0x4d/0x3c0\n ? process_one_work+0x3c0/0x3c0\n kthread+0xc6/0xf0\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x1f/0x30\n </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-35961","epss":0.00227,"percentile":0.13377,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-35961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-36024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36024","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Disable idle reallow as part of command/gpint execution  [Why] Workaroud for a race condition where DMCUB is in the process of committing to IPS1 during the handshake causing us to miss the transition into IPS2 and touch the INBOX1 RPTR causing a HW hang.  [How] Disable the reallow to ensure that we have enough of a gap between entry and exit and we're not seeing back-to-back wake_and_executes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36024","epss":0.00159,"percentile":0.05425,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36024","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07711499999999999},"relatedVulnerabilities":[{"id":"CVE-2024-36024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36024","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2aac387445610d6dfd681f5214388e86f5677ef7","https://git.kernel.org/stable/c/6226a5aa77370329e01ee8abe50a95e60618ce97"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Disable idle reallow as part of command/gpint execution\n\n[Why]\nWorkaroud for a race condition where DMCUB is in the process of\ncommitting to IPS1 during the handshake causing us to miss the\ntransition into IPS2 and touch the INBOX1 RPTR causing a HW hang.\n\n[How]\nDisable the reallow to ensure that we have enough of a gap between entry\nand exit and we're not seeing back-to-back wake_and_executes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36024","epss":0.00159,"percentile":0.05425,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36024","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-36881","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36881","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/userfaultfd: reset ptes when close() for wr-protected ones  Userfaultfd unregister includes a step to remove wr-protect bits from all the relevant pgtable entries, but that only covered an explicit UFFDIO_UNREGISTER ioctl, not a close() on the userfaultfd itself.  Cover that too.  This fixes a WARN trace.  The only user visible side effect is the user can observe leftover wr-protect bits even if the user close()ed on an userfaultfd when releasing the last reference of it.  However hopefully that should be harmless, and nothing bad should happen even if so.  This change is now more important after the recent page-table-check patch we merged in mm-unstable (446dd9ad37d0 (\"mm/page_table_check: support userfault wr-protect entries\")), as we'll do sanity check on uffd-wp bits without vma context.  So it's better if we can 100% guarantee no uffd-wp bit leftovers, to make sure each report will be valid.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36881","epss":0.00239,"percentile":0.14905,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12547500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-36881","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36881","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/377f3a9a3d032a52325a5b110379a25dd1ab1931","https://git.kernel.org/stable/c/8d8b68a5b0c9fb23d37df06bb273ead38fd5a29d","https://git.kernel.org/stable/c/c88033efe9a391e72ba6b5df4b01d6e628f4e734"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/userfaultfd: reset ptes when close() for wr-protected ones\n\nUserfaultfd unregister includes a step to remove wr-protect bits from all\nthe relevant pgtable entries, but that only covered an explicit\nUFFDIO_UNREGISTER ioctl, not a close() on the userfaultfd itself.  Cover\nthat too.  This fixes a WARN trace.\n\nThe only user visible side effect is the user can observe leftover\nwr-protect bits even if the user close()ed on an userfaultfd when\nreleasing the last reference of it.  However hopefully that should be\nharmless, and nothing bad should happen even if so.\n\nThis change is now more important after the recent page-table-check\npatch we merged in mm-unstable (446dd9ad37d0 (\"mm/page_table_check:\nsupport userfault wr-protect entries\")), as we'll do sanity check on\nuffd-wp bits without vma context.  So it's better if we can 100%\nguarantee no uffd-wp bit leftovers, to make sure each report will be\nvalid.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36881","epss":0.00239,"percentile":0.14905,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36881","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-36911","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36911","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hv_netvsc: Don't free decrypted memory  In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues.  The netvsc driver could free decrypted/shared pages if set_memory_decrypted() fails. Check the decrypted field in the gpadl to decide whether to free the memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36911","epss":0.00612,"percentile":0.47286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36911","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3213},"relatedVulnerabilities":[{"id":"CVE-2024-36911","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36911","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4aaed9dbe8acd2b6114458f0498a617283d6275b","https://git.kernel.org/stable/c/a56fe611326332bf6b7126e5559590c57dcebad4","https://git.kernel.org/stable/c/bbf9ac34677b57506a13682b31a2a718934c0e31"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: Don't free decrypted memory\n\nIn CoCo VMs it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nThe netvsc driver could free decrypted/shared pages if\nset_memory_decrypted() fails. Check the decrypted field in the gpadl\nto decide whether to free the memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36911","epss":0.00612,"percentile":0.47286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36911","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36911","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-36949","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36949","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  amd/amdkfd: sync all devices to wait all processes being evicted  If there are more than one device doing reset in parallel, the first device will call kfd_suspend_all_processes() to evict all processes on all devices, this call takes time to finish. other device will start reset and recover without waiting. if the process has not been evicted before doing recover, it will be restored, then caused page fault.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36949","epss":0.00223,"percentile":0.12816,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36949","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815500000000002},"relatedVulnerabilities":[{"id":"CVE-2024-36949","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36949","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/b6f6626528fe724b512c34f3fb5946c36a135f58","https://git.kernel.org/stable/c/d06af584be5a769d124b7302b32a033e9559761d","https://git.kernel.org/stable/c/ed28ef3840bbf93a64376ea7814ce39f86352e14"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\namd/amdkfd: sync all devices to wait all processes being evicted\n\nIf there are more than one device doing reset in parallel, the first\ndevice will call kfd_suspend_all_processes() to evict all processes\non all devices, this call takes time to finish. other device will\nstart reset and recover without waiting. if the process has not been\nevicted before doing recover, it will be restored, then caused page\nfault.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36949","epss":0.00223,"percentile":0.12816,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36949","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36949","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-36951","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36951","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: range check cp bad op exception interrupts  Due to a CP interrupt bug, bad packet garbage exception codes are raised. Do a range check so that the debugger and runtime do not receive garbage codes. Update the user api to guard exception code type checking as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36951","epss":0.00222,"percentile":0.12794,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11655000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-36951","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36951","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0cac183b98d8a8c692c98e8dba37df15a9e9210d","https://git.kernel.org/stable/c/41dc6791596656dd41100b85647ed489e1d5c2f2","https://git.kernel.org/stable/c/b6735bfe941486c5dfc9c3085d2d75d4923f9449"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: range check cp bad op exception interrupts\n\nDue to a CP interrupt bug, bad packet garbage exception codes are raised.\nDo a range check so that the debugger and runtime do not receive garbage\ncodes.\nUpdate the user api to guard exception code type checking as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36951","epss":0.00222,"percentile":0.12794,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36951","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-36968","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-36968","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init()  l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev->le_mtu may not fall in the valid range.  Move MTU from hci_dev to hci_conn to validate MTU and stop the connection process earlier if MTU is invalid. Also, add a missing validation in read_buffer_size() and make it return an error value if the validation fails. Now hci_conn_add() returns ERR_PTR() as it can fail due to the both a kzalloc failure and invalid MTU value.  divide error: 0000 [#1] PREEMPT SMP KASAN NOPTI CPU: 0 PID: 67 Comm: kworker/u5:0 Tainted: G        W          6.9.0-rc5+ #20 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Workqueue: hci0 hci_rx_work RIP: 0010:l2cap_le_flowctl_init+0x19e/0x3f0 net/bluetooth/l2cap_core.c:547 Code: e8 17 17 0c 00 66 41 89 9f 84 00 00 00 bf 01 00 00 00 41 b8 02 00 00 00 4c 89 fe 4c 89 e2 89 d9 e8 27 17 0c 00 44 89 f0 31 d2 <66> f7 f3 89 c3 ff c3 4d 8d b7 88 00 00 00 4c 89 f0 48 c1 e8 03 42 RSP: 0018:ffff88810bc0f858 EFLAGS: 00010246 RAX: 00000000000002a0 RBX: 0000000000000000 RCX: dffffc0000000000 RDX: 0000000000000000 RSI: ffff88810bc0f7c0 RDI: ffffc90002dcb66f RBP: ffff88810bc0f880 R08: aa69db2dda70ff01 R09: 0000ffaaaaaaaaaa R10: 0084000000ffaaaa R11: 0000000000000000 R12: ffff88810d65a084 R13: dffffc0000000000 R14: 00000000000002a0 R15: ffff88810d65a000 FS:  0000000000000000(0000) GS:ffff88811ac00000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000020000100 CR3: 0000000103268003 CR4: 0000000000770ef0 PKRU: 55555554 Call Trace:  <TASK>  l2cap_le_connect_req net/bluetooth/l2cap_core.c:4902 [inline]  l2cap_le_sig_cmd net/bluetooth/l2cap_core.c:5420 [inline]  l2cap_le_sig_channel net/bluetooth/l2cap_core.c:5486 [inline]  l2cap_recv_frame+0xe59d/0x11710 net/bluetooth/l2cap_core.c:6809  l2cap_recv_acldata+0x544/0x10a0 net/bluetooth/l2cap_core.c:7506  hci_acldata_packet net/bluetooth/hci_core.c:3939 [inline]  hci_rx_work+0x5e5/0xb20 net/bluetooth/hci_core.c:4176  process_one_work kernel/workqueue.c:3254 [inline]  process_scheduled_works+0x90f/0x1530 kernel/workqueue.c:3335  worker_thread+0x926/0xe70 kernel/workqueue.c:3416  kthread+0x2e3/0x380 kernel/kthread.c:388  ret_from_fork+0x5c/0x90 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244  </TASK> Modules linked in: ---[ end trace 0000000000000000 ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.1,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36968","epss":0.00293,"percentile":0.21685,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36968","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-36968","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16847499999999999},"relatedVulnerabilities":[{"id":"CVE-2024-36968","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-36968","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4d3dbaa252257d20611c3647290e6171f1bbd6c8","https://git.kernel.org/stable/c/a5b862c6a221459d54e494e88965b48dcfa6cc44","https://git.kernel.org/stable/c/ad3f7986c5a0f82b8b66a0afe1cc1f5421e1d674","https://git.kernel.org/stable/c/d2b2f7d3936dc5990549bc36ab7ac7ac37f22c30","https://git.kernel.org/stable/c/dfece2b4e3759759b2bdfac2cd6d0ee9fbf055f3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init()\n\nl2cap_le_flowctl_init() can cause both div-by-zero and an integer\noverflow since hdev->le_mtu may not fall in the valid range.\n\nMove MTU from hci_dev to hci_conn to validate MTU and stop the connection\nprocess earlier if MTU is invalid.\nAlso, add a missing validation in read_buffer_size() and make it return\nan error value if the validation fails.\nNow hci_conn_add() returns ERR_PTR() as it can fail due to the both a\nkzalloc failure and invalid MTU value.\n\ndivide error: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 0 PID: 67 Comm: kworker/u5:0 Tainted: G        W          6.9.0-rc5+ #20\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nWorkqueue: hci0 hci_rx_work\nRIP: 0010:l2cap_le_flowctl_init+0x19e/0x3f0 net/bluetooth/l2cap_core.c:547\nCode: e8 17 17 0c 00 66 41 89 9f 84 00 00 00 bf 01 00 00 00 41 b8 02 00 00 00 4c\n89 fe 4c 89 e2 89 d9 e8 27 17 0c 00 44 89 f0 31 d2 <66> f7 f3 89 c3 ff c3 4d 8d\nb7 88 00 00 00 4c 89 f0 48 c1 e8 03 42\nRSP: 0018:ffff88810bc0f858 EFLAGS: 00010246\nRAX: 00000000000002a0 RBX: 0000000000000000 RCX: dffffc0000000000\nRDX: 0000000000000000 RSI: ffff88810bc0f7c0 RDI: ffffc90002dcb66f\nRBP: ffff88810bc0f880 R08: aa69db2dda70ff01 R09: 0000ffaaaaaaaaaa\nR10: 0084000000ffaaaa R11: 0000000000000000 R12: ffff88810d65a084\nR13: dffffc0000000000 R14: 00000000000002a0 R15: ffff88810d65a000\nFS:  0000000000000000(0000) GS:ffff88811ac00000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000020000100 CR3: 0000000103268003 CR4: 0000000000770ef0\nPKRU: 55555554\nCall Trace:\n <TASK>\n l2cap_le_connect_req net/bluetooth/l2cap_core.c:4902 [inline]\n l2cap_le_sig_cmd net/bluetooth/l2cap_core.c:5420 [inline]\n l2cap_le_sig_channel net/bluetooth/l2cap_core.c:5486 [inline]\n l2cap_recv_frame+0xe59d/0x11710 net/bluetooth/l2cap_core.c:6809\n l2cap_recv_acldata+0x544/0x10a0 net/bluetooth/l2cap_core.c:7506\n hci_acldata_packet net/bluetooth/hci_core.c:3939 [inline]\n hci_rx_work+0x5e5/0xb20 net/bluetooth/hci_core.c:4176\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0x90f/0x1530 kernel/workqueue.c:3335\n worker_thread+0x926/0xe70 kernel/workqueue.c:3416\n kthread+0x2e3/0x380 kernel/kthread.c:388\n ret_from_fork+0x5c/0x90 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n </TASK>\nModules linked in:\n---[ end trace 0000000000000000 ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6.5,"exploitabilityScore":2.1,"impactScore":4},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7.6,"exploitabilityScore":2.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-36968","epss":0.00293,"percentile":0.21685,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-36968","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-36968","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-36968","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38557","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38557","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5: Reload only IB representors upon lag disable/enable  On lag disable, the bond IB device along with all of its representors are destroyed, and then the slaves' representors get reloaded.  In case the slave IB representor load fails, the eswitch error flow unloads all representors, including ethernet representors, where the netdevs get detached and removed from lag bond. Such flow is inaccurate as the lag driver is not responsible for loading/unloading ethernet representors. Furthermore, the flow described above begins by holding lag lock to prevent bond changes during disable flow. However, when reaching the ethernet representors detachment from lag, the lag lock is required again, triggering the following deadlock:  Call trace: __switch_to+0xf4/0x148 __schedule+0x2c8/0x7d0 schedule+0x50/0xe0 schedule_preempt_disabled+0x18/0x28 __mutex_lock.isra.13+0x2b8/0x570 __mutex_lock_slowpath+0x1c/0x28 mutex_lock+0x4c/0x68 mlx5_lag_remove_netdev+0x3c/0x1a0 [mlx5_core] mlx5e_uplink_rep_disable+0x70/0xa0 [mlx5_core] mlx5e_detach_netdev+0x6c/0xb0 [mlx5_core] mlx5e_netdev_change_profile+0x44/0x138 [mlx5_core] mlx5e_netdev_attach_nic_profile+0x28/0x38 [mlx5_core] mlx5e_vport_rep_unload+0x184/0x1b8 [mlx5_core] mlx5_esw_offloads_rep_load+0xd8/0xe0 [mlx5_core] mlx5_eswitch_reload_reps+0x74/0xd0 [mlx5_core] mlx5_disable_lag+0x130/0x138 [mlx5_core] mlx5_lag_disable_change+0x6c/0x70 [mlx5_core] // hold ldev->lock mlx5_devlink_eswitch_mode_set+0xc0/0x410 [mlx5_core] devlink_nl_cmd_eswitch_set_doit+0xdc/0x180 genl_family_rcv_msg_doit.isra.17+0xe8/0x138 genl_rcv_msg+0xe4/0x220 netlink_rcv_skb+0x44/0x108 genl_rcv+0x40/0x58 netlink_unicast+0x198/0x268 netlink_sendmsg+0x1d4/0x418 sock_sendmsg+0x54/0x60 __sys_sendto+0xf4/0x120 __arm64_sys_sendto+0x30/0x40 el0_svc_common+0x8c/0x120 do_el0_svc+0x30/0xa0 el0_svc+0x20/0x30 el0_sync_handler+0x90/0xb8 el0_sync+0x160/0x180  Thus, upon lag enable/disable, load and unload only the IB representors of the slaves preventing the deadlock mentioned above.  While at it, refactor the mlx5_esw_offloads_rep_load() function to have a static helper method for its internal logic, in symmetry with the representor unload design.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38557","epss":0.00183,"percentile":0.07955,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38557","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09607500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-38557","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38557","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0f06228d4a2dcc1fca5b3ddb0eefa09c05b102c4","https://git.kernel.org/stable/c/0f320f28f54b1b269a755be2e3fb3695e0b80b07","https://git.kernel.org/stable/c/e93fc8d959e56092e2eca1e5511c2d2f0ad6807a","https://git.kernel.org/stable/c/f03c714a0fdd1f93101a929d0e727c28a66383fc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Reload only IB representors upon lag disable/enable\n\nOn lag disable, the bond IB device along with all of its\nrepresentors are destroyed, and then the slaves' representors get reloaded.\n\nIn case the slave IB representor load fails, the eswitch error flow\nunloads all representors, including ethernet representors, where the\nnetdevs get detached and removed from lag bond. Such flow is inaccurate\nas the lag driver is not responsible for loading/unloading ethernet\nrepresentors. Furthermore, the flow described above begins by holding\nlag lock to prevent bond changes during disable flow. However, when\nreaching the ethernet representors detachment from lag, the lag lock is\nrequired again, triggering the following deadlock:\n\nCall trace:\n__switch_to+0xf4/0x148\n__schedule+0x2c8/0x7d0\nschedule+0x50/0xe0\nschedule_preempt_disabled+0x18/0x28\n__mutex_lock.isra.13+0x2b8/0x570\n__mutex_lock_slowpath+0x1c/0x28\nmutex_lock+0x4c/0x68\nmlx5_lag_remove_netdev+0x3c/0x1a0 [mlx5_core]\nmlx5e_uplink_rep_disable+0x70/0xa0 [mlx5_core]\nmlx5e_detach_netdev+0x6c/0xb0 [mlx5_core]\nmlx5e_netdev_change_profile+0x44/0x138 [mlx5_core]\nmlx5e_netdev_attach_nic_profile+0x28/0x38 [mlx5_core]\nmlx5e_vport_rep_unload+0x184/0x1b8 [mlx5_core]\nmlx5_esw_offloads_rep_load+0xd8/0xe0 [mlx5_core]\nmlx5_eswitch_reload_reps+0x74/0xd0 [mlx5_core]\nmlx5_disable_lag+0x130/0x138 [mlx5_core]\nmlx5_lag_disable_change+0x6c/0x70 [mlx5_core] // hold ldev->lock\nmlx5_devlink_eswitch_mode_set+0xc0/0x410 [mlx5_core]\ndevlink_nl_cmd_eswitch_set_doit+0xdc/0x180\ngenl_family_rcv_msg_doit.isra.17+0xe8/0x138\ngenl_rcv_msg+0xe4/0x220\nnetlink_rcv_skb+0x44/0x108\ngenl_rcv+0x40/0x58\nnetlink_unicast+0x198/0x268\nnetlink_sendmsg+0x1d4/0x418\nsock_sendmsg+0x54/0x60\n__sys_sendto+0xf4/0x120\n__arm64_sys_sendto+0x30/0x40\nel0_svc_common+0x8c/0x120\ndo_el0_svc+0x30/0xa0\nel0_svc+0x20/0x30\nel0_sync_handler+0x90/0xb8\nel0_sync+0x160/0x180\n\nThus, upon lag enable/disable, load and unload only the IB representors\nof the slaves preventing the deadlock mentioned above.\n\nWhile at it, refactor the mlx5_esw_offloads_rep_load() function to have\na static helper method for its internal logic, in symmetry with the\nrepresentor unload design.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38557","epss":0.00183,"percentile":0.07955,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38557","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38557","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38564","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38564","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE  bpf_prog_attach uses attach_type_to_prog_type to enforce proper attach type for BPF_PROG_TYPE_CGROUP_SKB. link_create uses bpf_prog_get and relies on bpf_prog_attach_check_attach_type to properly verify prog_type <> attach_type association.  Add missing attach_type enforcement for the link_create case. Otherwise, it's currently possible to attach cgroup_skb prog types to other cgroup hooks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38564","epss":0.00239,"percentile":0.14879,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12547500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-38564","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38564","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/543576ec15b17c0c93301ac8297333c7b6e84ac7","https://git.kernel.org/stable/c/6675c541f540a29487a802d3135280b69b9f568d","https://git.kernel.org/stable/c/67929e973f5a347f05fef064fea4ae79e7cdb5fd","https://git.kernel.org/stable/c/b34bbc76651065a5eafad8ddff1eb8d1f8473172"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE\n\nbpf_prog_attach uses attach_type_to_prog_type to enforce proper\nattach type for BPF_PROG_TYPE_CGROUP_SKB. link_create uses\nbpf_prog_get and relies on bpf_prog_attach_check_attach_type\nto properly verify prog_type <> attach_type association.\n\nAdd missing attach_type enforcement for the link_create case.\nOtherwise, it's currently possible to attach cgroup_skb prog\ntypes to other cgroup hooks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38564","epss":0.00239,"percentile":0.14879,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38564","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38570","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38570","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gfs2: Fix potential glock use-after-free on unmount  When a DLM lockspace is released and there ares still locks in that lockspace, DLM will unlock those locks automatically.  Commit fb6791d100d1b started exploiting this behavior to speed up filesystem unmount: gfs2 would simply free glocks it didn't want to unlock and then release the lockspace.  This didn't take the bast callbacks for asynchronous lock contention notifications into account, which remain active until until a lock is unlocked or its lockspace is released.  To prevent those callbacks from accessing deallocated objects, put the glocks that should not be unlocked on the sd_dead_glocks list, release the lockspace, and only then free those glocks.  As an additional measure, ignore unexpected ast and bast callbacks if the receiving glock is dead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38570","epss":0.00676,"percentile":0.50133,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38570","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.51714},"relatedVulnerabilities":[{"id":"CVE-2024-38570","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38570","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0636b34b44589b142700ac137b5f69802cfe2e37","https://git.kernel.org/stable/c/501cd8fabf621d10bd4893e37f6ce6c20523c8ca","https://git.kernel.org/stable/c/d98779e687726d8f8860f1c54b5687eec5f63a73","https://git.kernel.org/stable/c/e42e8a24d7f02d28763d16ca7ec5fc6d1f142af0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Fix potential glock use-after-free on unmount\n\nWhen a DLM lockspace is released and there ares still locks in that\nlockspace, DLM will unlock those locks automatically.  Commit\nfb6791d100d1b started exploiting this behavior to speed up filesystem\nunmount: gfs2 would simply free glocks it didn't want to unlock and then\nrelease the lockspace.  This didn't take the bast callbacks for\nasynchronous lock contention notifications into account, which remain\nactive until until a lock is unlocked or its lockspace is released.\n\nTo prevent those callbacks from accessing deallocated objects, put the\nglocks that should not be unlocked on the sd_dead_glocks list, release\nthe lockspace, and only then free those glocks.\n\nAs an additional measure, ignore unexpected ast and bast callbacks if\nthe receiving glock is dead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38570","epss":0.00676,"percentile":0.50133,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38570","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38570","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38594","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38594","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: stmmac: move the EST lock to struct stmmac_priv  Reinitialize the whole EST structure would also reset the mutex lock which is embedded in the EST structure, and then trigger the following warning. To address this, move the lock to struct stmmac_priv. We also need to reacquire the mutex lock when doing this initialization.  DEBUG_LOCKS_WARN_ON(lock->magic != lock) WARNING: CPU: 3 PID: 505 at kernel/locking/mutex.c:587 __mutex_lock+0xd84/0x1068  Modules linked in:  CPU: 3 PID: 505 Comm: tc Not tainted 6.9.0-rc6-00053-g0106679839f7-dirty #29  Hardware name: NXP i.MX8MPlus EVK board (DT)  pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)  pc : __mutex_lock+0xd84/0x1068  lr : __mutex_lock+0xd84/0x1068  sp : ffffffc0864e3570  x29: ffffffc0864e3570 x28: ffffffc0817bdc78 x27: 0000000000000003  x26: ffffff80c54f1808 x25: ffffff80c9164080 x24: ffffffc080d723ac  x23: 0000000000000000 x22: 0000000000000002 x21: 0000000000000000  x20: 0000000000000000 x19: ffffffc083bc3000 x18: ffffffffffffffff  x17: ffffffc08117b080 x16: 0000000000000002 x15: ffffff80d2d40000  x14: 00000000000002da x13: ffffff80d2d404b8 x12: ffffffc082b5a5c8  x11: ffffffc082bca680 x10: ffffffc082bb2640 x9 : ffffffc082bb2698  x8 : 0000000000017fe8 x7 : c0000000ffffefff x6 : 0000000000000001  x5 : ffffff8178fe0d48 x4 : 0000000000000000 x3 : 0000000000000027  x2 : ffffff8178fe0d50 x1 : 0000000000000000 x0 : 0000000000000000  Call trace:   __mutex_lock+0xd84/0x1068   mutex_lock_nested+0x28/0x34   tc_setup_taprio+0x118/0x68c   stmmac_setup_tc+0x50/0xf0   taprio_change+0x868/0xc9c","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38594","epss":0.0021,"percentile":0.1118,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11025},"relatedVulnerabilities":[{"id":"CVE-2024-38594","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38594","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/36ac9e7f2e5786bd37c5cd91132e1f39c29b8197","https://git.kernel.org/stable/c/487f9030b1ef34bab123f2df2a4ccbe01ba84416","https://git.kernel.org/stable/c/6f476aff2d8da1a189621c4c16a76a6c534e4312","https://git.kernel.org/stable/c/b538fefeb1026aad9dcdcbb410c42b56dff8aae9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: move the EST lock to struct stmmac_priv\n\nReinitialize the whole EST structure would also reset the mutex\nlock which is embedded in the EST structure, and then trigger\nthe following warning. To address this, move the lock to struct\nstmmac_priv. We also need to reacquire the mutex lock when doing\nthis initialization.\n\nDEBUG_LOCKS_WARN_ON(lock->magic != lock)\nWARNING: CPU: 3 PID: 505 at kernel/locking/mutex.c:587 __mutex_lock+0xd84/0x1068\n Modules linked in:\n CPU: 3 PID: 505 Comm: tc Not tainted 6.9.0-rc6-00053-g0106679839f7-dirty #29\n Hardware name: NXP i.MX8MPlus EVK board (DT)\n pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : __mutex_lock+0xd84/0x1068\n lr : __mutex_lock+0xd84/0x1068\n sp : ffffffc0864e3570\n x29: ffffffc0864e3570 x28: ffffffc0817bdc78 x27: 0000000000000003\n x26: ffffff80c54f1808 x25: ffffff80c9164080 x24: ffffffc080d723ac\n x23: 0000000000000000 x22: 0000000000000002 x21: 0000000000000000\n x20: 0000000000000000 x19: ffffffc083bc3000 x18: ffffffffffffffff\n x17: ffffffc08117b080 x16: 0000000000000002 x15: ffffff80d2d40000\n x14: 00000000000002da x13: ffffff80d2d404b8 x12: ffffffc082b5a5c8\n x11: ffffffc082bca680 x10: ffffffc082bb2640 x9 : ffffffc082bb2698\n x8 : 0000000000017fe8 x7 : c0000000ffffefff x6 : 0000000000000001\n x5 : ffffff8178fe0d48 x4 : 0000000000000000 x3 : 0000000000000027\n x2 : ffffff8178fe0d50 x1 : 0000000000000000 x0 : 0000000000000000\n Call trace:\n  __mutex_lock+0xd84/0x1068\n  mutex_lock_nested+0x28/0x34\n  tc_setup_taprio+0x118/0x68c\n  stmmac_setup_tc+0x50/0xf0\n  taprio_change+0x868/0xc9c","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38594","epss":0.0021,"percentile":0.1118,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38594","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38608","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38608","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Fix netif state handling  mlx5e_suspend cleans resources only if netif_device_present() returns true. However, mlx5e_resume changes the state of netif, via mlx5e_nic_enable, only if reg_state == NETREG_REGISTERED. In the below case, the above leads to NULL-ptr Oops[1] and memory leaks:  mlx5e_probe  _mlx5e_resume   mlx5e_attach_netdev    mlx5e_nic_enable  <-- netdev not reg, not calling netif_device_attach()   register_netdev <-- failed for some reason. ERROR_FLOW:  _mlx5e_suspend <-- netif_device_present return false, resources aren't freed :(  Hence, clean resources in this case as well.  [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 0 P4D 0 Oops: 0010 [#1] SMP CPU: 2 PID: 9345 Comm: test-ovs-ct-gen Not tainted 6.5.0_for_upstream_min_debug_2023_09_05_16_01 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:0x0 Code: Unable to access opcode bytes at0xffffffffffffffd6. RSP: 0018:ffff888178aaf758 EFLAGS: 00010246 Call Trace:  <TASK>  ? __die+0x20/0x60  ? page_fault_oops+0x14c/0x3c0  ? exc_page_fault+0x75/0x140  ? asm_exc_page_fault+0x22/0x30  notifier_call_chain+0x35/0xb0  blocking_notifier_call_chain+0x3d/0x60  mlx5_blocking_notifier_call_chain+0x22/0x30 [mlx5_core]  mlx5_core_uplink_netdev_event_replay+0x3e/0x60 [mlx5_core]  mlx5_mdev_netdev_track+0x53/0x60 [mlx5_ib]  mlx5_ib_roce_init+0xc3/0x340 [mlx5_ib]  __mlx5_ib_add+0x34/0xd0 [mlx5_ib]  mlx5r_probe+0xe1/0x210 [mlx5_ib]  ? auxiliary_match_id+0x6a/0x90  auxiliary_bus_probe+0x38/0x80  ? driver_sysfs_add+0x51/0x80  really_probe+0xc9/0x3e0  ? driver_probe_device+0x90/0x90  __driver_probe_device+0x80/0x160  driver_probe_device+0x1e/0x90  __device_attach_driver+0x7d/0x100  bus_for_each_drv+0x80/0xd0  __device_attach+0xbc/0x1f0  bus_probe_device+0x86/0xa0  device_add+0x637/0x840  __auxiliary_device_add+0x3b/0xa0  add_adev+0xc9/0x140 [mlx5_core]  mlx5_rescan_drivers_locked+0x22a/0x310 [mlx5_core]  mlx5_register_device+0x53/0xa0 [mlx5_core]  mlx5_init_one_devl_locked+0x5c4/0x9c0 [mlx5_core]  mlx5_init_one+0x3b/0x60 [mlx5_core]  probe_one+0x44c/0x730 [mlx5_core]  local_pci_probe+0x3e/0x90  pci_device_probe+0xbf/0x210  ? kernfs_create_link+0x5d/0xa0  ? sysfs_do_create_link_sd+0x60/0xc0  really_probe+0xc9/0x3e0  ? driver_probe_device+0x90/0x90  __driver_probe_device+0x80/0x160  driver_probe_device+0x1e/0x90  __device_attach_driver+0x7d/0x100  bus_for_each_drv+0x80/0xd0  __device_attach+0xbc/0x1f0  pci_bus_add_device+0x54/0x80  pci_iov_add_virtfn+0x2e6/0x320  sriov_enable+0x208/0x420  mlx5_core_sriov_configure+0x9e/0x200 [mlx5_core]  sriov_numvfs_store+0xae/0x1a0  kernfs_fop_write_iter+0x10c/0x1a0  vfs_write+0x291/0x3c0  ksys_write+0x5f/0xe0  do_syscall_64+0x3d/0x90  entry_SYSCALL_64_after_hwframe+0x46/0xb0  CR2: 0000000000000000  ---[ end trace 0000000000000000  ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38608","epss":0.00188,"percentile":0.0852,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38608","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09870000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-38608","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38608","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3d5918477f94e4c2f064567875c475468e264644","https://git.kernel.org/stable/c/f7e6cfb864a53af71c5cc904f1cc22215d68f5c6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix netif state handling\n\nmlx5e_suspend cleans resources only if netif_device_present() returns\ntrue. However, mlx5e_resume changes the state of netif, via\nmlx5e_nic_enable, only if reg_state == NETREG_REGISTERED.\nIn the below case, the above leads to NULL-ptr Oops[1] and memory\nleaks:\n\nmlx5e_probe\n _mlx5e_resume\n  mlx5e_attach_netdev\n   mlx5e_nic_enable  <-- netdev not reg, not calling netif_device_attach()\n  register_netdev <-- failed for some reason.\nERROR_FLOW:\n _mlx5e_suspend <-- netif_device_present return false, resources aren't freed :(\n\nHence, clean resources in this case as well.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0010 [#1] SMP\nCPU: 2 PID: 9345 Comm: test-ovs-ct-gen Not tainted 6.5.0_for_upstream_min_debug_2023_09_05_16_01 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:0x0\nCode: Unable to access opcode bytes at0xffffffffffffffd6.\nRSP: 0018:ffff888178aaf758 EFLAGS: 00010246\nCall Trace:\n <TASK>\n ? __die+0x20/0x60\n ? page_fault_oops+0x14c/0x3c0\n ? exc_page_fault+0x75/0x140\n ? asm_exc_page_fault+0x22/0x30\n notifier_call_chain+0x35/0xb0\n blocking_notifier_call_chain+0x3d/0x60\n mlx5_blocking_notifier_call_chain+0x22/0x30 [mlx5_core]\n mlx5_core_uplink_netdev_event_replay+0x3e/0x60 [mlx5_core]\n mlx5_mdev_netdev_track+0x53/0x60 [mlx5_ib]\n mlx5_ib_roce_init+0xc3/0x340 [mlx5_ib]\n __mlx5_ib_add+0x34/0xd0 [mlx5_ib]\n mlx5r_probe+0xe1/0x210 [mlx5_ib]\n ? auxiliary_match_id+0x6a/0x90\n auxiliary_bus_probe+0x38/0x80\n ? driver_sysfs_add+0x51/0x80\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n bus_probe_device+0x86/0xa0\n device_add+0x637/0x840\n __auxiliary_device_add+0x3b/0xa0\n add_adev+0xc9/0x140 [mlx5_core]\n mlx5_rescan_drivers_locked+0x22a/0x310 [mlx5_core]\n mlx5_register_device+0x53/0xa0 [mlx5_core]\n mlx5_init_one_devl_locked+0x5c4/0x9c0 [mlx5_core]\n mlx5_init_one+0x3b/0x60 [mlx5_core]\n probe_one+0x44c/0x730 [mlx5_core]\n local_pci_probe+0x3e/0x90\n pci_device_probe+0xbf/0x210\n ? kernfs_create_link+0x5d/0xa0\n ? sysfs_do_create_link_sd+0x60/0xc0\n really_probe+0xc9/0x3e0\n ? driver_probe_device+0x90/0x90\n __driver_probe_device+0x80/0x160\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x7d/0x100\n bus_for_each_drv+0x80/0xd0\n __device_attach+0xbc/0x1f0\n pci_bus_add_device+0x54/0x80\n pci_iov_add_virtfn+0x2e6/0x320\n sriov_enable+0x208/0x420\n mlx5_core_sriov_configure+0x9e/0x200 [mlx5_core]\n sriov_numvfs_store+0xae/0x1a0\n kernfs_fop_write_iter+0x10c/0x1a0\n vfs_write+0x291/0x3c0\n ksys_write+0x5f/0xe0\n do_syscall_64+0x3d/0x90\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n CR2: 0000000000000000\n ---[ end trace 0000000000000000  ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38608","epss":0.00188,"percentile":0.0852,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38608","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38608","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38620","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38620","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: HCI: Remove HCI_AMP support  Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP controllers.  Since we no longer need to differentiate between AMP and Primary controllers, as only HCI_PRIMARY is left, this also remove hdev->dev_type altogether.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38620","epss":0.00306,"percentile":0.23102,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.16065},"relatedVulnerabilities":[{"id":"CVE-2024-38620","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38620","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5af2e235b0d5b797e9531a00c50058319130e156","https://git.kernel.org/stable/c/84a4bb6548a29326564f0e659fb8064503ecc1c7","https://git.kernel.org/stable/c/9e6cf0eccfe15b67bf9773ecd101162dfdfed5e2","https://git.kernel.org/stable/c/af1d425b6dc67cd67809f835dd7afb6be4d43e03","https://git.kernel.org/stable/c/d3c7b012d912b31ad23b9349c0e499d6dddd48ec"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HCI: Remove HCI_AMP support\n\nSince BT_HS has been remove HCI_AMP controllers no longer has any use so\nremove it along with the capability of creating AMP controllers.\n\nSince we no longer need to differentiate between AMP and Primary\ncontrollers, as only HCI_PRIMARY is left, this also remove\nhdev->dev_type altogether.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38620","epss":0.00306,"percentile":0.23102,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38620","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38622","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38622","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm/dpu: Add callback function pointer check before its call  In dpu_core_irq_callback_handler() callback function pointer is compared to NULL, but then callback function is unconditionally called by this pointer. Fix this bug by adding conditional return.  Found by Linux Verification Center (linuxtesting.org) with SVACE.  Patchwork: https://patchwork.freedesktop.org/patch/588237/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38622","epss":0.00222,"percentile":0.12796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38622","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11655000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-38622","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38622","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/530f272053a5e72243a9cb07bb1296af6c346002","https://git.kernel.org/stable/c/873f67699114452c2a996c4e10faac8ff860c241","https://git.kernel.org/stable/c/9078630ed7f8f25d65d11823e7f2b11a8e2f4f0f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: Add callback function pointer check before its call\n\nIn dpu_core_irq_callback_handler() callback function pointer is compared to NULL,\nbut then callback function is unconditionally called by this pointer.\nFix this bug by adding conditional return.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\nPatchwork: https://patchwork.freedesktop.org/patch/588237/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38622","epss":0.00222,"percentile":0.12796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38622","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38622","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38625","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38625","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: Check 'folio' pointer for NULL  It can be NULL if bmap is called.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38625","epss":0.00221,"percentile":0.12632,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38625","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.116025},"relatedVulnerabilities":[{"id":"CVE-2024-38625","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38625","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1cd6c96219c429ebcfa8e79a865277376c563803","https://git.kernel.org/stable/c/6c8054d590668629bb2eb6fb4cbf22455d08ada8","https://git.kernel.org/stable/c/ff1068929459347f9e47f8d14c409dcf938c2641"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Check 'folio' pointer for NULL\n\nIt can be NULL if bmap is called.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38625","epss":0.00221,"percentile":0.12632,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38625","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38625","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-38630","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-38630","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  watchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger  When the cpu5wdt module is removing, the origin code uses del_timer() to de-activate the timer. If the timer handler is running, del_timer() could not stop it and will return directly. If the port region is released by release_region() and then the timer handler cpu5wdt_trigger() calls outb() to write into the region that is released, the use-after-free bug will happen.  Change del_timer() to timer_shutdown_sync() in order that the timer handler could be finished before the port region is released.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38630","epss":0.00251,"percentile":0.16481,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38630","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.192015},"relatedVulnerabilities":[{"id":"CVE-2024-38630","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-38630","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/573601521277119f2e2ba5f28ae6e87fc594f4d4","https://git.kernel.org/stable/c/9b1c063ffc075abf56f63e55d70b9778ff534314","https://git.kernel.org/stable/c/f19686d616500cd0d47b30cee82392b53f7f784a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger\n\nWhen the cpu5wdt module is removing, the origin code uses del_timer() to\nde-activate the timer. If the timer handler is running, del_timer() could\nnot stop it and will return directly. If the port region is released by\nrelease_region() and then the timer handler cpu5wdt_trigger() calls outb()\nto write into the region that is released, the use-after-free bug will\nhappen.\n\nChange del_timer() to timer_shutdown_sync() in order that the timer handler\ncould be finished before the port region is released.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-38630","epss":0.00251,"percentile":0.16481,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-38630","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-38630","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-39508","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-39508","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  io_uring/io-wq: Use set_bit() and test_bit() at worker->flags  Utilize set_bit() and test_bit() on worker->flags within io_uring/io-wq to address potential data races.  The structure io_worker->flags may be accessed through various data paths, leading to concurrency issues. When KCSAN is enabled, it reveals data races occurring in io_worker_handle_work and io_wq_activate_free_worker functions.  \t BUG: KCSAN: data-race in io_worker_handle_work / io_wq_activate_free_worker \t write to 0xffff8885c4246404 of 4 bytes by task 49071 on cpu 28: \t io_worker_handle_work (io_uring/io-wq.c:434 io_uring/io-wq.c:569) \t io_wq_worker (io_uring/io-wq.c:?) <snip>  \t read to 0xffff8885c4246404 of 4 bytes by task 49024 on cpu 5: \t io_wq_activate_free_worker (io_uring/io-wq.c:? io_uring/io-wq.c:285) \t io_wq_enqueue (io_uring/io-wq.c:947) \t io_queue_iowq (io_uring/io_uring.c:524) \t io_req_task_submit (io_uring/io_uring.c:1511) \t io_handle_tw_list (io_uring/io_uring.c:1198) <snip>  Line numbers against commit 18daea77cca6 (\"Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm\").  These races involve writes and reads to the same memory location by different tasks running on different CPUs. To mitigate this, refactor the code to use atomic operations such as set_bit(), test_bit(), and clear_bit() instead of basic \"and\" and \"or\" operations. This ensures thread-safe manipulation of worker flags.  Also, move `create_index` to avoid holes in the structure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-39508","epss":0.00224,"percentile":0.12998,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-39508","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10864},"relatedVulnerabilities":[{"id":"CVE-2024-39508","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-39508","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1cbb0affb15470a9621267fe0a8568007553a4bf","https://git.kernel.org/stable/c/8a565304927fbd28c9f028c492b5c1714002cbab","https://git.kernel.org/stable/c/ab702c3483db9046bab9f40306f1a28b22dbbdc0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/io-wq: Use set_bit() and test_bit() at worker->flags\n\nUtilize set_bit() and test_bit() on worker->flags within io_uring/io-wq\nto address potential data races.\n\nThe structure io_worker->flags may be accessed through various data\npaths, leading to concurrency issues. When KCSAN is enabled, it reveals\ndata races occurring in io_worker_handle_work and\nio_wq_activate_free_worker functions.\n\n\t BUG: KCSAN: data-race in io_worker_handle_work / io_wq_activate_free_worker\n\t write to 0xffff8885c4246404 of 4 bytes by task 49071 on cpu 28:\n\t io_worker_handle_work (io_uring/io-wq.c:434 io_uring/io-wq.c:569)\n\t io_wq_worker (io_uring/io-wq.c:?)\n<snip>\n\n\t read to 0xffff8885c4246404 of 4 bytes by task 49024 on cpu 5:\n\t io_wq_activate_free_worker (io_uring/io-wq.c:? io_uring/io-wq.c:285)\n\t io_wq_enqueue (io_uring/io-wq.c:947)\n\t io_queue_iowq (io_uring/io_uring.c:524)\n\t io_req_task_submit (io_uring/io_uring.c:1511)\n\t io_handle_tw_list (io_uring/io_uring.c:1198)\n<snip>\n\nLine numbers against commit 18daea77cca6 (\"Merge tag 'for-linus' of\ngit://git.kernel.org/pub/scm/virt/kvm/kvm\").\n\nThese races involve writes and reads to the same memory location by\ndifferent tasks running on different CPUs. To mitigate this, refactor\nthe code to use atomic operations such as set_bit(), test_bit(), and\nclear_bit() instead of basic \"and\" and \"or\" operations. This ensures\nthread-safe manipulation of worker flags.\n\nAlso, move `create_index` to avoid holes in the structure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-39508","epss":0.00224,"percentile":0.12998,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-39508","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-39508","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-40918","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-40918","namespace":"debian:distro:debian:12","severity":"Negligible","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  parisc: Try to fix random segmentation faults in package builds  PA-RISC systems with PA8800 and PA8900 processors have had problems with random segmentation faults for many years.  Systems with earlier processors are much more stable.  Systems with PA8800 and PA8900 processors have a large L2 cache which needs per page flushing for decent performance when a large range is flushed. The combined cache in these systems is also more sensitive to non-equivalent aliases than the caches in earlier systems.  The majority of random segmentation faults that I have looked at appear to be memory corruption in memory allocated using mmap and malloc.  My first attempt at fixing the random faults didn't work. On reviewing the cache code, I realized that there were two issues which the existing code didn't handle correctly. Both relate to cache move-in. Another issue is that the present bit in PTEs is racy.  1) PA-RISC caches have a mind of their own and they can speculatively load data and instructions for a page as long as there is a entry in the TLB for the page which allows move-in. TLBs are local to each CPU. Thus, the TLB entry for a page must be purged before flushing the page. This is particularly important on SMP systems.  In some of the flush routines, the flush routine would be called and then the TLB entry would be purged. This was because the flush routine needed the TLB entry to do the flush.  2) My initial approach to trying the fix the random faults was to try and use flush_cache_page_if_present for all flush operations. This actually made things worse and led to a couple of hardware lockups. It finally dawned on me that some lines weren't being flushed because the pte check code was racy. This resulted in random inequivalent mappings to physical pages.  The __flush_cache_page tmpalias flush sets up its own TLB entry and it doesn't need the existing TLB entry. As long as we can find the pte pointer for the vm page, we can get the pfn and physical address of the page. We can also purge the TLB entry for the page before doing the flush. Further, __flush_cache_page uses a special TLB entry that inhibits cache move-in.  When switching page mappings, we need to ensure that lines are removed from the cache.  It is not sufficient to just flush the lines to memory as they may come back.  This made it clear that we needed to implement all the required flush operations using tmpalias routines. This includes flushes for user and kernel pages.  After modifying the code to use tmpalias flushes, it became clear that the random segmentation faults were not fully resolved. The frequency of faults was worse on systems with a 64 MB L2 (PA8900) and systems with more CPUs (rp4440).  The warning that I added to flush_cache_page_if_present to detect pages that couldn't be flushed triggered frequently on some systems.  Helge and I looked at the pages that couldn't be flushed and found that the PTE was either cleared or for a swap page. Ignoring pages that were swapped out seemed okay but pages with cleared PTEs seemed problematic.  I looked at routines related to pte_clear and noticed ptep_clear_flush. The default implementation just flushes the TLB entry. However, it was obvious that on parisc we need to flush the cache page as well. If we don't flush the cache page, stale lines will be left in the cache and cause random corruption. Once a PTE is cleared, there is no way to find the physical address associated with the PTE and flush the associated page at a later time.  I implemented an updated change with a parisc specific version of ptep_clear_flush. It fixed the random data corruption on Helge's rp4440 and rp3440, as well as on my c8000.  At this point, I realized that I could restore the code where we only flush in flush_cache_page_if_present if the page has been accessed. However, for this, we also need to flush the cache when the accessed bit is cleared in ---truncated---","cvss":[],"epss":[{"cve":"CVE-2024-40918","epss":0.00295,"percentile":0.21898,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.014750000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-40918","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-40918","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5bf196f1936bf93df31112fbdfb78c03537c07b0","https://git.kernel.org/stable/c/72d95924ee35c8cd16ef52f912483ee938a34d49","https://git.kernel.org/stable/c/d66f2607d89f760cdffed88b22f309c895a2af20"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Try to fix random segmentation faults in package builds\n\nPA-RISC systems with PA8800 and PA8900 processors have had problems\nwith random segmentation faults for many years.  Systems with earlier\nprocessors are much more stable.\n\nSystems with PA8800 and PA8900 processors have a large L2 cache which\nneeds per page flushing for decent performance when a large range is\nflushed. The combined cache in these systems is also more sensitive to\nnon-equivalent aliases than the caches in earlier systems.\n\nThe majority of random segmentation faults that I have looked at\nappear to be memory corruption in memory allocated using mmap and\nmalloc.\n\nMy first attempt at fixing the random faults didn't work. On\nreviewing the cache code, I realized that there were two issues\nwhich the existing code didn't handle correctly. Both relate\nto cache move-in. Another issue is that the present bit in PTEs\nis racy.\n\n1) PA-RISC caches have a mind of their own and they can speculatively\nload data and instructions for a page as long as there is a entry in\nthe TLB for the page which allows move-in. TLBs are local to each\nCPU. Thus, the TLB entry for a page must be purged before flushing\nthe page. This is particularly important on SMP systems.\n\nIn some of the flush routines, the flush routine would be called\nand then the TLB entry would be purged. This was because the flush\nroutine needed the TLB entry to do the flush.\n\n2) My initial approach to trying the fix the random faults was to\ntry and use flush_cache_page_if_present for all flush operations.\nThis actually made things worse and led to a couple of hardware\nlockups. It finally dawned on me that some lines weren't being\nflushed because the pte check code was racy. This resulted in\nrandom inequivalent mappings to physical pages.\n\nThe __flush_cache_page tmpalias flush sets up its own TLB entry\nand it doesn't need the existing TLB entry. As long as we can find\nthe pte pointer for the vm page, we can get the pfn and physical\naddress of the page. We can also purge the TLB entry for the page\nbefore doing the flush. Further, __flush_cache_page uses a special\nTLB entry that inhibits cache move-in.\n\nWhen switching page mappings, we need to ensure that lines are\nremoved from the cache.  It is not sufficient to just flush the\nlines to memory as they may come back.\n\nThis made it clear that we needed to implement all the required\nflush operations using tmpalias routines. This includes flushes\nfor user and kernel pages.\n\nAfter modifying the code to use tmpalias flushes, it became clear\nthat the random segmentation faults were not fully resolved. The\nfrequency of faults was worse on systems with a 64 MB L2 (PA8900)\nand systems with more CPUs (rp4440).\n\nThe warning that I added to flush_cache_page_if_present to detect\npages that couldn't be flushed triggered frequently on some systems.\n\nHelge and I looked at the pages that couldn't be flushed and found\nthat the PTE was either cleared or for a swap page. Ignoring pages\nthat were swapped out seemed okay but pages with cleared PTEs seemed\nproblematic.\n\nI looked at routines related to pte_clear and noticed ptep_clear_flush.\nThe default implementation just flushes the TLB entry. However, it was\nobvious that on parisc we need to flush the cache page as well. If\nwe don't flush the cache page, stale lines will be left in the cache\nand cause random corruption. Once a PTE is cleared, there is no way\nto find the physical address associated with the PTE and flush the\nassociated page at a later time.\n\nI implemented an updated change with a parisc specific version of\nptep_clear_flush. It fixed the random data corruption on Helge's rp4440\nand rp3440, as well as on my c8000.\n\nAt this point, I realized that I could restore the code where we only\nflush in flush_cache_page_if_present if the page has been accessed.\nHowever, for this, we also need to flush the cache when the accessed\nbit is cleared in\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.3,"exploitabilityScore":1.1,"impactScore":5.2},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40918","epss":0.00295,"percentile":0.21898,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-40918","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-40965","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-40965","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i2c: lpi2c: Avoid calling clk_get_rate during transfer  Instead of repeatedly calling clk_get_rate for each transfer, lock the clock rate and cache the value. A deadlock has been observed while adding tlv320aic32x4 audio codec to the system. When this clock provider adds its clock, the clk mutex is locked already, it needs to access i2c, which in return needs the mutex for clk_get_rate as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40965","epss":0.00223,"percentile":0.1283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-40965","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11707500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-40965","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-40965","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2b42e9587a7a9c7b824e0feb92958f258263963e","https://git.kernel.org/stable/c/4268254a39484fc11ba991ae148bacbe75d9cc0a","https://git.kernel.org/stable/c/d038693e08adf9c162c6377800495e4f5a2df045"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: lpi2c: Avoid calling clk_get_rate during transfer\n\nInstead of repeatedly calling clk_get_rate for each transfer, lock\nthe clock rate and cache the value.\nA deadlock has been observed while adding tlv320aic32x4 audio codec to\nthe system. When this clock provider adds its clock, the clk mutex is\nlocked already, it needs to access i2c, which in return needs the mutex\nfor clk_get_rate as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40965","epss":0.00223,"percentile":0.1283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-40965","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-40965","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-40969","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-40969","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: don't set RO when shutting down f2fs  Shutdown does not check the error of thaw_super due to readonly, which causes a deadlock like below.  f2fs_ioc_shutdown(F2FS_GOING_DOWN_FULLSYNC)        issue_discard_thread  - bdev_freeze   - freeze_super  - f2fs_stop_checkpoint()   - f2fs_handle_critical_error                     - sb_start_write     - set RO                                         - waiting  - bdev_thaw   - thaw_super_locked     - return -EINVAL, if sb_rdonly()  - f2fs_stop_discard_thread   -> wait for kthread_stop(discard_thread);","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40969","epss":0.0022,"percentile":0.12495,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-40969","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11550000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-40969","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-40969","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1036d3ea7a32cb7cee00885c73a1f2ba7fbc499a","https://git.kernel.org/stable/c/3bdb7f161697e2d5123b89fe1778ef17a44858e7","https://git.kernel.org/stable/c/f47ed3b284b38f235355e281f57dfa8fffcc6563"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: don't set RO when shutting down f2fs\n\nShutdown does not check the error of thaw_super due to readonly, which\ncauses a deadlock like below.\n\nf2fs_ioc_shutdown(F2FS_GOING_DOWN_FULLSYNC)        issue_discard_thread\n - bdev_freeze\n  - freeze_super\n - f2fs_stop_checkpoint()\n  - f2fs_handle_critical_error                     - sb_start_write\n    - set RO                                         - waiting\n - bdev_thaw\n  - thaw_super_locked\n    - return -EINVAL, if sb_rdonly()\n - f2fs_stop_discard_thread\n  -> wait for kthread_stop(discard_thread);","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40969","epss":0.0022,"percentile":0.12495,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-40969","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-40969","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-40975","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-40975","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  platform/x86: x86-android-tablets: Unregister devices in reverse order  Not all subsystems support a device getting removed while there are still consumers of the device with a reference to the device.  One example of this is the regulator subsystem. If a regulator gets unregistered while there are still drivers holding a reference a WARN() at drivers/regulator/core.c:5829 triggers, e.g.:   WARNING: CPU: 1 PID: 1587 at drivers/regulator/core.c:5829 regulator_unregister  Hardware name: Intel Corp. VALLEYVIEW C0 PLATFORM/BYT-T FFD8, BIOS BLADE_21.X64.0005.R00.1504101516 FFD8_X64_R_2015_04_10_1516 04/10/2015  RIP: 0010:regulator_unregister  Call Trace:   <TASK>   regulator_unregister   devres_release_group   i2c_device_remove   device_release_driver_internal   bus_remove_device   device_del   device_unregister   x86_android_tablet_remove  On the Lenovo Yoga Tablet 2 series the bq24190 charger chip also provides a 5V boost converter output for powering USB devices connected to the micro USB port, the bq24190-charger driver exports this as a Vbus regulator.  On the 830 (8\") and 1050 (\"10\") models this regulator is controlled by a platform_device and x86_android_tablet_remove() removes platform_device-s before i2c_clients so the consumer gets removed first.  But on the 1380 (13\") model there is a lc824206xa micro-USB switch connected over I2C and the extcon driver for that controls the regulator. The bq24190 i2c-client *must* be registered first, because that creates the regulator with the lc824206xa listed as its consumer. If the regulator has not been registered yet the lc824206xa driver will end up getting a dummy regulator.  Since in this case both the regulator provider and consumer are I2C devices, the only way to ensure that the consumer is unregistered first is to unregister the I2C devices in reverse order of in which they were created.  For consistency and to avoid similar problems in the future change x86_android_tablet_remove() to unregister all device types in reverse order.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40975","epss":0.00288,"percentile":0.21187,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1512},"relatedVulnerabilities":[{"id":"CVE-2024-40975","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-40975","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/36ff963c133a25ed1166a25c3ba8b357ea010fda","https://git.kernel.org/stable/c/3de0f2627ef849735f155c1818247f58404dddfe","https://git.kernel.org/stable/c/f0c982853d665597d17e4995ff479fbbf79a9cf6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: x86-android-tablets: Unregister devices in reverse order\n\nNot all subsystems support a device getting removed while there are\nstill consumers of the device with a reference to the device.\n\nOne example of this is the regulator subsystem. If a regulator gets\nunregistered while there are still drivers holding a reference\na WARN() at drivers/regulator/core.c:5829 triggers, e.g.:\n\n WARNING: CPU: 1 PID: 1587 at drivers/regulator/core.c:5829 regulator_unregister\n Hardware name: Intel Corp. VALLEYVIEW C0 PLATFORM/BYT-T FFD8, BIOS BLADE_21.X64.0005.R00.1504101516 FFD8_X64_R_2015_04_10_1516 04/10/2015\n RIP: 0010:regulator_unregister\n Call Trace:\n  <TASK>\n  regulator_unregister\n  devres_release_group\n  i2c_device_remove\n  device_release_driver_internal\n  bus_remove_device\n  device_del\n  device_unregister\n  x86_android_tablet_remove\n\nOn the Lenovo Yoga Tablet 2 series the bq24190 charger chip also provides\na 5V boost converter output for powering USB devices connected to the micro\nUSB port, the bq24190-charger driver exports this as a Vbus regulator.\n\nOn the 830 (8\") and 1050 (\"10\") models this regulator is controlled by\na platform_device and x86_android_tablet_remove() removes platform_device-s\nbefore i2c_clients so the consumer gets removed first.\n\nBut on the 1380 (13\") model there is a lc824206xa micro-USB switch\nconnected over I2C and the extcon driver for that controls the regulator.\nThe bq24190 i2c-client *must* be registered first, because that creates\nthe regulator with the lc824206xa listed as its consumer. If the regulator\nhas not been registered yet the lc824206xa driver will end up getting\na dummy regulator.\n\nSince in this case both the regulator provider and consumer are I2C\ndevices, the only way to ensure that the consumer is unregistered first\nis to unregister the I2C devices in reverse order of in which they were\ncreated.\n\nFor consistency and to avoid similar problems in the future change\nx86_android_tablet_remove() to unregister all device types in reverse\norder.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40975","epss":0.00288,"percentile":0.21187,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-40975","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-40998","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-40998","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super()  In the following concurrency we will access the uninitialized rs->lock:  ext4_fill_super   ext4_register_sysfs    // sysfs registered msg_ratelimit_interval_ms                              // Other processes modify rs->interval to                              // non-zero via msg_ratelimit_interval_ms   ext4_orphan_cleanup     ext4_msg(sb, KERN_INFO, \"Errors on filesystem, \"       __ext4_msg         ___ratelimit(&(EXT4_SB(sb)->s_msg_ratelimit_state)           if (!rs->interval)  // do nothing if interval is 0             return 1;           raw_spin_trylock_irqsave(&rs->lock, flags)             raw_spin_trylock(lock)               _raw_spin_trylock                 __raw_spin_trylock                   spin_acquire(&lock->dep_map, 0, 1, _RET_IP_)                     lock_acquire                       __lock_acquire                         register_lock_class                           assign_lock_key                             dump_stack();   ratelimit_state_init(&sbi->s_msg_ratelimit_state, 5 * HZ, 10);     raw_spin_lock_init(&rs->lock);     // init rs->lock here  and get the following dump_stack:  ========================================================= INFO: trying to register non-static key. The code is fine but needs lockdep annotation, or maybe you didn't initialize this object before use? turning off the locking correctness validator. CPU: 12 PID: 753 Comm: mount Tainted: G E 6.7.0-rc6-next-20231222 #504 [...] Call Trace:  dump_stack_lvl+0xc5/0x170  dump_stack+0x18/0x30  register_lock_class+0x740/0x7c0  __lock_acquire+0x69/0x13a0  lock_acquire+0x120/0x450  _raw_spin_trylock+0x98/0xd0  ___ratelimit+0xf6/0x220  __ext4_msg+0x7f/0x160 [ext4]  ext4_orphan_cleanup+0x665/0x740 [ext4]  __ext4_fill_super+0x21ea/0x2b10 [ext4]  ext4_fill_super+0x14d/0x360 [ext4] [...] =========================================================  Normally interval is 0 until s_msg_ratelimit_state is initialized, so ___ratelimit() does nothing. But registering sysfs precedes initializing rs->lock, so it is possible to change rs->interval to a non-zero value via the msg_ratelimit_interval_ms interface of sysfs while rs->lock is uninitialized, and then a call to ext4_msg triggers the problem by accessing an uninitialized rs->lock. Therefore register sysfs after all initializations are complete to avoid such problems.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40998","epss":0.00271,"percentile":0.19359,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-40998","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.142275},"relatedVulnerabilities":[{"id":"CVE-2024-40998","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-40998","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/23afcd52af06880c6c913a0ad99022b8937b575c","https://git.kernel.org/stable/c/645267906944a9aeec9d5c56ee24a9096a288798","https://git.kernel.org/stable/c/b4b4fda34e535756f9e774fb2d09c4537b7dfd1c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super()\n\nIn the following concurrency we will access the uninitialized rs->lock:\n\next4_fill_super\n  ext4_register_sysfs\n   // sysfs registered msg_ratelimit_interval_ms\n                             // Other processes modify rs->interval to\n                             // non-zero via msg_ratelimit_interval_ms\n  ext4_orphan_cleanup\n    ext4_msg(sb, KERN_INFO, \"Errors on filesystem, \"\n      __ext4_msg\n        ___ratelimit(&(EXT4_SB(sb)->s_msg_ratelimit_state)\n          if (!rs->interval)  // do nothing if interval is 0\n            return 1;\n          raw_spin_trylock_irqsave(&rs->lock, flags)\n            raw_spin_trylock(lock)\n              _raw_spin_trylock\n                __raw_spin_trylock\n                  spin_acquire(&lock->dep_map, 0, 1, _RET_IP_)\n                    lock_acquire\n                      __lock_acquire\n                        register_lock_class\n                          assign_lock_key\n                            dump_stack();\n  ratelimit_state_init(&sbi->s_msg_ratelimit_state, 5 * HZ, 10);\n    raw_spin_lock_init(&rs->lock);\n    // init rs->lock here\n\nand get the following dump_stack:\n\n=========================================================\nINFO: trying to register non-static key.\nThe code is fine but needs lockdep annotation, or maybe\nyou didn't initialize this object before use?\nturning off the locking correctness validator.\nCPU: 12 PID: 753 Comm: mount Tainted: G E 6.7.0-rc6-next-20231222 #504\n[...]\nCall Trace:\n dump_stack_lvl+0xc5/0x170\n dump_stack+0x18/0x30\n register_lock_class+0x740/0x7c0\n __lock_acquire+0x69/0x13a0\n lock_acquire+0x120/0x450\n _raw_spin_trylock+0x98/0xd0\n ___ratelimit+0xf6/0x220\n __ext4_msg+0x7f/0x160 [ext4]\n ext4_orphan_cleanup+0x665/0x740 [ext4]\n __ext4_fill_super+0x21ea/0x2b10 [ext4]\n ext4_fill_super+0x14d/0x360 [ext4]\n[...]\n=========================================================\n\nNormally interval is 0 until s_msg_ratelimit_state is initialized, so\n___ratelimit() does nothing. But registering sysfs precedes initializing\nrs->lock, so it is possible to change rs->interval to a non-zero value\nvia the msg_ratelimit_interval_ms interface of sysfs while rs->lock is\nuninitialized, and then a call to ext4_msg triggers the problem by\naccessing an uninitialized rs->lock. Therefore register sysfs after all\ninitializations are complete to avoid such problems.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40998","epss":0.00271,"percentile":0.19359,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-40998","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-40998","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-40999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-40999","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ena: Add validation for completion descriptors consistency  Validate that `first` flag is set only for the first descriptor in multi-buffer packets. In case of an invalid descriptor, a reset will occur. A new reset reason for RX data corruption has been added.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40999","epss":0.00533,"percentile":0.43301,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.279825},"relatedVulnerabilities":[{"id":"CVE-2024-40999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-40999","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/42146ee5286f16f1674a84f7c274dcca65c6ff2e","https://git.kernel.org/stable/c/b37b98a3a0c1198bafe8c2d9ce0bc845b4e7a9a7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ena: Add validation for completion descriptors consistency\n\nValidate that `first` flag is set only for the first\ndescriptor in multi-buffer packets.\nIn case of an invalid descriptor, a reset will occur.\nA new reset reason for RX data corruption has been added.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-40999","epss":0.00533,"percentile":0.43301,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-40999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-41008","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-41008","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: change vm->task_info handling  This patch changes the handling and lifecycle of vm->task_info object. The major changes are: - vm->task_info is a dynamically allocated ptr now, and its uasge is   reference counted. - introducing two new helper funcs for task_info lifecycle management     - amdgpu_vm_get_task_info: reference counts up task_info before       returning this info     - amdgpu_vm_put_task_info: reference counts down task_info - last put to task_info() frees task_info from the vm.  This patch also does logistical changes required for existing usage of vm->task_info.  V2: Do not block all the prints when task_info not found (Felix)  V3: Fixed review comments from Felix    - Fix wrong indentation    - No debug message for -ENOMEM    - Add NULL check for task_info    - Do not duplicate the debug messages (ti vs no ti)    - Get first reference of task_info in vm_init(), put last      in vm_fini()  V4: Fixed review comments from Felix    - fix double reference increment in create_task_info    - change amdgpu_vm_get_task_info_pasid    - additional changes in amdgpu_gem.c while porting","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41008","epss":0.00189,"percentile":0.08621,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09922500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-41008","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41008","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/b8f67b9ddf4f8fe6dd536590712b5912ad78f99c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: change vm->task_info handling\n\nThis patch changes the handling and lifecycle of vm->task_info object.\nThe major changes are:\n- vm->task_info is a dynamically allocated ptr now, and its uasge is\n  reference counted.\n- introducing two new helper funcs for task_info lifecycle management\n    - amdgpu_vm_get_task_info: reference counts up task_info before\n      returning this info\n    - amdgpu_vm_put_task_info: reference counts down task_info\n- last put to task_info() frees task_info from the vm.\n\nThis patch also does logistical changes required for existing usage\nof vm->task_info.\n\nV2: Do not block all the prints when task_info not found (Felix)\n\nV3: Fixed review comments from Felix\n   - Fix wrong indentation\n   - No debug message for -ENOMEM\n   - Add NULL check for task_info\n   - Do not duplicate the debug messages (ti vs no ti)\n   - Get first reference of task_info in vm_init(), put last\n     in vm_fini()\n\nV4: Fixed review comments from Felix\n   - fix double reference increment in create_task_info\n   - change amdgpu_vm_get_task_info_pasid\n   - additional changes in amdgpu_gem.c while porting","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41008","epss":0.00189,"percentile":0.08621,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-41008","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-41023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-41023","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sched/deadline: Fix task_struct reference leak  During the execution of the following stress test with linux-rt:  stress-ng --cyclic 30 --timeout 30 --minimize --quiet  kmemleak frequently reported a memory leak concerning the task_struct:  unreferenced object 0xffff8881305b8000 (size 16136):   comm \"stress-ng\", pid 614, jiffies 4294883961 (age 286.412s)   object hex dump (first 32 bytes):     02 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00  .@..............     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................   debug hex dump (first 16 bytes):     53 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00  S...............   backtrace:     [<00000000046b6790>] dup_task_struct+0x30/0x540     [<00000000c5ca0f0b>] copy_process+0x3d9/0x50e0     [<00000000ced59777>] kernel_clone+0xb0/0x770     [<00000000a50befdc>] __do_sys_clone+0xb6/0xf0     [<000000001dbf2008>] do_syscall_64+0x5d/0xf0     [<00000000552900ff>] entry_SYSCALL_64_after_hwframe+0x6e/0x76  The issue occurs in start_dl_timer(), which increments the task_struct reference count and sets a timer. The timer callback, dl_task_timer, is supposed to decrement the reference count upon expiration. However, if enqueue_task_dl() is called before the timer expires and cancels it, the reference count is not decremented, leading to the leak.  This patch fixes the reference leak by ensuring the task_struct reference count is properly decremented when the timer is canceled.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41023","epss":0.00293,"percentile":0.21657,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-41023","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.153825},"relatedVulnerabilities":[{"id":"CVE-2024-41023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41023","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7a54d31face626f62de415ebe77b43f76c3ffaf4","https://git.kernel.org/stable/c/b58652db66c910c2245f5bee7deca41c12d707b9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/deadline: Fix task_struct reference leak\n\nDuring the execution of the following stress test with linux-rt:\n\nstress-ng --cyclic 30 --timeout 30 --minimize --quiet\n\nkmemleak frequently reported a memory leak concerning the task_struct:\n\nunreferenced object 0xffff8881305b8000 (size 16136):\n  comm \"stress-ng\", pid 614, jiffies 4294883961 (age 286.412s)\n  object hex dump (first 32 bytes):\n    02 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00  .@..............\n    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n  debug hex dump (first 16 bytes):\n    53 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00  S...............\n  backtrace:\n    [<00000000046b6790>] dup_task_struct+0x30/0x540\n    [<00000000c5ca0f0b>] copy_process+0x3d9/0x50e0\n    [<00000000ced59777>] kernel_clone+0xb0/0x770\n    [<00000000a50befdc>] __do_sys_clone+0xb6/0xf0\n    [<000000001dbf2008>] do_syscall_64+0x5d/0xf0\n    [<00000000552900ff>] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nThe issue occurs in start_dl_timer(), which increments the task_struct\nreference count and sets a timer. The timer callback, dl_task_timer,\nis supposed to decrement the reference count upon expiration. However,\nif enqueue_task_dl() is called before the timer expires and cancels it,\nthe reference count is not decremented, leading to the leak.\n\nThis patch fixes the reference leak by ensuring the task_struct\nreference count is properly decremented when the timer is canceled.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41023","epss":0.00293,"percentile":0.21657,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-41023","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-41023","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-41031","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-41031","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/filemap: skip to create PMD-sized page cache if needed  On ARM64, HPAGE_PMD_ORDER is 13 when the base page size is 64KB.  The PMD-sized page cache can't be supported by xarray as the following error messages indicate.  ------------[ cut here ]------------ WARNING: CPU: 35 PID: 7484 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128 Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib  \\ nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct    \\ nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4    \\ ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm      \\ fuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64      \\ sha1_ce virtio_net net_failover virtio_console virtio_blk failover \\ dimlib virtio_mmio CPU: 35 PID: 7484 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9 Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024 pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : xas_split_alloc+0xf8/0x128 lr : split_huge_page_to_list_to_order+0x1c4/0x720 sp : ffff800087a4f6c0 x29: ffff800087a4f6c0 x28: ffff800087a4f720 x27: 000000001fffffff x26: 0000000000000c40 x25: 000000000000000d x24: ffff00010625b858 x23: ffff800087a4f720 x22: ffffffdfc0780000 x21: 0000000000000000 x20: 0000000000000000 x19: ffffffdfc0780000 x18: 000000001ff40000 x17: 00000000ffffffff x16: 0000018000000000 x15: 51ec004000000000 x14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020 x11: 51ec000000000000 x10: 51ece1c0ffff8000 x9 : ffffbeb961a44d28 x8 : 0000000000000003 x7 : ffffffdfc0456420 x6 : ffff0000e1aa6eb8 x5 : 20bf08b4fe778fca x4 : ffffffdfc0456420 x3 : 0000000000000c40 x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000 Call trace:  xas_split_alloc+0xf8/0x128  split_huge_page_to_list_to_order+0x1c4/0x720  truncate_inode_partial_folio+0xdc/0x160  truncate_inode_pages_range+0x1b4/0x4a8  truncate_pagecache_range+0x84/0xa0  xfs_flush_unmap_range+0x70/0x90 [xfs]  xfs_file_fallocate+0xfc/0x4d8 [xfs]  vfs_fallocate+0x124/0x2e8  ksys_fallocate+0x4c/0xa0  __arm64_sys_fallocate+0x24/0x38  invoke_syscall.constprop.0+0x7c/0xd8  do_el0_svc+0xb4/0xd0  el0_svc+0x44/0x1d8  el0t_64_sync_handler+0x134/0x150  el0t_64_sync+0x17c/0x180  Fix it by skipping to allocate PMD-sized page cache when its size is larger than MAX_PAGECACHE_ORDER.  For this specific case, we will fall to regular path where the readahead window is determined by BDI's sysfs file (read_ahead_kb).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41031","epss":0.00288,"percentile":0.21188,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1512},"relatedVulnerabilities":[{"id":"CVE-2024-41031","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41031","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/06b5a69c27ec405a3c3f2da8520ff1ee70b94a21","https://git.kernel.org/stable/c/1ef650d3b1b2a16473981b447f38705fe9b93972","https://git.kernel.org/stable/c/3390916aca7af1893ed2ebcdfee1d6fdb65bb058"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/filemap: skip to create PMD-sized page cache if needed\n\nOn ARM64, HPAGE_PMD_ORDER is 13 when the base page size is 64KB.  The\nPMD-sized page cache can't be supported by xarray as the following error\nmessages indicate.\n\n------------[ cut here ]------------\nWARNING: CPU: 35 PID: 7484 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\nModules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib  \\\nnft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct    \\\nnft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4    \\\nip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm      \\\nfuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64      \\\nsha1_ce virtio_net net_failover virtio_console virtio_blk failover \\\ndimlib virtio_mmio\nCPU: 35 PID: 7484 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9\nHardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\npstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\npc : xas_split_alloc+0xf8/0x128\nlr : split_huge_page_to_list_to_order+0x1c4/0x720\nsp : ffff800087a4f6c0\nx29: ffff800087a4f6c0 x28: ffff800087a4f720 x27: 000000001fffffff\nx26: 0000000000000c40 x25: 000000000000000d x24: ffff00010625b858\nx23: ffff800087a4f720 x22: ffffffdfc0780000 x21: 0000000000000000\nx20: 0000000000000000 x19: ffffffdfc0780000 x18: 000000001ff40000\nx17: 00000000ffffffff x16: 0000018000000000 x15: 51ec004000000000\nx14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020\nx11: 51ec000000000000 x10: 51ece1c0ffff8000 x9 : ffffbeb961a44d28\nx8 : 0000000000000003 x7 : ffffffdfc0456420 x6 : ffff0000e1aa6eb8\nx5 : 20bf08b4fe778fca x4 : ffffffdfc0456420 x3 : 0000000000000c40\nx2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\nCall trace:\n xas_split_alloc+0xf8/0x128\n split_huge_page_to_list_to_order+0x1c4/0x720\n truncate_inode_partial_folio+0xdc/0x160\n truncate_inode_pages_range+0x1b4/0x4a8\n truncate_pagecache_range+0x84/0xa0\n xfs_flush_unmap_range+0x70/0x90 [xfs]\n xfs_file_fallocate+0xfc/0x4d8 [xfs]\n vfs_fallocate+0x124/0x2e8\n ksys_fallocate+0x4c/0xa0\n __arm64_sys_fallocate+0x24/0x38\n invoke_syscall.constprop.0+0x7c/0xd8\n do_el0_svc+0xb4/0xd0\n el0_svc+0x44/0x1d8\n el0t_64_sync_handler+0x134/0x150\n el0t_64_sync+0x17c/0x180\n\nFix it by skipping to allocate PMD-sized page cache when its size is\nlarger than MAX_PAGECACHE_ORDER.  For this specific case, we will fall to\nregular path where the readahead window is determined by BDI's sysfs file\n(read_ahead_kb).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41031","epss":0.00288,"percentile":0.21188,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-41031","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-41045","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-41045","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Defer work in bpf_timer_cancel_and_free  Currently, the same case as previous patch (two timer callbacks trying to cancel each other) can be invoked through bpf_map_update_elem as well, or more precisely, freeing map elements containing timers. Since this relies on hrtimer_cancel as well, it is prone to the same deadlock situation as the previous patch.  It would be sufficient to use hrtimer_try_to_cancel to fix this problem, as the timer cannot be enqueued after async_cancel_and_free. Once async_cancel_and_free has been done, the timer must be reinitialized before it can be armed again. The callback running in parallel trying to arm the timer will fail, and freeing bpf_hrtimer without waiting is sufficient (given kfree_rcu), and bpf_timer_cb will return HRTIMER_NORESTART, preventing the timer from being rearmed again.  However, there exists a UAF scenario where the callback arms the timer before entering this function, such that if cancellation fails (due to timer callback invoking this routine, or the target timer callback running concurrently). In such a case, if the timer expiration is significantly far in the future, the RCU grace period expiration happening before it will free the bpf_hrtimer state and along with it the struct hrtimer, that is enqueued.  Hence, it is clear cancellation needs to occur after async_cancel_and_free, and yet it cannot be done inline due to deadlock issues. We thus modify bpf_timer_cancel_and_free to defer work to the global workqueue, adding a work_struct alongside rcu_head (both used at _different_ points of time, so can share space).  Update existing code comments to reflect the new state of affairs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41045","epss":0.00269,"percentile":0.18896,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-41045","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.205785},"relatedVulnerabilities":[{"id":"CVE-2024-41045","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41045","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7aa5a19279c3639ae8b758b63f05d0c616a39fa1","https://git.kernel.org/stable/c/a6fcd19d7eac1335eb76bc16b6a66b7f574d1d69"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Defer work in bpf_timer_cancel_and_free\n\nCurrently, the same case as previous patch (two timer callbacks trying\nto cancel each other) can be invoked through bpf_map_update_elem as\nwell, or more precisely, freeing map elements containing timers. Since\nthis relies on hrtimer_cancel as well, it is prone to the same deadlock\nsituation as the previous patch.\n\nIt would be sufficient to use hrtimer_try_to_cancel to fix this problem,\nas the timer cannot be enqueued after async_cancel_and_free. Once\nasync_cancel_and_free has been done, the timer must be reinitialized\nbefore it can be armed again. The callback running in parallel trying to\narm the timer will fail, and freeing bpf_hrtimer without waiting is\nsufficient (given kfree_rcu), and bpf_timer_cb will return\nHRTIMER_NORESTART, preventing the timer from being rearmed again.\n\nHowever, there exists a UAF scenario where the callback arms the timer\nbefore entering this function, such that if cancellation fails (due to\ntimer callback invoking this routine, or the target timer callback\nrunning concurrently). In such a case, if the timer expiration is\nsignificantly far in the future, the RCU grace period expiration\nhappening before it will free the bpf_hrtimer state and along with it\nthe struct hrtimer, that is enqueued.\n\nHence, it is clear cancellation needs to occur after\nasync_cancel_and_free, and yet it cannot be done inline due to deadlock\nissues. We thus modify bpf_timer_cancel_and_free to defer work to the\nglobal workqueue, adding a work_struct alongside rcu_head (both used at\n_different_ points of time, so can share space).\n\nUpdate existing code comments to reflect the new state of affairs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41045","epss":0.00269,"percentile":0.18896,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-41045","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-41045","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-41082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-41082","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvme-fabrics: use reserved tag for reg read/write command  In some scenarios, if too many commands are issued by nvme command in the same time by user tasks, this may exhaust all tags of admin_q. If a reset (nvme reset or IO timeout) occurs before these commands finish, reconnect routine may fail to update nvme regs due to insufficient tags, which will cause kernel hang forever. In order to workaround this issue, maybe we can let reg_read32()/reg_read64()/reg_write32() use reserved tags. This maybe safe for nvmf:  1. For the disable ctrl path,  we will not issue connect command 2. For the enable ctrl / fw activate path, since connect and reg_xx()    are called serially.  So the reserved tags may still be enough while reg_xx() use reserved tags.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41082","epss":0.00226,"percentile":0.13235,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11865},"relatedVulnerabilities":[{"id":"CVE-2024-41082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41082","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/165da9c67a26f08c9b956c15d701da7690f45bcb","https://git.kernel.org/stable/c/7dc3bfcb4c9cc58970fff6aaa48172cb224d85aa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-fabrics: use reserved tag for reg read/write command\n\nIn some scenarios, if too many commands are issued by nvme command in\nthe same time by user tasks, this may exhaust all tags of admin_q. If\na reset (nvme reset or IO timeout) occurs before these commands finish,\nreconnect routine may fail to update nvme regs due to insufficient tags,\nwhich will cause kernel hang forever. In order to workaround this issue,\nmaybe we can let reg_read32()/reg_read64()/reg_write32() use reserved\ntags. This maybe safe for nvmf:\n\n1. For the disable ctrl path,  we will not issue connect command\n2. For the enable ctrl / fw activate path, since connect and reg_xx()\n   are called serially.\n\nSo the reserved tags may still be enough while reg_xx() use reserved tags.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41082","epss":0.00226,"percentile":0.13235,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-41082","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-41935","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-41935","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to shrink read extent node in batches  We use rwlock to protect core structure data of extent tree during its shrink, however, if there is a huge number of extent nodes in extent tree, during shrink of extent tree, it may hold rwlock for a very long time, which may trigger kernel hang issue.  This patch fixes to shrink read extent node in batches, so that, critical region of the rwlock can be shrunk to avoid its extreme long time hold.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41935","epss":0.00226,"percentile":0.13236,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-41935","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16498},"relatedVulnerabilities":[{"id":"CVE-2024-41935","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41935","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/295b50e95e900da31ff237e46e04525fa799b2cf","https://git.kernel.org/stable/c/3fc5d5a182f6a1f8bd4dc775feb54c369dd2c343","https://git.kernel.org/stable/c/924f7dd1e832e4e4530d14711db223d2803f7b61"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to shrink read extent node in batches\n\nWe use rwlock to protect core structure data of extent tree during\nits shrink, however, if there is a huge number of extent nodes in\nextent tree, during shrink of extent tree, it may hold rwlock for\na very long time, which may trigger kernel hang issue.\n\nThis patch fixes to shrink read extent node in batches, so that,\ncritical region of the rwlock can be shrunk to avoid its extreme\nlong time hold.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-41935","epss":0.00226,"percentile":0.13236,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-41935","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-41935","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42107","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42107","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ice: Don't process extts if PTP is disabled  The ice_ptp_extts_event() function can race with ice_ptp_release() and result in a NULL pointer dereference which leads to a kernel panic.  Panic occurs because the ice_ptp_extts_event() function calls ptp_clock_event() with a NULL pointer. The ice driver has already released the PTP clock by the time the interrupt for the next external timestamp event occurs.  To fix this, modify the ice_ptp_extts_event() function to check the PTP state and bail early if PTP is not ready.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42107","epss":0.00154,"percentile":0.04807,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42107","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-42107","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07469},"relatedVulnerabilities":[{"id":"CVE-2024-42107","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42107","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1c4e524811918600683b1ea87a5e0fc2db64fa9b","https://git.kernel.org/stable/c/996422e3230e41468f652d754fefd1bdbcd4604e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nice: Don't process extts if PTP is disabled\n\nThe ice_ptp_extts_event() function can race with ice_ptp_release() and\nresult in a NULL pointer dereference which leads to a kernel panic.\n\nPanic occurs because the ice_ptp_extts_event() function calls\nptp_clock_event() with a NULL pointer. The ice driver has already\nreleased the PTP clock by the time the interrupt for the next external\ntimestamp event occurs.\n\nTo fix this, modify the ice_ptp_extts_event() function to check the\nPTP state and bail early if PTP is not ready.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42107","epss":0.00154,"percentile":0.04807,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42107","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-42107","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42107","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42118","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42118","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Do not return negative stream id for array  [WHY] resource_stream_to_stream_idx returns an array index and it return -1 when not found; however, -1 is not a valid array index number.  [HOW] When this happens, call ASSERT(), and return a zero instead.  This fixes an OVERRUN and an NEGATIVE_RETURNS issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42118","epss":0.00235,"percentile":0.14377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42118","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17977500000000002},"relatedVulnerabilities":[{"id":"CVE-2024-42118","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42118","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3ac31c9a707dd1c7c890b95333182f955e9dcb57","https://git.kernel.org/stable/c/a76fa9c4f0fc0aa6f517da3fa7d7c23e8a32c7d0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Do not return negative stream id for array\n\n[WHY]\nresource_stream_to_stream_idx returns an array index and it return -1\nwhen not found; however, -1 is not a valid array index number.\n\n[HOW]\nWhen this happens, call ASSERT(), and return a zero instead.\n\nThis fixes an OVERRUN and an NEGATIVE_RETURNS issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42118","epss":0.00235,"percentile":0.14377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42118","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42118","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42123","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42123","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: fix double free err_addr pointer warnings  In amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages will be run many times so that double free err_addr in some special case. So set the err_addr to NULL to avoid the warnings.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42123","epss":0.00207,"percentile":0.10902,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42123","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09729},"relatedVulnerabilities":[{"id":"CVE-2024-42123","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42123","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/506c245f3f1cd989cb89811a7f06e04ff8813a0d","https://git.kernel.org/stable/c/8e24beb3c2b08a4763f920399a9cc577ed440a1a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix double free err_addr pointer warnings\n\nIn amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages\nwill be run many times so that double free err_addr in some special case.\nSo set the err_addr to NULL to avoid the warnings.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"exploitabilityScore":0.8,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42123","epss":0.00207,"percentile":0.10902,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42123","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42123","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42128","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42128","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  leds: an30259a: Use devm_mutex_init() for mutex initialization  In this driver LEDs are registered using devm_led_classdev_register() so they are automatically unregistered after module's remove() is done. led_classdev_unregister() calls module's led_set_brightness() to turn off the LEDs and that callback uses mutex which was destroyed already in module's remove() so use devm API instead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42128","epss":0.00225,"percentile":0.13088,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42128","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11812500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-42128","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42128","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3ead19aa341de89a8c3d88a091d8093ebea622e8","https://git.kernel.org/stable/c/9dba44460bfca657ca43f03ea9bafa4f9f7dd077","https://git.kernel.org/stable/c/c382e2e3eccb6b7ca8c7aff5092c1668428e7de6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nleds: an30259a: Use devm_mutex_init() for mutex initialization\n\nIn this driver LEDs are registered using devm_led_classdev_register()\nso they are automatically unregistered after module's remove() is done.\nled_classdev_unregister() calls module's led_set_brightness() to turn off\nthe LEDs and that callback uses mutex which was destroyed already\nin module's remove() so use devm API instead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42128","epss":0.00225,"percentile":0.13088,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42128","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42128","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42139","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42139","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ice: Fix improper extts handling  Extts events are disabled and enabled by the application ts2phc. However, in case where the driver is removed when the application is running, a specific extts event remains enabled and can cause a kernel crash. As a side effect, when the driver is reloaded and application is started again, remaining extts event for the channel from a previous run will keep firing and the message \"extts on unexpected channel\" might be printed to the user.  To avoid that, extts events shall be disabled when PTP is released.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42139","epss":0.002,"percentile":0.0987,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42139","cwe":"CWE-754","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10500000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-42139","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42139","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/00d3b4f54582d4e4a02cda5886bb336eeab268cc","https://git.kernel.org/stable/c/9f69b31ae9e25dec27ad31fbc64dd99af16ee3d3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix improper extts handling\n\nExtts events are disabled and enabled by the application ts2phc.\nHowever, in case where the driver is removed when the application is\nrunning, a specific extts event remains enabled and can cause a kernel\ncrash.\nAs a side effect, when the driver is reloaded and application is started\nagain, remaining extts event for the channel from a previous run will\nkeep firing and the message \"extts on unexpected channel\" might be\nprinted to the user.\n\nTo avoid that, extts events shall be disabled when PTP is released.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42139","epss":0.002,"percentile":0.0987,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42139","cwe":"CWE-754","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42139","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42155","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42155","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/pkey: Wipe copies of protected- and secure-keys  Although the clear-key of neither protected- nor secure-keys is accessible, this key material should only be visible to the calling process. So wipe all copies of protected- or secure-keys from stack, even in case of an error.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":0.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42155","epss":0.00188,"percentile":0.08503,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42155","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04606},"relatedVulnerabilities":[{"id":"CVE-2024-42155","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42155","namespace":"nvd:cpe","severity":"Low","urls":["https://git.kernel.org/stable/c/c746f7ced4ad88ee48d0b6c92710e4674403185b","https://git.kernel.org/stable/c/f2ebdadd85af4f4d0cae1e5d009c70eccc78c207"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Wipe copies of protected- and secure-keys\n\nAlthough the clear-key of neither protected- nor secure-keys is\naccessible, this key material should only be visible to the calling\nprocess. So wipe all copies of protected- or secure-keys from stack,\neven in case of an error.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":1.9,"exploitabilityScore":0.5,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42155","epss":0.00188,"percentile":0.08503,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42155","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42155","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42156","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42156","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/pkey: Wipe copies of clear-key structures on failure  Wipe all sensitive data from stack for all IOCTLs, which convert a clear-key into a protected- or secure-key.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42156","epss":0.00212,"percentile":0.11507,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42156","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09645999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-42156","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42156","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7f6243edd901b75aaece326c90a1cc0dcb60cc3d","https://git.kernel.org/stable/c/a891938947f4427f98cb1ce54f27223501efe750","https://git.kernel.org/stable/c/d65d76a44ffe74c73298ada25b0f578680576073"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Wipe copies of clear-key structures on failure\n\nWipe all sensitive data from stack for all IOCTLs, which convert a\nclear-key into a protected- or secure-key.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42156","epss":0.00212,"percentile":0.11507,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42156","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42156","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42158","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42158","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings  Replace memzero_explicit() and kfree() with kfree_sensitive() to fix warnings reported by Coccinelle:  WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1506) WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1643) WARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1770)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42158","epss":0.00187,"percentile":0.08443,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42158","cwe":"CWE-669","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.085085},"relatedVulnerabilities":[{"id":"CVE-2024-42158","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42158","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/22e6824622e8a8889df0f8fc4ed5aea0e702a694","https://git.kernel.org/stable/c/62151a0acde90823bdfa991d598c85cf4b1d387d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Use kfree_sensitive() to fix Coccinelle warnings\n\nReplace memzero_explicit() and kfree() with kfree_sensitive() to fix\nwarnings reported by Coccinelle:\n\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1506)\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1643)\nWARNING opportunity for kfree_sensitive/kvfree_sensitive (line 1770)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.1,"exploitabilityScore":0.5,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42158","epss":0.00187,"percentile":0.08443,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42158","cwe":"CWE-669","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42158","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42162","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42162","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gve: Account for stopped queues when reading NIC stats  We now account for the fact that the NIC might send us stats for a subset of queues. Without this change, gve_get_ethtool_stats might make an invalid access on the priv->stats_report->stats array.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42162","epss":0.00208,"percentile":0.10986,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42162","cwe":"CWE-754","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1508},"relatedVulnerabilities":[{"id":"CVE-2024-42162","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42162","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/32675d828c8a392e20d5b42375ed112c407e4b62","https://git.kernel.org/stable/c/af9bcf910b1f86244f39e15e701b2dc564b469a6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngve: Account for stopped queues when reading NIC stats\n\nWe now account for the fact that the NIC might send us stats for a\nsubset of queues. Without this change, gve_get_ethtool_stats might make\nan invalid access on the priv->stats_report->stats array.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42162","epss":0.00208,"percentile":0.10986,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42162","cwe":"CWE-754","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42162","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42239","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42239","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fail bpf_timer_cancel when callback is being cancelled  Given a schedule:  timer1 cb\t\t\ttimer2 cb  bpf_timer_cancel(timer2);\tbpf_timer_cancel(timer1);  Both bpf_timer_cancel calls would wait for the other callback to finish executing, introducing a lockup.  Add an atomic_t count named 'cancelling' in bpf_hrtimer. This keeps track of all in-flight cancellation requests for a given BPF timer. Whenever cancelling a BPF timer, we must check if we have outstanding cancellation requests, and if so, we must fail the operation with an error (-EDEADLK) since cancellation is synchronous and waits for the callback to finish executing. This implies that we can enter a deadlock situation involving two or more timer callbacks executing in parallel and attempting to cancel one another.  Note that we avoid incrementing the cancelling counter for the target timer (the one being cancelled) if bpf_timer_cancel is not invoked from a callback, to avoid spurious errors. The whole point of detecting cur->cancelling and returning -EDEADLK is to not enter a busy wait loop (which may or may not lead to a lockup). This does not apply in case the caller is in a non-callback context, the other side can continue to cancel as it sees fit without running into errors.  Background on prior attempts:  Earlier versions of this patch used a bool 'cancelling' bit and used the following pattern under timer->lock to publish cancellation status.  lock(t->lock); t->cancelling = true; mb(); if (cur->cancelling) \treturn -EDEADLK; unlock(t->lock); hrtimer_cancel(t->timer); t->cancelling = false;  The store outside the critical section could overwrite a parallel requests t->cancelling assignment to true, to ensure the parallely executing callback observes its cancellation status.  It would be necessary to clear this cancelling bit once hrtimer_cancel is done, but lack of serialization introduced races. Another option was explored where bpf_timer_start would clear the bit when (re)starting the timer under timer->lock. This would ensure serialized access to the cancelling bit, but may allow it to be cleared before in-flight hrtimer_cancel has finished executing, such that lockups can occur again.  Thus, we choose an atomic counter to keep track of all outstanding cancellation requests and use it to prevent lockups in case callbacks attempt to cancel each other while executing in parallel.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42239","epss":0.00166,"percentile":0.06109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42239","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08715},"relatedVulnerabilities":[{"id":"CVE-2024-42239","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42239","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3e4e8178a8666c56813bd167b848fca0f4c9af0a","https://git.kernel.org/stable/c/9369830518688ecd5b08ffc08ab3302ce2b5d0f7","https://git.kernel.org/stable/c/d4523831f07a267a943f0dde844bf8ead7495f13"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fail bpf_timer_cancel when callback is being cancelled\n\nGiven a schedule:\n\ntimer1 cb\t\t\ttimer2 cb\n\nbpf_timer_cancel(timer2);\tbpf_timer_cancel(timer1);\n\nBoth bpf_timer_cancel calls would wait for the other callback to finish\nexecuting, introducing a lockup.\n\nAdd an atomic_t count named 'cancelling' in bpf_hrtimer. This keeps\ntrack of all in-flight cancellation requests for a given BPF timer.\nWhenever cancelling a BPF timer, we must check if we have outstanding\ncancellation requests, and if so, we must fail the operation with an\nerror (-EDEADLK) since cancellation is synchronous and waits for the\ncallback to finish executing. This implies that we can enter a deadlock\nsituation involving two or more timer callbacks executing in parallel\nand attempting to cancel one another.\n\nNote that we avoid incrementing the cancelling counter for the target\ntimer (the one being cancelled) if bpf_timer_cancel is not invoked from\na callback, to avoid spurious errors. The whole point of detecting\ncur->cancelling and returning -EDEADLK is to not enter a busy wait loop\n(which may or may not lead to a lockup). This does not apply in case the\ncaller is in a non-callback context, the other side can continue to\ncancel as it sees fit without running into errors.\n\nBackground on prior attempts:\n\nEarlier versions of this patch used a bool 'cancelling' bit and used the\nfollowing pattern under timer->lock to publish cancellation status.\n\nlock(t->lock);\nt->cancelling = true;\nmb();\nif (cur->cancelling)\n\treturn -EDEADLK;\nunlock(t->lock);\nhrtimer_cancel(t->timer);\nt->cancelling = false;\n\nThe store outside the critical section could overwrite a parallel\nrequests t->cancelling assignment to true, to ensure the parallely\nexecuting callback observes its cancellation status.\n\nIt would be necessary to clear this cancelling bit once hrtimer_cancel\nis done, but lack of serialization introduced races. Another option was\nexplored where bpf_timer_start would clear the bit when (re)starting the\ntimer under timer->lock. This would ensure serialized access to the\ncancelling bit, but may allow it to be cleared before in-flight\nhrtimer_cancel has finished executing, such that lockups can occur\nagain.\n\nThus, we choose an atomic counter to keep track of all outstanding\ncancellation requests and use it to prevent lockups in case callbacks\nattempt to cancel each other while executing in parallel.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42239","epss":0.00166,"percentile":0.06109,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42239","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42239","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42241","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42241","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/shmem: disable PMD-sized page cache if needed  For shmem files, it's possible that PMD-sized page cache can't be supported by xarray.  For example, 512MB page cache on ARM64 when the base page size is 64KB can't be supported by xarray.  It leads to errors as the following messages indicate when this sort of xarray entry is split.  WARNING: CPU: 34 PID: 7578 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128 Modules linked in: binfmt_misc nft_fib_inet nft_fib_ipv4 nft_fib_ipv6   \\ nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject        \\ nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4  \\ ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse xfs  \\ libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_net \\ net_failover virtio_console virtio_blk failover dimlib virtio_mmio CPU: 34 PID: 7578 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9 Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024 pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : xas_split_alloc+0xf8/0x128 lr : split_huge_page_to_list_to_order+0x1c4/0x720 sp : ffff8000882af5f0 x29: ffff8000882af5f0 x28: ffff8000882af650 x27: ffff8000882af768 x26: 0000000000000cc0 x25: 000000000000000d x24: ffff00010625b858 x23: ffff8000882af650 x22: ffffffdfc0900000 x21: 0000000000000000 x20: 0000000000000000 x19: ffffffdfc0900000 x18: 0000000000000000 x17: 0000000000000000 x16: 0000018000000000 x15: 52f8004000000000 x14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020 x11: 52f8000000000000 x10: 52f8e1c0ffff6000 x9 : ffffbeb9619a681c x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff00010b02ddb0 x5 : ffffbeb96395e378 x4 : 0000000000000000 x3 : 0000000000000cc0 x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000 Call trace:  xas_split_alloc+0xf8/0x128  split_huge_page_to_list_to_order+0x1c4/0x720  truncate_inode_partial_folio+0xdc/0x160  shmem_undo_range+0x2bc/0x6a8  shmem_fallocate+0x134/0x430  vfs_fallocate+0x124/0x2e8  ksys_fallocate+0x4c/0xa0  __arm64_sys_fallocate+0x24/0x38  invoke_syscall.constprop.0+0x7c/0xd8  do_el0_svc+0xb4/0xd0  el0_svc+0x44/0x1d8  el0t_64_sync_handler+0x134/0x150  el0t_64_sync+0x17c/0x180  Fix it by disabling PMD-sized page cache when HPAGE_PMD_ORDER is larger than MAX_PAGECACHE_ORDER.  As Matthew Wilcox pointed, the page cache in a shmem file isn't represented by a multi-index entry and doesn't have this limitation when the xarry entry is split until commit 6b24ca4a1a8d (\"mm: Use multi-index entries in the page cache\").","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42241","epss":0.00211,"percentile":0.11434,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42241","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2024-42241","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42241","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/93893eacb372b0a4a30f7de6609b08c3ba6c4fd9","https://git.kernel.org/stable/c/9fd154ba926b34c833b7bfc4c14ee2e931b3d743","https://git.kernel.org/stable/c/cd25208ca9b0097f8e079d692fc678f36fdbc3f9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/shmem: disable PMD-sized page cache if needed\n\nFor shmem files, it's possible that PMD-sized page cache can't be\nsupported by xarray.  For example, 512MB page cache on ARM64 when the base\npage size is 64KB can't be supported by xarray.  It leads to errors as the\nfollowing messages indicate when this sort of xarray entry is split.\n\nWARNING: CPU: 34 PID: 7578 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\nModules linked in: binfmt_misc nft_fib_inet nft_fib_ipv4 nft_fib_ipv6   \\\nnft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject        \\\nnft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4  \\\nip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse xfs  \\\nlibcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_net \\\nnet_failover virtio_console virtio_blk failover dimlib virtio_mmio\nCPU: 34 PID: 7578 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9\nHardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\npstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\npc : xas_split_alloc+0xf8/0x128\nlr : split_huge_page_to_list_to_order+0x1c4/0x720\nsp : ffff8000882af5f0\nx29: ffff8000882af5f0 x28: ffff8000882af650 x27: ffff8000882af768\nx26: 0000000000000cc0 x25: 000000000000000d x24: ffff00010625b858\nx23: ffff8000882af650 x22: ffffffdfc0900000 x21: 0000000000000000\nx20: 0000000000000000 x19: ffffffdfc0900000 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000018000000000 x15: 52f8004000000000\nx14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020\nx11: 52f8000000000000 x10: 52f8e1c0ffff6000 x9 : ffffbeb9619a681c\nx8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff00010b02ddb0\nx5 : ffffbeb96395e378 x4 : 0000000000000000 x3 : 0000000000000cc0\nx2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\nCall trace:\n xas_split_alloc+0xf8/0x128\n split_huge_page_to_list_to_order+0x1c4/0x720\n truncate_inode_partial_folio+0xdc/0x160\n shmem_undo_range+0x2bc/0x6a8\n shmem_fallocate+0x134/0x430\n vfs_fallocate+0x124/0x2e8\n ksys_fallocate+0x4c/0xa0\n __arm64_sys_fallocate+0x24/0x38\n invoke_syscall.constprop.0+0x7c/0xd8\n do_el0_svc+0xb4/0xd0\n el0_svc+0x44/0x1d8\n el0t_64_sync_handler+0x134/0x150\n el0t_64_sync+0x17c/0x180\n\nFix it by disabling PMD-sized page cache when HPAGE_PMD_ORDER is larger\nthan MAX_PAGECACHE_ORDER.  As Matthew Wilcox pointed, the page cache in a\nshmem file isn't represented by a multi-index entry and doesn't have this\nlimitation when the xarry entry is split until commit 6b24ca4a1a8d (\"mm:\nUse multi-index entries in the page cache\").","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42241","epss":0.00211,"percentile":0.11434,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-42241","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42241","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42243","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42243","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray  Patch series \"mm/filemap: Limit page cache size to that supported by xarray\", v2.  Currently, xarray can't support arbitrary page cache size.  More details can be found from the WARN_ON() statement in xas_split_alloc().  In our test whose code is attached below, we hit the WARN_ON() on ARM64 system where the base page size is 64KB and huge page size is 512MB.  The issue was reported long time ago and some discussions on it can be found here [1].  [1] https://www.spinics.net/lists/linux-xfs/msg75404.html  In order to fix the issue, we need to adjust MAX_PAGECACHE_ORDER to one supported by xarray and avoid PMD-sized page cache if needed.  The code changes are suggested by David Hildenbrand.  PATCH[1] adjusts MAX_PAGECACHE_ORDER to that supported by xarray PATCH[2-3] avoids PMD-sized page cache in the synchronous readahead path PATCH[4] avoids PMD-sized page cache for shmem files if needed  Test program ============ # cat test.c #define _GNU_SOURCE #include <stdio.h> #include <stdlib.h> #include <unistd.h> #include <string.h> #include <fcntl.h> #include <errno.h> #include <sys/syscall.h> #include <sys/mman.h>  #define TEST_XFS_FILENAME\t\"/tmp/data\" #define TEST_SHMEM_FILENAME\t\"/dev/shm/data\" #define TEST_MEM_SIZE\t\t0x20000000  int main(int argc, char **argv) { \tconst char *filename; \tint fd = 0; \tvoid *buf = (void *)-1, *p; \tint pgsize = getpagesize(); \tint ret;  \tif (pgsize != 0x10000) { \t\tfprintf(stderr, \"64KB base page size is required\\n\"); \t\treturn -EPERM; \t}  \tsystem(\"echo force > /sys/kernel/mm/transparent_hugepage/shmem_enabled\"); \tsystem(\"rm -fr /tmp/data\"); \tsystem(\"rm -fr /dev/shm/data\"); \tsystem(\"echo 1 > /proc/sys/vm/drop_caches\");  \t/* Open xfs or shmem file */ \tfilename = TEST_XFS_FILENAME; \tif (argc > 1 && !strcmp(argv[1], \"shmem\")) \t\tfilename = TEST_SHMEM_FILENAME;  \tfd = open(filename, O_CREAT | O_RDWR | O_TRUNC); \tif (fd < 0) { \t\tfprintf(stderr, \"Unable to open <%s>\\n\", filename); \t\treturn -EIO; \t}  \t/* Extend file size */ \tret = ftruncate(fd, TEST_MEM_SIZE); \tif (ret) { \t\tfprintf(stderr, \"Error %d to ftruncate()\\n\", ret); \t\tgoto cleanup; \t}  \t/* Create VMA */ \tbuf = mmap(NULL, TEST_MEM_SIZE, \t\t   PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); \tif (buf == (void *)-1) { \t\tfprintf(stderr, \"Unable to mmap <%s>\\n\", filename); \t\tgoto cleanup; \t}  \tfprintf(stdout, \"mapped buffer at 0x%p\\n\", buf); \tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE);         if (ret) { \t\tfprintf(stderr, \"Unable to madvise(MADV_HUGEPAGE)\\n\"); \t\tgoto cleanup; \t}  \t/* Populate VMA */ \tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_WRITE); \tif (ret) { \t\tfprintf(stderr, \"Error %d to madvise(MADV_POPULATE_WRITE)\\n\", ret); \t\tgoto cleanup; \t}  \t/* Punch the file to enforce xarray split */ \tret = fallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,         \t\tTEST_MEM_SIZE - pgsize, pgsize); \tif (ret) \t\tfprintf(stderr, \"Error %d to fallocate()\\n\", ret);  cleanup: \tif (buf != (void *)-1) \t\tmunmap(buf, TEST_MEM_SIZE); \tif (fd > 0) \t\tclose(fd);  \treturn 0; }  # gcc test.c -o test # cat /proc/1/smaps | grep KernelPageSize | head -n 1 KernelPageSize:       64 kB # ./test shmem    : ------------[ cut here ]------------ WARNING: CPU: 17 PID: 5253 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128 Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib  \\ nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct    \\ nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4    \\ ip_set nf_tables rfkill nfnetlink vfat fat virtio_balloon          \\ drm fuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64  \\ virtio_net sha1_ce net_failover failover virtio_console virtio_blk \\ dimlib virtio_mmio CPU: 17 PID: 5253 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #12 Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024 pstate: 83400005 (Nzcv daif +PAN -UAO +TC ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42243","epss":0.00211,"percentile":0.11435,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2024-42243","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42243","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/099d90642a711caae377f53309abfe27e8724a8b","https://git.kernel.org/stable/c/333c5539a31f48828456aa9997ec2808f06a699a","https://git.kernel.org/stable/c/a0c42ddd0969fdc760a85e20e267776028a7ca4e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray\n\nPatch series \"mm/filemap: Limit page cache size to that supported by\nxarray\", v2.\n\nCurrently, xarray can't support arbitrary page cache size.  More details\ncan be found from the WARN_ON() statement in xas_split_alloc().  In our\ntest whose code is attached below, we hit the WARN_ON() on ARM64 system\nwhere the base page size is 64KB and huge page size is 512MB.  The issue\nwas reported long time ago and some discussions on it can be found here\n[1].\n\n[1] https://www.spinics.net/lists/linux-xfs/msg75404.html\n\nIn order to fix the issue, we need to adjust MAX_PAGECACHE_ORDER to one\nsupported by xarray and avoid PMD-sized page cache if needed.  The code\nchanges are suggested by David Hildenbrand.\n\nPATCH[1] adjusts MAX_PAGECACHE_ORDER to that supported by xarray\nPATCH[2-3] avoids PMD-sized page cache in the synchronous readahead path\nPATCH[4] avoids PMD-sized page cache for shmem files if needed\n\nTest program\n============\n# cat test.c\n#define _GNU_SOURCE\n#include <stdio.h>\n#include <stdlib.h>\n#include <unistd.h>\n#include <string.h>\n#include <fcntl.h>\n#include <errno.h>\n#include <sys/syscall.h>\n#include <sys/mman.h>\n\n#define TEST_XFS_FILENAME\t\"/tmp/data\"\n#define TEST_SHMEM_FILENAME\t\"/dev/shm/data\"\n#define TEST_MEM_SIZE\t\t0x20000000\n\nint main(int argc, char **argv)\n{\n\tconst char *filename;\n\tint fd = 0;\n\tvoid *buf = (void *)-1, *p;\n\tint pgsize = getpagesize();\n\tint ret;\n\n\tif (pgsize != 0x10000) {\n\t\tfprintf(stderr, \"64KB base page size is required\\n\");\n\t\treturn -EPERM;\n\t}\n\n\tsystem(\"echo force > /sys/kernel/mm/transparent_hugepage/shmem_enabled\");\n\tsystem(\"rm -fr /tmp/data\");\n\tsystem(\"rm -fr /dev/shm/data\");\n\tsystem(\"echo 1 > /proc/sys/vm/drop_caches\");\n\n\t/* Open xfs or shmem file */\n\tfilename = TEST_XFS_FILENAME;\n\tif (argc > 1 && !strcmp(argv[1], \"shmem\"))\n\t\tfilename = TEST_SHMEM_FILENAME;\n\n\tfd = open(filename, O_CREAT | O_RDWR | O_TRUNC);\n\tif (fd < 0) {\n\t\tfprintf(stderr, \"Unable to open <%s>\\n\", filename);\n\t\treturn -EIO;\n\t}\n\n\t/* Extend file size */\n\tret = ftruncate(fd, TEST_MEM_SIZE);\n\tif (ret) {\n\t\tfprintf(stderr, \"Error %d to ftruncate()\\n\", ret);\n\t\tgoto cleanup;\n\t}\n\n\t/* Create VMA */\n\tbuf = mmap(NULL, TEST_MEM_SIZE,\n\t\t   PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0);\n\tif (buf == (void *)-1) {\n\t\tfprintf(stderr, \"Unable to mmap <%s>\\n\", filename);\n\t\tgoto cleanup;\n\t}\n\n\tfprintf(stdout, \"mapped buffer at 0x%p\\n\", buf);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE);\n        if (ret) {\n\t\tfprintf(stderr, \"Unable to madvise(MADV_HUGEPAGE)\\n\");\n\t\tgoto cleanup;\n\t}\n\n\t/* Populate VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_WRITE);\n\tif (ret) {\n\t\tfprintf(stderr, \"Error %d to madvise(MADV_POPULATE_WRITE)\\n\", ret);\n\t\tgoto cleanup;\n\t}\n\n\t/* Punch the file to enforce xarray split */\n\tret = fallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,\n        \t\tTEST_MEM_SIZE - pgsize, pgsize);\n\tif (ret)\n\t\tfprintf(stderr, \"Error %d to fallocate()\\n\", ret);\n\ncleanup:\n\tif (buf != (void *)-1)\n\t\tmunmap(buf, TEST_MEM_SIZE);\n\tif (fd > 0)\n\t\tclose(fd);\n\n\treturn 0;\n}\n\n# gcc test.c -o test\n# cat /proc/1/smaps | grep KernelPageSize | head -n 1\nKernelPageSize:       64 kB\n# ./test shmem\n   :\n------------[ cut here ]------------\nWARNING: CPU: 17 PID: 5253 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\nModules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib  \\\nnft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct    \\\nnft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4    \\\nip_set nf_tables rfkill nfnetlink vfat fat virtio_balloon          \\\ndrm fuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64  \\\nvirtio_net sha1_ce net_failover failover virtio_console virtio_blk \\\ndimlib virtio_mmio\nCPU: 17 PID: 5253 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #12\nHardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\npstate: 83400005 (Nzcv daif +PAN -UAO +TC\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42243","epss":0.00211,"percentile":0.11435,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42243","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42279","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42279","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer  While transmitting with rx_len == 0, the RX FIFO is not going to be emptied in the interrupt handler. A subsequent transfer could then read crap from the previous transfer out of the RX FIFO into the start RX buffer. The core provides a register that will empty the RX and TX FIFOs, so do that before each transfer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42279","epss":0.00234,"percentile":0.14286,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12285},"relatedVulnerabilities":[{"id":"CVE-2024-42279","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42279","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3feda3677e8bbe833c3a62a4091377a08f015b80","https://git.kernel.org/stable/c/45e03d35229b680b79dfea1103a1f2f07d0b5d75","https://git.kernel.org/stable/c/9cf71eb0faef4bff01df4264841b8465382d7927"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: microchip-core: ensure TX and RX FIFOs are empty at start of a transfer\n\nWhile transmitting with rx_len == 0, the RX FIFO is not going to be\nemptied in the interrupt handler. A subsequent transfer could then\nread crap from the previous transfer out of the RX FIFO into the\nstart RX buffer. The core provides a register that will empty the RX and\nTX FIFOs, so do that before each transfer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42279","epss":0.00234,"percentile":0.14286,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42279","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-42317","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-42317","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/huge_memory: avoid PMD-size page cache if needed  xarray can't support arbitrary page cache size.  the largest and supported page cache size is defined as MAX_PAGECACHE_ORDER by commit 099d90642a71 (\"mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray\").  However, it's possible to have 512MB page cache in the huge memory's collapsing path on ARM64 system whose base page size is 64KB.  512MB page cache is breaking the limitation and a warning is raised when the xarray entry is split as shown in the following example.  [root@dhcp-10-26-1-207 ~]# cat /proc/1/smaps | grep KernelPageSize KernelPageSize:       64 kB [root@dhcp-10-26-1-207 ~]# cat /tmp/test.c    : int main(int argc, char **argv) { \tconst char *filename = TEST_XFS_FILENAME; \tint fd = 0; \tvoid *buf = (void *)-1, *p; \tint pgsize = getpagesize(); \tint ret = 0;  \tif (pgsize != 0x10000) { \t\tfprintf(stdout, \"System with 64KB base page size is required!\\n\"); \t\treturn -EPERM; \t}  \tsystem(\"echo 0 > /sys/devices/virtual/bdi/253:0/read_ahead_kb\"); \tsystem(\"echo 1 > /proc/sys/vm/drop_caches\");  \t/* Open the xfs file */ \tfd = open(filename, O_RDONLY); \tassert(fd > 0);  \t/* Create VMA */ \tbuf = mmap(NULL, TEST_MEM_SIZE, PROT_READ, MAP_SHARED, fd, 0); \tassert(buf != (void *)-1); \tfprintf(stdout, \"mapped buffer at 0x%p\\n\", buf);  \t/* Populate VMA */ \tret = madvise(buf, TEST_MEM_SIZE, MADV_NOHUGEPAGE); \tassert(ret == 0); \tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_READ); \tassert(ret == 0);  \t/* Collapse VMA */ \tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE); \tassert(ret == 0); \tret = madvise(buf, TEST_MEM_SIZE, MADV_COLLAPSE); \tif (ret) { \t\tfprintf(stdout, \"Error %d to madvise(MADV_COLLAPSE)\\n\", errno); \t\tgoto out; \t}  \t/* Split xarray entry. Write permission is needed */ \tmunmap(buf, TEST_MEM_SIZE); \tbuf = (void *)-1; \tclose(fd); \tfd = open(filename, O_RDWR); \tassert(fd > 0); \tfallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,  \t\t  TEST_MEM_SIZE - pgsize, pgsize); out: \tif (buf != (void *)-1) \t\tmunmap(buf, TEST_MEM_SIZE); \tif (fd > 0) \t\tclose(fd);  \treturn ret; }  [root@dhcp-10-26-1-207 ~]# gcc /tmp/test.c -o /tmp/test [root@dhcp-10-26-1-207 ~]# /tmp/test  ------------[ cut here ]------------  WARNING: CPU: 25 PID: 7560 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128  Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib    \\  nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct      \\  nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4      \\  ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse   \\  xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 virtio_net  \\  sha1_ce net_failover virtio_blk virtio_console failover dimlib virtio_mmio  CPU: 25 PID: 7560 Comm: test Kdump: loaded Not tainted 6.10.0-rc7-gavin+ #9  Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024  pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)  pc : xas_split_alloc+0xf8/0x128  lr : split_huge_page_to_list_to_order+0x1c4/0x780  sp : ffff8000ac32f660  x29: ffff8000ac32f660 x28: ffff0000e0969eb0 x27: ffff8000ac32f6c0  x26: 0000000000000c40 x25: ffff0000e0969eb0 x24: 000000000000000d  x23: ffff8000ac32f6c0 x22: ffffffdfc0700000 x21: 0000000000000000  x20: 0000000000000000 x19: ffffffdfc0700000 x18: 0000000000000000  x17: 0000000000000000 x16: ffffd5f3708ffc70 x15: 0000000000000000  x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000  x11: ffffffffffffffc0 x10: 0000000000000040 x9 : ffffd5f3708e692c  x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff0000e0969eb8  x5 : ffffd5f37289e378 x4 : 0000000000000000 x3 : 0000000000000c40  x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000  Call trace:   xas_split_alloc+0xf8/0x128   split_huge_page_to_list_to_order+0x1c4/0x780   truncate_inode_partial_folio+0xdc/0x160   truncate_inode_pages_range+0x1b4/0x4a8   truncate_pagecache_range+0x84/0xa ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42317","epss":0.00184,"percentile":0.08097,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0966},"relatedVulnerabilities":[{"id":"CVE-2024-42317","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42317","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/d659b715e94ac039803d7601505d3473393fc0be","https://git.kernel.org/stable/c/e60f62f75c99740a28e2bf7e6044086033012a16"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: avoid PMD-size page cache if needed\n\nxarray can't support arbitrary page cache size.  the largest and supported\npage cache size is defined as MAX_PAGECACHE_ORDER by commit 099d90642a71\n(\"mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray\").  However,\nit's possible to have 512MB page cache in the huge memory's collapsing\npath on ARM64 system whose base page size is 64KB.  512MB page cache is\nbreaking the limitation and a warning is raised when the xarray entry is\nsplit as shown in the following example.\n\n[root@dhcp-10-26-1-207 ~]# cat /proc/1/smaps | grep KernelPageSize\nKernelPageSize:       64 kB\n[root@dhcp-10-26-1-207 ~]# cat /tmp/test.c\n   :\nint main(int argc, char **argv)\n{\n\tconst char *filename = TEST_XFS_FILENAME;\n\tint fd = 0;\n\tvoid *buf = (void *)-1, *p;\n\tint pgsize = getpagesize();\n\tint ret = 0;\n\n\tif (pgsize != 0x10000) {\n\t\tfprintf(stdout, \"System with 64KB base page size is required!\\n\");\n\t\treturn -EPERM;\n\t}\n\n\tsystem(\"echo 0 > /sys/devices/virtual/bdi/253:0/read_ahead_kb\");\n\tsystem(\"echo 1 > /proc/sys/vm/drop_caches\");\n\n\t/* Open the xfs file */\n\tfd = open(filename, O_RDONLY);\n\tassert(fd > 0);\n\n\t/* Create VMA */\n\tbuf = mmap(NULL, TEST_MEM_SIZE, PROT_READ, MAP_SHARED, fd, 0);\n\tassert(buf != (void *)-1);\n\tfprintf(stdout, \"mapped buffer at 0x%p\\n\", buf);\n\n\t/* Populate VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_NOHUGEPAGE);\n\tassert(ret == 0);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_READ);\n\tassert(ret == 0);\n\n\t/* Collapse VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE);\n\tassert(ret == 0);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_COLLAPSE);\n\tif (ret) {\n\t\tfprintf(stdout, \"Error %d to madvise(MADV_COLLAPSE)\\n\", errno);\n\t\tgoto out;\n\t}\n\n\t/* Split xarray entry. Write permission is needed */\n\tmunmap(buf, TEST_MEM_SIZE);\n\tbuf = (void *)-1;\n\tclose(fd);\n\tfd = open(filename, O_RDWR);\n\tassert(fd > 0);\n\tfallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,\n \t\t  TEST_MEM_SIZE - pgsize, pgsize);\nout:\n\tif (buf != (void *)-1)\n\t\tmunmap(buf, TEST_MEM_SIZE);\n\tif (fd > 0)\n\t\tclose(fd);\n\n\treturn ret;\n}\n\n[root@dhcp-10-26-1-207 ~]# gcc /tmp/test.c -o /tmp/test\n[root@dhcp-10-26-1-207 ~]# /tmp/test\n ------------[ cut here ]------------\n WARNING: CPU: 25 PID: 7560 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\n Modules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib    \\\n nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct      \\\n nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4      \\\n ip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse   \\\n xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 virtio_net  \\\n sha1_ce net_failover virtio_blk virtio_console failover dimlib virtio_mmio\n CPU: 25 PID: 7560 Comm: test Kdump: loaded Not tainted 6.10.0-rc7-gavin+ #9\n Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\n pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : xas_split_alloc+0xf8/0x128\n lr : split_huge_page_to_list_to_order+0x1c4/0x780\n sp : ffff8000ac32f660\n x29: ffff8000ac32f660 x28: ffff0000e0969eb0 x27: ffff8000ac32f6c0\n x26: 0000000000000c40 x25: ffff0000e0969eb0 x24: 000000000000000d\n x23: ffff8000ac32f6c0 x22: ffffffdfc0700000 x21: 0000000000000000\n x20: 0000000000000000 x19: ffffffdfc0700000 x18: 0000000000000000\n x17: 0000000000000000 x16: ffffd5f3708ffc70 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: ffffffffffffffc0 x10: 0000000000000040 x9 : ffffd5f3708e692c\n x8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff0000e0969eb8\n x5 : ffffd5f37289e378 x4 : 0000000000000000 x3 : 0000000000000c40\n x2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\n Call trace:\n  xas_split_alloc+0xf8/0x128\n  split_huge_page_to_list_to_order+0x1c4/0x780\n  truncate_inode_partial_folio+0xdc/0x160\n  truncate_inode_pages_range+0x1b4/0x4a8\n  truncate_pagecache_range+0x84/0xa\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-42317","epss":0.00184,"percentile":0.08097,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-42317","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-43819","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-43819","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  kvm: s390: Reject memory region operations for ucontrol VMs  This change rejects the KVM_SET_USER_MEMORY_REGION and KVM_SET_USER_MEMORY_REGION2 ioctls when called on a ucontrol VM. This is necessary since ucontrol VMs have kvm->arch.gmap set to 0 and would thus result in a null pointer dereference further in. Memory management needs to be performed in userspace and using the ioctls KVM_S390_UCAS_MAP and KVM_S390_UCAS_UNMAP.  Also improve s390 specific documentation for KVM_SET_USER_MEMORY_REGION and KVM_SET_USER_MEMORY_REGION2.  [frankja@linux.ibm.com: commit message spelling fix, subject prefix fix]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43819","epss":0.0021,"percentile":0.11197,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43819","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11025},"relatedVulnerabilities":[{"id":"CVE-2024-43819","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-43819","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/49c9945c054df4c22008e2bf87ca74d3e2507aa6","https://git.kernel.org/stable/c/7816e58967d0e6cadce05c8540b47ed027dc2499"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nkvm: s390: Reject memory region operations for ucontrol VMs\n\nThis change rejects the KVM_SET_USER_MEMORY_REGION and\nKVM_SET_USER_MEMORY_REGION2 ioctls when called on a ucontrol VM.\nThis is necessary since ucontrol VMs have kvm->arch.gmap set to 0 and\nwould thus result in a null pointer dereference further in.\nMemory management needs to be performed in userspace and using the\nioctls KVM_S390_UCAS_MAP and KVM_S390_UCAS_UNMAP.\n\nAlso improve s390 specific documentation for KVM_SET_USER_MEMORY_REGION\nand KVM_SET_USER_MEMORY_REGION2.\n\n[frankja@linux.ibm.com: commit message spelling fix, subject prefix fix]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43819","epss":0.0021,"percentile":0.11197,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43819","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-43819","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-43824","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-43824","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()  Instead of getting the epc_features from pci_epc_get_features() API, use the cached pci_epf_test::epc_features value to avoid the NULL check. Since the NULL check is already performed in pci_epf_test_bind(), having one more check in pci_epf_test_core_init() is redundant and it is not possible to hit the NULL pointer dereference.  Also with commit a01e7214bef9 (\"PCI: endpoint: Remove \"core_init_notifier\" flag\"), 'epc_features' got dereferenced without the NULL check, leading to the following false positive Smatch warning:    drivers/pci/endpoint/functions/pci-epf-test.c:784 pci_epf_test_core_init() error: we previously assumed 'epc_features' could be null (see line 747)  Thus, remove the redundant NULL check and also use the epc_features:: {msix_capable/msi_capable} flags directly to avoid local variables.  [kwilczynski: commit log]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43824","epss":0.00198,"percentile":0.09668,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43824","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10395},"relatedVulnerabilities":[{"id":"CVE-2024-43824","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-43824","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5a5095a8bd1bd349cce1c879e5e44407a34dda8a","https://git.kernel.org/stable/c/af4ad016abb1632ff7ee598a6037952b495e5b80"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()\n\nInstead of getting the epc_features from pci_epc_get_features() API, use\nthe cached pci_epf_test::epc_features value to avoid the NULL check. Since\nthe NULL check is already performed in pci_epf_test_bind(), having one more\ncheck in pci_epf_test_core_init() is redundant and it is not possible to\nhit the NULL pointer dereference.\n\nAlso with commit a01e7214bef9 (\"PCI: endpoint: Remove \"core_init_notifier\"\nflag\"), 'epc_features' got dereferenced without the NULL check, leading to\nthe following false positive Smatch warning:\n\n  drivers/pci/endpoint/functions/pci-epf-test.c:784 pci_epf_test_core_init() error: we previously assumed 'epc_features' could be null (see line 747)\n\nThus, remove the redundant NULL check and also use the epc_features::\n{msix_capable/msi_capable} flags directly to avoid local variables.\n\n[kwilczynski: commit log]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43824","epss":0.00198,"percentile":0.09668,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43824","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-43824","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-43850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-43850","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  soc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove  The following warning is seen during bwmon_remove due to refcount imbalance, fix this by releasing the OPPs after use.  Logs: WARNING: at drivers/opp/core.c:1640 _opp_table_kref_release+0x150/0x158 Hardware name: Qualcomm Technologies, Inc. X1E80100 CRD (DT) ... Call trace: _opp_table_kref_release+0x150/0x158 dev_pm_opp_remove_table+0x100/0x1b4 devm_pm_opp_of_table_release+0x10/0x1c devm_action_release+0x14/0x20 devres_release_all+0xa4/0x104 device_unbind_cleanup+0x18/0x60 device_release_driver_internal+0x1ec/0x228 driver_detach+0x50/0x98 bus_remove_driver+0x6c/0xbc driver_unregister+0x30/0x60 platform_driver_unregister+0x14/0x20 bwmon_driver_exit+0x18/0x524 [icc_bwmon] __arm64_sys_delete_module+0x184/0x264 invoke_syscall+0x48/0x118 el0_svc_common.constprop.0+0xc8/0xe8 do_el0_svc+0x20/0x2c el0_svc+0x34/0xdc el0t_64_sync_handler+0x13c/0x158 el0t_64_sync+0x190/0x194 --[ end trace 0000000000000000 ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43850","epss":0.0021,"percentile":0.11183,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43850","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11025},"relatedVulnerabilities":[{"id":"CVE-2024-43850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-43850","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/24086640ab39396eb1a92d1cb1cd2f31b2677c52","https://git.kernel.org/stable/c/4100d4d019f8e140be1d4d3a9d8d93c1285f5d1c","https://git.kernel.org/stable/c/aad41f4c169bcb800ae88123799bdf8cdec3d366"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: icc-bwmon: Fix refcount imbalance seen during bwmon_remove\n\nThe following warning is seen during bwmon_remove due to refcount\nimbalance, fix this by releasing the OPPs after use.\n\nLogs:\nWARNING: at drivers/opp/core.c:1640 _opp_table_kref_release+0x150/0x158\nHardware name: Qualcomm Technologies, Inc. X1E80100 CRD (DT)\n...\nCall trace:\n_opp_table_kref_release+0x150/0x158\ndev_pm_opp_remove_table+0x100/0x1b4\ndevm_pm_opp_of_table_release+0x10/0x1c\ndevm_action_release+0x14/0x20\ndevres_release_all+0xa4/0x104\ndevice_unbind_cleanup+0x18/0x60\ndevice_release_driver_internal+0x1ec/0x228\ndriver_detach+0x50/0x98\nbus_remove_driver+0x6c/0xbc\ndriver_unregister+0x30/0x60\nplatform_driver_unregister+0x14/0x20\nbwmon_driver_exit+0x18/0x524 [icc_bwmon]\n__arm64_sys_delete_module+0x184/0x264\ninvoke_syscall+0x48/0x118\nel0_svc_common.constprop.0+0xc8/0xe8\ndo_el0_svc+0x20/0x2c\nel0_svc+0x34/0xdc\nel0t_64_sync_handler+0x13c/0x158\nel0t_64_sync+0x190/0x194\n--[ end trace 0000000000000000 ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43850","epss":0.0021,"percentile":0.11183,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43850","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-43850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-43872","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-43872","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/hns: Fix soft lockup under heavy CEQE load  CEQEs are handled in interrupt handler currently. This may cause the CPU core staying in interrupt context too long and lead to soft lockup under heavy load.  Handle CEQEs in BH workqueue and set an upper limit for the number of CEQE handled by a single call of work handler.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43872","epss":0.00324,"percentile":0.25175,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43872","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1701},"relatedVulnerabilities":[{"id":"CVE-2024-43872","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-43872","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/06580b33c183c9f98e2a2ca96a86137179032c08","https://git.kernel.org/stable/c/2fdf34038369c0a27811e7b4680662a14ada1d6b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix soft lockup under heavy CEQE load\n\nCEQEs are handled in interrupt handler currently. This may cause the\nCPU core staying in interrupt context too long and lead to soft lockup\nunder heavy load.\n\nHandle CEQEs in BH workqueue and set an upper limit for the number of\nCEQE handled by a single call of work handler.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43872","epss":0.00324,"percentile":0.25175,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43872","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-43872","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-43899","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-43899","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix null pointer deref in dcn20_resource.c  Fixes a hang thats triggered when MPV is run on a DCN401 dGPU:  mpv --hwdec=vaapi --vo=gpu --hwdec-codecs=all  and then enabling fullscreen playback (double click on the video)  The following calltrace will be seen:  [  181.843989] BUG: kernel NULL pointer dereference, address: 0000000000000000 [  181.843997] #PF: supervisor instruction fetch in kernel mode [  181.844003] #PF: error_code(0x0010) - not-present page [  181.844009] PGD 0 P4D 0 [  181.844020] Oops: 0010 [#1] PREEMPT SMP NOPTI [  181.844028] CPU: 6 PID: 1892 Comm: gnome-shell Tainted: G        W  OE      6.5.0-41-generic #41~22.04.2-Ubuntu [  181.844038] Hardware name: System manufacturer System Product Name/CROSSHAIR VI HERO, BIOS 6302 10/23/2018 [  181.844044] RIP: 0010:0x0 [  181.844079] Code: Unable to access opcode bytes at 0xffffffffffffffd6. [  181.844084] RSP: 0018:ffffb593c2b8f7b0 EFLAGS: 00010246 [  181.844093] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000004 [  181.844099] RDX: ffffb593c2b8f804 RSI: ffffb593c2b8f7e0 RDI: ffff9e3c8e758400 [  181.844105] RBP: ffffb593c2b8f7b8 R08: ffffb593c2b8f9c8 R09: ffffb593c2b8f96c [  181.844110] R10: 0000000000000000 R11: 0000000000000000 R12: ffffb593c2b8f9c8 [  181.844115] R13: 0000000000000001 R14: ffff9e3c88000000 R15: 0000000000000005 [  181.844121] FS:  00007c6e323bb5c0(0000) GS:ffff9e3f85f80000(0000) knlGS:0000000000000000 [  181.844128] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [  181.844134] CR2: ffffffffffffffd6 CR3: 0000000140fbe000 CR4: 00000000003506e0 [  181.844141] Call Trace: [  181.844146]  <TASK> [  181.844153]  ? show_regs+0x6d/0x80 [  181.844167]  ? __die+0x24/0x80 [  181.844179]  ? page_fault_oops+0x99/0x1b0 [  181.844192]  ? do_user_addr_fault+0x31d/0x6b0 [  181.844204]  ? exc_page_fault+0x83/0x1b0 [  181.844216]  ? asm_exc_page_fault+0x27/0x30 [  181.844237]  dcn20_get_dcc_compression_cap+0x23/0x30 [amdgpu] [  181.845115]  amdgpu_dm_plane_validate_dcc.constprop.0+0xe5/0x180 [amdgpu] [  181.845985]  amdgpu_dm_plane_fill_plane_buffer_attributes+0x300/0x580 [amdgpu] [  181.846848]  fill_dc_plane_info_and_addr+0x258/0x350 [amdgpu] [  181.847734]  fill_dc_plane_attributes+0x162/0x350 [amdgpu] [  181.848748]  dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu] [  181.849791]  ? dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu] [  181.850840]  amdgpu_dm_atomic_check+0xdfe/0x1760 [amdgpu]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43899","epss":0.00211,"percentile":0.11434,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43899","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2024-43899","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-43899","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6940c1d0c84a34d5a2038714c218238101a1db5b","https://git.kernel.org/stable/c/974fccd61758599a9716c4b909d9226749efe37e","https://git.kernel.org/stable/c/ecbf60782662f0a388493685b85a645a0ba1613c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null pointer deref in dcn20_resource.c\n\nFixes a hang thats triggered when MPV is run on a DCN401 dGPU:\n\nmpv --hwdec=vaapi --vo=gpu --hwdec-codecs=all\n\nand then enabling fullscreen playback (double click on the video)\n\nThe following calltrace will be seen:\n\n[  181.843989] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[  181.843997] #PF: supervisor instruction fetch in kernel mode\n[  181.844003] #PF: error_code(0x0010) - not-present page\n[  181.844009] PGD 0 P4D 0\n[  181.844020] Oops: 0010 [#1] PREEMPT SMP NOPTI\n[  181.844028] CPU: 6 PID: 1892 Comm: gnome-shell Tainted: G        W  OE      6.5.0-41-generic #41~22.04.2-Ubuntu\n[  181.844038] Hardware name: System manufacturer System Product Name/CROSSHAIR VI HERO, BIOS 6302 10/23/2018\n[  181.844044] RIP: 0010:0x0\n[  181.844079] Code: Unable to access opcode bytes at 0xffffffffffffffd6.\n[  181.844084] RSP: 0018:ffffb593c2b8f7b0 EFLAGS: 00010246\n[  181.844093] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000004\n[  181.844099] RDX: ffffb593c2b8f804 RSI: ffffb593c2b8f7e0 RDI: ffff9e3c8e758400\n[  181.844105] RBP: ffffb593c2b8f7b8 R08: ffffb593c2b8f9c8 R09: ffffb593c2b8f96c\n[  181.844110] R10: 0000000000000000 R11: 0000000000000000 R12: ffffb593c2b8f9c8\n[  181.844115] R13: 0000000000000001 R14: ffff9e3c88000000 R15: 0000000000000005\n[  181.844121] FS:  00007c6e323bb5c0(0000) GS:ffff9e3f85f80000(0000) knlGS:0000000000000000\n[  181.844128] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  181.844134] CR2: ffffffffffffffd6 CR3: 0000000140fbe000 CR4: 00000000003506e0\n[  181.844141] Call Trace:\n[  181.844146]  <TASK>\n[  181.844153]  ? show_regs+0x6d/0x80\n[  181.844167]  ? __die+0x24/0x80\n[  181.844179]  ? page_fault_oops+0x99/0x1b0\n[  181.844192]  ? do_user_addr_fault+0x31d/0x6b0\n[  181.844204]  ? exc_page_fault+0x83/0x1b0\n[  181.844216]  ? asm_exc_page_fault+0x27/0x30\n[  181.844237]  dcn20_get_dcc_compression_cap+0x23/0x30 [amdgpu]\n[  181.845115]  amdgpu_dm_plane_validate_dcc.constprop.0+0xe5/0x180 [amdgpu]\n[  181.845985]  amdgpu_dm_plane_fill_plane_buffer_attributes+0x300/0x580 [amdgpu]\n[  181.846848]  fill_dc_plane_info_and_addr+0x258/0x350 [amdgpu]\n[  181.847734]  fill_dc_plane_attributes+0x162/0x350 [amdgpu]\n[  181.848748]  dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu]\n[  181.849791]  ? dm_update_plane_state.constprop.0+0x4e3/0x6b0 [amdgpu]\n[  181.850840]  amdgpu_dm_atomic_check+0xdfe/0x1760 [amdgpu]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43899","epss":0.00211,"percentile":0.11434,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43899","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-43899","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-43901","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-43901","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix NULL pointer dereference for DTN log in DCN401  When users run the command:  cat /sys/kernel/debug/dri/0/amdgpu_dm_dtn_log  The following NULL pointer dereference happens:  [  +0.000003] BUG: kernel NULL pointer dereference, address: NULL [  +0.000005] #PF: supervisor instruction fetch in kernel mode [  +0.000002] #PF: error_code(0x0010) - not-present page [  +0.000002] PGD 0 P4D 0 [  +0.000004] Oops: 0010 [#1] PREEMPT SMP NOPTI [  +0.000003] RIP: 0010:0x0 [  +0.000008] Code: Unable to access opcode bytes at 0xffffffffffffffd6. [...] [  +0.000002] PKRU: 55555554 [  +0.000002] Call Trace: [  +0.000002]  <TASK> [  +0.000003]  ? show_regs+0x65/0x70 [  +0.000006]  ? __die+0x24/0x70 [  +0.000004]  ? page_fault_oops+0x160/0x470 [  +0.000006]  ? do_user_addr_fault+0x2b5/0x690 [  +0.000003]  ? prb_read_valid+0x1c/0x30 [  +0.000005]  ? exc_page_fault+0x8c/0x1a0 [  +0.000005]  ? asm_exc_page_fault+0x27/0x30 [  +0.000012]  dcn10_log_color_state+0xf9/0x510 [amdgpu] [  +0.000306]  ? srso_alias_return_thunk+0x5/0xfbef5 [  +0.000003]  ? vsnprintf+0x2fb/0x600 [  +0.000009]  dcn10_log_hw_state+0xfd0/0xfe0 [amdgpu] [  +0.000218]  ? __mod_memcg_lruvec_state+0xe8/0x170 [  +0.000008]  ? srso_alias_return_thunk+0x5/0xfbef5 [  +0.000002]  ? debug_smp_processor_id+0x17/0x20 [  +0.000003]  ? srso_alias_return_thunk+0x5/0xfbef5 [  +0.000002]  ? srso_alias_return_thunk+0x5/0xfbef5 [  +0.000002]  ? set_ptes.isra.0+0x2b/0x90 [  +0.000004]  ? srso_alias_return_thunk+0x5/0xfbef5 [  +0.000002]  ? _raw_spin_unlock+0x19/0x40 [  +0.000004]  ? srso_alias_return_thunk+0x5/0xfbef5 [  +0.000002]  ? do_anonymous_page+0x337/0x700 [  +0.000004]  dtn_log_read+0x82/0x120 [amdgpu] [  +0.000207]  full_proxy_read+0x66/0x90 [  +0.000007]  vfs_read+0xb0/0x340 [  +0.000005]  ? __count_memcg_events+0x79/0xe0 [  +0.000002]  ? srso_alias_return_thunk+0x5/0xfbef5 [  +0.000003]  ? count_memcg_events.constprop.0+0x1e/0x40 [  +0.000003]  ? handle_mm_fault+0xb2/0x370 [  +0.000003]  ksys_read+0x6b/0xf0 [  +0.000004]  __x64_sys_read+0x19/0x20 [  +0.000003]  do_syscall_64+0x60/0x130 [  +0.000004]  entry_SYSCALL_64_after_hwframe+0x6e/0x76 [  +0.000003] RIP: 0033:0x7fdf32f147e2 [...]  This error happens when the color log tries to read the gamut remap information from DCN401 which is not initialized in the dcn401_dpp_funcs which leads to a null pointer dereference. This commit addresses this issue by adding a proper guard to access the gamut_remap callback in case the specific ASIC did not implement this function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43901","epss":0.00182,"percentile":0.07871,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43901","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09555000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-43901","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-43901","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1e68b7ce6bc6073579fe8713ec6b85aa9cd2e351","https://git.kernel.org/stable/c/5af757124792817f8eb1bd0c80ad60fab519586b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix NULL pointer dereference for DTN log in DCN401\n\nWhen users run the command:\n\ncat /sys/kernel/debug/dri/0/amdgpu_dm_dtn_log\n\nThe following NULL pointer dereference happens:\n\n[  +0.000003] BUG: kernel NULL pointer dereference, address: NULL\n[  +0.000005] #PF: supervisor instruction fetch in kernel mode\n[  +0.000002] #PF: error_code(0x0010) - not-present page\n[  +0.000002] PGD 0 P4D 0\n[  +0.000004] Oops: 0010 [#1] PREEMPT SMP NOPTI\n[  +0.000003] RIP: 0010:0x0\n[  +0.000008] Code: Unable to access opcode bytes at 0xffffffffffffffd6.\n[...]\n[  +0.000002] PKRU: 55555554\n[  +0.000002] Call Trace:\n[  +0.000002]  <TASK>\n[  +0.000003]  ? show_regs+0x65/0x70\n[  +0.000006]  ? __die+0x24/0x70\n[  +0.000004]  ? page_fault_oops+0x160/0x470\n[  +0.000006]  ? do_user_addr_fault+0x2b5/0x690\n[  +0.000003]  ? prb_read_valid+0x1c/0x30\n[  +0.000005]  ? exc_page_fault+0x8c/0x1a0\n[  +0.000005]  ? asm_exc_page_fault+0x27/0x30\n[  +0.000012]  dcn10_log_color_state+0xf9/0x510 [amdgpu]\n[  +0.000306]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  +0.000003]  ? vsnprintf+0x2fb/0x600\n[  +0.000009]  dcn10_log_hw_state+0xfd0/0xfe0 [amdgpu]\n[  +0.000218]  ? __mod_memcg_lruvec_state+0xe8/0x170\n[  +0.000008]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  +0.000002]  ? debug_smp_processor_id+0x17/0x20\n[  +0.000003]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  +0.000002]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  +0.000002]  ? set_ptes.isra.0+0x2b/0x90\n[  +0.000004]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  +0.000002]  ? _raw_spin_unlock+0x19/0x40\n[  +0.000004]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  +0.000002]  ? do_anonymous_page+0x337/0x700\n[  +0.000004]  dtn_log_read+0x82/0x120 [amdgpu]\n[  +0.000207]  full_proxy_read+0x66/0x90\n[  +0.000007]  vfs_read+0xb0/0x340\n[  +0.000005]  ? __count_memcg_events+0x79/0xe0\n[  +0.000002]  ? srso_alias_return_thunk+0x5/0xfbef5\n[  +0.000003]  ? count_memcg_events.constprop.0+0x1e/0x40\n[  +0.000003]  ? handle_mm_fault+0xb2/0x370\n[  +0.000003]  ksys_read+0x6b/0xf0\n[  +0.000004]  __x64_sys_read+0x19/0x20\n[  +0.000003]  do_syscall_64+0x60/0x130\n[  +0.000004]  entry_SYSCALL_64_after_hwframe+0x6e/0x76\n[  +0.000003] RIP: 0033:0x7fdf32f147e2\n[...]\n\nThis error happens when the color log tries to read the gamut remap\ninformation from DCN401 which is not initialized in the dcn401_dpp_funcs\nwhich leads to a null pointer dereference. This commit addresses this\nissue by adding a proper guard to access the gamut_remap callback in\ncase the specific ASIC did not implement this function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43901","epss":0.00182,"percentile":0.07871,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43901","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-43901","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-43913","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-43913","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvme: apple: fix device reference counting  Drivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl. Split the allocation side out to make the error handling boundary easier to navigate. The apple driver had been doing this wrong, leaking the controller device memory on a tagset failure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43913","epss":0.00223,"percentile":0.12816,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43913","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11707500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-43913","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-43913","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/b9ecbfa45516182cd062fecd286db7907ba84210","https://git.kernel.org/stable/c/d59c4d0eb6adc24c2201f153ccb7fd0a335b0d3d","https://git.kernel.org/stable/c/f7d9a18572fcd7130459b7691bd19ee2a2e951ad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: apple: fix device reference counting\n\nDrivers must call nvme_uninit_ctrl after a successful nvme_init_ctrl.\nSplit the allocation side out to make the error handling boundary easier\nto navigate. The apple driver had been doing this wrong, leaking the\ncontroller device memory on a tagset failure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-43913","epss":0.00223,"percentile":0.12816,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-43913","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-43913","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-44941","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-44941","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to cover read extent cache access with lock  syzbot reports a f2fs bug as below:  BUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46 Read of size 4 at addr ffff8880739ab220 by task syz-executor200/5097  CPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 Call Trace:  <TASK>  __dump_stack lib/dump_stack.c:88 [inline]  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114  print_address_description mm/kasan/report.c:377 [inline]  print_report+0x169/0x550 mm/kasan/report.c:488  kasan_report+0x143/0x180 mm/kasan/report.c:601  sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46  do_read_inode fs/f2fs/inode.c:509 [inline]  f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560  f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237  generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413  exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444  exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584  do_handle_to_path fs/fhandle.c:155 [inline]  handle_to_path fs/fhandle.c:210 [inline]  do_handle_open+0x495/0x650 fs/fhandle.c:226  do_syscall_x64 arch/x86/entry/common.c:52 [inline]  do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f  We missed to cover sanity_check_extent_cache() w/ extent cache lock, so, below race case may happen, result in use after free issue.  - f2fs_iget  - do_read_inode   - f2fs_init_read_extent_tree   : add largest extent entry in to cache \t\t\t\t\t- shrink \t\t\t\t\t - f2fs_shrink_read_extent_tree \t\t\t\t\t  - __shrink_extent_tree \t\t\t\t\t   - __detach_extent_node \t\t\t\t\t   : drop largest extent entry   - sanity_check_extent_cache   : access et->largest w/o lock  let's refactor sanity_check_extent_cache() to avoid extent cache access and call it before f2fs_init_read_extent_tree() to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-44941","epss":0.00211,"percentile":0.11352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-44941","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.161415},"relatedVulnerabilities":[{"id":"CVE-2024-44941","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-44941","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/263df78166d3a9609b97d28c34029bd01874cbb8","https://git.kernel.org/stable/c/323ef20b5558b9d9fd10c1224327af6f11a8177d","https://git.kernel.org/stable/c/d7409b05a64f212735f0d33f5f1602051a886eab"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to cover read extent cache access with lock\n\nsyzbot reports a f2fs bug as below:\n\nBUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\nRead of size 4 at addr ffff8880739ab220 by task syz-executor200/5097\n\nCPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46\n do_read_inode fs/f2fs/inode.c:509 [inline]\n f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560\n f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237\n generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413\n exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444\n exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584\n do_handle_to_path fs/fhandle.c:155 [inline]\n handle_to_path fs/fhandle.c:210 [inline]\n do_handle_open+0x495/0x650 fs/fhandle.c:226\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nWe missed to cover sanity_check_extent_cache() w/ extent cache lock,\nso, below race case may happen, result in use after free issue.\n\n- f2fs_iget\n - do_read_inode\n  - f2fs_init_read_extent_tree\n  : add largest extent entry in to cache\n\t\t\t\t\t- shrink\n\t\t\t\t\t - f2fs_shrink_read_extent_tree\n\t\t\t\t\t  - __shrink_extent_tree\n\t\t\t\t\t   - __detach_extent_node\n\t\t\t\t\t   : drop largest extent entry\n  - sanity_check_extent_cache\n  : access et->largest w/o lock\n\nlet's refactor sanity_check_extent_cache() to avoid extent cache access\nand call it before f2fs_init_read_extent_tree() to fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-44941","epss":0.00211,"percentile":0.11352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-44941","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-44941","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-44942","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-44942","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC  syzbot reports a f2fs bug as below:  ------------[ cut here ]------------ kernel BUG at fs/f2fs/inline.c:258! CPU: 1 PID: 34 Comm: kworker/u8:2 Not tainted 6.9.0-rc6-syzkaller-00012-g9e4bc4bcae01 #0 RIP: 0010:f2fs_write_inline_data+0x781/0x790 fs/f2fs/inline.c:258 Call Trace:  f2fs_write_single_data_page+0xb65/0x1d60 fs/f2fs/data.c:2834  f2fs_write_cache_pages fs/f2fs/data.c:3133 [inline]  __f2fs_write_data_pages fs/f2fs/data.c:3288 [inline]  f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3315  do_writepages+0x35b/0x870 mm/page-writeback.c:2612  __writeback_single_inode+0x165/0x10b0 fs/fs-writeback.c:1650  writeback_sb_inodes+0x905/0x1260 fs/fs-writeback.c:1941  wb_writeback+0x457/0xce0 fs/fs-writeback.c:2117  wb_do_writeback fs/fs-writeback.c:2264 [inline]  wb_workfn+0x410/0x1090 fs/fs-writeback.c:2304  process_one_work kernel/workqueue.c:3254 [inline]  process_scheduled_works+0xa12/0x17c0 kernel/workqueue.c:3335  worker_thread+0x86d/0xd70 kernel/workqueue.c:3416  kthread+0x2f2/0x390 kernel/kthread.c:388  ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244  The root cause is: inline_data inode can be fuzzed, so that there may be valid blkaddr in its direct node, once f2fs triggers background GC to migrate the block, it will hit f2fs_bug_on() during dirty page writeback.  Let's add sanity check on F2FS_INLINE_DATA flag in inode during GC, so that, it can forbid migrating inline_data inode's data block for fixing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-44942","epss":0.00225,"percentile":0.13153,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.172125},"relatedVulnerabilities":[{"id":"CVE-2024-44942","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-44942","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/26c07775fb5dc74351d1c3a2bc3cdf609b03e49f","https://git.kernel.org/stable/c/ae00e6536a2dd54b64b39e9a39548870cf835745","https://git.kernel.org/stable/c/fc01008c92f40015aeeced94750855a7111b6929"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/inline.c:258!\nCPU: 1 PID: 34 Comm: kworker/u8:2 Not tainted 6.9.0-rc6-syzkaller-00012-g9e4bc4bcae01 #0\nRIP: 0010:f2fs_write_inline_data+0x781/0x790 fs/f2fs/inline.c:258\nCall Trace:\n f2fs_write_single_data_page+0xb65/0x1d60 fs/f2fs/data.c:2834\n f2fs_write_cache_pages fs/f2fs/data.c:3133 [inline]\n __f2fs_write_data_pages fs/f2fs/data.c:3288 [inline]\n f2fs_write_data_pages+0x1efe/0x3a90 fs/f2fs/data.c:3315\n do_writepages+0x35b/0x870 mm/page-writeback.c:2612\n __writeback_single_inode+0x165/0x10b0 fs/fs-writeback.c:1650\n writeback_sb_inodes+0x905/0x1260 fs/fs-writeback.c:1941\n wb_writeback+0x457/0xce0 fs/fs-writeback.c:2117\n wb_do_writeback fs/fs-writeback.c:2264 [inline]\n wb_workfn+0x410/0x1090 fs/fs-writeback.c:2304\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0xa12/0x17c0 kernel/workqueue.c:3335\n worker_thread+0x86d/0xd70 kernel/workqueue.c:3416\n kthread+0x2f2/0x390 kernel/kthread.c:388\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nThe root cause is: inline_data inode can be fuzzed, so that there may\nbe valid blkaddr in its direct node, once f2fs triggers background GC\nto migrate the block, it will hit f2fs_bug_on() during dirty page\nwriteback.\n\nLet's add sanity check on F2FS_INLINE_DATA flag in inode during GC,\nso that, it can forbid migrating inline_data inode's data block for\nfixing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-44942","epss":0.00225,"percentile":0.13153,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-44942","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-44951","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-44951","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  serial: sc16is7xx: fix TX fifo corruption  Sometimes, when a packet is received on channel A at almost the same time as a packet is about to be transmitted on channel B, we observe with a logic analyzer that the received packet on channel A is transmitted on channel B. In other words, the Tx buffer data on channel B is corrupted with data from channel A.  The problem appeared since commit 4409df5866b7 (\"serial: sc16is7xx: change EFR lock to operate on each channels\"), which changed the EFR locking to operate on each channel instead of chip-wise.  This commit has introduced a regression, because the EFR lock is used not only to protect the EFR registers access, but also, in a very obscure and undocumented way, to protect access to the data buffer, which is shared by the Tx and Rx handlers, but also by each channel of the IC.  Fix this regression first by switching to kfifo_out_linear_ptr() in sc16is7xx_handle_tx() to eliminate the need for a shared Rx/Tx buffer.  Secondly, replace the chip-wise Rx buffer with a separate Rx buffer for each channel.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-44951","epss":0.00181,"percentile":0.07772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-44951","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.138465},"relatedVulnerabilities":[{"id":"CVE-2024-44951","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-44951","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/09cfe05e9907f3276887a20e267cc40e202f4fdd","https://git.kernel.org/stable/c/133f4c00b8b2bfcacead9b81e7e8edfceb4b06c4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: sc16is7xx: fix TX fifo corruption\n\nSometimes, when a packet is received on channel A at almost the same time\nas a packet is about to be transmitted on channel B, we observe with a\nlogic analyzer that the received packet on channel A is transmitted on\nchannel B. In other words, the Tx buffer data on channel B is corrupted\nwith data from channel A.\n\nThe problem appeared since commit 4409df5866b7 (\"serial: sc16is7xx: change\nEFR lock to operate on each channels\"), which changed the EFR locking to\noperate on each channel instead of chip-wise.\n\nThis commit has introduced a regression, because the EFR lock is used not\nonly to protect the EFR registers access, but also, in a very obscure and\nundocumented way, to protect access to the data buffer, which is shared by\nthe Tx and Rx handlers, but also by each channel of the IC.\n\nFix this regression first by switching to kfifo_out_linear_ptr() in\nsc16is7xx_handle_tx() to eliminate the need for a shared Rx/Tx buffer.\n\nSecondly, replace the chip-wise Rx buffer with a separate Rx buffer for\neach channel.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-44951","epss":0.00181,"percentile":0.07772,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-44951","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-44951","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-44963","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-44963","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: do not BUG_ON() when freeing tree block after error  When freeing a tree block, at btrfs_free_tree_block(), if we fail to create a delayed reference we don't deal with the error and just do a BUG_ON(). The error most likely to happen is -ENOMEM, and we have a comment mentioning that only -ENOMEM can happen, but that is not true, because in case qgroups are enabled any error returned from btrfs_qgroup_trace_extent_post() (can be -EUCLEAN or anything returned from btrfs_search_slot() for example) can be propagated back to btrfs_free_tree_block().  So stop doing a BUG_ON() and return the error to the callers and make them abort the transaction to prevent leaking space. Syzbot was triggering this, likely due to memory allocation failure injection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-44963","epss":0.00239,"percentile":0.14918,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12547500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-44963","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-44963","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/22d907bcd283d69d5e60497fc0d51969545c583b","https://git.kernel.org/stable/c/98251cd60b4d702a8a81de442ab621e83a3fb24f","https://git.kernel.org/stable/c/bb3868033a4cccff7be57e9145f2117cbdc91c11"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not BUG_ON() when freeing tree block after error\n\nWhen freeing a tree block, at btrfs_free_tree_block(), if we fail to\ncreate a delayed reference we don't deal with the error and just do a\nBUG_ON(). The error most likely to happen is -ENOMEM, and we have a\ncomment mentioning that only -ENOMEM can happen, but that is not true,\nbecause in case qgroups are enabled any error returned from\nbtrfs_qgroup_trace_extent_post() (can be -EUCLEAN or anything returned\nfrom btrfs_search_slot() for example) can be propagated back to\nbtrfs_free_tree_block().\n\nSo stop doing a BUG_ON() and return the error to the callers and make\nthem abort the transaction to prevent leaking space. Syzbot was\ntriggering this, likely due to memory allocation failure injection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-44963","epss":0.00239,"percentile":0.14918,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-44963","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-45015","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-45015","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()  For cases where the crtc's connectors_changed was set without enable/active getting toggled , there is an atomic_enable() call followed by an atomic_disable() but without an atomic_mode_set().  This results in a NULL ptr access for the dpu_encoder_get_drm_fmt() call in the atomic_enable() as the dpu_encoder's connector was cleared in the atomic_disable() but not re-assigned as there was no atomic_mode_set() call.  Fix the NULL ptr access by moving the assignment for atomic_enable() and also use drm_atomic_get_new_connector_for_encoder() to get the connector from the atomic_state.  Patchwork: https://patchwork.freedesktop.org/patch/606729/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45015","epss":0.00208,"percentile":0.10979,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-45015","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10919999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-45015","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-45015","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3bacf814b6a61cc683c68465f175ebd938f09c52","https://git.kernel.org/stable/c/3fb61718bcbe309279205d1cc275a6435611dc77","https://git.kernel.org/stable/c/aedf02e46eb549dac8db4821a6b9f0c6bf6e3990"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()\n\nFor cases where the crtc's connectors_changed was set without enable/active\ngetting toggled , there is an atomic_enable() call followed by an\natomic_disable() but without an atomic_mode_set().\n\nThis results in a NULL ptr access for the dpu_encoder_get_drm_fmt() call in\nthe atomic_enable() as the dpu_encoder's connector was cleared in the\natomic_disable() but not re-assigned as there was no atomic_mode_set() call.\n\nFix the NULL ptr access by moving the assignment for atomic_enable() and also\nuse drm_atomic_get_new_connector_for_encoder() to get the connector from\nthe atomic_state.\n\nPatchwork: https://patchwork.freedesktop.org/patch/606729/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45015","epss":0.00208,"percentile":0.10979,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-45015","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-45015","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46678","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46678","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bonding: change ipsec_lock from spin lock to mutex  In the cited commit, bond->ipsec_lock is added to protect ipsec_list, hence xdo_dev_state_add and xdo_dev_state_delete are called inside this lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep, \"scheduling while atomic\" will be triggered when changing bond's active slave.  [  101.055189] BUG: scheduling while atomic: bash/902/0x00000200 [  101.055726] Modules linked in: [  101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1 [  101.058760] Hardware name: [  101.059434] Call Trace: [  101.059436]  <TASK> [  101.060873]  dump_stack_lvl+0x51/0x60 [  101.061275]  __schedule_bug+0x4e/0x60 [  101.061682]  __schedule+0x612/0x7c0 [  101.062078]  ? __mod_timer+0x25c/0x370 [  101.062486]  schedule+0x25/0xd0 [  101.062845]  schedule_timeout+0x77/0xf0 [  101.063265]  ? asm_common_interrupt+0x22/0x40 [  101.063724]  ? __bpf_trace_itimer_state+0x10/0x10 [  101.064215]  __wait_for_common+0x87/0x190 [  101.064648]  ? usleep_range_state+0x90/0x90 [  101.065091]  cmd_exec+0x437/0xb20 [mlx5_core] [  101.065569]  mlx5_cmd_do+0x1e/0x40 [mlx5_core] [  101.066051]  mlx5_cmd_exec+0x18/0x30 [mlx5_core] [  101.066552]  mlx5_crypto_create_dek_key+0xea/0x120 [mlx5_core] [  101.067163]  ? bonding_sysfs_store_option+0x4d/0x80 [bonding] [  101.067738]  ? kmalloc_trace+0x4d/0x350 [  101.068156]  mlx5_ipsec_create_sa_ctx+0x33/0x100 [mlx5_core] [  101.068747]  mlx5e_xfrm_add_state+0x47b/0xaa0 [mlx5_core] [  101.069312]  bond_change_active_slave+0x392/0x900 [bonding] [  101.069868]  bond_option_active_slave_set+0x1c2/0x240 [bonding] [  101.070454]  __bond_opt_set+0xa6/0x430 [bonding] [  101.070935]  __bond_opt_set_notify+0x2f/0x90 [bonding] [  101.071453]  bond_opt_tryset_rtnl+0x72/0xb0 [bonding] [  101.071965]  bonding_sysfs_store_option+0x4d/0x80 [bonding] [  101.072567]  kernfs_fop_write_iter+0x10c/0x1a0 [  101.073033]  vfs_write+0x2d8/0x400 [  101.073416]  ? alloc_fd+0x48/0x180 [  101.073798]  ksys_write+0x5f/0xe0 [  101.074175]  do_syscall_64+0x52/0x110 [  101.074576]  entry_SYSCALL_64_after_hwframe+0x4b/0x53  As bond_ipsec_add_sa_all and bond_ipsec_del_sa_all are only called from bond_change_active_slave, which requires holding the RTNL lock. And bond_ipsec_add_sa and bond_ipsec_del_sa are xfrm state xdo_dev_state_add and xdo_dev_state_delete APIs, which are in user context. So ipsec_lock doesn't have to be spin lock, change it to mutex, and thus the above issue can be resolved.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46678","epss":0.00174,"percentile":0.07065,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46678","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09135},"relatedVulnerabilities":[{"id":"CVE-2024-46678","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46678","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2aeeef906d5a526dc60cf4af92eda69836c39b1f","https://git.kernel.org/stable/c/56354b0a2c24a7828eeed7de4b4dc9652d9affa3","https://git.kernel.org/stable/c/6b598069164ac1bb60996d6ff94e7f9169dbd2d3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: change ipsec_lock from spin lock to mutex\n\nIn the cited commit, bond->ipsec_lock is added to protect ipsec_list,\nhence xdo_dev_state_add and xdo_dev_state_delete are called inside\nthis lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep,\n\"scheduling while atomic\" will be triggered when changing bond's\nactive slave.\n\n[  101.055189] BUG: scheduling while atomic: bash/902/0x00000200\n[  101.055726] Modules linked in:\n[  101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1\n[  101.058760] Hardware name:\n[  101.059434] Call Trace:\n[  101.059436]  <TASK>\n[  101.060873]  dump_stack_lvl+0x51/0x60\n[  101.061275]  __schedule_bug+0x4e/0x60\n[  101.061682]  __schedule+0x612/0x7c0\n[  101.062078]  ? __mod_timer+0x25c/0x370\n[  101.062486]  schedule+0x25/0xd0\n[  101.062845]  schedule_timeout+0x77/0xf0\n[  101.063265]  ? asm_common_interrupt+0x22/0x40\n[  101.063724]  ? __bpf_trace_itimer_state+0x10/0x10\n[  101.064215]  __wait_for_common+0x87/0x190\n[  101.064648]  ? usleep_range_state+0x90/0x90\n[  101.065091]  cmd_exec+0x437/0xb20 [mlx5_core]\n[  101.065569]  mlx5_cmd_do+0x1e/0x40 [mlx5_core]\n[  101.066051]  mlx5_cmd_exec+0x18/0x30 [mlx5_core]\n[  101.066552]  mlx5_crypto_create_dek_key+0xea/0x120 [mlx5_core]\n[  101.067163]  ? bonding_sysfs_store_option+0x4d/0x80 [bonding]\n[  101.067738]  ? kmalloc_trace+0x4d/0x350\n[  101.068156]  mlx5_ipsec_create_sa_ctx+0x33/0x100 [mlx5_core]\n[  101.068747]  mlx5e_xfrm_add_state+0x47b/0xaa0 [mlx5_core]\n[  101.069312]  bond_change_active_slave+0x392/0x900 [bonding]\n[  101.069868]  bond_option_active_slave_set+0x1c2/0x240 [bonding]\n[  101.070454]  __bond_opt_set+0xa6/0x430 [bonding]\n[  101.070935]  __bond_opt_set_notify+0x2f/0x90 [bonding]\n[  101.071453]  bond_opt_tryset_rtnl+0x72/0xb0 [bonding]\n[  101.071965]  bonding_sysfs_store_option+0x4d/0x80 [bonding]\n[  101.072567]  kernfs_fop_write_iter+0x10c/0x1a0\n[  101.073033]  vfs_write+0x2d8/0x400\n[  101.073416]  ? alloc_fd+0x48/0x180\n[  101.073798]  ksys_write+0x5f/0xe0\n[  101.074175]  do_syscall_64+0x52/0x110\n[  101.074576]  entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nAs bond_ipsec_add_sa_all and bond_ipsec_del_sa_all are only called\nfrom bond_change_active_slave, which requires holding the RTNL lock.\nAnd bond_ipsec_add_sa and bond_ipsec_del_sa are xfrm state\nxdo_dev_state_add and xdo_dev_state_delete APIs, which are in user\ncontext. So ipsec_lock doesn't have to be spin lock, change it to\nmutex, and thus the above issue can be resolved.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46678","epss":0.00174,"percentile":0.07065,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46678","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46678","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46681","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46681","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pktgen: use cpus_read_lock() in pg_net_init()  I have seen the WARN_ON(smp_processor_id() != cpu) firing in pktgen_thread_worker() during tests.  We must use cpus_read_lock()/cpus_read_unlock() around the for_each_online_cpu(cpu) loop.  While we are at it use WARN_ON_ONCE() to avoid a possible syslog flood.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46681","epss":0.00203,"percentile":0.10329,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2024-46681","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46681","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5f5f7366dda8ae870e8305d6e7b3c0c2686cd2cf","https://git.kernel.org/stable/c/979b581e4c69257acab1af415ddad6b2d78a2fa5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npktgen: use cpus_read_lock() in pg_net_init()\n\nI have seen the WARN_ON(smp_processor_id() != cpu) firing\nin pktgen_thread_worker() during tests.\n\nWe must use cpus_read_lock()/cpus_read_unlock()\naround the for_each_online_cpu(cpu) loop.\n\nWhile we are at it use WARN_ON_ONCE() to avoid a possible syslog flood.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46681","epss":0.00203,"percentile":0.10329,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46681","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46698","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46698","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  video/aperture: optionally match the device in sysfb_disable()  In aperture_remove_conflicting_pci_devices(), we currently only call sysfb_disable() on vga class devices.  This leads to the following problem when the pimary device is not VGA compatible:  1. A PCI device with a non-VGA class is the boot display 2. That device is probed first and it is not a VGA device so    sysfb_disable() is not called, but the device resources    are freed by aperture_detach_platform_device() 3. Non-primary GPU has a VGA class and it ends up calling sysfb_disable() 4. NULL pointer dereference via sysfb_disable() since the resources    have already been freed by aperture_detach_platform_device() when    it was called by the other device.  Fix this by passing a device pointer to sysfb_disable() and checking the device to determine if we should execute it or not.  v2: Fix build when CONFIG_SCREEN_INFO is not set v3: Move device check into the mutex     Drop primary variable in aperture_remove_conflicting_pci_devices()     Drop __init on pci sysfb_pci_dev_is_enabled()","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46698","epss":0.00189,"percentile":0.08652,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46698","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09922500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-46698","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46698","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/17e78f43de0c6da34204cc858b4cc05671ea9acf","https://git.kernel.org/stable/c/b49420d6a1aeb399e5b107fc6eb8584d0860fbd7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvideo/aperture: optionally match the device in sysfb_disable()\n\nIn aperture_remove_conflicting_pci_devices(), we currently only\ncall sysfb_disable() on vga class devices.  This leads to the\nfollowing problem when the pimary device is not VGA compatible:\n\n1. A PCI device with a non-VGA class is the boot display\n2. That device is probed first and it is not a VGA device so\n   sysfb_disable() is not called, but the device resources\n   are freed by aperture_detach_platform_device()\n3. Non-primary GPU has a VGA class and it ends up calling sysfb_disable()\n4. NULL pointer dereference via sysfb_disable() since the resources\n   have already been freed by aperture_detach_platform_device() when\n   it was called by the other device.\n\nFix this by passing a device pointer to sysfb_disable() and checking\nthe device to determine if we should execute it or not.\n\nv2: Fix build when CONFIG_SCREEN_INFO is not set\nv3: Move device check into the mutex\n    Drop primary variable in aperture_remove_conflicting_pci_devices()\n    Drop __init on pci sysfb_pci_dev_is_enabled()","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46698","epss":0.00189,"percentile":0.08652,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46698","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46698","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46727","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46727","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update  [Why] Coverity reports NULL_RETURN warning.  [How] Add otg_master NULL check.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46727","epss":0.00192,"percentile":0.08974,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46727","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1008},"relatedVulnerabilities":[{"id":"CVE-2024-46727","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46727","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/871cd9d881fa791d3f82885000713de07041c0ae","https://git.kernel.org/stable/c/aad4d3d3d3b6a362bf5db11e1f28c4a60620900d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add otg_master NULL check within resource_log_pipe_topology_update\n\n[Why]\nCoverity reports NULL_RETURN warning.\n\n[How]\nAdd otg_master NULL check.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46727","epss":0.00192,"percentile":0.08974,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46727","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46727","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46728","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46728","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Check index for aux_rd_interval before using  aux_rd_interval has size of 7 and should be checked.  This fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46728","epss":0.00219,"percentile":0.12309,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11497500000000002},"relatedVulnerabilities":[{"id":"CVE-2024-46728","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46728","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/48e0b68e2360b16edf2a0bae05c0051c00fbb48a","https://git.kernel.org/stable/c/6c588e9350dd7a9fb97a56fe74852c9ecc44450c","https://git.kernel.org/stable/c/9ba2ea6337b4f159aecb177555a6a81da92d302e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check index for aux_rd_interval before using\n\naux_rd_interval has size of 7 and should be checked.\n\nThis fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46728","epss":0.00219,"percentile":0.12309,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46728","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46729","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46729","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix incorrect size calculation for loop  [WHY] fe_clk_en has size of 5 but sizeof(fe_clk_en) has byte size 20 which is lager than the array size.  [HOW] Divide byte size 20 by its element size.  This fixes 2 OVERRUN issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46729","epss":0.00212,"percentile":0.11499,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46729","cwe":"CWE-131","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-46729","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16218000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-46729","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46729","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3941a3aa4b653b69876d894d08f3fff1cc965267","https://git.kernel.org/stable/c/712be65b3b372a82bff0865b9c090147764bf1c4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix incorrect size calculation for loop\n\n[WHY]\nfe_clk_en has size of 5 but sizeof(fe_clk_en) has byte size 20 which is\nlager than the array size.\n\n[HOW]\nDivide byte size 20 by its element size.\n\nThis fixes 2 OVERRUN issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46729","epss":0.00212,"percentile":0.11499,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46729","cwe":"CWE-131","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-46729","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46729","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46730","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46730","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Ensure array index tg_inst won't be -1  [WHY & HOW] tg_inst will be a negative if timing_generator_count equals 0, which should be checked before used.  This fixes 2 OVERRUN issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46730","epss":0.00202,"percentile":0.1019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46730","cwe":"CWE-191","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10605},"relatedVulnerabilities":[{"id":"CVE-2024-46730","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46730","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/687fe329f18ab0ab0496b20ed2cb003d4879d931","https://git.kernel.org/stable/c/a64284b9e1999ad5580debced4bc6d6adb28aad4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Ensure array index tg_inst won't be -1\n\n[WHY & HOW]\ntg_inst will be a negative if timing_generator_count equals 0, which\nshould be checked before used.\n\nThis fixes 2 OVERRUN issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46730","epss":0.00202,"percentile":0.1019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46730","cwe":"CWE-191","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46730","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46754","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46754","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Remove tst_run from lwt_seg6local_prog_ops.  The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input_action_end_bpf() first.  Martin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL probably didn't work since it was introduced in commit 04d4b274e2a (\"ipv6: sr: Add seg6local action End.BPF\"). The reason is that the per-CPU variable seg6_bpf_srh_states::srh is never assigned in the self test case but each BPF function expects it.  Remove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46754","epss":0.00247,"percentile":0.16007,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12967499999999998},"relatedVulnerabilities":[{"id":"CVE-2024-46754","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46754","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/9cd15511de7c619bbd0f54bb3f28e6e720ded5d6","https://git.kernel.org/stable/c/a675524cfbe88fd49c05ff8807a08646983e687c","https://git.kernel.org/stable/c/b05c2e25a5c168dbb46b6f7fcb741fd4e4f3b54a","https://git.kernel.org/stable/c/c13fda93aca118b8e5cd202e339046728ee7dddb","https://git.kernel.org/stable/c/e217492f6fa2228ad703ee3006d8fc4e5969fbd4","https://git.kernel.org/stable/c/ea3fae6984ba0f054550e4da22219489c12cd8d4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Remove tst_run from lwt_seg6local_prog_ops.\n\nThe syzbot reported that the lwt_seg6 related BPF ops can be invoked\nvia bpf_test_run() without without entering input_action_end_bpf()\nfirst.\n\nMartin KaFai Lau said that self test for BPF_PROG_TYPE_LWT_SEG6LOCAL\nprobably didn't work since it was introduced in commit 04d4b274e2a\n(\"ipv6: sr: Add seg6local action End.BPF\"). The reason is that the\nper-CPU variable seg6_bpf_srh_states::srh is never assigned in the self\ntest case but each BPF function expects it.\n\nRemove test_run for BPF_PROG_TYPE_LWT_SEG6LOCAL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46754","epss":0.00247,"percentile":0.16007,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46754","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46760","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46760","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw88: usb: schedule rx work after everything is set up  Right now it's possible to hit NULL pointer dereference in rtw_rx_fill_rx_status on hw object and/or its fields because initialization routine can start getting USB replies before rtw_dev is fully setup.  The stack trace looks like this:  rtw_rx_fill_rx_status rtw8821c_query_rx_desc rtw_usb_rx_handler ... queue_work rtw_usb_read_port_complete ... usb_submit_urb rtw_usb_rx_resubmit rtw_usb_init_rx rtw_usb_probe  So while we do the async stuff rtw_usb_probe continues and calls rtw_register_hw, which does all kinds of initialization (e.g. via ieee80211_register_hw) that rtw_rx_fill_rx_status relies on.  Fix this by moving the first usb_submit_urb after everything is set up.  For me, this bug manifested as: [    8.893177] rtw_8821cu 1-1:1.2: band wrong, packet dropped [    8.910904] rtw_8821cu 1-1:1.2: hw->conf.chandef.chan NULL in rtw_rx_fill_rx_status because I'm using Larry's backport of rtw88 driver with the NULL checks in rtw_rx_fill_rx_status.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46760","epss":0.00234,"percentile":0.14343,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46760","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12285},"relatedVulnerabilities":[{"id":"CVE-2024-46760","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46760","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/25eaef533bf3ccc6fee5067aac16f41f280e343e","https://git.kernel.org/stable/c/adc539784c98a7cc602cbf557debfc2e7b9be8b3","https://git.kernel.org/stable/c/c83d464b82a8ad62ec9077637f75d73fe955635a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: usb: schedule rx work after everything is set up\n\nRight now it's possible to hit NULL pointer dereference in\nrtw_rx_fill_rx_status on hw object and/or its fields because\ninitialization routine can start getting USB replies before\nrtw_dev is fully setup.\n\nThe stack trace looks like this:\n\nrtw_rx_fill_rx_status\nrtw8821c_query_rx_desc\nrtw_usb_rx_handler\n...\nqueue_work\nrtw_usb_read_port_complete\n...\nusb_submit_urb\nrtw_usb_rx_resubmit\nrtw_usb_init_rx\nrtw_usb_probe\n\nSo while we do the async stuff rtw_usb_probe continues and calls\nrtw_register_hw, which does all kinds of initialization (e.g.\nvia ieee80211_register_hw) that rtw_rx_fill_rx_status relies on.\n\nFix this by moving the first usb_submit_urb after everything\nis set up.\n\nFor me, this bug manifested as:\n[    8.893177] rtw_8821cu 1-1:1.2: band wrong, packet dropped\n[    8.910904] rtw_8821cu 1-1:1.2: hw->conf.chandef.chan NULL in rtw_rx_fill_rx_status\nbecause I'm using Larry's backport of rtw88 driver with the NULL\nchecks in rtw_rx_fill_rx_status.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46760","epss":0.00234,"percentile":0.14343,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46760","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46760","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46765","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46765","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ice: protect XDP configuration with a mutex  The main threat to data consistency in ice_xdp() is a possible asynchronous PF reset. It can be triggered by a user or by TX timeout handler.  XDP setup and PF reset code access the same resources in the following sections: * ice_vsi_close() in ice_prepare_for_reset() - already rtnl-locked * ice_vsi_rebuild() for the PF VSI - not protected * ice_vsi_open() - already rtnl-locked  With an unfortunate timing, such accesses can result in a crash such as the one below:  [ +1.999878] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 14 [ +2.002992] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 18 [Mar15 18:17] ice 0000:b1:00.0 ens801f0np0: NETDEV WATCHDOG: CPU: 38: transmit queue 14 timed out 80692736 ms [ +0.000093] ice 0000:b1:00.0 ens801f0np0: tx_timeout: VSI_num: 6, Q 14, NTC: 0x0, HW_HEAD: 0x0, NTU: 0x0, INT: 0x4000001 [ +0.000012] ice 0000:b1:00.0 ens801f0np0: tx_timeout recovery level 1, txqueue 14 [ +0.394718] ice 0000:b1:00.0: PTP reset successful [ +0.006184] BUG: kernel NULL pointer dereference, address: 0000000000000098 [ +0.000045] #PF: supervisor read access in kernel mode [ +0.000023] #PF: error_code(0x0000) - not-present page [ +0.000023] PGD 0 P4D 0 [ +0.000018] Oops: 0000 [#1] PREEMPT SMP NOPTI [ +0.000023] CPU: 38 PID: 7540 Comm: kworker/38:1 Not tainted 6.8.0-rc7 #1 [ +0.000031] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021 [ +0.000036] Workqueue: ice ice_service_task [ice] [ +0.000183] RIP: 0010:ice_clean_tx_ring+0xa/0xd0 [ice] [...] [ +0.000013] Call Trace: [ +0.000016] <TASK> [ +0.000014] ? __die+0x1f/0x70 [ +0.000029] ? page_fault_oops+0x171/0x4f0 [ +0.000029] ? schedule+0x3b/0xd0 [ +0.000027] ? exc_page_fault+0x7b/0x180 [ +0.000022] ? asm_exc_page_fault+0x22/0x30 [ +0.000031] ? ice_clean_tx_ring+0xa/0xd0 [ice] [ +0.000194] ice_free_tx_ring+0xe/0x60 [ice] [ +0.000186] ice_destroy_xdp_rings+0x157/0x310 [ice] [ +0.000151] ice_vsi_decfg+0x53/0xe0 [ice] [ +0.000180] ice_vsi_rebuild+0x239/0x540 [ice] [ +0.000186] ice_vsi_rebuild_by_type+0x76/0x180 [ice] [ +0.000145] ice_rebuild+0x18c/0x840 [ice] [ +0.000145] ? delay_tsc+0x4a/0xc0 [ +0.000022] ? delay_tsc+0x92/0xc0 [ +0.000020] ice_do_reset+0x140/0x180 [ice] [ +0.000886] ice_service_task+0x404/0x1030 [ice] [ +0.000824] process_one_work+0x171/0x340 [ +0.000685] worker_thread+0x277/0x3a0 [ +0.000675] ? preempt_count_add+0x6a/0xa0 [ +0.000677] ? _raw_spin_lock_irqsave+0x23/0x50 [ +0.000679] ? __pfx_worker_thread+0x10/0x10 [ +0.000653] kthread+0xf0/0x120 [ +0.000635] ? __pfx_kthread+0x10/0x10 [ +0.000616] ret_from_fork+0x2d/0x50 [ +0.000612] ? __pfx_kthread+0x10/0x10 [ +0.000604] ret_from_fork_asm+0x1b/0x30 [ +0.000604] </TASK>  The previous way of handling this through returning -EBUSY is not viable, particularly when destroying AF_XDP socket, because the kernel proceeds with removal anyway.  There is plenty of code between those calls and there is no need to create a large critical section that covers all of them, same as there is no need to protect ice_vsi_rebuild() with rtnl_lock().  Add xdp_state_lock mutex to protect ice_vsi_rebuild() and ice_xdp().  Leaving unprotected sections in between would result in two states that have to be considered: 1. when the VSI is closed, but not yet rebuild 2. when VSI is already rebuild, but not yet open  The latter case is actually already handled through !netif_running() case, we just need to adjust flag checking a little. The former one is not as trivial, because between ice_vsi_close() and ice_vsi_rebuild(), a lot of hardware interaction happens, this can make adding/deleting rings exit with an error. Luckily, VSI rebuild is pending and can apply new configuration for us in a managed fashion.  Therefore, add an additional VSI state flag ICE_VSI_REBUILD_PENDING to indicate that ice_x ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46765","epss":0.00244,"percentile":0.15596,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46765","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1281},"relatedVulnerabilities":[{"id":"CVE-2024-46765","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46765","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2504b8405768a57a71e660dbfd5abd59f679a03f","https://git.kernel.org/stable/c/2f057db2fb29bc209c103050647562e60554d3d3","https://git.kernel.org/stable/c/391f7dae3d836891fc6cfbde38add2d0e10c6b7f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nice: protect XDP configuration with a mutex\n\nThe main threat to data consistency in ice_xdp() is a possible asynchronous\nPF reset. It can be triggered by a user or by TX timeout handler.\n\nXDP setup and PF reset code access the same resources in the following\nsections:\n* ice_vsi_close() in ice_prepare_for_reset() - already rtnl-locked\n* ice_vsi_rebuild() for the PF VSI - not protected\n* ice_vsi_open() - already rtnl-locked\n\nWith an unfortunate timing, such accesses can result in a crash such as the\none below:\n\n[ +1.999878] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 14\n[ +2.002992] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 18\n[Mar15 18:17] ice 0000:b1:00.0 ens801f0np0: NETDEV WATCHDOG: CPU: 38: transmit queue 14 timed out 80692736 ms\n[ +0.000093] ice 0000:b1:00.0 ens801f0np0: tx_timeout: VSI_num: 6, Q 14, NTC: 0x0, HW_HEAD: 0x0, NTU: 0x0, INT: 0x4000001\n[ +0.000012] ice 0000:b1:00.0 ens801f0np0: tx_timeout recovery level 1, txqueue 14\n[ +0.394718] ice 0000:b1:00.0: PTP reset successful\n[ +0.006184] BUG: kernel NULL pointer dereference, address: 0000000000000098\n[ +0.000045] #PF: supervisor read access in kernel mode\n[ +0.000023] #PF: error_code(0x0000) - not-present page\n[ +0.000023] PGD 0 P4D 0\n[ +0.000018] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ +0.000023] CPU: 38 PID: 7540 Comm: kworker/38:1 Not tainted 6.8.0-rc7 #1\n[ +0.000031] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021\n[ +0.000036] Workqueue: ice ice_service_task [ice]\n[ +0.000183] RIP: 0010:ice_clean_tx_ring+0xa/0xd0 [ice]\n[...]\n[ +0.000013] Call Trace:\n[ +0.000016] <TASK>\n[ +0.000014] ? __die+0x1f/0x70\n[ +0.000029] ? page_fault_oops+0x171/0x4f0\n[ +0.000029] ? schedule+0x3b/0xd0\n[ +0.000027] ? exc_page_fault+0x7b/0x180\n[ +0.000022] ? asm_exc_page_fault+0x22/0x30\n[ +0.000031] ? ice_clean_tx_ring+0xa/0xd0 [ice]\n[ +0.000194] ice_free_tx_ring+0xe/0x60 [ice]\n[ +0.000186] ice_destroy_xdp_rings+0x157/0x310 [ice]\n[ +0.000151] ice_vsi_decfg+0x53/0xe0 [ice]\n[ +0.000180] ice_vsi_rebuild+0x239/0x540 [ice]\n[ +0.000186] ice_vsi_rebuild_by_type+0x76/0x180 [ice]\n[ +0.000145] ice_rebuild+0x18c/0x840 [ice]\n[ +0.000145] ? delay_tsc+0x4a/0xc0\n[ +0.000022] ? delay_tsc+0x92/0xc0\n[ +0.000020] ice_do_reset+0x140/0x180 [ice]\n[ +0.000886] ice_service_task+0x404/0x1030 [ice]\n[ +0.000824] process_one_work+0x171/0x340\n[ +0.000685] worker_thread+0x277/0x3a0\n[ +0.000675] ? preempt_count_add+0x6a/0xa0\n[ +0.000677] ? _raw_spin_lock_irqsave+0x23/0x50\n[ +0.000679] ? __pfx_worker_thread+0x10/0x10\n[ +0.000653] kthread+0xf0/0x120\n[ +0.000635] ? __pfx_kthread+0x10/0x10\n[ +0.000616] ret_from_fork+0x2d/0x50\n[ +0.000612] ? __pfx_kthread+0x10/0x10\n[ +0.000604] ret_from_fork_asm+0x1b/0x30\n[ +0.000604] </TASK>\n\nThe previous way of handling this through returning -EBUSY is not viable,\nparticularly when destroying AF_XDP socket, because the kernel proceeds\nwith removal anyway.\n\nThere is plenty of code between those calls and there is no need to create\na large critical section that covers all of them, same as there is no need\nto protect ice_vsi_rebuild() with rtnl_lock().\n\nAdd xdp_state_lock mutex to protect ice_vsi_rebuild() and ice_xdp().\n\nLeaving unprotected sections in between would result in two states that\nhave to be considered:\n1. when the VSI is closed, but not yet rebuild\n2. when VSI is already rebuild, but not yet open\n\nThe latter case is actually already handled through !netif_running() case,\nwe just need to adjust flag checking a little. The former one is not as\ntrivial, because between ice_vsi_close() and ice_vsi_rebuild(), a lot of\nhardware interaction happens, this can make adding/deleting rings exit\nwith an error. Luckily, VSI rebuild is pending and can apply new\nconfiguration for us in a managed fashion.\n\nTherefore, add an additional VSI state flag ICE_VSI_REBUILD_PENDING to\nindicate that ice_x\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46765","epss":0.00244,"percentile":0.15596,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46765","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46765","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46775","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46775","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Validate function returns  [WHAT & HOW] Function return values must be checked before data can be used in subsequent functions.  This fixes 4 CHECKED_RETURN issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46775","epss":0.00194,"percentile":0.09252,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10185000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-46775","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46775","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5639a3048c7079803256374204ad55ec52cd0b49","https://git.kernel.org/stable/c/673f816b9e1e92d1f70e1bf5f21b531e0ff9ad6c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Validate function returns\n\n[WHAT & HOW]\nFunction return values must be checked before data can be used\nin subsequent functions.\n\nThis fixes 4 CHECKED_RETURN issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46775","epss":0.00194,"percentile":0.09252,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46775","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46776","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46776","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Run DC_LOG_DC after checking link->link_enc  [WHAT] The DC_LOG_DC should be run after link->link_enc is checked, not before.  This fixes 1 REVERSE_INULL issue reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46776","epss":0.00235,"percentile":0.14387,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46776","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.123375},"relatedVulnerabilities":[{"id":"CVE-2024-46776","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46776","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3a82f62b0d9d7687eac47603bb6cd14a50fa718b","https://git.kernel.org/stable/c/874e3bb302f97b94ac548959ec4f925b8e7b45e2","https://git.kernel.org/stable/c/adc74d25cdbba978afbb57caec23bbcd0329f7b8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Run DC_LOG_DC after checking link->link_enc\n\n[WHAT]\nThe DC_LOG_DC should be run after link->link_enc is checked, not before.\n\nThis fixes 1 REVERSE_INULL issue reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46776","epss":0.00235,"percentile":0.14387,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46776","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46776","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46787","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46787","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  userfaultfd: fix checks for huge PMDs  Patch series \"userfaultfd: fix races around pmd_trans_huge() check\", v2.  The pmd_trans_huge() code in mfill_atomic() is wrong in three different ways depending on kernel version:  1. The pmd_trans_huge() check is racy and can lead to a BUG_ON() (if you hit    the right two race windows) - I've tested this in a kernel build with    some extra mdelay() calls. See the commit message for a description    of the race scenario.    On older kernels (before 6.5), I think the same bug can even    theoretically lead to accessing transhuge page contents as a page table    if you hit the right 5 narrow race windows (I haven't tested this case). 2. As pointed out by Qi Zheng, pmd_trans_huge() is not sufficient for    detecting PMDs that don't point to page tables.    On older kernels (before 6.5), you'd just have to win a single fairly    wide race to hit this.    I've tested this on 6.1 stable by racing migration (with a mdelay()    patched into try_to_migrate()) against UFFDIO_ZEROPAGE - on my x86    VM, that causes a kernel oops in ptlock_ptr(). 3. On newer kernels (>=6.5), for shmem mappings, khugepaged is allowed    to yank page tables out from under us (though I haven't tested that),    so I think the BUG_ON() checks in mfill_atomic() are just wrong.  I decided to write two separate fixes for these (one fix for bugs 1+2, one fix for bug 3), so that the first fix can be backported to kernels affected by bugs 1+2.   This patch (of 2):  This fixes two issues.  I discovered that the following race can occur:    mfill_atomic                other thread   ============                ============                               <zap PMD>   pmdp_get_lockless() [reads none pmd]   <bail if trans_huge>   <if none:>                               <pagefault creates transhuge zeropage>     __pte_alloc [no-op]                               <zap PMD>   <bail if pmd_trans_huge(*dst_pmd)>   BUG_ON(pmd_none(*dst_pmd))  I have experimentally verified this in a kernel with extra mdelay() calls; the BUG_ON(pmd_none(*dst_pmd)) triggers.  On kernels newer than commit 0d940a9b270b (\"mm/pgtable: allow pte_offset_map[_lock]() to fail\"), this can't lead to anything worse than a BUG_ON(), since the page table access helpers are actually designed to deal with page tables concurrently disappearing; but on older kernels (<=6.4), I think we could probably theoretically race past the two BUG_ON() checks and end up treating a hugepage as a page table.  The second issue is that, as Qi Zheng pointed out, there are other types of huge PMDs that pmd_trans_huge() can't catch: devmap PMDs and swap PMDs (in particular, migration PMDs).  On <=6.4, this is worse than the first issue: If mfill_atomic() runs on a PMD that contains a migration entry (which just requires winning a single, fairly wide race), it will pass the PMD to pte_offset_map_lock(), which assumes that the PMD points to a page table.  Breakage follows: First, the kernel tries to take the PTE lock (which will crash or maybe worse if there is no \"struct page\" for the address bits in the migration entry PMD - I think at least on X86 there usually is no corresponding \"struct page\" thanks to the PTE inversion mitigation, amd64 looks different).  If that didn't crash, the kernel would next try to write a PTE into what it wrongly thinks is a page table.  As part of fixing these issues, get rid of the check for pmd_trans_huge() before __pte_alloc() - that's redundant, we're going to have to check for that after the __pte_alloc() anyway.  Backport note: pmdp_get_lockless() is pmd_read_atomic() in older kernels.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46787","epss":0.0022,"percentile":0.12524,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1067},"relatedVulnerabilities":[{"id":"CVE-2024-46787","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46787","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3c6b4bcf37845c9359aed926324bed66bdd2448d","https://git.kernel.org/stable/c/71c186efc1b2cf1aeabfeff3b9bd5ac4c5ac14d8","https://git.kernel.org/stable/c/98cc18b1b71e23fe81a5194ed432b20c2d81a01a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: fix checks for huge PMDs\n\nPatch series \"userfaultfd: fix races around pmd_trans_huge() check\", v2.\n\nThe pmd_trans_huge() code in mfill_atomic() is wrong in three different\nways depending on kernel version:\n\n1. The pmd_trans_huge() check is racy and can lead to a BUG_ON() (if you hit\n   the right two race windows) - I've tested this in a kernel build with\n   some extra mdelay() calls. See the commit message for a description\n   of the race scenario.\n   On older kernels (before 6.5), I think the same bug can even\n   theoretically lead to accessing transhuge page contents as a page table\n   if you hit the right 5 narrow race windows (I haven't tested this case).\n2. As pointed out by Qi Zheng, pmd_trans_huge() is not sufficient for\n   detecting PMDs that don't point to page tables.\n   On older kernels (before 6.5), you'd just have to win a single fairly\n   wide race to hit this.\n   I've tested this on 6.1 stable by racing migration (with a mdelay()\n   patched into try_to_migrate()) against UFFDIO_ZEROPAGE - on my x86\n   VM, that causes a kernel oops in ptlock_ptr().\n3. On newer kernels (>=6.5), for shmem mappings, khugepaged is allowed\n   to yank page tables out from under us (though I haven't tested that),\n   so I think the BUG_ON() checks in mfill_atomic() are just wrong.\n\nI decided to write two separate fixes for these (one fix for bugs 1+2, one\nfix for bug 3), so that the first fix can be backported to kernels\naffected by bugs 1+2.\n\n\nThis patch (of 2):\n\nThis fixes two issues.\n\nI discovered that the following race can occur:\n\n  mfill_atomic                other thread\n  ============                ============\n                              <zap PMD>\n  pmdp_get_lockless() [reads none pmd]\n  <bail if trans_huge>\n  <if none:>\n                              <pagefault creates transhuge zeropage>\n    __pte_alloc [no-op]\n                              <zap PMD>\n  <bail if pmd_trans_huge(*dst_pmd)>\n  BUG_ON(pmd_none(*dst_pmd))\n\nI have experimentally verified this in a kernel with extra mdelay() calls;\nthe BUG_ON(pmd_none(*dst_pmd)) triggers.\n\nOn kernels newer than commit 0d940a9b270b (\"mm/pgtable: allow\npte_offset_map[_lock]() to fail\"), this can't lead to anything worse than\na BUG_ON(), since the page table access helpers are actually designed to\ndeal with page tables concurrently disappearing; but on older kernels\n(<=6.4), I think we could probably theoretically race past the two\nBUG_ON() checks and end up treating a hugepage as a page table.\n\nThe second issue is that, as Qi Zheng pointed out, there are other types\nof huge PMDs that pmd_trans_huge() can't catch: devmap PMDs and swap PMDs\n(in particular, migration PMDs).\n\nOn <=6.4, this is worse than the first issue: If mfill_atomic() runs on a\nPMD that contains a migration entry (which just requires winning a single,\nfairly wide race), it will pass the PMD to pte_offset_map_lock(), which\nassumes that the PMD points to a page table.\n\nBreakage follows: First, the kernel tries to take the PTE lock (which will\ncrash or maybe worse if there is no \"struct page\" for the address bits in\nthe migration entry PMD - I think at least on X86 there usually is no\ncorresponding \"struct page\" thanks to the PTE inversion mitigation, amd64\nlooks different).\n\nIf that didn't crash, the kernel would next try to write a PTE into what\nit wrongly thinks is a page table.\n\nAs part of fixing these issues, get rid of the check for pmd_trans_huge()\nbefore __pte_alloc() - that's redundant, we're going to have to check for\nthat after the __pte_alloc() anyway.\n\nBackport note: pmdp_get_lockless() is pmd_read_atomic() in older kernels.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46787","epss":0.0022,"percentile":0.12524,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46787","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Fix the warning division or modulo by zero  Checks the partition mode and returns an error for an invalid mode.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46806","epss":0.00235,"percentile":0.14387,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46806","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.123375},"relatedVulnerabilities":[{"id":"CVE-2024-46806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46806","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1a00f2ac82d6bc6689388c7edcd2a4bd82664f3c","https://git.kernel.org/stable/c/a01618adcba78c6bd6c4557a4a5e32f58b658cd1","https://git.kernel.org/stable/c/d116bb921e8b104f45d1f30a473ea99ef4262b9a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix the warning division or modulo by zero\n\nChecks the partition mode and returns an error for an invalid mode.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46806","epss":0.00235,"percentile":0.14387,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46806","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46808","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46808","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range  [Why & How] ASSERT if return NULL from kcalloc.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46808","epss":0.00204,"percentile":0.10378,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46808","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10710000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-46808","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46808","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5524fa301ba649f8cf00848f91468e0ba7e4f24c","https://git.kernel.org/stable/c/ca0b0b0a22306f2e51105ac48f4a09c2fbbb504e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range\n\n[Why & How]\nASSERT if return NULL from kcalloc.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46808","epss":0.00204,"percentile":0.10378,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46808","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46808","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46811","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46811","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box  [Why] Coverity reports OVERRUN warning. soc.num_states could be 40. But array range of bw_params->clk_table.entries is 8.  [How] Assert if soc.num_states greater than 8.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46811","epss":0.00246,"percentile":0.15912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46811","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18819},"relatedVulnerabilities":[{"id":"CVE-2024-46811","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46811","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/188fd1616ec43033cedbe343b6579e9921e2d898","https://git.kernel.org/stable/c/4003bac784380fed1f94f197350567eaa73a409d","https://git.kernel.org/stable/c/aba188d6f4ebaf52acf13f204db2bd2c22072504"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box\n\n[Why]\nCoverity reports OVERRUN warning. soc.num_states could\nbe 40. But array range of bw_params->clk_table.entries is 8.\n\n[How]\nAssert if soc.num_states greater than 8.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46811","epss":0.00246,"percentile":0.15912,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46811","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46811","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46813","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46813","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Check link_index before accessing dc->links[]  [WHY & HOW] dc->links[] has max size of MAX_LINKS and NULL is return when trying to access with out-of-bound index.  This fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46813","epss":0.00255,"percentile":0.17044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46813","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19507500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-46813","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46813","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/032c5407a608ac3b2a98bf4fbda27d12c20c5887","https://git.kernel.org/stable/c/8aa2864044b9d13e95fe224f32e808afbf79ecdf","https://git.kernel.org/stable/c/ac04759b4a002969cf0f1384f1b8bb2001cfa782"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check link_index before accessing dc->links[]\n\n[WHY & HOW]\ndc->links[] has max size of MAX_LINKS and NULL is return when trying to\naccess with out-of-bound index.\n\nThis fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46813","epss":0.00255,"percentile":0.17044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46813","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46813","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46834","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46834","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ethtool: fail closed if we can't get max channel used in indirection tables  Commit 0d1b7d6c9274 (\"bnxt: fix crashes when reducing ring count with active RSS contexts\") proves that allowing indirection table to contain channels with out of bounds IDs may lead to crashes. Currently the max channel check in the core gets skipped if driver can't fetch the indirection table or when we can't allocate memory.  Both of those conditions should be extremely rare but if they do happen we should try to be safe and fail the channel change.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46834","epss":0.00217,"percentile":0.12088,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11392500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-46834","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46834","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/101737d8b88dbd4be6010bac398fe810f1950036","https://git.kernel.org/stable/c/2899d58462ba868287d6ff3acad3675e7adf934f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: fail closed if we can't get max channel used in indirection tables\n\nCommit 0d1b7d6c9274 (\"bnxt: fix crashes when reducing ring count with\nactive RSS contexts\") proves that allowing indirection table to contain\nchannels with out of bounds IDs may lead to crashes. Currently the\nmax channel check in the core gets skipped if driver can't fetch\nthe indirection table or when we can't allocate memory.\n\nBoth of those conditions should be extremely rare but if they do\nhappen we should try to be safe and fail the channel change.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46834","epss":0.00217,"percentile":0.12088,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46834","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46860","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46860","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change  When disabling wifi mt7921_ipv6_addr_change() is called as a notifier. At this point mvif->phy is already NULL so we cannot use it here.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46860","epss":0.00206,"percentile":0.10724,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46860","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-46860","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46860","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/479ffee68d59c599f8aed8fa2dcc8e13e7bd13c3","https://git.kernel.org/stable/c/4bfee9346d8c17d928ef6da2b8bffab88fa2a553","https://git.kernel.org/stable/c/8d92bafd4c67efb692f722d73a07412b5f88c6d6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change\n\nWhen disabling wifi mt7921_ipv6_addr_change() is called as a notifier.\nAt this point mvif->phy is already NULL so we cannot use it here.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46860","epss":0.00206,"percentile":0.10724,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46860","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46860","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-46870","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-46870","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Disable DMCUB timeout for DCN35  [Why] DMCUB can intermittently take longer than expected to process commands.  Old ASIC policy was to continue while logging a diagnostic error - which works fine for ASIC without IPS, but with IPS this could lead to a race condition where we attempt to access DCN state while it's inaccessible, leading to a system hang when the NIU port is not disabled or register accesses that timeout and the display configuration in an undefined state.  [How] We need to investigate why these accesses take longer than expected, but for now we should disable the timeout on DCN35 to avoid this race condition. Since the waits happen only at lower interrupt levels the risk of taking too long at higher IRQ and causing a system watchdog timeout are minimal.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46870","epss":0.00131,"percentile":0.03068,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46870","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063535},"relatedVulnerabilities":[{"id":"CVE-2024-46870","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-46870","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/31c254c9cd4b122a10db297124f867107a696d83","https://git.kernel.org/stable/c/7c70e60fbf4bff1123f0e8d5cb1ae71df6164d7f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Disable DMCUB timeout for DCN35\n\n[Why]\nDMCUB can intermittently take longer than expected to process commands.\n\nOld ASIC policy was to continue while logging a diagnostic error - which\nworks fine for ASIC without IPS, but with IPS this could lead to a race\ncondition where we attempt to access DCN state while it's inaccessible,\nleading to a system hang when the NIU port is not disabled or register\naccesses that timeout and the display configuration in an undefined\nstate.\n\n[How]\nWe need to investigate why these accesses take longer than expected, but\nfor now we should disable the timeout on DCN35 to avoid this race\ncondition. Since the waits happen only at lower interrupt levels the\nrisk of taking too long at higher IRQ and causing a system watchdog\ntimeout are minimal.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-46870","epss":0.00131,"percentile":0.03068,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-46870","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-46870","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47141","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pinmux: Use sequential access to access desc->pinmux data  When two client of the same gpio call pinctrl_select_state() for the same functionality, we are seeing NULL pointer issue while accessing desc->mux_owner.  Let's say two processes A, B executing in pin_request() for the same pin and process A updates the desc->mux_usecount but not yet updated the desc->mux_owner while process B see the desc->mux_usecount which got updated by A path and further executes strcmp and while accessing desc->mux_owner it crashes with NULL pointer.  Serialize the access to mux related setting with a mutex lock.  \tcpu0 (process A)\t\t\tcpu1(process B)  pinctrl_select_state() {\t\t  pinctrl_select_state() {   pin_request() {\t\t\t\tpin_request() {   ... \t\t\t\t\t\t ....     } else {          desc->mux_usecount++;     \t\t\t\t\t\tdesc->mux_usecount && strcmp(desc->mux_owner, owner)) {           if (desc->mux_usecount > 1)                return 0;          desc->mux_owner = owner;    }\t\t\t\t\t\t}","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47141","epss":0.00173,"percentile":0.06828,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47141","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-47141","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.090825},"relatedVulnerabilities":[{"id":"CVE-2024-47141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47141","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2da32aed4a97ca1d70fb8b77926f72f30ce5fb4b","https://git.kernel.org/stable/c/5a3e85c3c397c781393ea5fb2f45b1f60f8a4e6e","https://git.kernel.org/stable/c/c11e2ec9a780f54982a187ee10ffd1b810715c85"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npinmux: Use sequential access to access desc->pinmux data\n\nWhen two client of the same gpio call pinctrl_select_state() for the\nsame functionality, we are seeing NULL pointer issue while accessing\ndesc->mux_owner.\n\nLet's say two processes A, B executing in pin_request() for the same pin\nand process A updates the desc->mux_usecount but not yet updated the\ndesc->mux_owner while process B see the desc->mux_usecount which got\nupdated by A path and further executes strcmp and while accessing\ndesc->mux_owner it crashes with NULL pointer.\n\nSerialize the access to mux related setting with a mutex lock.\n\n\tcpu0 (process A)\t\t\tcpu1(process B)\n\npinctrl_select_state() {\t\t  pinctrl_select_state() {\n  pin_request() {\t\t\t\tpin_request() {\n  ...\n\t\t\t\t\t\t ....\n    } else {\n         desc->mux_usecount++;\n    \t\t\t\t\t\tdesc->mux_usecount && strcmp(desc->mux_owner, owner)) {\n\n         if (desc->mux_usecount > 1)\n               return 0;\n         desc->mux_owner = owner;\n\n  }\t\t\t\t\t\t}","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47141","epss":0.00173,"percentile":0.06828,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47141","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-47141","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47141","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47658","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47658","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: stm32/cryp - call finalize with bh disabled  The finalize operation in interrupt mode produce a produces a spinlock recursion warning. The reason is the fact that BH must be disabled during this process.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47658","epss":0.00469,"percentile":0.39134,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.246225},"relatedVulnerabilities":[{"id":"CVE-2024-47658","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47658","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/56ddb9aa3b324c2d9645b5a7343e46010cf3f6ce","https://git.kernel.org/stable/c/5d734665cd5d93270731e0ff1dd673fec677f447","https://git.kernel.org/stable/c/d93a2f86b0a998aa1f0870c85a2a60a0771ef89a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: stm32/cryp - call finalize with bh disabled\n\nThe finalize operation in interrupt mode produce a produces a spinlock\nrecursion warning. The reason is the fact that BH must be disabled\nduring this process.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47658","epss":0.00469,"percentile":0.39134,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47658","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47661","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47661","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Avoid overflow from uint32_t to uint8_t  [WHAT & HOW] dmub_rb_cmd's ramping_boundary has size of uint8_t and it is assigned 0xFFFF. Fix it by changing it to uint8_t with value of 0xFF.  This fixes 2 INTEGER_OVERFLOW issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47661","epss":0.00183,"percentile":0.07965,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47661","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09607500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-47661","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47661","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/30d1b783b6eeaf49d311a072c70d618d993d01ec","https://git.kernel.org/stable/c/d6b54900c564e35989cf6813e4071504fa0a90e0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid overflow from uint32_t to uint8_t\n\n[WHAT & HOW]\ndmub_rb_cmd's ramping_boundary has size of uint8_t and it is assigned\n0xFFFF. Fix it by changing it to uint8_t with value of 0xFF.\n\nThis fixes 2 INTEGER_OVERFLOW issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47661","epss":0.00183,"percentile":0.07965,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47661","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47661","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47662","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47662","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection  [Why] These registers should not be read from driver and triggering the security violation when DMCUB work times out and diagnostics are collected blocks Z8 entry.  [How] Remove the register read from DCN35.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47662","epss":0.00181,"percentile":0.07802,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095025},"relatedVulnerabilities":[{"id":"CVE-2024-47662","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47662","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/466423c6dd8af23ebb3a69d43434d01aed0db356","https://git.kernel.org/stable/c/eba4b2a38ccdf074a053834509545703d6df1d57"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Remove register from DCN35 DMCUB diagnostic collection\n\n[Why]\nThese registers should not be read from driver and triggering the\nsecurity violation when DMCUB work times out and diagnostics are\ncollected blocks Z8 entry.\n\n[How]\nRemove the register read from DCN35.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47662","epss":0.00181,"percentile":0.07802,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47662","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47664","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47664","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware  If the value of max_speed_hz is 0, it may cause a division by zero error in hisi_calc_effective_speed(). The value of max_speed_hz is provided by firmware. Firmware is generally considered as a trusted domain. However, as division by zero errors can cause system failure, for defense measure, the value of max_speed is validated here. So 0 is regarded as invalid and an error code is returned.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47664","epss":0.00206,"percentile":0.10769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47664","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-47664","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47664","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/16ccaf581da4fcf1e4d66086cf37263f9a656d43","https://git.kernel.org/stable/c/5127c42c77de18651aa9e8e0a3ced190103b449c","https://git.kernel.org/stable/c/ee73a15d4a8ce8fb02d7866f7cf78fcdd16f0fcc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware\n\nIf the value of max_speed_hz is 0, it may cause a division by zero\nerror in hisi_calc_effective_speed().\nThe value of max_speed_hz is provided by firmware.\nFirmware is generally considered as a trusted domain. However, as\ndivision by zero errors can cause system failure, for defense measure,\nthe value of max_speed is validated here. So 0 is regarded as invalid\nand an error code is returned.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47664","epss":0.00206,"percentile":0.10769,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47664","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47664","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47691","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47691","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to avoid use-after-free in f2fs_stop_gc_thread()  syzbot reports a f2fs bug as below:   __dump_stack lib/dump_stack.c:88 [inline]  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114  print_report+0xe8/0x550 mm/kasan/report.c:491  kasan_report+0x143/0x180 mm/kasan/report.c:601  kasan_check_range+0x282/0x290 mm/kasan/generic.c:189  instrument_atomic_read_write include/linux/instrumented.h:96 [inline]  atomic_fetch_add_relaxed include/linux/atomic/atomic-instrumented.h:252 [inline]  __refcount_add include/linux/refcount.h:184 [inline]  __refcount_inc include/linux/refcount.h:241 [inline]  refcount_inc include/linux/refcount.h:258 [inline]  get_task_struct include/linux/sched/task.h:118 [inline]  kthread_stop+0xca/0x630 kernel/kthread.c:704  f2fs_stop_gc_thread+0x65/0xb0 fs/f2fs/gc.c:210  f2fs_do_shutdown+0x192/0x540 fs/f2fs/file.c:2283  f2fs_ioc_shutdown fs/f2fs/file.c:2325 [inline]  __f2fs_ioctl+0x443a/0xbe60 fs/f2fs/file.c:4325  vfs_ioctl fs/ioctl.c:51 [inline]  __do_sys_ioctl fs/ioctl.c:907 [inline]  __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893  do_syscall_x64 arch/x86/entry/common.c:52 [inline]  do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f  The root cause is below race condition, it may cause use-after-free issue in sbi->gc_th pointer.  - remount  - f2fs_remount   - f2fs_stop_gc_thread    - kfree(gc_th) \t\t\t\t- f2fs_ioc_shutdown \t\t\t\t - f2fs_do_shutdown \t\t\t\t  - f2fs_stop_gc_thread \t\t\t\t   - kthread_stop(gc_th->f2fs_gc_task)    : sbi->gc_thread = NULL;  We will call f2fs_do_shutdown() in two paths: - for f2fs_ioc_shutdown() path, we should grab sb->s_umount semaphore for fixing. - for f2fs_shutdown() path, it's safe since caller has already grabbed sb->s_umount semaphore.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47691","epss":0.00237,"percentile":0.14721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47691","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.181305},"relatedVulnerabilities":[{"id":"CVE-2024-47691","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47691","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7c339dee7eb0f8e4cadc317c595f898ef04dae30","https://git.kernel.org/stable/c/c7f114d864ac91515bb07ac271e9824a20f5ed95","https://git.kernel.org/stable/c/d79343cd66343709e409d96b2abb139a0a55ce34","https://git.kernel.org/stable/c/fc18e655b62ac6bc9f12f5de0d749b4a3fe1e812"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid use-after-free in f2fs_stop_gc_thread()\n\nsyzbot reports a f2fs bug as below:\n\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n print_report+0xe8/0x550 mm/kasan/report.c:491\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n kasan_check_range+0x282/0x290 mm/kasan/generic.c:189\n instrument_atomic_read_write include/linux/instrumented.h:96 [inline]\n atomic_fetch_add_relaxed include/linux/atomic/atomic-instrumented.h:252 [inline]\n __refcount_add include/linux/refcount.h:184 [inline]\n __refcount_inc include/linux/refcount.h:241 [inline]\n refcount_inc include/linux/refcount.h:258 [inline]\n get_task_struct include/linux/sched/task.h:118 [inline]\n kthread_stop+0xca/0x630 kernel/kthread.c:704\n f2fs_stop_gc_thread+0x65/0xb0 fs/f2fs/gc.c:210\n f2fs_do_shutdown+0x192/0x540 fs/f2fs/file.c:2283\n f2fs_ioc_shutdown fs/f2fs/file.c:2325 [inline]\n __f2fs_ioctl+0x443a/0xbe60 fs/f2fs/file.c:4325\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nThe root cause is below race condition, it may cause use-after-free\nissue in sbi->gc_th pointer.\n\n- remount\n - f2fs_remount\n  - f2fs_stop_gc_thread\n   - kfree(gc_th)\n\t\t\t\t- f2fs_ioc_shutdown\n\t\t\t\t - f2fs_do_shutdown\n\t\t\t\t  - f2fs_stop_gc_thread\n\t\t\t\t   - kthread_stop(gc_th->f2fs_gc_task)\n   : sbi->gc_thread = NULL;\n\nWe will call f2fs_do_shutdown() in two paths:\n- for f2fs_ioc_shutdown() path, we should grab sb->s_umount semaphore\nfor fixing.\n- for f2fs_shutdown() path, it's safe since caller has already grabbed\nsb->s_umount semaphore.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47691","epss":0.00237,"percentile":0.14721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47691","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47691","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47703","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47703","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf, lsm: Add check for BPF LSM return value  A bpf prog returning a positive number attached to file_alloc_security hook makes kernel panic.  This happens because file system can not filter out the positive number returned by the LSM prog using IS_ERR, and misinterprets this positive number as a file pointer.  Given that hook file_alloc_security never returned positive number before the introduction of BPF LSM, and other BPF LSM hooks may encounter similar issues, this patch adds LSM return value check in verifier, to ensure no unexpected value is returned.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47703","epss":0.00216,"percentile":0.12005,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2024-47703","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47703","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1050727d83e70449991c29dd1cf29fe936a63da3","https://git.kernel.org/stable/c/27ca3e20fe80be85a92b10064dfeb56cb2564b1c","https://git.kernel.org/stable/c/5d99e198be279045e6ecefe220f5c52f8ce9bfd5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, lsm: Add check for BPF LSM return value\n\nA bpf prog returning a positive number attached to file_alloc_security\nhook makes kernel panic.\n\nThis happens because file system can not filter out the positive number\nreturned by the LSM prog using IS_ERR, and misinterprets this positive\nnumber as a file pointer.\n\nGiven that hook file_alloc_security never returned positive number\nbefore the introduction of BPF LSM, and other BPF LSM hooks may\nencounter similar issues, this patch adds LSM return value check\nin verifier, to ensure no unexpected value is returned.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47703","epss":0.00216,"percentile":0.12005,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47703","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47752","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47752","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: mediatek: vcodec: Fix H264 stateless decoder smatch warning  Fix a smatch static checker warning on vdec_h264_req_if.c. Which leads to a kernel crash when fb is NULL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47752","epss":0.00208,"percentile":0.10979,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47752","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10919999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-47752","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47752","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/18181b0c1c5bd43846e5e0ae3d61a4a1adceab03","https://git.kernel.org/stable/c/7878d3a385efab560dce793b595447867fb163f2","https://git.kernel.org/stable/c/790d1848fac5ac3b1c474f66162598ab07a20c21","https://git.kernel.org/stable/c/c6b9f971b43980de8893610f606d751131fb5d86"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: Fix H264 stateless decoder smatch warning\n\nFix a smatch static checker warning on vdec_h264_req_if.c.\nWhich leads to a kernel crash when fb is NULL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47752","epss":0.00208,"percentile":0.10979,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47752","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47752","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-47794","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-47794","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Prevent tailcall infinite loop caused by freplace  There is a potential infinite loop issue that can occur when using a combination of tail calls and freplace.  In an upcoming selftest, the attach target for entry_freplace of tailcall_freplace.c is subprog_tc of tc_bpf2bpf.c, while the tail call in entry_freplace leads to entry_tc. This results in an infinite loop:  entry_tc -> subprog_tc -> entry_freplace --tailcall-> entry_tc.  The problem arises because the tail_call_cnt in entry_freplace resets to zero each time entry_freplace is executed, causing the tail call mechanism to never terminate, eventually leading to a kernel panic.  To fix this issue, the solution is twofold:  1. Prevent updating a program extended by an freplace program to a    prog_array map. 2. Prevent extending a program that is already part of a prog_array map    with an freplace program.  This ensures that:  * If a program or its subprogram has been extended by an freplace program,   it can no longer be updated to a prog_array map. * If a program has been added to a prog_array map, neither it nor its   subprograms can be extended by an freplace program.  Moreover, an extension program should not be tailcalled. As such, return -EINVAL if the program has a type of BPF_PROG_TYPE_EXT when adding it to a prog_array map.  Additionally, fix a minor code style issue by replacing eight spaces with a tab for proper formatting.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47794","epss":0.00204,"percentile":0.1046,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47794","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10710000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-47794","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47794","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/987aa730bad3e1ef66d9f30182294daa78f6387d","https://git.kernel.org/stable/c/d6083f040d5d8f8d748462c77e90547097df936e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Prevent tailcall infinite loop caused by freplace\n\nThere is a potential infinite loop issue that can occur when using a\ncombination of tail calls and freplace.\n\nIn an upcoming selftest, the attach target for entry_freplace of\ntailcall_freplace.c is subprog_tc of tc_bpf2bpf.c, while the tail call in\nentry_freplace leads to entry_tc. This results in an infinite loop:\n\nentry_tc -> subprog_tc -> entry_freplace --tailcall-> entry_tc.\n\nThe problem arises because the tail_call_cnt in entry_freplace resets to\nzero each time entry_freplace is executed, causing the tail call mechanism\nto never terminate, eventually leading to a kernel panic.\n\nTo fix this issue, the solution is twofold:\n\n1. Prevent updating a program extended by an freplace program to a\n   prog_array map.\n2. Prevent extending a program that is already part of a prog_array map\n   with an freplace program.\n\nThis ensures that:\n\n* If a program or its subprogram has been extended by an freplace program,\n  it can no longer be updated to a prog_array map.\n* If a program has been added to a prog_array map, neither it nor its\n  subprograms can be extended by an freplace program.\n\nMoreover, an extension program should not be tailcalled. As such, return\n-EINVAL if the program has a type of BPF_PROG_TYPE_EXT when adding it to a\nprog_array map.\n\nAdditionally, fix a minor code style issue by replacing eight spaces with a\ntab for proper formatting.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-47794","epss":0.00204,"percentile":0.1046,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-47794","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-47794","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49568","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49568","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg  When receiving proposal msg in server, the fields v2_ext_offset/ eid_cnt/ism_gid_cnt in proposal msg are from the remote client and can not be fully trusted. Especially the field v2_ext_offset, once exceed the max value, there has the chance to access wrong address, and crash may happen.  This patch checks the fields v2_ext_offset/eid_cnt/ism_gid_cnt before using them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49568","epss":0.00524,"percentile":0.42766,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2751},"relatedVulnerabilities":[{"id":"CVE-2024-49568","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49568","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/295a92e3df32e72aff0f4bc25c310e349d07ffbf","https://git.kernel.org/stable/c/42f6beb2d5779429417b5f8115a4e3fa695d2a6c","https://git.kernel.org/stable/c/7863c9f3d24ba49dbead7e03dfbe40deb5888fdf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg\n\nWhen receiving proposal msg in server, the fields v2_ext_offset/\neid_cnt/ism_gid_cnt in proposal msg are from the remote client\nand can not be fully trusted. Especially the field v2_ext_offset,\nonce exceed the max value, there has the chance to access wrong\naddress, and crash may happen.\n\nThis patch checks the fields v2_ext_offset/eid_cnt/ism_gid_cnt\nbefore using them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49568","epss":0.00524,"percentile":0.42766,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49568","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49569","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49569","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvme-rdma: unquiesce admin_q before destroy it  Kernel will hang on destroy admin_q while we create ctrl failed, such as following calltrace:  PID: 23644    TASK: ff2d52b40f439fc0  CPU: 2    COMMAND: \"nvme\"  #0 [ff61d23de260fb78] __schedule at ffffffff8323bc15  #1 [ff61d23de260fc08] schedule at ffffffff8323c014  #2 [ff61d23de260fc28] blk_mq_freeze_queue_wait at ffffffff82a3dba1  #3 [ff61d23de260fc78] blk_freeze_queue at ffffffff82a4113a  #4 [ff61d23de260fc90] blk_cleanup_queue at ffffffff82a33006  #5 [ff61d23de260fcb0] nvme_rdma_destroy_admin_queue at ffffffffc12686ce  #6 [ff61d23de260fcc8] nvme_rdma_setup_ctrl at ffffffffc1268ced  #7 [ff61d23de260fd28] nvme_rdma_create_ctrl at ffffffffc126919b  #8 [ff61d23de260fd68] nvmf_dev_write at ffffffffc024f362  #9 [ff61d23de260fe38] vfs_write at ffffffff827d5f25     RIP: 00007fda7891d574  RSP: 00007ffe2ef06958  RFLAGS: 00000202     RAX: ffffffffffffffda  RBX: 000055e8122a4d90  RCX: 00007fda7891d574     RDX: 000000000000012b  RSI: 000055e8122a4d90  RDI: 0000000000000004     RBP: 00007ffe2ef079c0   R8: 000000000000012b   R9: 000055e8122a4d90     R10: 0000000000000000  R11: 0000000000000202  R12: 0000000000000004     R13: 000055e8122923c0  R14: 000000000000012b  R15: 00007fda78a54500     ORIG_RAX: 0000000000000001  CS: 0033  SS: 002b  This due to we have quiesced admi_q before cancel requests, but forgot to unquiesce before destroy it, as a result we fail to drain the pending requests, and hang on blk_mq_freeze_queue_wait() forever. Here try to reuse nvme_rdma_teardown_admin_queue() to fix this issue and simplify the code.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":2.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49569","epss":0.00822,"percentile":0.55136,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.43977},"relatedVulnerabilities":[{"id":"CVE-2024-49569","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49569","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/05b436f3cf65c957eff86c5ea5ddfa2604b32c63","https://git.kernel.org/stable/c/427036030f4d796533dcadba9b845896cb6c10a7","https://git.kernel.org/stable/c/5858b687559809f05393af745cbadf06dee61295"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-rdma: unquiesce admin_q before destroy it\n\nKernel will hang on destroy admin_q while we create ctrl failed, such\nas following calltrace:\n\nPID: 23644    TASK: ff2d52b40f439fc0  CPU: 2    COMMAND: \"nvme\"\n #0 [ff61d23de260fb78] __schedule at ffffffff8323bc15\n #1 [ff61d23de260fc08] schedule at ffffffff8323c014\n #2 [ff61d23de260fc28] blk_mq_freeze_queue_wait at ffffffff82a3dba1\n #3 [ff61d23de260fc78] blk_freeze_queue at ffffffff82a4113a\n #4 [ff61d23de260fc90] blk_cleanup_queue at ffffffff82a33006\n #5 [ff61d23de260fcb0] nvme_rdma_destroy_admin_queue at ffffffffc12686ce\n #6 [ff61d23de260fcc8] nvme_rdma_setup_ctrl at ffffffffc1268ced\n #7 [ff61d23de260fd28] nvme_rdma_create_ctrl at ffffffffc126919b\n #8 [ff61d23de260fd68] nvmf_dev_write at ffffffffc024f362\n #9 [ff61d23de260fe38] vfs_write at ffffffff827d5f25\n    RIP: 00007fda7891d574  RSP: 00007ffe2ef06958  RFLAGS: 00000202\n    RAX: ffffffffffffffda  RBX: 000055e8122a4d90  RCX: 00007fda7891d574\n    RDX: 000000000000012b  RSI: 000055e8122a4d90  RDI: 0000000000000004\n    RBP: 00007ffe2ef079c0   R8: 000000000000012b   R9: 000055e8122a4d90\n    R10: 0000000000000000  R11: 0000000000000202  R12: 0000000000000004\n    R13: 000055e8122923c0  R14: 000000000000012b  R15: 00007fda78a54500\n    ORIG_RAX: 0000000000000001  CS: 0033  SS: 002b\n\nThis due to we have quiesced admi_q before cancel requests, but forgot\nto unquiesce before destroy it, as a result we fail to drain the\npending requests, and hang on blk_mq_freeze_queue_wait() forever. Here\ntry to reuse nvme_rdma_teardown_admin_queue() to fix this issue and\nsimplify the code.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.7,"exploitabilityScore":2.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49569","epss":0.00822,"percentile":0.55136,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49569","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49893","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49893","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Check stream_status before it is used  [WHAT & HOW] dc_state_get_stream_status can return null, and therefore null must be checked before stream_status is used.  This fixes 1 NULL_RETURNS issue reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49893","epss":0.00206,"percentile":0.10794,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49893","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-49893","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49893","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4914c8bfee1843fae046a12970b6f178e6642659","https://git.kernel.org/stable/c/58a8ee96f84d2c21abb85ad8c22d2bbdf59bd7a9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check stream_status before it is used\n\n[WHAT & HOW]\ndc_state_get_stream_status can return null, and therefore null must be\nchecked before stream_status is used.\n\nThis fixes 1 NULL_RETURNS issue reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49893","epss":0.00206,"percentile":0.10794,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49893","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49893","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49901","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49901","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm/adreno: Assign msm_gpu->pdev earlier to avoid nullptrs  There are some cases, such as the one uncovered by Commit 46d4efcccc68 (\"drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails\") where  msm_gpu_cleanup() : platform_set_drvdata(gpu->pdev, NULL);  is called on gpu->pdev == NULL, as the GPU device has not been fully initialized yet.  Turns out that there's more than just the aforementioned path that causes this to happen (e.g. the case when there's speedbin data in the catalog, but opp-supported-hw is missing in DT).  Assigning msm_gpu->pdev earlier seems like the least painful solution to this, therefore do so.  Patchwork: https://patchwork.freedesktop.org/patch/602742/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49901","epss":0.00235,"percentile":0.1439,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49901","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.123375},"relatedVulnerabilities":[{"id":"CVE-2024-49901","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49901","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/16007768551d5bfe53426645401435ca8d2ef54f","https://git.kernel.org/stable/c/9288a9676c529ad9c856096db68fad812499bc4a","https://git.kernel.org/stable/c/9773737375b20070ea935203fd66cb9fa17c5acb","https://git.kernel.org/stable/c/e8ac2060597a5768e4699bb61d604b4c09927b85"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/adreno: Assign msm_gpu->pdev earlier to avoid nullptrs\n\nThere are some cases, such as the one uncovered by Commit 46d4efcccc68\n(\"drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails\")\nwhere\n\nmsm_gpu_cleanup() : platform_set_drvdata(gpu->pdev, NULL);\n\nis called on gpu->pdev == NULL, as the GPU device has not been fully\ninitialized yet.\n\nTurns out that there's more than just the aforementioned path that\ncauses this to happen (e.g. the case when there's speedbin data in the\ncatalog, but opp-supported-hw is missing in DT).\n\nAssigning msm_gpu->pdev earlier seems like the least painful solution\nto this, therefore do so.\n\nPatchwork: https://patchwork.freedesktop.org/patch/602742/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49901","epss":0.00235,"percentile":0.1439,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49901","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49901","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49906","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49906","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Check null pointer before try to access it  [why & how] Change the order of the pipe_ctx->plane_state check to ensure that plane_state is not null before accessing it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49906","epss":0.00244,"percentile":0.15592,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49906","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1281},"relatedVulnerabilities":[{"id":"CVE-2024-49906","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49906","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1b686053c06ffb9f4524b288110cf2a831ff7a25","https://git.kernel.org/stable/c/2002ccb93004e76a471b180560accb2c1f850f35","https://git.kernel.org/stable/c/ebef6616219ff04abdeb39450625f85419787ee3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointer before try to access it\n\n[why & how]\nChange the order of the pipe_ctx->plane_state check to ensure that\nplane_state is not null before accessing it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49906","epss":0.00244,"percentile":0.15592,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49906","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49906","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49908","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49908","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (v2)  This commit adds a null check for the 'afb' variable in the amdgpu_dm_update_cursor function. Previously, 'afb' was assumed to be null at line 8388, but was used later in the code without a null check. This could potentially lead to a null pointer dereference.  Changes since v1: - Moved the null check for 'afb' to the line where 'afb' is used. (Alex)  Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm.c:8433 amdgpu_dm_update_cursor() \terror: we previously assumed 'afb' could be null (see line 8388)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49908","epss":0.00208,"percentile":0.1101,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49908","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10919999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-49908","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49908","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0fe20258b4989b9112b5e9470df33a0939403fd4","https://git.kernel.org/stable/c/a742168b6a39ead257da53bcbe472384d6e14a1b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (v2)\n\nThis commit adds a null check for the 'afb' variable in the\namdgpu_dm_update_cursor function. Previously, 'afb' was assumed to be\nnull at line 8388, but was used later in the code without a null check.\nThis could potentially lead to a null pointer dereference.\n\nChanges since v1:\n- Moved the null check for 'afb' to the line where 'afb' is used. (Alex)\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm.c:8433 amdgpu_dm_update_cursor()\n\terror: we previously assumed 'afb' could be null (see line 8388)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49908","epss":0.00208,"percentile":0.1101,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49908","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49908","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49910","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49910","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add NULL check for function pointer in dcn401_set_output_transfer_func  This commit adds a null check for the set_output_gamma function pointer in the dcn401_set_output_transfer_func function. Previously, set_output_gamma was being checked for null, but then it was being dereferenced without any null check. This could lead to a null pointer dereference if set_output_gamma is null.  To fix this, we now ensure that set_output_gamma is not null before dereferencing it. We do this by adding a null check for set_output_gamma before the call to set_output_gamma.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49910","epss":0.00208,"percentile":0.1101,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49910","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10919999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-49910","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49910","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/d8ee900b92b6526cf84275b49a473155ad75c70e","https://git.kernel.org/stable/c/dd340acd42c24a3f28dd22fae6bf38662334264c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for function pointer in dcn401_set_output_transfer_func\n\nThis commit adds a null check for the set_output_gamma function pointer\nin the dcn401_set_output_transfer_func function. Previously,\nset_output_gamma was being checked for null, but then it was being\ndereferenced without any null check. This could lead to a null pointer\ndereference if set_output_gamma is null.\n\nTo fix this, we now ensure that set_output_gamma is not null before\ndereferencing it. We do this by adding a null check for set_output_gamma\nbefore the call to set_output_gamma.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49910","epss":0.00208,"percentile":0.1101,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49910","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49910","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49914","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49914","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add null check for pipe_ctx->plane_state in dcn20_program_pipe  This commit addresses a null pointer dereference issue in the `dcn20_program_pipe` function. The issue could occur when `pipe_ctx->plane_state` is null.  The fix adds a check to ensure `pipe_ctx->plane_state` is not null before accessing. This prevents a null pointer dereference.  Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn20/dcn20_hwseq.c:1925 dcn20_program_pipe() error: we previously assumed 'pipe_ctx->plane_state' could be null (see line 1877)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49914","epss":0.00244,"percentile":0.15591,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49914","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1281},"relatedVulnerabilities":[{"id":"CVE-2024-49914","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49914","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/65a6fee22d5cfa645cb05489892dc9cd3d142fc2","https://git.kernel.org/stable/c/68f75e6f08aad66069a629db8d7840919156c761","https://git.kernel.org/stable/c/8e4ed3cf1642df0c4456443d865cff61a9598aa8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for pipe_ctx->plane_state in dcn20_program_pipe\n\nThis commit addresses a null pointer dereference issue in the\n`dcn20_program_pipe` function. The issue could occur when\n`pipe_ctx->plane_state` is null.\n\nThe fix adds a check to ensure `pipe_ctx->plane_state` is not null\nbefore accessing. This prevents a null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn20/dcn20_hwseq.c:1925 dcn20_program_pipe() error: we previously assumed 'pipe_ctx->plane_state' could be null (see line 1877)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49914","epss":0.00244,"percentile":0.15591,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49914","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49914","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49916","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49916","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn401_init_hw  This commit addresses a potential null pointer dereference issue in the `dcn401_init_hw` function. The issue could occur when `dc->clk_mgr` or `dc->clk_mgr->funcs` is null.  The fix adds a check to ensure `dc->clk_mgr` and `dc->clk_mgr->funcs` is not null before accessing its functions. This prevents a potential null pointer dereference.  Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn401/dcn401_hwseq.c:416 dcn401_init_hw() error: we previously assumed 'dc->clk_mgr' could be null (see line 225)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49916","epss":0.00208,"percentile":0.1101,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49916","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10919999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-49916","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49916","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4b6377f0e96085cbec96eb7f0b282430ccdd3d75","https://git.kernel.org/stable/c/ac1c41e318074d8a9ea925787e366be15d7645e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn401_init_hw\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn401_init_hw` function. The issue could occur when `dc->clk_mgr` or\n`dc->clk_mgr->funcs` is null.\n\nThe fix adds a check to ensure `dc->clk_mgr` and `dc->clk_mgr->funcs` is\nnot null before accessing its functions. This prevents a potential null\npointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn401/dcn401_hwseq.c:416 dcn401_init_hw() error: we previously assumed 'dc->clk_mgr' could be null (see line 225)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49916","epss":0.00208,"percentile":0.1101,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49916","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49916","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49918","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49918","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add null check for head_pipe in dcn32_acquire_idle_pipe_for_head_pipe_in_layer  This commit addresses a potential null pointer dereference issue in the `dcn32_acquire_idle_pipe_for_head_pipe_in_layer` function. The issue could occur when `head_pipe` is null.  The fix adds a check to ensure `head_pipe` is not null before asserting it. If `head_pipe` is null, the function returns NULL to prevent a potential null pointer dereference.  Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn32/dcn32_resource.c:2690 dcn32_acquire_idle_pipe_for_head_pipe_in_layer() error: we previously assumed 'head_pipe' could be null (see line 2681)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49918","epss":0.00239,"percentile":0.14917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49918","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12547500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-49918","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49918","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4f47292f488fa7041284dca1f1244116c18721f1","https://git.kernel.org/stable/c/96d4c2ee18d732a248d053aae8c4a27cb1d68d1c","https://git.kernel.org/stable/c/ac2140449184a26eac99585b7f69814bd3ba8f2d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for head_pipe in dcn32_acquire_idle_pipe_for_head_pipe_in_layer\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn32_acquire_idle_pipe_for_head_pipe_in_layer` function. The issue\ncould occur when `head_pipe` is null.\n\nThe fix adds a check to ensure `head_pipe` is not null before asserting\nit. If `head_pipe` is null, the function returns NULL to prevent a\npotential null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn32/dcn32_resource.c:2690 dcn32_acquire_idle_pipe_for_head_pipe_in_layer() error: we previously assumed 'head_pipe' could be null (see line 2681)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49918","epss":0.00239,"percentile":0.14917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49918","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49918","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49919","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49919","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add null check for head_pipe in dcn201_acquire_free_pipe_for_layer  This commit addresses a potential null pointer dereference issue in the `dcn201_acquire_free_pipe_for_layer` function. The issue could occur when `head_pipe` is null.  The fix adds a check to ensure `head_pipe` is not null before asserting it. If `head_pipe` is null, the function returns NULL to prevent a potential null pointer dereference.  Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn201/dcn201_resource.c:1016 dcn201_acquire_free_pipe_for_layer() error: we previously assumed 'head_pipe' could be null (see line 1010)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49919","epss":0.00237,"percentile":0.14665,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49919","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12442500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-49919","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49919","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/16ce8fd94da8599bb6f0496895d392a69aead1c0","https://git.kernel.org/stable/c/390d757621f5f35d11a63ed7d9d3262ead240064","https://git.kernel.org/stable/c/8a1b1655a490a492a5a6987254c935ecce4eb9de","https://git.kernel.org/stable/c/f22f4754aaa47d8c59f166ba3042182859e5dff7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for head_pipe in dcn201_acquire_free_pipe_for_layer\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn201_acquire_free_pipe_for_layer` function. The issue could occur\nwhen `head_pipe` is null.\n\nThe fix adds a check to ensure `head_pipe` is not null before asserting\nit. If `head_pipe` is null, the function returns NULL to prevent a\npotential null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn201/dcn201_resource.c:1016 dcn201_acquire_free_pipe_for_layer() error: we previously assumed 'head_pipe' could be null (see line 1010)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49919","epss":0.00237,"percentile":0.14665,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49919","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49919","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49920","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49920","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Check null pointers before multiple uses  [WHAT & HOW] Poniters, such as stream_enc and dc->bw_vbios, are null checked previously in the same function, so Coverity warns \"implies that stream_enc and dc->bw_vbios might be null\". They are used multiple times in the subsequent code and need to be checked.  This fixes 10 FORWARD_NULL issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49920","epss":0.00216,"percentile":0.1199,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49920","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2024-49920","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49920","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/26787fb6c2b2ee0d1a7e1574b36f4711ae40fe27","https://git.kernel.org/stable/c/fdd5ecbbff751c3b9061d8ebb08e5c96119915b4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before multiple uses\n\n[WHAT & HOW]\nPoniters, such as stream_enc and dc->bw_vbios, are null checked previously\nin the same function, so Coverity warns \"implies that stream_enc and\ndc->bw_vbios might be null\". They are used multiple times in the\nsubsequent code and need to be checked.\n\nThis fixes 10 FORWARD_NULL issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49920","epss":0.00216,"percentile":0.1199,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49920","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49920","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49921","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49921","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Check null pointers before used  [WHAT & HOW] Poniters, such as dc->clk_mgr, are null checked previously in the same function, so Coverity warns \"implies that \"dc->clk_mgr\" might be null\". As a result, these pointers need to be checked when used again.  This fixes 10 FORWARD_NULL issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49921","epss":0.00211,"percentile":0.11349,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49921","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2024-49921","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49921","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5b35bf1a82eb29841b67ff5643ba83762250fc24","https://git.kernel.org/stable/c/be1fb44389ca3038ad2430dac4234669bc177ee3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before used\n\n[WHAT & HOW]\nPoniters, such as dc->clk_mgr, are null checked previously in the same\nfunction, so Coverity warns \"implies that \"dc->clk_mgr\" might be null\".\nAs a result, these pointers need to be checked when used again.\n\nThis fixes 10 FORWARD_NULL issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49921","epss":0.00211,"percentile":0.11349,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49921","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49921","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49922","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49922","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Check null pointers before using them  [WHAT & HOW] These pointers are null checked previously in the same function, indicating they might be null as reported by Coverity. As a result, they need to be checked when used again.  This fixes 3 FORWARD_NULL issue reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49922","epss":0.00235,"percentile":0.14384,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49922","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.123375},"relatedVulnerabilities":[{"id":"CVE-2024-49922","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49922","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1ff12bcd7deaeed25efb5120433c6a45dd5504a8","https://git.kernel.org/stable/c/5e9386baa3033c369564d55de4bab62423e8a1d3","https://git.kernel.org/stable/c/65e1d2c291553ef3f433a0b7109cc3002a5f40ae"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before using them\n\n[WHAT & HOW]\nThese pointers are null checked previously in the same function,\nindicating they might be null as reported by Coverity. As a result,\nthey need to be checked when used again.\n\nThis fixes 3 FORWARD_NULL issue reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49922","epss":0.00235,"percentile":0.14384,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49922","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49922","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49923","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49923","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags  [WHAT & HOW] \"dcn20_validate_apply_pipe_split_flags\" dereferences merge, and thus it cannot be a null pointer. Let's pass a valid pointer to avoid null dereference.  This fixes 2 FORWARD_NULL issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49923","epss":0.00237,"percentile":0.14665,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49923","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12442500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-49923","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49923","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/39a580cd15397e102aaec25986ae5acf492f8930","https://git.kernel.org/stable/c/5559598742fb4538e4c51c48ef70563c49c2af23","https://git.kernel.org/stable/c/85aa996ecfaa95d1e922867390502d23ce21b905","https://git.kernel.org/stable/c/9a05270869f40c89f8d184fe2d37cb86e0d7e5f5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags\n\n[WHAT & HOW]\n\"dcn20_validate_apply_pipe_split_flags\" dereferences merge, and thus it\ncannot be a null pointer. Let's pass a valid pointer to avoid null\ndereference.\n\nThis fixes 2 FORWARD_NULL issues reported by Coverity.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49923","epss":0.00237,"percentile":0.14665,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49923","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49923","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49926","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49926","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rcu-tasks: Fix access non-existent percpu rtpcp variable in rcu_tasks_need_gpcb()  For kernels built with CONFIG_FORCE_NR_CPUS=y, the nr_cpu_ids is defined as NR_CPUS instead of the number of possible cpus, this will cause the following system panic:  smpboot: Allowing 4 CPUs, 0 hotplug CPUs ... setup_percpu: NR_CPUS:512 nr_cpumask_bits:512 nr_cpu_ids:512 nr_node_ids:1 ... BUG: unable to handle page fault for address: ffffffff9911c8c8 Oops: 0000 [#1] PREEMPT SMP PTI CPU: 0 PID: 15 Comm: rcu_tasks_trace Tainted: G W 6.6.21 #1 5dc7acf91a5e8e9ac9dcfc35bee0245691283ea6 RIP: 0010:rcu_tasks_need_gpcb+0x25d/0x2c0 RSP: 0018:ffffa371c00a3e60 EFLAGS: 00010082 CR2: ffffffff9911c8c8 CR3: 000000040fa20005 CR4: 00000000001706f0 Call Trace: <TASK> ? __die+0x23/0x80 ? page_fault_oops+0xa4/0x180 ? exc_page_fault+0x152/0x180 ? asm_exc_page_fault+0x26/0x40 ? rcu_tasks_need_gpcb+0x25d/0x2c0 ? __pfx_rcu_tasks_kthread+0x40/0x40 rcu_tasks_one_gp+0x69/0x180 rcu_tasks_kthread+0x94/0xc0 kthread+0xe8/0x140 ? __pfx_kthread+0x40/0x40 ret_from_fork+0x34/0x80 ? __pfx_kthread+0x40/0x40 ret_from_fork_asm+0x1b/0x80 </TASK>  Considering that there may be holes in the CPU numbers, use the maximum possible cpu number, instead of nr_cpu_ids, for configuring enqueue and dequeue limits.  [ neeraj.upadhyay: Fix htmldocs build error reported by Stephen Rothwell ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49926","epss":0.00235,"percentile":0.1439,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.123375},"relatedVulnerabilities":[{"id":"CVE-2024-49926","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49926","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/05095271a4fb0f6497121a057f9a2edf386d5d96","https://git.kernel.org/stable/c/3104bddc666ff64b90491868bbc4c7ebdd90aedf","https://git.kernel.org/stable/c/b3b2431ed27f4ebc28e26cdf005c1de42dc60bdf","https://git.kernel.org/stable/c/fd70e9f1d85f5323096ad313ba73f5fe3d15ea41"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrcu-tasks: Fix access non-existent percpu rtpcp variable in rcu_tasks_need_gpcb()\n\nFor kernels built with CONFIG_FORCE_NR_CPUS=y, the nr_cpu_ids is\ndefined as NR_CPUS instead of the number of possible cpus, this\nwill cause the following system panic:\n\nsmpboot: Allowing 4 CPUs, 0 hotplug CPUs\n...\nsetup_percpu: NR_CPUS:512 nr_cpumask_bits:512 nr_cpu_ids:512 nr_node_ids:1\n...\nBUG: unable to handle page fault for address: ffffffff9911c8c8\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 0 PID: 15 Comm: rcu_tasks_trace Tainted: G W\n6.6.21 #1 5dc7acf91a5e8e9ac9dcfc35bee0245691283ea6\nRIP: 0010:rcu_tasks_need_gpcb+0x25d/0x2c0\nRSP: 0018:ffffa371c00a3e60 EFLAGS: 00010082\nCR2: ffffffff9911c8c8 CR3: 000000040fa20005 CR4: 00000000001706f0\nCall Trace:\n<TASK>\n? __die+0x23/0x80\n? page_fault_oops+0xa4/0x180\n? exc_page_fault+0x152/0x180\n? asm_exc_page_fault+0x26/0x40\n? rcu_tasks_need_gpcb+0x25d/0x2c0\n? __pfx_rcu_tasks_kthread+0x40/0x40\nrcu_tasks_one_gp+0x69/0x180\nrcu_tasks_kthread+0x94/0xc0\nkthread+0xe8/0x140\n? __pfx_kthread+0x40/0x40\nret_from_fork+0x34/0x80\n? __pfx_kthread+0x40/0x40\nret_from_fork_asm+0x1b/0x80\n</TASK>\n\nConsidering that there may be holes in the CPU numbers, use the\nmaximum possible cpu number, instead of nr_cpu_ids, for configuring\nenqueue and dequeue limits.\n\n[ neeraj.upadhyay: Fix htmldocs build error reported by Stephen Rothwell ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49926","epss":0.00235,"percentile":0.1439,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49926","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49940","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  l2tp: prevent possible tunnel refcount underflow  When a session is created, it sets a backpointer to its tunnel. When the session refcount drops to 0, l2tp_session_free drops the tunnel refcount if session->tunnel is non-NULL. However, session->tunnel is set in l2tp_session_create, before the tunnel refcount is incremented by l2tp_session_register, which leaves a small window where session->tunnel is non-NULL when the tunnel refcount hasn't been bumped.  Moving the assignment to l2tp_session_register is trivial but l2tp_session_create calls l2tp_session_set_header_len which uses session->tunnel to get the tunnel's encap. Add an encap arg to l2tp_session_set_header_len to avoid using session->tunnel.  If l2tpv3 sessions have colliding IDs, it is possible for l2tp_v3_session_get to race with l2tp_session_register and fetch a session which doesn't yet have session->tunnel set. Add a check for this case.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49940","epss":0.00238,"percentile":0.14823,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12495000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-49940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49940","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/24256415d18695b46da06c93135f5b51c548b950","https://git.kernel.org/stable/c/f7415e60c25a6108cd7955a20b2e66b6251ffe02"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: prevent possible tunnel refcount underflow\n\nWhen a session is created, it sets a backpointer to its tunnel. When\nthe session refcount drops to 0, l2tp_session_free drops the tunnel\nrefcount if session->tunnel is non-NULL. However, session->tunnel is\nset in l2tp_session_create, before the tunnel refcount is incremented\nby l2tp_session_register, which leaves a small window where\nsession->tunnel is non-NULL when the tunnel refcount hasn't been\nbumped.\n\nMoving the assignment to l2tp_session_register is trivial but\nl2tp_session_create calls l2tp_session_set_header_len which uses\nsession->tunnel to get the tunnel's encap. Add an encap arg to\nl2tp_session_set_header_len to avoid using session->tunnel.\n\nIf l2tpv3 sessions have colliding IDs, it is possible for\nl2tp_v3_session_get to race with l2tp_session_register and fetch a\nsession which doesn't yet have session->tunnel set. Add a check for\nthis case.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49940","epss":0.00238,"percentile":0.14823,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49945","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49945","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/ncsi: Disable the ncsi work before freeing the associated structure  The work function can run after the ncsi device is freed, resulting in use-after-free bugs or kernel panic.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49945","epss":0.00228,"percentile":0.1355,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49945","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11969999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-49945","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49945","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/a0ffa68c70b367358b2672cdab6fa5bc4c40de2c","https://git.kernel.org/stable/c/dd41dab62f32d9e9e0669af8459d12a93834b238","https://git.kernel.org/stable/c/f6ca58696749268181f43150b3553f2bafd71e42"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ncsi: Disable the ncsi work before freeing the associated structure\n\nThe work function can run after the ncsi device is freed, resulting\nin use-after-free bugs or kernel panic.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49945","epss":0.00228,"percentile":0.1355,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49945","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49945","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49970","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49970","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Implement bounds check for stream encoder creation in DCN401  'stream_enc_regs' array is an array of dcn10_stream_enc_registers structures. The array is initialized with four elements, corresponding to the four calls to stream_enc_regs() in the array initializer. This means that valid indices for this array are 0, 1, 2, and 3.  The error message 'stream_enc_regs' 4 <= 5 below, is indicating that there is an attempt to access this array with an index of 5, which is out of bounds. This could lead to undefined behavior  Here, eng_id is used as an index to access the stream_enc_regs array. If eng_id is 5, this would result in an out-of-bounds access on the stream_enc_regs array.  Thus fixing Buffer overflow error in dcn401_stream_encoder_create  Found by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn401/dcn401_resource.c:1209 dcn401_stream_encoder_create() error: buffer overflow 'stream_enc_regs' 4 <= 5","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49970","epss":0.00222,"percentile":0.12704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49970","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11655000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-49970","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49970","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/b219b46ad42df1dea9258788bcfea37181f3ccb2","https://git.kernel.org/stable/c/bdf606810210e8e07a0cdf1af3c467291363b295"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Implement bounds check for stream encoder creation in DCN401\n\n'stream_enc_regs' array is an array of dcn10_stream_enc_registers\nstructures. The array is initialized with four elements, corresponding\nto the four calls to stream_enc_regs() in the array initializer. This\nmeans that valid indices for this array are 0, 1, 2, and 3.\n\nThe error message 'stream_enc_regs' 4 <= 5 below, is indicating that\nthere is an attempt to access this array with an index of 5, which is\nout of bounds. This could lead to undefined behavior\n\nHere, eng_id is used as an index to access the stream_enc_regs array. If\neng_id is 5, this would result in an out-of-bounds access on the\nstream_enc_regs array.\n\nThus fixing Buffer overflow error in dcn401_stream_encoder_create\n\nFound by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn401/dcn401_resource.c:1209 dcn401_stream_encoder_create() error: buffer overflow 'stream_enc_regs' 4 <= 5","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49970","epss":0.00222,"percentile":0.12704,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49970","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49970","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-49988","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-49988","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: add refcnt to ksmbd_conn struct  When sending an oplock break request, opinfo->conn is used, But freed ->conn can be used on multichannel. This patch add a reference count to the ksmbd_conn struct so that it can be freed when it is no longer used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49988","epss":0.00617,"percentile":0.47502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49988","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.323925},"relatedVulnerabilities":[{"id":"CVE-2024-49988","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-49988","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/18f06bacc197d4ac9b518ad1c69999bc3d83e7aa","https://git.kernel.org/stable/c/9fd3cde4628bcd3549ab95061f2bab74d2ed4f3b","https://git.kernel.org/stable/c/e9dac92f4482a382e8c0fe1bc243da5fc3526b0c","https://git.kernel.org/stable/c/ee426bfb9d09b29987369b897fe9b6485ac2be27"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add refcnt to ksmbd_conn struct\n\nWhen sending an oplock break request, opinfo->conn is used,\nBut freed ->conn can be used on multichannel.\nThis patch add a reference count to the ksmbd_conn struct\nso that it can be freed when it is no longer used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-49988","epss":0.00617,"percentile":0.47502,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-49988","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-49988","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50009","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50009","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cpufreq: amd-pstate: add check for cpufreq_cpu_get's return value  cpufreq_cpu_get may return NULL. To avoid NULL-dereference check it and return in case of error.  Found by Linux Verification Center (linuxtesting.org) with SVACE.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50009","epss":0.00231,"percentile":0.13891,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50009","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12127500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-50009","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50009","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5493f9714e4cdaf0ee7cec15899a231400cb1a9f","https://git.kernel.org/stable/c/5f250d44b8191d612355dd97b89b37bbc1b5d2cb","https://git.kernel.org/stable/c/cd9f7bf6cad8b2d3876105ce3c9fc63460a046f6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: amd-pstate: add check for cpufreq_cpu_get's return value\n\ncpufreq_cpu_get may return NULL. To avoid NULL-dereference check it\nand return in case of error.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50009","epss":0.00231,"percentile":0.13891,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50009","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50009","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50017","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  x86/mm/ident_map: Use gbpages only where full GB page should be mapped.  When ident_pud_init() uses only GB pages to create identity maps, large ranges of addresses not actually requested can be included in the resulting table; a 4K request will map a full GB.  This can include a lot of extra address space past that requested, including areas marked reserved by the BIOS.  That allows processor speculation into reserved regions, that on UV systems can cause system halts.  Only use GB pages when map creation requests include the full GB page of space.  Fall back to using smaller 2M pages when only portions of a GB page are included in the request.  No attempt is made to coalesce mapping requests. If a request requires a map entry at the 2M (pmd) level, subsequent mapping requests within the same 1G region will also be at the pmd level, even if adjacent or overlapping such requests could have been combined to map a full GB page. Existing usage starts with larger regions and then adds smaller regions, so this should not have any great consequence.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50017","epss":0.00221,"percentile":0.12645,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.116025},"relatedVulnerabilities":[{"id":"CVE-2024-50017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50017","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/a23823098ab2c277c14fc110b97d8d5c83597195","https://git.kernel.org/stable/c/cc31744a294584a36bf764a0ffa3255a8e69f036","https://git.kernel.org/stable/c/d113f9723f2bfd9c6feeb899b8ddbee6b8a6e01f","https://git.kernel.org/stable/c/d80a99892f7a992d103138fa4636b2c33abd6740"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm/ident_map: Use gbpages only where full GB page should be mapped.\n\nWhen ident_pud_init() uses only GB pages to create identity maps, large\nranges of addresses not actually requested can be included in the resulting\ntable; a 4K request will map a full GB.  This can include a lot of extra\naddress space past that requested, including areas marked reserved by the\nBIOS.  That allows processor speculation into reserved regions, that on UV\nsystems can cause system halts.\n\nOnly use GB pages when map creation requests include the full GB page of\nspace.  Fall back to using smaller 2M pages when only portions of a GB page\nare included in the request.\n\nNo attempt is made to coalesce mapping requests. If a request requires a\nmap entry at the 2M (pmd) level, subsequent mapping requests within the\nsame 1G region will also be at the pmd level, even if adjacent or\noverlapping such requests could have been combined to map a full GB page.\nExisting usage starts with larger regions and then adds smaller regions, so\nthis should not have any great consequence.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50017","epss":0.00221,"percentile":0.12645,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50028","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50028","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  thermal: core: Reference count the zone in thermal_zone_get_by_id()  There are places in the thermal netlink code where nothing prevents the thermal zone object from going away while being accessed after it has been returned by thermal_zone_get_by_id().  To address this, make thermal_zone_get_by_id() get a reference on the thermal zone device object to be returned with the help of get_device(), under thermal_list_lock, and adjust all of its callers to this change with the help of the cleanup.h infrastructure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50028","epss":0.00215,"percentile":0.11879,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.112875},"relatedVulnerabilities":[{"id":"CVE-2024-50028","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50028","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/a42a5839f400e929c489bb1b58f54596c4535167","https://git.kernel.org/stable/c/c95538b286efc6109c987e97a051bc7844ede802"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: core: Reference count the zone in thermal_zone_get_by_id()\n\nThere are places in the thermal netlink code where nothing prevents\nthe thermal zone object from going away while being accessed after it\nhas been returned by thermal_zone_get_by_id().\n\nTo address this, make thermal_zone_get_by_id() get a reference on the\nthermal zone device object to be returned with the help of get_device(),\nunder thermal_list_lock, and adjust all of its callers to this change\nwith the help of the cleanup.h infrastructure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50028","epss":0.00215,"percentile":0.11879,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50028","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50029","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50029","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync  This checks if the ACL connection remains valid as it could be destroyed while hci_enhanced_setup_sync is pending on cmd_sync leading to the following trace:  BUG: KASAN: slab-use-after-free in hci_enhanced_setup_sync+0x91b/0xa60 Read of size 1 at addr ffff888002328ffd by task kworker/u5:2/37  CPU: 0 UID: 0 PID: 37 Comm: kworker/u5:2 Not tainted 6.11.0-rc6-01300-g810be445d8d6 #7099 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 Workqueue: hci0 hci_cmd_sync_work Call Trace:  <TASK>  dump_stack_lvl+0x5d/0x80  ? hci_enhanced_setup_sync+0x91b/0xa60  print_report+0x152/0x4c0  ? hci_enhanced_setup_sync+0x91b/0xa60  ? __virt_addr_valid+0x1fa/0x420  ? hci_enhanced_setup_sync+0x91b/0xa60  kasan_report+0xda/0x1b0  ? hci_enhanced_setup_sync+0x91b/0xa60  hci_enhanced_setup_sync+0x91b/0xa60  ? __pfx_hci_enhanced_setup_sync+0x10/0x10  ? __pfx___mutex_lock+0x10/0x10  hci_cmd_sync_work+0x1c2/0x330  process_one_work+0x7d9/0x1360  ? __pfx_lock_acquire+0x10/0x10  ? __pfx_process_one_work+0x10/0x10  ? assign_work+0x167/0x240  worker_thread+0x5b7/0xf60  ? __kthread_parkme+0xac/0x1c0  ? __pfx_worker_thread+0x10/0x10  ? __pfx_worker_thread+0x10/0x10  kthread+0x293/0x360  ? __pfx_kthread+0x10/0x10  ret_from_fork+0x2f/0x70  ? __pfx_kthread+0x10/0x10  ret_from_fork_asm+0x1a/0x30  </TASK>  Allocated by task 34:  kasan_save_stack+0x30/0x50  kasan_save_track+0x14/0x30  __kasan_kmalloc+0x8f/0xa0  __hci_conn_add+0x187/0x17d0  hci_connect_sco+0x2e1/0xb90  sco_sock_connect+0x2a2/0xb80  __sys_connect+0x227/0x2a0  __x64_sys_connect+0x6d/0xb0  do_syscall_64+0x71/0x140  entry_SYSCALL_64_after_hwframe+0x76/0x7e  Freed by task 37:  kasan_save_stack+0x30/0x50  kasan_save_track+0x14/0x30  kasan_save_free_info+0x3b/0x60  __kasan_slab_free+0x101/0x160  kfree+0xd0/0x250  device_release+0x9a/0x210  kobject_put+0x151/0x280  hci_conn_del+0x448/0xbf0  hci_abort_conn_sync+0x46f/0x980  hci_cmd_sync_work+0x1c2/0x330  process_one_work+0x7d9/0x1360  worker_thread+0x5b7/0xf60  kthread+0x293/0x360  ret_from_fork+0x2f/0x70  ret_from_fork_asm+0x1a/0x30","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50029","epss":0.00369,"percentile":0.30139,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50029","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.282285},"relatedVulnerabilities":[{"id":"CVE-2024-50029","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50029","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/18fd04ad856df07733f5bb07e7f7168e7443d393","https://git.kernel.org/stable/c/867639300759e3e1c5b1e1a5ff89231f263a32a7","https://git.kernel.org/stable/c/98ccd44002d88cbf4edfc4480df532a3da5a013e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync\n\nThis checks if the ACL connection remains valid as it could be destroyed\nwhile hci_enhanced_setup_sync is pending on cmd_sync leading to the\nfollowing trace:\n\nBUG: KASAN: slab-use-after-free in hci_enhanced_setup_sync+0x91b/0xa60\nRead of size 1 at addr ffff888002328ffd by task kworker/u5:2/37\n\nCPU: 0 UID: 0 PID: 37 Comm: kworker/u5:2 Not tainted 6.11.0-rc6-01300-g810be445d8d6 #7099\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\nWorkqueue: hci0 hci_cmd_sync_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x5d/0x80\n ? hci_enhanced_setup_sync+0x91b/0xa60\n print_report+0x152/0x4c0\n ? hci_enhanced_setup_sync+0x91b/0xa60\n ? __virt_addr_valid+0x1fa/0x420\n ? hci_enhanced_setup_sync+0x91b/0xa60\n kasan_report+0xda/0x1b0\n ? hci_enhanced_setup_sync+0x91b/0xa60\n hci_enhanced_setup_sync+0x91b/0xa60\n ? __pfx_hci_enhanced_setup_sync+0x10/0x10\n ? __pfx___mutex_lock+0x10/0x10\n hci_cmd_sync_work+0x1c2/0x330\n process_one_work+0x7d9/0x1360\n ? __pfx_lock_acquire+0x10/0x10\n ? __pfx_process_one_work+0x10/0x10\n ? assign_work+0x167/0x240\n worker_thread+0x5b7/0xf60\n ? __kthread_parkme+0xac/0x1c0\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x293/0x360\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2f/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nAllocated by task 34:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n __hci_conn_add+0x187/0x17d0\n hci_connect_sco+0x2e1/0xb90\n sco_sock_connect+0x2a2/0xb80\n __sys_connect+0x227/0x2a0\n __x64_sys_connect+0x6d/0xb0\n do_syscall_64+0x71/0x140\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 37:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x101/0x160\n kfree+0xd0/0x250\n device_release+0x9a/0x210\n kobject_put+0x151/0x280\n hci_conn_del+0x448/0xbf0\n hci_abort_conn_sync+0x46f/0x980\n hci_cmd_sync_work+0x1c2/0x330\n process_one_work+0x7d9/0x1360\n worker_thread+0x5b7/0xf60\n kthread+0x293/0x360\n ret_from_fork+0x2f/0x70\n ret_from_fork_asm+0x1a/0x30","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50029","epss":0.00369,"percentile":0.30139,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50029","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50029","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50057","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50057","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: typec: tipd: Free IRQ only if it was requested before  In polling mode, if no IRQ was requested there is no need to free it. Call devm_free_irq() only if client->irq is set. This fixes the warning caused by the tps6598x module removal:  WARNING: CPU: 2 PID: 333 at kernel/irq/devres.c:144 devm_free_irq+0x80/0x8c ... ... Call trace:   devm_free_irq+0x80/0x8c   tps6598x_remove+0x28/0x88 [tps6598x]   i2c_device_remove+0x2c/0x9c   device_remove+0x4c/0x80   device_release_driver_internal+0x1cc/0x228   driver_detach+0x50/0x98   bus_remove_driver+0x6c/0xbc   driver_unregister+0x30/0x60   i2c_del_driver+0x54/0x64   tps6598x_i2c_driver_exit+0x18/0xc3c [tps6598x]   __arm64_sys_delete_module+0x184/0x264   invoke_syscall+0x48/0x110   el0_svc_common.constprop.0+0xc8/0xe8   do_el0_svc+0x20/0x2c   el0_svc+0x28/0x98   el0t_64_sync_handler+0x13c/0x158   el0t_64_sync+0x190/0x194","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50057","epss":0.00212,"percentile":0.11488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50057","cwe":"CWE-763","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06677999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-50057","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50057","namespace":"nvd:cpe","severity":"Low","urls":["https://git.kernel.org/stable/c/4d4b23c119542fbaed2a16794d3801cb4806ea02","https://git.kernel.org/stable/c/b72bf5cade51ba4055c8a8998d275e72e6b521ce","https://git.kernel.org/stable/c/db63d9868f7f310de44ba7bea584e2454f8b4ed0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tipd: Free IRQ only if it was requested before\n\nIn polling mode, if no IRQ was requested there is no need to free it.\nCall devm_free_irq() only if client->irq is set. This fixes the warning\ncaused by the tps6598x module removal:\n\nWARNING: CPU: 2 PID: 333 at kernel/irq/devres.c:144 devm_free_irq+0x80/0x8c\n...\n...\nCall trace:\n  devm_free_irq+0x80/0x8c\n  tps6598x_remove+0x28/0x88 [tps6598x]\n  i2c_device_remove+0x2c/0x9c\n  device_remove+0x4c/0x80\n  device_release_driver_internal+0x1cc/0x228\n  driver_detach+0x50/0x98\n  bus_remove_driver+0x6c/0xbc\n  driver_unregister+0x30/0x60\n  i2c_del_driver+0x54/0x64\n  tps6598x_i2c_driver_exit+0x18/0xc3c [tps6598x]\n  __arm64_sys_delete_module+0x184/0x264\n  invoke_syscall+0x48/0x110\n  el0_svc_common.constprop.0+0xc8/0xe8\n  do_el0_svc+0x20/0x2c\n  el0_svc+0x28/0x98\n  el0t_64_sync_handler+0x13c/0x158\n  el0t_64_sync+0x190/0x194","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50057","epss":0.00212,"percentile":0.11488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50057","cwe":"CWE-763","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50057","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50111","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50111","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Enable IRQ if do_ale() triggered in irq-enabled context  Unaligned access exception can be triggered in irq-enabled context such as user mode, in this case do_ale() may call get_user() which may cause sleep. Then we will get:   BUG: sleeping function called from invalid context at arch/loongarch/kernel/access-helper.h:7  in_atomic(): 0, irqs_disabled(): 1, non_block: 0, pid: 129, name: modprobe  preempt_count: 0, expected: 0  RCU nest depth: 0, expected: 0  CPU: 0 UID: 0 PID: 129 Comm: modprobe Tainted: G        W          6.12.0-rc1+ #1723  Tainted: [W]=WARN  Stack : 9000000105e0bd48 0000000000000000 9000000003803944 9000000105e08000          9000000105e0bc70 9000000105e0bc78 0000000000000000 0000000000000000          9000000105e0bc78 0000000000000001 9000000185e0ba07 9000000105e0b890          ffffffffffffffff 9000000105e0bc78 73924b81763be05b 9000000100194500          000000000000020c 000000000000000a 0000000000000000 0000000000000003          00000000000023f0 00000000000e1401 00000000072f8000 0000007ffbb0e260          0000000000000000 0000000000000000 9000000005437650 90000000055d5000          0000000000000000 0000000000000003 0000007ffbb0e1f0 0000000000000000          0000005567b00490 0000000000000000 9000000003803964 0000007ffbb0dfec          00000000000000b0 0000000000000007 0000000000000003 0000000000071c1d          ...  Call Trace:  [<9000000003803964>] show_stack+0x64/0x1a0  [<9000000004c57464>] dump_stack_lvl+0x74/0xb0  [<9000000003861ab4>] __might_resched+0x154/0x1a0  [<900000000380c96c>] emulate_load_store_insn+0x6c/0xf60  [<9000000004c58118>] do_ale+0x78/0x180  [<9000000003801bc8>] handle_ale+0x128/0x1e0  So enable IRQ if unaligned access exception is triggered in irq-enabled context to fix it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50111","epss":0.00235,"percentile":0.14388,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.123375},"relatedVulnerabilities":[{"id":"CVE-2024-50111","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50111","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/69cc6fad5df4ce652d969be69acc60e269e5eea1","https://git.kernel.org/stable/c/8915ed160dbd32b5ef5864df9a9fc11db83a77bb","https://git.kernel.org/stable/c/afbfb3568d78082078acc8bb2b29bb47af87253c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Enable IRQ if do_ale() triggered in irq-enabled context\n\nUnaligned access exception can be triggered in irq-enabled context such\nas user mode, in this case do_ale() may call get_user() which may cause\nsleep. Then we will get:\n\n BUG: sleeping function called from invalid context at arch/loongarch/kernel/access-helper.h:7\n in_atomic(): 0, irqs_disabled(): 1, non_block: 0, pid: 129, name: modprobe\n preempt_count: 0, expected: 0\n RCU nest depth: 0, expected: 0\n CPU: 0 UID: 0 PID: 129 Comm: modprobe Tainted: G        W          6.12.0-rc1+ #1723\n Tainted: [W]=WARN\n Stack : 9000000105e0bd48 0000000000000000 9000000003803944 9000000105e08000\n         9000000105e0bc70 9000000105e0bc78 0000000000000000 0000000000000000\n         9000000105e0bc78 0000000000000001 9000000185e0ba07 9000000105e0b890\n         ffffffffffffffff 9000000105e0bc78 73924b81763be05b 9000000100194500\n         000000000000020c 000000000000000a 0000000000000000 0000000000000003\n         00000000000023f0 00000000000e1401 00000000072f8000 0000007ffbb0e260\n         0000000000000000 0000000000000000 9000000005437650 90000000055d5000\n         0000000000000000 0000000000000003 0000007ffbb0e1f0 0000000000000000\n         0000005567b00490 0000000000000000 9000000003803964 0000007ffbb0dfec\n         00000000000000b0 0000000000000007 0000000000000003 0000000000071c1d\n         ...\n Call Trace:\n [<9000000003803964>] show_stack+0x64/0x1a0\n [<9000000004c57464>] dump_stack_lvl+0x74/0xb0\n [<9000000003861ab4>] __might_resched+0x154/0x1a0\n [<900000000380c96c>] emulate_load_store_insn+0x6c/0xf60\n [<9000000004c58118>] do_ale+0x78/0x180\n [<9000000003801bc8>] handle_ale+0x128/0x1e0\n\nSo enable IRQ if unaligned access exception is triggered in irq-enabled\ncontext to fix it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50111","epss":0.00235,"percentile":0.14388,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50111","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50135","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50135","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvme-pci: fix race condition between reset and nvme_dev_disable()  nvme_dev_disable() modifies the dev->online_queues field, therefore nvme_pci_update_nr_queues() should avoid racing against it, otherwise we could end up passing invalid values to blk_mq_update_nr_hw_queues().   WARNING: CPU: 39 PID: 61303 at drivers/pci/msi/api.c:347           pci_irq_get_affinity+0x187/0x210  Workqueue: nvme-reset-wq nvme_reset_work [nvme]  RIP: 0010:pci_irq_get_affinity+0x187/0x210  Call Trace:   <TASK>   ? blk_mq_pci_map_queues+0x87/0x3c0   ? pci_irq_get_affinity+0x187/0x210   blk_mq_pci_map_queues+0x87/0x3c0   nvme_pci_map_queues+0x189/0x460 [nvme]   blk_mq_update_nr_hw_queues+0x2a/0x40   nvme_reset_work+0x1be/0x2a0 [nvme]  Fix the bug by locking the shutdown_lock mutex before using dev->online_queues. Give up if nvme_dev_disable() is running or if it has been executed already.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50135","epss":0.00165,"percentile":0.06019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50135","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50135","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.080025},"relatedVulnerabilities":[{"id":"CVE-2024-50135","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50135","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/26bc0a81f64ce00fc4342c38eeb2eddaad084dd2","https://git.kernel.org/stable/c/4ed32cc0939b64e3d7b48c8c0d63ea038775f304","https://git.kernel.org/stable/c/b33e49a5f254474b33ce98fd45dd0ffdc247a0be"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix race condition between reset and nvme_dev_disable()\n\nnvme_dev_disable() modifies the dev->online_queues field, therefore\nnvme_pci_update_nr_queues() should avoid racing against it, otherwise\nwe could end up passing invalid values to blk_mq_update_nr_hw_queues().\n\n WARNING: CPU: 39 PID: 61303 at drivers/pci/msi/api.c:347\n          pci_irq_get_affinity+0x187/0x210\n Workqueue: nvme-reset-wq nvme_reset_work [nvme]\n RIP: 0010:pci_irq_get_affinity+0x187/0x210\n Call Trace:\n  <TASK>\n  ? blk_mq_pci_map_queues+0x87/0x3c0\n  ? pci_irq_get_affinity+0x187/0x210\n  blk_mq_pci_map_queues+0x87/0x3c0\n  nvme_pci_map_queues+0x189/0x460 [nvme]\n  blk_mq_update_nr_hw_queues+0x2a/0x40\n  nvme_reset_work+0x1be/0x2a0 [nvme]\n\nFix the bug by locking the shutdown_lock mutex before using\ndev->online_queues. Give up if nvme_dev_disable() is running or if\nit has been executed already.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50135","epss":0.00165,"percentile":0.06019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50135","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50135","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50135","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50166","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50166","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fsl/fman: Fix refcount handling of fman-related devices  In mac_probe() there are multiple calls to of_find_device_by_node(), fman_bind() and fman_port_bind() which takes references to of_dev->dev. Not all references taken by these calls are released later on error path in mac_probe() and in mac_remove() which lead to reference leaks.  Add references release.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50166","epss":0.00215,"percentile":0.11899,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50166","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.112875},"relatedVulnerabilities":[{"id":"CVE-2024-50166","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50166","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1dec67e0d9fbb087c2ab17bf1bd17208231c3bb1","https://git.kernel.org/stable/c/3c2a3619d565fe16bf59b0a047bab103a2ee4490","https://git.kernel.org/stable/c/5ed4334fc9512f934fe2ae9c4cf7f8142e451b8b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfsl/fman: Fix refcount handling of fman-related devices\n\nIn mac_probe() there are multiple calls to of_find_device_by_node(),\nfman_bind() and fman_port_bind() which takes references to of_dev->dev.\nNot all references taken by these calls are released later on error path\nin mac_probe() and in mac_remove() which lead to reference leaks.\n\nAdd references release.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50166","epss":0.00215,"percentile":0.11899,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50166","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50166","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50211","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50211","namespace":"debian:distro:debian:12","severity":"Low","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  udf: refactor inode_bmap() to handle error  Refactor inode_bmap() to handle error since udf_next_aext() can return error now. On situations like ftruncate, udf_extend_file() can now detect errors and bail out early without resorting to checking for particular offsets and assuming internal behavior of these functions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50211","epss":0.00214,"percentile":0.11777,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06740999999999998},"relatedVulnerabilities":[{"id":"CVE-2024-50211","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50211","namespace":"nvd:cpe","severity":"Low","urls":["https://git.kernel.org/stable/c/493447dd8336607fce426f7879e581095f6c606e","https://git.kernel.org/stable/c/b22d9a5698abf04341f8fbc30141e0673863c3a6","https://git.kernel.org/stable/c/c226964ec786f3797ed389a16392ce4357697d24"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nudf: refactor inode_bmap() to handle error\n\nRefactor inode_bmap() to handle error since udf_next_aext() can return\nerror now. On situations like ftruncate, udf_extend_file() can now\ndetect errors and bail out early without resorting to checking for\nparticular offsets and assuming internal behavior of these functions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50211","epss":0.00214,"percentile":0.11777,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50211","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50217","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50217","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()  Mounting btrfs from two images (which have the same one fsid and two different dev_uuids) in certain executing order may trigger an UAF for variable 'device->bdev_file' in __btrfs_free_extra_devids(). And following are the details:  1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs    devices by ioctl(BTRFS_IOC_SCAN_DEV):               /  btrfs_device_1 → loop0    fs_device              \\  btrfs_device_2 → loop1 2. mount /dev/loop0 /mnt    btrfs_open_devices     btrfs_device_1->bdev_file = btrfs_get_bdev_and_sb(loop0)     btrfs_device_2->bdev_file = btrfs_get_bdev_and_sb(loop1)    btrfs_fill_super     open_ctree      fail: btrfs_close_devices // -ENOMEM \t    btrfs_close_bdev(btrfs_device_1)              fput(btrfs_device_1->bdev_file) \t      // btrfs_device_1->bdev_file is freed \t    btrfs_close_bdev(btrfs_device_2)              fput(btrfs_device_2->bdev_file)  3. mount /dev/loop1 /mnt    btrfs_open_devices     btrfs_get_bdev_and_sb(&bdev_file)      // EIO, btrfs_device_1->bdev_file is not assigned,      // which points to a freed memory area     btrfs_device_2->bdev_file = btrfs_get_bdev_and_sb(loop1)    btrfs_fill_super     open_ctree      btrfs_free_extra_devids       if (btrfs_device_1->bdev_file)        fput(btrfs_device_1->bdev_file) // UAF !  Fix it by setting 'device->bdev_file' as 'NULL' after closing the btrfs_device in btrfs_close_one_device().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50217","epss":0.00276,"percentile":0.19867,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50217","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50217","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21114},"relatedVulnerabilities":[{"id":"CVE-2024-50217","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50217","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/47a83f8df39545f3f552bb6a1b6d9c30e37621dd","https://git.kernel.org/stable/c/aec8e6bf839101784f3ef037dcdb9432c3f32343","http://www.openwall.com/lists/oss-security/2025/04/10/4","http://www.openwall.com/lists/oss-security/2025/04/10/5","http://www.openwall.com/lists/oss-security/2025/04/10/6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()\n\nMounting btrfs from two images (which have the same one fsid and two\ndifferent dev_uuids) in certain executing order may trigger an UAF for\nvariable 'device->bdev_file' in __btrfs_free_extra_devids(). And\nfollowing are the details:\n\n1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs\n   devices by ioctl(BTRFS_IOC_SCAN_DEV):\n\n             /  btrfs_device_1 → loop0\n   fs_device\n             \\  btrfs_device_2 → loop1\n2. mount /dev/loop0 /mnt\n   btrfs_open_devices\n    btrfs_device_1->bdev_file = btrfs_get_bdev_and_sb(loop0)\n    btrfs_device_2->bdev_file = btrfs_get_bdev_and_sb(loop1)\n   btrfs_fill_super\n    open_ctree\n     fail: btrfs_close_devices // -ENOMEM\n\t    btrfs_close_bdev(btrfs_device_1)\n             fput(btrfs_device_1->bdev_file)\n\t      // btrfs_device_1->bdev_file is freed\n\t    btrfs_close_bdev(btrfs_device_2)\n             fput(btrfs_device_2->bdev_file)\n\n3. mount /dev/loop1 /mnt\n   btrfs_open_devices\n    btrfs_get_bdev_and_sb(&bdev_file)\n     // EIO, btrfs_device_1->bdev_file is not assigned,\n     // which points to a freed memory area\n    btrfs_device_2->bdev_file = btrfs_get_bdev_and_sb(loop1)\n   btrfs_fill_super\n    open_ctree\n     btrfs_free_extra_devids\n      if (btrfs_device_1->bdev_file)\n       fput(btrfs_device_1->bdev_file) // UAF !\n\nFix it by setting 'device->bdev_file' as 'NULL' after closing the\nbtrfs_device in btrfs_close_one_device().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50217","epss":0.00276,"percentile":0.19867,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50217","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50217","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50217","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50226","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50226","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cxl/port: Fix use-after-free, permit out-of-order decoder shutdown  In support of investigating an initialization failure report [1], cxl_test was updated to register mock memory-devices after the mock root-port/bus device had been registered. That led to cxl_test crashing with a use-after-free bug with the following signature:      cxl_port_attach_region: cxl region3: cxl_host_bridge.0:port3 decoder3.0 add: mem0:decoder7.0 @ 0 next: cxl_switch_uport.0 nr_eps: 1 nr_targets: 1     cxl_port_attach_region: cxl region3: cxl_host_bridge.0:port3 decoder3.0 add: mem4:decoder14.0 @ 1 next: cxl_switch_uport.0 nr_eps: 2 nr_targets: 1     cxl_port_setup_targets: cxl region3: cxl_switch_uport.0:port6 target[0] = cxl_switch_dport.0 for mem0:decoder7.0 @ 0 1)  cxl_port_setup_targets: cxl region3: cxl_switch_uport.0:port6 target[1] = cxl_switch_dport.4 for mem4:decoder14.0 @ 1     [..]     cxld_unregister: cxl decoder14.0:     cxl_region_decode_reset: cxl_region region3:     mock_decoder_reset: cxl_port port3: decoder3.0 reset 2)  mock_decoder_reset: cxl_port port3: decoder3.0: out of order reset, expected decoder3.1     cxl_endpoint_decoder_release: cxl decoder14.0:     [..]     cxld_unregister: cxl decoder7.0: 3)  cxl_region_decode_reset: cxl_region region3:     Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6bc3: 0000 [#1] PREEMPT SMP PTI     [..]     RIP: 0010:to_cxl_port+0x8/0x60 [cxl_core]     [..]     Call Trace:      <TASK>      cxl_region_decode_reset+0x69/0x190 [cxl_core]      cxl_region_detach+0xe8/0x210 [cxl_core]      cxl_decoder_kill_region+0x27/0x40 [cxl_core]      cxld_unregister+0x5d/0x60 [cxl_core]  At 1) a region has been established with 2 endpoint decoders (7.0 and 14.0). Those endpoints share a common switch-decoder in the topology (3.0). At teardown, 2), decoder14.0 is the first to be removed and hits the \"out of order reset case\" in the switch decoder. The effect though is that region3 cleanup is aborted leaving it in-tact and referencing decoder14.0. At 3) the second attempt to teardown region3 trips over the stale decoder14.0 object which has long since been deleted.  The fix here is to recognize that the CXL specification places no mandate on in-order shutdown of switch-decoders, the driver enforces in-order allocation, and hardware enforces in-order commit. So, rather than fail and leave objects dangling, always remove them.  In support of making cxl_region_decode_reset() always succeed, cxl_region_invalidate_memregion() failures are turned into warnings. Crashing the kernel is ok there since system integrity is at risk if caches cannot be managed around physical address mutation events like CXL region destruction.  A new device_for_each_child_reverse_from() is added to cleanup port->commit_end after all dependent decoders have been disabled. In other words if decoders are allocated 0->1->2 and disabled 1->2->0 then port->commit_end only decrements from 2 after 2 has been disabled, and it decrements all the way to zero since 1 was disabled previously.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50226","epss":0.00239,"percentile":0.14982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50226","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50226","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18283500000000003},"relatedVulnerabilities":[{"id":"CVE-2024-50226","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50226","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/101c268bd2f37e965a5468353e62d154db38838e","https://git.kernel.org/stable/c/78c8454fdce0eeee962be004eb6d99860c80dad1","https://git.kernel.org/stable/c/8e1b52c15c81106456437f8e49575040e489e355"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/port: Fix use-after-free, permit out-of-order decoder shutdown\n\nIn support of investigating an initialization failure report [1],\ncxl_test was updated to register mock memory-devices after the mock\nroot-port/bus device had been registered. That led to cxl_test crashing\nwith a use-after-free bug with the following signature:\n\n    cxl_port_attach_region: cxl region3: cxl_host_bridge.0:port3 decoder3.0 add: mem0:decoder7.0 @ 0 next: cxl_switch_uport.0 nr_eps: 1 nr_targets: 1\n    cxl_port_attach_region: cxl region3: cxl_host_bridge.0:port3 decoder3.0 add: mem4:decoder14.0 @ 1 next: cxl_switch_uport.0 nr_eps: 2 nr_targets: 1\n    cxl_port_setup_targets: cxl region3: cxl_switch_uport.0:port6 target[0] = cxl_switch_dport.0 for mem0:decoder7.0 @ 0\n1)  cxl_port_setup_targets: cxl region3: cxl_switch_uport.0:port6 target[1] = cxl_switch_dport.4 for mem4:decoder14.0 @ 1\n    [..]\n    cxld_unregister: cxl decoder14.0:\n    cxl_region_decode_reset: cxl_region region3:\n    mock_decoder_reset: cxl_port port3: decoder3.0 reset\n2)  mock_decoder_reset: cxl_port port3: decoder3.0: out of order reset, expected decoder3.1\n    cxl_endpoint_decoder_release: cxl decoder14.0:\n    [..]\n    cxld_unregister: cxl decoder7.0:\n3)  cxl_region_decode_reset: cxl_region region3:\n    Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6bc3: 0000 [#1] PREEMPT SMP PTI\n    [..]\n    RIP: 0010:to_cxl_port+0x8/0x60 [cxl_core]\n    [..]\n    Call Trace:\n     <TASK>\n     cxl_region_decode_reset+0x69/0x190 [cxl_core]\n     cxl_region_detach+0xe8/0x210 [cxl_core]\n     cxl_decoder_kill_region+0x27/0x40 [cxl_core]\n     cxld_unregister+0x5d/0x60 [cxl_core]\n\nAt 1) a region has been established with 2 endpoint decoders (7.0 and\n14.0). Those endpoints share a common switch-decoder in the topology\n(3.0). At teardown, 2), decoder14.0 is the first to be removed and hits\nthe \"out of order reset case\" in the switch decoder. The effect though\nis that region3 cleanup is aborted leaving it in-tact and\nreferencing decoder14.0. At 3) the second attempt to teardown region3\ntrips over the stale decoder14.0 object which has long since been\ndeleted.\n\nThe fix here is to recognize that the CXL specification places no\nmandate on in-order shutdown of switch-decoders, the driver enforces\nin-order allocation, and hardware enforces in-order commit. So, rather\nthan fail and leave objects dangling, always remove them.\n\nIn support of making cxl_region_decode_reset() always succeed,\ncxl_region_invalidate_memregion() failures are turned into warnings.\nCrashing the kernel is ok there since system integrity is at risk if\ncaches cannot be managed around physical address mutation events like\nCXL region destruction.\n\nA new device_for_each_child_reverse_from() is added to cleanup\nport->commit_end after all dependent decoders have been disabled. In\nother words if decoders are allocated 0->1->2 and disabled 1->2->0 then\nport->commit_end only decrements from 2 after 2 has been disabled, and\nit decrements all the way to zero since 1 was disabled previously.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50226","epss":0.00239,"percentile":0.14982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50226","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50226","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50226","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50282","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50282","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()  Avoid a possible buffer overflow if size is larger than 4K.  (cherry picked from commit f5d873f5825b40d886d03bd2aede91d4cf002434)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50282","epss":0.00273,"percentile":0.1954,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50282","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50282","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.208845},"relatedVulnerabilities":[{"id":"CVE-2024-50282","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50282","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2faaee36e6e30f9efc7fa6bcb0bdcbe05c23f51f","https://git.kernel.org/stable/c/4d75b9468021c73108b4439794d69e892b1d24e3","https://git.kernel.org/stable/c/673bdb4200c092692f83b5f7ba3df57021d52d29","https://git.kernel.org/stable/c/8906728f2fbd6504cb488f4afdd66af28f330a7a","https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()\n\nAvoid a possible buffer overflow if size is larger than 4K.\n\n(cherry picked from commit f5d873f5825b40d886d03bd2aede91d4cf002434)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50282","epss":0.00273,"percentile":0.1954,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50282","cwe":"CWE-120","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50282","cwe":"CWE-120","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50282","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50285","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50285","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: check outstanding simultaneous SMB operations  If Client send simultaneous SMB operations to ksmbd, It exhausts too much memory through the \"ksmbd_work_cache”. It will cause OOM issue. ksmbd has a credit mechanism but it can't handle this problem. This patch add the check if it exceeds max credits to prevent this problem by assuming that one smb request consumes at least one credit.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50285","epss":0.00597,"percentile":0.46605,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50285","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50285","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.313425},"relatedVulnerabilities":[{"id":"CVE-2024-50285","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50285","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0a77d947f599b1f39065015bec99390d0c0022ee","https://git.kernel.org/stable/c/1f993777275cbd8f74765c4f9d9285cb907c9be5","https://git.kernel.org/stable/c/e257ac6fe138623cf59fca8898abdf659dbc8356"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: check outstanding simultaneous SMB operations\n\nIf Client send simultaneous SMB operations to ksmbd, It exhausts too much\nmemory through the \"ksmbd_work_cache”. It will cause OOM issue.\nksmbd has a credit mechanism but it can't handle this problem. This patch\nadd the check if it exceeds max credits to prevent this problem by assuming\nthat one smb request consumes at least one credit.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50285","epss":0.00597,"percentile":0.46605,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-50285","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-50285","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50285","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-50289","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-50289","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: av7110: fix a spectre vulnerability  As warned by smatch: \tdrivers/staging/media/av7110/av7110_ca.c:270 dvb_ca_ioctl() warn: potential spectre issue 'av7110->ci_slot' [w] (local cap)  There is a spectre-related vulnerability at the code. Fix it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50289","epss":0.00177,"percentile":0.07366,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09292500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-50289","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-50289","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/458ea1c0be991573ec436aa0afa23baacfae101a","https://git.kernel.org/stable/c/f3927206c478bd249c225414f7a751752a30e7b9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: av7110: fix a spectre vulnerability\n\nAs warned by smatch:\n\tdrivers/staging/media/av7110/av7110_ca.c:270 dvb_ca_ioctl() warn: potential spectre issue 'av7110->ci_slot' [w] (local cap)\n\nThere is a spectre-related vulnerability at the code. Fix it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-50289","epss":0.00177,"percentile":0.07366,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-50289","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-52559","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52559","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()  The \"submit->cmd[i].size\" and \"submit->cmd[i].offset\" variables are u32 values that come from the user via the submit_lookup_cmds() function. This addition could lead to an integer wrapping bug so use size_add() to prevent that.  Patchwork: https://patchwork.freedesktop.org/patch/624696/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52559","epss":0.00237,"percentile":0.14738,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52559","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-52559","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12442500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-52559","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52559","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2b99b2c4621d13bd4374ef384e8f1fc188d0a5df","https://git.kernel.org/stable/c/2f1845e46c41ed500789d53dc45b383b7745c96c","https://git.kernel.org/stable/c/3a47f4b439beb98e955d501c609dfd12b7836d61","https://git.kernel.org/stable/c/e43a0f1327a1ee70754f8a0de6e0262cfa3e0b87"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()\n\nThe \"submit->cmd[i].size\" and \"submit->cmd[i].offset\" variables are u32\nvalues that come from the user via the submit_lookup_cmds() function.\nThis addition could lead to an integer wrapping bug so use size_add()\nto prevent that.\n\nPatchwork: https://patchwork.freedesktop.org/patch/624696/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52559","epss":0.00237,"percentile":0.14738,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-52559","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-52559","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52559","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-52560","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52560","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()  Extended the `mi_enum_attr()` function interface with an additional parameter, `struct ntfs_inode *ni`, to allow marking the inode as bad as soon as an error is detected.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52560","epss":0.00181,"percentile":0.07788,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095025},"relatedVulnerabilities":[{"id":"CVE-2024-52560","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52560","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2afd4d267e6dbaec8d3ccd4f5396cb84bc67aa2e","https://git.kernel.org/stable/c/d9c699f2c4dc174940ffe8600b20c267897da155"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()\n\nExtended the `mi_enum_attr()` function interface with an additional\nparameter, `struct ntfs_inode *ni`, to allow marking the inode\nas bad as soon as an error is detected.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-52560","epss":0.00181,"percentile":0.07788,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-52560","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53051","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53051","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability  Sometimes during hotplug scenario or suspend/resume scenario encoder is not always initialized when intel_hdcp_get_capability add a check to avoid kernel null pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53051","epss":0.00228,"percentile":0.136,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11969999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-53051","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53051","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/31b42af516afa1e184d1a9f9dd4096c54044269a","https://git.kernel.org/stable/c/4912e8fb3c37fb2dedf48d9c18bbbecd70e720f8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: Add encoder check in intel_hdcp_get_capability\n\nSometimes during hotplug scenario or suspend/resume scenario encoder is\nnot always initialized when intel_hdcp_get_capability add\na check to avoid kernel null pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53051","epss":0.00228,"percentile":0.136,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53051","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53056","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53056","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()  In mtk_crtc_create(), if the call to mbox_request_channel() fails then we set the \"mtk_crtc->cmdq_client.chan\" pointer to NULL.  In that situation, we do not call cmdq_pkt_create().  During the cleanup, we need to check if the \"mtk_crtc->cmdq_client.chan\" is NULL first before calling cmdq_pkt_destroy().  Calling cmdq_pkt_destroy() is unnecessary if we didn't call cmdq_pkt_create() and it will result in a NULL pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53056","epss":0.00206,"percentile":0.10794,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53056","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53056","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-53056","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53056","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4018651ba5c409034149f297d3dd3328b91561fd","https://git.kernel.org/stable/c/c60583a87cb4a85b69d1f448f0be5eb6ec62cbb2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()\n\nIn mtk_crtc_create(), if the call to mbox_request_channel() fails then we\nset the \"mtk_crtc->cmdq_client.chan\" pointer to NULL.  In that situation,\nwe do not call cmdq_pkt_create().\n\nDuring the cleanup, we need to check if the \"mtk_crtc->cmdq_client.chan\"\nis NULL first before calling cmdq_pkt_destroy().  Calling\ncmdq_pkt_destroy() is unnecessary if we didn't call cmdq_pkt_create() and\nit will result in a NULL pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53056","epss":0.00206,"percentile":0.10794,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53056","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53056","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53056","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53068","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53068","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  firmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier()  The scmi_dev->name is released prematurely in __scmi_device_destroy(), which causes slab-use-after-free when accessing scmi_dev->name in scmi_bus_notifier(). So move the release of scmi_dev->name to scmi_device_release() to avoid slab-use-after-free.    |  BUG: KASAN: slab-use-after-free in strncmp+0xe4/0xec   |  Read of size 1 at addr ffffff80a482bcc0 by task swapper/0/1   |   |  CPU: 1 PID: 1 Comm: swapper/0 Not tainted 6.6.38-debug #1   |  Hardware name: Qualcomm Technologies, Inc. SA8775P Ride (DT)   |  Call trace:   |   dump_backtrace+0x94/0x114   |   show_stack+0x18/0x24   |   dump_stack_lvl+0x48/0x60   |   print_report+0xf4/0x5b0   |   kasan_report+0xa4/0xec   |   __asan_report_load1_noabort+0x20/0x2c   |   strncmp+0xe4/0xec   |   scmi_bus_notifier+0x5c/0x54c   |   notifier_call_chain+0xb4/0x31c   |   blocking_notifier_call_chain+0x68/0x9c   |   bus_notify+0x54/0x78   |   device_del+0x1bc/0x840   |   device_unregister+0x20/0xb4   |   __scmi_device_destroy+0xac/0x280   |   scmi_device_destroy+0x94/0xd0   |   scmi_chan_setup+0x524/0x750   |   scmi_probe+0x7fc/0x1508   |   platform_probe+0xc4/0x19c   |   really_probe+0x32c/0x99c   |   __driver_probe_device+0x15c/0x3c4   |   driver_probe_device+0x5c/0x170   |   __driver_attach+0x1c8/0x440   |   bus_for_each_dev+0xf4/0x178   |   driver_attach+0x3c/0x58   |   bus_add_driver+0x234/0x4d4   |   driver_register+0xf4/0x3c0   |   __platform_driver_register+0x60/0x88   |   scmi_driver_init+0xb0/0x104   |   do_one_initcall+0xb4/0x664   |   kernel_init_freeable+0x3c8/0x894   |   kernel_init+0x24/0x1e8   |   ret_from_fork+0x10/0x20   |   |  Allocated by task 1:   |   kasan_save_stack+0x2c/0x54   |   kasan_set_track+0x2c/0x40   |   kasan_save_alloc_info+0x24/0x34   |   __kasan_kmalloc+0xa0/0xb8   |   __kmalloc_node_track_caller+0x6c/0x104   |   kstrdup+0x48/0x84   |   kstrdup_const+0x34/0x40   |   __scmi_device_create.part.0+0x8c/0x408   |   scmi_device_create+0x104/0x370   |   scmi_chan_setup+0x2a0/0x750   |   scmi_probe+0x7fc/0x1508   |   platform_probe+0xc4/0x19c   |   really_probe+0x32c/0x99c   |   __driver_probe_device+0x15c/0x3c4   |   driver_probe_device+0x5c/0x170   |   __driver_attach+0x1c8/0x440   |   bus_for_each_dev+0xf4/0x178   |   driver_attach+0x3c/0x58   |   bus_add_driver+0x234/0x4d4   |   driver_register+0xf4/0x3c0   |   __platform_driver_register+0x60/0x88   |   scmi_driver_init+0xb0/0x104   |   do_one_initcall+0xb4/0x664   |   kernel_init_freeable+0x3c8/0x894   |   kernel_init+0x24/0x1e8   |   ret_from_fork+0x10/0x20   |   |  Freed by task 1:   |   kasan_save_stack+0x2c/0x54   |   kasan_set_track+0x2c/0x40   |   kasan_save_free_info+0x38/0x5c   |   __kasan_slab_free+0xe8/0x164   |   __kmem_cache_free+0x11c/0x230   |   kfree+0x70/0x130   |   kfree_const+0x20/0x40   |   __scmi_device_destroy+0x70/0x280   |   scmi_device_destroy+0x94/0xd0   |   scmi_chan_setup+0x524/0x750   |   scmi_probe+0x7fc/0x1508   |   platform_probe+0xc4/0x19c   |   really_probe+0x32c/0x99c   |   __driver_probe_device+0x15c/0x3c4   |   driver_probe_device+0x5c/0x170   |   __driver_attach+0x1c8/0x440   |   bus_for_each_dev+0xf4/0x178   |   driver_attach+0x3c/0x58   |   bus_add_driver+0x234/0x4d4   |   driver_register+0xf4/0x3c0   |   __platform_driver_register+0x60/0x88   |   scmi_driver_init+0xb0/0x104   |   do_one_initcall+0xb4/0x664   |   kernel_init_freeable+0x3c8/0x894   |   kernel_init+0x24/0x1e8   |   ret_from_fork+0x10/0x20","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53068","epss":0.00221,"percentile":0.12615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53068","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53068","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16906500000000002},"relatedVulnerabilities":[{"id":"CVE-2024-53068","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53068","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/15b17bbcea07d49c43d21aa700485cbd9f9d00d8","https://git.kernel.org/stable/c/1e1f523b185a8ccdcba625b31ff0312d052900e2","https://git.kernel.org/stable/c/295416091e44806760ccf753aeafdafc0ae268f3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier()\n\nThe scmi_dev->name is released prematurely in __scmi_device_destroy(),\nwhich causes slab-use-after-free when accessing scmi_dev->name in\nscmi_bus_notifier(). So move the release of scmi_dev->name to\nscmi_device_release() to avoid slab-use-after-free.\n\n  |  BUG: KASAN: slab-use-after-free in strncmp+0xe4/0xec\n  |  Read of size 1 at addr ffffff80a482bcc0 by task swapper/0/1\n  |\n  |  CPU: 1 PID: 1 Comm: swapper/0 Not tainted 6.6.38-debug #1\n  |  Hardware name: Qualcomm Technologies, Inc. SA8775P Ride (DT)\n  |  Call trace:\n  |   dump_backtrace+0x94/0x114\n  |   show_stack+0x18/0x24\n  |   dump_stack_lvl+0x48/0x60\n  |   print_report+0xf4/0x5b0\n  |   kasan_report+0xa4/0xec\n  |   __asan_report_load1_noabort+0x20/0x2c\n  |   strncmp+0xe4/0xec\n  |   scmi_bus_notifier+0x5c/0x54c\n  |   notifier_call_chain+0xb4/0x31c\n  |   blocking_notifier_call_chain+0x68/0x9c\n  |   bus_notify+0x54/0x78\n  |   device_del+0x1bc/0x840\n  |   device_unregister+0x20/0xb4\n  |   __scmi_device_destroy+0xac/0x280\n  |   scmi_device_destroy+0x94/0xd0\n  |   scmi_chan_setup+0x524/0x750\n  |   scmi_probe+0x7fc/0x1508\n  |   platform_probe+0xc4/0x19c\n  |   really_probe+0x32c/0x99c\n  |   __driver_probe_device+0x15c/0x3c4\n  |   driver_probe_device+0x5c/0x170\n  |   __driver_attach+0x1c8/0x440\n  |   bus_for_each_dev+0xf4/0x178\n  |   driver_attach+0x3c/0x58\n  |   bus_add_driver+0x234/0x4d4\n  |   driver_register+0xf4/0x3c0\n  |   __platform_driver_register+0x60/0x88\n  |   scmi_driver_init+0xb0/0x104\n  |   do_one_initcall+0xb4/0x664\n  |   kernel_init_freeable+0x3c8/0x894\n  |   kernel_init+0x24/0x1e8\n  |   ret_from_fork+0x10/0x20\n  |\n  |  Allocated by task 1:\n  |   kasan_save_stack+0x2c/0x54\n  |   kasan_set_track+0x2c/0x40\n  |   kasan_save_alloc_info+0x24/0x34\n  |   __kasan_kmalloc+0xa0/0xb8\n  |   __kmalloc_node_track_caller+0x6c/0x104\n  |   kstrdup+0x48/0x84\n  |   kstrdup_const+0x34/0x40\n  |   __scmi_device_create.part.0+0x8c/0x408\n  |   scmi_device_create+0x104/0x370\n  |   scmi_chan_setup+0x2a0/0x750\n  |   scmi_probe+0x7fc/0x1508\n  |   platform_probe+0xc4/0x19c\n  |   really_probe+0x32c/0x99c\n  |   __driver_probe_device+0x15c/0x3c4\n  |   driver_probe_device+0x5c/0x170\n  |   __driver_attach+0x1c8/0x440\n  |   bus_for_each_dev+0xf4/0x178\n  |   driver_attach+0x3c/0x58\n  |   bus_add_driver+0x234/0x4d4\n  |   driver_register+0xf4/0x3c0\n  |   __platform_driver_register+0x60/0x88\n  |   scmi_driver_init+0xb0/0x104\n  |   do_one_initcall+0xb4/0x664\n  |   kernel_init_freeable+0x3c8/0x894\n  |   kernel_init+0x24/0x1e8\n  |   ret_from_fork+0x10/0x20\n  |\n  |  Freed by task 1:\n  |   kasan_save_stack+0x2c/0x54\n  |   kasan_set_track+0x2c/0x40\n  |   kasan_save_free_info+0x38/0x5c\n  |   __kasan_slab_free+0xe8/0x164\n  |   __kmem_cache_free+0x11c/0x230\n  |   kfree+0x70/0x130\n  |   kfree_const+0x20/0x40\n  |   __scmi_device_destroy+0x70/0x280\n  |   scmi_device_destroy+0x94/0xd0\n  |   scmi_chan_setup+0x524/0x750\n  |   scmi_probe+0x7fc/0x1508\n  |   platform_probe+0xc4/0x19c\n  |   really_probe+0x32c/0x99c\n  |   __driver_probe_device+0x15c/0x3c4\n  |   driver_probe_device+0x5c/0x170\n  |   __driver_attach+0x1c8/0x440\n  |   bus_for_each_dev+0xf4/0x178\n  |   driver_attach+0x3c/0x58\n  |   bus_add_driver+0x234/0x4d4\n  |   driver_register+0xf4/0x3c0\n  |   __platform_driver_register+0x60/0x88\n  |   scmi_driver_init+0xb0/0x104\n  |   do_one_initcall+0xb4/0x664\n  |   kernel_init_freeable+0x3c8/0x894\n  |   kernel_init+0x24/0x1e8\n  |   ret_from_fork+0x10/0x20","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53068","epss":0.00221,"percentile":0.12615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53068","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53068","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53068","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53079","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/thp: fix deferred split unqueue naming and locking  Recent changes are putting more pressure on THP deferred split queues: under load revealing long-standing races, causing list_del corruptions, \"Bad page state\"s and worse (I keep BUGs in both of those, so usually don't get to see how badly they end up without).  The relevant recent changes being 6.8's mTHP, 6.10's mTHP swapout, and 6.12's mTHP swapin, improved swap allocation, and underused THP splitting.  Before fixing locking: rename misleading folio_undo_large_rmappable(), which does not undo large_rmappable, to folio_unqueue_deferred_split(), which is what it does.  But that and its out-of-line __callee are mm internals of very limited usability: add comment and WARN_ON_ONCEs to check usage; and return a bool to say if a deferred split was unqueued, which can then be used in WARN_ON_ONCEs around safety checks (sparing callers the arcane conditionals in __folio_unqueue_deferred_split()).  Just omit the folio_unqueue_deferred_split() from free_unref_folios(), all of whose callers now call it beforehand (and if any forget then bad_page() will tell) - except for its caller put_pages_list(), which itself no longer has any callers (and will be deleted separately).  Swapout: mem_cgroup_swapout() has been resetting folio->memcg_data 0 without checking and unqueueing a THP folio from deferred split list; which is unfortunate, since the split_queue_lock depends on the memcg (when memcg is enabled); so swapout has been unqueueing such THPs later, when freeing the folio, using the pgdat's lock instead: potentially corrupting the memcg's list.  __remove_mapping() has frozen refcount to 0 here, so no problem with calling folio_unqueue_deferred_split() before resetting memcg_data.  That goes back to 5.4 commit 87eaceb3faa5 (\"mm: thp: make deferred split shrinker memcg aware\"): which included a check on swapcache before adding to deferred queue, but no check on deferred queue before adding THP to swapcache.  That worked fine with the usual sequence of events in reclaim (though there were a couple of rare ways in which a THP on deferred queue could have been swapped out), but 6.12 commit dafff3f4c850 (\"mm: split underused THPs\") avoids splitting underused THPs in reclaim, which makes swapcache THPs on deferred queue commonplace.  Keep the check on swapcache before adding to deferred queue?  Yes: it is no longer essential, but preserves the existing behaviour, and is likely to be a worthwhile optimization (vmstat showed much more traffic on the queue under swapping load if the check was removed); update its comment.  Memcg-v1 move (deprecated): mem_cgroup_move_account() has been changing folio->memcg_data without checking and unqueueing a THP folio from the deferred list, sometimes corrupting \"from\" memcg's list, like swapout.  Refcount is non-zero here, so folio_unqueue_deferred_split() can only be used in a WARN_ON_ONCE to validate the fix, which must be done earlier: mem_cgroup_move_charge_pte_range() first try to split the THP (splitting of course unqueues), or skip it if that fails.  Not ideal, but moving charge has been requested, and khugepaged should repair the THP later: nobody wants new custom unqueueing code just for this deprecated case.  The 87eaceb3faa5 commit did have the code to move from one deferred list to another (but was not conscious of its unsafety while refcount non-0); but that was removed by 5.6 commit fac0516b5534 (\"mm: thp: don't need care deferred split queue in memcg charge move path\"), which argued that the existence of a PMD mapping guarantees that the THP cannot be on a deferred list.  As above, false in rare cases, and now commonly false.  Backport to 6.11 should be straightforward.  Earlier backports must take care that other _deferred_list fixes and dependencies are included.  There is not a strong case for backports, but they can fix cornercases.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53079","epss":0.00178,"percentile":0.0748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53079","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53079","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09345},"relatedVulnerabilities":[{"id":"CVE-2024-53079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53079","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/afb1352d06b1b6b2cfd1f901c766a430c87078b3","https://git.kernel.org/stable/c/f8f931bba0f92052cf842b7e30917b1afcc77d5a","https://git.kernel.org/stable/c/fc4951c3e3358dd82ea508e893695b916c813f17"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/thp: fix deferred split unqueue naming and locking\n\nRecent changes are putting more pressure on THP deferred split queues:\nunder load revealing long-standing races, causing list_del corruptions,\n\"Bad page state\"s and worse (I keep BUGs in both of those, so usually\ndon't get to see how badly they end up without).  The relevant recent\nchanges being 6.8's mTHP, 6.10's mTHP swapout, and 6.12's mTHP swapin,\nimproved swap allocation, and underused THP splitting.\n\nBefore fixing locking: rename misleading folio_undo_large_rmappable(),\nwhich does not undo large_rmappable, to folio_unqueue_deferred_split(),\nwhich is what it does.  But that and its out-of-line __callee are mm\ninternals of very limited usability: add comment and WARN_ON_ONCEs to\ncheck usage; and return a bool to say if a deferred split was unqueued,\nwhich can then be used in WARN_ON_ONCEs around safety checks (sparing\ncallers the arcane conditionals in __folio_unqueue_deferred_split()).\n\nJust omit the folio_unqueue_deferred_split() from free_unref_folios(), all\nof whose callers now call it beforehand (and if any forget then bad_page()\nwill tell) - except for its caller put_pages_list(), which itself no\nlonger has any callers (and will be deleted separately).\n\nSwapout: mem_cgroup_swapout() has been resetting folio->memcg_data 0\nwithout checking and unqueueing a THP folio from deferred split list;\nwhich is unfortunate, since the split_queue_lock depends on the memcg\n(when memcg is enabled); so swapout has been unqueueing such THPs later,\nwhen freeing the folio, using the pgdat's lock instead: potentially\ncorrupting the memcg's list.  __remove_mapping() has frozen refcount to 0\nhere, so no problem with calling folio_unqueue_deferred_split() before\nresetting memcg_data.\n\nThat goes back to 5.4 commit 87eaceb3faa5 (\"mm: thp: make deferred split\nshrinker memcg aware\"): which included a check on swapcache before adding\nto deferred queue, but no check on deferred queue before adding THP to\nswapcache.  That worked fine with the usual sequence of events in reclaim\n(though there were a couple of rare ways in which a THP on deferred queue\ncould have been swapped out), but 6.12 commit dafff3f4c850 (\"mm: split\nunderused THPs\") avoids splitting underused THPs in reclaim, which makes\nswapcache THPs on deferred queue commonplace.\n\nKeep the check on swapcache before adding to deferred queue?  Yes: it is\nno longer essential, but preserves the existing behaviour, and is likely\nto be a worthwhile optimization (vmstat showed much more traffic on the\nqueue under swapping load if the check was removed); update its comment.\n\nMemcg-v1 move (deprecated): mem_cgroup_move_account() has been changing\nfolio->memcg_data without checking and unqueueing a THP folio from the\ndeferred list, sometimes corrupting \"from\" memcg's list, like swapout. \nRefcount is non-zero here, so folio_unqueue_deferred_split() can only be\nused in a WARN_ON_ONCE to validate the fix, which must be done earlier:\nmem_cgroup_move_charge_pte_range() first try to split the THP (splitting\nof course unqueues), or skip it if that fails.  Not ideal, but moving\ncharge has been requested, and khugepaged should repair the THP later:\nnobody wants new custom unqueueing code just for this deprecated case.\n\nThe 87eaceb3faa5 commit did have the code to move from one deferred list\nto another (but was not conscious of its unsafety while refcount non-0);\nbut that was removed by 5.6 commit fac0516b5534 (\"mm: thp: don't need care\ndeferred split queue in memcg charge move path\"), which argued that the\nexistence of a PMD mapping guarantees that the THP cannot be on a deferred\nlist.  As above, false in rare cases, and now commonly false.\n\nBackport to 6.11 should be straightforward.  Earlier backports must take\ncare that other _deferred_list fixes and dependencies are included.  There\nis not a strong case for backports, but they can fix cornercases.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53079","epss":0.00178,"percentile":0.0748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53079","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53079","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53085","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53085","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tpm: Lock TPM chip in tpm_pm_suspend() first  Setting TPM_CHIP_FLAG_SUSPENDED in the end of tpm_pm_suspend() can be racy according, as this leaves window for tpm_hwrng_read() to be called while the operation is in progress. The recent bug report gives also evidence of this behaviour.  Aadress this by locking the TPM chip before checking any chip->flags both in tpm_pm_suspend() and tpm_hwrng_read(). Move TPM_CHIP_FLAG_SUSPENDED check inside tpm_get_random() so that it will be always checked only when the lock is reserved.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53085","epss":0.00171,"percentile":0.06705,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53085","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.089775},"relatedVulnerabilities":[{"id":"CVE-2024-53085","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53085","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/9265fed6db601ee2ec47577815387458ef4f047a","https://git.kernel.org/stable/c/bc203fe416abdd1c29da594565a7c3c4e979488e","https://git.kernel.org/stable/c/cfaf83501a0cbb104499c5b0892ee5ebde4e967f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Lock TPM chip in tpm_pm_suspend() first\n\nSetting TPM_CHIP_FLAG_SUSPENDED in the end of tpm_pm_suspend() can be racy\naccording, as this leaves window for tpm_hwrng_read() to be called while\nthe operation is in progress. The recent bug report gives also evidence of\nthis behaviour.\n\nAadress this by locking the TPM chip before checking any chip->flags both\nin tpm_pm_suspend() and tpm_hwrng_read(). Move TPM_CHIP_FLAG_SUSPENDED\ncheck inside tpm_get_random() so that it will be always checked only when\nthe lock is reserved.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53085","epss":0.00171,"percentile":0.06705,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53085","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53085","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53089","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53089","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: KVM: Mark hrtimer to expire in hard interrupt context  Like commit 2c0d278f3293f (\"KVM: LAPIC: Mark hrtimer to expire in hard interrupt context\") and commit 9090825fa9974 (\"KVM: arm/arm64: Let the timer expire in hardirq context on RT\"), On PREEMPT_RT enabled kernels unmarked hrtimers are moved into soft interrupt expiry mode by default. Then the timers are canceled from an preempt-notifier which is invoked with disabled preemption which is not allowed on PREEMPT_RT.  The timer callback is short so in could be invoked in hard-IRQ context. So let the timer expire on hard-IRQ context even on -RT.  This fix a \"scheduling while atomic\" bug for PREEMPT_RT enabled kernels:   BUG: scheduling while atomic: qemu-system-loo/1011/0x00000002  Modules linked in: amdgpu rfkill nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat ns  CPU: 1 UID: 0 PID: 1011 Comm: qemu-system-loo Tainted: G        W          6.12.0-rc2+ #1774  Tainted: [W]=WARN  Hardware name: Loongson Loongson-3A5000-7A1000-1w-CRB/Loongson-LS3A5000-7A1000-1w-CRB, BIOS vUDK2018-LoongArch-V2.0.0-prebeta9 10/21/2022  Stack : ffffffffffffffff 0000000000000000 9000000004e3ea38 9000000116744000          90000001167475a0 0000000000000000 90000001167475a8 9000000005644830          90000000058dc000 90000000058dbff8 9000000116747420 0000000000000001          0000000000000001 6a613fc938313980 000000000790c000 90000001001c1140          00000000000003fe 0000000000000001 000000000000000d 0000000000000003          0000000000000030 00000000000003f3 000000000790c000 9000000116747830          90000000057ef000 0000000000000000 9000000005644830 0000000000000004          0000000000000000 90000000057f4b58 0000000000000001 9000000116747868          900000000451b600 9000000005644830 9000000003a13998 0000000010000020          00000000000000b0 0000000000000004 0000000000000000 0000000000071c1d          ...  Call Trace:  [<9000000003a13998>] show_stack+0x38/0x180  [<9000000004e3ea34>] dump_stack_lvl+0x84/0xc0  [<9000000003a71708>] __schedule_bug+0x48/0x60  [<9000000004e45734>] __schedule+0x1114/0x1660  [<9000000004e46040>] schedule_rtlock+0x20/0x60  [<9000000004e4e330>] rtlock_slowlock_locked+0x3f0/0x10a0  [<9000000004e4f038>] rt_spin_lock+0x58/0x80  [<9000000003b02d68>] hrtimer_cancel_wait_running+0x68/0xc0  [<9000000003b02e30>] hrtimer_cancel+0x70/0x80  [<ffff80000235eb70>] kvm_restore_timer+0x50/0x1a0 [kvm]  [<ffff8000023616c8>] kvm_arch_vcpu_load+0x68/0x2a0 [kvm]  [<ffff80000234c2d4>] kvm_sched_in+0x34/0x60 [kvm]  [<9000000003a749a0>] finish_task_switch.isra.0+0x140/0x2e0  [<9000000004e44a70>] __schedule+0x450/0x1660  [<9000000004e45cb0>] schedule+0x30/0x180  [<ffff800002354c70>] kvm_vcpu_block+0x70/0x120 [kvm]  [<ffff800002354d80>] kvm_vcpu_halt+0x60/0x3e0 [kvm]  [<ffff80000235b194>] kvm_handle_gspr+0x3f4/0x4e0 [kvm]  [<ffff80000235f548>] kvm_handle_exit+0x1c8/0x260 [kvm]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53089","epss":0.00193,"percentile":0.09054,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.101325},"relatedVulnerabilities":[{"id":"CVE-2024-53089","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53089","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1e4c384a4be9ed1e069e24f388ab2ee9951b77b5","https://git.kernel.org/stable/c/73adbd92f3223dc0c3506822b71c6b259d5d537b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: KVM: Mark hrtimer to expire in hard interrupt context\n\nLike commit 2c0d278f3293f (\"KVM: LAPIC: Mark hrtimer to expire in hard\ninterrupt context\") and commit 9090825fa9974 (\"KVM: arm/arm64: Let the\ntimer expire in hardirq context on RT\"), On PREEMPT_RT enabled kernels\nunmarked hrtimers are moved into soft interrupt expiry mode by default.\nThen the timers are canceled from an preempt-notifier which is invoked\nwith disabled preemption which is not allowed on PREEMPT_RT.\n\nThe timer callback is short so in could be invoked in hard-IRQ context.\nSo let the timer expire on hard-IRQ context even on -RT.\n\nThis fix a \"scheduling while atomic\" bug for PREEMPT_RT enabled kernels:\n\n BUG: scheduling while atomic: qemu-system-loo/1011/0x00000002\n Modules linked in: amdgpu rfkill nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat ns\n CPU: 1 UID: 0 PID: 1011 Comm: qemu-system-loo Tainted: G        W          6.12.0-rc2+ #1774\n Tainted: [W]=WARN\n Hardware name: Loongson Loongson-3A5000-7A1000-1w-CRB/Loongson-LS3A5000-7A1000-1w-CRB, BIOS vUDK2018-LoongArch-V2.0.0-prebeta9 10/21/2022\n Stack : ffffffffffffffff 0000000000000000 9000000004e3ea38 9000000116744000\n         90000001167475a0 0000000000000000 90000001167475a8 9000000005644830\n         90000000058dc000 90000000058dbff8 9000000116747420 0000000000000001\n         0000000000000001 6a613fc938313980 000000000790c000 90000001001c1140\n         00000000000003fe 0000000000000001 000000000000000d 0000000000000003\n         0000000000000030 00000000000003f3 000000000790c000 9000000116747830\n         90000000057ef000 0000000000000000 9000000005644830 0000000000000004\n         0000000000000000 90000000057f4b58 0000000000000001 9000000116747868\n         900000000451b600 9000000005644830 9000000003a13998 0000000010000020\n         00000000000000b0 0000000000000004 0000000000000000 0000000000071c1d\n         ...\n Call Trace:\n [<9000000003a13998>] show_stack+0x38/0x180\n [<9000000004e3ea34>] dump_stack_lvl+0x84/0xc0\n [<9000000003a71708>] __schedule_bug+0x48/0x60\n [<9000000004e45734>] __schedule+0x1114/0x1660\n [<9000000004e46040>] schedule_rtlock+0x20/0x60\n [<9000000004e4e330>] rtlock_slowlock_locked+0x3f0/0x10a0\n [<9000000004e4f038>] rt_spin_lock+0x58/0x80\n [<9000000003b02d68>] hrtimer_cancel_wait_running+0x68/0xc0\n [<9000000003b02e30>] hrtimer_cancel+0x70/0x80\n [<ffff80000235eb70>] kvm_restore_timer+0x50/0x1a0 [kvm]\n [<ffff8000023616c8>] kvm_arch_vcpu_load+0x68/0x2a0 [kvm]\n [<ffff80000234c2d4>] kvm_sched_in+0x34/0x60 [kvm]\n [<9000000003a749a0>] finish_task_switch.isra.0+0x140/0x2e0\n [<9000000004e44a70>] __schedule+0x450/0x1660\n [<9000000004e45cb0>] schedule+0x30/0x180\n [<ffff800002354c70>] kvm_vcpu_block+0x70/0x120 [kvm]\n [<ffff800002354d80>] kvm_vcpu_halt+0x60/0x3e0 [kvm]\n [<ffff80000235b194>] kvm_handle_gspr+0x3f4/0x4e0 [kvm]\n [<ffff80000235f548>] kvm_handle_exit+0x1c8/0x260 [kvm]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53089","epss":0.00193,"percentile":0.09054,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53089","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53090","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53090","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  afs: Fix lock recursion  afs_wake_up_async_call() can incur lock recursion.  The problem is that it is called from AF_RXRPC whilst holding the ->notify_lock, but it tries to take a ref on the afs_call struct in order to pass it to a work queue - but if the afs_call is already queued, we then have an extraneous ref that must be put... calling afs_put_call() may call back down into AF_RXRPC through rxrpc_kernel_shutdown_call(), however, which might try taking the ->notify_lock again.  This case isn't very common, however, so defer it to a workqueue.  The oops looks something like:    BUG: spinlock recursion on CPU#0, krxrpcio/7001/1646    lock: 0xffff888141399b30, .magic: dead4ead, .owner: krxrpcio/7001/1646, .owner_cpu: 0   CPU: 0 UID: 0 PID: 1646 Comm: krxrpcio/7001 Not tainted 6.12.0-rc2-build3+ #4351   Hardware name: ASUS All Series/H97-PLUS, BIOS 2306 10/09/2014   Call Trace:    <TASK>    dump_stack_lvl+0x47/0x70    do_raw_spin_lock+0x3c/0x90    rxrpc_kernel_shutdown_call+0x83/0xb0    afs_put_call+0xd7/0x180    rxrpc_notify_socket+0xa0/0x190    rxrpc_input_split_jumbo+0x198/0x1d0    rxrpc_input_data+0x14b/0x1e0    ? rxrpc_input_call_packet+0xc2/0x1f0    rxrpc_input_call_event+0xad/0x6b0    rxrpc_input_packet_on_conn+0x1e1/0x210    rxrpc_input_packet+0x3f2/0x4d0    rxrpc_io_thread+0x243/0x410    ? __pfx_rxrpc_io_thread+0x10/0x10    kthread+0xcf/0xe0    ? __pfx_kthread+0x10/0x10    ret_from_fork+0x24/0x40    ? __pfx_kthread+0x10/0x10    ret_from_fork_asm+0x1a/0x30    </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53090","epss":0.00461,"percentile":0.38597,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53090","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53090","cwe":"CWE-674","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24202500000000002},"relatedVulnerabilities":[{"id":"CVE-2024-53090","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53090","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/610a79ffea02102899a1373fe226d949944a7ed6","https://git.kernel.org/stable/c/d7cbf81df996b1eae2dee8deb6df08e2eba78661"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix lock recursion\n\nafs_wake_up_async_call() can incur lock recursion.  The problem is that it\nis called from AF_RXRPC whilst holding the ->notify_lock, but it tries to\ntake a ref on the afs_call struct in order to pass it to a work queue - but\nif the afs_call is already queued, we then have an extraneous ref that must\nbe put... calling afs_put_call() may call back down into AF_RXRPC through\nrxrpc_kernel_shutdown_call(), however, which might try taking the\n->notify_lock again.\n\nThis case isn't very common, however, so defer it to a workqueue.  The oops\nlooks something like:\n\n  BUG: spinlock recursion on CPU#0, krxrpcio/7001/1646\n   lock: 0xffff888141399b30, .magic: dead4ead, .owner: krxrpcio/7001/1646, .owner_cpu: 0\n  CPU: 0 UID: 0 PID: 1646 Comm: krxrpcio/7001 Not tainted 6.12.0-rc2-build3+ #4351\n  Hardware name: ASUS All Series/H97-PLUS, BIOS 2306 10/09/2014\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x47/0x70\n   do_raw_spin_lock+0x3c/0x90\n   rxrpc_kernel_shutdown_call+0x83/0xb0\n   afs_put_call+0xd7/0x180\n   rxrpc_notify_socket+0xa0/0x190\n   rxrpc_input_split_jumbo+0x198/0x1d0\n   rxrpc_input_data+0x14b/0x1e0\n   ? rxrpc_input_call_packet+0xc2/0x1f0\n   rxrpc_input_call_event+0xad/0x6b0\n   rxrpc_input_packet_on_conn+0x1e1/0x210\n   rxrpc_input_packet+0x3f2/0x4d0\n   rxrpc_io_thread+0x243/0x410\n   ? __pfx_rxrpc_io_thread+0x10/0x10\n   kthread+0xcf/0xe0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork+0x24/0x40\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork_asm+0x1a/0x30\n   </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53090","epss":0.00461,"percentile":0.38597,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53090","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53090","cwe":"CWE-674","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53090","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53091","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53091","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx  As the introduction of the support for vsock and unix sockets in sockmap, tls_sw_has_ctx_tx/rx cannot presume the socket passed in must be IS_ICSK. vsock and af_unix sockets have vsock_sock and unix_sock instead of inet_connection_sock. For these sockets, tls_get_ctx may return an invalid pointer and cause page fault in function tls_sw_ctx_rx.  BUG: unable to handle page fault for address: 0000000000040030 Workqueue: vsock-loopback vsock_loopback_work RIP: 0010:sk_psock_strp_data_ready+0x23/0x60 Call Trace:  ? __die+0x81/0xc3  ? no_context+0x194/0x350  ? do_page_fault+0x30/0x110  ? async_page_fault+0x3e/0x50  ? sk_psock_strp_data_ready+0x23/0x60  virtio_transport_recv_pkt+0x750/0x800  ? update_load_avg+0x7e/0x620  vsock_loopback_work+0xd0/0x100  process_one_work+0x1a7/0x360  worker_thread+0x30/0x390  ? create_worker+0x1a0/0x1a0  kthread+0x112/0x130  ? __kthread_cancel_work+0x40/0x40  ret_from_fork+0x1f/0x40  v2:   - Add IS_ICSK check v3:   - Update the commits in Fixes","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53091","epss":0.0023,"percentile":0.13794,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12075},"relatedVulnerabilities":[{"id":"CVE-2024-53091","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53091","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/44d0469f79bd3d0b3433732877358df7dc6b17b1","https://git.kernel.org/stable/c/6781cfa93a6a1b7f5be6819a5a2dd8f30f47ca26","https://git.kernel.org/stable/c/a078a480ff3f43d74d8a024ae10c3c7daf6db149"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx\n\nAs the introduction of the support for vsock and unix sockets in sockmap,\ntls_sw_has_ctx_tx/rx cannot presume the socket passed in must be IS_ICSK.\nvsock and af_unix sockets have vsock_sock and unix_sock instead of\ninet_connection_sock. For these sockets, tls_get_ctx may return an invalid\npointer and cause page fault in function tls_sw_ctx_rx.\n\nBUG: unable to handle page fault for address: 0000000000040030\nWorkqueue: vsock-loopback vsock_loopback_work\nRIP: 0010:sk_psock_strp_data_ready+0x23/0x60\nCall Trace:\n ? __die+0x81/0xc3\n ? no_context+0x194/0x350\n ? do_page_fault+0x30/0x110\n ? async_page_fault+0x3e/0x50\n ? sk_psock_strp_data_ready+0x23/0x60\n virtio_transport_recv_pkt+0x750/0x800\n ? update_load_avg+0x7e/0x620\n vsock_loopback_work+0xd0/0x100\n process_one_work+0x1a7/0x360\n worker_thread+0x30/0x390\n ? create_worker+0x1a0/0x1a0\n kthread+0x112/0x130\n ? __kthread_cancel_work+0x40/0x40\n ret_from_fork+0x1f/0x40\n\nv2:\n  - Add IS_ICSK check\nv3:\n  - Update the commits in Fixes","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53091","epss":0.0023,"percentile":0.13794,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53091","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53094","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53094","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES  While running ISER over SIW, the initiator machine encounters a warning from skb_splice_from_iter() indicating that a slab page is being used in send_page. To address this, it is better to add a sendpage_ok() check within the driver itself, and if it returns 0, then MSG_SPLICE_PAGES flag should be disabled before entering the network stack.  A similar issue has been discussed for NVMe in this thread: https://lore.kernel.org/all/20240530142417.146696-1-ofir.gal@volumez.com/    WARNING: CPU: 0 PID: 5342 at net/core/skbuff.c:7140 skb_splice_from_iter+0x173/0x320   Call Trace:    tcp_sendmsg_locked+0x368/0xe40    siw_tx_hdt+0x695/0xa40 [siw]    siw_qp_sq_process+0x102/0xb00 [siw]    siw_sq_resume+0x39/0x110 [siw]    siw_run_sq+0x74/0x160 [siw]    kthread+0xd2/0x100    ret_from_fork+0x34/0x40    ret_from_fork_asm+0x1a/0x30","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53094","epss":0.00588,"percentile":0.46162,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3087},"relatedVulnerabilities":[{"id":"CVE-2024-53094","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53094","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3406bfc813a9bbd9c3055795e985f527b7852e8c","https://git.kernel.org/stable/c/4e1e3dd88a4cedd5ccc1a3fc3d71e03b70a7a791","https://git.kernel.org/stable/c/bb5738957d92c8603a90c9664d34236641c221b2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES\n\nWhile running ISER over SIW, the initiator machine encounters a warning\nfrom skb_splice_from_iter() indicating that a slab page is being used in\nsend_page. To address this, it is better to add a sendpage_ok() check\nwithin the driver itself, and if it returns 0, then MSG_SPLICE_PAGES flag\nshould be disabled before entering the network stack.\n\nA similar issue has been discussed for NVMe in this thread:\nhttps://lore.kernel.org/all/20240530142417.146696-1-ofir.gal@volumez.com/\n\n  WARNING: CPU: 0 PID: 5342 at net/core/skbuff.c:7140 skb_splice_from_iter+0x173/0x320\n  Call Trace:\n   tcp_sendmsg_locked+0x368/0xe40\n   siw_tx_hdt+0x695/0xa40 [siw]\n   siw_qp_sq_process+0x102/0xb00 [siw]\n   siw_sq_resume+0x39/0x110 [siw]\n   siw_run_sq+0x74/0x160 [siw]\n   kthread+0xd2/0x100\n   ret_from_fork+0x34/0x40\n   ret_from_fork_asm+0x1a/0x30","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53094","epss":0.00588,"percentile":0.46162,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53094","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53095","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53095","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: Fix use-after-free of network namespace.  Recently, we got a customer report that CIFS triggers oops while reconnecting to a server.  [0]  The workload runs on Kubernetes, and some pods mount CIFS servers in non-root network namespaces.  The problem rarely happened, but it was always while the pod was dying.  The root cause is wrong reference counting for network namespace.  CIFS uses kernel sockets, which do not hold refcnt of the netns that the socket belongs to.  That means CIFS must ensure the socket is always freed before its netns; otherwise, use-after-free happens.  The repro steps are roughly:    1. mount CIFS in a non-root netns   2. drop packets from the netns   3. destroy the netns   4. unmount CIFS  We can reproduce the issue quickly with the script [1] below and see the splat [2] if CONFIG_NET_NS_REFCNT_TRACKER is enabled.  When the socket is TCP, it is hard to guarantee the netns lifetime without holding refcnt due to async timers.  Let's hold netns refcnt for each socket as done for SMC in commit 9744d2bf1976 (\"smc: Fix use-after-free in tcp_write_timer_handler().\").  Note that we need to move put_net() from cifs_put_tcp_session() to clean_demultiplex_info(); otherwise, __sock_create() still could touch a freed netns while cifsd tries to reconnect from cifs_demultiplex_thread().  Also, maybe_get_net() cannot be put just before __sock_create() because the code is not under RCU and there is a small chance that the same address happened to be reallocated to another netns.  [0]: CIFS: VFS: \\\\XXXXXXXXXXX has not responded in 15 seconds. Reconnecting... CIFS: Serverclose failed 4 times, giving up Unable to handle kernel paging request at virtual address 14de99e461f84a07 Mem abort info:   ESR = 0x0000000096000004   EC = 0x25: DABT (current EL), IL = 32 bits   SET = 0, FnV = 0   EA = 0, S1PTW = 0   FSC = 0x04: level 0 translation fault Data abort info:   ISV = 0, ISS = 0x00000004   CM = 0, WnR = 0 [14de99e461f84a07] address between user and kernel address ranges Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: cls_bpf sch_ingress nls_utf8 cifs cifs_arc4 cifs_md4 dns_resolver tcp_diag inet_diag veth xt_state xt_connmark nf_conntrack_netlink xt_nat xt_statistic xt_MASQUERADE xt_mark xt_addrtype ipt_REJECT nf_reject_ipv4 nft_chain_nat nf_nat xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xt_comment nft_compat nf_tables nfnetlink overlay nls_ascii nls_cp437 sunrpc vfat fat aes_ce_blk aes_ce_cipher ghash_ce sm4_ce_cipher sm4 sm3_ce sm3 sha3_ce sha512_ce sha512_arm64 sha1_ce ena button sch_fq_codel loop fuse configfs dmi_sysfs sha2_ce sha256_arm64 dm_mirror dm_region_hash dm_log dm_mod dax efivarfs CPU: 5 PID: 2690970 Comm: cifsd Not tainted 6.1.103-109.184.amzn2023.aarch64 #1 Hardware name: Amazon EC2 r7g.4xlarge/, BIOS 1.0 11/1/2018 pstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : fib_rules_lookup+0x44/0x238 lr : __fib_lookup+0x64/0xbc sp : ffff8000265db790 x29: ffff8000265db790 x28: 0000000000000000 x27: 000000000000bd01 x26: 0000000000000000 x25: ffff000b4baf8000 x24: ffff00047b5e4580 x23: ffff8000265db7e0 x22: 0000000000000000 x21: ffff00047b5e4500 x20: ffff0010e3f694f8 x19: 14de99e461f849f7 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000 x14: 0000000000000000 x13: 0000000000000000 x12: 3f92800abd010002 x11: 0000000000000001 x10: ffff0010e3f69420 x9 : ffff800008a6f294 x8 : 0000000000000000 x7 : 0000000000000006 x6 : 0000000000000000 x5 : 0000000000000001 x4 : ffff001924354280 x3 : ffff8000265db7e0 x2 : 0000000000000000 x1 : ffff0010e3f694f8 x0 : ffff00047b5e4500 Call trace:  fib_rules_lookup+0x44/0x238  __fib_lookup+0x64/0xbc  ip_route_output_key_hash_rcu+0x2c4/0x398  ip_route_output_key_hash+0x60/0x8c  tcp_v4_connect+0x290/0x488  __inet_stream_connect+0x108/0x3d0  inet_stream_connect+0x50/0x78  kernel_connect+0x6c/0xac  generic_ip_conne ---truncated---","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53095","epss":0.00564,"percentile":0.4501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53095","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.43146},"relatedVulnerabilities":[{"id":"CVE-2024-53095","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53095","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/c7f9282fc27fc36dbaffc8527c723de264a132f8","https://git.kernel.org/stable/c/e8c71494181153a134c96da28766a57bd1eac8cb","https://git.kernel.org/stable/c/ef7134c7fc48e1441b398e55a862232868a6f0a7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free of network namespace.\n\nRecently, we got a customer report that CIFS triggers oops while\nreconnecting to a server.  [0]\n\nThe workload runs on Kubernetes, and some pods mount CIFS servers\nin non-root network namespaces.  The problem rarely happened, but\nit was always while the pod was dying.\n\nThe root cause is wrong reference counting for network namespace.\n\nCIFS uses kernel sockets, which do not hold refcnt of the netns that\nthe socket belongs to.  That means CIFS must ensure the socket is\nalways freed before its netns; otherwise, use-after-free happens.\n\nThe repro steps are roughly:\n\n  1. mount CIFS in a non-root netns\n  2. drop packets from the netns\n  3. destroy the netns\n  4. unmount CIFS\n\nWe can reproduce the issue quickly with the script [1] below and see\nthe splat [2] if CONFIG_NET_NS_REFCNT_TRACKER is enabled.\n\nWhen the socket is TCP, it is hard to guarantee the netns lifetime\nwithout holding refcnt due to async timers.\n\nLet's hold netns refcnt for each socket as done for SMC in commit\n9744d2bf1976 (\"smc: Fix use-after-free in tcp_write_timer_handler().\").\n\nNote that we need to move put_net() from cifs_put_tcp_session() to\nclean_demultiplex_info(); otherwise, __sock_create() still could touch a\nfreed netns while cifsd tries to reconnect from cifs_demultiplex_thread().\n\nAlso, maybe_get_net() cannot be put just before __sock_create() because\nthe code is not under RCU and there is a small chance that the same\naddress happened to be reallocated to another netns.\n\n[0]:\nCIFS: VFS: \\\\XXXXXXXXXXX has not responded in 15 seconds. Reconnecting...\nCIFS: Serverclose failed 4 times, giving up\nUnable to handle kernel paging request at virtual address 14de99e461f84a07\nMem abort info:\n  ESR = 0x0000000096000004\n  EC = 0x25: DABT (current EL), IL = 32 bits\n  SET = 0, FnV = 0\n  EA = 0, S1PTW = 0\n  FSC = 0x04: level 0 translation fault\nData abort info:\n  ISV = 0, ISS = 0x00000004\n  CM = 0, WnR = 0\n[14de99e461f84a07] address between user and kernel address ranges\nInternal error: Oops: 0000000096000004 [#1] SMP\nModules linked in: cls_bpf sch_ingress nls_utf8 cifs cifs_arc4 cifs_md4 dns_resolver tcp_diag inet_diag veth xt_state xt_connmark nf_conntrack_netlink xt_nat xt_statistic xt_MASQUERADE xt_mark xt_addrtype ipt_REJECT nf_reject_ipv4 nft_chain_nat nf_nat xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xt_comment nft_compat nf_tables nfnetlink overlay nls_ascii nls_cp437 sunrpc vfat fat aes_ce_blk aes_ce_cipher ghash_ce sm4_ce_cipher sm4 sm3_ce sm3 sha3_ce sha512_ce sha512_arm64 sha1_ce ena button sch_fq_codel loop fuse configfs dmi_sysfs sha2_ce sha256_arm64 dm_mirror dm_region_hash dm_log dm_mod dax efivarfs\nCPU: 5 PID: 2690970 Comm: cifsd Not tainted 6.1.103-109.184.amzn2023.aarch64 #1\nHardware name: Amazon EC2 r7g.4xlarge/, BIOS 1.0 11/1/2018\npstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : fib_rules_lookup+0x44/0x238\nlr : __fib_lookup+0x64/0xbc\nsp : ffff8000265db790\nx29: ffff8000265db790 x28: 0000000000000000 x27: 000000000000bd01\nx26: 0000000000000000 x25: ffff000b4baf8000 x24: ffff00047b5e4580\nx23: ffff8000265db7e0 x22: 0000000000000000 x21: ffff00047b5e4500\nx20: ffff0010e3f694f8 x19: 14de99e461f849f7 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\nx14: 0000000000000000 x13: 0000000000000000 x12: 3f92800abd010002\nx11: 0000000000000001 x10: ffff0010e3f69420 x9 : ffff800008a6f294\nx8 : 0000000000000000 x7 : 0000000000000006 x6 : 0000000000000000\nx5 : 0000000000000001 x4 : ffff001924354280 x3 : ffff8000265db7e0\nx2 : 0000000000000000 x1 : ffff0010e3f694f8 x0 : ffff00047b5e4500\nCall trace:\n fib_rules_lookup+0x44/0x238\n __fib_lookup+0x64/0xbc\n ip_route_output_key_hash_rcu+0x2c4/0x398\n ip_route_output_key_hash+0x60/0x8c\n tcp_v4_connect+0x290/0x488\n __inet_stream_connect+0x108/0x3d0\n inet_stream_connect+0x50/0x78\n kernel_connect+0x6c/0xac\n generic_ip_conne\n---truncated---","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53095","epss":0.00564,"percentile":0.4501,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53095","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53095","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53114","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53114","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client  A number of Zen4 client SoCs advertise the ability to use virtualized VMLOAD/VMSAVE, but using these instructions is reported to be a cause of a random host reboot.  These instructions aren't intended to be advertised on Zen4 client so clear the capability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53114","epss":0.00206,"percentile":0.10794,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-53114","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53114","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/00c713f84f477a85e524f34aad8fbd11a1c051f0","https://git.kernel.org/stable/c/a5ca1dc46a6b610dd4627d8b633d6c84f9724ef0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client\n\nA number of Zen4 client SoCs advertise the ability to use virtualized\nVMLOAD/VMSAVE, but using these instructions is reported to be a cause\nof a random host reboot.\n\nThese instructions aren't intended to be advertised on Zen4 client\nso clear the capability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53114","epss":0.00206,"percentile":0.10794,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53114","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53134","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53134","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pmdomain: imx93-blk-ctrl: correct remove path  The check condition should be 'i < bc->onecell_data.num_domains', not 'bc->onecell_data.num_domains' which will make the look never finish and cause kernel panic.  Also disable runtime to address \"imx93-blk-ctrl 4ac10000.system-controller: Unbalanced pm_runtime_enable!\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53134","epss":0.00206,"percentile":0.10701,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53134","cwe":"CWE-670","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53134","cwe":"CWE-670","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-53134","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53134","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/201fb9e164a1e4c5937de2cf58bcb0327c08664f","https://git.kernel.org/stable/c/8fc228ab5d38a026eae7183a5f74a4fac43d9b6a","https://git.kernel.org/stable/c/f7c7c5aa556378a2c8da72c1f7f238b6648f95fb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx93-blk-ctrl: correct remove path\n\nThe check condition should be 'i < bc->onecell_data.num_domains', not\n'bc->onecell_data.num_domains' which will make the look never finish\nand cause kernel panic.\n\nAlso disable runtime to address\n\"imx93-blk-ctrl 4ac10000.system-controller: Unbalanced pm_runtime_enable!\"","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53134","epss":0.00206,"percentile":0.10701,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53134","cwe":"CWE-670","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53134","cwe":"CWE-670","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53134","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53147","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  exfat: fix out-of-bounds access of directory entries  In the case of the directory size is greater than or equal to the cluster size, if start_clu becomes an EOF cluster(an invalid cluster) due to file system corruption, then the directory entry where ei->hint_femp.eidx hint is outside the directory, resulting in an out-of-bounds access, which may cause further file system corruption.  This commit adds a check for start_clu, if it is an invalid cluster, the file or directory will be treated as empty.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53147","epss":0.00215,"percentile":0.11831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53147","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53147","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15695},"relatedVulnerabilities":[{"id":"CVE-2024-53147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53147","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/184fa506e392eb78364d9283c961217ff2c0617b","https://git.kernel.org/stable/c/3ddd1cb2b458ff6a193bc845f408dfff217db29e","https://git.kernel.org/stable/c/a0120d6463368378539ef928cf067d02372efb8c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix out-of-bounds access of directory entries\n\nIn the case of the directory size is greater than or equal to\nthe cluster size, if start_clu becomes an EOF cluster(an invalid\ncluster) due to file system corruption, then the directory entry\nwhere ei->hint_femp.eidx hint is outside the directory, resulting\nin an out-of-bounds access, which may cause further file system\ncorruption.\n\nThis commit adds a check for start_clu, if it is an invalid cluster,\nthe file or directory will be treated as empty.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53147","epss":0.00215,"percentile":0.11831,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53147","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53147","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53168","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53168","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket  BUG: KASAN: slab-use-after-free in tcp_write_timer_handler+0x156/0x3e0 Read of size 1 at addr ffff888111f322cd by task swapper/0/0  CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.12.0-rc4-dirty #7 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 Call Trace:  <IRQ>  dump_stack_lvl+0x68/0xa0  print_address_description.constprop.0+0x2c/0x3d0  print_report+0xb4/0x270  kasan_report+0xbd/0xf0  tcp_write_timer_handler+0x156/0x3e0  tcp_write_timer+0x66/0x170  call_timer_fn+0xfb/0x1d0  __run_timers+0x3f8/0x480  run_timer_softirq+0x9b/0x100  handle_softirqs+0x153/0x390  __irq_exit_rcu+0x103/0x120  irq_exit_rcu+0xe/0x20  sysvec_apic_timer_interrupt+0x76/0x90  </IRQ>  <TASK>  asm_sysvec_apic_timer_interrupt+0x1a/0x20 RIP: 0010:default_idle+0xf/0x20 Code: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90  90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 33 f8 25 00 fb f4 <fa> c3 cc cc cc  cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 RSP: 0018:ffffffffa2007e28 EFLAGS: 00000242 RAX: 00000000000f3b31 RBX: 1ffffffff4400fc7 RCX: ffffffffa09c3196 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff9f00590f RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed102360835d R10: ffff88811b041aeb R11: 0000000000000001 R12: 0000000000000000 R13: ffffffffa202d7c0 R14: 0000000000000000 R15: 00000000000147d0  default_idle_call+0x6b/0xa0  cpuidle_idle_call+0x1af/0x1f0  do_idle+0xbc/0x130  cpu_startup_entry+0x33/0x40  rest_init+0x11f/0x210  start_kernel+0x39a/0x420  x86_64_start_reservations+0x18/0x30  x86_64_start_kernel+0x97/0xa0  common_startup_64+0x13e/0x141  </TASK>  Allocated by task 595:  kasan_save_stack+0x24/0x50  kasan_save_track+0x14/0x30  __kasan_slab_alloc+0x87/0x90  kmem_cache_alloc_noprof+0x12b/0x3f0  copy_net_ns+0x94/0x380  create_new_namespaces+0x24c/0x500  unshare_nsproxy_namespaces+0x75/0xf0  ksys_unshare+0x24e/0x4f0  __x64_sys_unshare+0x1f/0x30  do_syscall_64+0x70/0x180  entry_SYSCALL_64_after_hwframe+0x76/0x7e  Freed by task 100:  kasan_save_stack+0x24/0x50  kasan_save_track+0x14/0x30  kasan_save_free_info+0x3b/0x60  __kasan_slab_free+0x54/0x70  kmem_cache_free+0x156/0x5d0  cleanup_net+0x5d3/0x670  process_one_work+0x776/0xa90  worker_thread+0x2e2/0x560  kthread+0x1a8/0x1f0  ret_from_fork+0x34/0x60  ret_from_fork_asm+0x1a/0x30  Reproduction script:  mkdir -p /mnt/nfsshare mkdir -p /mnt/nfs/netns_1 mkfs.ext4 /dev/sdb mount /dev/sdb /mnt/nfsshare systemctl restart nfs-server chmod 777 /mnt/nfsshare exportfs -i -o rw,no_root_squash *:/mnt/nfsshare  ip netns add netns_1 ip link add name veth_1_peer type veth peer veth_1 ifconfig veth_1_peer 11.11.0.254 up ip link set veth_1 netns netns_1 ip netns exec netns_1 ifconfig veth_1 11.11.0.1  ip netns exec netns_1 /root/iptables -A OUTPUT -d 11.11.0.254 -p tcp \\ \t--tcp-flags FIN FIN  -j DROP  (note: In my environment, a DESTROY_CLIENTID operation is always sent  immediately, breaking the nfs tcp connection.) ip netns exec netns_1 timeout -s 9 300 mount -t nfs -o proto=tcp,vers=4.1 \\ \t11.11.0.254:/mnt/nfsshare /mnt/nfs/netns_1  ip netns del netns_1  The reason here is that the tcp socket in netns_1 (nfs side) has been shutdown and closed (done in xs_destroy), but the FIN message (with ack) is discarded, and the nfsd side keeps sending retransmission messages. As a result, when the tcp sock in netns_1 processes the received message, it sends the message (FIN message) in the sending queue, and the tcp timer is re-established. When the network namespace is deleted, the net structure accessed by tcp's timer handler function causes problems.  To fix this problem, let's hold netns refcnt for the tcp kernel socket as done in other modules. This is an ugly hack which can easily be backported to earlier kernels. A proper fix which cleans up the interfaces will follow, but may not be so easy to backport.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53168","epss":0.00252,"percentile":0.16686,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53168","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53168","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19278},"relatedVulnerabilities":[{"id":"CVE-2024-53168","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53168","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0ca87e5063757132a044d35baba40a7d4bb25394","https://git.kernel.org/stable/c/3f23f96528e8fcf8619895c4c916c52653892ec1","https://git.kernel.org/stable/c/61c0a5eac96836de5e3a5897eccdc63162a94936","https://git.kernel.org/stable/c/694ccb05b79ee5f5a9f14c2f80d2635d3bb8bdc3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: fix one UAF issue caused by sunrpc kernel tcp socket\n\nBUG: KASAN: slab-use-after-free in tcp_write_timer_handler+0x156/0x3e0\nRead of size 1 at addr ffff888111f322cd by task swapper/0/0\n\nCPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.12.0-rc4-dirty #7\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1\nCall Trace:\n <IRQ>\n dump_stack_lvl+0x68/0xa0\n print_address_description.constprop.0+0x2c/0x3d0\n print_report+0xb4/0x270\n kasan_report+0xbd/0xf0\n tcp_write_timer_handler+0x156/0x3e0\n tcp_write_timer+0x66/0x170\n call_timer_fn+0xfb/0x1d0\n __run_timers+0x3f8/0x480\n run_timer_softirq+0x9b/0x100\n handle_softirqs+0x153/0x390\n __irq_exit_rcu+0x103/0x120\n irq_exit_rcu+0xe/0x20\n sysvec_apic_timer_interrupt+0x76/0x90\n </IRQ>\n <TASK>\n asm_sysvec_apic_timer_interrupt+0x1a/0x20\nRIP: 0010:default_idle+0xf/0x20\nCode: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90\n 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 33 f8 25 00 fb f4 <fa> c3 cc cc cc\n cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90\nRSP: 0018:ffffffffa2007e28 EFLAGS: 00000242\nRAX: 00000000000f3b31 RBX: 1ffffffff4400fc7 RCX: ffffffffa09c3196\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff9f00590f\nRBP: 0000000000000000 R08: 0000000000000001 R09: ffffed102360835d\nR10: ffff88811b041aeb R11: 0000000000000001 R12: 0000000000000000\nR13: ffffffffa202d7c0 R14: 0000000000000000 R15: 00000000000147d0\n default_idle_call+0x6b/0xa0\n cpuidle_idle_call+0x1af/0x1f0\n do_idle+0xbc/0x130\n cpu_startup_entry+0x33/0x40\n rest_init+0x11f/0x210\n start_kernel+0x39a/0x420\n x86_64_start_reservations+0x18/0x30\n x86_64_start_kernel+0x97/0xa0\n common_startup_64+0x13e/0x141\n </TASK>\n\nAllocated by task 595:\n kasan_save_stack+0x24/0x50\n kasan_save_track+0x14/0x30\n __kasan_slab_alloc+0x87/0x90\n kmem_cache_alloc_noprof+0x12b/0x3f0\n copy_net_ns+0x94/0x380\n create_new_namespaces+0x24c/0x500\n unshare_nsproxy_namespaces+0x75/0xf0\n ksys_unshare+0x24e/0x4f0\n __x64_sys_unshare+0x1f/0x30\n do_syscall_64+0x70/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 100:\n kasan_save_stack+0x24/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x54/0x70\n kmem_cache_free+0x156/0x5d0\n cleanup_net+0x5d3/0x670\n process_one_work+0x776/0xa90\n worker_thread+0x2e2/0x560\n kthread+0x1a8/0x1f0\n ret_from_fork+0x34/0x60\n ret_from_fork_asm+0x1a/0x30\n\nReproduction script:\n\nmkdir -p /mnt/nfsshare\nmkdir -p /mnt/nfs/netns_1\nmkfs.ext4 /dev/sdb\nmount /dev/sdb /mnt/nfsshare\nsystemctl restart nfs-server\nchmod 777 /mnt/nfsshare\nexportfs -i -o rw,no_root_squash *:/mnt/nfsshare\n\nip netns add netns_1\nip link add name veth_1_peer type veth peer veth_1\nifconfig veth_1_peer 11.11.0.254 up\nip link set veth_1 netns netns_1\nip netns exec netns_1 ifconfig veth_1 11.11.0.1\n\nip netns exec netns_1 /root/iptables -A OUTPUT -d 11.11.0.254 -p tcp \\\n\t--tcp-flags FIN FIN  -j DROP\n\n(note: In my environment, a DESTROY_CLIENTID operation is always sent\n immediately, breaking the nfs tcp connection.)\nip netns exec netns_1 timeout -s 9 300 mount -t nfs -o proto=tcp,vers=4.1 \\\n\t11.11.0.254:/mnt/nfsshare /mnt/nfs/netns_1\n\nip netns del netns_1\n\nThe reason here is that the tcp socket in netns_1 (nfs side) has been\nshutdown and closed (done in xs_destroy), but the FIN message (with ack)\nis discarded, and the nfsd side keeps sending retransmission messages.\nAs a result, when the tcp sock in netns_1 processes the received message,\nit sends the message (FIN message) in the sending queue, and the tcp timer\nis re-established. When the network namespace is deleted, the net structure\naccessed by tcp's timer handler function causes problems.\n\nTo fix this problem, let's hold netns refcnt for the tcp kernel socket as\ndone in other modules. This is an ugly hack which can easily be backported\nto earlier kernels. A proper fix which cleans up the interfaces will\nfollow, but may not be so easy to backport.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53168","epss":0.00252,"percentile":0.16686,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53168","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53168","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53168","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53176","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: During unmount, ensure all cached dir instances drop their dentry  The unmount process (cifs_kill_sb() calling close_all_cached_dirs()) can race with various cached directory operations, which ultimately results in dentries not being dropped and these kernel BUGs:  BUG: Dentry ffff88814f37e358{i=1000000000080,n=/}  still in use (2) [unmount of cifs cifs] VFS: Busy inodes after unmount of cifs (cifs) ------------[ cut here ]------------ kernel BUG at fs/super.c:661!  This happens when a cfid is in the process of being cleaned up when, and has been removed from the cfids->entries list, including:  - Receiving a lease break from the server - Server reconnection triggers invalidate_all_cached_dirs(), which   removes all the cfids from the list - The laundromat thread decides to expire an old cfid.  To solve these problems, dropping the dentry is done in queued work done in a newly-added cfid_put_wq workqueue, and close_all_cached_dirs() flushes that workqueue after it drops all the dentries of which it's aware. This is a global workqueue (rather than scoped to a mount), but the queued work is minimal.  The final cleanup work for cleaning up a cfid is performed via work queued in the serverclose_wq workqueue; this is done separate from dropping the dentries so that close_all_cached_dirs() doesn't block on any server operations.  Both of these queued works expect to invoked with a cfid reference and a tcon reference to avoid those objects from being freed while the work is ongoing.  While we're here, add proper locking to close_all_cached_dirs(), and locking around the freeing of cfid->dentry.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53176","epss":0.00554,"percentile":0.44415,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26869},"relatedVulnerabilities":[{"id":"CVE-2024-53176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53176","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3fa640d035e5ae526769615c35cb9ed4be6e3662","https://git.kernel.org/stable/c/548812afd96982a76a93ba76c0582ea670c40d9e","https://git.kernel.org/stable/c/73934e535cffbda1490fa97d82690a0f9aa73e94","https://git.kernel.org/stable/c/ff4528bbc82d0d90073751f7b49e7b9e9c7e5638"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: During unmount, ensure all cached dir instances drop their dentry\n\nThe unmount process (cifs_kill_sb() calling close_all_cached_dirs()) can\nrace with various cached directory operations, which ultimately results\nin dentries not being dropped and these kernel BUGs:\n\nBUG: Dentry ffff88814f37e358{i=1000000000080,n=/}  still in use (2) [unmount of cifs cifs]\nVFS: Busy inodes after unmount of cifs (cifs)\n------------[ cut here ]------------\nkernel BUG at fs/super.c:661!\n\nThis happens when a cfid is in the process of being cleaned up when, and\nhas been removed from the cfids->entries list, including:\n\n- Receiving a lease break from the server\n- Server reconnection triggers invalidate_all_cached_dirs(), which\n  removes all the cfids from the list\n- The laundromat thread decides to expire an old cfid.\n\nTo solve these problems, dropping the dentry is done in queued work done\nin a newly-added cfid_put_wq workqueue, and close_all_cached_dirs()\nflushes that workqueue after it drops all the dentries of which it's\naware. This is a global workqueue (rather than scoped to a mount), but\nthe queued work is minimal.\n\nThe final cleanup work for cleaning up a cfid is performed via work\nqueued in the serverclose_wq workqueue; this is done separate from\ndropping the dentries so that close_all_cached_dirs() doesn't block on\nany server operations.\n\nBoth of these queued works expect to invoked with a cfid reference and\na tcon reference to avoid those objects from being freed while the work\nis ongoing.\n\nWhile we're here, add proper locking to close_all_cached_dirs(), and\nlocking around the freeing of cfid->dentry.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53176","epss":0.00554,"percentile":0.44415,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53176","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53178","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: Don't leak cfid when reconnect races with open_cached_dir  open_cached_dir() may either race with the tcon reconnection even before compound_send_recv() or directly trigger a reconnection via SMB2_open_init() or SMB_query_info_init().  The reconnection process invokes invalidate_all_cached_dirs() via cifs_mark_open_files_invalid(), which removes all cfids from the cfids->entries list but doesn't drop a ref if has_lease isn't true. This results in the currently-being-constructed cfid not being on the list, but still having a refcount of 2. It leaks if returned from open_cached_dir().  Fix this by setting cfid->has_lease when the ref is actually taken; the cfid will not be used by other threads until it has a valid time.  Addresses these kmemleaks:  unreferenced object 0xffff8881090c4000 (size 1024):   comm \"bash\", pid 1860, jiffies 4295126592   hex dump (first 32 bytes):     00 01 00 00 00 00 ad de 22 01 00 00 00 00 ad de  ........\".......     00 ca 45 22 81 88 ff ff f8 dc 4f 04 81 88 ff ff  ..E\"......O.....   backtrace (crc 6f58c20f):     [<ffffffff8b895a1e>] __kmalloc_cache_noprof+0x2be/0x350     [<ffffffff8bda06e3>] open_cached_dir+0x993/0x1fb0     [<ffffffff8bdaa750>] cifs_readdir+0x15a0/0x1d50     [<ffffffff8b9a853f>] iterate_dir+0x28f/0x4b0     [<ffffffff8b9a9aed>] __x64_sys_getdents64+0xfd/0x200     [<ffffffff8cf6da05>] do_syscall_64+0x95/0x1a0     [<ffffffff8d00012f>] entry_SYSCALL_64_after_hwframe+0x76/0x7e unreferenced object 0xffff8881044fdcf8 (size 8):   comm \"bash\", pid 1860, jiffies 4295126592   hex dump (first 8 bytes):     00 cc cc cc cc cc cc cc                          ........   backtrace (crc 10c106a9):     [<ffffffff8b89a3d3>] __kmalloc_node_track_caller_noprof+0x363/0x480     [<ffffffff8b7d7256>] kstrdup+0x36/0x60     [<ffffffff8bda0700>] open_cached_dir+0x9b0/0x1fb0     [<ffffffff8bdaa750>] cifs_readdir+0x15a0/0x1d50     [<ffffffff8b9a853f>] iterate_dir+0x28f/0x4b0     [<ffffffff8b9a9aed>] __x64_sys_getdents64+0xfd/0x200     [<ffffffff8cf6da05>] do_syscall_64+0x95/0x1a0     [<ffffffff8d00012f>] entry_SYSCALL_64_after_hwframe+0x76/0x7e  And addresses these BUG splats when unmounting the SMB filesystem:  BUG: Dentry ffff888140590ba0{i=1000000000080,n=/}  still in use (2) [unmount of cifs cifs] WARNING: CPU: 3 PID: 3433 at fs/dcache.c:1536 umount_check+0xd0/0x100 Modules linked in: CPU: 3 UID: 0 PID: 3433 Comm: bash Not tainted 6.12.0-rc4-g850925a8133c-dirty #49 Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 RIP: 0010:umount_check+0xd0/0x100 Code: 8d 7c 24 40 e8 31 5a f4 ff 49 8b 54 24 40 41 56 49 89 e9 45 89 e8 48 89 d9 41 57 48 89 de 48 c7 c7 80 e7 db ac e8 f0 72 9a ff <0f> 0b 58 31 c0 5a 5b 5d 41 5c 41 5d 41 5e 41 5f e9 2b e5 5d 01 41 RSP: 0018:ffff88811cc27978 EFLAGS: 00010286 RAX: 0000000000000000 RBX: ffff888140590ba0 RCX: ffffffffaaf20bae RDX: dffffc0000000000 RSI: 0000000000000008 RDI: ffff8881f6fb6f40 RBP: ffff8881462ec000 R08: 0000000000000001 R09: ffffed1023984ee3 R10: ffff88811cc2771f R11: 00000000016cfcc0 R12: ffff888134383e08 R13: 0000000000000002 R14: ffff8881462ec668 R15: ffffffffaceab4c0 FS:  00007f23bfa98740(0000) GS:ffff8881f6f80000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000556de4a6f808 CR3: 0000000123c80000 CR4: 0000000000350ef0 Call Trace:  <TASK>  d_walk+0x6a/0x530  shrink_dcache_for_umount+0x6a/0x200  generic_shutdown_super+0x52/0x2a0  kill_anon_super+0x22/0x40  cifs_kill_sb+0x159/0x1e0  deactivate_locked_super+0x66/0xe0  cleanup_mnt+0x140/0x210  task_work_run+0xfb/0x170  syscall_exit_to_user_mode+0x29f/0x2b0  do_syscall_64+0xa1/0x1a0  entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f23bfb93ae7 Code: ff ff ff ff c3 66 0f 1f 44 00 00 48 8b 0d 11 93 0d 00 f7 d8 64 89 01 b8 ff ff ff ff eb bf 0f 1f 44 00 00 b8 50 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d e9 92 0d 00 f7 d8 64 89  ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53178","epss":0.00539,"percentile":0.43615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53178","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53178","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.261415},"relatedVulnerabilities":[{"id":"CVE-2024-53178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53178","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1d76332d783db12684b67592f1fb2057b88af4c3","https://git.kernel.org/stable/c/31fabf70d58388d5475e48ca8a6b7d2847b36678","https://git.kernel.org/stable/c/73a57b25b4df23f22814fc06b7e8f9cf570be026","https://git.kernel.org/stable/c/7afb86733685c64c604d32faf00fa4a1f22c2ab1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Don't leak cfid when reconnect races with open_cached_dir\n\nopen_cached_dir() may either race with the tcon reconnection even before\ncompound_send_recv() or directly trigger a reconnection via\nSMB2_open_init() or SMB_query_info_init().\n\nThe reconnection process invokes invalidate_all_cached_dirs() via\ncifs_mark_open_files_invalid(), which removes all cfids from the\ncfids->entries list but doesn't drop a ref if has_lease isn't true. This\nresults in the currently-being-constructed cfid not being on the list,\nbut still having a refcount of 2. It leaks if returned from\nopen_cached_dir().\n\nFix this by setting cfid->has_lease when the ref is actually taken; the\ncfid will not be used by other threads until it has a valid time.\n\nAddresses these kmemleaks:\n\nunreferenced object 0xffff8881090c4000 (size 1024):\n  comm \"bash\", pid 1860, jiffies 4295126592\n  hex dump (first 32 bytes):\n    00 01 00 00 00 00 ad de 22 01 00 00 00 00 ad de  ........\".......\n    00 ca 45 22 81 88 ff ff f8 dc 4f 04 81 88 ff ff  ..E\"......O.....\n  backtrace (crc 6f58c20f):\n    [<ffffffff8b895a1e>] __kmalloc_cache_noprof+0x2be/0x350\n    [<ffffffff8bda06e3>] open_cached_dir+0x993/0x1fb0\n    [<ffffffff8bdaa750>] cifs_readdir+0x15a0/0x1d50\n    [<ffffffff8b9a853f>] iterate_dir+0x28f/0x4b0\n    [<ffffffff8b9a9aed>] __x64_sys_getdents64+0xfd/0x200\n    [<ffffffff8cf6da05>] do_syscall_64+0x95/0x1a0\n    [<ffffffff8d00012f>] entry_SYSCALL_64_after_hwframe+0x76/0x7e\nunreferenced object 0xffff8881044fdcf8 (size 8):\n  comm \"bash\", pid 1860, jiffies 4295126592\n  hex dump (first 8 bytes):\n    00 cc cc cc cc cc cc cc                          ........\n  backtrace (crc 10c106a9):\n    [<ffffffff8b89a3d3>] __kmalloc_node_track_caller_noprof+0x363/0x480\n    [<ffffffff8b7d7256>] kstrdup+0x36/0x60\n    [<ffffffff8bda0700>] open_cached_dir+0x9b0/0x1fb0\n    [<ffffffff8bdaa750>] cifs_readdir+0x15a0/0x1d50\n    [<ffffffff8b9a853f>] iterate_dir+0x28f/0x4b0\n    [<ffffffff8b9a9aed>] __x64_sys_getdents64+0xfd/0x200\n    [<ffffffff8cf6da05>] do_syscall_64+0x95/0x1a0\n    [<ffffffff8d00012f>] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nAnd addresses these BUG splats when unmounting the SMB filesystem:\n\nBUG: Dentry ffff888140590ba0{i=1000000000080,n=/}  still in use (2) [unmount of cifs cifs]\nWARNING: CPU: 3 PID: 3433 at fs/dcache.c:1536 umount_check+0xd0/0x100\nModules linked in:\nCPU: 3 UID: 0 PID: 3433 Comm: bash Not tainted 6.12.0-rc4-g850925a8133c-dirty #49\nHardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020\nRIP: 0010:umount_check+0xd0/0x100\nCode: 8d 7c 24 40 e8 31 5a f4 ff 49 8b 54 24 40 41 56 49 89 e9 45 89 e8 48 89 d9 41 57 48 89 de 48 c7 c7 80 e7 db ac e8 f0 72 9a ff <0f> 0b 58 31 c0 5a 5b 5d 41 5c 41 5d 41 5e 41 5f e9 2b e5 5d 01 41\nRSP: 0018:ffff88811cc27978 EFLAGS: 00010286\nRAX: 0000000000000000 RBX: ffff888140590ba0 RCX: ffffffffaaf20bae\nRDX: dffffc0000000000 RSI: 0000000000000008 RDI: ffff8881f6fb6f40\nRBP: ffff8881462ec000 R08: 0000000000000001 R09: ffffed1023984ee3\nR10: ffff88811cc2771f R11: 00000000016cfcc0 R12: ffff888134383e08\nR13: 0000000000000002 R14: ffff8881462ec668 R15: ffffffffaceab4c0\nFS:  00007f23bfa98740(0000) GS:ffff8881f6f80000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000556de4a6f808 CR3: 0000000123c80000 CR4: 0000000000350ef0\nCall Trace:\n <TASK>\n d_walk+0x6a/0x530\n shrink_dcache_for_umount+0x6a/0x200\n generic_shutdown_super+0x52/0x2a0\n kill_anon_super+0x22/0x40\n cifs_kill_sb+0x159/0x1e0\n deactivate_locked_super+0x66/0xe0\n cleanup_mnt+0x140/0x210\n task_work_run+0xfb/0x170\n syscall_exit_to_user_mode+0x29f/0x2b0\n do_syscall_64+0xa1/0x1a0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f23bfb93ae7\nCode: ff ff ff ff c3 66 0f 1f 44 00 00 48 8b 0d 11 93 0d 00 f7 d8 64 89 01 b8 ff ff ff ff eb bf 0f 1f 44 00 00 b8 50 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d e9 92 0d 00 f7 d8 64 89 \n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53178","epss":0.00539,"percentile":0.43615,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53178","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53178","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53179","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix use-after-free of signing key  Customers have reported use-after-free in @ses->auth_key.response with SMB2.1 + sign mounts which occurs due to following race:  task A                         task B cifs_mount()  dfs_mount_share()   get_session()    cifs_mount_get_session()    cifs_send_recv()     cifs_get_smb_ses()          compound_send_recv()      cifs_setup_session()        smb2_setup_request()       kfree_sensitive()           smb2_calc_signature()                                    crypto_shash_setkey() *UAF*  Fix this by ensuring that we have a valid @ses->auth_key.response by checking whether @ses->ses_status is SES_GOOD or SES_EXITING with @ses->ses_lock held.  After commit 24a9799aa8ef (\"smb: client: fix UAF in smb2_reconnect_server()\"), we made sure to call ->logoff() only when @ses was known to be good (e.g. valid ->auth_key.response), so it's safe to access signing key when @ses->ses_status == SES_EXITING.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53179","epss":0.00603,"percentile":0.46859,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53179","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53179","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.461295},"relatedVulnerabilities":[{"id":"CVE-2024-53179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53179","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0e2b654a3848bf9da3b0d54c1ccf3f1b8c635591","https://git.kernel.org/stable/c/343d7fe6df9e247671440a932b6a73af4fa86d95","https://git.kernel.org/stable/c/39619c65ab4bbb3e78c818f537687653e112764d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free of signing key\n\nCustomers have reported use-after-free in @ses->auth_key.response with\nSMB2.1 + sign mounts which occurs due to following race:\n\ntask A                         task B\ncifs_mount()\n dfs_mount_share()\n  get_session()\n   cifs_mount_get_session()    cifs_send_recv()\n    cifs_get_smb_ses()          compound_send_recv()\n     cifs_setup_session()        smb2_setup_request()\n      kfree_sensitive()           smb2_calc_signature()\n                                   crypto_shash_setkey() *UAF*\n\nFix this by ensuring that we have a valid @ses->auth_key.response by\nchecking whether @ses->ses_status is SES_GOOD or SES_EXITING with\n@ses->ses_lock held.  After commit 24a9799aa8ef (\"smb: client: fix UAF\nin smb2_reconnect_server()\"), we made sure to call ->logoff() only\nwhen @ses was known to be good (e.g. valid ->auth_key.response), so\nit's safe to access signing key when @ses->ses_status == SES_EXITING.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53179","epss":0.00603,"percentile":0.46859,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53179","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53179","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53187","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53187","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  io_uring: check for overflows in io_pin_pages  WARNING: CPU: 0 PID: 5834 at io_uring/memmap.c:144 io_pin_pages+0x149/0x180 io_uring/memmap.c:144 CPU: 0 UID: 0 PID: 5834 Comm: syz-executor825 Not tainted 6.12.0-next-20241118-syzkaller #0 Call Trace:  <TASK>  __io_uaddr_map+0xfb/0x2d0 io_uring/memmap.c:183  io_rings_map io_uring/io_uring.c:2611 [inline]  io_allocate_scq_urings+0x1c0/0x650 io_uring/io_uring.c:3470  io_uring_create+0x5b5/0xc00 io_uring/io_uring.c:3692  io_uring_setup io_uring/io_uring.c:3781 [inline]  ...  </TASK>  io_pin_pages()'s uaddr parameter came directly from the user and can be garbage. Don't just add size to it as it can overflow.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53187","epss":0.00236,"percentile":0.14603,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53187","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53187","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12390000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-53187","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53187","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0c0a4eae26ac78379d0c1db053de168a8febc6c9","https://git.kernel.org/stable/c/29eac3eca72d4c2a71122050c37cd7d8f73ac4f3","https://git.kernel.org/stable/c/aaa90844afd499c9142d0199dfda74439314c013"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: check for overflows in io_pin_pages\n\nWARNING: CPU: 0 PID: 5834 at io_uring/memmap.c:144 io_pin_pages+0x149/0x180 io_uring/memmap.c:144\nCPU: 0 UID: 0 PID: 5834 Comm: syz-executor825 Not tainted 6.12.0-next-20241118-syzkaller #0\nCall Trace:\n <TASK>\n __io_uaddr_map+0xfb/0x2d0 io_uring/memmap.c:183\n io_rings_map io_uring/io_uring.c:2611 [inline]\n io_allocate_scq_urings+0x1c0/0x650 io_uring/io_uring.c:3470\n io_uring_create+0x5b5/0xc00 io_uring/io_uring.c:3692\n io_uring_setup io_uring/io_uring.c:3781 [inline]\n ...\n </TASK>\n\nio_pin_pages()'s uaddr parameter came directly from the user and can be\ngarbage. Don't just add size to it as it can overflow.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53187","epss":0.00236,"percentile":0.14603,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53187","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53187","cwe":"CWE-190","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53187","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53195","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53195","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: arm64: Get rid of userspace_irqchip_in_use  Improper use of userspace_irqchip_in_use led to syzbot hitting the following WARN_ON() in kvm_timer_update_irq():  WARNING: CPU: 0 PID: 3281 at arch/arm64/kvm/arch_timer.c:459 kvm_timer_update_irq+0x21c/0x394 Call trace:   kvm_timer_update_irq+0x21c/0x394 arch/arm64/kvm/arch_timer.c:459   kvm_timer_vcpu_reset+0x158/0x684 arch/arm64/kvm/arch_timer.c:968   kvm_reset_vcpu+0x3b4/0x560 arch/arm64/kvm/reset.c:264   kvm_vcpu_set_target arch/arm64/kvm/arm.c:1553 [inline]   kvm_arch_vcpu_ioctl_vcpu_init arch/arm64/kvm/arm.c:1573 [inline]   kvm_arch_vcpu_ioctl+0x112c/0x1b3c arch/arm64/kvm/arm.c:1695   kvm_vcpu_ioctl+0x4ec/0xf74 virt/kvm/kvm_main.c:4658   vfs_ioctl fs/ioctl.c:51 [inline]   __do_sys_ioctl fs/ioctl.c:907 [inline]   __se_sys_ioctl fs/ioctl.c:893 [inline]   __arm64_sys_ioctl+0x108/0x184 fs/ioctl.c:893   __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]   invoke_syscall+0x78/0x1b8 arch/arm64/kernel/syscall.c:49   el0_svc_common+0xe8/0x1b0 arch/arm64/kernel/syscall.c:132   do_el0_svc+0x40/0x50 arch/arm64/kernel/syscall.c:151   el0_svc+0x54/0x14c arch/arm64/kernel/entry-common.c:712   el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730   el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598  The following sequence led to the scenario:  - Userspace creates a VM and a vCPU.  - The vCPU is initialized with KVM_ARM_VCPU_PMU_V3 during    KVM_ARM_VCPU_INIT.  - Without any other setup, such as vGIC or vPMU, userspace issues    KVM_RUN on the vCPU. Since the vPMU is requested, but not setup,    kvm_arm_pmu_v3_enable() fails in kvm_arch_vcpu_run_pid_change().    As a result, KVM_RUN returns after enabling the timer, but before    incrementing 'userspace_irqchip_in_use':    kvm_arch_vcpu_run_pid_change()        ret = kvm_arm_pmu_v3_enable()            if (!vcpu->arch.pmu.created)                return -EINVAL;        if (ret)            return ret;        [...]        if (!irqchip_in_kernel(kvm))            static_branch_inc(&userspace_irqchip_in_use);  - Userspace ignores the error and issues KVM_ARM_VCPU_INIT again.    Since the timer is already enabled, control moves through the    following flow, ultimately hitting the WARN_ON():    kvm_timer_vcpu_reset()        if (timer->enabled)           kvm_timer_update_irq()               if (!userspace_irqchip())                   ret = kvm_vgic_inject_irq()                       ret = vgic_lazy_init()                           if (unlikely(!vgic_initialized(kvm)))                               if (kvm->arch.vgic.vgic_model !=                                   KVM_DEV_TYPE_ARM_VGIC_V2)                                       return -EBUSY;                   WARN_ON(ret);  Theoretically, since userspace_irqchip_in_use's functionality can be simply replaced by '!irqchip_in_kernel()', get rid of the static key to avoid the mismanagement, which also helps with the syzbot issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53195","epss":0.00218,"percentile":0.12168,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11445000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-53195","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53195","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/38d7aacca09230fdb98a34194fec2af597e8e20d","https://git.kernel.org/stable/c/c16e2dba39ff6ae84bb8dc9c8e0fb21d9b2f6f5c","https://git.kernel.org/stable/c/dd2f9861f27571d47998d71e7516bf7216db0b52","https://git.kernel.org/stable/c/fe425d5239a28c21e0c83ee7a8f4cb210d29fdb4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Get rid of userspace_irqchip_in_use\n\nImproper use of userspace_irqchip_in_use led to syzbot hitting the\nfollowing WARN_ON() in kvm_timer_update_irq():\n\nWARNING: CPU: 0 PID: 3281 at arch/arm64/kvm/arch_timer.c:459\nkvm_timer_update_irq+0x21c/0x394\nCall trace:\n  kvm_timer_update_irq+0x21c/0x394 arch/arm64/kvm/arch_timer.c:459\n  kvm_timer_vcpu_reset+0x158/0x684 arch/arm64/kvm/arch_timer.c:968\n  kvm_reset_vcpu+0x3b4/0x560 arch/arm64/kvm/reset.c:264\n  kvm_vcpu_set_target arch/arm64/kvm/arm.c:1553 [inline]\n  kvm_arch_vcpu_ioctl_vcpu_init arch/arm64/kvm/arm.c:1573 [inline]\n  kvm_arch_vcpu_ioctl+0x112c/0x1b3c arch/arm64/kvm/arm.c:1695\n  kvm_vcpu_ioctl+0x4ec/0xf74 virt/kvm/kvm_main.c:4658\n  vfs_ioctl fs/ioctl.c:51 [inline]\n  __do_sys_ioctl fs/ioctl.c:907 [inline]\n  __se_sys_ioctl fs/ioctl.c:893 [inline]\n  __arm64_sys_ioctl+0x108/0x184 fs/ioctl.c:893\n  __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n  invoke_syscall+0x78/0x1b8 arch/arm64/kernel/syscall.c:49\n  el0_svc_common+0xe8/0x1b0 arch/arm64/kernel/syscall.c:132\n  do_el0_svc+0x40/0x50 arch/arm64/kernel/syscall.c:151\n  el0_svc+0x54/0x14c arch/arm64/kernel/entry-common.c:712\n  el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730\n  el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\n\nThe following sequence led to the scenario:\n - Userspace creates a VM and a vCPU.\n - The vCPU is initialized with KVM_ARM_VCPU_PMU_V3 during\n   KVM_ARM_VCPU_INIT.\n - Without any other setup, such as vGIC or vPMU, userspace issues\n   KVM_RUN on the vCPU. Since the vPMU is requested, but not setup,\n   kvm_arm_pmu_v3_enable() fails in kvm_arch_vcpu_run_pid_change().\n   As a result, KVM_RUN returns after enabling the timer, but before\n   incrementing 'userspace_irqchip_in_use':\n   kvm_arch_vcpu_run_pid_change()\n       ret = kvm_arm_pmu_v3_enable()\n           if (!vcpu->arch.pmu.created)\n               return -EINVAL;\n       if (ret)\n           return ret;\n       [...]\n       if (!irqchip_in_kernel(kvm))\n           static_branch_inc(&userspace_irqchip_in_use);\n - Userspace ignores the error and issues KVM_ARM_VCPU_INIT again.\n   Since the timer is already enabled, control moves through the\n   following flow, ultimately hitting the WARN_ON():\n   kvm_timer_vcpu_reset()\n       if (timer->enabled)\n          kvm_timer_update_irq()\n              if (!userspace_irqchip())\n                  ret = kvm_vgic_inject_irq()\n                      ret = vgic_lazy_init()\n                          if (unlikely(!vgic_initialized(kvm)))\n                              if (kvm->arch.vgic.vgic_model !=\n                                  KVM_DEV_TYPE_ARM_VGIC_V2)\n                                      return -EBUSY;\n                  WARN_ON(ret);\n\nTheoretically, since userspace_irqchip_in_use's functionality can be\nsimply replaced by '!irqchip_in_kernel()', get rid of the static key\nto avoid the mismanagement, which also helps with the syzbot issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53195","epss":0.00218,"percentile":0.12168,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53195","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53216","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53216","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfsd: release svc_expkey/svc_export with rcu_work  The last reference for `cache_head` can be reduced to zero in `c_show` and `e_show`(using `rcu_read_lock` and `rcu_read_unlock`). Consequently, `svc_export_put` and `expkey_put` will be invoked, leading to two issues:  1. The `svc_export_put` will directly free ex_uuid. However,    `e_show`/`c_show` will access `ex_uuid` after `cache_put`, which can    trigger a use-after-free issue, shown below.     ==================================================================    BUG: KASAN: slab-use-after-free in svc_export_show+0x362/0x430 [nfsd]    Read of size 1 at addr ff11000010fdc120 by task cat/870     CPU: 1 UID: 0 PID: 870 Comm: cat Not tainted 6.12.0-rc3+ #1    Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS    1.16.1-2.fc37 04/01/2014    Call Trace:     <TASK>     dump_stack_lvl+0x53/0x70     print_address_description.constprop.0+0x2c/0x3a0     print_report+0xb9/0x280     kasan_report+0xae/0xe0     svc_export_show+0x362/0x430 [nfsd]     c_show+0x161/0x390 [sunrpc]     seq_read_iter+0x589/0x770     seq_read+0x1e5/0x270     proc_reg_read+0xe1/0x140     vfs_read+0x125/0x530     ksys_read+0xc1/0x160     do_syscall_64+0x5f/0x170     entry_SYSCALL_64_after_hwframe+0x76/0x7e     Allocated by task 830:     kasan_save_stack+0x20/0x40     kasan_save_track+0x14/0x30     __kasan_kmalloc+0x8f/0xa0     __kmalloc_node_track_caller_noprof+0x1bc/0x400     kmemdup_noprof+0x22/0x50     svc_export_parse+0x8a9/0xb80 [nfsd]     cache_do_downcall+0x71/0xa0 [sunrpc]     cache_write_procfs+0x8e/0xd0 [sunrpc]     proc_reg_write+0xe1/0x140     vfs_write+0x1a5/0x6d0     ksys_write+0xc1/0x160     do_syscall_64+0x5f/0x170     entry_SYSCALL_64_after_hwframe+0x76/0x7e     Freed by task 868:     kasan_save_stack+0x20/0x40     kasan_save_track+0x14/0x30     kasan_save_free_info+0x3b/0x60     __kasan_slab_free+0x37/0x50     kfree+0xf3/0x3e0     svc_export_put+0x87/0xb0 [nfsd]     cache_purge+0x17f/0x1f0 [sunrpc]     nfsd_destroy_serv+0x226/0x2d0 [nfsd]     nfsd_svc+0x125/0x1e0 [nfsd]     write_threads+0x16a/0x2a0 [nfsd]     nfsctl_transaction_write+0x74/0xa0 [nfsd]     vfs_write+0x1a5/0x6d0     ksys_write+0xc1/0x160     do_syscall_64+0x5f/0x170     entry_SYSCALL_64_after_hwframe+0x76/0x7e  2. We cannot sleep while using `rcu_read_lock`/`rcu_read_unlock`.    However, `svc_export_put`/`expkey_put` will call path_put, which    subsequently triggers a sleeping operation due to the following    `dput`.     =============================    WARNING: suspicious RCU usage    5.10.0-dirty #141 Not tainted    -----------------------------    ...    Call Trace:    dump_stack+0x9a/0xd0    ___might_sleep+0x231/0x240    dput+0x39/0x600    path_put+0x1b/0x30    svc_export_put+0x17/0x80    e_show+0x1c9/0x200    seq_read_iter+0x63f/0x7c0    seq_read+0x226/0x2d0    vfs_read+0x113/0x2c0    ksys_read+0xc9/0x170    do_syscall_64+0x33/0x40    entry_SYSCALL_64_after_hwframe+0x67/0xd1  Fix these issues by using `rcu_work` to help release `svc_expkey`/`svc_export`. This approach allows for an asynchronous context to invoke `path_put` and also facilitates the freeing of `uuid/exp/key` after an RCU grace period.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53216","epss":0.00222,"percentile":0.12716,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53216","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16983000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-53216","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53216","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2e4854599200f4d021df8ae17e69221d7c149f3e","https://git.kernel.org/stable/c/ad4363a24a5746b257c0beb5d8cc68f9b62c173f","https://git.kernel.org/stable/c/bd8524148dd8c123334b066faa90590ba2ef8e6f","https://git.kernel.org/stable/c/f8c989a0c89a75d30f899a7cabdc14d72522bb8d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: release svc_expkey/svc_export with rcu_work\n\nThe last reference for `cache_head` can be reduced to zero in `c_show`\nand `e_show`(using `rcu_read_lock` and `rcu_read_unlock`). Consequently,\n`svc_export_put` and `expkey_put` will be invoked, leading to two\nissues:\n\n1. The `svc_export_put` will directly free ex_uuid. However,\n   `e_show`/`c_show` will access `ex_uuid` after `cache_put`, which can\n   trigger a use-after-free issue, shown below.\n\n   ==================================================================\n   BUG: KASAN: slab-use-after-free in svc_export_show+0x362/0x430 [nfsd]\n   Read of size 1 at addr ff11000010fdc120 by task cat/870\n\n   CPU: 1 UID: 0 PID: 870 Comm: cat Not tainted 6.12.0-rc3+ #1\n   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n   1.16.1-2.fc37 04/01/2014\n   Call Trace:\n    <TASK>\n    dump_stack_lvl+0x53/0x70\n    print_address_description.constprop.0+0x2c/0x3a0\n    print_report+0xb9/0x280\n    kasan_report+0xae/0xe0\n    svc_export_show+0x362/0x430 [nfsd]\n    c_show+0x161/0x390 [sunrpc]\n    seq_read_iter+0x589/0x770\n    seq_read+0x1e5/0x270\n    proc_reg_read+0xe1/0x140\n    vfs_read+0x125/0x530\n    ksys_read+0xc1/0x160\n    do_syscall_64+0x5f/0x170\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n   Allocated by task 830:\n    kasan_save_stack+0x20/0x40\n    kasan_save_track+0x14/0x30\n    __kasan_kmalloc+0x8f/0xa0\n    __kmalloc_node_track_caller_noprof+0x1bc/0x400\n    kmemdup_noprof+0x22/0x50\n    svc_export_parse+0x8a9/0xb80 [nfsd]\n    cache_do_downcall+0x71/0xa0 [sunrpc]\n    cache_write_procfs+0x8e/0xd0 [sunrpc]\n    proc_reg_write+0xe1/0x140\n    vfs_write+0x1a5/0x6d0\n    ksys_write+0xc1/0x160\n    do_syscall_64+0x5f/0x170\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n   Freed by task 868:\n    kasan_save_stack+0x20/0x40\n    kasan_save_track+0x14/0x30\n    kasan_save_free_info+0x3b/0x60\n    __kasan_slab_free+0x37/0x50\n    kfree+0xf3/0x3e0\n    svc_export_put+0x87/0xb0 [nfsd]\n    cache_purge+0x17f/0x1f0 [sunrpc]\n    nfsd_destroy_serv+0x226/0x2d0 [nfsd]\n    nfsd_svc+0x125/0x1e0 [nfsd]\n    write_threads+0x16a/0x2a0 [nfsd]\n    nfsctl_transaction_write+0x74/0xa0 [nfsd]\n    vfs_write+0x1a5/0x6d0\n    ksys_write+0xc1/0x160\n    do_syscall_64+0x5f/0x170\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n2. We cannot sleep while using `rcu_read_lock`/`rcu_read_unlock`.\n   However, `svc_export_put`/`expkey_put` will call path_put, which\n   subsequently triggers a sleeping operation due to the following\n   `dput`.\n\n   =============================\n   WARNING: suspicious RCU usage\n   5.10.0-dirty #141 Not tainted\n   -----------------------------\n   ...\n   Call Trace:\n   dump_stack+0x9a/0xd0\n   ___might_sleep+0x231/0x240\n   dput+0x39/0x600\n   path_put+0x1b/0x30\n   svc_export_put+0x17/0x80\n   e_show+0x1c9/0x200\n   seq_read_iter+0x63f/0x7c0\n   seq_read+0x226/0x2d0\n   vfs_read+0x113/0x2c0\n   ksys_read+0xc9/0x170\n   do_syscall_64+0x33/0x40\n   entry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nFix these issues by using `rcu_work` to help release\n`svc_expkey`/`svc_export`. This approach allows for an asynchronous\ncontext to invoke `path_put` and also facilitates the freeing of\n`uuid/exp/key` after an RCU grace period.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53216","epss":0.00222,"percentile":0.12716,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53216","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53216","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53218","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53218","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix race in concurrent f2fs_stop_gc_thread  In my test case, concurrent calls to f2fs shutdown report the following stack trace:   Oops: general protection fault, probably for non-canonical address 0xc6cfff63bb5513fc: 0000 [#1] PREEMPT SMP PTI  CPU: 0 UID: 0 PID: 678 Comm: f2fs_rep_shutdo Not tainted 6.12.0-rc5-next-20241029-g6fb2fa9805c5-dirty #85  Call Trace:   <TASK>   ? show_regs+0x8b/0xa0   ? __die_body+0x26/0xa0   ? die_addr+0x54/0x90   ? exc_general_protection+0x24b/0x5c0   ? asm_exc_general_protection+0x26/0x30   ? kthread_stop+0x46/0x390   f2fs_stop_gc_thread+0x6c/0x110   f2fs_do_shutdown+0x309/0x3a0   f2fs_ioc_shutdown+0x150/0x1c0   __f2fs_ioctl+0xffd/0x2ac0   f2fs_ioctl+0x76/0xe0   vfs_ioctl+0x23/0x60   __x64_sys_ioctl+0xce/0xf0   x64_sys_call+0x2b1b/0x4540   do_syscall_64+0xa7/0x240   entry_SYSCALL_64_after_hwframe+0x76/0x7e  The root cause is a race condition in f2fs_stop_gc_thread() called from different f2fs shutdown paths:    [CPU0]                       [CPU1]   ----------------------       -----------------------   f2fs_stop_gc_thread          f2fs_stop_gc_thread                                  gc_th = sbi->gc_thread     gc_th = sbi->gc_thread     kfree(gc_th)     sbi->gc_thread = NULL                                  < gc_th != NULL >                                  kthread_stop(gc_th->f2fs_gc_task) //UAF  The commit c7f114d864ac (\"f2fs: fix to avoid use-after-free in f2fs_stop_gc_thread()\") attempted to fix this issue by using a read semaphore to prevent races between shutdown and remount threads, but it fails to prevent all race conditions.  Fix it by converting to write lock of s_umount in f2fs_do_shutdown().","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53218","epss":0.00221,"percentile":0.12648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53218","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16906500000000002},"relatedVulnerabilities":[{"id":"CVE-2024-53218","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53218","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/60457ed6c67625c87861f96912b4179dc2293896","https://git.kernel.org/stable/c/794fa8792d4eacac191f1cbcc2e81b7369e4662a","https://git.kernel.org/stable/c/7b0033dbc48340a1c1c3f12448ba17d6587ca092","https://git.kernel.org/stable/c/c631207897a9b3d41167ceca58e07f8f94720e42"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix race in concurrent f2fs_stop_gc_thread\n\nIn my test case, concurrent calls to f2fs shutdown report the following\nstack trace:\n\n Oops: general protection fault, probably for non-canonical address 0xc6cfff63bb5513fc: 0000 [#1] PREEMPT SMP PTI\n CPU: 0 UID: 0 PID: 678 Comm: f2fs_rep_shutdo Not tainted 6.12.0-rc5-next-20241029-g6fb2fa9805c5-dirty #85\n Call Trace:\n  <TASK>\n  ? show_regs+0x8b/0xa0\n  ? __die_body+0x26/0xa0\n  ? die_addr+0x54/0x90\n  ? exc_general_protection+0x24b/0x5c0\n  ? asm_exc_general_protection+0x26/0x30\n  ? kthread_stop+0x46/0x390\n  f2fs_stop_gc_thread+0x6c/0x110\n  f2fs_do_shutdown+0x309/0x3a0\n  f2fs_ioc_shutdown+0x150/0x1c0\n  __f2fs_ioctl+0xffd/0x2ac0\n  f2fs_ioctl+0x76/0xe0\n  vfs_ioctl+0x23/0x60\n  __x64_sys_ioctl+0xce/0xf0\n  x64_sys_call+0x2b1b/0x4540\n  do_syscall_64+0xa7/0x240\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe root cause is a race condition in f2fs_stop_gc_thread() called from\ndifferent f2fs shutdown paths:\n\n  [CPU0]                       [CPU1]\n  ----------------------       -----------------------\n  f2fs_stop_gc_thread          f2fs_stop_gc_thread\n                                 gc_th = sbi->gc_thread\n    gc_th = sbi->gc_thread\n    kfree(gc_th)\n    sbi->gc_thread = NULL\n                                 < gc_th != NULL >\n                                 kthread_stop(gc_th->f2fs_gc_task) //UAF\n\nThe commit c7f114d864ac (\"f2fs: fix to avoid use-after-free in\nf2fs_stop_gc_thread()\") attempted to fix this issue by using a read\nsemaphore to prevent races between shutdown and remount threads, but\nit fails to prevent all race conditions.\n\nFix it by converting to write lock of s_umount in f2fs_do_shutdown().","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53218","epss":0.00221,"percentile":0.12648,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53218","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53218","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53219","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  virtiofs: use pages instead of pointer for kernel direct IO  When trying to insert a 10MB kernel module kept in a virtio-fs with cache disabled, the following warning was reported:    ------------[ cut here ]------------   WARNING: CPU: 1 PID: 404 at mm/page_alloc.c:4551 ......   Modules linked in:   CPU: 1 PID: 404 Comm: insmod Not tainted 6.9.0-rc5+ #123   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ......   RIP: 0010:__alloc_pages+0x2bf/0x380   ......   Call Trace:    <TASK>    ? __warn+0x8e/0x150    ? __alloc_pages+0x2bf/0x380    __kmalloc_large_node+0x86/0x160    __kmalloc+0x33c/0x480    virtio_fs_enqueue_req+0x240/0x6d0    virtio_fs_wake_pending_and_unlock+0x7f/0x190    queue_request_and_unlock+0x55/0x60    fuse_simple_request+0x152/0x2b0    fuse_direct_io+0x5d2/0x8c0    fuse_file_read_iter+0x121/0x160    __kernel_read+0x151/0x2d0    kernel_read+0x45/0x50    kernel_read_file+0x1a9/0x2a0    init_module_from_file+0x6a/0xe0    idempotent_init_module+0x175/0x230    __x64_sys_finit_module+0x5d/0xb0    x64_sys_call+0x1c3/0x9e0    do_syscall_64+0x3d/0xc0    entry_SYSCALL_64_after_hwframe+0x4b/0x53    ......    </TASK>   ---[ end trace 0000000000000000 ]---  The warning is triggered as follows:  1) syscall finit_module() handles the module insertion and it invokes kernel_read_file() to read the content of the module first.  2) kernel_read_file() allocates a 10MB buffer by using vmalloc() and passes it to kernel_read(). kernel_read() constructs a kvec iter by using iov_iter_kvec() and passes it to fuse_file_read_iter().  3) virtio-fs disables the cache, so fuse_file_read_iter() invokes fuse_direct_io(). As for now, the maximal read size for kvec iter is only limited by fc->max_read. For virtio-fs, max_read is UINT_MAX, so fuse_direct_io() doesn't split the 10MB buffer. It saves the address and the size of the 10MB-sized buffer in out_args[0] of a fuse request and passes the fuse request to virtio_fs_wake_pending_and_unlock().  4) virtio_fs_wake_pending_and_unlock() uses virtio_fs_enqueue_req() to queue the request. Because virtiofs need DMA-able address, so virtio_fs_enqueue_req() uses kmalloc() to allocate a bounce buffer for all fuse args, copies these args into the bounce buffer and passed the physical address of the bounce buffer to virtiofsd. The total length of these fuse args for the passed fuse request is about 10MB, so copy_args_to_argbuf() invokes kmalloc() with a 10MB size parameter and it triggers the warning in __alloc_pages():  \tif (WARN_ON_ONCE_GFP(order > MAX_PAGE_ORDER, gfp)) \t\treturn NULL;  5) virtio_fs_enqueue_req() will retry the memory allocation in a kworker, but it won't help, because kmalloc() will always return NULL due to the abnormal size and finit_module() will hang forever.  A feasible solution is to limit the value of max_read for virtio-fs, so the length passed to kmalloc() will be limited. However it will affect the maximal read size for normal read. And for virtio-fs write initiated from kernel, it has the similar problem but now there is no way to limit fc->max_write in kernel.  So instead of limiting both the values of max_read and max_write in kernel, introducing use_pages_for_kvec_io in fuse_conn and setting it as true in virtiofs. When use_pages_for_kvec_io is enabled, fuse will use pages instead of pointer to pass the KVEC_IO data.  After switching to pages for KVEC_IO data, these pages will be used for DMA through virtio-fs. If these pages are backed by vmalloc(), {flush|invalidate}_kernel_vmap_range() are necessary to flush or invalidate the cache before the DMA operation. So add two new fields in fuse_args_pages to record the base address of vmalloc area and the condition indicating whether invalidation is needed. Perform the flush in fuse_get_user_pages() for write operations and the invalidation in fuse_release_user_pages() for read operations.  It may seem necessary to introduce another fie ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53219","epss":0.00221,"percentile":0.1259,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.116025},"relatedVulnerabilities":[{"id":"CVE-2024-53219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53219","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2bc07714dc955a91d2923a440ea02c3cb3376b10","https://git.kernel.org/stable/c/41748675c0bf252b3c5f600a95830f0936d366c1","https://git.kernel.org/stable/c/9a8fde56d4b6d51930936ed50f6370a9097328d1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtiofs: use pages instead of pointer for kernel direct IO\n\nWhen trying to insert a 10MB kernel module kept in a virtio-fs with cache\ndisabled, the following warning was reported:\n\n  ------------[ cut here ]------------\n  WARNING: CPU: 1 PID: 404 at mm/page_alloc.c:4551 ......\n  Modules linked in:\n  CPU: 1 PID: 404 Comm: insmod Not tainted 6.9.0-rc5+ #123\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ......\n  RIP: 0010:__alloc_pages+0x2bf/0x380\n  ......\n  Call Trace:\n   <TASK>\n   ? __warn+0x8e/0x150\n   ? __alloc_pages+0x2bf/0x380\n   __kmalloc_large_node+0x86/0x160\n   __kmalloc+0x33c/0x480\n   virtio_fs_enqueue_req+0x240/0x6d0\n   virtio_fs_wake_pending_and_unlock+0x7f/0x190\n   queue_request_and_unlock+0x55/0x60\n   fuse_simple_request+0x152/0x2b0\n   fuse_direct_io+0x5d2/0x8c0\n   fuse_file_read_iter+0x121/0x160\n   __kernel_read+0x151/0x2d0\n   kernel_read+0x45/0x50\n   kernel_read_file+0x1a9/0x2a0\n   init_module_from_file+0x6a/0xe0\n   idempotent_init_module+0x175/0x230\n   __x64_sys_finit_module+0x5d/0xb0\n   x64_sys_call+0x1c3/0x9e0\n   do_syscall_64+0x3d/0xc0\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n   ......\n   </TASK>\n  ---[ end trace 0000000000000000 ]---\n\nThe warning is triggered as follows:\n\n1) syscall finit_module() handles the module insertion and it invokes\nkernel_read_file() to read the content of the module first.\n\n2) kernel_read_file() allocates a 10MB buffer by using vmalloc() and\npasses it to kernel_read(). kernel_read() constructs a kvec iter by\nusing iov_iter_kvec() and passes it to fuse_file_read_iter().\n\n3) virtio-fs disables the cache, so fuse_file_read_iter() invokes\nfuse_direct_io(). As for now, the maximal read size for kvec iter is\nonly limited by fc->max_read. For virtio-fs, max_read is UINT_MAX, so\nfuse_direct_io() doesn't split the 10MB buffer. It saves the address and\nthe size of the 10MB-sized buffer in out_args[0] of a fuse request and\npasses the fuse request to virtio_fs_wake_pending_and_unlock().\n\n4) virtio_fs_wake_pending_and_unlock() uses virtio_fs_enqueue_req() to\nqueue the request. Because virtiofs need DMA-able address, so\nvirtio_fs_enqueue_req() uses kmalloc() to allocate a bounce buffer for\nall fuse args, copies these args into the bounce buffer and passed the\nphysical address of the bounce buffer to virtiofsd. The total length of\nthese fuse args for the passed fuse request is about 10MB, so\ncopy_args_to_argbuf() invokes kmalloc() with a 10MB size parameter and\nit triggers the warning in __alloc_pages():\n\n\tif (WARN_ON_ONCE_GFP(order > MAX_PAGE_ORDER, gfp))\n\t\treturn NULL;\n\n5) virtio_fs_enqueue_req() will retry the memory allocation in a\nkworker, but it won't help, because kmalloc() will always return NULL\ndue to the abnormal size and finit_module() will hang forever.\n\nA feasible solution is to limit the value of max_read for virtio-fs, so\nthe length passed to kmalloc() will be limited. However it will affect\nthe maximal read size for normal read. And for virtio-fs write initiated\nfrom kernel, it has the similar problem but now there is no way to limit\nfc->max_write in kernel.\n\nSo instead of limiting both the values of max_read and max_write in\nkernel, introducing use_pages_for_kvec_io in fuse_conn and setting it as\ntrue in virtiofs. When use_pages_for_kvec_io is enabled, fuse will use\npages instead of pointer to pass the KVEC_IO data.\n\nAfter switching to pages for KVEC_IO data, these pages will be used for\nDMA through virtio-fs. If these pages are backed by vmalloc(),\n{flush|invalidate}_kernel_vmap_range() are necessary to flush or\ninvalidate the cache before the DMA operation. So add two new fields in\nfuse_args_pages to record the base address of vmalloc area and the\ncondition indicating whether invalidation is needed. Perform the flush\nin fuse_get_user_pages() for write operations and the invalidation in\nfuse_release_user_pages() for read operations.\n\nIt may seem necessary to introduce another fie\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53219","epss":0.00221,"percentile":0.1259,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53224","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx5: Move events notifier registration to be after device registration  Move pkey change work initialization and cleanup from device resources stage to notifier stage, since this is the stage which handles this work events.  Fix a race between the device deregistration and pkey change work by moving MLX5_IB_STAGE_DEVICE_NOTIFIER to be after MLX5_IB_STAGE_IB_REG in order to ensure that the notifier is deregistered before the device during cleanup. Which ensures there are no works that are being executed after the device has already unregistered which can cause the panic below.  BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP PTI CPU: 1 PID: 630071 Comm: kworker/1:2 Kdump: loaded Tainted: G W OE --------- --- 5.14.0-162.6.1.el9_1.x86_64 #1 Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 090008 02/27/2023 Workqueue: events pkey_change_handler [mlx5_ib] RIP: 0010:setup_qp+0x38/0x1f0 [mlx5_ib] Code: ee 41 54 45 31 e4 55 89 f5 53 48 89 fb 48 83 ec 20 8b 77 08 65 48 8b 04 25 28 00 00 00 48 89 44 24 18 48 8b 07 48 8d 4c 24 16 <4c> 8b 38 49 8b 87 80 0b 00 00 4c 89 ff 48 8b 80 08 05 00 00 8b 40 RSP: 0018:ffffbcc54068be20 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffff954054494128 RCX: ffffbcc54068be36 RDX: ffff954004934000 RSI: 0000000000000001 RDI: ffff954054494128 RBP: 0000000000000023 R08: ffff954001be2c20 R09: 0000000000000001 R10: ffff954001be2c20 R11: ffff9540260133c0 R12: 0000000000000000 R13: 0000000000000023 R14: 0000000000000000 R15: ffff9540ffcb0905 FS: 0000000000000000(0000) GS:ffff9540ffc80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 000000010625c001 CR4: 00000000003706e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: mlx5_ib_gsi_pkey_change+0x20/0x40 [mlx5_ib] process_one_work+0x1e8/0x3c0 worker_thread+0x50/0x3b0 ? rescuer_thread+0x380/0x380 kthread+0x149/0x170 ? set_kthread_struct+0x50/0x50 ret_from_fork+0x22/0x30 Modules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) mlx5_fwctl(OE) fwctl(OE) ib_uverbs(OE) mlx5_core(OE) mlxdevm(OE) ib_core(OE) mlx_compat(OE) psample mlxfw(OE) tls knem(OE) netconsole nfsv3 nfs_acl nfs lockd grace fscache netfs qrtr rfkill sunrpc intel_rapl_msr intel_rapl_common rapl hv_balloon hv_utils i2c_piix4 pcspkr joydev fuse ext4 mbcache jbd2 sr_mod sd_mod cdrom t10_pi sg ata_generic pci_hyperv pci_hyperv_intf hyperv_drm drm_shmem_helper drm_kms_helper hv_storvsc syscopyarea hv_netvsc sysfillrect sysimgblt hid_hyperv fb_sys_fops scsi_transport_fc hyperv_keyboard drm ata_piix crct10dif_pclmul crc32_pclmul crc32c_intel libata ghash_clmulni_intel hv_vmbus serio_raw [last unloaded: ib_core] CR2: 0000000000000000 ---[ end trace f6f8be4eae12f7bc ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53224","epss":0.00322,"percentile":0.25041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53224","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16905},"relatedVulnerabilities":[{"id":"CVE-2024-53224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53224","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/542bd62b7a7f37182c9ef192c2bd25d118c144e4","https://git.kernel.org/stable/c/6b0acf6a94c31efa43fce4edc22413a3390f9c05","https://git.kernel.org/stable/c/921fcf2971a1e8d3b904ba2c2905b96f4ec3d4ad","https://git.kernel.org/stable/c/ede132a5cf559f3ab35a4c28bac4f4a6c20334d8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Move events notifier registration to be after device registration\n\nMove pkey change work initialization and cleanup from device resources\nstage to notifier stage, since this is the stage which handles this work\nevents.\n\nFix a race between the device deregistration and pkey change work by moving\nMLX5_IB_STAGE_DEVICE_NOTIFIER to be after MLX5_IB_STAGE_IB_REG in order to\nensure that the notifier is deregistered before the device during cleanup.\nWhich ensures there are no works that are being executed after the\ndevice has already unregistered which can cause the panic below.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 630071 Comm: kworker/1:2 Kdump: loaded Tainted: G W OE --------- --- 5.14.0-162.6.1.el9_1.x86_64 #1\nHardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 090008 02/27/2023\nWorkqueue: events pkey_change_handler [mlx5_ib]\nRIP: 0010:setup_qp+0x38/0x1f0 [mlx5_ib]\nCode: ee 41 54 45 31 e4 55 89 f5 53 48 89 fb 48 83 ec 20 8b 77 08 65 48 8b 04 25 28 00 00 00 48 89 44 24 18 48 8b 07 48 8d 4c 24 16 <4c> 8b 38 49 8b 87 80 0b 00 00 4c 89 ff 48 8b 80 08 05 00 00 8b 40\nRSP: 0018:ffffbcc54068be20 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffff954054494128 RCX: ffffbcc54068be36\nRDX: ffff954004934000 RSI: 0000000000000001 RDI: ffff954054494128\nRBP: 0000000000000023 R08: ffff954001be2c20 R09: 0000000000000001\nR10: ffff954001be2c20 R11: ffff9540260133c0 R12: 0000000000000000\nR13: 0000000000000023 R14: 0000000000000000 R15: ffff9540ffcb0905\nFS: 0000000000000000(0000) GS:ffff9540ffc80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000000 CR3: 000000010625c001 CR4: 00000000003706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\nmlx5_ib_gsi_pkey_change+0x20/0x40 [mlx5_ib]\nprocess_one_work+0x1e8/0x3c0\nworker_thread+0x50/0x3b0\n? rescuer_thread+0x380/0x380\nkthread+0x149/0x170\n? set_kthread_struct+0x50/0x50\nret_from_fork+0x22/0x30\nModules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) mlx5_fwctl(OE) fwctl(OE) ib_uverbs(OE) mlx5_core(OE) mlxdevm(OE) ib_core(OE) mlx_compat(OE) psample mlxfw(OE) tls knem(OE) netconsole nfsv3 nfs_acl nfs lockd grace fscache netfs qrtr rfkill sunrpc intel_rapl_msr intel_rapl_common rapl hv_balloon hv_utils i2c_piix4 pcspkr joydev fuse ext4 mbcache jbd2 sr_mod sd_mod cdrom t10_pi sg ata_generic pci_hyperv pci_hyperv_intf hyperv_drm drm_shmem_helper drm_kms_helper hv_storvsc syscopyarea hv_netvsc sysfillrect sysimgblt hid_hyperv fb_sys_fops scsi_transport_fc hyperv_keyboard drm ata_piix crct10dif_pclmul crc32_pclmul crc32c_intel libata ghash_clmulni_intel hv_vmbus serio_raw [last unloaded: ib_core]\nCR2: 0000000000000000\n---[ end trace f6f8be4eae12f7bc ]---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53224","epss":0.00322,"percentile":0.25041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-53224","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-53224","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-53687","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-53687","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  riscv: Fix IPIs usage in kfence_protect_page()  flush_tlb_kernel_range() may use IPIs to flush the TLBs of all the cores, which triggers the following warning when the irqs are disabled:  [    3.455330] WARNING: CPU: 1 PID: 0 at kernel/smp.c:815 smp_call_function_many_cond+0x452/0x520 [    3.456647] Modules linked in: [    3.457218] CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Not tainted 6.12.0-rc7-00010-g91d3de7240b8 #1 [    3.457416] Hardware name: QEMU QEMU Virtual Machine, BIOS [    3.457633] epc : smp_call_function_many_cond+0x452/0x520 [    3.457736]  ra : on_each_cpu_cond_mask+0x1e/0x30 [    3.457786] epc : ffffffff800b669a ra : ffffffff800b67c2 sp : ff2000000000bb50 [    3.457824]  gp : ffffffff815212b8 tp : ff6000008014f080 t0 : 000000000000003f [    3.457859]  t1 : ffffffff815221e0 t2 : 000000000000000f s0 : ff2000000000bc10 [    3.457920]  s1 : 0000000000000040 a0 : ffffffff815221e0 a1 : 0000000000000001 [    3.457953]  a2 : 0000000000010000 a3 : 0000000000000003 a4 : 0000000000000000 [    3.458006]  a5 : 0000000000000000 a6 : ffffffffffffffff a7 : 0000000000000000 [    3.458042]  s2 : ffffffff815223be s3 : 00fffffffffff000 s4 : ff600001ffe38fc0 [    3.458076]  s5 : ff600001ff950d00 s6 : 0000000200000120 s7 : 0000000000000001 [    3.458109]  s8 : 0000000000000001 s9 : ff60000080841ef0 s10: 0000000000000001 [    3.458141]  s11: ffffffff81524812 t3 : 0000000000000001 t4 : ff60000080092bc0 [    3.458172]  t5 : 0000000000000000 t6 : ff200000000236d0 [    3.458203] status: 0000000200000100 badaddr: ffffffff800b669a cause: 0000000000000003 [    3.458373] [<ffffffff800b669a>] smp_call_function_many_cond+0x452/0x520 [    3.458593] [<ffffffff800b67c2>] on_each_cpu_cond_mask+0x1e/0x30 [    3.458625] [<ffffffff8000e4ca>] __flush_tlb_range+0x118/0x1ca [    3.458656] [<ffffffff8000e6b2>] flush_tlb_kernel_range+0x1e/0x26 [    3.458683] [<ffffffff801ea56a>] kfence_protect+0xc0/0xce [    3.458717] [<ffffffff801e9456>] kfence_guarded_free+0xc6/0x1c0 [    3.458742] [<ffffffff801e9d6c>] __kfence_free+0x62/0xc6 [    3.458764] [<ffffffff801c57d8>] kfree+0x106/0x32c [    3.458786] [<ffffffff80588cf2>] detach_buf_split+0x188/0x1a8 [    3.458816] [<ffffffff8058708c>] virtqueue_get_buf_ctx+0xb6/0x1f6 [    3.458839] [<ffffffff805871da>] virtqueue_get_buf+0xe/0x16 [    3.458880] [<ffffffff80613d6a>] virtblk_done+0x5c/0xe2 [    3.458908] [<ffffffff8058766e>] vring_interrupt+0x6a/0x74 [    3.458930] [<ffffffff800747d8>] __handle_irq_event_percpu+0x7c/0xe2 [    3.458956] [<ffffffff800748f0>] handle_irq_event+0x3c/0x86 [    3.458978] [<ffffffff800786cc>] handle_simple_irq+0x9e/0xbe [    3.459004] [<ffffffff80073934>] generic_handle_domain_irq+0x1c/0x2a [    3.459027] [<ffffffff804bf87c>] imsic_handle_irq+0xba/0x120 [    3.459056] [<ffffffff80073934>] generic_handle_domain_irq+0x1c/0x2a [    3.459080] [<ffffffff804bdb76>] riscv_intc_aia_irq+0x24/0x34 [    3.459103] [<ffffffff809d0452>] handle_riscv_irq+0x2e/0x4c [    3.459133] [<ffffffff809d923e>] call_on_irq_stack+0x32/0x40  So only flush the local TLB and let the lazy kfence page fault handling deal with the faults which could happen when a core has an old protected pte version cached in its TLB. That leads to potential inaccuracies which can be tolerated when using kfence.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53687","epss":0.00218,"percentile":0.12168,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11445000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-53687","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-53687","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3abfc4130c4222099c69d023fed97f1180a8ad7b","https://git.kernel.org/stable/c/6f796a6a396d6f963f2cc8f5edd7dfba2cca097f","https://git.kernel.org/stable/c/b3431a8bb336cece8adc452437befa7d4534b2fd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Fix IPIs usage in kfence_protect_page()\n\nflush_tlb_kernel_range() may use IPIs to flush the TLBs of all the\ncores, which triggers the following warning when the irqs are disabled:\n\n[    3.455330] WARNING: CPU: 1 PID: 0 at kernel/smp.c:815 smp_call_function_many_cond+0x452/0x520\n[    3.456647] Modules linked in:\n[    3.457218] CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Not tainted 6.12.0-rc7-00010-g91d3de7240b8 #1\n[    3.457416] Hardware name: QEMU QEMU Virtual Machine, BIOS\n[    3.457633] epc : smp_call_function_many_cond+0x452/0x520\n[    3.457736]  ra : on_each_cpu_cond_mask+0x1e/0x30\n[    3.457786] epc : ffffffff800b669a ra : ffffffff800b67c2 sp : ff2000000000bb50\n[    3.457824]  gp : ffffffff815212b8 tp : ff6000008014f080 t0 : 000000000000003f\n[    3.457859]  t1 : ffffffff815221e0 t2 : 000000000000000f s0 : ff2000000000bc10\n[    3.457920]  s1 : 0000000000000040 a0 : ffffffff815221e0 a1 : 0000000000000001\n[    3.457953]  a2 : 0000000000010000 a3 : 0000000000000003 a4 : 0000000000000000\n[    3.458006]  a5 : 0000000000000000 a6 : ffffffffffffffff a7 : 0000000000000000\n[    3.458042]  s2 : ffffffff815223be s3 : 00fffffffffff000 s4 : ff600001ffe38fc0\n[    3.458076]  s5 : ff600001ff950d00 s6 : 0000000200000120 s7 : 0000000000000001\n[    3.458109]  s8 : 0000000000000001 s9 : ff60000080841ef0 s10: 0000000000000001\n[    3.458141]  s11: ffffffff81524812 t3 : 0000000000000001 t4 : ff60000080092bc0\n[    3.458172]  t5 : 0000000000000000 t6 : ff200000000236d0\n[    3.458203] status: 0000000200000100 badaddr: ffffffff800b669a cause: 0000000000000003\n[    3.458373] [<ffffffff800b669a>] smp_call_function_many_cond+0x452/0x520\n[    3.458593] [<ffffffff800b67c2>] on_each_cpu_cond_mask+0x1e/0x30\n[    3.458625] [<ffffffff8000e4ca>] __flush_tlb_range+0x118/0x1ca\n[    3.458656] [<ffffffff8000e6b2>] flush_tlb_kernel_range+0x1e/0x26\n[    3.458683] [<ffffffff801ea56a>] kfence_protect+0xc0/0xce\n[    3.458717] [<ffffffff801e9456>] kfence_guarded_free+0xc6/0x1c0\n[    3.458742] [<ffffffff801e9d6c>] __kfence_free+0x62/0xc6\n[    3.458764] [<ffffffff801c57d8>] kfree+0x106/0x32c\n[    3.458786] [<ffffffff80588cf2>] detach_buf_split+0x188/0x1a8\n[    3.458816] [<ffffffff8058708c>] virtqueue_get_buf_ctx+0xb6/0x1f6\n[    3.458839] [<ffffffff805871da>] virtqueue_get_buf+0xe/0x16\n[    3.458880] [<ffffffff80613d6a>] virtblk_done+0x5c/0xe2\n[    3.458908] [<ffffffff8058766e>] vring_interrupt+0x6a/0x74\n[    3.458930] [<ffffffff800747d8>] __handle_irq_event_percpu+0x7c/0xe2\n[    3.458956] [<ffffffff800748f0>] handle_irq_event+0x3c/0x86\n[    3.458978] [<ffffffff800786cc>] handle_simple_irq+0x9e/0xbe\n[    3.459004] [<ffffffff80073934>] generic_handle_domain_irq+0x1c/0x2a\n[    3.459027] [<ffffffff804bf87c>] imsic_handle_irq+0xba/0x120\n[    3.459056] [<ffffffff80073934>] generic_handle_domain_irq+0x1c/0x2a\n[    3.459080] [<ffffffff804bdb76>] riscv_intc_aia_irq+0x24/0x34\n[    3.459103] [<ffffffff809d0452>] handle_riscv_irq+0x2e/0x4c\n[    3.459133] [<ffffffff809d923e>] call_on_irq_stack+0x32/0x40\n\nSo only flush the local TLB and let the lazy kfence page fault handling\ndeal with the faults which could happen when a core has an old protected\npte version cached in its TLB. That leads to potential inaccuracies which\ncan be tolerated when using kfence.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-53687","epss":0.00218,"percentile":0.12168,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-53687","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-54683","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-54683","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: IDLETIMER: Fix for possible ABBA deadlock  Deletion of the last rule referencing a given idletimer may happen at the same time as a read of its file in sysfs:  | ====================================================== | WARNING: possible circular locking dependency detected | 6.12.0-rc7-01692-g5e9a28f41134-dirty #594 Not tainted | ------------------------------------------------------ | iptables/3303 is trying to acquire lock: | ffff8881057e04b8 (kn->active#48){++++}-{0:0}, at: __kernfs_remove+0x20 | | but task is already holding lock: | ffffffffa0249068 (list_mutex){+.+.}-{3:3}, at: idletimer_tg_destroy_v] | | which lock already depends on the new lock.  A simple reproducer is:  | #!/bin/bash | | while true; do |         iptables -A INPUT -i foo -j IDLETIMER --timeout 10 --label \"testme\" |         iptables -D INPUT -i foo -j IDLETIMER --timeout 10 --label \"testme\" | done & | while true; do |         cat /sys/class/xt_idletimer/timers/testme >/dev/null | done  Avoid this by freeing list_mutex right after deleting the element from the list, then continuing with the teardown.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-54683","epss":0.00162,"percentile":0.05771,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-54683","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-54683","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08505},"relatedVulnerabilities":[{"id":"CVE-2024-54683","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-54683","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/45fe76573a2557f632e248cc141342233f422b9a","https://git.kernel.org/stable/c/8c2c8445cda8f59c38dec7dc10509bcb23ae26a0","https://git.kernel.org/stable/c/f36b01994d68ffc253c8296e2228dfe6e6431c03"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: IDLETIMER: Fix for possible ABBA deadlock\n\nDeletion of the last rule referencing a given idletimer may happen at\nthe same time as a read of its file in sysfs:\n\n| ======================================================\n| WARNING: possible circular locking dependency detected\n| 6.12.0-rc7-01692-g5e9a28f41134-dirty #594 Not tainted\n| ------------------------------------------------------\n| iptables/3303 is trying to acquire lock:\n| ffff8881057e04b8 (kn->active#48){++++}-{0:0}, at: __kernfs_remove+0x20\n|\n| but task is already holding lock:\n| ffffffffa0249068 (list_mutex){+.+.}-{3:3}, at: idletimer_tg_destroy_v]\n|\n| which lock already depends on the new lock.\n\nA simple reproducer is:\n\n| #!/bin/bash\n|\n| while true; do\n|         iptables -A INPUT -i foo -j IDLETIMER --timeout 10 --label \"testme\"\n|         iptables -D INPUT -i foo -j IDLETIMER --timeout 10 --label \"testme\"\n| done &\n| while true; do\n|         cat /sys/class/xt_idletimer/timers/testme >/dev/null\n| done\n\nAvoid this by freeing list_mutex right after deleting the element from\nthe list, then continuing with the teardown.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-54683","epss":0.00162,"percentile":0.05771,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-54683","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-54683","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-54683","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56538","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56538","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm: zynqmp_kms: Unplug DRM device before removal  Prevent userspace accesses to the DRM device from causing use-after-frees by unplugging the device before we remove it. This causes any further userspace accesses to result in an error without further calls into this driver's internals.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56538","epss":0.0027,"percentile":0.1907,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56538","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56538","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.20655},"relatedVulnerabilities":[{"id":"CVE-2024-56538","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56538","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2e07c88914fc5289c21820b1aa94f058feb38197","https://git.kernel.org/stable/c/4fb97432e28a7e136b2d76135d50e988ada8e1af","https://git.kernel.org/stable/c/692f52aedccbf79b212a1e14e3735192b4c24a7d","https://git.kernel.org/stable/c/a17b9afe58c474657449cf87e238b1788200576b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: zynqmp_kms: Unplug DRM device before removal\n\nPrevent userspace accesses to the DRM device from causing\nuse-after-frees by unplugging the device before we remove it. This\ncauses any further userspace accesses to result in an error without\nfurther calls into this driver's internals.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56538","epss":0.0027,"percentile":0.1907,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56538","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56538","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56538","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56544","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56544","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  udmabuf: change folios array from kmalloc to kvmalloc  When PAGE_SIZE 4096, MAX_PAGE_ORDER 10, 64bit machine, page_alloc only support 4MB. If above this, trigger this warn and return NULL.  udmabuf can change size limit, if change it to 3072(3GB), and then alloc 3GB udmabuf, will fail create.  [ 4080.876581] ------------[ cut here ]------------ [ 4080.876843] WARNING: CPU: 3 PID: 2015 at mm/page_alloc.c:4556 __alloc_pages+0x2c8/0x350 [ 4080.878839] RIP: 0010:__alloc_pages+0x2c8/0x350 [ 4080.879470] Call Trace: [ 4080.879473]  <TASK> [ 4080.879473]  ? __alloc_pages+0x2c8/0x350 [ 4080.879475]  ? __warn.cold+0x8e/0xe8 [ 4080.880647]  ? __alloc_pages+0x2c8/0x350 [ 4080.880909]  ? report_bug+0xff/0x140 [ 4080.881175]  ? handle_bug+0x3c/0x80 [ 4080.881556]  ? exc_invalid_op+0x17/0x70 [ 4080.881559]  ? asm_exc_invalid_op+0x1a/0x20 [ 4080.882077]  ? udmabuf_create+0x131/0x400  Because MAX_PAGE_ORDER, kmalloc can max alloc 4096 * (1 << 10), 4MB memory, each array entry is pointer(8byte), so can save 524288 pages(2GB).  Further more, costly order(order 3) may not be guaranteed that it can be applied for, due to fragmentation.  This patch change udmabuf array use kvmalloc_array, this can fallback alloc into vmalloc, which can guarantee allocation for any size and does not affect the performance of kmalloc allocations.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56544","epss":0.00214,"percentile":0.11705,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56544","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56544","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11234999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-56544","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56544","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1c0844c6184e658064e14c4335885785ad3bf84b","https://git.kernel.org/stable/c/2acc6192aa8570661ed37868c02c03002b1dc290","https://git.kernel.org/stable/c/85bb72397cb63649fe493c96e27e1d0e4ed2ff63"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nudmabuf: change folios array from kmalloc to kvmalloc\n\nWhen PAGE_SIZE 4096, MAX_PAGE_ORDER 10, 64bit machine,\npage_alloc only support 4MB.\nIf above this, trigger this warn and return NULL.\n\nudmabuf can change size limit, if change it to 3072(3GB), and then alloc\n3GB udmabuf, will fail create.\n\n[ 4080.876581] ------------[ cut here ]------------\n[ 4080.876843] WARNING: CPU: 3 PID: 2015 at mm/page_alloc.c:4556 __alloc_pages+0x2c8/0x350\n[ 4080.878839] RIP: 0010:__alloc_pages+0x2c8/0x350\n[ 4080.879470] Call Trace:\n[ 4080.879473]  <TASK>\n[ 4080.879473]  ? __alloc_pages+0x2c8/0x350\n[ 4080.879475]  ? __warn.cold+0x8e/0xe8\n[ 4080.880647]  ? __alloc_pages+0x2c8/0x350\n[ 4080.880909]  ? report_bug+0xff/0x140\n[ 4080.881175]  ? handle_bug+0x3c/0x80\n[ 4080.881556]  ? exc_invalid_op+0x17/0x70\n[ 4080.881559]  ? asm_exc_invalid_op+0x1a/0x20\n[ 4080.882077]  ? udmabuf_create+0x131/0x400\n\nBecause MAX_PAGE_ORDER, kmalloc can max alloc 4096 * (1 << 10), 4MB\nmemory, each array entry is pointer(8byte), so can save 524288 pages(2GB).\n\nFurther more, costly order(order 3) may not be guaranteed that it can be\napplied for, due to fragmentation.\n\nThis patch change udmabuf array use kvmalloc_array, this can fallback\nalloc into vmalloc, which can guarantee allocation for any size and does\nnot affect the performance of kmalloc allocations.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56544","epss":0.00214,"percentile":0.11705,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56544","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56544","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56544","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56565","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56565","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to drop all discards after creating snapshot on lvm device  Piergiorgio reported a bug in bugzilla as below:  ------------[ cut here ]------------ WARNING: CPU: 2 PID: 969 at fs/f2fs/segment.c:1330 RIP: 0010:__submit_discard_cmd+0x27d/0x400 [f2fs] Call Trace:  __issue_discard_cmd+0x1ca/0x350 [f2fs]  issue_discard_thread+0x191/0x480 [f2fs]  kthread+0xcf/0x100  ret_from_fork+0x31/0x50  ret_from_fork_asm+0x1a/0x30  w/ below testcase, it can reproduce this bug quickly: - pvcreate /dev/vdb - vgcreate myvg1 /dev/vdb - lvcreate -L 1024m -n mylv1 myvg1 - mount /dev/myvg1/mylv1 /mnt/f2fs - dd if=/dev/zero of=/mnt/f2fs/file bs=1M count=20 - sync - rm /mnt/f2fs/file - sync - lvcreate -L 1024m -s -n mylv1-snapshot /dev/myvg1/mylv1 - umount /mnt/f2fs  The root cause is: it will update discard_max_bytes of mounted lvm device to zero after creating snapshot on this lvm device, then, __submit_discard_cmd() will pass parameter @nr_sects w/ zero value to __blkdev_issue_discard(), it returns a NULL bio pointer, result in panic.  This patch changes as below for fixing: 1. Let's drop all remained discards in f2fs_unfreeze() if snapshot of lvm device is created. 2. Checking discard_max_bytes before submitting discard during __submit_discard_cmd().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56565","epss":0.00216,"percentile":0.12014,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2024-56565","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56565","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/15136c3861a3341db261ebdbb6ae4ae1765635e2","https://git.kernel.org/stable/c/bc8aeb04fd80cb8cfae3058445c84410fd0beb5e","https://git.kernel.org/stable/c/ed24ab98242f8d22b66fbe0452c97751b5ea4e22"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to drop all discards after creating snapshot on lvm device\n\nPiergiorgio reported a bug in bugzilla as below:\n\n------------[ cut here ]------------\nWARNING: CPU: 2 PID: 969 at fs/f2fs/segment.c:1330\nRIP: 0010:__submit_discard_cmd+0x27d/0x400 [f2fs]\nCall Trace:\n __issue_discard_cmd+0x1ca/0x350 [f2fs]\n issue_discard_thread+0x191/0x480 [f2fs]\n kthread+0xcf/0x100\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x1a/0x30\n\nw/ below testcase, it can reproduce this bug quickly:\n- pvcreate /dev/vdb\n- vgcreate myvg1 /dev/vdb\n- lvcreate -L 1024m -n mylv1 myvg1\n- mount /dev/myvg1/mylv1 /mnt/f2fs\n- dd if=/dev/zero of=/mnt/f2fs/file bs=1M count=20\n- sync\n- rm /mnt/f2fs/file\n- sync\n- lvcreate -L 1024m -s -n mylv1-snapshot /dev/myvg1/mylv1\n- umount /mnt/f2fs\n\nThe root cause is: it will update discard_max_bytes of mounted lvm\ndevice to zero after creating snapshot on this lvm device, then,\n__submit_discard_cmd() will pass parameter @nr_sects w/ zero value\nto __blkdev_issue_discard(), it returns a NULL bio pointer, result\nin panic.\n\nThis patch changes as below for fixing:\n1. Let's drop all remained discards in f2fs_unfreeze() if snapshot\nof lvm device is created.\n2. Checking discard_max_bytes before submitting discard during\n__submit_discard_cmd().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56565","epss":0.00216,"percentile":0.12014,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56565","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56566","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56566","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/slub: Avoid list corruption when removing a slab from the full list  Boot with slub_debug=UFPZ.  If allocated object failed in alloc_consistency_checks, all objects of the slab will be marked as used, and then the slab will be removed from the partial list.  When an object belonging to the slab got freed later, the remove_full() function is called. Because the slab is neither on the partial list nor on the full list, it eventually lead to a list corruption (actually a list poison being detected).  So we need to mark and isolate the slab page with metadata corruption, do not put it back in circulation.  Because the debug caches avoid all the fastpaths, reusing the frozen bit to mark slab page with metadata corruption seems to be fine.  [ 4277.385669] list_del corruption, ffffea00044b3e50->next is LIST_POISON1 (dead000000000100) [ 4277.387023] ------------[ cut here ]------------ [ 4277.387880] kernel BUG at lib/list_debug.c:56! [ 4277.388680] invalid opcode: 0000 [#1] PREEMPT SMP PTI [ 4277.389562] CPU: 5 PID: 90 Comm: kworker/5:1 Kdump: loaded Tainted: G           OE      6.6.1-1 #1 [ 4277.392113] Workqueue: xfs-inodegc/vda1 xfs_inodegc_worker [xfs] [ 4277.393551] RIP: 0010:__list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.394518] Code: 48 91 82 e8 37 f9 9a ff 0f 0b 48 89 fe 48 c7 c7 28 49 91 82 e8 26 f9 9a ff 0f 0b 48 89 fe 48 c7 c7 58 49 91 [ 4277.397292] RSP: 0018:ffffc90000333b38 EFLAGS: 00010082 [ 4277.398202] RAX: 000000000000004e RBX: ffffea00044b3e50 RCX: 0000000000000000 [ 4277.399340] RDX: 0000000000000002 RSI: ffffffff828f8715 RDI: 00000000ffffffff [ 4277.400545] RBP: ffffea00044b3e40 R08: 0000000000000000 R09: ffffc900003339f0 [ 4277.401710] R10: 0000000000000003 R11: ffffffff82d44088 R12: ffff888112cf9910 [ 4277.402887] R13: 0000000000000001 R14: 0000000000000001 R15: ffff8881000424c0 [ 4277.404049] FS:  0000000000000000(0000) GS:ffff88842fd40000(0000) knlGS:0000000000000000 [ 4277.405357] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 4277.406389] CR2: 00007f2ad0b24000 CR3: 0000000102a3a006 CR4: 00000000007706e0 [ 4277.407589] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 4277.408780] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 4277.410000] PKRU: 55555554 [ 4277.410645] Call Trace: [ 4277.411234]  <TASK> [ 4277.411777]  ? die+0x32/0x80 [ 4277.412439]  ? do_trap+0xd6/0x100 [ 4277.413150]  ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.414158]  ? do_error_trap+0x6a/0x90 [ 4277.414948]  ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.415915]  ? exc_invalid_op+0x4c/0x60 [ 4277.416710]  ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.417675]  ? asm_exc_invalid_op+0x16/0x20 [ 4277.418482]  ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.419466]  ? __list_del_entry_valid_or_report+0x7b/0xc0 [ 4277.420410]  free_to_partial_list+0x515/0x5e0 [ 4277.421242]  ? xfs_iext_remove+0x41a/0xa10 [xfs] [ 4277.422298]  xfs_iext_remove+0x41a/0xa10 [xfs] [ 4277.423316]  ? xfs_inodegc_worker+0xb4/0x1a0 [xfs] [ 4277.424383]  xfs_bmap_del_extent_delay+0x4fe/0x7d0 [xfs] [ 4277.425490]  __xfs_bunmapi+0x50d/0x840 [xfs] [ 4277.426445]  xfs_itruncate_extents_flags+0x13a/0x490 [xfs] [ 4277.427553]  xfs_inactive_truncate+0xa3/0x120 [xfs] [ 4277.428567]  xfs_inactive+0x22d/0x290 [xfs] [ 4277.429500]  xfs_inodegc_worker+0xb4/0x1a0 [xfs] [ 4277.430479]  process_one_work+0x171/0x340 [ 4277.431227]  worker_thread+0x277/0x390 [ 4277.431962]  ? __pfx_worker_thread+0x10/0x10 [ 4277.432752]  kthread+0xf0/0x120 [ 4277.433382]  ? __pfx_kthread+0x10/0x10 [ 4277.434134]  ret_from_fork+0x2d/0x50 [ 4277.434837]  ? __pfx_kthread+0x10/0x10 [ 4277.435566]  ret_from_fork_asm+0x1b/0x30 [ 4277.436280]  </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56566","epss":0.00216,"percentile":0.12015,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56566","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2024-56566","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56566","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/33a213c04faff6c3a7fe77e947db81bc7270fe32","https://git.kernel.org/stable/c/943c0f601cd28c1073b92b5f944c6c6c2643e709","https://git.kernel.org/stable/c/dbc16915279a548a204154368da23d402c141c81"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slub: Avoid list corruption when removing a slab from the full list\n\nBoot with slub_debug=UFPZ.\n\nIf allocated object failed in alloc_consistency_checks, all objects of\nthe slab will be marked as used, and then the slab will be removed from\nthe partial list.\n\nWhen an object belonging to the slab got freed later, the remove_full()\nfunction is called. Because the slab is neither on the partial list nor\non the full list, it eventually lead to a list corruption (actually a\nlist poison being detected).\n\nSo we need to mark and isolate the slab page with metadata corruption,\ndo not put it back in circulation.\n\nBecause the debug caches avoid all the fastpaths, reusing the frozen bit\nto mark slab page with metadata corruption seems to be fine.\n\n[ 4277.385669] list_del corruption, ffffea00044b3e50->next is LIST_POISON1 (dead000000000100)\n[ 4277.387023] ------------[ cut here ]------------\n[ 4277.387880] kernel BUG at lib/list_debug.c:56!\n[ 4277.388680] invalid opcode: 0000 [#1] PREEMPT SMP PTI\n[ 4277.389562] CPU: 5 PID: 90 Comm: kworker/5:1 Kdump: loaded Tainted: G           OE      6.6.1-1 #1\n[ 4277.392113] Workqueue: xfs-inodegc/vda1 xfs_inodegc_worker [xfs]\n[ 4277.393551] RIP: 0010:__list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.394518] Code: 48 91 82 e8 37 f9 9a ff 0f 0b 48 89 fe 48 c7 c7 28 49 91 82 e8 26 f9 9a ff 0f 0b 48 89 fe 48 c7 c7 58 49 91\n[ 4277.397292] RSP: 0018:ffffc90000333b38 EFLAGS: 00010082\n[ 4277.398202] RAX: 000000000000004e RBX: ffffea00044b3e50 RCX: 0000000000000000\n[ 4277.399340] RDX: 0000000000000002 RSI: ffffffff828f8715 RDI: 00000000ffffffff\n[ 4277.400545] RBP: ffffea00044b3e40 R08: 0000000000000000 R09: ffffc900003339f0\n[ 4277.401710] R10: 0000000000000003 R11: ffffffff82d44088 R12: ffff888112cf9910\n[ 4277.402887] R13: 0000000000000001 R14: 0000000000000001 R15: ffff8881000424c0\n[ 4277.404049] FS:  0000000000000000(0000) GS:ffff88842fd40000(0000) knlGS:0000000000000000\n[ 4277.405357] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 4277.406389] CR2: 00007f2ad0b24000 CR3: 0000000102a3a006 CR4: 00000000007706e0\n[ 4277.407589] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 4277.408780] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 4277.410000] PKRU: 55555554\n[ 4277.410645] Call Trace:\n[ 4277.411234]  <TASK>\n[ 4277.411777]  ? die+0x32/0x80\n[ 4277.412439]  ? do_trap+0xd6/0x100\n[ 4277.413150]  ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.414158]  ? do_error_trap+0x6a/0x90\n[ 4277.414948]  ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.415915]  ? exc_invalid_op+0x4c/0x60\n[ 4277.416710]  ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.417675]  ? asm_exc_invalid_op+0x16/0x20\n[ 4277.418482]  ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.419466]  ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.420410]  free_to_partial_list+0x515/0x5e0\n[ 4277.421242]  ? xfs_iext_remove+0x41a/0xa10 [xfs]\n[ 4277.422298]  xfs_iext_remove+0x41a/0xa10 [xfs]\n[ 4277.423316]  ? xfs_inodegc_worker+0xb4/0x1a0 [xfs]\n[ 4277.424383]  xfs_bmap_del_extent_delay+0x4fe/0x7d0 [xfs]\n[ 4277.425490]  __xfs_bunmapi+0x50d/0x840 [xfs]\n[ 4277.426445]  xfs_itruncate_extents_flags+0x13a/0x490 [xfs]\n[ 4277.427553]  xfs_inactive_truncate+0xa3/0x120 [xfs]\n[ 4277.428567]  xfs_inactive+0x22d/0x290 [xfs]\n[ 4277.429500]  xfs_inodegc_worker+0xb4/0x1a0 [xfs]\n[ 4277.430479]  process_one_work+0x171/0x340\n[ 4277.431227]  worker_thread+0x277/0x390\n[ 4277.431962]  ? __pfx_worker_thread+0x10/0x10\n[ 4277.432752]  kthread+0xf0/0x120\n[ 4277.433382]  ? __pfx_kthread+0x10/0x10\n[ 4277.434134]  ret_from_fork+0x2d/0x50\n[ 4277.434837]  ? __pfx_kthread+0x10/0x10\n[ 4277.435566]  ret_from_fork_asm+0x1b/0x30\n[ 4277.436280]  </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56566","epss":0.00216,"percentile":0.12015,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56566","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56566","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56583","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sched/deadline: Fix warning in migrate_enable for boosted tasks  When running the following command:  while true; do     stress-ng --cyclic 30 --timeout 30s --minimize --quiet done  a warning is eventually triggered:  WARNING: CPU: 43 PID: 2848 at kernel/sched/deadline.c:794 setup_new_dl_entity+0x13e/0x180 ... Call Trace:  <TASK>  ? show_trace_log_lvl+0x1c4/0x2df  ? enqueue_dl_entity+0x631/0x6e0  ? setup_new_dl_entity+0x13e/0x180  ? __warn+0x7e/0xd0  ? report_bug+0x11a/0x1a0  ? handle_bug+0x3c/0x70  ? exc_invalid_op+0x14/0x70  ? asm_exc_invalid_op+0x16/0x20  enqueue_dl_entity+0x631/0x6e0  enqueue_task_dl+0x7d/0x120  __do_set_cpus_allowed+0xe3/0x280  __set_cpus_allowed_ptr_locked+0x140/0x1d0  __set_cpus_allowed_ptr+0x54/0xa0  migrate_enable+0x7e/0x150  rt_spin_unlock+0x1c/0x90  group_send_sig_info+0xf7/0x1a0  ? kill_pid_info+0x1f/0x1d0  kill_pid_info+0x78/0x1d0  kill_proc_info+0x5b/0x110  __x64_sys_kill+0x93/0xc0  do_syscall_64+0x5c/0xf0  entry_SYSCALL_64_after_hwframe+0x6e/0x76  RIP: 0033:0x7f0dab31f92b  This warning occurs because set_cpus_allowed dequeues and enqueues tasks with the ENQUEUE_RESTORE flag set. If the task is boosted, the warning is triggered. A boosted task already had its parameters set by rt_mutex_setprio, and a new call to setup_new_dl_entity is unnecessary, hence the WARN_ON call.  Check if we are requeueing a boosted task and avoid calling setup_new_dl_entity if that's the case.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56583","epss":0.00231,"percentile":0.13906,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12127500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-56583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56583","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0664e2c311b9fa43b33e3e81429cd0c2d7f9c638","https://git.kernel.org/stable/c/b600d30402854415aa57548a6b53dc6478f65517","https://git.kernel.org/stable/c/e41074904d9ed3fe582d6e544c77b40c22043c82"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/deadline: Fix warning in migrate_enable for boosted tasks\n\nWhen running the following command:\n\nwhile true; do\n    stress-ng --cyclic 30 --timeout 30s --minimize --quiet\ndone\n\na warning is eventually triggered:\n\nWARNING: CPU: 43 PID: 2848 at kernel/sched/deadline.c:794\nsetup_new_dl_entity+0x13e/0x180\n...\nCall Trace:\n <TASK>\n ? show_trace_log_lvl+0x1c4/0x2df\n ? enqueue_dl_entity+0x631/0x6e0\n ? setup_new_dl_entity+0x13e/0x180\n ? __warn+0x7e/0xd0\n ? report_bug+0x11a/0x1a0\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x14/0x70\n ? asm_exc_invalid_op+0x16/0x20\n enqueue_dl_entity+0x631/0x6e0\n enqueue_task_dl+0x7d/0x120\n __do_set_cpus_allowed+0xe3/0x280\n __set_cpus_allowed_ptr_locked+0x140/0x1d0\n __set_cpus_allowed_ptr+0x54/0xa0\n migrate_enable+0x7e/0x150\n rt_spin_unlock+0x1c/0x90\n group_send_sig_info+0xf7/0x1a0\n ? kill_pid_info+0x1f/0x1d0\n kill_pid_info+0x78/0x1d0\n kill_proc_info+0x5b/0x110\n __x64_sys_kill+0x93/0xc0\n do_syscall_64+0x5c/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n RIP: 0033:0x7f0dab31f92b\n\nThis warning occurs because set_cpus_allowed dequeues and enqueues tasks\nwith the ENQUEUE_RESTORE flag set. If the task is boosted, the warning\nis triggered. A boosted task already had its parameters set by\nrt_mutex_setprio, and a new call to setup_new_dl_entity is unnecessary,\nhence the WARN_ON call.\n\nCheck if we are requeueing a boosted task and avoid calling\nsetup_new_dl_entity if that's the case.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56583","epss":0.00231,"percentile":0.13906,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56583","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56588","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56588","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: hisi_sas: Create all dump files during debugfs initialization  For the current debugfs of hisi_sas, after user triggers dump, the driver allocate memory space to save the register information and create debugfs files to display the saved information. In this process, the debugfs files created after each dump.  Therefore, when the dump is triggered while the driver is unbind, the following hang occurs:  [67840.853907] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a0 [67840.862947] Mem abort info: [67840.865855]   ESR = 0x0000000096000004 [67840.869713]   EC = 0x25: DABT (current EL), IL = 32 bits [67840.875125]   SET = 0, FnV = 0 [67840.878291]   EA = 0, S1PTW = 0 [67840.881545]   FSC = 0x04: level 0 translation fault [67840.886528] Data abort info: [67840.889524]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [67840.895117]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [67840.900284]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [67840.905709] user pgtable: 4k pages, 48-bit VAs, pgdp=0000002803a1f000 [67840.912263] [00000000000000a0] pgd=0000000000000000, p4d=0000000000000000 [67840.919177] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP [67840.996435] pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [67841.003628] pc : down_write+0x30/0x98 [67841.007546] lr : start_creating.part.0+0x60/0x198 [67841.012495] sp : ffff8000b979ba20 [67841.016046] x29: ffff8000b979ba20 x28: 0000000000000010 x27: 0000000000024b40 [67841.023412] x26: 0000000000000012 x25: ffff20202b355ae8 x24: ffff20202b35a8c8 [67841.030779] x23: ffffa36877928208 x22: ffffa368b4972240 x21: ffff8000b979bb18 [67841.038147] x20: ffff00281dc1e3c0 x19: fffffffffffffffe x18: 0000000000000020 [67841.045515] x17: 0000000000000000 x16: ffffa368b128a530 x15: ffffffffffffffff [67841.052888] x14: ffff8000b979bc18 x13: ffffffffffffffff x12: ffff8000b979bb18 [67841.060263] x11: 0000000000000000 x10: 0000000000000000 x9 : ffffa368b1289b18 [67841.067640] x8 : 0000000000000012 x7 : 0000000000000000 x6 : 00000000000003a9 [67841.075014] x5 : 0000000000000000 x4 : ffff002818c5cb00 x3 : 0000000000000001 [67841.082388] x2 : 0000000000000000 x1 : ffff002818c5cb00 x0 : 00000000000000a0 [67841.089759] Call trace: [67841.092456]  down_write+0x30/0x98 [67841.096017]  start_creating.part.0+0x60/0x198 [67841.100613]  debugfs_create_dir+0x48/0x1f8 [67841.104950]  debugfs_create_files_v3_hw+0x88/0x348 [hisi_sas_v3_hw] [67841.111447]  debugfs_snapshot_regs_v3_hw+0x708/0x798 [hisi_sas_v3_hw] [67841.118111]  debugfs_trigger_dump_v3_hw_write+0x9c/0x120 [hisi_sas_v3_hw] [67841.125115]  full_proxy_write+0x68/0xc8 [67841.129175]  vfs_write+0xd8/0x3f0 [67841.132708]  ksys_write+0x70/0x108 [67841.136317]  __arm64_sys_write+0x24/0x38 [67841.140440]  invoke_syscall+0x50/0x128 [67841.144385]  el0_svc_common.constprop.0+0xc8/0xf0 [67841.149273]  do_el0_svc+0x24/0x38 [67841.152773]  el0_svc+0x38/0xd8 [67841.156009]  el0t_64_sync_handler+0xc0/0xc8 [67841.160361]  el0t_64_sync+0x1a4/0x1a8 [67841.164189] Code: b9000882 d2800002 d2800023 f9800011 (c85ffc05) [67841.170443] ---[ end trace 0000000000000000 ]---  To fix this issue, create all directories and files during debugfs initialization. In this way, the driver only needs to allocate memory space to save information each time the user triggers dumping.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56588","epss":0.00234,"percentile":0.14327,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56588","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12285},"relatedVulnerabilities":[{"id":"CVE-2024-56588","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56588","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6c55f99123075e5429850b41b06f7dfffcb708eb","https://git.kernel.org/stable/c/7c8c50c9855a9e1b0d1e3680e5ad839002a9deb5","https://git.kernel.org/stable/c/9f564f15f88490b484e02442dc4c4b11640ea172"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Create all dump files during debugfs initialization\n\nFor the current debugfs of hisi_sas, after user triggers dump, the\ndriver allocate memory space to save the register information and create\ndebugfs files to display the saved information. In this process, the\ndebugfs files created after each dump.\n\nTherefore, when the dump is triggered while the driver is unbind, the\nfollowing hang occurs:\n\n[67840.853907] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a0\n[67840.862947] Mem abort info:\n[67840.865855]   ESR = 0x0000000096000004\n[67840.869713]   EC = 0x25: DABT (current EL), IL = 32 bits\n[67840.875125]   SET = 0, FnV = 0\n[67840.878291]   EA = 0, S1PTW = 0\n[67840.881545]   FSC = 0x04: level 0 translation fault\n[67840.886528] Data abort info:\n[67840.889524]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[67840.895117]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[67840.900284]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[67840.905709] user pgtable: 4k pages, 48-bit VAs, pgdp=0000002803a1f000\n[67840.912263] [00000000000000a0] pgd=0000000000000000, p4d=0000000000000000\n[67840.919177] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[67840.996435] pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[67841.003628] pc : down_write+0x30/0x98\n[67841.007546] lr : start_creating.part.0+0x60/0x198\n[67841.012495] sp : ffff8000b979ba20\n[67841.016046] x29: ffff8000b979ba20 x28: 0000000000000010 x27: 0000000000024b40\n[67841.023412] x26: 0000000000000012 x25: ffff20202b355ae8 x24: ffff20202b35a8c8\n[67841.030779] x23: ffffa36877928208 x22: ffffa368b4972240 x21: ffff8000b979bb18\n[67841.038147] x20: ffff00281dc1e3c0 x19: fffffffffffffffe x18: 0000000000000020\n[67841.045515] x17: 0000000000000000 x16: ffffa368b128a530 x15: ffffffffffffffff\n[67841.052888] x14: ffff8000b979bc18 x13: ffffffffffffffff x12: ffff8000b979bb18\n[67841.060263] x11: 0000000000000000 x10: 0000000000000000 x9 : ffffa368b1289b18\n[67841.067640] x8 : 0000000000000012 x7 : 0000000000000000 x6 : 00000000000003a9\n[67841.075014] x5 : 0000000000000000 x4 : ffff002818c5cb00 x3 : 0000000000000001\n[67841.082388] x2 : 0000000000000000 x1 : ffff002818c5cb00 x0 : 00000000000000a0\n[67841.089759] Call trace:\n[67841.092456]  down_write+0x30/0x98\n[67841.096017]  start_creating.part.0+0x60/0x198\n[67841.100613]  debugfs_create_dir+0x48/0x1f8\n[67841.104950]  debugfs_create_files_v3_hw+0x88/0x348 [hisi_sas_v3_hw]\n[67841.111447]  debugfs_snapshot_regs_v3_hw+0x708/0x798 [hisi_sas_v3_hw]\n[67841.118111]  debugfs_trigger_dump_v3_hw_write+0x9c/0x120 [hisi_sas_v3_hw]\n[67841.125115]  full_proxy_write+0x68/0xc8\n[67841.129175]  vfs_write+0xd8/0x3f0\n[67841.132708]  ksys_write+0x70/0x108\n[67841.136317]  __arm64_sys_write+0x24/0x38\n[67841.140440]  invoke_syscall+0x50/0x128\n[67841.144385]  el0_svc_common.constprop.0+0xc8/0xf0\n[67841.149273]  do_el0_svc+0x24/0x38\n[67841.152773]  el0_svc+0x38/0xd8\n[67841.156009]  el0t_64_sync_handler+0xc0/0xc8\n[67841.160361]  el0t_64_sync+0x1a4/0x1a8\n[67841.164189] Code: b9000882 d2800002 d2800023 f9800011 (c85ffc05)\n[67841.170443] ---[ end trace 0000000000000000 ]---\n\nTo fix this issue, create all directories and files during debugfs\ninitialization. In this way, the driver only needs to allocate memory\nspace to save information each time the user triggers dumping.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56588","epss":0.00234,"percentile":0.14327,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56588","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56588","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56591","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56591","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_conn: Use disable_delayed_work_sync  This makes use of disable_delayed_work_sync instead cancel_delayed_work_sync as it not only cancel the ongoing work but also disables new submit which is disarable since the object holding the work is about to be freed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56591","epss":0.00281,"percentile":0.20413,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.147525},"relatedVulnerabilities":[{"id":"CVE-2024-56591","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56591","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2b0f2fc9ed62e73c95df1fa8ed2ba3dac54699df","https://git.kernel.org/stable/c/c55a4c5a04bae40dcdc1e1c19d8eb79a06fb3397"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Use disable_delayed_work_sync\n\nThis makes use of disable_delayed_work_sync instead\ncancel_delayed_work_sync as it not only cancel the ongoing work but also\ndisables new submit which is disarable since the object holding the work\nis about to be freed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56591","epss":0.00281,"percentile":0.20413,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56591","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56592","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56592","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Call free_htab_elem() after htab_unlock_bucket()  For htab of maps, when the map is removed from the htab, it may hold the last reference of the map. bpf_map_fd_put_ptr() will invoke bpf_map_free_id() to free the id of the removed map element. However, bpf_map_fd_put_ptr() is invoked while holding a bucket lock (raw_spin_lock_t), and bpf_map_free_id() attempts to acquire map_idr_lock (spinlock_t), triggering the following lockdep warning:    =============================   [ BUG: Invalid wait context ]   6.11.0-rc4+ #49 Not tainted   -----------------------------   test_maps/4881 is trying to lock:   ffffffff84884578 (map_idr_lock){+...}-{3:3}, at: bpf_map_free_id.part.0+0x21/0x70   other info that might help us debug this:   context-{5:5}   2 locks held by test_maps/4881:    #0: ffffffff846caf60 (rcu_read_lock){....}-{1:3}, at: bpf_fd_htab_map_update_elem+0xf9/0x270    #1: ffff888149ced148 (&htab->lockdep_key#2){....}-{2:2}, at: htab_map_update_elem+0x178/0xa80   stack backtrace:   CPU: 0 UID: 0 PID: 4881 Comm: test_maps Not tainted 6.11.0-rc4+ #49   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), ...   Call Trace:    <TASK>    dump_stack_lvl+0x6e/0xb0    dump_stack+0x10/0x20    __lock_acquire+0x73e/0x36c0    lock_acquire+0x182/0x450    _raw_spin_lock_irqsave+0x43/0x70    bpf_map_free_id.part.0+0x21/0x70    bpf_map_put+0xcf/0x110    bpf_map_fd_put_ptr+0x9a/0xb0    free_htab_elem+0x69/0xe0    htab_map_update_elem+0x50f/0xa80    bpf_fd_htab_map_update_elem+0x131/0x270    htab_map_update_elem+0x50f/0xa80    bpf_fd_htab_map_update_elem+0x131/0x270    bpf_map_update_value+0x266/0x380    __sys_bpf+0x21bb/0x36b0    __x64_sys_bpf+0x45/0x60    x64_sys_call+0x1b2a/0x20d0    do_syscall_64+0x5d/0x100    entry_SYSCALL_64_after_hwframe+0x76/0x7e  One way to fix the lockdep warning is using raw_spinlock_t for map_idr_lock as well. However, bpf_map_alloc_id() invokes idr_alloc_cyclic() after acquiring map_idr_lock, it will trigger a similar lockdep warning because the slab's lock (s->cpu_slab->lock) is still a spinlock.  Instead of changing map_idr_lock's type, fix the issue by invoking htab_put_fd_value() after htab_unlock_bucket(). However, only deferring the invocation of htab_put_fd_value() is not enough, because the old map pointers in htab of maps can not be saved during batched deletion. Therefore, also defer the invocation of free_htab_elem(), so these to-be-freed elements could be linked together similar to lru map.  There are four callers for ->map_fd_put_ptr:  (1) alloc_htab_elem() (through htab_put_fd_value()) It invokes ->map_fd_put_ptr() under a raw_spinlock_t. The invocation of htab_put_fd_value() can not simply move after htab_unlock_bucket(), because the old element has already been stashed in htab->extra_elems. It may be reused immediately after htab_unlock_bucket() and the invocation of htab_put_fd_value() after htab_unlock_bucket() may release the newly-added element incorrectly. Therefore, saving the map pointer of the old element for htab of maps before unlocking the bucket and releasing the map_ptr after unlock. Beside the map pointer in the old element, should do the same thing for the special fields in the old element as well.  (2) free_htab_elem() (through htab_put_fd_value()) Its caller includes __htab_map_lookup_and_delete_elem(), htab_map_delete_elem() and __htab_map_lookup_and_delete_batch().  For htab_map_delete_elem(), simply invoke free_htab_elem() after htab_unlock_bucket(). For __htab_map_lookup_and_delete_batch(), just like lru map, linking the to-be-freed element into node_to_free list and invoking free_htab_elem() for these element after unlock. It is safe to reuse batch_flink as the link for node_to_free, because these elements have been removed from the hash llist.  Because htab of maps doesn't support lookup_and_delete operation, __htab_map_lookup_and_delete_elem() doesn't have the problem, so kept it as ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56592","epss":0.00218,"percentile":0.12168,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11445000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-56592","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56592","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/10e8a2dec9ff1b81de8e892b0850924038adbc6d","https://git.kernel.org/stable/c/a50b4aa3007e63a590d501341f304676ebc74b3b","https://git.kernel.org/stable/c/b9e9ed90b10c82a4e9d4d70a2890f06bfcdd3b78"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Call free_htab_elem() after htab_unlock_bucket()\n\nFor htab of maps, when the map is removed from the htab, it may hold the\nlast reference of the map. bpf_map_fd_put_ptr() will invoke\nbpf_map_free_id() to free the id of the removed map element. However,\nbpf_map_fd_put_ptr() is invoked while holding a bucket lock\n(raw_spin_lock_t), and bpf_map_free_id() attempts to acquire map_idr_lock\n(spinlock_t), triggering the following lockdep warning:\n\n  =============================\n  [ BUG: Invalid wait context ]\n  6.11.0-rc4+ #49 Not tainted\n  -----------------------------\n  test_maps/4881 is trying to lock:\n  ffffffff84884578 (map_idr_lock){+...}-{3:3}, at: bpf_map_free_id.part.0+0x21/0x70\n  other info that might help us debug this:\n  context-{5:5}\n  2 locks held by test_maps/4881:\n   #0: ffffffff846caf60 (rcu_read_lock){....}-{1:3}, at: bpf_fd_htab_map_update_elem+0xf9/0x270\n   #1: ffff888149ced148 (&htab->lockdep_key#2){....}-{2:2}, at: htab_map_update_elem+0x178/0xa80\n  stack backtrace:\n  CPU: 0 UID: 0 PID: 4881 Comm: test_maps Not tainted 6.11.0-rc4+ #49\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), ...\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x6e/0xb0\n   dump_stack+0x10/0x20\n   __lock_acquire+0x73e/0x36c0\n   lock_acquire+0x182/0x450\n   _raw_spin_lock_irqsave+0x43/0x70\n   bpf_map_free_id.part.0+0x21/0x70\n   bpf_map_put+0xcf/0x110\n   bpf_map_fd_put_ptr+0x9a/0xb0\n   free_htab_elem+0x69/0xe0\n   htab_map_update_elem+0x50f/0xa80\n   bpf_fd_htab_map_update_elem+0x131/0x270\n   htab_map_update_elem+0x50f/0xa80\n   bpf_fd_htab_map_update_elem+0x131/0x270\n   bpf_map_update_value+0x266/0x380\n   __sys_bpf+0x21bb/0x36b0\n   __x64_sys_bpf+0x45/0x60\n   x64_sys_call+0x1b2a/0x20d0\n   do_syscall_64+0x5d/0x100\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nOne way to fix the lockdep warning is using raw_spinlock_t for\nmap_idr_lock as well. However, bpf_map_alloc_id() invokes\nidr_alloc_cyclic() after acquiring map_idr_lock, it will trigger a\nsimilar lockdep warning because the slab's lock (s->cpu_slab->lock) is\nstill a spinlock.\n\nInstead of changing map_idr_lock's type, fix the issue by invoking\nhtab_put_fd_value() after htab_unlock_bucket(). However, only deferring\nthe invocation of htab_put_fd_value() is not enough, because the old map\npointers in htab of maps can not be saved during batched deletion.\nTherefore, also defer the invocation of free_htab_elem(), so these\nto-be-freed elements could be linked together similar to lru map.\n\nThere are four callers for ->map_fd_put_ptr:\n\n(1) alloc_htab_elem() (through htab_put_fd_value())\nIt invokes ->map_fd_put_ptr() under a raw_spinlock_t. The invocation of\nhtab_put_fd_value() can not simply move after htab_unlock_bucket(),\nbecause the old element has already been stashed in htab->extra_elems.\nIt may be reused immediately after htab_unlock_bucket() and the\ninvocation of htab_put_fd_value() after htab_unlock_bucket() may release\nthe newly-added element incorrectly. Therefore, saving the map pointer\nof the old element for htab of maps before unlocking the bucket and\nreleasing the map_ptr after unlock. Beside the map pointer in the old\nelement, should do the same thing for the special fields in the old\nelement as well.\n\n(2) free_htab_elem() (through htab_put_fd_value())\nIts caller includes __htab_map_lookup_and_delete_elem(),\nhtab_map_delete_elem() and __htab_map_lookup_and_delete_batch().\n\nFor htab_map_delete_elem(), simply invoke free_htab_elem() after\nhtab_unlock_bucket(). For __htab_map_lookup_and_delete_batch(), just\nlike lru map, linking the to-be-freed element into node_to_free list\nand invoking free_htab_elem() for these element after unlock. It is safe\nto reuse batch_flink as the link for node_to_free, because these\nelements have been removed from the hash llist.\n\nBecause htab of maps doesn't support lookup_and_delete operation,\n__htab_map_lookup_and_delete_elem() doesn't have the problem, so kept\nit as\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56592","epss":0.00218,"percentile":0.12168,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56592","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56611","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56611","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MM  We currently assume that there is at least one VMA in a MM, which isn't true.  So we might end up having find_vma() return NULL, to then de-reference NULL.  So properly handle find_vma() returning NULL.  This fixes the report:  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024 RIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline] RIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194 Code: ... RSP: 0018:ffffc9000375fd08 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000 RDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044 RBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1 R10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003 R13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8 FS:  00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace:  <TASK>  kernel_migrate_pages+0x5b2/0x750 mm/mempolicy.c:1709  __do_sys_migrate_pages mm/mempolicy.c:1727 [inline]  __se_sys_migrate_pages mm/mempolicy.c:1723 [inline]  __x64_sys_migrate_pages+0x96/0x100 mm/mempolicy.c:1723  do_syscall_x64 arch/x86/entry/common.c:52 [inline]  do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f  [akpm@linux-foundation.org: add unlikely()]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56611","epss":0.00206,"percentile":0.10701,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56611","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56611","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-56611","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56611","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/091c1dd2d4df6edd1beebe0e5863d4034ade9572","https://git.kernel.org/stable/c/42d9fe2adf8613f9eea1f0c2619c9e2611eae0ea","https://git.kernel.org/stable/c/a13b2b9b0b0b04612c7d81e3b3dfb485c5f7abc3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MM\n\nWe currently assume that there is at least one VMA in a MM, which isn't\ntrue.\n\nSo we might end up having find_vma() return NULL, to then de-reference\nNULL.  So properly handle find_vma() returning NULL.\n\nThis fixes the report:\n\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nCPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024\nRIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline]\nRIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194\nCode: ...\nRSP: 0018:ffffc9000375fd08 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000\nRDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044\nRBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1\nR10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003\nR13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8\nFS:  00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n <TASK>\n kernel_migrate_pages+0x5b2/0x750 mm/mempolicy.c:1709\n __do_sys_migrate_pages mm/mempolicy.c:1727 [inline]\n __se_sys_migrate_pages mm/mempolicy.c:1723 [inline]\n __x64_sys_migrate_pages+0x96/0x100 mm/mempolicy.c:1723\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n[akpm@linux-foundation.org: add unlikely()]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56611","epss":0.00206,"percentile":0.10701,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56611","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56611","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56611","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56641","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56641","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/smc: initialize close_work early to avoid warning  We encountered a warning that close_work was canceled before initialization.    WARNING: CPU: 7 PID: 111103 at kernel/workqueue.c:3047 __flush_work+0x19e/0x1b0   Workqueue: events smc_lgr_terminate_work [smc]   RIP: 0010:__flush_work+0x19e/0x1b0   Call Trace:    ? __wake_up_common+0x7a/0x190    ? work_busy+0x80/0x80    __cancel_work_timer+0xe3/0x160    smc_close_cancel_work+0x1a/0x70 [smc]    smc_close_active_abort+0x207/0x360 [smc]    __smc_lgr_terminate.part.38+0xc8/0x180 [smc]    process_one_work+0x19e/0x340    worker_thread+0x30/0x370    ? process_one_work+0x340/0x340    kthread+0x117/0x130    ? __kthread_cancel_work+0x50/0x50    ret_from_fork+0x22/0x30  This is because when smc_close_cancel_work is triggered, e.g. the RDMA driver is rmmod and the LGR is terminated, the conn->close_work is flushed before initialization, resulting in WARN_ON(!work->func).  __smc_lgr_terminate             | smc_connect_{rdma|ism} -------------------------------------------------------------                                 | smc_conn_create \t\t\t\t| \\- smc_lgr_register_conn for conn in lgr->conns_all      | \\- smc_conn_kill                |    \\- smc_close_active_abort    |       \\- smc_close_cancel_work  |          \\- cancel_work_sync    |             \\- __flush_work     | \t         (close_work)   | \t                        | smc_close_init \t                        | \\- INIT_WORK(&close_work)  So fix this by initializing close_work before establishing the connection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56641","epss":0.0051,"percentile":0.41851,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26775000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-56641","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56641","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0541db8ee32c09463a72d0987382b3a3336b0043","https://git.kernel.org/stable/c/6638e52dcfafaf1b9cbc34544f0c832db0069ea1","https://git.kernel.org/stable/c/f0c37002210aaede10dae849d1a78efc2243add2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: initialize close_work early to avoid warning\n\nWe encountered a warning that close_work was canceled before\ninitialization.\n\n  WARNING: CPU: 7 PID: 111103 at kernel/workqueue.c:3047 __flush_work+0x19e/0x1b0\n  Workqueue: events smc_lgr_terminate_work [smc]\n  RIP: 0010:__flush_work+0x19e/0x1b0\n  Call Trace:\n   ? __wake_up_common+0x7a/0x190\n   ? work_busy+0x80/0x80\n   __cancel_work_timer+0xe3/0x160\n   smc_close_cancel_work+0x1a/0x70 [smc]\n   smc_close_active_abort+0x207/0x360 [smc]\n   __smc_lgr_terminate.part.38+0xc8/0x180 [smc]\n   process_one_work+0x19e/0x340\n   worker_thread+0x30/0x370\n   ? process_one_work+0x340/0x340\n   kthread+0x117/0x130\n   ? __kthread_cancel_work+0x50/0x50\n   ret_from_fork+0x22/0x30\n\nThis is because when smc_close_cancel_work is triggered, e.g. the RDMA\ndriver is rmmod and the LGR is terminated, the conn->close_work is\nflushed before initialization, resulting in WARN_ON(!work->func).\n\n__smc_lgr_terminate             | smc_connect_{rdma|ism}\n-------------------------------------------------------------\n                                | smc_conn_create\n\t\t\t\t| \\- smc_lgr_register_conn\nfor conn in lgr->conns_all      |\n\\- smc_conn_kill                |\n   \\- smc_close_active_abort    |\n      \\- smc_close_cancel_work  |\n         \\- cancel_work_sync    |\n            \\- __flush_work     |\n\t         (close_work)   |\n\t                        | smc_close_init\n\t                        | \\- INIT_WORK(&close_work)\n\nSo fix this by initializing close_work before establishing the\nconnection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56641","epss":0.0051,"percentile":0.41851,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56641","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56692","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56692","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to do sanity check on node blkaddr in truncate_node()  syzbot reports a f2fs bug as below:  ------------[ cut here ]------------ kernel BUG at fs/f2fs/segment.c:2534! RIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534 Call Trace:  truncate_node+0x1ae/0x8c0 fs/f2fs/node.c:909  f2fs_remove_inode_page+0x5c2/0x870 fs/f2fs/node.c:1288  f2fs_evict_inode+0x879/0x15c0 fs/f2fs/inode.c:856  evict+0x4e8/0x9b0 fs/inode.c:723  f2fs_handle_failed_inode+0x271/0x2e0 fs/f2fs/inode.c:986  f2fs_create+0x357/0x530 fs/f2fs/namei.c:394  lookup_open fs/namei.c:3595 [inline]  open_last_lookups fs/namei.c:3694 [inline]  path_openat+0x1c03/0x3590 fs/namei.c:3930  do_filp_open+0x235/0x490 fs/namei.c:3960  do_sys_openat2+0x13e/0x1d0 fs/open.c:1415  do_sys_open fs/open.c:1430 [inline]  __do_sys_openat fs/open.c:1446 [inline]  __se_sys_openat fs/open.c:1441 [inline]  __x64_sys_openat+0x247/0x2a0 fs/open.c:1441  do_syscall_x64 arch/x86/entry/common.c:52 [inline]  do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534  The root cause is: on a fuzzed image, blkaddr in nat entry may be corrupted, then it will cause system panic when using it in f2fs_invalidate_blocks(), to avoid this, let's add sanity check on nat blkaddr in truncate_node().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56692","epss":0.00216,"percentile":0.11997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56692","cwe":"CWE-754","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56692","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1134},"relatedVulnerabilities":[{"id":"CVE-2024-56692","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56692","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0a5c8b3fbf6200f1c66062d307c9a52084917788","https://git.kernel.org/stable/c/27d6e7eff07f8cce8e83b162d8f21a07458c860d","https://git.kernel.org/stable/c/6babe00ccd34fc65b78ef8b99754e32b4385f23d","https://git.kernel.org/stable/c/c1077078ce4589b5e5387f6b0aaa0d4534b9eb57"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on node blkaddr in truncate_node()\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/segment.c:2534!\nRIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534\nCall Trace:\n truncate_node+0x1ae/0x8c0 fs/f2fs/node.c:909\n f2fs_remove_inode_page+0x5c2/0x870 fs/f2fs/node.c:1288\n f2fs_evict_inode+0x879/0x15c0 fs/f2fs/inode.c:856\n evict+0x4e8/0x9b0 fs/inode.c:723\n f2fs_handle_failed_inode+0x271/0x2e0 fs/f2fs/inode.c:986\n f2fs_create+0x357/0x530 fs/f2fs/namei.c:394\n lookup_open fs/namei.c:3595 [inline]\n open_last_lookups fs/namei.c:3694 [inline]\n path_openat+0x1c03/0x3590 fs/namei.c:3930\n do_filp_open+0x235/0x490 fs/namei.c:3960\n do_sys_openat2+0x13e/0x1d0 fs/open.c:1415\n do_sys_open fs/open.c:1430 [inline]\n __do_sys_openat fs/open.c:1446 [inline]\n __se_sys_openat fs/open.c:1441 [inline]\n __x64_sys_openat+0x247/0x2a0 fs/open.c:1441\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534\n\nThe root cause is: on a fuzzed image, blkaddr in nat entry may be\ncorrupted, then it will cause system panic when using it in\nf2fs_invalidate_blocks(), to avoid this, let's add sanity check on\nnat blkaddr in truncate_node().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56692","epss":0.00216,"percentile":0.11997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56692","cwe":"CWE-754","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56692","cwe":"CWE-754","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56692","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56712","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56712","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  udmabuf: fix memory leak on last export_udmabuf() error path  In export_udmabuf(), if dma_buf_fd() fails because the FD table is full, a dma_buf owning the udmabuf has already been created; but the error handling in udmabuf_create() will tear down the udmabuf without doing anything about the containing dma_buf.  This leaves a dma_buf in memory that contains a dangling pointer; though that doesn't seem to lead to anything bad except a memory leak.  Fix it by moving the dma_buf_fd() call out of export_udmabuf() so that we can give it different error handling.  Note that the shape of this code changed a lot in commit 5e72b2b41a21 (\"udmabuf: convert udmabuf driver to use folios\"); but the memory leak seems to have existed since the introduction of udmabuf.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56712","epss":0.00188,"percentile":0.08482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56712","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56712","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09870000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-56712","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56712","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/c9fc8428d4255c2128da9c4d5cd92e554d0150cf","https://git.kernel.org/stable/c/f49856f525acd5bef52ae28b7da2e001bbe7439e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nudmabuf: fix memory leak on last export_udmabuf() error path\n\nIn export_udmabuf(), if dma_buf_fd() fails because the FD table is full, a\ndma_buf owning the udmabuf has already been created; but the error handling\nin udmabuf_create() will tear down the udmabuf without doing anything about\nthe containing dma_buf.\n\nThis leaves a dma_buf in memory that contains a dangling pointer; though\nthat doesn't seem to lead to anything bad except a memory leak.\n\nFix it by moving the dma_buf_fd() call out of export_udmabuf() so that we\ncan give it different error handling.\n\nNote that the shape of this code changed a lot in commit 5e72b2b41a21\n(\"udmabuf: convert udmabuf driver to use folios\"); but the memory leak\nseems to have existed since the introduction of udmabuf.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56712","epss":0.00188,"percentile":0.08482,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56712","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56712","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56712","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56729","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56729","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: Initialize cfid->tcon before performing network ops  Avoid leaking a tcon ref when a lease break races with opening the cached directory. Processing the leak break might take a reference to the tcon in cached_dir_lease_break() and then fail to release the ref in cached_dir_offload_close, since cfid->tcon is still NULL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56729","epss":0.00199,"percentile":0.0978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56729","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56729","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.096515},"relatedVulnerabilities":[{"id":"CVE-2024-56729","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56729","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1b9ab6b648f89441c8a13cb3fd8ca83ffebc5262","https://git.kernel.org/stable/c/4b216c8f9c7d84ef7de33ca60b97e08e03ef3292","https://git.kernel.org/stable/c/625e2357c8fcfae6e66dcc667dc656fe390bab15","https://git.kernel.org/stable/c/c353ee4fb119a2582d0e011f66a76a38f5cf984d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Initialize cfid->tcon before performing network ops\n\nAvoid leaking a tcon ref when a lease break races with opening the\ncached directory. Processing the leak break might take a reference to\nthe tcon in cached_dir_lease_break() and then fail to release the ref in\ncached_dir_offload_close, since cfid->tcon is still NULL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56729","epss":0.00199,"percentile":0.0978,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56729","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56729","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56729","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56742","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages()  Fix an unwind issue in mlx5vf_add_migration_pages().  If a set of pages is allocated but fails to be added to the SG table, they need to be freed to prevent a memory leak.  Any pages successfully added to the SG table will be freed as part of mlx5vf_free_data_buffer().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56742","epss":0.00214,"percentile":0.11694,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56742","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56742","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11234999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-56742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56742","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/22e87bf3f77c18f5982c19ffe2732ef0c7a25f16","https://git.kernel.org/stable/c/769fe4ce444b646b0bf6ac308de80686c730c7df","https://git.kernel.org/stable/c/c44f1b2ddfa81c8d7f8e9b6bc76c427bc00e69d5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages()\n\nFix an unwind issue in mlx5vf_add_migration_pages().\n\nIf a set of pages is allocated but fails to be added to the SG table,\nthey need to be freed to prevent a memory leak.\n\nAny pages successfully added to the SG table will be freed as part of\nmlx5vf_free_data_buffer().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"exploitabilityScore":1.9,"impactScore":1.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56742","epss":0.00214,"percentile":0.11694,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56742","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56742","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56742","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-56775","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56775","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix handling of plane refcount  [Why] The mechanism to backup and restore plane states doesn't maintain refcount, which can cause issues if the refcount of the plane changes in between backup and restore operations, such as memory leaks if the refcount was supposed to go down, or double frees / invalid memory accesses if the refcount was supposed to go up.  [How] Cache and re-apply current refcount when restoring plane states.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56775","epss":0.00205,"percentile":0.10545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56775","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56775","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56775","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15682500000000002},"relatedVulnerabilities":[{"id":"CVE-2024-56775","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56775","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/27227a234c1487cb7a684615f0749c455218833a","https://git.kernel.org/stable/c/8cb2f6793845f135b28361ba8e96901cae3e5790"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix handling of plane refcount\n\n[Why]\nThe mechanism to backup and restore plane states doesn't maintain\nrefcount, which can cause issues if the refcount of the plane changes\nin between backup and restore operations, such as memory leaks if the\nrefcount was supposed to go down, or double frees / invalid memory\naccesses if the refcount was supposed to go up.\n\n[How]\nCache and re-apply current refcount when restoring plane states.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-56775","epss":0.00205,"percentile":0.10545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-56775","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56775","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-56775","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-56775","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57795","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57795","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Remove the direct link to net_device  The similar patch in siw is in the link: https://git.kernel.org/rdma/rdma/c/16b87037b48889  This problem also occurred in RXE. The following analyze this problem. In the following Call Traces: \" BUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0 net/core/dev.c:8782 Read of size 4 at addr ffff8880554640b0 by task kworker/1:4/5295  CPU: 1 UID: 0 PID: 5295 Comm: kworker/1:4 Not tainted 6.12.0-rc3-syzkaller-00399-g9197b73fd7bb #0 Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: infiniband ib_cache_event_task Call Trace:  <TASK>  __dump_stack lib/dump_stack.c:94 [inline]  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:377 [inline]  print_report+0x169/0x550 mm/kasan/report.c:488  kasan_report+0x143/0x180 mm/kasan/report.c:601  dev_get_flags+0x188/0x1d0 net/core/dev.c:8782  rxe_query_port+0x12d/0x260 drivers/infiniband/sw/rxe/rxe_verbs.c:60  __ib_query_port drivers/infiniband/core/device.c:2111 [inline]  ib_query_port+0x168/0x7d0 drivers/infiniband/core/device.c:2143  ib_cache_update+0x1a9/0xb80 drivers/infiniband/core/cache.c:1494  ib_cache_event_task+0xf3/0x1e0 drivers/infiniband/core/cache.c:1568  process_one_work kernel/workqueue.c:3229 [inline]  process_scheduled_works+0xa65/0x1850 kernel/workqueue.c:3310  worker_thread+0x870/0xd30 kernel/workqueue.c:3391  kthread+0x2f2/0x390 kernel/kthread.c:389  ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244  </TASK> \"  1). In the link [1],  \"  infiniband syz2: set down \"  This means that on 839.350575, the event ib_cache_event_task was sent andi queued in ib_wq.  2). In the link [1],  \"  team0 (unregistering): Port device team_slave_0 removed \"  It indicates that before 843.251853, the net device should be freed.  3). In the link [1],  \"  BUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0 \"  This means that on 850.559070, this slab-use-after-free problem occurred.  In all, on 839.350575, the event ib_cache_event_task was sent and queued in ib_wq,  before 843.251853, the net device veth was freed.  on 850.559070, this event was executed, and the mentioned freed net device was called. Thus, the above call trace occurred.  [1] https://syzkaller.appspot.com/x/log.txt?x=12e7025f980000","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57795","epss":0.00222,"percentile":0.12716,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57795","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16983000000000004},"relatedVulnerabilities":[{"id":"CVE-2024-57795","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57795","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2ac5415022d16d63d912a39a06f32f1f51140261","https://git.kernel.org/stable/c/32ca3557d968e662957131374a5f81c9c9cdbba8","https://git.kernel.org/stable/c/9f6f54e6a6863131442b40e14d1792b090c7ce21"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Remove the direct link to net_device\n\nThe similar patch in siw is in the link:\nhttps://git.kernel.org/rdma/rdma/c/16b87037b48889\n\nThis problem also occurred in RXE. The following analyze this problem.\nIn the following Call Traces:\n\"\nBUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0 net/core/dev.c:8782\nRead of size 4 at addr ffff8880554640b0 by task kworker/1:4/5295\n\nCPU: 1 UID: 0 PID: 5295 Comm: kworker/1:4 Not tainted\n6.12.0-rc3-syzkaller-00399-g9197b73fd7bb #0\nHardware name: Google Compute Engine/Google Compute Engine,\nBIOS Google 09/13/2024\nWorkqueue: infiniband ib_cache_event_task\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n dev_get_flags+0x188/0x1d0 net/core/dev.c:8782\n rxe_query_port+0x12d/0x260 drivers/infiniband/sw/rxe/rxe_verbs.c:60\n __ib_query_port drivers/infiniband/core/device.c:2111 [inline]\n ib_query_port+0x168/0x7d0 drivers/infiniband/core/device.c:2143\n ib_cache_update+0x1a9/0xb80 drivers/infiniband/core/cache.c:1494\n ib_cache_event_task+0xf3/0x1e0 drivers/infiniband/core/cache.c:1568\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa65/0x1850 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f2/0x390 kernel/kthread.c:389\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n </TASK>\n\"\n\n1). In the link [1],\n\n\"\n infiniband syz2: set down\n\"\n\nThis means that on 839.350575, the event ib_cache_event_task was sent andi\nqueued in ib_wq.\n\n2). In the link [1],\n\n\"\n team0 (unregistering): Port device team_slave_0 removed\n\"\n\nIt indicates that before 843.251853, the net device should be freed.\n\n3). In the link [1],\n\n\"\n BUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0\n\"\n\nThis means that on 850.559070, this slab-use-after-free problem occurred.\n\nIn all, on 839.350575, the event ib_cache_event_task was sent and queued\nin ib_wq,\n\nbefore 843.251853, the net device veth was freed.\n\non 850.559070, this event was executed, and the mentioned freed net device\nwas called. Thus, the above call trace occurred.\n\n[1] https://syzkaller.appspot.com/x/log.txt?x=12e7025f980000","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57795","epss":0.00222,"percentile":0.12716,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57795","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57795","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57804","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57804","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs  The driver, through the SAS transport, exposes a sysfs interface to enable/disable PHYs in a controller/expander setup.  When multiple PHYs are disabled and enabled in rapid succession, the persistent and current config pages related to SAS IO unit/SAS Expander pages could get corrupted.  Use separate memory for each config request.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57804","epss":0.00184,"percentile":0.08095,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0966},"relatedVulnerabilities":[{"id":"CVE-2024-57804","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57804","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/711201a8b8334a397440ac0b859df0054e174bc9","https://git.kernel.org/stable/c/869fdc6f0606060301aef648231e186c7c542f5a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs\n\nThe driver, through the SAS transport, exposes a sysfs interface to\nenable/disable PHYs in a controller/expander setup.  When multiple PHYs\nare disabled and enabled in rapid succession, the persistent and current\nconfig pages related to SAS IO unit/SAS Expander pages could get\ncorrupted.\n\nUse separate memory for each config request.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57804","epss":0.00184,"percentile":0.08095,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57804","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57809","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57809","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  PCI: imx6: Fix suspend/resume support on i.MX6QDL  The suspend/resume functionality is currently broken on the i.MX6QDL platform, as documented in the NXP errata (ERR005723):    https://www.nxp.com/docs/en/errata/IMX6DQCE.pdf  This patch addresses the issue by sharing most of the suspend/resume sequences used by other i.MX devices, while avoiding modifications to critical registers that disrupt the PCIe functionality. It targets the same problem as the following downstream commit:    https://github.com/nxp-imx/linux-imx/commit/4e92355e1f79d225ea842511fcfd42b343b32995  Unlike the downstream commit, this patch also resets the connected PCIe device if possible. Without this reset, certain drivers, such as ath10k or iwlwifi, will crash on resume. The device reset is also done by the driver on other i.MX platforms, making this patch consistent with existing practices.  Upon resuming, the kernel will hang and display an error. Here's an example of the error encountered with the ath10k driver:    ath10k_pci 0000:01:00.0: Unable to change power state from D3hot to D0, device inaccessible   Unhandled fault: imprecise external abort (0x1406) at 0x0106f944  Without this patch, suspend/resume will fail on i.MX6QDL devices if a PCIe device is connected.  [kwilczynski: commit log, added tag for stable releases]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57809","epss":0.00177,"percentile":0.07344,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09292500000000001},"relatedVulnerabilities":[{"id":"CVE-2024-57809","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57809","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0a726f542d7c8cc0f9c5ed7df5a4bd4b59ac21b3","https://git.kernel.org/stable/c/ac43ea3d27a8f9beadf3af66c9ea4a566ebfff1f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: imx6: Fix suspend/resume support on i.MX6QDL\n\nThe suspend/resume functionality is currently broken on the i.MX6QDL\nplatform, as documented in the NXP errata (ERR005723):\n\n  https://www.nxp.com/docs/en/errata/IMX6DQCE.pdf\n\nThis patch addresses the issue by sharing most of the suspend/resume\nsequences used by other i.MX devices, while avoiding modifications to\ncritical registers that disrupt the PCIe functionality. It targets the\nsame problem as the following downstream commit:\n\n  https://github.com/nxp-imx/linux-imx/commit/4e92355e1f79d225ea842511fcfd42b343b32995\n\nUnlike the downstream commit, this patch also resets the connected PCIe\ndevice if possible. Without this reset, certain drivers, such as ath10k\nor iwlwifi, will crash on resume. The device reset is also done by the\ndriver on other i.MX platforms, making this patch consistent with\nexisting practices.\n\nUpon resuming, the kernel will hang and display an error. Here's an\nexample of the error encountered with the ath10k driver:\n\n  ath10k_pci 0000:01:00.0: Unable to change power state from D3hot to D0, device inaccessible\n  Unhandled fault: imprecise external abort (0x1406) at 0x0106f944\n\nWithout this patch, suspend/resume will fail on i.MX6QDL devices if a\nPCIe device is connected.\n\n[kwilczynski: commit log, added tag for stable releases]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57809","epss":0.00177,"percentile":0.07344,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57809","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57857","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57857","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/siw: Remove direct link to net_device  Do not manage a per device direct link to net_device. Rely on associated ib_devices net_device management, not doubling the effort locally. A badly managed local link to net_device was causing a 'KASAN: slab-use-after-free' exception during siw_query_port() call.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57857","epss":0.00212,"percentile":0.11512,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57857","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16218000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-57857","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57857","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/16b87037b48889d21854c8e97aec8a1baf2642b3","https://git.kernel.org/stable/c/4eafeb4f021c50d13f199239d913b37de3c83135"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Remove direct link to net_device\n\nDo not manage a per device direct link to net_device. Rely\non associated ib_devices net_device management, not doubling\nthe effort locally. A badly managed local link to net_device\nwas causing a 'KASAN: slab-use-after-free' exception during\nsiw_query_port() call.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57857","epss":0.00212,"percentile":0.11512,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57857","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57857","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57872","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57872","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove()  This will ensure that the scsi host is cleaned up properly using scsi_host_dev_release(). Otherwise, it may lead to memory leaks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57872","epss":0.00178,"percentile":0.07477,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57872","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-57872","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09345},"relatedVulnerabilities":[{"id":"CVE-2024-57872","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57872","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/897df60c16d54ad515a3d0887edab5c63da06d1f","https://git.kernel.org/stable/c/cd188519d2467ab4c2141587b0551ba030abff0e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: pltfrm: Dellocate HBA during ufshcd_pltfrm_remove()\n\nThis will ensure that the scsi host is cleaned up properly using\nscsi_host_dev_release(). Otherwise, it may lead to memory leaks.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57872","epss":0.00178,"percentile":0.07477,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57872","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-57872","cwe":"CWE-401","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57872","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57888","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57888","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker  After commit 746ae46c1113 (\"drm/sched: Mark scheduler work queues with WQ_MEM_RECLAIM\") amdgpu started seeing the following warning:   [ ] workqueue: WQ_MEM_RECLAIM sdma0:drm_sched_run_job_work [gpu_sched] is flushing !WQ_MEM_RECLAIM events:amdgpu_device_delay_enable_gfx_off [amdgpu] ...  [ ] Workqueue: sdma0 drm_sched_run_job_work [gpu_sched] ...  [ ] Call Trace:  [ ]  <TASK> ...  [ ]  ? check_flush_dependency+0xf5/0x110 ...  [ ]  cancel_delayed_work_sync+0x6e/0x80  [ ]  amdgpu_gfx_off_ctrl+0xab/0x140 [amdgpu]  [ ]  amdgpu_ring_alloc+0x40/0x50 [amdgpu]  [ ]  amdgpu_ib_schedule+0xf4/0x810 [amdgpu]  [ ]  ? drm_sched_run_job_work+0x22c/0x430 [gpu_sched]  [ ]  amdgpu_job_run+0xaa/0x1f0 [amdgpu]  [ ]  drm_sched_run_job_work+0x257/0x430 [gpu_sched]  [ ]  process_one_work+0x217/0x720 ...  [ ]  </TASK>  The intent of the verifcation done in check_flush_depedency is to ensure forward progress during memory reclaim, by flagging cases when either a memory reclaim process, or a memory reclaim work item is flushed from a context not marked as memory reclaim safe.  This is correct when flushing, but when called from the cancel(_delayed)_work_sync() paths it is a false positive because work is either already running, or will not be running at all. Therefore cancelling it is safe and we can relax the warning criteria by letting the helper know of the calling context.  References: 746ae46c1113 (\"drm/sched: Mark scheduler work queues with WQ_MEM_RECLAIM\")","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57888","epss":0.00206,"percentile":0.10701,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10815000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-57888","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57888","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1fd2a57dcb4de3cb40844a29c71b5d7b46a84334","https://git.kernel.org/stable/c/de35994ecd2dd6148ab5a6c5050a1670a04dec77","https://git.kernel.org/stable/c/ffb231471a407c96e114070bf828cd2378fdf431"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nworkqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker\n\nAfter commit\n746ae46c1113 (\"drm/sched: Mark scheduler work queues with WQ_MEM_RECLAIM\")\namdgpu started seeing the following warning:\n\n [ ] workqueue: WQ_MEM_RECLAIM sdma0:drm_sched_run_job_work [gpu_sched] is flushing !WQ_MEM_RECLAIM events:amdgpu_device_delay_enable_gfx_off [amdgpu]\n...\n [ ] Workqueue: sdma0 drm_sched_run_job_work [gpu_sched]\n...\n [ ] Call Trace:\n [ ]  <TASK>\n...\n [ ]  ? check_flush_dependency+0xf5/0x110\n...\n [ ]  cancel_delayed_work_sync+0x6e/0x80\n [ ]  amdgpu_gfx_off_ctrl+0xab/0x140 [amdgpu]\n [ ]  amdgpu_ring_alloc+0x40/0x50 [amdgpu]\n [ ]  amdgpu_ib_schedule+0xf4/0x810 [amdgpu]\n [ ]  ? drm_sched_run_job_work+0x22c/0x430 [gpu_sched]\n [ ]  amdgpu_job_run+0xaa/0x1f0 [amdgpu]\n [ ]  drm_sched_run_job_work+0x257/0x430 [gpu_sched]\n [ ]  process_one_work+0x217/0x720\n...\n [ ]  </TASK>\n\nThe intent of the verifcation done in check_flush_depedency is to ensure\nforward progress during memory reclaim, by flagging cases when either a\nmemory reclaim process, or a memory reclaim work item is flushed from a\ncontext not marked as memory reclaim safe.\n\nThis is correct when flushing, but when called from the\ncancel(_delayed)_work_sync() paths it is a false positive because work is\neither already running, or will not be running at all. Therefore\ncancelling it is safe and we can relax the warning criteria by letting the\nhelper know of the calling context.\n\nReferences: 746ae46c1113 (\"drm/sched: Mark scheduler work queues with WQ_MEM_RECLAIM\")","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57888","epss":0.00206,"percentile":0.10701,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57888","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57900","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57900","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ila: serialize calls to nf_register_net_hooks()  syzbot found a race in ila_add_mapping() [1]  commit 031ae72825ce (\"ila: call nf_unregister_net_hooks() sooner\") attempted to fix a similar issue.  Looking at the syzbot repro, we have concurrent ILA_CMD_ADD commands.  Add a mutex to make sure at most one thread is calling nf_register_net_hooks().  [1]  BUG: KASAN: slab-use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]  BUG: KASAN: slab-use-after-free in __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604 Read of size 4 at addr ffff888028f40008 by task dhcpcd/5501  CPU: 1 UID: 0 PID: 5501 Comm: dhcpcd Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Call Trace:  <IRQ>   __dump_stack lib/dump_stack.c:94 [inline]   dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120   print_address_description mm/kasan/report.c:378 [inline]   print_report+0xc3/0x620 mm/kasan/report.c:489   kasan_report+0xd9/0x110 mm/kasan/report.c:602   rht_key_hashfn include/linux/rhashtable.h:159 [inline]   __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604   rhashtable_lookup include/linux/rhashtable.h:646 [inline]   rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]   ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:127 [inline]   ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline]   ila_nf_input+0x1ee/0x620 net/ipv6/ila/ila_xlat.c:185   nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]   nf_hook_slow+0xbb/0x200 net/netfilter/core.c:626   nf_hook.constprop.0+0x42e/0x750 include/linux/netfilter.h:269   NF_HOOK include/linux/netfilter.h:312 [inline]   ipv6_rcv+0xa4/0x680 net/ipv6/ip6_input.c:309   __netif_receive_skb_one_core+0x12e/0x1e0 net/core/dev.c:5672   __netif_receive_skb+0x1d/0x160 net/core/dev.c:5785   process_backlog+0x443/0x15f0 net/core/dev.c:6117   __napi_poll.constprop.0+0xb7/0x550 net/core/dev.c:6883   napi_poll net/core/dev.c:6952 [inline]   net_rx_action+0xa94/0x1010 net/core/dev.c:7074   handle_softirqs+0x213/0x8f0 kernel/softirq.c:561   __do_softirq kernel/softirq.c:595 [inline]   invoke_softirq kernel/softirq.c:435 [inline]   __irq_exit_rcu+0x109/0x170 kernel/softirq.c:662   irq_exit_rcu+0x9/0x30 kernel/softirq.c:678   instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]   sysvec_apic_timer_interrupt+0xa4/0xc0 arch/x86/kernel/apic/apic.c:1049","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57900","epss":0.00261,"percentile":0.1784,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57900","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-57900","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.199665},"relatedVulnerabilities":[{"id":"CVE-2024-57900","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57900","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1638f430f8900f2375f5de45508fbe553997e190","https://git.kernel.org/stable/c/17e8fa894345e8d2c7a7642482267b275c3d4553","https://git.kernel.org/stable/c/260466b576bca0081a7d4acecc8e93687aa22d0e","https://git.kernel.org/stable/c/3d1b63cf468e446b9feaf4e4e73182b9cc82f460","https://git.kernel.org/stable/c/ad0677c37c14fa28913daea92d139644d7acf04e","https://git.kernel.org/stable/c/d3017895e393536b234cf80a83fc463c08a28137","https://git.kernel.org/stable/c/eba25e21dce7ec70e2b3f121b2f3a25a4ec43eca","https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nila: serialize calls to nf_register_net_hooks()\n\nsyzbot found a race in ila_add_mapping() [1]\n\ncommit 031ae72825ce (\"ila: call nf_unregister_net_hooks() sooner\")\nattempted to fix a similar issue.\n\nLooking at the syzbot repro, we have concurrent ILA_CMD_ADD commands.\n\nAdd a mutex to make sure at most one thread is calling nf_register_net_hooks().\n\n[1]\n BUG: KASAN: slab-use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n BUG: KASAN: slab-use-after-free in __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604\nRead of size 4 at addr ffff888028f40008 by task dhcpcd/5501\n\nCPU: 1 UID: 0 PID: 5501 Comm: dhcpcd Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nCall Trace:\n <IRQ>\n  __dump_stack lib/dump_stack.c:94 [inline]\n  dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n  print_address_description mm/kasan/report.c:378 [inline]\n  print_report+0xc3/0x620 mm/kasan/report.c:489\n  kasan_report+0xd9/0x110 mm/kasan/report.c:602\n  rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n  __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604\n  rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n  rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]\n  ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:127 [inline]\n  ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline]\n  ila_nf_input+0x1ee/0x620 net/ipv6/ila/ila_xlat.c:185\n  nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n  nf_hook_slow+0xbb/0x200 net/netfilter/core.c:626\n  nf_hook.constprop.0+0x42e/0x750 include/linux/netfilter.h:269\n  NF_HOOK include/linux/netfilter.h:312 [inline]\n  ipv6_rcv+0xa4/0x680 net/ipv6/ip6_input.c:309\n  __netif_receive_skb_one_core+0x12e/0x1e0 net/core/dev.c:5672\n  __netif_receive_skb+0x1d/0x160 net/core/dev.c:5785\n  process_backlog+0x443/0x15f0 net/core/dev.c:6117\n  __napi_poll.constprop.0+0xb7/0x550 net/core/dev.c:6883\n  napi_poll net/core/dev.c:6952 [inline]\n  net_rx_action+0xa94/0x1010 net/core/dev.c:7074\n  handle_softirqs+0x213/0x8f0 kernel/softirq.c:561\n  __do_softirq kernel/softirq.c:595 [inline]\n  invoke_softirq kernel/softirq.c:435 [inline]\n  __irq_exit_rcu+0x109/0x170 kernel/softirq.c:662\n  irq_exit_rcu+0x9/0x30 kernel/softirq.c:678\n  instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]\n  sysvec_apic_timer_interrupt+0xa4/0xc0 arch/x86/kernel/apic/apic.c:1049","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57900","epss":0.00261,"percentile":0.1784,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57900","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-57900","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57900","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57974","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57974","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  udp: Deal with race between UDP socket address change and rehash  If a UDP socket changes its local address while it's receiving datagrams, as a result of connect(), there is a period during which a lookup operation might fail to find it, after the address is changed but before the secondary hash (port and address) and the four-tuple hash (local and remote ports and addresses) are updated.  Secondary hash chains were introduced by commit 30fff9231fad (\"udp: bind() optimisation\") and, as a result, a rehash operation became needed to make a bound socket reachable again after a connect().  This operation was introduced by commit 719f835853a9 (\"udp: add rehash on connect()\") which isn't however a complete fix: the socket will be found once the rehashing completes, but not while it's pending.  This is noticeable with a socat(1) server in UDP4-LISTEN mode, and a client sending datagrams to it. After the server receives the first datagram (cf. _xioopen_ipdgram_listen()), it issues a connect() to the address of the sender, in order to set up a directed flow.  Now, if the client, running on a different CPU thread, happens to send a (subsequent) datagram while the server's socket changes its address, but is not rehashed yet, this will result in a failed lookup and a port unreachable error delivered to the client, as apparent from the following reproducer:    LEN=$(($(cat /proc/sys/net/core/wmem_default) / 4))   dd if=/dev/urandom bs=1 count=${LEN} of=tmp.in    while :; do   \ttaskset -c 1 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,trunc &   \tsleep 0.1 || sleep 1   \ttaskset -c 2 socat OPEN:tmp.in UDP4:localhost:1337,shut-null   \twait   done  where the client will eventually get ECONNREFUSED on a write() (typically the second or third one of a given iteration):    2024/11/13 21:28:23 socat[46901] E write(6, 0x556db2e3c000, 8192): Connection refused  This issue was first observed as a seldom failure in Podman's tests checking UDP functionality while using pasta(1) to connect the container's network namespace, which leads us to a reproducer with the lookup error resulting in an ICMP packet on a tap device:    LOCAL_ADDR=\"$(ip -j -4 addr show|jq -rM '.[] | .addr_info[0] | select(.scope == \"global\").local')\"    while :; do   \t./pasta --config-net -p pasta.pcap -u 1337 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,trunc &   \tsleep 0.2 || sleep 1   \tsocat OPEN:tmp.in UDP4:${LOCAL_ADDR}:1337,shut-null   \twait   \tcmp tmp.in tmp.out   done  Once this fails:    tmp.in tmp.out differ: char 8193, line 29  we can finally have a look at what's going on:    $ tshark -r pasta.pcap       1   0.000000           :: ? ff02::16     ICMPv6 110 Multicast Listener Report Message v2       2   0.168690 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192       3   0.168767 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192       4   0.168806 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192       5   0.168827 c6:47:05:8d:dc:04 ? Broadcast    ARP 42 Who has 88.198.0.161? Tell 88.198.0.164       6   0.168851 9a:55:9a:55:9a:55 ? c6:47:05:8d:dc:04 ARP 42 88.198.0.161 is at 9a:55:9a:55:9a:55       7   0.168875 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192       8   0.168896 88.198.0.164 ? 88.198.0.161 ICMP 590 Destination unreachable (Port unreachable)       9   0.168926 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192      10   0.168959 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192      11   0.168989 88.198.0.161 ? 88.198.0.164 UDP 4138 60260 ? 1337 Len=4096      12   0.169010 88.198.0.161 ? 88.198.0.164 UDP 42 60260 ? 1337 Len=0  On the third datagram received, the network namespace of the container initiates an ARP lookup to deliver the ICMP message.  In another variant of this reproducer, starting the client with:    strace -f pasta --config-net -u 1337 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,tru ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57974","epss":0.00145,"percentile":0.04062,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57974","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07032499999999998},"relatedVulnerabilities":[{"id":"CVE-2024-57974","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57974","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4f8344fce91c5766d368edb0ad80142eacd805c7","https://git.kernel.org/stable/c/a502ea6fa94b1f7be72a24bcf9e3f5f6b7e6e90c","https://git.kernel.org/stable/c/d65d3bf309b2649d27b24efd0d8784da2d81f2a6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nudp: Deal with race between UDP socket address change and rehash\n\nIf a UDP socket changes its local address while it's receiving\ndatagrams, as a result of connect(), there is a period during which\na lookup operation might fail to find it, after the address is changed\nbut before the secondary hash (port and address) and the four-tuple\nhash (local and remote ports and addresses) are updated.\n\nSecondary hash chains were introduced by commit 30fff9231fad (\"udp:\nbind() optimisation\") and, as a result, a rehash operation became\nneeded to make a bound socket reachable again after a connect().\n\nThis operation was introduced by commit 719f835853a9 (\"udp: add\nrehash on connect()\") which isn't however a complete fix: the\nsocket will be found once the rehashing completes, but not while\nit's pending.\n\nThis is noticeable with a socat(1) server in UDP4-LISTEN mode, and a\nclient sending datagrams to it. After the server receives the first\ndatagram (cf. _xioopen_ipdgram_listen()), it issues a connect() to\nthe address of the sender, in order to set up a directed flow.\n\nNow, if the client, running on a different CPU thread, happens to\nsend a (subsequent) datagram while the server's socket changes its\naddress, but is not rehashed yet, this will result in a failed\nlookup and a port unreachable error delivered to the client, as\napparent from the following reproducer:\n\n  LEN=$(($(cat /proc/sys/net/core/wmem_default) / 4))\n  dd if=/dev/urandom bs=1 count=${LEN} of=tmp.in\n\n  while :; do\n  \ttaskset -c 1 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,trunc &\n  \tsleep 0.1 || sleep 1\n  \ttaskset -c 2 socat OPEN:tmp.in UDP4:localhost:1337,shut-null\n  \twait\n  done\n\nwhere the client will eventually get ECONNREFUSED on a write()\n(typically the second or third one of a given iteration):\n\n  2024/11/13 21:28:23 socat[46901] E write(6, 0x556db2e3c000, 8192): Connection refused\n\nThis issue was first observed as a seldom failure in Podman's tests\nchecking UDP functionality while using pasta(1) to connect the\ncontainer's network namespace, which leads us to a reproducer with\nthe lookup error resulting in an ICMP packet on a tap device:\n\n  LOCAL_ADDR=\"$(ip -j -4 addr show|jq -rM '.[] | .addr_info[0] | select(.scope == \"global\").local')\"\n\n  while :; do\n  \t./pasta --config-net -p pasta.pcap -u 1337 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,trunc &\n  \tsleep 0.2 || sleep 1\n  \tsocat OPEN:tmp.in UDP4:${LOCAL_ADDR}:1337,shut-null\n  \twait\n  \tcmp tmp.in tmp.out\n  done\n\nOnce this fails:\n\n  tmp.in tmp.out differ: char 8193, line 29\n\nwe can finally have a look at what's going on:\n\n  $ tshark -r pasta.pcap\n      1   0.000000           :: ? ff02::16     ICMPv6 110 Multicast Listener Report Message v2\n      2   0.168690 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192\n      3   0.168767 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192\n      4   0.168806 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192\n      5   0.168827 c6:47:05:8d:dc:04 ? Broadcast    ARP 42 Who has 88.198.0.161? Tell 88.198.0.164\n      6   0.168851 9a:55:9a:55:9a:55 ? c6:47:05:8d:dc:04 ARP 42 88.198.0.161 is at 9a:55:9a:55:9a:55\n      7   0.168875 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192\n      8   0.168896 88.198.0.164 ? 88.198.0.161 ICMP 590 Destination unreachable (Port unreachable)\n      9   0.168926 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192\n     10   0.168959 88.198.0.161 ? 88.198.0.164 UDP 8234 60260 ? 1337 Len=8192\n     11   0.168989 88.198.0.161 ? 88.198.0.164 UDP 4138 60260 ? 1337 Len=4096\n     12   0.169010 88.198.0.161 ? 88.198.0.164 UDP 42 60260 ? 1337 Len=0\n\nOn the third datagram received, the network namespace of the container\ninitiates an ARP lookup to deliver the ICMP message.\n\nIn another variant of this reproducer, starting the client with:\n\n  strace -f pasta --config-net -u 1337 socat UDP4-LISTEN:1337,null-eof OPEN:tmp.out,create,tru\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57974","epss":0.00145,"percentile":0.04062,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57974","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57974","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57975","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57975","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: do proper folio cleanup when run_delalloc_nocow() failed  [BUG] With CONFIG_DEBUG_VM set, test case generic/476 has some chance to crash with the following VM_BUG_ON_FOLIO():    BTRFS error (device dm-3): cow_file_range failed, start 1146880 end 1253375 len 106496 ret -28   BTRFS error (device dm-3): run_delalloc_nocow failed, start 1146880 end 1253375 len 106496 ret -28   page: refcount:4 mapcount:0 mapping:00000000592787cc index:0x12 pfn:0x10664   aops:btrfs_aops [btrfs] ino:101 dentry name(?):\"f1774\"   flags: 0x2fffff80004028(uptodate|lru|private|node=0|zone=2|lastcpupid=0xfffff)   page dumped because: VM_BUG_ON_FOLIO(!folio_test_locked(folio))   ------------[ cut here ]------------   kernel BUG at mm/page-writeback.c:2992!   Internal error: Oops - BUG: 00000000f2000800 [#1] SMP   CPU: 2 UID: 0 PID: 3943513 Comm: kworker/u24:15 Tainted: G           OE      6.12.0-rc7-custom+ #87   Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE   Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022   Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs]   pc : folio_clear_dirty_for_io+0x128/0x258   lr : folio_clear_dirty_for_io+0x128/0x258   Call trace:    folio_clear_dirty_for_io+0x128/0x258    btrfs_folio_clamp_clear_dirty+0x80/0xd0 [btrfs]    __process_folios_contig+0x154/0x268 [btrfs]    extent_clear_unlock_delalloc+0x5c/0x80 [btrfs]    run_delalloc_nocow+0x5f8/0x760 [btrfs]    btrfs_run_delalloc_range+0xa8/0x220 [btrfs]    writepage_delalloc+0x230/0x4c8 [btrfs]    extent_writepage+0xb8/0x358 [btrfs]    extent_write_cache_pages+0x21c/0x4e8 [btrfs]    btrfs_writepages+0x94/0x150 [btrfs]    do_writepages+0x74/0x190    filemap_fdatawrite_wbc+0x88/0xc8    start_delalloc_inodes+0x178/0x3a8 [btrfs]    btrfs_start_delalloc_roots+0x174/0x280 [btrfs]    shrink_delalloc+0x114/0x280 [btrfs]    flush_space+0x250/0x2f8 [btrfs]    btrfs_async_reclaim_data_space+0x180/0x228 [btrfs]    process_one_work+0x164/0x408    worker_thread+0x25c/0x388    kthread+0x100/0x118    ret_from_fork+0x10/0x20   Code: 910a8021 a90363f7 a9046bf9 94012379 (d4210000)   ---[ end trace 0000000000000000 ]---  [CAUSE] The first two lines of extra debug messages show the problem is caused by the error handling of run_delalloc_nocow().  E.g. we have the following dirtied range (4K blocksize 4K page size):      0                 16K                  32K     |//////////////////////////////////////|     |  Pre-allocated  |  And the range [0, 16K) has a preallocated extent.  - Enter run_delalloc_nocow() for range [0, 16K)   Which found range [0, 16K) is preallocated, can do the proper NOCOW   write.  - Enter fallback_to_fow() for range [16K, 32K)   Since the range [16K, 32K) is not backed by preallocated extent, we   have to go COW.  - cow_file_range() failed for range [16K, 32K)   So cow_file_range() will do the clean up by clearing folio dirty,   unlock the folios.    Now the folios in range [16K, 32K) is unlocked.  - Enter extent_clear_unlock_delalloc() from run_delalloc_nocow()   Which is called with PAGE_START_WRITEBACK to start page writeback.   But folios can only be marked writeback when it's properly locked,   thus this triggered the VM_BUG_ON_FOLIO().  Furthermore there is another hidden but common bug that run_delalloc_nocow() is not clearing the folio dirty flags in its error handling path. This is the common bug shared between run_delalloc_nocow() and cow_file_range().  [FIX] - Clear folio dirty for range [@start, @cur_offset)   Introduce a helper, cleanup_dirty_folios(), which   will find and lock the folio in the range, clear the dirty flag and   start/end the writeback, with the extra handling for the   @locked_folio.  - Introduce a helper to clear folio dirty, start and end writeback  - Introduce a helper to record the last failed COW range end   This is to trace which range we should skip, to avoid double   unlocking.  - Skip the failed COW range for the e ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57975","epss":0.00211,"percentile":0.11377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57975","cwe":"CWE-459","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.110775},"relatedVulnerabilities":[{"id":"CVE-2024-57975","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57975","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2434533f1c963e7317c45880c98287e5bed98325","https://git.kernel.org/stable/c/5ae72abbf91eb172ce3a838a4dc34be3c9707296","https://git.kernel.org/stable/c/c2b47df81c8e20a8e8cd94f0d7df211137ae94ed"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do proper folio cleanup when run_delalloc_nocow() failed\n\n[BUG]\nWith CONFIG_DEBUG_VM set, test case generic/476 has some chance to crash\nwith the following VM_BUG_ON_FOLIO():\n\n  BTRFS error (device dm-3): cow_file_range failed, start 1146880 end 1253375 len 106496 ret -28\n  BTRFS error (device dm-3): run_delalloc_nocow failed, start 1146880 end 1253375 len 106496 ret -28\n  page: refcount:4 mapcount:0 mapping:00000000592787cc index:0x12 pfn:0x10664\n  aops:btrfs_aops [btrfs] ino:101 dentry name(?):\"f1774\"\n  flags: 0x2fffff80004028(uptodate|lru|private|node=0|zone=2|lastcpupid=0xfffff)\n  page dumped because: VM_BUG_ON_FOLIO(!folio_test_locked(folio))\n  ------------[ cut here ]------------\n  kernel BUG at mm/page-writeback.c:2992!\n  Internal error: Oops - BUG: 00000000f2000800 [#1] SMP\n  CPU: 2 UID: 0 PID: 3943513 Comm: kworker/u24:15 Tainted: G           OE      6.12.0-rc7-custom+ #87\n  Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\n  Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022\n  Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs]\n  pc : folio_clear_dirty_for_io+0x128/0x258\n  lr : folio_clear_dirty_for_io+0x128/0x258\n  Call trace:\n   folio_clear_dirty_for_io+0x128/0x258\n   btrfs_folio_clamp_clear_dirty+0x80/0xd0 [btrfs]\n   __process_folios_contig+0x154/0x268 [btrfs]\n   extent_clear_unlock_delalloc+0x5c/0x80 [btrfs]\n   run_delalloc_nocow+0x5f8/0x760 [btrfs]\n   btrfs_run_delalloc_range+0xa8/0x220 [btrfs]\n   writepage_delalloc+0x230/0x4c8 [btrfs]\n   extent_writepage+0xb8/0x358 [btrfs]\n   extent_write_cache_pages+0x21c/0x4e8 [btrfs]\n   btrfs_writepages+0x94/0x150 [btrfs]\n   do_writepages+0x74/0x190\n   filemap_fdatawrite_wbc+0x88/0xc8\n   start_delalloc_inodes+0x178/0x3a8 [btrfs]\n   btrfs_start_delalloc_roots+0x174/0x280 [btrfs]\n   shrink_delalloc+0x114/0x280 [btrfs]\n   flush_space+0x250/0x2f8 [btrfs]\n   btrfs_async_reclaim_data_space+0x180/0x228 [btrfs]\n   process_one_work+0x164/0x408\n   worker_thread+0x25c/0x388\n   kthread+0x100/0x118\n   ret_from_fork+0x10/0x20\n  Code: 910a8021 a90363f7 a9046bf9 94012379 (d4210000)\n  ---[ end trace 0000000000000000 ]---\n\n[CAUSE]\nThe first two lines of extra debug messages show the problem is caused\nby the error handling of run_delalloc_nocow().\n\nE.g. we have the following dirtied range (4K blocksize 4K page size):\n\n    0                 16K                  32K\n    |//////////////////////////////////////|\n    |  Pre-allocated  |\n\nAnd the range [0, 16K) has a preallocated extent.\n\n- Enter run_delalloc_nocow() for range [0, 16K)\n  Which found range [0, 16K) is preallocated, can do the proper NOCOW\n  write.\n\n- Enter fallback_to_fow() for range [16K, 32K)\n  Since the range [16K, 32K) is not backed by preallocated extent, we\n  have to go COW.\n\n- cow_file_range() failed for range [16K, 32K)\n  So cow_file_range() will do the clean up by clearing folio dirty,\n  unlock the folios.\n\n  Now the folios in range [16K, 32K) is unlocked.\n\n- Enter extent_clear_unlock_delalloc() from run_delalloc_nocow()\n  Which is called with PAGE_START_WRITEBACK to start page writeback.\n  But folios can only be marked writeback when it's properly locked,\n  thus this triggered the VM_BUG_ON_FOLIO().\n\nFurthermore there is another hidden but common bug that\nrun_delalloc_nocow() is not clearing the folio dirty flags in its error\nhandling path.\nThis is the common bug shared between run_delalloc_nocow() and\ncow_file_range().\n\n[FIX]\n- Clear folio dirty for range [@start, @cur_offset)\n  Introduce a helper, cleanup_dirty_folios(), which\n  will find and lock the folio in the range, clear the dirty flag and\n  start/end the writeback, with the extra handling for the\n  @locked_folio.\n\n- Introduce a helper to clear folio dirty, start and end writeback\n\n- Introduce a helper to record the last failed COW range end\n  This is to trace which range we should skip, to avoid double\n  unlocking.\n\n- Skip the failed COW range for the e\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57975","epss":0.00211,"percentile":0.11377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57975","cwe":"CWE-459","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57975","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57976","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57976","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: do proper folio cleanup when cow_file_range() failed  [BUG] When testing with COW fixup marked as BUG_ON() (this is involved with the new pin_user_pages*() change, which should not result new out-of-band dirty pages), I hit a crash triggered by the BUG_ON() from hitting COW fixup path.  This BUG_ON() happens just after a failed btrfs_run_delalloc_range():    BTRFS error (device dm-2): failed to run delalloc range, root 348 ino 405 folio 65536 submit_bitmap 6-15 start 90112 len 106496: -28   ------------[ cut here ]------------   kernel BUG at fs/btrfs/extent_io.c:1444!   Internal error: Oops - BUG: 00000000f2000800 [#1] SMP   CPU: 0 UID: 0 PID: 434621 Comm: kworker/u24:8 Tainted: G           OE      6.12.0-rc7-custom+ #86   Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022   Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs]   pc : extent_writepage_io+0x2d4/0x308 [btrfs]   lr : extent_writepage_io+0x2d4/0x308 [btrfs]   Call trace:    extent_writepage_io+0x2d4/0x308 [btrfs]    extent_writepage+0x218/0x330 [btrfs]    extent_write_cache_pages+0x1d4/0x4b0 [btrfs]    btrfs_writepages+0x94/0x150 [btrfs]    do_writepages+0x74/0x190    filemap_fdatawrite_wbc+0x88/0xc8    start_delalloc_inodes+0x180/0x3b0 [btrfs]    btrfs_start_delalloc_roots+0x174/0x280 [btrfs]    shrink_delalloc+0x114/0x280 [btrfs]    flush_space+0x250/0x2f8 [btrfs]    btrfs_async_reclaim_data_space+0x180/0x228 [btrfs]    process_one_work+0x164/0x408    worker_thread+0x25c/0x388    kthread+0x100/0x118    ret_from_fork+0x10/0x20   Code: aa1403e1 9402f3ef aa1403e0 9402f36f (d4210000)   ---[ end trace 0000000000000000 ]---  [CAUSE] That failure is mostly from cow_file_range(), where we can hit -ENOSPC.  Although the -ENOSPC is already a bug related to our space reservation code, let's just focus on the error handling.  For example, we have the following dirty range [0, 64K) of an inode, with 4K sector size and 4K page size:     0        16K        32K       48K       64K    |///////////////////////////////////////|    |#######################################|  Where |///| means page are still dirty, and |###| means the extent io tree has EXTENT_DELALLOC flag.  - Enter extent_writepage() for page 0  - Enter btrfs_run_delalloc_range() for range [0, 64K)  - Enter cow_file_range() for range [0, 64K)  - Function btrfs_reserve_extent() only reserved one 16K extent   So we created extent map and ordered extent for range [0, 16K)     0        16K        32K       48K       64K    |////////|//////////////////////////////|    |<- OE ->|##############################|     And range [0, 16K) has its delalloc flag cleared.    But since we haven't yet submit any bio, involved 4 pages are still    dirty.  - Function btrfs_reserve_extent() returns with -ENOSPC   Now we have to run error cleanup, which will clear all   EXTENT_DELALLOC* flags and clear the dirty flags for the remaining   ranges:     0        16K        32K       48K       64K    |////////|                              |    |        |                              |    Note that range [0, 16K) still has its pages dirty.  - Some time later, writeback is triggered again for the range [0, 16K)   since the page range still has dirty flags.  - btrfs_run_delalloc_range() will do nothing because there is no   EXTENT_DELALLOC flag.  - extent_writepage_io() finds page 0 has no ordered flag   Which falls into the COW fixup path, triggering the BUG_ON().  Unfortunately this error handling bug dates back to the introduction of btrfs.  Thankfully with the abuse of COW fixup, at least it won't crash the kernel.  [FIX] Instead of immediately unlocking the extent and folios, we keep the extent and folios locked until either erroring out or the whole delalloc range finished.  When the whole delalloc range finished without error, we just unlock the whole range with PAGE_SET_ORDERED (and PAGE_UNLOCK for !keep_locked cases) ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57976","epss":0.0022,"percentile":0.12451,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57976","cwe":"CWE-459","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11550000000000002},"relatedVulnerabilities":[{"id":"CVE-2024-57976","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57976","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/06f364284794f149d2abc167c11d556cf20c954b","https://git.kernel.org/stable/c/10b3772292bf1be45604ba83fd9650eb94382e78","https://git.kernel.org/stable/c/692cf71173bb41395c855acbbbe197d3aedfa5d4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do proper folio cleanup when cow_file_range() failed\n\n[BUG]\nWhen testing with COW fixup marked as BUG_ON() (this is involved with the\nnew pin_user_pages*() change, which should not result new out-of-band\ndirty pages), I hit a crash triggered by the BUG_ON() from hitting COW\nfixup path.\n\nThis BUG_ON() happens just after a failed btrfs_run_delalloc_range():\n\n  BTRFS error (device dm-2): failed to run delalloc range, root 348 ino 405 folio 65536 submit_bitmap 6-15 start 90112 len 106496: -28\n  ------------[ cut here ]------------\n  kernel BUG at fs/btrfs/extent_io.c:1444!\n  Internal error: Oops - BUG: 00000000f2000800 [#1] SMP\n  CPU: 0 UID: 0 PID: 434621 Comm: kworker/u24:8 Tainted: G           OE      6.12.0-rc7-custom+ #86\n  Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022\n  Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs]\n  pc : extent_writepage_io+0x2d4/0x308 [btrfs]\n  lr : extent_writepage_io+0x2d4/0x308 [btrfs]\n  Call trace:\n   extent_writepage_io+0x2d4/0x308 [btrfs]\n   extent_writepage+0x218/0x330 [btrfs]\n   extent_write_cache_pages+0x1d4/0x4b0 [btrfs]\n   btrfs_writepages+0x94/0x150 [btrfs]\n   do_writepages+0x74/0x190\n   filemap_fdatawrite_wbc+0x88/0xc8\n   start_delalloc_inodes+0x180/0x3b0 [btrfs]\n   btrfs_start_delalloc_roots+0x174/0x280 [btrfs]\n   shrink_delalloc+0x114/0x280 [btrfs]\n   flush_space+0x250/0x2f8 [btrfs]\n   btrfs_async_reclaim_data_space+0x180/0x228 [btrfs]\n   process_one_work+0x164/0x408\n   worker_thread+0x25c/0x388\n   kthread+0x100/0x118\n   ret_from_fork+0x10/0x20\n  Code: aa1403e1 9402f3ef aa1403e0 9402f36f (d4210000)\n  ---[ end trace 0000000000000000 ]---\n\n[CAUSE]\nThat failure is mostly from cow_file_range(), where we can hit -ENOSPC.\n\nAlthough the -ENOSPC is already a bug related to our space reservation\ncode, let's just focus on the error handling.\n\nFor example, we have the following dirty range [0, 64K) of an inode,\nwith 4K sector size and 4K page size:\n\n   0        16K        32K       48K       64K\n   |///////////////////////////////////////|\n   |#######################################|\n\nWhere |///| means page are still dirty, and |###| means the extent io\ntree has EXTENT_DELALLOC flag.\n\n- Enter extent_writepage() for page 0\n\n- Enter btrfs_run_delalloc_range() for range [0, 64K)\n\n- Enter cow_file_range() for range [0, 64K)\n\n- Function btrfs_reserve_extent() only reserved one 16K extent\n  So we created extent map and ordered extent for range [0, 16K)\n\n   0        16K        32K       48K       64K\n   |////////|//////////////////////////////|\n   |<- OE ->|##############################|\n\n   And range [0, 16K) has its delalloc flag cleared.\n   But since we haven't yet submit any bio, involved 4 pages are still\n   dirty.\n\n- Function btrfs_reserve_extent() returns with -ENOSPC\n  Now we have to run error cleanup, which will clear all\n  EXTENT_DELALLOC* flags and clear the dirty flags for the remaining\n  ranges:\n\n   0        16K        32K       48K       64K\n   |////////|                              |\n   |        |                              |\n\n  Note that range [0, 16K) still has its pages dirty.\n\n- Some time later, writeback is triggered again for the range [0, 16K)\n  since the page range still has dirty flags.\n\n- btrfs_run_delalloc_range() will do nothing because there is no\n  EXTENT_DELALLOC flag.\n\n- extent_writepage_io() finds page 0 has no ordered flag\n  Which falls into the COW fixup path, triggering the BUG_ON().\n\nUnfortunately this error handling bug dates back to the introduction of\nbtrfs.  Thankfully with the abuse of COW fixup, at least it won't crash\nthe kernel.\n\n[FIX]\nInstead of immediately unlocking the extent and folios, we keep the extent\nand folios locked until either erroring out or the whole delalloc range\nfinished.\n\nWhen the whole delalloc range finished without error, we just unlock the\nwhole range with PAGE_SET_ORDERED (and PAGE_UNLOCK for !keep_locked\ncases)\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57976","epss":0.0022,"percentile":0.12451,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57976","cwe":"CWE-459","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57976","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57982","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57982","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: state: fix out-of-bounds read during lookup  lookup and resize can run in parallel.  The xfrm_state_hash_generation seqlock ensures a retry, but the hash functions can observe a hmask value that is too large for the new hlist array.  rehash does:   rcu_assign_pointer(net->xfrm.state_bydst, ndst) [..]   net->xfrm.state_hmask = nhashmask;  While state lookup does:   h = xfrm_dst_hash(net, daddr, saddr, tmpl->reqid, encap_family);   hlist_for_each_entry_rcu(x, net->xfrm.state_bydst + h, bydst) {  This is only safe in case the update to state_bydst is larger than net->xfrm.xfrm_state_hmask (or if the lookup function gets serialized via state spinlock again).  Fix this by prefetching state_hmask and the associated pointers. The xfrm_state_hash_generation seqlock retry will ensure that the pointer and the hmask will be consistent.  The existing helpers, like xfrm_dst_hash(), are now unsafe for RCU side, add lockdep assertions to document that they are only safe for insert side.  xfrm_state_lookup_byaddr() uses the spinlock rather than RCU. AFAICS this is an oversight from back when state lookup was converted to RCU, this lock should be replaced with RCU in a future patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57982","epss":0.00245,"percentile":0.15679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57982","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-57982","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17884999999999998},"relatedVulnerabilities":[{"id":"CVE-2024-57982","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57982","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/a16871c7832ea6435abb6e0b58289ae7dcb7e4fc","https://git.kernel.org/stable/c/b86dc510308d7a8955f3f47a4fea4bef887653e4","https://git.kernel.org/stable/c/dd4c2a174994238d55ab54da2545543d36f4e0d0","https://git.kernel.org/stable/c/e952837f3ddb0ff726d5b582aa1aad9aa38d024d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: state: fix out-of-bounds read during lookup\n\nlookup and resize can run in parallel.\n\nThe xfrm_state_hash_generation seqlock ensures a retry, but the hash\nfunctions can observe a hmask value that is too large for the new hlist\narray.\n\nrehash does:\n  rcu_assign_pointer(net->xfrm.state_bydst, ndst) [..]\n  net->xfrm.state_hmask = nhashmask;\n\nWhile state lookup does:\n  h = xfrm_dst_hash(net, daddr, saddr, tmpl->reqid, encap_family);\n  hlist_for_each_entry_rcu(x, net->xfrm.state_bydst + h, bydst) {\n\nThis is only safe in case the update to state_bydst is larger than\nnet->xfrm.xfrm_state_hmask (or if the lookup function gets\nserialized via state spinlock again).\n\nFix this by prefetching state_hmask and the associated pointers.\nThe xfrm_state_hash_generation seqlock retry will ensure that the pointer\nand the hmask will be consistent.\n\nThe existing helpers, like xfrm_dst_hash(), are now unsafe for RCU side,\nadd lockdep assertions to document that they are only safe for insert\nside.\n\nxfrm_state_lookup_byaddr() uses the spinlock rather than RCU.\nAFAICS this is an oversight from back when state lookup was converted to\nRCU, this lock should be replaced with RCU in a future patch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57982","epss":0.00245,"percentile":0.15679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57982","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-57982","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57982","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57984","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57984","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition  In dw_i3c_common_probe, &master->hj_work is bound with dw_i3c_hj_work. And dw_i3c_master_irq_handler can call dw_i3c_master_irq_handle_ibis function to start the work.  If we remove the module which will call dw_i3c_common_remove to make cleanup, it will free master->base through i3c_master_unregister while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows:  CPU0                                      CPU1                                       | dw_i3c_hj_work dw_i3c_common_remove                 | i3c_master_unregister(&master->base) | device_unregister(&master->dev)      | device_release                       | //free master->base                  |                                      | i3c_master_do_daa(&master->base)                                      | //use master->base  Fix it by ensuring that the work is canceled before proceeding with the cleanup in dw_i3c_common_remove.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57984","epss":0.00228,"percentile":0.13492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57984","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17442},"relatedVulnerabilities":[{"id":"CVE-2024-57984","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57984","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/60d2fb033a999bb644f8e8606ff4a1b82de36c6f","https://git.kernel.org/stable/c/9b0063098fcde17cd2894f2c96459b23388507ca","https://git.kernel.org/stable/c/b75439c945b94dd8a2b645355bdb56f948052601","https://git.kernel.org/stable/c/fc84dd3c909a372c0d130f5f84c404717c17eed8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition\n\nIn dw_i3c_common_probe, &master->hj_work is bound with\ndw_i3c_hj_work. And dw_i3c_master_irq_handler can call\ndw_i3c_master_irq_handle_ibis function to start the work.\n\nIf we remove the module which will call dw_i3c_common_remove to\nmake cleanup, it will free master->base through i3c_master_unregister\nwhile the work mentioned above will be used. The sequence of operations\nthat may lead to a UAF bug is as follows:\n\nCPU0                                      CPU1\n\n                                     | dw_i3c_hj_work\ndw_i3c_common_remove                 |\ni3c_master_unregister(&master->base) |\ndevice_unregister(&master->dev)      |\ndevice_release                       |\n//free master->base                  |\n                                     | i3c_master_do_daa(&master->base)\n                                     | //use master->base\n\nFix it by ensuring that the work is canceled before proceeding with\nthe cleanup in dw_i3c_common_remove.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57984","epss":0.00228,"percentile":0.13492,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-57984","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57984","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-57999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-57999","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW  Power Hypervisor can possibily allocate MMIO window intersecting with Dynamic DMA Window (DDW) range, which is over 32-bit addressing.  These MMIO pages needs to be marked as reserved so that IOMMU doesn't map DMA buffers in this range.  The current code is not marking these pages correctly which is resulting in LPAR to OOPS while booting. The stack is at below  BUG: Unable to handle kernel data access on read at 0xc00800005cd40000 Faulting instruction address: 0xc00000000005cdac Oops: Kernel access of bad area, sig: 11 [#1] LE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries Modules linked in: af_packet rfkill ibmveth(X) lpfc(+) nvmet_fc nvmet nvme_keyring crct10dif_vpmsum nvme_fc nvme_fabrics nvme_core be2net(+) nvme_auth rtc_generic nfsd auth_rpcgss nfs_acl lockd grace sunrpc fuse configfs ip_tables x_tables xfs libcrc32c dm_service_time ibmvfc(X) scsi_transport_fc vmx_crypto gf128mul crc32c_vpmsum dm_mirror dm_region_hash dm_log dm_multipath dm_mod sd_mod scsi_dh_emc scsi_dh_rdac scsi_dh_alua t10_pi crc64_rocksoft_generic crc64_rocksoft sg crc64 scsi_mod Supported: Yes, External CPU: 8 PID: 241 Comm: kworker/8:1 Kdump: loaded Not tainted 6.4.0-150600.23.14-default #1 SLE15-SP6 b44ee71c81261b9e4bab5e0cde1f2ed891d5359b Hardware name: IBM,9080-M9S POWER9 (raw) 0x4e2103 0xf000005 of:IBM,FW950.B0 (VH950_149) hv:phyp pSeries Workqueue: events work_for_cpu_fn NIP:  c00000000005cdac LR: c00000000005e830 CTR: 0000000000000000 REGS: c00001400c9ff770 TRAP: 0300   Not tainted  (6.4.0-150600.23.14-default) MSR:  800000000280b033 <SF,VEC,VSX,EE,FP,ME,IR,DR,RI,LE>  CR: 24228448  XER: 00000001 CFAR: c00000000005cdd4 DAR: c00800005cd40000 DSISR: 40000000 IRQMASK: 0 GPR00: c00000000005e830 c00001400c9ffa10 c000000001987d00 c00001400c4fe800 GPR04: 0000080000000000 0000000000000001 0000000004000000 0000000000800000 GPR08: 0000000004000000 0000000000000001 c00800005cd40000 ffffffffffffffff GPR12: 0000000084228882 c00000000a4c4f00 0000000000000010 0000080000000000 GPR16: c00001400c4fe800 0000000004000000 0800000000000000 c00000006088b800 GPR20: c00001401a7be980 c00001400eff3800 c000000002a2da68 000000000000002b GPR24: c0000000026793a8 c000000002679368 000000000000002a c0000000026793c8 GPR28: 000008007effffff 0000080000000000 0000000000800000 c00001400c4fe800 NIP [c00000000005cdac] iommu_table_reserve_pages+0xac/0x100 LR [c00000000005e830] iommu_init_table+0x80/0x1e0 Call Trace: [c00001400c9ffa10] [c00000000005e810] iommu_init_table+0x60/0x1e0 (unreliable) [c00001400c9ffa90] [c00000000010356c] iommu_bypass_supported_pSeriesLP+0x9cc/0xe40 [c00001400c9ffc30] [c00000000005c300] dma_iommu_dma_supported+0xf0/0x230 [c00001400c9ffcb0] [c00000000024b0c4] dma_supported+0x44/0x90 [c00001400c9ffcd0] [c00000000024b14c] dma_set_mask+0x3c/0x80 [c00001400c9ffd00] [c0080000555b715c] be_probe+0xc4/0xb90 [be2net] [c00001400c9ffdc0] [c000000000986f3c] local_pci_probe+0x6c/0x110 [c00001400c9ffe40] [c000000000188f28] work_for_cpu_fn+0x38/0x60 [c00001400c9ffe70] [c00000000018e454] process_one_work+0x314/0x620 [c00001400c9fff10] [c00000000018f280] worker_thread+0x2b0/0x620 [c00001400c9fff90] [c00000000019bb18] kthread+0x148/0x150 [c00001400c9fffe0] [c00000000000ded8] start_kernel_thread+0x14/0x18  There are 2 issues in the code  1. The index is \"int\" while the address is \"unsigned long\". This results in    negative value when setting the bitmap.  2. The DMA offset is page shifted but the MMIO range is used as-is (64-bit    address). MMIO address needs to be page shifted as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57999","epss":0.00227,"percentile":0.13332,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11917499999999999},"relatedVulnerabilities":[{"id":"CVE-2024-57999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-57999","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7043d58ecd1381674f5b2c894deb6986a1a4896b","https://git.kernel.org/stable/c/8f70caad82e9c088ed93b4fea48d941ab6441886","https://git.kernel.org/stable/c/d8cc20a8cceb3b5e8ad2e11365e3100ba36a27e9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW\n\nPower Hypervisor can possibily allocate MMIO window intersecting with\nDynamic DMA Window (DDW) range, which is over 32-bit addressing.\n\nThese MMIO pages needs to be marked as reserved so that IOMMU doesn't map\nDMA buffers in this range.\n\nThe current code is not marking these pages correctly which is resulting\nin LPAR to OOPS while booting. The stack is at below\n\nBUG: Unable to handle kernel data access on read at 0xc00800005cd40000\nFaulting instruction address: 0xc00000000005cdac\nOops: Kernel access of bad area, sig: 11 [#1]\nLE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries\nModules linked in: af_packet rfkill ibmveth(X) lpfc(+) nvmet_fc nvmet nvme_keyring crct10dif_vpmsum nvme_fc nvme_fabrics nvme_core be2net(+) nvme_auth rtc_generic nfsd auth_rpcgss nfs_acl lockd grace sunrpc fuse configfs ip_tables x_tables xfs libcrc32c dm_service_time ibmvfc(X) scsi_transport_fc vmx_crypto gf128mul crc32c_vpmsum dm_mirror dm_region_hash dm_log dm_multipath dm_mod sd_mod scsi_dh_emc scsi_dh_rdac scsi_dh_alua t10_pi crc64_rocksoft_generic crc64_rocksoft sg crc64 scsi_mod\nSupported: Yes, External\nCPU: 8 PID: 241 Comm: kworker/8:1 Kdump: loaded Not tainted 6.4.0-150600.23.14-default #1 SLE15-SP6 b44ee71c81261b9e4bab5e0cde1f2ed891d5359b\nHardware name: IBM,9080-M9S POWER9 (raw) 0x4e2103 0xf000005 of:IBM,FW950.B0 (VH950_149) hv:phyp pSeries\nWorkqueue: events work_for_cpu_fn\nNIP:  c00000000005cdac LR: c00000000005e830 CTR: 0000000000000000\nREGS: c00001400c9ff770 TRAP: 0300   Not tainted  (6.4.0-150600.23.14-default)\nMSR:  800000000280b033 <SF,VEC,VSX,EE,FP,ME,IR,DR,RI,LE>  CR: 24228448  XER: 00000001\nCFAR: c00000000005cdd4 DAR: c00800005cd40000 DSISR: 40000000 IRQMASK: 0\nGPR00: c00000000005e830 c00001400c9ffa10 c000000001987d00 c00001400c4fe800\nGPR04: 0000080000000000 0000000000000001 0000000004000000 0000000000800000\nGPR08: 0000000004000000 0000000000000001 c00800005cd40000 ffffffffffffffff\nGPR12: 0000000084228882 c00000000a4c4f00 0000000000000010 0000080000000000\nGPR16: c00001400c4fe800 0000000004000000 0800000000000000 c00000006088b800\nGPR20: c00001401a7be980 c00001400eff3800 c000000002a2da68 000000000000002b\nGPR24: c0000000026793a8 c000000002679368 000000000000002a c0000000026793c8\nGPR28: 000008007effffff 0000080000000000 0000000000800000 c00001400c4fe800\nNIP [c00000000005cdac] iommu_table_reserve_pages+0xac/0x100\nLR [c00000000005e830] iommu_init_table+0x80/0x1e0\nCall Trace:\n[c00001400c9ffa10] [c00000000005e810] iommu_init_table+0x60/0x1e0 (unreliable)\n[c00001400c9ffa90] [c00000000010356c] iommu_bypass_supported_pSeriesLP+0x9cc/0xe40\n[c00001400c9ffc30] [c00000000005c300] dma_iommu_dma_supported+0xf0/0x230\n[c00001400c9ffcb0] [c00000000024b0c4] dma_supported+0x44/0x90\n[c00001400c9ffcd0] [c00000000024b14c] dma_set_mask+0x3c/0x80\n[c00001400c9ffd00] [c0080000555b715c] be_probe+0xc4/0xb90 [be2net]\n[c00001400c9ffdc0] [c000000000986f3c] local_pci_probe+0x6c/0x110\n[c00001400c9ffe40] [c000000000188f28] work_for_cpu_fn+0x38/0x60\n[c00001400c9ffe70] [c00000000018e454] process_one_work+0x314/0x620\n[c00001400c9fff10] [c00000000018f280] worker_thread+0x2b0/0x620\n[c00001400c9fff90] [c00000000019bb18] kthread+0x148/0x150\n[c00001400c9fffe0] [c00000000000ded8] start_kernel_thread+0x14/0x18\n\nThere are 2 issues in the code\n\n1. The index is \"int\" while the address is \"unsigned long\". This results in\n   negative value when setting the bitmap.\n\n2. The DMA offset is page shifted but the MMIO range is used as-is (64-bit\n   address). MMIO address needs to be page shifted as well.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-57999","epss":0.00227,"percentile":0.13332,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-57999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58006","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58006","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()  In commit 4284c88fff0e (\"PCI: designware-ep: Allow pci_epc_set_bar() update inbound map address\") set_bar() was modified to support dynamically changing the backing physical address of a BAR that was already configured.  This means that set_bar() can be called twice, without ever calling clear_bar() (as calling clear_bar() would clear the BAR's PCI address assigned by the host).  This can only be done if the new BAR size/flags does not differ from the existing BAR configuration. Add these missing checks.  If we allow set_bar() to set e.g. a new BAR size that differs from the existing BAR size, the new address translation range will be smaller than the BAR size already determined by the host, which would mean that a read past the new BAR size would pass the iATU untranslated, which could allow the host to read memory not belonging to the new struct pci_epf_bar.  While at it, add comments which clarifies the support for dynamically changing the physical address of a BAR. (Which was also missing.)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58006","epss":0.0023,"percentile":0.13828,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12075},"relatedVulnerabilities":[{"id":"CVE-2024-58006","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58006","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3229c15d6267de8e704b4085df8a82a5af2d63eb","https://git.kernel.org/stable/c/3708acbd5f169ebafe1faa519cb28adc56295546","https://git.kernel.org/stable/c/b5cacfd067060c75088363ed3e19779078be2755"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()\n\nIn commit 4284c88fff0e (\"PCI: designware-ep: Allow pci_epc_set_bar() update\ninbound map address\") set_bar() was modified to support dynamically\nchanging the backing physical address of a BAR that was already configured.\n\nThis means that set_bar() can be called twice, without ever calling\nclear_bar() (as calling clear_bar() would clear the BAR's PCI address\nassigned by the host).\n\nThis can only be done if the new BAR size/flags does not differ from the\nexisting BAR configuration. Add these missing checks.\n\nIf we allow set_bar() to set e.g. a new BAR size that differs from the\nexisting BAR size, the new address translation range will be smaller than\nthe BAR size already determined by the host, which would mean that a read\npast the new BAR size would pass the iATU untranslated, which could allow\nthe host to read memory not belonging to the new struct pci_epf_bar.\n\nWhile at it, add comments which clarifies the support for dynamically\nchanging the physical address of a BAR. (Which was also missing.)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"exploitabilityScore":2.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58006","epss":0.0023,"percentile":0.13828,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58006","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58012","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58012","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during params  Each cpu DAI should associate with a widget. However, the topology might not create the right number of DAI widgets for aggregated amps. And it will cause NULL pointer deference. Check that the DAI widget associated with the CPU DAI is valid to prevent NULL pointer deference due to missing DAI widgets in topologies with aggregated amps.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58012","epss":0.0021,"percentile":0.11219,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-58012","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-58012","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11025},"relatedVulnerabilities":[{"id":"CVE-2024-58012","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58012","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/569922b82ca660f8b24e705f6cf674e6b1f99cc7","https://git.kernel.org/stable/c/789a2fbf0900982788408d3b0034e0e3f914fb3b","https://git.kernel.org/stable/c/e012a77e4d7632cf615ba9625b1600ed8985c3b5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during params\n\nEach cpu DAI should associate with a widget. However, the topology might\nnot create the right number of DAI widgets for aggregated amps. And it\nwill cause NULL pointer deference.\nCheck that the DAI widget associated with the CPU DAI is valid to prevent\nNULL pointer deference due to missing DAI widgets in topologies with\naggregated amps.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58012","epss":0.0021,"percentile":0.11219,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-58012","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-58012","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58012","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58053","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58053","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix handling of received connection abort  Fix the handling of a connection abort that we've received.  Though the abort is at the connection level, it needs propagating to the calls on that connection.  Whilst the propagation bit is performed, the calls aren't then woken up to go and process their termination, and as no further input is forthcoming, they just hang.  Also add some tracing for the logging of connection aborts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58053","epss":0.00454,"percentile":0.38113,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23834999999999998},"relatedVulnerabilities":[{"id":"CVE-2024-58053","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58053","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0e56ebde245e4799ce74d38419426f2a80d39950","https://git.kernel.org/stable/c/5842ce7b120c65624052a8da04460d35b26caac0","https://git.kernel.org/stable/c/96d1d927c4d03ee9dcee7640bca70b74e63504fc","https://git.kernel.org/stable/c/9c6702260557c0183d8417c79a37777a3d3e58e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix handling of received connection abort\n\nFix the handling of a connection abort that we've received.  Though the\nabort is at the connection level, it needs propagating to the calls on that\nconnection.  Whilst the propagation bit is performed, the calls aren't then\nwoken up to go and process their termination, and as no further input is\nforthcoming, they just hang.\n\nAlso add some tracing for the logging of connection aborts.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58053","epss":0.00454,"percentile":0.38113,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58053","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58089","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58089","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix double accounting race when btrfs_run_delalloc_range() failed  [BUG] When running btrfs with block size (4K) smaller than page size (64K, aarch64), there is a very high chance to crash the kernel at generic/750, with the following messages: (before the call traces, there are 3 extra debug messages added)    BTRFS warning (device dm-3): read-write for sector size 4096 with page size 65536 is experimental   BTRFS info (device dm-3): checking UUID tree   hrtimer: interrupt took 5451385 ns   BTRFS error (device dm-3): cow_file_range failed, root=4957 inode=257 start=1605632 len=69632: -28   BTRFS error (device dm-3): run_delalloc_nocow failed, root=4957 inode=257 start=1605632 len=69632: -28   BTRFS error (device dm-3): failed to run delalloc range, root=4957 ino=257 folio=1572864 submit_bitmap=8-15 start=1605632 len=69632: -28   ------------[ cut here ]------------   WARNING: CPU: 2 PID: 3020984 at ordered-data.c:360 can_finish_ordered_extent+0x370/0x3b8 [btrfs]   CPU: 2 UID: 0 PID: 3020984 Comm: kworker/u24:1 Tainted: G           OE      6.13.0-rc1-custom+ #89   Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE   Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022   Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs]   pc : can_finish_ordered_extent+0x370/0x3b8 [btrfs]   lr : can_finish_ordered_extent+0x1ec/0x3b8 [btrfs]   Call trace:    can_finish_ordered_extent+0x370/0x3b8 [btrfs] (P)    can_finish_ordered_extent+0x1ec/0x3b8 [btrfs] (L)    btrfs_mark_ordered_io_finished+0x130/0x2b8 [btrfs]    extent_writepage+0x10c/0x3b8 [btrfs]    extent_write_cache_pages+0x21c/0x4e8 [btrfs]    btrfs_writepages+0x94/0x160 [btrfs]    do_writepages+0x74/0x190    filemap_fdatawrite_wbc+0x74/0xa0    start_delalloc_inodes+0x17c/0x3b0 [btrfs]    btrfs_start_delalloc_roots+0x17c/0x288 [btrfs]    shrink_delalloc+0x11c/0x280 [btrfs]    flush_space+0x288/0x328 [btrfs]    btrfs_async_reclaim_data_space+0x180/0x228 [btrfs]    process_one_work+0x228/0x680    worker_thread+0x1bc/0x360    kthread+0x100/0x118    ret_from_fork+0x10/0x20   ---[ end trace 0000000000000000 ]---   BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1605632 OE len=16384 to_dec=16384 left=0   BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1622016 OE len=12288 to_dec=12288 left=0   Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008   BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1634304 OE len=8192 to_dec=4096 left=0   CPU: 1 UID: 0 PID: 3286940 Comm: kworker/u24:3 Tainted: G        W  OE      6.13.0-rc1-custom+ #89   Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022   Workqueue:  btrfs_work_helper [btrfs] (btrfs-endio-write)   pstate: 404000c5 (nZcv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)   pc : process_one_work+0x110/0x680   lr : worker_thread+0x1bc/0x360   Call trace:    process_one_work+0x110/0x680 (P)    worker_thread+0x1bc/0x360 (L)    worker_thread+0x1bc/0x360    kthread+0x100/0x118    ret_from_fork+0x10/0x20   Code: f84086a1 f9000fe1 53041c21 b9003361 (f9400661)   ---[ end trace 0000000000000000 ]---   Kernel panic - not syncing: Oops: Fatal exception   SMP: stopping secondary CPUs   SMP: failed to stop secondary CPUs 2-3   Dumping ftrace buffer:      (ftrace buffer empty)   Kernel Offset: 0x275bb9540000 from 0xffff800080000000   PHYS_OFFSET: 0xffff8fbba0000000   CPU features: 0x100,00000070,00801250,8201720b  [CAUSE] The above warning is triggered immediately after the delalloc range failure, this happens in the following sequence:  - Range [1568K, 1636K) is dirty     1536K  1568K     1600K    1636K  1664K    |      |/////////|////////|      |    Where 1536K, 1600K and 1664K are page boundaries (64K page size)  - Enter extent_writepage() for page 1536K  - Enter run_delalloc_nocow() with locke ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58089","epss":0.00224,"percentile":0.12981,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-58089","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-58089","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1176},"relatedVulnerabilities":[{"id":"CVE-2024-58089","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58089","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0283ee1912c8e243c931f4ee5b3672e954fe0384","https://git.kernel.org/stable/c/21333148b5c9e52f41fafcedec3810b56a5e0e40","https://git.kernel.org/stable/c/72dad8e377afa50435940adfb697e070d3556670"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix double accounting race when btrfs_run_delalloc_range() failed\n\n[BUG]\nWhen running btrfs with block size (4K) smaller than page size (64K,\naarch64), there is a very high chance to crash the kernel at\ngeneric/750, with the following messages:\n(before the call traces, there are 3 extra debug messages added)\n\n  BTRFS warning (device dm-3): read-write for sector size 4096 with page size 65536 is experimental\n  BTRFS info (device dm-3): checking UUID tree\n  hrtimer: interrupt took 5451385 ns\n  BTRFS error (device dm-3): cow_file_range failed, root=4957 inode=257 start=1605632 len=69632: -28\n  BTRFS error (device dm-3): run_delalloc_nocow failed, root=4957 inode=257 start=1605632 len=69632: -28\n  BTRFS error (device dm-3): failed to run delalloc range, root=4957 ino=257 folio=1572864 submit_bitmap=8-15 start=1605632 len=69632: -28\n  ------------[ cut here ]------------\n  WARNING: CPU: 2 PID: 3020984 at ordered-data.c:360 can_finish_ordered_extent+0x370/0x3b8 [btrfs]\n  CPU: 2 UID: 0 PID: 3020984 Comm: kworker/u24:1 Tainted: G           OE      6.13.0-rc1-custom+ #89\n  Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\n  Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022\n  Workqueue: events_unbound btrfs_async_reclaim_data_space [btrfs]\n  pc : can_finish_ordered_extent+0x370/0x3b8 [btrfs]\n  lr : can_finish_ordered_extent+0x1ec/0x3b8 [btrfs]\n  Call trace:\n   can_finish_ordered_extent+0x370/0x3b8 [btrfs] (P)\n   can_finish_ordered_extent+0x1ec/0x3b8 [btrfs] (L)\n   btrfs_mark_ordered_io_finished+0x130/0x2b8 [btrfs]\n   extent_writepage+0x10c/0x3b8 [btrfs]\n   extent_write_cache_pages+0x21c/0x4e8 [btrfs]\n   btrfs_writepages+0x94/0x160 [btrfs]\n   do_writepages+0x74/0x190\n   filemap_fdatawrite_wbc+0x74/0xa0\n   start_delalloc_inodes+0x17c/0x3b0 [btrfs]\n   btrfs_start_delalloc_roots+0x17c/0x288 [btrfs]\n   shrink_delalloc+0x11c/0x280 [btrfs]\n   flush_space+0x288/0x328 [btrfs]\n   btrfs_async_reclaim_data_space+0x180/0x228 [btrfs]\n   process_one_work+0x228/0x680\n   worker_thread+0x1bc/0x360\n   kthread+0x100/0x118\n   ret_from_fork+0x10/0x20\n  ---[ end trace 0000000000000000 ]---\n  BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1605632 OE len=16384 to_dec=16384 left=0\n  BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1622016 OE len=12288 to_dec=12288 left=0\n  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008\n  BTRFS critical (device dm-3): bad ordered extent accounting, root=4957 ino=257 OE offset=1634304 OE len=8192 to_dec=4096 left=0\n  CPU: 1 UID: 0 PID: 3286940 Comm: kworker/u24:3 Tainted: G        W  OE      6.13.0-rc1-custom+ #89\n  Hardware name: QEMU KVM Virtual Machine, BIOS unknown 2/2/2022\n  Workqueue:  btrfs_work_helper [btrfs] (btrfs-endio-write)\n  pstate: 404000c5 (nZcv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n  pc : process_one_work+0x110/0x680\n  lr : worker_thread+0x1bc/0x360\n  Call trace:\n   process_one_work+0x110/0x680 (P)\n   worker_thread+0x1bc/0x360 (L)\n   worker_thread+0x1bc/0x360\n   kthread+0x100/0x118\n   ret_from_fork+0x10/0x20\n  Code: f84086a1 f9000fe1 53041c21 b9003361 (f9400661)\n  ---[ end trace 0000000000000000 ]---\n  Kernel panic - not syncing: Oops: Fatal exception\n  SMP: stopping secondary CPUs\n  SMP: failed to stop secondary CPUs 2-3\n  Dumping ftrace buffer:\n     (ftrace buffer empty)\n  Kernel Offset: 0x275bb9540000 from 0xffff800080000000\n  PHYS_OFFSET: 0xffff8fbba0000000\n  CPU features: 0x100,00000070,00801250,8201720b\n\n[CAUSE]\nThe above warning is triggered immediately after the delalloc range\nfailure, this happens in the following sequence:\n\n- Range [1568K, 1636K) is dirty\n\n   1536K  1568K     1600K    1636K  1664K\n   |      |/////////|////////|      |\n\n  Where 1536K, 1600K and 1664K are page boundaries (64K page size)\n\n- Enter extent_writepage() for page 1536K\n\n- Enter run_delalloc_nocow() with locke\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58089","epss":0.00224,"percentile":0.12981,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-58089","cwe":"CWE-770","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-58089","cwe":"CWE-770","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58089","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58094","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58094","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  jfs: add check read-only before truncation in jfs_truncate_nolock()  Added a check for \"read-only\" mode in the `jfs_truncate_nolock` function to avoid errors related to writing to a read-only filesystem.  Call stack:  block_write_begin() {   jfs_write_failed() {     jfs_truncate() {       jfs_truncate_nolock() {         txEnd() {           ...           log = JFS_SBI(tblk->sb)->log;           // (log == NULL)  If the `isReadOnly(ip)` condition is triggered in `jfs_truncate_nolock`, the function execution will stop, and no further data modification will occur. Instead, the `xtTruncate` function will be called with the \"COMMIT_WMAP\" flag, preventing modifications in \"read-only\" mode.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58094","epss":0.00218,"percentile":0.12166,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11445000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-58094","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58094","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1fee021d6cf1d41b3f6e3fd028939be8f5d5c5db","https://git.kernel.org/stable/c/41da1715cd24e177678f93ee27f737b095fc838b","https://git.kernel.org/stable/c/77038187890ea82d237b05c8a9c4e08a38b1efcb","https://git.kernel.org/stable/c/b5799dd77054c1ec49b0088b006c9908e256843b","https://git.kernel.org/stable/c/b57a8983916fc2cf54fd8de3afc733c6b3d1c0e5","https://git.kernel.org/stable/c/b98506e61e1bb6764c6711198cfab826df8ca952","https://git.kernel.org/stable/c/f605bc3e162f5c6faa9bd3602ce496053d06a4bb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add check read-only before truncation in jfs_truncate_nolock()\n\nAdded a check for \"read-only\" mode in the `jfs_truncate_nolock`\nfunction to avoid errors related to writing to a read-only\nfilesystem.\n\nCall stack:\n\nblock_write_begin() {\n  jfs_write_failed() {\n    jfs_truncate() {\n      jfs_truncate_nolock() {\n        txEnd() {\n          ...\n          log = JFS_SBI(tblk->sb)->log;\n          // (log == NULL)\n\nIf the `isReadOnly(ip)` condition is triggered in\n`jfs_truncate_nolock`, the function execution will stop, and no\nfurther data modification will occur. Instead, the `xtTruncate`\nfunction will be called with the \"COMMIT_WMAP\" flag, preventing\nmodifications in \"read-only\" mode.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58094","epss":0.00218,"percentile":0.12166,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58094","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58095","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58095","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  jfs: add check read-only before txBeginAnon() call  Added a read-only check before calling `txBeginAnon` in `extAlloc` and `extRecord`. This prevents modification attempts on a read-only mounted filesystem, avoiding potential errors or crashes.  Call trace:  txBeginAnon+0xac/0x154  extAlloc+0xe8/0xdec fs/jfs/jfs_extent.c:78  jfs_get_block+0x340/0xb98 fs/jfs/inode.c:248  __block_write_begin_int+0x580/0x166c fs/buffer.c:2128  __block_write_begin fs/buffer.c:2177 [inline]  block_write_begin+0x98/0x11c fs/buffer.c:2236  jfs_write_begin+0x44/0x88 fs/jfs/inode.c:299","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58095","epss":0.00196,"percentile":0.09397,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10289999999999999},"relatedVulnerabilities":[{"id":"CVE-2024-58095","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58095","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0176e69743ecc02961f2ae1ea42439cd2bf9ed58","https://git.kernel.org/stable/c/15469c408af2d7a52fb186a92f2f091b0f13b1fb","https://git.kernel.org/stable/c/469bd67fc338e77d7585e4f20d4212afd44fefdc","https://git.kernel.org/stable/c/47a99881ecc50ff2bf4e7a6c3058fe1704073df9","https://git.kernel.org/stable/c/939dba7a6404d4ac88e2539cb21ac659f5757fd9","https://git.kernel.org/stable/c/93f11ab37f1c657f4265228ba3c2ff66bbefa24d","https://git.kernel.org/stable/c/97ac32b08442f5327867ad7d70d6ac6ebaa2a41a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add check read-only before txBeginAnon() call\n\nAdded a read-only check before calling `txBeginAnon` in `extAlloc`\nand `extRecord`. This prevents modification attempts on a read-only\nmounted filesystem, avoiding potential errors or crashes.\n\nCall trace:\n txBeginAnon+0xac/0x154\n extAlloc+0xe8/0xdec fs/jfs/jfs_extent.c:78\n jfs_get_block+0x340/0xb98 fs/jfs/inode.c:248\n __block_write_begin_int+0x580/0x166c fs/buffer.c:2128\n __block_write_begin fs/buffer.c:2177 [inline]\n block_write_begin+0x98/0x11c fs/buffer.c:2236\n jfs_write_begin+0x44/0x88 fs/jfs/inode.c:299","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58095","epss":0.00196,"percentile":0.09397,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58095","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58096","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58096","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode  ath11k_hal_srng_* should be used with srng->lock to protect srng data.  For ath11k_dp_rx_mon_dest_process() and ath11k_dp_full_mon_process_rx(), they use ath11k_hal_srng_* for many times but never call srng->lock.  So when running (full) monitor mode, warning will occur: RIP: 0010:ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k] Call Trace:  ? ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]  ath11k_dp_rx_process_mon_status+0xc45/0x1190 [ath11k]  ? idr_alloc_u32+0x97/0xd0  ath11k_dp_rx_process_mon_rings+0x32a/0x550 [ath11k]  ath11k_dp_service_srng+0x289/0x5a0 [ath11k]  ath11k_pcic_ext_grp_napi_poll+0x30/0xd0 [ath11k]  __napi_poll+0x30/0x1f0  net_rx_action+0x198/0x320  __do_softirq+0xdd/0x319  So add srng->lock for them to avoid such warnings.  Inorder to fetch the srng->lock, should change srng's definition from 'void' to 'struct hal_srng'. And initialize them elsewhere to prevent one line of code from being too long. This is consistent with other ring process functions, such as ath11k_dp_process_rx().  Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30 Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58096","epss":0.00241,"percentile":0.15233,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.126525},"relatedVulnerabilities":[{"id":"CVE-2024-58096","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58096","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1d2178918efc928e11bed9631469ef79ff0a862a","https://git.kernel.org/stable/c/27ca8004ba93a0665faa6d477eaeb551e03de6c8","https://git.kernel.org/stable/c/63b7af49496d0e32f7a748b6af3361ec138b1bd3","https://git.kernel.org/stable/c/b85758e76b6452740fc2a08ced6759af64c0d59a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode\n\nath11k_hal_srng_* should be used with srng->lock to protect srng data.\n\nFor ath11k_dp_rx_mon_dest_process() and ath11k_dp_full_mon_process_rx(),\nthey use ath11k_hal_srng_* for many times but never call srng->lock.\n\nSo when running (full) monitor mode, warning will occur:\nRIP: 0010:ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]\nCall Trace:\n ? ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]\n ath11k_dp_rx_process_mon_status+0xc45/0x1190 [ath11k]\n ? idr_alloc_u32+0x97/0xd0\n ath11k_dp_rx_process_mon_rings+0x32a/0x550 [ath11k]\n ath11k_dp_service_srng+0x289/0x5a0 [ath11k]\n ath11k_pcic_ext_grp_napi_poll+0x30/0xd0 [ath11k]\n __napi_poll+0x30/0x1f0\n net_rx_action+0x198/0x320\n __do_softirq+0xdd/0x319\n\nSo add srng->lock for them to avoid such warnings.\n\nInorder to fetch the srng->lock, should change srng's definition from\n'void' to 'struct hal_srng'. And initialize them elsewhere to prevent\none line of code from being too long. This is consistent with other ring\nprocess functions, such as ath11k_dp_process_rx().\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58096","epss":0.00241,"percentile":0.15233,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58096","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58097","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58097","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: fix RCU stall while reaping monitor destination ring  While processing the monitor destination ring, MSDUs are reaped from the link descriptor based on the corresponding buf_id.  However, sometimes the driver cannot obtain a valid buffer corresponding to the buf_id received from the hardware. This causes an infinite loop in the destination processing, resulting in a kernel crash.  kernel log: ath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309 ath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed ath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309 ath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed  Fix this by skipping the problematic buf_id and reaping the next entry, replacing the break with the next MSDU processing.  Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30 Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58097","epss":0.00197,"percentile":0.09537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-58097","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-58097","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.103425},"relatedVulnerabilities":[{"id":"CVE-2024-58097","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58097","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/16c6c35c03ea73054a1f6d3302a4ce4a331b427d","https://git.kernel.org/stable/c/8db5de0cf02fccf4c759aa58edbe65659daf607c","https://git.kernel.org/stable/c/9f1a002f0171d27f3554e529f3c70df438f05dfe","https://git.kernel.org/stable/c/b4991fc41745645f8050506f5a8578bd11e6b378"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix RCU stall while reaping monitor destination ring\n\nWhile processing the monitor destination ring, MSDUs are reaped from the\nlink descriptor based on the corresponding buf_id.\n\nHowever, sometimes the driver cannot obtain a valid buffer corresponding\nto the buf_id received from the hardware. This causes an infinite loop\nin the destination processing, resulting in a kernel crash.\n\nkernel log:\nath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309\nath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed\nath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309\nath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed\n\nFix this by skipping the problematic buf_id and reaping the next entry,\nreplacing the break with the next MSDU processing.\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58097","epss":0.00197,"percentile":0.09537,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-58097","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2024-58097","cwe":"CWE-835","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58097","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58098","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58098","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: track changes_pkt_data property for global functions  When processing calls to certain helpers, verifier invalidates all packet pointers in a current state. For example, consider the following program:      __attribute__((__noinline__))     long skb_pull_data(struct __sk_buff *sk, __u32 len)     {         return bpf_skb_pull_data(sk, len);     }      SEC(\"tc\")     int test_invalidate_checks(struct __sk_buff *sk)     {         int *p = (void *)(long)sk->data;         if ((void *)(p + 1) > (void *)(long)sk->data_end) return TCX_DROP;         skb_pull_data(sk, 0);         *p = 42;         return TCX_PASS;     }  After a call to bpf_skb_pull_data() the pointer 'p' can't be used safely. See function filter.c:bpf_helper_changes_pkt_data() for a list of such helpers.  At the moment verifier invalidates packet pointers when processing helper function calls, and does not traverse global sub-programs when processing calls to global sub-programs. This means that calls to helpers done from global sub-programs do not invalidate pointers in the caller state. E.g. the program above is unsafe, but is not rejected by verifier.  This commit fixes the omission by computing field bpf_subprog_info->changes_pkt_data for each sub-program before main verification pass. changes_pkt_data should be set if: - subprogram calls helper for which bpf_helper_changes_pkt_data   returns true; - subprogram calls a global function,   for which bpf_subprog_info->changes_pkt_data should be set.  The verifier.c:check_cfg() pass is modified to compute this information. The commit relies on depth first instruction traversal done by check_cfg() and absence of recursive function calls: - check_cfg() would eventually visit every call to subprogram S in a   state when S is fully explored; - when S is fully explored:   - every direct helper call within S is explored     (and thus changes_pkt_data is set if needed);   - every call to subprogram S1 called by S was visited with S1 fully     explored (and thus S inherits changes_pkt_data from S1).  The downside of such approach is that dead code elimination is not taken into account: if a helper call inside global function is dead because of current configuration, verifier would conservatively assume that the call occurs for the purpose of the changes_pkt_data computation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58098","epss":0.00186,"percentile":0.08372,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09765},"relatedVulnerabilities":[{"id":"CVE-2024-58098","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58098","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1d572c60488b52882b719ed273767ee3b280413d","https://git.kernel.org/stable/c/51081a3f25c742da5a659d7fc6fd77ebfdd555be","https://git.kernel.org/stable/c/79751e9227a5910c0e5a2c7186877d91821d957d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: track changes_pkt_data property for global functions\n\nWhen processing calls to certain helpers, verifier invalidates all\npacket pointers in a current state. For example, consider the\nfollowing program:\n\n    __attribute__((__noinline__))\n    long skb_pull_data(struct __sk_buff *sk, __u32 len)\n    {\n        return bpf_skb_pull_data(sk, len);\n    }\n\n    SEC(\"tc\")\n    int test_invalidate_checks(struct __sk_buff *sk)\n    {\n        int *p = (void *)(long)sk->data;\n        if ((void *)(p + 1) > (void *)(long)sk->data_end) return TCX_DROP;\n        skb_pull_data(sk, 0);\n        *p = 42;\n        return TCX_PASS;\n    }\n\nAfter a call to bpf_skb_pull_data() the pointer 'p' can't be used\nsafely. See function filter.c:bpf_helper_changes_pkt_data() for a list\nof such helpers.\n\nAt the moment verifier invalidates packet pointers when processing\nhelper function calls, and does not traverse global sub-programs when\nprocessing calls to global sub-programs. This means that calls to\nhelpers done from global sub-programs do not invalidate pointers in\nthe caller state. E.g. the program above is unsafe, but is not\nrejected by verifier.\n\nThis commit fixes the omission by computing field\nbpf_subprog_info->changes_pkt_data for each sub-program before main\nverification pass.\nchanges_pkt_data should be set if:\n- subprogram calls helper for which bpf_helper_changes_pkt_data\n  returns true;\n- subprogram calls a global function,\n  for which bpf_subprog_info->changes_pkt_data should be set.\n\nThe verifier.c:check_cfg() pass is modified to compute this\ninformation. The commit relies on depth first instruction traversal\ndone by check_cfg() and absence of recursive function calls:\n- check_cfg() would eventually visit every call to subprogram S in a\n  state when S is fully explored;\n- when S is fully explored:\n  - every direct helper call within S is explored\n    (and thus changes_pkt_data is set if needed);\n  - every call to subprogram S1 called by S was visited with S1 fully\n    explored (and thus S inherits changes_pkt_data from S1).\n\nThe downside of such approach is that dead code elimination is not\ntaken into account: if a helper call inside global function is dead\nbecause of current configuration, verifier would conservatively assume\nthat the call occurs for the purpose of the changes_pkt_data\ncomputation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58098","epss":0.00186,"percentile":0.08372,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58098","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58100","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58100","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: check changes_pkt_data property for extension programs  When processing calls to global sub-programs, verifier decides whether to invalidate all packet pointers in current state depending on the changes_pkt_data property of the global sub-program.  Because of this, an extension program replacing a global sub-program must be compatible with changes_pkt_data property of the sub-program being replaced.  This commit: - adds changes_pkt_data flag to struct bpf_prog_aux:   - this flag is set in check_cfg() for main sub-program;   - in jit_subprogs() for other sub-programs; - modifies bpf_check_attach_btf_id() to check changes_pkt_data flag; - moves call to check_attach_btf_id() after the call to check_cfg(),   because it needs changes_pkt_data flag to be set:      bpf_check:       ...                             ...     - check_attach_btf_id             resolve_pseudo_ldimm64       resolve_pseudo_ldimm64   -->    bpf_prog_is_offloaded       bpf_prog_is_offloaded           check_cfg       check_cfg                     + check_attach_btf_id       ...                             ...  The following fields are set by check_attach_btf_id(): - env->ops - prog->aux->attach_btf_trace - prog->aux->attach_func_name - prog->aux->attach_func_proto - prog->aux->dst_trampoline - prog->aux->mod - prog->aux->saved_dst_attach_type - prog->aux->saved_dst_prog_type - prog->expected_attach_type  Neither of these fields are used by resolve_pseudo_ldimm64() or bpf_prog_offload_verifier_prep() (for netronome and netdevsim drivers), so the reordering is safe.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58100","epss":0.00188,"percentile":0.08533,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09870000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-58100","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58100","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3846e2bea565ee1c5195dcc625fda9868fb0e3b3","https://git.kernel.org/stable/c/7197fc4acdf238ec8ad06de5a8235df0c1f9c7d7","https://git.kernel.org/stable/c/81f6d0530ba031b5f038a091619bf2ff29568852"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: check changes_pkt_data property for extension programs\n\nWhen processing calls to global sub-programs, verifier decides whether\nto invalidate all packet pointers in current state depending on the\nchanges_pkt_data property of the global sub-program.\n\nBecause of this, an extension program replacing a global sub-program\nmust be compatible with changes_pkt_data property of the sub-program\nbeing replaced.\n\nThis commit:\n- adds changes_pkt_data flag to struct bpf_prog_aux:\n  - this flag is set in check_cfg() for main sub-program;\n  - in jit_subprogs() for other sub-programs;\n- modifies bpf_check_attach_btf_id() to check changes_pkt_data flag;\n- moves call to check_attach_btf_id() after the call to check_cfg(),\n  because it needs changes_pkt_data flag to be set:\n\n    bpf_check:\n      ...                             ...\n    - check_attach_btf_id             resolve_pseudo_ldimm64\n      resolve_pseudo_ldimm64   -->    bpf_prog_is_offloaded\n      bpf_prog_is_offloaded           check_cfg\n      check_cfg                     + check_attach_btf_id\n      ...                             ...\n\nThe following fields are set by check_attach_btf_id():\n- env->ops\n- prog->aux->attach_btf_trace\n- prog->aux->attach_func_name\n- prog->aux->attach_func_proto\n- prog->aux->dst_trampoline\n- prog->aux->mod\n- prog->aux->saved_dst_attach_type\n- prog->aux->saved_dst_prog_type\n- prog->expected_attach_type\n\nNeither of these fields are used by resolve_pseudo_ldimm64() or\nbpf_prog_offload_verifier_prep() (for netronome and netdevsim\ndrivers), so the reordering is safe.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58100","epss":0.00188,"percentile":0.08533,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58100","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58237","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58237","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: consider that tail calls invalidate packet pointers  Tail-called programs could execute any of the helpers that invalidate packet pointers. Hence, conservatively assume that each tail call invalidates packet pointers.  Making the change in bpf_helper_changes_pkt_data() automatically makes use of check_cfg() logic that computes 'changes_pkt_data' effect for global sub-programs, such that the following program could be rejected:      int tail_call(struct __sk_buff *sk)     {     \tbpf_tail_call_static(sk, &jmp_table, 0);     \treturn 0;     }      SEC(\"tc\")     int not_safe(struct __sk_buff *sk)     {     \tint *p = (void *)(long)sk->data;     \t... make p valid ...     \ttail_call(sk);     \t*p = 42; /* this is unsafe */     \t...     }  The tc_bpf2bpf.c:subprog_tc() needs change: mark it as a function that can invalidate packet pointers. Otherwise, it can't be freplaced with tailcall_freplace.c:entry_freplace() that does a tail call.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58237","epss":0.00188,"percentile":0.08533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-58237","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09870000000000001},"relatedVulnerabilities":[{"id":"CVE-2024-58237","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58237","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1a4607ffba35bf2a630aab299e34dd3f6e658d70","https://git.kernel.org/stable/c/1c2244437f9ad3dd91215f920401a14f2542dbfc","https://git.kernel.org/stable/c/f1692ee23dcaaddc24ba407b269707ee5df1301f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: consider that tail calls invalidate packet pointers\n\nTail-called programs could execute any of the helpers that invalidate\npacket pointers. Hence, conservatively assume that each tail call\ninvalidates packet pointers.\n\nMaking the change in bpf_helper_changes_pkt_data() automatically makes\nuse of check_cfg() logic that computes 'changes_pkt_data' effect for\nglobal sub-programs, such that the following program could be\nrejected:\n\n    int tail_call(struct __sk_buff *sk)\n    {\n    \tbpf_tail_call_static(sk, &jmp_table, 0);\n    \treturn 0;\n    }\n\n    SEC(\"tc\")\n    int not_safe(struct __sk_buff *sk)\n    {\n    \tint *p = (void *)(long)sk->data;\n    \t... make p valid ...\n    \ttail_call(sk);\n    \t*p = 42; /* this is unsafe */\n    \t...\n    }\n\nThe tc_bpf2bpf.c:subprog_tc() needs change: mark it as a function that\ncan invalidate packet pointers. Otherwise, it can't be freplaced with\ntailcall_freplace.c:entry_freplace() that does a tail call.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58237","epss":0.00188,"percentile":0.08533,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2024-58237","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58237","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2024-58241","dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-58241","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_core: Disable works on hci_unregister_dev  This make use of disable_work_* on hci_unregister_dev since the hci_dev is about to be freed new submissions are not disarable.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58241","epss":0.00134,"percentile":0.03263,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07035},"relatedVulnerabilities":[{"id":"CVE-2024-58241","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-58241","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/989fa5171f005ecf63440057218d8aeb1795287d","https://git.kernel.org/stable/c/cfdb13a54e05eb98d9940cb6d1a13e7f994d811f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Disable works on hci_unregister_dev\n\nThis make use of disable_work_* on hci_unregister_dev since the hci_dev is\nabout to be freed new submissions are not disarable.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-58241","epss":0.00134,"percentile":0.03263,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2024-58241","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21634","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21634","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cgroup/cpuset: remove kernfs active break  A warning was found:  WARNING: CPU: 10 PID: 3486953 at fs/kernfs/file.c:828 CPU: 10 PID: 3486953 Comm: rmdir Kdump: loaded Tainted: G RIP: 0010:kernfs_should_drain_open_files+0x1a1/0x1b0 RSP: 0018:ffff8881107ef9e0 EFLAGS: 00010202 RAX: 0000000080000002 RBX: ffff888154738c00 RCX: dffffc0000000000 RDX: 0000000000000007 RSI: 0000000000000004 RDI: ffff888154738c04 RBP: ffff888154738c04 R08: ffffffffaf27fa15 R09: ffffed102a8e7180 R10: ffff888154738c07 R11: 0000000000000000 R12: ffff888154738c08 R13: ffff888750f8c000 R14: ffff888750f8c0e8 R15: ffff888154738ca0 FS:  00007f84cd0be740(0000) GS:ffff8887ddc00000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000555f9fbe00c8 CR3: 0000000153eec001 CR4: 0000000000370ee0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace:  kernfs_drain+0x15e/0x2f0  __kernfs_remove+0x165/0x300  kernfs_remove_by_name_ns+0x7b/0xc0  cgroup_rm_file+0x154/0x1c0  cgroup_addrm_files+0x1c2/0x1f0  css_clear_dir+0x77/0x110  kill_css+0x4c/0x1b0  cgroup_destroy_locked+0x194/0x380  cgroup_rmdir+0x2a/0x140  It can be explained by: rmdir \t\t\t\techo 1 > cpuset.cpus \t\t\t\tkernfs_fop_write_iter // active=0 cgroup_rm_file kernfs_remove_by_name_ns\tkernfs_get_active // active=1 __kernfs_remove\t\t\t\t\t  // active=0x80000002 kernfs_drain\t\t\tcpuset_write_resmask wait_event //waiting (active == 0x80000001) \t\t\t\tkernfs_break_active_protection \t\t\t\t// active = 0x80000001 // continue \t\t\t\tkernfs_unbreak_active_protection \t\t\t\t// active = 0x80000002 ... kernfs_should_drain_open_files // warning occurs \t\t\t\tkernfs_put_active  This warning is caused by 'kernfs_break_active_protection' when it is writing to cpuset.cpus, and the cgroup is removed concurrently.  The commit 3a5a6d0c2b03 (\"cpuset: don't nest cgroup_mutex inside get_online_cpus()\") made cpuset_hotplug_workfn asynchronous, This change involves calling flush_work(), which can create a multiple processes circular locking dependency that involve cgroup_mutex, potentially leading to a deadlock. To avoid deadlock. the commit 76bb5ab8f6e3 (\"cpuset: break kernfs active protection in cpuset_write_resmask()\") added 'kernfs_break_active_protection' in the cpuset_write_resmask. This could lead to this warning.  After the commit 2125c0034c5d (\"cgroup/cpuset: Make cpuset hotplug processing synchronous\"), the cpuset_write_resmask no longer needs to wait the hotplug to finish, which means that concurrent hotplug and cpuset operations are no longer possible. Therefore, the deadlock doesn't exist anymore and it does not have to 'break active protection' now. To fix this warning, just remove kernfs_break_active_protection operation in the 'cpuset_write_resmask'.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21634","epss":0.00142,"percentile":0.03796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21634","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21634","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07455},"relatedVulnerabilities":[{"id":"CVE-2025-21634","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21634","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/11cb1d643a74665a4e14749414f48f82cbc15c64","https://git.kernel.org/stable/c/3cb97a927fffe443e1e7e8eddbfebfdb062e86ed"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: remove kernfs active break\n\nA warning was found:\n\nWARNING: CPU: 10 PID: 3486953 at fs/kernfs/file.c:828\nCPU: 10 PID: 3486953 Comm: rmdir Kdump: loaded Tainted: G\nRIP: 0010:kernfs_should_drain_open_files+0x1a1/0x1b0\nRSP: 0018:ffff8881107ef9e0 EFLAGS: 00010202\nRAX: 0000000080000002 RBX: ffff888154738c00 RCX: dffffc0000000000\nRDX: 0000000000000007 RSI: 0000000000000004 RDI: ffff888154738c04\nRBP: ffff888154738c04 R08: ffffffffaf27fa15 R09: ffffed102a8e7180\nR10: ffff888154738c07 R11: 0000000000000000 R12: ffff888154738c08\nR13: ffff888750f8c000 R14: ffff888750f8c0e8 R15: ffff888154738ca0\nFS:  00007f84cd0be740(0000) GS:ffff8887ddc00000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000555f9fbe00c8 CR3: 0000000153eec001 CR4: 0000000000370ee0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n kernfs_drain+0x15e/0x2f0\n __kernfs_remove+0x165/0x300\n kernfs_remove_by_name_ns+0x7b/0xc0\n cgroup_rm_file+0x154/0x1c0\n cgroup_addrm_files+0x1c2/0x1f0\n css_clear_dir+0x77/0x110\n kill_css+0x4c/0x1b0\n cgroup_destroy_locked+0x194/0x380\n cgroup_rmdir+0x2a/0x140\n\nIt can be explained by:\nrmdir \t\t\t\techo 1 > cpuset.cpus\n\t\t\t\tkernfs_fop_write_iter // active=0\ncgroup_rm_file\nkernfs_remove_by_name_ns\tkernfs_get_active // active=1\n__kernfs_remove\t\t\t\t\t  // active=0x80000002\nkernfs_drain\t\t\tcpuset_write_resmask\nwait_event\n//waiting (active == 0x80000001)\n\t\t\t\tkernfs_break_active_protection\n\t\t\t\t// active = 0x80000001\n// continue\n\t\t\t\tkernfs_unbreak_active_protection\n\t\t\t\t// active = 0x80000002\n...\nkernfs_should_drain_open_files\n// warning occurs\n\t\t\t\tkernfs_put_active\n\nThis warning is caused by 'kernfs_break_active_protection' when it is\nwriting to cpuset.cpus, and the cgroup is removed concurrently.\n\nThe commit 3a5a6d0c2b03 (\"cpuset: don't nest cgroup_mutex inside\nget_online_cpus()\") made cpuset_hotplug_workfn asynchronous, This change\ninvolves calling flush_work(), which can create a multiple processes\ncircular locking dependency that involve cgroup_mutex, potentially leading\nto a deadlock. To avoid deadlock. the commit 76bb5ab8f6e3 (\"cpuset: break\nkernfs active protection in cpuset_write_resmask()\") added\n'kernfs_break_active_protection' in the cpuset_write_resmask. This could\nlead to this warning.\n\nAfter the commit 2125c0034c5d (\"cgroup/cpuset: Make cpuset hotplug\nprocessing synchronous\"), the cpuset_write_resmask no longer needs to\nwait the hotplug to finish, which means that concurrent hotplug and cpuset\noperations are no longer possible. Therefore, the deadlock doesn't exist\nanymore and it does not have to 'break active protection' now. To fix this\nwarning, just remove kernfs_break_active_protection operation in the\n'cpuset_write_resmask'.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21634","epss":0.00142,"percentile":0.03796,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21634","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21634","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21634","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21635","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21635","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy  As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recommended for different reasons:  - Inconsistency: getting info from the reader's/writer's netns vs only   from the opener's netns.  - current->nsproxy can be NULL in some cases, resulting in an 'Oops'   (null-ptr-deref), e.g. when the current task is exiting, as spotted by   syzbot [1] using acct(2).  The per-netns structure can be obtained from the table->data using container_of(), then the 'net' one can be retrieved from the listen socket (if available).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21635","epss":0.00183,"percentile":0.08,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21635","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21635","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09607500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-21635","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21635","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7f5611cbc4871c7fb1ad36c2e5a9edad63dca95c","https://git.kernel.org/stable/c/de8d6de0ee27be4b2b1e5b06f04aeacbabbba492"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's/writer's netns vs only\n  from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n  (null-ptr-deref), e.g. when the current task is exiting, as spotted by\n  syzbot [1] using acct(2).\n\nThe per-netns structure can be obtained from the table->data using\ncontainer_of(), then the 'net' one can be retrieved from the listen\nsocket (if available).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21635","epss":0.00183,"percentile":0.08,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21635","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21635","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21635","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21649","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: hns3: fix kernel crash when 1588 is sent on HIP08 devices  Currently, HIP08 devices does not register the ptp devices, so the hdev->ptp is NULL. But the tx process would still try to set hardware time stamp info with SKBTX_HW_TSTAMP flag and cause a kernel crash.  [  128.087798] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000018 ... [  128.280251] pc : hclge_ptp_set_tx_info+0x2c/0x140 [hclge] [  128.286600] lr : hclge_ptp_set_tx_info+0x20/0x140 [hclge] [  128.292938] sp : ffff800059b93140 [  128.297200] x29: ffff800059b93140 x28: 0000000000003280 [  128.303455] x27: ffff800020d48280 x26: ffff0cb9dc814080 [  128.309715] x25: ffff0cb9cde93fa0 x24: 0000000000000001 [  128.315969] x23: 0000000000000000 x22: 0000000000000194 [  128.322219] x21: ffff0cd94f986000 x20: 0000000000000000 [  128.328462] x19: ffff0cb9d2a166c0 x18: 0000000000000000 [  128.334698] x17: 0000000000000000 x16: ffffcf1fc523ed24 [  128.340934] x15: 0000ffffd530a518 x14: 0000000000000000 [  128.347162] x13: ffff0cd6bdb31310 x12: 0000000000000368 [  128.353388] x11: ffff0cb9cfbc7070 x10: ffff2cf55dd11e02 [  128.359606] x9 : ffffcf1f85a212b4 x8 : ffff0cd7cf27dab0 [  128.365831] x7 : 0000000000000a20 x6 : ffff0cd7cf27d000 [  128.372040] x5 : 0000000000000000 x4 : 000000000000ffff [  128.378243] x3 : 0000000000000400 x2 : ffffcf1f85a21294 [  128.384437] x1 : ffff0cb9db520080 x0 : ffff0cb9db500080 [  128.390626] Call trace: [  128.393964]  hclge_ptp_set_tx_info+0x2c/0x140 [hclge] [  128.399893]  hns3_nic_net_xmit+0x39c/0x4c4 [hns3] [  128.405468]  xmit_one.constprop.0+0xc4/0x200 [  128.410600]  dev_hard_start_xmit+0x54/0xf0 [  128.415556]  sch_direct_xmit+0xe8/0x634 [  128.420246]  __dev_queue_xmit+0x224/0xc70 [  128.425101]  dev_queue_xmit+0x1c/0x40 [  128.429608]  ovs_vport_send+0xac/0x1a0 [openvswitch] [  128.435409]  do_output+0x60/0x17c [openvswitch] [  128.440770]  do_execute_actions+0x898/0x8c4 [openvswitch] [  128.446993]  ovs_execute_actions+0x64/0xf0 [openvswitch] [  128.453129]  ovs_dp_process_packet+0xa0/0x224 [openvswitch] [  128.459530]  ovs_vport_receive+0x7c/0xfc [openvswitch] [  128.465497]  internal_dev_xmit+0x34/0xb0 [openvswitch] [  128.471460]  xmit_one.constprop.0+0xc4/0x200 [  128.476561]  dev_hard_start_xmit+0x54/0xf0 [  128.481489]  __dev_queue_xmit+0x968/0xc70 [  128.486330]  dev_queue_xmit+0x1c/0x40 [  128.490856]  ip_finish_output2+0x250/0x570 [  128.495810]  __ip_finish_output+0x170/0x1e0 [  128.500832]  ip_finish_output+0x3c/0xf0 [  128.505504]  ip_output+0xbc/0x160 [  128.509654]  ip_send_skb+0x58/0xd4 [  128.513892]  udp_send_skb+0x12c/0x354 [  128.518387]  udp_sendmsg+0x7a8/0x9c0 [  128.522793]  inet_sendmsg+0x4c/0x8c [  128.527116]  __sock_sendmsg+0x48/0x80 [  128.531609]  __sys_sendto+0x124/0x164 [  128.536099]  __arm64_sys_sendto+0x30/0x5c [  128.540935]  invoke_syscall+0x50/0x130 [  128.545508]  el0_svc_common.constprop.0+0x10c/0x124 [  128.551205]  do_el0_svc+0x34/0xdc [  128.555347]  el0_svc+0x20/0x30 [  128.559227]  el0_sync_handler+0xb8/0xc0 [  128.563883]  el0_sync+0x160/0x180","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21649","epss":0.00185,"percentile":0.08154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21649","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09712500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-21649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21649","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/9741e72b2286de8b38de9db685588ac421a95c87","https://git.kernel.org/stable/c/f19ab3ef96d9626e5f1bdc56d3574c355e83d623"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix kernel crash when 1588 is sent on HIP08 devices\n\nCurrently, HIP08 devices does not register the ptp devices, so the\nhdev->ptp is NULL. But the tx process would still try to set hardware time\nstamp info with SKBTX_HW_TSTAMP flag and cause a kernel crash.\n\n[  128.087798] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000018\n...\n[  128.280251] pc : hclge_ptp_set_tx_info+0x2c/0x140 [hclge]\n[  128.286600] lr : hclge_ptp_set_tx_info+0x20/0x140 [hclge]\n[  128.292938] sp : ffff800059b93140\n[  128.297200] x29: ffff800059b93140 x28: 0000000000003280\n[  128.303455] x27: ffff800020d48280 x26: ffff0cb9dc814080\n[  128.309715] x25: ffff0cb9cde93fa0 x24: 0000000000000001\n[  128.315969] x23: 0000000000000000 x22: 0000000000000194\n[  128.322219] x21: ffff0cd94f986000 x20: 0000000000000000\n[  128.328462] x19: ffff0cb9d2a166c0 x18: 0000000000000000\n[  128.334698] x17: 0000000000000000 x16: ffffcf1fc523ed24\n[  128.340934] x15: 0000ffffd530a518 x14: 0000000000000000\n[  128.347162] x13: ffff0cd6bdb31310 x12: 0000000000000368\n[  128.353388] x11: ffff0cb9cfbc7070 x10: ffff2cf55dd11e02\n[  128.359606] x9 : ffffcf1f85a212b4 x8 : ffff0cd7cf27dab0\n[  128.365831] x7 : 0000000000000a20 x6 : ffff0cd7cf27d000\n[  128.372040] x5 : 0000000000000000 x4 : 000000000000ffff\n[  128.378243] x3 : 0000000000000400 x2 : ffffcf1f85a21294\n[  128.384437] x1 : ffff0cb9db520080 x0 : ffff0cb9db500080\n[  128.390626] Call trace:\n[  128.393964]  hclge_ptp_set_tx_info+0x2c/0x140 [hclge]\n[  128.399893]  hns3_nic_net_xmit+0x39c/0x4c4 [hns3]\n[  128.405468]  xmit_one.constprop.0+0xc4/0x200\n[  128.410600]  dev_hard_start_xmit+0x54/0xf0\n[  128.415556]  sch_direct_xmit+0xe8/0x634\n[  128.420246]  __dev_queue_xmit+0x224/0xc70\n[  128.425101]  dev_queue_xmit+0x1c/0x40\n[  128.429608]  ovs_vport_send+0xac/0x1a0 [openvswitch]\n[  128.435409]  do_output+0x60/0x17c [openvswitch]\n[  128.440770]  do_execute_actions+0x898/0x8c4 [openvswitch]\n[  128.446993]  ovs_execute_actions+0x64/0xf0 [openvswitch]\n[  128.453129]  ovs_dp_process_packet+0xa0/0x224 [openvswitch]\n[  128.459530]  ovs_vport_receive+0x7c/0xfc [openvswitch]\n[  128.465497]  internal_dev_xmit+0x34/0xb0 [openvswitch]\n[  128.471460]  xmit_one.constprop.0+0xc4/0x200\n[  128.476561]  dev_hard_start_xmit+0x54/0xf0\n[  128.481489]  __dev_queue_xmit+0x968/0xc70\n[  128.486330]  dev_queue_xmit+0x1c/0x40\n[  128.490856]  ip_finish_output2+0x250/0x570\n[  128.495810]  __ip_finish_output+0x170/0x1e0\n[  128.500832]  ip_finish_output+0x3c/0xf0\n[  128.505504]  ip_output+0xbc/0x160\n[  128.509654]  ip_send_skb+0x58/0xd4\n[  128.513892]  udp_send_skb+0x12c/0x354\n[  128.518387]  udp_sendmsg+0x7a8/0x9c0\n[  128.522793]  inet_sendmsg+0x4c/0x8c\n[  128.527116]  __sock_sendmsg+0x48/0x80\n[  128.531609]  __sys_sendto+0x124/0x164\n[  128.536099]  __arm64_sys_sendto+0x30/0x5c\n[  128.540935]  invoke_syscall+0x50/0x130\n[  128.545508]  el0_svc_common.constprop.0+0x10c/0x124\n[  128.551205]  do_el0_svc+0x34/0xdc\n[  128.555347]  el0_svc+0x20/0x30\n[  128.559227]  el0_sync_handler+0xb8/0xc0\n[  128.563883]  el0_sync+0x160/0x180","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21649","epss":0.00185,"percentile":0.08154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21649","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21649","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21649","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21651","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: hns3: don't auto enable misc vector  Currently, there is a time window between misc irq enabled and service task inited. If an interrupte is reported at this time, it will cause warning like below:  [   16.324639] Call trace: [   16.324641]  __queue_delayed_work+0xb8/0xe0 [   16.324643]  mod_delayed_work_on+0x78/0xd0 [   16.324655]  hclge_errhand_task_schedule+0x58/0x90 [hclge] [   16.324662]  hclge_misc_irq_handle+0x168/0x240 [hclge] [   16.324666]  __handle_irq_event_percpu+0x64/0x1e0 [   16.324667]  handle_irq_event+0x80/0x170 [   16.324670]  handle_fasteoi_edge_irq+0x110/0x2bc [   16.324671]  __handle_domain_irq+0x84/0xfc [   16.324673]  gic_handle_irq+0x88/0x2c0 [   16.324674]  el1_irq+0xb8/0x140 [   16.324677]  arch_cpu_idle+0x18/0x40 [   16.324679]  default_idle_call+0x5c/0x1bc [   16.324682]  cpuidle_idle_call+0x18c/0x1c4 [   16.324684]  do_idle+0x174/0x17c [   16.324685]  cpu_startup_entry+0x30/0x6c [   16.324687]  secondary_start_kernel+0x1a4/0x280 [   16.324688] ---[ end trace 6aa0bff672a964aa ]---  So don't auto enable misc vector when request irq..","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21651","epss":0.00132,"percentile":0.03129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21651","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06402},"relatedVulnerabilities":[{"id":"CVE-2025-21651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21651","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/98b1e3b27734139c76295754b6c317aa4df6d32e","https://git.kernel.org/stable/c/bcf430d3bb5525fc89a92a0c451c725ba1aa4306"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: don't auto enable misc vector\n\nCurrently, there is a time window between misc irq enabled\nand service task inited. If an interrupte is reported at\nthis time, it will cause warning like below:\n\n[   16.324639] Call trace:\n[   16.324641]  __queue_delayed_work+0xb8/0xe0\n[   16.324643]  mod_delayed_work_on+0x78/0xd0\n[   16.324655]  hclge_errhand_task_schedule+0x58/0x90 [hclge]\n[   16.324662]  hclge_misc_irq_handle+0x168/0x240 [hclge]\n[   16.324666]  __handle_irq_event_percpu+0x64/0x1e0\n[   16.324667]  handle_irq_event+0x80/0x170\n[   16.324670]  handle_fasteoi_edge_irq+0x110/0x2bc\n[   16.324671]  __handle_domain_irq+0x84/0xfc\n[   16.324673]  gic_handle_irq+0x88/0x2c0\n[   16.324674]  el1_irq+0xb8/0x140\n[   16.324677]  arch_cpu_idle+0x18/0x40\n[   16.324679]  default_idle_call+0x5c/0x1bc\n[   16.324682]  cpuidle_idle_call+0x18c/0x1c4\n[   16.324684]  do_idle+0x174/0x17c\n[   16.324685]  cpu_startup_entry+0x30/0x6c\n[   16.324687]  secondary_start_kernel+0x1a4/0x280\n[   16.324688] ---[ end trace 6aa0bff672a964aa ]---\n\nSo don't auto enable misc vector when request irq..","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21651","epss":0.00132,"percentile":0.03129,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21651","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21651","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21656","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21656","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur  scsi_execute_cmd() function can return both negative (linux codes) and positive (scsi_cmnd result field) error codes.  Currently the driver just passes error codes of scsi_execute_cmd() to hwmon core, which is incorrect because hwmon only checks for negative error codes. This leads to hwmon reporting uninitialized data to userspace in case of SCSI errors (for example if the disk drive was disconnected).  This patch checks scsi_execute_cmd() output and returns -EIO if it's error code is positive.  [groeck: Avoid inline variable declaration for portability]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21656","epss":0.00203,"percentile":0.10291,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2025-21656","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21656","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/42268d885e44af875a6474f7bba519cc6cea6a9d","https://git.kernel.org/stable/c/53e25b10a28edaf8c2a1d3916fd8929501a50dfc","https://git.kernel.org/stable/c/82163d63ae7a4c36142cd252388737205bb7e4b9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur\n\nscsi_execute_cmd() function can return both negative (linux codes) and\npositive (scsi_cmnd result field) error codes.\n\nCurrently the driver just passes error codes of scsi_execute_cmd() to\nhwmon core, which is incorrect because hwmon only checks for negative\nerror codes. This leads to hwmon reporting uninitialized data to\nuserspace in case of SCSI errors (for example if the disk drive was\ndisconnected).\n\nThis patch checks scsi_execute_cmd() output and returns -EIO if it's\nerror code is positive.\n\n[groeck: Avoid inline variable declaration for portability]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21656","epss":0.00203,"percentile":0.10291,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21656","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21658","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21658","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: avoid NULL pointer dereference if no valid extent tree  [BUG] Syzbot reported a crash with the following call trace:    BTRFS info (device loop0): scrub: started on devid 1   BUG: kernel NULL pointer dereference, address: 0000000000000208   #PF: supervisor read access in kernel mode   #PF: error_code(0x0000) - not-present page   PGD 106e70067 P4D 106e70067 PUD 107143067 PMD 0   Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI   CPU: 1 UID: 0 PID: 689 Comm: repro Kdump: loaded Tainted: G           O       6.13.0-rc4-custom+ #206   Tainted: [O]=OOT_MODULE   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022   RIP: 0010:find_first_extent_item+0x26/0x1f0 [btrfs]   Call Trace:    <TASK>    scrub_find_fill_first_stripe+0x13d/0x3b0 [btrfs]    scrub_simple_mirror+0x175/0x260 [btrfs]    scrub_stripe+0x5d4/0x6c0 [btrfs]    scrub_chunk+0xbb/0x170 [btrfs]    scrub_enumerate_chunks+0x2f4/0x5f0 [btrfs]    btrfs_scrub_dev+0x240/0x600 [btrfs]    btrfs_ioctl+0x1dc8/0x2fa0 [btrfs]    ? do_sys_openat2+0xa5/0xf0    __x64_sys_ioctl+0x97/0xc0    do_syscall_64+0x4f/0x120    entry_SYSCALL_64_after_hwframe+0x76/0x7e    </TASK>  [CAUSE] The reproducer is using a corrupted image where extent tree root is corrupted, thus forcing to use \"rescue=all,ro\" mount option to mount the image.  Then it triggered a scrub, but since scrub relies on extent tree to find where the data/metadata extents are, scrub_find_fill_first_stripe() relies on an non-empty extent root.  But unfortunately scrub_find_fill_first_stripe() doesn't really expect an NULL pointer for extent root, it use extent_root to grab fs_info and triggered a NULL pointer dereference.  [FIX] Add an extra check for a valid extent root at the beginning of scrub_find_fill_first_stripe().  The new error path is introduced by 42437a6386ff (\"btrfs: introduce mount option rescue=ignorebadroots\"), but that's pretty old, and later commit b979547513ff (\"btrfs: scrub: introduce helper to find and fill sector info for a scrub_stripe\") changed how we do scrub.  So for kernels older than 6.6, the fix will need manual backport.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21658","epss":0.00203,"percentile":0.1029,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21658","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21658","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2025-21658","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21658","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/24b85a8b0310e0144da9ab30be42e87e6476638a","https://git.kernel.org/stable/c/6aecd91a5c5b68939cf4169e32bc49f3cd2dd329","https://git.kernel.org/stable/c/aee5f69f3e6cd82bfefaca1b70b40b6cd8f3f784"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: avoid NULL pointer dereference if no valid extent tree\n\n[BUG]\nSyzbot reported a crash with the following call trace:\n\n  BTRFS info (device loop0): scrub: started on devid 1\n  BUG: kernel NULL pointer dereference, address: 0000000000000208\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  PGD 106e70067 P4D 106e70067 PUD 107143067 PMD 0\n  Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n  CPU: 1 UID: 0 PID: 689 Comm: repro Kdump: loaded Tainted: G           O       6.13.0-rc4-custom+ #206\n  Tainted: [O]=OOT_MODULE\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022\n  RIP: 0010:find_first_extent_item+0x26/0x1f0 [btrfs]\n  Call Trace:\n   <TASK>\n   scrub_find_fill_first_stripe+0x13d/0x3b0 [btrfs]\n   scrub_simple_mirror+0x175/0x260 [btrfs]\n   scrub_stripe+0x5d4/0x6c0 [btrfs]\n   scrub_chunk+0xbb/0x170 [btrfs]\n   scrub_enumerate_chunks+0x2f4/0x5f0 [btrfs]\n   btrfs_scrub_dev+0x240/0x600 [btrfs]\n   btrfs_ioctl+0x1dc8/0x2fa0 [btrfs]\n   ? do_sys_openat2+0xa5/0xf0\n   __x64_sys_ioctl+0x97/0xc0\n   do_syscall_64+0x4f/0x120\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n   </TASK>\n\n[CAUSE]\nThe reproducer is using a corrupted image where extent tree root is\ncorrupted, thus forcing to use \"rescue=all,ro\" mount option to mount the\nimage.\n\nThen it triggered a scrub, but since scrub relies on extent tree to find\nwhere the data/metadata extents are, scrub_find_fill_first_stripe()\nrelies on an non-empty extent root.\n\nBut unfortunately scrub_find_fill_first_stripe() doesn't really expect\nan NULL pointer for extent root, it use extent_root to grab fs_info and\ntriggered a NULL pointer dereference.\n\n[FIX]\nAdd an extra check for a valid extent root at the beginning of\nscrub_find_fill_first_stripe().\n\nThe new error path is introduced by 42437a6386ff (\"btrfs: introduce\nmount option rescue=ignorebadroots\"), but that's pretty old, and later\ncommit b979547513ff (\"btrfs: scrub: introduce helper to find and fill\nsector info for a scrub_stripe\") changed how we do scrub.\n\nSo for kernels older than 6.6, the fix will need manual backport.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21658","epss":0.00203,"percentile":0.1029,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21658","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21658","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21658","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21673","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix double free of TCP_Server_Info::hostname  When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS targets before it realizes it should exit the loop, so @server->hostname can't be freed as long as cifsd thread isn't done.  Otherwise the following can happen:    RIP: 0010:__slab_free+0x223/0x3c0   Code: 5e 41 5f c3 cc cc cc cc 4c 89 de 4c 89 cf 44 89 44 24 08 4c 89   1c 24 e8 fb cf 8e 00 44 8b 44 24 08 4c 8b 1c 24 e9 5f fe ff ff <0f>   0b 41 f7 45 08 00 0d 21 00 0f 85 2d ff ff ff e9 1f ff ff ff 80   RSP: 0018:ffffb26180dbfd08 EFLAGS: 00010246   RAX: ffff8ea34728e510 RBX: ffff8ea34728e500 RCX: 0000000000800068   RDX: 0000000000800068 RSI: 0000000000000000 RDI: ffff8ea340042400   RBP: ffffe112041ca380 R08: 0000000000000001 R09: 0000000000000000   R10: 6170732e31303000 R11: 70726f632e786563 R12: ffff8ea34728e500   R13: ffff8ea340042400 R14: ffff8ea34728e500 R15: 0000000000800068   FS: 0000000000000000(0000) GS:ffff8ea66fd80000(0000)   000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   CR2: 00007ffc25376080 CR3: 000000012a2ba001 CR4:   PKRU: 55555554   Call Trace:    <TASK>    ? show_trace_log_lvl+0x1c4/0x2df    ? show_trace_log_lvl+0x1c4/0x2df    ? __reconnect_target_unlocked+0x3e/0x160 [cifs]    ? __die_body.cold+0x8/0xd    ? die+0x2b/0x50    ? do_trap+0xce/0x120    ? __slab_free+0x223/0x3c0    ? do_error_trap+0x65/0x80    ? __slab_free+0x223/0x3c0    ? exc_invalid_op+0x4e/0x70    ? __slab_free+0x223/0x3c0    ? asm_exc_invalid_op+0x16/0x20    ? __slab_free+0x223/0x3c0    ? extract_hostname+0x5c/0xa0 [cifs]    ? extract_hostname+0x5c/0xa0 [cifs]    ? __kmalloc+0x4b/0x140    __reconnect_target_unlocked+0x3e/0x160 [cifs]    reconnect_dfs_server+0x145/0x430 [cifs]    cifs_handle_standard+0x1ad/0x1d0 [cifs]    cifs_demultiplex_thread+0x592/0x730 [cifs]    ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]    kthread+0xdd/0x100    ? __pfx_kthread+0x10/0x10    ret_from_fork+0x29/0x50    </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21673","epss":0.00411,"percentile":0.34556,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21673","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21673","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.215775},"relatedVulnerabilities":[{"id":"CVE-2025-21673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21673","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1ea68070338518a1d31ce71e6abfe1b30001b27a","https://git.kernel.org/stable/c/a2be5f2ba34d0c6d5ef2624b24e3d852561fcd6a","https://git.kernel.org/stable/c/fa2f9906a7b333ba757a7dbae0713d8a5396186e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double free of TCP_Server_Info::hostname\n\nWhen shutting down the server in cifs_put_tcp_session(), cifsd thread\nmight be reconnecting to multiple DFS targets before it realizes it\nshould exit the loop, so @server->hostname can't be freed as long as\ncifsd thread isn't done.  Otherwise the following can happen:\n\n  RIP: 0010:__slab_free+0x223/0x3c0\n  Code: 5e 41 5f c3 cc cc cc cc 4c 89 de 4c 89 cf 44 89 44 24 08 4c 89\n  1c 24 e8 fb cf 8e 00 44 8b 44 24 08 4c 8b 1c 24 e9 5f fe ff ff <0f>\n  0b 41 f7 45 08 00 0d 21 00 0f 85 2d ff ff ff e9 1f ff ff ff 80\n  RSP: 0018:ffffb26180dbfd08 EFLAGS: 00010246\n  RAX: ffff8ea34728e510 RBX: ffff8ea34728e500 RCX: 0000000000800068\n  RDX: 0000000000800068 RSI: 0000000000000000 RDI: ffff8ea340042400\n  RBP: ffffe112041ca380 R08: 0000000000000001 R09: 0000000000000000\n  R10: 6170732e31303000 R11: 70726f632e786563 R12: ffff8ea34728e500\n  R13: ffff8ea340042400 R14: ffff8ea34728e500 R15: 0000000000800068\n  FS: 0000000000000000(0000) GS:ffff8ea66fd80000(0000)\n  000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007ffc25376080 CR3: 000000012a2ba001 CR4:\n  PKRU: 55555554\n  Call Trace:\n   <TASK>\n   ? show_trace_log_lvl+0x1c4/0x2df\n   ? show_trace_log_lvl+0x1c4/0x2df\n   ? __reconnect_target_unlocked+0x3e/0x160 [cifs]\n   ? __die_body.cold+0x8/0xd\n   ? die+0x2b/0x50\n   ? do_trap+0xce/0x120\n   ? __slab_free+0x223/0x3c0\n   ? do_error_trap+0x65/0x80\n   ? __slab_free+0x223/0x3c0\n   ? exc_invalid_op+0x4e/0x70\n   ? __slab_free+0x223/0x3c0\n   ? asm_exc_invalid_op+0x16/0x20\n   ? __slab_free+0x223/0x3c0\n   ? extract_hostname+0x5c/0xa0 [cifs]\n   ? extract_hostname+0x5c/0xa0 [cifs]\n   ? __kmalloc+0x4b/0x140\n   __reconnect_target_unlocked+0x3e/0x160 [cifs]\n   reconnect_dfs_server+0x145/0x430 [cifs]\n   cifs_handle_standard+0x1ad/0x1d0 [cifs]\n   cifs_demultiplex_thread+0x592/0x730 [cifs]\n   ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]\n   kthread+0xdd/0x100\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork+0x29/0x50\n   </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21673","epss":0.00411,"percentile":0.34556,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21673","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21673","cwe":"CWE-415","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21673","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21693","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21693","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm: zswap: properly synchronize freeing resources during CPU hotunplug  In zswap_compress() and zswap_decompress(), the per-CPU acomp_ctx of the current CPU at the beginning of the operation is retrieved and used throughout.  However, since neither preemption nor migration are disabled, it is possible that the operation continues on a different CPU.  If the original CPU is hotunplugged while the acomp_ctx is still in use, we run into a UAF bug as some of the resources attached to the acomp_ctx are freed during hotunplug in zswap_cpu_comp_dead() (i.e.  acomp_ctx.buffer, acomp_ctx.req, or acomp_ctx.acomp).  The problem was introduced in commit 1ec3b5fe6eec (\"mm/zswap: move to use crypto_acomp API for hardware acceleration\") when the switch to the crypto_acomp API was made.  Prior to that, the per-CPU crypto_comp was retrieved using get_cpu_ptr() which disables preemption and makes sure the CPU cannot go away from under us.  Preemption cannot be disabled with the crypto_acomp API as a sleepable context is needed.  Use the acomp_ctx.mutex to synchronize CPU hotplug callbacks allocating and freeing resources with compression/decompression paths.  Make sure that acomp_ctx.req is NULL when the resources are freed.  In the compression/decompression paths, check if acomp_ctx.req is NULL after acquiring the mutex (meaning the CPU was offlined) and retry on the new CPU.  The initialization of acomp_ctx.mutex is moved from the CPU hotplug callback to the pool initialization where it belongs (where the mutex is allocated).  In addition to adding clarity, this makes sure that CPU hotplug cannot reinitialize a mutex that is already locked by compression/decompression.  Previously a fix was attempted by holding cpus_read_lock() [1].  This would have caused a potential deadlock as it is possible for code already holding the lock to fall into reclaim and enter zswap (causing a deadlock).  A fix was also attempted using SRCU for synchronization, but Johannes pointed out that synchronize_srcu() cannot be used in CPU hotplug notifiers [2].  Alternative fixes that were considered/attempted and could have worked: - Refcounting the per-CPU acomp_ctx. This involves complexity in   handling the race between the refcount dropping to zero in   zswap_[de]compress() and the refcount being re-initialized when the   CPU is onlined. - Disabling migration before getting the per-CPU acomp_ctx [3], but   that's discouraged and is a much bigger hammer than needed, and could   result in subtle performance issues.  [1]https://lkml.kernel.org/20241219212437.2714151-1-yosryahmed@google.com/ [2]https://lkml.kernel.org/20250107074724.1756696-2-yosryahmed@google.com/ [3]https://lkml.kernel.org/20250107222236.2715883-2-yosryahmed@google.com/  [yosryahmed@google.com: remove comment]","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21693","epss":0.00203,"percentile":0.10377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21693","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15529500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-21693","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21693","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/12dcb0ef540629a281533f9dedc1b6b8e14cfb65","https://git.kernel.org/stable/c/8d29ff5d50304daa41dc3cfdda4a9d1e46cf5be1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: zswap: properly synchronize freeing resources during CPU hotunplug\n\nIn zswap_compress() and zswap_decompress(), the per-CPU acomp_ctx of the\ncurrent CPU at the beginning of the operation is retrieved and used\nthroughout.  However, since neither preemption nor migration are disabled,\nit is possible that the operation continues on a different CPU.\n\nIf the original CPU is hotunplugged while the acomp_ctx is still in use,\nwe run into a UAF bug as some of the resources attached to the acomp_ctx\nare freed during hotunplug in zswap_cpu_comp_dead() (i.e. \nacomp_ctx.buffer, acomp_ctx.req, or acomp_ctx.acomp).\n\nThe problem was introduced in commit 1ec3b5fe6eec (\"mm/zswap: move to use\ncrypto_acomp API for hardware acceleration\") when the switch to the\ncrypto_acomp API was made.  Prior to that, the per-CPU crypto_comp was\nretrieved using get_cpu_ptr() which disables preemption and makes sure the\nCPU cannot go away from under us.  Preemption cannot be disabled with the\ncrypto_acomp API as a sleepable context is needed.\n\nUse the acomp_ctx.mutex to synchronize CPU hotplug callbacks allocating\nand freeing resources with compression/decompression paths.  Make sure\nthat acomp_ctx.req is NULL when the resources are freed.  In the\ncompression/decompression paths, check if acomp_ctx.req is NULL after\nacquiring the mutex (meaning the CPU was offlined) and retry on the new\nCPU.\n\nThe initialization of acomp_ctx.mutex is moved from the CPU hotplug\ncallback to the pool initialization where it belongs (where the mutex is\nallocated).  In addition to adding clarity, this makes sure that CPU\nhotplug cannot reinitialize a mutex that is already locked by\ncompression/decompression.\n\nPreviously a fix was attempted by holding cpus_read_lock() [1].  This\nwould have caused a potential deadlock as it is possible for code already\nholding the lock to fall into reclaim and enter zswap (causing a\ndeadlock).  A fix was also attempted using SRCU for synchronization, but\nJohannes pointed out that synchronize_srcu() cannot be used in CPU hotplug\nnotifiers [2].\n\nAlternative fixes that were considered/attempted and could have worked:\n- Refcounting the per-CPU acomp_ctx. This involves complexity in\n  handling the race between the refcount dropping to zero in\n  zswap_[de]compress() and the refcount being re-initialized when the\n  CPU is onlined.\n- Disabling migration before getting the per-CPU acomp_ctx [3], but\n  that's discouraged and is a much bigger hammer than needed, and could\n  result in subtle performance issues.\n\n[1]https://lkml.kernel.org/20241219212437.2714151-1-yosryahmed@google.com/\n[2]https://lkml.kernel.org/20250107074724.1756696-2-yosryahmed@google.com/\n[3]https://lkml.kernel.org/20250107222236.2715883-2-yosryahmed@google.com/\n\n[yosryahmed@google.com: remove comment]","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21693","epss":0.00203,"percentile":0.10377,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21693","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21693","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21696","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21696","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm: clear uffd-wp PTE/PMD state on mremap()  When mremap()ing a memory region previously registered with userfaultfd as write-protected but without UFFD_FEATURE_EVENT_REMAP, an inconsistency in flag clearing leads to a mismatch between the vma flags (which have uffd-wp cleared) and the pte/pmd flags (which do not have uffd-wp cleared).  This mismatch causes a subsequent mprotect(PROT_WRITE) to trigger a warning in page_table_check_pte_flags() due to setting the pte to writable while uffd-wp is still set.  Fix this by always explicitly clearing the uffd-wp pte/pmd flags on any such mremap() so that the values are consistent with the existing clearing of VM_UFFD_WP.  Be careful to clear the logical flag regardless of its physical form; a PTE bit, a swap PTE bit, or a PTE marker.  Cover PTE, huge PMD and hugetlb paths.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21696","epss":0.00191,"percentile":0.08895,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10027499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-21696","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21696","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0cef0bb836e3cfe00f08f9606c72abd72fe78ca3","https://git.kernel.org/stable/c/310ac886d68de661c3a334198d8604b722d7fdf8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: clear uffd-wp PTE/PMD state on mremap()\n\nWhen mremap()ing a memory region previously registered with userfaultfd as\nwrite-protected but without UFFD_FEATURE_EVENT_REMAP, an inconsistency in\nflag clearing leads to a mismatch between the vma flags (which have\nuffd-wp cleared) and the pte/pmd flags (which do not have uffd-wp\ncleared).  This mismatch causes a subsequent mprotect(PROT_WRITE) to\ntrigger a warning in page_table_check_pte_flags() due to setting the pte\nto writable while uffd-wp is still set.\n\nFix this by always explicitly clearing the uffd-wp pte/pmd flags on any\nsuch mremap() so that the values are consistent with the existing clearing\nof VM_UFFD_WP.  Be careful to clear the logical flag regardless of its\nphysical form; a PTE bit, a swap PTE bit, or a PTE marker.  Cover PTE,\nhuge PMD and hugetlb paths.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21696","epss":0.00191,"percentile":0.08895,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21696","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21714","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21714","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx5: Fix implicit ODP use after free  Prevent double queueing of implicit ODP mr destroy work by using __xa_cmpxchg() to make sure this is the only time we are destroying this specific mr.  Without this change, we could try to invalidate this mr twice, which in turn could result in queuing a MR work destroy twice, and eventually the second work could execute after the MR was freed due to the first work, causing a user after free and trace below.     refcount_t: underflow; use-after-free.    WARNING: CPU: 2 PID: 12178 at lib/refcount.c:28 refcount_warn_saturate+0x12b/0x130    Modules linked in: bonding ib_ipoib vfio_pci ip_gre geneve nf_tables ip6_gre gre ip6_tunnel tunnel6 ipip tunnel4 ib_umad rdma_ucm mlx5_vfio_pci vfio_pci_core vfio_iommu_type1 mlx5_ib vfio ib_uverbs mlx5_core iptable_raw openvswitch nsh rpcrdma ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm ib_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay zram zsmalloc fuse [last unloaded: ib_uverbs]    CPU: 2 PID: 12178 Comm: kworker/u20:5 Not tainted 6.5.0-rc1_net_next_mlx5_58c644e #1    Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014    Workqueue: events_unbound free_implicit_child_mr_work [mlx5_ib]    RIP: 0010:refcount_warn_saturate+0x12b/0x130    Code: 48 c7 c7 38 95 2a 82 c6 05 bc c6 fe 00 01 e8 0c 66 aa ff 0f 0b 5b c3 48 c7 c7 e0 94 2a 82 c6 05 a7 c6 fe 00 01 e8 f5 65 aa ff <0f> 0b 5b c3 90 8b 07 3d 00 00 00 c0 74 12 83 f8 01 74 13 8d 50 ff    RSP: 0018:ffff8881008e3e40 EFLAGS: 00010286    RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000027    RDX: ffff88852c91b5c8 RSI: 0000000000000001 RDI: ffff88852c91b5c0    RBP: ffff8881dacd4e00 R08: 00000000ffffffff R09: 0000000000000019    R10: 000000000000072e R11: 0000000063666572 R12: ffff88812bfd9e00    R13: ffff8881c792d200 R14: ffff88810011c005 R15: ffff8881002099c0    FS:  0000000000000000(0000) GS:ffff88852c900000(0000) knlGS:0000000000000000    CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033    CR2: 00007f5694b5e000 CR3: 00000001153f6003 CR4: 0000000000370ea0    DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000    DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400    Call Trace:     <TASK>     ? refcount_warn_saturate+0x12b/0x130     free_implicit_child_mr_work+0x180/0x1b0 [mlx5_ib]     process_one_work+0x1cc/0x3c0     worker_thread+0x218/0x3c0     kthread+0xc6/0xf0     ret_from_fork+0x1f/0x30     </TASK>","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21714","epss":0.00196,"percentile":0.09411,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21714","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.14994},"relatedVulnerabilities":[{"id":"CVE-2025-21714","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21714","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7cc8f681f6d4ae4478ae0f60485fc768f2b450da","https://git.kernel.org/stable/c/d3d930411ce390e532470194296658a960887773","https://git.kernel.org/stable/c/edfb65dbb9ffd3102f3ff4dd21316158e56f1976"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix implicit ODP use after free\n\nPrevent double queueing of implicit ODP mr destroy work by using\n__xa_cmpxchg() to make sure this is the only time we are destroying this\nspecific mr.\n\nWithout this change, we could try to invalidate this mr twice, which in\nturn could result in queuing a MR work destroy twice, and eventually the\nsecond work could execute after the MR was freed due to the first work,\ncausing a user after free and trace below.\n\n   refcount_t: underflow; use-after-free.\n   WARNING: CPU: 2 PID: 12178 at lib/refcount.c:28 refcount_warn_saturate+0x12b/0x130\n   Modules linked in: bonding ib_ipoib vfio_pci ip_gre geneve nf_tables ip6_gre gre ip6_tunnel tunnel6 ipip tunnel4 ib_umad rdma_ucm mlx5_vfio_pci vfio_pci_core vfio_iommu_type1 mlx5_ib vfio ib_uverbs mlx5_core iptable_raw openvswitch nsh rpcrdma ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm ib_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay zram zsmalloc fuse [last unloaded: ib_uverbs]\n   CPU: 2 PID: 12178 Comm: kworker/u20:5 Not tainted 6.5.0-rc1_net_next_mlx5_58c644e #1\n   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n   Workqueue: events_unbound free_implicit_child_mr_work [mlx5_ib]\n   RIP: 0010:refcount_warn_saturate+0x12b/0x130\n   Code: 48 c7 c7 38 95 2a 82 c6 05 bc c6 fe 00 01 e8 0c 66 aa ff 0f 0b 5b c3 48 c7 c7 e0 94 2a 82 c6 05 a7 c6 fe 00 01 e8 f5 65 aa ff <0f> 0b 5b c3 90 8b 07 3d 00 00 00 c0 74 12 83 f8 01 74 13 8d 50 ff\n   RSP: 0018:ffff8881008e3e40 EFLAGS: 00010286\n   RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000027\n   RDX: ffff88852c91b5c8 RSI: 0000000000000001 RDI: ffff88852c91b5c0\n   RBP: ffff8881dacd4e00 R08: 00000000ffffffff R09: 0000000000000019\n   R10: 000000000000072e R11: 0000000063666572 R12: ffff88812bfd9e00\n   R13: ffff8881c792d200 R14: ffff88810011c005 R15: ffff8881002099c0\n   FS:  0000000000000000(0000) GS:ffff88852c900000(0000) knlGS:0000000000000000\n   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n   CR2: 00007f5694b5e000 CR3: 00000001153f6003 CR4: 0000000000370ea0\n   DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n   DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n   Call Trace:\n    <TASK>\n    ? refcount_warn_saturate+0x12b/0x130\n    free_implicit_child_mr_work+0x180/0x1b0 [mlx5_ib]\n    process_one_work+0x1cc/0x3c0\n    worker_thread+0x218/0x3c0\n    kthread+0xc6/0xf0\n    ret_from_fork+0x1f/0x30\n    </TASK>","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21714","epss":0.00196,"percentile":0.09411,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21714","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21714","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21723","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21723","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: mpi3mr: Fix possible crash when setting up bsg fails  If bsg_setup_queue() fails, the bsg_queue is assigned a non-NULL value. Consequently, in mpi3mr_bsg_exit(), the condition \"if(!mrioc->bsg_queue)\" will not be satisfied, preventing execution from entering bsg_remove_queue(), which could lead to the following crash:  BUG: kernel NULL pointer dereference, address: 000000000000041c Call Trace:   <TASK>   mpi3mr_bsg_exit+0x1f/0x50 [mpi3mr]   mpi3mr_remove+0x6f/0x340 [mpi3mr]   pci_device_remove+0x3f/0xb0   device_release_driver_internal+0x19d/0x220   unbind_store+0xa4/0xb0   kernfs_fop_write_iter+0x11f/0x200   vfs_write+0x1fc/0x3e0   ksys_write+0x67/0xe0   do_syscall_64+0x38/0x80   entry_SYSCALL_64_after_hwframe+0x78/0xe2","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21723","epss":0.00223,"percentile":0.12909,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21723","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21723","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11707500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-21723","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21723","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/19b248069d1b1424982723a2bf3941ad864d5204","https://git.kernel.org/stable/c/295006f6e8c17212d3098811166e29627d19e05c","https://git.kernel.org/stable/c/832b8f95a2832321b8200ae478ed988b25faaef4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Fix possible crash when setting up bsg fails\n\nIf bsg_setup_queue() fails, the bsg_queue is assigned a non-NULL value.\nConsequently, in mpi3mr_bsg_exit(), the condition \"if(!mrioc->bsg_queue)\"\nwill not be satisfied, preventing execution from entering\nbsg_remove_queue(), which could lead to the following crash:\n\nBUG: kernel NULL pointer dereference, address: 000000000000041c\nCall Trace:\n  <TASK>\n  mpi3mr_bsg_exit+0x1f/0x50 [mpi3mr]\n  mpi3mr_remove+0x6f/0x340 [mpi3mr]\n  pci_device_remove+0x3f/0xb0\n  device_release_driver_internal+0x19d/0x220\n  unbind_store+0xa4/0xb0\n  kernfs_fop_write_iter+0x11f/0x200\n  vfs_write+0x1fc/0x3e0\n  ksys_write+0x67/0xe0\n  do_syscall_64+0x38/0x80\n  entry_SYSCALL_64_after_hwframe+0x78/0xe2","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21723","epss":0.00223,"percentile":0.12909,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21723","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21723","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21723","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21729","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21729","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw89: fix race between cancel_hw_scan and hw_scan completion  The rtwdev->scanning flag isn't protected by mutex originally, so cancel_hw_scan can pass the condition, but suddenly hw_scan completion unset the flag and calls ieee80211_scan_completed() that will free local->hw_scan_req. Then, cancel_hw_scan raises null-ptr-deref and use-after-free. Fix it by moving the check condition to where protected by mutex.   KASAN: null-ptr-deref in range [0x0000000000000088-0x000000000000008f]  CPU: 2 PID: 6922 Comm: kworker/2:2 Tainted: G           OE  Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB6WW (2.76 ) 09/10/2019  Workqueue: events cfg80211_conn_work [cfg80211]  RIP: 0010:rtw89_fw_h2c_scan_offload_be+0xc33/0x13c3 [rtw89_core]  Code: 00 45 89 6c 24 1c 0f 85 23 01 00 00 48 8b 85 20 ff ff ff 48 8d  RSP: 0018:ffff88811fd9f068 EFLAGS: 00010206  RAX: dffffc0000000000 RBX: ffff88811fd9f258 RCX: 0000000000000001  RDX: 0000000000000011 RSI: 0000000000000001 RDI: 0000000000000089  RBP: ffff88811fd9f170 R08: 0000000000000000 R09: 0000000000000000  R10: ffff88811fd9f108 R11: 0000000000000000 R12: ffff88810e47f960  R13: 0000000000000000 R14: 000000000000ffff R15: 0000000000000000  FS:  0000000000000000(0000) GS:ffff8881d6f00000(0000) knlGS:0000000000000000  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033  CR2: 00007531dfca55b0 CR3: 00000001be296004 CR4: 00000000001706e0  Call Trace:   <TASK>   ? show_regs+0x61/0x73   ? __die_body+0x20/0x73   ? die_addr+0x4f/0x7b   ? exc_general_protection+0x191/0x1db   ? asm_exc_general_protection+0x27/0x30   ? rtw89_fw_h2c_scan_offload_be+0xc33/0x13c3 [rtw89_core]   ? rtw89_fw_h2c_scan_offload_be+0x458/0x13c3 [rtw89_core]   ? __pfx_rtw89_fw_h2c_scan_offload_be+0x10/0x10 [rtw89_core]   ? do_raw_spin_lock+0x75/0xdb   ? __pfx_do_raw_spin_lock+0x10/0x10   rtw89_hw_scan_offload+0xb5e/0xbf7 [rtw89_core]   ? _raw_spin_unlock+0xe/0x24   ? __mutex_lock.constprop.0+0x40c/0x471   ? __pfx_rtw89_hw_scan_offload+0x10/0x10 [rtw89_core]   ? __mutex_lock_slowpath+0x13/0x1f   ? mutex_lock+0xa2/0xdc   ? __pfx_mutex_lock+0x10/0x10   rtw89_hw_scan_abort+0x58/0xb7 [rtw89_core]   rtw89_ops_cancel_hw_scan+0x120/0x13b [rtw89_core]   ieee80211_scan_cancel+0x468/0x4d0 [mac80211]   ieee80211_prep_connection+0x858/0x899 [mac80211]   ieee80211_mgd_auth+0xbea/0xdde [mac80211]   ? __pfx_ieee80211_mgd_auth+0x10/0x10 [mac80211]   ? cfg80211_find_elem+0x15/0x29 [cfg80211]   ? is_bss+0x1b7/0x1d7 [cfg80211]   ieee80211_auth+0x18/0x27 [mac80211]   cfg80211_mlme_auth+0x3bb/0x3e7 [cfg80211]   cfg80211_conn_do_work+0x410/0xb81 [cfg80211]   ? __pfx_cfg80211_conn_do_work+0x10/0x10 [cfg80211]   ? __kasan_check_read+0x11/0x1f   ? psi_group_change+0x8bc/0x944   ? __kasan_check_write+0x14/0x22   ? mutex_lock+0x8e/0xdc   ? __pfx_mutex_lock+0x10/0x10   ? __pfx___radix_tree_lookup+0x10/0x10   cfg80211_conn_work+0x245/0x34d [cfg80211]   ? __pfx_cfg80211_conn_work+0x10/0x10 [cfg80211]   ? update_cfs_rq_load_avg+0x3bc/0x3d7   ? sched_clock_noinstr+0x9/0x1a   ? sched_clock+0x10/0x24   ? sched_clock_cpu+0x7e/0x42e   ? newidle_balance+0x796/0x937   ? __pfx_sched_clock_cpu+0x10/0x10   ? __pfx_newidle_balance+0x10/0x10   ? __kasan_check_read+0x11/0x1f   ? psi_group_change+0x8bc/0x944   ? _raw_spin_unlock+0xe/0x24   ? raw_spin_rq_unlock+0x47/0x54   ? raw_spin_rq_unlock_irq+0x9/0x1f   ? finish_task_switch.isra.0+0x347/0x586   ? __schedule+0x27bf/0x2892   ? mutex_unlock+0x80/0xd0   ? do_raw_spin_lock+0x75/0xdb   ? __pfx___schedule+0x10/0x10   process_scheduled_works+0x58c/0x821   worker_thread+0x4c7/0x586   ? __kasan_check_read+0x11/0x1f   kthread+0x285/0x294   ? __pfx_worker_thread+0x10/0x10   ? __pfx_kthread+0x10/0x10   ret_from_fork+0x29/0x6f   ? __pfx_kthread+0x10/0x10   ret_from_fork_asm+0x1b/0x30   </TASK>","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21729","epss":0.00198,"percentile":0.0974,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21729","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15147000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-21729","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21729","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2403cb3c235d5e339b580cc3a825493769fadca8","https://git.kernel.org/stable/c/5afcd6fcd1e1c1fd6bcc9a360c121d10eddade67","https://git.kernel.org/stable/c/ba4bb0402c60e945c4c396c51f0acac3c3e3ea5c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: fix race between cancel_hw_scan and hw_scan completion\n\nThe rtwdev->scanning flag isn't protected by mutex originally, so\ncancel_hw_scan can pass the condition, but suddenly hw_scan completion\nunset the flag and calls ieee80211_scan_completed() that will free\nlocal->hw_scan_req. Then, cancel_hw_scan raises null-ptr-deref and\nuse-after-free. Fix it by moving the check condition to where\nprotected by mutex.\n\n KASAN: null-ptr-deref in range [0x0000000000000088-0x000000000000008f]\n CPU: 2 PID: 6922 Comm: kworker/2:2 Tainted: G           OE\n Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB6WW (2.76 ) 09/10/2019\n Workqueue: events cfg80211_conn_work [cfg80211]\n RIP: 0010:rtw89_fw_h2c_scan_offload_be+0xc33/0x13c3 [rtw89_core]\n Code: 00 45 89 6c 24 1c 0f 85 23 01 00 00 48 8b 85 20 ff ff ff 48 8d\n RSP: 0018:ffff88811fd9f068 EFLAGS: 00010206\n RAX: dffffc0000000000 RBX: ffff88811fd9f258 RCX: 0000000000000001\n RDX: 0000000000000011 RSI: 0000000000000001 RDI: 0000000000000089\n RBP: ffff88811fd9f170 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff88811fd9f108 R11: 0000000000000000 R12: ffff88810e47f960\n R13: 0000000000000000 R14: 000000000000ffff R15: 0000000000000000\n FS:  0000000000000000(0000) GS:ffff8881d6f00000(0000) knlGS:0000000000000000\n CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007531dfca55b0 CR3: 00000001be296004 CR4: 00000000001706e0\n Call Trace:\n  <TASK>\n  ? show_regs+0x61/0x73\n  ? __die_body+0x20/0x73\n  ? die_addr+0x4f/0x7b\n  ? exc_general_protection+0x191/0x1db\n  ? asm_exc_general_protection+0x27/0x30\n  ? rtw89_fw_h2c_scan_offload_be+0xc33/0x13c3 [rtw89_core]\n  ? rtw89_fw_h2c_scan_offload_be+0x458/0x13c3 [rtw89_core]\n  ? __pfx_rtw89_fw_h2c_scan_offload_be+0x10/0x10 [rtw89_core]\n  ? do_raw_spin_lock+0x75/0xdb\n  ? __pfx_do_raw_spin_lock+0x10/0x10\n  rtw89_hw_scan_offload+0xb5e/0xbf7 [rtw89_core]\n  ? _raw_spin_unlock+0xe/0x24\n  ? __mutex_lock.constprop.0+0x40c/0x471\n  ? __pfx_rtw89_hw_scan_offload+0x10/0x10 [rtw89_core]\n  ? __mutex_lock_slowpath+0x13/0x1f\n  ? mutex_lock+0xa2/0xdc\n  ? __pfx_mutex_lock+0x10/0x10\n  rtw89_hw_scan_abort+0x58/0xb7 [rtw89_core]\n  rtw89_ops_cancel_hw_scan+0x120/0x13b [rtw89_core]\n  ieee80211_scan_cancel+0x468/0x4d0 [mac80211]\n  ieee80211_prep_connection+0x858/0x899 [mac80211]\n  ieee80211_mgd_auth+0xbea/0xdde [mac80211]\n  ? __pfx_ieee80211_mgd_auth+0x10/0x10 [mac80211]\n  ? cfg80211_find_elem+0x15/0x29 [cfg80211]\n  ? is_bss+0x1b7/0x1d7 [cfg80211]\n  ieee80211_auth+0x18/0x27 [mac80211]\n  cfg80211_mlme_auth+0x3bb/0x3e7 [cfg80211]\n  cfg80211_conn_do_work+0x410/0xb81 [cfg80211]\n  ? __pfx_cfg80211_conn_do_work+0x10/0x10 [cfg80211]\n  ? __kasan_check_read+0x11/0x1f\n  ? psi_group_change+0x8bc/0x944\n  ? __kasan_check_write+0x14/0x22\n  ? mutex_lock+0x8e/0xdc\n  ? __pfx_mutex_lock+0x10/0x10\n  ? __pfx___radix_tree_lookup+0x10/0x10\n  cfg80211_conn_work+0x245/0x34d [cfg80211]\n  ? __pfx_cfg80211_conn_work+0x10/0x10 [cfg80211]\n  ? update_cfs_rq_load_avg+0x3bc/0x3d7\n  ? sched_clock_noinstr+0x9/0x1a\n  ? sched_clock+0x10/0x24\n  ? sched_clock_cpu+0x7e/0x42e\n  ? newidle_balance+0x796/0x937\n  ? __pfx_sched_clock_cpu+0x10/0x10\n  ? __pfx_newidle_balance+0x10/0x10\n  ? __kasan_check_read+0x11/0x1f\n  ? psi_group_change+0x8bc/0x944\n  ? _raw_spin_unlock+0xe/0x24\n  ? raw_spin_rq_unlock+0x47/0x54\n  ? raw_spin_rq_unlock_irq+0x9/0x1f\n  ? finish_task_switch.isra.0+0x347/0x586\n  ? __schedule+0x27bf/0x2892\n  ? mutex_unlock+0x80/0xd0\n  ? do_raw_spin_lock+0x75/0xdb\n  ? __pfx___schedule+0x10/0x10\n  process_scheduled_works+0x58c/0x821\n  worker_thread+0x4c7/0x586\n  ? __kasan_check_read+0x11/0x1f\n  kthread+0x285/0x294\n  ? __pfx_worker_thread+0x10/0x10\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork+0x29/0x6f\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork_asm+0x1b/0x30\n  </TASK>","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21729","epss":0.00198,"percentile":0.0974,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21729","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21729","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21732","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21732","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error  This patch addresses a race condition for an ODP MR that can result in a CQE with an error on the UMR QP.  During the __mlx5_ib_dereg_mr() flow, the following sequence of calls occurs:  mlx5_revoke_mr()  mlx5r_umr_revoke_mr()  mlx5r_umr_post_send_wait()  At this point, the lkey is freed from the hardware's perspective.  However, concurrently, mlx5_ib_invalidate_range() might be triggered by another task attempting to invalidate a range for the same freed lkey.  This task will:  - Acquire the umem_odp->umem_mutex lock.  - Call mlx5r_umr_update_xlt() on the UMR QP.  - Since the lkey has already been freed, this can lead to a CQE error,    causing the UMR QP to enter an error state [1].  To resolve this race condition, the umem_odp->umem_mutex lock is now also acquired as part of the mlx5_revoke_mr() scope.  Upon successful revoke, we set umem_odp->private which points to that MR to NULL, preventing any further invalidation attempts on its lkey.  [1] From dmesg:     infiniband rocep8s0f0: dump_cqe:277:(pid 0): WC error: 6, Message: memory bind operation error    cqe_dump: 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00    cqe_dump: 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00    cqe_dump: 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00    cqe_dump: 00000030: 00 00 00 00 08 00 78 06 25 00 11 b9 00 0e dd d2     WARNING: CPU: 15 PID: 1506 at drivers/infiniband/hw/mlx5/umr.c:394 mlx5r_umr_post_send_wait+0x15a/0x2b0 [mlx5_ib]    Modules linked in: ip6table_mangle ip6table_natip6table_filter ip6_tables iptable_mangle xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_umad ib_ipoib ib_cm mlx5_ib ib_uverbs ib_core fuse mlx5_core    CPU: 15 UID: 0 PID: 1506 Comm: ibv_rc_pingpong Not tainted 6.12.0-rc7+ #1626    Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014    RIP: 0010:mlx5r_umr_post_send_wait+0x15a/0x2b0 [mlx5_ib]    [..]    Call Trace:    <TASK>    mlx5r_umr_update_xlt+0x23c/0x3e0 [mlx5_ib]    mlx5_ib_invalidate_range+0x2e1/0x330 [mlx5_ib]    __mmu_notifier_invalidate_range_start+0x1e1/0x240    zap_page_range_single+0xf1/0x1a0    madvise_vma_behavior+0x677/0x6e0    do_madvise+0x1a2/0x4b0    __x64_sys_madvise+0x25/0x30    do_syscall_64+0x6b/0x140    entry_SYSCALL_64_after_hwframe+0x76/0x7e","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21732","epss":0.00136,"percentile":0.03393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21732","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06596},"relatedVulnerabilities":[{"id":"CVE-2025-21732","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21732","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5297f5ddffef47b94172ab0d3d62270002a3dcc1","https://git.kernel.org/stable/c/abb604a1a9c87255c7a6f3b784410a9707baf467","https://git.kernel.org/stable/c/b13d32786acabf70a7b04ed24b7468fc3c82977c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error\n\nThis patch addresses a race condition for an ODP MR that can result in a\nCQE with an error on the UMR QP.\n\nDuring the __mlx5_ib_dereg_mr() flow, the following sequence of calls\noccurs:\n\nmlx5_revoke_mr()\n mlx5r_umr_revoke_mr()\n mlx5r_umr_post_send_wait()\n\nAt this point, the lkey is freed from the hardware's perspective.\n\nHowever, concurrently, mlx5_ib_invalidate_range() might be triggered by\nanother task attempting to invalidate a range for the same freed lkey.\n\nThis task will:\n - Acquire the umem_odp->umem_mutex lock.\n - Call mlx5r_umr_update_xlt() on the UMR QP.\n - Since the lkey has already been freed, this can lead to a CQE error,\n   causing the UMR QP to enter an error state [1].\n\nTo resolve this race condition, the umem_odp->umem_mutex lock is now also\nacquired as part of the mlx5_revoke_mr() scope.  Upon successful revoke,\nwe set umem_odp->private which points to that MR to NULL, preventing any\nfurther invalidation attempts on its lkey.\n\n[1] From dmesg:\n\n   infiniband rocep8s0f0: dump_cqe:277:(pid 0): WC error: 6, Message: memory bind operation error\n   cqe_dump: 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n   cqe_dump: 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n   cqe_dump: 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n   cqe_dump: 00000030: 00 00 00 00 08 00 78 06 25 00 11 b9 00 0e dd d2\n\n   WARNING: CPU: 15 PID: 1506 at drivers/infiniband/hw/mlx5/umr.c:394 mlx5r_umr_post_send_wait+0x15a/0x2b0 [mlx5_ib]\n   Modules linked in: ip6table_mangle ip6table_natip6table_filter ip6_tables iptable_mangle xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_umad ib_ipoib ib_cm mlx5_ib ib_uverbs ib_core fuse mlx5_core\n   CPU: 15 UID: 0 PID: 1506 Comm: ibv_rc_pingpong Not tainted 6.12.0-rc7+ #1626\n   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n   RIP: 0010:mlx5r_umr_post_send_wait+0x15a/0x2b0 [mlx5_ib]\n   [..]\n   Call Trace:\n   <TASK>\n   mlx5r_umr_update_xlt+0x23c/0x3e0 [mlx5_ib]\n   mlx5_ib_invalidate_range+0x2e1/0x330 [mlx5_ib]\n   __mmu_notifier_invalidate_range_start+0x1e1/0x240\n   zap_page_range_single+0xf1/0x1a0\n   madvise_vma_behavior+0x677/0x6e0\n   do_madvise+0x1a2/0x4b0\n   __x64_sys_madvise+0x25/0x30\n   do_syscall_64+0x6b/0x140\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21732","epss":0.00136,"percentile":0.03393,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21732","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21732","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21759","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21759","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: mcast: extend RCU protection in igmp6_send()  igmp6_send() can be called without RTNL or RCU being held.  Extend RCU protection so that we can safely fetch the net pointer and avoid a potential UAF.  Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.  Instead use alloc_skb() and charge the net->ipv6.igmp_sk socket under RCU protection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21759","epss":0.07773,"percentile":0.94282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21759","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":5.946344999999999},"relatedVulnerabilities":[{"id":"CVE-2025-21759","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21759","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/087c1faa594fa07a66933d750c0b2610aa1a2946","https://git.kernel.org/stable/c/0bf8e2f3768629d437a32cb824149e6e98254381","https://git.kernel.org/stable/c/81b25a07ebf53f9ef4ca8f3d96a8ddb94561dd5a","https://git.kernel.org/stable/c/8e92d6a413feaf968a33f0b439ecf27404407458"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: extend RCU protection in igmp6_send()\n\nigmp6_send() can be called without RTNL or RCU being held.\n\nExtend RCU protection so that we can safely fetch the net pointer\nand avoid a potential UAF.\n\nNote that we no longer can use sock_alloc_send_skb() because\nipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.\n\nInstead use alloc_skb() and charge the net->ipv6.igmp_sk\nsocket under RCU protection.","cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21759","epss":0.07773,"percentile":0.94282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21759","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21759","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21768","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21768","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels  Some lwtunnels have a dst cache for post-transformation dst. If the packet destination did not change we may end up recording a reference to the lwtunnel in its own cache, and the lwtunnel state will never be freed.  Discovered by the ioam6.sh test, kmemleak was recently fixed to catch per-cpu memory leaks. I'm not sure if rpl and seg6 can actually hit this, but in principle I don't see why not.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21768","epss":0.00199,"percentile":0.09842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21768","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10447500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-21768","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21768","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4c0f200c7d06fedddde82209c099014d63f4a6c0","https://git.kernel.org/stable/c/5ab11a4e219e93b8b31a27f8ec98d42afadd8b7a","https://git.kernel.org/stable/c/92191dd1073088753821b862b791dcc83e558e07"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels\n\nSome lwtunnels have a dst cache for post-transformation dst.\nIf the packet destination did not change we may end up recording\na reference to the lwtunnel in its own cache, and the lwtunnel\nstate will never be freed.\n\nDiscovered by the ioam6.sh test, kmemleak was recently fixed\nto catch per-cpu memory leaks. I'm not sure if rpl and seg6\ncan actually hit this, but in principle I don't see why not.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21768","epss":0.00199,"percentile":0.09842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21768","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21768","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21801","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21801","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ravb: Fix missing rtnl lock in suspend/resume path  Fix the suspend/resume path by ensuring the rtnl lock is held where required. Calls to ravb_open, ravb_close and wol operations must be performed under the rtnl lock to prevent conflicts with ongoing ndo operations.  Without this fix, the following warning is triggered: [   39.032969] ============================= [   39.032983] WARNING: suspicious RCU usage [   39.033019] ----------------------------- [   39.033033] drivers/net/phy/phy_device.c:2004 suspicious rcu_dereference_protected() usage! ... [   39.033597] stack backtrace: [   39.033613] CPU: 0 UID: 0 PID: 174 Comm: python3 Not tainted 6.13.0-rc7-next-20250116-arm64-renesas-00002-g35245dfdc62c #7 [   39.033623] Hardware name: Renesas SMARC EVK version 2 based on r9a08g045s33 (DT) [   39.033628] Call trace: [   39.033633]  show_stack+0x14/0x1c (C) [   39.033652]  dump_stack_lvl+0xb4/0xc4 [   39.033664]  dump_stack+0x14/0x1c [   39.033671]  lockdep_rcu_suspicious+0x16c/0x22c [   39.033682]  phy_detach+0x160/0x190 [   39.033694]  phy_disconnect+0x40/0x54 [   39.033703]  ravb_close+0x6c/0x1cc [   39.033714]  ravb_suspend+0x48/0x120 [   39.033721]  dpm_run_callback+0x4c/0x14c [   39.033731]  device_suspend+0x11c/0x4dc [   39.033740]  dpm_suspend+0xdc/0x214 [   39.033748]  dpm_suspend_start+0x48/0x60 [   39.033758]  suspend_devices_and_enter+0x124/0x574 [   39.033769]  pm_suspend+0x1ac/0x274 [   39.033778]  state_store+0x88/0x124 [   39.033788]  kobj_attr_store+0x14/0x24 [   39.033798]  sysfs_kf_write+0x48/0x6c [   39.033808]  kernfs_fop_write_iter+0x118/0x1a8 [   39.033817]  vfs_write+0x27c/0x378 [   39.033825]  ksys_write+0x64/0xf4 [   39.033833]  __arm64_sys_write+0x18/0x20 [   39.033841]  invoke_syscall+0x44/0x104 [   39.033852]  el0_svc_common.constprop.0+0xb4/0xd4 [   39.033862]  do_el0_svc+0x18/0x20 [   39.033870]  el0_svc+0x3c/0xf0 [   39.033880]  el0t_64_sync_handler+0xc0/0xc4 [   39.033888]  el0t_64_sync+0x154/0x158 [   39.041274] ravb 11c30000.ethernet eth0: Link is Down","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21801","epss":0.00194,"percentile":0.09237,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10185000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-21801","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21801","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0296981941cf291edfbc318d3255a93439f368e4","https://git.kernel.org/stable/c/2c2ebb2b49573e5f8726112ad06b1dffc3c9ea03","https://git.kernel.org/stable/c/ad19522c007bb24ed874468f8baa1503c4662cf4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: Fix missing rtnl lock in suspend/resume path\n\nFix the suspend/resume path by ensuring the rtnl lock is held where\nrequired. Calls to ravb_open, ravb_close and wol operations must be\nperformed under the rtnl lock to prevent conflicts with ongoing ndo\noperations.\n\nWithout this fix, the following warning is triggered:\n[   39.032969] =============================\n[   39.032983] WARNING: suspicious RCU usage\n[   39.033019] -----------------------------\n[   39.033033] drivers/net/phy/phy_device.c:2004 suspicious\nrcu_dereference_protected() usage!\n...\n[   39.033597] stack backtrace:\n[   39.033613] CPU: 0 UID: 0 PID: 174 Comm: python3 Not tainted\n6.13.0-rc7-next-20250116-arm64-renesas-00002-g35245dfdc62c #7\n[   39.033623] Hardware name: Renesas SMARC EVK version 2 based on\nr9a08g045s33 (DT)\n[   39.033628] Call trace:\n[   39.033633]  show_stack+0x14/0x1c (C)\n[   39.033652]  dump_stack_lvl+0xb4/0xc4\n[   39.033664]  dump_stack+0x14/0x1c\n[   39.033671]  lockdep_rcu_suspicious+0x16c/0x22c\n[   39.033682]  phy_detach+0x160/0x190\n[   39.033694]  phy_disconnect+0x40/0x54\n[   39.033703]  ravb_close+0x6c/0x1cc\n[   39.033714]  ravb_suspend+0x48/0x120\n[   39.033721]  dpm_run_callback+0x4c/0x14c\n[   39.033731]  device_suspend+0x11c/0x4dc\n[   39.033740]  dpm_suspend+0xdc/0x214\n[   39.033748]  dpm_suspend_start+0x48/0x60\n[   39.033758]  suspend_devices_and_enter+0x124/0x574\n[   39.033769]  pm_suspend+0x1ac/0x274\n[   39.033778]  state_store+0x88/0x124\n[   39.033788]  kobj_attr_store+0x14/0x24\n[   39.033798]  sysfs_kf_write+0x48/0x6c\n[   39.033808]  kernfs_fop_write_iter+0x118/0x1a8\n[   39.033817]  vfs_write+0x27c/0x378\n[   39.033825]  ksys_write+0x64/0xf4\n[   39.033833]  __arm64_sys_write+0x18/0x20\n[   39.033841]  invoke_syscall+0x44/0x104\n[   39.033852]  el0_svc_common.constprop.0+0xb4/0xd4\n[   39.033862]  do_el0_svc+0x18/0x20\n[   39.033870]  el0_svc+0x3c/0xf0\n[   39.033880]  el0t_64_sync_handler+0xc0/0xc4\n[   39.033888]  el0t_64_sync+0x154/0x158\n[   39.041274] ravb 11c30000.ethernet eth0: Link is Down","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21801","epss":0.00194,"percentile":0.09237,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21801","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21825","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21825","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT  During the update procedure, when overwrite element in a pre-allocated htab, the freeing of old_element is protected by the bucket lock. The reason why the bucket lock is necessary is that the old_element has already been stashed in htab->extra_elems after alloc_htab_elem() returns. If freeing the old_element after the bucket lock is unlocked, the stashed element may be reused by concurrent update procedure and the freeing of old_element will run concurrently with the reuse of the old_element. However, the invocation of check_and_free_fields() may acquire a spin-lock which violates the lockdep rule because its caller has already held a raw-spin-lock (bucket lock). The following warning will be reported when such race happens:    BUG: scheduling while atomic: test_progs/676/0x00000003   3 locks held by test_progs/676:   #0: ffffffff864b0240 (rcu_read_lock_trace){....}-{0:0}, at: bpf_prog_test_run_syscall+0x2c0/0x830   #1: ffff88810e961188 (&htab->lockdep_key){....}-{2:2}, at: htab_map_update_elem+0x306/0x1500   #2: ffff8881f4eac1b8 (&base->softirq_expiry_lock){....}-{2:2}, at: hrtimer_cancel_wait_running+0xe9/0x1b0   Modules linked in: bpf_testmod(O)   Preemption disabled at:   [<ffffffff817837a3>] htab_map_update_elem+0x293/0x1500   CPU: 0 UID: 0 PID: 676 Comm: test_progs Tainted: G ... 6.12.0+ #11   Tainted: [W]=WARN, [O]=OOT_MODULE   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)...   Call Trace:   <TASK>   dump_stack_lvl+0x57/0x70   dump_stack+0x10/0x20   __schedule_bug+0x120/0x170   __schedule+0x300c/0x4800   schedule_rtlock+0x37/0x60   rtlock_slowlock_locked+0x6d9/0x54c0   rt_spin_lock+0x168/0x230   hrtimer_cancel_wait_running+0xe9/0x1b0   hrtimer_cancel+0x24/0x30   bpf_timer_delete_work+0x1d/0x40   bpf_timer_cancel_and_free+0x5e/0x80   bpf_obj_free_fields+0x262/0x4a0   check_and_free_fields+0x1d0/0x280   htab_map_update_elem+0x7fc/0x1500   bpf_prog_9f90bc20768e0cb9_overwrite_cb+0x3f/0x43   bpf_prog_ea601c4649694dbd_overwrite_timer+0x5d/0x7e   bpf_prog_test_run_syscall+0x322/0x830   __sys_bpf+0x135d/0x3ca0   __x64_sys_bpf+0x75/0xb0   x64_sys_call+0x1b5/0xa10   do_syscall_64+0x3b/0xc0   entry_SYSCALL_64_after_hwframe+0x4b/0x53   ...   </TASK>  It seems feasible to break the reuse and refill of per-cpu extra_elems into two independent parts: reuse the per-cpu extra_elems with bucket lock being held and refill the old_element as per-cpu extra_elems after the bucket lock is unlocked. However, it will make the concurrent overwrite procedures on the same CPU return unexpected -E2BIG error when the map is full.  Therefore, the patch fixes the lock problem by breaking the cancelling of bpf_timer into two steps for PREEMPT_RT: 1) use hrtimer_try_to_cancel() and check its return value 2) if the timer is running, use hrtimer_cancel() through a kworker to    cancel it again Considering that the current implementation of hrtimer_cancel() will try to acquire a being held softirq_expiry_lock when the current timer is running, these steps above are reasonable. However, it also has downside. When the timer is running, the cancelling of the timer is delayed when releasing the last map uref. The delay is also fixable (e.g., break the cancelling of bpf timer into two parts: one part in locked scope, another one in unlocked scope), it can be revised later if necessary.  It is a bit hard to decide the right fix tag. One reason is that the problem depends on PREEMPT_RT which is enabled in v6.12. Considering the softirq_expiry_lock lock exists since v5.4 and bpf_timer is introduced in v5.15, the bpf_timer commit is used in the fixes tag and an extra depends-on tag is added to state the dependency on PREEMPT_RT.  Depends-on: v6.12+ with PREEMPT_RT enabled","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21825","epss":0.00175,"percentile":0.07128,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21825","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084875},"relatedVulnerabilities":[{"id":"CVE-2025-21825","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21825","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/33e47d9573075342a41783a55c8c67bc71246fc1","https://git.kernel.org/stable/c/58f038e6d209d2dd862fcf5de55407855856794d","https://git.kernel.org/stable/c/fbeda3d939ca10063aafa7a77cc0f409d82cda88"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Cancel the running bpf_timer through kworker for PREEMPT_RT\n\nDuring the update procedure, when overwrite element in a pre-allocated\nhtab, the freeing of old_element is protected by the bucket lock. The\nreason why the bucket lock is necessary is that the old_element has\nalready been stashed in htab->extra_elems after alloc_htab_elem()\nreturns. If freeing the old_element after the bucket lock is unlocked,\nthe stashed element may be reused by concurrent update procedure and the\nfreeing of old_element will run concurrently with the reuse of the\nold_element. However, the invocation of check_and_free_fields() may\nacquire a spin-lock which violates the lockdep rule because its caller\nhas already held a raw-spin-lock (bucket lock). The following warning\nwill be reported when such race happens:\n\n  BUG: scheduling while atomic: test_progs/676/0x00000003\n  3 locks held by test_progs/676:\n  #0: ffffffff864b0240 (rcu_read_lock_trace){....}-{0:0}, at: bpf_prog_test_run_syscall+0x2c0/0x830\n  #1: ffff88810e961188 (&htab->lockdep_key){....}-{2:2}, at: htab_map_update_elem+0x306/0x1500\n  #2: ffff8881f4eac1b8 (&base->softirq_expiry_lock){....}-{2:2}, at: hrtimer_cancel_wait_running+0xe9/0x1b0\n  Modules linked in: bpf_testmod(O)\n  Preemption disabled at:\n  [<ffffffff817837a3>] htab_map_update_elem+0x293/0x1500\n  CPU: 0 UID: 0 PID: 676 Comm: test_progs Tainted: G ... 6.12.0+ #11\n  Tainted: [W]=WARN, [O]=OOT_MODULE\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)...\n  Call Trace:\n  <TASK>\n  dump_stack_lvl+0x57/0x70\n  dump_stack+0x10/0x20\n  __schedule_bug+0x120/0x170\n  __schedule+0x300c/0x4800\n  schedule_rtlock+0x37/0x60\n  rtlock_slowlock_locked+0x6d9/0x54c0\n  rt_spin_lock+0x168/0x230\n  hrtimer_cancel_wait_running+0xe9/0x1b0\n  hrtimer_cancel+0x24/0x30\n  bpf_timer_delete_work+0x1d/0x40\n  bpf_timer_cancel_and_free+0x5e/0x80\n  bpf_obj_free_fields+0x262/0x4a0\n  check_and_free_fields+0x1d0/0x280\n  htab_map_update_elem+0x7fc/0x1500\n  bpf_prog_9f90bc20768e0cb9_overwrite_cb+0x3f/0x43\n  bpf_prog_ea601c4649694dbd_overwrite_timer+0x5d/0x7e\n  bpf_prog_test_run_syscall+0x322/0x830\n  __sys_bpf+0x135d/0x3ca0\n  __x64_sys_bpf+0x75/0xb0\n  x64_sys_call+0x1b5/0xa10\n  do_syscall_64+0x3b/0xc0\n  entry_SYSCALL_64_after_hwframe+0x4b/0x53\n  ...\n  </TASK>\n\nIt seems feasible to break the reuse and refill of per-cpu extra_elems\ninto two independent parts: reuse the per-cpu extra_elems with bucket\nlock being held and refill the old_element as per-cpu extra_elems after\nthe bucket lock is unlocked. However, it will make the concurrent\noverwrite procedures on the same CPU return unexpected -E2BIG error when\nthe map is full.\n\nTherefore, the patch fixes the lock problem by breaking the cancelling\nof bpf_timer into two steps for PREEMPT_RT:\n1) use hrtimer_try_to_cancel() and check its return value\n2) if the timer is running, use hrtimer_cancel() through a kworker to\n   cancel it again\nConsidering that the current implementation of hrtimer_cancel() will try\nto acquire a being held softirq_expiry_lock when the current timer is\nrunning, these steps above are reasonable. However, it also has\ndownside. When the timer is running, the cancelling of the timer is\ndelayed when releasing the last map uref. The delay is also fixable\n(e.g., break the cancelling of bpf timer into two parts: one part in\nlocked scope, another one in unlocked scope), it can be revised later if\nnecessary.\n\nIt is a bit hard to decide the right fix tag. One reason is that the\nproblem depends on PREEMPT_RT which is enabled in v6.12. Considering the\nsoftirq_expiry_lock lock exists since v5.4 and bpf_timer is introduced\nin v5.15, the bpf_timer commit is used in the fixes tag and an extra\ndepends-on tag is added to state the dependency on PREEMPT_RT.\n\nDepends-on: v6.12+ with PREEMPT_RT enabled","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21825","epss":0.00175,"percentile":0.07128,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21825","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21825","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21831","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21831","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1  commit 9d26d3a8f1b0 (\"PCI: Put PCIe ports into D3 during suspend\") sets the policy that all PCIe ports are allowed to use D3.  When the system is suspended if the port is not power manageable by the platform and won't be used for wakeup via a PME this sets up the policy for these ports to go into D3hot.  This policy generally makes sense from an OSPM perspective but it leads to problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a specific old BIOS. This manifests as a system hang.  On the affected Device + BIOS combination, add a quirk for the root port of the problematic controller to ensure that these root ports are not put into D3hot at suspend.  This patch is based on    https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com  but with the added condition both in the documentation and in the code to apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only the affected root ports.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21831","epss":0.00178,"percentile":0.0748,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09345},"relatedVulnerabilities":[{"id":"CVE-2025-21831","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21831","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5ee3dd6e59b834e4d66e8b16fc684749ee40a257","https://git.kernel.org/stable/c/8852e056e297df1d8635ee7504e780d3184e45d0","https://git.kernel.org/stable/c/a78dfe50fffe6058afed2bb04c50c2c9a16664ee","https://git.kernel.org/stable/c/b1049f2d68693c80a576c4578d96774a68df2bad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1\n\ncommit 9d26d3a8f1b0 (\"PCI: Put PCIe ports into D3 during suspend\") sets the\npolicy that all PCIe ports are allowed to use D3.  When the system is\nsuspended if the port is not power manageable by the platform and won't be\nused for wakeup via a PME this sets up the policy for these ports to go\ninto D3hot.\n\nThis policy generally makes sense from an OSPM perspective but it leads to\nproblems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a\nspecific old BIOS. This manifests as a system hang.\n\nOn the affected Device + BIOS combination, add a quirk for the root port of\nthe problematic controller to ensure that these root ports are not put into\nD3hot at suspend.\n\nThis patch is based on\n\n  https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com\n\nbut with the added condition both in the documentation and in the code to\napply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only\nthe affected root ports.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21831","epss":0.00178,"percentile":0.0748,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21831","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21836","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21836","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  io_uring/kbuf: reallocate buf lists on upgrade  IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement that most of the field should stay stable after publish. Always reallocate it instead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21836","epss":0.00247,"percentile":0.15973,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12967499999999998},"relatedVulnerabilities":[{"id":"CVE-2025-21836","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21836","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/146a185f6c05ee263db715f860620606303c4633","https://git.kernel.org/stable/c/2a5febbef40ce968e295a7aeaa5d5cbd9e3e5ad4","https://git.kernel.org/stable/c/7d0dc28dae836caf7645fef62a10befc624dd17b","https://git.kernel.org/stable/c/8802766324e1f5d414a81ac43365c20142e85603","https://u1f383.github.io/slides/talks/2025_Hexacon-Deja_Vu_in_Linux_io_uring_Breaking_Memory_Sharing_Again_After_Generations_of_Fixes.pdf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/kbuf: reallocate buf lists on upgrade\n\nIORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it\nwas created for legacy selected buffer and has been emptied. It violates\nthe requirement that most of the field should stay stable after publish.\nAlways reallocate it instead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21836","epss":0.00247,"percentile":0.15973,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21836","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21870","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21870","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers  Other, non DAI copier widgets could have the same  stream name (sname) as the ALH copier and in that case the copier->data is NULL, no alh_data is attached, which could lead to NULL pointer dereference. We could check for this NULL pointer in sof_ipc4_prepare_copier_module() and avoid the crash, but a similar loop in sof_ipc4_widget_setup_comp_dai() will miscalculate the ALH device count, causing broken audio.  The correct fix is to harden the matching logic by making sure that the 1. widget is a DAI widget - so dai = w->private is valid 2. the dai (and thus the copier) is ALH copier","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21870","epss":0.002,"percentile":0.09913,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21870","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10500000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-21870","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21870","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6fd60136d256b3b948333ebdb3835f41a95ab7ef","https://git.kernel.org/stable/c/87c8768a96092ce75cd47fe076db5080db7ac515","https://git.kernel.org/stable/c/93c6c2e5801aab09ef1ef99f248f3cd323c3f152"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers\n\nOther, non DAI copier widgets could have the same  stream name (sname) as\nthe ALH copier and in that case the copier->data is NULL, no alh_data is\nattached, which could lead to NULL pointer dereference.\nWe could check for this NULL pointer in sof_ipc4_prepare_copier_module()\nand avoid the crash, but a similar loop in sof_ipc4_widget_setup_comp_dai()\nwill miscalculate the ALH device count, causing broken audio.\n\nThe correct fix is to harden the matching logic by making sure that the\n1. widget is a DAI widget - so dai = w->private is valid\n2. the dai (and thus the copier) is ALH copier","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21870","epss":0.002,"percentile":0.09913,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21870","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21870","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21872","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21872","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  efi: Don't map the entire mokvar table to determine its size  Currently, when validating the mokvar table, we (re)map the entire table on each iteration of the loop, adding space as we discover new entries. If the table grows over a certain size, this fails due to limitations of early_memmap(), and we get a failure and traceback:    ------------[ cut here ]------------   WARNING: CPU: 0 PID: 0 at mm/early_ioremap.c:139 __early_ioremap+0xef/0x220   ...   Call Trace:    <TASK>    ? __early_ioremap+0xef/0x220    ? __warn.cold+0x93/0xfa    ? __early_ioremap+0xef/0x220    ? report_bug+0xff/0x140    ? early_fixup_exception+0x5d/0xb0    ? early_idt_handler_common+0x2f/0x3a    ? __early_ioremap+0xef/0x220    ? efi_mokvar_table_init+0xce/0x1d0    ? setup_arch+0x864/0xc10    ? start_kernel+0x6b/0xa10    ? x86_64_start_reservations+0x24/0x30    ? x86_64_start_kernel+0xed/0xf0    ? common_startup_64+0x13e/0x141    </TASK>   ---[ end trace 0000000000000000 ]---   mokvar: Failed to map EFI MOKvar config table pa=0x7c4c3000, size=265187.  Mapping the entire structure isn't actually necessary, as we don't ever need more than one entry header mapped at once.  Changes efi_mokvar_table_init() to only map each entry header, not the entire table, when determining the table size.  Since we're not mapping any data past the variable name, it also changes the code to enforce that each variable name is NUL terminated, rather than attempting to verify it in place.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21872","epss":0.00202,"percentile":0.10242,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10605},"relatedVulnerabilities":[{"id":"CVE-2025-21872","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21872","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2b90e7ace79774a3540ce569e000388f8d22c9e0","https://git.kernel.org/stable/c/46c0454ffb78ce9d3355a3cccac86383ea8ddd55","https://git.kernel.org/stable/c/65f4aebb8127708ba668dd938e83b8558abfc5cd","https://git.kernel.org/stable/c/97bd560b6cc4c26386a53b4881bf03e96f9ba03a","https://git.kernel.org/stable/c/ea3f0b362dfe4ef885ef812bfaf4088176422c91","https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nefi: Don't map the entire mokvar table to determine its size\n\nCurrently, when validating the mokvar table, we (re)map the entire table\non each iteration of the loop, adding space as we discover new entries.\nIf the table grows over a certain size, this fails due to limitations of\nearly_memmap(), and we get a failure and traceback:\n\n  ------------[ cut here ]------------\n  WARNING: CPU: 0 PID: 0 at mm/early_ioremap.c:139 __early_ioremap+0xef/0x220\n  ...\n  Call Trace:\n   <TASK>\n   ? __early_ioremap+0xef/0x220\n   ? __warn.cold+0x93/0xfa\n   ? __early_ioremap+0xef/0x220\n   ? report_bug+0xff/0x140\n   ? early_fixup_exception+0x5d/0xb0\n   ? early_idt_handler_common+0x2f/0x3a\n   ? __early_ioremap+0xef/0x220\n   ? efi_mokvar_table_init+0xce/0x1d0\n   ? setup_arch+0x864/0xc10\n   ? start_kernel+0x6b/0xa10\n   ? x86_64_start_reservations+0x24/0x30\n   ? x86_64_start_kernel+0xed/0xf0\n   ? common_startup_64+0x13e/0x141\n   </TASK>\n  ---[ end trace 0000000000000000 ]---\n  mokvar: Failed to map EFI MOKvar config table pa=0x7c4c3000, size=265187.\n\nMapping the entire structure isn't actually necessary, as we don't ever\nneed more than one entry header mapped at once.\n\nChanges efi_mokvar_table_init() to only map each entry header, not the\nentire table, when determining the table size.  Since we're not mapping\nany data past the variable name, it also changes the code to enforce\nthat each variable name is NUL terminated, rather than attempting to\nverify it in place.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21872","epss":0.00202,"percentile":0.10242,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21872","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21885","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21885","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/bnxt_re: Fix the page details for the srq created by kernel consumers  While using nvme target with use_srq on, below kernel panic is noticed.  [  549.698111] bnxt_en 0000:41:00.0 enp65s0np0: FEC autoneg off encoding: Clause 91 RS(544,514) [  566.393619] Oops: divide error: 0000 [#1] PREEMPT SMP NOPTI .. [  566.393799]  <TASK> [  566.393807]  ? __die_body+0x1a/0x60 [  566.393823]  ? die+0x38/0x60 [  566.393835]  ? do_trap+0xe4/0x110 [  566.393847]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [  566.393867]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [  566.393881]  ? do_error_trap+0x7c/0x120 [  566.393890]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [  566.393911]  ? exc_divide_error+0x34/0x50 [  566.393923]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [  566.393939]  ? asm_exc_divide_error+0x16/0x20 [  566.393966]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re] [  566.393997]  bnxt_qplib_create_srq+0xc9/0x340 [bnxt_re] [  566.394040]  bnxt_re_create_srq+0x335/0x3b0 [bnxt_re] [  566.394057]  ? srso_return_thunk+0x5/0x5f [  566.394068]  ? __init_swait_queue_head+0x4a/0x60 [  566.394090]  ib_create_srq_user+0xa7/0x150 [ib_core] [  566.394147]  nvmet_rdma_queue_connect+0x7d0/0xbe0 [nvmet_rdma] [  566.394174]  ? lock_release+0x22c/0x3f0 [  566.394187]  ? srso_return_thunk+0x5/0x5f  Page size and shift info is set only for the user space SRQs. Set page size and page shift for kernel space SRQs also.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21885","epss":0.00425,"percentile":0.35816,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.22312500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-21885","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21885","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2cf8e6b52aecb8fbb71c41fe5add3212814031a2","https://git.kernel.org/stable/c/722c3db62bf60cd23acbdc8c4f445bfedae4498e","https://git.kernel.org/stable/c/b66535356a4834a234f99e16a97eb51f2c6c5a7d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Fix the page details for the srq created by kernel consumers\n\nWhile using nvme target with use_srq on, below kernel panic is noticed.\n\n[  549.698111] bnxt_en 0000:41:00.0 enp65s0np0: FEC autoneg off encoding: Clause 91 RS(544,514)\n[  566.393619] Oops: divide error: 0000 [#1] PREEMPT SMP NOPTI\n..\n[  566.393799]  <TASK>\n[  566.393807]  ? __die_body+0x1a/0x60\n[  566.393823]  ? die+0x38/0x60\n[  566.393835]  ? do_trap+0xe4/0x110\n[  566.393847]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[  566.393867]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[  566.393881]  ? do_error_trap+0x7c/0x120\n[  566.393890]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[  566.393911]  ? exc_divide_error+0x34/0x50\n[  566.393923]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[  566.393939]  ? asm_exc_divide_error+0x16/0x20\n[  566.393966]  ? bnxt_qplib_alloc_init_hwq+0x1d4/0x580 [bnxt_re]\n[  566.393997]  bnxt_qplib_create_srq+0xc9/0x340 [bnxt_re]\n[  566.394040]  bnxt_re_create_srq+0x335/0x3b0 [bnxt_re]\n[  566.394057]  ? srso_return_thunk+0x5/0x5f\n[  566.394068]  ? __init_swait_queue_head+0x4a/0x60\n[  566.394090]  ib_create_srq_user+0xa7/0x150 [ib_core]\n[  566.394147]  nvmet_rdma_queue_connect+0x7d0/0xbe0 [nvmet_rdma]\n[  566.394174]  ? lock_release+0x22c/0x3f0\n[  566.394187]  ? srso_return_thunk+0x5/0x5f\n\nPage size and shift info is set only for the user space SRQs.\nSet page size and page shift for kernel space SRQs also.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21885","epss":0.00425,"percentile":0.35816,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21885","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21888","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21888","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx5: Fix a WARN during dereg_mr for DM type  Memory regions (MR) of type DM (device memory) do not have an associated umem.  In the __mlx5_ib_dereg_mr() -> mlx5_free_priv_descs() flow, the code incorrectly takes the wrong branch, attempting to call dma_unmap_single() on a DMA address that is not mapped.  This results in a WARN [1], as shown below.  The issue is resolved by properly accounting for the DM type and ensuring the correct branch is selected in mlx5_free_priv_descs().  [1] WARNING: CPU: 12 PID: 1346 at drivers/iommu/dma-iommu.c:1230 iommu_dma_unmap_page+0x79/0x90 Modules linked in: ip6table_mangle ip6table_nat ip6table_filter ip6_tables iptable_mangle xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry ovelay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm mlx5_ib ib_uverbs ib_core fuse mlx5_core CPU: 12 UID: 0 PID: 1346 Comm: ibv_rc_pingpong Not tainted 6.12.0-rc7+ #1631 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:iommu_dma_unmap_page+0x79/0x90 Code: 2b 49 3b 29 72 26 49 3b 69 08 73 20 4d 89 f0 44 89 e9 4c 89 e2 48 89 ee 48 89 df 5b 5d 41 5c 41 5d 41 5e 41 5f e9 07 b8 88 ff <0f> 0b 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc 66 0f 1f 44 00 RSP: 0018:ffffc90001913a10 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff88810194b0a8 RCX: 0000000000000000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001 RBP: ffff88810194b0a8 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000000 R13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000000 FS:  00007f537abdd740(0000) GS:ffff88885fb00000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f537aeb8000 CR3: 000000010c248001 CR4: 0000000000372eb0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> ? __warn+0x84/0x190 ? iommu_dma_unmap_page+0x79/0x90 ? report_bug+0xf8/0x1c0 ? handle_bug+0x55/0x90 ? exc_invalid_op+0x13/0x60 ? asm_exc_invalid_op+0x16/0x20 ? iommu_dma_unmap_page+0x79/0x90 dma_unmap_page_attrs+0xe6/0x290 mlx5_free_priv_descs+0xb0/0xe0 [mlx5_ib] __mlx5_ib_dereg_mr+0x37e/0x520 [mlx5_ib] ? _raw_spin_unlock_irq+0x24/0x40 ? wait_for_completion+0xfe/0x130 ? rdma_restrack_put+0x63/0xe0 [ib_core] ib_dereg_mr_user+0x5f/0x120 [ib_core] ? lock_release+0xc6/0x280 destroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs] uverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs] uobj_destroy+0x3f/0x70 [ib_uverbs] ib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs] ? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs] ? lock_acquire+0xc1/0x2f0 ? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs] ? ib_uverbs_ioctl+0x116/0x170 [ib_uverbs] ? lock_release+0xc6/0x280 ib_uverbs_ioctl+0xe7/0x170 [ib_uverbs] ? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs] __x64_sys_ioctl+0x1b0/0xa70 do_syscall_64+0x6b/0x140 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f537adaf17b Code: 0f 1e fa 48 8b 05 1d ad 0c 00 64 c7 00 26 00 00 00 48 c7 c0 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa b8 10 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d ed ac 0c 00 f7 d8 64 89 01 48 RSP: 002b:00007ffff218f0b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007ffff218f1d8 RCX: 00007f537adaf17b RDX: 00007ffff218f1c0 RSI: 00000000c0181b01 RDI: 0000000000000003 RBP: 00007ffff218f1a0 R08: 00007f537aa8d010 R09: 0000561ee2e4f270 R10: 00007f537aace3a8 R11: 0000000000000246 R12: 00007ffff218f190 R13: 000000000000001c R14: 0000561ee2e4d7c0 R15: 00007ffff218f450 </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21888","epss":0.00189,"percentile":0.08678,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09922500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-21888","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21888","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0bd34bdd468e93a779c403de3cf7d43ee633b3e0","https://git.kernel.org/stable/c/abc7b3f1f056d69a8f11d6dceecc0c9549ace770","https://git.kernel.org/stable/c/f1298cad47ae29828c5c5be77e733ccfcaef6a7f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix a WARN during dereg_mr for DM type\n\nMemory regions (MR) of type DM (device memory) do not have an associated\numem.\n\nIn the __mlx5_ib_dereg_mr() -> mlx5_free_priv_descs() flow, the code\nincorrectly takes the wrong branch, attempting to call\ndma_unmap_single() on a DMA address that is not mapped.\n\nThis results in a WARN [1], as shown below.\n\nThe issue is resolved by properly accounting for the DM type and\nensuring the correct branch is selected in mlx5_free_priv_descs().\n\n[1]\nWARNING: CPU: 12 PID: 1346 at drivers/iommu/dma-iommu.c:1230 iommu_dma_unmap_page+0x79/0x90\nModules linked in: ip6table_mangle ip6table_nat ip6table_filter ip6_tables iptable_mangle xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry ovelay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm mlx5_ib ib_uverbs ib_core fuse mlx5_core\nCPU: 12 UID: 0 PID: 1346 Comm: ibv_rc_pingpong Not tainted 6.12.0-rc7+ #1631\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:iommu_dma_unmap_page+0x79/0x90\nCode: 2b 49 3b 29 72 26 49 3b 69 08 73 20 4d 89 f0 44 89 e9 4c 89 e2 48 89 ee 48 89 df 5b 5d 41 5c 41 5d 41 5e 41 5f e9 07 b8 88 ff <0f> 0b 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc 66 0f 1f 44 00\nRSP: 0018:ffffc90001913a10 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff88810194b0a8 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000001\nRBP: ffff88810194b0a8 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000000\nR13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000000\nFS:  00007f537abdd740(0000) GS:ffff88885fb00000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f537aeb8000 CR3: 000000010c248001 CR4: 0000000000372eb0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n<TASK>\n? __warn+0x84/0x190\n? iommu_dma_unmap_page+0x79/0x90\n? report_bug+0xf8/0x1c0\n? handle_bug+0x55/0x90\n? exc_invalid_op+0x13/0x60\n? asm_exc_invalid_op+0x16/0x20\n? iommu_dma_unmap_page+0x79/0x90\ndma_unmap_page_attrs+0xe6/0x290\nmlx5_free_priv_descs+0xb0/0xe0 [mlx5_ib]\n__mlx5_ib_dereg_mr+0x37e/0x520 [mlx5_ib]\n? _raw_spin_unlock_irq+0x24/0x40\n? wait_for_completion+0xfe/0x130\n? rdma_restrack_put+0x63/0xe0 [ib_core]\nib_dereg_mr_user+0x5f/0x120 [ib_core]\n? lock_release+0xc6/0x280\ndestroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs]\nuverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs]\nuobj_destroy+0x3f/0x70 [ib_uverbs]\nib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs]\n? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs]\n? lock_acquire+0xc1/0x2f0\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n? ib_uverbs_ioctl+0x116/0x170 [ib_uverbs]\n? lock_release+0xc6/0x280\nib_uverbs_ioctl+0xe7/0x170 [ib_uverbs]\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n__x64_sys_ioctl+0x1b0/0xa70\ndo_syscall_64+0x6b/0x140\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f537adaf17b\nCode: 0f 1e fa 48 8b 05 1d ad 0c 00 64 c7 00 26 00 00 00 48 c7 c0 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa b8 10 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d ed ac 0c 00 f7 d8 64 89 01 48\nRSP: 002b:00007ffff218f0b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007ffff218f1d8 RCX: 00007f537adaf17b\nRDX: 00007ffff218f1c0 RSI: 00000000c0181b01 RDI: 0000000000000003\nRBP: 00007ffff218f1a0 R08: 00007f537aa8d010 R09: 0000561ee2e4f270\nR10: 00007f537aace3a8 R11: 0000000000000246 R12: 00007ffff218f190\nR13: 000000000000001c R14: 0000561ee2e4d7c0 R15: 00007ffff218f450\n</TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21888","epss":0.00189,"percentile":0.08678,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21888","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21892","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21892","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx5: Fix the recovery flow of the UMR QP  This patch addresses an issue in the recovery flow of the UMR QP, ensuring tasks do not get stuck, as highlighted by the call trace [1].  During recovery, before transitioning the QP to the RESET state, the software must wait for all outstanding WRs to complete.  Failing to do so can cause the firmware to skip sending some flushed CQEs with errors and simply discard them upon the RESET, as per the IB specification.  This race condition can result in lost CQEs and tasks becoming stuck.  To resolve this, the patch sends a final WR which serves only as a barrier before moving the QP state to RESET.  Once a CQE is received for that final WR, it guarantees that no outstanding WRs remain, making it safe to transition the QP to RESET and subsequently back to RTS, restoring proper functionality.  Note: For the barrier WR, we simply reuse the failed and ready WR. Since the QP is in an error state, it will only receive IB_WC_WR_FLUSH_ERR. However, as it serves only as a barrier we don't care about its status.  [1] INFO: task rdma_resource_l:1922 blocked for more than 120 seconds. Tainted: G        W          6.12.0-rc7+ #1626 \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message. task:rdma_resource_l state:D stack:0  pid:1922 tgid:1922  ppid:1369      flags:0x00004004 Call Trace: <TASK> __schedule+0x420/0xd30 schedule+0x47/0x130 schedule_timeout+0x280/0x300 ? mark_held_locks+0x48/0x80 ? lockdep_hardirqs_on_prepare+0xe5/0x1a0 wait_for_completion+0x75/0x130 mlx5r_umr_post_send_wait+0x3c2/0x5b0 [mlx5_ib] ? __pfx_mlx5r_umr_done+0x10/0x10 [mlx5_ib] mlx5r_umr_revoke_mr+0x93/0xc0 [mlx5_ib] __mlx5_ib_dereg_mr+0x299/0x520 [mlx5_ib] ? _raw_spin_unlock_irq+0x24/0x40 ? wait_for_completion+0xfe/0x130 ? rdma_restrack_put+0x63/0xe0 [ib_core] ib_dereg_mr_user+0x5f/0x120 [ib_core] ? lock_release+0xc6/0x280 destroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs] uverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs] uobj_destroy+0x3f/0x70 [ib_uverbs] ib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs] ? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs] ? __lock_acquire+0x64e/0x2080 ? mark_held_locks+0x48/0x80 ? find_held_lock+0x2d/0xa0 ? lock_acquire+0xc1/0x2f0 ? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs] ? __fget_files+0xc3/0x1b0 ib_uverbs_ioctl+0xe7/0x170 [ib_uverbs] ? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs] __x64_sys_ioctl+0x1b0/0xa70 do_syscall_64+0x6b/0x140 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7f99c918b17b RSP: 002b:00007ffc766d0468 EFLAGS: 00000246 ORIG_RAX:      0000000000000010 RAX: ffffffffffffffda RBX: 00007ffc766d0578 RCX:      00007f99c918b17b RDX: 00007ffc766d0560 RSI: 00000000c0181b01 RDI:      0000000000000003 RBP: 00007ffc766d0540 R08: 00007f99c8f99010 R09:      000000000000bd7e R10: 00007f99c94c1c70 R11: 0000000000000246 R12:      00007ffc766d0530 R13: 000000000000001c R14: 0000000040246a80 R15:      0000000000000000 </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21892","epss":0.00135,"percentile":0.0333,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21892","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.065475},"relatedVulnerabilities":[{"id":"CVE-2025-21892","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21892","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1d2b84d8d054313deed2b2fcafe1168bbcb9e99f","https://git.kernel.org/stable/c/3e3bf255992cc02404e9d209b127c1c9944239cf","https://git.kernel.org/stable/c/d97505baea64d93538b16baf14ce7b8c1fbad746"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix the recovery flow of the UMR QP\n\nThis patch addresses an issue in the recovery flow of the UMR QP,\nensuring tasks do not get stuck, as highlighted by the call trace [1].\n\nDuring recovery, before transitioning the QP to the RESET state, the\nsoftware must wait for all outstanding WRs to complete.\n\nFailing to do so can cause the firmware to skip sending some flushed\nCQEs with errors and simply discard them upon the RESET, as per the IB\nspecification.\n\nThis race condition can result in lost CQEs and tasks becoming stuck.\n\nTo resolve this, the patch sends a final WR which serves only as a\nbarrier before moving the QP state to RESET.\n\nOnce a CQE is received for that final WR, it guarantees that no\noutstanding WRs remain, making it safe to transition the QP to RESET and\nsubsequently back to RTS, restoring proper functionality.\n\nNote:\nFor the barrier WR, we simply reuse the failed and ready WR.\nSince the QP is in an error state, it will only receive\nIB_WC_WR_FLUSH_ERR. However, as it serves only as a barrier we don't\ncare about its status.\n\n[1]\nINFO: task rdma_resource_l:1922 blocked for more than 120 seconds.\nTainted: G        W          6.12.0-rc7+ #1626\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:rdma_resource_l state:D stack:0  pid:1922 tgid:1922  ppid:1369\n     flags:0x00004004\nCall Trace:\n<TASK>\n__schedule+0x420/0xd30\nschedule+0x47/0x130\nschedule_timeout+0x280/0x300\n? mark_held_locks+0x48/0x80\n? lockdep_hardirqs_on_prepare+0xe5/0x1a0\nwait_for_completion+0x75/0x130\nmlx5r_umr_post_send_wait+0x3c2/0x5b0 [mlx5_ib]\n? __pfx_mlx5r_umr_done+0x10/0x10 [mlx5_ib]\nmlx5r_umr_revoke_mr+0x93/0xc0 [mlx5_ib]\n__mlx5_ib_dereg_mr+0x299/0x520 [mlx5_ib]\n? _raw_spin_unlock_irq+0x24/0x40\n? wait_for_completion+0xfe/0x130\n? rdma_restrack_put+0x63/0xe0 [ib_core]\nib_dereg_mr_user+0x5f/0x120 [ib_core]\n? lock_release+0xc6/0x280\ndestroy_hw_idr_uobject+0x1d/0x60 [ib_uverbs]\nuverbs_destroy_uobject+0x58/0x1d0 [ib_uverbs]\nuobj_destroy+0x3f/0x70 [ib_uverbs]\nib_uverbs_cmd_verbs+0x3e4/0xbb0 [ib_uverbs]\n? __pfx_uverbs_destroy_def_handler+0x10/0x10 [ib_uverbs]\n? __lock_acquire+0x64e/0x2080\n? mark_held_locks+0x48/0x80\n? find_held_lock+0x2d/0xa0\n? lock_acquire+0xc1/0x2f0\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n? __fget_files+0xc3/0x1b0\nib_uverbs_ioctl+0xe7/0x170 [ib_uverbs]\n? ib_uverbs_ioctl+0xcb/0x170 [ib_uverbs]\n__x64_sys_ioctl+0x1b0/0xa70\ndo_syscall_64+0x6b/0x140\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f99c918b17b\nRSP: 002b:00007ffc766d0468 EFLAGS: 00000246 ORIG_RAX:\n     0000000000000010\nRAX: ffffffffffffffda RBX: 00007ffc766d0578 RCX:\n     00007f99c918b17b\nRDX: 00007ffc766d0560 RSI: 00000000c0181b01 RDI:\n     0000000000000003\nRBP: 00007ffc766d0540 R08: 00007f99c8f99010 R09:\n     000000000000bd7e\nR10: 00007f99c94c1c70 R11: 0000000000000246 R12:\n     00007ffc766d0530\nR13: 000000000000001c R14: 0000000040246a80 R15:\n     0000000000000000\n</TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21892","epss":0.00135,"percentile":0.0333,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21892","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21892","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21894","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21894","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC  Actually ENETC VFs do not support HWTSTAMP_TX_ONESTEP_SYNC because only ENETC PF can access PMa_SINGLE_STEP registers. And there will be a crash if VFs are used to test one-step timestamp, the crash log as follows.  [  129.110909] Unable to handle kernel paging request at virtual address 00000000000080c0 [  129.287769] Call trace: [  129.290219]  enetc_port_mac_wr+0x30/0xec (P) [  129.294504]  enetc_start_xmit+0xda4/0xe74 [  129.298525]  enetc_xmit+0x70/0xec [  129.301848]  dev_hard_start_xmit+0x98/0x118","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21894","epss":0.00203,"percentile":0.10314,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2025-21894","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21894","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1748531839298ab7be682155f6cd98ae04773e6a","https://git.kernel.org/stable/c/3d9634211121700568d0e3635ebdd5df06d20440","https://git.kernel.org/stable/c/8c393efd7420cc994864d059fcc6219bfd7cb840","https://git.kernel.org/stable/c/a562d0c4a893eae3ea51d512c4d90ab858a6b7ec"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC\n\nActually ENETC VFs do not support HWTSTAMP_TX_ONESTEP_SYNC because only\nENETC PF can access PMa_SINGLE_STEP registers. And there will be a crash\nif VFs are used to test one-step timestamp, the crash log as follows.\n\n[  129.110909] Unable to handle kernel paging request at virtual address 00000000000080c0\n[  129.287769] Call trace:\n[  129.290219]  enetc_port_mac_wr+0x30/0xec (P)\n[  129.294504]  enetc_start_xmit+0xda4/0xe74\n[  129.298525]  enetc_xmit+0x70/0xec\n[  129.301848]  dev_hard_start_xmit+0x98/0x118","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21894","epss":0.00203,"percentile":0.10314,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21894","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21907","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21907","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm: memory-failure: update ttu flag inside unmap_poisoned_folio  Patch series \"mm: memory_failure: unmap poisoned folio during migrate properly\", v3.  Fix two bugs during folio migration if the folio is poisoned.   This patch (of 3):  Commit 6da6b1d4a7df (\"mm/hwpoison: convert TTU_IGNORE_HWPOISON to TTU_HWPOISON\") introduce TTU_HWPOISON to replace TTU_IGNORE_HWPOISON in order to stop send SIGBUS signal when accessing an error page after a memory error on a clean folio.  However during page migration, anon folio must be set with TTU_HWPOISON during unmap_*().  For pagecache we need some policy just like the one in hwpoison_user_mappings to set this flag.  So move this policy from hwpoison_user_mappings to unmap_poisoned_folio to handle this warning properly.  Warning will be produced during unamp poison folio with the following log:    ------------[ cut here ]------------   WARNING: CPU: 1 PID: 365 at mm/rmap.c:1847 try_to_unmap_one+0x8fc/0xd3c   Modules linked in:   CPU: 1 UID: 0 PID: 365 Comm: bash Tainted: G        W          6.13.0-rc1-00018-gacdb4bbda7ab #42   Tainted: [W]=WARN   Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015   pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)   pc : try_to_unmap_one+0x8fc/0xd3c   lr : try_to_unmap_one+0x3dc/0xd3c   Call trace:    try_to_unmap_one+0x8fc/0xd3c (P)    try_to_unmap_one+0x3dc/0xd3c (L)    rmap_walk_anon+0xdc/0x1f8    rmap_walk+0x3c/0x58    try_to_unmap+0x88/0x90    unmap_poisoned_folio+0x30/0xa8    do_migrate_range+0x4a0/0x568    offline_pages+0x5a4/0x670    memory_block_action+0x17c/0x374    memory_subsys_offline+0x3c/0x78    device_offline+0xa4/0xd0    state_store+0x8c/0xf0    dev_attr_store+0x18/0x2c    sysfs_kf_write+0x44/0x54    kernfs_fop_write_iter+0x118/0x1a8    vfs_write+0x3a8/0x4bc    ksys_write+0x6c/0xf8    __arm64_sys_write+0x1c/0x28    invoke_syscall+0x44/0x100    el0_svc_common.constprop.0+0x40/0xe0    do_el0_svc+0x1c/0x28    el0_svc+0x30/0xd0    el0t_64_sync_handler+0xc8/0xcc    el0t_64_sync+0x198/0x19c   ---[ end trace 0000000000000000 ]---  [mawupeng1@huawei.com: unmap_poisoned_folio(): remove shadowed local `mapping', per Miaohe]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21907","epss":0.00199,"percentile":0.09844,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10447500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-21907","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21907","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/425c12c076e6fc6b2cb04b9f960319d31dcabc76","https://git.kernel.org/stable/c/608cc7deb428f1122ed426060233622ebf667b6e","https://git.kernel.org/stable/c/b81679b1633aa43c0d973adfa816d78c1ed0d032"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: memory-failure: update ttu flag inside unmap_poisoned_folio\n\nPatch series \"mm: memory_failure: unmap poisoned folio during migrate\nproperly\", v3.\n\nFix two bugs during folio migration if the folio is poisoned.\n\n\nThis patch (of 3):\n\nCommit 6da6b1d4a7df (\"mm/hwpoison: convert TTU_IGNORE_HWPOISON to\nTTU_HWPOISON\") introduce TTU_HWPOISON to replace TTU_IGNORE_HWPOISON in\norder to stop send SIGBUS signal when accessing an error page after a\nmemory error on a clean folio.  However during page migration, anon folio\nmust be set with TTU_HWPOISON during unmap_*().  For pagecache we need\nsome policy just like the one in hwpoison_user_mappings to set this flag. \nSo move this policy from hwpoison_user_mappings to unmap_poisoned_folio to\nhandle this warning properly.\n\nWarning will be produced during unamp poison folio with the following log:\n\n  ------------[ cut here ]------------\n  WARNING: CPU: 1 PID: 365 at mm/rmap.c:1847 try_to_unmap_one+0x8fc/0xd3c\n  Modules linked in:\n  CPU: 1 UID: 0 PID: 365 Comm: bash Tainted: G        W          6.13.0-rc1-00018-gacdb4bbda7ab #42\n  Tainted: [W]=WARN\n  Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n  pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n  pc : try_to_unmap_one+0x8fc/0xd3c\n  lr : try_to_unmap_one+0x3dc/0xd3c\n  Call trace:\n   try_to_unmap_one+0x8fc/0xd3c (P)\n   try_to_unmap_one+0x3dc/0xd3c (L)\n   rmap_walk_anon+0xdc/0x1f8\n   rmap_walk+0x3c/0x58\n   try_to_unmap+0x88/0x90\n   unmap_poisoned_folio+0x30/0xa8\n   do_migrate_range+0x4a0/0x568\n   offline_pages+0x5a4/0x670\n   memory_block_action+0x17c/0x374\n   memory_subsys_offline+0x3c/0x78\n   device_offline+0xa4/0xd0\n   state_store+0x8c/0xf0\n   dev_attr_store+0x18/0x2c\n   sysfs_kf_write+0x44/0x54\n   kernfs_fop_write_iter+0x118/0x1a8\n   vfs_write+0x3a8/0x4bc\n   ksys_write+0x6c/0xf8\n   __arm64_sys_write+0x1c/0x28\n   invoke_syscall+0x44/0x100\n   el0_svc_common.constprop.0+0x40/0xe0\n   do_el0_svc+0x1c/0x28\n   el0_svc+0x30/0xd0\n   el0t_64_sync_handler+0xc8/0xcc\n   el0t_64_sync+0x198/0x19c\n  ---[ end trace 0000000000000000 ]---\n\n[mawupeng1@huawei.com: unmap_poisoned_folio(): remove shadowed local `mapping', per Miaohe]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21907","epss":0.00199,"percentile":0.09844,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21907","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21927","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21927","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()  nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, a target might send a packet with an invalid header length (e.g. 255), causing nvme_tcp_verify_hdgst() to access memory outside the allocated area and cause memory corruptions by overwriting it with the calculated digest.  Fix this by rejecting packets with an unexpected header length.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21927","epss":0.00482,"percentile":0.40039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21927","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21927","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.36872999999999995},"relatedVulnerabilities":[{"id":"CVE-2025-21927","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21927","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/22b06c89aa6b2d1ecb8aea72edfb9d53af8d5126","https://git.kernel.org/stable/c/9fbc953d6b38bc824392e01850f0aeee3b348722","https://git.kernel.org/stable/c/ad95bab0cd28ed77c2c0d0b6e76e03e031391064"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()\n\nnvme_tcp_recv_pdu() doesn't check the validity of the header length.\nWhen header digests are enabled, a target might send a packet with an\ninvalid header length (e.g. 255), causing nvme_tcp_verify_hdgst()\nto access memory outside the allocated area and cause memory corruptions\nby overwriting it with the calculated digest.\n\nFix this by rejecting packets with an unexpected header length.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21927","epss":0.00482,"percentile":0.40039,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21927","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21927","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21927","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21949","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21949","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Set hugetlb mmap base address aligned with pmd size  With ltp test case \"testcases/bin/hugefork02\", there is a dmesg error report message such as:   kernel BUG at mm/hugetlb.c:5550!  Oops - BUG[#1]:  CPU: 0 UID: 0 PID: 1517 Comm: hugefork02 Not tainted 6.14.0-rc2+ #241  Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022  pc 90000000004eaf1c ra 9000000000485538 tp 900000010edbc000 sp 900000010edbf940  a0 900000010edbfb00 a1 9000000108d20280 a2 00007fffe9474000 a3 00007ffff3474000  a4 0000000000000000 a5 0000000000000003 a6 00000000003cadd3 a7 0000000000000000  t0 0000000001ffffff t1 0000000001474000 t2 900000010ecd7900 t3 00007fffe9474000  t4 00007fffe9474000 t5 0000000000000040 t6 900000010edbfb00 t7 0000000000000001  t8 0000000000000005 u0 90000000004849d0 s9 900000010edbfa00 s0 9000000108d20280  s1 00007fffe9474000 s2 0000000002000000 s3 9000000108d20280 s4 9000000002b38b10  s5 900000010edbfb00 s6 00007ffff3474000 s7 0000000000000406 s8 900000010edbfa08     ra: 9000000000485538 unmap_vmas+0x130/0x218    ERA: 90000000004eaf1c __unmap_hugepage_range+0x6f4/0x7d0   PRMD: 00000004 (PPLV0 +PIE -PWE)   EUEN: 00000007 (+FPE +SXE +ASXE -BTE)   ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)  ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0)  PRID: 0014c010 (Loongson-64bit, Loongson-3A5000)  Process hugefork02 (pid: 1517, threadinfo=00000000a670eaf4, task=000000007a95fc64)  Call Trace:  [<90000000004eaf1c>] __unmap_hugepage_range+0x6f4/0x7d0  [<9000000000485534>] unmap_vmas+0x12c/0x218  [<9000000000494068>] exit_mmap+0xe0/0x308  [<900000000025fdc4>] mmput+0x74/0x180  [<900000000026a284>] do_exit+0x294/0x898  [<900000000026aa30>] do_group_exit+0x30/0x98  [<900000000027bed4>] get_signal+0x83c/0x868  [<90000000002457b4>] arch_do_signal_or_restart+0x54/0xfa0  [<90000000015795e8>] irqentry_exit_to_user_mode+0xb8/0x138  [<90000000002572d0>] tlb_do_page_fault_1+0x114/0x1b4  The problem is that base address allocated from hugetlbfs is not aligned with pmd size. Here add a checking for hugetlbfs and align base address with pmd size. After this patch the test case \"testcases/bin/hugefork02\" passes to run.  This is similar to the commit 7f24cbc9c4d42db8a3c8484d1 (\"mm/mmap: teach generic_get_unmapped_area{_topdown} to handle hugetlb mappings\").","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21949","epss":0.0018,"percentile":0.07701,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2025-21949","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21949","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/242b34f48a377afe4b285b472bd0f17744fca8e8","https://git.kernel.org/stable/c/3109d5ff484b7bc7b955f166974c6776d91f247b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Set hugetlb mmap base address aligned with pmd size\n\nWith ltp test case \"testcases/bin/hugefork02\", there is a dmesg error\nreport message such as:\n\n kernel BUG at mm/hugetlb.c:5550!\n Oops - BUG[#1]:\n CPU: 0 UID: 0 PID: 1517 Comm: hugefork02 Not tainted 6.14.0-rc2+ #241\n Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022\n pc 90000000004eaf1c ra 9000000000485538 tp 900000010edbc000 sp 900000010edbf940\n a0 900000010edbfb00 a1 9000000108d20280 a2 00007fffe9474000 a3 00007ffff3474000\n a4 0000000000000000 a5 0000000000000003 a6 00000000003cadd3 a7 0000000000000000\n t0 0000000001ffffff t1 0000000001474000 t2 900000010ecd7900 t3 00007fffe9474000\n t4 00007fffe9474000 t5 0000000000000040 t6 900000010edbfb00 t7 0000000000000001\n t8 0000000000000005 u0 90000000004849d0 s9 900000010edbfa00 s0 9000000108d20280\n s1 00007fffe9474000 s2 0000000002000000 s3 9000000108d20280 s4 9000000002b38b10\n s5 900000010edbfb00 s6 00007ffff3474000 s7 0000000000000406 s8 900000010edbfa08\n    ra: 9000000000485538 unmap_vmas+0x130/0x218\n   ERA: 90000000004eaf1c __unmap_hugepage_range+0x6f4/0x7d0\n  PRMD: 00000004 (PPLV0 +PIE -PWE)\n  EUEN: 00000007 (+FPE +SXE +ASXE -BTE)\n  ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)\n ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0)\n PRID: 0014c010 (Loongson-64bit, Loongson-3A5000)\n Process hugefork02 (pid: 1517, threadinfo=00000000a670eaf4, task=000000007a95fc64)\n Call Trace:\n [<90000000004eaf1c>] __unmap_hugepage_range+0x6f4/0x7d0\n [<9000000000485534>] unmap_vmas+0x12c/0x218\n [<9000000000494068>] exit_mmap+0xe0/0x308\n [<900000000025fdc4>] mmput+0x74/0x180\n [<900000000026a284>] do_exit+0x294/0x898\n [<900000000026aa30>] do_group_exit+0x30/0x98\n [<900000000027bed4>] get_signal+0x83c/0x868\n [<90000000002457b4>] arch_do_signal_or_restart+0x54/0xfa0\n [<90000000015795e8>] irqentry_exit_to_user_mode+0xb8/0x138\n [<90000000002572d0>] tlb_do_page_fault_1+0x114/0x1b4\n\nThe problem is that base address allocated from hugetlbfs is not aligned\nwith pmd size. Here add a checking for hugetlbfs and align base address\nwith pmd size. After this patch the test case \"testcases/bin/hugefork02\"\npasses to run.\n\nThis is similar to the commit 7f24cbc9c4d42db8a3c8484d1 (\"mm/mmap: teach\ngeneric_get_unmapped_area{_topdown} to handle hugetlb mappings\").","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21949","epss":0.0018,"percentile":0.07701,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21949","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21955","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21955","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: prevent connection release during oplock break notification  ksmbd_work could be freed when after connection release. Increment r_count of ksmbd_conn to indicate that requests are not finished yet and to not release the connection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21955","epss":0.00483,"percentile":0.40075,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25357500000000005},"relatedVulnerabilities":[{"id":"CVE-2025-21955","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21955","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/09aeab68033161cb54f194da93e51a11aee6144b","https://git.kernel.org/stable/c/3aa660c059240e0c795217182cf7df32909dd917","https://git.kernel.org/stable/c/a4261bbc33fbf99b99c80aa3a2c5097611802980","https://git.kernel.org/stable/c/f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent connection release during oplock break notification\n\nksmbd_work could be freed when after connection release.\nIncrement r_count of ksmbd_conn to indicate that requests\nare not finished yet and to not release the connection.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21955","epss":0.00483,"percentile":0.40075,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21955","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21961","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  eth: bnxt: fix truesize for mb-xdp-pass case  When mb-xdp is set and return is XDP_PASS, packet is converted from xdp_buff to sk_buff with xdp_update_skb_shared_info() in bnxt_xdp_build_skb(). bnxt_xdp_build_skb() passes incorrect truesize argument to xdp_update_skb_shared_info(). The truesize is calculated as BNXT_RX_PAGE_SIZE * sinfo->nr_frags but the skb_shared_info was wiped by napi_build_skb() before. So it stores sinfo->nr_frags before bnxt_xdp_build_skb() and use it instead of getting skb_shared_info from xdp_get_shared_info_from_buff().  Splat looks like:  ------------[ cut here ]------------  WARNING: CPU: 2 PID: 0 at net/core/skbuff.c:6072 skb_try_coalesce+0x504/0x590  Modules linked in: xt_nat xt_tcpudp veth af_packet xt_conntrack nft_chain_nat xt_MASQUERADE nf_conntrack_netlink xfrm_user xt_addrtype nft_coms  CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.14.0-rc2+ #3  RIP: 0010:skb_try_coalesce+0x504/0x590  Code: 4b fd ff ff 49 8b 34 24 40 80 e6 40 0f 84 3d fd ff ff 49 8b 74 24 48 40 f6 c6 01 0f 84 2e fd ff ff 48 8d 4e ff e9 25 fd ff ff <0f> 0b e99  RSP: 0018:ffffb62c4120caa8 EFLAGS: 00010287  RAX: 0000000000000003 RBX: ffffb62c4120cb14 RCX: 0000000000000ec0  RDX: 0000000000001000 RSI: ffffa06e5d7dc000 RDI: 0000000000000003  RBP: ffffa06e5d7ddec0 R08: ffffa06e6120a800 R09: ffffa06e7a119900  R10: 0000000000002310 R11: ffffa06e5d7dcec0 R12: ffffe4360575f740  R13: ffffe43600000000 R14: 0000000000000002 R15: 0000000000000002  FS:  0000000000000000(0000) GS:ffffa0755f700000(0000) knlGS:0000000000000000  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033  CR2: 00007f147b76b0f8 CR3: 00000001615d4000 CR4: 00000000007506f0  PKRU: 55555554  Call Trace:   <IRQ>   ? __warn+0x84/0x130   ? skb_try_coalesce+0x504/0x590   ? report_bug+0x18a/0x1a0   ? handle_bug+0x53/0x90   ? exc_invalid_op+0x14/0x70   ? asm_exc_invalid_op+0x16/0x20   ? skb_try_coalesce+0x504/0x590   inet_frag_reasm_finish+0x11f/0x2e0   ip_defrag+0x37a/0x900   ip_local_deliver+0x51/0x120   ip_sublist_rcv_finish+0x64/0x70   ip_sublist_rcv+0x179/0x210   ip_list_rcv+0xf9/0x130  How to reproduce: <Node A> ip link set $interface1 xdp obj xdp_pass.o ip link set $interface1 mtu 9000 up ip a a 10.0.0.1/24 dev $interface1 <Node B> ip link set $interfac2 mtu 9000 up ip a a 10.0.0.2/24 dev $interface2 ping 10.0.0.1 -s 65000  Following ping.py patch adds xdp-mb-pass case. so ping.py is going to be able to reproduce this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21961","epss":0.00462,"percentile":0.38644,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24255000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-21961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21961","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/19107e71be330dbccb9f8f9f4cf0a9abeadad802","https://git.kernel.org/stable/c/9f7b2aa5034e24d3c49db73d5f760c0435fe31c2","https://git.kernel.org/stable/c/b4679807c6083ade4d47f03f80da891afcb6ef62"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\neth: bnxt: fix truesize for mb-xdp-pass case\n\nWhen mb-xdp is set and return is XDP_PASS, packet is converted from\nxdp_buff to sk_buff with xdp_update_skb_shared_info() in\nbnxt_xdp_build_skb().\nbnxt_xdp_build_skb() passes incorrect truesize argument to\nxdp_update_skb_shared_info().\nThe truesize is calculated as BNXT_RX_PAGE_SIZE * sinfo->nr_frags but\nthe skb_shared_info was wiped by napi_build_skb() before.\nSo it stores sinfo->nr_frags before bnxt_xdp_build_skb() and use it\ninstead of getting skb_shared_info from xdp_get_shared_info_from_buff().\n\nSplat looks like:\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 0 at net/core/skbuff.c:6072 skb_try_coalesce+0x504/0x590\n Modules linked in: xt_nat xt_tcpudp veth af_packet xt_conntrack nft_chain_nat xt_MASQUERADE nf_conntrack_netlink xfrm_user xt_addrtype nft_coms\n CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.14.0-rc2+ #3\n RIP: 0010:skb_try_coalesce+0x504/0x590\n Code: 4b fd ff ff 49 8b 34 24 40 80 e6 40 0f 84 3d fd ff ff 49 8b 74 24 48 40 f6 c6 01 0f 84 2e fd ff ff 48 8d 4e ff e9 25 fd ff ff <0f> 0b e99\n RSP: 0018:ffffb62c4120caa8 EFLAGS: 00010287\n RAX: 0000000000000003 RBX: ffffb62c4120cb14 RCX: 0000000000000ec0\n RDX: 0000000000001000 RSI: ffffa06e5d7dc000 RDI: 0000000000000003\n RBP: ffffa06e5d7ddec0 R08: ffffa06e6120a800 R09: ffffa06e7a119900\n R10: 0000000000002310 R11: ffffa06e5d7dcec0 R12: ffffe4360575f740\n R13: ffffe43600000000 R14: 0000000000000002 R15: 0000000000000002\n FS:  0000000000000000(0000) GS:ffffa0755f700000(0000) knlGS:0000000000000000\n CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f147b76b0f8 CR3: 00000001615d4000 CR4: 00000000007506f0\n PKRU: 55555554\n Call Trace:\n  <IRQ>\n  ? __warn+0x84/0x130\n  ? skb_try_coalesce+0x504/0x590\n  ? report_bug+0x18a/0x1a0\n  ? handle_bug+0x53/0x90\n  ? exc_invalid_op+0x14/0x70\n  ? asm_exc_invalid_op+0x16/0x20\n  ? skb_try_coalesce+0x504/0x590\n  inet_frag_reasm_finish+0x11f/0x2e0\n  ip_defrag+0x37a/0x900\n  ip_local_deliver+0x51/0x120\n  ip_sublist_rcv_finish+0x64/0x70\n  ip_sublist_rcv+0x179/0x210\n  ip_list_rcv+0xf9/0x130\n\nHow to reproduce:\n<Node A>\nip link set $interface1 xdp obj xdp_pass.o\nip link set $interface1 mtu 9000 up\nip a a 10.0.0.1/24 dev $interface1\n<Node B>\nip link set $interfac2 mtu 9000 up\nip a a 10.0.0.2/24 dev $interface2\nping 10.0.0.1 -s 65000\n\nFollowing ping.py patch adds xdp-mb-pass case. so ping.py is going to be\nable to reproduce this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21961","epss":0.00462,"percentile":0.38644,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21967","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21967","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free in ksmbd_free_work_struct  ->interim_entry of ksmbd_work could be deleted after oplock is freed. We don't need to manage it with linked list. The interim request could be immediately sent whenever a oplock break wait is needed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21967","epss":0.00368,"percentile":0.30085,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21967","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21967","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28152000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-21967","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21967","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/62746ae3f5414244a96293e3b017be637b641280","https://git.kernel.org/stable/c/bb39ed47065455604729404729d9116868638d31","https://git.kernel.org/stable/c/eb51f6f59d19b92f6fe84d3873f958495ab32f0a","https://git.kernel.org/stable/c/fb776765bfc21d5e4ed03bb3d4406c2b86ff1ac3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in ksmbd_free_work_struct\n\n->interim_entry of ksmbd_work could be deleted after oplock is freed.\nWe don't need to manage it with linked list. The interim request could be\nimmediately sent whenever a oplock break wait is needed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21967","epss":0.00368,"percentile":0.30085,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21967","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21967","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21967","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21969","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21969","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd  After the hci sync command releases l2cap_conn, the hci receive data work queue references the released l2cap_conn when sending to the upper layer. Add hci dev lock to the hci receive data work queue to synchronize the two.  [1] BUG: KASAN: slab-use-after-free in l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954 Read of size 8 at addr ffff8880271a4000 by task kworker/u9:2/5837  CPU: 0 UID: 0 PID: 5837 Comm: kworker/u9:2 Not tainted 6.13.0-rc5-syzkaller-00163-gab75170520d4 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: hci1 hci_rx_work Call Trace:  <TASK>  __dump_stack lib/dump_stack.c:94 [inline]  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:378 [inline]  print_report+0x169/0x550 mm/kasan/report.c:489  kasan_report+0x143/0x180 mm/kasan/report.c:602  l2cap_build_cmd net/bluetooth/l2cap_core.c:2964 [inline]  l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954  l2cap_sig_send_rej net/bluetooth/l2cap_core.c:5502 [inline]  l2cap_sig_channel net/bluetooth/l2cap_core.c:5538 [inline]  l2cap_recv_frame+0x221f/0x10db0 net/bluetooth/l2cap_core.c:6817  hci_acldata_packet net/bluetooth/hci_core.c:3797 [inline]  hci_rx_work+0x508/0xdb0 net/bluetooth/hci_core.c:4040  process_one_work kernel/workqueue.c:3229 [inline]  process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310  worker_thread+0x870/0xd30 kernel/workqueue.c:3391  kthread+0x2f0/0x390 kernel/kthread.c:389  ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244  </TASK>  Allocated by task 5837:  kasan_save_stack mm/kasan/common.c:47 [inline]  kasan_save_track+0x3f/0x80 mm/kasan/common.c:68  poison_kmalloc_redzone mm/kasan/common.c:377 [inline]  __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394  kasan_kmalloc include/linux/kasan.h:260 [inline]  __kmalloc_cache_noprof+0x243/0x390 mm/slub.c:4329  kmalloc_noprof include/linux/slab.h:901 [inline]  kzalloc_noprof include/linux/slab.h:1037 [inline]  l2cap_conn_add+0xa9/0x8e0 net/bluetooth/l2cap_core.c:6860  l2cap_connect_cfm+0x115/0x1090 net/bluetooth/l2cap_core.c:7239  hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline]  hci_remote_features_evt+0x68e/0xac0 net/bluetooth/hci_event.c:3726  hci_event_func net/bluetooth/hci_event.c:7473 [inline]  hci_event_packet+0xac2/0x1540 net/bluetooth/hci_event.c:7525  hci_rx_work+0x3f3/0xdb0 net/bluetooth/hci_core.c:4035  process_one_work kernel/workqueue.c:3229 [inline]  process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310  worker_thread+0x870/0xd30 kernel/workqueue.c:3391  kthread+0x2f0/0x390 kernel/kthread.c:389  ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244  Freed by task 54:  kasan_save_stack mm/kasan/common.c:47 [inline]  kasan_save_track+0x3f/0x80 mm/kasan/common.c:68  kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:582  poison_slab_object mm/kasan/common.c:247 [inline]  __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264  kasan_slab_free include/linux/kasan.h:233 [inline]  slab_free_hook mm/slub.c:2353 [inline]  slab_free mm/slub.c:4613 [inline]  kfree+0x196/0x430 mm/slub.c:4761  l2cap_connect_cfm+0xcc/0x1090 net/bluetooth/l2cap_core.c:7235  hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline]  hci_conn_failed+0x287/0x400 net/bluetooth/hci_conn.c:1266  hci_abort_conn_sync+0x56c/0x11f0 net/bluetooth/hci_sync.c:5603  hci_cmd_sync_work+0x22b/0x400 net/bluetooth/hci_sync.c:332  process_one_work kernel/workqueue.c:3229 [inline]  process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310  worker_thread+0x870/0xd30 kernel/workqueue.c:3391  kthread+0x2f0/0x390 kernel/kthread.c:389  ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entr ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21969","epss":0.00226,"percentile":0.13219,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21969","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21969","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17289},"relatedVulnerabilities":[{"id":"CVE-2025-21969","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21969","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7790a79c6fce8d5d552bc64f5c82819f719e4f28","https://git.kernel.org/stable/c/b4f82f9ed43aefa79bec2504ae8c29be0c0f5d1d","https://git.kernel.org/stable/c/c96cce853542b3b13da3738f35ef1be8cfcc9d1d","https://git.kernel.org/stable/c/f8094625a591eeb0b75b1bd9e713fac1d93f5ca9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd\n\nAfter the hci sync command releases l2cap_conn, the hci receive data work\nqueue references the released l2cap_conn when sending to the upper layer.\nAdd hci dev lock to the hci receive data work queue to synchronize the two.\n\n[1]\nBUG: KASAN: slab-use-after-free in l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954\nRead of size 8 at addr ffff8880271a4000 by task kworker/u9:2/5837\n\nCPU: 0 UID: 0 PID: 5837 Comm: kworker/u9:2 Not tainted 6.13.0-rc5-syzkaller-00163-gab75170520d4 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: hci1 hci_rx_work\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:489\n kasan_report+0x143/0x180 mm/kasan/report.c:602\n l2cap_build_cmd net/bluetooth/l2cap_core.c:2964 [inline]\n l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954\n l2cap_sig_send_rej net/bluetooth/l2cap_core.c:5502 [inline]\n l2cap_sig_channel net/bluetooth/l2cap_core.c:5538 [inline]\n l2cap_recv_frame+0x221f/0x10db0 net/bluetooth/l2cap_core.c:6817\n hci_acldata_packet net/bluetooth/hci_core.c:3797 [inline]\n hci_rx_work+0x508/0xdb0 net/bluetooth/hci_core.c:4040\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n </TASK>\n\nAllocated by task 5837:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x243/0x390 mm/slub.c:4329\n kmalloc_noprof include/linux/slab.h:901 [inline]\n kzalloc_noprof include/linux/slab.h:1037 [inline]\n l2cap_conn_add+0xa9/0x8e0 net/bluetooth/l2cap_core.c:6860\n l2cap_connect_cfm+0x115/0x1090 net/bluetooth/l2cap_core.c:7239\n hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline]\n hci_remote_features_evt+0x68e/0xac0 net/bluetooth/hci_event.c:3726\n hci_event_func net/bluetooth/hci_event.c:7473 [inline]\n hci_event_packet+0xac2/0x1540 net/bluetooth/hci_event.c:7525\n hci_rx_work+0x3f3/0xdb0 net/bluetooth/hci_core.c:4035\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nFreed by task 54:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:582\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline]\n slab_free_hook mm/slub.c:2353 [inline]\n slab_free mm/slub.c:4613 [inline]\n kfree+0x196/0x430 mm/slub.c:4761\n l2cap_connect_cfm+0xcc/0x1090 net/bluetooth/l2cap_core.c:7235\n hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline]\n hci_conn_failed+0x287/0x400 net/bluetooth/hci_conn.c:1266\n hci_abort_conn_sync+0x56c/0x11f0 net/bluetooth/hci_sync.c:5603\n hci_cmd_sync_work+0x22b/0x400 net/bluetooth/hci_sync.c:332\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entr\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21969","epss":0.00226,"percentile":0.13219,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21969","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-21969","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21969","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21972","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21972","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: mctp: unshare packets when reassembling  Ensure that the frag_list used for reassembly isn't shared with other packets. This avoids incorrect reassembly when packets are cloned, and prevents a memory leak due to circular references between fragments and their skb_shared_info.  The upcoming MCTP-over-USB driver uses skb_clone which can trigger the problem - other MCTP drivers don't share SKBs.  A kunit test is added to reproduce the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21972","epss":0.00229,"percentile":0.13676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21972","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.120225},"relatedVulnerabilities":[{"id":"CVE-2025-21972","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21972","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5c47d5bfa7b096cf8890afac32141c578583f8e0","https://git.kernel.org/stable/c/f44fff3d3c6cd67b6f348b821d73c4d6888c7a6e","https://git.kernel.org/stable/c/f5d83cf0eeb90fade4d5c4d17d24b8bee9ceeecc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: unshare packets when reassembling\n\nEnsure that the frag_list used for reassembly isn't shared with other\npackets. This avoids incorrect reassembly when packets are cloned, and\nprevents a memory leak due to circular references between fragments and\ntheir skb_shared_info.\n\nThe upcoming MCTP-over-USB driver uses skb_clone which can trigger the\nproblem - other MCTP drivers don't share SKBs.\n\nA kunit test is added to reproduce the issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21972","epss":0.00229,"percentile":0.13676,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21972","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21972","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21976","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21976","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: hyperv_fb: Allow graceful removal of framebuffer  When a Hyper-V framebuffer device is unbind, hyperv_fb driver tries to release the framebuffer forcefully. If this framebuffer is in use it produce the following WARN and hence this framebuffer is never released.  [   44.111220] WARNING: CPU: 35 PID: 1882 at drivers/video/fbdev/core/fb_info.c:70 framebuffer_release+0x2c/0x40 < snip > [   44.111289] Call Trace: [   44.111290]  <TASK> [   44.111291]  ? show_regs+0x6c/0x80 [   44.111295]  ? __warn+0x8d/0x150 [   44.111298]  ? framebuffer_release+0x2c/0x40 [   44.111300]  ? report_bug+0x182/0x1b0 [   44.111303]  ? handle_bug+0x6e/0xb0 [   44.111306]  ? exc_invalid_op+0x18/0x80 [   44.111308]  ? asm_exc_invalid_op+0x1b/0x20 [   44.111311]  ? framebuffer_release+0x2c/0x40 [   44.111313]  ? hvfb_remove+0x86/0xa0 [hyperv_fb] [   44.111315]  vmbus_remove+0x24/0x40 [hv_vmbus] [   44.111323]  device_remove+0x40/0x80 [   44.111325]  device_release_driver_internal+0x20b/0x270 [   44.111327]  ? bus_find_device+0xb3/0xf0  Fix this by moving the release of framebuffer and assosiated memory to fb_ops.fb_destroy function, so that framebuffer framework handles it gracefully.  While we fix this, also replace manual registrations/unregistration of framebuffer with devm_register_framebuffer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21976","epss":0.00196,"percentile":0.09412,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10289999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-21976","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21976","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4545e2aa121aea304d33903099c03e29ed4fe50a","https://git.kernel.org/stable/c/a7b583dc99c6cf4a96877017be1d08247e1ef2c7","https://git.kernel.org/stable/c/ea2f45ab0e53b255f72c85ccd99e2b394fc5fceb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: hyperv_fb: Allow graceful removal of framebuffer\n\nWhen a Hyper-V framebuffer device is unbind, hyperv_fb driver tries to\nrelease the framebuffer forcefully. If this framebuffer is in use it\nproduce the following WARN and hence this framebuffer is never released.\n\n[   44.111220] WARNING: CPU: 35 PID: 1882 at drivers/video/fbdev/core/fb_info.c:70 framebuffer_release+0x2c/0x40\n< snip >\n[   44.111289] Call Trace:\n[   44.111290]  <TASK>\n[   44.111291]  ? show_regs+0x6c/0x80\n[   44.111295]  ? __warn+0x8d/0x150\n[   44.111298]  ? framebuffer_release+0x2c/0x40\n[   44.111300]  ? report_bug+0x182/0x1b0\n[   44.111303]  ? handle_bug+0x6e/0xb0\n[   44.111306]  ? exc_invalid_op+0x18/0x80\n[   44.111308]  ? asm_exc_invalid_op+0x1b/0x20\n[   44.111311]  ? framebuffer_release+0x2c/0x40\n[   44.111313]  ? hvfb_remove+0x86/0xa0 [hyperv_fb]\n[   44.111315]  vmbus_remove+0x24/0x40 [hv_vmbus]\n[   44.111323]  device_remove+0x40/0x80\n[   44.111325]  device_release_driver_internal+0x20b/0x270\n[   44.111327]  ? bus_find_device+0xb3/0xf0\n\nFix this by moving the release of framebuffer and assosiated memory\nto fb_ops.fb_destroy function, so that framebuffer framework handles\nit gracefully.\n\nWhile we fix this, also replace manual registrations/unregistration of\nframebuffer with devm_register_framebuffer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21976","epss":0.00196,"percentile":0.09412,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21976","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-21985","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-21985","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix out-of-bound accesses  [WHAT & HOW] hpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4), but location can have size up to 6. As a result, it is necessary to check location against MAX_HPO_DP2_ENCODERS.  Similiarly, disp_cfg_stream_location can be used as an array index which should be 0..5, so the ASSERT's conditions should be less without equal.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21985","epss":0.00196,"percentile":0.09412,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21985","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.14307999999999998},"relatedVulnerabilities":[{"id":"CVE-2025-21985","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-21985","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/36793d90d76f667d26c6dd025571481ee0c96abc","https://git.kernel.org/stable/c/8adbb2a98b00926315fd513b5fe2596b5716b82d","https://git.kernel.org/stable/c/9aedc776b11038f04f4641241bb7e877781e4aa4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix out-of-bound accesses\n\n[WHAT & HOW]\nhpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4),\nbut location can have size up to 6. As a result, it is necessary to\ncheck location against MAX_HPO_DP2_ENCODERS.\n\nSimiliarly, disp_cfg_stream_location can be used as an array index which\nshould be 0..5, so the ASSERT's conditions should be less without equal.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-21985","epss":0.00196,"percentile":0.09412,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-21985","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-21985","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22028","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22028","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: vimc: skip .s_stream() for stopped entities  Syzbot reported [1] a warning prompted by a check in call_s_stream() that checks whether .s_stream() operation is warranted for unstarted or stopped subdevs.  Add a simple fix in vimc_streamer_pipeline_terminate() ensuring that entities skip a call to .s_stream() unless they have been previously properly started.  [1] Syzbot report: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 5933 at drivers/media/v4l2-core/v4l2-subdev.c:460 call_s_stream+0x2df/0x350 drivers/media/v4l2-core/v4l2-subdev.c:460 Modules linked in: CPU: 0 UID: 0 PID: 5933 Comm: syz-executor330 Not tainted 6.13.0-rc2-syzkaller-00362-g2d8308bf5b67 #0 ... Call Trace:  <TASK>  vimc_streamer_pipeline_terminate+0x218/0x320 drivers/media/test-drivers/vimc/vimc-streamer.c:62  vimc_streamer_pipeline_init drivers/media/test-drivers/vimc/vimc-streamer.c:101 [inline]  vimc_streamer_s_stream+0x650/0x9a0 drivers/media/test-drivers/vimc/vimc-streamer.c:203  vimc_capture_start_streaming+0xa1/0x130 drivers/media/test-drivers/vimc/vimc-capture.c:256  vb2_start_streaming+0x15f/0x5a0 drivers/media/common/videobuf2/videobuf2-core.c:1789  vb2_core_streamon+0x2a7/0x450 drivers/media/common/videobuf2/videobuf2-core.c:2348  vb2_streamon drivers/media/common/videobuf2/videobuf2-v4l2.c:875 [inline]  vb2_ioctl_streamon+0xf4/0x170 drivers/media/common/videobuf2/videobuf2-v4l2.c:1118  __video_do_ioctl+0xaf0/0xf00 drivers/media/v4l2-core/v4l2-ioctl.c:3122  video_usercopy+0x4d2/0x1620 drivers/media/v4l2-core/v4l2-ioctl.c:3463  v4l2_ioctl+0x1ba/0x250 drivers/media/v4l2-core/v4l2-dev.c:366  vfs_ioctl fs/ioctl.c:51 [inline]  __do_sys_ioctl fs/ioctl.c:906 [inline]  __se_sys_ioctl fs/ioctl.c:892 [inline]  __x64_sys_ioctl+0x190/0x200 fs/ioctl.c:892  do_syscall_x64 arch/x86/entry/common.c:52 [inline]  do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f2b85c01b19 ...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22028","epss":0.00193,"percentile":0.091,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.101325},"relatedVulnerabilities":[{"id":"CVE-2025-22028","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22028","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/36cef585e2a31e4ddf33a004b0584a7a572246de","https://git.kernel.org/stable/c/6f6064dab4dcfb7e34a395040a0c9dc22cc8765d","https://git.kernel.org/stable/c/7a58d4c4cf8ff60ab1f93399deefaf6057da91c7","https://git.kernel.org/stable/c/845e9286ff99ee88cfdeb2b748f730003a512190","https://git.kernel.org/stable/c/a505075730d23ccc19fc4ac382a0ed73b630c057"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vimc: skip .s_stream() for stopped entities\n\nSyzbot reported [1] a warning prompted by a check in call_s_stream()\nthat checks whether .s_stream() operation is warranted for unstarted\nor stopped subdevs.\n\nAdd a simple fix in vimc_streamer_pipeline_terminate() ensuring that\nentities skip a call to .s_stream() unless they have been previously\nproperly started.\n\n[1] Syzbot report:\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 5933 at drivers/media/v4l2-core/v4l2-subdev.c:460 call_s_stream+0x2df/0x350 drivers/media/v4l2-core/v4l2-subdev.c:460\nModules linked in:\nCPU: 0 UID: 0 PID: 5933 Comm: syz-executor330 Not tainted 6.13.0-rc2-syzkaller-00362-g2d8308bf5b67 #0\n...\nCall Trace:\n <TASK>\n vimc_streamer_pipeline_terminate+0x218/0x320 drivers/media/test-drivers/vimc/vimc-streamer.c:62\n vimc_streamer_pipeline_init drivers/media/test-drivers/vimc/vimc-streamer.c:101 [inline]\n vimc_streamer_s_stream+0x650/0x9a0 drivers/media/test-drivers/vimc/vimc-streamer.c:203\n vimc_capture_start_streaming+0xa1/0x130 drivers/media/test-drivers/vimc/vimc-capture.c:256\n vb2_start_streaming+0x15f/0x5a0 drivers/media/common/videobuf2/videobuf2-core.c:1789\n vb2_core_streamon+0x2a7/0x450 drivers/media/common/videobuf2/videobuf2-core.c:2348\n vb2_streamon drivers/media/common/videobuf2/videobuf2-v4l2.c:875 [inline]\n vb2_ioctl_streamon+0xf4/0x170 drivers/media/common/videobuf2/videobuf2-v4l2.c:1118\n __video_do_ioctl+0xaf0/0xf00 drivers/media/v4l2-core/v4l2-ioctl.c:3122\n video_usercopy+0x4d2/0x1620 drivers/media/v4l2-core/v4l2-ioctl.c:3463\n v4l2_ioctl+0x1ba/0x250 drivers/media/v4l2-core/v4l2-dev.c:366\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl fs/ioctl.c:892 [inline]\n __x64_sys_ioctl+0x190/0x200 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f2b85c01b19\n...","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22028","epss":0.00193,"percentile":0.091,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22028","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22037","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22037","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix null pointer dereference in alloc_preauth_hash()  The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauth_info is not allocated. This patch add KSMBD_SESS_NEED_SETUP status of connection to ignore session setup request if smb2 negotiate phase is not complete.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22037","epss":0.66418,"percentile":0.99233,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22037","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":34.86945},"relatedVulnerabilities":[{"id":"CVE-2025-22037","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22037","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/8f216b33a5e1b3489c073b1ea1b3d7cb63c8dc4d","https://git.kernel.org/stable/c/b8eb243e670ecf30e91524dd12f7260dac07d335","https://git.kernel.org/stable/c/c8b5b7c5da7d0c31c9b7190b4a7bba5281fc4780","https://git.kernel.org/stable/c/ca8bed31edf728a662ef9d6f39f50e7a7dc2b5ad","https://git.kernel.org/stable/c/cce57cd8c5dead24127cf2308fdd60fcad2d6ba6","https://www.zerodayinitiative.com/advisories/ZDI-25-310/"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix null pointer dereference in alloc_preauth_hash()\n\nThe Client send malformed smb2 negotiate request. ksmbd return error\nresponse. Subsequently, the client can send smb2 session setup even\nthought conn->preauth_info is not allocated.\nThis patch add KSMBD_SESS_NEED_SETUP status of connection to ignore\nsession setup request if smb2 negotiate phase is not complete.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22037","epss":0.66418,"percentile":0.99233,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22037","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22037","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22039","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix overflow in dacloffset bounds check  The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check in both smb_check_perm_dacl() and smb_inherit_dacl().  This could result in out-of-bounds memory access and a kernel crash when dereferencing the DACL pointer.  This patch converts dacloffset to unsigned int and uses check_add_overflow() to validate access to the DACL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22039","epss":0.0068,"percentile":0.50295,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22039","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-22039","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.49639999999999995},"relatedVulnerabilities":[{"id":"CVE-2025-22039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22039","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/443b373a4df5a2cb9f7b8c4658b2afedeb16397f","https://git.kernel.org/stable/c/6a9cd9ff0fa2bcc30b2bfb8bdb161eb20e44b9dc","https://git.kernel.org/stable/c/6b8d379048b168a0dff5ab1acb975b933f368514","https://git.kernel.org/stable/c/beff0bc9d69bc8e733f9bca28e2d3df5b3e10e42"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix overflow in dacloffset bounds check\n\nThe dacloffset field was originally typed as int and used in an\nunchecked addition, which could overflow and bypass the existing\nbounds check in both smb_check_perm_dacl() and smb_inherit_dacl().\n\nThis could result in out-of-bounds memory access and a kernel crash\nwhen dereferencing the DACL pointer.\n\nThis patch converts dacloffset to unsigned int and uses\ncheck_add_overflow() to validate access to the DACL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22039","epss":0.0068,"percentile":0.50295,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22039","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-22039","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22043","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22043","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: add bounds check for durable handle context  Add missing bounds check for durable handle context.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22043","epss":0.00458,"percentile":0.38379,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24045},"relatedVulnerabilities":[{"id":"CVE-2025-22043","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22043","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1107b9ed92194603593c51829a3887812ae9e806","https://git.kernel.org/stable/c/29b946714d6aa77de54c71243bba39469ac43ef2","https://git.kernel.org/stable/c/542027e123fc0bfd61dd59e21ae0ee4ef2101b29","https://git.kernel.org/stable/c/8d4848c45943c9cf5e86142fd7347efa97f497db","https://git.kernel.org/stable/c/f0db3d9d416e332a0d6f045a1509539d3a4cd898"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add bounds check for durable handle context\n\nAdd missing bounds check for durable handle context.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22043","epss":0.00458,"percentile":0.38379,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22043","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22048","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22048","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: BPF: Don't override subprog's return value  The verifier test `calls: div by 0 in subprog` triggers a panic at the ld.bu instruction. The ld.bu insn is trying to load byte from memory address returned by the subprog. The subprog actually set the correct address at the a5 register (dedicated register for BPF return values). But at commit 73c359d1d356 (\"LoongArch: BPF: Sign-extend return values\") we also sign extended a5 to the a0 register (return value in LoongArch). For function call insn, we later propagate the a0 register back to a5 register. This is right for native calls but wrong for bpf2bpf calls which expect zero-extended return value in a5 register. So only move a0 to a5 for native calls (i.e. non-BPF_PSEUDO_CALL).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22048","epss":0.00203,"percentile":0.10372,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.106575},"relatedVulnerabilities":[{"id":"CVE-2025-22048","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22048","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/223d565d8892481684091cfbaf3466f2b0e289d3","https://git.kernel.org/stable/c/60f3caff1492e5b8616b9578c4bedb5c0a88ed14","https://git.kernel.org/stable/c/780628a780b622759d9e5adc76d15432144da1a3","https://git.kernel.org/stable/c/7df2696256a034405d3c5a71b3a4c54725de4404","https://git.kernel.org/stable/c/996e90ab446641553e8e21707b38b9709605e0e0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Don't override subprog's return value\n\nThe verifier test `calls: div by 0 in subprog` triggers a panic at the\nld.bu instruction. The ld.bu insn is trying to load byte from memory\naddress returned by the subprog. The subprog actually set the correct\naddress at the a5 register (dedicated register for BPF return values).\nBut at commit 73c359d1d356 (\"LoongArch: BPF: Sign-extend return values\")\nwe also sign extended a5 to the a0 register (return value in LoongArch).\nFor function call insn, we later propagate the a0 register back to a5\nregister. This is right for native calls but wrong for bpf2bpf calls\nwhich expect zero-extended return value in a5 register. So only move a0\nto a5 for native calls (i.e. non-BPF_PSEUDO_CALL).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22048","epss":0.00203,"percentile":0.10372,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22048","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22053","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22053","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ibmveth: make veth_pool_store stop hanging  v2: - Created a single error handling unlock and exit in veth_pool_store - Greatly expanded commit message with previous explanatory-only text  Summary: Use rtnl_mutex to synchronize veth_pool_store with itself, ibmveth_close and ibmveth_open, preventing multiple calls in a row to napi_disable.  Background: Two (or more) threads could call veth_pool_store through writing to /sys/devices/vio/30000002/pool*/*. You can do this easily with a little shell script. This causes a hang.  I configured LOCKDEP, compiled ibmveth.c with DEBUG, and built a new kernel. I ran this test again and saw:      Setting pool0/active to 0     Setting pool1/active to 1     [   73.911067][ T4365] ibmveth 30000002 eth0: close starting     Setting pool1/active to 1     Setting pool1/active to 0     [   73.911367][ T4366] ibmveth 30000002 eth0: close starting     [   73.916056][ T4365] ibmveth 30000002 eth0: close complete     [   73.916064][ T4365] ibmveth 30000002 eth0: open starting     [  110.808564][  T712] systemd-journald[712]: Sent WATCHDOG=1 notification.     [  230.808495][  T712] systemd-journald[712]: Sent WATCHDOG=1 notification.     [  243.683786][  T123] INFO: task stress.sh:4365 blocked for more than 122 seconds.     [  243.683827][  T123]       Not tainted 6.14.0-01103-g2df0c02dab82-dirty #8     [  243.683833][  T123] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.     [  243.683838][  T123] task:stress.sh       state:D stack:28096 pid:4365  tgid:4365  ppid:4364   task_flags:0x400040 flags:0x00042000     [  243.683852][  T123] Call Trace:     [  243.683857][  T123] [c00000000c38f690] [0000000000000001] 0x1 (unreliable)     [  243.683868][  T123] [c00000000c38f840] [c00000000001f908] __switch_to+0x318/0x4e0     [  243.683878][  T123] [c00000000c38f8a0] [c000000001549a70] __schedule+0x500/0x12a0     [  243.683888][  T123] [c00000000c38f9a0] [c00000000154a878] schedule+0x68/0x210     [  243.683896][  T123] [c00000000c38f9d0] [c00000000154ac80] schedule_preempt_disabled+0x30/0x50     [  243.683904][  T123] [c00000000c38fa00] [c00000000154dbb0] __mutex_lock+0x730/0x10f0     [  243.683913][  T123] [c00000000c38fb10] [c000000001154d40] napi_enable+0x30/0x60     [  243.683921][  T123] [c00000000c38fb40] [c000000000f4ae94] ibmveth_open+0x68/0x5dc     [  243.683928][  T123] [c00000000c38fbe0] [c000000000f4aa20] veth_pool_store+0x220/0x270     [  243.683936][  T123] [c00000000c38fc70] [c000000000826278] sysfs_kf_write+0x68/0xb0     [  243.683944][  T123] [c00000000c38fcb0] [c0000000008240b8] kernfs_fop_write_iter+0x198/0x2d0     [  243.683951][  T123] [c00000000c38fd00] [c00000000071b9ac] vfs_write+0x34c/0x650     [  243.683958][  T123] [c00000000c38fdc0] [c00000000071bea8] ksys_write+0x88/0x150     [  243.683966][  T123] [c00000000c38fe10] [c0000000000317f4] system_call_exception+0x124/0x340     [  243.683973][  T123] [c00000000c38fe50] [c00000000000d05c] system_call_vectored_common+0x15c/0x2ec     ...     [  243.684087][  T123] Showing all locks held in the system:     [  243.684095][  T123] 1 lock held by khungtaskd/123:     [  243.684099][  T123]  #0: c00000000278e370 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x50/0x248     [  243.684114][  T123] 4 locks held by stress.sh/4365:     [  243.684119][  T123]  #0: c00000003a4cd3f8 (sb_writers#3){.+.+}-{0:0}, at: ksys_write+0x88/0x150     [  243.684132][  T123]  #1: c000000041aea888 (&of->mutex#2){+.+.}-{3:3}, at: kernfs_fop_write_iter+0x154/0x2d0     [  243.684143][  T123]  #2: c0000000366fb9a8 (kn->active#64){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x160/0x2d0     [  243.684155][  T123]  #3: c000000035ff4cb8 (&dev->lock){+.+.}-{3:3}, at: napi_enable+0x30/0x60     [  243.684166][  T123] 5 locks held by stress.sh/4366:     [  243.684170][  T123]  #0: c00000003a4cd3f8 (sb_writers#3){.+.+}-{0:0}, at: ksys_write+0x88/0x150     [  243. ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22053","epss":0.00147,"percentile":0.04294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22053","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.077175},"relatedVulnerabilities":[{"id":"CVE-2025-22053","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22053","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/053f3ff67d7feefc75797863f3d84b47ad47086f","https://git.kernel.org/stable/c/0a2470e3ecde64fc7e3781dc474923193621ae67","https://git.kernel.org/stable/c/1e458c292f4c687dcf5aad32dd4836d03cd2191f","https://git.kernel.org/stable/c/86cc70f5c85dc09bf7f3e1eee380eefe73c90765","https://git.kernel.org/stable/c/8a88bb092f4208355880b9fdcc69d491aa297595"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ibmveth: make veth_pool_store stop hanging\n\nv2:\n- Created a single error handling unlock and exit in veth_pool_store\n- Greatly expanded commit message with previous explanatory-only text\n\nSummary: Use rtnl_mutex to synchronize veth_pool_store with itself,\nibmveth_close and ibmveth_open, preventing multiple calls in a row to\nnapi_disable.\n\nBackground: Two (or more) threads could call veth_pool_store through\nwriting to /sys/devices/vio/30000002/pool*/*. You can do this easily\nwith a little shell script. This causes a hang.\n\nI configured LOCKDEP, compiled ibmveth.c with DEBUG, and built a new\nkernel. I ran this test again and saw:\n\n    Setting pool0/active to 0\n    Setting pool1/active to 1\n    [   73.911067][ T4365] ibmveth 30000002 eth0: close starting\n    Setting pool1/active to 1\n    Setting pool1/active to 0\n    [   73.911367][ T4366] ibmveth 30000002 eth0: close starting\n    [   73.916056][ T4365] ibmveth 30000002 eth0: close complete\n    [   73.916064][ T4365] ibmveth 30000002 eth0: open starting\n    [  110.808564][  T712] systemd-journald[712]: Sent WATCHDOG=1 notification.\n    [  230.808495][  T712] systemd-journald[712]: Sent WATCHDOG=1 notification.\n    [  243.683786][  T123] INFO: task stress.sh:4365 blocked for more than 122 seconds.\n    [  243.683827][  T123]       Not tainted 6.14.0-01103-g2df0c02dab82-dirty #8\n    [  243.683833][  T123] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n    [  243.683838][  T123] task:stress.sh       state:D stack:28096 pid:4365  tgid:4365  ppid:4364   task_flags:0x400040 flags:0x00042000\n    [  243.683852][  T123] Call Trace:\n    [  243.683857][  T123] [c00000000c38f690] [0000000000000001] 0x1 (unreliable)\n    [  243.683868][  T123] [c00000000c38f840] [c00000000001f908] __switch_to+0x318/0x4e0\n    [  243.683878][  T123] [c00000000c38f8a0] [c000000001549a70] __schedule+0x500/0x12a0\n    [  243.683888][  T123] [c00000000c38f9a0] [c00000000154a878] schedule+0x68/0x210\n    [  243.683896][  T123] [c00000000c38f9d0] [c00000000154ac80] schedule_preempt_disabled+0x30/0x50\n    [  243.683904][  T123] [c00000000c38fa00] [c00000000154dbb0] __mutex_lock+0x730/0x10f0\n    [  243.683913][  T123] [c00000000c38fb10] [c000000001154d40] napi_enable+0x30/0x60\n    [  243.683921][  T123] [c00000000c38fb40] [c000000000f4ae94] ibmveth_open+0x68/0x5dc\n    [  243.683928][  T123] [c00000000c38fbe0] [c000000000f4aa20] veth_pool_store+0x220/0x270\n    [  243.683936][  T123] [c00000000c38fc70] [c000000000826278] sysfs_kf_write+0x68/0xb0\n    [  243.683944][  T123] [c00000000c38fcb0] [c0000000008240b8] kernfs_fop_write_iter+0x198/0x2d0\n    [  243.683951][  T123] [c00000000c38fd00] [c00000000071b9ac] vfs_write+0x34c/0x650\n    [  243.683958][  T123] [c00000000c38fdc0] [c00000000071bea8] ksys_write+0x88/0x150\n    [  243.683966][  T123] [c00000000c38fe10] [c0000000000317f4] system_call_exception+0x124/0x340\n    [  243.683973][  T123] [c00000000c38fe50] [c00000000000d05c] system_call_vectored_common+0x15c/0x2ec\n    ...\n    [  243.684087][  T123] Showing all locks held in the system:\n    [  243.684095][  T123] 1 lock held by khungtaskd/123:\n    [  243.684099][  T123]  #0: c00000000278e370 (rcu_read_lock){....}-{1:2}, at: debug_show_all_locks+0x50/0x248\n    [  243.684114][  T123] 4 locks held by stress.sh/4365:\n    [  243.684119][  T123]  #0: c00000003a4cd3f8 (sb_writers#3){.+.+}-{0:0}, at: ksys_write+0x88/0x150\n    [  243.684132][  T123]  #1: c000000041aea888 (&of->mutex#2){+.+.}-{3:3}, at: kernfs_fop_write_iter+0x154/0x2d0\n    [  243.684143][  T123]  #2: c0000000366fb9a8 (kn->active#64){.+.+}-{0:0}, at: kernfs_fop_write_iter+0x160/0x2d0\n    [  243.684155][  T123]  #3: c000000035ff4cb8 (&dev->lock){+.+.}-{3:3}, at: napi_enable+0x30/0x60\n    [  243.684166][  T123] 5 locks held by stress.sh/4366:\n    [  243.684170][  T123]  #0: c00000003a4cd3f8 (sb_writers#3){.+.+}-{0:0}, at: ksys_write+0x88/0x150\n    [  243.\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22053","epss":0.00147,"percentile":0.04294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22053","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22053","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22057","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22057","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: decrease cached dst counters in dst_release  Upstream fix ac888d58869b (\"net: do not delay dst_entries_add() in dst_release()\") moved decrementing the dst count from dst_destroy to dst_release to avoid accessing already freed data in case of netns dismantle. However in case CONFIG_DST_CACHE is enabled and OvS+tunnels are used, this fix is incomplete as the same issue will be seen for cached dsts:    Unable to handle kernel paging request at virtual address ffff5aabf6b5c000   Call trace:    percpu_counter_add_batch+0x3c/0x160 (P)    dst_release+0xec/0x108    dst_cache_destroy+0x68/0xd8    dst_destroy+0x13c/0x168    dst_destroy_rcu+0x1c/0xb0    rcu_do_batch+0x18c/0x7d0    rcu_core+0x174/0x378    rcu_core_si+0x18/0x30  Fix this by invalidating the cache, and thus decrementing cached dst counters, in dst_release too.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22057","epss":0.00202,"percentile":0.10243,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10605},"relatedVulnerabilities":[{"id":"CVE-2025-22057","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22057","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3a0a3ff6593d670af2451ec363ccb7b18aec0c0a","https://git.kernel.org/stable/c/836415a8405c9665ae55352fc5ba865c242f5e4f","https://git.kernel.org/stable/c/92a5c18513117be69bc00419dd1724c1940f8fcd","https://git.kernel.org/stable/c/ccc331fd5bcae131d2627d5ef099d4a1f6540aea","https://git.kernel.org/stable/c/e833e7ad64eb2f63867f65303be49ca30ee8819e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: decrease cached dst counters in dst_release\n\nUpstream fix ac888d58869b (\"net: do not delay dst_entries_add() in\ndst_release()\") moved decrementing the dst count from dst_destroy to\ndst_release to avoid accessing already freed data in case of netns\ndismantle. However in case CONFIG_DST_CACHE is enabled and OvS+tunnels\nare used, this fix is incomplete as the same issue will be seen for\ncached dsts:\n\n  Unable to handle kernel paging request at virtual address ffff5aabf6b5c000\n  Call trace:\n   percpu_counter_add_batch+0x3c/0x160 (P)\n   dst_release+0xec/0x108\n   dst_cache_destroy+0x68/0xd8\n   dst_destroy+0x13c/0x168\n   dst_destroy_rcu+0x1c/0xb0\n   rcu_do_batch+0x18c/0x7d0\n   rcu_core+0x174/0x378\n   rcu_core_si+0x18/0x30\n\nFix this by invalidating the cache, and thus decrementing cached dst\ncounters, in dst_release too.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22057","epss":0.00202,"percentile":0.10243,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22057","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22070","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22070","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/9p: fix NULL pointer dereference on mkdir  When a 9p tree was mounted with option 'posixacl', parent directory had a default ACL set for its subdirectories, e.g.:    setfacl -m default:group:simpsons:rwx parentdir  then creating a subdirectory crashed 9p client, as v9fs_fid_add() call in function v9fs_vfs_mkdir_dotl() sets the passed 'fid' pointer to NULL (since dafbe689736) even though the subsequent v9fs_set_create_acl() call expects a valid non-NULL 'fid' pointer:    [   37.273191] BUG: kernel NULL pointer dereference, address: 0000000000000000   ...   [   37.322338] Call Trace:   [   37.323043]  <TASK>   [   37.323621] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)   [   37.324448] ? page_fault_oops (arch/x86/mm/fault.c:714)   [   37.325532] ? search_module_extables (kernel/module/main.c:3733)   [   37.326742] ? p9_client_walk (net/9p/client.c:1165) 9pnet   [   37.328006] ? search_bpf_extables (kernel/bpf/core.c:804)   [   37.329142] ? exc_page_fault (./arch/x86/include/asm/paravirt.h:686 arch/x86/mm/fault.c:1488 arch/x86/mm/fault.c:1538)   [   37.330196] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:574)   [   37.331330] ? p9_client_walk (net/9p/client.c:1165) 9pnet   [   37.332562] ? v9fs_fid_xattr_get (fs/9p/xattr.c:30) 9p   [   37.333824] v9fs_fid_xattr_set (fs/9p/fid.h:23 fs/9p/xattr.c:121) 9p   [   37.335077] v9fs_set_acl (fs/9p/acl.c:276) 9p   [   37.336112] v9fs_set_create_acl (fs/9p/acl.c:307) 9p   [   37.337326] v9fs_vfs_mkdir_dotl (fs/9p/vfs_inode_dotl.c:411) 9p   [   37.338590] vfs_mkdir (fs/namei.c:4313)   [   37.339535] do_mkdirat (fs/namei.c:4336)   [   37.340465] __x64_sys_mkdir (fs/namei.c:4354)   [   37.341455] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)   [   37.342447] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)  Fix this by simply swapping the sequence of these two calls in v9fs_vfs_mkdir_dotl(), i.e. calling v9fs_set_create_acl() before v9fs_fid_add().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22070","epss":0.00193,"percentile":0.09099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22070","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-22070","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.101325},"relatedVulnerabilities":[{"id":"CVE-2025-22070","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22070","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2139dea5c53e3bb63ac49a6901c85e525a80ee8a","https://git.kernel.org/stable/c/3f61ac7c65bdb26accb52f9db66313597e759821","https://git.kernel.org/stable/c/6517b395cb1e43fbf3962dd93e6fb4a5e5ab100e","https://git.kernel.org/stable/c/8522051c58d68146b93e8a5ba9987e83b3d64e7b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/9p: fix NULL pointer dereference on mkdir\n\nWhen a 9p tree was mounted with option 'posixacl', parent directory had a\ndefault ACL set for its subdirectories, e.g.:\n\n  setfacl -m default:group:simpsons:rwx parentdir\n\nthen creating a subdirectory crashed 9p client, as v9fs_fid_add() call in\nfunction v9fs_vfs_mkdir_dotl() sets the passed 'fid' pointer to NULL\n(since dafbe689736) even though the subsequent v9fs_set_create_acl() call\nexpects a valid non-NULL 'fid' pointer:\n\n  [   37.273191] BUG: kernel NULL pointer dereference, address: 0000000000000000\n  ...\n  [   37.322338] Call Trace:\n  [   37.323043]  <TASK>\n  [   37.323621] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)\n  [   37.324448] ? page_fault_oops (arch/x86/mm/fault.c:714)\n  [   37.325532] ? search_module_extables (kernel/module/main.c:3733)\n  [   37.326742] ? p9_client_walk (net/9p/client.c:1165) 9pnet\n  [   37.328006] ? search_bpf_extables (kernel/bpf/core.c:804)\n  [   37.329142] ? exc_page_fault (./arch/x86/include/asm/paravirt.h:686 arch/x86/mm/fault.c:1488 arch/x86/mm/fault.c:1538)\n  [   37.330196] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:574)\n  [   37.331330] ? p9_client_walk (net/9p/client.c:1165) 9pnet\n  [   37.332562] ? v9fs_fid_xattr_get (fs/9p/xattr.c:30) 9p\n  [   37.333824] v9fs_fid_xattr_set (fs/9p/fid.h:23 fs/9p/xattr.c:121) 9p\n  [   37.335077] v9fs_set_acl (fs/9p/acl.c:276) 9p\n  [   37.336112] v9fs_set_create_acl (fs/9p/acl.c:307) 9p\n  [   37.337326] v9fs_vfs_mkdir_dotl (fs/9p/vfs_inode_dotl.c:411) 9p\n  [   37.338590] vfs_mkdir (fs/namei.c:4313)\n  [   37.339535] do_mkdirat (fs/namei.c:4336)\n  [   37.340465] __x64_sys_mkdir (fs/namei.c:4354)\n  [   37.341455] do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\n  [   37.342447] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nFix this by simply swapping the sequence of these two calls in\nv9fs_vfs_mkdir_dotl(), i.e. calling v9fs_set_create_acl() before\nv9fs_fid_add().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22070","epss":0.00193,"percentile":0.09099,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22070","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-22070","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22070","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22103","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22103","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: fix NULL pointer dereference in l3mdev_l3_rcv  When delete l3s ipvlan:      ip link del link eth0 ipvlan1 type ipvlan mode l3s  This may cause a null pointer dereference:      Call trace:      ip_rcv_finish+0x48/0xd0      ip_rcv+0x5c/0x100      __netif_receive_skb_one_core+0x64/0xb0      __netif_receive_skb+0x20/0x80      process_backlog+0xb4/0x204      napi_poll+0xe8/0x294      net_rx_action+0xd8/0x22c      __do_softirq+0x12c/0x354  This is because l3mdev_l3_rcv() visit dev->l3mdev_ops after ipvlan_l3s_unregister() assign the dev->l3mdev_ops to NULL. The process like this:      (CPU1)                     | (CPU2)     l3mdev_l3_rcv()            |       check dev->priv_flags:   |         master = skb->dev;     |                                |                                | ipvlan_l3s_unregister()                                |   set dev->priv_flags                                |   dev->l3mdev_ops = NULL;                                |       visit master->l3mdev_ops |  To avoid this by do not set dev->l3mdev_ops when unregister l3s ipvlan.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22103","epss":0.00195,"percentile":0.09298,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22103","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.102375},"relatedVulnerabilities":[{"id":"CVE-2025-22103","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22103","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0032c99e83b9ce6d5995d65900aa4b6ffb501cce","https://git.kernel.org/stable/c/52b44d8c653459c658b733d13658afdde45f6836","https://git.kernel.org/stable/c/59599bce44af3df7a215ebc81cb166426e1c9204","https://git.kernel.org/stable/c/f9dff65140efc289f01bcf39c3ca66a8806b6132"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix NULL pointer dereference in l3mdev_l3_rcv\n\nWhen delete l3s ipvlan:\n\n    ip link del link eth0 ipvlan1 type ipvlan mode l3s\n\nThis may cause a null pointer dereference:\n\n    Call trace:\n     ip_rcv_finish+0x48/0xd0\n     ip_rcv+0x5c/0x100\n     __netif_receive_skb_one_core+0x64/0xb0\n     __netif_receive_skb+0x20/0x80\n     process_backlog+0xb4/0x204\n     napi_poll+0xe8/0x294\n     net_rx_action+0xd8/0x22c\n     __do_softirq+0x12c/0x354\n\nThis is because l3mdev_l3_rcv() visit dev->l3mdev_ops after\nipvlan_l3s_unregister() assign the dev->l3mdev_ops to NULL. The process\nlike this:\n\n    (CPU1)                     | (CPU2)\n    l3mdev_l3_rcv()            |\n      check dev->priv_flags:   |\n        master = skb->dev;     |\n                               |\n                               | ipvlan_l3s_unregister()\n                               |   set dev->priv_flags\n                               |   dev->l3mdev_ops = NULL;\n                               |\n      visit master->l3mdev_ops |\n\nTo avoid this by do not set dev->l3mdev_ops when unregister l3s ipvlan.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22103","epss":0.00195,"percentile":0.09298,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22103","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22103","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22104","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ibmvnic: Use kernel helpers for hex dumps  Previously, when the driver was printing hex dumps, the buffer was cast to an 8 byte long and printed using string formatters. If the buffer size was not a multiple of 8 then a read buffer overflow was possible.  Therefore, create a new ibmvnic function that loops over a buffer and calls hex_dump_to_buffer instead.  This patch address KASAN reports like the one below:   ibmvnic 30000003 env3: Login Buffer:   ibmvnic 30000003 env3: 01000000af000000   <...>   ibmvnic 30000003 env3: 2e6d62692e736261   ibmvnic 30000003 env3: 65050003006d6f63   ==================================================================   BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic]   Read of size 8 at addr c0000001331a9aa8 by task ip/17681   <...>   Allocated by task 17681:   <...>   ibmvnic_login+0x2f0/0xffc [ibmvnic]   ibmvnic_open+0x148/0x308 [ibmvnic]   __dev_open+0x1ac/0x304   <...>   The buggy address is located 168 bytes inside of                 allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf)   <...>   =================================================================   ibmvnic 30000003 env3: 000000000033766e","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22104","epss":0.00217,"percentile":0.12147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22104","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.15841},"relatedVulnerabilities":[{"id":"CVE-2025-22104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22104","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/005fee039dd845122d313ac8f2122b0d09dc5d7b","https://git.kernel.org/stable/c/19efa170e01207c8ada726f3f6c65b31fcba2a73","https://git.kernel.org/stable/c/9bc078818ec76344c2e06b81d7aee2df3adecfbf","https://git.kernel.org/stable/c/ae6b1d6c1acee3a2000394d83ec9f1028321e207","https://git.kernel.org/stable/c/d93a6caab5d7d9b5ce034d75b1e1e993338e3852"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: Use kernel helpers for hex dumps\n\nPreviously, when the driver was printing hex dumps, the buffer was cast\nto an 8 byte long and printed using string formatters. If the buffer\nsize was not a multiple of 8 then a read buffer overflow was possible.\n\nTherefore, create a new ibmvnic function that loops over a buffer and\ncalls hex_dump_to_buffer instead.\n\nThis patch address KASAN reports like the one below:\n  ibmvnic 30000003 env3: Login Buffer:\n  ibmvnic 30000003 env3: 01000000af000000\n  <...>\n  ibmvnic 30000003 env3: 2e6d62692e736261\n  ibmvnic 30000003 env3: 65050003006d6f63\n  ==================================================================\n  BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic]\n  Read of size 8 at addr c0000001331a9aa8 by task ip/17681\n  <...>\n  Allocated by task 17681:\n  <...>\n  ibmvnic_login+0x2f0/0xffc [ibmvnic]\n  ibmvnic_open+0x148/0x308 [ibmvnic]\n  __dev_open+0x1ac/0x304\n  <...>\n  The buggy address is located 168 bytes inside of\n                allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf)\n  <...>\n  =================================================================\n  ibmvnic 30000003 env3: 000000000033766e","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22104","epss":0.00217,"percentile":0.12147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22104","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22104","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22109","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22109","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ax25: Remove broken autobind  Binding AX25 socket by using the autobind feature leads to memory leaks in ax25_connect() and also refcount leaks in ax25_release(). Memory leak was detected with kmemleak:  ================================================================ unreferenced object 0xffff8880253cd680 (size 96): backtrace: __kmalloc_node_track_caller_noprof (./include/linux/kmemleak.h:43) kmemdup_noprof (mm/util.c:136) ax25_rt_autobind (net/ax25/ax25_route.c:428) ax25_connect (net/ax25/af_ax25.c:1282) __sys_connect_file (net/socket.c:2045) __sys_connect (net/socket.c:2064) __x64_sys_connect (net/socket.c:2067) do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) ================================================================  When socket is bound, refcounts must be incremented the way it is done in ax25_bind() and ax25_setsockopt() (SO_BINDTODEVICE). In case of autobind, the refcounts are not incremented.  This bug leads to the following issue reported by Syzkaller:  ================================================================ ax25_connect(): syz-executor318 uses autobind, please contact jreuter@yaina.de ------------[ cut here ]------------ refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 0 PID: 5317 at lib/refcount.c:31 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:31 Modules linked in: CPU: 0 UID: 0 PID: 5317 Comm: syz-executor318 Not tainted 6.14.0-rc4-syzkaller-00278-gece144f151ac #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:31 ... Call Trace:  <TASK>  __refcount_dec include/linux/refcount.h:336 [inline]  refcount_dec include/linux/refcount.h:351 [inline]  ref_tracker_free+0x6af/0x7e0 lib/ref_tracker.c:236  netdev_tracker_free include/linux/netdevice.h:4302 [inline]  netdev_put include/linux/netdevice.h:4319 [inline]  ax25_release+0x368/0x960 net/ax25/af_ax25.c:1080  __sock_release net/socket.c:647 [inline]  sock_close+0xbc/0x240 net/socket.c:1398  __fput+0x3e9/0x9f0 fs/file_table.c:464  __do_sys_close fs/open.c:1580 [inline]  __se_sys_close fs/open.c:1565 [inline]  __x64_sys_close+0x7f/0x110 fs/open.c:1565  do_syscall_x64 arch/x86/entry/common.c:52 [inline]  do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f  ...  </TASK> ================================================================  Considering the issues above and the comments left in the code that say: \"check if we can remove this feature. It is broken.\"; \"autobinding in this may or may not work\"; - it is better to completely remove this feature than to fix it because it is broken and leads to various kinds of memory bugs.  Now calling connect() without first binding socket will result in an error (-EINVAL). Userspace software that relies on the autobind feature might get broken. However, this feature does not seem widely used with this specific driver as it was not reliable at any point of time, and it is already broken anyway. E.g. ax25-tools and ax25-apps packages for popular distributions do not use the autobind feature for AF_AX25.  Found by Linux Verification Center (linuxtesting.org) with Syzkaller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22109","epss":0.00171,"percentile":0.06699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22109","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.089775},"relatedVulnerabilities":[{"id":"CVE-2025-22109","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22109","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2f6efbabceb6b2914ee9bafb86d9a51feae9cce8","https://git.kernel.org/stable/c/61203fdd3e35519db9a98b6ff8983c620ffc4696"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Remove broken autobind\n\nBinding AX25 socket by using the autobind feature leads to memory leaks\nin ax25_connect() and also refcount leaks in ax25_release(). Memory\nleak was detected with kmemleak:\n\n================================================================\nunreferenced object 0xffff8880253cd680 (size 96):\nbacktrace:\n__kmalloc_node_track_caller_noprof (./include/linux/kmemleak.h:43)\nkmemdup_noprof (mm/util.c:136)\nax25_rt_autobind (net/ax25/ax25_route.c:428)\nax25_connect (net/ax25/af_ax25.c:1282)\n__sys_connect_file (net/socket.c:2045)\n__sys_connect (net/socket.c:2064)\n__x64_sys_connect (net/socket.c:2067)\ndo_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n================================================================\n\nWhen socket is bound, refcounts must be incremented the way it is done\nin ax25_bind() and ax25_setsockopt() (SO_BINDTODEVICE). In case of\nautobind, the refcounts are not incremented.\n\nThis bug leads to the following issue reported by Syzkaller:\n\n================================================================\nax25_connect(): syz-executor318 uses autobind, please contact jreuter@yaina.de\n------------[ cut here ]------------\nrefcount_t: decrement hit 0; leaking memory.\nWARNING: CPU: 0 PID: 5317 at lib/refcount.c:31 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:31\nModules linked in:\nCPU: 0 UID: 0 PID: 5317 Comm: syz-executor318 Not tainted 6.14.0-rc4-syzkaller-00278-gece144f151ac #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nRIP: 0010:refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:31\n...\nCall Trace:\n <TASK>\n __refcount_dec include/linux/refcount.h:336 [inline]\n refcount_dec include/linux/refcount.h:351 [inline]\n ref_tracker_free+0x6af/0x7e0 lib/ref_tracker.c:236\n netdev_tracker_free include/linux/netdevice.h:4302 [inline]\n netdev_put include/linux/netdevice.h:4319 [inline]\n ax25_release+0x368/0x960 net/ax25/af_ax25.c:1080\n __sock_release net/socket.c:647 [inline]\n sock_close+0xbc/0x240 net/socket.c:1398\n __fput+0x3e9/0x9f0 fs/file_table.c:464\n __do_sys_close fs/open.c:1580 [inline]\n __se_sys_close fs/open.c:1565 [inline]\n __x64_sys_close+0x7f/0x110 fs/open.c:1565\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n ...\n </TASK>\n================================================================\n\nConsidering the issues above and the comments left in the code that say:\n\"check if we can remove this feature. It is broken.\"; \"autobinding in this\nmay or may not work\"; - it is better to completely remove this feature than\nto fix it because it is broken and leads to various kinds of memory bugs.\n\nNow calling connect() without first binding socket will result in an\nerror (-EINVAL). Userspace software that relies on the autobind feature\nmight get broken. However, this feature does not seem widely used with\nthis specific driver as it was not reliable at any point of time, and it\nis already broken anyway. E.g. ax25-tools and ax25-apps packages for\npopular distributions do not use the autobind feature for AF_AX25.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22109","epss":0.00171,"percentile":0.06699,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22109","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22109","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22113","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22113","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: avoid journaling sb update on error if journal is destroying  Presently we always BUG_ON if trying to start a transaction on a journal marked with JBD2_UNMOUNT, since this should never happen. However, while ltp running stress tests, it was observed that in case of some error handling paths, it is possible for update_super_work to start a transaction after the journal is destroyed eg:  (umount) ext4_kill_sb   kill_block_super     generic_shutdown_super       sync_filesystem /* commits all txns */       evict_inodes         /* might start a new txn */       ext4_put_super \tflush_work(&sbi->s_sb_upd_work) /* flush the workqueue */         jbd2_journal_destroy           journal_kill_thread             journal->j_flags |= JBD2_UNMOUNT;           jbd2_journal_commit_transaction             jbd2_journal_get_descriptor_buffer               jbd2_journal_bmap                 ext4_journal_bmap                   ext4_map_blocks                     ...                     ext4_inode_error                       ext4_handle_error                         schedule_work(&sbi->s_sb_upd_work)                                                 /* work queue kicks in */                                                update_super_work                                                  jbd2_journal_start                                                    start_this_handle                                                      BUG_ON(journal->j_flags &                                                             JBD2_UNMOUNT)  Hence, introduce a new mount flag to indicate journal is destroying and only do a journaled (and deferred) update of sb if this flag is not set. Otherwise, just fallback to an un-journaled commit.  Further, in the journal destroy path, we have the following sequence:    1. Set mount flag indicating journal is destroying   2. force a commit and wait for it   3. flush pending sb updates  This sequence is important as it ensures that, after this point, there is no sb update that might be journaled so it is safe to update the sb outside the journal. (To avoid race discussed in 2d01ddc86606)  Also, we don't need a similar check in ext4_grp_locked_error since it is only called from mballoc and AFAICT it would be always valid to schedule work here.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22113","epss":0.00194,"percentile":0.09204,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10185000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-22113","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22113","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/ce2f26e73783b4a7c46a86e3af5b5c8de0971790","https://git.kernel.org/stable/c/db05767b5bc307143d99fe2afd8c43af58d2ebef","https://git.kernel.org/stable/c/eddca44ddf810e27f0c96913aa3cc92ebd679ddb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid journaling sb update on error if journal is destroying\n\nPresently we always BUG_ON if trying to start a transaction on a journal marked\nwith JBD2_UNMOUNT, since this should never happen. However, while ltp running\nstress tests, it was observed that in case of some error handling paths, it is\npossible for update_super_work to start a transaction after the journal is\ndestroyed eg:\n\n(umount)\next4_kill_sb\n  kill_block_super\n    generic_shutdown_super\n      sync_filesystem /* commits all txns */\n      evict_inodes\n        /* might start a new txn */\n      ext4_put_super\n\tflush_work(&sbi->s_sb_upd_work) /* flush the workqueue */\n        jbd2_journal_destroy\n          journal_kill_thread\n            journal->j_flags |= JBD2_UNMOUNT;\n          jbd2_journal_commit_transaction\n            jbd2_journal_get_descriptor_buffer\n              jbd2_journal_bmap\n                ext4_journal_bmap\n                  ext4_map_blocks\n                    ...\n                    ext4_inode_error\n                      ext4_handle_error\n                        schedule_work(&sbi->s_sb_upd_work)\n\n                                               /* work queue kicks in */\n                                               update_super_work\n                                                 jbd2_journal_start\n                                                   start_this_handle\n                                                     BUG_ON(journal->j_flags &\n                                                            JBD2_UNMOUNT)\n\nHence, introduce a new mount flag to indicate journal is destroying and only do\na journaled (and deferred) update of sb if this flag is not set. Otherwise, just\nfallback to an un-journaled commit.\n\nFurther, in the journal destroy path, we have the following sequence:\n\n  1. Set mount flag indicating journal is destroying\n  2. force a commit and wait for it\n  3. flush pending sb updates\n\nThis sequence is important as it ensures that, after this point, there is no sb\nupdate that might be journaled so it is safe to update the sb outside the\njournal. (To avoid race discussed in 2d01ddc86606)\n\nAlso, we don't need a similar check in ext4_grp_locked_error since it is only\ncalled from mballoc and AFAICT it would be always valid to schedule work here.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22113","epss":0.00194,"percentile":0.09204,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22113","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22115","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22115","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix block group refcount race in btrfs_create_pending_block_groups()  Block group creation is done in two phases, which results in a slightly unintuitive property: a block group can be allocated/deallocated from after btrfs_make_block_group() adds it to the space_info with btrfs_add_bg_to_space_info(), but before creation is completely completed in btrfs_create_pending_block_groups(). As a result, it is possible for a block group to go unused and have 'btrfs_mark_bg_unused' called on it concurrently with 'btrfs_create_pending_block_groups'. This causes a number of issues, which were fixed with the block group flag 'BLOCK_GROUP_FLAG_NEW'.  However, this fix is not quite complete. Since it does not use the unused_bg_lock, it is possible for the following race to occur:  btrfs_create_pending_block_groups            btrfs_mark_bg_unused                                            if list_empty // false         list_del_init         clear_bit                                            else if (test_bit) // true                                                 list_move_tail  And we get into the exact same broken ref count and invalid new_bgs state for transaction cleanup that BLOCK_GROUP_FLAG_NEW was designed to prevent.  The broken refcount aspect will result in a warning like:    [1272.943527] refcount_t: underflow; use-after-free.   [1272.943967] WARNING: CPU: 1 PID: 61 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110   [1272.944731] Modules linked in: btrfs virtio_net xor zstd_compress raid6_pq null_blk [last unloaded: btrfs]   [1272.945550] CPU: 1 UID: 0 PID: 61 Comm: kworker/u32:1 Kdump: loaded Tainted: G        W          6.14.0-rc5+ #108   [1272.946368] Tainted: [W]=WARN   [1272.946585] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014   [1272.947273] Workqueue: btrfs_discard btrfs_discard_workfn [btrfs]   [1272.947788] RIP: 0010:refcount_warn_saturate+0xba/0x110   [1272.949532] RSP: 0018:ffffbf1200247df0 EFLAGS: 00010282   [1272.949901] RAX: 0000000000000000 RBX: ffffa14b00e3f800 RCX: 0000000000000000   [1272.950437] RDX: 0000000000000000 RSI: ffffbf1200247c78 RDI: 00000000ffffdfff   [1272.950986] RBP: ffffa14b00dc2860 R08: 00000000ffffdfff R09: ffffffff90526268   [1272.951512] R10: ffffffff904762c0 R11: 0000000063666572 R12: ffffa14b00dc28c0   [1272.952024] R13: 0000000000000000 R14: ffffa14b00dc2868 R15: 000001285dcd12c0   [1272.952850] FS:  0000000000000000(0000) GS:ffffa14d33c40000(0000) knlGS:0000000000000000   [1272.953458] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   [1272.953931] CR2: 00007f838cbda000 CR3: 000000010104e000 CR4: 00000000000006f0   [1272.954474] Call Trace:   [1272.954655]  <TASK>   [1272.954812]  ? refcount_warn_saturate+0xba/0x110   [1272.955173]  ? __warn.cold+0x93/0xd7   [1272.955487]  ? refcount_warn_saturate+0xba/0x110   [1272.955816]  ? report_bug+0xe7/0x120   [1272.956103]  ? handle_bug+0x53/0x90   [1272.956424]  ? exc_invalid_op+0x13/0x60   [1272.956700]  ? asm_exc_invalid_op+0x16/0x20   [1272.957011]  ? refcount_warn_saturate+0xba/0x110   [1272.957399]  btrfs_discard_cancel_work.cold+0x26/0x2b [btrfs]   [1272.957853]  btrfs_put_block_group.cold+0x5d/0x8e [btrfs]   [1272.958289]  btrfs_discard_workfn+0x194/0x380 [btrfs]   [1272.958729]  process_one_work+0x130/0x290   [1272.959026]  worker_thread+0x2ea/0x420   [1272.959335]  ? __pfx_worker_thread+0x10/0x10   [1272.959644]  kthread+0xd7/0x1c0   [1272.959872]  ? __pfx_kthread+0x10/0x10   [1272.960172]  ret_from_fork+0x30/0x50   [1272.960474]  ? __pfx_kthread+0x10/0x10   [1272.960745]  ret_from_fork_asm+0x1a/0x30   [1272.961035]  </TASK>   [1272.961238] ---[ end trace 0000000000000000 ]---  Though we have seen them in the async discard workfn as well. It is most likely to happen after a relocation finishes which cancels discard, tears down the block group, etc.  Fix this fully by taking the lock arou ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22115","epss":0.00141,"percentile":0.03732,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22115","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.068385},"relatedVulnerabilities":[{"id":"CVE-2025-22115","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22115","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2d8e5168d48a91e7a802d3003e72afb4304bebfa","https://git.kernel.org/stable/c/9d383a6fc59271aaaf07a33b23b2eac5b9268b7a","https://git.kernel.org/stable/c/ee56da95f8962b86fec4ef93f866e64c8d025a58"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix block group refcount race in btrfs_create_pending_block_groups()\n\nBlock group creation is done in two phases, which results in a slightly\nunintuitive property: a block group can be allocated/deallocated from\nafter btrfs_make_block_group() adds it to the space_info with\nbtrfs_add_bg_to_space_info(), but before creation is completely completed\nin btrfs_create_pending_block_groups(). As a result, it is possible for a\nblock group to go unused and have 'btrfs_mark_bg_unused' called on it\nconcurrently with 'btrfs_create_pending_block_groups'. This causes a\nnumber of issues, which were fixed with the block group flag\n'BLOCK_GROUP_FLAG_NEW'.\n\nHowever, this fix is not quite complete. Since it does not use the\nunused_bg_lock, it is possible for the following race to occur:\n\nbtrfs_create_pending_block_groups            btrfs_mark_bg_unused\n                                           if list_empty // false\n        list_del_init\n        clear_bit\n                                           else if (test_bit) // true\n                                                list_move_tail\n\nAnd we get into the exact same broken ref count and invalid new_bgs\nstate for transaction cleanup that BLOCK_GROUP_FLAG_NEW was designed to\nprevent.\n\nThe broken refcount aspect will result in a warning like:\n\n  [1272.943527] refcount_t: underflow; use-after-free.\n  [1272.943967] WARNING: CPU: 1 PID: 61 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110\n  [1272.944731] Modules linked in: btrfs virtio_net xor zstd_compress raid6_pq null_blk [last unloaded: btrfs]\n  [1272.945550] CPU: 1 UID: 0 PID: 61 Comm: kworker/u32:1 Kdump: loaded Tainted: G        W          6.14.0-rc5+ #108\n  [1272.946368] Tainted: [W]=WARN\n  [1272.946585] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n  [1272.947273] Workqueue: btrfs_discard btrfs_discard_workfn [btrfs]\n  [1272.947788] RIP: 0010:refcount_warn_saturate+0xba/0x110\n  [1272.949532] RSP: 0018:ffffbf1200247df0 EFLAGS: 00010282\n  [1272.949901] RAX: 0000000000000000 RBX: ffffa14b00e3f800 RCX: 0000000000000000\n  [1272.950437] RDX: 0000000000000000 RSI: ffffbf1200247c78 RDI: 00000000ffffdfff\n  [1272.950986] RBP: ffffa14b00dc2860 R08: 00000000ffffdfff R09: ffffffff90526268\n  [1272.951512] R10: ffffffff904762c0 R11: 0000000063666572 R12: ffffa14b00dc28c0\n  [1272.952024] R13: 0000000000000000 R14: ffffa14b00dc2868 R15: 000001285dcd12c0\n  [1272.952850] FS:  0000000000000000(0000) GS:ffffa14d33c40000(0000) knlGS:0000000000000000\n  [1272.953458] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  [1272.953931] CR2: 00007f838cbda000 CR3: 000000010104e000 CR4: 00000000000006f0\n  [1272.954474] Call Trace:\n  [1272.954655]  <TASK>\n  [1272.954812]  ? refcount_warn_saturate+0xba/0x110\n  [1272.955173]  ? __warn.cold+0x93/0xd7\n  [1272.955487]  ? refcount_warn_saturate+0xba/0x110\n  [1272.955816]  ? report_bug+0xe7/0x120\n  [1272.956103]  ? handle_bug+0x53/0x90\n  [1272.956424]  ? exc_invalid_op+0x13/0x60\n  [1272.956700]  ? asm_exc_invalid_op+0x16/0x20\n  [1272.957011]  ? refcount_warn_saturate+0xba/0x110\n  [1272.957399]  btrfs_discard_cancel_work.cold+0x26/0x2b [btrfs]\n  [1272.957853]  btrfs_put_block_group.cold+0x5d/0x8e [btrfs]\n  [1272.958289]  btrfs_discard_workfn+0x194/0x380 [btrfs]\n  [1272.958729]  process_one_work+0x130/0x290\n  [1272.959026]  worker_thread+0x2ea/0x420\n  [1272.959335]  ? __pfx_worker_thread+0x10/0x10\n  [1272.959644]  kthread+0xd7/0x1c0\n  [1272.959872]  ? __pfx_kthread+0x10/0x10\n  [1272.960172]  ret_from_fork+0x30/0x50\n  [1272.960474]  ? __pfx_kthread+0x10/0x10\n  [1272.960745]  ret_from_fork_asm+0x1a/0x30\n  [1272.961035]  </TASK>\n  [1272.961238] ---[ end trace 0000000000000000 ]---\n\nThough we have seen them in the async discard workfn as well. It is\nmost likely to happen after a relocation finishes which cancels discard,\ntears down the block group, etc.\n\nFix this fully by taking the lock arou\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22115","epss":0.00141,"percentile":0.03732,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22115","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22115","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22125","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22125","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md/raid1,raid10: don't ignore IO flags  If blk-wbt is enabled by default, it's found that raid write performance is quite bad because all IO are throttled by wbt of underlying disks, due to flag REQ_IDLE is ignored. And turns out this behaviour exist since blk-wbt is introduced.  Other than REQ_IDLE, other flags should not be ignored as well, for example REQ_META can be set for filesystems, clearing it can cause priority reverse problems; And REQ_NOWAIT should not be cleared as well, because io will wait instead of failing directly in underlying disks.  Fix those problems by keep IO flags from master bio.  Fises: f51d46d0e7cb (\"md: add support for REQ_NOWAIT\")","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22125","epss":0.00181,"percentile":0.07834,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095025},"relatedVulnerabilities":[{"id":"CVE-2025-22125","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22125","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/10f4ff4baeb6951cf58282954318827b6852d501","https://git.kernel.org/stable/c/73506e581c0b1814cdfd2229d589f30751d7de26","https://git.kernel.org/stable/c/8a0adf3d778c4a0893c6d34a9e1b0082a6f1c495","https://git.kernel.org/stable/c/e879a0d9cb086c8e52ce6c04e5bfa63825a6213c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1,raid10: don't ignore IO flags\n\nIf blk-wbt is enabled by default, it's found that raid write performance\nis quite bad because all IO are throttled by wbt of underlying disks,\ndue to flag REQ_IDLE is ignored. And turns out this behaviour exist since\nblk-wbt is introduced.\n\nOther than REQ_IDLE, other flags should not be ignored as well, for\nexample REQ_META can be set for filesystems, clearing it can cause priority\nreverse problems; And REQ_NOWAIT should not be cleared as well, because\nio will wait instead of failing directly in underlying disks.\n\nFix those problems by keep IO flags from master bio.\n\nFises: f51d46d0e7cb (\"md: add support for REQ_NOWAIT\")","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22125","epss":0.00181,"percentile":0.07834,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22125","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-22127","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-22127","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix potential deadloop in prepare_compress_overwrite()  Jan Prusakowski reported a kernel hang issue as below:  When running xfstests on linux-next kernel (6.14.0-rc3, 6.12) I encountered a problem in generic/475 test where fsstress process gets blocked in __f2fs_write_data_pages() and the test hangs. The options I used are:  MKFS_OPTIONS  -- -O compression -O extra_attr -O project_quota -O quota /dev/vdc MOUNT_OPTIONS -- -o acl,user_xattr -o discard,compress_extension=* /dev/vdc /vdc  INFO: task kworker/u8:0:11 blocked for more than 122 seconds.       Not tainted 6.14.0-rc3-xfstests-lockdep #1 \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message. task:kworker/u8:0    state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208160 flags:0x00004000 Workqueue: writeback wb_workfn (flush-253:0) Call Trace:  <TASK>  __schedule+0x309/0x8e0  schedule+0x3a/0x100  schedule_preempt_disabled+0x15/0x30  __mutex_lock+0x59a/0xdb0  __f2fs_write_data_pages+0x3ac/0x400  do_writepages+0xe8/0x290  __writeback_single_inode+0x5c/0x360  writeback_sb_inodes+0x22f/0x570  wb_writeback+0xb0/0x410  wb_do_writeback+0x47/0x2f0  wb_workfn+0x5a/0x1c0  process_one_work+0x223/0x5b0  worker_thread+0x1d5/0x3c0  kthread+0xfd/0x230  ret_from_fork+0x31/0x50  ret_from_fork_asm+0x1a/0x30  </TASK>  The root cause is: once generic/475 starts toload error table to dm device, f2fs_prepare_compress_overwrite() will loop reading compressed cluster pages due to IO error, meanwhile it has held .writepages lock, it can block all other writeback tasks.  Let's fix this issue w/ below changes: - add f2fs_handle_page_eio() in prepare_compress_overwrite() to detect IO error. - detect cp_error earler in f2fs_read_multi_pages().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22127","epss":0.00139,"percentile":0.03623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22127","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.072975},"relatedVulnerabilities":[{"id":"CVE-2025-22127","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22127","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3147ee567dd9004a49826ddeaf0a4b12865d4409","https://git.kernel.org/stable/c/7215cf8ef54bdc9082dffac4662416d54961e258","https://git.kernel.org/stable/c/7cd460bd9e7c6e6c30a33982603f65fb5deab1e4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix potential deadloop in prepare_compress_overwrite()\n\nJan Prusakowski reported a kernel hang issue as below:\n\nWhen running xfstests on linux-next kernel (6.14.0-rc3, 6.12) I\nencountered a problem in generic/475 test where fsstress process\ngets blocked in __f2fs_write_data_pages() and the test hangs.\nThe options I used are:\n\nMKFS_OPTIONS  -- -O compression -O extra_attr -O project_quota -O quota /dev/vdc\nMOUNT_OPTIONS -- -o acl,user_xattr -o discard,compress_extension=* /dev/vdc /vdc\n\nINFO: task kworker/u8:0:11 blocked for more than 122 seconds.\n      Not tainted 6.14.0-rc3-xfstests-lockdep #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:kworker/u8:0    state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208160 flags:0x00004000\nWorkqueue: writeback wb_workfn (flush-253:0)\nCall Trace:\n <TASK>\n __schedule+0x309/0x8e0\n schedule+0x3a/0x100\n schedule_preempt_disabled+0x15/0x30\n __mutex_lock+0x59a/0xdb0\n __f2fs_write_data_pages+0x3ac/0x400\n do_writepages+0xe8/0x290\n __writeback_single_inode+0x5c/0x360\n writeback_sb_inodes+0x22f/0x570\n wb_writeback+0xb0/0x410\n wb_do_writeback+0x47/0x2f0\n wb_workfn+0x5a/0x1c0\n process_one_work+0x223/0x5b0\n worker_thread+0x1d5/0x3c0\n kthread+0xfd/0x230\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nThe root cause is: once generic/475 starts toload error table to dm\ndevice, f2fs_prepare_compress_overwrite() will loop reading compressed\ncluster pages due to IO error, meanwhile it has held .writepages lock,\nit can block all other writeback tasks.\n\nLet's fix this issue w/ below changes:\n- add f2fs_handle_page_eio() in prepare_compress_overwrite() to\ndetect IO error.\n- detect cp_error earler in f2fs_read_multi_pages().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22127","epss":0.00139,"percentile":0.03623,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-22127","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-22127","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-23129","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-23129","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path  If a shared IRQ is used by the driver due to platform limitation, then the IRQ affinity hint is set right after the allocation of IRQ vectors in ath11k_pci_alloc_msi(). This does no harm unless one of the functions requesting the IRQ fails and attempt to free the IRQ. This results in the below warning:  WARNING: CPU: 7 PID: 349 at kernel/irq/manage.c:1929 free_irq+0x278/0x29c Call trace:  free_irq+0x278/0x29c  ath11k_pcic_free_irq+0x70/0x10c [ath11k]  ath11k_pci_probe+0x800/0x820 [ath11k_pci]  local_pci_probe+0x40/0xbc  The warning is due to not clearing the affinity hint before freeing the IRQs.  So to fix this issue, clear the IRQ affinity hint before calling ath11k_pcic_free_irq() in the error path. The affinity will be cleared once again further down the error path due to code organization, but that does no harm.  Tested-on: QCA6390 hw2.0 PCI WLAN.HST.1.0.1-05266-QCAHSTSWPLZ_V2_TO_X86-1","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-23129","epss":0.00179,"percentile":0.07599,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.093975},"relatedVulnerabilities":[{"id":"CVE-2025-23129","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-23129","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3fc42cfcc6e336f25dee79b34e57c4a63cd652a5","https://git.kernel.org/stable/c/68410c5bd381a81bcc92b808e7dc4e6b9ed25d11","https://git.kernel.org/stable/c/80dc5a2ce5b75d648e08549617f5c555d07ae43c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path\n\nIf a shared IRQ is used by the driver due to platform limitation, then the\nIRQ affinity hint is set right after the allocation of IRQ vectors in\nath11k_pci_alloc_msi(). This does no harm unless one of the functions\nrequesting the IRQ fails and attempt to free the IRQ. This results in the\nbelow warning:\n\nWARNING: CPU: 7 PID: 349 at kernel/irq/manage.c:1929 free_irq+0x278/0x29c\nCall trace:\n free_irq+0x278/0x29c\n ath11k_pcic_free_irq+0x70/0x10c [ath11k]\n ath11k_pci_probe+0x800/0x820 [ath11k_pci]\n local_pci_probe+0x40/0xbc\n\nThe warning is due to not clearing the affinity hint before freeing the\nIRQs.\n\nSo to fix this issue, clear the IRQ affinity hint before calling\nath11k_pcic_free_irq() in the error path. The affinity will be cleared once\nagain further down the error path due to code organization, but that does\nno harm.\n\nTested-on: QCA6390 hw2.0 PCI WLAN.HST.1.0.1-05266-QCAHSTSWPLZ_V2_TO_X86-1","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-23129","epss":0.00179,"percentile":0.07599,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-23129","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-23130","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-23130","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to avoid panic once fallocation fails for pinfile  syzbot reports a f2fs bug as below:  ------------[ cut here ]------------ kernel BUG at fs/f2fs/segment.c:2746! CPU: 0 UID: 0 PID: 5323 Comm: syz.0.0 Not tainted 6.13.0-rc2-syzkaller-00018-g7cb1b4663150 #0 RIP: 0010:get_new_segment fs/f2fs/segment.c:2746 [inline] RIP: 0010:new_curseg+0x1f52/0x1f70 fs/f2fs/segment.c:2876 Call Trace:  <TASK>  __allocate_new_segment+0x1ce/0x940 fs/f2fs/segment.c:3210  f2fs_allocate_new_section fs/f2fs/segment.c:3224 [inline]  f2fs_allocate_pinning_section+0xfa/0x4e0 fs/f2fs/segment.c:3238  f2fs_expand_inode_data+0x696/0xca0 fs/f2fs/file.c:1830  f2fs_fallocate+0x537/0xa10 fs/f2fs/file.c:1940  vfs_fallocate+0x569/0x6e0 fs/open.c:327  do_vfs_ioctl+0x258c/0x2e40 fs/ioctl.c:885  __do_sys_ioctl fs/ioctl.c:904 [inline]  __se_sys_ioctl+0x80/0x170 fs/ioctl.c:892  do_syscall_x64 arch/x86/entry/common.c:52 [inline]  do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Concurrent pinfile allocation may run out of free section, result in panic in get_new_segment(), let's expand pin_sem lock coverage to include f2fs_gc(), so that we can make sure to reclaim enough free space for following allocation.  In addition, do below changes to enhance error path handling: - call f2fs_bug_on() only in non-pinfile allocation path in get_new_segment(). - call reset_curseg_fields() to reset all fields of curseg in new_curseg()","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-23130","epss":0.00179,"percentile":0.076,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.093975},"relatedVulnerabilities":[{"id":"CVE-2025-23130","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-23130","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2dda0930fb79b847b4bfceb737577d0f6bc24d7d","https://git.kernel.org/stable/c/48ea8b200414ac69ea96f4c231f5c7ef1fbeffef","https://git.kernel.org/stable/c/9392862608d081a8346a3b841f862d732fce954b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid panic once fallocation fails for pinfile\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/segment.c:2746!\nCPU: 0 UID: 0 PID: 5323 Comm: syz.0.0 Not tainted 6.13.0-rc2-syzkaller-00018-g7cb1b4663150 #0\nRIP: 0010:get_new_segment fs/f2fs/segment.c:2746 [inline]\nRIP: 0010:new_curseg+0x1f52/0x1f70 fs/f2fs/segment.c:2876\nCall Trace:\n <TASK>\n __allocate_new_segment+0x1ce/0x940 fs/f2fs/segment.c:3210\n f2fs_allocate_new_section fs/f2fs/segment.c:3224 [inline]\n f2fs_allocate_pinning_section+0xfa/0x4e0 fs/f2fs/segment.c:3238\n f2fs_expand_inode_data+0x696/0xca0 fs/f2fs/file.c:1830\n f2fs_fallocate+0x537/0xa10 fs/f2fs/file.c:1940\n vfs_fallocate+0x569/0x6e0 fs/open.c:327\n do_vfs_ioctl+0x258c/0x2e40 fs/ioctl.c:885\n __do_sys_ioctl fs/ioctl.c:904 [inline]\n __se_sys_ioctl+0x80/0x170 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nConcurrent pinfile allocation may run out of free section, result in\npanic in get_new_segment(), let's expand pin_sem lock coverage to\ninclude f2fs_gc(), so that we can make sure to reclaim enough free\nspace for following allocation.\n\nIn addition, do below changes to enhance error path handling:\n- call f2fs_bug_on() only in non-pinfile allocation path in\nget_new_segment().\n- call reset_curseg_fields() to reset all fields of curseg in\nnew_curseg()","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-23130","epss":0.00179,"percentile":0.076,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-23130","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-23132","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-23132","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: quota: fix to avoid warning in dquot_writeback_dquots()  F2FS-fs (dm-59): checkpoint=enable has some unwritten data.  ------------[ cut here ]------------ WARNING: CPU: 6 PID: 8013 at fs/quota/dquot.c:691 dquot_writeback_dquots+0x2fc/0x308 pc : dquot_writeback_dquots+0x2fc/0x308 lr : f2fs_quota_sync+0xcc/0x1c4 Call trace: dquot_writeback_dquots+0x2fc/0x308 f2fs_quota_sync+0xcc/0x1c4 f2fs_write_checkpoint+0x3d4/0x9b0 f2fs_issue_checkpoint+0x1bc/0x2c0 f2fs_sync_fs+0x54/0x150 f2fs_do_sync_file+0x2f8/0x814 __f2fs_ioctl+0x1960/0x3244 f2fs_ioctl+0x54/0xe0 __arm64_sys_ioctl+0xa8/0xe4 invoke_syscall+0x58/0x114  checkpoint and f2fs_remount may race as below, resulting triggering warning in dquot_writeback_dquots().  atomic write                                    remount                                                 - do_remount                                                  - down_write(&sb->s_umount);                                                   - f2fs_remount - ioctl  - f2fs_do_sync_file   - f2fs_sync_fs    - f2fs_write_checkpoint     - block_operations      - locked = down_read_trylock(&sbi->sb->s_umount)        : fail to lock due to the write lock was held by remount                                                  - up_write(&sb->s_umount);      - f2fs_quota_sync       - dquot_writeback_dquots        - WARN_ON_ONCE(!rwsem_is_locked(&sb->s_umount))        : trigger warning because s_umount lock was unlocked by remount  If checkpoint comes from mount/umount/remount/freeze/quotactl, caller of checkpoint has already held s_umount lock, calling dquot_writeback_dquots() in the context should be safe.  So let's record task to sbi->umount_lock_holder, so that checkpoint can know whether the lock has held in the context or not by checking current w/ it.  In addition, in order to not misrepresent caller of checkpoint, we should not allow to trigger async checkpoint for those callers: mount/umount/remount/ freeze/quotactl.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-23132","epss":0.00162,"percentile":0.0572,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08505},"relatedVulnerabilities":[{"id":"CVE-2025-23132","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-23132","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/d7acf0a6c87aa282c86a36dbaa2f92fda88c5884","https://git.kernel.org/stable/c/eb85c2410d6f581e957cd03a644ff6ddbe592af9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: quota: fix to avoid warning in dquot_writeback_dquots()\n\nF2FS-fs (dm-59): checkpoint=enable has some unwritten data.\n\n------------[ cut here ]------------\nWARNING: CPU: 6 PID: 8013 at fs/quota/dquot.c:691 dquot_writeback_dquots+0x2fc/0x308\npc : dquot_writeback_dquots+0x2fc/0x308\nlr : f2fs_quota_sync+0xcc/0x1c4\nCall trace:\ndquot_writeback_dquots+0x2fc/0x308\nf2fs_quota_sync+0xcc/0x1c4\nf2fs_write_checkpoint+0x3d4/0x9b0\nf2fs_issue_checkpoint+0x1bc/0x2c0\nf2fs_sync_fs+0x54/0x150\nf2fs_do_sync_file+0x2f8/0x814\n__f2fs_ioctl+0x1960/0x3244\nf2fs_ioctl+0x54/0xe0\n__arm64_sys_ioctl+0xa8/0xe4\ninvoke_syscall+0x58/0x114\n\ncheckpoint and f2fs_remount may race as below, resulting triggering warning\nin dquot_writeback_dquots().\n\natomic write                                    remount\n                                                - do_remount\n                                                 - down_write(&sb->s_umount);\n                                                  - f2fs_remount\n- ioctl\n - f2fs_do_sync_file\n  - f2fs_sync_fs\n   - f2fs_write_checkpoint\n    - block_operations\n     - locked = down_read_trylock(&sbi->sb->s_umount)\n       : fail to lock due to the write lock was held by remount\n                                                 - up_write(&sb->s_umount);\n     - f2fs_quota_sync\n      - dquot_writeback_dquots\n       - WARN_ON_ONCE(!rwsem_is_locked(&sb->s_umount))\n       : trigger warning because s_umount lock was unlocked by remount\n\nIf checkpoint comes from mount/umount/remount/freeze/quotactl, caller of\ncheckpoint has already held s_umount lock, calling dquot_writeback_dquots()\nin the context should be safe.\n\nSo let's record task to sbi->umount_lock_holder, so that checkpoint can\nknow whether the lock has held in the context or not by checking current\nw/ it.\n\nIn addition, in order to not misrepresent caller of checkpoint, we should\nnot allow to trigger async checkpoint for those callers: mount/umount/remount/\nfreeze/quotactl.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-23132","epss":0.00162,"percentile":0.0572,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-23132","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-23133","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-23133","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: update channel list in reg notifier instead reg worker  Currently when ath11k gets a new channel list, it will be processed according to the following steps: 1. update new channel list to cfg80211 and queue reg_work. 2. cfg80211 handles new channel list during reg_work. 3. update cfg80211's handled channel list to firmware by ath11k_reg_update_chan_list().  But ath11k will immediately execute step 3 after reg_work is just queued. Since step 2 is asynchronous, cfg80211 may not have completed handling the new channel list, which may leading to an out-of-bounds write error: BUG: KASAN: slab-out-of-bounds in ath11k_reg_update_chan_list Call Trace:     ath11k_reg_update_chan_list+0xbfe/0xfe0 [ath11k]     kfree+0x109/0x3a0     ath11k_regd_update+0x1cf/0x350 [ath11k]     ath11k_regd_update_work+0x14/0x20 [ath11k]     process_one_work+0xe35/0x14c0  Should ensure step 2 is completely done before executing step 3. Thus Wen raised patch[1]. When flag NL80211_REGDOM_SET_BY_DRIVER is set, cfg80211 will notify ath11k after step 2 is done.  So enable the flag NL80211_REGDOM_SET_BY_DRIVER then cfg80211 will notify ath11k after step 2 is done. At this time, there will be no KASAN bug during the execution of the step 3.  [1] https://patchwork.kernel.org/project/linux-wireless/patch/20230201065313.27203-1-quic_wgong@quicinc.com/  Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-23133","epss":0.00251,"percentile":0.16454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-23133","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.192015},"relatedVulnerabilities":[{"id":"CVE-2025-23133","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-23133","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/26618c039b78a76c373d4e02c5fbd52e3a73aead","https://git.kernel.org/stable/c/933ab187e679e6fbdeea1835ae39efcc59c022d2","https://git.kernel.org/stable/c/f952fb83c9c6f908d27500764c4aee1df04b9d3f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: update channel list in reg notifier instead reg worker\n\nCurrently when ath11k gets a new channel list, it will be processed\naccording to the following steps:\n1. update new channel list to cfg80211 and queue reg_work.\n2. cfg80211 handles new channel list during reg_work.\n3. update cfg80211's handled channel list to firmware by\nath11k_reg_update_chan_list().\n\nBut ath11k will immediately execute step 3 after reg_work is just\nqueued. Since step 2 is asynchronous, cfg80211 may not have completed\nhandling the new channel list, which may leading to an out-of-bounds\nwrite error:\nBUG: KASAN: slab-out-of-bounds in ath11k_reg_update_chan_list\nCall Trace:\n    ath11k_reg_update_chan_list+0xbfe/0xfe0 [ath11k]\n    kfree+0x109/0x3a0\n    ath11k_regd_update+0x1cf/0x350 [ath11k]\n    ath11k_regd_update_work+0x14/0x20 [ath11k]\n    process_one_work+0xe35/0x14c0\n\nShould ensure step 2 is completely done before executing step 3. Thus\nWen raised patch[1]. When flag NL80211_REGDOM_SET_BY_DRIVER is set,\ncfg80211 will notify ath11k after step 2 is done.\n\nSo enable the flag NL80211_REGDOM_SET_BY_DRIVER then cfg80211 will\nnotify ath11k after step 2 is done. At this time, there will be no\nKASAN bug during the execution of the step 3.\n\n[1] https://patchwork.kernel.org/project/linux-wireless/patch/20230201065313.27203-1-quic_wgong@quicinc.com/\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-23133","epss":0.00251,"percentile":0.16454,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-23133","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-23133","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37747","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37747","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf: Fix hang while freeing sigtrap event  Perf can hang while freeing a sigtrap event if a related deferred signal hadn't managed to be sent before the file got closed:  perf_event_overflow()    task_work_add(perf_pending_task)  fput()    task_work_add(____fput())  task_work_run()     ____fput()         perf_release()             perf_event_release_kernel()                 _free_event()                     perf_pending_task_sync()                         task_work_cancel() -> FAILED                         rcuwait_wait_event()  Once task_work_run() is running, the list of pending callbacks is removed from the task_struct and from this point on task_work_cancel() can't remove any pending and not yet started work items, hence the task_work_cancel() failure and the hang on rcuwait_wait_event().  Task work could be changed to remove one work at a time, so a work running on the current task can always cancel a pending one, however the wait / wake design is still subject to inverted dependencies when remote targets are involved, as pictured by Oleg:  T1                                                      T2  fd = perf_event_open(pid => T2->pid);                  fd = perf_event_open(pid => T1->pid); close(fd)                                              close(fd)     <IRQ>                                                  <IRQ>     perf_event_overflow()                                  perf_event_overflow()        task_work_add(perf_pending_task)                        task_work_add(perf_pending_task)     </IRQ>                                                 </IRQ>     fput()                                                 fput()         task_work_add(____fput())                              task_work_add(____fput())      task_work_run()                                        task_work_run()         ____fput()                                             ____fput()             perf_release()                                         perf_release()                 perf_event_release_kernel()                            perf_event_release_kernel()                     _free_event()                                          _free_event()                         perf_pending_task_sync()                               perf_pending_task_sync()                             rcuwait_wait_event()                                   rcuwait_wait_event()  Therefore the only option left is to acquire the event reference count upon queueing the perf task work and release it from the task work, just like it was done before 3a5465418f5f (\"perf: Fix event leak upon exec and file release\") but without the leaks it fixed.  Some adjustments are necessary to make it work:  * A child event might dereference its parent upon freeing. Care must be   taken to release the parent last.  * Some places assuming the event doesn't have any reference held and   therefore can be freed right away must instead put the reference and   let the reference counting to its job.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37747","epss":0.0018,"percentile":0.07679,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2025-37747","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37747","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1267bd38f161c1a27d9b722de017027167a225a0","https://git.kernel.org/stable/c/56799bc035658738f362acec3e7647bb84e68933","https://git.kernel.org/stable/c/665b87b8f8b3aeb49083ef3b65c4953e7753fc12","https://git.kernel.org/stable/c/fa1827fa968c0674e9b6fca223fa9fb4da4493eb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix hang while freeing sigtrap event\n\nPerf can hang while freeing a sigtrap event if a related deferred\nsignal hadn't managed to be sent before the file got closed:\n\nperf_event_overflow()\n   task_work_add(perf_pending_task)\n\nfput()\n   task_work_add(____fput())\n\ntask_work_run()\n    ____fput()\n        perf_release()\n            perf_event_release_kernel()\n                _free_event()\n                    perf_pending_task_sync()\n                        task_work_cancel() -> FAILED\n                        rcuwait_wait_event()\n\nOnce task_work_run() is running, the list of pending callbacks is\nremoved from the task_struct and from this point on task_work_cancel()\ncan't remove any pending and not yet started work items, hence the\ntask_work_cancel() failure and the hang on rcuwait_wait_event().\n\nTask work could be changed to remove one work at a time, so a work\nrunning on the current task can always cancel a pending one, however\nthe wait / wake design is still subject to inverted dependencies when\nremote targets are involved, as pictured by Oleg:\n\nT1                                                      T2\n\nfd = perf_event_open(pid => T2->pid);                  fd = perf_event_open(pid => T1->pid);\nclose(fd)                                              close(fd)\n    <IRQ>                                                  <IRQ>\n    perf_event_overflow()                                  perf_event_overflow()\n       task_work_add(perf_pending_task)                        task_work_add(perf_pending_task)\n    </IRQ>                                                 </IRQ>\n    fput()                                                 fput()\n        task_work_add(____fput())                              task_work_add(____fput())\n\n    task_work_run()                                        task_work_run()\n        ____fput()                                             ____fput()\n            perf_release()                                         perf_release()\n                perf_event_release_kernel()                            perf_event_release_kernel()\n                    _free_event()                                          _free_event()\n                        perf_pending_task_sync()                               perf_pending_task_sync()\n                            rcuwait_wait_event()                                   rcuwait_wait_event()\n\nTherefore the only option left is to acquire the event reference count\nupon queueing the perf task work and release it from the task work, just\nlike it was done before 3a5465418f5f (\"perf: Fix event leak upon exec and file release\")\nbut without the leaks it fixed.\n\nSome adjustments are necessary to make it work:\n\n* A child event might dereference its parent upon freeing. Care must be\n  taken to release the parent last.\n\n* Some places assuming the event doesn't have any reference held and\n  therefore can be freed right away must instead put the reference and\n  let the reference counting to its job.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37747","epss":0.0018,"percentile":0.07679,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37747","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37750","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37750","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix UAF in decryption with multichannel  After commit f7025d861694 (\"smb: client: allocate crypto only for primary server\") and commit b0abcd65ec54 (\"smb: client: fix UAF in async decryption\"), the channels started reusing AEAD TFM from primary channel to perform synchronous decryption, but that can't done as there could be multiple cifsd threads (one per channel) simultaneously accessing it to perform decryption.  This fixes the following KASAN splat when running fstest generic/249 with 'vers=3.1.1,multichannel,max_channels=4,seal' against Windows Server 2022:  BUG: KASAN: slab-use-after-free in gf128mul_4k_lle+0xba/0x110 Read of size 8 at addr ffff8881046c18a0 by task cifsd/986 CPU: 3 UID: 0 PID: 986 Comm: cifsd Not tainted 6.15.0-rc1 #1 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-3.fc41 04/01/2014 Call Trace:  <TASK>  dump_stack_lvl+0x5d/0x80  print_report+0x156/0x528  ? gf128mul_4k_lle+0xba/0x110  ? __virt_addr_valid+0x145/0x300  ? __phys_addr+0x46/0x90  ? gf128mul_4k_lle+0xba/0x110  kasan_report+0xdf/0x1a0  ? gf128mul_4k_lle+0xba/0x110  gf128mul_4k_lle+0xba/0x110  ghash_update+0x189/0x210  shash_ahash_update+0x295/0x370  ? __pfx_shash_ahash_update+0x10/0x10  ? __pfx_shash_ahash_update+0x10/0x10  ? __pfx_extract_iter_to_sg+0x10/0x10  ? ___kmalloc_large_node+0x10e/0x180  ? __asan_memset+0x23/0x50  crypto_ahash_update+0x3c/0xc0  gcm_hash_assoc_remain_continue+0x93/0xc0  crypt_message+0xe09/0xec0 [cifs]  ? __pfx_crypt_message+0x10/0x10 [cifs]  ? _raw_spin_unlock+0x23/0x40  ? __pfx_cifs_readv_from_socket+0x10/0x10 [cifs]  decrypt_raw_data+0x229/0x380 [cifs]  ? __pfx_decrypt_raw_data+0x10/0x10 [cifs]  ? __pfx_cifs_read_iter_from_socket+0x10/0x10 [cifs]  smb3_receive_transform+0x837/0xc80 [cifs]  ? __pfx_smb3_receive_transform+0x10/0x10 [cifs]  ? __pfx___might_resched+0x10/0x10  ? __pfx_smb3_is_transform_hdr+0x10/0x10 [cifs]  cifs_demultiplex_thread+0x692/0x1570 [cifs]  ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]  ? rcu_is_watching+0x20/0x50  ? rcu_lockdep_current_cpu_online+0x62/0xb0  ? find_held_lock+0x32/0x90  ? kvm_sched_clock_read+0x11/0x20  ? local_clock_noinstr+0xd/0xd0  ? trace_irq_enable.constprop.0+0xa8/0xe0  ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]  kthread+0x1fe/0x380  ? kthread+0x10f/0x380  ? __pfx_kthread+0x10/0x10  ? local_clock_noinstr+0xd/0xd0  ? ret_from_fork+0x1b/0x60  ? local_clock+0x15/0x30  ? lock_release+0x29b/0x390  ? rcu_is_watching+0x20/0x50  ? __pfx_kthread+0x10/0x10  ret_from_fork+0x31/0x60  ? __pfx_kthread+0x10/0x10  ret_from_fork_asm+0x1a/0x30  </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37750","epss":0.00367,"percentile":0.30019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37750","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28075500000000003},"relatedVulnerabilities":[{"id":"CVE-2025-37750","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37750","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/9502dd5c7029902f4a425bf959917a5a9e7c0e50","https://git.kernel.org/stable/c/950557922c1298464749c216d8763e97faf5d0a6","https://git.kernel.org/stable/c/aa5a1e4b882964eb79d5b5d1d1e8a1a5efbb1d15","https://git.kernel.org/stable/c/e859b216d94668bc66330e61be201234f4413d1a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix UAF in decryption with multichannel\n\nAfter commit f7025d861694 (\"smb: client: allocate crypto only for\nprimary server\") and commit b0abcd65ec54 (\"smb: client: fix UAF in\nasync decryption\"), the channels started reusing AEAD TFM from primary\nchannel to perform synchronous decryption, but that can't done as\nthere could be multiple cifsd threads (one per channel) simultaneously\naccessing it to perform decryption.\n\nThis fixes the following KASAN splat when running fstest generic/249\nwith 'vers=3.1.1,multichannel,max_channels=4,seal' against Windows\nServer 2022:\n\nBUG: KASAN: slab-use-after-free in gf128mul_4k_lle+0xba/0x110\nRead of size 8 at addr ffff8881046c18a0 by task cifsd/986\nCPU: 3 UID: 0 PID: 986 Comm: cifsd Not tainted 6.15.0-rc1 #1\nPREEMPT(voluntary)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-3.fc41\n04/01/2014\nCall Trace:\n <TASK>\n dump_stack_lvl+0x5d/0x80\n print_report+0x156/0x528\n ? gf128mul_4k_lle+0xba/0x110\n ? __virt_addr_valid+0x145/0x300\n ? __phys_addr+0x46/0x90\n ? gf128mul_4k_lle+0xba/0x110\n kasan_report+0xdf/0x1a0\n ? gf128mul_4k_lle+0xba/0x110\n gf128mul_4k_lle+0xba/0x110\n ghash_update+0x189/0x210\n shash_ahash_update+0x295/0x370\n ? __pfx_shash_ahash_update+0x10/0x10\n ? __pfx_shash_ahash_update+0x10/0x10\n ? __pfx_extract_iter_to_sg+0x10/0x10\n ? ___kmalloc_large_node+0x10e/0x180\n ? __asan_memset+0x23/0x50\n crypto_ahash_update+0x3c/0xc0\n gcm_hash_assoc_remain_continue+0x93/0xc0\n crypt_message+0xe09/0xec0 [cifs]\n ? __pfx_crypt_message+0x10/0x10 [cifs]\n ? _raw_spin_unlock+0x23/0x40\n ? __pfx_cifs_readv_from_socket+0x10/0x10 [cifs]\n decrypt_raw_data+0x229/0x380 [cifs]\n ? __pfx_decrypt_raw_data+0x10/0x10 [cifs]\n ? __pfx_cifs_read_iter_from_socket+0x10/0x10 [cifs]\n smb3_receive_transform+0x837/0xc80 [cifs]\n ? __pfx_smb3_receive_transform+0x10/0x10 [cifs]\n ? __pfx___might_resched+0x10/0x10\n ? __pfx_smb3_is_transform_hdr+0x10/0x10 [cifs]\n cifs_demultiplex_thread+0x692/0x1570 [cifs]\n ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]\n ? rcu_is_watching+0x20/0x50\n ? rcu_lockdep_current_cpu_online+0x62/0xb0\n ? find_held_lock+0x32/0x90\n ? kvm_sched_clock_read+0x11/0x20\n ? local_clock_noinstr+0xd/0xd0\n ? trace_irq_enable.constprop.0+0xa8/0xe0\n ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]\n kthread+0x1fe/0x380\n ? kthread+0x10f/0x380\n ? __pfx_kthread+0x10/0x10\n ? local_clock_noinstr+0xd/0xd0\n ? ret_from_fork+0x1b/0x60\n ? local_clock+0x15/0x30\n ? lock_release+0x29b/0x390\n ? rcu_is_watching+0x20/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x31/0x60\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37750","epss":0.00367,"percentile":0.30019,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37750","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37750","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37776","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37776","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free in smb_break_all_levII_oplock()  There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use read lock to protect whole loop.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37776","epss":0.00337,"percentile":0.26644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37776","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24432500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-37776","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37776","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/18b4fac5ef17f77fed9417d22210ceafd6525fc7","https://git.kernel.org/stable/c/296cb5457cc6f4a754c4ae29855f8a253d52bcc6","https://git.kernel.org/stable/c/d54ab1520d43e95f9b2e22d7a05fc9614192e5a5","https://git.kernel.org/stable/c/d73686367ad68534257cd88a36ca3c52cb8b81d8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in smb_break_all_levII_oplock()\n\nThere is a room in smb_break_all_levII_oplock that can cause racy issues\nwhen unlocking in the middle of the loop. This patch use read lock\nto protect whole loop.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37776","epss":0.00337,"percentile":0.26644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37776","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37776","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37777","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37777","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free in __smb2_lease_break_noti()  Move tcp_transport free to ksmbd_conn_free. If ksmbd connection is referenced when ksmbd server thread terminates, It will not be freed, but conn->tcp_transport is freed. __smb2_lease_break_noti can be performed asynchronously when the connection is disconnected. __smb2_lease_break_noti calls ksmbd_conn_write, which can cause use-after-free when conn->ksmbd_transport is already freed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37777","epss":0.00353,"percentile":0.28483,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37777","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.270045},"relatedVulnerabilities":[{"id":"CVE-2025-37777","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37777","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1aec4d14cf81b7b3e7b69eb1cfa94144eed7138e","https://git.kernel.org/stable/c/1da8bd9a10ecd718692732294d15fd801c0eabb5","https://git.kernel.org/stable/c/21a4e47578d44c6b37c4fc4aba8ed7cc8dbb13de","https://git.kernel.org/stable/c/e59796fc80603bcd8569d4d2e10b213c1918edb4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in __smb2_lease_break_noti()\n\nMove tcp_transport free to ksmbd_conn_free. If ksmbd connection is\nreferenced when ksmbd server thread terminates, It will not be freed,\nbut conn->tcp_transport is freed. __smb2_lease_break_noti can be performed\nasynchronously when the connection is disconnected. __smb2_lease_break_noti\ncalls ksmbd_conn_write, which can cause use-after-free\nwhen conn->ksmbd_transport is already freed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37777","epss":0.00353,"percentile":0.28483,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37777","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37777","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37800","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37800","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  driver core: fix potential NULL pointer dereference in dev_uevent()  If userspace reads \"uevent\" device attribute at the same time as another threads unbinds the device from its driver, change to dev->driver from a valid pointer to NULL may result in crash. Fix this by using READ_ONCE() when fetching the pointer, and take bus' drivers klist lock to make sure driver instance will not disappear while we access it.  Use WRITE_ONCE() when setting the driver pointer to ensure there is no tearing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37800","epss":0.00194,"percentile":0.0918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37800","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10185000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-37800","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37800","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/18daa52418e7e4629ed1703b64777294209d2622","https://git.kernel.org/stable/c/2b344e779d9afd0fcb5ee4000e4d0fc7d8d867eb","https://git.kernel.org/stable/c/3781e4b83e174364998855de777e184cf0b62c40","https://git.kernel.org/stable/c/abe56be73eb10a677d16066f65ff9d30251f5eee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: fix potential NULL pointer dereference in dev_uevent()\n\nIf userspace reads \"uevent\" device attribute at the same time as another\nthreads unbinds the device from its driver, change to dev->driver from a\nvalid pointer to NULL may result in crash. Fix this by using READ_ONCE()\nwhen fetching the pointer, and take bus' drivers klist lock to make sure\ndriver instance will not disappear while we access it.\n\nUse WRITE_ONCE() when setting the driver pointer to ensure there is no\ntearing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37800","epss":0.00194,"percentile":0.0918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37800","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37800","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37802","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37802","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix WARNING \"do not call blocking ops when !TASK_RUNNING\"  wait_event_timeout() will set the state of the current task to TASK_UNINTERRUPTIBLE, before doing the condition check. This means that ksmbd_durable_scavenger_alive() will try to acquire the mutex while already in a sleeping state. The scheduler warns us by giving the following warning:  do not call blocking ops when !TASK_RUNNING; state=2 set at  [<0000000061515a6f>] prepare_to_wait_event+0x9f/0x6c0 WARNING: CPU: 2 PID: 4147 at kernel/sched/core.c:10099 __might_sleep+0x12f/0x160  mutex lock is not needed in ksmbd_durable_scavenger_alive().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37802","epss":0.00324,"percentile":0.25194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37802","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1701},"relatedVulnerabilities":[{"id":"CVE-2025-37802","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37802","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1df0d4c616138784e033ad337961b6e1a6bcd999","https://git.kernel.org/stable/c/8f805b3746d2f41702c77cba22f94f8415fadd1a","https://git.kernel.org/stable/c/cd161198e091e8a62b9bd631be970ea9a87d2d6a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix WARNING \"do not call blocking ops when !TASK_RUNNING\"\n\nwait_event_timeout() will set the state of the current\ntask to TASK_UNINTERRUPTIBLE, before doing the condition check. This\nmeans that ksmbd_durable_scavenger_alive() will try to acquire the mutex\nwhile already in a sleeping state. The scheduler warns us by giving\nthe following warning:\n\ndo not call blocking ops when !TASK_RUNNING; state=2 set at\n [<0000000061515a6f>] prepare_to_wait_event+0x9f/0x6c0\nWARNING: CPU: 2 PID: 4147 at kernel/sched/core.c:10099 __might_sleep+0x12f/0x160\n\nmutex lock is not needed in ksmbd_durable_scavenger_alive().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37802","epss":0.00324,"percentile":0.25194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37802","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37802","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37806","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: Keep write operations atomic  syzbot reported a NULL pointer dereference in __generic_file_write_iter. [1]  Before the write operation is completed, the user executes ioctl[2] to clear the compress flag of the file, which causes the is_compressed() judgment to return 0, further causing the program to enter the wrong process and call the wrong ops ntfs_aops_cmpr, which triggers the null pointer dereference of write_begin.  Use inode lock to synchronize ioctl and write to avoid this case.  [1] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 Mem abort info:   ESR = 0x0000000086000006   EC = 0x21: IABT (current EL), IL = 32 bits   SET = 0, FnV = 0   EA = 0, S1PTW = 0   FSC = 0x06: level 2 translation fault user pgtable: 4k pages, 48-bit VAs, pgdp=000000011896d000 [0000000000000000] pgd=0800000118b44403, p4d=0800000118b44403, pud=0800000117517403, pmd=0000000000000000 Internal error: Oops: 0000000086000006 [#1] PREEMPT SMP Modules linked in: CPU: 0 UID: 0 PID: 6427 Comm: syz-executor347 Not tainted 6.13.0-rc3-syzkaller-g573067a5a685 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : 0x0 lr : generic_perform_write+0x29c/0x868 mm/filemap.c:4055 sp : ffff80009d4978a0 x29: ffff80009d4979c0 x28: dfff800000000000 x27: ffff80009d497bc8 x26: 0000000000000000 x25: ffff80009d497960 x24: ffff80008ba71c68 x23: 0000000000000000 x22: ffff0000c655dac0 x21: 0000000000001000 x20: 000000000000000c x19: 1ffff00013a92f2c x18: ffff0000e183aa1c x17: 0004060000000014 x16: ffff800083275834 x15: 0000000000000001 x14: 0000000000000000 x13: 0000000000000001 x12: ffff0000c655dac0 x11: 0000000000ff0100 x10: 0000000000ff0100 x9 : 0000000000000000 x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000 x5 : ffff80009d497980 x4 : ffff80009d497960 x3 : 0000000000001000 x2 : 0000000000000000 x1 : ffff0000e183a928 x0 : ffff0000d60b0fc0 Call trace:  0x0 (P)  __generic_file_write_iter+0xfc/0x204 mm/filemap.c:4156  ntfs_file_write_iter+0x54c/0x630 fs/ntfs3/file.c:1267  new_sync_write fs/read_write.c:586 [inline]  vfs_write+0x920/0xcf4 fs/read_write.c:679  ksys_write+0x15c/0x26c fs/read_write.c:731  __do_sys_write fs/read_write.c:742 [inline]  __se_sys_write fs/read_write.c:739 [inline]  __arm64_sys_write+0x7c/0x90 fs/read_write.c:739  __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]  invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49  el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132  do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151  el0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:744  el0t_64_sync_handler+0x84/0x108 arch/arm64/kernel/entry-common.c:762  [2] ioctl$FS_IOC_SETFLAGS(r0, 0x40086602, &(0x7f00000000c0)=0x20)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37806","epss":0.00187,"percentile":0.08373,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37806","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.098175},"relatedVulnerabilities":[{"id":"CVE-2025-37806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37806","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/285cec318bf5a7a6c8ba999b2b6ec96f9a20590f","https://git.kernel.org/stable/c/464139e18f619aa14fb921a61721862f43421c54","https://git.kernel.org/stable/c/8db49e89a7f8b48ee59fa9ad32b6ed0879747df8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Keep write operations atomic\n\nsyzbot reported a NULL pointer dereference in __generic_file_write_iter. [1]\n\nBefore the write operation is completed, the user executes ioctl[2] to clear\nthe compress flag of the file, which causes the is_compressed() judgment to\nreturn 0, further causing the program to enter the wrong process and call the\nwrong ops ntfs_aops_cmpr, which triggers the null pointer dereference of\nwrite_begin.\n\nUse inode lock to synchronize ioctl and write to avoid this case.\n\n[1]\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000000\nMem abort info:\n  ESR = 0x0000000086000006\n  EC = 0x21: IABT (current EL), IL = 32 bits\n  SET = 0, FnV = 0\n  EA = 0, S1PTW = 0\n  FSC = 0x06: level 2 translation fault\nuser pgtable: 4k pages, 48-bit VAs, pgdp=000000011896d000\n[0000000000000000] pgd=0800000118b44403, p4d=0800000118b44403, pud=0800000117517403, pmd=0000000000000000\nInternal error: Oops: 0000000086000006 [#1] PREEMPT SMP\nModules linked in:\nCPU: 0 UID: 0 PID: 6427 Comm: syz-executor347 Not tainted 6.13.0-rc3-syzkaller-g573067a5a685 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\npstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : 0x0\nlr : generic_perform_write+0x29c/0x868 mm/filemap.c:4055\nsp : ffff80009d4978a0\nx29: ffff80009d4979c0 x28: dfff800000000000 x27: ffff80009d497bc8\nx26: 0000000000000000 x25: ffff80009d497960 x24: ffff80008ba71c68\nx23: 0000000000000000 x22: ffff0000c655dac0 x21: 0000000000001000\nx20: 000000000000000c x19: 1ffff00013a92f2c x18: ffff0000e183aa1c\nx17: 0004060000000014 x16: ffff800083275834 x15: 0000000000000001\nx14: 0000000000000000 x13: 0000000000000001 x12: ffff0000c655dac0\nx11: 0000000000ff0100 x10: 0000000000ff0100 x9 : 0000000000000000\nx8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\nx5 : ffff80009d497980 x4 : ffff80009d497960 x3 : 0000000000001000\nx2 : 0000000000000000 x1 : ffff0000e183a928 x0 : ffff0000d60b0fc0\nCall trace:\n 0x0 (P)\n __generic_file_write_iter+0xfc/0x204 mm/filemap.c:4156\n ntfs_file_write_iter+0x54c/0x630 fs/ntfs3/file.c:1267\n new_sync_write fs/read_write.c:586 [inline]\n vfs_write+0x920/0xcf4 fs/read_write.c:679\n ksys_write+0x15c/0x26c fs/read_write.c:731\n __do_sys_write fs/read_write.c:742 [inline]\n __se_sys_write fs/read_write.c:739 [inline]\n __arm64_sys_write+0x7c/0x90 fs/read_write.c:739\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:744\n el0t_64_sync_handler+0x84/0x108 arch/arm64/kernel/entry-common.c:762\n\n[2]\nioctl$FS_IOC_SETFLAGS(r0, 0x40086602, &(0x7f00000000c0)=0x20)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37806","epss":0.00187,"percentile":0.08373,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37806","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37806","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37807","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37807","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix kmemleak warning for percpu hashmap  Vlad Poenaru reported the following kmemleak issue:    unreferenced object 0x606fd7c44ac8 (size 32):     backtrace (crc 0):       pcpu_alloc_noprof+0x730/0xeb0       bpf_map_alloc_percpu+0x69/0xc0       prealloc_init+0x9d/0x1b0       htab_map_alloc+0x363/0x510       map_create+0x215/0x3a0       __sys_bpf+0x16b/0x3e0       __x64_sys_bpf+0x18/0x20       do_syscall_64+0x7b/0x150       entry_SYSCALL_64_after_hwframe+0x4b/0x53  Further investigation shows the reason is due to not 8-byte aligned store of percpu pointer in htab_elem_set_ptr():   *(void __percpu **)(l->key + key_size) = pptr;  Note that the whole htab_elem alignment is 8 (for x86_64). If the key_size is 4, that means pptr is stored in a location which is 4 byte aligned but not 8 byte aligned. In mm/kmemleak.c, scan_block() scans the memory based on 8 byte stride, so it won't detect above pptr, hence reporting the memory leak.  In htab_map_alloc(), we already have          htab->elem_size = sizeof(struct htab_elem) +                           round_up(htab->map.key_size, 8);         if (percpu)                 htab->elem_size += sizeof(void *);         else                 htab->elem_size += round_up(htab->map.value_size, 8);  So storing pptr with 8-byte alignment won't cause any problem and can fix kmemleak too.  The issue can be reproduced with bpf selftest as well:   1. Enable CONFIG_DEBUG_KMEMLEAK config   2. Add a getchar() before skel destroy in test_hash_map() in prog_tests/for_each.c.      The purpose is to keep map available so kmemleak can be detected.   3. run './test_progs -t for_each/hash_map &' and a kmemleak should be reported.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37807","epss":0.00187,"percentile":0.08373,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37807","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.098175},"relatedVulnerabilities":[{"id":"CVE-2025-37807","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37807","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/11ba7ce076e5903e7bdc1fd1498979c331b3c286","https://git.kernel.org/stable/c/1f1c29aa1934177349c17e3c32e68ec38a7a56df","https://git.kernel.org/stable/c/7758e308aeda1038aba1944f7302d34161b3effe"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix kmemleak warning for percpu hashmap\n\nVlad Poenaru reported the following kmemleak issue:\n\n  unreferenced object 0x606fd7c44ac8 (size 32):\n    backtrace (crc 0):\n      pcpu_alloc_noprof+0x730/0xeb0\n      bpf_map_alloc_percpu+0x69/0xc0\n      prealloc_init+0x9d/0x1b0\n      htab_map_alloc+0x363/0x510\n      map_create+0x215/0x3a0\n      __sys_bpf+0x16b/0x3e0\n      __x64_sys_bpf+0x18/0x20\n      do_syscall_64+0x7b/0x150\n      entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nFurther investigation shows the reason is due to not 8-byte aligned\nstore of percpu pointer in htab_elem_set_ptr():\n  *(void __percpu **)(l->key + key_size) = pptr;\n\nNote that the whole htab_elem alignment is 8 (for x86_64). If the key_size\nis 4, that means pptr is stored in a location which is 4 byte aligned but\nnot 8 byte aligned. In mm/kmemleak.c, scan_block() scans the memory based\non 8 byte stride, so it won't detect above pptr, hence reporting the memory\nleak.\n\nIn htab_map_alloc(), we already have\n\n        htab->elem_size = sizeof(struct htab_elem) +\n                          round_up(htab->map.key_size, 8);\n        if (percpu)\n                htab->elem_size += sizeof(void *);\n        else\n                htab->elem_size += round_up(htab->map.value_size, 8);\n\nSo storing pptr with 8-byte alignment won't cause any problem and can fix\nkmemleak too.\n\nThe issue can be reproduced with bpf selftest as well:\n  1. Enable CONFIG_DEBUG_KMEMLEAK config\n  2. Add a getchar() before skel destroy in test_hash_map() in prog_tests/for_each.c.\n     The purpose is to keep map available so kmemleak can be detected.\n  3. run './test_progs -t for_each/hash_map &' and a kmemleak should be reported.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37807","epss":0.00187,"percentile":0.08373,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37807","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37807","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37833","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37833","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads  Fix niu_try_msix() to not cause a fatal trap on sparc systems.  Set PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to work around a bug in the hardware or firmware.  For each vector entry in the msix table, niu chips will cause a fatal trap if any registers in that entry are read before that entries' ENTRY_DATA register is written to. Testing indicates writes to other registers are not sufficient to prevent the fatal trap, however the value does not appear to matter. This only needs to happen once after power up, so simply rebooting into a kernel lacking this fix will NOT cause the trap.  NON-RESUMABLE ERROR: Reporting on cpu 64 NON-RESUMABLE ERROR: TPC [0x00000000005f6900] <msix_prepare_msi_desc+0x90/0xa0> NON-RESUMABLE ERROR: RAW [4010000000000016:00000e37f93e32ff:0000000202000080:ffffffffffffffff NON-RESUMABLE ERROR:      0000000800000000:0000000000000000:0000000000000000:0000000000000000] NON-RESUMABLE ERROR: handle [0x4010000000000016] stick [0x00000e37f93e32ff] NON-RESUMABLE ERROR: type [precise nonresumable] NON-RESUMABLE ERROR: attrs [0x02000080] < ASI sp-faulted priv > NON-RESUMABLE ERROR: raddr [0xffffffffffffffff] NON-RESUMABLE ERROR: insn effective address [0x000000c50020000c] NON-RESUMABLE ERROR: size [0x8] NON-RESUMABLE ERROR: asi [0x00] CPU: 64 UID: 0 PID: 745 Comm: kworker/64:1 Not tainted 6.11.5 #63 Workqueue: events work_for_cpu_fn TSTATE: 0000000011001602 TPC: 00000000005f6900 TNPC: 00000000005f6904 Y: 00000000    Not tainted TPC: <msix_prepare_msi_desc+0x90/0xa0> g0: 00000000000002e9 g1: 000000000000000c g2: 000000c50020000c g3: 0000000000000100 g4: ffff8000470307c0 g5: ffff800fec5be000 g6: ffff800047a08000 g7: 0000000000000000 o0: ffff800014feb000 o1: ffff800047a0b620 o2: 0000000000000011 o3: ffff800047a0b620 o4: 0000000000000080 o5: 0000000000000011 sp: ffff800047a0ad51 ret_pc: 00000000005f7128 RPC: <__pci_enable_msix_range+0x3cc/0x460> l0: 000000000000000d l1: 000000000000c01f l2: ffff800014feb0a8 l3: 0000000000000020 l4: 000000000000c000 l5: 0000000000000001 l6: 0000000020000000 l7: ffff800047a0b734 i0: ffff800014feb000 i1: ffff800047a0b730 i2: 0000000000000001 i3: 000000000000000d i4: 0000000000000000 i5: 0000000000000000 i6: ffff800047a0ae81 i7: 00000000101888b0 I7: <niu_try_msix.constprop.0+0xc0/0x130 [niu]> Call Trace: [<00000000101888b0>] niu_try_msix.constprop.0+0xc0/0x130 [niu] [<000000001018f840>] niu_get_invariants+0x183c/0x207c [niu] [<00000000101902fc>] niu_pci_init_one+0x27c/0x2fc [niu] [<00000000005ef3e4>] local_pci_probe+0x28/0x74 [<0000000000469240>] work_for_cpu_fn+0x8/0x1c [<000000000046b008>] process_scheduled_works+0x144/0x210 [<000000000046b518>] worker_thread+0x13c/0x1c0 [<00000000004710e0>] kthread+0xb8/0xc8 [<00000000004060c8>] ret_from_fork+0x1c/0x2c [<0000000000000000>] 0x0 Kernel panic - not syncing: Non-resumable error.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37833","epss":0.00174,"percentile":0.06974,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09135},"relatedVulnerabilities":[{"id":"CVE-2025-37833","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37833","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/64903e4849a71cf7f7c7e5d45225ccefc1280929","https://git.kernel.org/stable/c/c187aaa9e79b4b6d86ac7ba941e579ad33df5538","https://git.kernel.org/stable/c/fbb429ddff5c8e479edcc7dde5a542c9295944e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads\n\nFix niu_try_msix() to not cause a fatal trap on sparc systems.\n\nSet PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to\nwork around a bug in the hardware or firmware.\n\nFor each vector entry in the msix table, niu chips will cause a fatal\ntrap if any registers in that entry are read before that entries'\nENTRY_DATA register is written to. Testing indicates writes to other\nregisters are not sufficient to prevent the fatal trap, however the value\ndoes not appear to matter. This only needs to happen once after power up,\nso simply rebooting into a kernel lacking this fix will NOT cause the\ntrap.\n\nNON-RESUMABLE ERROR: Reporting on cpu 64\nNON-RESUMABLE ERROR: TPC [0x00000000005f6900] <msix_prepare_msi_desc+0x90/0xa0>\nNON-RESUMABLE ERROR: RAW [4010000000000016:00000e37f93e32ff:0000000202000080:ffffffffffffffff\nNON-RESUMABLE ERROR:      0000000800000000:0000000000000000:0000000000000000:0000000000000000]\nNON-RESUMABLE ERROR: handle [0x4010000000000016] stick [0x00000e37f93e32ff]\nNON-RESUMABLE ERROR: type [precise nonresumable]\nNON-RESUMABLE ERROR: attrs [0x02000080] < ASI sp-faulted priv >\nNON-RESUMABLE ERROR: raddr [0xffffffffffffffff]\nNON-RESUMABLE ERROR: insn effective address [0x000000c50020000c]\nNON-RESUMABLE ERROR: size [0x8]\nNON-RESUMABLE ERROR: asi [0x00]\nCPU: 64 UID: 0 PID: 745 Comm: kworker/64:1 Not tainted 6.11.5 #63\nWorkqueue: events work_for_cpu_fn\nTSTATE: 0000000011001602 TPC: 00000000005f6900 TNPC: 00000000005f6904 Y: 00000000    Not tainted\nTPC: <msix_prepare_msi_desc+0x90/0xa0>\ng0: 00000000000002e9 g1: 000000000000000c g2: 000000c50020000c g3: 0000000000000100\ng4: ffff8000470307c0 g5: ffff800fec5be000 g6: ffff800047a08000 g7: 0000000000000000\no0: ffff800014feb000 o1: ffff800047a0b620 o2: 0000000000000011 o3: ffff800047a0b620\no4: 0000000000000080 o5: 0000000000000011 sp: ffff800047a0ad51 ret_pc: 00000000005f7128\nRPC: <__pci_enable_msix_range+0x3cc/0x460>\nl0: 000000000000000d l1: 000000000000c01f l2: ffff800014feb0a8 l3: 0000000000000020\nl4: 000000000000c000 l5: 0000000000000001 l6: 0000000020000000 l7: ffff800047a0b734\ni0: ffff800014feb000 i1: ffff800047a0b730 i2: 0000000000000001 i3: 000000000000000d\ni4: 0000000000000000 i5: 0000000000000000 i6: ffff800047a0ae81 i7: 00000000101888b0\nI7: <niu_try_msix.constprop.0+0xc0/0x130 [niu]>\nCall Trace:\n[<00000000101888b0>] niu_try_msix.constprop.0+0xc0/0x130 [niu]\n[<000000001018f840>] niu_get_invariants+0x183c/0x207c [niu]\n[<00000000101902fc>] niu_pci_init_one+0x27c/0x2fc [niu]\n[<00000000005ef3e4>] local_pci_probe+0x28/0x74\n[<0000000000469240>] work_for_cpu_fn+0x8/0x1c\n[<000000000046b008>] process_scheduled_works+0x144/0x210\n[<000000000046b518>] worker_thread+0x13c/0x1c0\n[<00000000004710e0>] kthread+0xb8/0xc8\n[<00000000004060c8>] ret_from_fork+0x1c/0x2c\n[<0000000000000000>] 0x0\nKernel panic - not syncing: Non-resumable error.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37833","epss":0.00174,"percentile":0.06974,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37833","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37834","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37834","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/vmscan: don't try to reclaim hwpoison folio  Syzkaller reports a bug as follows:  Injecting memory failure for pfn 0x18b00e at process virtual address 0x20ffd000 Memory failure: 0x18b00e: dirty swapcache page still referenced by 2 users Memory failure: 0x18b00e: recovery action for dirty swapcache page: Failed page: refcount:2 mapcount:0 mapping:0000000000000000 index:0x20ffd pfn:0x18b00e memcg:ffff0000dd6d9000 anon flags: 0x5ffffe00482011(locked|dirty|arch_1|swapbacked|hwpoison|node=0|zone=2|lastcpupid=0xfffff) raw: 005ffffe00482011 dead000000000100 dead000000000122 ffff0000e232a7c9 raw: 0000000000020ffd 0000000000000000 00000002ffffffff ffff0000dd6d9000 page dumped because: VM_BUG_ON_FOLIO(!folio_test_uptodate(folio)) ------------[ cut here ]------------ kernel BUG at mm/swap_state.c:184! Internal error: Oops - BUG: 00000000f2000800 [#1] SMP Modules linked in: CPU: 0 PID: 60 Comm: kswapd0 Not tainted 6.6.0-gcb097e7de84e #3 Hardware name: linux,dummy-virt (DT) pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : add_to_swap+0xbc/0x158 lr : add_to_swap+0xbc/0x158 sp : ffff800087f37340 x29: ffff800087f37340 x28: fffffc00052c0380 x27: ffff800087f37780 x26: ffff800087f37490 x25: ffff800087f37c78 x24: ffff800087f377a0 x23: ffff800087f37c50 x22: 0000000000000000 x21: fffffc00052c03b4 x20: 0000000000000000 x19: fffffc00052c0380 x18: 0000000000000000 x17: 296f696c6f662865 x16: 7461646f7470755f x15: 747365745f6f696c x14: 6f6621284f494c4f x13: 0000000000000001 x12: ffff600036d8b97b x11: 1fffe00036d8b97a x10: ffff600036d8b97a x9 : dfff800000000000 x8 : 00009fffc9274686 x7 : ffff0001b6c5cbd3 x6 : 0000000000000001 x5 : ffff0000c25896c0 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 0000000000000000 x1 : ffff0000c25896c0 x0 : 0000000000000000 Call trace:  add_to_swap+0xbc/0x158  shrink_folio_list+0x12ac/0x2648  shrink_inactive_list+0x318/0x948  shrink_lruvec+0x450/0x720  shrink_node_memcgs+0x280/0x4a8  shrink_node+0x128/0x978  balance_pgdat+0x4f0/0xb20  kswapd+0x228/0x438  kthread+0x214/0x230  ret_from_fork+0x10/0x20  I can reproduce this issue with the following steps:  1) When a dirty swapcache page is isolated by reclaim process and the    page isn't locked, inject memory failure for the page.     me_swapcache_dirty() clears uptodate flag and tries to delete from lru,    but fails.  Reclaim process will put the hwpoisoned page back to lru.  2) The process that maps the hwpoisoned page exits, the page is deleted    the page will never be freed and will be in the lru forever.  3) If we trigger a reclaim again and tries to reclaim the page,    add_to_swap() will trigger VM_BUG_ON_FOLIO due to the uptodate flag is    cleared.  To fix it, skip the hwpoisoned page in shrink_folio_list().  Besides, the hwpoison folio may not be unmapped by hwpoison_user_mappings() yet, unmap it in shrink_folio_list(), otherwise the folio will fail to be unmaped by hwpoison_user_mappings() since the folio isn't in lru list.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37834","epss":0.00174,"percentile":0.06974,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09135},"relatedVulnerabilities":[{"id":"CVE-2025-37834","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37834","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1b0449544c6482179ac84530b61fc192a6527bfd","https://git.kernel.org/stable/c/1c9798bf8145a92abf45aa9d38a6406d9eb8bdf0","https://git.kernel.org/stable/c/912e9f0300c3564b72a8808db406e313193a37ad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmscan: don't try to reclaim hwpoison folio\n\nSyzkaller reports a bug as follows:\n\nInjecting memory failure for pfn 0x18b00e at process virtual address 0x20ffd000\nMemory failure: 0x18b00e: dirty swapcache page still referenced by 2 users\nMemory failure: 0x18b00e: recovery action for dirty swapcache page: Failed\npage: refcount:2 mapcount:0 mapping:0000000000000000 index:0x20ffd pfn:0x18b00e\nmemcg:ffff0000dd6d9000\nanon flags: 0x5ffffe00482011(locked|dirty|arch_1|swapbacked|hwpoison|node=0|zone=2|lastcpupid=0xfffff)\nraw: 005ffffe00482011 dead000000000100 dead000000000122 ffff0000e232a7c9\nraw: 0000000000020ffd 0000000000000000 00000002ffffffff ffff0000dd6d9000\npage dumped because: VM_BUG_ON_FOLIO(!folio_test_uptodate(folio))\n------------[ cut here ]------------\nkernel BUG at mm/swap_state.c:184!\nInternal error: Oops - BUG: 00000000f2000800 [#1] SMP\nModules linked in:\nCPU: 0 PID: 60 Comm: kswapd0 Not tainted 6.6.0-gcb097e7de84e #3\nHardware name: linux,dummy-virt (DT)\npstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : add_to_swap+0xbc/0x158\nlr : add_to_swap+0xbc/0x158\nsp : ffff800087f37340\nx29: ffff800087f37340 x28: fffffc00052c0380 x27: ffff800087f37780\nx26: ffff800087f37490 x25: ffff800087f37c78 x24: ffff800087f377a0\nx23: ffff800087f37c50 x22: 0000000000000000 x21: fffffc00052c03b4\nx20: 0000000000000000 x19: fffffc00052c0380 x18: 0000000000000000\nx17: 296f696c6f662865 x16: 7461646f7470755f x15: 747365745f6f696c\nx14: 6f6621284f494c4f x13: 0000000000000001 x12: ffff600036d8b97b\nx11: 1fffe00036d8b97a x10: ffff600036d8b97a x9 : dfff800000000000\nx8 : 00009fffc9274686 x7 : ffff0001b6c5cbd3 x6 : 0000000000000001\nx5 : ffff0000c25896c0 x4 : 0000000000000000 x3 : 0000000000000000\nx2 : 0000000000000000 x1 : ffff0000c25896c0 x0 : 0000000000000000\nCall trace:\n add_to_swap+0xbc/0x158\n shrink_folio_list+0x12ac/0x2648\n shrink_inactive_list+0x318/0x948\n shrink_lruvec+0x450/0x720\n shrink_node_memcgs+0x280/0x4a8\n shrink_node+0x128/0x978\n balance_pgdat+0x4f0/0xb20\n kswapd+0x228/0x438\n kthread+0x214/0x230\n ret_from_fork+0x10/0x20\n\nI can reproduce this issue with the following steps:\n\n1) When a dirty swapcache page is isolated by reclaim process and the\n   page isn't locked, inject memory failure for the page. \n   me_swapcache_dirty() clears uptodate flag and tries to delete from lru,\n   but fails.  Reclaim process will put the hwpoisoned page back to lru.\n\n2) The process that maps the hwpoisoned page exits, the page is deleted\n   the page will never be freed and will be in the lru forever.\n\n3) If we trigger a reclaim again and tries to reclaim the page,\n   add_to_swap() will trigger VM_BUG_ON_FOLIO due to the uptodate flag is\n   cleared.\n\nTo fix it, skip the hwpoisoned page in shrink_folio_list().  Besides, the\nhwpoison folio may not be unmapped by hwpoison_user_mappings() yet, unmap\nit in shrink_folio_list(), otherwise the folio will fail to be unmaped by\nhwpoison_user_mappings() since the folio isn't in lru list.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37834","epss":0.00174,"percentile":0.06974,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37834","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37842","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37842","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: fsl-qspi: use devm function instead of driver remove  Driver use devm APIs to manage clk/irq/resources and register the spi controller, but the legacy remove function will be called first during device detach and trigger kernel panic. Drop the remove function and use devm_add_action_or_reset() for driver cleanup to ensure the release sequence.  Trigger kernel panic on i.MX8MQ by echo 30bb0000.spi >/sys/bus/platform/drivers/fsl-quadspi/unbind","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37842","epss":0.00261,"percentile":0.17809,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.137025},"relatedVulnerabilities":[{"id":"CVE-2025-37842","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37842","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/40369bfe717e96e26650eeecfa5a6363563df6e4","https://git.kernel.org/stable/c/439688dbe82baa10d4430dc3252bb5ef1183a171","https://git.kernel.org/stable/c/50ae352c1848cab408fb4f7d7f50c71f818bbdbf","https://git.kernel.org/stable/c/f68b27d82a749117d9c7d7f33fa53f46373e38e2","https://git.kernel.org/stable/c/f9bfb3a5f6f616f3eb7665c8ff3bcb9760ae33c8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: fsl-qspi: use devm function instead of driver remove\n\nDriver use devm APIs to manage clk/irq/resources and register the spi\ncontroller, but the legacy remove function will be called first during\ndevice detach and trigger kernel panic. Drop the remove function and use\ndevm_add_action_or_reset() for driver cleanup to ensure the release\nsequence.\n\nTrigger kernel panic on i.MX8MQ by\necho 30bb0000.spi >/sys/bus/platform/drivers/fsl-quadspi/unbind","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37842","epss":0.00261,"percentile":0.17809,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37842","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37853","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37853","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: debugfs hang_hws skip GPU with MES  debugfs hang_hws is used by GPU reset test with HWS, for MES this crash the kernel with NULL pointer access because dqm->packet_mgr is not setup for MES path.  Skip GPU with MES for now, MES hang_hws debugfs interface will be supported later.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37853","epss":0.00261,"percentile":0.1781,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37853","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.137025},"relatedVulnerabilities":[{"id":"CVE-2025-37853","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37853","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1a322b330dc0b775d1d7a84e55c752d9451bfe7d","https://git.kernel.org/stable/c/24b9e0e2e6147314c22d821f0542c4dd9a320c40","https://git.kernel.org/stable/c/a36f8d544522a19ef06ed9e84667d154dcb6be52","https://git.kernel.org/stable/c/f84c57906f0fd2185e557d2552b20aa8430a4677","https://git.kernel.org/stable/c/fe9d0061c413f8fb8c529b18b592b04170850ded"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: debugfs hang_hws skip GPU with MES\n\ndebugfs hang_hws is used by GPU reset test with HWS, for MES this crash\nthe kernel with NULL pointer access because dqm->packet_mgr is not setup\nfor MES path.\n\nSkip GPU with MES for now, MES hang_hws debugfs interface will be\nsupported later.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37853","epss":0.00261,"percentile":0.1781,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37853","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37853","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37856","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37856","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: harden block_group::bg_list against list_del() races  As far as I can tell, these calls of list_del_init() on bg_list cannot run concurrently with btrfs_mark_bg_unused() or btrfs_mark_bg_to_reclaim(), as they are in transaction error paths and situations where the block group is readonly.  However, if there is any chance at all of racing with mark_bg_unused(), or a different future user of bg_list, better to be safe than sorry.  Otherwise we risk the following interleaving (bg_list refcount in parens)  T1 (some random op)                       T2 (btrfs_mark_bg_unused)                                         !list_empty(&bg->bg_list); (1) list_del_init(&bg->bg_list); (1)                                         list_move_tail (1) btrfs_put_block_group (0)                                         btrfs_delete_unused_bgs                                              bg = list_first_entry                                              list_del_init(&bg->bg_list);                                              btrfs_put_block_group(bg); (-1)  Ultimately, this results in a broken ref count that hits zero one deref early and the real final deref underflows the refcount, resulting in a WARNING.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37856","epss":0.0026,"percentile":0.17631,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13649999999999998},"relatedVulnerabilities":[{"id":"CVE-2025-37856","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37856","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/185fd73e5ac06027c4be9a129e59193f6a3ef202","https://git.kernel.org/stable/c/7511e29cf1355b2c47d0effb39e463119913e2f6","https://git.kernel.org/stable/c/909e60fb469d4101c6b08cf6e622efb062bb24a1","https://git.kernel.org/stable/c/bf089c4d1141b27332c092b1dcca5022c415a3b6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: harden block_group::bg_list against list_del() races\n\nAs far as I can tell, these calls of list_del_init() on bg_list cannot\nrun concurrently with btrfs_mark_bg_unused() or btrfs_mark_bg_to_reclaim(),\nas they are in transaction error paths and situations where the block\ngroup is readonly.\n\nHowever, if there is any chance at all of racing with mark_bg_unused(),\nor a different future user of bg_list, better to be safe than sorry.\n\nOtherwise we risk the following interleaving (bg_list refcount in parens)\n\nT1 (some random op)                       T2 (btrfs_mark_bg_unused)\n                                        !list_empty(&bg->bg_list); (1)\nlist_del_init(&bg->bg_list); (1)\n                                        list_move_tail (1)\nbtrfs_put_block_group (0)\n                                        btrfs_delete_unused_bgs\n                                             bg = list_first_entry\n                                             list_del_init(&bg->bg_list);\n                                             btrfs_put_block_group(bg); (-1)\n\nUltimately, this results in a broken ref count that hits zero one deref\nearly and the real final deref underflows the refcount, resulting in a WARNING.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37856","epss":0.0026,"percentile":0.17631,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37856","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37860","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37860","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sfc: fix NULL dereferences in ef100_process_design_param()  Since cited commit, ef100_probe_main() and hence also  ef100_check_design_params() run before efx->net_dev is created;  consequently, we cannot netif_set_tso_max_size() or _segs() at this  point. Move those netif calls to ef100_probe_netdev(), and also replace  netif_err within the design params code with pci_err.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37860","epss":0.00253,"percentile":0.16813,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37860","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-37860","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13282500000000003},"relatedVulnerabilities":[{"id":"CVE-2025-37860","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37860","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/8241ecec1cdc6699ae197d52d58e76bddd995fa5","https://git.kernel.org/stable/c/e56391011381d6d029da377a65ac314cb3d5def2","https://git.kernel.org/stable/c/f21623b8446735b5e2ac5f8ee69b8743177d7b19"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsfc: fix NULL dereferences in ef100_process_design_param()\n\nSince cited commit, ef100_probe_main() and hence also\n ef100_check_design_params() run before efx->net_dev is created;\n consequently, we cannot netif_set_tso_max_size() or _segs() at this\n point.\nMove those netif calls to ef100_probe_netdev(), and also replace\n netif_err within the design params code with pci_err.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37860","epss":0.00253,"percentile":0.16813,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37860","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-37860","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37860","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37861","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue  When the task management thread processes reply queues while the reset thread resets them, the task management thread accesses an invalid queue ID (0xFFFF), set by the reset thread, which points to unallocated memory, causing a crash.  Add flag 'io_admin_reset_sync' to synchronize access between the reset, I/O, and admin threads. Before a reset, the reset handler sets this flag to block I/O and admin processing threads. If any thread bypasses the initial check, the reset thread waits up to 10 seconds for processing to finish. If the wait exceeds 10 seconds, the controller is marked as unrecoverable.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37861","epss":0.00275,"percentile":0.19712,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37861","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21037499999999998},"relatedVulnerabilities":[{"id":"CVE-2025-37861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37861","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/65ba18c84dbd03afe9b38c06c151239d97a09834","https://git.kernel.org/stable/c/75b67dca4195e11ccf966a704787b2aa2754a457","https://git.kernel.org/stable/c/8d310d66e2b0f5f9f709764641647e8a3a4924fa","https://git.kernel.org/stable/c/f195fc060c738d303a21fae146dbf85e1595fb4c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue\n\nWhen the task management thread processes reply queues while the reset\nthread resets them, the task management thread accesses an invalid queue ID\n(0xFFFF), set by the reset thread, which points to unallocated memory,\ncausing a crash.\n\nAdd flag 'io_admin_reset_sync' to synchronize access between the reset,\nI/O, and admin threads. Before a reset, the reset handler sets this flag to\nblock I/O and admin processing threads. If any thread bypasses the initial\ncheck, the reset thread waits up to 10 seconds for processing to finish. If\nthe wait exceeds 10 seconds, the controller is marked as unrecoverable.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37861","epss":0.00275,"percentile":0.19712,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37861","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37880","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37880","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  um: work around sched_yield not yielding in time-travel mode  sched_yield by a userspace may not actually cause scheduling in time-travel mode as no time has passed. In the case seen it appears to be a badly implemented userspace spinlock in ASAN. Unfortunately, with time-travel it causes an extreme slowdown or even deadlock depending on the kernel configuration (CONFIG_UML_MAX_USERSPACE_ITERATIONS).  Work around it by accounting time to the process whenever it executes a sched_yield syscall.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37880","epss":0.00168,"percentile":0.06383,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37880","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08820000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-37880","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37880","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/887c5c12e80c8424bd471122d2e8b6b462e12874","https://git.kernel.org/stable/c/990ddc65173776f1e01e7135d8c1fd5f8fd4d5d2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\num: work around sched_yield not yielding in time-travel mode\n\nsched_yield by a userspace may not actually cause scheduling in\ntime-travel mode as no time has passed. In the case seen it appears to\nbe a badly implemented userspace spinlock in ASAN. Unfortunately, with\ntime-travel it causes an extreme slowdown or even deadlock depending on\nthe kernel configuration (CONFIG_UML_MAX_USERSPACE_ITERATIONS).\n\nWork around it by accounting time to the process whenever it executes a\nsched_yield syscall.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37880","epss":0.00168,"percentile":0.06383,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37880","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37880","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37893","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37893","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: BPF: Fix off-by-one error in build_prologue()  Vincent reported that running BPF progs with tailcalls on LoongArch causes kernel hard lockup. Debugging the issues shows that the JITed image missing a jirl instruction at the end of the epilogue.  There are two passes in JIT compiling, the first pass set the flags and the second pass generates JIT code based on those flags. With BPF progs mixing bpf2bpf and tailcalls, build_prologue() generates N insns in the first pass and then generates N+1 insns in the second pass. This makes epilogue_offset off by one and we will jump to some unexpected insn and cause lockup. Fix this by inserting a nop insn.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37893","epss":0.00266,"percentile":0.1841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37893","cwe":"CWE-193","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-37893","cwe":"CWE-193","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13965000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-37893","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37893","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/205a2182c51ffebaef54d643e3745e720cded08b","https://git.kernel.org/stable/c/48b904de2408af5f936f0e03f48dfcddeab58aa0","https://git.kernel.org/stable/c/7e2586991e36663c9bc48c828b83eab180ad30a9","https://git.kernel.org/stable/c/b3ffad2f02db4aace6799fe0049508b8925eae45","https://git.kernel.org/stable/c/c74d95a5679741ef428974ab788f5b0758dc78ae"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Fix off-by-one error in build_prologue()\n\nVincent reported that running BPF progs with tailcalls on LoongArch\ncauses kernel hard lockup. Debugging the issues shows that the JITed\nimage missing a jirl instruction at the end of the epilogue.\n\nThere are two passes in JIT compiling, the first pass set the flags and\nthe second pass generates JIT code based on those flags. With BPF progs\nmixing bpf2bpf and tailcalls, build_prologue() generates N insns in the\nfirst pass and then generates N+1 insns in the second pass. This makes\nepilogue_offset off by one and we will jump to some unexpected insn and\ncause lockup. Fix this by inserting a nop insn.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37893","epss":0.00266,"percentile":0.1841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37893","cwe":"CWE-193","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-37893","cwe":"CWE-193","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37893","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37952","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37952","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: Fix UAF in __close_file_table_ids  A use-after-free is possible if one thread destroys the file via __ksmbd_close_fd while another thread holds a reference to it. The existing checks on fp->refcount are not sufficient to prevent this.  The fix takes ft->lock around the section which removes the file from the file table. This prevents two threads acquiring the same file pointer via __close_file_table_ids, as well as the other functions which retrieve a file from the IDR and which already use this same lock.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37952","epss":0.0035,"percentile":0.28206,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37952","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26775000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-37952","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37952","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/16727e442568a46d9cca69fe2595896de86e120d","https://git.kernel.org/stable/c/36991c1ccde2d5a521577c448ffe07fcccfe104d","https://git.kernel.org/stable/c/9e9841e232b51171ddf3bc4ee517d5d28dc8cad6","https://git.kernel.org/stable/c/fec1f9e9a650e8e7011330a085c77e7bf2a08ea9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: Fix UAF in __close_file_table_ids\n\nA use-after-free is possible if one thread destroys the file\nvia __ksmbd_close_fd while another thread holds a reference to\nit. The existing checks on fp->refcount are not sufficient to\nprevent this.\n\nThe fix takes ft->lock around the section which removes the\nfile from the file table. This prevents two threads acquiring the\nsame file pointer via __close_file_table_ids, as well as the other\nfunctions which retrieve a file from the IDR and which already use\nthis same lock.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37952","epss":0.0035,"percentile":0.28206,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37952","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37952","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37956","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37956","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: prevent rename with empty string  Client can send empty newname string to ksmbd server. It will cause a kernel oops from d_alloc. This patch return the error when attempting to rename a file or directory with an empty new name string.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37956","epss":0.00354,"percentile":0.28696,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.18585000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-37956","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37956","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/53e3e5babc0963a92d856a5ec0ce92c59f54bc12","https://git.kernel.org/stable/c/6ee551672c8cf36108b0cfba92ec0c7c28ac3439","https://git.kernel.org/stable/c/c57301e332cc413fe0a7294a90725f4e21e9549d","https://git.kernel.org/stable/c/d7f2c00acb1ef64304fd40ac507e9213ff1d9b5c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent rename with empty string\n\nClient can send empty newname string to ksmbd server.\nIt will cause a kernel oops from d_alloc.\nThis patch return the error when attempting to rename\na file or directory with an empty new name string.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37956","epss":0.00354,"percentile":0.28696,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37956","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37957","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37957","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception  Previously, commit ed129ec9057f (\"KVM: x86: forcibly leave nested mode on vCPU reset\") addressed an issue where a triple fault occurring in nested mode could lead to use-after-free scenarios. However, the commit did not handle the analogous situation for System Management Mode (SMM).  This omission results in triggering a WARN when KVM forces a vCPU INIT after SHUTDOWN interception while the vCPU is in SMM. This situation was reprodused using Syzkaller by:    1) Creating a KVM VM and vCPU   2) Sending a KVM_SMI ioctl to explicitly enter SMM   3) Executing invalid instructions causing consecutive exceptions and      eventually a triple fault  The issue manifests as follows:    WARNING: CPU: 0 PID: 25506 at arch/x86/kvm/x86.c:12112   kvm_vcpu_reset+0x1d2/0x1530 arch/x86/kvm/x86.c:12112   Modules linked in:   CPU: 0 PID: 25506 Comm: syz-executor.0 Not tainted   6.1.130-syzkaller-00157-g164fe5dde9b6 #0   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),   BIOS 1.12.0-1 04/01/2014   RIP: 0010:kvm_vcpu_reset+0x1d2/0x1530 arch/x86/kvm/x86.c:12112   Call Trace:    <TASK>    shutdown_interception+0x66/0xb0 arch/x86/kvm/svm/svm.c:2136    svm_invoke_exit_handler+0x110/0x530 arch/x86/kvm/svm/svm.c:3395    svm_handle_exit+0x424/0x920 arch/x86/kvm/svm/svm.c:3457    vcpu_enter_guest arch/x86/kvm/x86.c:10959 [inline]    vcpu_run+0x2c43/0x5a90 arch/x86/kvm/x86.c:11062    kvm_arch_vcpu_ioctl_run+0x50f/0x1cf0 arch/x86/kvm/x86.c:11283    kvm_vcpu_ioctl+0x570/0xf00 arch/x86/kvm/../../../virt/kvm/kvm_main.c:4122    vfs_ioctl fs/ioctl.c:51 [inline]    __do_sys_ioctl fs/ioctl.c:870 [inline]    __se_sys_ioctl fs/ioctl.c:856 [inline]    __x64_sys_ioctl+0x19a/0x210 fs/ioctl.c:856    do_syscall_x64 arch/x86/entry/common.c:51 [inline]    do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81    entry_SYSCALL_64_after_hwframe+0x6e/0xd8  Architecturally, INIT is blocked when the CPU is in SMM, hence KVM's WARN() in kvm_vcpu_reset() to guard against KVM bugs, e.g. to detect improper emulation of INIT.  SHUTDOWN on SVM is a weird edge case where KVM needs to do _something_ sane with the VMCB, since it's technically undefined, and INIT is the least awful choice given KVM's ABI.  So, double down on stuffing INIT on SHUTDOWN, and force the vCPU out of SMM to avoid any weirdness (and the WARN).  Found by Linux Verification Center (linuxtesting.org) with Syzkaller.  [sean: massage changelog, make it clear this isn't architectural behavior]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37957","epss":0.0018,"percentile":0.07693,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37957","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1377},"relatedVulnerabilities":[{"id":"CVE-2025-37957","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37957","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/a2620f8932fa9fdabc3d78ed6efb004ca409019f","https://git.kernel.org/stable/c/d362b21fefcef7eda8f1cd78a5925735d2b3287c","https://git.kernel.org/stable/c/e9b28bc65fd3a56755ba503258024608292b4ab1","https://git.kernel.org/stable/c/ec24e62a1dd3540ee696314422040180040c1e4a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception\n\nPreviously, commit ed129ec9057f (\"KVM: x86: forcibly leave nested mode\non vCPU reset\") addressed an issue where a triple fault occurring in\nnested mode could lead to use-after-free scenarios. However, the commit\ndid not handle the analogous situation for System Management Mode (SMM).\n\nThis omission results in triggering a WARN when KVM forces a vCPU INIT\nafter SHUTDOWN interception while the vCPU is in SMM. This situation was\nreprodused using Syzkaller by:\n\n  1) Creating a KVM VM and vCPU\n  2) Sending a KVM_SMI ioctl to explicitly enter SMM\n  3) Executing invalid instructions causing consecutive exceptions and\n     eventually a triple fault\n\nThe issue manifests as follows:\n\n  WARNING: CPU: 0 PID: 25506 at arch/x86/kvm/x86.c:12112\n  kvm_vcpu_reset+0x1d2/0x1530 arch/x86/kvm/x86.c:12112\n  Modules linked in:\n  CPU: 0 PID: 25506 Comm: syz-executor.0 Not tainted\n  6.1.130-syzkaller-00157-g164fe5dde9b6 #0\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),\n  BIOS 1.12.0-1 04/01/2014\n  RIP: 0010:kvm_vcpu_reset+0x1d2/0x1530 arch/x86/kvm/x86.c:12112\n  Call Trace:\n   <TASK>\n   shutdown_interception+0x66/0xb0 arch/x86/kvm/svm/svm.c:2136\n   svm_invoke_exit_handler+0x110/0x530 arch/x86/kvm/svm/svm.c:3395\n   svm_handle_exit+0x424/0x920 arch/x86/kvm/svm/svm.c:3457\n   vcpu_enter_guest arch/x86/kvm/x86.c:10959 [inline]\n   vcpu_run+0x2c43/0x5a90 arch/x86/kvm/x86.c:11062\n   kvm_arch_vcpu_ioctl_run+0x50f/0x1cf0 arch/x86/kvm/x86.c:11283\n   kvm_vcpu_ioctl+0x570/0xf00 arch/x86/kvm/../../../virt/kvm/kvm_main.c:4122\n   vfs_ioctl fs/ioctl.c:51 [inline]\n   __do_sys_ioctl fs/ioctl.c:870 [inline]\n   __se_sys_ioctl fs/ioctl.c:856 [inline]\n   __x64_sys_ioctl+0x19a/0x210 fs/ioctl.c:856\n   do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n   do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81\n   entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nArchitecturally, INIT is blocked when the CPU is in SMM, hence KVM's WARN()\nin kvm_vcpu_reset() to guard against KVM bugs, e.g. to detect improper\nemulation of INIT.  SHUTDOWN on SVM is a weird edge case where KVM needs to\ndo _something_ sane with the VMCB, since it's technically undefined, and\nINIT is the least awful choice given KVM's ABI.\n\nSo, double down on stuffing INIT on SHUTDOWN, and force the vCPU out of\nSMM to avoid any weirdness (and the WARN).\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.\n\n[sean: massage changelog, make it clear this isn't architectural behavior]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37957","epss":0.0018,"percentile":0.07693,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-37957","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37957","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-37977","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-37977","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set  If dma-coherent property isn't set then descriptors are non-cacheable and the iocc shareability bits should be disabled. Without this UFS can end up in an incompatible configuration and suffer from random cache related stability issues.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37977","epss":0.00183,"percentile":0.0799,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09607500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-37977","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-37977","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/869749e48115ef944eeabec8e84138908471fa51","https://git.kernel.org/stable/c/f0c6728a6f2e269ebb234a9b5bb6c2c24aafeb51","https://git.kernel.org/stable/c/f92bb7436802f8eb7ee72dc911a33c8897fde366"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: exynos: Disable iocc if dma-coherent property isn't set\n\nIf dma-coherent property isn't set then descriptors are non-cacheable\nand the iocc shareability bits should be disabled. Without this UFS can\nend up in an incompatible configuration and suffer from random cache\nrelated stability issues.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-37977","epss":0.00183,"percentile":0.0799,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-37977","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38006","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38006","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: mctp: Don't access ifa_index when missing  In mctp_dump_addrinfo, ifa_index can be used to filter interfaces, but only when the struct ifaddrmsg is provided. Otherwise it will be comparing to uninitialised memory - reproducible in the syzkaller case from dhcpd, or busybox \"ip addr show\".  The kernel MCTP implementation has always filtered by ifa_index, so existing userspace programs expecting to dump MCTP addresses must already be passing a valid ifa_index value (either 0 or a real index).  BUG: KMSAN: uninit-value in mctp_dump_addrinfo+0x208/0xac0 net/mctp/device.c:128  mctp_dump_addrinfo+0x208/0xac0 net/mctp/device.c:128  rtnl_dump_all+0x3ec/0x5b0 net/core/rtnetlink.c:4380  rtnl_dumpit+0xd5/0x2f0 net/core/rtnetlink.c:6824  netlink_dump+0x97b/0x1690 net/netlink/af_netlink.c:2309","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38006","epss":0.00176,"percentile":0.07203,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38006","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09240000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38006","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38006","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/24fa213dffa470166ec014f979f36c6ff44afb45","https://git.kernel.org/stable/c/8ef7b3f0db69e2f4a80be351f6aee9a4c2332ef9","https://git.kernel.org/stable/c/acab78ae12c7fefb4f3bfe22e00770a5faa42724","https://git.kernel.org/stable/c/d4d1561d17eb72908e4489c0900d96e0484fac20","https://git.kernel.org/stable/c/f11cf946c0a92c560a890d68e4775723353599e1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: Don't access ifa_index when missing\n\nIn mctp_dump_addrinfo, ifa_index can be used to filter interfaces, but\nonly when the struct ifaddrmsg is provided. Otherwise it will be\ncomparing to uninitialised memory - reproducible in the syzkaller case from\ndhcpd, or busybox \"ip addr show\".\n\nThe kernel MCTP implementation has always filtered by ifa_index, so\nexisting userspace programs expecting to dump MCTP addresses must\nalready be passing a valid ifa_index value (either 0 or a real index).\n\nBUG: KMSAN: uninit-value in mctp_dump_addrinfo+0x208/0xac0 net/mctp/device.c:128\n mctp_dump_addrinfo+0x208/0xac0 net/mctp/device.c:128\n rtnl_dump_all+0x3ec/0x5b0 net/core/rtnetlink.c:4380\n rtnl_dumpit+0xd5/0x2f0 net/core/rtnetlink.c:6824\n netlink_dump+0x97b/0x1690 net/netlink/af_netlink.c:2309","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38006","epss":0.00176,"percentile":0.07203,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38006","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38006","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38014","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38014","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: idxd: Refactor remove call with idxd_cleanup() helper  The idxd_cleanup() helper cleans up perfmon, interrupts, internals and so on. Refactor remove call with the idxd_cleanup() helper to avoid code duplication. Note, this also fixes the missing put_device() for idxd groups, enginces and wqs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38014","epss":0.00176,"percentile":0.07205,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09240000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38014","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38014","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/23dc14c52d84b02b39d816bf16a754c0e7d48f9c","https://git.kernel.org/stable/c/a409e919ca321cc0e28f8abf96fde299f0072a81","https://git.kernel.org/stable/c/a7bd00f7e9bd075f3e4fbcc608d8ea445aed8692","https://git.kernel.org/stable/c/d530dd65f6f3c04bbf141702ecccd70170ed04ad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Refactor remove call with idxd_cleanup() helper\n\nThe idxd_cleanup() helper cleans up perfmon, interrupts, internals and\nso on. Refactor remove call with the idxd_cleanup() helper to avoid code\nduplication. Note, this also fixes the missing put_device() for idxd\ngroups, enginces and wqs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38014","epss":0.00176,"percentile":0.07205,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38014","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38029","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38029","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  kasan: avoid sleepable page allocation from atomic context  apply_to_pte_range() enters the lazy MMU mode and then invokes kasan_populate_vmalloc_pte() callback on each page table walk iteration.  However, the callback can go into sleep when trying to allocate a single page, e.g.  if an architecutre disables preemption on lazy MMU mode enter.  On s390 if make arch_enter_lazy_mmu_mode() -> preempt_enable() and arch_leave_lazy_mmu_mode() -> preempt_disable(), such crash occurs:  [    0.663336] BUG: sleeping function called from invalid context at ./include/linux/sched/mm.h:321 [    0.663348] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2, name: kthreadd [    0.663358] preempt_count: 1, expected: 0 [    0.663366] RCU nest depth: 0, expected: 0 [    0.663375] no locks held by kthreadd/2. [    0.663383] Preemption disabled at: [    0.663386] [<0002f3284cbb4eda>] apply_to_pte_range+0xfa/0x4a0 [    0.663405] CPU: 0 UID: 0 PID: 2 Comm: kthreadd Not tainted 6.15.0-rc5-gcc-kasan-00043-gd76bb1ebb558-dirty #162 PREEMPT [    0.663408] Hardware name: IBM 3931 A01 701 (KVM/Linux) [    0.663409] Call Trace: [    0.663410]  [<0002f3284c385f58>] dump_stack_lvl+0xe8/0x140 [    0.663413]  [<0002f3284c507b9e>] __might_resched+0x66e/0x700 [    0.663415]  [<0002f3284cc4f6c0>] __alloc_frozen_pages_noprof+0x370/0x4b0 [    0.663419]  [<0002f3284ccc73c0>] alloc_pages_mpol+0x1a0/0x4a0 [    0.663421]  [<0002f3284ccc8518>] alloc_frozen_pages_noprof+0x88/0xc0 [    0.663424]  [<0002f3284ccc8572>] alloc_pages_noprof+0x22/0x120 [    0.663427]  [<0002f3284cc341ac>] get_free_pages_noprof+0x2c/0xc0 [    0.663429]  [<0002f3284cceba70>] kasan_populate_vmalloc_pte+0x50/0x120 [    0.663433]  [<0002f3284cbb4ef8>] apply_to_pte_range+0x118/0x4a0 [    0.663435]  [<0002f3284cbc7c14>] apply_to_pmd_range+0x194/0x3e0 [    0.663437]  [<0002f3284cbc99be>] __apply_to_page_range+0x2fe/0x7a0 [    0.663440]  [<0002f3284cbc9e88>] apply_to_page_range+0x28/0x40 [    0.663442]  [<0002f3284ccebf12>] kasan_populate_vmalloc+0x82/0xa0 [    0.663445]  [<0002f3284cc1578c>] alloc_vmap_area+0x34c/0xc10 [    0.663448]  [<0002f3284cc1c2a6>] __get_vm_area_node+0x186/0x2a0 [    0.663451]  [<0002f3284cc1e696>] __vmalloc_node_range_noprof+0x116/0x310 [    0.663454]  [<0002f3284cc1d950>] __vmalloc_node_noprof+0xd0/0x110 [    0.663457]  [<0002f3284c454b88>] alloc_thread_stack_node+0xf8/0x330 [    0.663460]  [<0002f3284c458d56>] dup_task_struct+0x66/0x4d0 [    0.663463]  [<0002f3284c45be90>] copy_process+0x280/0x4b90 [    0.663465]  [<0002f3284c460940>] kernel_clone+0xd0/0x4b0 [    0.663467]  [<0002f3284c46115e>] kernel_thread+0xbe/0xe0 [    0.663469]  [<0002f3284c4e440e>] kthreadd+0x50e/0x7f0 [    0.663472]  [<0002f3284c38c04a>] __ret_from_fork+0x8a/0xf0 [    0.663475]  [<0002f3284ed57ff2>] ret_from_fork+0xa/0x38  Instead of allocating single pages per-PTE, bulk-allocate the shadow memory prior to applying kasan_populate_vmalloc_pte() callback on a page range.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38029","epss":0.00148,"percentile":0.04376,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0777},"relatedVulnerabilities":[{"id":"CVE-2025-38029","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38029","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6748dd09196248b985cca39eaf651d5317271977","https://git.kernel.org/stable/c/b6ea95a34cbd014ab6ade4248107b86b0aaf2d6c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nkasan: avoid sleepable page allocation from atomic context\n\napply_to_pte_range() enters the lazy MMU mode and then invokes\nkasan_populate_vmalloc_pte() callback on each page table walk iteration. \nHowever, the callback can go into sleep when trying to allocate a single\npage, e.g.  if an architecutre disables preemption on lazy MMU mode enter.\n\nOn s390 if make arch_enter_lazy_mmu_mode() -> preempt_enable() and\narch_leave_lazy_mmu_mode() -> preempt_disable(), such crash occurs:\n\n[    0.663336] BUG: sleeping function called from invalid context at ./include/linux/sched/mm.h:321\n[    0.663348] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2, name: kthreadd\n[    0.663358] preempt_count: 1, expected: 0\n[    0.663366] RCU nest depth: 0, expected: 0\n[    0.663375] no locks held by kthreadd/2.\n[    0.663383] Preemption disabled at:\n[    0.663386] [<0002f3284cbb4eda>] apply_to_pte_range+0xfa/0x4a0\n[    0.663405] CPU: 0 UID: 0 PID: 2 Comm: kthreadd Not tainted 6.15.0-rc5-gcc-kasan-00043-gd76bb1ebb558-dirty #162 PREEMPT\n[    0.663408] Hardware name: IBM 3931 A01 701 (KVM/Linux)\n[    0.663409] Call Trace:\n[    0.663410]  [<0002f3284c385f58>] dump_stack_lvl+0xe8/0x140\n[    0.663413]  [<0002f3284c507b9e>] __might_resched+0x66e/0x700\n[    0.663415]  [<0002f3284cc4f6c0>] __alloc_frozen_pages_noprof+0x370/0x4b0\n[    0.663419]  [<0002f3284ccc73c0>] alloc_pages_mpol+0x1a0/0x4a0\n[    0.663421]  [<0002f3284ccc8518>] alloc_frozen_pages_noprof+0x88/0xc0\n[    0.663424]  [<0002f3284ccc8572>] alloc_pages_noprof+0x22/0x120\n[    0.663427]  [<0002f3284cc341ac>] get_free_pages_noprof+0x2c/0xc0\n[    0.663429]  [<0002f3284cceba70>] kasan_populate_vmalloc_pte+0x50/0x120\n[    0.663433]  [<0002f3284cbb4ef8>] apply_to_pte_range+0x118/0x4a0\n[    0.663435]  [<0002f3284cbc7c14>] apply_to_pmd_range+0x194/0x3e0\n[    0.663437]  [<0002f3284cbc99be>] __apply_to_page_range+0x2fe/0x7a0\n[    0.663440]  [<0002f3284cbc9e88>] apply_to_page_range+0x28/0x40\n[    0.663442]  [<0002f3284ccebf12>] kasan_populate_vmalloc+0x82/0xa0\n[    0.663445]  [<0002f3284cc1578c>] alloc_vmap_area+0x34c/0xc10\n[    0.663448]  [<0002f3284cc1c2a6>] __get_vm_area_node+0x186/0x2a0\n[    0.663451]  [<0002f3284cc1e696>] __vmalloc_node_range_noprof+0x116/0x310\n[    0.663454]  [<0002f3284cc1d950>] __vmalloc_node_noprof+0xd0/0x110\n[    0.663457]  [<0002f3284c454b88>] alloc_thread_stack_node+0xf8/0x330\n[    0.663460]  [<0002f3284c458d56>] dup_task_struct+0x66/0x4d0\n[    0.663463]  [<0002f3284c45be90>] copy_process+0x280/0x4b90\n[    0.663465]  [<0002f3284c460940>] kernel_clone+0xd0/0x4b0\n[    0.663467]  [<0002f3284c46115e>] kernel_thread+0xbe/0xe0\n[    0.663469]  [<0002f3284c4e440e>] kthreadd+0x50e/0x7f0\n[    0.663472]  [<0002f3284c38c04a>] __ret_from_fork+0x8a/0xf0\n[    0.663475]  [<0002f3284ed57ff2>] ret_from_fork+0xa/0x38\n\nInstead of allocating single pages per-PTE, bulk-allocate the shadow\nmemory prior to applying kasan_populate_vmalloc_pte() callback on a page\nrange.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38029","epss":0.00148,"percentile":0.04376,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38029","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38038","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38038","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cpufreq: amd-pstate: Remove unnecessary driver_lock in set_boost  set_boost is a per-policy function call, hence a driver wide lock is unnecessary. Also this mutex_acquire can collide with the mutex_acquire from the mode-switch path in status_store(), which can lead to a deadlock. So, remove it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38038","epss":0.00174,"percentile":0.0696,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09135},"relatedVulnerabilities":[{"id":"CVE-2025-38038","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38038","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/61e931ee145eeab8196e585ff4334870b130b744","https://git.kernel.org/stable/c/cd347d071713234586762d79c5a691785e9be418","https://git.kernel.org/stable/c/db1cafc77aaaf871509da06f4a864e9af6d6791f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: amd-pstate: Remove unnecessary driver_lock in set_boost\n\nset_boost is a per-policy function call, hence a driver wide lock is\nunnecessary. Also this mutex_acquire can collide with the mutex_acquire\nfrom the mode-switch path in status_store(), which can lead to a\ndeadlock. So, remove it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38038","epss":0.00174,"percentile":0.0696,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38038","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38039","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38039","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Avoid WARN_ON when configuring MQPRIO with HTB offload enabled  When attempting to enable MQPRIO while HTB offload is already configured, the driver currently returns `-EINVAL` and triggers a `WARN_ON`, leading to an unnecessary call trace.  Update the code to handle this case more gracefully by returning `-EOPNOTSUPP` instead, while also providing a helpful user message.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38039","epss":0.00176,"percentile":0.07206,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09240000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38039","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38039","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/090c0ba179eaf7b670e720aa054533756a43d565","https://git.kernel.org/stable/c/689805dcc474c2accb5cffbbcea1c06ee4a54570","https://git.kernel.org/stable/c/9e2bac6835f73895598df5a3a125a19497fad46b","https://git.kernel.org/stable/c/b82e496531c571caf8a2ef247f51c160bab2162e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Avoid WARN_ON when configuring MQPRIO with HTB offload enabled\n\nWhen attempting to enable MQPRIO while HTB offload is already\nconfigured, the driver currently returns `-EINVAL` and triggers a\n`WARN_ON`, leading to an unnecessary call trace.\n\nUpdate the code to handle this case more gracefully by returning\n`-EOPNOTSUPP` instead, while also providing a helpful user message.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38039","epss":0.00176,"percentile":0.07206,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38039","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38041","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38041","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  clk: sunxi-ng: h616: Reparent GPU clock during frequency changes  The H616 manual does not state that the GPU PLL supports dynamic frequency configuration, so we must take extra care when changing the frequency. Currently any attempt to do device DVFS on the GPU lead to panfrost various ooops, and GPU hangs.  The manual describes the algorithm for changing the PLL frequency, which the CPU PLL notifier code already support, so we reuse that to reparent the GPU clock to GPU1 clock during frequency changes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38041","epss":0.00148,"percentile":0.04378,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0777},"relatedVulnerabilities":[{"id":"CVE-2025-38041","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38041","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1439673b78185eaaa5fae444b3a9d58c434ee78e","https://git.kernel.org/stable/c/eb963d7948ce6571939c6875424b557b25f16610"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nclk: sunxi-ng: h616: Reparent GPU clock during frequency changes\n\nThe H616 manual does not state that the GPU PLL supports\ndynamic frequency configuration, so we must take extra care when changing\nthe frequency. Currently any attempt to do device DVFS on the GPU lead\nto panfrost various ooops, and GPU hangs.\n\nThe manual describes the algorithm for changing the PLL\nfrequency, which the CPU PLL notifier code already support, so we reuse\nthat to reparent the GPU clock to GPU1 clock during frequency\nchanges.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38041","epss":0.00148,"percentile":0.04378,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38041","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38042","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38042","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: ti: k3-udma-glue: Drop skip_fdq argument from k3_udma_glue_reset_rx_chn  The user of k3_udma_glue_reset_rx_chn() e.g. ti_am65_cpsw_nuss can run on multiple platforms having different DMA architectures. On some platforms there can be one FDQ for all flows in the RX channel while for others there is a separate FDQ for each flow in the RX channel.  So far we have been relying on the skip_fdq argument of k3_udma_glue_reset_rx_chn().  Instead of relying on the user to provide this information, infer it based on DMA architecture during k3_udma_glue_request_rx_chn() and save it in an internal flag 'single_fdq'. Use that flag at k3_udma_glue_reset_rx_chn() to deicide if the FDQ needs to be cleared for every flow or just for flow 0.  Fixes the below issue on ti_am65_cpsw_nuss driver on AM62-SK.  > ip link set eth1 down > ip link set eth0 down > ethtool -L eth0 rx 8 > ip link set eth0 up > modprobe -r ti_am65_cpsw_nuss  [  103.045726] ------------[ cut here ]------------ [  103.050505] k3_knav_desc_pool size 512000 != avail 64000 [  103.050703] WARNING: CPU: 1 PID: 450 at drivers/net/ethernet/ti/k3-cppi-desc-pool.c:33 k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] [  103.068810] Modules linked in: ti_am65_cpsw_nuss(-) k3_cppi_desc_pool snd_soc_hdmi_codec crct10dif_ce snd_soc_simple_card snd_soc_simple_card_utils display_connector rtc_ti_k3 k3_j72xx_bandgap tidss drm_client_lib snd_soc_davinci_mcas p drm_dma_helper tps6598x phylink snd_soc_ti_udma rti_wdt drm_display_helper snd_soc_tlv320aic3x_i2c typec at24 phy_gmii_sel snd_soc_ti_edma snd_soc_tlv320aic3x sii902x snd_soc_ti_sdma sa2ul omap_mailbox drm_kms_helper authenc cfg80211 r fkill fuse drm drm_panel_orientation_quirks backlight ip_tables x_tables ipv6 [last unloaded: k3_cppi_desc_pool] [  103.119950] CPU: 1 UID: 0 PID: 450 Comm: modprobe Not tainted 6.13.0-rc7-00001-g9c5e3435fa66 #1011 [  103.119968] Hardware name: Texas Instruments AM625 SK (DT) [  103.119974] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [  103.119983] pc : k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] [  103.148007] lr : k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] [  103.154709] sp : ffff8000826ebbc0 [  103.158015] x29: ffff8000826ebbc0 x28: ffff0000090b6300 x27: 0000000000000000 [  103.165145] x26: 0000000000000000 x25: 0000000000000000 x24: ffff0000019df6b0 [  103.172271] x23: ffff0000019df6b8 x22: ffff0000019df410 x21: ffff8000826ebc88 [  103.179397] x20: 000000000007d000 x19: ffff00000a3b3000 x18: 0000000000000000 [  103.186522] x17: 0000000000000000 x16: 0000000000000000 x15: 000001e8c35e1cde [  103.193647] x14: 0000000000000396 x13: 000000000000035c x12: 0000000000000000 [  103.200772] x11: 000000000000003a x10: 00000000000009c0 x9 : ffff8000826eba20 [  103.207897] x8 : ffff0000090b6d20 x7 : ffff00007728c180 x6 : ffff00007728c100 [  103.215022] x5 : 0000000000000001 x4 : ffff000000508a50 x3 : ffff7ffff6146000 [  103.222147] x2 : 0000000000000000 x1 : e300b4173ee6b200 x0 : 0000000000000000 [  103.229274] Call trace: [  103.231714]  k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] (P) [  103.238408]  am65_cpsw_nuss_free_rx_chns+0x28/0x4c [ti_am65_cpsw_nuss] [  103.244942]  devm_action_release+0x14/0x20 [  103.249040]  release_nodes+0x3c/0x68 [  103.252610]  devres_release_all+0x8c/0xdc [  103.256614]  device_unbind_cleanup+0x18/0x60 [  103.260876]  device_release_driver_internal+0xf8/0x178 [  103.266004]  driver_detach+0x50/0x9c [  103.269571]  bus_remove_driver+0x6c/0xbc [  103.273485]  driver_unregister+0x30/0x60 [  103.277401]  platform_driver_unregister+0x14/0x20 [  103.282096]  am65_cpsw_nuss_driver_exit+0x18/0xff4 [ti_am65_cpsw_nuss] [  103.288620]  __arm64_sys_delete_module+0x17c/0x25c [  103.293404]  invoke_syscall+0x44/0x100 [  103.297149]  el0_svc_common.constprop.0+0xc0/0xe0 [  103.301845]  do_el0_svc+0x1c/0x28 [  103.305155]  el0_svc+0x28/0x98 ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38042","epss":0.00148,"percentile":0.04376,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0777},"relatedVulnerabilities":[{"id":"CVE-2025-38042","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38042","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0da30874729baeb01889b0eca16cfda122687503","https://git.kernel.org/stable/c/d0dd9d133ef8fdc894e0be9aa27dc49ef5f813cb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: ti: k3-udma-glue: Drop skip_fdq argument from k3_udma_glue_reset_rx_chn\n\nThe user of k3_udma_glue_reset_rx_chn() e.g. ti_am65_cpsw_nuss can\nrun on multiple platforms having different DMA architectures.\nOn some platforms there can be one FDQ for all flows in the RX channel\nwhile for others there is a separate FDQ for each flow in the RX channel.\n\nSo far we have been relying on the skip_fdq argument of\nk3_udma_glue_reset_rx_chn().\n\nInstead of relying on the user to provide this information, infer it\nbased on DMA architecture during k3_udma_glue_request_rx_chn() and save it\nin an internal flag 'single_fdq'. Use that flag at\nk3_udma_glue_reset_rx_chn() to deicide if the FDQ needs\nto be cleared for every flow or just for flow 0.\n\nFixes the below issue on ti_am65_cpsw_nuss driver on AM62-SK.\n\n> ip link set eth1 down\n> ip link set eth0 down\n> ethtool -L eth0 rx 8\n> ip link set eth0 up\n> modprobe -r ti_am65_cpsw_nuss\n\n[  103.045726] ------------[ cut here ]------------\n[  103.050505] k3_knav_desc_pool size 512000 != avail 64000\n[  103.050703] WARNING: CPU: 1 PID: 450 at drivers/net/ethernet/ti/k3-cppi-desc-pool.c:33 k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool]\n[  103.068810] Modules linked in: ti_am65_cpsw_nuss(-) k3_cppi_desc_pool snd_soc_hdmi_codec crct10dif_ce snd_soc_simple_card snd_soc_simple_card_utils display_connector rtc_ti_k3 k3_j72xx_bandgap tidss drm_client_lib snd_soc_davinci_mcas\np drm_dma_helper tps6598x phylink snd_soc_ti_udma rti_wdt drm_display_helper snd_soc_tlv320aic3x_i2c typec at24 phy_gmii_sel snd_soc_ti_edma snd_soc_tlv320aic3x sii902x snd_soc_ti_sdma sa2ul omap_mailbox drm_kms_helper authenc cfg80211 r\nfkill fuse drm drm_panel_orientation_quirks backlight ip_tables x_tables ipv6 [last unloaded: k3_cppi_desc_pool]\n[  103.119950] CPU: 1 UID: 0 PID: 450 Comm: modprobe Not tainted 6.13.0-rc7-00001-g9c5e3435fa66 #1011\n[  103.119968] Hardware name: Texas Instruments AM625 SK (DT)\n[  103.119974] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[  103.119983] pc : k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool]\n[  103.148007] lr : k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool]\n[  103.154709] sp : ffff8000826ebbc0\n[  103.158015] x29: ffff8000826ebbc0 x28: ffff0000090b6300 x27: 0000000000000000\n[  103.165145] x26: 0000000000000000 x25: 0000000000000000 x24: ffff0000019df6b0\n[  103.172271] x23: ffff0000019df6b8 x22: ffff0000019df410 x21: ffff8000826ebc88\n[  103.179397] x20: 000000000007d000 x19: ffff00000a3b3000 x18: 0000000000000000\n[  103.186522] x17: 0000000000000000 x16: 0000000000000000 x15: 000001e8c35e1cde\n[  103.193647] x14: 0000000000000396 x13: 000000000000035c x12: 0000000000000000\n[  103.200772] x11: 000000000000003a x10: 00000000000009c0 x9 : ffff8000826eba20\n[  103.207897] x8 : ffff0000090b6d20 x7 : ffff00007728c180 x6 : ffff00007728c100\n[  103.215022] x5 : 0000000000000001 x4 : ffff000000508a50 x3 : ffff7ffff6146000\n[  103.222147] x2 : 0000000000000000 x1 : e300b4173ee6b200 x0 : 0000000000000000\n[  103.229274] Call trace:\n[  103.231714]  k3_cppi_desc_pool_destroy+0xa0/0xa8 [k3_cppi_desc_pool] (P)\n[  103.238408]  am65_cpsw_nuss_free_rx_chns+0x28/0x4c [ti_am65_cpsw_nuss]\n[  103.244942]  devm_action_release+0x14/0x20\n[  103.249040]  release_nodes+0x3c/0x68\n[  103.252610]  devres_release_all+0x8c/0xdc\n[  103.256614]  device_unbind_cleanup+0x18/0x60\n[  103.260876]  device_release_driver_internal+0xf8/0x178\n[  103.266004]  driver_detach+0x50/0x9c\n[  103.269571]  bus_remove_driver+0x6c/0xbc\n[  103.273485]  driver_unregister+0x30/0x60\n[  103.277401]  platform_driver_unregister+0x14/0x20\n[  103.282096]  am65_cpsw_nuss_driver_exit+0x18/0xff4 [ti_am65_cpsw_nuss]\n[  103.288620]  __arm64_sys_delete_module+0x17c/0x25c\n[  103.293404]  invoke_syscall+0x44/0x100\n[  103.297149]  el0_svc_common.constprop.0+0xc0/0xe0\n[  103.301845]  do_el0_svc+0x1c/0x28\n[  103.305155]  el0_svc+0x28/0x98\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38042","epss":0.00148,"percentile":0.04376,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38042","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38045","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38045","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: iwlwifi: fix debug actions order  The order of actions taken for debug was implemented incorrectly. Now we implemented the dump split and do the FW reset only in the middle of the dump (rather than the FW killing itself on error.) As a result, some of the actions taken when applying the config will now crash the device, so we need to fix the order.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38045","epss":0.00176,"percentile":0.07206,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09240000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38045","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38045","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/181e8b56b74ad3920456dcdc8a361520d9007956","https://git.kernel.org/stable/c/2b790fe67ed483d86c1aeb8be6735bf792caa7e5","https://git.kernel.org/stable/c/328fbc96ecbee16c5fcbfcb3ac57b476f94da2f0","https://git.kernel.org/stable/c/eb29b4ffafb20281624dcd2cbb768d6f30edf600"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: fix debug actions order\n\nThe order of actions taken for debug was implemented incorrectly.\nNow we implemented the dump split and do the FW reset only in the\nmiddle of the dump (rather than the FW killing itself on error.)\nAs a result, some of the actions taken when applying the config\nwill now crash the device, so we need to fix the order.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38045","epss":0.00176,"percentile":0.07206,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38045","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: avoid NULL pointer dereference if no valid csum tree  [BUG] When trying read-only scrub on a btrfs with rescue=idatacsums mount option, it will crash with the following call trace:    BUG: kernel NULL pointer dereference, address: 0000000000000208   #PF: supervisor read access in kernel mode   #PF: error_code(0x0000) - not-present page   CPU: 1 UID: 0 PID: 835 Comm: btrfs Tainted: G           O        6.15.0-rc3-custom+ #236 PREEMPT(full)   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022   RIP: 0010:btrfs_lookup_csums_bitmap+0x49/0x480 [btrfs]   Call Trace:    <TASK>    scrub_find_fill_first_stripe+0x35b/0x3d0 [btrfs]    scrub_simple_mirror+0x175/0x290 [btrfs]    scrub_stripe+0x5f7/0x6f0 [btrfs]    scrub_chunk+0x9a/0x150 [btrfs]    scrub_enumerate_chunks+0x333/0x660 [btrfs]    btrfs_scrub_dev+0x23e/0x600 [btrfs]    btrfs_ioctl+0x1dcf/0x2f80 [btrfs]    __x64_sys_ioctl+0x97/0xc0    do_syscall_64+0x4f/0x120    entry_SYSCALL_64_after_hwframe+0x76/0x7e  [CAUSE] Mount option \"rescue=idatacsums\" will completely skip loading the csum tree, so that any data read will not find any data csum thus we will ignore data checksum verification.  Normally call sites utilizing csum tree will check the fs state flag NO_DATA_CSUMS bit, but unfortunately scrub does not check that bit at all.  This results in scrub to call btrfs_search_slot() on a NULL pointer and triggered above crash.  [FIX] Check both extent and csum tree root before doing any tree search.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38059","epss":0.00176,"percentile":0.07201,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38059","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09240000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38059","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/50d0de59f66cbe6d597481e099bf1c70fd07e0a9","https://git.kernel.org/stable/c/6e9770de024964b1017f99ee94f71967bd6edaeb","https://git.kernel.org/stable/c/d35bed14b0bc95c6845863a3744ecd10b888c830","https://git.kernel.org/stable/c/f95d186255b319c48a365d47b69bd997fecb674e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: avoid NULL pointer dereference if no valid csum tree\n\n[BUG]\nWhen trying read-only scrub on a btrfs with rescue=idatacsums mount\noption, it will crash with the following call trace:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000208\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  CPU: 1 UID: 0 PID: 835 Comm: btrfs Tainted: G           O        6.15.0-rc3-custom+ #236 PREEMPT(full)\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022\n  RIP: 0010:btrfs_lookup_csums_bitmap+0x49/0x480 [btrfs]\n  Call Trace:\n   <TASK>\n   scrub_find_fill_first_stripe+0x35b/0x3d0 [btrfs]\n   scrub_simple_mirror+0x175/0x290 [btrfs]\n   scrub_stripe+0x5f7/0x6f0 [btrfs]\n   scrub_chunk+0x9a/0x150 [btrfs]\n   scrub_enumerate_chunks+0x333/0x660 [btrfs]\n   btrfs_scrub_dev+0x23e/0x600 [btrfs]\n   btrfs_ioctl+0x1dcf/0x2f80 [btrfs]\n   __x64_sys_ioctl+0x97/0xc0\n   do_syscall_64+0x4f/0x120\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n[CAUSE]\nMount option \"rescue=idatacsums\" will completely skip loading the csum\ntree, so that any data read will not find any data csum thus we will\nignore data checksum verification.\n\nNormally call sites utilizing csum tree will check the fs state flag\nNO_DATA_CSUMS bit, but unfortunately scrub does not check that bit at all.\n\nThis results in scrub to call btrfs_search_slot() on a NULL pointer\nand triggered above crash.\n\n[FIX]\nCheck both extent and csum tree root before doing any tree search.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38059","epss":0.00176,"percentile":0.07201,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38059","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38064","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  virtio: break and reset virtio devices on device_shutdown()  Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory accesses during the hang.  \tInvalid read at addr 0x102877002, size 2, region '(null)', reason: rejected \tInvalid write at addr 0x102877A44, size 2, region '(null)', reason: rejected \t...  It was traced down to virtio-console. Kexec works fine if virtio-console is not in use.  The issue is that virtio-console continues to write to the MMIO even after underlying virtio-pci device is reset.  Additionally, Eric noticed that IOMMUs are reset before devices, if devices are not reset on shutdown they continue to poke at guest memory and get errors from the IOMMU. Some devices get wedged then.  The problem can be solved by breaking all virtio devices on virtio bus shutdown, then resetting them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38064","epss":0.00146,"percentile":0.04164,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07665000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38064","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/8bd2fa086a04886798b505f28db4002525895203","https://git.kernel.org/stable/c/aee42f3d57bfa37b2716df4584edeecf63b9df4c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: break and reset virtio devices on device_shutdown()\n\nHongyu reported a hang on kexec in a VM. QEMU reported invalid memory\naccesses during the hang.\n\n\tInvalid read at addr 0x102877002, size 2, region '(null)', reason: rejected\n\tInvalid write at addr 0x102877A44, size 2, region '(null)', reason: rejected\n\t...\n\nIt was traced down to virtio-console. Kexec works fine if virtio-console\nis not in use.\n\nThe issue is that virtio-console continues to write to the MMIO even after\nunderlying virtio-pci device is reset.\n\nAdditionally, Eric noticed that IOMMUs are reset before devices, if\ndevices are not reset on shutdown they continue to poke at guest memory\nand get errors from the IOMMU. Some devices get wedged then.\n\nThe problem can be solved by breaking all virtio devices on virtio\nbus shutdown, then resetting them.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38064","epss":0.00146,"percentile":0.04164,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38064","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38069","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38069","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  PCI: endpoint: pci-epf-test: Fix double free that causes kernel to oops  Fix a kernel oops found while testing the stm32_pcie Endpoint driver with handling of PERST# deassertion:  During EP initialization, pci_epf_test_alloc_space() allocates all BARs, which are further freed if epc_set_bar() fails (for instance, due to no free inbound window).  However, when pci_epc_set_bar() fails, the error path:    pci_epc_set_bar() ->     pci_epf_free_space()  does not clear the previous assignment to epf_test->reg[bar].  Then, if the host reboots, the PERST# deassertion restarts the BAR allocation sequence with the same allocation failure (no free inbound window), creating a double free situation since epf_test->reg[bar] was deallocated and is still non-NULL.  Thus, make sure that pci_epf_alloc_space() and pci_epf_free_space() invocations are symmetric, and as such, set epf_test->reg[bar] to NULL when memory is freed.  [kwilczynski: commit log]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38069","epss":0.00171,"percentile":0.06644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38069","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.130815},"relatedVulnerabilities":[{"id":"CVE-2025-38069","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38069","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/8b83893d1f6c6061a7d58169ecdf9d5ee9f306ee","https://git.kernel.org/stable/c/934e9d137d937706004c325fa1474f9e3f1ba10a","https://git.kernel.org/stable/c/fe2329eff5bee461ebcafadb6ca1df0cbf5945fd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: pci-epf-test: Fix double free that causes kernel to oops\n\nFix a kernel oops found while testing the stm32_pcie Endpoint driver\nwith handling of PERST# deassertion:\n\nDuring EP initialization, pci_epf_test_alloc_space() allocates all BARs,\nwhich are further freed if epc_set_bar() fails (for instance, due to no\nfree inbound window).\n\nHowever, when pci_epc_set_bar() fails, the error path:\n\n  pci_epc_set_bar() ->\n    pci_epf_free_space()\n\ndoes not clear the previous assignment to epf_test->reg[bar].\n\nThen, if the host reboots, the PERST# deassertion restarts the BAR\nallocation sequence with the same allocation failure (no free inbound\nwindow), creating a double free situation since epf_test->reg[bar] was\ndeallocated and is still non-NULL.\n\nThus, make sure that pci_epf_alloc_space() and pci_epf_free_space()\ninvocations are symmetric, and as such, set epf_test->reg[bar] to NULL\nwhen memory is freed.\n\n[kwilczynski: commit log]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38069","epss":0.00171,"percentile":0.06644,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38069","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38069","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38080","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38080","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Increase block_sequence array size  [Why] It's possible to generate more than 50 steps in hwss_build_fast_sequence, for example with a 6-pipe asic where all pipes are in one MPC chain. This overflows the block_sequence buffer and corrupts block_sequence_steps, causing a crash.  [How] Expand block_sequence to 100 items. A naive upper bound on the possible number of steps for a 6-pipe asic, ignoring the potential for steps to be mutually exclusive, is 91 with current code, therefore 100 is sufficient.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38080","epss":0.00162,"percentile":0.0577,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08505},"relatedVulnerabilities":[{"id":"CVE-2025-38080","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38080","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3a7810c212bcf2f722671dadf4b23ff70a7d23ee","https://git.kernel.org/stable/c/bf1666072e7482317cf2302621766482a21a62c7","https://git.kernel.org/stable/c/de67e80ab48f1f23663831007a2fa3c1471a7757","https://git.kernel.org/stable/c/e55c5704b12eeea27e212bfab8f7e51ad3e8ac1f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Increase block_sequence array size\n\n[Why]\nIt's possible to generate more than 50 steps in hwss_build_fast_sequence,\nfor example with a 6-pipe asic where all pipes are in one MPC chain. This\noverflows the block_sequence buffer and corrupts block_sequence_steps,\ncausing a crash.\n\n[How]\nExpand block_sequence to 100 items. A naive upper bound on the possible\nnumber of steps for a 6-pipe asic, ignoring the potential for steps to be\nmutually exclusive, is 91 with current code, therefore 100 is sufficient.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38080","epss":0.00162,"percentile":0.0577,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38080","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38081","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi-rockchip: Fix register out of bounds access  Do not write native chip select stuff for GPIO chip selects. GPIOs can be numbered much higher than native CS. Also, it makes no sense.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38081","epss":0.00165,"percentile":0.06041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38081","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12045},"relatedVulnerabilities":[{"id":"CVE-2025-38081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38081","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/254e04ec799c1ff8c1e2bd08a57c6a849895d6ff","https://git.kernel.org/stable/c/4a120221661fcecb253448d7b041a52d47f1d91f","https://git.kernel.org/stable/c/7a874e8b54ea21094f7fd2d428b164394c6cb316","https://git.kernel.org/stable/c/ace57bd1fb49d193edec5f6a1f255f48dd5fca90"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi-rockchip: Fix register out of bounds access\n\nDo not write native chip select stuff for GPIO chip selects.\nGPIOs can be numbered much higher than native CS.\nAlso, it makes no sense.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38081","epss":0.00165,"percentile":0.06041,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38081","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38096","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38096","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: iwlwifi: don't warn when if there is a FW error  iwl_trans_reclaim is warning if it is called when the FW is not alive. But if it is called when there is a pending restart, i.e. after a FW error, there is no need to warn, instead - return silently.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38096","epss":0.00165,"percentile":0.06027,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08662500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38096","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38096","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0446d34a853d9576e2a7628c803d2abd2f8cf3a8","https://git.kernel.org/stable/c/c7f50d0433a016d43681592836a3d484817bfb34","https://git.kernel.org/stable/c/d07a08f42dc7230c902e1af2a899a72b0a03aa69"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: don't warn when if there is a FW error\n\niwl_trans_reclaim is warning if it is called when the FW is not alive.\nBut if it is called when there is a pending restart, i.e. after a FW\nerror, there is no need to warn, instead - return silently.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38096","epss":0.00165,"percentile":0.06027,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38096","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38117","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: MGMT: Protect mgmt_pending list with its own lock  This uses a mutex to protect from concurrent access of mgmt_pending list which can cause crashes like:  ================================================================== BUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91 Read of size 2 at addr ffff0000c48885b2 by task syz.4.334/7318  CPU: 0 UID: 0 PID: 7318 Comm: syz.4.334 Not tainted 6.15.0-rc7-syzkaller-g187899f4124a #0 PREEMPT Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 Call trace:  show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C)  __dump_stack+0x30/0x40 lib/dump_stack.c:94  dump_stack_lvl+0xd8/0x12c lib/dump_stack.c:120  print_address_description+0xa8/0x254 mm/kasan/report.c:408  print_report+0x68/0x84 mm/kasan/report.c:521  kasan_report+0xb0/0x110 mm/kasan/report.c:634  __asan_report_load2_noabort+0x20/0x2c mm/kasan/report_generic.c:379  hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91  mgmt_pending_find+0x7c/0x140 net/bluetooth/mgmt_util.c:223  pending_find net/bluetooth/mgmt.c:947 [inline]  remove_adv_monitor+0x44/0x1a4 net/bluetooth/mgmt.c:5445  hci_mgmt_cmd+0x780/0xc00 net/bluetooth/hci_sock.c:1712  hci_sock_sendmsg+0x544/0xbb0 net/bluetooth/hci_sock.c:1832  sock_sendmsg_nosec net/socket.c:712 [inline]  __sock_sendmsg net/socket.c:727 [inline]  sock_write_iter+0x25c/0x378 net/socket.c:1131  new_sync_write fs/read_write.c:591 [inline]  vfs_write+0x62c/0x97c fs/read_write.c:684  ksys_write+0x120/0x210 fs/read_write.c:736  __do_sys_write fs/read_write.c:747 [inline]  __se_sys_write fs/read_write.c:744 [inline]  __arm64_sys_write+0x7c/0x90 fs/read_write.c:744  __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]  invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49  el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132  do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151  el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767  el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786  el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600  Allocated by task 7037:  kasan_save_stack mm/kasan/common.c:47 [inline]  kasan_save_track+0x40/0x78 mm/kasan/common.c:68  kasan_save_alloc_info+0x44/0x54 mm/kasan/generic.c:562  poison_kmalloc_redzone mm/kasan/common.c:377 [inline]  __kasan_kmalloc+0x9c/0xb4 mm/kasan/common.c:394  kasan_kmalloc include/linux/kasan.h:260 [inline]  __do_kmalloc_node mm/slub.c:4327 [inline]  __kmalloc_noprof+0x2fc/0x4c8 mm/slub.c:4339  kmalloc_noprof include/linux/slab.h:909 [inline]  sk_prot_alloc+0xc4/0x1f0 net/core/sock.c:2198  sk_alloc+0x44/0x3ac net/core/sock.c:2254  bt_sock_alloc+0x4c/0x300 net/bluetooth/af_bluetooth.c:148  hci_sock_create+0xa8/0x194 net/bluetooth/hci_sock.c:2202  bt_sock_create+0x14c/0x24c net/bluetooth/af_bluetooth.c:132  __sock_create+0x43c/0x91c net/socket.c:1541  sock_create net/socket.c:1599 [inline]  __sys_socket_create net/socket.c:1636 [inline]  __sys_socket+0xd4/0x1c0 net/socket.c:1683  __do_sys_socket net/socket.c:1697 [inline]  __se_sys_socket net/socket.c:1695 [inline]  __arm64_sys_socket+0x7c/0x94 net/socket.c:1695  __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]  invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49  el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132  do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151  el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767  el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786  el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600  Freed by task 6607:  kasan_save_stack mm/kasan/common.c:47 [inline]  kasan_save_track+0x40/0x78 mm/kasan/common.c:68  kasan_save_free_info+0x58/0x70 mm/kasan/generic.c:576  poison_slab_object mm/kasan/common.c:247 [inline]  __kasan_slab_free+0x68/0x88 mm/kasan/common.c:264  kasan_slab_free include/linux/kasan.h:233 [inline ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38117","epss":0.0016,"percentile":0.05481,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38117","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12240000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38117","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38117","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4e83f2dbb2bf677e614109df24426c4dded472d4","https://git.kernel.org/stable/c/6fe26f694c824b8a4dbf50c635bee1302e3f099c","https://git.kernel.org/stable/c/7b5958332f20dc66b19be564c402dbc21b927a81","https://git.kernel.org/stable/c/bdd56875c6926d8009914f427df71797693e90d4","https://git.kernel.org/stable/c/d7882db79135c829a922daf3571f33ea1e056ae3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Protect mgmt_pending list with its own lock\n\nThis uses a mutex to protect from concurrent access of mgmt_pending\nlist which can cause crashes like:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91\nRead of size 2 at addr ffff0000c48885b2 by task syz.4.334/7318\n\nCPU: 0 UID: 0 PID: 7318 Comm: syz.4.334 Not tainted 6.15.0-rc7-syzkaller-g187899f4124a #0 PREEMPT\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025\nCall trace:\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C)\n __dump_stack+0x30/0x40 lib/dump_stack.c:94\n dump_stack_lvl+0xd8/0x12c lib/dump_stack.c:120\n print_address_description+0xa8/0x254 mm/kasan/report.c:408\n print_report+0x68/0x84 mm/kasan/report.c:521\n kasan_report+0xb0/0x110 mm/kasan/report.c:634\n __asan_report_load2_noabort+0x20/0x2c mm/kasan/report_generic.c:379\n hci_sock_get_channel+0x60/0x68 net/bluetooth/hci_sock.c:91\n mgmt_pending_find+0x7c/0x140 net/bluetooth/mgmt_util.c:223\n pending_find net/bluetooth/mgmt.c:947 [inline]\n remove_adv_monitor+0x44/0x1a4 net/bluetooth/mgmt.c:5445\n hci_mgmt_cmd+0x780/0xc00 net/bluetooth/hci_sock.c:1712\n hci_sock_sendmsg+0x544/0xbb0 net/bluetooth/hci_sock.c:1832\n sock_sendmsg_nosec net/socket.c:712 [inline]\n __sock_sendmsg net/socket.c:727 [inline]\n sock_write_iter+0x25c/0x378 net/socket.c:1131\n new_sync_write fs/read_write.c:591 [inline]\n vfs_write+0x62c/0x97c fs/read_write.c:684\n ksys_write+0x120/0x210 fs/read_write.c:736\n __do_sys_write fs/read_write.c:747 [inline]\n __se_sys_write fs/read_write.c:744 [inline]\n __arm64_sys_write+0x7c/0x90 fs/read_write.c:744\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nAllocated by task 7037:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x44/0x54 mm/kasan/generic.c:562\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x9c/0xb4 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4327 [inline]\n __kmalloc_noprof+0x2fc/0x4c8 mm/slub.c:4339\n kmalloc_noprof include/linux/slab.h:909 [inline]\n sk_prot_alloc+0xc4/0x1f0 net/core/sock.c:2198\n sk_alloc+0x44/0x3ac net/core/sock.c:2254\n bt_sock_alloc+0x4c/0x300 net/bluetooth/af_bluetooth.c:148\n hci_sock_create+0xa8/0x194 net/bluetooth/hci_sock.c:2202\n bt_sock_create+0x14c/0x24c net/bluetooth/af_bluetooth.c:132\n __sock_create+0x43c/0x91c net/socket.c:1541\n sock_create net/socket.c:1599 [inline]\n __sys_socket_create net/socket.c:1636 [inline]\n __sys_socket+0xd4/0x1c0 net/socket.c:1683\n __do_sys_socket net/socket.c:1697 [inline]\n __se_sys_socket net/socket.c:1695 [inline]\n __arm64_sys_socket+0x7c/0x94 net/socket.c:1695\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x58/0x17c arch/arm64/kernel/entry-common.c:767\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:786\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nFreed by task 6607:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_free_info+0x58/0x70 mm/kasan/generic.c:576\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x68/0x88 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38117","epss":0.0016,"percentile":0.05481,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38117","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38117","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38127","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38127","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ice: fix Tx scheduler error handling in XDP callback  When the XDP program is loaded, the XDP callback adds new Tx queues. This means that the callback must update the Tx scheduler with the new queue number. In the event of a Tx scheduler failure, the XDP callback should also fail and roll back any changes previously made for XDP preparation.  The previous implementation had a bug that not all changes made by the XDP callback were rolled back. This caused the crash with the following call trace:  [  +9.549584] ice 0000:ca:00.0: Failed VSI LAN queue config for XDP, error: -5 [  +0.382335] Oops: general protection fault, probably for non-canonical address 0x50a2250a90495525: 0000 [#1] SMP NOPTI [  +0.010710] CPU: 103 UID: 0 PID: 0 Comm: swapper/103 Not tainted 6.14.0-net-next-mar-31+ #14 PREEMPT(voluntary) [  +0.010175] Hardware name: Intel Corporation M50CYP2SBSTD/M50CYP2SBSTD, BIOS SE5C620.86B.01.01.0005.2202160810 02/16/2022 [  +0.010946] RIP: 0010:__ice_update_sample+0x39/0xe0 [ice]  [...]  [  +0.002715] Call Trace: [  +0.002452]  <IRQ> [  +0.002021]  ? __die_body.cold+0x19/0x29 [  +0.003922]  ? die_addr+0x3c/0x60 [  +0.003319]  ? exc_general_protection+0x17c/0x400 [  +0.004707]  ? asm_exc_general_protection+0x26/0x30 [  +0.004879]  ? __ice_update_sample+0x39/0xe0 [ice] [  +0.004835]  ice_napi_poll+0x665/0x680 [ice] [  +0.004320]  __napi_poll+0x28/0x190 [  +0.003500]  net_rx_action+0x198/0x360 [  +0.003752]  ? update_rq_clock+0x39/0x220 [  +0.004013]  handle_softirqs+0xf1/0x340 [  +0.003840]  ? sched_clock_cpu+0xf/0x1f0 [  +0.003925]  __irq_exit_rcu+0xc2/0xe0 [  +0.003665]  common_interrupt+0x85/0xa0 [  +0.003839]  </IRQ> [  +0.002098]  <TASK> [  +0.002106]  asm_common_interrupt+0x26/0x40 [  +0.004184] RIP: 0010:cpuidle_enter_state+0xd3/0x690  Fix this by performing the missing unmapping of XDP queues from q_vectors and setting the XDP rings pointer back to NULL after all those queues are released. Also, add an immediate exit from the XDP callback in case of ring preparation failure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38127","epss":0.00176,"percentile":0.07237,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09240000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38127","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38127","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0153f36041b8e52019ebfa8629c13bf8f9b0a951","https://git.kernel.org/stable/c/0e061abaad1498c5b76c10c594d4359ceb6b9145","https://git.kernel.org/stable/c/1d3c5d0dec6797eca3a861dab0816fa9505d9c3e","https://git.kernel.org/stable/c/276849954d7cbe6eec827b21fe2df43f9bf07011"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix Tx scheduler error handling in XDP callback\n\nWhen the XDP program is loaded, the XDP callback adds new Tx queues.\nThis means that the callback must update the Tx scheduler with the new\nqueue number. In the event of a Tx scheduler failure, the XDP callback\nshould also fail and roll back any changes previously made for XDP\npreparation.\n\nThe previous implementation had a bug that not all changes made by the\nXDP callback were rolled back. This caused the crash with the following\ncall trace:\n\n[  +9.549584] ice 0000:ca:00.0: Failed VSI LAN queue config for XDP, error: -5\n[  +0.382335] Oops: general protection fault, probably for non-canonical address 0x50a2250a90495525: 0000 [#1] SMP NOPTI\n[  +0.010710] CPU: 103 UID: 0 PID: 0 Comm: swapper/103 Not tainted 6.14.0-net-next-mar-31+ #14 PREEMPT(voluntary)\n[  +0.010175] Hardware name: Intel Corporation M50CYP2SBSTD/M50CYP2SBSTD, BIOS SE5C620.86B.01.01.0005.2202160810 02/16/2022\n[  +0.010946] RIP: 0010:__ice_update_sample+0x39/0xe0 [ice]\n\n[...]\n\n[  +0.002715] Call Trace:\n[  +0.002452]  <IRQ>\n[  +0.002021]  ? __die_body.cold+0x19/0x29\n[  +0.003922]  ? die_addr+0x3c/0x60\n[  +0.003319]  ? exc_general_protection+0x17c/0x400\n[  +0.004707]  ? asm_exc_general_protection+0x26/0x30\n[  +0.004879]  ? __ice_update_sample+0x39/0xe0 [ice]\n[  +0.004835]  ice_napi_poll+0x665/0x680 [ice]\n[  +0.004320]  __napi_poll+0x28/0x190\n[  +0.003500]  net_rx_action+0x198/0x360\n[  +0.003752]  ? update_rq_clock+0x39/0x220\n[  +0.004013]  handle_softirqs+0xf1/0x340\n[  +0.003840]  ? sched_clock_cpu+0xf/0x1f0\n[  +0.003925]  __irq_exit_rcu+0xc2/0xe0\n[  +0.003665]  common_interrupt+0x85/0xa0\n[  +0.003839]  </IRQ>\n[  +0.002098]  <TASK>\n[  +0.002106]  asm_common_interrupt+0x26/0x40\n[  +0.004184] RIP: 0010:cpuidle_enter_state+0xd3/0x690\n\nFix this by performing the missing unmapping of XDP queues from\nq_vectors and setting the XDP rings pointer back to NULL after all those\nqueues are released.\nAlso, add an immediate exit from the XDP callback in case of ring\npreparation failure.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38127","epss":0.00176,"percentile":0.07237,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38127","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38132","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38132","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  coresight: holding cscfg_csdev_lock while removing cscfg from csdev  There'll be possible race scenario for coresight config:  CPU0                                          CPU1 (perf enable)                                 load module                                               cscfg_load_config_sets()                                               activate config. // sysfs                                               (sys_active_cnt == 1) ... cscfg_csdev_enable_active_config()   lock(csdev->cscfg_csdev_lock)                                               deactivate config // sysfs                                               (sys_activec_cnt == 0)                                               cscfg_unload_config_sets()   <iterating config_csdev_list>               cscfg_remove_owned_csdev_configs()   // here load config activate by CPU1   unlock(csdev->cscfg_csdev_lock)  iterating config_csdev_list could be raced with config_csdev_list's entry delete.  To resolve this race , hold csdev->cscfg_csdev_lock() while cscfg_remove_owned_csdev_configs()","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38132","epss":0.00141,"percentile":0.03765,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07402500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38132","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38132","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/42f8afb0b161631fd1d814d017f75f955475ad41","https://git.kernel.org/stable/c/53b9e2659719b04f5ba7593f2af0f2335f75e94a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: holding cscfg_csdev_lock while removing cscfg from csdev\n\nThere'll be possible race scenario for coresight config:\n\nCPU0                                          CPU1\n(perf enable)                                 load module\n                                              cscfg_load_config_sets()\n                                              activate config. // sysfs\n                                              (sys_active_cnt == 1)\n...\ncscfg_csdev_enable_active_config()\n  lock(csdev->cscfg_csdev_lock)\n                                              deactivate config // sysfs\n                                              (sys_activec_cnt == 0)\n                                              cscfg_unload_config_sets()\n  <iterating config_csdev_list>               cscfg_remove_owned_csdev_configs()\n  // here load config activate by CPU1\n  unlock(csdev->cscfg_csdev_lock)\n\niterating config_csdev_list could be raced with config_csdev_list's\nentry delete.\n\nTo resolve this race , hold csdev->cscfg_csdev_lock() while\ncscfg_remove_owned_csdev_configs()","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38132","epss":0.00141,"percentile":0.03765,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38132","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38140","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38140","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm: limit swapping tables for devices with zone write plugs  dm_revalidate_zones() only allowed new or previously unzoned devices to call blk_revalidate_disk_zones(). If the device was already zoned, disk->nr_zones would always equal md->nr_zones, so dm_revalidate_zones() returned without doing any work. This would make the zoned settings for the device not match the new table. If the device had zone write plug resources, it could run into errors like bdev_zone_is_seq() reading invalid memory because disk->conv_zones_bitmap was the wrong size.  If the device doesn't have any zone write plug resources, calling blk_revalidate_disk_zones() will always correctly update device.  If blk_revalidate_disk_zones() fails, it can still overwrite or clear the current disk->nr_zones value. In this case, DM must restore the previous value of disk->nr_zones, so that the zoned settings will continue to match the previous value that it fell back to.  If the device already has zone write plug resources, blk_revalidate_disk_zones() will not correctly update them, if it is called for arbitrary zoned device changes.  Since there is not much need for this ability, the easiest solution is to disallow any table reloads that change the zoned settings, for devices that already have zone plug resources.  Specifically, if a device already has zone plug resources allocated, it can only switch to another zoned table that also emulates zone append.  Also, it cannot change the device size or the zone size. A device can switch to an error target.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38140","epss":0.0014,"percentile":0.03673,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0735},"relatedVulnerabilities":[{"id":"CVE-2025-38140","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38140","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/121218bef4c1df165181f5cd8fc3a2246bac817e","https://git.kernel.org/stable/c/ac8acb0bfd98a1c65f3ca9a3e217a766124eebd8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm: limit swapping tables for devices with zone write plugs\n\ndm_revalidate_zones() only allowed new or previously unzoned devices to\ncall blk_revalidate_disk_zones(). If the device was already zoned,\ndisk->nr_zones would always equal md->nr_zones, so dm_revalidate_zones()\nreturned without doing any work. This would make the zoned settings for\nthe device not match the new table. If the device had zone write plug\nresources, it could run into errors like bdev_zone_is_seq() reading\ninvalid memory because disk->conv_zones_bitmap was the wrong size.\n\nIf the device doesn't have any zone write plug resources, calling\nblk_revalidate_disk_zones() will always correctly update device.  If\nblk_revalidate_disk_zones() fails, it can still overwrite or clear the\ncurrent disk->nr_zones value. In this case, DM must restore the previous\nvalue of disk->nr_zones, so that the zoned settings will continue to\nmatch the previous value that it fell back to.\n\nIf the device already has zone write plug resources,\nblk_revalidate_disk_zones() will not correctly update them, if it is\ncalled for arbitrary zoned device changes.  Since there is not much need\nfor this ability, the easiest solution is to disallow any table reloads\nthat change the zoned settings, for devices that already have zone plug\nresources.  Specifically, if a device already has zone plug resources\nallocated, it can only switch to another zoned table that also emulates\nzone append.  Also, it cannot change the device size or the zone size. A\ndevice can switch to an error target.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38140","epss":0.0014,"percentile":0.03673,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38140","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38182","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ublk: santizize the arguments from userspace when adding a device  Sanity check the values for queue depth and number of queues we get from userspace when adding a device.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38182","epss":0.00164,"percentile":0.05947,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-38182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38182","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0f8df5d6f25ac17c52a8bc6418e60a3e63130550","https://git.kernel.org/stable/c/3162d8235c8c4d585525cee8a59d1c180940a968","https://git.kernel.org/stable/c/8c8472855884355caf3d8e0c50adf825f83454b2","https://git.kernel.org/stable/c/e2b2b7cf6368580114851cb3932f2ad9fbf23386"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nublk: santizize the arguments from userspace when adding a device\n\nSanity check the values for queue depth and number of queues\nwe get from userspace when adding a device.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38182","epss":0.00164,"percentile":0.05947,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38182","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38195","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38195","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()  ERROR INFO:  CPU 25 Unable to handle kernel paging request at virtual address 0x0          ...  Call Trace:  [<900000000023c30c>] huge_pte_offset+0x3c/0x58  [<900000000057fd4c>] hugetlb_follow_page_mask+0x74/0x438  [<900000000051fee8>] __get_user_pages+0xe0/0x4c8  [<9000000000522414>] faultin_page_range+0x84/0x380  [<9000000000564e8c>] madvise_vma_behavior+0x534/0xa48  [<900000000056689c>] do_madvise+0x1bc/0x3e8  [<9000000000566df4>] sys_madvise+0x24/0x38  [<90000000015b9e88>] do_syscall+0x78/0x98  [<9000000000221f18>] handle_syscall+0xb8/0x158  In some cases, pmd may be NULL and rely on NULL as the return value for processing, so it is necessary to determine this situation here.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38195","epss":0.00156,"percentile":0.0505,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0819},"relatedVulnerabilities":[{"id":"CVE-2025-38195","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38195","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/985f086f281b7bbb6644851e63af1a17ffff9277","https://git.kernel.org/stable/c/b427d98d55217b53c88643579fbbd8a4c351a105","https://git.kernel.org/stable/c/b5c7397b7fd125203c60b59860c168ee92291272","https://git.kernel.org/stable/c/ee084fa96123ede8b0563a1b5a9b23adc43cd50d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Fix panic caused by NULL-PMD in huge_pte_offset()\n\nERROR INFO:\n\nCPU 25 Unable to handle kernel paging request at virtual address 0x0\n         ...\n Call Trace:\n [<900000000023c30c>] huge_pte_offset+0x3c/0x58\n [<900000000057fd4c>] hugetlb_follow_page_mask+0x74/0x438\n [<900000000051fee8>] __get_user_pages+0xe0/0x4c8\n [<9000000000522414>] faultin_page_range+0x84/0x380\n [<9000000000564e8c>] madvise_vma_behavior+0x534/0xa48\n [<900000000056689c>] do_madvise+0x1bc/0x3e8\n [<9000000000566df4>] sys_madvise+0x24/0x38\n [<90000000015b9e88>] do_syscall+0x78/0x98\n [<9000000000221f18>] handle_syscall+0xb8/0x158\n\nIn some cases, pmd may be NULL and rely on NULL as the return value for\nprocessing, so it is necessary to determine this situation here.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38195","epss":0.00156,"percentile":0.0505,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38195","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38203","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38203","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  jfs: Fix null-ptr-deref in jfs_ioc_trim  [ Syzkaller Report ]  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000087: 0000 [#1 KASAN: null-ptr-deref in range [0x0000000000000438-0x000000000000043f] CPU: 2 UID: 0 PID: 10614 Comm: syz-executor.0 Not tainted 6.13.0-rc6-gfbfd64d25c7a-dirty #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Sched_ext: serialise (enabled+all), task: runnable_at=-30ms RIP: 0010:jfs_ioc_trim+0x34b/0x8f0 Code: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93 90 82 fe ff 4c 89 ff 31 f6 RSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206 RAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a RDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001 RBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000 R10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000 R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438 FS:  00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> ? __die_body+0x61/0xb0 ? die_addr+0xb1/0xe0 ? exc_general_protection+0x333/0x510 ? asm_exc_general_protection+0x26/0x30 ? jfs_ioc_trim+0x34b/0x8f0 jfs_ioctl+0x3c8/0x4f0 ? __pfx_jfs_ioctl+0x10/0x10 ? __pfx_jfs_ioctl+0x10/0x10 __se_sys_ioctl+0x269/0x350 ? __pfx___se_sys_ioctl+0x10/0x10 ? do_syscall_64+0xfb/0x210 do_syscall_64+0xee/0x210 ? syscall_exit_to_user_mode+0x1e0/0x330 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe51f4903ad Code: c3 e8 a7 2b 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d RSP: 002b:00007fe5202250c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007fe51f5cbf80 RCX: 00007fe51f4903ad RDX: 0000000020000680 RSI: 00000000c0185879 RDI: 0000000000000005 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 00007fe520225640 R13: 000000000000000e R14: 00007fe51f44fca0 R15: 00007fe52021d000 </TASK> Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:jfs_ioc_trim+0x34b/0x8f0 Code: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93 90 82 fe ff 4c 89 ff 31 f6 RSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206 RAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a RDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001 RBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000 R10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000 R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438 FS:  00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Kernel panic - not syncing: Fatal exception  [ Analysis ]  We believe that we have found a concurrency bug in the `fs/jfs` module that results in a null pointer dereference. There is a closely related issue which has been fixed:  https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d6c1b3599b2feb5c7291f5ac3a36e5fa7cedb234  ... but, unfortunately, the accepted patch appears to still be susceptible to a null pointer dereference under some interleavings.  To trigger the bug, we think that `JFS_SBI(ipbmap->i_sb)->bmap` is set to NULL in `dbFreeBits` and then dereferenced in `jfs_ioc_trim`. This bug manifests quite rarely under normal circumstances, but is triggereable from a syz-program.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38203","epss":0.00166,"percentile":0.06105,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38203","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08715},"relatedVulnerabilities":[{"id":"CVE-2025-38203","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38203","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0d50231d473f89024158dc62624930de45d13718","https://git.kernel.org/stable/c/233340626cf1b1887dca181f9f811db60c73f802","https://git.kernel.org/stable/c/4a2de0f5b8d7f218bea5bd43d30b466e8b272b8d","https://git.kernel.org/stable/c/4a8cb9908b51500a76f5156423bd295df53bff89","https://git.kernel.org/stable/c/9806ae34d7d661c372247cd36f83bfa0523d60ed","https://git.kernel.org/stable/c/a39f811a9f5edb6d97bede8e6fe730393d3c8537","https://git.kernel.org/stable/c/a4685408ff6c3e2af366ad9a7274f45ff3f394ee","https://git.kernel.org/stable/c/a9d41c925069c950e18160e12a7e10e0f58c56fb","https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix null-ptr-deref in jfs_ioc_trim\n\n[ Syzkaller Report ]\n\nOops: general protection fault, probably for non-canonical address\n0xdffffc0000000087: 0000 [#1\nKASAN: null-ptr-deref in range [0x0000000000000438-0x000000000000043f]\nCPU: 2 UID: 0 PID: 10614 Comm: syz-executor.0 Not tainted\n6.13.0-rc6-gfbfd64d25c7a-dirty #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nSched_ext: serialise (enabled+all), task: runnable_at=-30ms\nRIP: 0010:jfs_ioc_trim+0x34b/0x8f0\nCode: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93\n90 82 fe ff 4c 89 ff 31 f6\nRSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206\nRAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a\nRDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001\nRBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000\nR10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438\nFS:  00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n<TASK>\n? __die_body+0x61/0xb0\n? die_addr+0xb1/0xe0\n? exc_general_protection+0x333/0x510\n? asm_exc_general_protection+0x26/0x30\n? jfs_ioc_trim+0x34b/0x8f0\njfs_ioctl+0x3c8/0x4f0\n? __pfx_jfs_ioctl+0x10/0x10\n? __pfx_jfs_ioctl+0x10/0x10\n__se_sys_ioctl+0x269/0x350\n? __pfx___se_sys_ioctl+0x10/0x10\n? do_syscall_64+0xfb/0x210\ndo_syscall_64+0xee/0x210\n? syscall_exit_to_user_mode+0x1e0/0x330\nentry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fe51f4903ad\nCode: c3 e8 a7 2b 00 00 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 89 f8 48\n89 f7 48 89 d6 48 89 ca 4d\nRSP: 002b:00007fe5202250c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007fe51f5cbf80 RCX: 00007fe51f4903ad\nRDX: 0000000020000680 RSI: 00000000c0185879 RDI: 0000000000000005\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 00007fe520225640\nR13: 000000000000000e R14: 00007fe51f44fca0 R15: 00007fe52021d000\n</TASK>\nModules linked in:\n---[ end trace 0000000000000000 ]---\nRIP: 0010:jfs_ioc_trim+0x34b/0x8f0\nCode: e7 e8 59 a4 87 fe 4d 8b 24 24 4d 8d bc 24 38 04 00 00 48 8d 93\n90 82 fe ff 4c 89 ff 31 f6\nRSP: 0018:ffffc900055f7cd0 EFLAGS: 00010206\nRAX: 0000000000000087 RBX: 00005866a9e67ff8 RCX: 000000000000000a\nRDX: 0000000000000001 RSI: 0000000000000004 RDI: 0000000000000001\nRBP: dffffc0000000000 R08: ffff88807c180003 R09: 1ffff1100f830000\nR10: dffffc0000000000 R11: ffffed100f830001 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000438\nFS:  00007fe520225640(0000) GS:ffff8880b7e80000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005593c91b2c88 CR3: 000000014927c000 CR4: 00000000000006f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nKernel panic - not syncing: Fatal exception\n\n[ Analysis ]\n\nWe believe that we have found a concurrency bug in the `fs/jfs` module\nthat results in a null pointer dereference. There is a closely related\nissue which has been fixed:\n\nhttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d6c1b3599b2feb5c7291f5ac3a36e5fa7cedb234\n\n... but, unfortunately, the accepted patch appears to still be\nsusceptible to a null pointer dereference under some interleavings.\n\nTo trigger the bug, we think that `JFS_SBI(ipbmap->i_sb)->bmap` is set\nto NULL in `dbFreeBits` and then dereferenced in `jfs_ioc_trim`. This\nbug manifests quite rarely under normal circumstances, but is\ntriggereable from a syz-program.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38203","epss":0.00166,"percentile":0.06105,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38203","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38203","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38204","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38204","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  jfs: fix array-index-out-of-bounds read in add_missing_indices  stbl is s8 but it must contain offsets into slot which can go from 0 to 127.  Added a bound check for that error and return -EIO if the check fails. Also make jfs_readdir return with error if add_missing_indices returns with an error.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38204","epss":0.00165,"percentile":0.06089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38204","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12045},"relatedVulnerabilities":[{"id":"CVE-2025-38204","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38204","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/44618bee303bed151ef3a525ff79fbd7689593b5","https://git.kernel.org/stable/c/5dff41a86377563f7a2b968aae00d25b4ceb37c9","https://git.kernel.org/stable/c/81af4b34fd72d390d7f237c6a545cc6d09707956","https://git.kernel.org/stable/c/bfa4655d28f338e68d345aed80d19be7999bbce2","https://git.kernel.org/stable/c/c8399564a58fb6ea2ff21a6fd278417943cb51a5","https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds read in add_missing_indices\n\nstbl is s8 but it must contain offsets into slot which can go from 0 to\n127.\n\nAdded a bound check for that error and return -EIO if the check fails.\nAlso make jfs_readdir return with error if add_missing_indices returns\nwith an error.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38204","epss":0.00165,"percentile":0.06089,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38204","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38204","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38206","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38206","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  exfat: fix double free in delayed_free  The double free could happen in the following path.  exfat_create_upcase_table()         exfat_create_upcase_table() : return error         exfat_free_upcase_table() : free ->vol_utbl         exfat_load_default_upcase_table : return error      exfat_kill_sb()            delayed_free()                   exfat_free_upcase_table() <--------- double free This patch set ->vol_util as NULL after freeing it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38206","epss":0.00166,"percentile":0.06194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38206","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12699},"relatedVulnerabilities":[{"id":"CVE-2025-38206","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38206","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/13d8de1b6568dcc31a95534ced16bc0c9a67bc15","https://git.kernel.org/stable/c/1f3d9724e16d62c7d42c67d6613b8512f2887c22","https://git.kernel.org/stable/c/29abaf93357f4a7d083cf399d4306999e20db31d","https://git.kernel.org/stable/c/66e84439ec2af776ce749e8540f8fdd257774152","https://git.kernel.org/stable/c/ac65f76db9b2ff3fbc9e198c0e9aaf81b111b7d0","https://git.kernel.org/stable/c/d3cef0e7a5c1aa6217c51faa9ce8ecac35d6e1fd","https://git.kernel.org/stable/c/ea27703eb0efbadcd45b9949526160ed90536a72","https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix double free in delayed_free\n\nThe double free could happen in the following path.\n\nexfat_create_upcase_table()\n        exfat_create_upcase_table() : return error\n        exfat_free_upcase_table() : free ->vol_utbl\n        exfat_load_default_upcase_table : return error\n     exfat_kill_sb()\n           delayed_free()\n                  exfat_free_upcase_table() <--------- double free\nThis patch set ->vol_util as NULL after freeing it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38206","epss":0.00166,"percentile":0.06194,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38206","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38206","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38207","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38207","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm: fix uprobe pte be overwritten when expanding vma  Patch series \"Fix uprobe pte be overwritten when expanding vma\".   This patch (of 4):  We encountered a BUG alert triggered by Syzkaller as follows:    BUG: Bad rss-counter state mm:00000000b4a60fca type:MM_ANONPAGES val:1  And we can reproduce it with the following steps: 1. register uprobe on file at zero offset 2. mmap the file at zero offset:    addr1 = mmap(NULL, 2 * 4096, PROT_NONE, MAP_PRIVATE, fd, 0); 3. mremap part of vma1 to new vma2:    addr2 = mremap(addr1, 4096, 2 * 4096, MREMAP_MAYMOVE); 4. mremap back to orig addr1:    mremap(addr2, 4096, 4096, MREMAP_MAYMOVE | MREMAP_FIXED, addr1);  In step 3, the vma1 range [addr1, addr1 + 4096] will be remap to new vma2 with range [addr2, addr2 + 8192], and remap uprobe anon page from the vma1 to vma2, then unmap the vma1 range [addr1, addr1 + 4096].  In step 4, the vma2 range [addr2, addr2 + 4096] will be remap back to the addr range [addr1, addr1 + 4096].  Since the addr range [addr1 + 4096, addr1 + 8192] still maps the file, it will take vma_merge_new_range to expand the range, and then do uprobe_mmap in vma_complete.  Since the merged vma pgoff is also zero offset, it will install uprobe anon page to the merged vma.  However, the upcomming move_page_tables step, which use set_pte_at to remap the vma2 uprobe pte to the merged vma, will overwrite the newly uprobe pte in the merged vma, and lead that pte to be orphan.  Since the uprobe pte will be remapped to the merged vma, we can remove the unnecessary uprobe_mmap upon merged vma.  This problem was first found in linux-6.6.y and also exists in the community syzkaller: https://lore.kernel.org/all/000000000000ada39605a5e71711@google.com/T/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38207","epss":0.00134,"percentile":0.0323,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07035},"relatedVulnerabilities":[{"id":"CVE-2025-38207","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38207","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2b12d06c37fd3a394376f42f026a7478d826ed63","https://git.kernel.org/stable/c/58b83b9a9a929611a2a2e7d88f45cb0d786b7ee0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix uprobe pte be overwritten when expanding vma\n\nPatch series \"Fix uprobe pte be overwritten when expanding vma\".\n\n\nThis patch (of 4):\n\nWe encountered a BUG alert triggered by Syzkaller as follows:\n   BUG: Bad rss-counter state mm:00000000b4a60fca type:MM_ANONPAGES val:1\n\nAnd we can reproduce it with the following steps:\n1. register uprobe on file at zero offset\n2. mmap the file at zero offset:\n   addr1 = mmap(NULL, 2 * 4096, PROT_NONE, MAP_PRIVATE, fd, 0);\n3. mremap part of vma1 to new vma2:\n   addr2 = mremap(addr1, 4096, 2 * 4096, MREMAP_MAYMOVE);\n4. mremap back to orig addr1:\n   mremap(addr2, 4096, 4096, MREMAP_MAYMOVE | MREMAP_FIXED, addr1);\n\nIn step 3, the vma1 range [addr1, addr1 + 4096] will be remap to new vma2\nwith range [addr2, addr2 + 8192], and remap uprobe anon page from the vma1\nto vma2, then unmap the vma1 range [addr1, addr1 + 4096].\n\nIn step 4, the vma2 range [addr2, addr2 + 4096] will be remap back to the\naddr range [addr1, addr1 + 4096].  Since the addr range [addr1 + 4096,\naddr1 + 8192] still maps the file, it will take vma_merge_new_range to\nexpand the range, and then do uprobe_mmap in vma_complete.  Since the\nmerged vma pgoff is also zero offset, it will install uprobe anon page to\nthe merged vma.  However, the upcomming move_page_tables step, which use\nset_pte_at to remap the vma2 uprobe pte to the merged vma, will overwrite\nthe newly uprobe pte in the merged vma, and lead that pte to be orphan.\n\nSince the uprobe pte will be remapped to the merged vma, we can remove the\nunnecessary uprobe_mmap upon merged vma.\n\nThis problem was first found in linux-6.6.y and also exists in the\ncommunity syzkaller:\nhttps://lore.kernel.org/all/000000000000ada39605a5e71711@google.com/T/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38207","epss":0.00134,"percentile":0.0323,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38207","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38234","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38234","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sched/rt: Fix race in push_rt_task  Overview ======== When a CPU chooses to call push_rt_task and picks a task to push to another CPU's runqueue then it will call find_lock_lowest_rq method which would take a double lock on both CPUs' runqueues. If one of the locks aren't readily available, it may lead to dropping the current runqueue lock and reacquiring both the locks at once. During this window it is possible that the task is already migrated and is running on some other CPU. These cases are already handled. However, if the task is migrated and has already been executed and another CPU is now trying to wake it up (ttwu) such that it is queued again on the runqeue (on_rq is 1) and also if the task was run by the same CPU, then the current checks will pass even though the task was migrated out and is no longer in the pushable tasks list.  Crashes ======= This bug resulted in quite a few flavors of crashes triggering kernel panics with various crash signatures such as assert failures, page faults, null pointer dereferences, and queue corruption errors all coming from scheduler itself.  Some of the crashes: -> kernel BUG at kernel/sched/rt.c:1616! BUG_ON(idx >= MAX_RT_PRIO)    Call Trace:    ? __die_body+0x1a/0x60    ? die+0x2a/0x50    ? do_trap+0x85/0x100    ? pick_next_task_rt+0x6e/0x1d0    ? do_error_trap+0x64/0xa0    ? pick_next_task_rt+0x6e/0x1d0    ? exc_invalid_op+0x4c/0x60    ? pick_next_task_rt+0x6e/0x1d0    ? asm_exc_invalid_op+0x12/0x20    ? pick_next_task_rt+0x6e/0x1d0    __schedule+0x5cb/0x790    ? update_ts_time_stats+0x55/0x70    schedule_idle+0x1e/0x40    do_idle+0x15e/0x200    cpu_startup_entry+0x19/0x20    start_secondary+0x117/0x160    secondary_startup_64_no_verify+0xb0/0xbb  -> BUG: kernel NULL pointer dereference, address: 00000000000000c0    Call Trace:    ? __die_body+0x1a/0x60    ? no_context+0x183/0x350    ? __warn+0x8a/0xe0    ? exc_page_fault+0x3d6/0x520    ? asm_exc_page_fault+0x1e/0x30    ? pick_next_task_rt+0xb5/0x1d0    ? pick_next_task_rt+0x8c/0x1d0    __schedule+0x583/0x7e0    ? update_ts_time_stats+0x55/0x70    schedule_idle+0x1e/0x40    do_idle+0x15e/0x200    cpu_startup_entry+0x19/0x20    start_secondary+0x117/0x160    secondary_startup_64_no_verify+0xb0/0xbb  -> BUG: unable to handle page fault for address: ffff9464daea5900    kernel BUG at kernel/sched/rt.c:1861! BUG_ON(rq->cpu != task_cpu(p))  -> kernel BUG at kernel/sched/rt.c:1055! BUG_ON(!rq->nr_running)    Call Trace:    ? __die_body+0x1a/0x60    ? die+0x2a/0x50    ? do_trap+0x85/0x100    ? dequeue_top_rt_rq+0xa2/0xb0    ? do_error_trap+0x64/0xa0    ? dequeue_top_rt_rq+0xa2/0xb0    ? exc_invalid_op+0x4c/0x60    ? dequeue_top_rt_rq+0xa2/0xb0    ? asm_exc_invalid_op+0x12/0x20    ? dequeue_top_rt_rq+0xa2/0xb0    dequeue_rt_entity+0x1f/0x70    dequeue_task_rt+0x2d/0x70    __schedule+0x1a8/0x7e0    ? blk_finish_plug+0x25/0x40    schedule+0x3c/0xb0    futex_wait_queue_me+0xb6/0x120    futex_wait+0xd9/0x240    do_futex+0x344/0xa90    ? get_mm_exe_file+0x30/0x60    ? audit_exe_compare+0x58/0x70    ? audit_filter_rules.constprop.26+0x65e/0x1220    __x64_sys_futex+0x148/0x1f0    do_syscall_64+0x30/0x80    entry_SYSCALL_64_after_hwframe+0x62/0xc7  -> BUG: unable to handle page fault for address: ffff8cf3608bc2c0    Call Trace:    ? __die_body+0x1a/0x60    ? no_context+0x183/0x350    ? spurious_kernel_fault+0x171/0x1c0    ? exc_page_fault+0x3b6/0x520    ? plist_check_list+0x15/0x40    ? plist_check_list+0x2e/0x40    ? asm_exc_page_fault+0x1e/0x30    ? _cond_resched+0x15/0x30    ? futex_wait_queue_me+0xc8/0x120    ? futex_wait+0xd9/0x240    ? try_to_wake_up+0x1b8/0x490    ? futex_wake+0x78/0x160    ? do_futex+0xcd/0xa90    ? plist_check_list+0x15/0x40    ? plist_check_list+0x2e/0x40    ? plist_del+0x6a/0xd0    ? plist_check_list+0x15/0x40    ? plist_check_list+0x2e/0x40    ? dequeue_pushable_task+0x20/0x70    ? __schedule+0x382/0x7e0    ? asm_sysvec_reschedule_i ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38234","epss":0.00147,"percentile":0.04278,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38234","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.071295},"relatedVulnerabilities":[{"id":"CVE-2025-38234","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38234","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/07ecabfbca64f4f0b6071cf96e49d162fa9d138d","https://git.kernel.org/stable/c/690e47d1403e90b7f2366f03b52ed3304194c793","https://git.kernel.org/stable/c/9f6022b2573ae068793810db719e131df3ded405","https://git.kernel.org/stable/c/debfbc047196df1f6bfd52f2d028c21dce67f0de"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/rt: Fix race in push_rt_task\n\nOverview\n========\nWhen a CPU chooses to call push_rt_task and picks a task to push to\nanother CPU's runqueue then it will call find_lock_lowest_rq method\nwhich would take a double lock on both CPUs' runqueues. If one of the\nlocks aren't readily available, it may lead to dropping the current\nrunqueue lock and reacquiring both the locks at once. During this window\nit is possible that the task is already migrated and is running on some\nother CPU. These cases are already handled. However, if the task is\nmigrated and has already been executed and another CPU is now trying to\nwake it up (ttwu) such that it is queued again on the runqeue\n(on_rq is 1) and also if the task was run by the same CPU, then the\ncurrent checks will pass even though the task was migrated out and is no\nlonger in the pushable tasks list.\n\nCrashes\n=======\nThis bug resulted in quite a few flavors of crashes triggering kernel\npanics with various crash signatures such as assert failures, page\nfaults, null pointer dereferences, and queue corruption errors all\ncoming from scheduler itself.\n\nSome of the crashes:\n-> kernel BUG at kernel/sched/rt.c:1616! BUG_ON(idx >= MAX_RT_PRIO)\n   Call Trace:\n   ? __die_body+0x1a/0x60\n   ? die+0x2a/0x50\n   ? do_trap+0x85/0x100\n   ? pick_next_task_rt+0x6e/0x1d0\n   ? do_error_trap+0x64/0xa0\n   ? pick_next_task_rt+0x6e/0x1d0\n   ? exc_invalid_op+0x4c/0x60\n   ? pick_next_task_rt+0x6e/0x1d0\n   ? asm_exc_invalid_op+0x12/0x20\n   ? pick_next_task_rt+0x6e/0x1d0\n   __schedule+0x5cb/0x790\n   ? update_ts_time_stats+0x55/0x70\n   schedule_idle+0x1e/0x40\n   do_idle+0x15e/0x200\n   cpu_startup_entry+0x19/0x20\n   start_secondary+0x117/0x160\n   secondary_startup_64_no_verify+0xb0/0xbb\n\n-> BUG: kernel NULL pointer dereference, address: 00000000000000c0\n   Call Trace:\n   ? __die_body+0x1a/0x60\n   ? no_context+0x183/0x350\n   ? __warn+0x8a/0xe0\n   ? exc_page_fault+0x3d6/0x520\n   ? asm_exc_page_fault+0x1e/0x30\n   ? pick_next_task_rt+0xb5/0x1d0\n   ? pick_next_task_rt+0x8c/0x1d0\n   __schedule+0x583/0x7e0\n   ? update_ts_time_stats+0x55/0x70\n   schedule_idle+0x1e/0x40\n   do_idle+0x15e/0x200\n   cpu_startup_entry+0x19/0x20\n   start_secondary+0x117/0x160\n   secondary_startup_64_no_verify+0xb0/0xbb\n\n-> BUG: unable to handle page fault for address: ffff9464daea5900\n   kernel BUG at kernel/sched/rt.c:1861! BUG_ON(rq->cpu != task_cpu(p))\n\n-> kernel BUG at kernel/sched/rt.c:1055! BUG_ON(!rq->nr_running)\n   Call Trace:\n   ? __die_body+0x1a/0x60\n   ? die+0x2a/0x50\n   ? do_trap+0x85/0x100\n   ? dequeue_top_rt_rq+0xa2/0xb0\n   ? do_error_trap+0x64/0xa0\n   ? dequeue_top_rt_rq+0xa2/0xb0\n   ? exc_invalid_op+0x4c/0x60\n   ? dequeue_top_rt_rq+0xa2/0xb0\n   ? asm_exc_invalid_op+0x12/0x20\n   ? dequeue_top_rt_rq+0xa2/0xb0\n   dequeue_rt_entity+0x1f/0x70\n   dequeue_task_rt+0x2d/0x70\n   __schedule+0x1a8/0x7e0\n   ? blk_finish_plug+0x25/0x40\n   schedule+0x3c/0xb0\n   futex_wait_queue_me+0xb6/0x120\n   futex_wait+0xd9/0x240\n   do_futex+0x344/0xa90\n   ? get_mm_exe_file+0x30/0x60\n   ? audit_exe_compare+0x58/0x70\n   ? audit_filter_rules.constprop.26+0x65e/0x1220\n   __x64_sys_futex+0x148/0x1f0\n   do_syscall_64+0x30/0x80\n   entry_SYSCALL_64_after_hwframe+0x62/0xc7\n\n-> BUG: unable to handle page fault for address: ffff8cf3608bc2c0\n   Call Trace:\n   ? __die_body+0x1a/0x60\n   ? no_context+0x183/0x350\n   ? spurious_kernel_fault+0x171/0x1c0\n   ? exc_page_fault+0x3b6/0x520\n   ? plist_check_list+0x15/0x40\n   ? plist_check_list+0x2e/0x40\n   ? asm_exc_page_fault+0x1e/0x30\n   ? _cond_resched+0x15/0x30\n   ? futex_wait_queue_me+0xc8/0x120\n   ? futex_wait+0xd9/0x240\n   ? try_to_wake_up+0x1b8/0x490\n   ? futex_wake+0x78/0x160\n   ? do_futex+0xcd/0xa90\n   ? plist_check_list+0x15/0x40\n   ? plist_check_list+0x2e/0x40\n   ? plist_del+0x6a/0xd0\n   ? plist_check_list+0x15/0x40\n   ? plist_check_list+0x2e/0x40\n   ? dequeue_pushable_task+0x20/0x70\n   ? __schedule+0x382/0x7e0\n   ? asm_sysvec_reschedule_i\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38234","epss":0.00147,"percentile":0.04278,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38234","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38234","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38237","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38237","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()  In fimc_is_hw_change_mode(), the function changes camera modes without waiting for hardware completion, risking corrupted data or system hangs if subsequent operations proceed before the hardware is ready.  Add fimc_is_hw_wait_intmsr0_intmsd0() after mode configuration, ensuring hardware state synchronization and stable interrupt handling.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38237","epss":0.00154,"percentile":0.04876,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08084999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-38237","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38237","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/14acbb5af101b7bb58c0952949bba4c5fdf0ee7e","https://git.kernel.org/stable/c/2fbe83fe23f541798bcdd7d6b56a08d4ac205bad","https://git.kernel.org/stable/c/71209954f1e8ff0f0ba944c8d3b64bbed83d400c","https://git.kernel.org/stable/c/9b03c3ce32a685f9cb82d33c63fc18bfcee0ba1b","https://git.kernel.org/stable/c/b0d92b94278561f43057003a73a17ce13b7c1a1a","https://git.kernel.org/stable/c/bb97dfab7615fea97322b8a6131546e80f878a69","https://git.kernel.org/stable/c/bd9f6ce7d512fa21249415c16af801a4ed5d97b6","https://git.kernel.org/stable/c/e4077a10a25560ec0bd0b42322e4ea027d6f76e2","https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode()\n\nIn fimc_is_hw_change_mode(), the function changes camera modes without\nwaiting for hardware completion, risking corrupted data or system hangs\nif subsequent operations proceed before the hardware is ready.\n\nAdd fimc_is_hw_wait_intmsr0_intmsd0() after mode configuration, ensuring\nhardware state synchronization and stable interrupt handling.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38237","epss":0.00154,"percentile":0.04876,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38237","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38244","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix potential deadlock when reconnecting channels  Fix cifs_signal_cifsd_for_reconnect() to take the correct lock order and prevent the following deadlock from happening  ====================================================== WARNING: possible circular locking dependency detected 6.16.0-rc3-build2+ #1301 Tainted: G S      W ------------------------------------------------------ cifsd/6055 is trying to acquire lock: ffff88810ad56038 (&tcp_ses->srv_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x134/0x200  but task is already holding lock: ffff888119c64330 (&ret_buf->chan_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0xcf/0x200  which lock already depends on the new lock.  the existing dependency chain (in reverse order) is:  -> #2 (&ret_buf->chan_lock){+.+.}-{3:3}:        validate_chain+0x1cf/0x270        __lock_acquire+0x60e/0x780        lock_acquire.part.0+0xb4/0x1f0        _raw_spin_lock+0x2f/0x40        cifs_setup_session+0x81/0x4b0        cifs_get_smb_ses+0x771/0x900        cifs_mount_get_session+0x7e/0x170        cifs_mount+0x92/0x2d0        cifs_smb3_do_mount+0x161/0x460        smb3_get_tree+0x55/0x90        vfs_get_tree+0x46/0x180        do_new_mount+0x1b0/0x2e0        path_mount+0x6ee/0x740        do_mount+0x98/0xe0        __do_sys_mount+0x148/0x180        do_syscall_64+0xa4/0x260        entry_SYSCALL_64_after_hwframe+0x76/0x7e  -> #1 (&ret_buf->ses_lock){+.+.}-{3:3}:        validate_chain+0x1cf/0x270        __lock_acquire+0x60e/0x780        lock_acquire.part.0+0xb4/0x1f0        _raw_spin_lock+0x2f/0x40        cifs_match_super+0x101/0x320        sget+0xab/0x270        cifs_smb3_do_mount+0x1e0/0x460        smb3_get_tree+0x55/0x90        vfs_get_tree+0x46/0x180        do_new_mount+0x1b0/0x2e0        path_mount+0x6ee/0x740        do_mount+0x98/0xe0        __do_sys_mount+0x148/0x180        do_syscall_64+0xa4/0x260        entry_SYSCALL_64_after_hwframe+0x76/0x7e  -> #0 (&tcp_ses->srv_lock){+.+.}-{3:3}:        check_noncircular+0x95/0xc0        check_prev_add+0x115/0x2f0        validate_chain+0x1cf/0x270        __lock_acquire+0x60e/0x780        lock_acquire.part.0+0xb4/0x1f0        _raw_spin_lock+0x2f/0x40        cifs_signal_cifsd_for_reconnect+0x134/0x200        __cifs_reconnect+0x8f/0x500        cifs_handle_standard+0x112/0x280        cifs_demultiplex_thread+0x64d/0xbc0        kthread+0x2f7/0x310        ret_from_fork+0x2a/0x230        ret_from_fork_asm+0x1a/0x30  other info that might help us debug this:  Chain exists of:   &tcp_ses->srv_lock --> &ret_buf->ses_lock --> &ret_buf->chan_lock   Possible unsafe locking scenario:         CPU0                    CPU1        ----                    ----   lock(&ret_buf->chan_lock);                                lock(&ret_buf->ses_lock);                                lock(&ret_buf->chan_lock);   lock(&tcp_ses->srv_lock);   *** DEADLOCK ***  3 locks held by cifsd/6055:  #0: ffffffff857de398 (&cifs_tcp_ses_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x7b/0x200  #1: ffff888119c64060 (&ret_buf->ses_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x9c/0x200  #2: ffff888119c64330 (&ret_buf->chan_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0xcf/0x200","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38244","epss":0.0022,"percentile":0.12429,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38244","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11550000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-38244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38244","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/711741f94ac3cf9f4e3aa73aa171e76d188c0819","https://git.kernel.org/stable/c/7f3ead8ebc0ef65b6c89a13912b4e80218425629","https://git.kernel.org/stable/c/c82c7041258d96e3286f6790ab700e4edd3cc9e3","https://git.kernel.org/stable/c/fe035dc78aa6ca8f862857d45beaf7a0e03206ca"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential deadlock when reconnecting channels\n\nFix cifs_signal_cifsd_for_reconnect() to take the correct lock order\nand prevent the following deadlock from happening\n\n======================================================\nWARNING: possible circular locking dependency detected\n6.16.0-rc3-build2+ #1301 Tainted: G S      W\n------------------------------------------------------\ncifsd/6055 is trying to acquire lock:\nffff88810ad56038 (&tcp_ses->srv_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x134/0x200\n\nbut task is already holding lock:\nffff888119c64330 (&ret_buf->chan_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0xcf/0x200\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-> #2 (&ret_buf->chan_lock){+.+.}-{3:3}:\n       validate_chain+0x1cf/0x270\n       __lock_acquire+0x60e/0x780\n       lock_acquire.part.0+0xb4/0x1f0\n       _raw_spin_lock+0x2f/0x40\n       cifs_setup_session+0x81/0x4b0\n       cifs_get_smb_ses+0x771/0x900\n       cifs_mount_get_session+0x7e/0x170\n       cifs_mount+0x92/0x2d0\n       cifs_smb3_do_mount+0x161/0x460\n       smb3_get_tree+0x55/0x90\n       vfs_get_tree+0x46/0x180\n       do_new_mount+0x1b0/0x2e0\n       path_mount+0x6ee/0x740\n       do_mount+0x98/0xe0\n       __do_sys_mount+0x148/0x180\n       do_syscall_64+0xa4/0x260\n       entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n-> #1 (&ret_buf->ses_lock){+.+.}-{3:3}:\n       validate_chain+0x1cf/0x270\n       __lock_acquire+0x60e/0x780\n       lock_acquire.part.0+0xb4/0x1f0\n       _raw_spin_lock+0x2f/0x40\n       cifs_match_super+0x101/0x320\n       sget+0xab/0x270\n       cifs_smb3_do_mount+0x1e0/0x460\n       smb3_get_tree+0x55/0x90\n       vfs_get_tree+0x46/0x180\n       do_new_mount+0x1b0/0x2e0\n       path_mount+0x6ee/0x740\n       do_mount+0x98/0xe0\n       __do_sys_mount+0x148/0x180\n       do_syscall_64+0xa4/0x260\n       entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n-> #0 (&tcp_ses->srv_lock){+.+.}-{3:3}:\n       check_noncircular+0x95/0xc0\n       check_prev_add+0x115/0x2f0\n       validate_chain+0x1cf/0x270\n       __lock_acquire+0x60e/0x780\n       lock_acquire.part.0+0xb4/0x1f0\n       _raw_spin_lock+0x2f/0x40\n       cifs_signal_cifsd_for_reconnect+0x134/0x200\n       __cifs_reconnect+0x8f/0x500\n       cifs_handle_standard+0x112/0x280\n       cifs_demultiplex_thread+0x64d/0xbc0\n       kthread+0x2f7/0x310\n       ret_from_fork+0x2a/0x230\n       ret_from_fork_asm+0x1a/0x30\n\nother info that might help us debug this:\n\nChain exists of:\n  &tcp_ses->srv_lock --> &ret_buf->ses_lock --> &ret_buf->chan_lock\n\n Possible unsafe locking scenario:\n\n       CPU0                    CPU1\n       ----                    ----\n  lock(&ret_buf->chan_lock);\n                               lock(&ret_buf->ses_lock);\n                               lock(&ret_buf->chan_lock);\n  lock(&tcp_ses->srv_lock);\n\n *** DEADLOCK ***\n\n3 locks held by cifsd/6055:\n #0: ffffffff857de398 (&cifs_tcp_ses_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x7b/0x200\n #1: ffff888119c64060 (&ret_buf->ses_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0x9c/0x200\n #2: ffff888119c64330 (&ret_buf->chan_lock){+.+.}-{3:3}, at: cifs_signal_cifsd_for_reconnect+0xcf/0x200","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38244","epss":0.0022,"percentile":0.12429,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38244","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38246","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38246","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bnxt: properly flush XDP redirect lists  We encountered following crash when testing a XDP_REDIRECT feature in production:  [56251.579676] list_add corruption. next->prev should be prev (ffff93120dd40f30), but was ffffb301ef3a6740. (next=ffff93120dd 40f30). [56251.601413] ------------[ cut here ]------------ [56251.611357] kernel BUG at lib/list_debug.c:29! [56251.621082] Oops: invalid opcode: 0000 [#1] PREEMPT SMP NOPTI [56251.632073] CPU: 111 UID: 0 PID: 0 Comm: swapper/111 Kdump: loaded Tainted: P           O       6.12.33-cloudflare-2025.6. 3 #1 [56251.653155] Tainted: [P]=PROPRIETARY_MODULE, [O]=OOT_MODULE [56251.663877] Hardware name: MiTAC GC68B-B8032-G11P6-GPU/S8032GM-HE-CFR, BIOS V7.020.B10-sig 01/22/2025 [56251.682626] RIP: 0010:__list_add_valid_or_report+0x4b/0xa0 [56251.693203] Code: 0e 48 c7 c7 68 e7 d9 97 e8 42 16 fe ff 0f 0b 48 8b 52 08 48 39 c2 74 14 48 89 f1 48 c7 c7 90 e7 d9 97 48  89 c6 e8 25 16 fe ff <0f> 0b 4c 8b 02 49 39 f0 74 14 48 89 d1 48 c7 c7 e8 e7 d9 97 4c 89 [56251.725811] RSP: 0018:ffff93120dd40b80 EFLAGS: 00010246 [56251.736094] RAX: 0000000000000075 RBX: ffffb301e6bba9d8 RCX: 0000000000000000 [56251.748260] RDX: 0000000000000000 RSI: ffff9149afda0b80 RDI: ffff9149afda0b80 [56251.760349] RBP: ffff9131e49c8000 R08: 0000000000000000 R09: ffff93120dd40a18 [56251.772382] R10: ffff9159cf2ce1a8 R11: 0000000000000003 R12: ffff911a80850000 [56251.784364] R13: ffff93120fbc7000 R14: 0000000000000010 R15: ffff9139e7510e40 [56251.796278] FS:  0000000000000000(0000) GS:ffff9149afd80000(0000) knlGS:0000000000000000 [56251.809133] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [56251.819561] CR2: 00007f5e85e6f300 CR3: 00000038b85e2006 CR4: 0000000000770ef0 [56251.831365] PKRU: 55555554 [56251.838653] Call Trace: [56251.845560]  <IRQ> [56251.851943]  cpu_map_enqueue.cold+0x5/0xa [56251.860243]  xdp_do_redirect+0x2d9/0x480 [56251.868388]  bnxt_rx_xdp+0x1d8/0x4c0 [bnxt_en] [56251.877028]  bnxt_rx_pkt+0x5f7/0x19b0 [bnxt_en] [56251.885665]  ? cpu_max_write+0x1e/0x100 [56251.893510]  ? srso_alias_return_thunk+0x5/0xfbef5 [56251.902276]  __bnxt_poll_work+0x190/0x340 [bnxt_en] [56251.911058]  bnxt_poll+0xab/0x1b0 [bnxt_en] [56251.919041]  ? srso_alias_return_thunk+0x5/0xfbef5 [56251.927568]  ? srso_alias_return_thunk+0x5/0xfbef5 [56251.935958]  ? srso_alias_return_thunk+0x5/0xfbef5 [56251.944250]  __napi_poll+0x2b/0x160 [56251.951155]  bpf_trampoline_6442548651+0x79/0x123 [56251.959262]  __napi_poll+0x5/0x160 [56251.966037]  net_rx_action+0x3d2/0x880 [56251.973133]  ? srso_alias_return_thunk+0x5/0xfbef5 [56251.981265]  ? srso_alias_return_thunk+0x5/0xfbef5 [56251.989262]  ? __hrtimer_run_queues+0x162/0x2a0 [56251.996967]  ? srso_alias_return_thunk+0x5/0xfbef5 [56252.004875]  ? srso_alias_return_thunk+0x5/0xfbef5 [56252.012673]  ? bnxt_msix+0x62/0x70 [bnxt_en] [56252.019903]  handle_softirqs+0xcf/0x270 [56252.026650]  irq_exit_rcu+0x67/0x90 [56252.032933]  common_interrupt+0x85/0xa0 [56252.039498]  </IRQ> [56252.044246]  <TASK> [56252.048935]  asm_common_interrupt+0x26/0x40 [56252.055727] RIP: 0010:cpuidle_enter_state+0xb8/0x420 [56252.063305] Code: dc 01 00 00 e8 f9 79 3b ff e8 64 f7 ff ff 49 89 c5 0f 1f 44 00 00 31 ff e8 a5 32 3a ff 45 84 ff 0f 85 ae  01 00 00 fb 45 85 f6 <0f> 88 88 01 00 00 48 8b 04 24 49 63 ce 4c 89 ea 48 6b f1 68 48 29 [56252.088911] RSP: 0018:ffff93120c97fe98 EFLAGS: 00000202 [56252.096912] RAX: ffff9149afd80000 RBX: ffff9141d3a72800 RCX: 0000000000000000 [56252.106844] RDX: 00003329176c6b98 RSI: ffffffe36db3fdc7 RDI: 0000000000000000 [56252.116733] RBP: 0000000000000002 R08: 0000000000000002 R09: 000000000000004e [56252.126652] R10: ffff9149afdb30c4 R11: 071c71c71c71c71c R12: ffffffff985ff860 [56252.136637] R13: 00003329176c6b98 R14: 0000000000000002 R15: 0000000000000000 [56252.146667]  ? cpuidle_enter_state+0xab/0x420 [56252.153909]  cpuidle_enter+0x2d/0x40 [56252.160360]  do_idle+0x176/0x1c0 [56252.166456 ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38246","epss":0.00302,"percentile":0.22657,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15855000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-38246","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38246","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/02bf488d56df9db4f5147280b65d9011e1ab88d2","https://git.kernel.org/stable/c/16254aa985d14dee050564c4a3936f3dc096e1f7","https://git.kernel.org/stable/c/9caca6ac0e26cd20efd490d8b3b2ffb1c7c00f6f","https://git.kernel.org/stable/c/c6665b8f0f58082c480ed8627029f44d046ef2c8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt: properly flush XDP redirect lists\n\nWe encountered following crash when testing a XDP_REDIRECT feature\nin production:\n\n[56251.579676] list_add corruption. next->prev should be prev (ffff93120dd40f30), but was ffffb301ef3a6740. (next=ffff93120dd\n40f30).\n[56251.601413] ------------[ cut here ]------------\n[56251.611357] kernel BUG at lib/list_debug.c:29!\n[56251.621082] Oops: invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n[56251.632073] CPU: 111 UID: 0 PID: 0 Comm: swapper/111 Kdump: loaded Tainted: P           O       6.12.33-cloudflare-2025.6.\n3 #1\n[56251.653155] Tainted: [P]=PROPRIETARY_MODULE, [O]=OOT_MODULE\n[56251.663877] Hardware name: MiTAC GC68B-B8032-G11P6-GPU/S8032GM-HE-CFR, BIOS V7.020.B10-sig 01/22/2025\n[56251.682626] RIP: 0010:__list_add_valid_or_report+0x4b/0xa0\n[56251.693203] Code: 0e 48 c7 c7 68 e7 d9 97 e8 42 16 fe ff 0f 0b 48 8b 52 08 48 39 c2 74 14 48 89 f1 48 c7 c7 90 e7 d9 97 48\n 89 c6 e8 25 16 fe ff <0f> 0b 4c 8b 02 49 39 f0 74 14 48 89 d1 48 c7 c7 e8 e7 d9 97 4c 89\n[56251.725811] RSP: 0018:ffff93120dd40b80 EFLAGS: 00010246\n[56251.736094] RAX: 0000000000000075 RBX: ffffb301e6bba9d8 RCX: 0000000000000000\n[56251.748260] RDX: 0000000000000000 RSI: ffff9149afda0b80 RDI: ffff9149afda0b80\n[56251.760349] RBP: ffff9131e49c8000 R08: 0000000000000000 R09: ffff93120dd40a18\n[56251.772382] R10: ffff9159cf2ce1a8 R11: 0000000000000003 R12: ffff911a80850000\n[56251.784364] R13: ffff93120fbc7000 R14: 0000000000000010 R15: ffff9139e7510e40\n[56251.796278] FS:  0000000000000000(0000) GS:ffff9149afd80000(0000) knlGS:0000000000000000\n[56251.809133] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[56251.819561] CR2: 00007f5e85e6f300 CR3: 00000038b85e2006 CR4: 0000000000770ef0\n[56251.831365] PKRU: 55555554\n[56251.838653] Call Trace:\n[56251.845560]  <IRQ>\n[56251.851943]  cpu_map_enqueue.cold+0x5/0xa\n[56251.860243]  xdp_do_redirect+0x2d9/0x480\n[56251.868388]  bnxt_rx_xdp+0x1d8/0x4c0 [bnxt_en]\n[56251.877028]  bnxt_rx_pkt+0x5f7/0x19b0 [bnxt_en]\n[56251.885665]  ? cpu_max_write+0x1e/0x100\n[56251.893510]  ? srso_alias_return_thunk+0x5/0xfbef5\n[56251.902276]  __bnxt_poll_work+0x190/0x340 [bnxt_en]\n[56251.911058]  bnxt_poll+0xab/0x1b0 [bnxt_en]\n[56251.919041]  ? srso_alias_return_thunk+0x5/0xfbef5\n[56251.927568]  ? srso_alias_return_thunk+0x5/0xfbef5\n[56251.935958]  ? srso_alias_return_thunk+0x5/0xfbef5\n[56251.944250]  __napi_poll+0x2b/0x160\n[56251.951155]  bpf_trampoline_6442548651+0x79/0x123\n[56251.959262]  __napi_poll+0x5/0x160\n[56251.966037]  net_rx_action+0x3d2/0x880\n[56251.973133]  ? srso_alias_return_thunk+0x5/0xfbef5\n[56251.981265]  ? srso_alias_return_thunk+0x5/0xfbef5\n[56251.989262]  ? __hrtimer_run_queues+0x162/0x2a0\n[56251.996967]  ? srso_alias_return_thunk+0x5/0xfbef5\n[56252.004875]  ? srso_alias_return_thunk+0x5/0xfbef5\n[56252.012673]  ? bnxt_msix+0x62/0x70 [bnxt_en]\n[56252.019903]  handle_softirqs+0xcf/0x270\n[56252.026650]  irq_exit_rcu+0x67/0x90\n[56252.032933]  common_interrupt+0x85/0xa0\n[56252.039498]  </IRQ>\n[56252.044246]  <TASK>\n[56252.048935]  asm_common_interrupt+0x26/0x40\n[56252.055727] RIP: 0010:cpuidle_enter_state+0xb8/0x420\n[56252.063305] Code: dc 01 00 00 e8 f9 79 3b ff e8 64 f7 ff ff 49 89 c5 0f 1f 44 00 00 31 ff e8 a5 32 3a ff 45 84 ff 0f 85 ae\n 01 00 00 fb 45 85 f6 <0f> 88 88 01 00 00 48 8b 04 24 49 63 ce 4c 89 ea 48 6b f1 68 48 29\n[56252.088911] RSP: 0018:ffff93120c97fe98 EFLAGS: 00000202\n[56252.096912] RAX: ffff9149afd80000 RBX: ffff9141d3a72800 RCX: 0000000000000000\n[56252.106844] RDX: 00003329176c6b98 RSI: ffffffe36db3fdc7 RDI: 0000000000000000\n[56252.116733] RBP: 0000000000000002 R08: 0000000000000002 R09: 000000000000004e\n[56252.126652] R10: ffff9149afdb30c4 R11: 071c71c71c71c71c R12: ffffffff985ff860\n[56252.136637] R13: 00003329176c6b98 R14: 0000000000000002 R15: 0000000000000000\n[56252.146667]  ? cpuidle_enter_state+0xab/0x420\n[56252.153909]  cpuidle_enter+0x2d/0x40\n[56252.160360]  do_idle+0x176/0x1c0\n[56252.166456\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38246","epss":0.00302,"percentile":0.22657,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38246","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38248","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38248","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bridge: mcast: Fix use-after-free during router port configuration  The bridge maintains a global list of ports behind which a multicast router resides. The list is consulted during forwarding to ensure multicast packets are forwarded to these ports even if the ports are not member in the matching MDB entry.  When per-VLAN multicast snooping is enabled, the per-port multicast context is disabled on each port and the port is removed from the global router port list:   # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1  # ip link add name dummy1 up master br1 type dummy  # ip link set dev dummy1 type bridge_slave mcast_router 2  $ bridge -d mdb show | grep router  router ports on br1: dummy1  # ip link set dev br1 type bridge mcast_vlan_snooping 1  $ bridge -d mdb show | grep router  However, the port can be re-added to the global list even when per-VLAN multicast snooping is enabled:   # ip link set dev dummy1 type bridge_slave mcast_router 0  # ip link set dev dummy1 type bridge_slave mcast_router 2  $ bridge -d mdb show | grep router  router ports on br1: dummy1  Since commit 4b30ae9adb04 (\"net: bridge: mcast: re-implement br_multicast_{enable, disable}_port functions\"), when per-VLAN multicast snooping is enabled, multicast disablement on a port will disable the per-{port, VLAN} multicast contexts and not the per-port one. As a result, a port will remain in the global router port list even after it is deleted. This will lead to a use-after-free [1] when the list is traversed (when adding a new port to the list, for example):   # ip link del dev dummy1  # ip link add name dummy2 up master br1 type dummy  # ip link set dev dummy2 type bridge_slave mcast_router 2  Similarly, stale entries can also be found in the per-VLAN router port list. When per-VLAN multicast snooping is disabled, the per-{port, VLAN} contexts are disabled on each port and the port is removed from the per-VLAN router port list:   # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1 mcast_vlan_snooping 1  # ip link add name dummy1 up master br1 type dummy  # bridge vlan add vid 2 dev dummy1  # bridge vlan global set vid 2 dev br1 mcast_snooping 1  # bridge vlan set vid 2 dev dummy1 mcast_router 2  $ bridge vlan global show dev br1 vid 2 | grep router        router ports: dummy1  # ip link set dev br1 type bridge mcast_vlan_snooping 0  $ bridge vlan global show dev br1 vid 2 | grep router  However, the port can be re-added to the per-VLAN list even when per-VLAN multicast snooping is disabled:   # bridge vlan set vid 2 dev dummy1 mcast_router 0  # bridge vlan set vid 2 dev dummy1 mcast_router 2  $ bridge vlan global show dev br1 vid 2 | grep router        router ports: dummy1  When the VLAN is deleted from the port, the per-{port, VLAN} multicast context will not be disabled since multicast snooping is not enabled on the VLAN. As a result, the port will remain in the per-VLAN router port list even after it is no longer member in the VLAN. This will lead to a use-after-free [2] when the list is traversed (when adding a new port to the list, for example):   # ip link add name dummy2 up master br1 type dummy  # bridge vlan add vid 2 dev dummy2  # bridge vlan del vid 2 dev dummy1  # bridge vlan set vid 2 dev dummy2 mcast_router 2  Fix these issues by removing the port from the relevant (global or per-VLAN) router port list in br_multicast_port_ctx_deinit(). The function is invoked during port deletion with the per-port multicast context and during VLAN deletion with the per-{port, VLAN} multicast context.  Note that deleting the multicast router timer is not enough as it only takes care of the temporary multicast router states (1 or 3) and not the permanent one (2).  [1] BUG: KASAN: slab-out-of-bounds in br_multicast_add_router.part.0+0x3f1/0x560 Write of size 8 at addr ffff888004a67328 by task ip/384 [...] Call Trace:  <TASK>  dump_stack ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38248","epss":0.00264,"percentile":0.18206,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38248","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.20195999999999997},"relatedVulnerabilities":[{"id":"CVE-2025-38248","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38248","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4d3c2a1d4c7c33103f1ddfdbc5cfe1ea4f6d0dcd","https://git.kernel.org/stable/c/7544f3f5b0b58c396f374d060898b5939da31709","https://git.kernel.org/stable/c/bdced577da71b118b6ed4242ebd47f81bf54d406","https://git.kernel.org/stable/c/f05a4f9e959e0fc098046044c650acf897ea52d2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: mcast: Fix use-after-free during router port configuration\n\nThe bridge maintains a global list of ports behind which a multicast\nrouter resides. The list is consulted during forwarding to ensure\nmulticast packets are forwarded to these ports even if the ports are not\nmember in the matching MDB entry.\n\nWhen per-VLAN multicast snooping is enabled, the per-port multicast\ncontext is disabled on each port and the port is removed from the global\nrouter port list:\n\n # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1\n # ip link add name dummy1 up master br1 type dummy\n # ip link set dev dummy1 type bridge_slave mcast_router 2\n $ bridge -d mdb show | grep router\n router ports on br1: dummy1\n # ip link set dev br1 type bridge mcast_vlan_snooping 1\n $ bridge -d mdb show | grep router\n\nHowever, the port can be re-added to the global list even when per-VLAN\nmulticast snooping is enabled:\n\n # ip link set dev dummy1 type bridge_slave mcast_router 0\n # ip link set dev dummy1 type bridge_slave mcast_router 2\n $ bridge -d mdb show | grep router\n router ports on br1: dummy1\n\nSince commit 4b30ae9adb04 (\"net: bridge: mcast: re-implement\nbr_multicast_{enable, disable}_port functions\"), when per-VLAN multicast\nsnooping is enabled, multicast disablement on a port will disable the\nper-{port, VLAN} multicast contexts and not the per-port one. As a\nresult, a port will remain in the global router port list even after it\nis deleted. This will lead to a use-after-free [1] when the list is\ntraversed (when adding a new port to the list, for example):\n\n # ip link del dev dummy1\n # ip link add name dummy2 up master br1 type dummy\n # ip link set dev dummy2 type bridge_slave mcast_router 2\n\nSimilarly, stale entries can also be found in the per-VLAN router port\nlist. When per-VLAN multicast snooping is disabled, the per-{port, VLAN}\ncontexts are disabled on each port and the port is removed from the\nper-VLAN router port list:\n\n # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1 mcast_vlan_snooping 1\n # ip link add name dummy1 up master br1 type dummy\n # bridge vlan add vid 2 dev dummy1\n # bridge vlan global set vid 2 dev br1 mcast_snooping 1\n # bridge vlan set vid 2 dev dummy1 mcast_router 2\n $ bridge vlan global show dev br1 vid 2 | grep router\n       router ports: dummy1\n # ip link set dev br1 type bridge mcast_vlan_snooping 0\n $ bridge vlan global show dev br1 vid 2 | grep router\n\nHowever, the port can be re-added to the per-VLAN list even when\nper-VLAN multicast snooping is disabled:\n\n # bridge vlan set vid 2 dev dummy1 mcast_router 0\n # bridge vlan set vid 2 dev dummy1 mcast_router 2\n $ bridge vlan global show dev br1 vid 2 | grep router\n       router ports: dummy1\n\nWhen the VLAN is deleted from the port, the per-{port, VLAN} multicast\ncontext will not be disabled since multicast snooping is not enabled\non the VLAN. As a result, the port will remain in the per-VLAN router\nport list even after it is no longer member in the VLAN. This will lead\nto a use-after-free [2] when the list is traversed (when adding a new\nport to the list, for example):\n\n # ip link add name dummy2 up master br1 type dummy\n # bridge vlan add vid 2 dev dummy2\n # bridge vlan del vid 2 dev dummy1\n # bridge vlan set vid 2 dev dummy2 mcast_router 2\n\nFix these issues by removing the port from the relevant (global or\nper-VLAN) router port list in br_multicast_port_ctx_deinit(). The\nfunction is invoked during port deletion with the per-port multicast\ncontext and during VLAN deletion with the per-{port, VLAN} multicast\ncontext.\n\nNote that deleting the multicast router timer is not enough as it only\ntakes care of the temporary multicast router states (1 or 3) and not the\npermanent one (2).\n\n[1]\nBUG: KASAN: slab-out-of-bounds in br_multicast_add_router.part.0+0x3f1/0x560\nWrite of size 8 at addr ffff888004a67328 by task ip/384\n[...]\nCall Trace:\n <TASK>\n dump_stack\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38248","epss":0.00264,"percentile":0.18206,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38248","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38248","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38261","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38261","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  riscv: save the SR_SUM status over switches  When threads/tasks are switched we need to ensure the old execution's SR_SUM state is saved and the new thread has the old SR_SUM state restored.  The issue was seen under heavy load especially with the syz-stress tool running, with crashes as follows in schedule_tail:  Unable to handle kernel access to user memory without uaccess routines at virtual address 000000002749f0d0 Oops [#1] Modules linked in: CPU: 1 PID: 4875 Comm: syz-executor.0 Not tainted 5.12.0-rc2-syzkaller-00467-g0d7588ab9ef9 #0 Hardware name: riscv-virtio,qemu (DT) epc : schedule_tail+0x72/0xb2 kernel/sched/core.c:4264  ra : task_pid_vnr include/linux/sched.h:1421 [inline]  ra : schedule_tail+0x70/0xb2 kernel/sched/core.c:4264 epc : ffffffe00008c8b0 ra : ffffffe00008c8ae sp : ffffffe025d17ec0  gp : ffffffe005d25378 tp : ffffffe00f0d0000 t0 : 0000000000000000  t1 : 0000000000000001 t2 : 00000000000f4240 s0 : ffffffe025d17ee0  s1 : 000000002749f0d0 a0 : 000000000000002a a1 : 0000000000000003  a2 : 1ffffffc0cfac500 a3 : ffffffe0000c80cc a4 : 5ae9db91c19bbe00  a5 : 0000000000000000 a6 : 0000000000f00000 a7 : ffffffe000082eba  s2 : 0000000000040000 s3 : ffffffe00eef96c0 s4 : ffffffe022c77fe0  s5 : 0000000000004000 s6 : ffffffe067d74e00 s7 : ffffffe067d74850  s8 : ffffffe067d73e18 s9 : ffffffe067d74e00 s10: ffffffe00eef96e8  s11: 000000ae6cdf8368 t3 : 5ae9db91c19bbe00 t4 : ffffffc4043cafb2  t5 : ffffffc4043cafba t6 : 0000000000040000 status: 0000000000000120 badaddr: 000000002749f0d0 cause: 000000000000000f Call Trace: [<ffffffe00008c8b0>] schedule_tail+0x72/0xb2 kernel/sched/core.c:4264 [<ffffffe000005570>] ret_from_exception+0x0/0x14 Dumping ftrace buffer:    (ftrace buffer empty) ---[ end trace b5f8f9231dc87dda ]---  The issue comes from the put_user() in schedule_tail (kernel/sched/core.c) doing the following:  asmlinkage __visible void schedule_tail(struct task_struct *prev) { ...         if (current->set_child_tid)                 put_user(task_pid_vnr(current), current->set_child_tid); ... }  the put_user() macro causes the code sequence to come out as follows:  1:\t__enable_user_access() 2:\treg = task_pid_vnr(current); 3:\t*current->set_child_tid = reg; 4:\t__disable_user_access()  The problem is that we may have a sleeping function as argument which could clear SR_SUM causing the panic above. This was fixed by evaluating the argument of the put_user() macro outside the user-enabled section in commit 285a76bb2cf5 (\"riscv: evaluate put_user() arg before enabling user access\")\"  In order for riscv to take advantage of unsafe_get/put_XXX() macros and to avoid the same issue we had with put_user() and sleeping functions we must ensure code flow can go through switch_to() from within a region of code with SR_SUM enabled and come back with SR_SUM still enabled. This patch addresses the problem allowing future work to enable full use of unsafe_get/put_XXX() macros without needing to take a CSR bit flip cost on every access. Make switch_to() save and restore SR_SUM.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38261","epss":0.00142,"percentile":0.03792,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07455},"relatedVulnerabilities":[{"id":"CVE-2025-38261","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38261","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/69ea599a8dab93a620c92c255be4239a06290a77","https://git.kernel.org/stable/c/788aa64c01f1262310b4c1fb827a36df170d86ea"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: save the SR_SUM status over switches\n\nWhen threads/tasks are switched we need to ensure the old execution's\nSR_SUM state is saved and the new thread has the old SR_SUM state\nrestored.\n\nThe issue was seen under heavy load especially with the syz-stress tool\nrunning, with crashes as follows in schedule_tail:\n\nUnable to handle kernel access to user memory without uaccess routines\nat virtual address 000000002749f0d0\nOops [#1]\nModules linked in:\nCPU: 1 PID: 4875 Comm: syz-executor.0 Not tainted\n5.12.0-rc2-syzkaller-00467-g0d7588ab9ef9 #0\nHardware name: riscv-virtio,qemu (DT)\nepc : schedule_tail+0x72/0xb2 kernel/sched/core.c:4264\n ra : task_pid_vnr include/linux/sched.h:1421 [inline]\n ra : schedule_tail+0x70/0xb2 kernel/sched/core.c:4264\nepc : ffffffe00008c8b0 ra : ffffffe00008c8ae sp : ffffffe025d17ec0\n gp : ffffffe005d25378 tp : ffffffe00f0d0000 t0 : 0000000000000000\n t1 : 0000000000000001 t2 : 00000000000f4240 s0 : ffffffe025d17ee0\n s1 : 000000002749f0d0 a0 : 000000000000002a a1 : 0000000000000003\n a2 : 1ffffffc0cfac500 a3 : ffffffe0000c80cc a4 : 5ae9db91c19bbe00\n a5 : 0000000000000000 a6 : 0000000000f00000 a7 : ffffffe000082eba\n s2 : 0000000000040000 s3 : ffffffe00eef96c0 s4 : ffffffe022c77fe0\n s5 : 0000000000004000 s6 : ffffffe067d74e00 s7 : ffffffe067d74850\n s8 : ffffffe067d73e18 s9 : ffffffe067d74e00 s10: ffffffe00eef96e8\n s11: 000000ae6cdf8368 t3 : 5ae9db91c19bbe00 t4 : ffffffc4043cafb2\n t5 : ffffffc4043cafba t6 : 0000000000040000\nstatus: 0000000000000120 badaddr: 000000002749f0d0 cause:\n000000000000000f\nCall Trace:\n[<ffffffe00008c8b0>] schedule_tail+0x72/0xb2 kernel/sched/core.c:4264\n[<ffffffe000005570>] ret_from_exception+0x0/0x14\nDumping ftrace buffer:\n   (ftrace buffer empty)\n---[ end trace b5f8f9231dc87dda ]---\n\nThe issue comes from the put_user() in schedule_tail\n(kernel/sched/core.c) doing the following:\n\nasmlinkage __visible void schedule_tail(struct task_struct *prev)\n{\n...\n        if (current->set_child_tid)\n                put_user(task_pid_vnr(current), current->set_child_tid);\n...\n}\n\nthe put_user() macro causes the code sequence to come out as follows:\n\n1:\t__enable_user_access()\n2:\treg = task_pid_vnr(current);\n3:\t*current->set_child_tid = reg;\n4:\t__disable_user_access()\n\nThe problem is that we may have a sleeping function as argument which\ncould clear SR_SUM causing the panic above. This was fixed by\nevaluating the argument of the put_user() macro outside the user-enabled\nsection in commit 285a76bb2cf5 (\"riscv: evaluate put_user() arg before\nenabling user access\")\"\n\nIn order for riscv to take advantage of unsafe_get/put_XXX() macros and\nto avoid the same issue we had with put_user() and sleeping functions we\nmust ensure code flow can go through switch_to() from within a region of\ncode with SR_SUM enabled and come back with SR_SUM still enabled. This\npatch addresses the problem allowing future work to enable full use of\nunsafe_get/put_XXX() macros without needing to take a CSR bit flip cost\non every access. Make switch_to() save and restore SR_SUM.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38261","epss":0.00142,"percentile":0.03792,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38261","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38264","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38264","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvme-tcp: sanitize request list handling  Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of any list, otherwise a malicious R2T PDU might inject a loop in request list processing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38264","epss":0.00292,"percentile":0.21592,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15330000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-38264","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38264","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0bf04c874fcb1ae46a863034296e4b33d8fbd66c","https://git.kernel.org/stable/c/78a4adcd3fedb0728436e8094848ebf4c6bae006","https://git.kernel.org/stable/c/f054ea62598197714a6ca7b3b387a027308f8b13"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: sanitize request list handling\n\nValidate the request in nvme_tcp_handle_r2t() to ensure it's not part of\nany list, otherwise a malicious R2T PDU might inject a loop in request\nlist processing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38264","epss":0.00292,"percentile":0.21592,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38264","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38272","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38272","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: dsa: b53: do not enable EEE on bcm63xx  BCM63xx internal switches do not support EEE, but provide multiple RGMII ports where external PHYs may be connected. If one of these PHYs are EEE capable, we may try to enable EEE for the MACs, which then hangs the system on access of the (non-existent) EEE registers.  Fix this by checking if the switch actually supports EEE before attempting to configure it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38272","epss":0.00164,"percentile":0.05878,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0861},"relatedVulnerabilities":[{"id":"CVE-2025-38272","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38272","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1237c2d4a8db79dfd4369bff6930b0e385ed7d5c","https://git.kernel.org/stable/c/2dbccf1eb8c04b84ee3afdb1d6b787db02e7befc","https://git.kernel.org/stable/c/3fbe3f4c57fda09f32e13fa05f53a0cc6f500619"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: b53: do not enable EEE on bcm63xx\n\nBCM63xx internal switches do not support EEE, but provide multiple RGMII\nports where external PHYs may be connected. If one of these PHYs are EEE\ncapable, we may try to enable EEE for the MACs, which then hangs the\nsystem on access of the (non-existent) EEE registers.\n\nFix this by checking if the switch actually supports EEE before\nattempting to configure it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38272","epss":0.00164,"percentile":0.05878,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38272","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38283","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38283","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hisi_acc_vfio_pci: bugfix live migration function without VF device driver  If the VF device driver is not loaded in the Guest OS and we attempt to perform device data migration, the address of the migrated data will be NULL. The live migration recovery operation on the destination side will access a null address value, which will cause access errors.  Therefore, live migration of VMs without added VF device drivers does not require device data migration. In addition, when the queue address data obtained by the destination is empty, device queue recovery processing will not be performed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38283","epss":0.00174,"percentile":0.07056,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09135},"relatedVulnerabilities":[{"id":"CVE-2025-38283","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38283","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2777a40998deb36f96b6afc48bd397cf58a4edf0","https://git.kernel.org/stable/c/53e8e8e909f7c3a77857d09d2b733a42547f57ee","https://git.kernel.org/stable/c/59a834592dd200969fdf3c61be1cb0615c647e45","https://git.kernel.org/stable/c/b5ef128926cd34dffa2a66607b9c82b902581ef8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhisi_acc_vfio_pci: bugfix live migration function without VF device driver\n\nIf the VF device driver is not loaded in the Guest OS and we attempt to\nperform device data migration, the address of the migrated data will\nbe NULL.\nThe live migration recovery operation on the destination side will\naccess a null address value, which will cause access errors.\n\nTherefore, live migration of VMs without added VF device drivers\ndoes not require device data migration.\nIn addition, when the queue address data obtained by the destination\nis empty, device queue recovery processing will not be performed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38283","epss":0.00174,"percentile":0.07056,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38283","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38311","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38311","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iavf: get rid of the crit lock  Get rid of the crit lock. That frees us from the error prone logic of try_locks.  Thanks to netdev_lock() by Jakub it is now easy, and in most cases we were protected by it already - replace crit lock by netdev lock when it was not the case.  Lockdep reports that we should cancel the work under crit_lock [splat1], and that was the scheme we have mostly followed since [1] by Slawomir. But when that is done we still got into deadlocks [splat2]. So instead we should look at the bigger problem, namely \"weird locking/scheduling\" of the iavf. The first step to fix that is to remove the crit lock. I will followup with a -next series that simplifies scheduling/tasks.  Cancel the work without netdev lock (weird unlock+lock scheme), to fix the [splat2] (which would be totally ugly if we would kept the crit lock).  Extend protected part of iavf_watchdog_task() to include scheduling more work.  Note that the removed comment in iavf_reset_task() was misplaced, it belonged to inside of the removed if condition, so it's gone now.  [splat1] - w/o this patch - The deadlock during VF removal:      WARNING: possible circular locking dependency detected      sh/3825 is trying to acquire lock:       ((work_completion)(&(&adapter->watchdog_task)->work)){+.+.}-{0:0}, at: start_flush_work+0x1a1/0x470           but task is already holding lock:       (&adapter->crit_lock){+.+.}-{4:4}, at: iavf_remove+0xd1/0x690 [iavf]           which lock already depends on the new lock.  [splat2] - when cancelling work under crit lock, w/o this series, \t   see [2] for the band aid attempt     WARNING: possible circular locking dependency detected     sh/3550 is trying to acquire lock:     ((wq_completion)iavf){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90         but task is already holding lock:     (&dev->lock){+.+.}-{4:4}, at: iavf_remove+0xa6/0x6e0 [iavf]         which lock already depends on the new lock.  [1] fc2e6b3b132a (\"iavf: Rework mutexes for better synchronisation\") [2] https://github.com/pkitszel/linux/commit/52dddbfc2bb60294083f5711a158a","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38311","epss":0.00096,"percentile":0.00782,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38311","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0504},"relatedVulnerabilities":[{"id":"CVE-2025-38311","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38311","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/120f28a6f314fef7f282c99f196923fe44081cad","https://git.kernel.org/stable/c/620ab4d6215de0b25227f9fff1a8c7fb66837cb8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niavf: get rid of the crit lock\n\nGet rid of the crit lock.\nThat frees us from the error prone logic of try_locks.\n\nThanks to netdev_lock() by Jakub it is now easy, and in most cases we were\nprotected by it already - replace crit lock by netdev lock when it was not\nthe case.\n\nLockdep reports that we should cancel the work under crit_lock [splat1],\nand that was the scheme we have mostly followed since [1] by Slawomir.\nBut when that is done we still got into deadlocks [splat2]. So instead\nwe should look at the bigger problem, namely \"weird locking/scheduling\"\nof the iavf. The first step to fix that is to remove the crit lock.\nI will followup with a -next series that simplifies scheduling/tasks.\n\nCancel the work without netdev lock (weird unlock+lock scheme),\nto fix the [splat2] (which would be totally ugly if we would kept\nthe crit lock).\n\nExtend protected part of iavf_watchdog_task() to include scheduling\nmore work.\n\nNote that the removed comment in iavf_reset_task() was misplaced,\nit belonged to inside of the removed if condition, so it's gone now.\n\n[splat1] - w/o this patch - The deadlock during VF removal:\n     WARNING: possible circular locking dependency detected\n     sh/3825 is trying to acquire lock:\n      ((work_completion)(&(&adapter->watchdog_task)->work)){+.+.}-{0:0}, at: start_flush_work+0x1a1/0x470\n          but task is already holding lock:\n      (&adapter->crit_lock){+.+.}-{4:4}, at: iavf_remove+0xd1/0x690 [iavf]\n          which lock already depends on the new lock.\n\n[splat2] - when cancelling work under crit lock, w/o this series,\n\t   see [2] for the band aid attempt\n    WARNING: possible circular locking dependency detected\n    sh/3550 is trying to acquire lock:\n    ((wq_completion)iavf){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90\n        but task is already holding lock:\n    (&dev->lock){+.+.}-{4:4}, at: iavf_remove+0xa6/0x6e0 [iavf]\n        which lock already depends on the new lock.\n\n[1] fc2e6b3b132a (\"iavf: Rework mutexes for better synchronisation\")\n[2] https://github.com/pkitszel/linux/commit/52dddbfc2bb60294083f5711a158a","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38311","epss":0.00096,"percentile":0.00782,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38311","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38311","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38333","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38333","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to bail out in get_new_segment()  ------------[ cut here ]------------ WARNING: CPU: 3 PID: 579 at fs/f2fs/segment.c:2832 new_curseg+0x5e8/0x6dc pc : new_curseg+0x5e8/0x6dc Call trace:  new_curseg+0x5e8/0x6dc  f2fs_allocate_data_block+0xa54/0xe28  do_write_page+0x6c/0x194  f2fs_do_write_node_page+0x38/0x78  __write_node_page+0x248/0x6d4  f2fs_sync_node_pages+0x524/0x72c  f2fs_write_checkpoint+0x4bc/0x9b0  __checkpoint_and_complete_reqs+0x80/0x244  issue_checkpoint_thread+0x8c/0xec  kthread+0x114/0x1bc  ret_from_fork+0x10/0x20  get_new_segment() detects inconsistent status in between free_segmap and free_secmap, let's record such error into super block, and bail out get_new_segment() instead of continue using the segment.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38333","epss":0.00161,"percentile":0.05577,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084525},"relatedVulnerabilities":[{"id":"CVE-2025-38333","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38333","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/bb5eb8a5b222fa5092f60d5555867a05ebc3bdf2","https://git.kernel.org/stable/c/ca860f507a61c7c3d4dde47b830a5c0d555cf83c","https://git.kernel.org/stable/c/f0023d7a2a86999c8e1300e911d92f995a5310a8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to bail out in get_new_segment()\n\n------------[ cut here ]------------\nWARNING: CPU: 3 PID: 579 at fs/f2fs/segment.c:2832 new_curseg+0x5e8/0x6dc\npc : new_curseg+0x5e8/0x6dc\nCall trace:\n new_curseg+0x5e8/0x6dc\n f2fs_allocate_data_block+0xa54/0xe28\n do_write_page+0x6c/0x194\n f2fs_do_write_node_page+0x38/0x78\n __write_node_page+0x248/0x6d4\n f2fs_sync_node_pages+0x524/0x72c\n f2fs_write_checkpoint+0x4bc/0x9b0\n __checkpoint_and_complete_reqs+0x80/0x244\n issue_checkpoint_thread+0x8c/0xec\n kthread+0x114/0x1bc\n ret_from_fork+0x10/0x20\n\nget_new_segment() detects inconsistent status in between free_segmap\nand free_secmap, let's record such error into super block, and bail\nout get_new_segment() instead of continue using the segment.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38333","epss":0.00161,"percentile":0.05577,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38333","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38359","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38359","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/mm: Fix in_atomic() handling in do_secure_storage_access()  Kernel user spaces accesses to not exported pages in atomic context incorrectly try to resolve the page fault. With debug options enabled call traces like this can be seen:  BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1523 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 419074, name: qemu-system-s39 preempt_count: 1, expected: 0 RCU nest depth: 0, expected: 0 INFO: lockdep is turned off. Preemption disabled at: [<00000383ea47cfa2>] copy_page_from_iter_atomic+0xa2/0x8a0 CPU: 12 UID: 0 PID: 419074 Comm: qemu-system-s39 Tainted: G        W           6.16.0-20250531.rc0.git0.69b3a602feac.63.fc42.s390x+debug #1 PREEMPT Tainted: [W]=WARN Hardware name: IBM 3931 A01 703 (LPAR) Call Trace:  [<00000383e990d282>] dump_stack_lvl+0xa2/0xe8  [<00000383e99bf152>] __might_resched+0x292/0x2d0  [<00000383eaa7c374>] down_read+0x34/0x2d0  [<00000383e99432f8>] do_secure_storage_access+0x108/0x360  [<00000383eaa724b0>] __do_pgm_check+0x130/0x220  [<00000383eaa842e4>] pgm_check_handler+0x114/0x160  [<00000383ea47d028>] copy_page_from_iter_atomic+0x128/0x8a0 ([<00000383ea47d016>] copy_page_from_iter_atomic+0x116/0x8a0)  [<00000383e9c45eae>] generic_perform_write+0x16e/0x310  [<00000383e9eb87f4>] ext4_buffered_write_iter+0x84/0x160  [<00000383e9da0de4>] vfs_write+0x1c4/0x460  [<00000383e9da123c>] ksys_write+0x7c/0x100  [<00000383eaa7284e>] __do_syscall+0x15e/0x280  [<00000383eaa8417e>] system_call+0x6e/0x90 INFO: lockdep is turned off.  It is not allowed to take the mmap_lock while in atomic context. Therefore handle such a secure storage access fault as if the accessed page is not mapped: the uaccess function will return -EFAULT, and the caller has to deal with this. Usually this means that the access is retried in process context, which allows to resolve the page fault (or in this case export the page).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38359","epss":0.00107,"percentile":0.01248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38359","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2025-38359","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38359","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/11709abccf93b08adde95ef313c300b0d4bc28f1","https://git.kernel.org/stable/c/d2e317dfd2d1fe416c77315d17c5d57dbe374915"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Fix in_atomic() handling in do_secure_storage_access()\n\nKernel user spaces accesses to not exported pages in atomic context\nincorrectly try to resolve the page fault.\nWith debug options enabled call traces like this can be seen:\n\nBUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1523\nin_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 419074, name: qemu-system-s39\npreempt_count: 1, expected: 0\nRCU nest depth: 0, expected: 0\nINFO: lockdep is turned off.\nPreemption disabled at:\n[<00000383ea47cfa2>] copy_page_from_iter_atomic+0xa2/0x8a0\nCPU: 12 UID: 0 PID: 419074 Comm: qemu-system-s39\nTainted: G        W           6.16.0-20250531.rc0.git0.69b3a602feac.63.fc42.s390x+debug #1 PREEMPT\nTainted: [W]=WARN\nHardware name: IBM 3931 A01 703 (LPAR)\nCall Trace:\n [<00000383e990d282>] dump_stack_lvl+0xa2/0xe8\n [<00000383e99bf152>] __might_resched+0x292/0x2d0\n [<00000383eaa7c374>] down_read+0x34/0x2d0\n [<00000383e99432f8>] do_secure_storage_access+0x108/0x360\n [<00000383eaa724b0>] __do_pgm_check+0x130/0x220\n [<00000383eaa842e4>] pgm_check_handler+0x114/0x160\n [<00000383ea47d028>] copy_page_from_iter_atomic+0x128/0x8a0\n([<00000383ea47d016>] copy_page_from_iter_atomic+0x116/0x8a0)\n [<00000383e9c45eae>] generic_perform_write+0x16e/0x310\n [<00000383e9eb87f4>] ext4_buffered_write_iter+0x84/0x160\n [<00000383e9da0de4>] vfs_write+0x1c4/0x460\n [<00000383e9da123c>] ksys_write+0x7c/0x100\n [<00000383eaa7284e>] __do_syscall+0x15e/0x280\n [<00000383eaa8417e>] system_call+0x6e/0x90\nINFO: lockdep is turned off.\n\nIt is not allowed to take the mmap_lock while in atomic context. Therefore\nhandle such a secure storage access fault as if the accessed page is not\nmapped: the uaccess function will return -EFAULT, and the caller has to\ndeal with this. Usually this means that the access is retried in process\ncontext, which allows to resolve the page fault (or in this case export the\npage).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38359","epss":0.00107,"percentile":0.01248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38359","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38359","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38369","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38369","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: idxd: Check availability of workqueue allocated by idxd wq driver before using  Running IDXD workloads in a container with the /dev directory mounted can trigger a call trace or even a kernel panic when the parent process of the container is terminated.  This issue occurs because, under certain configurations, Docker does not properly propagate the mount replica back to the original mount point.  In this case, when the user driver detaches, the WQ is destroyed but it still calls destroy_workqueue() attempting to completes all pending work. It's necessary to check wq->wq and skip the drain if it no longer exists.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38369","epss":0.00158,"percentile":0.05272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38369","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12087},"relatedVulnerabilities":[{"id":"CVE-2025-38369","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38369","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/17502e7d7b7113346296f6758324798d536c31fd","https://git.kernel.org/stable/c/98fd66c8ba77e3a7137575f610271014bc0e701f","https://git.kernel.org/stable/c/aee7a7439f8c0884da87694a401930204a57128f","https://git.kernel.org/stable/c/e0051a3daa8b2cb318b03b2f9317c3e40855847a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Check availability of workqueue allocated by idxd wq driver before using\n\nRunning IDXD workloads in a container with the /dev directory mounted can\ntrigger a call trace or even a kernel panic when the parent process of the\ncontainer is terminated.\n\nThis issue occurs because, under certain configurations, Docker does not\nproperly propagate the mount replica back to the original mount point.\n\nIn this case, when the user driver detaches, the WQ is destroyed but it\nstill calls destroy_workqueue() attempting to completes all pending work.\nIt's necessary to check wq->wq and skip the drain if it no longer exists.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38369","epss":0.00158,"percentile":0.05272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38369","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38369","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38426","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38426","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Add basic validation for RAS header  If RAS header read from EEPROM is corrupted, it could result in trying to allocate huge memory for reading the records. Add some validation to header fields.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38426","epss":0.0016,"percentile":0.05544,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2025-38426","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38426","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0479268fdfaaff6e15d69e8a8387410f36d1b793","https://git.kernel.org/stable/c/5df0d6addb7e9b6f71f7162d1253762a5be9138e","https://git.kernel.org/stable/c/b52f52bc5ba9feb026c0be600f8ac584fd12d187","https://git.kernel.org/stable/c/e1903358b2152f5d64a83e796bb776aba0d3628d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Add basic validation for RAS header\n\nIf RAS header read from EEPROM is corrupted, it could result in trying\nto allocate huge memory for reading the records. Add some validation to\nheader fields.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38426","epss":0.0016,"percentile":0.05544,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38426","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38429","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38429","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bus: mhi: ep: Update read pointer only after buffer is written  Inside mhi_ep_ring_add_element, the read pointer (rd_offset) is updated before the buffer is written, potentially causing race conditions where the host sees an updated read pointer before the buffer is actually written. Updating rd_offset prematurely can lead to the host accessing an uninitialized or incomplete element, resulting in data corruption.  Invoke the buffer write before updating rd_offset to ensure the element is fully written before signaling its availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38429","epss":0.00389,"percentile":0.32294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38429","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.204225},"relatedVulnerabilities":[{"id":"CVE-2025-38429","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38429","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0007ef098dab48f1ba58364c40b4809f1e21b130","https://git.kernel.org/stable/c/44b9620e82bbec2b9a6ac77f63913636d84f96dc","https://git.kernel.org/stable/c/6f18d174b73d0ceeaa341f46c0986436b3aefc9a","https://git.kernel.org/stable/c/f704a80d9fa268e51a6cc5242714502c3c1fa605"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: ep: Update read pointer only after buffer is written\n\nInside mhi_ep_ring_add_element, the read pointer (rd_offset) is updated\nbefore the buffer is written, potentially causing race conditions where\nthe host sees an updated read pointer before the buffer is actually\nwritten. Updating rd_offset prematurely can lead to the host accessing\nan uninitialized or incomplete element, resulting in data corruption.\n\nInvoke the buffer write before updating rd_offset to ensure the element\nis fully written before signaling its availability.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38429","epss":0.00389,"percentile":0.32294,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38429","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38429","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38438","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak.  sof_pdata->tplg_filename can have address allocated by kstrdup() and can be overwritten. Memory leak was detected with kmemleak:  unreferenced object 0xffff88812391ff60 (size 16):   comm \"kworker/4:1\", pid 161, jiffies 4294802931   hex dump (first 16 bytes):     73 6f 66 2d 68 64 61 2d 67 65 6e 65 72 69 63 00  sof-hda-generic.   backtrace (crc 4bf1675c):     __kmalloc_node_track_caller_noprof+0x49c/0x6b0     kstrdup+0x46/0xc0     hda_machine_select.cold+0x1de/0x12cf [snd_sof_intel_hda_generic]     sof_init_environment+0x16f/0xb50 [snd_sof]     sof_probe_continue+0x45/0x7c0 [snd_sof]     sof_probe_work+0x1e/0x40 [snd_sof]     process_one_work+0x894/0x14b0     worker_thread+0x5e5/0xfb0     kthread+0x39d/0x760     ret_from_fork+0x31/0x70     ret_from_fork_asm+0x1a/0x30","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38438","epss":0.00157,"percentile":0.05211,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38438","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.082425},"relatedVulnerabilities":[{"id":"CVE-2025-38438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38438","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/58ecf51af12cb32b890858b52b2c34e80590c74a","https://git.kernel.org/stable/c/68397fda2caa90e99a7c0bcb2cf604e42ef3b91f","https://git.kernel.org/stable/c/6c038b58a2dc5a008c7e7a1297f5aaa4deaaaa7e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak.\n\nsof_pdata->tplg_filename can have address allocated by kstrdup()\nand can be overwritten. Memory leak was detected with kmemleak:\n\nunreferenced object 0xffff88812391ff60 (size 16):\n  comm \"kworker/4:1\", pid 161, jiffies 4294802931\n  hex dump (first 16 bytes):\n    73 6f 66 2d 68 64 61 2d 67 65 6e 65 72 69 63 00  sof-hda-generic.\n  backtrace (crc 4bf1675c):\n    __kmalloc_node_track_caller_noprof+0x49c/0x6b0\n    kstrdup+0x46/0xc0\n    hda_machine_select.cold+0x1de/0x12cf [snd_sof_intel_hda_generic]\n    sof_init_environment+0x16f/0xb50 [snd_sof]\n    sof_probe_continue+0x45/0x7c0 [snd_sof]\n    sof_probe_work+0x1e/0x40 [snd_sof]\n    process_one_work+0x894/0x14b0\n    worker_thread+0x5e5/0xfb0\n    kthread+0x39d/0x760\n    ret_from_fork+0x31/0x70\n    ret_from_fork_asm+0x1a/0x30","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38438","epss":0.00157,"percentile":0.05211,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38438","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38449","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38449","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/gem: Acquire references on GEM handles for framebuffers  A GEM handle can be released while the GEM buffer object is attached to a DRM framebuffer. This leads to the release of the dma-buf backing the buffer object, if any. [1] Trying to use the framebuffer in further mode-setting operations leads to a segmentation fault. Most easily happens with driver that use shadow planes for vmap-ing the dma-buf during a page flip. An example is shown below.  [  156.791968] ------------[ cut here ]------------ [  156.796830] WARNING: CPU: 2 PID: 2255 at drivers/dma-buf/dma-buf.c:1527 dma_buf_vmap+0x224/0x430 [...] [  156.942028] RIP: 0010:dma_buf_vmap+0x224/0x430 [  157.043420] Call Trace: [  157.045898]  <TASK> [  157.048030]  ? show_trace_log_lvl+0x1af/0x2c0 [  157.052436]  ? show_trace_log_lvl+0x1af/0x2c0 [  157.056836]  ? show_trace_log_lvl+0x1af/0x2c0 [  157.061253]  ? drm_gem_shmem_vmap+0x74/0x710 [  157.065567]  ? dma_buf_vmap+0x224/0x430 [  157.069446]  ? __warn.cold+0x58/0xe4 [  157.073061]  ? dma_buf_vmap+0x224/0x430 [  157.077111]  ? report_bug+0x1dd/0x390 [  157.080842]  ? handle_bug+0x5e/0xa0 [  157.084389]  ? exc_invalid_op+0x14/0x50 [  157.088291]  ? asm_exc_invalid_op+0x16/0x20 [  157.092548]  ? dma_buf_vmap+0x224/0x430 [  157.096663]  ? dma_resv_get_singleton+0x6d/0x230 [  157.101341]  ? __pfx_dma_buf_vmap+0x10/0x10 [  157.105588]  ? __pfx_dma_resv_get_singleton+0x10/0x10 [  157.110697]  drm_gem_shmem_vmap+0x74/0x710 [  157.114866]  drm_gem_vmap+0xa9/0x1b0 [  157.118763]  drm_gem_vmap_unlocked+0x46/0xa0 [  157.123086]  drm_gem_fb_vmap+0xab/0x300 [  157.126979]  drm_atomic_helper_prepare_planes.part.0+0x487/0xb10 [  157.133032]  ? lockdep_init_map_type+0x19d/0x880 [  157.137701]  drm_atomic_helper_commit+0x13d/0x2e0 [  157.142671]  ? drm_atomic_nonblocking_commit+0xa0/0x180 [  157.147988]  drm_mode_atomic_ioctl+0x766/0xe40 [...] [  157.346424] ---[ end trace 0000000000000000 ]---  Acquiring GEM handles for the framebuffer's GEM buffer objects prevents this from happening. The framebuffer's cleanup later puts the handle references.  Commit 1a148af06000 (\"drm/gem-shmem: Use dma_buf from GEM object instance\") triggers the segmentation fault easily by using the dma-buf field more widely. The underlying issue with reference counting has been present before.  v2: - acquire the handle instead of the BO (Christian) - fix comment style (Christian) - drop the Fixes tag (Christian) - rename err_ gotos - add missing Link tag","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38449","epss":0.00159,"percentile":0.05406,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38449","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08347500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38449","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38449","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/08480e285c6a82ce689008d643e4a51db0aaef8b","https://git.kernel.org/stable/c/3cf520d9860d4ec9f7f32068825da31f18dd3f25","https://git.kernel.org/stable/c/5307dce878d4126e1b375587318955bd019c3741","https://git.kernel.org/stable/c/cb4c956a15f8b7f870649454771fc3761f504b5f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gem: Acquire references on GEM handles for framebuffers\n\nA GEM handle can be released while the GEM buffer object is attached\nto a DRM framebuffer. This leads to the release of the dma-buf backing\nthe buffer object, if any. [1] Trying to use the framebuffer in further\nmode-setting operations leads to a segmentation fault. Most easily\nhappens with driver that use shadow planes for vmap-ing the dma-buf\nduring a page flip. An example is shown below.\n\n[  156.791968] ------------[ cut here ]------------\n[  156.796830] WARNING: CPU: 2 PID: 2255 at drivers/dma-buf/dma-buf.c:1527 dma_buf_vmap+0x224/0x430\n[...]\n[  156.942028] RIP: 0010:dma_buf_vmap+0x224/0x430\n[  157.043420] Call Trace:\n[  157.045898]  <TASK>\n[  157.048030]  ? show_trace_log_lvl+0x1af/0x2c0\n[  157.052436]  ? show_trace_log_lvl+0x1af/0x2c0\n[  157.056836]  ? show_trace_log_lvl+0x1af/0x2c0\n[  157.061253]  ? drm_gem_shmem_vmap+0x74/0x710\n[  157.065567]  ? dma_buf_vmap+0x224/0x430\n[  157.069446]  ? __warn.cold+0x58/0xe4\n[  157.073061]  ? dma_buf_vmap+0x224/0x430\n[  157.077111]  ? report_bug+0x1dd/0x390\n[  157.080842]  ? handle_bug+0x5e/0xa0\n[  157.084389]  ? exc_invalid_op+0x14/0x50\n[  157.088291]  ? asm_exc_invalid_op+0x16/0x20\n[  157.092548]  ? dma_buf_vmap+0x224/0x430\n[  157.096663]  ? dma_resv_get_singleton+0x6d/0x230\n[  157.101341]  ? __pfx_dma_buf_vmap+0x10/0x10\n[  157.105588]  ? __pfx_dma_resv_get_singleton+0x10/0x10\n[  157.110697]  drm_gem_shmem_vmap+0x74/0x710\n[  157.114866]  drm_gem_vmap+0xa9/0x1b0\n[  157.118763]  drm_gem_vmap_unlocked+0x46/0xa0\n[  157.123086]  drm_gem_fb_vmap+0xab/0x300\n[  157.126979]  drm_atomic_helper_prepare_planes.part.0+0x487/0xb10\n[  157.133032]  ? lockdep_init_map_type+0x19d/0x880\n[  157.137701]  drm_atomic_helper_commit+0x13d/0x2e0\n[  157.142671]  ? drm_atomic_nonblocking_commit+0xa0/0x180\n[  157.147988]  drm_mode_atomic_ioctl+0x766/0xe40\n[...]\n[  157.346424] ---[ end trace 0000000000000000 ]---\n\nAcquiring GEM handles for the framebuffer's GEM buffer objects prevents\nthis from happening. The framebuffer's cleanup later puts the handle\nreferences.\n\nCommit 1a148af06000 (\"drm/gem-shmem: Use dma_buf from GEM object\ninstance\") triggers the segmentation fault easily by using the dma-buf\nfield more widely. The underlying issue with reference counting has\nbeen present before.\n\nv2:\n- acquire the handle instead of the BO (Christian)\n- fix comment style (Christian)\n- drop the Fixes tag (Christian)\n- rename err_ gotos\n- add missing Link tag","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38449","epss":0.00159,"percentile":0.05406,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38449","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38449","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38507","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38507","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: nintendo: avoid bluetooth suspend/resume stalls  Ensure we don't stall or panic the kernel when using bluetooth-connected controllers. This was reported as an issue on android devices using kernel 6.6 due to the resume hook which had been added for usb joycons.  First, set a new state value to JOYCON_CTLR_STATE_SUSPENDED in a newly-added nintendo_hid_suspend. This makes sure we will not stall out the kernel waiting for input reports during led classdev suspend. The stalls could happen if connectivity is unreliable or lost to the controller prior to suspend.  Second, since we lose connectivity during suspend, do not try joycon_init() for bluetooth controllers in the nintendo_hid_resume path.  Tested via multiple suspend/resume flows when using the controller both in USB and bluetooth modes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38507","epss":0.00146,"percentile":0.04229,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07665000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38507","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38507","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4a0381080397e77792a5168069f174d3e56175ff","https://git.kernel.org/stable/c/72cb7eef06a5cde42b324dea85fa11fd5bb6a08a","https://git.kernel.org/stable/c/7b4a026313529a487821ef6ab494a61f12c1db08"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: avoid bluetooth suspend/resume stalls\n\nEnsure we don't stall or panic the kernel when using bluetooth-connected\ncontrollers. This was reported as an issue on android devices using\nkernel 6.6 due to the resume hook which had been added for usb joycons.\n\nFirst, set a new state value to JOYCON_CTLR_STATE_SUSPENDED in a\nnewly-added nintendo_hid_suspend. This makes sure we will not stall out\nthe kernel waiting for input reports during led classdev suspend. The\nstalls could happen if connectivity is unreliable or lost to the\ncontroller prior to suspend.\n\nSecond, since we lose connectivity during suspend, do not try\njoycon_init() for bluetooth controllers in the nintendo_hid_resume path.\n\nTested via multiple suspend/resume flows when using the controller both\nin USB and bluetooth modes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38507","epss":0.00146,"percentile":0.04229,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38507","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38524","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38524","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix recv-recv race of completed call  If a call receives an event (such as incoming data), the call gets placed on the socket's queue and a thread in recvmsg can be awakened to go and process it.  Once the thread has picked up the call off of the queue, further events will cause it to be requeued, and once the socket lock is dropped (recvmsg uses call->user_mutex to allow the socket to be used in parallel), a second thread can come in and its recvmsg can pop the call off the socket queue again.  In such a case, the first thread will be receiving stuff from the call and the second thread will be blocked on call->user_mutex.  The first thread can, at this point, process both the event that it picked call for and the event that the second thread picked the call for and may see the call terminate - in which case the call will be \"released\", decoupling the call from the user call ID assigned to it (RXRPC_USER_CALL_ID in the control message).  The first thread will return okay, but then the second thread will wake up holding the user_mutex and, if it sees that the call has been released by the first thread, it will BUG thusly:  \tkernel BUG at net/rxrpc/recvmsg.c:474!  Fix this by just dequeuing the call and ignoring it if it is seen to be already released.  We can't tell userspace about it anyway as the user call ID has become stale.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38524","epss":0.00263,"percentile":0.18156,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38524","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12755499999999997},"relatedVulnerabilities":[{"id":"CVE-2025-38524","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38524","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4aed0eeca58e26d752bb08b293b8dc75c6820b23","https://git.kernel.org/stable/c/6c75a97a32a5fa2060c3dd30207e63b6914b606d","https://git.kernel.org/stable/c/7692bde890061797f3dece0148d7859e85c55778","https://git.kernel.org/stable/c/839fe96c15209dc2255c064bb44b636efe04f032","https://git.kernel.org/stable/c/962fb1f651c2cf2083e0c3ef53ba69e3b96d3fbc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix recv-recv race of completed call\n\nIf a call receives an event (such as incoming data), the call gets placed\non the socket's queue and a thread in recvmsg can be awakened to go and\nprocess it.  Once the thread has picked up the call off of the queue,\nfurther events will cause it to be requeued, and once the socket lock is\ndropped (recvmsg uses call->user_mutex to allow the socket to be used in\nparallel), a second thread can come in and its recvmsg can pop the call off\nthe socket queue again.\n\nIn such a case, the first thread will be receiving stuff from the call and\nthe second thread will be blocked on call->user_mutex.  The first thread\ncan, at this point, process both the event that it picked call for and the\nevent that the second thread picked the call for and may see the call\nterminate - in which case the call will be \"released\", decoupling the call\nfrom the user call ID assigned to it (RXRPC_USER_CALL_ID in the control\nmessage).\n\nThe first thread will return okay, but then the second thread will wake up\nholding the user_mutex and, if it sees that the call has been released by\nthe first thread, it will BUG thusly:\n\n\tkernel BUG at net/rxrpc/recvmsg.c:474!\n\nFix this by just dequeuing the call and ignoring it if it is seen to be\nalready released.  We can't tell userspace about it anyway as the user call\nID has become stale.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38524","epss":0.00263,"percentile":0.18156,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38524","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38524","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38531","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38531","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iio: common: st_sensors: Fix use of uninitialize device structs  Throughout the various probe functions &indio_dev->dev is used before it is initialized. This caused a kernel panic in st_sensors_power_enable() when the call to devm_regulator_bulk_get_enable() fails and then calls dev_err_probe() with the uninitialized device.  This seems to only cause a panic with dev_err_probe(), dev_err(), dev_warn() and dev_info() don't seem to cause a panic, but are fixed as well.  The issue is reported and traced here: [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38531","epss":0.00159,"percentile":0.05385,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38531","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08347500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38531","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38531","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3297a9016a45144883ec990bd4bd5b1d79cafb46","https://git.kernel.org/stable/c/610615c9668037e3eca11132063b93b2d945af13","https://git.kernel.org/stable/c/9f92e93e257b33e73622640a9205f8642ec16ddd","https://git.kernel.org/stable/c/f9d4b618f1b9e6d760cc7c15052b92f7faf47201"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: common: st_sensors: Fix use of uninitialize device structs\n\nThroughout the various probe functions &indio_dev->dev is used before it\nis initialized. This caused a kernel panic in st_sensors_power_enable()\nwhen the call to devm_regulator_bulk_get_enable() fails and then calls\ndev_err_probe() with the uninitialized device.\n\nThis seems to only cause a panic with dev_err_probe(), dev_err(),\ndev_warn() and dev_info() don't seem to cause a panic, but are fixed\nas well.\n\nThe issue is reported and traced here: [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38531","epss":0.00159,"percentile":0.05385,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38531","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38531","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38544","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38544","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix bug due to prealloc collision  When userspace is using AF_RXRPC to provide a server, it has to preallocate incoming calls and assign to them call IDs that will be used to thread related recvmsg() and sendmsg() together.  The preallocated call IDs will automatically be attached to calls as they come in until the pool is empty.  To the kernel, the call IDs are just arbitrary numbers, but userspace can use the call ID to hold a pointer to prepared structs.  In any case, the user isn't permitted to create two calls with the same call ID (call IDs become available again when the call ends) and EBADSLT should result from sendmsg() if an attempt is made to preallocate a call with an in-use call ID.  However, the cleanup in the error handling will trigger both assertions in rxrpc_cleanup_call() because the call isn't marked complete and isn't marked as having been released.  Fix this by setting the call state in rxrpc_service_prealloc_one() and then marking it as being released before calling the cleanup function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38544","epss":0.00148,"percentile":0.04348,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38544","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0777},"relatedVulnerabilities":[{"id":"CVE-2025-38544","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38544","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/432c5363cd6fe5a928bbc94524d28b05515684dd","https://git.kernel.org/stable/c/5385ad53793de2ab11e396bdcdaa65bb04b4dad6","https://git.kernel.org/stable/c/69e4186773c6445b258fb45b6e1df18df831ec45","https://git.kernel.org/stable/c/d8ffb47a443919277cb093c3db1ec6c0a06880b1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix bug due to prealloc collision\n\nWhen userspace is using AF_RXRPC to provide a server, it has to preallocate\nincoming calls and assign to them call IDs that will be used to thread\nrelated recvmsg() and sendmsg() together.  The preallocated call IDs will\nautomatically be attached to calls as they come in until the pool is empty.\n\nTo the kernel, the call IDs are just arbitrary numbers, but userspace can\nuse the call ID to hold a pointer to prepared structs.  In any case, the\nuser isn't permitted to create two calls with the same call ID (call IDs\nbecome available again when the call ends) and EBADSLT should result from\nsendmsg() if an attempt is made to preallocate a call with an in-use call\nID.\n\nHowever, the cleanup in the error handling will trigger both assertions in\nrxrpc_cleanup_call() because the call isn't marked complete and isn't\nmarked as having been released.\n\nFix this by setting the call state in rxrpc_service_prealloc_one() and then\nmarking it as being released before calling the cleanup function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38544","epss":0.00148,"percentile":0.04348,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38544","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38544","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38582","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38582","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/hns: Fix double destruction of rsv_qp  rsv_qp may be double destroyed in error flow, first in free_mr_init(), and then in hns_roce_exit(). Fix it by moving the free_mr_init() call into hns_roce_v2_init().  list_del corruption, ffff589732eb9b50->next is LIST_POISON1 (dead000000000100) WARNING: CPU: 8 PID: 1047115 at lib/list_debug.c:53 __list_del_entry_valid+0x148/0x240 ... Call trace:  __list_del_entry_valid+0x148/0x240  hns_roce_qp_remove+0x4c/0x3f0 [hns_roce_hw_v2]  hns_roce_v2_destroy_qp_common+0x1dc/0x5f4 [hns_roce_hw_v2]  hns_roce_v2_destroy_qp+0x22c/0x46c [hns_roce_hw_v2]  free_mr_exit+0x6c/0x120 [hns_roce_hw_v2]  hns_roce_v2_exit+0x170/0x200 [hns_roce_hw_v2]  hns_roce_exit+0x118/0x350 [hns_roce_hw_v2]  __hns_roce_hw_v2_init_instance+0x1c8/0x304 [hns_roce_hw_v2]  hns_roce_hw_v2_reset_notify_init+0x170/0x21c [hns_roce_hw_v2]  hns_roce_hw_v2_reset_notify+0x6c/0x190 [hns_roce_hw_v2]  hclge_notify_roce_client+0x6c/0x160 [hclge]  hclge_reset_rebuild+0x150/0x5c0 [hclge]  hclge_reset+0x10c/0x140 [hclge]  hclge_reset_subtask+0x80/0x104 [hclge]  hclge_reset_service_task+0x168/0x3ac [hclge]  hclge_service_task+0x50/0x100 [hclge]  process_one_work+0x250/0x9a0  worker_thread+0x324/0x990  kthread+0x190/0x210  ret_from_fork+0x10/0x18","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38582","epss":0.00169,"percentile":0.06496,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38582","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.129285},"relatedVulnerabilities":[{"id":"CVE-2025-38582","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38582","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/10b083dbba22be19baa848432b6f25aa68ab2db5","https://git.kernel.org/stable/c/c6957b95ecc5b63c5a4bb4ecc28af326cf8f6dc8","https://git.kernel.org/stable/c/dab173bae3303f074f063750a8dead2550d8c782","https://git.kernel.org/stable/c/fc8b0f5b16bab2e032b4cfcd6218d5df3b80b2ea"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix double destruction of rsv_qp\n\nrsv_qp may be double destroyed in error flow, first in free_mr_init(),\nand then in hns_roce_exit(). Fix it by moving the free_mr_init() call\ninto hns_roce_v2_init().\n\nlist_del corruption, ffff589732eb9b50->next is LIST_POISON1 (dead000000000100)\nWARNING: CPU: 8 PID: 1047115 at lib/list_debug.c:53 __list_del_entry_valid+0x148/0x240\n...\nCall trace:\n __list_del_entry_valid+0x148/0x240\n hns_roce_qp_remove+0x4c/0x3f0 [hns_roce_hw_v2]\n hns_roce_v2_destroy_qp_common+0x1dc/0x5f4 [hns_roce_hw_v2]\n hns_roce_v2_destroy_qp+0x22c/0x46c [hns_roce_hw_v2]\n free_mr_exit+0x6c/0x120 [hns_roce_hw_v2]\n hns_roce_v2_exit+0x170/0x200 [hns_roce_hw_v2]\n hns_roce_exit+0x118/0x350 [hns_roce_hw_v2]\n __hns_roce_hw_v2_init_instance+0x1c8/0x304 [hns_roce_hw_v2]\n hns_roce_hw_v2_reset_notify_init+0x170/0x21c [hns_roce_hw_v2]\n hns_roce_hw_v2_reset_notify+0x6c/0x190 [hns_roce_hw_v2]\n hclge_notify_roce_client+0x6c/0x160 [hclge]\n hclge_reset_rebuild+0x150/0x5c0 [hclge]\n hclge_reset+0x10c/0x140 [hclge]\n hclge_reset_subtask+0x80/0x104 [hclge]\n hclge_reset_service_task+0x168/0x3ac [hclge]\n hclge_service_task+0x50/0x100 [hclge]\n process_one_work+0x250/0x9a0\n worker_thread+0x324/0x990\n kthread+0x190/0x210\n ret_from_fork+0x10/0x18","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38582","epss":0.00169,"percentile":0.06496,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38582","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38582","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38585","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38585","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()  When gmin_get_config_var() calls efi.get_variable() and the EFI variable is larger than the expected buffer size, two behaviors combine to create a stack buffer overflow:  1. gmin_get_config_var() does not return the proper error code when    efi.get_variable() fails. It returns the stale 'ret' value from    earlier operations instead of indicating the EFI failure.  2. When efi.get_variable() returns EFI_BUFFER_TOO_SMALL, it updates    *out_len to the required buffer size but writes no data to the output    buffer. However, due to bug #1, gmin_get_var_int() believes the call    succeeded.  The caller gmin_get_var_int() then performs: - Allocates val[CFG_VAR_NAME_MAX + 1] (65 bytes) on stack - Calls gmin_get_config_var(dev, is_gmin, var, val, &len) with len=64 - If EFI variable is >64 bytes, efi.get_variable() sets len=required_size - Due to bug #1, thinks call succeeded with len=required_size - Executes val[len] = 0, writing past end of 65-byte stack buffer  This creates a stack buffer overflow when EFI variables are larger than 64 bytes. Since EFI variables can be controlled by firmware or system configuration, this could potentially be exploited for code execution.  Fix the bug by returning proper error codes from gmin_get_config_var() based on EFI status instead of stale 'ret' value.  The gmin_get_var_int() function is called during device initialization for camera sensor configuration on Intel Bay Trail and Cherry Trail platforms using the atomisp camera stack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38585","epss":0.00211,"percentile":0.11351,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38585","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.161415},"relatedVulnerabilities":[{"id":"CVE-2025-38585","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38585","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1a7a2f59fb2eb0718a0cff1e5822500cefe50ed9","https://git.kernel.org/stable/c/3d672fe065aa00f4d66f42e3c9720f69a3ed43e7","https://git.kernel.org/stable/c/51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654","https://git.kernel.org/stable/c/e6d3453a002e89537e6136f6c774659b297a549b","https://git.kernel.org/stable/c/ee4cf798202d285dcbe85e4467a094c44f5ed8e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()\n\nWhen gmin_get_config_var() calls efi.get_variable() and the EFI variable\nis larger than the expected buffer size, two behaviors combine to create\na stack buffer overflow:\n\n1. gmin_get_config_var() does not return the proper error code when\n   efi.get_variable() fails. It returns the stale 'ret' value from\n   earlier operations instead of indicating the EFI failure.\n\n2. When efi.get_variable() returns EFI_BUFFER_TOO_SMALL, it updates\n   *out_len to the required buffer size but writes no data to the output\n   buffer. However, due to bug #1, gmin_get_var_int() believes the call\n   succeeded.\n\nThe caller gmin_get_var_int() then performs:\n- Allocates val[CFG_VAR_NAME_MAX + 1] (65 bytes) on stack\n- Calls gmin_get_config_var(dev, is_gmin, var, val, &len) with len=64\n- If EFI variable is >64 bytes, efi.get_variable() sets len=required_size\n- Due to bug #1, thinks call succeeded with len=required_size\n- Executes val[len] = 0, writing past end of 65-byte stack buffer\n\nThis creates a stack buffer overflow when EFI variables are larger than\n64 bytes. Since EFI variables can be controlled by firmware or system\nconfiguration, this could potentially be exploited for code execution.\n\nFix the bug by returning proper error codes from gmin_get_config_var()\nbased on EFI status instead of stale 'ret' value.\n\nThe gmin_get_var_int() function is called during device initialization\nfor camera sensor configuration on Intel Bay Trail and Cherry Trail\nplatforms using the atomisp camera stack.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38585","epss":0.00211,"percentile":0.11351,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38585","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38585","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38590","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38590","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Remove skb secpath if xfrm state is not found  Hardware returns a unique identifier for a decrypted packet's xfrm state, this state is looked up in an xarray. However, the state might have been freed by the time of this lookup.  Currently, if the state is not found, only a counter is incremented. The secpath (sp) extension on the skb is not removed, resulting in sp->len becoming 0.  Subsequently, functions like __xfrm_policy_check() attempt to access fields such as xfrm_input_state(skb)->xso.type (which dereferences sp->xvec[sp->len - 1]) without first validating sp->len. This leads to a crash when dereferencing an invalid state pointer.  This patch prevents the crash by explicitly removing the secpath extension from the skb if the xfrm state is not found after hardware decryption. This ensures downstream functions do not operate on a zero-length secpath.   BUG: unable to handle page fault for address: ffffffff000002c8  #PF: supervisor read access in kernel mode  #PF: error_code(0x0000) - not-present page  PGD 282e067 P4D 282e067 PUD 0  Oops: Oops: 0000 [#1] SMP  CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014  RIP: 0010:__xfrm_policy_check+0x61a/0xa30  Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0 03 48 98 49 01 c5 41 8b 45 00 83 e8 01 48 98 49 8b 44 c5 10 <0f> b6 80 c8 02 00 00 83 e0 0c 3c 04 0f 84 0c 02 00 00 31 ff 80 fa  RSP: 0018:ffff88885fb04918 EFLAGS: 00010297  RAX: ffffffff00000000 RBX: 0000000000000002 RCX: 0000000000000000  RDX: 0000000000000002 RSI: 0000000000000002 RDI: 0000000000000000  RBP: ffffffff8311af80 R08: 0000000000000020 R09: 00000000c2eda353  R10: ffff88812be2bbc8 R11: 000000001faab533 R12: ffff88885fb049c8  R13: ffff88812be2bbc8 R14: 0000000000000000 R15: ffff88811896ae00  FS:  0000000000000000(0000) GS:ffff8888dca82000(0000) knlGS:0000000000000000  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033  CR2: ffffffff000002c8 CR3: 0000000243050002 CR4: 0000000000372eb0  DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000  DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400  Call Trace:   <IRQ>   ? try_to_wake_up+0x108/0x4c0   ? udp4_lib_lookup2+0xbe/0x150   ? udp_lib_lport_inuse+0x100/0x100   ? __udp4_lib_lookup+0x2b0/0x410   __xfrm_policy_check2.constprop.0+0x11e/0x130   udp_queue_rcv_one_skb+0x1d/0x530   udp_unicast_rcv_skb+0x76/0x90   __udp4_lib_rcv+0xa64/0xe90   ip_protocol_deliver_rcu+0x20/0x130   ip_local_deliver_finish+0x75/0xa0   ip_local_deliver+0xc1/0xd0   ? ip_protocol_deliver_rcu+0x130/0x130   ip_sublist_rcv+0x1f9/0x240   ? ip_rcv_finish_core+0x430/0x430   ip_list_rcv+0xfc/0x130   __netif_receive_skb_list_core+0x181/0x1e0   netif_receive_skb_list_internal+0x200/0x360   ? mlx5e_build_rx_skb+0x1bc/0xda0 [mlx5_core]   gro_receive_skb+0xfd/0x210   mlx5e_handle_rx_cqe_mpwrq+0x141/0x280 [mlx5_core]   mlx5e_poll_rx_cq+0xcc/0x8e0 [mlx5_core]   ? mlx5e_handle_rx_dim+0x91/0xd0 [mlx5_core]   mlx5e_napi_poll+0x114/0xab0 [mlx5_core]   __napi_poll+0x25/0x170   net_rx_action+0x32d/0x3a0   ? mlx5_eq_comp_int+0x8d/0x280 [mlx5_core]   ? notifier_call_chain+0x33/0xa0   handle_softirqs+0xda/0x250   irq_exit_rcu+0x6d/0xc0   common_interrupt+0x81/0xa0   </IRQ>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38590","epss":0.00364,"percentile":0.29728,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38590","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19110000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-38590","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38590","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/137b12a4900eb6971b889839eab6036f72cbb217","https://git.kernel.org/stable/c/314f568b84b01f6eac1e4313ca47f9ade4349443","https://git.kernel.org/stable/c/3a5782431d84716b66302b07ff1b32fea1023bd5","https://git.kernel.org/stable/c/6d19c44b5c6dd72f9a357d0399604ec16a77de3c","https://git.kernel.org/stable/c/781a0bbf377443ef06f3248221f06cb555935530"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Remove skb secpath if xfrm state is not found\n\nHardware returns a unique identifier for a decrypted packet's xfrm\nstate, this state is looked up in an xarray. However, the state might\nhave been freed by the time of this lookup.\n\nCurrently, if the state is not found, only a counter is incremented.\nThe secpath (sp) extension on the skb is not removed, resulting in\nsp->len becoming 0.\n\nSubsequently, functions like __xfrm_policy_check() attempt to access\nfields such as xfrm_input_state(skb)->xso.type (which dereferences\nsp->xvec[sp->len - 1]) without first validating sp->len. This leads to\na crash when dereferencing an invalid state pointer.\n\nThis patch prevents the crash by explicitly removing the secpath\nextension from the skb if the xfrm state is not found after hardware\ndecryption. This ensures downstream functions do not operate on a\nzero-length secpath.\n\n BUG: unable to handle page fault for address: ffffffff000002c8\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 282e067 P4D 282e067 PUD 0\n Oops: Oops: 0000 [#1] SMP\n CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n RIP: 0010:__xfrm_policy_check+0x61a/0xa30\n Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0 03 48 98 49 01 c5 41 8b 45 00 83 e8 01 48 98 49 8b 44 c5 10 <0f> b6 80 c8 02 00 00 83 e0 0c 3c 04 0f 84 0c 02 00 00 31 ff 80 fa\n RSP: 0018:ffff88885fb04918 EFLAGS: 00010297\n RAX: ffffffff00000000 RBX: 0000000000000002 RCX: 0000000000000000\n RDX: 0000000000000002 RSI: 0000000000000002 RDI: 0000000000000000\n RBP: ffffffff8311af80 R08: 0000000000000020 R09: 00000000c2eda353\n R10: ffff88812be2bbc8 R11: 000000001faab533 R12: ffff88885fb049c8\n R13: ffff88812be2bbc8 R14: 0000000000000000 R15: ffff88811896ae00\n FS:  0000000000000000(0000) GS:ffff8888dca82000(0000) knlGS:0000000000000000\n CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: ffffffff000002c8 CR3: 0000000243050002 CR4: 0000000000372eb0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n  <IRQ>\n  ? try_to_wake_up+0x108/0x4c0\n  ? udp4_lib_lookup2+0xbe/0x150\n  ? udp_lib_lport_inuse+0x100/0x100\n  ? __udp4_lib_lookup+0x2b0/0x410\n  __xfrm_policy_check2.constprop.0+0x11e/0x130\n  udp_queue_rcv_one_skb+0x1d/0x530\n  udp_unicast_rcv_skb+0x76/0x90\n  __udp4_lib_rcv+0xa64/0xe90\n  ip_protocol_deliver_rcu+0x20/0x130\n  ip_local_deliver_finish+0x75/0xa0\n  ip_local_deliver+0xc1/0xd0\n  ? ip_protocol_deliver_rcu+0x130/0x130\n  ip_sublist_rcv+0x1f9/0x240\n  ? ip_rcv_finish_core+0x430/0x430\n  ip_list_rcv+0xfc/0x130\n  __netif_receive_skb_list_core+0x181/0x1e0\n  netif_receive_skb_list_internal+0x200/0x360\n  ? mlx5e_build_rx_skb+0x1bc/0xda0 [mlx5_core]\n  gro_receive_skb+0xfd/0x210\n  mlx5e_handle_rx_cqe_mpwrq+0x141/0x280 [mlx5_core]\n  mlx5e_poll_rx_cq+0xcc/0x8e0 [mlx5_core]\n  ? mlx5e_handle_rx_dim+0x91/0xd0 [mlx5_core]\n  mlx5e_napi_poll+0x114/0xab0 [mlx5_core]\n  __napi_poll+0x25/0x170\n  net_rx_action+0x32d/0x3a0\n  ? mlx5_eq_comp_int+0x8d/0x280 [mlx5_core]\n  ? notifier_call_chain+0x33/0xa0\n  handle_softirqs+0xda/0x250\n  irq_exit_rcu+0x6d/0xc0\n  common_interrupt+0x81/0xa0\n  </IRQ>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38590","epss":0.00364,"percentile":0.29728,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38590","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38590","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38595","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xen: fix UAF in dmabuf_exp_from_pages()  [dma_buf_fd() fixes; no preferences regarding the tree it goes through - up to xen folks]  As soon as we'd inserted a file reference into descriptor table, another thread could close it.  That's fine for the case when all we are doing is returning that descriptor to userland (it's a race, but it's a userland race and there's nothing the kernel can do about it).  However, if we follow fd_install() with any kind of access to objects that would be destroyed on close (be it the struct file itself or anything destroyed by its ->release()), we have a UAF.  dma_buf_fd() is a combination of reserving a descriptor and fd_install(). gntdev dmabuf_exp_from_pages() calls it and then proceeds to access the objects destroyed on close - starting with gntdev_dmabuf itself.  Fix that by doing reserving descriptor before anything else and do fd_install() only when everything had been set up.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38595","epss":0.00168,"percentile":0.06302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38595","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12852},"relatedVulnerabilities":[{"id":"CVE-2025-38595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38595","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3edfd2353f301bfffd5ee41066e37320a59ccc2d","https://git.kernel.org/stable/c/532c8b51b3a8676cbf533a291f8156774f30ea87","https://git.kernel.org/stable/c/d59d49af4aeed9a81e673e37c26c6a3bacf1a181","https://git.kernel.org/stable/c/e5907885260401bba300d4d18d79875c05b82651"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxen: fix UAF in dmabuf_exp_from_pages()\n\n[dma_buf_fd() fixes; no preferences regarding the tree it goes through -\nup to xen folks]\n\nAs soon as we'd inserted a file reference into descriptor table, another\nthread could close it.  That's fine for the case when all we are doing is\nreturning that descriptor to userland (it's a race, but it's a userland\nrace and there's nothing the kernel can do about it).  However, if we\nfollow fd_install() with any kind of access to objects that would be\ndestroyed on close (be it the struct file itself or anything destroyed\nby its ->release()), we have a UAF.\n\ndma_buf_fd() is a combination of reserving a descriptor and fd_install().\ngntdev dmabuf_exp_from_pages() calls it and then proceeds to access the\nobjects destroyed on close - starting with gntdev_dmabuf itself.\n\nFix that by doing reserving descriptor before anything else and do\nfd_install() only when everything had been set up.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38595","epss":0.00168,"percentile":0.06302,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38595","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38595","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38597","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38597","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port  Each window of a vop2 is usable by a specific set of video ports, so while binding the vop2, we look through the list of available windows trying to find one designated as primary-plane and usable by that specific port.  The code later wants to use drm_crtc_init_with_planes with that found primary plane, but nothing has checked so far if a primary plane was actually found.  For whatever reason, the rk3576 vp2 does not have a usable primary window (if vp0 is also in use) which brought the issue to light and ended in a null-pointer dereference further down.  As we expect a primary-plane to exist for a video-port, add a check at the end of the window-iteration and fail probing if none was found.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38597","epss":0.00157,"percentile":0.05212,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38597","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.082425},"relatedVulnerabilities":[{"id":"CVE-2025-38597","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38597","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/38682edbbad272b5f8c7bf55128b42cd10626f73","https://git.kernel.org/stable/c/e1eef239399927b368f70a716044fb10085627c8","https://git.kernel.org/stable/c/f9f68bf1d0efeadb6c427c9dbb30f307a7def19b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port\n\nEach window of a vop2 is usable by a specific set of video ports, so while\nbinding the vop2, we look through the list of available windows trying to\nfind one designated as primary-plane and usable by that specific port.\n\nThe code later wants to use drm_crtc_init_with_planes with that found\nprimary plane, but nothing has checked so far if a primary plane was\nactually found.\n\nFor whatever reason, the rk3576 vp2 does not have a usable primary window\n(if vp0 is also in use) which brought the issue to light and ended in a\nnull-pointer dereference further down.\n\nAs we expect a primary-plane to exist for a video-port, add a check at\nthe end of the window-iteration and fail probing if none was found.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38597","epss":0.00157,"percentile":0.05212,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38597","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38597","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38615","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: cancle set bad inode after removing name fails  The reproducer uses a file0 on a ntfs3 file system with a corrupted i_link. When renaming, the file0's inode is marked as a bad inode because the file name cannot be deleted.  The underlying bug is that make_bad_inode() is called on a live inode. In some cases it's \"icache lookup finds a normal inode, d_splice_alias() is called to attach it to dentry, while another thread decides to call make_bad_inode() on it - that would evict it from icache, but we'd already found it there earlier\". In some it's outright \"we have an inode attached to dentry - that's how we got it in the first place; let's call make_bad_inode() on it just for shits and giggles\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38615","epss":0.00168,"percentile":0.06301,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08820000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38615","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/358d4f821c03add421a4c49290538a705852ccf1","https://git.kernel.org/stable/c/3ed2cc6a6e93fbeb8c0cafce1e7fb1f64a331dcc","https://git.kernel.org/stable/c/a285395020780adac1ffbc844069c3d700bf007a","https://git.kernel.org/stable/c/b35a50d639ca5259466ef5fea85529bb4fb17d5b","https://git.kernel.org/stable/c/d99208b91933fd2a58ed9ed321af07dacd06ddc3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: cancle set bad inode after removing name fails\n\nThe reproducer uses a file0 on a ntfs3 file system with a corrupted i_link.\nWhen renaming, the file0's inode is marked as a bad inode because the file\nname cannot be deleted.\n\nThe underlying bug is that make_bad_inode() is called on a live inode.\nIn some cases it's \"icache lookup finds a normal inode, d_splice_alias()\nis called to attach it to dentry, while another thread decides to call\nmake_bad_inode() on it - that would evict it from icache, but we'd already\nfound it there earlier\".\nIn some it's outright \"we have an inode attached to dentry - that's how we\ngot it in the first place; let's call make_bad_inode() on it just for shits\nand giggles\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38615","epss":0.00168,"percentile":0.06301,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38615","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38616","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tls: handle data disappearing from under the TLS ULP  TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the TCP socket entered before the TLS ULP was installed, or uses some non-standard read API (eg. zerocopy ones). Replace the WARN_ON() and a buggy early exit (which leaves anchor pointing to a freed skb) with real error handling. Wipe the parsing state and tell the reader to retry.  We already reload the anchor every time we (re)acquire the socket lock, so the only condition we need to avoid is an out of bounds read (not having enough bytes in the socket for previously parsed record len).  If some data was read from under TLS but there's enough in the queue we'll reload and decrypt what is most likely not a valid TLS record. Leading to some undefined behavior from TLS perspective (corrupting a stream? missing an alert? missing an attack?) but no kernel crash should take place.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38616","epss":0.00197,"percentile":0.09612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38616","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.14381},"relatedVulnerabilities":[{"id":"CVE-2025-38616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38616","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2fb97ed9e2672b4f6e24ce206ac1a875ce4bcb38","https://git.kernel.org/stable/c/6db015fc4b5d5f63a64a193f65d98da3a7fc811d","https://git.kernel.org/stable/c/db3658a12d5ec4db7185ae7476151a50521b7207","https://git.kernel.org/stable/c/eb0336f213fe88bbdb7d2b19c9c9ec19245a3155","https://git.kernel.org/stable/c/ef50eaab631f9bf519ddbdfa42ccb0528adc1fc8","https://git.kernel.org/stable/c/f1fe99919f629f980d0b8a7ff16950bffe06a859"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: handle data disappearing from under the TLS ULP\n\nTLS expects that it owns the receive queue of the TCP socket.\nThis cannot be guaranteed in case the reader of the TCP socket\nentered before the TLS ULP was installed, or uses some non-standard\nread API (eg. zerocopy ones). Replace the WARN_ON() and a buggy\nearly exit (which leaves anchor pointing to a freed skb) with real\nerror handling. Wipe the parsing state and tell the reader to retry.\n\nWe already reload the anchor every time we (re)acquire the socket lock,\nso the only condition we need to avoid is an out of bounds read\n(not having enough bytes in the socket for previously parsed record len).\n\nIf some data was read from under TLS but there's enough in the queue\nwe'll reload and decrypt what is most likely not a valid TLS record.\nLeading to some undefined behavior from TLS perspective (corrupting\na stream? missing an alert? missing an attack?) but no kernel crash\nshould take place.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38616","epss":0.00197,"percentile":0.09612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38616","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38616","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38636","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38636","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rv: Use strings in da monitors tracepoints  Using DA monitors tracepoints with KASAN enabled triggers the following warning:   BUG: KASAN: global-out-of-bounds in do_trace_event_raw_event_event_da_monitor+0xd6/0x1a0  Read of size 32 at addr ffffffffaada8980 by task ...  Call Trace:   <TASK>  [...]   do_trace_event_raw_event_event_da_monitor+0xd6/0x1a0   ? __pfx_do_trace_event_raw_event_event_da_monitor+0x10/0x10   ? trace_event_sncid+0x83/0x200   trace_event_sncid+0x163/0x200  [...]  The buggy address belongs to the variable:   automaton_snep+0x4e0/0x5e0  This is caused by the tracepoints reading 32 bytes __array instead of __string from the automata definition. Such strings are literals and reading 32 bytes ends up in out of bound memory accesses (e.g. the next automaton's data in this case). The error is harmless as, while printing the string, we stop at the null terminator, but it should still be fixed.  Use the __string facilities while defining the tracepoints to avoid reading out of bound memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38636","epss":0.00149,"percentile":0.04435,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38636","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10877},"relatedVulnerabilities":[{"id":"CVE-2025-38636","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38636","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0ebc70d973ce7a81826b5c4f55f743e07f5864d9","https://git.kernel.org/stable/c/7f904ff6e58d398c4336f3c19c42b338324451f7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrv: Use strings in da monitors tracepoints\n\nUsing DA monitors tracepoints with KASAN enabled triggers the following\nwarning:\n\n BUG: KASAN: global-out-of-bounds in do_trace_event_raw_event_event_da_monitor+0xd6/0x1a0\n Read of size 32 at addr ffffffffaada8980 by task ...\n Call Trace:\n  <TASK>\n [...]\n  do_trace_event_raw_event_event_da_monitor+0xd6/0x1a0\n  ? __pfx_do_trace_event_raw_event_event_da_monitor+0x10/0x10\n  ? trace_event_sncid+0x83/0x200\n  trace_event_sncid+0x163/0x200\n [...]\n The buggy address belongs to the variable:\n  automaton_snep+0x4e0/0x5e0\n\nThis is caused by the tracepoints reading 32 bytes __array instead of\n__string from the automata definition. Such strings are literals and\nreading 32 bytes ends up in out of bound memory accesses (e.g. the next\nautomaton's data in this case).\nThe error is harmless as, while printing the string, we stop at the null\nterminator, but it should still be fixed.\n\nUse the __string facilities while defining the tracepoints to avoid\nreading out of bound memory.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38636","epss":0.00149,"percentile":0.04435,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38636","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38636","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38692","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38692","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  exfat: add cluster chain loop check for dir  An infinite loop may occur if the following conditions occur due to file system corruption.  (1) Condition for exfat_count_dir_entries() to loop infinitely.     - The cluster chain includes a loop.     - There is no UNUSED entry in the cluster chain.  (2) Condition for exfat_create_upcase_table() to loop infinitely.     - The cluster chain of the root directory includes a loop.     - There are no UNUSED entry and up-case table entry in the cluster       chain of the root directory.  (3) Condition for exfat_load_bitmap() to loop infinitely.     - The cluster chain of the root directory includes a loop.     - There are no UNUSED entry and bitmap entry in the cluster chain       of the root directory.  (4) Condition for exfat_find_dir_entry() to loop infinitely.     - The cluster chain includes a loop.     - The unused directory entries were exhausted by some operation.  (5) Condition for exfat_check_dir_empty() to loop infinitely.     - The cluster chain includes a loop.     - The unused directory entries were exhausted by some operation.     - All files and sub-directories under the directory are deleted.  This commit adds checks to break the above infinite loop.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38692","epss":0.00155,"percentile":0.04997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38692","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.081375},"relatedVulnerabilities":[{"id":"CVE-2025-38692","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38692","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4c3cda20c4cf1871e27868d08fda06b79bc7d568","https://git.kernel.org/stable/c/868f23286c1a13162330fa6c614fe350f78e3f82","https://git.kernel.org/stable/c/99f9a97dce39ad413c39b92c90393bbd6778f3fd","https://git.kernel.org/stable/c/aa8fe7b7b73d4c9a41bb96cb3fb3092f794ecb33","https://git.kernel.org/stable/c/e2066ca3ef49a30920d8536fa366b2a183a808ee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: add cluster chain loop check for dir\n\nAn infinite loop may occur if the following conditions occur due to\nfile system corruption.\n\n(1) Condition for exfat_count_dir_entries() to loop infinitely.\n    - The cluster chain includes a loop.\n    - There is no UNUSED entry in the cluster chain.\n\n(2) Condition for exfat_create_upcase_table() to loop infinitely.\n    - The cluster chain of the root directory includes a loop.\n    - There are no UNUSED entry and up-case table entry in the cluster\n      chain of the root directory.\n\n(3) Condition for exfat_load_bitmap() to loop infinitely.\n    - The cluster chain of the root directory includes a loop.\n    - There are no UNUSED entry and bitmap entry in the cluster chain\n      of the root directory.\n\n(4) Condition for exfat_find_dir_entry() to loop infinitely.\n    - The cluster chain includes a loop.\n    - The unused directory entries were exhausted by some operation.\n\n(5) Condition for exfat_check_dir_empty() to loop infinitely.\n    - The cluster chain includes a loop.\n    - The unused directory entries were exhausted by some operation.\n    - All files and sub-directories under the directory are deleted.\n\nThis commit adds checks to break the above infinite loop.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38692","epss":0.00155,"percentile":0.04997,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38692","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38692","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38705","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38705","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/pm: fix null pointer access  Writing a string without delimiters (' ', '\\n', '\\0') to the under gpu_od/fan_ctrl sysfs or pp_power_profile_mode for the CUSTOM profile will result in a null pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38705","epss":0.00155,"percentile":0.05,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38705","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.081375},"relatedVulnerabilities":[{"id":"CVE-2025-38705","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38705","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5d8cc029e5595760c7d18c64632e8e40a86a9b2e","https://git.kernel.org/stable/c/a83ffafd02a7af59848755c109d544e3894af737","https://git.kernel.org/stable/c/cef79c18538e9ce2ca6e5b3fa95c38ec41dcd07a","https://git.kernel.org/stable/c/d524d40e3a6152a3ea1125af729f8cd8ca65efde"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: fix null pointer access\n\nWriting a string without delimiters (' ', '\\n', '\\0') to the under\ngpu_od/fan_ctrl sysfs or pp_power_profile_mode for the CUSTOM profile\nwill result in a null pointer dereference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38705","epss":0.00155,"percentile":0.05,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38705","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38705","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38709","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  loop: Avoid updating block size under exclusive owner  Syzbot came up with a reproducer where a loop device block size is changed underneath a mounted filesystem. This causes a mismatch between the block device block size and the block size stored in the superblock causing confusion in various places such as fs/buffer.c. The particular issue triggered by syzbot was a warning in __getblk_slow() due to requested buffer size not matching block device block size.  Fix the problem by getting exclusive hold of the loop device to change its block size. This fails if somebody (such as filesystem) has already an exclusive ownership of the block device and thus prevents modifying the loop device under some exclusive owner which doesn't expect it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38709","epss":0.00146,"percentile":0.04177,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07665000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-38709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38709","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/139a000d20f2f38ce34296feddd641d730fe1c08","https://git.kernel.org/stable/c/457d2c5e112fd08dc1039b1ae39a83ec1782360d","https://git.kernel.org/stable/c/5d67b30aefeb7a949040bbb1b4e3b84c5d29a624","https://git.kernel.org/stable/c/7e49538288e523427beedd26993d446afef1a6fb","https://git.kernel.org/stable/c/b928438cc87c0bf7ae078e4b7b6e14261e84c5c5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nloop: Avoid updating block size under exclusive owner\n\nSyzbot came up with a reproducer where a loop device block size is\nchanged underneath a mounted filesystem. This causes a mismatch between\nthe block device block size and the block size stored in the superblock\ncausing confusion in various places such as fs/buffer.c. The particular\nissue triggered by syzbot was a warning in __getblk_slow() due to\nrequested buffer size not matching block device block size.\n\nFix the problem by getting exclusive hold of the loop device to change\nits block size. This fails if somebody (such as filesystem) has already\nan exclusive ownership of the block device and thus prevents modifying\nthe loop device under some exclusive owner which doesn't expect it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38709","epss":0.00146,"percentile":0.04177,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38709","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38716","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hfs: fix general protection fault in hfs_find_init()  The hfs_find_init() method can trigger the crash if tree pointer is NULL:  [   45.746290][ T9787] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000008: 0000 [#1] SMP KAI [   45.747287][ T9787] KASAN: null-ptr-deref in range [0x0000000000000040-0x0000000000000047] [   45.748716][ T9787] CPU: 2 UID: 0 PID: 9787 Comm: repro Not tainted 6.16.0-rc3 #10 PREEMPT(full) [   45.750250][ T9787] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [   45.751983][ T9787] RIP: 0010:hfs_find_init+0x86/0x230 [   45.752834][ T9787] Code: c1 ea 03 80 3c 02 00 0f 85 9a 01 00 00 4c 8d 6b 40 48 c7 45 18 00 00 00 00 48 b8 00 00 00 00 00 fc [   45.755574][ T9787] RSP: 0018:ffffc90015157668 EFLAGS: 00010202 [   45.756432][ T9787] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff819a4d09 [   45.757457][ T9787] RDX: 0000000000000008 RSI: ffffffff819acd3a RDI: ffffc900151576e8 [   45.758282][ T9787] RBP: ffffc900151576d0 R08: 0000000000000005 R09: 0000000000000000 [   45.758943][ T9787] R10: 0000000080000000 R11: 0000000000000001 R12: 0000000000000004 [   45.759619][ T9787] R13: 0000000000000040 R14: ffff88802c50814a R15: 0000000000000000 [   45.760293][ T9787] FS:  00007ffb72734540(0000) GS:ffff8880cec64000(0000) knlGS:0000000000000000 [   45.761050][ T9787] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [   45.761606][ T9787] CR2: 00007f9bd8225000 CR3: 000000010979a000 CR4: 00000000000006f0 [   45.762286][ T9787] Call Trace: [   45.762570][ T9787]  <TASK> [   45.762824][ T9787]  hfs_ext_read_extent+0x190/0x9d0 [   45.763269][ T9787]  ? submit_bio_noacct_nocheck+0x2dd/0xce0 [   45.763766][ T9787]  ? __pfx_hfs_ext_read_extent+0x10/0x10 [   45.764250][ T9787]  hfs_get_block+0x55f/0x830 [   45.764646][ T9787]  block_read_full_folio+0x36d/0x850 [   45.765105][ T9787]  ? __pfx_hfs_get_block+0x10/0x10 [   45.765541][ T9787]  ? const_folio_flags+0x5b/0x100 [   45.765972][ T9787]  ? __pfx_hfs_read_folio+0x10/0x10 [   45.766415][ T9787]  filemap_read_folio+0xbe/0x290 [   45.766840][ T9787]  ? __pfx_filemap_read_folio+0x10/0x10 [   45.767325][ T9787]  ? __filemap_get_folio+0x32b/0xbf0 [   45.767780][ T9787]  do_read_cache_folio+0x263/0x5c0 [   45.768223][ T9787]  ? __pfx_hfs_read_folio+0x10/0x10 [   45.768666][ T9787]  read_cache_page+0x5b/0x160 [   45.769070][ T9787]  hfs_btree_open+0x491/0x1740 [   45.769481][ T9787]  hfs_mdb_get+0x15e2/0x1fb0 [   45.769877][ T9787]  ? __pfx_hfs_mdb_get+0x10/0x10 [   45.770316][ T9787]  ? find_held_lock+0x2b/0x80 [   45.770731][ T9787]  ? lockdep_init_map_type+0x5c/0x280 [   45.771200][ T9787]  ? lockdep_init_map_type+0x5c/0x280 [   45.771674][ T9787]  hfs_fill_super+0x38e/0x720 [   45.772092][ T9787]  ? __pfx_hfs_fill_super+0x10/0x10 [   45.772549][ T9787]  ? snprintf+0xbe/0x100 [   45.772931][ T9787]  ? __pfx_snprintf+0x10/0x10 [   45.773350][ T9787]  ? do_raw_spin_lock+0x129/0x2b0 [   45.773796][ T9787]  ? find_held_lock+0x2b/0x80 [   45.774215][ T9787]  ? set_blocksize+0x40a/0x510 [   45.774636][ T9787]  ? sb_set_blocksize+0x176/0x1d0 [   45.775087][ T9787]  ? setup_bdev_super+0x369/0x730 [   45.775533][ T9787]  get_tree_bdev_flags+0x384/0x620 [   45.775985][ T9787]  ? __pfx_hfs_fill_super+0x10/0x10 [   45.776453][ T9787]  ? __pfx_get_tree_bdev_flags+0x10/0x10 [   45.776950][ T9787]  ? bpf_lsm_capable+0x9/0x10 [   45.777365][ T9787]  ? security_capable+0x80/0x260 [   45.777803][ T9787]  vfs_get_tree+0x8e/0x340 [   45.778203][ T9787]  path_mount+0x13de/0x2010 [   45.778604][ T9787]  ? kmem_cache_free+0x2b0/0x4c0 [   45.779052][ T9787]  ? __pfx_path_mount+0x10/0x10 [   45.779480][ T9787]  ? getname_flags.part.0+0x1c5/0x550 [   45.779954][ T9787]  ? putname+0x154/0x1a0 [   45.780335][ T9787]  __x64_sys_mount+0x27b/0x300 [   45.780758][ T9787]  ? __pfx___x64_sys_mount+0x10/0x10 [   45.781232][ T9787]  ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38716","epss":0.00145,"percentile":0.04073,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38716","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.076125},"relatedVulnerabilities":[{"id":"CVE-2025-38716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38716","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4f032979b63ad52e08aadf0faeac34ed35133ec0","https://git.kernel.org/stable/c/5d8b249527362e0ccafcaf76b3bec2a0d2aa1498","https://git.kernel.org/stable/c/6e20e10064fdc43231636fca519c15c013a8e3d6","https://git.kernel.org/stable/c/736a0516a16268995f4898eded49bfef077af709","https://git.kernel.org/stable/c/b918c17a1934ac6309b0083f41d4e9d8fb3bb46c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhfs: fix general protection fault in hfs_find_init()\n\nThe hfs_find_init() method can trigger the crash\nif tree pointer is NULL:\n\n[   45.746290][ T9787] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000008: 0000 [#1] SMP KAI\n[   45.747287][ T9787] KASAN: null-ptr-deref in range [0x0000000000000040-0x0000000000000047]\n[   45.748716][ T9787] CPU: 2 UID: 0 PID: 9787 Comm: repro Not tainted 6.16.0-rc3 #10 PREEMPT(full)\n[   45.750250][ T9787] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[   45.751983][ T9787] RIP: 0010:hfs_find_init+0x86/0x230\n[   45.752834][ T9787] Code: c1 ea 03 80 3c 02 00 0f 85 9a 01 00 00 4c 8d 6b 40 48 c7 45 18 00 00 00 00 48 b8 00 00 00 00 00 fc\n[   45.755574][ T9787] RSP: 0018:ffffc90015157668 EFLAGS: 00010202\n[   45.756432][ T9787] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff819a4d09\n[   45.757457][ T9787] RDX: 0000000000000008 RSI: ffffffff819acd3a RDI: ffffc900151576e8\n[   45.758282][ T9787] RBP: ffffc900151576d0 R08: 0000000000000005 R09: 0000000000000000\n[   45.758943][ T9787] R10: 0000000080000000 R11: 0000000000000001 R12: 0000000000000004\n[   45.759619][ T9787] R13: 0000000000000040 R14: ffff88802c50814a R15: 0000000000000000\n[   45.760293][ T9787] FS:  00007ffb72734540(0000) GS:ffff8880cec64000(0000) knlGS:0000000000000000\n[   45.761050][ T9787] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[   45.761606][ T9787] CR2: 00007f9bd8225000 CR3: 000000010979a000 CR4: 00000000000006f0\n[   45.762286][ T9787] Call Trace:\n[   45.762570][ T9787]  <TASK>\n[   45.762824][ T9787]  hfs_ext_read_extent+0x190/0x9d0\n[   45.763269][ T9787]  ? submit_bio_noacct_nocheck+0x2dd/0xce0\n[   45.763766][ T9787]  ? __pfx_hfs_ext_read_extent+0x10/0x10\n[   45.764250][ T9787]  hfs_get_block+0x55f/0x830\n[   45.764646][ T9787]  block_read_full_folio+0x36d/0x850\n[   45.765105][ T9787]  ? __pfx_hfs_get_block+0x10/0x10\n[   45.765541][ T9787]  ? const_folio_flags+0x5b/0x100\n[   45.765972][ T9787]  ? __pfx_hfs_read_folio+0x10/0x10\n[   45.766415][ T9787]  filemap_read_folio+0xbe/0x290\n[   45.766840][ T9787]  ? __pfx_filemap_read_folio+0x10/0x10\n[   45.767325][ T9787]  ? __filemap_get_folio+0x32b/0xbf0\n[   45.767780][ T9787]  do_read_cache_folio+0x263/0x5c0\n[   45.768223][ T9787]  ? __pfx_hfs_read_folio+0x10/0x10\n[   45.768666][ T9787]  read_cache_page+0x5b/0x160\n[   45.769070][ T9787]  hfs_btree_open+0x491/0x1740\n[   45.769481][ T9787]  hfs_mdb_get+0x15e2/0x1fb0\n[   45.769877][ T9787]  ? __pfx_hfs_mdb_get+0x10/0x10\n[   45.770316][ T9787]  ? find_held_lock+0x2b/0x80\n[   45.770731][ T9787]  ? lockdep_init_map_type+0x5c/0x280\n[   45.771200][ T9787]  ? lockdep_init_map_type+0x5c/0x280\n[   45.771674][ T9787]  hfs_fill_super+0x38e/0x720\n[   45.772092][ T9787]  ? __pfx_hfs_fill_super+0x10/0x10\n[   45.772549][ T9787]  ? snprintf+0xbe/0x100\n[   45.772931][ T9787]  ? __pfx_snprintf+0x10/0x10\n[   45.773350][ T9787]  ? do_raw_spin_lock+0x129/0x2b0\n[   45.773796][ T9787]  ? find_held_lock+0x2b/0x80\n[   45.774215][ T9787]  ? set_blocksize+0x40a/0x510\n[   45.774636][ T9787]  ? sb_set_blocksize+0x176/0x1d0\n[   45.775087][ T9787]  ? setup_bdev_super+0x369/0x730\n[   45.775533][ T9787]  get_tree_bdev_flags+0x384/0x620\n[   45.775985][ T9787]  ? __pfx_hfs_fill_super+0x10/0x10\n[   45.776453][ T9787]  ? __pfx_get_tree_bdev_flags+0x10/0x10\n[   45.776950][ T9787]  ? bpf_lsm_capable+0x9/0x10\n[   45.777365][ T9787]  ? security_capable+0x80/0x260\n[   45.777803][ T9787]  vfs_get_tree+0x8e/0x340\n[   45.778203][ T9787]  path_mount+0x13de/0x2010\n[   45.778604][ T9787]  ? kmem_cache_free+0x2b0/0x4c0\n[   45.779052][ T9787]  ? __pfx_path_mount+0x10/0x10\n[   45.779480][ T9787]  ? getname_flags.part.0+0x1c5/0x550\n[   45.779954][ T9787]  ? putname+0x154/0x1a0\n[   45.780335][ T9787]  __x64_sys_mount+0x27b/0x300\n[   45.780758][ T9787]  ? __pfx___x64_sys_mount+0x10/0x10\n[   45.781232][ T9787] \n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38716","epss":0.00145,"percentile":0.04073,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38716","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38716","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38717","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38717","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: kcm: Fix race condition in kcm_unattach()  syzbot found a race condition when kcm_unattach(psock) and kcm_release(kcm) are executed at the same time.  kcm_unattach() is missing a check of the flag kcm->tx_stopped before calling queue_work().  If the kcm has a reserved psock, kcm_unattach() might get executed between cancel_work_sync() and unreserve_psock() in kcm_release(), requeuing kcm->tx_work right before kcm gets freed in kcm_done().  Remove kcm->tx_stopped and replace it by the less error-prone disable_work_sync().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38717","epss":0.00114,"percentile":0.01647,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38717","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05528999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-38717","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38717","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/52565a935213cd6a8662ddb8efe5b4219343a25d","https://git.kernel.org/stable/c/7275dc3bb8f91b23125ff3f47b6529935cf46152","https://git.kernel.org/stable/c/798733ee5d5788b12e8a52db1519abc17e826f69","https://git.kernel.org/stable/c/c0bffbc92a1ca3960fb9cdb8e9f75a68468eb308"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: kcm: Fix race condition in kcm_unattach()\n\nsyzbot found a race condition when kcm_unattach(psock)\nand kcm_release(kcm) are executed at the same time.\n\nkcm_unattach() is missing a check of the flag\nkcm->tx_stopped before calling queue_work().\n\nIf the kcm has a reserved psock, kcm_unattach() might get executed\nbetween cancel_work_sync() and unreserve_psock() in kcm_release(),\nrequeuing kcm->tx_work right before kcm gets freed in kcm_done().\n\nRemove kcm->tx_stopped and replace it by the less\nerror-prone disable_work_sync().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38717","epss":0.00114,"percentile":0.01647,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38717","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38717","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38722","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38722","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  habanalabs: fix UAF in export_dmabuf()  As soon as we'd inserted a file reference into descriptor table, another thread could close it.  That's fine for the case when all we are doing is returning that descriptor to userland (it's a race, but it's a userland race and there's nothing the kernel can do about it).  However, if we follow fd_install() with any kind of access to objects that would be destroyed on close (be it the struct file itself or anything destroyed by its ->release()), we have a UAF.  dma_buf_fd() is a combination of reserving a descriptor and fd_install(). habanalabs export_dmabuf() calls it and then proceeds to access the objects destroyed on close.  In particular, it grabs an extra reference to another struct file that will be dropped as part of ->release() for ours; that \"will be\" is actually \"might have already been\".  Fix that by reserving descriptor before anything else and do fd_install() only when everything had been set up.  As a side benefit, we no longer have the failure exit with file already created, but reference to underlying file (as well as ->dmabuf_export_cnt, etc.) not grabbed yet; unlike dma_buf_fd(), fd_install() can't fail.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38722","epss":0.00153,"percentile":0.04722,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38722","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.117045},"relatedVulnerabilities":[{"id":"CVE-2025-38722","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38722","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/33927f3d0ecdcff06326d6e4edb6166aed42811c","https://git.kernel.org/stable/c/40deceb38f9db759772d1c289c28fd2a543f57fc","https://git.kernel.org/stable/c/55c232d7e0241f1d5120b595e7a9de24c75ed3d8","https://git.kernel.org/stable/c/c07886761fd6251db6938d4e747002e3d150d231"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhabanalabs: fix UAF in export_dmabuf()\n\nAs soon as we'd inserted a file reference into descriptor table, another\nthread could close it.  That's fine for the case when all we are doing is\nreturning that descriptor to userland (it's a race, but it's a userland\nrace and there's nothing the kernel can do about it).  However, if we\nfollow fd_install() with any kind of access to objects that would be\ndestroyed on close (be it the struct file itself or anything destroyed\nby its ->release()), we have a UAF.\n\ndma_buf_fd() is a combination of reserving a descriptor and fd_install().\nhabanalabs export_dmabuf() calls it and then proceeds to access the\nobjects destroyed on close.  In particular, it grabs an extra reference to\nanother struct file that will be dropped as part of ->release() for ours;\nthat \"will be\" is actually \"might have already been\".\n\nFix that by reserving descriptor before anything else and do fd_install()\nonly when everything had been set up.  As a side benefit, we no longer\nhave the failure exit with file already created, but reference to\nunderlying file (as well as ->dmabuf_export_cnt, etc.) not grabbed yet;\nunlike dma_buf_fd(), fd_install() can't fail.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38722","epss":0.00153,"percentile":0.04722,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38722","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38722","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-38734","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-38734","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/smc: fix UAF on smcsk after smc_listen_out()  BPF CI testing report a UAF issue:    [   16.446633] BUG: kernel NULL pointer dereference, address: 000000000000003  0   [   16.447134] #PF: supervisor read access in kernel mod  e   [   16.447516] #PF: error_code(0x0000) - not-present pag  e   [   16.447878] PGD 0 P4D   0   [   16.448063] Oops: Oops: 0000 [#1] PREEMPT SMP NOPT  I   [   16.448409] CPU: 0 UID: 0 PID: 9 Comm: kworker/0:1 Tainted: G           OE      6.13.0-rc3-g89e8a75fda73-dirty #4  2   [   16.449124] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODUL  E   [   16.449502] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/201  4   [   16.450201] Workqueue: smc_hs_wq smc_listen_wor  k   [   16.450531] RIP: 0010:smc_listen_work+0xc02/0x159  0   [   16.452158] RSP: 0018:ffffb5ab40053d98 EFLAGS: 0001024  6   [   16.452526] RAX: 0000000000000001 RBX: 0000000000000002 RCX: 000000000000030  0   [   16.452994] RDX: 0000000000000280 RSI: 00003513840053f0 RDI: 000000000000000  0   [   16.453492] RBP: ffffa097808e3800 R08: ffffa09782dba1e0 R09: 000000000000000  5   [   16.453987] R10: 0000000000000000 R11: 0000000000000000 R12: ffffa0978274640  0   [   16.454497] R13: 0000000000000000 R14: 0000000000000000 R15: ffffa09782d4092  0   [   16.454996] FS:  0000000000000000(0000) GS:ffffa097bbc00000(0000) knlGS:000000000000000  0   [   16.455557] CS:  0010 DS: 0000 ES: 0000 CR0: 000000008005003  3   [   16.455961] CR2: 0000000000000030 CR3: 0000000102788004 CR4: 0000000000770ef  0   [   16.456459] PKRU: 5555555  4   [   16.456654] Call Trace  :   [   16.456832]  <TASK  >   [   16.456989]  ? __die+0x23/0x7  0   [   16.457215]  ? page_fault_oops+0x180/0x4c  0   [   16.457508]  ? __lock_acquire+0x3e6/0x249  0   [   16.457801]  ? exc_page_fault+0x68/0x20  0   [   16.458080]  ? asm_exc_page_fault+0x26/0x3  0   [   16.458389]  ? smc_listen_work+0xc02/0x159  0   [   16.458689]  ? smc_listen_work+0xc02/0x159  0   [   16.458987]  ? lock_is_held_type+0x8f/0x10  0   [   16.459284]  process_one_work+0x1ea/0x6d  0   [   16.459570]  worker_thread+0x1c3/0x38  0   [   16.459839]  ? __pfx_worker_thread+0x10/0x1  0   [   16.460144]  kthread+0xe0/0x11  0   [   16.460372]  ? __pfx_kthread+0x10/0x1  0   [   16.460640]  ret_from_fork+0x31/0x5  0   [   16.460896]  ? __pfx_kthread+0x10/0x1  0   [   16.461166]  ret_from_fork_asm+0x1a/0x3  0   [   16.461453]  </TASK  >   [   16.461616] Modules linked in: bpf_testmod(OE) [last unloaded: bpf_testmod(OE)  ]   [   16.462134] CR2: 000000000000003  0   [   16.462380] ---[ end trace 0000000000000000 ]---   [   16.462710] RIP: 0010:smc_listen_work+0xc02/0x1590  The direct cause of this issue is that after smc_listen_out_connected(), newclcsock->sk may be NULL since it will releases the smcsk. Therefore, if the application closes the socket immediately after accept, newclcsock->sk can be NULL. A possible execution order could be as follows:  smc_listen_work                                 | userspace ----------------------------------------------------------------- lock_sock(sk)                                   | smc_listen_out_connected()                      | | \\- smc_listen_out                             | |    | \\- release_sock                          |      | |- sk->sk_data_ready()                   |                                                 | fd = accept();                                                 | close(fd);                                                 |  \\- socket->sk = NULL; /* newclcsock->sk is NULL now */ SMC_STAT_SERV_SUCC_INC(sock_net(newclcsock->sk))  Since smc_listen_out_connected() will not fail, simply swapping the order of the code can easily fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38734","epss":0.00451,"percentile":0.37947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38734","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.345015},"relatedVulnerabilities":[{"id":"CVE-2025-38734","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-38734","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/070b4af44c4b6e4c35fb1ca7001a6a88fd2d318f","https://git.kernel.org/stable/c/2e765ba0ee0eae35688b443e97108308a716773e","https://git.kernel.org/stable/c/85545f1525f9fa9bf44fec77ba011024f15da342","https://git.kernel.org/stable/c/d9cef55ed49117bd63695446fb84b4b91815c0b4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix UAF on smcsk after smc_listen_out()\n\nBPF CI testing report a UAF issue:\n\n  [   16.446633] BUG: kernel NULL pointer dereference, address: 000000000000003  0\n  [   16.447134] #PF: supervisor read access in kernel mod  e\n  [   16.447516] #PF: error_code(0x0000) - not-present pag  e\n  [   16.447878] PGD 0 P4D   0\n  [   16.448063] Oops: Oops: 0000 [#1] PREEMPT SMP NOPT  I\n  [   16.448409] CPU: 0 UID: 0 PID: 9 Comm: kworker/0:1 Tainted: G           OE      6.13.0-rc3-g89e8a75fda73-dirty #4  2\n  [   16.449124] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODUL  E\n  [   16.449502] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/201  4\n  [   16.450201] Workqueue: smc_hs_wq smc_listen_wor  k\n  [   16.450531] RIP: 0010:smc_listen_work+0xc02/0x159  0\n  [   16.452158] RSP: 0018:ffffb5ab40053d98 EFLAGS: 0001024  6\n  [   16.452526] RAX: 0000000000000001 RBX: 0000000000000002 RCX: 000000000000030  0\n  [   16.452994] RDX: 0000000000000280 RSI: 00003513840053f0 RDI: 000000000000000  0\n  [   16.453492] RBP: ffffa097808e3800 R08: ffffa09782dba1e0 R09: 000000000000000  5\n  [   16.453987] R10: 0000000000000000 R11: 0000000000000000 R12: ffffa0978274640  0\n  [   16.454497] R13: 0000000000000000 R14: 0000000000000000 R15: ffffa09782d4092  0\n  [   16.454996] FS:  0000000000000000(0000) GS:ffffa097bbc00000(0000) knlGS:000000000000000  0\n  [   16.455557] CS:  0010 DS: 0000 ES: 0000 CR0: 000000008005003  3\n  [   16.455961] CR2: 0000000000000030 CR3: 0000000102788004 CR4: 0000000000770ef  0\n  [   16.456459] PKRU: 5555555  4\n  [   16.456654] Call Trace  :\n  [   16.456832]  <TASK  >\n  [   16.456989]  ? __die+0x23/0x7  0\n  [   16.457215]  ? page_fault_oops+0x180/0x4c  0\n  [   16.457508]  ? __lock_acquire+0x3e6/0x249  0\n  [   16.457801]  ? exc_page_fault+0x68/0x20  0\n  [   16.458080]  ? asm_exc_page_fault+0x26/0x3  0\n  [   16.458389]  ? smc_listen_work+0xc02/0x159  0\n  [   16.458689]  ? smc_listen_work+0xc02/0x159  0\n  [   16.458987]  ? lock_is_held_type+0x8f/0x10  0\n  [   16.459284]  process_one_work+0x1ea/0x6d  0\n  [   16.459570]  worker_thread+0x1c3/0x38  0\n  [   16.459839]  ? __pfx_worker_thread+0x10/0x1  0\n  [   16.460144]  kthread+0xe0/0x11  0\n  [   16.460372]  ? __pfx_kthread+0x10/0x1  0\n  [   16.460640]  ret_from_fork+0x31/0x5  0\n  [   16.460896]  ? __pfx_kthread+0x10/0x1  0\n  [   16.461166]  ret_from_fork_asm+0x1a/0x3  0\n  [   16.461453]  </TASK  >\n  [   16.461616] Modules linked in: bpf_testmod(OE) [last unloaded: bpf_testmod(OE)  ]\n  [   16.462134] CR2: 000000000000003  0\n  [   16.462380] ---[ end trace 0000000000000000 ]---\n  [   16.462710] RIP: 0010:smc_listen_work+0xc02/0x1590\n\nThe direct cause of this issue is that after smc_listen_out_connected(),\nnewclcsock->sk may be NULL since it will releases the smcsk. Therefore,\nif the application closes the socket immediately after accept,\nnewclcsock->sk can be NULL. A possible execution order could be as\nfollows:\n\nsmc_listen_work                                 | userspace\n-----------------------------------------------------------------\nlock_sock(sk)                                   |\nsmc_listen_out_connected()                      |\n| \\- smc_listen_out                             |\n|    | \\- release_sock                          |\n     | |- sk->sk_data_ready()                   |\n                                                | fd = accept();\n                                                | close(fd);\n                                                |  \\- socket->sk = NULL;\n/* newclcsock->sk is NULL now */\nSMC_STAT_SERV_SUCC_INC(sock_net(newclcsock->sk))\n\nSince smc_listen_out_connected() will not fail, simply swapping the order\nof the code can easily fix this issue.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-38734","epss":0.00451,"percentile":0.37947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-38734","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-38734","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39677","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39677","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: Fix backlog accounting in qdisc_dequeue_internal  This issue applies for the following qdiscs: hhf, fq, fq_codel, and fq_pie, and occurs in their change handlers when adjusting to the new limit. The problem is the following in the values passed to the subsequent qdisc_tree_reduce_backlog call given a tbf parent:     When the tbf parent runs out of tokens, skbs of these qdiscs will    be placed in gso_skb. Their peek handlers are qdisc_peek_dequeued,    which accounts for both qlen and backlog. However, in the case of    qdisc_dequeue_internal, ONLY qlen is accounted for when pulling    from gso_skb. This means that these qdiscs are missing a    qdisc_qstats_backlog_dec when dropping packets to satisfy the    new limit in their change handlers.     One can observe this issue with the following (with tc patched to    support a limit of 0):     export TARGET=fq    tc qdisc del dev lo root    tc qdisc add dev lo root handle 1: tbf rate 8bit burst 100b latency 1ms    tc qdisc replace dev lo handle 3: parent 1:1 $TARGET limit 1000    echo ''; echo 'add child'; tc -s -d qdisc show dev lo    ping -I lo -f -c2 -s32 -W0.001 127.0.0.1 2>&1 >/dev/null    echo ''; echo 'after ping'; tc -s -d qdisc show dev lo    tc qdisc change dev lo handle 3: parent 1:1 $TARGET limit 0    echo ''; echo 'after limit drop'; tc -s -d qdisc show dev lo    tc qdisc replace dev lo handle 2: parent 1:1 sfq    echo ''; echo 'post graft'; tc -s -d qdisc show dev lo     The second to last show command shows 0 packets but a positive    number (74) of backlog bytes. The problem becomes clearer in the    last show command, where qdisc_purge_queue triggers    qdisc_tree_reduce_backlog with the positive backlog and causes an    underflow in the tbf parent's backlog (4096 Mb instead of 0).  To fix this issue, the codepath for all clients of qdisc_dequeue_internal has been simplified: codel, pie, hhf, fq, fq_pie, and fq_codel. qdisc_dequeue_internal handles the backlog adjustments for all cases that do not directly use the dequeue handler.  The old fq_codel_change limit adjustment loop accumulated the arguments to the subsequent qdisc_tree_reduce_backlog call through the cstats field. However, this is confusing and error prone as fq_codel_dequeue could also potentially mutate this field (which qdisc_dequeue_internal calls in the non gso_skb case), so we have unified the code here with other qdiscs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39677","epss":0.00144,"percentile":0.0402,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0756},"relatedVulnerabilities":[{"id":"CVE-2025-39677","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39677","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/52bf272636bda69587952b35ae97690b8dc89941","https://git.kernel.org/stable/c/a225f44d84b8900d679c5f5a9ea46fe9c0cc7802"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: Fix backlog accounting in qdisc_dequeue_internal\n\nThis issue applies for the following qdiscs: hhf, fq, fq_codel, and\nfq_pie, and occurs in their change handlers when adjusting to the new\nlimit. The problem is the following in the values passed to the\nsubsequent qdisc_tree_reduce_backlog call given a tbf parent:\n\n   When the tbf parent runs out of tokens, skbs of these qdiscs will\n   be placed in gso_skb. Their peek handlers are qdisc_peek_dequeued,\n   which accounts for both qlen and backlog. However, in the case of\n   qdisc_dequeue_internal, ONLY qlen is accounted for when pulling\n   from gso_skb. This means that these qdiscs are missing a\n   qdisc_qstats_backlog_dec when dropping packets to satisfy the\n   new limit in their change handlers.\n\n   One can observe this issue with the following (with tc patched to\n   support a limit of 0):\n\n   export TARGET=fq\n   tc qdisc del dev lo root\n   tc qdisc add dev lo root handle 1: tbf rate 8bit burst 100b latency 1ms\n   tc qdisc replace dev lo handle 3: parent 1:1 $TARGET limit 1000\n   echo ''; echo 'add child'; tc -s -d qdisc show dev lo\n   ping -I lo -f -c2 -s32 -W0.001 127.0.0.1 2>&1 >/dev/null\n   echo ''; echo 'after ping'; tc -s -d qdisc show dev lo\n   tc qdisc change dev lo handle 3: parent 1:1 $TARGET limit 0\n   echo ''; echo 'after limit drop'; tc -s -d qdisc show dev lo\n   tc qdisc replace dev lo handle 2: parent 1:1 sfq\n   echo ''; echo 'post graft'; tc -s -d qdisc show dev lo\n\n   The second to last show command shows 0 packets but a positive\n   number (74) of backlog bytes. The problem becomes clearer in the\n   last show command, where qdisc_purge_queue triggers\n   qdisc_tree_reduce_backlog with the positive backlog and causes an\n   underflow in the tbf parent's backlog (4096 Mb instead of 0).\n\nTo fix this issue, the codepath for all clients of qdisc_dequeue_internal\nhas been simplified: codel, pie, hhf, fq, fq_pie, and fq_codel.\nqdisc_dequeue_internal handles the backlog adjustments for all cases that\ndo not directly use the dequeue handler.\n\nThe old fq_codel_change limit adjustment loop accumulated the arguments to\nthe subsequent qdisc_tree_reduce_backlog call through the cstats field.\nHowever, this is confusing and error prone as fq_codel_dequeue could also\npotentially mutate this field (which qdisc_dequeue_internal calls in the\nnon gso_skb case), so we have unified the code here with other qdiscs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39677","epss":0.00144,"percentile":0.0402,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39677","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39705","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39705","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: fix a Null pointer dereference vulnerability  [Why] A null pointer dereference vulnerability exists in the AMD display driver's (DC module) cleanup function dc_destruct(). When display control context (dc->ctx) construction fails (due to memory allocation failure), this pointer remains NULL. During subsequent error handling when dc_destruct() is called, there's no NULL check before dereferencing the perf_trace member (dc->ctx->perf_trace), causing a kernel null pointer dereference crash.  [How] Check if dc->ctx is non-NULL before dereferencing.  (Updated commit text and removed unnecessary error message) (cherry picked from commit 9dd8e2ba268c636c240a918e0a31e6feaee19404)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39705","epss":0.00143,"percentile":0.03942,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39705","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07507500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-39705","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39705","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0961673cc5f0055957aa46f25eb4ef6c07e00165","https://git.kernel.org/stable/c/1bcf63a44381691d6192872801f830ce3250e367","https://git.kernel.org/stable/c/4ade995b9b25b3c6e8dc42c27070340f1358d8c8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix a Null pointer dereference vulnerability\n\n[Why]\nA null pointer dereference vulnerability exists in the AMD display driver's\n(DC module) cleanup function dc_destruct().\nWhen display control context (dc->ctx) construction fails\n(due to memory allocation failure), this pointer remains NULL.\nDuring subsequent error handling when dc_destruct() is called,\nthere's no NULL check before dereferencing the perf_trace member\n(dc->ctx->perf_trace), causing a kernel null pointer dereference crash.\n\n[How]\nCheck if dc->ctx is non-NULL before dereferencing.\n\n(Updated commit text and removed unnecessary error message)\n(cherry picked from commit 9dd8e2ba268c636c240a918e0a31e6feaee19404)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39705","epss":0.00143,"percentile":0.03942,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39705","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39705","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39707","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39707","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities  HUBBUB structure is not initialized on DCE hardware, so check if it is NULL to avoid null dereference while accessing amdgpu_dm_capabilities file in debugfs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39707","epss":0.00143,"percentile":0.03934,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39707","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07507500000000002},"relatedVulnerabilities":[{"id":"CVE-2025-39707","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39707","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/83cfdc2b018cd9c0f927b781d4e07c0d4a911fac","https://git.kernel.org/stable/c/98e92fceb9507901e3e8b550e93b843306abd354","https://git.kernel.org/stable/c/b4a69f7f29c8a459ad6b4d8a8b72450f1d9fd288"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities\n\nHUBBUB structure is not initialized on DCE hardware, so check if it is NULL\nto avoid null dereference while accessing amdgpu_dm_capabilities file in\ndebugfs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39707","epss":0.00143,"percentile":0.03934,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39707","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39707","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39720","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix refcount leak causing resource not released  When ksmbd_conn_releasing(opinfo->conn) returns true,the refcount was not decremented properly, causing a refcount leak that prevents the count from reaching zero and the memory from being released.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39720","epss":0.0028,"percentile":0.20286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39720","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.147},"relatedVulnerabilities":[{"id":"CVE-2025-39720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39720","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/36e010bb865fbaa1202fe9bcce3fd486d6db7606","https://git.kernel.org/stable/c/89bb430f621124af39bb31763c4a8b504c9651e2","https://git.kernel.org/stable/c/9a7abce6e8c0e2145b346a6d4abf0d9655e9b0e8","https://git.kernel.org/stable/c/a1d2bab4d53368a526c97aba92671dd71814f95a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix refcount leak causing resource not released\n\nWhen ksmbd_conn_releasing(opinfo->conn) returns true,the refcount was not\ndecremented properly, causing a refcount leak that prevents the count from\nreaching zero and the memory from being released.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39720","epss":0.0028,"percentile":0.20286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39720","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39720","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39726","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39726","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/ism: fix concurrency management in ism_cmd()  The s390x ISM device data sheet clearly states that only one request-response sequence is allowable per ISM function at any point in time.  Unfortunately as of today the s390/ism driver in Linux does not honor that requirement. This patch aims to rectify that.  This problem was discovered based on Aliaksei's bug report which states that for certain workloads the ISM functions end up entering error state (with PEC 2 as seen from the logs) after a while and as a consequence connections handled by the respective function break, and for future connection requests the ISM device is not considered -- given it is in a dysfunctional state. During further debugging PEC 3A was observed as well.  A kernel message like [ 1211.244319] zpci: 061a:00:00.0: Event 0x2 reports an error for PCI function 0x61a is a reliable indicator of the stated function entering error state with PEC 2. Let me also point out that a kernel message like [ 1211.244325] zpci: 061a:00:00.0: The ism driver bound to the device does not support error recovery is a reliable indicator that the ISM function won't be auto-recovered because the ISM driver currently lacks support for it.  On a technical level, without this synchronization, commands (inputs to the FW) may be partially or fully overwritten (corrupted) by another CPU trying to issue commands on the same function. There is hard evidence that this can lead to DMB token values being used as DMB IOVAs, leading to PEC 2 PCI events indicating invalid DMA. But this is only one of the failure modes imaginable. In theory even completely losing one command and executing another one twice and then trying to interpret the outputs as if the command we intended to execute was actually executed and not the other one is also possible.  Frankly, I don't feel confident about providing an exhaustive list of possible consequences.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39726","epss":0.00235,"percentile":0.14488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39726","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11397499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-39726","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39726","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1194ad0d44d66b273a02a3a22882dc863a68d764","https://git.kernel.org/stable/c/897e8601b9cff1d054cdd53047f568b0e1995726","https://git.kernel.org/stable/c/faf44487dfc80817f178dc8de7a0b73f960d019b","https://git.kernel.org/stable/c/fafaa4982bedb5532f5952000f714a3e63023f40"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/ism: fix concurrency management in ism_cmd()\n\nThe s390x ISM device data sheet clearly states that only one\nrequest-response sequence is allowable per ISM function at any point in\ntime.  Unfortunately as of today the s390/ism driver in Linux does not\nhonor that requirement. This patch aims to rectify that.\n\nThis problem was discovered based on Aliaksei's bug report which states\nthat for certain workloads the ISM functions end up entering error state\n(with PEC 2 as seen from the logs) after a while and as a consequence\nconnections handled by the respective function break, and for future\nconnection requests the ISM device is not considered -- given it is in a\ndysfunctional state. During further debugging PEC 3A was observed as\nwell.\n\nA kernel message like\n[ 1211.244319] zpci: 061a:00:00.0: Event 0x2 reports an error for PCI function 0x61a\nis a reliable indicator of the stated function entering error state\nwith PEC 2. Let me also point out that a kernel message like\n[ 1211.244325] zpci: 061a:00:00.0: The ism driver bound to the device does not support error recovery\nis a reliable indicator that the ISM function won't be auto-recovered\nbecause the ISM driver currently lacks support for it.\n\nOn a technical level, without this synchronization, commands (inputs to\nthe FW) may be partially or fully overwritten (corrupted) by another CPU\ntrying to issue commands on the same function. There is hard evidence that\nthis can lead to DMB token values being used as DMB IOVAs, leading to\nPEC 2 PCI events indicating invalid DMA. But this is only one of the\nfailure modes imaginable. In theory even completely losing one command\nand executing another one twice and then trying to interpret the outputs\nas if the command we intended to execute was actually executed and not\nthe other one is also possible.  Frankly, I don't feel confident about\nproviding an exhaustive list of possible consequences.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39726","epss":0.00235,"percentile":0.14488,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39726","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39726","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39732","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39732","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()  ath11k_mac_disable_peer_fixed_rate() is passed as the iterator to ieee80211_iterate_stations_atomic(). Note in this case the iterator is required to be atomic, however ath11k_mac_disable_peer_fixed_rate() does not follow it as it might sleep. Consequently below warning is seen:  BUG: sleeping function called from invalid context at wmi.c:304 Call Trace:  <TASK>  dump_stack_lvl  __might_resched.cold  ath11k_wmi_cmd_send  ath11k_wmi_set_peer_param  ath11k_mac_disable_peer_fixed_rate  ieee80211_iterate_stations_atomic  ath11k_mac_op_set_bitrate_mask.cold  Change to ieee80211_iterate_stations_mtx() to fix this issue.  Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39732","epss":0.00153,"percentile":0.04722,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.080325},"relatedVulnerabilities":[{"id":"CVE-2025-39732","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39732","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/65c12b104cb942d588a1a093acc4537fb3d3b129","https://git.kernel.org/stable/c/6bdef22d540258ca06f079f7b6ae100669a19b47","https://git.kernel.org/stable/c/7d4d0db0dc9424de2bdc0b45e919e4892603356f","https://git.kernel.org/stable/c/9c0e3144924c7db701575a73af341d33184afeaf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()\n\nath11k_mac_disable_peer_fixed_rate() is passed as the iterator to\nieee80211_iterate_stations_atomic(). Note in this case the iterator is\nrequired to be atomic, however ath11k_mac_disable_peer_fixed_rate() does\nnot follow it as it might sleep. Consequently below warning is seen:\n\nBUG: sleeping function called from invalid context at wmi.c:304\nCall Trace:\n <TASK>\n dump_stack_lvl\n __might_resched.cold\n ath11k_wmi_cmd_send\n ath11k_wmi_set_peer_param\n ath11k_mac_disable_peer_fixed_rate\n ieee80211_iterate_stations_atomic\n ath11k_mac_op_set_bitrate_mask.cold\n\nChange to ieee80211_iterate_stations_mtx() to fix this issue.\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39732","epss":0.00153,"percentile":0.04722,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39732","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39744","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39744","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rcu: Fix rcu_read_unlock() deadloop due to IRQ work  During rcu_read_unlock_special(), if this happens during irq_exit(), we can lockup if an IPI is issued. This is because the IPI itself triggers the irq_exit() path causing a recursive lock up.  This is precisely what Xiongfeng found when invoking a BPF program on the trace_tick_stop() tracepoint As shown in the trace below. Fix by managing the irq_work state correctly.  irq_exit()   __irq_exit_rcu()     /* in_hardirq() returns false after this */     preempt_count_sub(HARDIRQ_OFFSET)     tick_irq_exit()       tick_nohz_irq_exit() \t    tick_nohz_stop_sched_tick() \t      trace_tick_stop()  /* a bpf prog is hooked on this trace point */ \t\t   __bpf_trace_tick_stop() \t\t      bpf_trace_run2() \t\t\t    rcu_read_unlock_special()                               /* will send a IPI to itself */ \t\t\t      irq_work_queue_on(&rdp->defer_qs_iw, rdp->cpu);  A simple reproducer can also be obtained by doing the following in tick_irq_exit(). It will hang on boot without the patch:    static inline void tick_irq_exit(void)   {  +\trcu_read_lock();  +\tWRITE_ONCE(current->rcu_read_unlock_special.b.need_qs, true);  +\trcu_read_unlock();  +  [neeraj: Apply Frederic's suggested fix for PREEMPT_RT]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39744","epss":0.00159,"percentile":0.05419,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39744","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11606999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-39744","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39744","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1cfa244f7198d325594e627574930b7b91df5bfe","https://git.kernel.org/stable/c/56c5ef194f4509df63fc0f7a91ea5973ce479b1e","https://git.kernel.org/stable/c/b41642c87716bbd09797b1e4ea7d904f06c39b7b","https://git.kernel.org/stable/c/ddebb2a7677673cf4438a04e1a48b8ed6b0c8e9a","https://git.kernel.org/stable/c/e7a375453cca2b8a0d2fa1b82b913f3fed7c0507"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrcu: Fix rcu_read_unlock() deadloop due to IRQ work\n\nDuring rcu_read_unlock_special(), if this happens during irq_exit(), we\ncan lockup if an IPI is issued. This is because the IPI itself triggers\nthe irq_exit() path causing a recursive lock up.\n\nThis is precisely what Xiongfeng found when invoking a BPF program on\nthe trace_tick_stop() tracepoint As shown in the trace below. Fix by\nmanaging the irq_work state correctly.\n\nirq_exit()\n  __irq_exit_rcu()\n    /* in_hardirq() returns false after this */\n    preempt_count_sub(HARDIRQ_OFFSET)\n    tick_irq_exit()\n      tick_nohz_irq_exit()\n\t    tick_nohz_stop_sched_tick()\n\t      trace_tick_stop()  /* a bpf prog is hooked on this trace point */\n\t\t   __bpf_trace_tick_stop()\n\t\t      bpf_trace_run2()\n\t\t\t    rcu_read_unlock_special()\n                              /* will send a IPI to itself */\n\t\t\t      irq_work_queue_on(&rdp->defer_qs_iw, rdp->cpu);\n\nA simple reproducer can also be obtained by doing the following in\ntick_irq_exit(). It will hang on boot without the patch:\n\n  static inline void tick_irq_exit(void)\n  {\n +\trcu_read_lock();\n +\tWRITE_ONCE(current->rcu_read_unlock_special.b.need_qs, true);\n +\trcu_read_unlock();\n +\n\n[neeraj: Apply Frederic's suggested fix for PREEMPT_RT]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39744","epss":0.00159,"percentile":0.05419,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39744","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39744","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39746","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39746","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath10k: shutdown driver when hardware is unreliable  In rare cases, ath10k may lose connection with the PCIe bus due to some unknown reasons, which could further lead to system crashes during resuming due to watchdog timeout:  ath10k_pci 0000:01:00.0: wmi command 20486 timeout, restarting hardware ath10k_pci 0000:01:00.0: already restarting ath10k_pci 0000:01:00.0: failed to stop WMI vdev 0: -11 ath10k_pci 0000:01:00.0: failed to stop vdev 0: -11 ieee80211 phy0: PM: **** DPM device timeout **** Call Trace:  panic+0x125/0x315  dpm_watchdog_set+0x54/0x54  dpm_watchdog_handler+0x57/0x57  call_timer_fn+0x31/0x13c  At this point, all WMI commands will timeout and attempt to restart device. So set a threshold for consecutive restart failures. If the threshold is exceeded, consider the hardware is unreliable and all ath10k operations should be skipped to avoid system crash.  fail_cont_count and pending_recovery are atomic variables, and do not involve complex conditional logic. Therefore, even if recovery check and reconfig complete are executed concurrently, the recovery mechanism will not be broken.  Tested-on: QCA6174 hw3.2 PCI WLAN.RM.4.4.1-00288-QCARMSWPZ-1","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39746","epss":0.00155,"percentile":0.05009,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.081375},"relatedVulnerabilities":[{"id":"CVE-2025-39746","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39746","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/201c9b4485edc618863a60f97a2d88bddd139467","https://git.kernel.org/stable/c/84ca5632b8d05d1c2e25604d1d63434b2fb61c85","https://git.kernel.org/stable/c/c256a94d1b1b15109740306f7f2a7c2173e12072","https://git.kernel.org/stable/c/e36991bddf8be63e79659f654cdb1722db4e8132"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath10k: shutdown driver when hardware is unreliable\n\nIn rare cases, ath10k may lose connection with the PCIe bus due to\nsome unknown reasons, which could further lead to system crashes during\nresuming due to watchdog timeout:\n\nath10k_pci 0000:01:00.0: wmi command 20486 timeout, restarting hardware\nath10k_pci 0000:01:00.0: already restarting\nath10k_pci 0000:01:00.0: failed to stop WMI vdev 0: -11\nath10k_pci 0000:01:00.0: failed to stop vdev 0: -11\nieee80211 phy0: PM: **** DPM device timeout ****\nCall Trace:\n panic+0x125/0x315\n dpm_watchdog_set+0x54/0x54\n dpm_watchdog_handler+0x57/0x57\n call_timer_fn+0x31/0x13c\n\nAt this point, all WMI commands will timeout and attempt to restart\ndevice. So set a threshold for consecutive restart failures. If the\nthreshold is exceeded, consider the hardware is unreliable and all\nath10k operations should be skipped to avoid system crash.\n\nfail_cont_count and pending_recovery are atomic variables, and\ndo not involve complex conditional logic. Therefore, even if recovery\ncheck and reconfig complete are executed concurrently, the recovery\nmechanism will not be broken.\n\nTested-on: QCA6174 hw3.2 PCI WLAN.RM.4.4.1-00288-QCARMSWPZ-1","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39746","epss":0.00155,"percentile":0.05009,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39746","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39747","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39747","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm: Add error handling for krealloc in metadata setup  Function msm_ioctl_gem_info_set_metadata() now checks for krealloc failure and returns -ENOMEM, avoiding potential NULL pointer dereference. Explicitly avoids __GFP_NOFAIL due to deadlock risks and allocation constraints.  Patchwork: https://patchwork.freedesktop.org/patch/661235/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39747","epss":0.00155,"percentile":0.05,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39747","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.081375},"relatedVulnerabilities":[{"id":"CVE-2025-39747","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39747","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/01e3eda8edc3c4caaa49261d1a56c799b0bd6268","https://git.kernel.org/stable/c/1c8c354098ea9d4376a58c96ae6b65288a6f15d8","https://git.kernel.org/stable/c/53dc780c1e94ea782d8936b41bfaa83c663702eb","https://git.kernel.org/stable/c/d5386bcede7b57b193c658dcbb9d22004cde7580"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Add error handling for krealloc in metadata setup\n\nFunction msm_ioctl_gem_info_set_metadata() now checks for krealloc\nfailure and returns -ENOMEM, avoiding potential NULL pointer dereference.\nExplicitly avoids __GFP_NOFAIL due to deadlock risks and allocation constraints.\n\nPatchwork: https://patchwork.freedesktop.org/patch/661235/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39747","epss":0.00155,"percentile":0.05,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39747","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39747","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39754","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39754","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/smaps: fix race between smaps_hugetlb_range and migration  smaps_hugetlb_range() handles the pte without holdling ptl, and may be concurrenct with migration, leaing to BUG_ON in pfn_swap_entry_to_page().  The race is as follows.  smaps_hugetlb_range              migrate_pages   huge_ptep_get                                    remove_migration_ptes \t\t\t\t   folio_unlock   pfn_swap_entry_folio     BUG_ON  To fix it, hold ptl lock in smaps_hugetlb_range().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39754","epss":0.00111,"percentile":0.0147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39754","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05383500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-39754","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39754","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/09fc018f48871123ad5dbd7b03c956580232ed76","https://git.kernel.org/stable/c/2a1f3663974162b8f1e098196f557cfc1d160138","https://git.kernel.org/stable/c/45d19b4b6c2d422771c29b83462d84afcbb33f01","https://git.kernel.org/stable/c/b625883ccbcc2b57808db51d1375b1d7b9bcb3e5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/smaps: fix race between smaps_hugetlb_range and migration\n\nsmaps_hugetlb_range() handles the pte without holdling ptl, and may be\nconcurrenct with migration, leaing to BUG_ON in pfn_swap_entry_to_page(). \nThe race is as follows.\n\nsmaps_hugetlb_range              migrate_pages\n  huge_ptep_get\n                                   remove_migration_ptes\n\t\t\t\t   folio_unlock\n  pfn_swap_entry_folio\n    BUG_ON\n\nTo fix it, hold ptl lock in smaps_hugetlb_range().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39754","epss":0.00111,"percentile":0.0147,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39754","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39754","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39762","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39762","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: add null check  [WHY] Prevents null pointer dereferences to enhance function robustness  [HOW] Adds early null check and return false if invalid.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39762","epss":0.00154,"percentile":0.04823,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39762","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08084999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-39762","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39762","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/10d97cc1a14ef1f611e156b0b27e8b226e103cc2","https://git.kernel.org/stable/c/13895744e2c639324cf3cb18f2ba4e3f400dd0dd","https://git.kernel.org/stable/c/158b9201c17fc93ed4253c2f03b77fd2671669a1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: add null check\n\n[WHY]\nPrevents null pointer dereferences to enhance function robustness\n\n[HOW]\nAdds early null check and return false if invalid.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39762","epss":0.00154,"percentile":0.04823,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39762","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39762","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39767","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39767","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Optimize module load time by optimizing PLT/GOT counting  When enabling CONFIG_KASAN, CONFIG_PREEMPT_VOLUNTARY_BUILD and CONFIG_PREEMPT_VOLUNTARY at the same time, there will be soft deadlock, the relevant logs are as follows:  rcu: INFO: rcu_sched self-detected stall on CPU ... Call Trace: [<900000000024f9e4>] show_stack+0x5c/0x180 [<90000000002482f4>] dump_stack_lvl+0x94/0xbc [<9000000000224544>] rcu_dump_cpu_stacks+0x1fc/0x280 [<900000000037ac80>] rcu_sched_clock_irq+0x720/0xf88 [<9000000000396c34>] update_process_times+0xb4/0x150 [<90000000003b2474>] tick_nohz_handler+0xf4/0x250 [<9000000000397e28>] __hrtimer_run_queues+0x1d0/0x428 [<9000000000399b2c>] hrtimer_interrupt+0x214/0x538 [<9000000000253634>] constant_timer_interrupt+0x64/0x80 [<9000000000349938>] __handle_irq_event_percpu+0x78/0x1a0 [<9000000000349a78>] handle_irq_event_percpu+0x18/0x88 [<9000000000354c00>] handle_percpu_irq+0x90/0xf0 [<9000000000348c74>] handle_irq_desc+0x94/0xb8 [<9000000001012b28>] handle_cpu_irq+0x68/0xa0 [<9000000001def8c0>] handle_loongarch_irq+0x30/0x48 [<9000000001def958>] do_vint+0x80/0xd0 [<9000000000268a0c>] kasan_mem_to_shadow.part.0+0x2c/0x2a0 [<90000000006344f4>] __asan_load8+0x4c/0x120 [<900000000025c0d0>] module_frob_arch_sections+0x5c8/0x6b8 [<90000000003895f0>] load_module+0x9e0/0x2958 [<900000000038b770>] __do_sys_init_module+0x208/0x2d0 [<9000000001df0c34>] do_syscall+0x94/0x190 [<900000000024d6fc>] handle_syscall+0xbc/0x158  After analysis, this is because the slow speed of loading the amdgpu module leads to the long time occupation of the cpu and then the soft deadlock.  When loading a module, module_frob_arch_sections() tries to figure out the number of PLTs/GOTs that will be needed to handle all the RELAs. It will call the count_max_entries() to find in an out-of-order date which counting algorithm has O(n^2) complexity.  To make it faster, we sort the relocation list by info and addend. That way, to check for a duplicate relocation, it just needs to compare with the previous entry. This reduces the complexity of the algorithm to O(n  log n), as done in commit d4e0340919fb (\"arm64/module: Optimize module load time by optimizing PLT counting\"). This gives sinificant reduction in module load time for modules with large number of relocations.  After applying this patch, the soft deadlock problem has been solved, and the kernel starts normally without \"Call Trace\".  Using the default configuration to test some modules, the results are as follows:  Module              Size ip_tables           36K fat                 143K radeon              2.5MB amdgpu              16MB  Without this patch: Module              Module load time (ms)\tCount(PLTs/GOTs) ip_tables           18\t\t\t\t59/6 fat                 0\t\t\t\t162/14 radeon              54\t\t\t\t1221/84 amdgpu              1411\t\t\t4525/1098  With this patch: Module              Module load time (ms)\tCount(PLTs/GOTs) ip_tables           18\t\t\t\t59/6 fat                 0\t\t\t\t162/14 radeon              22\t\t\t\t1221/84 amdgpu              45\t\t\t\t4525/1098","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39767","epss":0.00113,"percentile":0.01612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39767","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059325},"relatedVulnerabilities":[{"id":"CVE-2025-39767","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39767","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5189c0b7c251363a4dd7678ed11b054c54f36f6f","https://git.kernel.org/stable/c/63dbd8fb2af3a89466538599a9acb2d11ef65c06","https://git.kernel.org/stable/c/a096b0280168d0c8b0ec1cbbfd56c8b81af8c7d8","https://git.kernel.org/stable/c/e94cdb9fb279430cbd323a74c7ec124c85109747"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Optimize module load time by optimizing PLT/GOT counting\n\nWhen enabling CONFIG_KASAN, CONFIG_PREEMPT_VOLUNTARY_BUILD and\nCONFIG_PREEMPT_VOLUNTARY at the same time, there will be soft deadlock,\nthe relevant logs are as follows:\n\nrcu: INFO: rcu_sched self-detected stall on CPU\n...\nCall Trace:\n[<900000000024f9e4>] show_stack+0x5c/0x180\n[<90000000002482f4>] dump_stack_lvl+0x94/0xbc\n[<9000000000224544>] rcu_dump_cpu_stacks+0x1fc/0x280\n[<900000000037ac80>] rcu_sched_clock_irq+0x720/0xf88\n[<9000000000396c34>] update_process_times+0xb4/0x150\n[<90000000003b2474>] tick_nohz_handler+0xf4/0x250\n[<9000000000397e28>] __hrtimer_run_queues+0x1d0/0x428\n[<9000000000399b2c>] hrtimer_interrupt+0x214/0x538\n[<9000000000253634>] constant_timer_interrupt+0x64/0x80\n[<9000000000349938>] __handle_irq_event_percpu+0x78/0x1a0\n[<9000000000349a78>] handle_irq_event_percpu+0x18/0x88\n[<9000000000354c00>] handle_percpu_irq+0x90/0xf0\n[<9000000000348c74>] handle_irq_desc+0x94/0xb8\n[<9000000001012b28>] handle_cpu_irq+0x68/0xa0\n[<9000000001def8c0>] handle_loongarch_irq+0x30/0x48\n[<9000000001def958>] do_vint+0x80/0xd0\n[<9000000000268a0c>] kasan_mem_to_shadow.part.0+0x2c/0x2a0\n[<90000000006344f4>] __asan_load8+0x4c/0x120\n[<900000000025c0d0>] module_frob_arch_sections+0x5c8/0x6b8\n[<90000000003895f0>] load_module+0x9e0/0x2958\n[<900000000038b770>] __do_sys_init_module+0x208/0x2d0\n[<9000000001df0c34>] do_syscall+0x94/0x190\n[<900000000024d6fc>] handle_syscall+0xbc/0x158\n\nAfter analysis, this is because the slow speed of loading the amdgpu\nmodule leads to the long time occupation of the cpu and then the soft\ndeadlock.\n\nWhen loading a module, module_frob_arch_sections() tries to figure out\nthe number of PLTs/GOTs that will be needed to handle all the RELAs. It\nwill call the count_max_entries() to find in an out-of-order date which\ncounting algorithm has O(n^2) complexity.\n\nTo make it faster, we sort the relocation list by info and addend. That\nway, to check for a duplicate relocation, it just needs to compare with\nthe previous entry. This reduces the complexity of the algorithm to O(n\n log n), as done in commit d4e0340919fb (\"arm64/module: Optimize module\nload time by optimizing PLT counting\"). This gives sinificant reduction\nin module load time for modules with large number of relocations.\n\nAfter applying this patch, the soft deadlock problem has been solved,\nand the kernel starts normally without \"Call Trace\".\n\nUsing the default configuration to test some modules, the results are as\nfollows:\n\nModule              Size\nip_tables           36K\nfat                 143K\nradeon              2.5MB\namdgpu              16MB\n\nWithout this patch:\nModule              Module load time (ms)\tCount(PLTs/GOTs)\nip_tables           18\t\t\t\t59/6\nfat                 0\t\t\t\t162/14\nradeon              54\t\t\t\t1221/84\namdgpu              1411\t\t\t4525/1098\n\nWith this patch:\nModule              Module load time (ms)\tCount(PLTs/GOTs)\nip_tables           18\t\t\t\t59/6\nfat                 0\t\t\t\t162/14\nradeon              22\t\t\t\t1221/84\namdgpu              45\t\t\t\t4525/1098","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39767","epss":0.00113,"percentile":0.01612,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39767","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39767","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39779","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39779","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: subpage: keep TOWRITE tag until folio is cleaned  btrfs_subpage_set_writeback() calls folio_start_writeback() the first time a folio is written back, and it also clears the PAGECACHE_TAG_TOWRITE tag even if there are still dirty blocks in the folio. This can break ordering guarantees, such as those required by btrfs_wait_ordered_extents().  That ordering breakage leads to a real failure. For example, running generic/464 on a zoned setup will hit the following ASSERT. This happens because the broken ordering fails to flush existing dirty pages before the file size is truncated.    assertion failed: !list_empty(&ordered->list) :: 0, in fs/btrfs/zoned.c:1899   ------------[ cut here ]------------   kernel BUG at fs/btrfs/zoned.c:1899!   Oops: invalid opcode: 0000 [#1] SMP NOPTI   CPU: 2 UID: 0 PID: 1906169 Comm: kworker/u130:2 Kdump: loaded Not tainted 6.16.0-rc6-BTRFS-ZNS+ #554 PREEMPT(voluntary)   Hardware name: Supermicro Super Server/H12SSL-NT, BIOS 2.0 02/22/2021   Workqueue: btrfs-endio-write btrfs_work_helper [btrfs]   RIP: 0010:btrfs_finish_ordered_zoned.cold+0x50/0x52 [btrfs]   RSP: 0018:ffffc9002efdbd60 EFLAGS: 00010246   RAX: 000000000000004c RBX: ffff88811923c4e0 RCX: 0000000000000000   RDX: 0000000000000000 RSI: ffffffff827e38b1 RDI: 00000000ffffffff   RBP: ffff88810005d000 R08: 00000000ffffdfff R09: ffffffff831051c8   R10: ffffffff83055220 R11: 0000000000000000 R12: ffff8881c2458c00   R13: ffff88811923c540 R14: ffff88811923c5e8 R15: ffff8881c1bd9680   FS:  0000000000000000(0000) GS:ffff88a04acd0000(0000) knlGS:0000000000000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   CR2: 00007f907c7a918c CR3: 0000000004024000 CR4: 0000000000350ef0   Call Trace:    <TASK>    ? srso_return_thunk+0x5/0x5f    btrfs_finish_ordered_io+0x4a/0x60 [btrfs]    btrfs_work_helper+0xf9/0x490 [btrfs]    process_one_work+0x204/0x590    ? srso_return_thunk+0x5/0x5f    worker_thread+0x1d6/0x3d0    ? __pfx_worker_thread+0x10/0x10    kthread+0x118/0x230    ? __pfx_kthread+0x10/0x10    ret_from_fork+0x205/0x260    ? __pfx_kthread+0x10/0x10    ret_from_fork_asm+0x1a/0x30    </TASK>  Consider process A calling writepages() with WB_SYNC_NONE. In zoned mode or for compressed writes, it locks several folios for delalloc and starts writing them out. Let's call the last locked folio folio X. Suppose the write range only partially covers folio X, leaving some pages dirty. Process A calls btrfs_subpage_set_writeback() when building a bio. This function call clears the TOWRITE tag of folio X, whose size = 8K and the block size = 4K. It is following state.     0     4K    8K    |/////|/////|  (flag: DIRTY, tag: DIRTY)    <-----> Process A will write this range.  Now suppose process B concurrently calls writepages() with WB_SYNC_ALL. It calls tag_pages_for_writeback() to tag dirty folios with PAGECACHE_TAG_TOWRITE. Since folio X is still dirty, it gets tagged. Then, B collects tagged folios using filemap_get_folios_tag() and must wait for folio X to be written before returning from writepages().     0     4K    8K    |/////|/////|  (flag: DIRTY, tag: DIRTY|TOWRITE)  However, between tagging and collecting, process A may call btrfs_subpage_set_writeback() and clear folio X's TOWRITE tag.    0     4K    8K    |     |/////|  (flag: DIRTY|WRITEBACK, tag: DIRTY)  As a result, process B won't see folio X in its batch, and returns without waiting for it. This breaks the WB_SYNC_ALL ordering requirement.  Fix this by using btrfs_subpage_set_writeback_keepwrite(), which retains the TOWRITE tag. We now manually clear the tag only after the folio becomes clean, via the xas operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39779","epss":0.00151,"percentile":0.04584,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07927500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-39779","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39779","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3d61136945a7008fc90d013c3c67007ce0c96131","https://git.kernel.org/stable/c/b1511360c8ac882b0c52caa263620538e8d73220","https://git.kernel.org/stable/c/bce7a5c77a1e7a759e227b7713dde18c52da4759"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: subpage: keep TOWRITE tag until folio is cleaned\n\nbtrfs_subpage_set_writeback() calls folio_start_writeback() the first time\na folio is written back, and it also clears the PAGECACHE_TAG_TOWRITE tag\neven if there are still dirty blocks in the folio. This can break ordering\nguarantees, such as those required by btrfs_wait_ordered_extents().\n\nThat ordering breakage leads to a real failure. For example, running\ngeneric/464 on a zoned setup will hit the following ASSERT. This happens\nbecause the broken ordering fails to flush existing dirty pages before the\nfile size is truncated.\n\n  assertion failed: !list_empty(&ordered->list) :: 0, in fs/btrfs/zoned.c:1899\n  ------------[ cut here ]------------\n  kernel BUG at fs/btrfs/zoned.c:1899!\n  Oops: invalid opcode: 0000 [#1] SMP NOPTI\n  CPU: 2 UID: 0 PID: 1906169 Comm: kworker/u130:2 Kdump: loaded Not tainted 6.16.0-rc6-BTRFS-ZNS+ #554 PREEMPT(voluntary)\n  Hardware name: Supermicro Super Server/H12SSL-NT, BIOS 2.0 02/22/2021\n  Workqueue: btrfs-endio-write btrfs_work_helper [btrfs]\n  RIP: 0010:btrfs_finish_ordered_zoned.cold+0x50/0x52 [btrfs]\n  RSP: 0018:ffffc9002efdbd60 EFLAGS: 00010246\n  RAX: 000000000000004c RBX: ffff88811923c4e0 RCX: 0000000000000000\n  RDX: 0000000000000000 RSI: ffffffff827e38b1 RDI: 00000000ffffffff\n  RBP: ffff88810005d000 R08: 00000000ffffdfff R09: ffffffff831051c8\n  R10: ffffffff83055220 R11: 0000000000000000 R12: ffff8881c2458c00\n  R13: ffff88811923c540 R14: ffff88811923c5e8 R15: ffff8881c1bd9680\n  FS:  0000000000000000(0000) GS:ffff88a04acd0000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007f907c7a918c CR3: 0000000004024000 CR4: 0000000000350ef0\n  Call Trace:\n   <TASK>\n   ? srso_return_thunk+0x5/0x5f\n   btrfs_finish_ordered_io+0x4a/0x60 [btrfs]\n   btrfs_work_helper+0xf9/0x490 [btrfs]\n   process_one_work+0x204/0x590\n   ? srso_return_thunk+0x5/0x5f\n   worker_thread+0x1d6/0x3d0\n   ? __pfx_worker_thread+0x10/0x10\n   kthread+0x118/0x230\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork+0x205/0x260\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork_asm+0x1a/0x30\n   </TASK>\n\nConsider process A calling writepages() with WB_SYNC_NONE. In zoned mode or\nfor compressed writes, it locks several folios for delalloc and starts\nwriting them out. Let's call the last locked folio folio X. Suppose the\nwrite range only partially covers folio X, leaving some pages dirty.\nProcess A calls btrfs_subpage_set_writeback() when building a bio. This\nfunction call clears the TOWRITE tag of folio X, whose size = 8K and\nthe block size = 4K. It is following state.\n\n   0     4K    8K\n   |/////|/////|  (flag: DIRTY, tag: DIRTY)\n   <-----> Process A will write this range.\n\nNow suppose process B concurrently calls writepages() with WB_SYNC_ALL. It\ncalls tag_pages_for_writeback() to tag dirty folios with\nPAGECACHE_TAG_TOWRITE. Since folio X is still dirty, it gets tagged. Then,\nB collects tagged folios using filemap_get_folios_tag() and must wait for\nfolio X to be written before returning from writepages().\n\n   0     4K    8K\n   |/////|/////|  (flag: DIRTY, tag: DIRTY|TOWRITE)\n\nHowever, between tagging and collecting, process A may call\nbtrfs_subpage_set_writeback() and clear folio X's TOWRITE tag.\n   0     4K    8K\n   |     |/////|  (flag: DIRTY|WRITEBACK, tag: DIRTY)\n\nAs a result, process B won't see folio X in its batch, and returns without\nwaiting for it. This breaks the WB_SYNC_ALL ordering requirement.\n\nFix this by using btrfs_subpage_set_writeback_keepwrite(), which retains\nthe TOWRITE tag. We now manually clear the tag only after the folio becomes\nclean, via the xas operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39779","epss":0.00151,"percentile":0.04584,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39779","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39789","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39789","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: x86/aegis - Add missing error checks  The skcipher_walk functions can allocate memory and can fail, so checking for errors is necessary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39789","epss":0.00134,"percentile":0.03262,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07035},"relatedVulnerabilities":[{"id":"CVE-2025-39789","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39789","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3d9eb180fbe8828cce43bce4c370124685b205c3","https://git.kernel.org/stable/c/475104178f4d30e749ee4f5473c87f692b93bebb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: x86/aegis - Add missing error checks\n\nThe skcipher_walk functions can allocate memory and can fail, so\nchecking for errors is necessary.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39789","epss":0.00134,"percentile":0.03262,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39789","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39797","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39797","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: Duplicate SPI Handling  The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI Netlink message, which triggers the kernel function xfrm_alloc_spi(). This function is expected to ensure uniqueness of the Security Parameter Index (SPI) for inbound Security Associations (SAs). However, it can return success even when the requested SPI is already in use, leading to duplicate SPIs assigned to multiple inbound SAs, differentiated only by their destination addresses.  This behavior causes inconsistencies during SPI lookups for inbound packets. Since the lookup may return an arbitrary SA among those with the same SPI, packet processing can fail, resulting in packet drops.  According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA is uniquely identified by the SPI and optionally protocol.  Reproducing the Issue Reliably: To consistently reproduce the problem, restrict the available SPI range in charon.conf : spi_min = 0x10000000 spi_max = 0x10000002 This limits the system to only 2 usable SPI values. Next, create more than 2 Child SA. each using unique pair of src/dst address. As soon as the 3rd Child SA is initiated, it will be assigned a duplicate SPI, since the SPI pool is already exhausted. With a narrow SPI range, the issue is consistently reproducible. With a broader/default range, it becomes rare and unpredictable.  Current implementation: xfrm_spi_hash() lookup function computes hash using daddr, proto, and family. So if two SAs have the same SPI but different destination addresses, then they will: a. Hash into different buckets b. Be stored in different linked lists (byspi + h) c. Not be seen in the same hlist_for_each_entry_rcu() iteration. As a result, the lookup will result in NULL and kernel allows that Duplicate SPI  Proposed Change: xfrm_state_lookup_spi_proto() does a truly global search - across all states, regardless of hash bucket and matches SPI and proto.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39797","epss":0.00156,"percentile":0.05053,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11934},"relatedVulnerabilities":[{"id":"CVE-2025-39797","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39797","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/29e9158f91f99057dbd35db5e8674d93b38549fe","https://git.kernel.org/stable/c/2fc5b54368a1bf1d2d74b4d3b8eea5309a653e38","https://git.kernel.org/stable/c/3d8090bb53424432fa788fe9a49e8ceca74f0544","https://git.kernel.org/stable/c/94f39804d891cffe4ce17737d295f3b195bc7299","https://git.kernel.org/stable/c/c67d4e7a8f90fb6361ca89d4d5c9a28f4e935e47"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Duplicate SPI Handling\n\nThe issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI\nNetlink message, which triggers the kernel function xfrm_alloc_spi().\nThis function is expected to ensure uniqueness of the Security Parameter\nIndex (SPI) for inbound Security Associations (SAs). However, it can\nreturn success even when the requested SPI is already in use, leading\nto duplicate SPIs assigned to multiple inbound SAs, differentiated\nonly by their destination addresses.\n\nThis behavior causes inconsistencies during SPI lookups for inbound packets.\nSince the lookup may return an arbitrary SA among those with the same SPI,\npacket processing can fail, resulting in packet drops.\n\nAccording to RFC 4301 section 4.4.2 , for inbound processing a unicast SA\nis uniquely identified by the SPI and optionally protocol.\n\nReproducing the Issue Reliably:\nTo consistently reproduce the problem, restrict the available SPI range in\ncharon.conf : spi_min = 0x10000000 spi_max = 0x10000002\nThis limits the system to only 2 usable SPI values.\nNext, create more than 2 Child SA. each using unique pair of src/dst address.\nAs soon as the 3rd Child SA is initiated, it will be assigned a duplicate\nSPI, since the SPI pool is already exhausted.\nWith a narrow SPI range, the issue is consistently reproducible.\nWith a broader/default range, it becomes rare and unpredictable.\n\nCurrent implementation:\nxfrm_spi_hash() lookup function computes hash using daddr, proto, and family.\nSo if two SAs have the same SPI but different destination addresses, then\nthey will:\na. Hash into different buckets\nb. Be stored in different linked lists (byspi + h)\nc. Not be seen in the same hlist_for_each_entry_rcu() iteration.\nAs a result, the lookup will result in NULL and kernel allows that Duplicate SPI\n\nProposed Change:\nxfrm_state_lookup_spi_proto() does a truly global search - across all states,\nregardless of hash bucket and matches SPI and proto.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39797","epss":0.00156,"percentile":0.05053,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39797","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39810","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39810","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bnxt_en: Fix memory corruption when FW resources change during ifdown  bnxt_set_dflt_rings() assumes that it is always called before any TC has been created.  So it doesn't take bp->num_tc into account and assumes that it is always 0 or 1.  In the FW resource or capability change scenario, the FW will return flags in bnxt_hwrm_if_change() that will cause the driver to reinitialize and call bnxt_cancel_reservations().  This will lead to bnxt_init_dflt_ring_mode() calling bnxt_set_dflt_rings() and bp->num_tc may be greater than 1.  This will cause bp->tx_ring[] to be sized too small and cause memory corruption in bnxt_alloc_cp_rings().  Fix it by properly scaling the TX rings by bp->num_tc in the code paths mentioned above.  Add 2 helper functions to determine bp->tx_nr_rings and bp->tx_nr_rings_per_tc.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39810","epss":0.00163,"percentile":0.05842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39810","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39810","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12469499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-39810","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39810","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2747328ba2714f1a7454208dbbc1dc0631990b4a","https://git.kernel.org/stable/c/9ab6a9950f152e094395d2e3967f889857daa185","https://git.kernel.org/stable/c/d00e98977ef519280b075d783653e2c492fffbb6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix memory corruption when FW resources change during ifdown\n\nbnxt_set_dflt_rings() assumes that it is always called before any TC has\nbeen created.  So it doesn't take bp->num_tc into account and assumes\nthat it is always 0 or 1.\n\nIn the FW resource or capability change scenario, the FW will return\nflags in bnxt_hwrm_if_change() that will cause the driver to\nreinitialize and call bnxt_cancel_reservations().  This will lead to\nbnxt_init_dflt_ring_mode() calling bnxt_set_dflt_rings() and bp->num_tc\nmay be greater than 1.  This will cause bp->tx_ring[] to be sized too\nsmall and cause memory corruption in bnxt_alloc_cp_rings().\n\nFix it by properly scaling the TX rings by bp->num_tc in the code\npaths mentioned above.  Add 2 helper functions to determine\nbp->tx_nr_rings and bp->tx_nr_rings_per_tc.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39810","epss":0.00163,"percentile":0.05842,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39810","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39810","cwe":"CWE-787","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39810","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39829","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39829","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  trace/fgraph: Fix the warning caused by missing unregister notifier  This warning was triggered during testing on v6.16:  notifier callback ftrace_suspend_notifier_call already registered WARNING: CPU: 2 PID: 86 at kernel/notifier.c:23 notifier_chain_register+0x44/0xb0 ... Call Trace:  <TASK>  blocking_notifier_chain_register+0x34/0x60  register_ftrace_graph+0x330/0x410  ftrace_profile_write+0x1e9/0x340  vfs_write+0xf8/0x420  ? filp_flush+0x8a/0xa0  ? filp_close+0x1f/0x30  ? do_dup2+0xaf/0x160  ksys_write+0x65/0xe0  do_syscall_64+0xa4/0x260  entry_SYSCALL_64_after_hwframe+0x77/0x7f  When writing to the function_profile_enabled interface, the notifier was not unregistered after start_graph_tracing failed, causing a warning the next time function_profile_enabled was written.  Fixed by adding unregister_pm_notifier in the exception path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39829","epss":0.00144,"percentile":0.04032,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0756},"relatedVulnerabilities":[{"id":"CVE-2025-39829","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39829","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/000aa47a51233fd38a629b029478e0278e1e9fbe","https://git.kernel.org/stable/c/2a2deb9f8df70480050351ac27041f19bb9e718b","https://git.kernel.org/stable/c/edede7a6dcd7435395cf757d053974aaab6ab1c2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntrace/fgraph: Fix the warning caused by missing unregister notifier\n\nThis warning was triggered during testing on v6.16:\n\nnotifier callback ftrace_suspend_notifier_call already registered\nWARNING: CPU: 2 PID: 86 at kernel/notifier.c:23 notifier_chain_register+0x44/0xb0\n...\nCall Trace:\n <TASK>\n blocking_notifier_chain_register+0x34/0x60\n register_ftrace_graph+0x330/0x410\n ftrace_profile_write+0x1e9/0x340\n vfs_write+0xf8/0x420\n ? filp_flush+0x8a/0xa0\n ? filp_close+0x1f/0x30\n ? do_dup2+0xaf/0x160\n ksys_write+0x65/0xe0\n do_syscall_64+0xa4/0x260\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nWhen writing to the function_profile_enabled interface, the notifier was\nnot unregistered after start_graph_tracing failed, causing a warning the\nnext time function_profile_enabled was written.\n\nFixed by adding unregister_pm_notifier in the exception path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39829","epss":0.00144,"percentile":0.04032,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39829","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39833","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39833","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mISDN: hfcpci: Fix warning when deleting uninitialized timer  With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads to the following splat:  [  250.215892] ODEBUG: assert_init not available (active state 0) object: ffffffffc01a3dc0 object type: timer_list hint: 0x0 [  250.217520] WARNING: CPU: 0 PID: 233 at lib/debugobjects.c:612 debug_print_object+0x1b6/0x2c0 [  250.218775] Modules linked in: hfcpci(-) mISDN_core [  250.219537] CPU: 0 UID: 0 PID: 233 Comm: rmmod Not tainted 6.17.0-rc2-g6f713187ac98 #2 PREEMPT(voluntary) [  250.220940] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [  250.222377] RIP: 0010:debug_print_object+0x1b6/0x2c0 [  250.223131] Code: fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 4f 41 56 48 8b 14 dd a0 4e 01 9f 48 89 ee 48 c7 c7 20 46 01 9f e8 cb 84d [  250.225805] RSP: 0018:ffff888015ea7c08 EFLAGS: 00010286 [  250.226608] RAX: 0000000000000000 RBX: 0000000000000005 RCX: ffffffff9be93a95 [  250.227708] RDX: 1ffff1100d945138 RSI: 0000000000000008 RDI: ffff88806ca289c0 [  250.228993] RBP: ffffffff9f014a00 R08: 0000000000000001 R09: ffffed1002bd4f39 [  250.230043] R10: ffff888015ea79cf R11: 0000000000000001 R12: 0000000000000001 [  250.231185] R13: ffffffff9eea0520 R14: 0000000000000000 R15: ffff888015ea7cc8 [  250.232454] FS:  00007f3208f01540(0000) GS:ffff8880caf5a000(0000) knlGS:0000000000000000 [  250.233851] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [  250.234856] CR2: 00007f32090a7421 CR3: 0000000004d63000 CR4: 00000000000006f0 [  250.236117] Call Trace: [  250.236599]  <TASK> [  250.236967]  ? trace_irq_enable.constprop.0+0xd4/0x130 [  250.237920]  debug_object_assert_init+0x1f6/0x310 [  250.238762]  ? __pfx_debug_object_assert_init+0x10/0x10 [  250.239658]  ? __lock_acquire+0xdea/0x1c70 [  250.240369]  __try_to_del_timer_sync+0x69/0x140 [  250.241172]  ? __pfx___try_to_del_timer_sync+0x10/0x10 [  250.242058]  ? __timer_delete_sync+0xc6/0x120 [  250.242842]  ? lock_acquire+0x30/0x80 [  250.243474]  ? __timer_delete_sync+0xc6/0x120 [  250.244262]  __timer_delete_sync+0x98/0x120 [  250.245015]  HFC_cleanup+0x10/0x20 [hfcpci] [  250.245704]  __do_sys_delete_module+0x348/0x510 [  250.246461]  ? __pfx___do_sys_delete_module+0x10/0x10 [  250.247338]  do_syscall_64+0xc1/0x360 [  250.247924]  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Fix this by initializing hfc_tl timer with DEFINE_TIMER macro. Also, use mod_timer instead of manual timeout update.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39833","epss":0.00145,"percentile":0.04073,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39833","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39833","cwe":"CWE-908","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.076125},"relatedVulnerabilities":[{"id":"CVE-2025-39833","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39833","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/43fc5da8133badf17f5df250ba03b9d882254845","https://git.kernel.org/stable/c/544ffd62ddd093c71150e4d4c542f98153fb8e46","https://git.kernel.org/stable/c/75194165e65018c581b128379b91b0b2d64638d9","https://git.kernel.org/stable/c/97766512a9951b9fd6fc97f1b93211642bb0b220","https://git.kernel.org/stable/c/d8be1288e398ccda2dc590fdaa0551f192f6a1c6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: hfcpci: Fix warning when deleting uninitialized timer\n\nWith CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads\nto the following splat:\n\n[  250.215892] ODEBUG: assert_init not available (active state 0) object: ffffffffc01a3dc0 object type: timer_list hint: 0x0\n[  250.217520] WARNING: CPU: 0 PID: 233 at lib/debugobjects.c:612 debug_print_object+0x1b6/0x2c0\n[  250.218775] Modules linked in: hfcpci(-) mISDN_core\n[  250.219537] CPU: 0 UID: 0 PID: 233 Comm: rmmod Not tainted 6.17.0-rc2-g6f713187ac98 #2 PREEMPT(voluntary)\n[  250.220940] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[  250.222377] RIP: 0010:debug_print_object+0x1b6/0x2c0\n[  250.223131] Code: fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 4f 41 56 48 8b 14 dd a0 4e 01 9f 48 89 ee 48 c7 c7 20 46 01 9f e8 cb 84d\n[  250.225805] RSP: 0018:ffff888015ea7c08 EFLAGS: 00010286\n[  250.226608] RAX: 0000000000000000 RBX: 0000000000000005 RCX: ffffffff9be93a95\n[  250.227708] RDX: 1ffff1100d945138 RSI: 0000000000000008 RDI: ffff88806ca289c0\n[  250.228993] RBP: ffffffff9f014a00 R08: 0000000000000001 R09: ffffed1002bd4f39\n[  250.230043] R10: ffff888015ea79cf R11: 0000000000000001 R12: 0000000000000001\n[  250.231185] R13: ffffffff9eea0520 R14: 0000000000000000 R15: ffff888015ea7cc8\n[  250.232454] FS:  00007f3208f01540(0000) GS:ffff8880caf5a000(0000) knlGS:0000000000000000\n[  250.233851] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  250.234856] CR2: 00007f32090a7421 CR3: 0000000004d63000 CR4: 00000000000006f0\n[  250.236117] Call Trace:\n[  250.236599]  <TASK>\n[  250.236967]  ? trace_irq_enable.constprop.0+0xd4/0x130\n[  250.237920]  debug_object_assert_init+0x1f6/0x310\n[  250.238762]  ? __pfx_debug_object_assert_init+0x10/0x10\n[  250.239658]  ? __lock_acquire+0xdea/0x1c70\n[  250.240369]  __try_to_del_timer_sync+0x69/0x140\n[  250.241172]  ? __pfx___try_to_del_timer_sync+0x10/0x10\n[  250.242058]  ? __timer_delete_sync+0xc6/0x120\n[  250.242842]  ? lock_acquire+0x30/0x80\n[  250.243474]  ? __timer_delete_sync+0xc6/0x120\n[  250.244262]  __timer_delete_sync+0x98/0x120\n[  250.245015]  HFC_cleanup+0x10/0x20 [hfcpci]\n[  250.245704]  __do_sys_delete_module+0x348/0x510\n[  250.246461]  ? __pfx___do_sys_delete_module+0x10/0x10\n[  250.247338]  do_syscall_64+0xc1/0x360\n[  250.247924]  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFix this by initializing hfc_tl timer with DEFINE_TIMER macro.\nAlso, use mod_timer instead of manual timeout update.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39833","epss":0.00145,"percentile":0.04073,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39833","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39833","cwe":"CWE-908","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39833","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39850","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39850","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects  When the \"proxy\" option is enabled on a VXLAN device, the device will suppress ARP requests and IPv6 Neighbor Solicitation messages if it is able to reply on behalf of the remote host. That is, if a matching and valid neighbor entry is configured on the VXLAN device whose MAC address is not behind the \"any\" remote (0.0.0.0 / ::).  The code currently assumes that the FDB entry for the neighbor's MAC address points to a valid remote destination, but this is incorrect if the entry is associated with an FDB nexthop group. This can result in a NPD [1][3] which can be reproduced using [2][4].  Fix by checking that the remote destination exists before dereferencing it.  [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] CPU: 4 UID: 0 PID: 365 Comm: arping Not tainted 6.17.0-rc2-virtme-g2a89cb21162c #2 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014 RIP: 0010:vxlan_xmit+0xb58/0x15f0 [...] Call Trace:  <TASK>  dev_hard_start_xmit+0x5d/0x1c0  __dev_queue_xmit+0x246/0xfd0  packet_sendmsg+0x113a/0x1850  __sock_sendmsg+0x38/0x70  __sys_sendto+0x126/0x180  __x64_sys_sendto+0x24/0x30  do_syscall_64+0xa4/0x260  entry_SYSCALL_64_after_hwframe+0x4b/0x53  [2]  #!/bin/bash   ip address add 192.0.2.1/32 dev lo   ip nexthop add id 1 via 192.0.2.2 fdb  ip nexthop add id 10 group 1 fdb   ip link add name vx0 up type vxlan id 10010 local 192.0.2.1 dstport 4789 proxy   ip neigh add 192.0.2.3 lladdr 00:11:22:33:44:55 nud perm dev vx0   bridge fdb add 00:11:22:33:44:55 dev vx0 self static nhid 10   arping -b -c 1 -s 192.0.2.1 -I vx0 192.0.2.3  [3] BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] CPU: 13 UID: 0 PID: 372 Comm: ndisc6 Not tainted 6.17.0-rc2-virtmne-g6ee90cb26014 #3 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1v996), BIOS 1.17.0-4.fc41 04/01/2x014 RIP: 0010:vxlan_xmit+0x803/0x1600 [...] Call Trace:  <TASK>  dev_hard_start_xmit+0x5d/0x1c0  __dev_queue_xmit+0x246/0xfd0  ip6_finish_output2+0x210/0x6c0  ip6_finish_output+0x1af/0x2b0  ip6_mr_output+0x92/0x3e0  ip6_send_skb+0x30/0x90  rawv6_sendmsg+0xe6e/0x12e0  __sock_sendmsg+0x38/0x70  __sys_sendto+0x126/0x180  __x64_sys_sendto+0x24/0x30  do_syscall_64+0xa4/0x260  entry_SYSCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7f383422ec77  [4]  #!/bin/bash   ip address add 2001:db8:1::1/128 dev lo   ip nexthop add id 1 via 2001:db8:1::1 fdb  ip nexthop add id 10 group 1 fdb   ip link add name vx0 up type vxlan id 10010 local 2001:db8:1::1 dstport 4789 proxy   ip neigh add 2001:db8:1::3 lladdr 00:11:22:33:44:55 nud perm dev vx0   bridge fdb add 00:11:22:33:44:55 dev vx0 self static nhid 10   ndisc6 -r 1 -s 2001:db8:1::1 -w 1 2001:db8:1::3 vx0","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39850","epss":0.00144,"percentile":0.04032,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39850","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39850","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0756},"relatedVulnerabilities":[{"id":"CVE-2025-39850","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39850","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1f5d2fd1ca04a23c18b1bde9a43ce2fa2ffa1bce","https://git.kernel.org/stable/c/8cfa0f076842f9b3b4eb52ae0e41d16e25cbf8fa","https://git.kernel.org/stable/c/e211e3f4199ac829bd493632efcd131d337cba9d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects\n\nWhen the \"proxy\" option is enabled on a VXLAN device, the device will\nsuppress ARP requests and IPv6 Neighbor Solicitation messages if it is\nable to reply on behalf of the remote host. That is, if a matching and\nvalid neighbor entry is configured on the VXLAN device whose MAC address\nis not behind the \"any\" remote (0.0.0.0 / ::).\n\nThe code currently assumes that the FDB entry for the neighbor's MAC\naddress points to a valid remote destination, but this is incorrect if\nthe entry is associated with an FDB nexthop group. This can result in a\nNPD [1][3] which can be reproduced using [2][4].\n\nFix by checking that the remote destination exists before dereferencing\nit.\n\n[1]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n[...]\nCPU: 4 UID: 0 PID: 365 Comm: arping Not tainted 6.17.0-rc2-virtme-g2a89cb21162c #2 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014\nRIP: 0010:vxlan_xmit+0xb58/0x15f0\n[...]\nCall Trace:\n <TASK>\n dev_hard_start_xmit+0x5d/0x1c0\n __dev_queue_xmit+0x246/0xfd0\n packet_sendmsg+0x113a/0x1850\n __sock_sendmsg+0x38/0x70\n __sys_sendto+0x126/0x180\n __x64_sys_sendto+0x24/0x30\n do_syscall_64+0xa4/0x260\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n[2]\n #!/bin/bash\n\n ip address add 192.0.2.1/32 dev lo\n\n ip nexthop add id 1 via 192.0.2.2 fdb\n ip nexthop add id 10 group 1 fdb\n\n ip link add name vx0 up type vxlan id 10010 local 192.0.2.1 dstport 4789 proxy\n\n ip neigh add 192.0.2.3 lladdr 00:11:22:33:44:55 nud perm dev vx0\n\n bridge fdb add 00:11:22:33:44:55 dev vx0 self static nhid 10\n\n arping -b -c 1 -s 192.0.2.1 -I vx0 192.0.2.3\n\n[3]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n[...]\nCPU: 13 UID: 0 PID: 372 Comm: ndisc6 Not tainted 6.17.0-rc2-virtmne-g6ee90cb26014 #3 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1v996), BIOS 1.17.0-4.fc41 04/01/2x014\nRIP: 0010:vxlan_xmit+0x803/0x1600\n[...]\nCall Trace:\n <TASK>\n dev_hard_start_xmit+0x5d/0x1c0\n __dev_queue_xmit+0x246/0xfd0\n ip6_finish_output2+0x210/0x6c0\n ip6_finish_output+0x1af/0x2b0\n ip6_mr_output+0x92/0x3e0\n ip6_send_skb+0x30/0x90\n rawv6_sendmsg+0xe6e/0x12e0\n __sock_sendmsg+0x38/0x70\n __sys_sendto+0x126/0x180\n __x64_sys_sendto+0x24/0x30\n do_syscall_64+0xa4/0x260\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\nRIP: 0033:0x7f383422ec77\n\n[4]\n #!/bin/bash\n\n ip address add 2001:db8:1::1/128 dev lo\n\n ip nexthop add id 1 via 2001:db8:1::1 fdb\n ip nexthop add id 10 group 1 fdb\n\n ip link add name vx0 up type vxlan id 10010 local 2001:db8:1::1 dstport 4789 proxy\n\n ip neigh add 2001:db8:1::3 lladdr 00:11:22:33:44:55 nud perm dev vx0\n\n bridge fdb add 00:11:22:33:44:55 dev vx0 self static nhid 10\n\n ndisc6 -r 1 -s 2001:db8:1::1 -w 1 2001:db8:1::3 vx0","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39850","epss":0.00144,"percentile":0.04032,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39850","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39850","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39850","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39851","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39851","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: Fix NPD when refreshing an FDB entry with a nexthop object  VXLAN FDB entries can point to either a remote destination or an FDB nexthop group. The latter is usually used in EVPN deployments where learning is disabled.  However, when learning is enabled, an incoming packet might try to refresh an FDB entry that points to an FDB nexthop group and therefore does not have a remote. Such packets should be dropped, but they are only dropped after dereferencing the non-existent remote, resulting in a NPD [1] which can be reproduced using [2].  Fix by dropping such packets earlier. Remove the misleading comment from first_remote_rcu().  [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] CPU: 13 UID: 0 PID: 361 Comm: mausezahn Not tainted 6.17.0-rc1-virtme-g9f6b606b6b37 #1 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014 RIP: 0010:vxlan_snoop+0x98/0x1e0 [...] Call Trace:  <TASK>  vxlan_encap_bypass+0x209/0x240  encap_bypass_if_local+0xb1/0x100  vxlan_xmit_one+0x1375/0x17e0  vxlan_xmit+0x6b4/0x15f0  dev_hard_start_xmit+0x5d/0x1c0  __dev_queue_xmit+0x246/0xfd0  packet_sendmsg+0x113a/0x1850  __sock_sendmsg+0x38/0x70  __sys_sendto+0x126/0x180  __x64_sys_sendto+0x24/0x30  do_syscall_64+0xa4/0x260  entry_SYSCALL_64_after_hwframe+0x4b/0x53  [2]  #!/bin/bash   ip address add 192.0.2.1/32 dev lo  ip address add 192.0.2.2/32 dev lo   ip nexthop add id 1 via 192.0.2.3 fdb  ip nexthop add id 10 group 1 fdb   ip link add name vx0 up type vxlan id 10010 local 192.0.2.1 dstport 12345 localbypass  ip link add name vx1 up type vxlan id 10020 local 192.0.2.2 dstport 54321 learning   bridge fdb add 00:11:22:33:44:55 dev vx0 self static dst 192.0.2.2 port 54321 vni 10020  bridge fdb add 00:aa:bb:cc:dd:ee dev vx1 self static nhid 10   mausezahn vx0 -a 00:aa:bb:cc:dd:ee -b 00:11:22:33:44:55 -c 1 -q","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39851","epss":0.00293,"percentile":0.21729,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39851","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39851","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.153825},"relatedVulnerabilities":[{"id":"CVE-2025-39851","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39851","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0e8630f24c14d9c655d19eabe2e52a9e9f713307","https://git.kernel.org/stable/c/4ff4f3104da6507e0f118c63c4560dfdeb59dce3","https://git.kernel.org/stable/c/6ead38147ebb813f08be6ea8ef547a0e4c09559a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: Fix NPD when refreshing an FDB entry with a nexthop object\n\nVXLAN FDB entries can point to either a remote destination or an FDB\nnexthop group. The latter is usually used in EVPN deployments where\nlearning is disabled.\n\nHowever, when learning is enabled, an incoming packet might try to\nrefresh an FDB entry that points to an FDB nexthop group and therefore\ndoes not have a remote. Such packets should be dropped, but they are\nonly dropped after dereferencing the non-existent remote, resulting in a\nNPD [1] which can be reproduced using [2].\n\nFix by dropping such packets earlier. Remove the misleading comment from\nfirst_remote_rcu().\n\n[1]\nBUG: kernel NULL pointer dereference, address: 0000000000000000\n[...]\nCPU: 13 UID: 0 PID: 361 Comm: mausezahn Not tainted 6.17.0-rc1-virtme-g9f6b606b6b37 #1 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014\nRIP: 0010:vxlan_snoop+0x98/0x1e0\n[...]\nCall Trace:\n <TASK>\n vxlan_encap_bypass+0x209/0x240\n encap_bypass_if_local+0xb1/0x100\n vxlan_xmit_one+0x1375/0x17e0\n vxlan_xmit+0x6b4/0x15f0\n dev_hard_start_xmit+0x5d/0x1c0\n __dev_queue_xmit+0x246/0xfd0\n packet_sendmsg+0x113a/0x1850\n __sock_sendmsg+0x38/0x70\n __sys_sendto+0x126/0x180\n __x64_sys_sendto+0x24/0x30\n do_syscall_64+0xa4/0x260\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n[2]\n #!/bin/bash\n\n ip address add 192.0.2.1/32 dev lo\n ip address add 192.0.2.2/32 dev lo\n\n ip nexthop add id 1 via 192.0.2.3 fdb\n ip nexthop add id 10 group 1 fdb\n\n ip link add name vx0 up type vxlan id 10010 local 192.0.2.1 dstport 12345 localbypass\n ip link add name vx1 up type vxlan id 10020 local 192.0.2.2 dstport 54321 learning\n\n bridge fdb add 00:11:22:33:44:55 dev vx0 self static dst 192.0.2.2 port 54321 vni 10020\n bridge fdb add 00:aa:bb:cc:dd:ee dev vx1 self static nhid 10\n\n mausezahn vx0 -a 00:aa:bb:cc:dd:ee -b 00:11:22:33:44:55 -c 1 -q","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39851","epss":0.00293,"percentile":0.21729,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39851","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39851","cwe":"CWE-476","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39851","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39859","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39859","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog  The ptp_ocp_detach() only shuts down the watchdog timer if it is pending. However, if the timer handler is already running, the timer_delete_sync() is not called. This leads to race conditions where the devlink that contains the ptp_ocp is deallocated while the timer handler is still accessing it, resulting in use-after-free bugs. The following details one of the race scenarios.  (thread 1)                           | (thread 2) ptp_ocp_remove()                     |   ptp_ocp_detach()                   | ptp_ocp_watchdog()     if (timer_pending(&bp->watchdog))|   bp = timer_container_of()       timer_delete_sync()            |                                      |   devlink_free(devlink) //free       |                                      |   bp-> //use  Resolve this by unconditionally calling timer_delete_sync() to ensure the timer is reliably deactivated, preventing any access after free.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39859","epss":0.00146,"percentile":0.04169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39859","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39859","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11168999999999998},"relatedVulnerabilities":[{"id":"CVE-2025-39859","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39859","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/8bf935cf789872350b04c1a6468b0a509f67afb2","https://git.kernel.org/stable/c/f10d3c7267ac7387a5129d5506c3c5f2460cfd9b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog\n\nThe ptp_ocp_detach() only shuts down the watchdog timer if it is\npending. However, if the timer handler is already running, the\ntimer_delete_sync() is not called. This leads to race conditions\nwhere the devlink that contains the ptp_ocp is deallocated while\nthe timer handler is still accessing it, resulting in use-after-free\nbugs. The following details one of the race scenarios.\n\n(thread 1)                           | (thread 2)\nptp_ocp_remove()                     |\n  ptp_ocp_detach()                   | ptp_ocp_watchdog()\n    if (timer_pending(&bp->watchdog))|   bp = timer_container_of()\n      timer_delete_sync()            |\n                                     |\n  devlink_free(devlink) //free       |\n                                     |   bp-> //use\n\nResolve this by unconditionally calling timer_delete_sync() to ensure\nthe timer is reliably deactivated, preventing any access after free.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39859","epss":0.00146,"percentile":0.04169,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39859","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39859","cwe":"CWE-416","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39859","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39886","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39886","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init()  Currently, calling bpf_map_kmalloc_node() from __bpf_async_init() can cause various locking issues; see the following stack trace (edited for style) as one example:  ...  [10.011566]  do_raw_spin_lock.cold  [10.011570]  try_to_wake_up             (5) double-acquiring the same  [10.011575]  kick_pool                      rq_lock, causing a hardlockup  [10.011579]  __queue_work  [10.011582]  queue_work_on  [10.011585]  kernfs_notify  [10.011589]  cgroup_file_notify  [10.011593]  try_charge_memcg           (4) memcg accounting raises an  [10.011597]  obj_cgroup_charge_pages        MEMCG_MAX event  [10.011599]  obj_cgroup_charge_account  [10.011600]  __memcg_slab_post_alloc_hook  [10.011603]  __kmalloc_node_noprof ...  [10.011611]  bpf_map_kmalloc_node  [10.011612]  __bpf_async_init  [10.011615]  bpf_timer_init             (3) BPF calls bpf_timer_init()  [10.011617]  bpf_prog_xxxxxxxxxxxxxxxx_fcg_runnable  [10.011619]  bpf__sched_ext_ops_runnable  [10.011620]  enqueue_task_scx           (2) BPF runs with rq_lock held  [10.011622]  enqueue_task  [10.011626]  ttwu_do_activate  [10.011629]  sched_ttwu_pending         (1) grabs rq_lock ...  The above was reproduced on bpf-next (b338cf849ec8) by modifying ./tools/sched_ext/scx_flatcg.bpf.c to call bpf_timer_init() during ops.runnable(), and hacking the memcg accounting code a bit to make a bpf_timer_init() call more likely to raise an MEMCG_MAX event.  We have also run into other similar variants (both internally and on bpf-next), including double-acquiring cgroup_file_kn_lock, the same worker_pool::lock, etc.  As suggested by Shakeel, fix this by using __GFP_HIGH instead of GFP_ATOMIC in __bpf_async_init(), so that e.g. if try_charge_memcg() raises an MEMCG_MAX event, we call __memcg_memory_event() with @allow_spinning=false and avoid calling cgroup_file_notify() there.  Depends on mm patch \"memcg: skip cgroup_file_notify if spinning is not allowed\": https://lore.kernel.org/bpf/20250905201606.66198-1-shakeel.butt@linux.dev/  v0 approach s/bpf_map_kmalloc_node/bpf_mem_alloc/ https://lore.kernel.org/bpf/20250905061919.439648-1-yepeilin@google.com/ v1 approach: https://lore.kernel.org/bpf/20250905234547.862249-1-yepeilin@google.com/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39886","epss":0.00149,"percentile":0.04423,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.078225},"relatedVulnerabilities":[{"id":"CVE-2025-39886","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39886","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/449682e76f32601f211816d3e2100bed87e67a4c","https://git.kernel.org/stable/c/6d78b4473cdb08b74662355a9e8510bde09c511e","https://git.kernel.org/stable/c/ac70cd446f83ccb25532b343919ab86eacdcd06a","https://git.kernel.org/stable/c/cd1fd26bb13473c1734e3026b2b97025a0a4087b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Tell memcg to use allow_spinning=false path in bpf_timer_init()\n\nCurrently, calling bpf_map_kmalloc_node() from __bpf_async_init() can\ncause various locking issues; see the following stack trace (edited for\nstyle) as one example:\n\n...\n [10.011566]  do_raw_spin_lock.cold\n [10.011570]  try_to_wake_up             (5) double-acquiring the same\n [10.011575]  kick_pool                      rq_lock, causing a hardlockup\n [10.011579]  __queue_work\n [10.011582]  queue_work_on\n [10.011585]  kernfs_notify\n [10.011589]  cgroup_file_notify\n [10.011593]  try_charge_memcg           (4) memcg accounting raises an\n [10.011597]  obj_cgroup_charge_pages        MEMCG_MAX event\n [10.011599]  obj_cgroup_charge_account\n [10.011600]  __memcg_slab_post_alloc_hook\n [10.011603]  __kmalloc_node_noprof\n...\n [10.011611]  bpf_map_kmalloc_node\n [10.011612]  __bpf_async_init\n [10.011615]  bpf_timer_init             (3) BPF calls bpf_timer_init()\n [10.011617]  bpf_prog_xxxxxxxxxxxxxxxx_fcg_runnable\n [10.011619]  bpf__sched_ext_ops_runnable\n [10.011620]  enqueue_task_scx           (2) BPF runs with rq_lock held\n [10.011622]  enqueue_task\n [10.011626]  ttwu_do_activate\n [10.011629]  sched_ttwu_pending         (1) grabs rq_lock\n...\n\nThe above was reproduced on bpf-next (b338cf849ec8) by modifying\n./tools/sched_ext/scx_flatcg.bpf.c to call bpf_timer_init() during\nops.runnable(), and hacking the memcg accounting code a bit to make\na bpf_timer_init() call more likely to raise an MEMCG_MAX event.\n\nWe have also run into other similar variants (both internally and on\nbpf-next), including double-acquiring cgroup_file_kn_lock, the same\nworker_pool::lock, etc.\n\nAs suggested by Shakeel, fix this by using __GFP_HIGH instead of\nGFP_ATOMIC in __bpf_async_init(), so that e.g. if try_charge_memcg()\nraises an MEMCG_MAX event, we call __memcg_memory_event() with\n@allow_spinning=false and avoid calling cgroup_file_notify() there.\n\nDepends on mm patch\n\"memcg: skip cgroup_file_notify if spinning is not allowed\":\nhttps://lore.kernel.org/bpf/20250905201606.66198-1-shakeel.butt@linux.dev/\n\nv0 approach s/bpf_map_kmalloc_node/bpf_mem_alloc/\nhttps://lore.kernel.org/bpf/20250905061919.439648-1-yepeilin@google.com/\nv1 approach:\nhttps://lore.kernel.org/bpf/20250905234547.862249-1-yepeilin@google.com/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39886","epss":0.00149,"percentile":0.04423,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39886","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39901","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39901","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i40e: remove read access to debugfs files  The 'command' and 'netdev_ops' debugfs files are a legacy debugging interface supported by the i40e driver since its early days by commit 02e9c290814c (\"i40e: debugfs interface\").  Both of these debugfs files provide a read handler which is mostly useless, and which is implemented with questionable logic. They both use a static 256 byte buffer which is initialized to the empty string. In the case of the 'command' file this buffer is literally never used and simply wastes space. In the case of the 'netdev_ops' file, the last command written is saved here.  On read, the files contents are presented as the name of the device followed by a colon and then the contents of their respective static buffer. For 'command' this will always be \"<device>: \". For 'netdev_ops', this will be \"<device>: <last command written>\". But note the buffer is shared between all devices operated by this module. At best, it is mostly meaningless information, and at worse it could be accessed simultaneously as there doesn't appear to be any locking mechanism.  We have also recently received multiple reports for both read functions about their use of snprintf and potential overflow that could result in reading arbitrary kernel memory. For the 'command' file, this is definitely impossible, since the static buffer is always zero and never written to. For the 'netdev_ops' file, it does appear to be possible, if the user carefully crafts the command input, it will be copied into the buffer, which could be large enough to cause snprintf to truncate, which then causes the copy_to_user to read beyond the length of the buffer allocated by kzalloc.  A minimal fix would be to replace snprintf() with scnprintf() which would cap the return to the number of bytes written, preventing an overflow. A more involved fix would be to drop the mostly useless static buffers, saving 512 bytes and modifying the read functions to stop needing those as input.  Instead, lets just completely drop the read access to these files. These are debug interfaces exposed as part of debugfs, and I don't believe that dropping read access will break any script, as the provided output is pretty useless. You can find the netdev name through other more standard interfaces, and the 'netdev_ops' interface can easily result in garbage if you issue simultaneous writes to multiple devices at once.  In order to properly remove the i40e_dbg_netdev_ops_buf, we need to refactor its write function to avoid using the static buffer. Instead, use the same logic as the i40e_dbg_command_write, with an allocated buffer. Update the code to use this instead of the static buffer, and ensure we free the buffer on exit. This fixes simultaneous writes to 'netdev_ops' on multiple devices, and allows us to remove the now unused static buffer along with removing the read access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39901","epss":0.00153,"percentile":0.04739,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39901","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39901","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11168999999999998},"relatedVulnerabilities":[{"id":"CVE-2025-39901","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39901","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6fd8b30a5cb84d74015bc651799d1ab1e047946c","https://git.kernel.org/stable/c/70d3dad7d5ad077965d7a63eed1942b7ba49bfb4","https://git.kernel.org/stable/c/7d190963b80f4cd99d7008615600aa7cc993c6ba","https://git.kernel.org/stable/c/9fcdb1c3c4ba134434694c001dbff343f1ffa319","https://git.kernel.org/stable/c/ef40d9411469306e524e7887c51b709377e6ef65"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: remove read access to debugfs files\n\nThe 'command' and 'netdev_ops' debugfs files are a legacy debugging\ninterface supported by the i40e driver since its early days by commit\n02e9c290814c (\"i40e: debugfs interface\").\n\nBoth of these debugfs files provide a read handler which is mostly useless,\nand which is implemented with questionable logic. They both use a static\n256 byte buffer which is initialized to the empty string. In the case of\nthe 'command' file this buffer is literally never used and simply wastes\nspace. In the case of the 'netdev_ops' file, the last command written is\nsaved here.\n\nOn read, the files contents are presented as the name of the device\nfollowed by a colon and then the contents of their respective static\nbuffer. For 'command' this will always be \"<device>: \". For 'netdev_ops',\nthis will be \"<device>: <last command written>\". But note the buffer is\nshared between all devices operated by this module. At best, it is mostly\nmeaningless information, and at worse it could be accessed simultaneously\nas there doesn't appear to be any locking mechanism.\n\nWe have also recently received multiple reports for both read functions\nabout their use of snprintf and potential overflow that could result in\nreading arbitrary kernel memory. For the 'command' file, this is definitely\nimpossible, since the static buffer is always zero and never written to.\nFor the 'netdev_ops' file, it does appear to be possible, if the user\ncarefully crafts the command input, it will be copied into the buffer,\nwhich could be large enough to cause snprintf to truncate, which then\ncauses the copy_to_user to read beyond the length of the buffer allocated\nby kzalloc.\n\nA minimal fix would be to replace snprintf() with scnprintf() which would\ncap the return to the number of bytes written, preventing an overflow. A\nmore involved fix would be to drop the mostly useless static buffers,\nsaving 512 bytes and modifying the read functions to stop needing those as\ninput.\n\nInstead, lets just completely drop the read access to these files. These\nare debug interfaces exposed as part of debugfs, and I don't believe that\ndropping read access will break any script, as the provided output is\npretty useless. You can find the netdev name through other more standard\ninterfaces, and the 'netdev_ops' interface can easily result in garbage if\nyou issue simultaneous writes to multiple devices at once.\n\nIn order to properly remove the i40e_dbg_netdev_ops_buf, we need to\nrefactor its write function to avoid using the static buffer. Instead, use\nthe same logic as the i40e_dbg_command_write, with an allocated buffer.\nUpdate the code to use this instead of the static buffer, and ensure we\nfree the buffer on exit. This fixes simultaneous writes to 'netdev_ops' on\nmultiple devices, and allows us to remove the now unused static buffer\nalong with removing the read access.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39901","epss":0.00153,"percentile":0.04739,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39901","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39901","cwe":"CWE-125","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39901","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39910","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39910","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc()  kasan_populate_vmalloc() and its helpers ignore the caller's gfp_mask and always allocate memory using the hardcoded GFP_KERNEL flag.  This makes them inconsistent with vmalloc(), which was recently extended to support GFP_NOFS and GFP_NOIO allocations.  Page table allocations performed during shadow population also ignore the external gfp_mask.  To preserve the intended semantics of GFP_NOFS and GFP_NOIO, wrap the apply_to_page_range() calls into the appropriate memalloc scope.  xfs calls vmalloc with GFP_NOFS, so this bug could lead to deadlock.  There was a report here https://lkml.kernel.org/r/686ea951.050a0220.385921.0016.GAE@google.com  This patch:  - Extends kasan_populate_vmalloc() and helpers to take gfp_mask;  - Passes gfp_mask down to alloc_pages_bulk() and __get_free_page();  - Enforces GFP_NOFS/NOIO semantics with memalloc_*_save()/restore()    around apply_to_page_range();  - Updates vmalloc.c and percpu allocator call sites accordingly.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39910","epss":0.00101,"percentile":0.00972,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39910","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39910","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.053025},"relatedVulnerabilities":[{"id":"CVE-2025-39910","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39910","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/33b95d90427cb4babf32059e323a6d0c027610fe","https://git.kernel.org/stable/c/79357cd06d41d0f5a11b17d7c86176e395d10ef2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc()\n\nkasan_populate_vmalloc() and its helpers ignore the caller's gfp_mask and\nalways allocate memory using the hardcoded GFP_KERNEL flag.  This makes\nthem inconsistent with vmalloc(), which was recently extended to support\nGFP_NOFS and GFP_NOIO allocations.\n\nPage table allocations performed during shadow population also ignore the\nexternal gfp_mask.  To preserve the intended semantics of GFP_NOFS and\nGFP_NOIO, wrap the apply_to_page_range() calls into the appropriate\nmemalloc scope.\n\nxfs calls vmalloc with GFP_NOFS, so this bug could lead to deadlock.\n\nThere was a report here\nhttps://lkml.kernel.org/r/686ea951.050a0220.385921.0016.GAE@google.com\n\nThis patch:\n - Extends kasan_populate_vmalloc() and helpers to take gfp_mask;\n - Passes gfp_mask down to alloc_pages_bulk() and __get_free_page();\n - Enforces GFP_NOFS/NOIO semantics with memalloc_*_save()/restore()\n   around apply_to_page_range();\n - Updates vmalloc.c and percpu allocator call sites accordingly.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39910","epss":0.00101,"percentile":0.00972,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39910","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39910","cwe":"CWE-667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39910","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39925","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39925","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: j1939: implement NETDEV_UNREGISTER notification handler  syzbot is reporting    unregister_netdevice: waiting for vcan0 to become free. Usage count = 2  problem, for j1939 protocol did not have NETDEV_UNREGISTER notification handler for undoing changes made by j1939_sk_bind().  Commit 25fe97cb7620 (\"can: j1939: move j1939_priv_put() into sk_destruct callback\") expects that a call to j1939_priv_put() can be unconditionally delayed until j1939_sk_sock_destruct() is called. But we need to call j1939_priv_put() against an extra ref held by j1939_sk_bind() call (as a part of undoing changes made by j1939_sk_bind()) as soon as NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct() is called via j1939_sk_release()). Otherwise, the extra ref on \"struct j1939_priv\" held by j1939_sk_bind() call prevents \"struct net_device\" from dropping the usage count to 1; making it impossible for unregister_netdevice() to continue.  [mkl: remove space in front of label]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39925","epss":0.00147,"percentile":0.04237,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.077175},"relatedVulnerabilities":[{"id":"CVE-2025-39925","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39925","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2c88069fac2c792e228e6a4ae71c9b9b5b9a87a6","https://git.kernel.org/stable/c/479d8a2aedcc1db16f14c1a8a9c74b5bdf18b9ac","https://git.kernel.org/stable/c/4e154cb5e7681c2910e2dfa09f05e3469e333745","https://git.kernel.org/stable/c/76957b618ce729c3bd1e782fbc9d9991af653925","https://git.kernel.org/stable/c/7fcbe5b2c6a4b5407bf2241fdb71e0a390f6ab9a","https://git.kernel.org/stable/c/da9e8f429139928570407e8f90559b5d46c20262"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: implement NETDEV_UNREGISTER notification handler\n\nsyzbot is reporting\n\n  unregister_netdevice: waiting for vcan0 to become free. Usage count = 2\n\nproblem, for j1939 protocol did not have NETDEV_UNREGISTER notification\nhandler for undoing changes made by j1939_sk_bind().\n\nCommit 25fe97cb7620 (\"can: j1939: move j1939_priv_put() into sk_destruct\ncallback\") expects that a call to j1939_priv_put() can be unconditionally\ndelayed until j1939_sk_sock_destruct() is called. But we need to call\nj1939_priv_put() against an extra ref held by j1939_sk_bind() call\n(as a part of undoing changes made by j1939_sk_bind()) as soon as\nNETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct()\nis called via j1939_sk_release()). Otherwise, the extra ref on \"struct\nj1939_priv\" held by j1939_sk_bind() call prevents \"struct net_device\" from\ndropping the usage count to 1; making it impossible for\nunregister_netdevice() to continue.\n\n[mkl: remove space in front of label]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39925","epss":0.00147,"percentile":0.04237,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39925","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39927","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39927","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ceph: fix race condition validating r_parent before applying state  Add validation to ensure the cached parent directory inode matches the directory info in MDS replies. This prevents client-side race conditions where concurrent operations (e.g. rename) cause r_parent to become stale between request initiation and reply processing, which could lead to applying state changes to incorrect directory inodes.  [ idryomov: folded a kerneldoc fixup and a follow-up fix from Alex to   move CEPH_CAP_PIN reference when r_parent is updated:    When the parent directory lock is not held, req->r_parent can become   stale and is updated to point to the correct inode.  However, the   associated CEPH_CAP_PIN reference was not being adjusted.  The   CEPH_CAP_PIN is a reference on an inode that is tracked for   accounting purposes.  Moving this pin is important to keep the   accounting balanced. When the pin was not moved from the old parent   to the new one, it created two problems: The reference on the old,   stale parent was never released, causing a reference leak.   A reference for the new parent was never acquired, creating the risk   of a reference underflow later in ceph_mdsc_release_request().  This   patch corrects the logic by releasing the pin from the old parent and   acquiring it for the new parent when r_parent is switched.  This   ensures reference accounting stays balanced. ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39927","epss":0.00113,"percentile":0.01569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39927","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39927","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05480499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-39927","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39927","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/15f519e9f883b316d86e2bb6b767a023aafd9d83","https://git.kernel.org/stable/c/2bfe45987eb346e299d9f763f9cd05f77011519f","https://git.kernel.org/stable/c/db378e6f83ec705c6091c65d482d555edc2b0a72"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix race condition validating r_parent before applying state\n\nAdd validation to ensure the cached parent directory inode matches the\ndirectory info in MDS replies. This prevents client-side race conditions\nwhere concurrent operations (e.g. rename) cause r_parent to become stale\nbetween request initiation and reply processing, which could lead to\napplying state changes to incorrect directory inodes.\n\n[ idryomov: folded a kerneldoc fixup and a follow-up fix from Alex to\n  move CEPH_CAP_PIN reference when r_parent is updated:\n\n  When the parent directory lock is not held, req->r_parent can become\n  stale and is updated to point to the correct inode.  However, the\n  associated CEPH_CAP_PIN reference was not being adjusted.  The\n  CEPH_CAP_PIN is a reference on an inode that is tracked for\n  accounting purposes.  Moving this pin is important to keep the\n  accounting balanced. When the pin was not moved from the old parent\n  to the new one, it created two problems: The reference on the old,\n  stale parent was never released, causing a reference leak.\n  A reference for the new parent was never acquired, creating the risk\n  of a reference underflow later in ceph_mdsc_release_request().  This\n  patch corrects the logic by releasing the pin from the old parent and\n  acquiring it for the new parent when r_parent is switched.  This\n  ensures reference accounting stays balanced. ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39927","epss":0.00113,"percentile":0.01569,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39927","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2025-39927","cwe":"CWE-362","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39927","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39932","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39932","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)  In smbd_destroy() we may destroy the memory so we better wait until post_send_credits_work is no longer pending and will never be started again.  I actually just hit the case using rxe:  WARNING: CPU: 0 PID: 138 at drivers/infiniband/sw/rxe/rxe_verbs.c:1032 rxe_post_recv+0x1ee/0x480 [rdma_rxe] ... [ 5305.686979] [    T138]  smbd_post_recv+0x445/0xc10 [cifs] [ 5305.687135] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687149] [    T138]  ? __kasan_check_write+0x14/0x30 [ 5305.687185] [    T138]  ? __pfx_smbd_post_recv+0x10/0x10 [cifs] [ 5305.687329] [    T138]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10 [ 5305.687356] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687368] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687378] [    T138]  ? _raw_spin_unlock_irqrestore+0x11/0x60 [ 5305.687389] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687399] [    T138]  ? get_receive_buffer+0x168/0x210 [cifs] [ 5305.687555] [    T138]  smbd_post_send_credits+0x382/0x4b0 [cifs] [ 5305.687701] [    T138]  ? __pfx_smbd_post_send_credits+0x10/0x10 [cifs] [ 5305.687855] [    T138]  ? __pfx___schedule+0x10/0x10 [ 5305.687865] [    T138]  ? __pfx__raw_spin_lock_irq+0x10/0x10 [ 5305.687875] [    T138]  ? queue_delayed_work_on+0x8e/0xa0 [ 5305.687889] [    T138]  process_one_work+0x629/0xf80 [ 5305.687908] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5 [ 5305.687917] [    T138]  ? __kasan_check_write+0x14/0x30 [ 5305.687933] [    T138]  worker_thread+0x87f/0x1570 ...  It means rxe_post_recv was called after rdma_destroy_qp(). This happened because put_receive_buffer() was triggered by ib_drain_qp() and called: queue_work(info->workqueue, &info->post_send_credits_work);","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39932","epss":0.00289,"percentile":0.21245,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15172500000000003},"relatedVulnerabilities":[{"id":"CVE-2025-39932","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39932","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3fabb1236f2e3ad78d531be0a4ad9f4a4ccdda87","https://git.kernel.org/stable/c/6ae90a2baf923e85eb037b636aa641250bf4220f","https://git.kernel.org/stable/c/d9dcbbcf9145b68aa85c40947311a6907277e097"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)\n\nIn smbd_destroy() we may destroy the memory so we better\nwait until post_send_credits_work is no longer pending\nand will never be started again.\n\nI actually just hit the case using rxe:\n\nWARNING: CPU: 0 PID: 138 at drivers/infiniband/sw/rxe/rxe_verbs.c:1032 rxe_post_recv+0x1ee/0x480 [rdma_rxe]\n...\n[ 5305.686979] [    T138]  smbd_post_recv+0x445/0xc10 [cifs]\n[ 5305.687135] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5\n[ 5305.687149] [    T138]  ? __kasan_check_write+0x14/0x30\n[ 5305.687185] [    T138]  ? __pfx_smbd_post_recv+0x10/0x10 [cifs]\n[ 5305.687329] [    T138]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n[ 5305.687356] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5\n[ 5305.687368] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5\n[ 5305.687378] [    T138]  ? _raw_spin_unlock_irqrestore+0x11/0x60\n[ 5305.687389] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5\n[ 5305.687399] [    T138]  ? get_receive_buffer+0x168/0x210 [cifs]\n[ 5305.687555] [    T138]  smbd_post_send_credits+0x382/0x4b0 [cifs]\n[ 5305.687701] [    T138]  ? __pfx_smbd_post_send_credits+0x10/0x10 [cifs]\n[ 5305.687855] [    T138]  ? __pfx___schedule+0x10/0x10\n[ 5305.687865] [    T138]  ? __pfx__raw_spin_lock_irq+0x10/0x10\n[ 5305.687875] [    T138]  ? queue_delayed_work_on+0x8e/0xa0\n[ 5305.687889] [    T138]  process_one_work+0x629/0xf80\n[ 5305.687908] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5\n[ 5305.687917] [    T138]  ? __kasan_check_write+0x14/0x30\n[ 5305.687933] [    T138]  worker_thread+0x87f/0x1570\n...\n\nIt means rxe_post_recv was called after rdma_destroy_qp().\nThis happened because put_receive_buffer() was triggered\nby ib_drain_qp() and called:\nqueue_work(info->workqueue, &info->post_send_credits_work);","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39932","epss":0.00289,"percentile":0.21245,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39932","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39933","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39933","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: let recv_done verify data_offset, data_length and remaining_data_length  This is inspired by the related server fixes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39933","epss":0.00209,"percentile":0.11075,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10972499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-39933","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39933","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/581fb78e0388b78911b0c920e4073737090c8b5f","https://git.kernel.org/stable/c/f57e53ea252363234f86674db475839e5b87102e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: let recv_done verify data_offset, data_length and remaining_data_length\n\nThis is inspired by the related server fixes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":9.4,"exploitabilityScore":3.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39933","epss":0.00209,"percentile":0.11075,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39933","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39940","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm-stripe: fix a possible integer overflow  There's a possible integer overflow in stripe_io_hints if we have too large chunk size. Test if the overflow happened, and if it did, don't set limits->io_min and limits->io_opt;","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39940","epss":0.00144,"percentile":0.04033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39940","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0756},"relatedVulnerabilities":[{"id":"CVE-2025-39940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39940","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1071d560afb4c245c2076494226df47db5a35708","https://git.kernel.org/stable/c/ee27658c239b27721397f3e4eb16370b5cce596e","https://git.kernel.org/stable/c/f8f64254bca5ae58f3b679441962bda4c409f659"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-stripe: fix a possible integer overflow\n\nThere's a possible integer overflow in stripe_io_hints if we have too\nlarge chunk size. Test if the overflow happened, and if it did, don't set\nlimits->io_min and limits->io_opt;","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39940","epss":0.00144,"percentile":0.04033,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39940","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39947","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39947","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Harden uplink netdev access against device unbind  The function mlx5_uplink_netdev_get() gets the uplink netdevice pointer from mdev->mlx5e_res.uplink_netdev. However, the netdevice can be removed and its pointer cleared when unbound from the mlx5_core.eth driver. This results in a NULL pointer, causing a kernel panic.   BUG: unable to handle page fault for address: 0000000000001300  at RIP: 0010:mlx5e_vport_rep_load+0x22a/0x270 [mlx5_core]  Call Trace:   <TASK>   mlx5_esw_offloads_rep_load+0x68/0xe0 [mlx5_core]   esw_offloads_enable+0x593/0x910 [mlx5_core]   mlx5_eswitch_enable_locked+0x341/0x420 [mlx5_core]   mlx5_devlink_eswitch_mode_set+0x17e/0x3a0 [mlx5_core]   devlink_nl_eswitch_set_doit+0x60/0xd0   genl_family_rcv_msg_doit+0xe0/0x130   genl_rcv_msg+0x183/0x290   netlink_rcv_skb+0x4b/0xf0   genl_rcv+0x24/0x40   netlink_unicast+0x255/0x380   netlink_sendmsg+0x1f3/0x420   __sock_sendmsg+0x38/0x60   __sys_sendto+0x119/0x180   do_syscall_64+0x53/0x1d0   entry_SYSCALL_64_after_hwframe+0x4b/0x53  Ensure the pointer is valid before use by checking it for NULL. If it is valid, immediately call netdev_hold() to take a reference, and preventing the netdevice from being freed while it is in use.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39947","epss":0.00146,"percentile":0.04178,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39947","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07665000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-39947","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39947","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2cb17c88edd3a1c7aa6bc880dcdb35a6866fcb2e","https://git.kernel.org/stable/c/6b4be64fd9fec16418f365c2d8e47a7566e9eba5","https://git.kernel.org/stable/c/8df354eb2dd63d111ed5ae2e956e0dbb22bcf93b","https://git.kernel.org/stable/c/d1f3db4e7a3be29fc17f01850f162363f919370d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Harden uplink netdev access against device unbind\n\nThe function mlx5_uplink_netdev_get() gets the uplink netdevice\npointer from mdev->mlx5e_res.uplink_netdev. However, the netdevice can\nbe removed and its pointer cleared when unbound from the mlx5_core.eth\ndriver. This results in a NULL pointer, causing a kernel panic.\n\n BUG: unable to handle page fault for address: 0000000000001300\n at RIP: 0010:mlx5e_vport_rep_load+0x22a/0x270 [mlx5_core]\n Call Trace:\n  <TASK>\n  mlx5_esw_offloads_rep_load+0x68/0xe0 [mlx5_core]\n  esw_offloads_enable+0x593/0x910 [mlx5_core]\n  mlx5_eswitch_enable_locked+0x341/0x420 [mlx5_core]\n  mlx5_devlink_eswitch_mode_set+0x17e/0x3a0 [mlx5_core]\n  devlink_nl_eswitch_set_doit+0x60/0xd0\n  genl_family_rcv_msg_doit+0xe0/0x130\n  genl_rcv_msg+0x183/0x290\n  netlink_rcv_skb+0x4b/0xf0\n  genl_rcv+0x24/0x40\n  netlink_unicast+0x255/0x380\n  netlink_sendmsg+0x1f3/0x420\n  __sock_sendmsg+0x38/0x60\n  __sys_sendto+0x119/0x180\n  do_syscall_64+0x53/0x1d0\n  entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nEnsure the pointer is valid before use by checking it for NULL. If it\nis valid, immediately call netdev_hold() to take a reference, and\npreventing the netdevice from being freed while it is in use.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39947","epss":0.00146,"percentile":0.04178,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39947","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39947","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39952","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39952","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: wilc1000: avoid buffer overflow in WID string configuration  Fix the following copy overflow warning identified by Smatch checker.   drivers/net/wireless/microchip/wilc1000/wlan_cfg.c:184 wilc_wlan_parse_response_frame()         error: '__memcpy()' 'cfg->s[i]->str' copy overflow (512 vs 65537)  This patch introduces size check before accessing the memory buffer. The checks are base on the WID type of received data from the firmware. For WID string configuration, the size limit is determined by individual element size in 'struct wilc_cfg_str_vals' that is maintained in 'len' field of 'struct wilc_cfg_str'.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39952","epss":0.00228,"percentile":0.13534,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39952","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17442},"relatedVulnerabilities":[{"id":"CVE-2025-39952","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39952","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2203ef417044b10a8563ade6a17c74183745d72e","https://git.kernel.org/stable/c/6085291a1a5865d4ad70f0e5812d524ebd5d1711","https://git.kernel.org/stable/c/ae50f8562306a7ea1cf3c9722f97ee244f974729","https://git.kernel.org/stable/c/fe9e4d0c39311d0f97b024147a0d155333f388b5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: avoid buffer overflow in WID string configuration\n\nFix the following copy overflow warning identified by Smatch checker.\n\n drivers/net/wireless/microchip/wilc1000/wlan_cfg.c:184 wilc_wlan_parse_response_frame()\n        error: '__memcpy()' 'cfg->s[i]->str' copy overflow (512 vs 65537)\n\nThis patch introduces size check before accessing the memory buffer.\nThe checks are base on the WID type of received data from the firmware.\nFor WID string configuration, the size limit is determined by individual\nelement size in 'struct wilc_cfg_str_vals' that is maintained in 'len' field\nof 'struct wilc_cfg_str'.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39952","epss":0.00228,"percentile":0.13534,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39952","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39952","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39961","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/amd/pgtbl: Fix possible race while increase page table level  The AMD IOMMU host page table implementation supports dynamic page table levels (up to 6 levels), starting with a 3-level configuration that expands based on IOVA address. The kernel maintains a root pointer and current page table level to enable proper page table walks in alloc_pte()/fetch_pte() operations.  The IOMMU IOVA allocator initially starts with 32-bit address and onces its exhuasted it switches to 64-bit address (max address is determined based on IOMMU and device DMA capability). To support larger IOVA, AMD IOMMU driver increases page table level.  But in unmap path (iommu_v1_unmap_pages()), fetch_pte() reads pgtable->[root/mode] without lock. So its possible that in exteme corner case, when increase_address_space() is updating pgtable->[root/mode], fetch_pte() reads wrong page table level (pgtable->mode). It does compare the value with level encoded in page table and returns NULL. This will result is iommu_unmap ops to fail and upper layer may retry/log WARN_ON.  CPU 0                                         CPU 1 ------                                       ------ map pages                                    unmap pages alloc_pte() -> increase_address_space()      iommu_v1_unmap_pages() -> fetch_pte()   pgtable->root = pte (new root value)                                              READ pgtable->[mode/root] \t\t\t\t\t       Reads new root, old mode   Updates mode (pgtable->mode += 1)  Since Page table level updates are infrequent and already synchronized with a spinlock, implement seqcount to enable lock-free read operations on the read path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39961","epss":0.00115,"percentile":0.01727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39961","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.055775},"relatedVulnerabilities":[{"id":"CVE-2025-39961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39961","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/075abf0b1a958acfbea2435003d228e738e90346","https://git.kernel.org/stable/c/1e56310b40fd2e7e0b9493da9ff488af145bdd0c","https://git.kernel.org/stable/c/7d462bdecb7d9c32934dab44aaeb7ea7d73a27a2","https://git.kernel.org/stable/c/cd92c8ab336c3a633d46e6f35ebcd3509ae7db3b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd/pgtbl: Fix possible race while increase page table level\n\nThe AMD IOMMU host page table implementation supports dynamic page table levels\n(up to 6 levels), starting with a 3-level configuration that expands based on\nIOVA address. The kernel maintains a root pointer and current page table level\nto enable proper page table walks in alloc_pte()/fetch_pte() operations.\n\nThe IOMMU IOVA allocator initially starts with 32-bit address and onces its\nexhuasted it switches to 64-bit address (max address is determined based\non IOMMU and device DMA capability). To support larger IOVA, AMD IOMMU\ndriver increases page table level.\n\nBut in unmap path (iommu_v1_unmap_pages()), fetch_pte() reads\npgtable->[root/mode] without lock. So its possible that in exteme corner case,\nwhen increase_address_space() is updating pgtable->[root/mode], fetch_pte()\nreads wrong page table level (pgtable->mode). It does compare the value with\nlevel encoded in page table and returns NULL. This will result is\niommu_unmap ops to fail and upper layer may retry/log WARN_ON.\n\nCPU 0                                         CPU 1\n------                                       ------\nmap pages                                    unmap pages\nalloc_pte() -> increase_address_space()      iommu_v1_unmap_pages() -> fetch_pte()\n  pgtable->root = pte (new root value)\n                                             READ pgtable->[mode/root]\n\t\t\t\t\t       Reads new root, old mode\n  Updates mode (pgtable->mode += 1)\n\nSince Page table level updates are infrequent and already synchronized with a\nspinlock, implement seqcount to enable lock-free read operations on the read path.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39961","epss":0.00115,"percentile":0.01727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39961","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39981","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39981","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: MGMT: Fix possible UAFs  This attemps to fix possible UAFs caused by struct mgmt_pending being freed while still being processed like in the following trace, in order to fix mgmt_pending_valid is introduce and use to check if the mgmt_pending hasn't been removed from the pending list, on the complete callbacks it is used to check and in addtion remove the cmd from the list while holding mgmt_pending_lock to avoid TOCTOU problems since if the cmd is left on the list it can still be accessed and freed.  BUG: KASAN: slab-use-after-free in mgmt_add_adv_patterns_monitor_sync+0x35/0x50 net/bluetooth/mgmt.c:5223 Read of size 8 at addr ffff8880709d4dc0 by task kworker/u11:0/55  CPU: 0 UID: 0 PID: 55 Comm: kworker/u11:0 Not tainted 6.16.4 #2 PREEMPT(full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1ubuntu1 04/01/2014 Workqueue: hci0 hci_cmd_sync_work Call Trace:  <TASK>  dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:378 [inline]  print_report+0xca/0x240 mm/kasan/report.c:482  kasan_report+0x118/0x150 mm/kasan/report.c:595  mgmt_add_adv_patterns_monitor_sync+0x35/0x50 net/bluetooth/mgmt.c:5223  hci_cmd_sync_work+0x210/0x3a0 net/bluetooth/hci_sync.c:332  process_one_work kernel/workqueue.c:3238 [inline]  process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3321  worker_thread+0x8a0/0xda0 kernel/workqueue.c:3402  kthread+0x711/0x8a0 kernel/kthread.c:464  ret_from_fork+0x3fc/0x770 arch/x86/kernel/process.c:148  ret_from_fork_asm+0x1a/0x30 home/kwqcheii/source/fuzzing/kernel/kasan/linux-6.16.4/arch/x86/entry/entry_64.S:245  </TASK>  Allocated by task 12210:  kasan_save_stack mm/kasan/common.c:47 [inline]  kasan_save_track+0x3e/0x80 mm/kasan/common.c:68  poison_kmalloc_redzone mm/kasan/common.c:377 [inline]  __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:394  kasan_kmalloc include/linux/kasan.h:260 [inline]  __kmalloc_cache_noprof+0x230/0x3d0 mm/slub.c:4364  kmalloc_noprof include/linux/slab.h:905 [inline]  kzalloc_noprof include/linux/slab.h:1039 [inline]  mgmt_pending_new+0x65/0x1e0 net/bluetooth/mgmt_util.c:269  mgmt_pending_add+0x35/0x140 net/bluetooth/mgmt_util.c:296  __add_adv_patterns_monitor+0x130/0x200 net/bluetooth/mgmt.c:5247  add_adv_patterns_monitor+0x214/0x360 net/bluetooth/mgmt.c:5364  hci_mgmt_cmd+0x9c9/0xef0 net/bluetooth/hci_sock.c:1719  hci_sock_sendmsg+0x6ca/0xef0 net/bluetooth/hci_sock.c:1839  sock_sendmsg_nosec net/socket.c:714 [inline]  __sock_sendmsg+0x219/0x270 net/socket.c:729  sock_write_iter+0x258/0x330 net/socket.c:1133  new_sync_write fs/read_write.c:593 [inline]  vfs_write+0x5c9/0xb30 fs/read_write.c:686  ksys_write+0x145/0x250 fs/read_write.c:738  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Freed by task 12221:  kasan_save_stack mm/kasan/common.c:47 [inline]  kasan_save_track+0x3e/0x80 mm/kasan/common.c:68  kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:576  poison_slab_object mm/kasan/common.c:247 [inline]  __kasan_slab_free+0x62/0x70 mm/kasan/common.c:264  kasan_slab_free include/linux/kasan.h:233 [inline]  slab_free_hook mm/slub.c:2381 [inline]  slab_free mm/slub.c:4648 [inline]  kfree+0x18e/0x440 mm/slub.c:4847  mgmt_pending_free net/bluetooth/mgmt_util.c:311 [inline]  mgmt_pending_foreach+0x30d/0x380 net/bluetooth/mgmt_util.c:257  __mgmt_power_off+0x169/0x350 net/bluetooth/mgmt.c:9444  hci_dev_close_sync+0x754/0x1330 net/bluetooth/hci_sync.c:5290  hci_dev_do_close net/bluetooth/hci_core.c:501 [inline]  hci_dev_close+0x108/0x200 net/bluetooth/hci_core.c:526  sock_do_ioctl+0xd9/0x300 net/socket.c:1192  sock_ioctl+0x576/0x790 net/socket.c:1313  vfs_ioctl fs/ioctl.c:51 [inline]  __do_sys_ioctl fs/ioctl.c:907 [inline]  __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:893  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0xf ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39981","epss":0.0014,"percentile":0.03642,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10709999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-39981","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39981","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b60eb04b8524e1b4b3f07fea0d16fda9a677d9a","https://git.kernel.org/stable/c/302a1f674c00dd5581ab8e493ef44767c5101aab","https://git.kernel.org/stable/c/87a1f16f07c6c43771754075e08f45b41d237421","https://git.kernel.org/stable/c/d71b98f253b079cbadc83266383f26fe7e9e103b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix possible UAFs\n\nThis attemps to fix possible UAFs caused by struct mgmt_pending being\nfreed while still being processed like in the following trace, in order\nto fix mgmt_pending_valid is introduce and use to check if the\nmgmt_pending hasn't been removed from the pending list, on the complete\ncallbacks it is used to check and in addtion remove the cmd from the list\nwhile holding mgmt_pending_lock to avoid TOCTOU problems since if the cmd\nis left on the list it can still be accessed and freed.\n\nBUG: KASAN: slab-use-after-free in mgmt_add_adv_patterns_monitor_sync+0x35/0x50 net/bluetooth/mgmt.c:5223\nRead of size 8 at addr ffff8880709d4dc0 by task kworker/u11:0/55\n\nCPU: 0 UID: 0 PID: 55 Comm: kworker/u11:0 Not tainted 6.16.4 #2 PREEMPT(full)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1ubuntu1 04/01/2014\nWorkqueue: hci0 hci_cmd_sync_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n mgmt_add_adv_patterns_monitor_sync+0x35/0x50 net/bluetooth/mgmt.c:5223\n hci_cmd_sync_work+0x210/0x3a0 net/bluetooth/hci_sync.c:332\n process_one_work kernel/workqueue.c:3238 [inline]\n process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3321\n worker_thread+0x8a0/0xda0 kernel/workqueue.c:3402\n kthread+0x711/0x8a0 kernel/kthread.c:464\n ret_from_fork+0x3fc/0x770 arch/x86/kernel/process.c:148\n ret_from_fork_asm+0x1a/0x30 home/kwqcheii/source/fuzzing/kernel/kasan/linux-6.16.4/arch/x86/entry/entry_64.S:245\n </TASK>\n\nAllocated by task 12210:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x230/0x3d0 mm/slub.c:4364\n kmalloc_noprof include/linux/slab.h:905 [inline]\n kzalloc_noprof include/linux/slab.h:1039 [inline]\n mgmt_pending_new+0x65/0x1e0 net/bluetooth/mgmt_util.c:269\n mgmt_pending_add+0x35/0x140 net/bluetooth/mgmt_util.c:296\n __add_adv_patterns_monitor+0x130/0x200 net/bluetooth/mgmt.c:5247\n add_adv_patterns_monitor+0x214/0x360 net/bluetooth/mgmt.c:5364\n hci_mgmt_cmd+0x9c9/0xef0 net/bluetooth/hci_sock.c:1719\n hci_sock_sendmsg+0x6ca/0xef0 net/bluetooth/hci_sock.c:1839\n sock_sendmsg_nosec net/socket.c:714 [inline]\n __sock_sendmsg+0x219/0x270 net/socket.c:729\n sock_write_iter+0x258/0x330 net/socket.c:1133\n new_sync_write fs/read_write.c:593 [inline]\n vfs_write+0x5c9/0xb30 fs/read_write.c:686\n ksys_write+0x145/0x250 fs/read_write.c:738\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 12221:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:576\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x62/0x70 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline]\n slab_free_hook mm/slub.c:2381 [inline]\n slab_free mm/slub.c:4648 [inline]\n kfree+0x18e/0x440 mm/slub.c:4847\n mgmt_pending_free net/bluetooth/mgmt_util.c:311 [inline]\n mgmt_pending_foreach+0x30d/0x380 net/bluetooth/mgmt_util.c:257\n __mgmt_power_off+0x169/0x350 net/bluetooth/mgmt.c:9444\n hci_dev_close_sync+0x754/0x1330 net/bluetooth/hci_sync.c:5290\n hci_dev_do_close net/bluetooth/hci_core.c:501 [inline]\n hci_dev_close+0x108/0x200 net/bluetooth/hci_core.c:526\n sock_do_ioctl+0xd9/0x300 net/socket.c:1192\n sock_ioctl+0x576/0x790 net/socket.c:1313\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xf\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39981","epss":0.0014,"percentile":0.03642,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39981","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39989","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39989","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  x86/mce: use is_copy_from_user() to determine copy-from-user context  Patch series \"mm/hwpoison: Fix regressions in memory failure handling\", v4.  ## 1. What am I trying to do:  This patchset resolves two critical regressions related to memory failure handling that have appeared in the upstream kernel since version 5.17, as compared to 5.10 LTS.      - copyin case: poison found in user page while kernel copying from user space     - instr case: poison found while instruction fetching in user space  ## 2. What is the expected outcome and why  - For copyin case:  Kernel can recover from poison found where kernel is doing get_user() or copy_from_user() if those places get an error return and the kernel return -EFAULT to the process instead of crashing.  More specifily, MCE handler checks the fixup handler type to decide whether an in kernel #MC can be recovered.  When EX_TYPE_UACCESS is found, the PC jumps to recovery code specified in _ASM_EXTABLE_FAULT() and return a -EFAULT to user space.  - For instr case:  If a poison found while instruction fetching in user space, full recovery is possible.  User process takes #PF, Linux allocates a new page and fills by reading from storage.   ## 3. What actually happens and why  - For copyin case: kernel panic since v5.17  Commit 4c132d1d844a (\"x86/futex: Remove .fixup usage\") introduced a new extable fixup type, EX_TYPE_EFAULT_REG, and later patches updated the extable fixup type for copy-from-user operations, changing it from EX_TYPE_UACCESS to EX_TYPE_EFAULT_REG.  It breaks previous EX_TYPE_UACCESS handling when posion found in get_user() or copy_from_user().  - For instr case: user process is killed by a SIGBUS signal due to #CMCI   and #MCE race  When an uncorrected memory error is consumed there is a race between the CMCI from the memory controller reporting an uncorrected error with a UCNA signature, and the core reporting and SRAR signature machine check when the data is about to be consumed.  ### Background: why *UN*corrected errors tied to *C*MCI in Intel platform [1]  Prior to Icelake memory controllers reported patrol scrub events that detected a previously unseen uncorrected error in memory by signaling a broadcast machine check with an SRAO (Software Recoverable Action Optional) signature in the machine check bank.  This was overkill because it's not an urgent problem that no core is on the verge of consuming that bad data.  It's also found that multi SRAO UCE may cause nested MCE interrupts and finally become an IERR.  Hence, Intel downgrades the machine check bank signature of patrol scrub from SRAO to UCNA (Uncorrected, No Action required), and signal changed to #CMCI.  Just to add to the confusion, Linux does take an action (in uc_decode_notifier()) to try to offline the page despite the UC*NA* signature name.  ### Background: why #CMCI and #MCE race when poison is consuming in     Intel platform [1]  Having decided that CMCI/UCNA is the best action for patrol scrub errors, the memory controller uses it for reads too.  But the memory controller is executing asynchronously from the core, and can't tell the difference between a \"real\" read and a speculative read.  So it will do CMCI/UCNA if an error is found in any read.  Thus:  1) Core is clever and thinks address A is needed soon, issues a    speculative read.  2) Core finds it is going to use address A soon after sending the read    request  3) The CMCI from the memory controller is in a race with MCE from the    core that will soon try to retire the load from address A.  Quite often (because speculation has got better) the CMCI from the memory controller is delivered before the core is committed to the instruction reading address A, so the interrupt is taken, and Linux offlines the page (marking it as poison).   ## Why user process is killed for instr case  Commit 046545a661af (\"mm/hwpoison: fix error page recovered but reported \"not ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39989","epss":0.00237,"percentile":0.1467,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39989","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12442500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-39989","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39989","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0b8388e97ba6a8c033f9a8b5565af41af07f9345","https://git.kernel.org/stable/c/1a15bb8303b6b104e78028b6c68f76a0d4562134","https://git.kernel.org/stable/c/3e3d8169c0950a0b3cd5105f6403a78350dcac80","https://git.kernel.org/stable/c/449413da90a337f343cc5a73070cbd68e92e8a54","https://git.kernel.org/stable/c/5724654a084f701dc64b08d34a0e800f22f0e6e4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mce: use is_copy_from_user() to determine copy-from-user context\n\nPatch series \"mm/hwpoison: Fix regressions in memory failure handling\",\nv4.\n\n## 1. What am I trying to do:\n\nThis patchset resolves two critical regressions related to memory failure\nhandling that have appeared in the upstream kernel since version 5.17, as\ncompared to 5.10 LTS.\n\n    - copyin case: poison found in user page while kernel copying from user space\n    - instr case: poison found while instruction fetching in user space\n\n## 2. What is the expected outcome and why\n\n- For copyin case:\n\nKernel can recover from poison found where kernel is doing get_user() or\ncopy_from_user() if those places get an error return and the kernel return\n-EFAULT to the process instead of crashing.  More specifily, MCE handler\nchecks the fixup handler type to decide whether an in kernel #MC can be\nrecovered.  When EX_TYPE_UACCESS is found, the PC jumps to recovery code\nspecified in _ASM_EXTABLE_FAULT() and return a -EFAULT to user space.\n\n- For instr case:\n\nIf a poison found while instruction fetching in user space, full recovery\nis possible.  User process takes #PF, Linux allocates a new page and fills\nby reading from storage.\n\n\n## 3. What actually happens and why\n\n- For copyin case: kernel panic since v5.17\n\nCommit 4c132d1d844a (\"x86/futex: Remove .fixup usage\") introduced a new\nextable fixup type, EX_TYPE_EFAULT_REG, and later patches updated the\nextable fixup type for copy-from-user operations, changing it from\nEX_TYPE_UACCESS to EX_TYPE_EFAULT_REG.  It breaks previous EX_TYPE_UACCESS\nhandling when posion found in get_user() or copy_from_user().\n\n- For instr case: user process is killed by a SIGBUS signal due to #CMCI\n  and #MCE race\n\nWhen an uncorrected memory error is consumed there is a race between the\nCMCI from the memory controller reporting an uncorrected error with a UCNA\nsignature, and the core reporting and SRAR signature machine check when\nthe data is about to be consumed.\n\n### Background: why *UN*corrected errors tied to *C*MCI in Intel platform [1]\n\nPrior to Icelake memory controllers reported patrol scrub events that\ndetected a previously unseen uncorrected error in memory by signaling a\nbroadcast machine check with an SRAO (Software Recoverable Action\nOptional) signature in the machine check bank.  This was overkill because\nit's not an urgent problem that no core is on the verge of consuming that\nbad data.  It's also found that multi SRAO UCE may cause nested MCE\ninterrupts and finally become an IERR.\n\nHence, Intel downgrades the machine check bank signature of patrol scrub\nfrom SRAO to UCNA (Uncorrected, No Action required), and signal changed to\n#CMCI.  Just to add to the confusion, Linux does take an action (in\nuc_decode_notifier()) to try to offline the page despite the UC*NA*\nsignature name.\n\n### Background: why #CMCI and #MCE race when poison is consuming in\n    Intel platform [1]\n\nHaving decided that CMCI/UCNA is the best action for patrol scrub errors,\nthe memory controller uses it for reads too.  But the memory controller is\nexecuting asynchronously from the core, and can't tell the difference\nbetween a \"real\" read and a speculative read.  So it will do CMCI/UCNA if\nan error is found in any read.\n\nThus:\n\n1) Core is clever and thinks address A is needed soon, issues a\n   speculative read.\n\n2) Core finds it is going to use address A soon after sending the read\n   request\n\n3) The CMCI from the memory controller is in a race with MCE from the\n   core that will soon try to retire the load from address A.\n\nQuite often (because speculation has got better) the CMCI from the memory\ncontroller is delivered before the core is committed to the instruction\nreading address A, so the interrupt is taken, and Linux offlines the page\n(marking it as poison).\n\n\n## Why user process is killed for instr case\n\nCommit 046545a661af (\"mm/hwpoison: fix error page recovered but reported\n\"not\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39989","epss":0.00237,"percentile":0.1467,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-39989","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39989","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-39990","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-39990","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Check the helper function is valid in get_helper_proto  kernel test robot reported verifier bug [1] where the helper func pointer could be NULL due to disabled config option.  As Alexei suggested we could check on that in get_helper_proto directly. Marking tail_call helper func with BPF_PTR_POISON, because it is unused by design.    [1] https://lore.kernel.org/oe-lkp/202507160818.68358831-lkp@intel.com","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39990","epss":0.00141,"percentile":0.03736,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.107865},"relatedVulnerabilities":[{"id":"CVE-2025-39990","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-39990","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3d429cb1278e995e22995ef117fa96d223a67e93","https://git.kernel.org/stable/c/6233715b4b714068d6c831d214a4e8792109875a","https://git.kernel.org/stable/c/e4414b01c1cd9887bbde92f946c1ba94e40d6d64"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check the helper function is valid in get_helper_proto\n\nkernel test robot reported verifier bug [1] where the helper func\npointer could be NULL due to disabled config option.\n\nAs Alexei suggested we could check on that in get_helper_proto\ndirectly. Marking tail_call helper func with BPF_PTR_POISON,\nbecause it is unused by design.\n\n  [1] https://lore.kernel.org/oe-lkp/202507160818.68358831-lkp@intel.com","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-39990","epss":0.00141,"percentile":0.03736,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-39990","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40003","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40003","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work  The origin code calls cancel_delayed_work() in ocelot_stats_deinit() to cancel the cyclic delayed work item ocelot->stats_work. However, cancel_delayed_work() may fail to cancel the work item if it is already executing. While destroy_workqueue() does wait for all pending work items in the work queue to complete before destroying the work queue, it cannot prevent the delayed work item from being rescheduled within the ocelot_check_stats_work() function. This limitation exists because the delayed work item is only enqueued into the work queue after its timer expires. Before the timer expiration, destroy_workqueue() has no visibility of this pending work item. Once the work queue appears empty, destroy_workqueue() proceeds with destruction. When the timer eventually expires, the delayed work item gets queued again, leading to the following warning:  workqueue: cannot queue ocelot_check_stats_work on wq ocelot-switch-stats WARNING: CPU: 2 PID: 0 at kernel/workqueue.c:2255 __queue_work+0x875/0xaf0 ... RIP: 0010:__queue_work+0x875/0xaf0 ... RSP: 0018:ffff88806d108b10 EFLAGS: 00010086 RAX: 0000000000000000 RBX: 0000000000000101 RCX: 0000000000000027 RDX: 0000000000000027 RSI: 0000000000000004 RDI: ffff88806d123e88 RBP: ffffffff813c3170 R08: 0000000000000000 R09: ffffed100da247d2 R10: ffffed100da247d1 R11: ffff88806d123e8b R12: ffff88800c00f000 R13: ffff88800d7285c0 R14: ffff88806d0a5580 R15: ffff88800d7285a0 FS:  0000000000000000(0000) GS:ffff8880e5725000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe18e45ea10 CR3: 0000000005e6c000 CR4: 00000000000006f0 Call Trace:  <IRQ>  ? kasan_report+0xc6/0xf0  ? __pfx_delayed_work_timer_fn+0x10/0x10  ? __pfx_delayed_work_timer_fn+0x10/0x10  call_timer_fn+0x25/0x1c0  __run_timer_base.part.0+0x3be/0x8c0  ? __pfx_delayed_work_timer_fn+0x10/0x10  ? rcu_sched_clock_irq+0xb06/0x27d0  ? __pfx___run_timer_base.part.0+0x10/0x10  ? try_to_wake_up+0xb15/0x1960  ? _raw_spin_lock_irq+0x80/0xe0  ? __pfx__raw_spin_lock_irq+0x10/0x10  tmigr_handle_remote_up+0x603/0x7e0  ? __pfx_tmigr_handle_remote_up+0x10/0x10  ? sched_balance_trigger+0x1c0/0x9f0  ? sched_tick+0x221/0x5a0  ? _raw_spin_lock_irq+0x80/0xe0  ? __pfx__raw_spin_lock_irq+0x10/0x10  ? tick_nohz_handler+0x339/0x440  ? __pfx_tmigr_handle_remote_up+0x10/0x10  __walk_groups.isra.0+0x42/0x150  tmigr_handle_remote+0x1f4/0x2e0  ? __pfx_tmigr_handle_remote+0x10/0x10  ? ktime_get+0x60/0x140  ? lapic_next_event+0x11/0x20  ? clockevents_program_event+0x1d4/0x2a0  ? hrtimer_interrupt+0x322/0x780  handle_softirqs+0x16a/0x550  irq_exit_rcu+0xaf/0xe0  sysvec_apic_timer_interrupt+0x70/0x80  </IRQ> ...  The following diagram reveals the cause of the above warning:  CPU 0 (remove)             | CPU 1 (delayed work callback) mscc_ocelot_remove()       |   ocelot_deinit()          | ocelot_check_stats_work()     ocelot_stats_deinit()  |       cancel_delayed_work()|   ...                            |   queue_delayed_work()       destroy_workqueue()  | (wait a time)                            | __queue_work() //UAF  The above scenario actually constitutes a UAF vulnerability.  The ocelot_stats_deinit() is only invoked when initialization failure or resource destruction, so we must ensure that any delayed work items cannot be rescheduled.  Replace cancel_delayed_work() with disable_delayed_work_sync() to guarantee proper cancellation of the delayed work item and ensure completion of any currently executing work before the workqueue is deallocated.  A deadlock concern was considered: ocelot_stats_deinit() is called in a process context and is not holding any locks that the delayed work item might also need. Therefore, the use of the _sync() variant is safe here.  This bug was identified through static analysis. To reproduce the issue and validate the fix, I simulated ocelot-swit ---truncated---","cvss":[],"epss":[{"cve":"CVE-2025-40003","epss":0.00225,"percentile":0.13132,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11249999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-40003","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40003","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/70acdd1eb35ffb3afdcb59e4c3bbb178da411d0f","https://git.kernel.org/stable/c/bc9ea787079671cb19a8b25ff9f02be5ef6bfcf5","https://git.kernel.org/stable/c/c3363db5d0685a8d077ade706051bbccc75f7e14"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mscc: ocelot: Fix use-after-free caused by cyclic delayed work\n\nThe origin code calls cancel_delayed_work() in ocelot_stats_deinit()\nto cancel the cyclic delayed work item ocelot->stats_work. However,\ncancel_delayed_work() may fail to cancel the work item if it is already\nexecuting. While destroy_workqueue() does wait for all pending work items\nin the work queue to complete before destroying the work queue, it cannot\nprevent the delayed work item from being rescheduled within the\nocelot_check_stats_work() function. This limitation exists because the\ndelayed work item is only enqueued into the work queue after its timer\nexpires. Before the timer expiration, destroy_workqueue() has no visibility\nof this pending work item. Once the work queue appears empty,\ndestroy_workqueue() proceeds with destruction. When the timer eventually\nexpires, the delayed work item gets queued again, leading to the following\nwarning:\n\nworkqueue: cannot queue ocelot_check_stats_work on wq ocelot-switch-stats\nWARNING: CPU: 2 PID: 0 at kernel/workqueue.c:2255 __queue_work+0x875/0xaf0\n...\nRIP: 0010:__queue_work+0x875/0xaf0\n...\nRSP: 0018:ffff88806d108b10 EFLAGS: 00010086\nRAX: 0000000000000000 RBX: 0000000000000101 RCX: 0000000000000027\nRDX: 0000000000000027 RSI: 0000000000000004 RDI: ffff88806d123e88\nRBP: ffffffff813c3170 R08: 0000000000000000 R09: ffffed100da247d2\nR10: ffffed100da247d1 R11: ffff88806d123e8b R12: ffff88800c00f000\nR13: ffff88800d7285c0 R14: ffff88806d0a5580 R15: ffff88800d7285a0\nFS:  0000000000000000(0000) GS:ffff8880e5725000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fe18e45ea10 CR3: 0000000005e6c000 CR4: 00000000000006f0\nCall Trace:\n <IRQ>\n ? kasan_report+0xc6/0xf0\n ? __pfx_delayed_work_timer_fn+0x10/0x10\n ? __pfx_delayed_work_timer_fn+0x10/0x10\n call_timer_fn+0x25/0x1c0\n __run_timer_base.part.0+0x3be/0x8c0\n ? __pfx_delayed_work_timer_fn+0x10/0x10\n ? rcu_sched_clock_irq+0xb06/0x27d0\n ? __pfx___run_timer_base.part.0+0x10/0x10\n ? try_to_wake_up+0xb15/0x1960\n ? _raw_spin_lock_irq+0x80/0xe0\n ? __pfx__raw_spin_lock_irq+0x10/0x10\n tmigr_handle_remote_up+0x603/0x7e0\n ? __pfx_tmigr_handle_remote_up+0x10/0x10\n ? sched_balance_trigger+0x1c0/0x9f0\n ? sched_tick+0x221/0x5a0\n ? _raw_spin_lock_irq+0x80/0xe0\n ? __pfx__raw_spin_lock_irq+0x10/0x10\n ? tick_nohz_handler+0x339/0x440\n ? __pfx_tmigr_handle_remote_up+0x10/0x10\n __walk_groups.isra.0+0x42/0x150\n tmigr_handle_remote+0x1f4/0x2e0\n ? __pfx_tmigr_handle_remote+0x10/0x10\n ? ktime_get+0x60/0x140\n ? lapic_next_event+0x11/0x20\n ? clockevents_program_event+0x1d4/0x2a0\n ? hrtimer_interrupt+0x322/0x780\n handle_softirqs+0x16a/0x550\n irq_exit_rcu+0xaf/0xe0\n sysvec_apic_timer_interrupt+0x70/0x80\n </IRQ>\n...\n\nThe following diagram reveals the cause of the above warning:\n\nCPU 0 (remove)             | CPU 1 (delayed work callback)\nmscc_ocelot_remove()       |\n  ocelot_deinit()          | ocelot_check_stats_work()\n    ocelot_stats_deinit()  |\n      cancel_delayed_work()|   ...\n                           |   queue_delayed_work()\n      destroy_workqueue()  | (wait a time)\n                           | __queue_work() //UAF\n\nThe above scenario actually constitutes a UAF vulnerability.\n\nThe ocelot_stats_deinit() is only invoked when initialization\nfailure or resource destruction, so we must ensure that any\ndelayed work items cannot be rescheduled.\n\nReplace cancel_delayed_work() with disable_delayed_work_sync()\nto guarantee proper cancellation of the delayed work item and\nensure completion of any currently executing work before the\nworkqueue is deallocated.\n\nA deadlock concern was considered: ocelot_stats_deinit() is called\nin a process context and is not holding any locks that the delayed\nwork item might also need. Therefore, the use of the _sync() variant\nis safe here.\n\nThis bug was identified through static analysis. To reproduce the\nissue and validate the fix, I simulated ocelot-swit\n---truncated---","cvss":[],"epss":[{"cve":"CVE-2025-40003","epss":0.00225,"percentile":0.13132,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40003","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40025","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to do sanity check on node footer for non inode dnode  As syzbot reported below:  ------------[ cut here ]------------ kernel BUG at fs/f2fs/file.c:1243! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 5354 Comm: syz.0.0 Not tainted 6.17.0-rc1-syzkaller-00211-g90d970cade8e #0 PREEMPT(full) RIP: 0010:f2fs_truncate_hole+0x69e/0x6c0 fs/f2fs/file.c:1243 Call Trace:  <TASK>  f2fs_punch_hole+0x2db/0x330 fs/f2fs/file.c:1306  f2fs_fallocate+0x546/0x990 fs/f2fs/file.c:2018  vfs_fallocate+0x666/0x7e0 fs/open.c:342  ksys_fallocate fs/open.c:366 [inline]  __do_sys_fallocate fs/open.c:371 [inline]  __se_sys_fallocate fs/open.c:369 [inline]  __x64_sys_fallocate+0xc0/0x110 fs/open.c:369  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f1e65f8ebe9  w/ a fuzzed image, f2fs may encounter panic due to it detects inconsistent truncation range in direct node in f2fs_truncate_hole().  The root cause is: a non-inode dnode may has the same footer.ino and footer.nid, so the dnode will be parsed as an inode, then ADDRS_PER_PAGE() may return wrong blkaddr count which may be 923 typically, by chance, dn.ofs_in_node is equal to 923, then count can be calculated to 0 in below statement, later it will trigger panic w/ f2fs_bug_on(, count == 0 || ...).  \tcount = min(end_offset - dn.ofs_in_node, pg_end - pg_start);  This patch introduces a new node_type NODE_TYPE_NON_INODE, then allowing passing the new_type to sanity_check_node_footer in f2fs_get_node_folio() to detect corruption that a non-inode dnode has the same footer.ino and footer.nid.  Scripts to reproduce: mkfs.f2fs -f /dev/vdb mount /dev/vdb /mnt/f2fs touch /mnt/f2fs/foo touch /mnt/f2fs/bar dd if=/dev/zero of=/mnt/f2fs/foo bs=1M count=8 umount /mnt/f2fs inject.f2fs --node --mb i_nid --nid 4 --idx 0 --val 5 /dev/vdb mount /dev/vdb /mnt/f2fs xfs_io /mnt/f2fs/foo -c \"fpunch 6984k 4k\"","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40025","epss":0.00133,"percentile":0.03191,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.101745},"relatedVulnerabilities":[{"id":"CVE-2025-40025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40025","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/186098f34b8a5d65eb828f952c8cc56272c60ea0","https://git.kernel.org/stable/c/c18ecd99e0c707ef8f83cace861cbc3162f4fdf1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on node footer for non inode dnode\n\nAs syzbot reported below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/file.c:1243!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nCPU: 0 UID: 0 PID: 5354 Comm: syz.0.0 Not tainted 6.17.0-rc1-syzkaller-00211-g90d970cade8e #0 PREEMPT(full)\nRIP: 0010:f2fs_truncate_hole+0x69e/0x6c0 fs/f2fs/file.c:1243\nCall Trace:\n <TASK>\n f2fs_punch_hole+0x2db/0x330 fs/f2fs/file.c:1306\n f2fs_fallocate+0x546/0x990 fs/f2fs/file.c:2018\n vfs_fallocate+0x666/0x7e0 fs/open.c:342\n ksys_fallocate fs/open.c:366 [inline]\n __do_sys_fallocate fs/open.c:371 [inline]\n __se_sys_fallocate fs/open.c:369 [inline]\n __x64_sys_fallocate+0xc0/0x110 fs/open.c:369\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f1e65f8ebe9\n\nw/ a fuzzed image, f2fs may encounter panic due to it detects inconsistent\ntruncation range in direct node in f2fs_truncate_hole().\n\nThe root cause is: a non-inode dnode may has the same footer.ino and\nfooter.nid, so the dnode will be parsed as an inode, then ADDRS_PER_PAGE()\nmay return wrong blkaddr count which may be 923 typically, by chance,\ndn.ofs_in_node is equal to 923, then count can be calculated to 0 in below\nstatement, later it will trigger panic w/ f2fs_bug_on(, count == 0 || ...).\n\n\tcount = min(end_offset - dn.ofs_in_node, pg_end - pg_start);\n\nThis patch introduces a new node_type NODE_TYPE_NON_INODE, then allowing\npassing the new_type to sanity_check_node_footer in f2fs_get_node_folio()\nto detect corruption that a non-inode dnode has the same footer.ino and\nfooter.nid.\n\nScripts to reproduce:\nmkfs.f2fs -f /dev/vdb\nmount /dev/vdb /mnt/f2fs\ntouch /mnt/f2fs/foo\ntouch /mnt/f2fs/bar\ndd if=/dev/zero of=/mnt/f2fs/foo bs=1M count=8\numount /mnt/f2fs\ninject.f2fs --node --mb i_nid --nid 4 --idx 0 --val 5 /dev/vdb\nmount /dev/vdb /mnt/f2fs\nxfs_io /mnt/f2fs/foo -c \"fpunch 6984k 4k\"","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40025","epss":0.00133,"percentile":0.03191,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40054","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40054","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix UAF issue in f2fs_merge_page_bio()  As JY reported in bugzilla [1],  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 pc : [0xffffffe51d249484] f2fs_is_cp_guaranteed+0x70/0x98 lr : [0xffffffe51d24adbc] f2fs_merge_page_bio+0x520/0x6d4 CPU: 3 UID: 0 PID: 6790 Comm: kworker/u16:3 Tainted: P    B   W  OE      6.12.30-android16-5-maybe-dirty-4k #1 5f7701c9cbf727d1eebe77c89bbbeb3371e895e5 Tainted: [P]=PROPRIETARY_MODULE, [B]=BAD_PAGE, [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Workqueue: writeback wb_workfn (flush-254:49) Call trace:  f2fs_is_cp_guaranteed+0x70/0x98  f2fs_inplace_write_data+0x174/0x2f4  f2fs_do_write_data_page+0x214/0x81c  f2fs_write_single_data_page+0x28c/0x764  f2fs_write_data_pages+0x78c/0xce4  do_writepages+0xe8/0x2fc  __writeback_single_inode+0x4c/0x4b4  writeback_sb_inodes+0x314/0x540  __writeback_inodes_wb+0xa4/0xf4  wb_writeback+0x160/0x448  wb_workfn+0x2f0/0x5dc  process_scheduled_works+0x1c8/0x458  worker_thread+0x334/0x3f0  kthread+0x118/0x1ac  ret_from_fork+0x10/0x20  [1] https://bugzilla.kernel.org/show_bug.cgi?id=220575  The panic was caused by UAF issue w/ below race condition:  kworker - writepages  - f2fs_write_cache_pages   - f2fs_write_single_data_page    - f2fs_do_write_data_page     - f2fs_inplace_write_data      - f2fs_merge_page_bio       - add_inu_page       : cache page #1 into bio & cache bio in         io->bio_list   - f2fs_write_single_data_page    - f2fs_do_write_data_page     - f2fs_inplace_write_data      - f2fs_merge_page_bio       - add_inu_page       : cache page #2 into bio which is linked         in io->bio_list \t\t\t\t\t\twrite \t\t\t\t\t\t- f2fs_write_begin \t\t\t\t\t\t: write page #1 \t\t\t\t\t\t - f2fs_folio_wait_writeback \t\t\t\t\t\t  - f2fs_submit_merged_ipu_write \t\t\t\t\t\t   - f2fs_submit_write_bio \t\t\t\t\t\t   : submit bio which inclues page #1 and #2  \t\t\t\t\t\tsoftware IRQ \t\t\t\t\t\t- f2fs_write_end_io \t\t\t\t\t\t - fscrypt_free_bounce_page \t\t\t\t\t\t : freed bounced page which belongs to page #2       - inc_page_count( , WB_DATA_TYPE(data_folio), false)       : data_folio points to fio->encrypted_page         the bounced page can be freed before         accessing it in f2fs_is_cp_guarantee()  It can reproduce w/ below testcase: Run below script in shell #1: for ((i=1;i>0;i++)) do xfs_io -f /mnt/f2fs/enc/file \\ -c \"pwrite 0 32k\" -c \"fdatasync\"  Run below script in shell #2: for ((i=1;i>0;i++)) do xfs_io -f /mnt/f2fs/enc/file \\ -c \"pwrite 0 32k\" -c \"fdatasync\"  So, in f2fs_merge_page_bio(), let's avoid using fio->encrypted_page after commit page into internal ipu cache.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40054","epss":0.00155,"percentile":0.04931,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.118575},"relatedVulnerabilities":[{"id":"CVE-2025-40054","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40054","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/01118321e0c8a5f3ece57d0d377bfc92d83cd210","https://git.kernel.org/stable/c/1f7b44b4a2b2939f08b279cbb9e6b5dcb8ffea32","https://git.kernel.org/stable/c/410337c2301ae78a081e1b5ebbe8ec374fef4cb6","https://git.kernel.org/stable/c/68e094232dfe5027c4fd2dcded93d2d6800bae04","https://git.kernel.org/stable/c/7dd611131d82d7fc4212b555eb1103160bdad302","https://git.kernel.org/stable/c/e193d8953647c8b575830852aa5ea0995b98d2b1","https://git.kernel.org/stable/c/edf7e9040fc52c922db947f9c6c36f07377c52ea"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix UAF issue in f2fs_merge_page_bio()\n\nAs JY reported in bugzilla [1],\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000000\npc : [0xffffffe51d249484] f2fs_is_cp_guaranteed+0x70/0x98\nlr : [0xffffffe51d24adbc] f2fs_merge_page_bio+0x520/0x6d4\nCPU: 3 UID: 0 PID: 6790 Comm: kworker/u16:3 Tainted: P    B   W  OE      6.12.30-android16-5-maybe-dirty-4k #1 5f7701c9cbf727d1eebe77c89bbbeb3371e895e5\nTainted: [P]=PROPRIETARY_MODULE, [B]=BAD_PAGE, [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nWorkqueue: writeback wb_workfn (flush-254:49)\nCall trace:\n f2fs_is_cp_guaranteed+0x70/0x98\n f2fs_inplace_write_data+0x174/0x2f4\n f2fs_do_write_data_page+0x214/0x81c\n f2fs_write_single_data_page+0x28c/0x764\n f2fs_write_data_pages+0x78c/0xce4\n do_writepages+0xe8/0x2fc\n __writeback_single_inode+0x4c/0x4b4\n writeback_sb_inodes+0x314/0x540\n __writeback_inodes_wb+0xa4/0xf4\n wb_writeback+0x160/0x448\n wb_workfn+0x2f0/0x5dc\n process_scheduled_works+0x1c8/0x458\n worker_thread+0x334/0x3f0\n kthread+0x118/0x1ac\n ret_from_fork+0x10/0x20\n\n[1] https://bugzilla.kernel.org/show_bug.cgi?id=220575\n\nThe panic was caused by UAF issue w/ below race condition:\n\nkworker\n- writepages\n - f2fs_write_cache_pages\n  - f2fs_write_single_data_page\n   - f2fs_do_write_data_page\n    - f2fs_inplace_write_data\n     - f2fs_merge_page_bio\n      - add_inu_page\n      : cache page #1 into bio & cache bio in\n        io->bio_list\n  - f2fs_write_single_data_page\n   - f2fs_do_write_data_page\n    - f2fs_inplace_write_data\n     - f2fs_merge_page_bio\n      - add_inu_page\n      : cache page #2 into bio which is linked\n        in io->bio_list\n\t\t\t\t\t\twrite\n\t\t\t\t\t\t- f2fs_write_begin\n\t\t\t\t\t\t: write page #1\n\t\t\t\t\t\t - f2fs_folio_wait_writeback\n\t\t\t\t\t\t  - f2fs_submit_merged_ipu_write\n\t\t\t\t\t\t   - f2fs_submit_write_bio\n\t\t\t\t\t\t   : submit bio which inclues page #1 and #2\n\n\t\t\t\t\t\tsoftware IRQ\n\t\t\t\t\t\t- f2fs_write_end_io\n\t\t\t\t\t\t - fscrypt_free_bounce_page\n\t\t\t\t\t\t : freed bounced page which belongs to page #2\n      - inc_page_count( , WB_DATA_TYPE(data_folio), false)\n      : data_folio points to fio->encrypted_page\n        the bounced page can be freed before\n        accessing it in f2fs_is_cp_guarantee()\n\nIt can reproduce w/ below testcase:\nRun below script in shell #1:\nfor ((i=1;i>0;i++)) do xfs_io -f /mnt/f2fs/enc/file \\\n-c \"pwrite 0 32k\" -c \"fdatasync\"\n\nRun below script in shell #2:\nfor ((i=1;i>0;i++)) do xfs_io -f /mnt/f2fs/enc/file \\\n-c \"pwrite 0 32k\" -c \"fdatasync\"\n\nSo, in f2fs_merge_page_bio(), let's avoid using fio->encrypted_page after\ncommit page into internal ipu cache.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40054","epss":0.00155,"percentile":0.04931,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40054","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40057","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40057","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ptp: Add a upper bound on max_vclocks  syzbot reported WARNING in max_vclocks_store.  This occurs when the argument max is too large for kcalloc to handle.  Extend the guard to guard against values that are too large for kcalloc","cvss":[],"epss":[{"cve":"CVE-2025-40057","epss":0.00199,"percentile":0.09788,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0995},"relatedVulnerabilities":[{"id":"CVE-2025-40057","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40057","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/35ce5f163889dbce88eda1df661b357a09bbed87","https://git.kernel.org/stable/c/8dd446056336faa2283d62cefc2f576536845edc","https://git.kernel.org/stable/c/e9f35294e18da82162004a2f35976e7031aaf7f9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nptp: Add a upper bound on max_vclocks\n\nsyzbot reported WARNING in max_vclocks_store.\n\nThis occurs when the argument max is too large for kcalloc to handle.\n\nExtend the guard to guard against values that are too large for\nkcalloc","cvss":[],"epss":[{"cve":"CVE-2025-40057","epss":0.00199,"percentile":0.09788,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40057","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40064","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40064","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smc: Fix use-after-free in __pnet_find_base_ndev().  syzbot reported use-after-free of net_device in __pnet_find_base_ndev(), which was called during connect(). [0]  smc_pnet_find_ism_resource() fetches sk_dst_get(sk)->dev and passes down to pnet_find_base_ndev(), where RTNL is held.  Then, UAF happened at __pnet_find_base_ndev() when the dev is first used.  This means dev had already been freed before acquiring RTNL in pnet_find_base_ndev().  While dev is going away, dst->dev could be swapped with blackhole_netdev, and the dev's refcnt by dst will be released.  We must hold dev's refcnt before calling smc_pnet_find_ism_resource().  Also, smc_pnet_find_roce_resource() has the same problem.  Let's use __sk_dst_get() and dst_dev_rcu() in the two functions.  [0]: BUG: KASAN: use-after-free in __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926 Read of size 1 at addr ffff888036bac33a by task syz.0.3632/18609  CPU: 1 UID: 0 PID: 18609 Comm: syz.0.3632 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025 Call Trace:  <TASK>  dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:378 [inline]  print_report+0xca/0x240 mm/kasan/report.c:482  kasan_report+0x118/0x150 mm/kasan/report.c:595  __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926  pnet_find_base_ndev net/smc/smc_pnet.c:946 [inline]  smc_pnet_find_ism_by_pnetid net/smc/smc_pnet.c:1103 [inline]  smc_pnet_find_ism_resource+0xef/0x390 net/smc/smc_pnet.c:1154  smc_find_ism_device net/smc/af_smc.c:1030 [inline]  smc_find_proposal_devices net/smc/af_smc.c:1115 [inline]  __smc_connect+0x372/0x1890 net/smc/af_smc.c:1545  smc_connect+0x877/0xd90 net/smc/af_smc.c:1715  __sys_connect_file net/socket.c:2086 [inline]  __sys_connect+0x313/0x440 net/socket.c:2105  __do_sys_connect net/socket.c:2111 [inline]  __se_sys_connect net/socket.c:2108 [inline]  __x64_sys_connect+0x7a/0x90 net/socket.c:2108  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f47cbf8eba9 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f47ccdb1038 EFLAGS: 00000246 ORIG_RAX: 000000000000002a RAX: ffffffffffffffda RBX: 00007f47cc1d5fa0 RCX: 00007f47cbf8eba9 RDX: 0000000000000010 RSI: 0000200000000280 RDI: 000000000000000b RBP: 00007f47cc011e19 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f47cc1d6038 R14: 00007f47cc1d5fa0 R15: 00007ffc512f8aa8  </TASK>  The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff888036bacd00 pfn:0x36bac flags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff) raw: 00fff00000000000 ffffea0001243d08 ffff8880b863fdc0 0000000000000000 raw: ffff888036bacd00 0000000000000000 00000000ffffffff 0000000000000000 page dumped because: kasan: bad access detected page_owner tracks the page as freed page last allocated via order 2, migratetype Unmovable, gfp_mask 0x446dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO|__GFP_NOWARN|__GFP_RETRY_MAYFAIL|__GFP_COMP), pid 16741, tgid 16741 (syz-executor), ts 343313197788, free_ts 380670750466  set_page_owner include/linux/page_owner.h:32 [inline]  post_alloc_hook+0x240/0x2a0 mm/page_alloc.c:1851  prep_new_page mm/page_alloc.c:1859 [inline]  get_page_from_freelist+0x21e4/0x22c0 mm/page_alloc.c:3858  __alloc_frozen_pages_noprof+0x181/0x370 mm/page_alloc.c:5148  alloc_pages_mpol+0x232/0x4a0 mm/mempolicy.c:2416  ___kmalloc_large_node+0x5f/0x1b0 mm/slub.c:4317  __kmalloc_large_node_noprof+0x18/0x90 mm/slub.c:4348  __do_kmalloc_node mm/slub.c:4364 [inline]  __kvmalloc_node ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40064","epss":0.0014,"percentile":0.03642,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10709999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-40064","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40064","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/005a7173d8e4710646043a681af36f79ce05a29b","https://git.kernel.org/stable/c/08aca586482e88aab9616a3e81bc36cad22674a5","https://git.kernel.org/stable/c/233927b645cb7a14bb98d23ac72e4c7243a9f0d9","https://git.kernel.org/stable/c/302dbed4760bcd19a661cc1c282d91bb7481307e","https://git.kernel.org/stable/c/3d3466878afd8d43ec0ca2facfbc7f03e40d0f79"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmc: Fix use-after-free in __pnet_find_base_ndev().\n\nsyzbot reported use-after-free of net_device in __pnet_find_base_ndev(),\nwhich was called during connect(). [0]\n\nsmc_pnet_find_ism_resource() fetches sk_dst_get(sk)->dev and passes\ndown to pnet_find_base_ndev(), where RTNL is held.  Then, UAF happened\nat __pnet_find_base_ndev() when the dev is first used.\n\nThis means dev had already been freed before acquiring RTNL in\npnet_find_base_ndev().\n\nWhile dev is going away, dst->dev could be swapped with blackhole_netdev,\nand the dev's refcnt by dst will be released.\n\nWe must hold dev's refcnt before calling smc_pnet_find_ism_resource().\n\nAlso, smc_pnet_find_roce_resource() has the same problem.\n\nLet's use __sk_dst_get() and dst_dev_rcu() in the two functions.\n\n[0]:\nBUG: KASAN: use-after-free in __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926\nRead of size 1 at addr ffff888036bac33a by task syz.0.3632/18609\n\nCPU: 1 UID: 0 PID: 18609 Comm: syz.0.3632 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025\nCall Trace:\n <TASK>\n dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n __pnet_find_base_ndev+0x1b1/0x1c0 net/smc/smc_pnet.c:926\n pnet_find_base_ndev net/smc/smc_pnet.c:946 [inline]\n smc_pnet_find_ism_by_pnetid net/smc/smc_pnet.c:1103 [inline]\n smc_pnet_find_ism_resource+0xef/0x390 net/smc/smc_pnet.c:1154\n smc_find_ism_device net/smc/af_smc.c:1030 [inline]\n smc_find_proposal_devices net/smc/af_smc.c:1115 [inline]\n __smc_connect+0x372/0x1890 net/smc/af_smc.c:1545\n smc_connect+0x877/0xd90 net/smc/af_smc.c:1715\n __sys_connect_file net/socket.c:2086 [inline]\n __sys_connect+0x313/0x440 net/socket.c:2105\n __do_sys_connect net/socket.c:2111 [inline]\n __se_sys_connect net/socket.c:2108 [inline]\n __x64_sys_connect+0x7a/0x90 net/socket.c:2108\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f47cbf8eba9\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f47ccdb1038 EFLAGS: 00000246 ORIG_RAX: 000000000000002a\nRAX: ffffffffffffffda RBX: 00007f47cc1d5fa0 RCX: 00007f47cbf8eba9\nRDX: 0000000000000010 RSI: 0000200000000280 RDI: 000000000000000b\nRBP: 00007f47cc011e19 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007f47cc1d6038 R14: 00007f47cc1d5fa0 R15: 00007ffc512f8aa8\n </TASK>\n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff888036bacd00 pfn:0x36bac\nflags: 0xfff00000000000(node=0|zone=1|lastcpupid=0x7ff)\nraw: 00fff00000000000 ffffea0001243d08 ffff8880b863fdc0 0000000000000000\nraw: ffff888036bacd00 0000000000000000 00000000ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as freed\npage last allocated via order 2, migratetype Unmovable, gfp_mask 0x446dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO|__GFP_NOWARN|__GFP_RETRY_MAYFAIL|__GFP_COMP), pid 16741, tgid 16741 (syz-executor), ts 343313197788, free_ts 380670750466\n set_page_owner include/linux/page_owner.h:32 [inline]\n post_alloc_hook+0x240/0x2a0 mm/page_alloc.c:1851\n prep_new_page mm/page_alloc.c:1859 [inline]\n get_page_from_freelist+0x21e4/0x22c0 mm/page_alloc.c:3858\n __alloc_frozen_pages_noprof+0x181/0x370 mm/page_alloc.c:5148\n alloc_pages_mpol+0x232/0x4a0 mm/mempolicy.c:2416\n ___kmalloc_large_node+0x5f/0x1b0 mm/slub.c:4317\n __kmalloc_large_node_noprof+0x18/0x90 mm/slub.c:4348\n __do_kmalloc_node mm/slub.c:4364 [inline]\n __kvmalloc_node\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40064","epss":0.0014,"percentile":0.03642,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40064","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40065","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40065","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RISC-V: KVM: Write hgatp register with valid mode bits  According to the RISC-V Privileged Architecture Spec, when MODE=Bare is selected,software must write zero to the remaining fields of hgatp.  We have detected the valid mode supported by the HW before, So using a valid mode to detect how many vmid bits are supported.","cvss":[],"epss":[{"cve":"CVE-2025-40065","epss":0.00174,"percentile":0.06942,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.087},"relatedVulnerabilities":[{"id":"CVE-2025-40065","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40065","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2b351e3d04be9e1533f26c3464f1e44a5beace30","https://git.kernel.org/stable/c/d00b61cd37f4c183ce0edbc9f8ccf6d5430ea357"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRISC-V: KVM: Write hgatp register with valid mode bits\n\nAccording to the RISC-V Privileged Architecture Spec, when MODE=Bare\nis selected,software must write zero to the remaining fields of hgatp.\n\nWe have detected the valid mode supported by the HW before, So using a\nvalid mode to detect how many vmid bits are supported.","cvss":[],"epss":[{"cve":"CVE-2025-40065","epss":0.00174,"percentile":0.06942,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40065","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40071","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40071","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tty: n_gsm: Don't block input queue by waiting MSC  Currently gsm_queue() processes incoming frames and when opening a DLC channel it calls gsm_dlci_open() which calls gsm_modem_update(). If basic mode is used it calls gsm_modem_upd_via_msc() and it cannot block the input queue by waiting the response to come into the same input queue.  Instead allow sending Modem Status Command without waiting for remote end to respond. Define a new function gsm_modem_send_initial_msc() for this purpose. As MSC is only valid for basic encoding, it does not do anything for advanced or when convergence layer type 2 is used.","cvss":[],"epss":[{"cve":"CVE-2025-40071","epss":0.00187,"percentile":0.0845,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0935},"relatedVulnerabilities":[{"id":"CVE-2025-40071","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40071","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3cf0b3c243e56bc43be560617416c1d9f301f44c","https://git.kernel.org/stable/c/5416e89b81b00443cb03c88df8da097ae091a141","https://git.kernel.org/stable/c/c36785f9de03df56ff9b8eca30fa681a12b2310d","https://git.kernel.org/stable/c/c5a2791a7f11939f05f95c01f0aec0c55bbf28d5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntty: n_gsm: Don't block input queue by waiting MSC\n\nCurrently gsm_queue() processes incoming frames and when opening\na DLC channel it calls gsm_dlci_open() which calls gsm_modem_update().\nIf basic mode is used it calls gsm_modem_upd_via_msc() and it\ncannot block the input queue by waiting the response to come\ninto the same input queue.\n\nInstead allow sending Modem Status Command without waiting for remote\nend to respond. Define a new function gsm_modem_send_initial_msc()\nfor this purpose. As MSC is only valid for basic encoding, it does\nnot do anything for advanced or when convergence layer type 2 is used.","cvss":[],"epss":[{"cve":"CVE-2025-40071","epss":0.00187,"percentile":0.0845,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40071","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40074","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40074","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: start using dst_dev_rcu()  Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF.  Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40074","epss":0.00413,"percentile":0.34663,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.38822},"relatedVulnerabilities":[{"id":"CVE-2025-40074","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40074","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/684efb2c86c887685f9aa65e1a21b3df6c1f822d","https://git.kernel.org/stable/c/6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8","https://git.kernel.org/stable/c/923e0734c386984d45de508528a7a7ad91d791cc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: start using dst_dev_rcu()\n\nChange icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF.\n\nChange ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(),\nipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40074","epss":0.00413,"percentile":0.34663,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40074","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40075","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40075","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tcp_metrics: use dst_dev_net_rcu()  Replace three dst_dev() with a lockdep enabled helper.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40075","epss":0.00376,"percentile":0.30957,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.29328000000000004},"relatedVulnerabilities":[{"id":"CVE-2025-40075","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40075","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/07613a95326ebad2d1b88d883cd72546025a4f3e","https://git.kernel.org/stable/c/4b89397807eb04986427c4786d065e9442834ad4","https://git.kernel.org/stable/c/50c127a69cd6285300931853b352a1918cfa180f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_metrics: use dst_dev_net_rcu()\n\nReplace three dst_dev() with a lockdep enabled helper.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40075","epss":0.00376,"percentile":0.30957,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40075","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40077","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40077","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to avoid overflow while left shift operation  Should cast type of folio->index from pgoff_t to loff_t to avoid overflow while left shift operation.","cvss":[],"epss":[{"cve":"CVE-2025-40077","epss":0.00187,"percentile":0.08449,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0935},"relatedVulnerabilities":[{"id":"CVE-2025-40077","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40077","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0e75a098b0a37f02ca31fe99ac16004c8163cf67","https://git.kernel.org/stable/c/0fe1c6bec54ea68ed8c987b3890f2296364e77bb","https://git.kernel.org/stable/c/57d3381dfb97ff73ddd18601017fec21cca80985","https://git.kernel.org/stable/c/ef49378864bb1ed14cd48c8e687729e12714d849"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid overflow while left shift operation\n\nShould cast type of folio->index from pgoff_t to loff_t to avoid overflow\nwhile left shift operation.","cvss":[],"epss":[{"cve":"CVE-2025-40077","epss":0.00187,"percentile":0.08449,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40077","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40097","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40097","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: hda: Fix missing pointer check in hda_component_manager_init function  The __component_match_add function may assign the 'matchptr' pointer the value ERR_PTR(-ENOMEM), which will subsequently be dereferenced.  The call stack leading to the error looks like this:  hda_component_manager_init |-> component_match_add     |-> component_match_add_release         |-> __component_match_add ( ... ,**matchptr, ... )             |-> *matchptr = ERR_PTR(-ENOMEM);       // assign |-> component_master_add_with_match( ...  match)     |-> component_match_realloc(match, match->num); // dereference  Add IS_ERR() check to prevent the crash.  Found by Linux Verification Center (linuxtesting.org) with SVACE.","cvss":[],"epss":[{"cve":"CVE-2025-40097","epss":0.00185,"percentile":0.08224,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0925},"relatedVulnerabilities":[{"id":"CVE-2025-40097","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40097","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1cf11d80db5df805b538c942269e05a65bcaf5bc","https://git.kernel.org/stable/c/218a8504e62fc2c8a1fd12523346b7a2b9bd2474","https://git.kernel.org/stable/c/47d1b9ca923b55c3f407788f1f15b04957e0e027"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: Fix missing pointer check in hda_component_manager_init function\n\nThe __component_match_add function may assign the 'matchptr' pointer\nthe value ERR_PTR(-ENOMEM), which will subsequently be dereferenced.\n\nThe call stack leading to the error looks like this:\n\nhda_component_manager_init\n|-> component_match_add\n    |-> component_match_add_release\n        |-> __component_match_add ( ... ,**matchptr, ... )\n            |-> *matchptr = ERR_PTR(-ENOMEM);       // assign\n|-> component_master_add_with_match( ...  match)\n    |-> component_match_realloc(match, match->num); // dereference\n\nAdd IS_ERR() check to prevent the crash.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.","cvss":[],"epss":[{"cve":"CVE-2025-40097","epss":0.00185,"percentile":0.08224,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40097","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40102","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40102","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: arm64: Prevent access to vCPU events before init  Another day, another syzkaller bug. KVM erroneously allows userspace to pend vCPU events for a vCPU that hasn't been initialized yet, leading to KVM interpreting a bunch of uninitialized garbage for routing / injecting the exception.  In one case the injection code and the hyp disagree on whether the vCPU has a 32bit EL1 and put the vCPU into an illegal mode for AArch64, tripping the BUG() in exception_target_el() during the next injection:    kernel BUG at arch/arm64/kvm/inject_fault.c:40!   Internal error: Oops - BUG: 00000000f2000800 [#1]  SMP   CPU: 3 UID: 0 PID: 318 Comm: repro Not tainted 6.17.0-rc4-00104-g10fd0285305d #6 PREEMPT   Hardware name: linux,dummy-virt (DT)   pstate: 21402009 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)   pc : exception_target_el+0x88/0x8c   lr : pend_serror_exception+0x18/0x13c   sp : ffff800082f03a10   x29: ffff800082f03a10 x28: ffff0000cb132280 x27: 0000000000000000   x26: 0000000000000000 x25: ffff0000c2a99c20 x24: 0000000000000000   x23: 0000000000008000 x22: 0000000000000002 x21: 0000000000000004   x20: 0000000000008000 x19: ffff0000c2a99c20 x18: 0000000000000000   x17: 0000000000000000 x16: 0000000000000000 x15: 00000000200000c0   x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000   x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000   x8 : ffff800082f03af8 x7 : 0000000000000000 x6 : 0000000000000000   x5 : ffff800080f621f0 x4 : 0000000000000000 x3 : 0000000000000000   x2 : 000000000040009b x1 : 0000000000000003 x0 : ffff0000c2a99c20   Call trace:    exception_target_el+0x88/0x8c (P)    kvm_inject_serror_esr+0x40/0x3b4    __kvm_arm_vcpu_set_events+0xf0/0x100    kvm_arch_vcpu_ioctl+0x180/0x9d4    kvm_vcpu_ioctl+0x60c/0x9f4    __arm64_sys_ioctl+0xac/0x104    invoke_syscall+0x48/0x110    el0_svc_common.constprop.0+0x40/0xe0    do_el0_svc+0x1c/0x28    el0_svc+0x34/0xf0    el0t_64_sync_handler+0xa0/0xe4    el0t_64_sync+0x198/0x19c   Code: f946bc01 b4fffe61 9101e020 17fffff2 (d4210000)  Reject the ioctls outright as no sane VMM would call these before KVM_ARM_VCPU_INIT anyway. Even if it did the exception would've been thrown away by the eventual reset of the vCPU's state.","cvss":[],"epss":[{"cve":"CVE-2025-40102","epss":0.00207,"percentile":0.10896,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1035},"relatedVulnerabilities":[{"id":"CVE-2025-40102","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40102","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0aa1b76fe1429629215a7c79820e4b96233ac4a3","https://git.kernel.org/stable/c/64a04e6320fc5affbadc59dc7024d79f909bfe84","https://git.kernel.org/stable/c/7b854e68365a84dfa984ee81268e10b9311ac9d2","https://git.kernel.org/stable/c/b0ab34a9e4cd5b88b522cc156e792cefe3085334","https://git.kernel.org/stable/c/b498f0da45a388b40195f7198455c62fe366a372","https://git.kernel.org/stable/c/c0fcd72e7eb50205dc20731033b0b1c67ecbe4dc","https://git.kernel.org/stable/c/d64461d38972302f0243498ff409b0d54e14e106"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Prevent access to vCPU events before init\n\nAnother day, another syzkaller bug. KVM erroneously allows userspace to\npend vCPU events for a vCPU that hasn't been initialized yet, leading to\nKVM interpreting a bunch of uninitialized garbage for routing /\ninjecting the exception.\n\nIn one case the injection code and the hyp disagree on whether the vCPU\nhas a 32bit EL1 and put the vCPU into an illegal mode for AArch64,\ntripping the BUG() in exception_target_el() during the next injection:\n\n  kernel BUG at arch/arm64/kvm/inject_fault.c:40!\n  Internal error: Oops - BUG: 00000000f2000800 [#1]  SMP\n  CPU: 3 UID: 0 PID: 318 Comm: repro Not tainted 6.17.0-rc4-00104-g10fd0285305d #6 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  pstate: 21402009 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n  pc : exception_target_el+0x88/0x8c\n  lr : pend_serror_exception+0x18/0x13c\n  sp : ffff800082f03a10\n  x29: ffff800082f03a10 x28: ffff0000cb132280 x27: 0000000000000000\n  x26: 0000000000000000 x25: ffff0000c2a99c20 x24: 0000000000000000\n  x23: 0000000000008000 x22: 0000000000000002 x21: 0000000000000004\n  x20: 0000000000008000 x19: ffff0000c2a99c20 x18: 0000000000000000\n  x17: 0000000000000000 x16: 0000000000000000 x15: 00000000200000c0\n  x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n  x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000\n  x8 : ffff800082f03af8 x7 : 0000000000000000 x6 : 0000000000000000\n  x5 : ffff800080f621f0 x4 : 0000000000000000 x3 : 0000000000000000\n  x2 : 000000000040009b x1 : 0000000000000003 x0 : ffff0000c2a99c20\n  Call trace:\n   exception_target_el+0x88/0x8c (P)\n   kvm_inject_serror_esr+0x40/0x3b4\n   __kvm_arm_vcpu_set_events+0xf0/0x100\n   kvm_arch_vcpu_ioctl+0x180/0x9d4\n   kvm_vcpu_ioctl+0x60c/0x9f4\n   __arm64_sys_ioctl+0xac/0x104\n   invoke_syscall+0x48/0x110\n   el0_svc_common.constprop.0+0x40/0xe0\n   do_el0_svc+0x1c/0x28\n   el0_svc+0x34/0xf0\n   el0t_64_sync_handler+0xa0/0xe4\n   el0t_64_sync+0x198/0x19c\n  Code: f946bc01 b4fffe61 9101e020 17fffff2 (d4210000)\n\nReject the ioctls outright as no sane VMM would call these before\nKVM_ARM_VCPU_INIT anyway. Even if it did the exception would've been\nthrown away by the eventual reset of the vCPU's state.","cvss":[],"epss":[{"cve":"CVE-2025-40102","epss":0.00207,"percentile":0.10896,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40102","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40136","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40136","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: hisilicon/qm - request reserved interrupt for virtual function  The device interrupt vector 3 is an error interrupt for physical function and a reserved interrupt for virtual function. However, the driver has not registered the reserved interrupt for virtual function. When allocating interrupts, the number of interrupts is allocated based on powers of two, which includes this interrupt. When the system enables GICv4 and the virtual function passthrough to the virtual machine, releasing the interrupt in the driver triggers a warning.  The WARNING report is: WARNING: CPU: 62 PID: 14889 at arch/arm64/kvm/vgic/vgic-its.c:852 its_free_ite+0x94/0xb4  Therefore, register a reserved interrupt for VF and set the IRQF_NO_AUTOEN flag to avoid that warning.","cvss":[],"epss":[{"cve":"CVE-2025-40136","epss":0.00185,"percentile":0.08168,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0925},"relatedVulnerabilities":[{"id":"CVE-2025-40136","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40136","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/854da2b0df1654d63963d587b12fec6068d89643","https://git.kernel.org/stable/c/9228facb308157ac0bdd264b873187896f7a9c7a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/qm - request reserved interrupt for virtual function\n\nThe device interrupt vector 3 is an error interrupt for\nphysical function and a reserved interrupt for virtual function.\nHowever, the driver has not registered the reserved interrupt for\nvirtual function. When allocating interrupts, the number of interrupts\nis allocated based on powers of two, which includes this interrupt.\nWhen the system enables GICv4 and the virtual function passthrough\nto the virtual machine, releasing the interrupt in the driver\ntriggers a warning.\n\nThe WARNING report is:\nWARNING: CPU: 62 PID: 14889 at arch/arm64/kvm/vgic/vgic-its.c:852 its_free_ite+0x94/0xb4\n\nTherefore, register a reserved interrupt for VF and set the\nIRQF_NO_AUTOEN flag to avoid that warning.","cvss":[],"epss":[{"cve":"CVE-2025-40136","epss":0.00185,"percentile":0.08168,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40136","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40137","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40137","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to truncate first page in error path of f2fs_truncate()  syzbot reports a bug as below:  loop0: detected capacity change from 0 to 40427 F2FS-fs (loop0): Wrong SSA boundary, start(3584) end(4096) blocks(3072) F2FS-fs (loop0): Can't find valid F2FS filesystem in 1th superblock F2FS-fs (loop0): invalid crc value F2FS-fs (loop0): f2fs_convert_inline_folio: corrupted inline inode ino=3, i_addr[0]:0x1601, run fsck to fix. ------------[ cut here ]------------ kernel BUG at fs/inode.c:753! RIP: 0010:clear_inode+0x169/0x190 fs/inode.c:753 Call Trace:  <TASK>  evict+0x504/0x9c0 fs/inode.c:810  f2fs_fill_super+0x5612/0x6fa0 fs/f2fs/super.c:5047  get_tree_bdev_flags+0x40e/0x4d0 fs/super.c:1692  vfs_get_tree+0x8f/0x2b0 fs/super.c:1815  do_new_mount+0x2a2/0x9e0 fs/namespace.c:3808  do_mount fs/namespace.c:4136 [inline]  __do_sys_mount fs/namespace.c:4347 [inline]  __se_sys_mount+0x317/0x410 fs/namespace.c:4324  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f  During f2fs_evict_inode(), clear_inode() detects that we missed to truncate all page cache before destorying inode, that is because in below path, we will create page #0 in cache, but missed to drop it in error path, let's fix it.  - evict  - f2fs_evict_inode   - f2fs_truncate    - f2fs_convert_inline_inode     - f2fs_grab_cache_folio     : create page #0 in cache     - f2fs_convert_inline_folio     : sanity check failed, return -EFSCORRUPTED   - clear_inode detects that inode->i_data.nrpages is not zero","cvss":[],"epss":[{"cve":"CVE-2025-40137","epss":0.00199,"percentile":0.0985,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0995},"relatedVulnerabilities":[{"id":"CVE-2025-40137","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40137","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3b0c8908faa18cded84d64822882a830ab1f4d26","https://git.kernel.org/stable/c/83a8e4efea022506a0e049e7206bdf8be9f78148","https://git.kernel.org/stable/c/9251a9e6e871cb03c4714a18efa8f5d4a8818450","https://git.kernel.org/stable/c/a7b7ebdd7045a36454b3e388a2ecf50344fad9e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to truncate first page in error path of f2fs_truncate()\n\nsyzbot reports a bug as below:\n\nloop0: detected capacity change from 0 to 40427\nF2FS-fs (loop0): Wrong SSA boundary, start(3584) end(4096) blocks(3072)\nF2FS-fs (loop0): Can't find valid F2FS filesystem in 1th superblock\nF2FS-fs (loop0): invalid crc value\nF2FS-fs (loop0): f2fs_convert_inline_folio: corrupted inline inode ino=3, i_addr[0]:0x1601, run fsck to fix.\n------------[ cut here ]------------\nkernel BUG at fs/inode.c:753!\nRIP: 0010:clear_inode+0x169/0x190 fs/inode.c:753\nCall Trace:\n <TASK>\n evict+0x504/0x9c0 fs/inode.c:810\n f2fs_fill_super+0x5612/0x6fa0 fs/f2fs/super.c:5047\n get_tree_bdev_flags+0x40e/0x4d0 fs/super.c:1692\n vfs_get_tree+0x8f/0x2b0 fs/super.c:1815\n do_new_mount+0x2a2/0x9e0 fs/namespace.c:3808\n do_mount fs/namespace.c:4136 [inline]\n __do_sys_mount fs/namespace.c:4347 [inline]\n __se_sys_mount+0x317/0x410 fs/namespace.c:4324\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0x3b0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nDuring f2fs_evict_inode(), clear_inode() detects that we missed to truncate\nall page cache before destorying inode, that is because in below path, we\nwill create page #0 in cache, but missed to drop it in error path, let's fix\nit.\n\n- evict\n - f2fs_evict_inode\n  - f2fs_truncate\n   - f2fs_convert_inline_inode\n    - f2fs_grab_cache_folio\n    : create page #0 in cache\n    - f2fs_convert_inline_folio\n    : sanity check failed, return -EFSCORRUPTED\n  - clear_inode detects that inode->i_data.nrpages is not zero","cvss":[],"epss":[{"cve":"CVE-2025-40137","epss":0.00199,"percentile":0.0985,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40137","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40139","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40139","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().  smc_clc_prfx_set() is called during connect() and not under RCU nor RTNL.  Using sk_dst_get(sk)->dev could trigger UAF.  Let's use __sk_dst_get() and dev_dst_rcu() under rcu_read_lock() after kernel_getsockname().  Note that the returned value of smc_clc_prfx_set() is not used in the caller.  While at it, we change the 1st arg of smc_clc_prfx_set[46]_rcu() not to touch dst there.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40139","epss":0.00153,"percentile":0.04739,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.117045},"relatedVulnerabilities":[{"id":"CVE-2025-40139","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40139","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0736993bfe5c7a9c744ae3fac62d769dfdae54e1","https://git.kernel.org/stable/c/5a2fccc4b32c13ddde3676f9e15e1a9baa7d6fde","https://git.kernel.org/stable/c/80d1fd39f4e37d836655e9f7ffccaf78925049bf","https://git.kernel.org/stable/c/935d783e5de9b64587f3adb25641dd8385e64ddb","https://git.kernel.org/stable/c/956c57daba55cf9ed25d9f2512883b8a1a927599"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().\n\nsmc_clc_prfx_set() is called during connect() and not under RCU\nnor RTNL.\n\nUsing sk_dst_get(sk)->dev could trigger UAF.\n\nLet's use __sk_dst_get() and dev_dst_rcu() under rcu_read_lock()\nafter kernel_getsockname().\n\nNote that the returned value of smc_clc_prfx_set() is not used\nin the caller.\n\nWhile at it, we change the 1st arg of smc_clc_prfx_set[46]_rcu()\nnot to touch dst there.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40139","epss":0.00153,"percentile":0.04739,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40139","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40146","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40146","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  blk-mq: fix potential deadlock while nr_requests grown  Allocate and free sched_tags while queue is freezed can deadlock[1], this is a long term problem, hence allocate memory before freezing queue and free memory after queue is unfreezed.  [1] https://lore.kernel.org/all/0659ea8d-a463-47c8-9180-43c719e106eb@linux.ibm.com/","cvss":[],"epss":[{"cve":"CVE-2025-40146","epss":0.00225,"percentile":0.1316,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11249999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-40146","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40146","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/8d26acf8477174d8ef690eb6affe13a630f586ae","https://git.kernel.org/stable/c/b86433721f46d934940528f28d49c1dedb690df1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: fix potential deadlock while nr_requests grown\n\nAllocate and free sched_tags while queue is freezed can deadlock[1],\nthis is a long term problem, hence allocate memory before freezing\nqueue and free memory after queue is unfreezed.\n\n[1] https://lore.kernel.org/all/0659ea8d-a463-47c8-9180-43c719e106eb@linux.ibm.com/","cvss":[],"epss":[{"cve":"CVE-2025-40146","epss":0.00225,"percentile":0.1316,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40146","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40158","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40158","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: use RCU in ip6_output()  Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF.  We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40158","epss":0.0044,"percentile":0.37091,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3432},"relatedVulnerabilities":[{"id":"CVE-2025-40158","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40158","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0393f85c3241c19ba8550f04a812e7d19f6b3082","https://git.kernel.org/stable/c/11709573cc4e48dc34c80fc7ab9ce5b159e29695"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: use RCU in ip6_output()\n\nUse RCU in ip6_output() in order to use dst_dev_rcu() to prevent\npossible UAF.\n\nWe can remove rcu_read_lock()/rcu_read_unlock() pairs\nfrom ip6_finish_output2().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40158","epss":0.0044,"percentile":0.37091,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40158","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40160","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40160","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xen/events: Return -EEXIST for bound VIRQs  Change find_virq() to return -EEXIST when a VIRQ is bound to a different CPU than the one passed in.  With that, remove the BUG_ON() from bind_virq_to_irq() to propogate the error upwards.  Some VIRQs are per-cpu, but others are per-domain or global.  Those must be bound to CPU0 and can then migrate elsewhere.  The lookup for per-domain and global will probably fail when migrated off CPU 0, especially when the current CPU is tracked.  This now returns -EEXIST instead of BUG_ON().  A second call to bind a per-domain or global VIRQ is not expected, but make it non-fatal to avoid trying to look up the irq, since we don't know which per_cpu(virq_to_irq) it will be in.","cvss":[],"epss":[{"cve":"CVE-2025-40160","epss":0.00187,"percentile":0.08447,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0935},"relatedVulnerabilities":[{"id":"CVE-2025-40160","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40160","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/07ce121d93a5e5fb2440a24da3dbf408fcee978e","https://git.kernel.org/stable/c/612ef6056855c0aacb9b25d1d853c435754483f7","https://git.kernel.org/stable/c/a1e7f07ae6b594f1ba5be46c6125b43bc505c5aa","https://git.kernel.org/stable/c/f81db055a793eca9d05f79658ff62adafb41d664"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxen/events: Return -EEXIST for bound VIRQs\n\nChange find_virq() to return -EEXIST when a VIRQ is bound to a\ndifferent CPU than the one passed in.  With that, remove the BUG_ON()\nfrom bind_virq_to_irq() to propogate the error upwards.\n\nSome VIRQs are per-cpu, but others are per-domain or global.  Those must\nbe bound to CPU0 and can then migrate elsewhere.  The lookup for\nper-domain and global will probably fail when migrated off CPU 0,\nespecially when the current CPU is tracked.  This now returns -EEXIST\ninstead of BUG_ON().\n\nA second call to bind a per-domain or global VIRQ is not expected, but\nmake it non-fatal to avoid trying to look up the irq, since we don't\nknow which per_cpu(virq_to_irq) it will be in.","cvss":[],"epss":[{"cve":"CVE-2025-40160","epss":0.00187,"percentile":0.08447,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40160","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40168","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40168","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().  smc_clc_prfx_match() is called from smc_listen_work() and not under RCU nor RTNL.  Using sk_dst_get(sk)->dev could trigger UAF.  Let's use __sk_dst_get() and dst_dev_rcu().  Note that the returned value of smc_clc_prfx_match() is not used in the caller.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40168","epss":0.00392,"percentile":0.3257,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.30576000000000003},"relatedVulnerabilities":[{"id":"CVE-2025-40168","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40168","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/235f81045c008169cc4e1955b4a64e118eebe61b","https://git.kernel.org/stable/c/326e5cf301d0bec0a672aa834d8254c4f9df6255","https://git.kernel.org/stable/c/3f119c37aa293af41400cccb3d89fab8dcf774b0","https://git.kernel.org/stable/c/4f5f52a5842937f945582a93cb9daed9ea526fee","https://git.kernel.org/stable/c/d26e80f7fb62d77757b67a1b94e4ac756bc9c658"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().\n\nsmc_clc_prfx_match() is called from smc_listen_work() and\nnot under RCU nor RTNL.\n\nUsing sk_dst_get(sk)->dev could trigger UAF.\n\nLet's use __sk_dst_get() and dst_dev_rcu().\n\nNote that the returned value of smc_clc_prfx_match() is not\nused in the caller.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40168","epss":0.00392,"percentile":0.3257,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40168","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40170","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40170","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: use dst_dev_rcu() in sk_setup_caps()  Use RCU to protect accesses to dst->dev from sk_setup_caps() and sk_dst_gso_max_size().  Also use dst_dev_rcu() in ip6_dst_mtu_maybe_forward(), and ip_dst_mtu_maybe_forward().  ip4_dst_hoplimit() can use dst_dev_net_rcu().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40170","epss":0.00147,"percentile":0.04281,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.112455},"relatedVulnerabilities":[{"id":"CVE-2025-40170","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40170","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5d1be493d1110c9e720b4c51a6e587bb2fb4ac12","https://git.kernel.org/stable/c/99a2ace61b211b0be861b07fbaa062fca4b58879","https://git.kernel.org/stable/c/a805729c0091073d8f0415cfa96c7acd1bc17a48"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: use dst_dev_rcu() in sk_setup_caps()\n\nUse RCU to protect accesses to dst->dev from sk_setup_caps()\nand sk_dst_gso_max_size().\n\nAlso use dst_dev_rcu() in ip6_dst_mtu_maybe_forward(),\nand ip_dst_mtu_maybe_forward().\n\nip4_dst_hoplimit() can use dst_dev_net_rcu().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40170","epss":0.00147,"percentile":0.04281,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40170","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40180","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop  The cleanup loop was starting at the wrong array index, causing out-of-bounds access. Start the loop at the correct index for zero-indexed arrays to prevent accessing memory beyond the allocated array bounds.","cvss":[],"epss":[{"cve":"CVE-2025-40180","epss":0.00199,"percentile":0.09789,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0995},"relatedVulnerabilities":[{"id":"CVE-2025-40180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40180","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0aead8197fc1a85b0a89646e418feb49a564b029","https://git.kernel.org/stable/c/ab96f08ecedd263ecaab9df8455bfb23b07fdcc2","https://git.kernel.org/stable/c/cd0cbf2713f6e027ebba867cb7409ae345a31312"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop\n\nThe cleanup loop was starting at the wrong array index, causing\nout-of-bounds access.\nStart the loop at the correct index for zero-indexed arrays to prevent\naccessing memory beyond the allocated array bounds.","cvss":[],"epss":[{"cve":"CVE-2025-40180","epss":0.00199,"percentile":0.09789,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40180","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40206","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40206","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_objref: validate objref and objrefmap expressions  Referencing a synproxy stateful object from OUTPUT hook causes kernel crash due to infinite recursive calls:  BUG: TASK stack guard page was hit at 000000008bda5b8c (stack is 000000003ab1c4a5..00000000494d8b12) [...] Call Trace:  __find_rr_leaf+0x99/0x230  fib6_table_lookup+0x13b/0x2d0  ip6_pol_route+0xa4/0x400  fib6_rule_lookup+0x156/0x240  ip6_route_output_flags+0xc6/0x150  __nf_ip6_route+0x23/0x50  synproxy_send_tcp_ipv6+0x106/0x200  synproxy_send_client_synack_ipv6+0x1aa/0x1f0  nft_synproxy_do_eval+0x263/0x310  nft_do_chain+0x5a8/0x5f0 [nf_tables  nft_do_chain_inet+0x98/0x110  nf_hook_slow+0x43/0xc0  __ip6_local_out+0xf0/0x170  ip6_local_out+0x17/0x70  synproxy_send_tcp_ipv6+0x1a2/0x200  synproxy_send_client_synack_ipv6+0x1aa/0x1f0 [...]  Implement objref and objrefmap expression validate functions.  Currently, only NFT_OBJECT_SYNPROXY object type requires validation. This will also handle a jump to a chain using a synproxy object from the OUTPUT hook.  Now when trying to reference a synproxy object in the OUTPUT hook, nft will produce the following error:  synproxy_crash.nft: Error: Could not process rule: Operation not supported   synproxy name mysynproxy   ^^^^^^^^^^^^^^^^^^^^^^^^","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40206","epss":0.00142,"percentile":0.0386,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10863},"relatedVulnerabilities":[{"id":"CVE-2025-40206","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40206","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0028e0134c64d9ed21728341a74fcfc59cd0f944","https://git.kernel.org/stable/c/4c1cf72ec10be5a9ad264650cadffa1fbce6fabd","https://git.kernel.org/stable/c/7ea55a44493a5a36c3b3293b88bbe4841f9dbaf0","https://git.kernel.org/stable/c/f31bcea12222a26d6f151df9c4a6d21f2eec1724","https://git.kernel.org/stable/c/f359b809d54c6e3dd1d039b97e0b68390b0e53e4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_objref: validate objref and objrefmap expressions\n\nReferencing a synproxy stateful object from OUTPUT hook causes kernel\ncrash due to infinite recursive calls:\n\nBUG: TASK stack guard page was hit at 000000008bda5b8c (stack is 000000003ab1c4a5..00000000494d8b12)\n[...]\nCall Trace:\n __find_rr_leaf+0x99/0x230\n fib6_table_lookup+0x13b/0x2d0\n ip6_pol_route+0xa4/0x400\n fib6_rule_lookup+0x156/0x240\n ip6_route_output_flags+0xc6/0x150\n __nf_ip6_route+0x23/0x50\n synproxy_send_tcp_ipv6+0x106/0x200\n synproxy_send_client_synack_ipv6+0x1aa/0x1f0\n nft_synproxy_do_eval+0x263/0x310\n nft_do_chain+0x5a8/0x5f0 [nf_tables\n nft_do_chain_inet+0x98/0x110\n nf_hook_slow+0x43/0xc0\n __ip6_local_out+0xf0/0x170\n ip6_local_out+0x17/0x70\n synproxy_send_tcp_ipv6+0x1a2/0x200\n synproxy_send_client_synack_ipv6+0x1aa/0x1f0\n[...]\n\nImplement objref and objrefmap expression validate functions.\n\nCurrently, only NFT_OBJECT_SYNPROXY object type requires validation.\nThis will also handle a jump to a chain using a synproxy object from the\nOUTPUT hook.\n\nNow when trying to reference a synproxy object in the OUTPUT hook, nft\nwill produce the following error:\n\nsynproxy_crash.nft: Error: Could not process rule: Operation not supported\n  synproxy name mysynproxy\n  ^^^^^^^^^^^^^^^^^^^^^^^^","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40206","epss":0.00142,"percentile":0.0386,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40206","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40247","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40247","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm: Fix pgtable prealloc error path  The following splat was reported:      Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010     Mem abort info:       ESR = 0x0000000096000004       EC = 0x25: DABT (current EL), IL = 32 bits       SET = 0, FnV = 0       EA = 0, S1PTW = 0       FSC = 0x04: level 0 translation fault     Data abort info:       ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000       CM = 0, WnR = 0, TnD = 0, TagAccess = 0       GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0     user pgtable: 4k pages, 48-bit VAs, pgdp=00000008d0fd8000     [0000000000000010] pgd=0000000000000000, p4d=0000000000000000     Internal error: Oops: 0000000096000004 [#1]  SMP     CPU: 5 UID: 1000 PID: 149076 Comm: Xwayland Tainted: G S                  6.16.0-rc2-00809-g0b6974bb4134-dirty #367 PREEMPT     Tainted: [S]=CPU_OUT_OF_SPEC     Hardware name: Qualcomm Technologies, Inc. SM8650 HDK (DT)     pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)     pc : build_detached_freelist+0x28/0x224     lr : kmem_cache_free_bulk.part.0+0x38/0x244     sp : ffff000a508c7a20     x29: ffff000a508c7a20 x28: ffff000a508c7d50 x27: ffffc4e49d16f350     x26: 0000000000000058 x25: 00000000fffffffc x24: 0000000000000000     x23: ffff00098c4e1450 x22: 00000000fffffffc x21: 0000000000000000     x20: ffff000a508c7af8 x19: 0000000000000002 x18: 00000000000003e8     x17: ffff000809523850 x16: ffff000809523820 x15: 0000000000401640     x14: ffff000809371140 x13: 0000000000000130 x12: ffff0008b5711e30     x11: 00000000001058fa x10: 0000000000000a80 x9 : ffff000a508c7940     x8 : ffff000809371ba0 x7 : 781fffe033087fff x6 : 0000000000000000     x5 : ffff0008003cd000 x4 : 781fffe033083fff x3 : ffff000a508c7af8     x2 : fffffdffc0000000 x1 : 0001000000000000 x0 : ffff0008001a6a00     Call trace:      build_detached_freelist+0x28/0x224 (P)      kmem_cache_free_bulk.part.0+0x38/0x244      kmem_cache_free_bulk+0x10/0x1c      msm_iommu_pagetable_prealloc_cleanup+0x3c/0xd0      msm_vma_job_free+0x30/0x240      msm_ioctl_vm_bind+0x1d0/0x9a0      drm_ioctl_kernel+0x84/0x104      drm_ioctl+0x358/0x4d4      __arm64_sys_ioctl+0x8c/0xe0      invoke_syscall+0x44/0x100      el0_svc_common.constprop.0+0x3c/0xe0      do_el0_svc+0x18/0x20      el0_svc+0x30/0x100      el0t_64_sync_handler+0x104/0x130      el0t_64_sync+0x170/0x174     Code: aa0203f5 b26287e2 f2dfbfe2 aa0303f4 (f8737ab6)     ---[ end trace 0000000000000000 ]---  Since msm_vma_job_free() is called directly from the ioctl, this looks like an error path cleanup issue.  Which I think results from prealloc_cleanup() called without a preceding successful prealloc_allocate() call.  So handle that case better.  Patchwork: https://patchwork.freedesktop.org/patch/678677/","cvss":[],"epss":[{"cve":"CVE-2025-40247","epss":0.00186,"percentile":0.08356,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.093},"relatedVulnerabilities":[{"id":"CVE-2025-40247","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40247","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/830d68f2cb8ab6fb798bb9555016709a9e012af0","https://git.kernel.org/stable/c/b865da18b6cb878f33b5920693d03f23b9c4d1a3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Fix pgtable prealloc error path\n\nThe following splat was reported:\n\n    Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010\n    Mem abort info:\n      ESR = 0x0000000096000004\n      EC = 0x25: DABT (current EL), IL = 32 bits\n      SET = 0, FnV = 0\n      EA = 0, S1PTW = 0\n      FSC = 0x04: level 0 translation fault\n    Data abort info:\n      ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n      CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n      GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n    user pgtable: 4k pages, 48-bit VAs, pgdp=00000008d0fd8000\n    [0000000000000010] pgd=0000000000000000, p4d=0000000000000000\n    Internal error: Oops: 0000000096000004 [#1]  SMP\n    CPU: 5 UID: 1000 PID: 149076 Comm: Xwayland Tainted: G S                  6.16.0-rc2-00809-g0b6974bb4134-dirty #367 PREEMPT\n    Tainted: [S]=CPU_OUT_OF_SPEC\n    Hardware name: Qualcomm Technologies, Inc. SM8650 HDK (DT)\n    pstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n    pc : build_detached_freelist+0x28/0x224\n    lr : kmem_cache_free_bulk.part.0+0x38/0x244\n    sp : ffff000a508c7a20\n    x29: ffff000a508c7a20 x28: ffff000a508c7d50 x27: ffffc4e49d16f350\n    x26: 0000000000000058 x25: 00000000fffffffc x24: 0000000000000000\n    x23: ffff00098c4e1450 x22: 00000000fffffffc x21: 0000000000000000\n    x20: ffff000a508c7af8 x19: 0000000000000002 x18: 00000000000003e8\n    x17: ffff000809523850 x16: ffff000809523820 x15: 0000000000401640\n    x14: ffff000809371140 x13: 0000000000000130 x12: ffff0008b5711e30\n    x11: 00000000001058fa x10: 0000000000000a80 x9 : ffff000a508c7940\n    x8 : ffff000809371ba0 x7 : 781fffe033087fff x6 : 0000000000000000\n    x5 : ffff0008003cd000 x4 : 781fffe033083fff x3 : ffff000a508c7af8\n    x2 : fffffdffc0000000 x1 : 0001000000000000 x0 : ffff0008001a6a00\n    Call trace:\n     build_detached_freelist+0x28/0x224 (P)\n     kmem_cache_free_bulk.part.0+0x38/0x244\n     kmem_cache_free_bulk+0x10/0x1c\n     msm_iommu_pagetable_prealloc_cleanup+0x3c/0xd0\n     msm_vma_job_free+0x30/0x240\n     msm_ioctl_vm_bind+0x1d0/0x9a0\n     drm_ioctl_kernel+0x84/0x104\n     drm_ioctl+0x358/0x4d4\n     __arm64_sys_ioctl+0x8c/0xe0\n     invoke_syscall+0x44/0x100\n     el0_svc_common.constprop.0+0x3c/0xe0\n     do_el0_svc+0x18/0x20\n     el0_svc+0x30/0x100\n     el0t_64_sync_handler+0x104/0x130\n     el0t_64_sync+0x170/0x174\n    Code: aa0203f5 b26287e2 f2dfbfe2 aa0303f4 (f8737ab6)\n    ---[ end trace 0000000000000000 ]---\n\nSince msm_vma_job_free() is called directly from the ioctl, this looks\nlike an error path cleanup issue.  Which I think results from\nprealloc_cleanup() called without a preceding successful\nprealloc_allocate() call.  So handle that case better.\n\nPatchwork: https://patchwork.freedesktop.org/patch/678677/","cvss":[],"epss":[{"cve":"CVE-2025-40247","epss":0.00186,"percentile":0.08356,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40247","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40266","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40266","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: arm64: Check the untrusted offset in FF-A memory share  Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX] is set from the host kernel.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40266","epss":0.0015,"percentile":0.04464,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11775},"relatedVulnerabilities":[{"id":"CVE-2025-40266","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40266","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/103e17aac09cdd358133f9e00998b75d6c1f1518","https://git.kernel.org/stable/c/bc1909ef38788f2ee3d8011d70bf029948433051","https://git.kernel.org/stable/c/f9f1aed6c8a3427900da3121e1868124854569c3","https://git.kernel.org/stable/c/fc3139d9f4c1fe1c7d5f25f99676bd8e9c6a1041"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Check the untrusted offset in FF-A memory share\n\nVerify the offset to prevent OOB access in the hypervisor\nFF-A buffer in case an untrusted large enough value\n[U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX]\nis set from the host kernel.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40266","epss":0.0015,"percentile":0.04464,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40266","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40268","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40268","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cifs: client: fix memory leak in smb3_fs_context_parse_param  The user calls fsconfig twice, but when the program exits, free() only frees ctx->source for the second fsconfig, not the first. Regarding fc->source, there is no code in the fs context related to its memory reclamation.  To fix this memory leak, release the source memory corresponding to ctx or fc before each parsing.  syzbot reported: BUG: memory leak unreferenced object 0xffff888128afa360 (size 96):   backtrace (crc 79c9c7ba):     kstrdup+0x3c/0x80 mm/util.c:84     smb3_fs_context_parse_param+0x229b/0x36c0 fs/smb/client/fs_context.c:1444  BUG: memory leak unreferenced object 0xffff888112c7d900 (size 96):   backtrace (crc 79c9c7ba):     smb3_fs_context_fullpath+0x70/0x1b0 fs/smb/client/fs_context.c:629     smb3_fs_context_parse_param+0x2266/0x36c0 fs/smb/client/fs_context.c:1438","cvss":[],"epss":[{"cve":"CVE-2025-40268","epss":0.00187,"percentile":0.08448,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0935},"relatedVulnerabilities":[{"id":"CVE-2025-40268","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40268","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4515743cc7a42e1d67468402a6420c195532a6fa","https://git.kernel.org/stable/c/48c17341577e25a22feb13d694374b61d974edbc","https://git.kernel.org/stable/c/868fc62811d3fabcf5685e14f36377a855d5412d","https://git.kernel.org/stable/c/e8c73eb7db0a498cd4b22d2819e6ab1a6f506bd6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: client: fix memory leak in smb3_fs_context_parse_param\n\nThe user calls fsconfig twice, but when the program exits, free() only\nfrees ctx->source for the second fsconfig, not the first.\nRegarding fc->source, there is no code in the fs context related to its\nmemory reclamation.\n\nTo fix this memory leak, release the source memory corresponding to ctx\nor fc before each parsing.\n\nsyzbot reported:\nBUG: memory leak\nunreferenced object 0xffff888128afa360 (size 96):\n  backtrace (crc 79c9c7ba):\n    kstrdup+0x3c/0x80 mm/util.c:84\n    smb3_fs_context_parse_param+0x229b/0x36c0 fs/smb/client/fs_context.c:1444\n\nBUG: memory leak\nunreferenced object 0xffff888112c7d900 (size 96):\n  backtrace (crc 79c9c7ba):\n    smb3_fs_context_fullpath+0x70/0x1b0 fs/smb/client/fs_context.c:629\n    smb3_fs_context_parse_param+0x2266/0x36c0 fs/smb/client/fs_context.c:1438","cvss":[],"epss":[{"cve":"CVE-2025-40268","epss":0.00187,"percentile":0.08448,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40268","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40289","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40289","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM  Otherwise accessing them can cause a crash.","cvss":[],"epss":[{"cve":"CVE-2025-40289","epss":0.00184,"percentile":0.08073,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2025-40289","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40289","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/33cc891b56b93cad1a83263eaf2e417436f70c82","https://git.kernel.org/stable/c/39a1c8c860e32d775f29917939e87b6a7c08ebb1","https://git.kernel.org/stable/c/a67a9f99ce1306898d7129a199d42876bc06a0f0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM\n\nOtherwise accessing them can cause a crash.","cvss":[],"epss":[{"cve":"CVE-2025-40289","epss":0.00184,"percentile":0.08073,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40289","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40303","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40303","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: ensure no dirty metadata is written back for an fs with errors  [BUG] During development of a minor feature (make sure all btrfs_bio::end_io() is called in task context), I noticed a crash in generic/388, where metadata writes triggered new works after btrfs_stop_all_workers().  It turns out that it can even happen without any code modification, just using RAID5 for metadata and the same workload from generic/388 is going to trigger the use-after-free.  [CAUSE] If btrfs hits an error, the fs is marked as error, no new transaction is allowed thus metadata is in a frozen state.  But there are some metadata modifications before that error, and they are still in the btree inode page cache.  Since there will be no real transaction commit, all those dirty folios are just kept as is in the page cache, and they can not be invalidated by invalidate_inode_pages2() call inside close_ctree(), because they are dirty.  And finally after btrfs_stop_all_workers(), we call iput() on btree inode, which triggers writeback of those dirty metadata.  And if the fs is using RAID56 metadata, this will trigger RMW and queue new works into rmw_workers, which is already stopped, causing warning from queue_work() and use-after-free.  [FIX] Add a special handling for write_one_eb(), that if the fs is already in an error state, immediately mark the bbio as failure, instead of really submitting them.  Then during close_ctree(), iput() will just discard all those dirty tree blocks without really writing them back, thus no more new jobs for already stopped-and-freed workqueues.  The extra discard in write_one_eb() also acts as an extra safenet. E.g. the transaction abort is triggered by some extent/free space tree corruptions, and since extent/free space tree is already corrupted some tree blocks may be allocated where they shouldn't be (overwriting existing tree blocks). In that case writing them back will further corrupting the fs.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40303","epss":0.00138,"percentile":0.0355,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2025-40303","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40303","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/066ee13f05fbd82ada01883e51f0695172f98dff","https://git.kernel.org/stable/c/2618849f31e7cf51fadd4a5242458501a6d5b315","https://git.kernel.org/stable/c/54a5b5a15588e3b0b294df31474d08a2678d4291","https://git.kernel.org/stable/c/e2b3859067bf012d53c49b3f885fef40624a2c83"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: ensure no dirty metadata is written back for an fs with errors\n\n[BUG]\nDuring development of a minor feature (make sure all btrfs_bio::end_io()\nis called in task context), I noticed a crash in generic/388, where\nmetadata writes triggered new works after btrfs_stop_all_workers().\n\nIt turns out that it can even happen without any code modification, just\nusing RAID5 for metadata and the same workload from generic/388 is going\nto trigger the use-after-free.\n\n[CAUSE]\nIf btrfs hits an error, the fs is marked as error, no new\ntransaction is allowed thus metadata is in a frozen state.\n\nBut there are some metadata modifications before that error, and they are\nstill in the btree inode page cache.\n\nSince there will be no real transaction commit, all those dirty folios\nare just kept as is in the page cache, and they can not be invalidated\nby invalidate_inode_pages2() call inside close_ctree(), because they are\ndirty.\n\nAnd finally after btrfs_stop_all_workers(), we call iput() on btree\ninode, which triggers writeback of those dirty metadata.\n\nAnd if the fs is using RAID56 metadata, this will trigger RMW and queue\nnew works into rmw_workers, which is already stopped, causing warning\nfrom queue_work() and use-after-free.\n\n[FIX]\nAdd a special handling for write_one_eb(), that if the fs is already in\nan error state, immediately mark the bbio as failure, instead of really\nsubmitting them.\n\nThen during close_ctree(), iput() will just discard all those dirty\ntree blocks without really writing them back, thus no more new jobs for\nalready stopped-and-freed workqueues.\n\nThe extra discard in write_one_eb() also acts as an extra safenet.\nE.g. the transaction abort is triggered by some extent/free space\ntree corruptions, and since extent/free space tree is already corrupted\nsome tree blocks may be allocated where they shouldn't be (overwriting\nexisting tree blocks). In that case writing them back will further\ncorrupting the fs.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40303","epss":0.00138,"percentile":0.0355,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40303","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40307","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40307","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  exfat: validate cluster allocation bits of the allocation bitmap  syzbot created an exfat image with cluster bits not set for the allocation bitmap. exfat-fs reads and uses the allocation bitmap without checking this. The problem is that if the start cluster of the allocation bitmap is 6, cluster 6 can be allocated when creating a directory with mkdir. exfat zeros out this cluster in exfat_mkdir, which can delete existing entries. This can reallocate the allocated entries. In addition, the allocation bitmap is also zeroed out, so cluster 6 can be reallocated. This patch adds exfat_test_bitmap_range to validate that clusters used for the allocation bitmap are correctly marked as in-use.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40307","epss":0.00147,"percentile":0.04235,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.112455},"relatedVulnerabilities":[{"id":"CVE-2025-40307","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40307","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/13c1d24803d5b0446b3f6f0fdd67e07ac1fdc7bf","https://git.kernel.org/stable/c/67ce8034dc0278ddd88cad93d4218a945180dddd","https://git.kernel.org/stable/c/6bc58b4c53795ab5fe00648344aa7d9d61175f90","https://git.kernel.org/stable/c/79c1587b6cda74deb0c86fc7ba194b92958c793c","https://git.kernel.org/stable/c/87f827d53bd0688597bda63ae95908e2ad39bac0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: validate cluster allocation bits of the allocation bitmap\n\nsyzbot created an exfat image with cluster bits not set for the allocation\nbitmap. exfat-fs reads and uses the allocation bitmap without checking\nthis. The problem is that if the start cluster of the allocation bitmap\nis 6, cluster 6 can be allocated when creating a directory with mkdir.\nexfat zeros out this cluster in exfat_mkdir, which can delete existing\nentries. This can reallocate the allocated entries. In addition,\nthe allocation bitmap is also zeroed out, so cluster 6 can be reallocated.\nThis patch adds exfat_test_bitmap_range to validate that clusters used for\nthe allocation bitmap are correctly marked as in-use.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40307","epss":0.00147,"percentile":0.04235,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40307","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40311","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40311","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  accel/habanalabs: support mapping cb with vmalloc-backed coherent memory  When IOMMU is enabled, dma_alloc_coherent() with GFP_USER may return addresses from the vmalloc range. If such an address is mapped without VM_MIXEDMAP, vm_insert_page() will trigger a BUG_ON due to the VM_PFNMAP restriction.  Fix this by checking for vmalloc addresses and setting VM_MIXEDMAP in the VMA before mapping. This ensures safe mapping and avoids kernel crashes. The memory is still driver-allocated and cannot be accessed directly by userspace.","cvss":[],"epss":[{"cve":"CVE-2025-40311","epss":0.00186,"percentile":0.08286,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.093},"relatedVulnerabilities":[{"id":"CVE-2025-40311","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40311","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/513024d5a0e34fd34247043f1876b6138ca52847","https://git.kernel.org/stable/c/73c7c2cdb442fc4160d2a2a4bfffbd162af06cb9","https://git.kernel.org/stable/c/7ec8ac9f73d4a9438c2186768d6de27ace37531e","https://git.kernel.org/stable/c/d1dfe21a332d38a6a09658ec29a55940afb5fe36"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/habanalabs: support mapping cb with vmalloc-backed coherent memory\n\nWhen IOMMU is enabled, dma_alloc_coherent() with GFP_USER may return\naddresses from the vmalloc range. If such an address is mapped without\nVM_MIXEDMAP, vm_insert_page() will trigger a BUG_ON due to the\nVM_PFNMAP restriction.\n\nFix this by checking for vmalloc addresses and setting VM_MIXEDMAP\nin the VMA before mapping. This ensures safe mapping and avoids kernel\ncrashes. The memory is still driver-allocated and cannot be accessed\ndirectly by userspace.","cvss":[],"epss":[{"cve":"CVE-2025-40311","epss":0.00186,"percentile":0.08286,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40311","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40325","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40325","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md/raid10: wait barrier before returning discard request with REQ_NOWAIT  raid10_handle_discard should wait barrier before returning a discard bio which has REQ_NOWAIT. And there is no need to print warning calltrace if a discard bio has REQ_NOWAIT flag. Quality engineer usually checks dmesg and reports error if dmesg has warning/error calltrace.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40325","epss":0.00235,"percentile":0.14449,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.123375},"relatedVulnerabilities":[{"id":"CVE-2025-40325","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40325","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/31d3156efe909b53ba174861a3da880c688f5edc","https://git.kernel.org/stable/c/31ff67982c5fa39c0093b9d9f429fef91c2494b7","https://git.kernel.org/stable/c/3db4404435397a345431b45f57876a3df133f3b4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: wait barrier before returning discard request with REQ_NOWAIT\n\nraid10_handle_discard should wait barrier before returning a discard bio\nwhich has REQ_NOWAIT. And there is no need to print warning calltrace\nif a discard bio has REQ_NOWAIT flag. Quality engineer usually checks\ndmesg and reports error if dmesg has warning/error calltrace.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40325","epss":0.00235,"percentile":0.14449,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40325","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40328","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix potential UAF in smb2_close_cached_fid()  find_or_create_cached_dir() could grab a new reference after kref_put() had seen the refcount drop to zero but before cfid_list_lock is acquired in smb2_close_cached_fid(), leading to use-after-free.  Switch to kref_put_lock() so cfid_release() is called with cfid_list_lock held, closing that gap.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40328","epss":0.00461,"percentile":0.38601,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3757150000000001},"relatedVulnerabilities":[{"id":"CVE-2025-40328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40328","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/065bd62412271a2d734810dd50336cae88c54427","https://git.kernel.org/stable/c/734e99623c5b65bf2c03e35978a0b980ebc3c2f8","https://git.kernel.org/stable/c/bdb596ceb4b7c3f28786a33840263728217fbcf5","https://git.kernel.org/stable/c/cb52d9c86d70298de0ab7c7953653898cbc0efd6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential UAF in smb2_close_cached_fid()\n\nfind_or_create_cached_dir() could grab a new reference after kref_put()\nhad seen the refcount drop to zero but before cfid_list_lock is acquired\nin smb2_close_cached_fid(), leading to use-after-free.\n\nSwitch to kref_put_lock() so cfid_release() is called with\ncfid_list_lock held, closing that gap.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40328","epss":0.00461,"percentile":0.38601,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40328","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40333","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40333","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix infinite loop in __insert_extent_tree()  When we get wrong extent info data, and look up extent_node in rb tree, it will cause infinite loop (CONFIG_F2FS_CHECK_FS=n). Avoiding this by return NULL and print some kernel messages in that case.","cvss":[],"epss":[{"cve":"CVE-2025-40333","epss":0.00221,"percentile":0.12651,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11050000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-40333","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40333","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/23361bd54966b437e1ed3eb1a704572f4b279e58","https://git.kernel.org/stable/c/765f8816d3959ef1f3f7f85e2af748594d091f40","https://git.kernel.org/stable/c/c0b9951bb2668d67eb4817bb23fc109abc08c075","https://git.kernel.org/stable/c/f4c31adcb2a0556f43776d4e51a67de88d7fb9ee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix infinite loop in __insert_extent_tree()\n\nWhen we get wrong extent info data, and look up extent_node in rb tree,\nit will cause infinite loop (CONFIG_F2FS_CHECK_FS=n). Avoiding this by\nreturn NULL and print some kernel messages in that case.","cvss":[],"epss":[{"cve":"CVE-2025-40333","epss":0.00221,"percentile":0.12651,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40333","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40337","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40337","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: stmmac: Correctly handle Rx checksum offload errors  The stmmac_rx function would previously set skb->ip_summed to CHECKSUM_UNNECESSARY if hardware checksum offload (CoE) was enabled and the packet was of a known IP ethertype.  However, this logic failed to check if the hardware had actually reported a checksum error. The hardware status, indicating a header or payload checksum failure, was being ignored at this stage. This could cause corrupt packets to be passed up the network stack as valid.  This patch corrects the logic by checking the `csum_none` status flag, which is set when the hardware reports a checksum error. If this flag is set, skb->ip_summed is now correctly set to CHECKSUM_NONE, ensuring the kernel's network stack will perform its own validation and properly handle the corrupt packet.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40337","epss":0.00481,"percentile":0.39982,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.37758499999999995},"relatedVulnerabilities":[{"id":"CVE-2025-40337","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40337","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1aa319e0f12d2d761a31556b82a5852c98eb0bea","https://git.kernel.org/stable/c/63fbe0e6413279d5ea5842e2423e351ded547683","https://git.kernel.org/stable/c/719fcdf29051f7471d5d433475af76219019d33d","https://git.kernel.org/stable/c/ee0aace5f844ef59335148875d05bec8764e71e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: Correctly handle Rx checksum offload errors\n\nThe stmmac_rx function would previously set skb->ip_summed to\nCHECKSUM_UNNECESSARY if hardware checksum offload (CoE) was enabled\nand the packet was of a known IP ethertype.\n\nHowever, this logic failed to check if the hardware had actually\nreported a checksum error. The hardware status, indicating a header or\npayload checksum failure, was being ignored at this stage. This could\ncause corrupt packets to be passed up the network stack as valid.\n\nThis patch corrects the logic by checking the `csum_none` status flag,\nwhich is set when the hardware reports a checksum error. If this flag\nis set, skb->ip_summed is now correctly set to CHECKSUM_NONE,\nensuring the kernel's network stack will perform its own validation and\nproperly handle the corrupt packet.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40337","epss":0.00481,"percentile":0.39982,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40337","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40338","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40338","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: Intel: avs: Do not share the name pointer between components  By sharing 'name' directly, tearing down components may lead to use-after-free errors. Duplicate the name to avoid that.  At the same time, update the order of operations - since commit cee28113db17 (\"ASoC: dmaengine_pcm: Allow passing component name via config\") the framework does not override component->name if set before invoking the initializer.","cvss":[],"epss":[{"cve":"CVE-2025-40338","epss":0.00215,"percentile":0.11914,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1075},"relatedVulnerabilities":[{"id":"CVE-2025-40338","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40338","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/128bf29c992988f8b4f3829227339908fde5ec86","https://git.kernel.org/stable/c/4dee5c1cc439b0d5ef87f741518268ad6a95b23d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Do not share the name pointer between components\n\nBy sharing 'name' directly, tearing down components may lead to\nuse-after-free errors. Duplicate the name to avoid that.\n\nAt the same time, update the order of operations - since commit\ncee28113db17 (\"ASoC: dmaengine_pcm: Allow passing component name via\nconfig\") the framework does not override component->name if set before\ninvoking the initializer.","cvss":[],"epss":[{"cve":"CVE-2025-40338","epss":0.00215,"percentile":0.11914,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40338","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40339","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40339","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: fix nullptr err of vm_handle_moved  If a amdgpu_bo_va is fpriv->prt_va, the bo of this one is always NULL. So, such kind of amdgpu_bo_va should be updated separately before amdgpu_vm_handle_moved.","cvss":[],"epss":[{"cve":"CVE-2025-40339","epss":0.00225,"percentile":0.13132,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11249999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-40339","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40339","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/273d1ea12e42e9babb9783837906f3c466f213d3","https://git.kernel.org/stable/c/47281febebe337586569aa4c5694a7511063a42e","https://git.kernel.org/stable/c/859958a7faefe5b7742b7b8cdbc170713d4bf158"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix nullptr err of vm_handle_moved\n\nIf a amdgpu_bo_va is fpriv->prt_va, the bo of this one is always NULL.\nSo, such kind of amdgpu_bo_va should be updated separately before\namdgpu_vm_handle_moved.","cvss":[],"epss":[{"cve":"CVE-2025-40339","epss":0.00225,"percentile":0.13132,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40339","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40354","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40354","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: increase max link count and fix link->enc NULL pointer access  [why] 1.) dc->links[MAX_LINKS] array size smaller than actual requested. max_connector + max_dpia + 4 virtual = 14. increase from 12 to 14.  2.) hw_init() access null LINK_ENC for dpia non display_endpoint.  (cherry picked from commit d7f5a61e1b04ed87b008c8d327649d184dc5bb45)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40354","epss":0.00148,"percentile":0.04314,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11322000000000002},"relatedVulnerabilities":[{"id":"CVE-2025-40354","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40354","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/a3fc0d36cfb927f8986b83bf5fba47dbedad3c63","https://git.kernel.org/stable/c/bec947cbe9a65783adb475a5fb47980d7b4f4796","https://git.kernel.org/stable/c/f28092be4e12b7df9e4f415d25bf0d767bc2d9ed"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: increase max link count and fix link->enc NULL pointer access\n\n[why]\n1.) dc->links[MAX_LINKS] array size smaller than actual requested.\nmax_connector + max_dpia + 4 virtual = 14.\nincrease from 12 to 14.\n\n2.) hw_init() access null LINK_ENC for dpia non display_endpoint.\n\n(cherry picked from commit d7f5a61e1b04ed87b008c8d327649d184dc5bb45)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-40354","epss":0.00148,"percentile":0.04314,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40354","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-40355","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-40355","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sysfs: check visibility before changing group attribute ownership  Since commit 0c17270f9b92 (\"net: sysfs: Implement is_visible for phys_(port_id, port_name, switch_id)\"), __dev_change_net_namespace() can hit WARN_ON() when trying to change owner of a file that isn't visible. See the trace below:   WARNING: CPU: 6 PID: 2938 at net/core/dev.c:12410 __dev_change_net_namespace+0xb89/0xc30  CPU: 6 UID: 0 PID: 2938 Comm: incusd Not tainted 6.17.1-1-mainline #1 PREEMPT(full)  4b783b4a638669fb644857f484487d17cb45ed1f  Hardware name: Framework Laptop 13 (AMD Ryzen 7040Series)/FRANMDCP07, BIOS 03.07 02/19/2025  RIP: 0010:__dev_change_net_namespace+0xb89/0xc30  [...]  Call Trace:   <TASK>   ? if6_seq_show+0x30/0x50   do_setlink.isra.0+0xc7/0x1270   ? __nla_validate_parse+0x5c/0xcc0   ? security_capable+0x94/0x1a0   rtnl_newlink+0x858/0xc20   ? update_curr+0x8e/0x1c0   ? update_entity_lag+0x71/0x80   ? sched_balance_newidle+0x358/0x450   ? psi_task_switch+0x113/0x2a0   ? __pfx_rtnl_newlink+0x10/0x10   rtnetlink_rcv_msg+0x346/0x3e0   ? sched_clock+0x10/0x30   ? __pfx_rtnetlink_rcv_msg+0x10/0x10   netlink_rcv_skb+0x59/0x110   netlink_unicast+0x285/0x3c0   ? __alloc_skb+0xdb/0x1a0   netlink_sendmsg+0x20d/0x430   ____sys_sendmsg+0x39f/0x3d0   ? import_iovec+0x2f/0x40   ___sys_sendmsg+0x99/0xe0   __sys_sendmsg+0x8a/0xf0   do_syscall_64+0x81/0x970   ? __sys_bind+0xe3/0x110   ? syscall_exit_work+0x143/0x1b0   ? do_syscall_64+0x244/0x970   ? sock_alloc_file+0x63/0xc0   ? syscall_exit_work+0x143/0x1b0   ? do_syscall_64+0x244/0x970   ? alloc_fd+0x12e/0x190   ? put_unused_fd+0x2a/0x70   ? do_sys_openat2+0xa2/0xe0   ? syscall_exit_work+0x143/0x1b0   ? do_syscall_64+0x244/0x970   ? exc_page_fault+0x7e/0x1a0   entry_SYSCALL_64_after_hwframe+0x76/0x7e  [...]   </TASK>  Fix this by checking is_visible() before trying to touch the attribute.","cvss":[],"epss":[{"cve":"CVE-2025-40355","epss":0.00181,"percentile":0.07753,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0905},"relatedVulnerabilities":[{"id":"CVE-2025-40355","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-40355","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/ac2c526e103285d80a0330b91a318f6c9276d35a","https://git.kernel.org/stable/c/c7fbb8218b4ad35fec0bd2256d2b9c8d60331f33"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsysfs: check visibility before changing group attribute ownership\n\nSince commit 0c17270f9b92 (\"net: sysfs: Implement is_visible for\nphys_(port_id, port_name, switch_id)\"), __dev_change_net_namespace() can\nhit WARN_ON() when trying to change owner of a file that isn't visible.\nSee the trace below:\n\n WARNING: CPU: 6 PID: 2938 at net/core/dev.c:12410 __dev_change_net_namespace+0xb89/0xc30\n CPU: 6 UID: 0 PID: 2938 Comm: incusd Not tainted 6.17.1-1-mainline #1 PREEMPT(full)  4b783b4a638669fb644857f484487d17cb45ed1f\n Hardware name: Framework Laptop 13 (AMD Ryzen 7040Series)/FRANMDCP07, BIOS 03.07 02/19/2025\n RIP: 0010:__dev_change_net_namespace+0xb89/0xc30\n [...]\n Call Trace:\n  <TASK>\n  ? if6_seq_show+0x30/0x50\n  do_setlink.isra.0+0xc7/0x1270\n  ? __nla_validate_parse+0x5c/0xcc0\n  ? security_capable+0x94/0x1a0\n  rtnl_newlink+0x858/0xc20\n  ? update_curr+0x8e/0x1c0\n  ? update_entity_lag+0x71/0x80\n  ? sched_balance_newidle+0x358/0x450\n  ? psi_task_switch+0x113/0x2a0\n  ? __pfx_rtnl_newlink+0x10/0x10\n  rtnetlink_rcv_msg+0x346/0x3e0\n  ? sched_clock+0x10/0x30\n  ? __pfx_rtnetlink_rcv_msg+0x10/0x10\n  netlink_rcv_skb+0x59/0x110\n  netlink_unicast+0x285/0x3c0\n  ? __alloc_skb+0xdb/0x1a0\n  netlink_sendmsg+0x20d/0x430\n  ____sys_sendmsg+0x39f/0x3d0\n  ? import_iovec+0x2f/0x40\n  ___sys_sendmsg+0x99/0xe0\n  __sys_sendmsg+0x8a/0xf0\n  do_syscall_64+0x81/0x970\n  ? __sys_bind+0xe3/0x110\n  ? syscall_exit_work+0x143/0x1b0\n  ? do_syscall_64+0x244/0x970\n  ? sock_alloc_file+0x63/0xc0\n  ? syscall_exit_work+0x143/0x1b0\n  ? do_syscall_64+0x244/0x970\n  ? alloc_fd+0x12e/0x190\n  ? put_unused_fd+0x2a/0x70\n  ? do_sys_openat2+0xa2/0xe0\n  ? syscall_exit_work+0x143/0x1b0\n  ? do_syscall_64+0x244/0x970\n  ? exc_page_fault+0x7e/0x1a0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n [...]\n  </TASK>\n\nFix this by checking is_visible() before trying to touch the attribute.","cvss":[],"epss":[{"cve":"CVE-2025-40355","epss":0.00181,"percentile":0.07753,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-40355","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68183","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68183","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr  Currently when both IMA and EVM are in fix mode, the IMA signature will be reset to IMA hash if a program first stores IMA signature in security.ima and then writes/removes some other security xattr for the file.  For example, on Fedora, after booting the kernel with \"ima_appraise=fix evm=fix ima_policy=appraise_tcb\" and installing rpm-plugin-ima, installing/reinstalling a package will not make good reference IMA signature generated. Instead IMA hash is generated,      # getfattr -m - -d -e hex /usr/bin/bash     # file: usr/bin/bash     security.ima=0x0404...  This happens because when setting security.selinux, the IMA_DIGSIG flag that had been set early was cleared. As a result, IMA hash is generated when the file is closed.  Similarly, IMA signature can be cleared on file close after removing security xattr like security.evm or setting/removing ACL.  Prevent replacing the IMA file signature with a file hash, by preventing the IMA_DIGSIG flag from being reset.  Here's a minimal C reproducer which sets security.selinux as the last step which can also replaced by removing security.evm or setting ACL,      #include <stdio.h>     #include <sys/xattr.h>     #include <fcntl.h>     #include <unistd.h>     #include <string.h>     #include <stdlib.h>      int main() {         const char* file_path = \"/usr/sbin/test_binary\";         const char* hex_string = \"030204d33204490066306402304\";         int length = strlen(hex_string);         char* ima_attr_value;         int fd;          fd = open(file_path, O_WRONLY|O_CREAT|O_EXCL, 0644);         if (fd == -1) {             perror(\"Error opening file\");             return 1;         }          ima_attr_value = (char*)malloc(length / 2 );         for (int i = 0, j = 0; i < length; i += 2, j++) {             sscanf(hex_string + i, \"%2hhx\", &ima_attr_value[j]);         }          if (fsetxattr(fd, \"security.ima\", ima_attr_value, length/2, 0) == -1) {             perror(\"Error setting extended attribute\");             close(fd);             return 1;         }          const char* selinux_value= \"system_u:object_r:bin_t:s0\";         if (fsetxattr(fd, \"security.selinux\", selinux_value, strlen(selinux_value), 0) == -1) {             perror(\"Error setting extended attribute\");             close(fd);             return 1;         }          close(fd);          return 0;     }","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68183","epss":0.00151,"percentile":0.04548,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11551499999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68183","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68183","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/02aa671c08a4834bef5166743a7b88686fbfa023","https://git.kernel.org/stable/c/88b4cbcf6b041ae0f2fc8a34554a5b6a83a2b7cd","https://git.kernel.org/stable/c/d2993a7e98eb70c737c6f5365a190e79c72b8407","https://git.kernel.org/stable/c/edd824eb45e4f7e05ad3ab090dab6dbdb79cd292"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr\n\nCurrently when both IMA and EVM are in fix mode, the IMA signature will\nbe reset to IMA hash if a program first stores IMA signature in\nsecurity.ima and then writes/removes some other security xattr for the\nfile.\n\nFor example, on Fedora, after booting the kernel with \"ima_appraise=fix\nevm=fix ima_policy=appraise_tcb\" and installing rpm-plugin-ima,\ninstalling/reinstalling a package will not make good reference IMA\nsignature generated. Instead IMA hash is generated,\n\n    # getfattr -m - -d -e hex /usr/bin/bash\n    # file: usr/bin/bash\n    security.ima=0x0404...\n\nThis happens because when setting security.selinux, the IMA_DIGSIG flag\nthat had been set early was cleared. As a result, IMA hash is generated\nwhen the file is closed.\n\nSimilarly, IMA signature can be cleared on file close after removing\nsecurity xattr like security.evm or setting/removing ACL.\n\nPrevent replacing the IMA file signature with a file hash, by preventing\nthe IMA_DIGSIG flag from being reset.\n\nHere's a minimal C reproducer which sets security.selinux as the last\nstep which can also replaced by removing security.evm or setting ACL,\n\n    #include <stdio.h>\n    #include <sys/xattr.h>\n    #include <fcntl.h>\n    #include <unistd.h>\n    #include <string.h>\n    #include <stdlib.h>\n\n    int main() {\n        const char* file_path = \"/usr/sbin/test_binary\";\n        const char* hex_string = \"030204d33204490066306402304\";\n        int length = strlen(hex_string);\n        char* ima_attr_value;\n        int fd;\n\n        fd = open(file_path, O_WRONLY|O_CREAT|O_EXCL, 0644);\n        if (fd == -1) {\n            perror(\"Error opening file\");\n            return 1;\n        }\n\n        ima_attr_value = (char*)malloc(length / 2 );\n        for (int i = 0, j = 0; i < length; i += 2, j++) {\n            sscanf(hex_string + i, \"%2hhx\", &ima_attr_value[j]);\n        }\n\n        if (fsetxattr(fd, \"security.ima\", ima_attr_value, length/2, 0) == -1) {\n            perror(\"Error setting extended attribute\");\n            close(fd);\n            return 1;\n        }\n\n        const char* selinux_value= \"system_u:object_r:bin_t:s0\";\n        if (fsetxattr(fd, \"security.selinux\", selinux_value, strlen(selinux_value), 0) == -1) {\n            perror(\"Error setting extended attribute\");\n            close(fd);\n            return 1;\n        }\n\n        close(fd);\n\n        return 0;\n    }","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68183","epss":0.00151,"percentile":0.04548,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68183","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68188","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68188","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()  Use RCU to avoid a pair of atomic operations and a potential UAF on dst_dev()->flags.","cvss":[],"epss":[{"cve":"CVE-2025-68188","epss":0.00194,"percentile":0.09252,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097},"relatedVulnerabilities":[{"id":"CVE-2025-68188","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68188","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/06da08d9355bf8e2070459bbedbe372ccc02cc0e","https://git.kernel.org/stable/c/b62a59c18b692f892dcb8109c1c2e653b2abc95c","https://git.kernel.org/stable/c/bc2b881a0896c111c1041d8bb1f92a3b3873ace5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()\n\nUse RCU to avoid a pair of atomic operations and a potential\nUAF on dst_dev()->flags.","cvss":[],"epss":[{"cve":"CVE-2025-68188","epss":0.00194,"percentile":0.09252,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68188","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68190","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68190","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked()  kcalloc() may fail. When WS is non-zero and allocation fails, ectx.ws remains NULL while ectx.ws_size is set, leading to a potential NULL pointer dereference in atom_get_src_int() when accessing WS entries.  Return -ENOMEM on allocation failure to avoid the NULL dereference.","cvss":[],"epss":[{"cve":"CVE-2025-68190","epss":0.00193,"percentile":0.09052,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0965},"relatedVulnerabilities":[{"id":"CVE-2025-68190","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68190","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/35f3fb86bb0158a298d6834e7e110dcaf07f490c","https://git.kernel.org/stable/c/997e28d3d00a1d30649629515e4402612921205b","https://git.kernel.org/stable/c/cc9a8e238e42c1f43b98c097995137d644b69245"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked()\n\nkcalloc() may fail. When WS is non-zero and allocation fails, ectx.ws\nremains NULL while ectx.ws_size is set, leading to a potential NULL\npointer dereference in atom_get_src_int() when accessing WS entries.\n\nReturn -ENOMEM on allocation failure to avoid the NULL dereference.","cvss":[],"epss":[{"cve":"CVE-2025-68190","epss":0.00193,"percentile":0.09052,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68190","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68209","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68209","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mlx5: Fix default values in create CQ  Currently, CQs without a completion function are assigned the mlx5_add_cq_to_tasklet function by default. This is problematic since only user CQs created through the mlx5_ib driver are intended to use this function.  Additionally, all CQs that will use doorbells instead of polling for completions must call mlx5_cq_arm. However, the default CQ creation flow leaves a valid value in the CQ's arm_db field, allowing FW to send interrupts to polling-only CQs in certain corner cases.  These two factors would allow a polling-only kernel CQ to be triggered by an EQ interrupt and call a completion function intended only for user CQs, causing a null pointer exception.  Some areas in the driver have prevented this issue with one-off fixes but did not address the root cause.  This patch fixes the described issue by adding defaults to the create CQ flow. It adds a default dummy completion function to protect against null pointer exceptions, and it sets an invalid command sequence number by default in kernel CQs to prevent the FW from sending an interrupt to the CQ until it is armed. User CQs are responsible for their own initialization values.  Callers of mlx5_core_create_cq are responsible for changing the completion function and arming the CQ per their needs.","cvss":[],"epss":[{"cve":"CVE-2025-68209","epss":0.00181,"percentile":0.07754,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0905},"relatedVulnerabilities":[{"id":"CVE-2025-68209","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68209","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/08469f5393a1a39f26a6e2eb2e8c33187665c1f4","https://git.kernel.org/stable/c/e5eba42f01340f73888dfe560be2806057c25913"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmlx5: Fix default values in create CQ\n\nCurrently, CQs without a completion function are assigned the\nmlx5_add_cq_to_tasklet function by default. This is problematic since\nonly user CQs created through the mlx5_ib driver are intended to use\nthis function.\n\nAdditionally, all CQs that will use doorbells instead of polling for\ncompletions must call mlx5_cq_arm. However, the default CQ creation flow\nleaves a valid value in the CQ's arm_db field, allowing FW to send\ninterrupts to polling-only CQs in certain corner cases.\n\nThese two factors would allow a polling-only kernel CQ to be triggered\nby an EQ interrupt and call a completion function intended only for user\nCQs, causing a null pointer exception.\n\nSome areas in the driver have prevented this issue with one-off fixes\nbut did not address the root cause.\n\nThis patch fixes the described issue by adding defaults to the create CQ\nflow. It adds a default dummy completion function to protect against\nnull pointer exceptions, and it sets an invalid command sequence number\nby default in kernel CQs to prevent the FW from sending an interrupt to\nthe CQ until it is armed. User CQs are responsible for their own\ninitialization values.\n\nCallers of mlx5_core_create_cq are responsible for changing the\ncompletion function and arming the CQ per their needs.","cvss":[],"epss":[{"cve":"CVE-2025-68209","epss":0.00181,"percentile":0.07754,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68209","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68219","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cifs: fix memory leak in smb3_fs_context_parse_param error path  Add proper cleanup of ctx->source and fc->source to the cifs_parse_mount_err error handler. This ensures that memory allocated for the source strings is correctly freed on all error paths, matching the cleanup already performed in the success path by smb3_cleanup_fs_context_contents(). Pointers are also set to NULL after freeing to prevent potential double-free issues.  This change fixes a memory leak originally detected by syzbot. The leak occurred when processing Opt_source mount options if an error happened after ctx->source and fc->source were successfully allocated but before the function completed.  The specific leak sequence was: 1. ctx->source = smb3_fs_context_fullpath(ctx, '/') allocates memory 2. fc->source = kstrdup(ctx->source, GFP_KERNEL) allocates more memory 3. A subsequent error jumps to cifs_parse_mount_err 4. The old error handler freed passwords but not the source strings, causing the memory to leak.  This issue was not addressed by commit e8c73eb7db0a (\"cifs: client: fix memory leak in smb3_fs_context_parse_param\"), which only fixed leaks from repeated fsconfig() calls but not this error path.  Patch updated with minor change suggested by kernel test robot","cvss":[],"epss":[{"cve":"CVE-2025-68219","epss":0.00195,"percentile":0.09312,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-68219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68219","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/37010021d7e0341bb241ca00bcbae31f2c50b23f","https://git.kernel.org/stable/c/48d69290270891f988e72edddd9688c20515421d","https://git.kernel.org/stable/c/7627864dc3121f39e220f5253a227edf472de59e","https://git.kernel.org/stable/c/7e4d9120cfa413dd34f4f434befc5dbe6c38b2e5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix memory leak in smb3_fs_context_parse_param error path\n\nAdd proper cleanup of ctx->source and fc->source to the\ncifs_parse_mount_err error handler. This ensures that memory allocated\nfor the source strings is correctly freed on all error paths, matching\nthe cleanup already performed in the success path by\nsmb3_cleanup_fs_context_contents().\nPointers are also set to NULL after freeing to prevent potential\ndouble-free issues.\n\nThis change fixes a memory leak originally detected by syzbot. The\nleak occurred when processing Opt_source mount options if an error\nhappened after ctx->source and fc->source were successfully\nallocated but before the function completed.\n\nThe specific leak sequence was:\n1. ctx->source = smb3_fs_context_fullpath(ctx, '/') allocates memory\n2. fc->source = kstrdup(ctx->source, GFP_KERNEL) allocates more memory\n3. A subsequent error jumps to cifs_parse_mount_err\n4. The old error handler freed passwords but not the source strings,\ncausing the memory to leak.\n\nThis issue was not addressed by commit e8c73eb7db0a (\"cifs: client:\nfix memory leak in smb3_fs_context_parse_param\"), which only fixed\nleaks from repeated fsconfig() calls but not this error path.\n\nPatch updated with minor change suggested by kernel test robot","cvss":[],"epss":[{"cve":"CVE-2025-68219","epss":0.00195,"percentile":0.09312,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68236","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68236","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3)  According to UFS specifications, the power-off sequence for a UFS device includes:   - Sending an SSU command with Power_Condition=3 and await a response.   - Asserting RST_N low.   - Turning off REF_CLK.   - Turning off VCC.   - Turning off VCCQ/VCCQ2.  As part of ufs shutdown, after the SSU command completion, asserting hardware reset (HWRST) triggers the device firmware to wake up and execute its reset routine. This routine initializes hardware blocks and takes a few milliseconds to complete. During this time, the ICCQ draws a large current.  This large ICCQ current may cause issues for the regulator which is supplying power to UFS, because the turn off request from UFS driver to the regulator framework will be immediately followed by low power mode(LPM) request by regulator framework. This is done by framework because UFS which is the only client is requesting for disable. So if the rail is still in the process of shutting down while ICCQ exceeds LPM current thresholds, and LPM mode is activated in hardware during this state, it may trigger an overcurrent protection (OCP) fault in the regulator.  To prevent this, a 10ms delay is added after asserting HWRST. This allows the reset operation to complete while power rails remain active and in high-power mode.  Currently there is no way for Host to query whether the reset is completed or not and hence this the delay is based on experiments with Qualcomm UFS controllers across multiple UFS vendors.","cvss":[],"epss":[{"cve":"CVE-2025-68236","epss":0.00168,"percentile":0.06394,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2025-68236","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68236","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/5127be409c6c3815c4a7d8f6d88043e44f9b9543","https://git.kernel.org/stable/c/b712f234a74c1f5ce70b5d7aec3fc2499c258141"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3)\n\nAccording to UFS specifications, the power-off sequence for a UFS device\nincludes:\n\n - Sending an SSU command with Power_Condition=3 and await a response.\n\n - Asserting RST_N low.\n\n - Turning off REF_CLK.\n\n - Turning off VCC.\n\n - Turning off VCCQ/VCCQ2.\n\nAs part of ufs shutdown, after the SSU command completion, asserting\nhardware reset (HWRST) triggers the device firmware to wake up and\nexecute its reset routine. This routine initializes hardware blocks and\ntakes a few milliseconds to complete. During this time, the ICCQ draws a\nlarge current.\n\nThis large ICCQ current may cause issues for the regulator which is\nsupplying power to UFS, because the turn off request from UFS driver to\nthe regulator framework will be immediately followed by low power\nmode(LPM) request by regulator framework. This is done by framework\nbecause UFS which is the only client is requesting for disable. So if\nthe rail is still in the process of shutting down while ICCQ exceeds LPM\ncurrent thresholds, and LPM mode is activated in hardware during this\nstate, it may trigger an overcurrent protection (OCP) fault in the\nregulator.\n\nTo prevent this, a 10ms delay is added after asserting HWRST. This\nallows the reset operation to complete while power rails remain active\nand in high-power mode.\n\nCurrently there is no way for Host to query whether the reset is\ncompleted or not and hence this the delay is based on experiments with\nQualcomm UFS controllers across multiple UFS vendors.","cvss":[],"epss":[{"cve":"CVE-2025-68236","epss":0.00168,"percentile":0.06394,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68236","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68296","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68296","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup  Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). Without holding the console lock the call races with switching outputs.  VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon function uses struct fb_info.node, which is set by register_framebuffer(). As the fb-helper code currently sets up VGA switcheroo before registering the framebuffer, the value of node is -1 and therefore not a legal value. For example, fbcon uses the value within set_con2fb_map() [1] as an index into an array.  Moving vga_switcheroo_client_fb_set() after register_framebuffer() can result in VGA switching that does not switch fbcon correctly.  Therefore move vga_switcheroo_client_fb_set() under fbcon_fb_registered(), which already holds the console lock. Fbdev calls fbcon_fb_registered() from within register_framebuffer(). Serializes the helper with VGA switcheroo's call to fbcon_remap_all().  Although vga_switcheroo_client_fb_set() takes an instance of struct fb_info as parameter, it really only needs the contained fbcon state. Moving the call to fbcon initialization is therefore cleaner than before. Only amdgpu, i915, nouveau and radeon support vga_switcheroo. For all other drivers, this change does nothing.","cvss":[],"epss":[{"cve":"CVE-2025-68296","epss":0.00201,"percentile":0.10021,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1005},"relatedVulnerabilities":[{"id":"CVE-2025-68296","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68296","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a","https://git.kernel.org/stable/c/482330f8261b4bea8146d9bd69c1199e5dfcbb5c","https://git.kernel.org/stable/c/711ebd961190def4c69ea24b2f0be75e995af24a","https://git.kernel.org/stable/c/eb76d0f5553575599561010f24c277cc5b31d003"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup\n\nProtect vga_switcheroo_client_fb_set() with console lock. Avoids OOB\naccess in fbcon_remap_all(). Without holding the console lock the call\nraces with switching outputs.\n\nVGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon\nfunction uses struct fb_info.node, which is set by register_framebuffer().\nAs the fb-helper code currently sets up VGA switcheroo before registering\nthe framebuffer, the value of node is -1 and therefore not a legal value.\nFor example, fbcon uses the value within set_con2fb_map() [1] as an index\ninto an array.\n\nMoving vga_switcheroo_client_fb_set() after register_framebuffer() can\nresult in VGA switching that does not switch fbcon correctly.\n\nTherefore move vga_switcheroo_client_fb_set() under fbcon_fb_registered(),\nwhich already holds the console lock. Fbdev calls fbcon_fb_registered()\nfrom within register_framebuffer(). Serializes the helper with VGA\nswitcheroo's call to fbcon_remap_all().\n\nAlthough vga_switcheroo_client_fb_set() takes an instance of struct fb_info\nas parameter, it really only needs the contained fbcon state. Moving the\ncall to fbcon initialization is therefore cleaner than before. Only amdgpu,\ni915, nouveau and radeon support vga_switcheroo. For all other drivers,\nthis change does nothing.","cvss":[],"epss":[{"cve":"CVE-2025-68296","epss":0.00201,"percentile":0.10021,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68296","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68304","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68304","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_core: lookup hci_conn on RX path on protocol side  The hdev lock/lookup/unlock/use pattern in the packet RX path doesn't ensure hci_conn* is not concurrently modified/deleted. This locking appears to be leftover from before conn_hash started using RCU commit bf4c63252490b (\"Bluetooth: convert conn hash to RCU\") and not clear if it had purpose since then.  Currently, there are code paths that delete hci_conn* from elsewhere than the ordered hdev->workqueue where the RX work runs in. E.g. commit 5af1f84ed13a (\"Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync\") introduced some of these, and there probably were a few others before it.  It's better to do the locking so that even if these run concurrently no UAF is possible.  Move the lookup of hci_conn and associated socket-specific conn to protocol recv handlers, and do them within a single critical section to cover hci_conn* usage and lookup.  syzkaller has reported a crash that appears to be this issue:      [Task hdev->workqueue]          [Task 2]                                     hci_disconnect_all_sync     l2cap_recv_acldata(hcon)                                       hci_conn_get(hcon)                                       hci_abort_conn_sync(hcon)                                         hci_dev_lock       hci_dev_lock                                         hci_conn_del(hcon)       v-------------------------------- hci_dev_unlock                                       hci_conn_put(hcon)       conn = hcon->l2cap_data (UAF)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68304","epss":0.00227,"percentile":0.13455,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.185005},"relatedVulnerabilities":[{"id":"CVE-2025-68304","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68304","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/79a2d4678ba90bdba577dc3af88cc900d6dcd5ee","https://git.kernel.org/stable/c/ec74cdf77310c43b01b83ee898a9bd4b4b0b8e93"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: lookup hci_conn on RX path on protocol side\n\nThe hdev lock/lookup/unlock/use pattern in the packet RX path doesn't\nensure hci_conn* is not concurrently modified/deleted. This locking\nappears to be leftover from before conn_hash started using RCU\ncommit bf4c63252490b (\"Bluetooth: convert conn hash to RCU\")\nand not clear if it had purpose since then.\n\nCurrently, there are code paths that delete hci_conn* from elsewhere\nthan the ordered hdev->workqueue where the RX work runs in. E.g.\ncommit 5af1f84ed13a (\"Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync\")\nintroduced some of these, and there probably were a few others before\nit.  It's better to do the locking so that even if these run\nconcurrently no UAF is possible.\n\nMove the lookup of hci_conn and associated socket-specific conn to\nprotocol recv handlers, and do them within a single critical section\nto cover hci_conn* usage and lookup.\n\nsyzkaller has reported a crash that appears to be this issue:\n\n    [Task hdev->workqueue]          [Task 2]\n                                    hci_disconnect_all_sync\n    l2cap_recv_acldata(hcon)\n                                      hci_conn_get(hcon)\n                                      hci_abort_conn_sync(hcon)\n                                        hci_dev_lock\n      hci_dev_lock\n                                        hci_conn_del(hcon)\n      v-------------------------------- hci_dev_unlock\n                                      hci_conn_put(hcon)\n      conn = hcon->l2cap_data (UAF)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68304","epss":0.00227,"percentile":0.13455,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68304","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68320","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68320","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  lan966x: Fix sleeping in atomic context  The following warning was seen when we try to connect using ssh to the device.  BUG: sleeping function called from invalid context at kernel/locking/mutex.c:575 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 104, name: dropbear preempt_count: 1, expected: 0 INFO: lockdep is turned off. CPU: 0 UID: 0 PID: 104 Comm: dropbear Tainted: G        W           6.18.0-rc2-00399-g6f1ab1b109b9-dirty #530 NONE Tainted: [W]=WARN Hardware name: Generic DT based system Call trace:  unwind_backtrace from show_stack+0x10/0x14  show_stack from dump_stack_lvl+0x7c/0xac  dump_stack_lvl from __might_resched+0x16c/0x2b0  __might_resched from __mutex_lock+0x64/0xd34  __mutex_lock from mutex_lock_nested+0x1c/0x24  mutex_lock_nested from lan966x_stats_get+0x5c/0x558  lan966x_stats_get from dev_get_stats+0x40/0x43c  dev_get_stats from dev_seq_printf_stats+0x3c/0x184  dev_seq_printf_stats from dev_seq_show+0x10/0x30  dev_seq_show from seq_read_iter+0x350/0x4ec  seq_read_iter from seq_read+0xfc/0x194  seq_read from proc_reg_read+0xac/0x100  proc_reg_read from vfs_read+0xb0/0x2b0  vfs_read from ksys_read+0x6c/0xec  ksys_read from ret_fast_syscall+0x0/0x1c Exception stack(0xf0b11fa8 to 0xf0b11ff0) 1fa0:                   00000001 00001000 00000008 be9048d8 00001000 00000001 1fc0: 00000001 00001000 00000008 00000003 be905920 0000001e 00000000 00000001 1fe0: 0005404c be9048c0 00018684 b6ec2cd8  It seems that we are using a mutex in a atomic context which is wrong. Change the mutex with a spinlock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68320","epss":0.00405,"percentile":0.33989,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.30374999999999996},"relatedVulnerabilities":[{"id":"CVE-2025-68320","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68320","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0216721ce71252f60d89af49c8dff613358058d3","https://git.kernel.org/stable/c/3ac743c60ec502163c435712d527eeced8d83348","https://git.kernel.org/stable/c/5a5d2f7727752b64d13263eacd9f8d08a322e662","https://git.kernel.org/stable/c/c8ab03aa5bd9fd8bfe5d9552d8605826759fdd4d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlan966x: Fix sleeping in atomic context\n\nThe following warning was seen when we try to connect using ssh to the device.\n\nBUG: sleeping function called from invalid context at kernel/locking/mutex.c:575\nin_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 104, name: dropbear\npreempt_count: 1, expected: 0\nINFO: lockdep is turned off.\nCPU: 0 UID: 0 PID: 104 Comm: dropbear Tainted: G        W           6.18.0-rc2-00399-g6f1ab1b109b9-dirty #530 NONE\nTainted: [W]=WARN\nHardware name: Generic DT based system\nCall trace:\n unwind_backtrace from show_stack+0x10/0x14\n show_stack from dump_stack_lvl+0x7c/0xac\n dump_stack_lvl from __might_resched+0x16c/0x2b0\n __might_resched from __mutex_lock+0x64/0xd34\n __mutex_lock from mutex_lock_nested+0x1c/0x24\n mutex_lock_nested from lan966x_stats_get+0x5c/0x558\n lan966x_stats_get from dev_get_stats+0x40/0x43c\n dev_get_stats from dev_seq_printf_stats+0x3c/0x184\n dev_seq_printf_stats from dev_seq_show+0x10/0x30\n dev_seq_show from seq_read_iter+0x350/0x4ec\n seq_read_iter from seq_read+0xfc/0x194\n seq_read from proc_reg_read+0xac/0x100\n proc_reg_read from vfs_read+0xb0/0x2b0\n vfs_read from ksys_read+0x6c/0xec\n ksys_read from ret_fast_syscall+0x0/0x1c\nException stack(0xf0b11fa8 to 0xf0b11ff0)\n1fa0:                   00000001 00001000 00000008 be9048d8 00001000 00000001\n1fc0: 00000001 00001000 00000008 00000003 be905920 0000001e 00000000 00000001\n1fe0: 0005404c be9048c0 00018684 b6ec2cd8\n\nIt seems that we are using a mutex in a atomic context which is wrong.\nChange the mutex with a spinlock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68320","epss":0.00405,"percentile":0.33989,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68320","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68322","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68322","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  parisc: Avoid crash due to unaligned access in unwinder  Guenter Roeck reported this kernel crash on his emulated B160L machine:  Starting network: udhcpc: started, v1.36.1  Backtrace:   [<104320d4>] unwind_once+0x1c/0x5c   [<10434a00>] walk_stackframe.isra.0+0x74/0xb8   [<10434a6c>] arch_stack_walk+0x28/0x38   [<104e5efc>] stack_trace_save+0x48/0x5c   [<105d1bdc>] set_track_prepare+0x44/0x6c   [<105d9c80>] ___slab_alloc+0xfc4/0x1024   [<105d9d38>] __slab_alloc.isra.0+0x58/0x90   [<105dc80c>] kmem_cache_alloc_noprof+0x2ac/0x4a0   [<105b8e54>] __anon_vma_prepare+0x60/0x280   [<105a823c>] __vmf_anon_prepare+0x68/0x94   [<105a8b34>] do_wp_page+0x8cc/0xf10   [<105aad88>] handle_mm_fault+0x6c0/0xf08   [<10425568>] do_page_fault+0x110/0x440   [<10427938>] handle_interruption+0x184/0x748   [<11178398>] schedule+0x4c/0x190   BUG: spinlock recursion on CPU#0, ifconfig/2420   lock: terminate_lock.2+0x0/0x1c, .magic: dead4ead, .owner: ifconfig/2420, .owner_cpu: 0  While creating the stack trace, the unwinder uses the stack pointer to guess the previous frame to read the previous stack pointer from memory.  The crash happens, because the unwinder tries to read from unaligned memory and as such triggers the unalignment trap handler which then leads to the spinlock recursion and finally to a deadlock.  Fix it by checking the alignment before accessing the memory.","cvss":[],"epss":[{"cve":"CVE-2025-68322","epss":0.0018,"percentile":0.07611,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09},"relatedVulnerabilities":[{"id":"CVE-2025-68322","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68322","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/009270208f76456c2cefcd565da263b90bb2eadb","https://git.kernel.org/stable/c/9ac1f44723f26881b9fe7e69c7bc25397b879155","https://git.kernel.org/stable/c/fd9f30d1038ee1624baa17a6ff11effe5f7617cb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Avoid crash due to unaligned access in unwinder\n\nGuenter Roeck reported this kernel crash on his emulated B160L machine:\n\nStarting network: udhcpc: started, v1.36.1\n Backtrace:\n  [<104320d4>] unwind_once+0x1c/0x5c\n  [<10434a00>] walk_stackframe.isra.0+0x74/0xb8\n  [<10434a6c>] arch_stack_walk+0x28/0x38\n  [<104e5efc>] stack_trace_save+0x48/0x5c\n  [<105d1bdc>] set_track_prepare+0x44/0x6c\n  [<105d9c80>] ___slab_alloc+0xfc4/0x1024\n  [<105d9d38>] __slab_alloc.isra.0+0x58/0x90\n  [<105dc80c>] kmem_cache_alloc_noprof+0x2ac/0x4a0\n  [<105b8e54>] __anon_vma_prepare+0x60/0x280\n  [<105a823c>] __vmf_anon_prepare+0x68/0x94\n  [<105a8b34>] do_wp_page+0x8cc/0xf10\n  [<105aad88>] handle_mm_fault+0x6c0/0xf08\n  [<10425568>] do_page_fault+0x110/0x440\n  [<10427938>] handle_interruption+0x184/0x748\n  [<11178398>] schedule+0x4c/0x190\n  BUG: spinlock recursion on CPU#0, ifconfig/2420\n  lock: terminate_lock.2+0x0/0x1c, .magic: dead4ead, .owner: ifconfig/2420, .owner_cpu: 0\n\nWhile creating the stack trace, the unwinder uses the stack pointer to guess\nthe previous frame to read the previous stack pointer from memory.  The crash\nhappens, because the unwinder tries to read from unaligned memory and as such\ntriggers the unalignment trap handler which then leads to the spinlock\nrecursion and finally to a deadlock.\n\nFix it by checking the alignment before accessing the memory.","cvss":[],"epss":[{"cve":"CVE-2025-68322","epss":0.0018,"percentile":0.07611,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68322","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68324","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68324","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: imm: Fix use-after-free bug caused by unfinished delayed work  The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands.  When the IMM parallel port SCSI host adapter is detached through imm_detach(), the imm_struct device instance is deallocated.  However, the delayed work might still be pending or executing when imm_detach() is called, leading to use-after-free bugs when the work function imm_interrupt() accesses the already freed imm_struct memory.  The race condition can occur as follows:  CPU 0(detach thread)   | CPU 1                        | imm_queuecommand()                        |   imm_queuecommand_lck() imm_detach()           |     schedule_delayed_work()   kfree(dev) //FREE    | imm_interrupt()                        |   dev = container_of(...) //USE                            dev-> //USE  Add disable_delayed_work_sync() in imm_detach() to guarantee proper cancellation of the delayed work item before imm_struct is deallocated.","cvss":[],"epss":[{"cve":"CVE-2025-68324","epss":0.00183,"percentile":0.08006,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0915},"relatedVulnerabilities":[{"id":"CVE-2025-68324","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68324","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/31ab2aad7a7b7501e904a09bf361e44671f66092","https://git.kernel.org/stable/c/48dd41fa2d6c6a0c50e714deeba06ffe7f91961b","https://git.kernel.org/stable/c/9e434426cc23ad5e2aad649327b59aea00294b13","https://git.kernel.org/stable/c/ab58153ec64fa3fc9aea09ca09dc9322e0b54a7c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: imm: Fix use-after-free bug caused by unfinished delayed work\n\nThe delayed work item 'imm_tq' is initialized in imm_attach() and\nscheduled via imm_queuecommand() for processing SCSI commands.  When the\nIMM parallel port SCSI host adapter is detached through imm_detach(),\nthe imm_struct device instance is deallocated.\n\nHowever, the delayed work might still be pending or executing\nwhen imm_detach() is called, leading to use-after-free bugs\nwhen the work function imm_interrupt() accesses the already\nfreed imm_struct memory.\n\nThe race condition can occur as follows:\n\nCPU 0(detach thread)   | CPU 1\n                       | imm_queuecommand()\n                       |   imm_queuecommand_lck()\nimm_detach()           |     schedule_delayed_work()\n  kfree(dev) //FREE    | imm_interrupt()\n                       |   dev = container_of(...) //USE\n                           dev-> //USE\n\nAdd disable_delayed_work_sync() in imm_detach() to guarantee proper\ncancellation of the delayed work item before imm_struct is deallocated.","cvss":[],"epss":[{"cve":"CVE-2025-68324","epss":0.00183,"percentile":0.08006,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68324","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68334","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68334","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  platform/x86/amd/pmc: Add support for Van Gogh SoC  The ROG Xbox Ally (non-X) SoC features a similar architecture to the Steam Deck. While the Steam Deck supports S3 (s2idle causes a crash), this support was dropped by the Xbox Ally which only S0ix suspend.  Since the handler is missing here, this causes the device to not suspend and the AMD GPU driver to crash while trying to resume afterwards due to a power hang.","cvss":[],"epss":[{"cve":"CVE-2025-68334","epss":0.00183,"percentile":0.08005,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0915},"relatedVulnerabilities":[{"id":"CVE-2025-68334","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68334","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/8af210df4f71dda74dc027da69372a028c6d4d84","https://git.kernel.org/stable/c/9654c56b111cd1415aca7e77f0c63c109453c409","https://git.kernel.org/stable/c/996092ba6df66e2ac8cf9022007a7c8a412e7733","https://git.kernel.org/stable/c/db4a3f0fbedb0398f77b9047e8b8bb2b49f355bb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Add support for Van Gogh SoC\n\nThe ROG Xbox Ally (non-X) SoC features a similar architecture to the\nSteam Deck. While the Steam Deck supports S3 (s2idle causes a crash),\nthis support was dropped by the Xbox Ally which only S0ix suspend.\n\nSince the handler is missing here, this causes the device to not suspend\nand the AMD GPU driver to crash while trying to resume afterwards due to\na power hang.","cvss":[],"epss":[{"cve":"CVE-2025-68334","epss":0.00183,"percentile":0.08005,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68334","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68342","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68342","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data  The URB received in gs_usb_receive_bulk_callback() contains a struct gs_host_frame. The length of the data after the header depends on the gs_host_frame hf::flags and the active device features (e.g. time stamping).  Introduce a new function gs_usb_get_minimum_length() and check that we have at least received the required amount of data before accessing it. Only copy the data to that skb that has actually been received.  [mkl: rename gs_usb_get_minimum_length() -> +gs_usb_get_minimum_rx_length()]","cvss":[],"epss":[{"cve":"CVE-2025-68342","epss":0.00182,"percentile":0.07852,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.091},"relatedVulnerabilities":[{"id":"CVE-2025-68342","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68342","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/395d988f93861101ec89d0dd9e3b876ae9392a5b","https://git.kernel.org/stable/c/4ffac725154cf6a253f5e6aa0c8946232b6a0af5","https://git.kernel.org/stable/c/ad55004a3cb5b41ef78aa6c09e7bc5a489ba652b","https://git.kernel.org/stable/c/fb0c7c77a7ae3a2c3404b7d0173b8739a754b513"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data\n\nThe URB received in gs_usb_receive_bulk_callback() contains a struct\ngs_host_frame. The length of the data after the header depends on the\ngs_host_frame hf::flags and the active device features (e.g. time\nstamping).\n\nIntroduce a new function gs_usb_get_minimum_length() and check that we have\nat least received the required amount of data before accessing it. Only\ncopy the data to that skb that has actually been received.\n\n[mkl: rename gs_usb_get_minimum_length() -> +gs_usb_get_minimum_rx_length()]","cvss":[],"epss":[{"cve":"CVE-2025-68342","epss":0.00182,"percentile":0.07852,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68342","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68378","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68378","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix stackmap overflow check in __bpf_get_stackid()  Syzkaller reported a KASAN slab-out-of-bounds write in __bpf_get_stackid() when copying stack trace data. The issue occurs when the perf trace  contains more stack entries than the stack map bucket can hold,  leading to an out-of-bounds write in the bucket's data array.","cvss":[],"epss":[{"cve":"CVE-2025-68378","epss":0.00184,"percentile":0.08071,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2025-68378","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68378","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/23f852daa4bab4d579110e034e4d513f7d490846","https://git.kernel.org/stable/c/2a008f6de163279deffd488c1deab081bce5667c","https://git.kernel.org/stable/c/4669a8db976c8cbd5427fe9945f12c5fa5168ff3","https://git.kernel.org/stable/c/d1f424a77b6bd27b361737ed73df49a0158f1590"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix stackmap overflow check in __bpf_get_stackid()\n\nSyzkaller reported a KASAN slab-out-of-bounds write in __bpf_get_stackid()\nwhen copying stack trace data. The issue occurs when the perf trace\n contains more stack entries than the stack map bucket can hold,\n leading to an out-of-bounds write in the bucket's data array.","cvss":[],"epss":[{"cve":"CVE-2025-68378","epss":0.00184,"percentile":0.08071,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68378","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68379","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68379","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Fix null deref on srq->rq.queue after resize failure  A NULL pointer dereference can occur in rxe_srq_chk_attr() when ibv_modify_srq() is invoked twice in succession under certain error conditions. The first call may fail in rxe_queue_resize(), which leads rxe_srq_from_attr() to set srq->rq.queue = NULL. The second call then triggers a crash (null deref) when accessing srq->rq.queue->buf->index_mask.  Call Trace: <TASK> rxe_modify_srq+0x170/0x480 [rdma_rxe] ? __pfx_rxe_modify_srq+0x10/0x10 [rdma_rxe] ? uverbs_try_lock_object+0x4f/0xa0 [ib_uverbs] ? rdma_lookup_get_uobject+0x1f0/0x380 [ib_uverbs] ib_uverbs_modify_srq+0x204/0x290 [ib_uverbs] ? __pfx_ib_uverbs_modify_srq+0x10/0x10 [ib_uverbs] ? tryinc_node_nr_active+0xe6/0x150 ? uverbs_fill_udata+0xed/0x4f0 [ib_uverbs] ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x2c0/0x470 [ib_uverbs] ? __pfx_ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x10/0x10 [ib_uverbs] ? uverbs_fill_udata+0xed/0x4f0 [ib_uverbs] ib_uverbs_run_method+0x55a/0x6e0 [ib_uverbs] ? __pfx_ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x10/0x10 [ib_uverbs] ib_uverbs_cmd_verbs+0x54d/0x800 [ib_uverbs] ? __pfx_ib_uverbs_cmd_verbs+0x10/0x10 [ib_uverbs] ? __pfx___raw_spin_lock_irqsave+0x10/0x10 ? __pfx_do_vfs_ioctl+0x10/0x10 ? ioctl_has_perm.constprop.0.isra.0+0x2c7/0x4c0 ? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10 ib_uverbs_ioctl+0x13e/0x220 [ib_uverbs] ? __pfx_ib_uverbs_ioctl+0x10/0x10 [ib_uverbs] __x64_sys_ioctl+0x138/0x1c0 do_syscall_64+0x82/0x250 ? fdget_pos+0x58/0x4c0 ? ksys_write+0xf3/0x1c0 ? __pfx_ksys_write+0x10/0x10 ? do_syscall_64+0xc8/0x250 ? __pfx_vm_mmap_pgoff+0x10/0x10 ? fget+0x173/0x230 ? fput+0x2a/0x80 ? ksys_mmap_pgoff+0x224/0x4c0 ? do_syscall_64+0xc8/0x250 ? do_user_addr_fault+0x37b/0xfe0 ? clear_bhb_loop+0x50/0xa0 ? clear_bhb_loop+0x50/0xa0 ? clear_bhb_loop+0x50/0xa0 entry_SYSCALL_64_after_hwframe+0x76/0x7e","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68379","epss":0.00141,"percentile":0.03736,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.107865},"relatedVulnerabilities":[{"id":"CVE-2025-68379","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68379","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/503a5e4690ae14c18570141bc0dcf7501a8419b0","https://git.kernel.org/stable/c/58aca869babd48cb9c3d6ee9e1452c4b9f5266a6","https://git.kernel.org/stable/c/5dbeb421e137824aa9bd8358bdfc926a3965fc0d","https://git.kernel.org/stable/c/b8f6eeb87a76b6fb1f6381b0b2894568e1b784f7","https://git.kernel.org/stable/c/bc4c14a3863cc0e03698caec9a0cdabd779776ee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix null deref on srq->rq.queue after resize failure\n\nA NULL pointer dereference can occur in rxe_srq_chk_attr() when\nibv_modify_srq() is invoked twice in succession under certain error\nconditions. The first call may fail in rxe_queue_resize(), which leads\nrxe_srq_from_attr() to set srq->rq.queue = NULL. The second call then\ntriggers a crash (null deref) when accessing\nsrq->rq.queue->buf->index_mask.\n\nCall Trace:\n<TASK>\nrxe_modify_srq+0x170/0x480 [rdma_rxe]\n? __pfx_rxe_modify_srq+0x10/0x10 [rdma_rxe]\n? uverbs_try_lock_object+0x4f/0xa0 [ib_uverbs]\n? rdma_lookup_get_uobject+0x1f0/0x380 [ib_uverbs]\nib_uverbs_modify_srq+0x204/0x290 [ib_uverbs]\n? __pfx_ib_uverbs_modify_srq+0x10/0x10 [ib_uverbs]\n? tryinc_node_nr_active+0xe6/0x150\n? uverbs_fill_udata+0xed/0x4f0 [ib_uverbs]\nib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x2c0/0x470 [ib_uverbs]\n? __pfx_ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x10/0x10 [ib_uverbs]\n? uverbs_fill_udata+0xed/0x4f0 [ib_uverbs]\nib_uverbs_run_method+0x55a/0x6e0 [ib_uverbs]\n? __pfx_ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x10/0x10 [ib_uverbs]\nib_uverbs_cmd_verbs+0x54d/0x800 [ib_uverbs]\n? __pfx_ib_uverbs_cmd_verbs+0x10/0x10 [ib_uverbs]\n? __pfx___raw_spin_lock_irqsave+0x10/0x10\n? __pfx_do_vfs_ioctl+0x10/0x10\n? ioctl_has_perm.constprop.0.isra.0+0x2c7/0x4c0\n? __pfx_ioctl_has_perm.constprop.0.isra.0+0x10/0x10\nib_uverbs_ioctl+0x13e/0x220 [ib_uverbs]\n? __pfx_ib_uverbs_ioctl+0x10/0x10 [ib_uverbs]\n__x64_sys_ioctl+0x138/0x1c0\ndo_syscall_64+0x82/0x250\n? fdget_pos+0x58/0x4c0\n? ksys_write+0xf3/0x1c0\n? __pfx_ksys_write+0x10/0x10\n? do_syscall_64+0xc8/0x250\n? __pfx_vm_mmap_pgoff+0x10/0x10\n? fget+0x173/0x230\n? fput+0x2a/0x80\n? ksys_mmap_pgoff+0x224/0x4c0\n? do_syscall_64+0xc8/0x250\n? do_user_addr_fault+0x37b/0xfe0\n? clear_bhb_loop+0x50/0xa0\n? clear_bhb_loop+0x50/0xa0\n? clear_bhb_loop+0x50/0xa0\nentry_SYSCALL_64_after_hwframe+0x76/0x7e","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68379","epss":0.00141,"percentile":0.03736,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68379","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68736","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68736","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  landlock: Fix handling of disconnected directories  Disconnected files or directories can appear when they are visible and opened from a bind mount, but have been renamed or moved from the source of the bind mount in a way that makes them inaccessible from the mount point (i.e. out of scope).  Previously, access rights tied to files or directories opened through a disconnected directory were collected by walking the related hierarchy down to the root of the filesystem, without taking into account the mount point because it couldn't be found. This could lead to inconsistent access results, potential access right widening, and hard-to-debug renames, especially since such paths cannot be printed.  For a sandboxed task to create a disconnected directory, it needs to have write access (i.e. FS_MAKE_REG, FS_REMOVE_FILE, and FS_REFER) to the underlying source of the bind mount, and read access to the related mount point.   Because a sandboxed task cannot acquire more access rights than those defined by its Landlock domain, this could lead to inconsistent access rights due to missing permissions that should be inherited from the mount point hierarchy, while inheriting permissions from the filesystem hierarchy hidden by this mount point instead.  Landlock now handles files and directories opened from disconnected directories by taking into account the filesystem hierarchy when the mount point is not found in the hierarchy walk, and also always taking into account the mount point from which these disconnected directories were opened.  This ensures that a rename is not allowed if it would widen access rights [1].  The rationale is that, even if disconnected hierarchies might not be visible or accessible to a sandboxed task, relying on the collected access rights from them improves the guarantee that access rights will not be widened during a rename because of the access right comparison between the source and the destination (see LANDLOCK_ACCESS_FS_REFER). It may look like this would grant more access on disconnected files and directories, but the security policies are always enforced for all the evaluated hierarchies.  This new behavior should be less surprising to users and safer from an access control perspective.  Remove a wrong WARN_ON_ONCE() canary in collect_domain_accesses() and fix the related comment.  Because opened files have their access rights stored in the related file security properties, there is no impact for disconnected or unlinked files.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68736","epss":0.0014,"percentile":0.03711,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11410000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-68736","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68736","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/426d5b681b2f3339ff04da39b81d71176dc8c87c","https://git.kernel.org/stable/c/49c9e09d961025b22e61ef9ad56aa1c21b6ce2f1","https://git.kernel.org/stable/c/cadb28f8b3fd6908e3051e86158c65c3a8e1c907","https://git.kernel.org/stable/c/fbf718d5afe21057694a0c0223a18b0c7a5960b6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlandlock: Fix handling of disconnected directories\n\nDisconnected files or directories can appear when they are visible and\nopened from a bind mount, but have been renamed or moved from the source\nof the bind mount in a way that makes them inaccessible from the mount\npoint (i.e. out of scope).\n\nPreviously, access rights tied to files or directories opened through a\ndisconnected directory were collected by walking the related hierarchy\ndown to the root of the filesystem, without taking into account the\nmount point because it couldn't be found. This could lead to\ninconsistent access results, potential access right widening, and\nhard-to-debug renames, especially since such paths cannot be printed.\n\nFor a sandboxed task to create a disconnected directory, it needs to\nhave write access (i.e. FS_MAKE_REG, FS_REMOVE_FILE, and FS_REFER) to\nthe underlying source of the bind mount, and read access to the related\nmount point.   Because a sandboxed task cannot acquire more access\nrights than those defined by its Landlock domain, this could lead to\ninconsistent access rights due to missing permissions that should be\ninherited from the mount point hierarchy, while inheriting permissions\nfrom the filesystem hierarchy hidden by this mount point instead.\n\nLandlock now handles files and directories opened from disconnected\ndirectories by taking into account the filesystem hierarchy when the\nmount point is not found in the hierarchy walk, and also always taking\ninto account the mount point from which these disconnected directories\nwere opened.  This ensures that a rename is not allowed if it would\nwiden access rights [1].\n\nThe rationale is that, even if disconnected hierarchies might not be\nvisible or accessible to a sandboxed task, relying on the collected\naccess rights from them improves the guarantee that access rights will\nnot be widened during a rename because of the access right comparison\nbetween the source and the destination (see LANDLOCK_ACCESS_FS_REFER).\nIt may look like this would grant more access on disconnected files and\ndirectories, but the security policies are always enforced for all the\nevaluated hierarchies.  This new behavior should be less surprising to\nusers and safer from an access control perspective.\n\nRemove a wrong WARN_ON_ONCE() canary in collect_domain_accesses() and\nfix the related comment.\n\nBecause opened files have their access rights stored in the related file\nsecurity properties, there is no impact for disconnected or unlinked\nfiles.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68736","epss":0.0014,"percentile":0.03711,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68736","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68745","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68745","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: qla2xxx: Clear cmds after chip reset  Commit aefed3e5548f (\"scsi: qla2xxx: target: Fix offline port handling and host reset handling\") caused two problems:  1. Commands sent to FW, after chip reset got stuck and never freed as FW    is not going to respond to them anymore.  2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd().  Commit 26f9ce53817a    (\"scsi: qla2xxx: Fix missed DMA unmap for aborted commands\")    attempted to fix this, but introduced another bug under different    circumstances when two different CPUs were racing to call    qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in    dma_unmap_sg_attrs().  So revert \"scsi: qla2xxx: Fix missed DMA unmap for aborted commands\" and partially revert \"scsi: qla2xxx: target: Fix offline port handling and host reset handling\" at __qla2x00_abort_all_cmds.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68745","epss":0.00361,"percentile":0.29309,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33934},"relatedVulnerabilities":[{"id":"CVE-2025-68745","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68745","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/5c1fb3fd05da3d55b8cbc42d7d660b313cbdc936","https://git.kernel.org/stable/c/d46c69a087aa3d1513f7a78f871b80251ea0c1ae"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Clear cmds after chip reset\n\nCommit aefed3e5548f (\"scsi: qla2xxx: target: Fix offline port handling\nand host reset handling\") caused two problems:\n\n1. Commands sent to FW, after chip reset got stuck and never freed as FW\n   is not going to respond to them anymore.\n\n2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd().  Commit 26f9ce53817a\n   (\"scsi: qla2xxx: Fix missed DMA unmap for aborted commands\")\n   attempted to fix this, but introduced another bug under different\n   circumstances when two different CPUs were racing to call\n   qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in\n   dma_unmap_sg_attrs().\n\nSo revert \"scsi: qla2xxx: Fix missed DMA unmap for aborted commands\" and\npartially revert \"scsi: qla2xxx: target: Fix offline port handling and\nhost reset handling\" at __qla2x00_abort_all_cmds.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68745","epss":0.00361,"percentile":0.29309,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68745","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68755","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68755","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: most: remove broken i2c driver  The MOST I2C driver has been completely broken for five years without anyone noticing so remove the driver from staging.  Specifically, commit 723de0f9171e (\"staging: most: remove device from interface structure\") started requiring drivers to set the interface device pointer before registration, but the I2C driver was never updated which results in a NULL pointer dereference if anyone ever tries to probe it.","cvss":[],"epss":[{"cve":"CVE-2025-68755","epss":0.00184,"percentile":0.08071,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2025-68755","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68755","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/495df2da6944477d282d5cc0c13174d06e25b310","https://git.kernel.org/stable/c/6059a66dba7f26b21852831432e17075f1a1c783","https://git.kernel.org/stable/c/6cbba922934805f86eece6ba7010b7201962695d","https://git.kernel.org/stable/c/e463548fd80e779efea1cb2d3049b8a7231e6925"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: most: remove broken i2c driver\n\nThe MOST I2C driver has been completely broken for five years without\nanyone noticing so remove the driver from staging.\n\nSpecifically, commit 723de0f9171e (\"staging: most: remove device from\ninterface structure\") started requiring drivers to set the interface\ndevice pointer before registration, but the I2C driver was never updated\nwhich results in a NULL pointer dereference if anyone ever tries to\nprobe it.","cvss":[],"epss":[{"cve":"CVE-2025-68755","epss":0.00184,"percentile":0.08071,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68755","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68768","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68768","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  inet: frags: flush pending skbs in fqdir_pre_exit()  We have been seeing occasional deadlocks on pernet_ops_rwsem since September in NIPA. The stuck task was usually modprobe (often loading a driver like ipvlan), trying to take the lock as a Writer. lockdep does not track readers for rwsems so the read wasn't obvious from the reports.  On closer inspection the Reader holding the lock was conntrack looping forever in nf_conntrack_cleanup_net_list(). Based on past experience with occasional NIPA crashes I looked thru the tests which run before the crash and noticed that the crash follows ip_defrag.sh. An immediate red flag. Scouring thru (de)fragmentation queues reveals skbs sitting around, holding conntrack references.  The problem is that since conntrack depends on nf_defrag_ipv6, nf_defrag_ipv6 will load first. Since nf_defrag_ipv6 loads first its netns exit hooks run _after_ conntrack's netns exit hook.  Flush all fragment queue SKBs during fqdir_pre_exit() to release conntrack references before conntrack cleanup runs. Also flush the queues in timer expiry handlers when they discover fqdir->dead is set, in case packet sneaks in while we're running the pre_exit flush.  The commit under Fixes is not exactly the culprit, but I think previously the timer firing would eventually unblock the spinning conntrack.","cvss":[],"epss":[{"cve":"CVE-2025-68768","epss":0.00178,"percentile":0.0749,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.089},"relatedVulnerabilities":[{"id":"CVE-2025-68768","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68768","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/006a5035b495dec008805df249f92c22c89c3d2e","https://git.kernel.org/stable/c/22ee4010866da81aeee08e1ea3fddbe418feb212","https://git.kernel.org/stable/c/543555954b1ee8d1903a7020324efb41b0c97428","https://git.kernel.org/stable/c/c70df25214ac9b32b53e18e6ae3b8f073ffa6903"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: flush pending skbs in fqdir_pre_exit()\n\nWe have been seeing occasional deadlocks on pernet_ops_rwsem since\nSeptember in NIPA. The stuck task was usually modprobe (often loading\na driver like ipvlan), trying to take the lock as a Writer.\nlockdep does not track readers for rwsems so the read wasn't obvious\nfrom the reports.\n\nOn closer inspection the Reader holding the lock was conntrack looping\nforever in nf_conntrack_cleanup_net_list(). Based on past experience\nwith occasional NIPA crashes I looked thru the tests which run before\nthe crash and noticed that the crash follows ip_defrag.sh. An immediate\nred flag. Scouring thru (de)fragmentation queues reveals skbs sitting\naround, holding conntrack references.\n\nThe problem is that since conntrack depends on nf_defrag_ipv6,\nnf_defrag_ipv6 will load first. Since nf_defrag_ipv6 loads first its\nnetns exit hooks run _after_ conntrack's netns exit hook.\n\nFlush all fragment queue SKBs during fqdir_pre_exit() to release\nconntrack references before conntrack cleanup runs. Also flush\nthe queues in timer expiry handlers when they discover fqdir->dead\nis set, in case packet sneaks in while we're running the pre_exit\nflush.\n\nThe commit under Fixes is not exactly the culprit, but I think\npreviously the timer firing would eventually unblock the spinning\nconntrack.","cvss":[],"epss":[{"cve":"CVE-2025-68768","epss":0.00178,"percentile":0.0749,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68768","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68781","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal  The delayed work item otg_event is initialized in fsl_otg_conf() and scheduled under two conditions: 1. When a host controller binds to the OTG controller. 2. When the USB ID pin state changes (cable insertion/removal).  A race condition occurs when the device is removed via fsl_otg_remove(): the fsl_otg instance may be freed while the delayed work is still pending or executing. This leads to use-after-free when the work function fsl_otg_event() accesses the already freed memory.  The problematic scenario:  (detach thread)            | (delayed work) fsl_otg_remove()           |   kfree(fsl_otg_dev) //FREE| fsl_otg_event()                            |   og = container_of(...) //USE                            |   og-> //USE  Fix this by calling disable_delayed_work_sync() in fsl_otg_remove() before deallocating the fsl_otg structure. This ensures the delayed work is properly canceled and completes execution prior to memory deallocation.  This bug was identified through static analysis.","cvss":[],"epss":[{"cve":"CVE-2025-68781","epss":0.0019,"percentile":0.08726,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095},"relatedVulnerabilities":[{"id":"CVE-2025-68781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68781","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2e7c47e2eb3cfeadf78a1ccbac8492c60d508f23","https://git.kernel.org/stable/c/41ca62e3e21e48c2903b3b45e232cf4f2ff7434f","https://git.kernel.org/stable/c/69f9a0701abc3d1f8225074c56c27e6c16a37222"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: phy: fsl-usb: Fix use-after-free in delayed work during device removal\n\nThe delayed work item otg_event is initialized in fsl_otg_conf() and\nscheduled under two conditions:\n1. When a host controller binds to the OTG controller.\n2. When the USB ID pin state changes (cable insertion/removal).\n\nA race condition occurs when the device is removed via fsl_otg_remove():\nthe fsl_otg instance may be freed while the delayed work is still pending\nor executing. This leads to use-after-free when the work function\nfsl_otg_event() accesses the already freed memory.\n\nThe problematic scenario:\n\n(detach thread)            | (delayed work)\nfsl_otg_remove()           |\n  kfree(fsl_otg_dev) //FREE| fsl_otg_event()\n                           |   og = container_of(...) //USE\n                           |   og-> //USE\n\nFix this by calling disable_delayed_work_sync() in fsl_otg_remove()\nbefore deallocating the fsl_otg structure. This ensures the delayed work\nis properly canceled and completes execution prior to memory deallocation.\n\nThis bug was identified through static analysis.","cvss":[],"epss":[{"cve":"CVE-2025-68781","epss":0.0019,"percentile":0.08726,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68781","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68794","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68794","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iomap: adjust read range correctly for non-block-aligned positions  iomap_adjust_read_range() assumes that the position and length passed in are block-aligned. This is not always the case however, as shown in the syzbot generated case for erofs. This causes too many bytes to be skipped for uptodate blocks, which results in returning the incorrect position and length to read in. If all the blocks are uptodate, this underflows length and returns a position beyond the folio.  Fix the calculation to also take into account the block offset when calculating how many bytes can be skipped for uptodate blocks.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68794","epss":0.00533,"percentile":0.43316,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.50102},"relatedVulnerabilities":[{"id":"CVE-2025-68794","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68794","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/12053695c8ef5410e8cc6c9ed4c0db9cd9c82b3e","https://git.kernel.org/stable/c/142194fb21afe964d2d194cab1fc357cbf87e899","https://git.kernel.org/stable/c/275b37a1e5c2c8abd313e8075f6aec9a349f291b","https://git.kernel.org/stable/c/7aa6bc3e8766990824f66ca76c19596ce10daf3e","https://git.kernel.org/stable/c/82b60ffbb532d919959702768dca04c3c0500ae5","https://git.kernel.org/stable/c/b8c9f25fd84328c5fcc4f70c6d1e8f1d4787eaac","https://git.kernel.org/stable/c/ce20f49ac9194cf81a77f01d1c316d7c17ae753c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niomap: adjust read range correctly for non-block-aligned positions\n\niomap_adjust_read_range() assumes that the position and length passed in\nare block-aligned. This is not always the case however, as shown in the\nsyzbot generated case for erofs. This causes too many bytes to be\nskipped for uptodate blocks, which results in returning the incorrect\nposition and length to read in. If all the blocks are uptodate, this\nunderflows length and returns a position beyond the folio.\n\nFix the calculation to also take into account the block offset when\ncalculating how many bytes can be skipped for uptodate blocks.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68794","epss":0.00533,"percentile":0.43316,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68794","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68809","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68809","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: vfs: fix race on m_flags in vfs_cache  ksmbd maintains delete-on-close and pending-delete state in ksmbd_inode->m_flags. In vfs_cache.c this field is accessed under inconsistent locking: some paths read and modify m_flags under ci->m_lock while others do so without taking the lock at all.  Examples:   - ksmbd_query_inode_status() and __ksmbd_inode_close() use    ci->m_lock when checking or updating m_flags.  - ksmbd_inode_pending_delete(), ksmbd_set_inode_pending_delete(),    ksmbd_clear_inode_pending_delete() and ksmbd_fd_set_delete_on_close()    used to read and modify m_flags without ci->m_lock.  This creates a potential data race on m_flags when multiple threads open, close and delete the same file concurrently. In the worst case delete-on-close and pending-delete bits can be lost or observed in an inconsistent state, leading to confusing delete semantics (files that stay on disk after delete-on-close, or files that disappear while still in use).  Fix it by:   - Making ksmbd_query_inode_status() look at m_flags under ci->m_lock    after dropping inode_hash_lock.  - Adding ci->m_lock protection to all helpers that read or modify    m_flags (ksmbd_inode_pending_delete(), ksmbd_set_inode_pending_delete(),    ksmbd_clear_inode_pending_delete(), ksmbd_fd_set_delete_on_close()).  - Keeping the existing ci->m_lock protection in __ksmbd_inode_close(),    and moving the actual unlink/xattr removal outside the lock.  This unifies the locking around m_flags and removes the data race while preserving the existing delete-on-close behaviour.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68809","epss":0.00468,"percentile":0.39064,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.42354},"relatedVulnerabilities":[{"id":"CVE-2025-68809","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68809","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/5adad9727a815c26013b0d41cfee92ffa7d4037c","https://git.kernel.org/stable/c/991f8a79db99b14c48d20d2052c82d65b9186cad","https://git.kernel.org/stable/c/ccc78781041589ea383e61d5d7a1e9a31b210b93","https://git.kernel.org/stable/c/ee63729760f5b61a66f345c54dc4c7514e62383d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: vfs: fix race on m_flags in vfs_cache\n\nksmbd maintains delete-on-close and pending-delete state in\nksmbd_inode->m_flags. In vfs_cache.c this field is accessed under\ninconsistent locking: some paths read and modify m_flags under\nci->m_lock while others do so without taking the lock at all.\n\nExamples:\n\n - ksmbd_query_inode_status() and __ksmbd_inode_close() use\n   ci->m_lock when checking or updating m_flags.\n - ksmbd_inode_pending_delete(), ksmbd_set_inode_pending_delete(),\n   ksmbd_clear_inode_pending_delete() and ksmbd_fd_set_delete_on_close()\n   used to read and modify m_flags without ci->m_lock.\n\nThis creates a potential data race on m_flags when multiple threads\nopen, close and delete the same file concurrently. In the worst case\ndelete-on-close and pending-delete bits can be lost or observed in an\ninconsistent state, leading to confusing delete semantics (files that\nstay on disk after delete-on-close, or files that disappear while still\nin use).\n\nFix it by:\n\n - Making ksmbd_query_inode_status() look at m_flags under ci->m_lock\n   after dropping inode_hash_lock.\n - Adding ci->m_lock protection to all helpers that read or modify\n   m_flags (ksmbd_inode_pending_delete(), ksmbd_set_inode_pending_delete(),\n   ksmbd_clear_inode_pending_delete(), ksmbd_fd_set_delete_on_close()).\n - Keeping the existing ci->m_lock protection in __ksmbd_inode_close(),\n   and moving the actual unlink/xattr removal outside the lock.\n\nThis unifies the locking around m_flags and removes the data race while\npreserving the existing delete-on-close behaviour.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68809","epss":0.00468,"percentile":0.39064,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68809","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-68822","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68822","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: alps - fix use-after-free bugs caused by dev3_register_work  The dev3_register_work delayed work item is initialized within alps_reconnect() and scheduled upon receipt of the first bare PS/2 packet from an external PS/2 device connected to the ALPS touchpad. During device detachment, the original implementation calls flush_workqueue() in psmouse_disconnect() to ensure completion of dev3_register_work. However, the flush_workqueue() in psmouse_disconnect() only blocks and waits for work items that were already queued to the workqueue prior to its invocation. Any work items submitted after flush_workqueue() is called are not included in the set of tasks that the flush operation awaits. This means that after flush_workqueue() has finished executing, the dev3_register_work could still be scheduled. Although the psmouse state is set to PSMOUSE_CMD_MODE in psmouse_disconnect(), the scheduling of dev3_register_work remains unaffected.  The race condition can occur as follows:  CPU 0 (cleanup path)     | CPU 1 (delayed work) psmouse_disconnect()     |   psmouse_set_state()    |   flush_workqueue()      | alps_report_bare_ps2_packet()   alps_disconnect()      |   psmouse_queue_work()     kfree(priv); // FREE | alps_register_bare_ps2_mouse()                          |   priv = container_of(work...); // USE                          |   priv->dev3 // USE  Add disable_delayed_work_sync() in alps_disconnect() to ensure that dev3_register_work is properly canceled and prevented from executing after the alps_data structure has been deallocated.  This bug is identified by static analysis.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68822","epss":0.00131,"percentile":0.03061,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.100215},"relatedVulnerabilities":[{"id":"CVE-2025-68822","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68822","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/a9c115e017b2c633d25bdfe6709dda6fc36f08c2","https://git.kernel.org/stable/c/bf40644ef8c8a288742fa45580897ed0e0289474","https://git.kernel.org/stable/c/ed8c61b89be0c45f029228b2913d5cf7b5cda1a7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: alps - fix use-after-free bugs caused by dev3_register_work\n\nThe dev3_register_work delayed work item is initialized within\nalps_reconnect() and scheduled upon receipt of the first bare\nPS/2 packet from an external PS/2 device connected to the ALPS\ntouchpad. During device detachment, the original implementation\ncalls flush_workqueue() in psmouse_disconnect() to ensure\ncompletion of dev3_register_work. However, the flush_workqueue()\nin psmouse_disconnect() only blocks and waits for work items that\nwere already queued to the workqueue prior to its invocation. Any\nwork items submitted after flush_workqueue() is called are not\nincluded in the set of tasks that the flush operation awaits.\nThis means that after flush_workqueue() has finished executing,\nthe dev3_register_work could still be scheduled. Although the\npsmouse state is set to PSMOUSE_CMD_MODE in psmouse_disconnect(),\nthe scheduling of dev3_register_work remains unaffected.\n\nThe race condition can occur as follows:\n\nCPU 0 (cleanup path)     | CPU 1 (delayed work)\npsmouse_disconnect()     |\n  psmouse_set_state()    |\n  flush_workqueue()      | alps_report_bare_ps2_packet()\n  alps_disconnect()      |   psmouse_queue_work()\n    kfree(priv); // FREE | alps_register_bare_ps2_mouse()\n                         |   priv = container_of(work...); // USE\n                         |   priv->dev3 // USE\n\nAdd disable_delayed_work_sync() in alps_disconnect() to ensure\nthat dev3_register_work is properly canceled and prevented from\nexecuting after the alps_data structure has been deallocated.\n\nThis bug is identified by static analysis.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-68822","epss":0.00131,"percentile":0.03061,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-68822","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71065","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71065","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to avoid potential deadlock  As Jiaming Zhang and syzbot reported, there is potential deadlock in f2fs as below:  Chain exists of:   &sbi->cp_rwsem --> fs_reclaim --> sb_internal#2   Possible unsafe locking scenario:         CPU0                    CPU1        ----                    ----   rlock(sb_internal#2);                                lock(fs_reclaim);                                lock(sb_internal#2);   rlock(&sbi->cp_rwsem);   *** DEADLOCK ***  3 locks held by kswapd0/73:  #0: ffffffff8e247a40 (fs_reclaim){+.+.}-{0:0}, at: balance_pgdat mm/vmscan.c:7015 [inline]  #0: ffffffff8e247a40 (fs_reclaim){+.+.}-{0:0}, at: kswapd+0x951/0x2800 mm/vmscan.c:7389  #1: ffff8880118400e0 (&type->s_umount_key#50){.+.+}-{4:4}, at: super_trylock_shared fs/super.c:562 [inline]  #1: ffff8880118400e0 (&type->s_umount_key#50){.+.+}-{4:4}, at: super_cache_scan+0x91/0x4b0 fs/super.c:197  #2: ffff888011840610 (sb_internal#2){.+.+}-{0:0}, at: f2fs_evict_inode+0x8d9/0x1b60 fs/f2fs/inode.c:890  stack backtrace: CPU: 0 UID: 0 PID: 73 Comm: kswapd0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 Call Trace:  <TASK>  dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120  print_circular_bug+0x2ee/0x310 kernel/locking/lockdep.c:2043  check_noncircular+0x134/0x160 kernel/locking/lockdep.c:2175  check_prev_add kernel/locking/lockdep.c:3165 [inline]  check_prevs_add kernel/locking/lockdep.c:3284 [inline]  validate_chain+0xb9b/0x2140 kernel/locking/lockdep.c:3908  __lock_acquire+0xab9/0xd20 kernel/locking/lockdep.c:5237  lock_acquire+0x120/0x360 kernel/locking/lockdep.c:5868  down_read+0x46/0x2e0 kernel/locking/rwsem.c:1537  f2fs_down_read fs/f2fs/f2fs.h:2278 [inline]  f2fs_lock_op fs/f2fs/f2fs.h:2357 [inline]  f2fs_do_truncate_blocks+0x21c/0x10c0 fs/f2fs/file.c:791  f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:867  f2fs_truncate+0x489/0x7c0 fs/f2fs/file.c:925  f2fs_evict_inode+0x9f2/0x1b60 fs/f2fs/inode.c:897  evict+0x504/0x9c0 fs/inode.c:810  f2fs_evict_inode+0x1dc/0x1b60 fs/f2fs/inode.c:853  evict+0x504/0x9c0 fs/inode.c:810  dispose_list fs/inode.c:852 [inline]  prune_icache_sb+0x21b/0x2c0 fs/inode.c:1000  super_cache_scan+0x39b/0x4b0 fs/super.c:224  do_shrink_slab+0x6ef/0x1110 mm/shrinker.c:437  shrink_slab_memcg mm/shrinker.c:550 [inline]  shrink_slab+0x7ef/0x10d0 mm/shrinker.c:628  shrink_one+0x28a/0x7c0 mm/vmscan.c:4955  shrink_many mm/vmscan.c:5016 [inline]  lru_gen_shrink_node mm/vmscan.c:5094 [inline]  shrink_node+0x315d/0x3780 mm/vmscan.c:6081  kswapd_shrink_node mm/vmscan.c:6941 [inline]  balance_pgdat mm/vmscan.c:7124 [inline]  kswapd+0x147c/0x2800 mm/vmscan.c:7389  kthread+0x70e/0x8a0 kernel/kthread.c:463  ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245  </TASK>  The root cause is deadlock among four locks as below:  kswapd - fs_reclaim\t\t\t\t--- Lock A  - shrink_one   - evict    - f2fs_evict_inode     - sb_start_intwrite\t\t\t--- Lock B  - iput  - evict   - f2fs_evict_inode    - sb_start_intwrite\t\t\t--- Lock B    - f2fs_truncate     - f2fs_truncate_blocks      - f2fs_do_truncate_blocks       - f2fs_lock_op\t\t\t--- Lock C  ioctl - f2fs_ioc_commit_atomic_write  - f2fs_lock_op\t\t\t\t--- Lock C   - __f2fs_commit_atomic_write    - __replace_atomic_write_block     - f2fs_get_dnode_of_data      - __get_node_folio       - f2fs_check_nid_range        - f2fs_handle_error         - f2fs_record_errors          - f2fs_down_write\t\t--- Lock D  open - do_open  - do_truncate   - security_inode_need_killpriv    - f2fs_getxattr     - lookup_all_xattrs      - f2fs_handle_error       - f2fs_record_errors        - f2fs_down_write\t\t--- Lock D         - f2fs_commit_super          - read_mapping_folio           - filemap_alloc_folio_noprof            - prepare_alloc_pages             - fs_reclaim_acquire\t--- Lock A  In order to a ---truncated---","cvss":[],"epss":[{"cve":"CVE-2025-71065","epss":0.00178,"percentile":0.0749,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.089},"relatedVulnerabilities":[{"id":"CVE-2025-71065","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71065","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/6c3bab5c6261aa22c561ef56b7365959a90e7d91","https://git.kernel.org/stable/c/86a85a7b622e6e8dba69810257733ce5eab5ed55","https://git.kernel.org/stable/c/8bd6dff8b801abaa362272894bda795bf0cf1307","https://git.kernel.org/stable/c/ca8b201f28547e28343a6f00a6e91fa8c09572fe"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid potential deadlock\n\nAs Jiaming Zhang and syzbot reported, there is potential deadlock in\nf2fs as below:\n\nChain exists of:\n  &sbi->cp_rwsem --> fs_reclaim --> sb_internal#2\n\n Possible unsafe locking scenario:\n\n       CPU0                    CPU1\n       ----                    ----\n  rlock(sb_internal#2);\n                               lock(fs_reclaim);\n                               lock(sb_internal#2);\n  rlock(&sbi->cp_rwsem);\n\n *** DEADLOCK ***\n\n3 locks held by kswapd0/73:\n #0: ffffffff8e247a40 (fs_reclaim){+.+.}-{0:0}, at: balance_pgdat mm/vmscan.c:7015 [inline]\n #0: ffffffff8e247a40 (fs_reclaim){+.+.}-{0:0}, at: kswapd+0x951/0x2800 mm/vmscan.c:7389\n #1: ffff8880118400e0 (&type->s_umount_key#50){.+.+}-{4:4}, at: super_trylock_shared fs/super.c:562 [inline]\n #1: ffff8880118400e0 (&type->s_umount_key#50){.+.+}-{4:4}, at: super_cache_scan+0x91/0x4b0 fs/super.c:197\n #2: ffff888011840610 (sb_internal#2){.+.+}-{0:0}, at: f2fs_evict_inode+0x8d9/0x1b60 fs/f2fs/inode.c:890\n\nstack backtrace:\nCPU: 0 UID: 0 PID: 73 Comm: kswapd0 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nCall Trace:\n <TASK>\n dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120\n print_circular_bug+0x2ee/0x310 kernel/locking/lockdep.c:2043\n check_noncircular+0x134/0x160 kernel/locking/lockdep.c:2175\n check_prev_add kernel/locking/lockdep.c:3165 [inline]\n check_prevs_add kernel/locking/lockdep.c:3284 [inline]\n validate_chain+0xb9b/0x2140 kernel/locking/lockdep.c:3908\n __lock_acquire+0xab9/0xd20 kernel/locking/lockdep.c:5237\n lock_acquire+0x120/0x360 kernel/locking/lockdep.c:5868\n down_read+0x46/0x2e0 kernel/locking/rwsem.c:1537\n f2fs_down_read fs/f2fs/f2fs.h:2278 [inline]\n f2fs_lock_op fs/f2fs/f2fs.h:2357 [inline]\n f2fs_do_truncate_blocks+0x21c/0x10c0 fs/f2fs/file.c:791\n f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:867\n f2fs_truncate+0x489/0x7c0 fs/f2fs/file.c:925\n f2fs_evict_inode+0x9f2/0x1b60 fs/f2fs/inode.c:897\n evict+0x504/0x9c0 fs/inode.c:810\n f2fs_evict_inode+0x1dc/0x1b60 fs/f2fs/inode.c:853\n evict+0x504/0x9c0 fs/inode.c:810\n dispose_list fs/inode.c:852 [inline]\n prune_icache_sb+0x21b/0x2c0 fs/inode.c:1000\n super_cache_scan+0x39b/0x4b0 fs/super.c:224\n do_shrink_slab+0x6ef/0x1110 mm/shrinker.c:437\n shrink_slab_memcg mm/shrinker.c:550 [inline]\n shrink_slab+0x7ef/0x10d0 mm/shrinker.c:628\n shrink_one+0x28a/0x7c0 mm/vmscan.c:4955\n shrink_many mm/vmscan.c:5016 [inline]\n lru_gen_shrink_node mm/vmscan.c:5094 [inline]\n shrink_node+0x315d/0x3780 mm/vmscan.c:6081\n kswapd_shrink_node mm/vmscan.c:6941 [inline]\n balance_pgdat mm/vmscan.c:7124 [inline]\n kswapd+0x147c/0x2800 mm/vmscan.c:7389\n kthread+0x70e/0x8a0 kernel/kthread.c:463\n ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n </TASK>\n\nThe root cause is deadlock among four locks as below:\n\nkswapd\n- fs_reclaim\t\t\t\t--- Lock A\n - shrink_one\n  - evict\n   - f2fs_evict_inode\n    - sb_start_intwrite\t\t\t--- Lock B\n\n- iput\n - evict\n  - f2fs_evict_inode\n   - sb_start_intwrite\t\t\t--- Lock B\n   - f2fs_truncate\n    - f2fs_truncate_blocks\n     - f2fs_do_truncate_blocks\n      - f2fs_lock_op\t\t\t--- Lock C\n\nioctl\n- f2fs_ioc_commit_atomic_write\n - f2fs_lock_op\t\t\t\t--- Lock C\n  - __f2fs_commit_atomic_write\n   - __replace_atomic_write_block\n    - f2fs_get_dnode_of_data\n     - __get_node_folio\n      - f2fs_check_nid_range\n       - f2fs_handle_error\n        - f2fs_record_errors\n         - f2fs_down_write\t\t--- Lock D\n\nopen\n- do_open\n - do_truncate\n  - security_inode_need_killpriv\n   - f2fs_getxattr\n    - lookup_all_xattrs\n     - f2fs_handle_error\n      - f2fs_record_errors\n       - f2fs_down_write\t\t--- Lock D\n        - f2fs_commit_super\n         - read_mapping_folio\n          - filemap_alloc_folio_noprof\n           - prepare_alloc_pages\n            - fs_reclaim_acquire\t--- Lock A\n\nIn order to a\n---truncated---","cvss":[],"epss":[{"cve":"CVE-2025-71065","epss":0.00178,"percentile":0.0749,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71065","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71068","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71068","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  svcrdma: bound check rq_pages index in inline path  svc_rdma_copy_inline_range indexed rqstp->rq_pages[rc_curpage] without verifying rc_curpage stays within the allocated page array. Add guards before the first use and after advancing to a new page.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71068","epss":0.00317,"percentile":0.24347,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24250500000000003},"relatedVulnerabilities":[{"id":"CVE-2025-71068","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71068","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5f140b525180c628db8fa6c897f138194a2de417","https://git.kernel.org/stable/c/7ba826aae1d43212f3baa53a2175ad949e21926e","https://git.kernel.org/stable/c/a22316f5e9a29e4b92030bd8fb9435fe0eb1d5c9","https://git.kernel.org/stable/c/d1bea0ce35b6095544ee82bb54156fc62c067e58","https://git.kernel.org/stable/c/da1ccfc4c452541584a4eae89e337cfa21be6d5a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: bound check rq_pages index in inline path\n\nsvc_rdma_copy_inline_range indexed rqstp->rq_pages[rc_curpage] without\nverifying rc_curpage stays within the allocated page array. Add guards\nbefore the first use and after advancing to a new page.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71068","epss":0.00317,"percentile":0.24347,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71068","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71073","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71073","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: lkkbd - disable pending work before freeing device  lkkbd_interrupt() schedules lk->tq via schedule_work(), and the work handler lkkbd_reinit() dereferences the lkkbd structure and its serio/input_dev fields.  lkkbd_disconnect() and error paths in lkkbd_connect() free the lkkbd structure without preventing the reinit work from being queued again until serio_close() returns. This can allow the work handler to run after the structure has been freed, leading to a potential use-after-free.  Use disable_work_sync() instead of cancel_work_sync() to ensure the reinit work cannot be re-queued, and call it both in lkkbd_disconnect() and in lkkbd_connect() error paths after serio_open().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71073","epss":0.00132,"percentile":0.03097,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71073","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10097999999999999},"relatedVulnerabilities":[{"id":"CVE-2025-71073","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71073","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3a7cd1397c209076c371d53bf39a55c138f62342","https://git.kernel.org/stable/c/cffc4e29b1e2d44ab094cf142d7c461ff09b9104","https://git.kernel.org/stable/c/e58c88f0cb2d8ed89de78f6f17409d29cfab6c5c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: lkkbd - disable pending work before freeing device\n\nlkkbd_interrupt() schedules lk->tq via schedule_work(), and the work\nhandler lkkbd_reinit() dereferences the lkkbd structure and its\nserio/input_dev fields.\n\nlkkbd_disconnect() and error paths in lkkbd_connect() free the lkkbd\nstructure without preventing the reinit work from being queued again\nuntil serio_close() returns. This can allow the work handler to run\nafter the structure has been freed, leading to a potential use-after-free.\n\nUse disable_work_sync() instead of cancel_work_sync() to ensure the\nreinit work cannot be re-queued, and call it both in lkkbd_disconnect()\nand in lkkbd_connect() error paths after serio_open().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71073","epss":0.00132,"percentile":0.03097,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71073","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71073","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71074","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71074","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  functionfs: fix the open/removal races  ffs_epfile_open() can race with removal, ending up with file->private_data pointing to freed object.  There is a total count of opened files on functionfs (both ep0 and dynamic ones) and when it hits zero, dynamic files get removed. Unfortunately, that removal can happen while another thread is in ffs_epfile_open(), but has not incremented the count yet. In that case open will succeed, leaving us with UAF on any subsequent read() or write().  The root cause is that ffs->opened is misused; atomic_dec_and_test() vs. atomic_add_return() is not a good idea, when object remains visible all along.  To untangle that \t* serialize openers on ffs->mutex (both for ep0 and for dynamic files) \t* have dynamic ones use atomic_inc_not_zero() and fail if we had zero ->opened; in that case the file we are opening is doomed. \t* have the inodes of dynamic files marked on removal (from the callback of simple_recursive_removal()) - clear ->i_private there. \t* have open of dynamic ones verify they hadn't been already removed, along with checking that state is FFS_ACTIVE.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71074","epss":0.00106,"percentile":0.01202,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71074","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05141},"relatedVulnerabilities":[{"id":"CVE-2025-71074","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71074","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/e5bf5ee266633cb18fff6f98f0b7d59a62819eee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfunctionfs: fix the open/removal races\n\nffs_epfile_open() can race with removal, ending up with file->private_data\npointing to freed object.\n\nThere is a total count of opened files on functionfs (both ep0 and\ndynamic ones) and when it hits zero, dynamic files get removed.\nUnfortunately, that removal can happen while another thread is\nin ffs_epfile_open(), but has not incremented the count yet.\nIn that case open will succeed, leaving us with UAF on any subsequent\nread() or write().\n\nThe root cause is that ffs->opened is misused; atomic_dec_and_test() vs.\natomic_add_return() is not a good idea, when object remains visible all\nalong.\n\nTo untangle that\n\t* serialize openers on ffs->mutex (both for ep0 and for dynamic files)\n\t* have dynamic ones use atomic_inc_not_zero() and fail if we had\nzero ->opened; in that case the file we are opening is doomed.\n\t* have the inodes of dynamic files marked on removal (from the\ncallback of simple_recursive_removal()) - clear ->i_private there.\n\t* have open of dynamic ones verify they hadn't been already removed,\nalong with checking that state is FFS_ACTIVE.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71074","epss":0.00106,"percentile":0.01202,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71074","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71074","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71109","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71109","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits  Since commit e424054000878 (\"MIPS: Tracing: Reduce the overhead of dynamic Function Tracer\"), the macro UASM_i_LA_mostly has been used, and this macro can generate more than 2 instructions. At the same time, the code in ftrace assumes that no more than 2 instructions can be generated, which is why it stores them in an int[2] array. However, as previously noted, the macro UASM_i_LA_mostly (and now UASM_i_LA) causes a buffer overflow when _mcount is beyond 32 bits. This leads to corruption of the variables located in the __read_mostly section.  This corruption was observed because the variable __cpu_primary_thread_mask was corrupted, causing a hang very early during boot.  This fix prevents the corruption by avoiding the generation of instructions if they could exceed 2 instructions in length. Fortunately, insn_la_mcount is only used if the instrumented code is located outside the kernel code section, so dynamic ftrace can still be used, albeit in a more limited scope. This is still preferable to corrupting memory and/or crashing the kernel.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71109","epss":0.00187,"percentile":0.08378,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71109","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.098175},"relatedVulnerabilities":[{"id":"CVE-2025-71109","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71109","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/36dac9a3dda1f2bae343191bc16b910c603cac25","https://git.kernel.org/stable/c/7f39b9d0e86ed6236b9a5fb67616ab1f76c4f150","https://git.kernel.org/stable/c/e3e33ac2eb69d595079a1a1e444c2fb98efdd42d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits\n\nSince commit e424054000878 (\"MIPS: Tracing: Reduce the overhead of\ndynamic Function Tracer\"), the macro UASM_i_LA_mostly has been used,\nand this macro can generate more than 2 instructions. At the same\ntime, the code in ftrace assumes that no more than 2 instructions can\nbe generated, which is why it stores them in an int[2] array. However,\nas previously noted, the macro UASM_i_LA_mostly (and now UASM_i_LA)\ncauses a buffer overflow when _mcount is beyond 32 bits. This leads to\ncorruption of the variables located in the __read_mostly section.\n\nThis corruption was observed because the variable\n__cpu_primary_thread_mask was corrupted, causing a hang very early\nduring boot.\n\nThis fix prevents the corruption by avoiding the generation of\ninstructions if they could exceed 2 instructions in\nlength. Fortunately, insn_la_mcount is only used if the instrumented\ncode is located outside the kernel code section, so dynamic ftrace can\nstill be used, albeit in a more limited scope. This is still\npreferable to corrupting memory and/or crashing the kernel.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71109","epss":0.00187,"percentile":0.08378,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71109","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71109","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71129","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71129","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: BPF: Sign extend kfunc call arguments  The kfunc calls are native calls so they should follow LoongArch calling conventions. Sign extend its arguments properly to avoid kernel panic. This is done by adding a new emit_abi_ext() helper. The emit_abi_ext() helper performs extension in place meaning a value already store in the target register (Note: this is different from the existing sign_extend() helper and thus we can't reuse it).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71129","epss":0.00121,"percentile":0.02162,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2025-71129","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71129","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0d666db731e95890e0eda7ea61bc925fd2be90c6","https://git.kernel.org/stable/c/321993a874f571a94b5a596f1132f798c663b56e","https://git.kernel.org/stable/c/3f5a238f24d7b75f9efe324d3539ad388f58536e","https://git.kernel.org/stable/c/fd43edf357a3a1f5ed1c4bf450b60001c9091c39"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Sign extend kfunc call arguments\n\nThe kfunc calls are native calls so they should follow LoongArch calling\nconventions. Sign extend its arguments properly to avoid kernel panic.\nThis is done by adding a new emit_abi_ext() helper. The emit_abi_ext()\nhelper performs extension in place meaning a value already store in the\ntarget register (Note: this is different from the existing sign_extend()\nhelper and thus we can't reuse it).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71129","epss":0.00121,"percentile":0.02162,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71129","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71138","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71138","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm/dpu: Add missing NULL pointer check for pingpong interface  It is checked almost always in dpu_encoder_phys_wb_setup_ctl(), but in a single place the check is missing. Also use convenient locals instead of phys_enc->* where available.  Patchwork: https://patchwork.freedesktop.org/patch/693860/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71138","epss":0.00121,"percentile":0.02161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71138","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2025-71138","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71138","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/35ea3282136a630a3fd92b76f5a3a02651145ef1","https://git.kernel.org/stable/c/471baae774a30a04cf066907b60eaf3732928cb7","https://git.kernel.org/stable/c/678d1c86566dfbb247ba25482d37fddde6140cc9","https://git.kernel.org/stable/c/88733a0b64872357e5ecd82b7488121503cb9cc6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: Add missing NULL pointer check for pingpong interface\n\nIt is checked almost always in dpu_encoder_phys_wb_setup_ctl(), but in a\nsingle place the check is missing.\nAlso use convenient locals instead of phys_enc->* where available.\n\nPatchwork: https://patchwork.freedesktop.org/patch/693860/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71138","epss":0.00121,"percentile":0.02161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71138","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71138","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71152","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: dsa: properly keep track of conduit reference  Problem description -------------------  DSA has a mumbo-jumbo of reference handling of the conduit net device and its kobject which, sadly, is just wrong and doesn't make sense.  There are two distinct problems.  1. The OF path, which uses of_find_net_device_by_node(), never releases    the elevated refcount on the conduit's kobject. Nominally, the OF and    non-OF paths should result in objects having identical reference    counts taken, and it is already suspicious that    dsa_dev_to_net_device() has a put_device() call which is missing in    dsa_port_parse_of(), but we can actually even verify that an issue    exists. With CONFIG_DEBUG_KOBJECT_RELEASE=y, if we run this command    \"before\" and \"after\" applying this patch:  (unbind the conduit driver for net device eno2) echo 0000:00:00.2 > /sys/bus/pci/drivers/fsl_enetc/unbind  we see these lines in the output diff which appear only with the patch applied:  kobject: 'eno2' (ffff002009a3a6b8): kobject_release, parent 0000000000000000 (delayed 1000) kobject: '109' (ffff0020099d59a0): kobject_release, parent 0000000000000000 (delayed 1000)  2. After we find the conduit interface one way (OF) or another (non-OF),    it can get unregistered at any time, and DSA remains with a long-lived,    but in this case stale, cpu_dp->conduit pointer. Holding the net    device's underlying kobject isn't actually of much help, it just    prevents it from being freed (but we never need that kobject    directly). What helps us to prevent the net device from being    unregistered is the parallel netdev reference mechanism (dev_hold()    and dev_put()).  Actually we actually use that netdev tracker mechanism implicitly on user ports since commit 2f1e8ea726e9 (\"net: dsa: link interfaces with the DSA master to get rid of lockdep warnings\"), via netdev_upper_dev_link(). But time still passes at DSA switch probe time between the initial of_find_net_device_by_node() code and the user port creation time, time during which the conduit could unregister itself and DSA wouldn't know about it.  So we have to run of_find_net_device_by_node() under rtnl_lock() to prevent that from happening, and release the lock only with the netdev tracker having acquired the reference.  Do we need to keep the reference until dsa_unregister_switch() / dsa_switch_shutdown()? 1: Maybe yes. A switch device will still be registered even if all user    ports failed to probe, see commit 86f8b1c01a0a (\"net: dsa: Do not    make user port errors fatal\"), and the cpu_dp->conduit pointers    remain valid.  I haven't audited all call paths to see whether they    will actually use the conduit in lack of any user port, but if they    do, it seems safer to not rely on user ports for that reference. 2. Definitely yes. We support changing the conduit which a user port is    associated to, and we can get into a situation where we've moved all    user ports away from a conduit, thus no longer hold any reference to    it via the net device tracker. But we shouldn't let it go nonetheless    - see the next change in relation to dsa_tree_find_first_conduit()    and LAG conduits which disappear.    We have to be prepared to return to the physical conduit, so the CPU    port must explicitly keep another reference to it. This is also to    say: the user ports and their CPU ports may not always keep a    reference to the same conduit net device, and both are needed.  As for the conduit's kobject for the /sys/class/net/ entry, we don't care about it, we can release it as soon as we hold the net device object itself.  History and blame attribution -----------------------------  The code has been refactored so many times, it is very difficult to follow and properly attribute a blame, but I'll try to make a short history which I hope to be correct.  We have two distinct probing paths: - one for OF, introduced in 2016 i ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71152","epss":0.00124,"percentile":0.02481,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09486},"relatedVulnerabilities":[{"id":"CVE-2025-71152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71152","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/06e219f6a706c367c93051f408ac61417643d2f9","https://git.kernel.org/stable/c/0e766b77ba5093583dfe609fae0aa1545c46dbbd","https://git.kernel.org/stable/c/b358fc6ff3b35a29f7f677da1c67af67d0d560cb","https://git.kernel.org/stable/c/ec2b34acb1894cfc10ed22d8277ca4f11e9f4b23"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: properly keep track of conduit reference\n\nProblem description\n-------------------\n\nDSA has a mumbo-jumbo of reference handling of the conduit net device\nand its kobject which, sadly, is just wrong and doesn't make sense.\n\nThere are two distinct problems.\n\n1. The OF path, which uses of_find_net_device_by_node(), never releases\n   the elevated refcount on the conduit's kobject. Nominally, the OF and\n   non-OF paths should result in objects having identical reference\n   counts taken, and it is already suspicious that\n   dsa_dev_to_net_device() has a put_device() call which is missing in\n   dsa_port_parse_of(), but we can actually even verify that an issue\n   exists. With CONFIG_DEBUG_KOBJECT_RELEASE=y, if we run this command\n   \"before\" and \"after\" applying this patch:\n\n(unbind the conduit driver for net device eno2)\necho 0000:00:00.2 > /sys/bus/pci/drivers/fsl_enetc/unbind\n\nwe see these lines in the output diff which appear only with the patch\napplied:\n\nkobject: 'eno2' (ffff002009a3a6b8): kobject_release, parent 0000000000000000 (delayed 1000)\nkobject: '109' (ffff0020099d59a0): kobject_release, parent 0000000000000000 (delayed 1000)\n\n2. After we find the conduit interface one way (OF) or another (non-OF),\n   it can get unregistered at any time, and DSA remains with a long-lived,\n   but in this case stale, cpu_dp->conduit pointer. Holding the net\n   device's underlying kobject isn't actually of much help, it just\n   prevents it from being freed (but we never need that kobject\n   directly). What helps us to prevent the net device from being\n   unregistered is the parallel netdev reference mechanism (dev_hold()\n   and dev_put()).\n\nActually we actually use that netdev tracker mechanism implicitly on\nuser ports since commit 2f1e8ea726e9 (\"net: dsa: link interfaces with\nthe DSA master to get rid of lockdep warnings\"), via netdev_upper_dev_link().\nBut time still passes at DSA switch probe time between the initial\nof_find_net_device_by_node() code and the user port creation time, time\nduring which the conduit could unregister itself and DSA wouldn't know\nabout it.\n\nSo we have to run of_find_net_device_by_node() under rtnl_lock() to\nprevent that from happening, and release the lock only with the netdev\ntracker having acquired the reference.\n\nDo we need to keep the reference until dsa_unregister_switch() /\ndsa_switch_shutdown()?\n1: Maybe yes. A switch device will still be registered even if all user\n   ports failed to probe, see commit 86f8b1c01a0a (\"net: dsa: Do not\n   make user port errors fatal\"), and the cpu_dp->conduit pointers\n   remain valid.  I haven't audited all call paths to see whether they\n   will actually use the conduit in lack of any user port, but if they\n   do, it seems safer to not rely on user ports for that reference.\n2. Definitely yes. We support changing the conduit which a user port is\n   associated to, and we can get into a situation where we've moved all\n   user ports away from a conduit, thus no longer hold any reference to\n   it via the net device tracker. But we shouldn't let it go nonetheless\n   - see the next change in relation to dsa_tree_find_first_conduit()\n   and LAG conduits which disappear.\n   We have to be prepared to return to the physical conduit, so the CPU\n   port must explicitly keep another reference to it. This is also to\n   say: the user ports and their CPU ports may not always keep a\n   reference to the same conduit net device, and both are needed.\n\nAs for the conduit's kobject for the /sys/class/net/ entry, we don't\ncare about it, we can release it as soon as we hold the net device\nobject itself.\n\nHistory and blame attribution\n-----------------------------\n\nThe code has been refactored so many times, it is very difficult to\nfollow and properly attribute a blame, but I'll try to make a short\nhistory which I hope to be correct.\n\nWe have two distinct probing paths:\n- one for OF, introduced in 2016 i\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71152","epss":0.00124,"percentile":0.02481,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71160","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71160","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: avoid chain re-validation if possible  Hamza Mahfooz reports cpu soft lock-ups in nft_chain_validate():   watchdog: BUG: soft lockup - CPU#1 stuck for 27s! [iptables-nft-re:37547] [..]  RIP: 0010:nft_chain_validate+0xcb/0x110 [nf_tables] [..]   nft_immediate_validate+0x36/0x50 [nf_tables]   nft_chain_validate+0xc9/0x110 [nf_tables]   nft_immediate_validate+0x36/0x50 [nf_tables]   nft_chain_validate+0xc9/0x110 [nf_tables]   nft_immediate_validate+0x36/0x50 [nf_tables]   nft_chain_validate+0xc9/0x110 [nf_tables]   nft_immediate_validate+0x36/0x50 [nf_tables]   nft_chain_validate+0xc9/0x110 [nf_tables]   nft_immediate_validate+0x36/0x50 [nf_tables]   nft_chain_validate+0xc9/0x110 [nf_tables]   nft_immediate_validate+0x36/0x50 [nf_tables]   nft_chain_validate+0xc9/0x110 [nf_tables]   nft_table_validate+0x6b/0xb0 [nf_tables]   nf_tables_validate+0x8b/0xa0 [nf_tables]   nf_tables_commit+0x1df/0x1eb0 [nf_tables] [..]  Currently nf_tables will traverse the entire table (chain graph), starting from the entry points (base chains), exploring all possible paths (chain jumps).  But there are cases where we could avoid revalidation.  Consider: 1  input -> j2 -> j3 2  input -> j2 -> j3 3  input -> j1 -> j2 -> j3  Then the second rule does not need to revalidate j2, and, by extension j3, because this was already checked during validation of the first rule. We need to validate it only for rule 3.  This is needed because chain loop detection also ensures we do not exceed the jump stack: Just because we know that j2 is cycle free, its last jump might now exceed the allowed stack size.  We also need to update all reachable chains with the new largest observed call depth.  Care has to be taken to revalidate even if the chain depth won't be an issue: chain validation also ensures that expressions are not called from invalid base chains.  For example, the masquerade expression can only be called from NAT postrouting base chains.  Therefore we also need to keep record of the base chain context (type, hooknum) and revalidate if the chain becomes reachable from a different hook location.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71160","epss":0.00167,"percentile":0.06249,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.087675},"relatedVulnerabilities":[{"id":"CVE-2025-71160","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71160","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/09d6074995c186e449979fe6c1b0f1a69cf9bd3b","https://git.kernel.org/stable/c/14fa3d1927f1382f86e3f70a51f26005c8e3cff6","https://git.kernel.org/stable/c/53de1e6cde8f9b791d9cf61aa0e7b02cf5bbe8b1","https://git.kernel.org/stable/c/8e1a1bc4f5a42747c08130b8242ebebd1210b32f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: avoid chain re-validation if possible\n\nHamza Mahfooz reports cpu soft lock-ups in\nnft_chain_validate():\n\n watchdog: BUG: soft lockup - CPU#1 stuck for 27s! [iptables-nft-re:37547]\n[..]\n RIP: 0010:nft_chain_validate+0xcb/0x110 [nf_tables]\n[..]\n  nft_immediate_validate+0x36/0x50 [nf_tables]\n  nft_chain_validate+0xc9/0x110 [nf_tables]\n  nft_immediate_validate+0x36/0x50 [nf_tables]\n  nft_chain_validate+0xc9/0x110 [nf_tables]\n  nft_immediate_validate+0x36/0x50 [nf_tables]\n  nft_chain_validate+0xc9/0x110 [nf_tables]\n  nft_immediate_validate+0x36/0x50 [nf_tables]\n  nft_chain_validate+0xc9/0x110 [nf_tables]\n  nft_immediate_validate+0x36/0x50 [nf_tables]\n  nft_chain_validate+0xc9/0x110 [nf_tables]\n  nft_immediate_validate+0x36/0x50 [nf_tables]\n  nft_chain_validate+0xc9/0x110 [nf_tables]\n  nft_table_validate+0x6b/0xb0 [nf_tables]\n  nf_tables_validate+0x8b/0xa0 [nf_tables]\n  nf_tables_commit+0x1df/0x1eb0 [nf_tables]\n[..]\n\nCurrently nf_tables will traverse the entire table (chain graph), starting\nfrom the entry points (base chains), exploring all possible paths\n(chain jumps).  But there are cases where we could avoid revalidation.\n\nConsider:\n1  input -> j2 -> j3\n2  input -> j2 -> j3\n3  input -> j1 -> j2 -> j3\n\nThen the second rule does not need to revalidate j2, and, by extension j3,\nbecause this was already checked during validation of the first rule.\nWe need to validate it only for rule 3.\n\nThis is needed because chain loop detection also ensures we do not exceed\nthe jump stack: Just because we know that j2 is cycle free, its last jump\nmight now exceed the allowed stack size.  We also need to update all\nreachable chains with the new largest observed call depth.\n\nCare has to be taken to revalidate even if the chain depth won't be an\nissue: chain validation also ensures that expressions are not called from\ninvalid base chains.  For example, the masquerade expression can only be\ncalled from NAT postrouting base chains.\n\nTherefore we also need to keep record of the base chain context (type,\nhooknum) and revalidate if the chain becomes reachable from a different\nhook location.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71160","epss":0.00167,"percentile":0.06249,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71160","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71184","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix NULL dereference on root when tracing inode eviction  When evicting an inode the first thing we do is to setup tracing for it, which implies fetching the root's id. But in btrfs_evict_inode() the root might be NULL, as implied in the next check that we do in btrfs_evict_inode().  Hence, we either should set the ->root_objectid to 0 in case the root is NULL, or we move tracing setup after checking that the root is not NULL. Setting the rootid to 0 at least gives us the possibility to trace this call even in the case when the root is NULL, so that's the solution taken here.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71184","epss":0.00123,"percentile":0.02352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71184","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06457500000000001},"relatedVulnerabilities":[{"id":"CVE-2025-71184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71184","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/582ba48e4a4c06fef6bdcf4e57b7b9af660bbd0c","https://git.kernel.org/stable/c/64d8abd8c5305795a2b35fc96039d99d34f5e762","https://git.kernel.org/stable/c/99e057f3d3ef24b99a7b1d84e01dd1bd890098da","https://git.kernel.org/stable/c/f157dd661339fc6f5f2b574fe2429c43bd309534"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix NULL dereference on root when tracing inode eviction\n\nWhen evicting an inode the first thing we do is to setup tracing for it,\nwhich implies fetching the root's id. But in btrfs_evict_inode() the\nroot might be NULL, as implied in the next check that we do in\nbtrfs_evict_inode().\n\nHence, we either should set the ->root_objectid to 0 in case the root is\nNULL, or we move tracing setup after checking that the root is not\nNULL. Setting the rootid to 0 at least gives us the possibility to trace\nthis call even in the case when the root is NULL, so that's the solution\ntaken here.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71184","epss":0.00123,"percentile":0.02352,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71184","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71184","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71188","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71188","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: lpc18xx-dmamux: fix device leak on route allocation  Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation.  Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71188","epss":0.0019,"percentile":0.08791,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71188","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09975},"relatedVulnerabilities":[{"id":"CVE-2025-71188","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71188","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1e47d80f6720f0224efd19bcf081d39637569c10","https://git.kernel.org/stable/c/3d396ebfb3049a2b5fac51d2c967db5114b685e8","https://git.kernel.org/stable/c/499ddae78c4baa9b94df76b2d2eb6b150d15377f","https://git.kernel.org/stable/c/992eb8055a6e5dbb808672d20d68e60d5a89b12b","https://git.kernel.org/stable/c/9fba97baa520c9446df51a64708daf27c5a7ed32","https://git.kernel.org/stable/c/adef147a8d8c3d767abf88ad2c381ffab2993086","https://git.kernel.org/stable/c/d4d63059dee7e7cae0c4d9a532ed558bc90efb55","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: lpc18xx-dmamux: fix device leak on route allocation\n\nMake sure to drop the reference taken when looking up the DMA mux\nplatform device during route allocation.\n\nNote that holding a reference to a device does not prevent its driver\ndata from going away so there is no point in keeping the reference.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71188","epss":0.0019,"percentile":0.08791,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71188","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71188","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71193","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71193","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  phy: qcom-qusb2: Fix NULL pointer dereference on early suspend  Enabling runtime PM before attaching the QPHY instance as driver data can lead to a NULL pointer dereference in runtime PM callbacks that expect valid driver data. There is a small window where the suspend callback may run after PM runtime enabling and before runtime forbid. This causes a sporadic crash during boot:  ``` Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a1 [...] CPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 6.16.7+ #116 PREEMPT Workqueue: pm pm_runtime_work pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : qusb2_phy_runtime_suspend+0x14/0x1e0 [phy_qcom_qusb2] lr : pm_generic_runtime_suspend+0x2c/0x44 [...] ```  Attach the QPHY instance as driver data before enabling runtime PM to prevent NULL pointer dereference in runtime PM callbacks.  Reorder pm_runtime_enable() and pm_runtime_forbid() to prevent a short window where an unnecessary runtime suspend can occur.  Use the devres-managed version to ensure PM runtime is symmetrically disabled during driver removal for proper cleanup.","cvss":[],"epss":[{"cve":"CVE-2025-71193","epss":0.00174,"percentile":0.07052,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.087},"relatedVulnerabilities":[{"id":"CVE-2025-71193","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71193","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1ca52c0983c34fca506921791202ed5bdafd5306","https://git.kernel.org/stable/c/4ac15caa27ff842b068a54f1c6a8ff8b31f658e7","https://git.kernel.org/stable/c/beba460a299150b5d8dcbe3474a8f4bdf0205180","https://git.kernel.org/stable/c/d50a9b7fd07296a1ab81c49ceba14cae3d31df86"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nphy: qcom-qusb2: Fix NULL pointer dereference on early suspend\n\nEnabling runtime PM before attaching the QPHY instance as driver data\ncan lead to a NULL pointer dereference in runtime PM callbacks that\nexpect valid driver data. There is a small window where the suspend\ncallback may run after PM runtime enabling and before runtime forbid.\nThis causes a sporadic crash during boot:\n\n```\nUnable to handle kernel NULL pointer dereference at virtual address 00000000000000a1\n[...]\nCPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 6.16.7+ #116 PREEMPT\nWorkqueue: pm pm_runtime_work\npstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : qusb2_phy_runtime_suspend+0x14/0x1e0 [phy_qcom_qusb2]\nlr : pm_generic_runtime_suspend+0x2c/0x44\n[...]\n```\n\nAttach the QPHY instance as driver data before enabling runtime PM to\nprevent NULL pointer dereference in runtime PM callbacks.\n\nReorder pm_runtime_enable() and pm_runtime_forbid() to prevent a\nshort window where an unnecessary runtime suspend can occur.\n\nUse the devres-managed version to ensure PM runtime is symmetrically\ndisabled during driver removal for proper cleanup.","cvss":[],"epss":[{"cve":"CVE-2025-71193","epss":0.00174,"percentile":0.07052,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71193","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71198","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection  The st_lsm6dsx_acc_channels array of struct iio_chan_spec has a non-NULL event_spec field, indicating support for IIO events. However, event detection is not supported for all sensors, and if userspace tries to configure accelerometer wakeup events on a sensor device that does not support them (e.g. LSM6DS0), st_lsm6dsx_write_event() dereferences a NULL pointer when trying to write to the wakeup register. Define an additional struct iio_chan_spec array whose members have a NULL event_spec field, and use this array instead of st_lsm6dsx_acc_channels for sensors without event detection capability.","cvss":[],"epss":[{"cve":"CVE-2025-71198","epss":0.00174,"percentile":0.07053,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.087},"relatedVulnerabilities":[{"id":"CVE-2025-71198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71198","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4d60ffcdedfe2cdb68a1cde19bb292bc67451629","https://git.kernel.org/stable/c/7673167fac9323110973a3300637adba7d45de3a","https://git.kernel.org/stable/c/81ed6e42d6e555dd978c9dd5e3f7c20cb121221b","https://git.kernel.org/stable/c/c34e2e2d67b3bb8d5a6d09b0d6dac845cdd13fb3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection\n\nThe st_lsm6dsx_acc_channels array of struct iio_chan_spec has a non-NULL\nevent_spec field, indicating support for IIO events. However, event\ndetection is not supported for all sensors, and if userspace tries to\nconfigure accelerometer wakeup events on a sensor device that does not\nsupport them (e.g. LSM6DS0), st_lsm6dsx_write_event() dereferences a NULL\npointer when trying to write to the wakeup register.\nDefine an additional struct iio_chan_spec array whose members have a NULL\nevent_spec field, and use this array instead of st_lsm6dsx_acc_channels for\nsensors without event detection capability.","cvss":[],"epss":[{"cve":"CVE-2025-71198","epss":0.00174,"percentile":0.07053,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71202","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71202","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/sva: invalidate stale IOTLB entries for kernel address space  Introduce a new IOMMU interface to flush IOTLB paging cache entries for the CPU kernel address space.  This interface is invoked from the x86 architecture code that manages combined user and kernel page tables, specifically before any kernel page table page is freed and reused.  This addresses the main issue with vfree() which is a common occurrence and can be triggered by unprivileged users.  While this resolves the primary problem, it doesn't address some extremely rare case related to memory unplug of memory that was present as reserved memory at boot, which cannot be triggered by unprivileged users.  The discussion can be found at the link below.  Enable SVA on x86 architecture since the IOMMU can now receive notification to flush the paging cache before freeing the CPU kernel page table pages.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71202","epss":0.00114,"percentile":0.0162,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2025-71202","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71202","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/9f0a7ab700f8620e433b05c57fbd26c92ea186d9","https://git.kernel.org/stable/c/e37d5a2d60a338c5917c45296bac65da1382eda5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/sva: invalidate stale IOTLB entries for kernel address space\n\nIntroduce a new IOMMU interface to flush IOTLB paging cache entries for\nthe CPU kernel address space.  This interface is invoked from the x86\narchitecture code that manages combined user and kernel page tables,\nspecifically before any kernel page table page is freed and reused.\n\nThis addresses the main issue with vfree() which is a common occurrence\nand can be triggered by unprivileged users.  While this resolves the\nprimary problem, it doesn't address some extremely rare case related to\nmemory unplug of memory that was present as reserved memory at boot, which\ncannot be triggered by unprivileged users.  The discussion can be found at\nthe link below.\n\nEnable SVA on x86 architecture since the IOMMU can now receive\nnotification to flush the paging cache before freeing the CPU kernel page\ntable pages.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71202","epss":0.00114,"percentile":0.0162,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71202","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71225","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md: suspend array while updating raid_disks via sysfs  In raid1_reshape(), freeze_array() is called before modifying the r1bio memory pool (conf->r1bio_pool) and conf->raid_disks, and unfreeze_array() is called after the update is completed.  However, freeze_array() only waits until nr_sync_pending and (nr_pending - nr_queued) of all buckets reaches zero. When an I/O error occurs, nr_queued is increased and the corresponding r1bio is queued to either retry_list or bio_end_io_list. As a result, freeze_array() may unblock before these r1bios are released.  This can lead to a situation where conf->raid_disks and the mempool have already been updated while queued r1bios, allocated with the old raid_disks value, are later released. Consequently, free_r1bio() may access memory out of bounds in put_all_bios() and release r1bios of the wrong size to the new mempool, potentially causing issues with the mempool as well.  Since only normal I/O might increase nr_queued while an I/O error occurs, suspending the array avoids this issue.  Note: Updating raid_disks via ioctl SET_ARRAY_INFO already suspends the array. Therefore, we suspend the array when updating raid_disks via sysfs to avoid this issue too.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71225","epss":0.00084,"percentile":0.00289,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71225","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04326000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-71225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71225","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0107b18cd8ac17eb3e54786adc05a85cdbb6ef22","https://git.kernel.org/stable/c/165d1359f945b72c5f90088f60d48ff46115269e","https://git.kernel.org/stable/c/2cc583653bbe050bacd1cadcc9776d39bf449740"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd: suspend array while updating raid_disks via sysfs\n\nIn raid1_reshape(), freeze_array() is called before modifying the r1bio\nmemory pool (conf->r1bio_pool) and conf->raid_disks, and\nunfreeze_array() is called after the update is completed.\n\nHowever, freeze_array() only waits until nr_sync_pending and\n(nr_pending - nr_queued) of all buckets reaches zero. When an I/O error\noccurs, nr_queued is increased and the corresponding r1bio is queued to\neither retry_list or bio_end_io_list. As a result, freeze_array() may\nunblock before these r1bios are released.\n\nThis can lead to a situation where conf->raid_disks and the mempool have\nalready been updated while queued r1bios, allocated with the old\nraid_disks value, are later released. Consequently, free_r1bio() may\naccess memory out of bounds in put_all_bios() and release r1bios of the\nwrong size to the new mempool, potentially causing issues with the\nmempool as well.\n\nSince only normal I/O might increase nr_queued while an I/O error occurs,\nsuspending the array avoids this issue.\n\nNote: Updating raid_disks via ioctl SET_ARRAY_INFO already suspends\nthe array. Therefore, we suspend the array when updating raid_disks\nvia sysfs to avoid this issue too.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"exploitabilityScore":1.1,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71225","epss":0.00084,"percentile":0.00289,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71225","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71227","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71227","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: don't WARN for connections on invalid channels  It's not clear (to me) how exactly syzbot managed to hit this, but it seems conceivable that e.g. regulatory changed and has disabled a channel between scanning (channel is checked to be usable by cfg80211_get_ies_channel_number) and connecting on the channel later.  With one scenario that isn't covered elsewhere described above, the warning isn't good, replace it with a (more informative) error message.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71227","epss":0.001,"percentile":0.00938,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.052500000000000005},"relatedVulnerabilities":[{"id":"CVE-2025-71227","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71227","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/10d3ff7e5812c8d70300f6fa8f524009a06aa7e1","https://git.kernel.org/stable/c/99067b58a408a384d2a45c105eb3dce980a862ce"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: don't WARN for connections on invalid channels\n\nIt's not clear (to me) how exactly syzbot managed to hit this,\nbut it seems conceivable that e.g. regulatory changed and has\ndisabled a channel between scanning (channel is checked to be\nusable by cfg80211_get_ies_channel_number) and connecting on\nthe channel later.\n\nWith one scenario that isn't covered elsewhere described above,\nthe warning isn't good, replace it with a (more informative)\nerror message.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71227","epss":0.001,"percentile":0.00938,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71227","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71272","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71272","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  most: core: fix resource leak in most_register_interface error paths  The function most_register_interface() did not correctly release resources if it failed early (before registering the device). In these cases, it returned an error code immediately, leaking the memory allocated for the interface.  Fix this by initializing the device early via device_initialize() and calling put_device() on all error paths.  The most_register_interface() is expected to call put_device() on error which frees the resources allocated in the caller. The put_device() either calls release_mdev() or dim2_release(), depending on the caller.  Switch to using device_add() instead of device_register() to handle the split initialization.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71272","epss":0.00127,"percentile":0.02727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71272","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2025-71272","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71272","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1f4c9d8a1021281750c6cda126d6f8a40cc24e71","https://git.kernel.org/stable/c/2f483f3817fb0e4209ac5de928778b1da0cc8574","https://git.kernel.org/stable/c/a49028a796d7b94f8e3ab9bd34b18f36be235459","https://git.kernel.org/stable/c/af0b99b2214a10554adb5b868240d23af6e64e71"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmost: core: fix resource leak in most_register_interface error paths\n\nThe function most_register_interface() did not correctly release resources\nif it failed early (before registering the device). In these cases, it\nreturned an error code immediately, leaking the memory allocated for the\ninterface.\n\nFix this by initializing the device early via device_initialize() and\ncalling put_device() on all error paths.\n\nThe most_register_interface() is expected to call put_device() on\nerror which frees the resources allocated in the caller. The\nput_device() either calls release_mdev() or dim2_release(),\ndepending on the caller.\n\nSwitch to using device_add() instead of device_register() to handle\nthe split initialization.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71272","epss":0.00127,"percentile":0.02727,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71272","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71272","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71273","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71273","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()  Simplify the code by using device managed memory allocations.  This also fixes a memory leak in rtw_register_hw(). The supported bands were not freed in the error path.  Copied from commit 145df52a8671 (\"wifi: rtw89: Convert rtw89_core_set_supported_band to use devm_*\").","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71273","epss":0.00122,"percentile":0.02255,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71273","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2025-71273","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71273","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1bd90e0a99fdc8dc5deb3c92bf865e4496b4b311","https://git.kernel.org/stable/c/2ba12401cc1f2d970fa2e7d5b15abde3f5abd40d","https://git.kernel.org/stable/c/9b5418070ee8468fac9e8bf641c83d46b85bff30","https://git.kernel.org/stable/c/ad9b80ee310ed734482a2e5da874b67f88ac0ef8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()\n\nSimplify the code by using device managed memory allocations.\n\nThis also fixes a memory leak in rtw_register_hw(). The supported bands\nwere not freed in the error path.\n\nCopied from commit 145df52a8671 (\"wifi: rtw89: Convert\nrtw89_core_set_supported_band to use devm_*\").","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71273","epss":0.00122,"percentile":0.02255,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71273","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71273","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71285","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71285","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: qrtr: Drop the MHI auto_queue feature for IPCR DL channels  MHI stack offers the 'auto_queue' feature, which allows the MHI stack to auto queue the buffers for the RX path (DL channel). Though this feature simplifies the client driver design, it introduces race between the client drivers and the MHI stack. For instance, with auto_queue, the 'dl_callback' for the DL channel may get called before the client driver is fully probed. This means, by the time the dl_callback gets called, the client driver's structures might not be initialized, leading to NULL ptr dereference.  Currently, the drivers have to workaround this issue by initializing the internal structures before calling mhi_prepare_for_transfer_autoqueue(). But even so, there is a chance that the client driver's internal code path may call the MHI queue APIs before mhi_prepare_for_transfer_autoqueue() is called, leading to similar NULL ptr dereference. This issue has been reported on the Qcom X1E80100 CRD machines affecting boot.  So to properly fix all these races, drop the MHI 'auto_queue' feature altogether and let the client driver (QRTR) manage the RX buffers manually. In the QRTR driver, queue the RX buffers based on the ring length during probe and recycle the buffers in 'dl_callback' once they are consumed. This also warrants removing the setting of 'auto_queue' flag from controller drivers.  Currently, this 'auto_queue' feature is only enabled for IPCR DL channel. So only the QRTR client driver requires the modification.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71285","epss":0.00126,"percentile":0.02616,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71285","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2025-71285","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71285","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/51731792a25cb312ca94cdccfa139eb46de1b2ef","https://git.kernel.org/stable/c/7bdff9b9b0c65ac7105416fe3a40686832515e20","https://git.kernel.org/stable/c/8c464e00e0754e016816b1860fa9592dcad80eb2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: Drop the MHI auto_queue feature for IPCR DL channels\n\nMHI stack offers the 'auto_queue' feature, which allows the MHI stack to\nauto queue the buffers for the RX path (DL channel). Though this feature\nsimplifies the client driver design, it introduces race between the client\ndrivers and the MHI stack. For instance, with auto_queue, the 'dl_callback'\nfor the DL channel may get called before the client driver is fully probed.\nThis means, by the time the dl_callback gets called, the client driver's\nstructures might not be initialized, leading to NULL ptr dereference.\n\nCurrently, the drivers have to workaround this issue by initializing the\ninternal structures before calling mhi_prepare_for_transfer_autoqueue().\nBut even so, there is a chance that the client driver's internal code path\nmay call the MHI queue APIs before mhi_prepare_for_transfer_autoqueue() is\ncalled, leading to similar NULL ptr dereference. This issue has been\nreported on the Qcom X1E80100 CRD machines affecting boot.\n\nSo to properly fix all these races, drop the MHI 'auto_queue' feature\naltogether and let the client driver (QRTR) manage the RX buffers manually.\nIn the QRTR driver, queue the RX buffers based on the ring length during\nprobe and recycle the buffers in 'dl_callback' once they are consumed. This\nalso warrants removing the setting of 'auto_queue' flag from controller\ndrivers.\n\nCurrently, this 'auto_queue' feature is only enabled for IPCR DL channel.\nSo only the QRTR client driver requires the modification.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71285","epss":0.00126,"percentile":0.02616,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71285","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71285","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71289","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71289","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: handle attr_set_size() errors when truncating files  If attr_set_size() fails while truncating down, the error is silently ignored and the inode may be left in an inconsistent state.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71289","epss":0.00254,"percentile":0.1694,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13335},"relatedVulnerabilities":[{"id":"CVE-2025-71289","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71289","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3a718675d6af4992e34ffe86b8f36d471a5afe0e","https://git.kernel.org/stable/c/576248a34b927e93b2fd3fff7df735ba73ad7d01","https://git.kernel.org/stable/c/6dfea43d11513b7f2892529de55e8f0855108a2c","https://git.kernel.org/stable/c/92300ac7ff17cad67ff2f3fbb7003afa326134e0","https://git.kernel.org/stable/c/d73dcd1520d65a34420761641a36b951b14c8c53"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: handle attr_set_size() errors when truncating files\n\nIf attr_set_size() fails while truncating down, the error is silently\nignored and the inode may be left in an inconsistent state.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71289","epss":0.00254,"percentile":0.1694,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71289","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71313","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71313","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  PCI: endpoint: Add missing NULL check for alloc_workqueue()  alloc_workqueue() can return NULL on memory allocation failure. Without proper error checking, this may lead to a NULL pointer dereference when queue_work() is later called with the NULL workqueue pointer in epf_ntb_epc_init().  Add a NULL check immediately after alloc_workqueue() and return -ENOMEM on failure to prevent the driver from loading with an invalid workqueue pointer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71313","epss":0.00107,"percentile":0.01282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71313","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2025-71313","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71313","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/03f336a869b3a3f119d3ae52ac9723739c7fb7b6","https://git.kernel.org/stable/c/314eab6740bcda504ef978be599f805de05ce6de"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: Add missing NULL check for alloc_workqueue()\n\nalloc_workqueue() can return NULL on memory allocation failure. Without\nproper error checking, this may lead to a NULL pointer dereference when\nqueue_work() is later called with the NULL workqueue pointer in\nepf_ntb_epc_init().\n\nAdd a NULL check immediately after alloc_workqueue() and return -ENOMEM on\nfailure to prevent the driver from loading with an invalid workqueue\npointer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71313","epss":0.00107,"percentile":0.01282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2025-71313","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71313","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2025-71315","dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-71315","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vkms: Convert to DRM's vblank timer  Replace vkms' vblank timer with the DRM implementation. The DRM code is identical in concept, but differs in implementation.  Vblank timers are covered in vblank helpers and initializer macros, so remove the corresponding hrtimer in struct vkms_output. The vblank timer calls vkms' custom timeout code via handle_vblank_timeout in struct drm_crtc_helper_funcs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71315","epss":0.00112,"percentile":0.01521,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2025-71315","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-71315","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/02e2681ffe1addde1fc8c35d05657b16bfa79613","https://git.kernel.org/stable/c/a0582cc923985c6b72fe871b5f7aa7c682bfc230"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vkms: Convert to DRM's vblank timer\n\nReplace vkms' vblank timer with the DRM implementation. The DRM\ncode is identical in concept, but differs in implementation.\n\nVblank timers are covered in vblank helpers and initializer macros,\nso remove the corresponding hrtimer in struct vkms_output. The\nvblank timer calls vkms' custom timeout code via handle_vblank_timeout\nin struct drm_crtc_helper_funcs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-71315","epss":0.00112,"percentile":0.01521,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2025-71315","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-22996","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-22996","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv  mlx5e_priv is an unstable structure that can be memset(0) if profile attaching fails, mlx5e_priv in mlx5e_dev devlink private is used to reference the netdev and mdev associated with that struct. Instead, store netdev directly into mlx5e_dev and get mdev from the containing mlx5_adev aux device structure.  This fixes a kernel oops in mlx5e_remove when switchdev mode fails due to change profile failure.  $ devlink dev eswitch set pci/0000:00:03.0 mode switchdev Error: mlx5_core: Failed setting eswitch to offloads. dmesg: workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12 workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12  $ devlink dev reload pci/0000:00:03.0 ==> oops  BUG: kernel NULL pointer dereference, address: 0000000000000520  #PF: supervisor read access in kernel mode  #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 3 UID: 0 PID: 521 Comm: devlink Not tainted 6.18.0-rc5+ #117 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 RIP: 0010:mlx5e_remove+0x68/0x130 RSP: 0018:ffffc900034838f0 EFLAGS: 00010246 RAX: ffff88810283c380 RBX: ffff888101874400 RCX: ffffffff826ffc45 RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000 RBP: ffff888102d789c0 R08: ffff8881007137f0 R09: ffff888100264e10 R10: ffffc90003483898 R11: ffffc900034838a0 R12: ffff888100d261a0 R13: ffff888100d261a0 R14: ffff8881018749a0 R15: ffff888101874400 FS:  00007f8565fea740(0000) GS:ffff88856a759000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000520 CR3: 000000010b11a004 CR4: 0000000000370ef0 Call Trace:  <TASK>  device_release_driver_internal+0x19c/0x200  bus_remove_device+0xc6/0x130  device_del+0x160/0x3d0  ? devl_param_driverinit_value_get+0x2d/0x90  mlx5_detach_device+0x89/0xe0  mlx5_unload_one_devl_locked+0x3a/0x70  mlx5_devlink_reload_down+0xc8/0x220  devlink_reload+0x7d/0x260  devlink_nl_reload_doit+0x45b/0x5a0  genl_family_rcv_msg_doit+0xe8/0x140","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-22996","epss":0.00158,"percentile":0.05311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-22996","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08295000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-22996","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22996","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/123eda2e5b1638e298e3a66bb1e64a8da92de5e1","https://git.kernel.org/stable/c/a3d4f87d41f5140f1cf5c02fce5cdad2637f6244","https://git.kernel.org/stable/c/dcb2ad755a16cb0ecd2dc98234d71a6e216ae7fe"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv\n\nmlx5e_priv is an unstable structure that can be memset(0) if profile\nattaching fails, mlx5e_priv in mlx5e_dev devlink private is used to\nreference the netdev and mdev associated with that struct. Instead,\nstore netdev directly into mlx5e_dev and get mdev from the containing\nmlx5_adev aux device structure.\n\nThis fixes a kernel oops in mlx5e_remove when switchdev mode fails due\nto change profile failure.\n\n$ devlink dev eswitch set pci/0000:00:03.0 mode switchdev\nError: mlx5_core: Failed setting eswitch to offloads.\ndmesg:\nworkqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\nmlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12\nmlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12\nworkqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\nmlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12\nmlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12\n\n$ devlink dev reload pci/0000:00:03.0 ==> oops\n\nBUG: kernel NULL pointer dereference, address: 0000000000000520\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\nPGD 0 P4D 0\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 3 UID: 0 PID: 521 Comm: devlink Not tainted 6.18.0-rc5+ #117 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\nRIP: 0010:mlx5e_remove+0x68/0x130\nRSP: 0018:ffffc900034838f0 EFLAGS: 00010246\nRAX: ffff88810283c380 RBX: ffff888101874400 RCX: ffffffff826ffc45\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000\nRBP: ffff888102d789c0 R08: ffff8881007137f0 R09: ffff888100264e10\nR10: ffffc90003483898 R11: ffffc900034838a0 R12: ffff888100d261a0\nR13: ffff888100d261a0 R14: ffff8881018749a0 R15: ffff888101874400\nFS:  00007f8565fea740(0000) GS:ffff88856a759000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000520 CR3: 000000010b11a004 CR4: 0000000000370ef0\nCall Trace:\n <TASK>\n device_release_driver_internal+0x19c/0x200\n bus_remove_device+0xc6/0x130\n device_del+0x160/0x3d0\n ? devl_param_driverinit_value_get+0x2d/0x90\n mlx5_detach_device+0x89/0xe0\n mlx5_unload_one_devl_locked+0x3a/0x70\n mlx5_devlink_reload_down+0xc8/0x220\n devlink_reload+0x7d/0x260\n devlink_nl_reload_doit+0x45b/0x5a0\n genl_family_rcv_msg_doit+0xe8/0x140","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-22996","epss":0.00158,"percentile":0.05311,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-22996","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-22996","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23000","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23000","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Fix crash on profile change rollback failure  mlx5e_netdev_change_profile can fail to attach a new profile and can fail to rollback to old profile, in such case, we could end up with a dangling netdev with a fully reset netdev_priv. A retry to change profile, e.g. another attempt to call mlx5e_netdev_change_profile via switchdev mode change, will crash trying to access the now NULL priv->mdev.  This fix allows mlx5e_netdev_change_profile() to handle previous failures and an empty priv, by not assuming priv is valid.  Pass netdev and mdev to all flows requiring mlx5e_netdev_change_profile() and avoid passing priv. In mlx5e_netdev_change_profile() check if current priv is valid, and if not, just attach the new profile without trying to access the old one.  This fixes the following oops, when enabling switchdev mode for the 2nd time after first time failure:   ## Enabling switchdev mode first time:  mlx5_core 0012:03:00.1: E-Switch: Supported tc chains and prios offload workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12 workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12                                                                          ^^^^^^^^ mlx5_core 0000:00:03.0: E-Switch: Disable: mode(LEGACY), nvfs(0), necvfs(0), active vports(0)   ## retry: Enabling switchdev mode 2nd time:  mlx5_core 0000:00:03.0: E-Switch: Supported tc chains and prios offload BUG: kernel NULL pointer dereference, address: 0000000000000038  #PF: supervisor read access in kernel mode  #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 13 UID: 0 PID: 520 Comm: devlink Not tainted 6.18.0-rc4+ #91 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 RIP: 0010:mlx5e_detach_netdev+0x3c/0x90 Code: 50 00 00 f0 80 4f 78 02 48 8b bf e8 07 00 00 48 85 ff 74 16 48 8b 73 78 48 d1 ee 83 e6 01 83 f6 01 40 0f b6 f6 e8 c4 42 00 00 <48> 8b 45 38 48 85 c0 74 08 48 89 df e8 cc 47 40 1e 48 8b bb f0 07 RSP: 0018:ffffc90000673890 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff8881036a89c0 RCX: 0000000000000000 RDX: ffff888113f63800 RSI: ffffffff822fe720 RDI: 0000000000000000 RBP: 0000000000000000 R08: 0000000000002dcd R09: 0000000000000000 R10: ffffc900006738e8 R11: 00000000ffffffff R12: 0000000000000000 R13: 0000000000000000 R14: ffff8881036a89c0 R15: 0000000000000000 FS:  00007fdfb8384740(0000) GS:ffff88856a9d6000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000038 CR3: 0000000112ae0005 CR4: 0000000000370ef0 Call Trace:  <TASK>  mlx5e_netdev_change_profile+0x45/0xb0  mlx5e_vport_rep_load+0x27b/0x2d0  mlx5_esw_offloads_rep_load+0x72/0xf0  esw_offloads_enable+0x5d0/0x970  mlx5_eswitch_enable_locked+0x349/0x430  ? is_mp_supported+0x57/0xb0  mlx5_devlink_eswitch_mode_set+0x26b/0x430  devlink_nl_eswitch_set_doit+0x6f/0xf0  genl_family_rcv_msg_doit+0xe8/0x140  genl_rcv_msg+0x18b/0x290  ? __pfx_devlink_nl_pre_doit+0x10/0x10  ? __pfx_devlink_nl_eswitch_set_doit+0x10/0x10  ? __pfx_devlink_nl_post_doit+0x10/0x10  ? __pfx_genl_rcv_msg+0x10/0x10  netlink_rcv_skb+0x52/0x100  genl_rcv+0x28/0x40  netlink_unicast+0x282/0x3e0  ? __alloc_skb+0xd6/0x190  netlink_sendmsg+0x1f7/0x430  __sys_sendto+0x213/0x220  ? __sys_recvmsg+0x6a/0xd0  __x64_sys_sendto+0x24/0x30  do_syscall_64+0x50/0x1f0  entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7fdfb8495047","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23000","epss":0.00153,"percentile":0.04748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23000","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.080325},"relatedVulnerabilities":[{"id":"CVE-2026-23000","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23000","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4dadc4077e3f77d6d31e199a925fc7a705e7adeb","https://git.kernel.org/stable/c/dad52950b409d6923880d65a4cddb383286e17d2","https://git.kernel.org/stable/c/e05b8084a20f6bd5827d338c928e5e0fcbafa496"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix crash on profile change rollback failure\n\nmlx5e_netdev_change_profile can fail to attach a new profile and can\nfail to rollback to old profile, in such case, we could end up with a\ndangling netdev with a fully reset netdev_priv. A retry to change\nprofile, e.g. another attempt to call mlx5e_netdev_change_profile via\nswitchdev mode change, will crash trying to access the now NULL\npriv->mdev.\n\nThis fix allows mlx5e_netdev_change_profile() to handle previous\nfailures and an empty priv, by not assuming priv is valid.\n\nPass netdev and mdev to all flows requiring\nmlx5e_netdev_change_profile() and avoid passing priv.\nIn mlx5e_netdev_change_profile() check if current priv is valid, and if\nnot, just attach the new profile without trying to access the old one.\n\nThis fixes the following oops, when enabling switchdev mode for the 2nd\ntime after first time failure:\n\n ## Enabling switchdev mode first time:\n\nmlx5_core 0012:03:00.1: E-Switch: Supported tc chains and prios offload\nworkqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\nmlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12\nmlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12\nworkqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\nmlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12\nmlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12\n                                                                         ^^^^^^^^\nmlx5_core 0000:00:03.0: E-Switch: Disable: mode(LEGACY), nvfs(0), necvfs(0), active vports(0)\n\n ## retry: Enabling switchdev mode 2nd time:\n\nmlx5_core 0000:00:03.0: E-Switch: Supported tc chains and prios offload\nBUG: kernel NULL pointer dereference, address: 0000000000000038\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\nPGD 0 P4D 0\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 13 UID: 0 PID: 520 Comm: devlink Not tainted 6.18.0-rc4+ #91 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\nRIP: 0010:mlx5e_detach_netdev+0x3c/0x90\nCode: 50 00 00 f0 80 4f 78 02 48 8b bf e8 07 00 00 48 85 ff 74 16 48 8b 73 78 48 d1 ee 83 e6 01 83 f6 01 40 0f b6 f6 e8 c4 42 00 00 <48> 8b 45 38 48 85 c0 74 08 48 89 df e8 cc 47 40 1e 48 8b bb f0 07\nRSP: 0018:ffffc90000673890 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff8881036a89c0 RCX: 0000000000000000\nRDX: ffff888113f63800 RSI: ffffffff822fe720 RDI: 0000000000000000\nRBP: 0000000000000000 R08: 0000000000002dcd R09: 0000000000000000\nR10: ffffc900006738e8 R11: 00000000ffffffff R12: 0000000000000000\nR13: 0000000000000000 R14: ffff8881036a89c0 R15: 0000000000000000\nFS:  00007fdfb8384740(0000) GS:ffff88856a9d6000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000038 CR3: 0000000112ae0005 CR4: 0000000000370ef0\nCall Trace:\n <TASK>\n mlx5e_netdev_change_profile+0x45/0xb0\n mlx5e_vport_rep_load+0x27b/0x2d0\n mlx5_esw_offloads_rep_load+0x72/0xf0\n esw_offloads_enable+0x5d0/0x970\n mlx5_eswitch_enable_locked+0x349/0x430\n ? is_mp_supported+0x57/0xb0\n mlx5_devlink_eswitch_mode_set+0x26b/0x430\n devlink_nl_eswitch_set_doit+0x6f/0xf0\n genl_family_rcv_msg_doit+0xe8/0x140\n genl_rcv_msg+0x18b/0x290\n ? __pfx_devlink_nl_pre_doit+0x10/0x10\n ? __pfx_devlink_nl_eswitch_set_doit+0x10/0x10\n ? __pfx_devlink_nl_post_doit+0x10/0x10\n ? __pfx_genl_rcv_msg+0x10/0x10\n netlink_rcv_skb+0x52/0x100\n genl_rcv+0x28/0x40\n netlink_unicast+0x282/0x3e0\n ? __alloc_skb+0xd6/0x190\n netlink_sendmsg+0x1f7/0x430\n __sys_sendto+0x213/0x220\n ? __sys_recvmsg+0x6a/0xd0\n __x64_sys_sendto+0x24/0x30\n do_syscall_64+0x50/0x1f0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7fdfb8495047","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23000","epss":0.00153,"percentile":0.04748,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23000","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23000","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23004","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23004","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()  syzbot was able to crash the kernel in rt6_uncached_list_flush_dev() in an interesting way [1]  Crash happens in list_del_init()/INIT_LIST_HEAD() while writing list->prev, while the prior write on list->next went well.  static inline void INIT_LIST_HEAD(struct list_head *list) { \tWRITE_ONCE(list->next, list); // This went well \tWRITE_ONCE(list->prev, list); // Crash, @list has been freed. }  Issue here is that rt6_uncached_list_del() did not attempt to lock ul->lock, as list_empty(&rt->dst.rt_uncached) returned true because the WRITE_ONCE(list->next, list) happened on the other CPU.  We might use list_del_init_careful() and list_empty_careful(), or make sure rt6_uncached_list_del() always grabs the spinlock whenever rt->dst.rt_uncached_list has been set.  A similar fix is neeed for IPv4.  [1]   BUG: KASAN: slab-use-after-free in INIT_LIST_HEAD include/linux/list.h:46 [inline]  BUG: KASAN: slab-use-after-free in list_del_init include/linux/list.h:296 [inline]  BUG: KASAN: slab-use-after-free in rt6_uncached_list_flush_dev net/ipv6/route.c:191 [inline]  BUG: KASAN: slab-use-after-free in rt6_disable_ip+0x633/0x730 net/ipv6/route.c:5020 Write of size 8 at addr ffff8880294cfa78 by task kworker/u8:14/3450  CPU: 0 UID: 0 PID: 3450 Comm: kworker/u8:14 Tainted: G             L      syzkaller #0 PREEMPT_{RT,(full)} Tainted: [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 Workqueue: netns cleanup_net Call Trace:  <TASK>   dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120   print_address_description mm/kasan/report.c:378 [inline]   print_report+0xca/0x240 mm/kasan/report.c:482   kasan_report+0x118/0x150 mm/kasan/report.c:595   INIT_LIST_HEAD include/linux/list.h:46 [inline]   list_del_init include/linux/list.h:296 [inline]   rt6_uncached_list_flush_dev net/ipv6/route.c:191 [inline]   rt6_disable_ip+0x633/0x730 net/ipv6/route.c:5020   addrconf_ifdown+0x143/0x18a0 net/ipv6/addrconf.c:3853  addrconf_notify+0x1bc/0x1050 net/ipv6/addrconf.c:-1   notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85   call_netdevice_notifiers_extack net/core/dev.c:2268 [inline]   call_netdevice_notifiers net/core/dev.c:2282 [inline]   netif_close_many+0x29c/0x410 net/core/dev.c:1785   unregister_netdevice_many_notify+0xb50/0x2330 net/core/dev.c:12353   ops_exit_rtnl_list net/core/net_namespace.c:187 [inline]   ops_undo_list+0x3dc/0x990 net/core/net_namespace.c:248   cleanup_net+0x4de/0x7b0 net/core/net_namespace.c:696   process_one_work kernel/workqueue.c:3257 [inline]   process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340   worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421   kthread+0x711/0x8a0 kernel/kthread.c:463   ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158   ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246  </TASK>  Allocated by task 803:   kasan_save_stack mm/kasan/common.c:57 [inline]   kasan_save_track+0x3e/0x80 mm/kasan/common.c:78   unpoison_slab_object mm/kasan/common.c:340 [inline]   __kasan_slab_alloc+0x6c/0x80 mm/kasan/common.c:366   kasan_slab_alloc include/linux/kasan.h:253 [inline]   slab_post_alloc_hook mm/slub.c:4953 [inline]   slab_alloc_node mm/slub.c:5263 [inline]   kmem_cache_alloc_noprof+0x18d/0x6c0 mm/slub.c:5270   dst_alloc+0x105/0x170 net/core/dst.c:89   ip6_dst_alloc net/ipv6/route.c:342 [inline]   icmp6_dst_alloc+0x75/0x460 net/ipv6/route.c:3333   mld_sendpack+0x683/0xe60 net/ipv6/mcast.c:1844   mld_send_cr net/ipv6/mcast.c:2154 [inline]   mld_ifc_work+0x83e/0xd60 net/ipv6/mcast.c:2693   process_one_work kernel/workqueue.c:3257 [inline]   process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340   worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421   kthread+0x711/0x8a0 kernel/kthread.c:463   ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158   ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entr ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23004","epss":0.0012,"percentile":0.02103,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23004","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.058199999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-23004","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23004","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/722de945216144af7cd4d39bdeb936108d2595a7","https://git.kernel.org/stable/c/815db2363e51f0ef416947492d4dac5b7a520f56","https://git.kernel.org/stable/c/9a6f0c4d5796ab89b5a28a890ce542344d58bd69","https://git.kernel.org/stable/c/f24a52948c95e02facbca2b3b6eb5a225e27eb01"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()\n\nsyzbot was able to crash the kernel in rt6_uncached_list_flush_dev()\nin an interesting way [1]\n\nCrash happens in list_del_init()/INIT_LIST_HEAD() while writing\nlist->prev, while the prior write on list->next went well.\n\nstatic inline void INIT_LIST_HEAD(struct list_head *list)\n{\n\tWRITE_ONCE(list->next, list); // This went well\n\tWRITE_ONCE(list->prev, list); // Crash, @list has been freed.\n}\n\nIssue here is that rt6_uncached_list_del() did not attempt to lock\nul->lock, as list_empty(&rt->dst.rt_uncached) returned\ntrue because the WRITE_ONCE(list->next, list) happened on the other CPU.\n\nWe might use list_del_init_careful() and list_empty_careful(),\nor make sure rt6_uncached_list_del() always grabs the spinlock\nwhenever rt->dst.rt_uncached_list has been set.\n\nA similar fix is neeed for IPv4.\n\n[1]\n\n BUG: KASAN: slab-use-after-free in INIT_LIST_HEAD include/linux/list.h:46 [inline]\n BUG: KASAN: slab-use-after-free in list_del_init include/linux/list.h:296 [inline]\n BUG: KASAN: slab-use-after-free in rt6_uncached_list_flush_dev net/ipv6/route.c:191 [inline]\n BUG: KASAN: slab-use-after-free in rt6_disable_ip+0x633/0x730 net/ipv6/route.c:5020\nWrite of size 8 at addr ffff8880294cfa78 by task kworker/u8:14/3450\n\nCPU: 0 UID: 0 PID: 3450 Comm: kworker/u8:14 Tainted: G             L      syzkaller #0 PREEMPT_{RT,(full)}\nTainted: [L]=SOFTLOCKUP\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025\nWorkqueue: netns cleanup_net\nCall Trace:\n <TASK>\n  dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120\n  print_address_description mm/kasan/report.c:378 [inline]\n  print_report+0xca/0x240 mm/kasan/report.c:482\n  kasan_report+0x118/0x150 mm/kasan/report.c:595\n  INIT_LIST_HEAD include/linux/list.h:46 [inline]\n  list_del_init include/linux/list.h:296 [inline]\n  rt6_uncached_list_flush_dev net/ipv6/route.c:191 [inline]\n  rt6_disable_ip+0x633/0x730 net/ipv6/route.c:5020\n  addrconf_ifdown+0x143/0x18a0 net/ipv6/addrconf.c:3853\n addrconf_notify+0x1bc/0x1050 net/ipv6/addrconf.c:-1\n  notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85\n  call_netdevice_notifiers_extack net/core/dev.c:2268 [inline]\n  call_netdevice_notifiers net/core/dev.c:2282 [inline]\n  netif_close_many+0x29c/0x410 net/core/dev.c:1785\n  unregister_netdevice_many_notify+0xb50/0x2330 net/core/dev.c:12353\n  ops_exit_rtnl_list net/core/net_namespace.c:187 [inline]\n  ops_undo_list+0x3dc/0x990 net/core/net_namespace.c:248\n  cleanup_net+0x4de/0x7b0 net/core/net_namespace.c:696\n  process_one_work kernel/workqueue.c:3257 [inline]\n  process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340\n  worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421\n  kthread+0x711/0x8a0 kernel/kthread.c:463\n  ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158\n  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246\n </TASK>\n\nAllocated by task 803:\n  kasan_save_stack mm/kasan/common.c:57 [inline]\n  kasan_save_track+0x3e/0x80 mm/kasan/common.c:78\n  unpoison_slab_object mm/kasan/common.c:340 [inline]\n  __kasan_slab_alloc+0x6c/0x80 mm/kasan/common.c:366\n  kasan_slab_alloc include/linux/kasan.h:253 [inline]\n  slab_post_alloc_hook mm/slub.c:4953 [inline]\n  slab_alloc_node mm/slub.c:5263 [inline]\n  kmem_cache_alloc_noprof+0x18d/0x6c0 mm/slub.c:5270\n  dst_alloc+0x105/0x170 net/core/dst.c:89\n  ip6_dst_alloc net/ipv6/route.c:342 [inline]\n  icmp6_dst_alloc+0x75/0x460 net/ipv6/route.c:3333\n  mld_sendpack+0x683/0xe60 net/ipv6/mcast.c:1844\n  mld_send_cr net/ipv6/mcast.c:2154 [inline]\n  mld_ifc_work+0x83e/0xd60 net/ipv6/mcast.c:2693\n  process_one_work kernel/workqueue.c:3257 [inline]\n  process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340\n  worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421\n  kthread+0x711/0x8a0 kernel/kthread.c:463\n  ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158\n  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entr\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23004","epss":0.0012,"percentile":0.02103,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23004","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23004","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23035","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23035","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv  mlx5e_priv is an unstable structure that can be memset(0) if profile attaching fails.  Pass netdev to mlx5e_destroy_netdev() to guarantee it will work on a valid netdev.  On mlx5e_remove: Check validity of priv->profile, before attempting to cleanup any resources that might be not there.  This fixes a kernel oops in mlx5e_remove when switchdev mode fails due to change profile failure.  $ devlink dev eswitch set pci/0000:00:03.0 mode switchdev Error: mlx5_core: Failed setting eswitch to offloads. dmesg: workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12 workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR mlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12 mlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12  $ devlink dev reload pci/0000:00:03.0 ==> oops  BUG: kernel NULL pointer dereference, address: 0000000000000370 PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 15 UID: 0 PID: 520 Comm: devlink Not tainted 6.18.0-rc5+ #115 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 RIP: 0010:mlx5e_dcbnl_dscp_app+0x23/0x100 RSP: 0018:ffffc9000083f8b8 EFLAGS: 00010286 RAX: ffff8881126fc380 RBX: ffff8881015ac400 RCX: ffffffff826ffc45 RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8881035109c0 RBP: ffff8881035109c0 R08: ffff888101e3e838 R09: ffff888100264e10 R10: ffffc9000083f898 R11: ffffc9000083f8a0 R12: ffff888101b921a0 R13: ffff888101b921a0 R14: ffff8881015ac9a0 R15: ffff8881015ac400 FS:  00007f789a3c8740(0000) GS:ffff88856aa59000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000370 CR3: 000000010b6c0001 CR4: 0000000000370ef0 Call Trace:  <TASK>  mlx5e_remove+0x57/0x110  device_release_driver_internal+0x19c/0x200  bus_remove_device+0xc6/0x130  device_del+0x160/0x3d0  ? devl_param_driverinit_value_get+0x2d/0x90  mlx5_detach_device+0x89/0xe0  mlx5_unload_one_devl_locked+0x3a/0x70  mlx5_devlink_reload_down+0xc8/0x220  devlink_reload+0x7d/0x260  devlink_nl_reload_doit+0x45b/0x5a0  genl_family_rcv_msg_doit+0xe8/0x140","cvss":[],"epss":[{"cve":"CVE-2026-23035","epss":0.00217,"percentile":0.12079,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1085},"relatedVulnerabilities":[{"id":"CVE-2026-23035","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23035","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4ef8512e1427111f7ba92b4a847d181ff0aeec42","https://git.kernel.org/stable/c/66a25f6b7c0bfd84e6d27b536f5d24116dbd52da","https://git.kernel.org/stable/c/a7625bacaa8c8c2bfcde6dd6d1397bd63ad82b02"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv\n\nmlx5e_priv is an unstable structure that can be memset(0) if profile\nattaching fails.\n\nPass netdev to mlx5e_destroy_netdev() to guarantee it will work on a\nvalid netdev.\n\nOn mlx5e_remove: Check validity of priv->profile, before attempting\nto cleanup any resources that might be not there.\n\nThis fixes a kernel oops in mlx5e_remove when switchdev mode fails due\nto change profile failure.\n\n$ devlink dev eswitch set pci/0000:00:03.0 mode switchdev\nError: mlx5_core: Failed setting eswitch to offloads.\ndmesg:\nworkqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\nmlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12\nmlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: new profile init failed, -12\nworkqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\nmlx5_core 0012:03:00.1: mlx5e_netdev_init_profile:6214:(pid 37199): mlx5e_priv_init failed, err=-12\nmlx5_core 0012:03:00.1 gpu3rdma1: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12\n\n$ devlink dev reload pci/0000:00:03.0 ==> oops\n\nBUG: kernel NULL pointer dereference, address: 0000000000000370\nPGD 0 P4D 0\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 15 UID: 0 PID: 520 Comm: devlink Not tainted 6.18.0-rc5+ #115 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\nRIP: 0010:mlx5e_dcbnl_dscp_app+0x23/0x100\nRSP: 0018:ffffc9000083f8b8 EFLAGS: 00010286\nRAX: ffff8881126fc380 RBX: ffff8881015ac400 RCX: ffffffff826ffc45\nRDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8881035109c0\nRBP: ffff8881035109c0 R08: ffff888101e3e838 R09: ffff888100264e10\nR10: ffffc9000083f898 R11: ffffc9000083f8a0 R12: ffff888101b921a0\nR13: ffff888101b921a0 R14: ffff8881015ac9a0 R15: ffff8881015ac400\nFS:  00007f789a3c8740(0000) GS:ffff88856aa59000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000370 CR3: 000000010b6c0001 CR4: 0000000000370ef0\nCall Trace:\n <TASK>\n mlx5e_remove+0x57/0x110\n device_release_driver_internal+0x19c/0x200\n bus_remove_device+0xc6/0x130\n device_del+0x160/0x3d0\n ? devl_param_driverinit_value_get+0x2d/0x90\n mlx5_detach_device+0x89/0xe0\n mlx5_unload_one_devl_locked+0x3a/0x70\n mlx5_devlink_reload_down+0xc8/0x220\n devlink_reload+0x7d/0x260\n devlink_nl_reload_doit+0x45b/0x5a0\n genl_family_rcv_msg_doit+0xe8/0x140","cvss":[],"epss":[{"cve":"CVE-2026-23035","epss":0.00217,"percentile":0.12079,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23035","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23050","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23050","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pNFS: Fix a deadlock when returning a delegation during open()  Ben Coddington reports seeing a hang in the following stack trace:   0 [ffffd0b50e1774e0] __schedule at ffffffff9ca05415   1 [ffffd0b50e177548] schedule at ffffffff9ca05717   2 [ffffd0b50e177558] bit_wait at ffffffff9ca061e1   3 [ffffd0b50e177568] __wait_on_bit at ffffffff9ca05cfb   4 [ffffd0b50e1775c8] out_of_line_wait_on_bit at ffffffff9ca05ea5   5 [ffffd0b50e177618] pnfs_roc at ffffffffc154207b [nfsv4]   6 [ffffd0b50e1776b8] _nfs4_proc_delegreturn at ffffffffc1506586 [nfsv4]   7 [ffffd0b50e177788] nfs4_proc_delegreturn at ffffffffc1507480 [nfsv4]   8 [ffffd0b50e1777f8] nfs_do_return_delegation at ffffffffc1523e41 [nfsv4]   9 [ffffd0b50e177838] nfs_inode_set_delegation at ffffffffc1524a75 [nfsv4]  10 [ffffd0b50e177888] nfs4_process_delegation at ffffffffc14f41dd [nfsv4]  11 [ffffd0b50e1778a0] _nfs4_opendata_to_nfs4_state at ffffffffc1503edf [nfsv4]  12 [ffffd0b50e1778c0] _nfs4_open_and_get_state at ffffffffc1504e56 [nfsv4]  13 [ffffd0b50e177978] _nfs4_do_open at ffffffffc15051b8 [nfsv4]  14 [ffffd0b50e1779f8] nfs4_do_open at ffffffffc150559c [nfsv4]  15 [ffffd0b50e177a80] nfs4_atomic_open at ffffffffc15057fb [nfsv4]  16 [ffffd0b50e177ad0] nfs4_file_open at ffffffffc15219be [nfsv4]  17 [ffffd0b50e177b78] do_dentry_open at ffffffff9c09e6ea  18 [ffffd0b50e177ba8] vfs_open at ffffffff9c0a082e  19 [ffffd0b50e177bd0] dentry_open at ffffffff9c0a0935  The issue is that the delegreturn is being asked to wait for a layout return that cannot complete because a state recovery was initiated. The state recovery cannot complete until the open() finishes processing the delegations it was given.  The solution is to propagate the existing flags that indicate a non-blocking call to the function pnfs_roc(), so that it knows not to wait in this situation.","cvss":[],"epss":[{"cve":"CVE-2026-23050","epss":0.00174,"percentile":0.07053,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.087},"relatedVulnerabilities":[{"id":"CVE-2026-23050","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23050","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/857bf9056291a16785ae3be1d291026b2437fc48","https://git.kernel.org/stable/c/a316fd9d3065b753b03d802530004aea481512cc","https://git.kernel.org/stable/c/c57387d447a2bcbaea009ba5f9497adf3de5edeb","https://git.kernel.org/stable/c/d6c75aa9d607044d1e5c8498eff0259eed356c32"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npNFS: Fix a deadlock when returning a delegation during open()\n\nBen Coddington reports seeing a hang in the following stack trace:\n  0 [ffffd0b50e1774e0] __schedule at ffffffff9ca05415\n  1 [ffffd0b50e177548] schedule at ffffffff9ca05717\n  2 [ffffd0b50e177558] bit_wait at ffffffff9ca061e1\n  3 [ffffd0b50e177568] __wait_on_bit at ffffffff9ca05cfb\n  4 [ffffd0b50e1775c8] out_of_line_wait_on_bit at ffffffff9ca05ea5\n  5 [ffffd0b50e177618] pnfs_roc at ffffffffc154207b [nfsv4]\n  6 [ffffd0b50e1776b8] _nfs4_proc_delegreturn at ffffffffc1506586 [nfsv4]\n  7 [ffffd0b50e177788] nfs4_proc_delegreturn at ffffffffc1507480 [nfsv4]\n  8 [ffffd0b50e1777f8] nfs_do_return_delegation at ffffffffc1523e41 [nfsv4]\n  9 [ffffd0b50e177838] nfs_inode_set_delegation at ffffffffc1524a75 [nfsv4]\n 10 [ffffd0b50e177888] nfs4_process_delegation at ffffffffc14f41dd [nfsv4]\n 11 [ffffd0b50e1778a0] _nfs4_opendata_to_nfs4_state at ffffffffc1503edf [nfsv4]\n 12 [ffffd0b50e1778c0] _nfs4_open_and_get_state at ffffffffc1504e56 [nfsv4]\n 13 [ffffd0b50e177978] _nfs4_do_open at ffffffffc15051b8 [nfsv4]\n 14 [ffffd0b50e1779f8] nfs4_do_open at ffffffffc150559c [nfsv4]\n 15 [ffffd0b50e177a80] nfs4_atomic_open at ffffffffc15057fb [nfsv4]\n 16 [ffffd0b50e177ad0] nfs4_file_open at ffffffffc15219be [nfsv4]\n 17 [ffffd0b50e177b78] do_dentry_open at ffffffff9c09e6ea\n 18 [ffffd0b50e177ba8] vfs_open at ffffffff9c0a082e\n 19 [ffffd0b50e177bd0] dentry_open at ffffffff9c0a0935\n\nThe issue is that the delegreturn is being asked to wait for a layout\nreturn that cannot complete because a state recovery was initiated. The\nstate recovery cannot complete until the open() finishes processing the\ndelegations it was given.\n\nThe solution is to propagate the existing flags that indicate a\nnon-blocking call to the function pnfs_roc(), so that it knows not to\nwait in this situation.","cvss":[],"epss":[{"cve":"CVE-2026-23050","epss":0.00174,"percentile":0.07053,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23050","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23088","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23088","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing: Fix crash on synthetic stacktrace field usage  When creating a synthetic event based on an existing synthetic event that had a stacktrace field and the new synthetic event used that field a kernel crash occurred:   ~# cd /sys/kernel/tracing  ~# echo 's:stack unsigned long stack[];' > dynamic_events  ~# echo 'hist:keys=prev_pid:s0=common_stacktrace if prev_state & 3' >> events/sched/sched_switch/trigger  ~# echo 'hist:keys=next_pid:s1=$s0:onmatch(sched.sched_switch).trace(stack,$s1)' >> events/sched/sched_switch/trigger  The above creates a synthetic event that takes a stacktrace when a task schedules out in a non-running state and passes that stacktrace to the sched_switch event when that task schedules back in. It triggers the \"stack\" synthetic event that has a stacktrace as its field (called \"stack\").   ~# echo 's:syscall_stack s64 id; unsigned long stack[];' >> dynamic_events  ~# echo 'hist:keys=common_pid:s2=stack' >> events/synthetic/stack/trigger  ~# echo 'hist:keys=common_pid:s3=$s2,i0=id:onmatch(synthetic.stack).trace(syscall_stack,$i0,$s3)' >> events/raw_syscalls/sys_exit/trigger  The above makes another synthetic event called \"syscall_stack\" that attaches the first synthetic event (stack) to the sys_exit trace event and records the stacktrace from the stack event with the id of the system call that is exiting.  When enabling this event (or using it in a historgram):   ~# echo 1 > events/synthetic/syscall_stack/enable  Produces a kernel crash!   BUG: unable to handle page fault for address: 0000000000400010  #PF: supervisor read access in kernel mode  #PF: error_code(0x0000) - not-present page  PGD 0 P4D 0  Oops: Oops: 0000 [#1] SMP PTI  CPU: 6 UID: 0 PID: 1257 Comm: bash Not tainted 6.16.3+deb14-amd64 #1 PREEMPT(lazy)  Debian 6.16.3-1  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014  RIP: 0010:trace_event_raw_event_synth+0x90/0x380  Code: c5 00 00 00 00 85 d2 0f 84 e1 00 00 00 31 db eb 34 0f 1f 00 66 66 2e 0f 1f 84 00 00 00 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 <49> 8b 04 24 48 83 c3 01 8d 0c c5 08 00 00 00 01 cd 41 3b 5d 40 0f  RSP: 0018:ffffd2670388f958 EFLAGS: 00010202  RAX: ffff8ba1065cc100 RBX: 0000000000000000 RCX: 0000000000000000  RDX: 0000000000000001 RSI: fffff266ffda7b90 RDI: ffffd2670388f9b0  RBP: 0000000000000010 R08: ffff8ba104e76000 R09: ffffd2670388fa50  R10: ffff8ba102dd42e0 R11: ffffffff9a908970 R12: 0000000000400010  R13: ffff8ba10a246400 R14: ffff8ba10a710220 R15: fffff266ffda7b90  FS:  00007fa3bc63f740(0000) GS:ffff8ba2e0f48000(0000) knlGS:0000000000000000  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033  CR2: 0000000000400010 CR3: 0000000107f9e003 CR4: 0000000000172ef0  Call Trace:   <TASK>   ? __tracing_map_insert+0x208/0x3a0   action_trace+0x67/0x70   event_hist_trigger+0x633/0x6d0   event_triggers_call+0x82/0x130   trace_event_buffer_commit+0x19d/0x250   trace_event_raw_event_sys_exit+0x62/0xb0   syscall_exit_work+0x9d/0x140   do_syscall_64+0x20a/0x2f0   ? trace_event_raw_event_sched_switch+0x12b/0x170   ? save_fpregs_to_fpstate+0x3e/0x90   ? _raw_spin_unlock+0xe/0x30   ? finish_task_switch.isra.0+0x97/0x2c0   ? __rseq_handle_notify_resume+0xad/0x4c0   ? __schedule+0x4b8/0xd00   ? restore_fpregs_from_fpstate+0x3c/0x90   ? switch_fpu_return+0x5b/0xe0   ? do_syscall_64+0x1ef/0x2f0   ? do_fault+0x2e9/0x540   ? __handle_mm_fault+0x7d1/0xf70   ? count_memcg_events+0x167/0x1d0   ? handle_mm_fault+0x1d7/0x2e0   ? do_user_addr_fault+0x2c3/0x7f0   entry_SYSCALL_64_after_hwframe+0x76/0x7e  The reason is that the stacktrace field is not labeled as such, and is treated as a normal field and not as a dynamic event that it is.  In trace_event_raw_event_synth() the event is field is still treated as a dynamic array, but the retrieval of the data is considered a normal field, and the reference is just the meta data:  // Meta data is retrieved instead of a dynamic array ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23088","epss":0.00127,"percentile":0.02653,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23088","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2026-23088","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23088","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/327af07dff6ab5650b21491eb4f69694999ff3d1","https://git.kernel.org/stable/c/3b90d099efa2b67239bd3b3dc3521ec584261748","https://git.kernel.org/stable/c/90f9f5d64cae4e72defd96a2a22760173cb3c9ec","https://git.kernel.org/stable/c/98ecbfb2598c9c7ca755a29f402da9d36c057077"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix crash on synthetic stacktrace field usage\n\nWhen creating a synthetic event based on an existing synthetic event that\nhad a stacktrace field and the new synthetic event used that field a\nkernel crash occurred:\n\n ~# cd /sys/kernel/tracing\n ~# echo 's:stack unsigned long stack[];' > dynamic_events\n ~# echo 'hist:keys=prev_pid:s0=common_stacktrace if prev_state & 3' >> events/sched/sched_switch/trigger\n ~# echo 'hist:keys=next_pid:s1=$s0:onmatch(sched.sched_switch).trace(stack,$s1)' >> events/sched/sched_switch/trigger\n\nThe above creates a synthetic event that takes a stacktrace when a task\nschedules out in a non-running state and passes that stacktrace to the\nsched_switch event when that task schedules back in. It triggers the\n\"stack\" synthetic event that has a stacktrace as its field (called \"stack\").\n\n ~# echo 's:syscall_stack s64 id; unsigned long stack[];' >> dynamic_events\n ~# echo 'hist:keys=common_pid:s2=stack' >> events/synthetic/stack/trigger\n ~# echo 'hist:keys=common_pid:s3=$s2,i0=id:onmatch(synthetic.stack).trace(syscall_stack,$i0,$s3)' >> events/raw_syscalls/sys_exit/trigger\n\nThe above makes another synthetic event called \"syscall_stack\" that\nattaches the first synthetic event (stack) to the sys_exit trace event and\nrecords the stacktrace from the stack event with the id of the system call\nthat is exiting.\n\nWhen enabling this event (or using it in a historgram):\n\n ~# echo 1 > events/synthetic/syscall_stack/enable\n\nProduces a kernel crash!\n\n BUG: unable to handle page fault for address: 0000000000400010\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 [#1] SMP PTI\n CPU: 6 UID: 0 PID: 1257 Comm: bash Not tainted 6.16.3+deb14-amd64 #1 PREEMPT(lazy)  Debian 6.16.3-1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n RIP: 0010:trace_event_raw_event_synth+0x90/0x380\n Code: c5 00 00 00 00 85 d2 0f 84 e1 00 00 00 31 db eb 34 0f 1f 00 66 66 2e 0f 1f 84 00 00 00 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 <49> 8b 04 24 48 83 c3 01 8d 0c c5 08 00 00 00 01 cd 41 3b 5d 40 0f\n RSP: 0018:ffffd2670388f958 EFLAGS: 00010202\n RAX: ffff8ba1065cc100 RBX: 0000000000000000 RCX: 0000000000000000\n RDX: 0000000000000001 RSI: fffff266ffda7b90 RDI: ffffd2670388f9b0\n RBP: 0000000000000010 R08: ffff8ba104e76000 R09: ffffd2670388fa50\n R10: ffff8ba102dd42e0 R11: ffffffff9a908970 R12: 0000000000400010\n R13: ffff8ba10a246400 R14: ffff8ba10a710220 R15: fffff266ffda7b90\n FS:  00007fa3bc63f740(0000) GS:ffff8ba2e0f48000(0000) knlGS:0000000000000000\n CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000400010 CR3: 0000000107f9e003 CR4: 0000000000172ef0\n Call Trace:\n  <TASK>\n  ? __tracing_map_insert+0x208/0x3a0\n  action_trace+0x67/0x70\n  event_hist_trigger+0x633/0x6d0\n  event_triggers_call+0x82/0x130\n  trace_event_buffer_commit+0x19d/0x250\n  trace_event_raw_event_sys_exit+0x62/0xb0\n  syscall_exit_work+0x9d/0x140\n  do_syscall_64+0x20a/0x2f0\n  ? trace_event_raw_event_sched_switch+0x12b/0x170\n  ? save_fpregs_to_fpstate+0x3e/0x90\n  ? _raw_spin_unlock+0xe/0x30\n  ? finish_task_switch.isra.0+0x97/0x2c0\n  ? __rseq_handle_notify_resume+0xad/0x4c0\n  ? __schedule+0x4b8/0xd00\n  ? restore_fpregs_from_fpstate+0x3c/0x90\n  ? switch_fpu_return+0x5b/0xe0\n  ? do_syscall_64+0x1ef/0x2f0\n  ? do_fault+0x2e9/0x540\n  ? __handle_mm_fault+0x7d1/0xf70\n  ? count_memcg_events+0x167/0x1d0\n  ? handle_mm_fault+0x1d7/0x2e0\n  ? do_user_addr_fault+0x2c3/0x7f0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe reason is that the stacktrace field is not labeled as such, and is\ntreated as a normal field and not as a dynamic event that it is.\n\nIn trace_event_raw_event_synth() the event is field is still treated as a\ndynamic array, but the retrieval of the data is considered a normal field,\nand the reference is just the meta data:\n\n// Meta data is retrieved instead of a dynamic array\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23088","epss":0.00127,"percentile":0.02653,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23088","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23088","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23118","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23118","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix data-race warning and potential load/store tearing  Fix the following:          BUG: KCSAN: data-race in rxrpc_peer_keepalive_worker / rxrpc_send_data_packet  which is reporting an issue with the reads and writes to ->last_tx_at in:          conn->peer->last_tx_at = ktime_get_seconds();  and:          keepalive_at = peer->last_tx_at + RXRPC_KEEPALIVE_TIME;  The lockless accesses to these to values aren't actually a problem as the read only needs an approximate time of last transmission for the purposes of deciding whether or not the transmission of a keepalive packet is warranted yet.  Also, as ->last_tx_at is a 64-bit value, tearing can occur on a 32-bit arch.  Fix both of these by switching to an unsigned int for ->last_tx_at and only storing the LSW of the time64_t.  It can then be reconstructed at need provided no more than 68 years has elapsed since the last transmission.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23118","epss":0.00086,"percentile":0.0035,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23118","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04171},"relatedVulnerabilities":[{"id":"CVE-2026-23118","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23118","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5d5fe8bcd331f1e34e0943ec7c18432edfcf0e8b","https://git.kernel.org/stable/c/a426f29ac3fa3465093567ab763ada46762fb57c","https://git.kernel.org/stable/c/c08cf314191cd0f8699089715efb9eff030f0086","https://git.kernel.org/stable/c/f8cf1368e0a5491b27189a695c36f64e48f3d19d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix data-race warning and potential load/store tearing\n\nFix the following:\n\n        BUG: KCSAN: data-race in rxrpc_peer_keepalive_worker / rxrpc_send_data_packet\n\nwhich is reporting an issue with the reads and writes to ->last_tx_at in:\n\n        conn->peer->last_tx_at = ktime_get_seconds();\n\nand:\n\n        keepalive_at = peer->last_tx_at + RXRPC_KEEPALIVE_TIME;\n\nThe lockless accesses to these to values aren't actually a problem as the\nread only needs an approximate time of last transmission for the purposes\nof deciding whether or not the transmission of a keepalive packet is\nwarranted yet.\n\nAlso, as ->last_tx_at is a 64-bit value, tearing can occur on a 32-bit\narch.\n\nFix both of these by switching to an unsigned int for ->last_tx_at and only\nstoring the LSW of the time64_t.  It can then be reconstructed at need\nprovided no more than 68 years has elapsed since the last transmission.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23118","epss":0.00086,"percentile":0.0035,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23118","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23118","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23137","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23137","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  of: unittest: Fix memory leak in unittest_data_add()  In unittest_data_add(), if of_resolve_phandles() fails, the allocated unittest_data is not freed, leading to a memory leak.  Fix this by using scope-based cleanup helper __free(kfree) for automatic resource cleanup. This ensures unittest_data is automatically freed when it goes out of scope in error paths.  For the success path, use retain_and_null_ptr() to transfer ownership of the memory to the device tree and prevent double freeing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23137","epss":0.00107,"percentile":0.01275,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23137","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-23137","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23137","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/235a1eb8d2dcc49a6cf0a5ee1aa85544a5d0054b","https://git.kernel.org/stable/c/f09b0f705bd7197863b90256ef533a6414d1db2c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nof: unittest: Fix memory leak in unittest_data_add()\n\nIn unittest_data_add(), if of_resolve_phandles() fails, the allocated\nunittest_data is not freed, leading to a memory leak.\n\nFix this by using scope-based cleanup helper __free(kfree) for automatic\nresource cleanup. This ensures unittest_data is automatically freed when\nit goes out of scope in error paths.\n\nFor the success path, use retain_and_null_ptr() to transfer ownership\nof the memory to the device tree and prevent double freeing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23137","epss":0.00107,"percentile":0.01275,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23137","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23137","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23138","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23138","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing: Add recursion protection in kernel stack trace recording  A bug was reported about an infinite recursion caused by tracing the rcu events with the kernel stack trace trigger enabled. The stack trace code called back into RCU which then called the stack trace again.  Expand the ftrace recursion protection to add a set of bits to protect events from recursion. Each bit represents the context that the event is in (normal, softirq, interrupt and NMI).  Have the stack trace code use the interrupt context to protect against recursion.  Note, the bug showed an issue in both the RCU code as well as the tracing stacktrace code. This only handles the tracing stack trace side of the bug. The RCU fix will be handled separately.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23138","epss":0.00122,"percentile":0.02266,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-23138","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23138","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/19e18e6dabb1bbba76d2809ca7d8ae9e1f5975fe","https://git.kernel.org/stable/c/5b7f91acffd2c4c000971553d22efa1e1bb4feae","https://git.kernel.org/stable/c/5f1ef0dfcb5b7f4a91a9b0e0ba533efd9f7e2cdb","https://git.kernel.org/stable/c/9b03768037d91ce727effb1c5d92d2c7781bf692"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Add recursion protection in kernel stack trace recording\n\nA bug was reported about an infinite recursion caused by tracing the rcu\nevents with the kernel stack trace trigger enabled. The stack trace code\ncalled back into RCU which then called the stack trace again.\n\nExpand the ftrace recursion protection to add a set of bits to protect\nevents from recursion. Each bit represents the context that the event is\nin (normal, softirq, interrupt and NMI).\n\nHave the stack trace code use the interrupt context to protect against\nrecursion.\n\nNote, the bug showed an issue in both the RCU code as well as the tracing\nstacktrace code. This only handles the tracing stack trace side of the\nbug. The RCU fix will be handled separately.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23138","epss":0.00122,"percentile":0.02266,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23138","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23171","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23171","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bonding: fix use-after-free due to enslave fail after slave array update  Fix a use-after-free which happens due to enslave failure after the new slave has been added to the array. Since the new slave can be used for Tx immediately, we can use it after it has been freed by the enslave error cleanup path which frees the allocated slave memory. Slave update array is supposed to be called last when further enslave failures are not expected. Move it after xdp setup to avoid any problems.  It is very easy to reproduce the problem with a simple xdp_pass prog:  ip l add bond1 type bond mode balance-xor  ip l set bond1 up  ip l set dev bond1 xdp object xdp_pass.o sec xdp_pass  ip l add dumdum type dummy  Then run in parallel:  while :; do ip l set dumdum master bond1 1>/dev/null 2>&1; done;  mausezahn bond1 -a own -b rand -A rand -B 1.1.1.1 -c 0 -t tcp \"dp=1-1023, flags=syn\"  The crash happens almost immediately:  [  605.602850] Oops: general protection fault, probably for non-canonical address 0xe0e6fc2460000137: 0000 [#1] SMP KASAN NOPTI  [  605.602916] KASAN: maybe wild-memory-access in range [0x07380123000009b8-0x07380123000009bf]  [  605.602946] CPU: 0 UID: 0 PID: 2445 Comm: mausezahn Kdump: loaded Tainted: G    B               6.19.0-rc6+ #21 PREEMPT(voluntary)  [  605.602979] Tainted: [B]=BAD_PAGE  [  605.602998] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014  [  605.603032] RIP: 0010:netdev_core_pick_tx+0xcd/0x210  [  605.603063] Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 3e 01 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b 6b 08 49 8d 7d 30 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 25 01 00 00 49 8b 45 30 4c 89 e2 48 89 ee 48 89  [  605.603111] RSP: 0018:ffff88817b9af348 EFLAGS: 00010213  [  605.603145] RAX: dffffc0000000000 RBX: ffff88817d28b420 RCX: 0000000000000000  [  605.603172] RDX: 00e7002460000137 RSI: 0000000000000008 RDI: 07380123000009be  [  605.603199] RBP: ffff88817b541a00 R08: 0000000000000001 R09: fffffbfff3ed8c0c  [  605.603226] R10: ffffffff9f6c6067 R11: 0000000000000001 R12: 0000000000000000  [  605.603253] R13: 073801230000098e R14: ffff88817d28b448 R15: ffff88817b541a84  [  605.603286] FS:  00007f6570ef67c0(0000) GS:ffff888221dfa000(0000) knlGS:0000000000000000  [  605.603319] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033  [  605.603343] CR2: 00007f65712fae40 CR3: 000000011371b000 CR4: 0000000000350ef0  [  605.603373] Call Trace:  [  605.603392]  <TASK>  [  605.603410]  __dev_queue_xmit+0x448/0x32a0  [  605.603434]  ? __pfx_vprintk_emit+0x10/0x10  [  605.603461]  ? __pfx_vprintk_emit+0x10/0x10  [  605.603484]  ? __pfx___dev_queue_xmit+0x10/0x10  [  605.603507]  ? bond_start_xmit+0xbfb/0xc20 [bonding]  [  605.603546]  ? _printk+0xcb/0x100  [  605.603566]  ? __pfx__printk+0x10/0x10  [  605.603589]  ? bond_start_xmit+0xbfb/0xc20 [bonding]  [  605.603627]  ? add_taint+0x5e/0x70  [  605.603648]  ? add_taint+0x2a/0x70  [  605.603670]  ? end_report.cold+0x51/0x75  [  605.603693]  ? bond_start_xmit+0xbfb/0xc20 [bonding]  [  605.603731]  bond_start_xmit+0x623/0xc20 [bonding]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23171","epss":0.00117,"percentile":0.01863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23171","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-23171","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23171","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/172dcb67dd35b162357df229d7806acc724cd469","https://git.kernel.org/stable/c/2889d92c5f728351c9930c7996d22fe6e906e785","https://git.kernel.org/stable/c/bd25b092a06a3e05f7e8bd6da6fa7318777d8c3d","https://git.kernel.org/stable/c/e9acda52fd2ee0cdca332f996da7a95c5fd25294"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix use-after-free due to enslave fail after slave array update\n\nFix a use-after-free which happens due to enslave failure after the new\nslave has been added to the array. Since the new slave can be used for Tx\nimmediately, we can use it after it has been freed by the enslave error\ncleanup path which frees the allocated slave memory. Slave update array is\nsupposed to be called last when further enslave failures are not expected.\nMove it after xdp setup to avoid any problems.\n\nIt is very easy to reproduce the problem with a simple xdp_pass prog:\n ip l add bond1 type bond mode balance-xor\n ip l set bond1 up\n ip l set dev bond1 xdp object xdp_pass.o sec xdp_pass\n ip l add dumdum type dummy\n\nThen run in parallel:\n while :; do ip l set dumdum master bond1 1>/dev/null 2>&1; done;\n mausezahn bond1 -a own -b rand -A rand -B 1.1.1.1 -c 0 -t tcp \"dp=1-1023, flags=syn\"\n\nThe crash happens almost immediately:\n [  605.602850] Oops: general protection fault, probably for non-canonical address 0xe0e6fc2460000137: 0000 [#1] SMP KASAN NOPTI\n [  605.602916] KASAN: maybe wild-memory-access in range [0x07380123000009b8-0x07380123000009bf]\n [  605.602946] CPU: 0 UID: 0 PID: 2445 Comm: mausezahn Kdump: loaded Tainted: G    B               6.19.0-rc6+ #21 PREEMPT(voluntary)\n [  605.602979] Tainted: [B]=BAD_PAGE\n [  605.602998] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n [  605.603032] RIP: 0010:netdev_core_pick_tx+0xcd/0x210\n [  605.603063] Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 3e 01 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b 6b 08 49 8d 7d 30 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 25 01 00 00 49 8b 45 30 4c 89 e2 48 89 ee 48 89\n [  605.603111] RSP: 0018:ffff88817b9af348 EFLAGS: 00010213\n [  605.603145] RAX: dffffc0000000000 RBX: ffff88817d28b420 RCX: 0000000000000000\n [  605.603172] RDX: 00e7002460000137 RSI: 0000000000000008 RDI: 07380123000009be\n [  605.603199] RBP: ffff88817b541a00 R08: 0000000000000001 R09: fffffbfff3ed8c0c\n [  605.603226] R10: ffffffff9f6c6067 R11: 0000000000000001 R12: 0000000000000000\n [  605.603253] R13: 073801230000098e R14: ffff88817d28b448 R15: ffff88817b541a84\n [  605.603286] FS:  00007f6570ef67c0(0000) GS:ffff888221dfa000(0000) knlGS:0000000000000000\n [  605.603319] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n [  605.603343] CR2: 00007f65712fae40 CR3: 000000011371b000 CR4: 0000000000350ef0\n [  605.603373] Call Trace:\n [  605.603392]  <TASK>\n [  605.603410]  __dev_queue_xmit+0x448/0x32a0\n [  605.603434]  ? __pfx_vprintk_emit+0x10/0x10\n [  605.603461]  ? __pfx_vprintk_emit+0x10/0x10\n [  605.603484]  ? __pfx___dev_queue_xmit+0x10/0x10\n [  605.603507]  ? bond_start_xmit+0xbfb/0xc20 [bonding]\n [  605.603546]  ? _printk+0xcb/0x100\n [  605.603566]  ? __pfx__printk+0x10/0x10\n [  605.603589]  ? bond_start_xmit+0xbfb/0xc20 [bonding]\n [  605.603627]  ? add_taint+0x5e/0x70\n [  605.603648]  ? add_taint+0x2a/0x70\n [  605.603670]  ? end_report.cold+0x51/0x75\n [  605.603693]  ? bond_start_xmit+0xbfb/0xc20 [bonding]\n [  605.603731]  bond_start_xmit+0x623/0xc20 [bonding]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23171","epss":0.00117,"percentile":0.01863,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23171","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23171","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23191","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23191","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: aloop: Fix racy access at PCM trigger  The PCM trigger callback of aloop driver tries to check the PCM state and stop the stream of the tied substream in the corresponding cable. Since both check and stop operations are performed outside the cable lock, this may result in UAF when a program attempts to trigger frequently while opening/closing the tied stream, as spotted by fuzzers.  For addressing the UAF, this patch changes two things: - It covers the most of code in loopback_check_format() with   cable->lock spinlock, and add the proper NULL checks.  This avoids   already some racy accesses. - In addition, now we try to check the state of the capture PCM stream   that may be stopped in this function, which was the major pain point   leading to UAF.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23191","epss":0.00113,"percentile":0.01602,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23191","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08192499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-23191","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23191","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5727ccf9d19ca414cb76d9b647883822e2789c2e","https://git.kernel.org/stable/c/826af7fa62e347464b1b4e0ba2fe19a92438084f","https://git.kernel.org/stable/c/bad15420050db1803767e58756114800cce91ea4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Fix racy access at PCM trigger\n\nThe PCM trigger callback of aloop driver tries to check the PCM state\nand stop the stream of the tied substream in the corresponding cable.\nSince both check and stop operations are performed outside the cable\nlock, this may result in UAF when a program attempts to trigger\nfrequently while opening/closing the tied stream, as spotted by\nfuzzers.\n\nFor addressing the UAF, this patch changes two things:\n- It covers the most of code in loopback_check_format() with\n  cable->lock spinlock, and add the proper NULL checks.  This avoids\n  already some racy accesses.\n- In addition, now we try to check the state of the capture PCM stream\n  that may be stopped in this function, which was the major pain point\n  leading to UAF.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23191","epss":0.00113,"percentile":0.01602,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23191","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23191","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23207","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23207","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: tegra210-quad: Protect curr_xfer check in IRQ handler  Now that all other accesses to curr_xfer are done under the lock, protect the curr_xfer NULL check in tegra_qspi_isr_thread() with the spinlock. Without this protection, the following race can occur:    CPU0 (ISR thread)              CPU1 (timeout path)   ----------------               -------------------   if (!tqspi->curr_xfer)     // sees non-NULL                                  spin_lock()                                  tqspi->curr_xfer = NULL                                  spin_unlock()   handle_*_xfer()     spin_lock()     t = tqspi->curr_xfer  // NULL!     ... t->len ...        // NULL dereference!  With this patch, all curr_xfer accesses are now properly synchronized.  Although all accesses to curr_xfer are done under the lock, in tegra_qspi_isr_thread() it checks for NULL, releases the lock and reacquires it later in handle_cpu_based_xfer()/handle_dma_based_xfer(). There is a potential for an update in between, which could cause a NULL pointer dereference.  To handle this, add a NULL check inside the handlers after acquiring the lock. This ensures that if the timeout path has already cleared curr_xfer, the handler will safely return without dereferencing the NULL pointer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23207","epss":0.00088,"percentile":0.00418,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23207","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-23207","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04268},"relatedVulnerabilities":[{"id":"CVE-2026-23207","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23207","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2ac3a105e51496147c0e44e49466eecfcc532d57","https://git.kernel.org/stable/c/84e926c1c272a35ddb9b86842d32fa833a60dfc7","https://git.kernel.org/stable/c/edf9088b6e1d6d88982db7eb5e736a0e4fbcc09e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: tegra210-quad: Protect curr_xfer check in IRQ handler\n\nNow that all other accesses to curr_xfer are done under the lock,\nprotect the curr_xfer NULL check in tegra_qspi_isr_thread() with the\nspinlock. Without this protection, the following race can occur:\n\n  CPU0 (ISR thread)              CPU1 (timeout path)\n  ----------------               -------------------\n  if (!tqspi->curr_xfer)\n    // sees non-NULL\n                                 spin_lock()\n                                 tqspi->curr_xfer = NULL\n                                 spin_unlock()\n  handle_*_xfer()\n    spin_lock()\n    t = tqspi->curr_xfer  // NULL!\n    ... t->len ...        // NULL dereference!\n\nWith this patch, all curr_xfer accesses are now properly synchronized.\n\nAlthough all accesses to curr_xfer are done under the lock, in\ntegra_qspi_isr_thread() it checks for NULL, releases the lock and\nreacquires it later in handle_cpu_based_xfer()/handle_dma_based_xfer().\nThere is a potential for an update in between, which could cause a NULL\npointer dereference.\n\nTo handle this, add a NULL check inside the handlers after acquiring\nthe lock. This ensures that if the timeout path has already cleared\ncurr_xfer, the handler will safely return without dereferencing the\nNULL pointer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23207","epss":0.00088,"percentile":0.00418,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23207","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-23207","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23207","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23208","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23208","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: Prevent excessive number of frames  In this case, the user constructed the parameters with maxpacksize 40 for rate 22050 / pps 1000, and packsize[0] 22 packsize[1] 23. The buffer size for each data URB is maxpacksize * packets, which in this example is 40 * 6 = 240; When the user performs a write operation to send audio data into the ALSA PCM playback stream, the calculated number of frames is packsize[0] * packets = 264, which exceeds the allocated URB buffer size, triggering the out-of-bounds (OOB) issue reported by syzbot [1].  Added a check for the number of single data URB frames when calculating the number of frames to prevent [1].  [1] BUG: KASAN: slab-out-of-bounds in copy_to_urb+0x261/0x460 sound/usb/pcm.c:1487 Write of size 264 at addr ffff88804337e800 by task syz.0.17/5506 Call Trace:  copy_to_urb+0x261/0x460 sound/usb/pcm.c:1487  prepare_playback_urb+0x953/0x13d0 sound/usb/pcm.c:1611  prepare_outbound_urb+0x377/0xc50 sound/usb/endpoint.c:333","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23208","epss":0.00121,"percentile":0.02163,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23208","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.092565},"relatedVulnerabilities":[{"id":"CVE-2026-23208","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23208","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/282aba56713bbc58155716b55ca7222b2d9cf3c8","https://git.kernel.org/stable/c/480a1490c595a242f27493a4544b3efb21b29f6a","https://git.kernel.org/stable/c/62932d9ed639a9fa71b4ac1a56766a4b43abb7e4","https://git.kernel.org/stable/c/ab0b5e92fc36ee82c1bd01fe896d0f775ed5de41","https://git.kernel.org/stable/c/c4dc012b027c9eb101583011089dea14d744e314","https://git.kernel.org/stable/c/d67dde02049e632ba58d3c44a164a74b6a737154","https://git.kernel.org/stable/c/e0ed5a36fb3ab9e7b9ee45cd17f09f6d5f594360","https://git.kernel.org/stable/c/ef5749ef8b307bf8717945701b1b79d036af0a15"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Prevent excessive number of frames\n\nIn this case, the user constructed the parameters with maxpacksize 40\nfor rate 22050 / pps 1000, and packsize[0] 22 packsize[1] 23. The buffer\nsize for each data URB is maxpacksize * packets, which in this example\nis 40 * 6 = 240; When the user performs a write operation to send audio\ndata into the ALSA PCM playback stream, the calculated number of frames\nis packsize[0] * packets = 264, which exceeds the allocated URB buffer\nsize, triggering the out-of-bounds (OOB) issue reported by syzbot [1].\n\nAdded a check for the number of single data URB frames when calculating\nthe number of frames to prevent [1].\n\n[1]\nBUG: KASAN: slab-out-of-bounds in copy_to_urb+0x261/0x460 sound/usb/pcm.c:1487\nWrite of size 264 at addr ffff88804337e800 by task syz.0.17/5506\nCall Trace:\n copy_to_urb+0x261/0x460 sound/usb/pcm.c:1487\n prepare_playback_urb+0x953/0x13d0 sound/usb/pcm.c:1611\n prepare_outbound_urb+0x377/0xc50 sound/usb/endpoint.c:333","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23208","epss":0.00121,"percentile":0.02163,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23208","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23208","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23213","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23213","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/pm: Disable MMIO access during SMU Mode 1 reset  During Mode 1 reset, the ASIC undergoes a reset cycle and becomes temporarily inaccessible via PCIe. Any attempt to access MMIO registers during this window (e.g., from interrupt handlers or other driver threads) can result in uncompleted PCIe transactions, leading to NMI panics or system hangs.  To prevent this, set the `no_hw_access` flag to true immediately after triggering the reset. This signals other driver components to skip register accesses while the device is offline.  A memory barrier `smp_mb()` is added to ensure the flag update is globally visible to all cores before the driver enters the sleep/wait state.  (cherry picked from commit 7edb503fe4b6d67f47d8bb0dfafb8e699bb0f8a4)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23213","epss":0.00113,"percentile":0.01575,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059325},"relatedVulnerabilities":[{"id":"CVE-2026-23213","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23213","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0de604d0357d0d22cbf03af1077d174b641707b6","https://git.kernel.org/stable/c/c1853ebbec980d5c05d431bfd6ded73b1363fd00","https://git.kernel.org/stable/c/cd7ff7fd3e4b77f0b5a292e0926532eaa07c5162"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Disable MMIO access during SMU Mode 1 reset\n\nDuring Mode 1 reset, the ASIC undergoes a reset cycle and becomes\ntemporarily inaccessible via PCIe. Any attempt to access MMIO registers\nduring this window (e.g., from interrupt handlers or other driver threads)\ncan result in uncompleted PCIe transactions, leading to NMI panics or\nsystem hangs.\n\nTo prevent this, set the `no_hw_access` flag to true immediately after\ntriggering the reset. This signals other driver components to skip\nregister accesses while the device is offline.\n\nA memory barrier `smp_mb()` is added to ensure the flag update is\nglobally visible to all cores before the driver enters the sleep/wait\nstate.\n\n(cherry picked from commit 7edb503fe4b6d67f47d8bb0dfafb8e699bb0f8a4)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23213","epss":0.00113,"percentile":0.01575,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23213","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23214","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23214","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: reject new transactions if the fs is fully read-only  [BUG] There is a bug report where a heavily fuzzed fs is mounted with all rescue mount options, which leads to the following warnings during unmount:    BTRFS: Transaction aborted (error -22)   Modules linked in:   CPU: 0 UID: 0 PID: 9758 Comm: repro.out Not tainted   6.19.0-rc5-00002-gb71e635feefc #7 PREEMPT(full)   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014   RIP: 0010:find_free_extent_update_loop fs/btrfs/extent-tree.c:4208 [inline]   RIP: 0010:find_free_extent+0x52f0/0x5d20 fs/btrfs/extent-tree.c:4611   Call Trace:    <TASK>    btrfs_reserve_extent+0x2cd/0x790 fs/btrfs/extent-tree.c:4705    btrfs_alloc_tree_block+0x1e1/0x10e0 fs/btrfs/extent-tree.c:5157    btrfs_force_cow_block+0x578/0x2410 fs/btrfs/ctree.c:517    btrfs_cow_block+0x3c4/0xa80 fs/btrfs/ctree.c:708    btrfs_search_slot+0xcad/0x2b50 fs/btrfs/ctree.c:2130    btrfs_truncate_inode_items+0x45d/0x2350 fs/btrfs/inode-item.c:499    btrfs_evict_inode+0x923/0xe70 fs/btrfs/inode.c:5628    evict+0x5f4/0xae0 fs/inode.c:837    __dentry_kill+0x209/0x660 fs/dcache.c:670    finish_dput+0xc9/0x480 fs/dcache.c:879    shrink_dcache_for_umount+0xa0/0x170 fs/dcache.c:1661    generic_shutdown_super+0x67/0x2c0 fs/super.c:621    kill_anon_super+0x3b/0x70 fs/super.c:1289    btrfs_kill_super+0x41/0x50 fs/btrfs/super.c:2127    deactivate_locked_super+0xbc/0x130 fs/super.c:474    cleanup_mnt+0x425/0x4c0 fs/namespace.c:1318    task_work_run+0x1d4/0x260 kernel/task_work.c:233    exit_task_work include/linux/task_work.h:40 [inline]    do_exit+0x694/0x22f0 kernel/exit.c:971    do_group_exit+0x21c/0x2d0 kernel/exit.c:1112    __do_sys_exit_group kernel/exit.c:1123 [inline]    __se_sys_exit_group kernel/exit.c:1121 [inline]    __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1121    x64_sys_call+0x2210/0x2210 arch/x86/include/generated/asm/syscalls_64.h:232    do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]    do_syscall_64+0xe8/0xf80 arch/x86/entry/syscall_64.c:94    entry_SYSCALL_64_after_hwframe+0x77/0x7f   RIP: 0033:0x44f639   Code: Unable to access opcode bytes at 0x44f60f.   RSP: 002b:00007ffc15c4e088 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7   RAX: ffffffffffffffda RBX: 00000000004c32f0 RCX: 000000000044f639   RDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000001   RBP: 0000000000000001 R08: ffffffffffffffc0 R09: 0000000000000000   R10: 0000000000000000 R11: 0000000000000246 R12: 00000000004c32f0   R13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000001    </TASK>  Since rescue mount options will mark the full fs read-only, there should be no new transaction triggered.  But during unmount we will evict all inodes, which can trigger a new transaction, and triggers warnings on a heavily corrupted fs.  [CAUSE] Btrfs allows new transaction even on a read-only fs, this is to allow log replay happen even on read-only mounts, just like what ext4/xfs do.  However with rescue mount options, the fs is fully read-only and cannot be remounted read-write, thus in that case we should also reject any new transactions.  [FIX] If we find the fs has rescue mount options, we should treat the fs as error, so that no new transaction can be started.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23214","epss":0.00112,"percentile":0.01544,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-23214","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23214","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1972f44c189c8aacde308fa9284e474c1a5cbd9f","https://git.kernel.org/stable/c/3228b2eceb6c3d7e237f8a5330113dbd164fb90d","https://git.kernel.org/stable/c/a928eecf030a9a5dc5f5ca98332699f379b91963"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject new transactions if the fs is fully read-only\n\n[BUG]\nThere is a bug report where a heavily fuzzed fs is mounted with all\nrescue mount options, which leads to the following warnings during\nunmount:\n\n  BTRFS: Transaction aborted (error -22)\n  Modules linked in:\n  CPU: 0 UID: 0 PID: 9758 Comm: repro.out Not tainted\n  6.19.0-rc5-00002-gb71e635feefc #7 PREEMPT(full)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n  RIP: 0010:find_free_extent_update_loop fs/btrfs/extent-tree.c:4208 [inline]\n  RIP: 0010:find_free_extent+0x52f0/0x5d20 fs/btrfs/extent-tree.c:4611\n  Call Trace:\n   <TASK>\n   btrfs_reserve_extent+0x2cd/0x790 fs/btrfs/extent-tree.c:4705\n   btrfs_alloc_tree_block+0x1e1/0x10e0 fs/btrfs/extent-tree.c:5157\n   btrfs_force_cow_block+0x578/0x2410 fs/btrfs/ctree.c:517\n   btrfs_cow_block+0x3c4/0xa80 fs/btrfs/ctree.c:708\n   btrfs_search_slot+0xcad/0x2b50 fs/btrfs/ctree.c:2130\n   btrfs_truncate_inode_items+0x45d/0x2350 fs/btrfs/inode-item.c:499\n   btrfs_evict_inode+0x923/0xe70 fs/btrfs/inode.c:5628\n   evict+0x5f4/0xae0 fs/inode.c:837\n   __dentry_kill+0x209/0x660 fs/dcache.c:670\n   finish_dput+0xc9/0x480 fs/dcache.c:879\n   shrink_dcache_for_umount+0xa0/0x170 fs/dcache.c:1661\n   generic_shutdown_super+0x67/0x2c0 fs/super.c:621\n   kill_anon_super+0x3b/0x70 fs/super.c:1289\n   btrfs_kill_super+0x41/0x50 fs/btrfs/super.c:2127\n   deactivate_locked_super+0xbc/0x130 fs/super.c:474\n   cleanup_mnt+0x425/0x4c0 fs/namespace.c:1318\n   task_work_run+0x1d4/0x260 kernel/task_work.c:233\n   exit_task_work include/linux/task_work.h:40 [inline]\n   do_exit+0x694/0x22f0 kernel/exit.c:971\n   do_group_exit+0x21c/0x2d0 kernel/exit.c:1112\n   __do_sys_exit_group kernel/exit.c:1123 [inline]\n   __se_sys_exit_group kernel/exit.c:1121 [inline]\n   __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1121\n   x64_sys_call+0x2210/0x2210 arch/x86/include/generated/asm/syscalls_64.h:232\n   do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n   do_syscall_64+0xe8/0xf80 arch/x86/entry/syscall_64.c:94\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  RIP: 0033:0x44f639\n  Code: Unable to access opcode bytes at 0x44f60f.\n  RSP: 002b:00007ffc15c4e088 EFLAGS: 00000246 ORIG_RAX: 00000000000000e7\n  RAX: ffffffffffffffda RBX: 00000000004c32f0 RCX: 000000000044f639\n  RDX: 000000000000003c RSI: 00000000000000e7 RDI: 0000000000000001\n  RBP: 0000000000000001 R08: ffffffffffffffc0 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000246 R12: 00000000004c32f0\n  R13: 0000000000000001 R14: 0000000000000000 R15: 0000000000000001\n   </TASK>\n\nSince rescue mount options will mark the full fs read-only, there should\nbe no new transaction triggered.\n\nBut during unmount we will evict all inodes, which can trigger a new\ntransaction, and triggers warnings on a heavily corrupted fs.\n\n[CAUSE]\nBtrfs allows new transaction even on a read-only fs, this is to allow\nlog replay happen even on read-only mounts, just like what ext4/xfs do.\n\nHowever with rescue mount options, the fs is fully read-only and cannot\nbe remounted read-write, thus in that case we should also reject any new\ntransactions.\n\n[FIX]\nIf we find the fs has rescue mount options, we should treat the fs as\nerror, so that no new transaction can be started.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23214","epss":0.00112,"percentile":0.01544,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23214","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23226","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23226","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: add chann_lock to protect ksmbd_chann_list xarray  ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del).  Adds rw_semaphore chann_lock to struct ksmbd_session and protects all xa_load/xa_store/xa_erase accesses.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23226","epss":0.00423,"percentile":0.35682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23226","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.323595},"relatedVulnerabilities":[{"id":"CVE-2026-23226","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23226","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/36ef605c0395b94b826a8c8d6f2697071173de6e","https://git.kernel.org/stable/c/4c2ca31608521895dd742a43beca4b4d29762345","https://git.kernel.org/stable/c/4f3a06cc57976cafa8c6f716646be6c79a99e485","https://git.kernel.org/stable/c/e4a8a96a93d08570e0405cfd989a8a07e5b6ff33"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add chann_lock to protect ksmbd_chann_list xarray\n\nksmbd_chann_list xarray lacks synchronization, allowing use-after-free in\nmulti-channel sessions (between lookup_chann_list() and ksmbd_chann_del).\n\nAdds rw_semaphore chann_lock to struct ksmbd_session and protects\nall xa_load/xa_store/xa_erase accesses.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23226","epss":0.00423,"percentile":0.35682,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23226","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23226","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23239","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23239","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  espintcp: Fix race condition in espintcp_close()  This issue was discovered during a code audit.  After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths such as the Delayed ACK handler or ksoftirqd. As a result, the espintcp_tx_work() worker may dereference a freed espintcp ctx or sk.  The following is a simple race scenario:             cpu0                             cpu1    espintcp_close()     cancel_work_sync(&ctx->work);                                      espintcp_write_space()                                        schedule_work(&ctx->work);  To prevent this race condition, cancel_work_sync() is replaced with disable_work_sync().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23239","epss":0.00101,"percentile":0.01001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23239","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.077265},"relatedVulnerabilities":[{"id":"CVE-2026-23239","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23239","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/022ff7f347588de6e17879a1da6019647b21321b","https://git.kernel.org/stable/c/664e9df53226b4505a0894817ecad2c610ab11d8","https://git.kernel.org/stable/c/e1512c1db9e8794d8d130addd2615ec27231d994","https://git.kernel.org/stable/c/f7ad8b1d0e421c524604d5076b73232093490d5c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nespintcp: Fix race condition in espintcp_close()\n\nThis issue was discovered during a code audit.\n\nAfter cancel_work_sync() is called from espintcp_close(),\nespintcp_tx_work() can still be scheduled from paths such as\nthe Delayed ACK handler or ksoftirqd.\nAs a result, the espintcp_tx_work() worker may dereference a\nfreed espintcp ctx or sk.\n\nThe following is a simple race scenario:\n\n           cpu0                             cpu1\n\n  espintcp_close()\n    cancel_work_sync(&ctx->work);\n                                     espintcp_write_space()\n                                       schedule_work(&ctx->work);\n\nTo prevent this race condition, cancel_work_sync() is\nreplaced with disable_work_sync().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23239","epss":0.00101,"percentile":0.01001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23239","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23239","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23240","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23240","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tls: Fix race condition in tls_sw_cancel_work_tx()  This issue was discovered during a code audit.  After cancel_delayed_work_sync() is called from tls_sk_proto_close(), tx_work_handler() can still be scheduled from paths such as the Delayed ACK handler or ksoftirqd. As a result, the tx_work_handler() worker may dereference a freed TLS object.  The following is a simple race scenario:            cpu0                         cpu1  tls_sk_proto_close()   tls_sw_cancel_work_tx()                                  tls_write_space()                                    tls_sw_write_space()                                      if (!test_and_set_bit(BIT_TX_SCHEDULED, &tx_ctx->tx_bitmask))     set_bit(BIT_TX_SCHEDULED, &ctx->tx_bitmask);     cancel_delayed_work_sync(&ctx->tx_work.work);                                      schedule_delayed_work(&tx_ctx->tx_work.work, 0);  To prevent this race condition, cancel_delayed_work_sync() is replaced with disable_delayed_work_sync().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23240","epss":0.0049,"percentile":0.40589,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23240","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.4606},"relatedVulnerabilities":[{"id":"CVE-2026-23240","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23240","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/17153f154f80be2b47ebf52840f2d8f724eb2f3b","https://git.kernel.org/stable/c/7bb09315f93dce6acc54bf59e5a95ba7365c2be4","https://git.kernel.org/stable/c/854cd32bc74fe573353095e90958490e4e4d641b","https://git.kernel.org/stable/c/a5de36d6cee74a92c1a21b260bc507e64bc451de"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: Fix race condition in tls_sw_cancel_work_tx()\n\nThis issue was discovered during a code audit.\n\nAfter cancel_delayed_work_sync() is called from tls_sk_proto_close(),\ntx_work_handler() can still be scheduled from paths such as the\nDelayed ACK handler or ksoftirqd.\nAs a result, the tx_work_handler() worker may dereference a freed\nTLS object.\n\nThe following is a simple race scenario:\n\n          cpu0                         cpu1\n\ntls_sk_proto_close()\n  tls_sw_cancel_work_tx()\n                                 tls_write_space()\n                                   tls_sw_write_space()\n                                     if (!test_and_set_bit(BIT_TX_SCHEDULED, &tx_ctx->tx_bitmask))\n    set_bit(BIT_TX_SCHEDULED, &ctx->tx_bitmask);\n    cancel_delayed_work_sync(&ctx->tx_work.work);\n                                     schedule_delayed_work(&tx_ctx->tx_work.work, 0);\n\nTo prevent this race condition, cancel_delayed_work_sync() is\nreplaced with disable_delayed_work_sync().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23240","epss":0.0049,"percentile":0.40589,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23240","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23240","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23247","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23247","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tcp: secure_seq: add back ports to TS offset  This reverts 28ee1b746f49 (\"secure_seq: downgrade to per-host timestamp offsets\")  tcp_tw_recycle went away in 2017.  Zhouyan Deng reported off-path TCP source port leakage via SYN cookie side-channel that can be fixed in multiple ways.  One of them is to bring back TCP ports in TS offset randomization.  As a bonus, we perform a single siphash() computation to provide both an ISN and a TS offset.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23247","epss":0.00118,"percentile":0.01926,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.061950000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-23247","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23247","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/165573e41f2f66ef98940cf65f838b2cb575d9d1","https://git.kernel.org/stable/c/46e5b0d7cf55821527adea471ffe52a5afbd9caf","https://git.kernel.org/stable/c/5da5662181ef8a251e3ba564903002c2e87de452","https://git.kernel.org/stable/c/eae2f14ab2efccdb7480fae7d42c4b0116ef8805"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: secure_seq: add back ports to TS offset\n\nThis reverts 28ee1b746f49 (\"secure_seq: downgrade to per-host timestamp offsets\")\n\ntcp_tw_recycle went away in 2017.\n\nZhouyan Deng reported off-path TCP source port leakage via\nSYN cookie side-channel that can be fixed in multiple ways.\n\nOne of them is to bring back TCP ports in TS offset randomization.\n\nAs a bonus, we perform a single siphash() computation\nto provide both an ISN and a TS offset.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23247","epss":0.00118,"percentile":0.01926,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23247","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23265","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23265","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to do sanity check on node footer in {read,write}_end_io  -----------[ cut here ]------------ kernel BUG at fs/f2fs/data.c:358! Call Trace:  <IRQ>  blk_update_request+0x5eb/0xe70 block/blk-mq.c:987  blk_mq_end_request+0x3e/0x70 block/blk-mq.c:1149  blk_complete_reqs block/blk-mq.c:1224 [inline]  blk_done_softirq+0x107/0x160 block/blk-mq.c:1229  handle_softirqs+0x283/0x870 kernel/softirq.c:579  __do_softirq kernel/softirq.c:613 [inline]  invoke_softirq kernel/softirq.c:453 [inline]  __irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680  irq_exit_rcu+0x9/0x30 kernel/softirq.c:696  instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1050 [inline]  sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1050  </IRQ>  In f2fs_write_end_io(), it detects there is inconsistency in between node page index (nid) and footer.nid of node page.  If footer of node page is corrupted in fuzzed image, then we load corrupted node page w/ async method, e.g. f2fs_ra_node_pages() or f2fs_ra_node_page(), in where we won't do sanity check on node footer, once node page becomes dirty, we will encounter this bug after node page writeback.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23265","epss":0.00112,"percentile":0.01549,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-23265","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23265","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/50ac3ecd8e05b6bcc350c71a4307d40c030ec7e4","https://git.kernel.org/stable/c/855c54f1803e3ebc613677b4f389c7f92656a1fc","https://git.kernel.org/stable/c/c386753db52b3a80afa6612bfdcb925aa5ca260f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on node footer in {read,write}_end_io\n\n-----------[ cut here ]------------\nkernel BUG at fs/f2fs/data.c:358!\nCall Trace:\n <IRQ>\n blk_update_request+0x5eb/0xe70 block/blk-mq.c:987\n blk_mq_end_request+0x3e/0x70 block/blk-mq.c:1149\n blk_complete_reqs block/blk-mq.c:1224 [inline]\n blk_done_softirq+0x107/0x160 block/blk-mq.c:1229\n handle_softirqs+0x283/0x870 kernel/softirq.c:579\n __do_softirq kernel/softirq.c:613 [inline]\n invoke_softirq kernel/softirq.c:453 [inline]\n __irq_exit_rcu+0xca/0x1f0 kernel/softirq.c:680\n irq_exit_rcu+0x9/0x30 kernel/softirq.c:696\n instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1050 [inline]\n sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1050\n </IRQ>\n\nIn f2fs_write_end_io(), it detects there is inconsistency in between\nnode page index (nid) and footer.nid of node page.\n\nIf footer of node page is corrupted in fuzzed image, then we load corrupted\nnode page w/ async method, e.g. f2fs_ra_node_pages() or f2fs_ra_node_page(),\nin where we won't do sanity check on node footer, once node page becomes\ndirty, we will encounter this bug after node page writeback.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23265","epss":0.00112,"percentile":0.01549,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23265","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23276","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23276","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: add xmit recursion limit to tunnel xmit functions  Tunnel xmit functions (iptunnel_xmit, ip6tunnel_xmit) lack their own recursion limit. When a bond device in broadcast mode has GRE tap interfaces as slaves, and those GRE tunnels route back through the bond, multicast/broadcast traffic triggers infinite recursion between bond_xmit_broadcast() and ip_tunnel_xmit()/ip6_tnl_xmit(), causing kernel stack overflow.  The existing XMIT_RECURSION_LIMIT (8) in the no-qdisc path is not sufficient because tunnel recursion involves route lookups and full IP output, consuming much more stack per level. Use a lower limit of 4 (IP_TUNNEL_RECURSION_LIMIT) to prevent overflow.  Add recursion detection using dev_xmit_recursion helpers directly in iptunnel_xmit() and ip6tunnel_xmit() to cover all IPv4/IPv6 tunnel paths including UDP encapsulated tunnels (VXLAN, Geneve, etc.).  Move dev_xmit_recursion helpers from net/core/dev.h to public header include/linux/netdevice.h so they can be used by tunnel code.   BUG: KASAN: stack-out-of-bounds in blake2s.constprop.0+0xe7/0x160  Write of size 32 at addr ffff88810033fed0 by task kworker/0:1/11  Workqueue: mld mld_ifc_work  Call Trace:   <TASK>   __build_flow_key.constprop.0 (net/ipv4/route.c:515)   ip_rt_update_pmtu (net/ipv4/route.c:1073)   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:84)   ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847)   gre_tap_xmit (net/ipv4/ip_gre.c:779)   dev_hard_start_xmit (net/core/dev.c:3887)   sch_direct_xmit (net/sched/sch_generic.c:347)   __dev_queue_xmit (net/core/dev.c:4802)   bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312)   bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279)   bond_start_xmit (drivers/net/bonding/bond_main.c:5530)   dev_hard_start_xmit (net/core/dev.c:3887)   __dev_queue_xmit (net/core/dev.c:4841)   ip_finish_output2 (net/ipv4/ip_output.c:237)   ip_output (net/ipv4/ip_output.c:438)   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:86)   gre_tap_xmit (net/ipv4/ip_gre.c:779)   dev_hard_start_xmit (net/core/dev.c:3887)   sch_direct_xmit (net/sched/sch_generic.c:347)   __dev_queue_xmit (net/core/dev.c:4802)   bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312)   bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279)   bond_start_xmit (drivers/net/bonding/bond_main.c:5530)   dev_hard_start_xmit (net/core/dev.c:3887)   __dev_queue_xmit (net/core/dev.c:4841)   ip_finish_output2 (net/ipv4/ip_output.c:237)   ip_output (net/ipv4/ip_output.c:438)   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:86)   ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847)   gre_tap_xmit (net/ipv4/ip_gre.c:779)   dev_hard_start_xmit (net/core/dev.c:3887)   sch_direct_xmit (net/sched/sch_generic.c:347)   __dev_queue_xmit (net/core/dev.c:4802)   bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312)   bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279)   bond_start_xmit (drivers/net/bonding/bond_main.c:5530)   dev_hard_start_xmit (net/core/dev.c:3887)   __dev_queue_xmit (net/core/dev.c:4841)   mld_sendpack   mld_ifc_work   process_one_work   worker_thread   </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23276","epss":0.00128,"percentile":0.02789,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23276","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06720000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-23276","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23276","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6f1a9140ecda3baba3d945b9a6155af4268aafc4","https://git.kernel.org/stable/c/834c4f645726a25fd71ea50cdfb5c135f8f95d85","https://git.kernel.org/stable/c/8a57deeb256069f262957d8012418559ff66c385","https://git.kernel.org/stable/c/b56b8d19bd05e2a8338385c770bc2b60590bc81e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add xmit recursion limit to tunnel xmit functions\n\nTunnel xmit functions (iptunnel_xmit, ip6tunnel_xmit) lack their own\nrecursion limit. When a bond device in broadcast mode has GRE tap\ninterfaces as slaves, and those GRE tunnels route back through the\nbond, multicast/broadcast traffic triggers infinite recursion between\nbond_xmit_broadcast() and ip_tunnel_xmit()/ip6_tnl_xmit(), causing\nkernel stack overflow.\n\nThe existing XMIT_RECURSION_LIMIT (8) in the no-qdisc path is not\nsufficient because tunnel recursion involves route lookups and full IP\noutput, consuming much more stack per level. Use a lower limit of 4\n(IP_TUNNEL_RECURSION_LIMIT) to prevent overflow.\n\nAdd recursion detection using dev_xmit_recursion helpers directly in\niptunnel_xmit() and ip6tunnel_xmit() to cover all IPv4/IPv6 tunnel\npaths including UDP encapsulated tunnels (VXLAN, Geneve, etc.).\n\nMove dev_xmit_recursion helpers from net/core/dev.h to public header\ninclude/linux/netdevice.h so they can be used by tunnel code.\n\n BUG: KASAN: stack-out-of-bounds in blake2s.constprop.0+0xe7/0x160\n Write of size 32 at addr ffff88810033fed0 by task kworker/0:1/11\n Workqueue: mld mld_ifc_work\n Call Trace:\n  <TASK>\n  __build_flow_key.constprop.0 (net/ipv4/route.c:515)\n  ip_rt_update_pmtu (net/ipv4/route.c:1073)\n  iptunnel_xmit (net/ipv4/ip_tunnel_core.c:84)\n  ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847)\n  gre_tap_xmit (net/ipv4/ip_gre.c:779)\n  dev_hard_start_xmit (net/core/dev.c:3887)\n  sch_direct_xmit (net/sched/sch_generic.c:347)\n  __dev_queue_xmit (net/core/dev.c:4802)\n  bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312)\n  bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279)\n  bond_start_xmit (drivers/net/bonding/bond_main.c:5530)\n  dev_hard_start_xmit (net/core/dev.c:3887)\n  __dev_queue_xmit (net/core/dev.c:4841)\n  ip_finish_output2 (net/ipv4/ip_output.c:237)\n  ip_output (net/ipv4/ip_output.c:438)\n  iptunnel_xmit (net/ipv4/ip_tunnel_core.c:86)\n  gre_tap_xmit (net/ipv4/ip_gre.c:779)\n  dev_hard_start_xmit (net/core/dev.c:3887)\n  sch_direct_xmit (net/sched/sch_generic.c:347)\n  __dev_queue_xmit (net/core/dev.c:4802)\n  bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312)\n  bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279)\n  bond_start_xmit (drivers/net/bonding/bond_main.c:5530)\n  dev_hard_start_xmit (net/core/dev.c:3887)\n  __dev_queue_xmit (net/core/dev.c:4841)\n  ip_finish_output2 (net/ipv4/ip_output.c:237)\n  ip_output (net/ipv4/ip_output.c:438)\n  iptunnel_xmit (net/ipv4/ip_tunnel_core.c:86)\n  ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847)\n  gre_tap_xmit (net/ipv4/ip_gre.c:779)\n  dev_hard_start_xmit (net/core/dev.c:3887)\n  sch_direct_xmit (net/sched/sch_generic.c:347)\n  __dev_queue_xmit (net/core/dev.c:4802)\n  bond_dev_queue_xmit (drivers/net/bonding/bond_main.c:312)\n  bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5279)\n  bond_start_xmit (drivers/net/bonding/bond_main.c:5530)\n  dev_hard_start_xmit (net/core/dev.c:3887)\n  __dev_queue_xmit (net/core/dev.c:4841)\n  mld_sendpack\n  mld_ifc_work\n  process_one_work\n  worker_thread\n  </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23276","epss":0.00128,"percentile":0.02789,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23276","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23276","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23327","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23327","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()  cxl_payload_from_user_allowed() casts and dereferences the input payload without first verifying its size. When a raw mailbox command is sent with an undersized payload (ie: 1 byte for CXL_MBOX_OP_CLEAR_LOG, which expects a 16-byte UUID), uuid_equal() reads past the allocated buffer, triggering a KASAN splat:  BUG: KASAN: slab-out-of-bounds in memcmp+0x176/0x1d0 lib/string.c:683 Read of size 8 at addr ffff88810130f5c0 by task syz.1.62/2258  CPU: 2 UID: 0 PID: 2258 Comm: syz.1.62 Not tainted 6.19.0-dirty #3 PREEMPT(voluntary) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 Call Trace:  <TASK>  __dump_stack lib/dump_stack.c:94 [inline]  dump_stack_lvl+0xab/0xe0 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:378 [inline]  print_report+0xce/0x650 mm/kasan/report.c:482  kasan_report+0xce/0x100 mm/kasan/report.c:595  memcmp+0x176/0x1d0 lib/string.c:683  uuid_equal include/linux/uuid.h:73 [inline]  cxl_payload_from_user_allowed drivers/cxl/core/mbox.c:345 [inline]  cxl_mbox_cmd_ctor drivers/cxl/core/mbox.c:368 [inline]  cxl_validate_cmd_from_user drivers/cxl/core/mbox.c:522 [inline]  cxl_send_cmd+0x9c0/0xb50 drivers/cxl/core/mbox.c:643  __cxl_memdev_ioctl drivers/cxl/core/memdev.c:698 [inline]  cxl_memdev_ioctl+0x14f/0x190 drivers/cxl/core/memdev.c:713  vfs_ioctl fs/ioctl.c:51 [inline]  __do_sys_ioctl fs/ioctl.c:597 [inline]  __se_sys_ioctl fs/ioctl.c:583 [inline]  __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0xa8/0x330 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fdaf331ba79 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fdaf1d77038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007fdaf3585fa0 RCX: 00007fdaf331ba79 RDX: 00002000000001c0 RSI: 00000000c030ce02 RDI: 0000000000000003 RBP: 00007fdaf33749df R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007fdaf3586038 R14: 00007fdaf3585fa0 R15: 00007ffced2af768  </TASK>  Add 'in_size' parameter to cxl_payload_from_user_allowed() and validate the payload is large enough.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23327","epss":0.00124,"percentile":0.02425,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23327","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09052},"relatedVulnerabilities":[{"id":"CVE-2026-23327","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23327","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/60b5d1f68338aff2c5af0113f04aefa7169c50c2","https://git.kernel.org/stable/c/7c8a7b7f063b7e7ae9bba4cbaa14a5d2fe3a55e1","https://git.kernel.org/stable/c/dc184ac2f0ba77ae19725ee06ad3ab36bb9d1f61"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()\n\ncxl_payload_from_user_allowed() casts and dereferences the input\npayload without first verifying its size. When a raw mailbox command\nis sent with an undersized payload (ie: 1 byte for CXL_MBOX_OP_CLEAR_LOG,\nwhich expects a 16-byte UUID), uuid_equal() reads past the allocated buffer,\ntriggering a KASAN splat:\n\nBUG: KASAN: slab-out-of-bounds in memcmp+0x176/0x1d0 lib/string.c:683\nRead of size 8 at addr ffff88810130f5c0 by task syz.1.62/2258\n\nCPU: 2 UID: 0 PID: 2258 Comm: syz.1.62 Not tainted 6.19.0-dirty #3 PREEMPT(voluntary)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xab/0xe0 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xce/0x650 mm/kasan/report.c:482\n kasan_report+0xce/0x100 mm/kasan/report.c:595\n memcmp+0x176/0x1d0 lib/string.c:683\n uuid_equal include/linux/uuid.h:73 [inline]\n cxl_payload_from_user_allowed drivers/cxl/core/mbox.c:345 [inline]\n cxl_mbox_cmd_ctor drivers/cxl/core/mbox.c:368 [inline]\n cxl_validate_cmd_from_user drivers/cxl/core/mbox.c:522 [inline]\n cxl_send_cmd+0x9c0/0xb50 drivers/cxl/core/mbox.c:643\n __cxl_memdev_ioctl drivers/cxl/core/memdev.c:698 [inline]\n cxl_memdev_ioctl+0x14f/0x190 drivers/cxl/core/memdev.c:713\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:597 [inline]\n __se_sys_ioctl fs/ioctl.c:583 [inline]\n __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xa8/0x330 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fdaf331ba79\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fdaf1d77038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007fdaf3585fa0 RCX: 00007fdaf331ba79\nRDX: 00002000000001c0 RSI: 00000000c030ce02 RDI: 0000000000000003\nRBP: 00007fdaf33749df R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007fdaf3586038 R14: 00007fdaf3585fa0 R15: 00007ffced2af768\n </TASK>\n\nAdd 'in_size' parameter to cxl_payload_from_user_allowed() and validate\nthe payload is large enough.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23327","epss":0.00124,"percentile":0.02425,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23327","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23327","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23330","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23330","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: nci: complete pending data exchange on device close  In nci_close_device(), complete any pending data exchange before closing. The data exchange callback (e.g. rawsock_data_exchange_complete) holds a socket reference.  NIPA occasionally hits this leak:  unreferenced object 0xff1100000f435000 (size 2048):   comm \"nci_dev\", pid 3954, jiffies 4295441245   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     27 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00  '..@............   backtrace (crc ec2b3c5):     __kmalloc_noprof+0x4db/0x730     sk_prot_alloc.isra.0+0xe4/0x1d0     sk_alloc+0x36/0x760     rawsock_create+0xd1/0x540     nfc_sock_create+0x11f/0x280     __sock_create+0x22d/0x630     __sys_socket+0x115/0x1d0     __x64_sys_socket+0x72/0xd0     do_syscall_64+0x117/0xfc0     entry_SYSCALL_64_after_hwframe+0x4b/0x53","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23330","epss":0.00122,"percentile":0.02257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23330","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-23330","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23330","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/66083581945bd5b8e99fe49b5aeb83d03f62d053","https://git.kernel.org/stable/c/702029337b057085ea13f964822dcd95e0fe53f5","https://git.kernel.org/stable/c/91ff0d8c3464da7f0c43da38c195e60b660128bf","https://git.kernel.org/stable/c/9df613ef6e8e873cdab969a11f74823488977f1f","https://git.kernel.org/stable/c/d05f55d68ebdebb2b0a8480d766eaae88c8c92de"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: complete pending data exchange on device close\n\nIn nci_close_device(), complete any pending data exchange before\nclosing. The data exchange callback (e.g.\nrawsock_data_exchange_complete) holds a socket reference.\n\nNIPA occasionally hits this leak:\n\nunreferenced object 0xff1100000f435000 (size 2048):\n  comm \"nci_dev\", pid 3954, jiffies 4295441245\n  hex dump (first 32 bytes):\n    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n    27 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00  '..@............\n  backtrace (crc ec2b3c5):\n    __kmalloc_noprof+0x4db/0x730\n    sk_prot_alloc.isra.0+0xe4/0x1d0\n    sk_alloc+0x36/0x760\n    rawsock_create+0xd1/0x540\n    nfc_sock_create+0x11f/0x280\n    __sock_create+0x22d/0x630\n    __sys_socket+0x115/0x1d0\n    __x64_sys_socket+0x72/0xd0\n    do_syscall_64+0x117/0xfc0\n    entry_SYSCALL_64_after_hwframe+0x4b/0x53","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23330","epss":0.00122,"percentile":0.02257,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23330","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23330","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23346","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23346","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  arm64: io: Extract user memory type in ioremap_prot()  The only caller of ioremap_prot() outside of the generic ioremap() implementation is generic_access_phys(), which passes a 'pgprot_t' value determined from the user mapping of the target 'pfn' being accessed by the kernel. On arm64, the 'pgprot_t' contains all of the non-address bits from the pte, including the permission controls, and so we end up returning a new user mapping from ioremap_prot() which faults when accessed from the kernel on systems with PAN:    | Unable to handle kernel read from unreadable memory at virtual address ffff80008ea89000   | ...   | Call trace:   |   __memcpy_fromio+0x80/0xf8   |   generic_access_phys+0x20c/0x2b8   |   __access_remote_vm+0x46c/0x5b8   |   access_remote_vm+0x18/0x30   |   environ_read+0x238/0x3e8   |   vfs_read+0xe4/0x2b0   |   ksys_read+0xcc/0x178   |   __arm64_sys_read+0x4c/0x68  Extract only the memory type from the user 'pgprot_t' in ioremap_prot() and assert that we're being passed a user mapping, to protect us against any changes in future that may require additional handling. To avoid falsely flagging users of ioremap(), provide our own ioremap() macro which simply wraps __ioremap_prot().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23346","epss":0.00127,"percentile":0.0272,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2026-23346","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23346","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3d64dcc0799c2d6921ba027716b7be721eb19fa8","https://git.kernel.org/stable/c/64858b76ec67c5fc40fef8ec1841fecb78c1ebde","https://git.kernel.org/stable/c/8f098037139b294050053123ab2bc0f819d08932","https://git.kernel.org/stable/c/d1ad8fe7f72d73e1617bac79f2ec7a3bedf47e2a","https://git.kernel.org/stable/c/eeecafce5afffb4da703666ebefbd4d6e2a5abf6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: io: Extract user memory type in ioremap_prot()\n\nThe only caller of ioremap_prot() outside of the generic ioremap()\nimplementation is generic_access_phys(), which passes a 'pgprot_t' value\ndetermined from the user mapping of the target 'pfn' being accessed by\nthe kernel. On arm64, the 'pgprot_t' contains all of the non-address\nbits from the pte, including the permission controls, and so we end up\nreturning a new user mapping from ioremap_prot() which faults when\naccessed from the kernel on systems with PAN:\n\n  | Unable to handle kernel read from unreadable memory at virtual address ffff80008ea89000\n  | ...\n  | Call trace:\n  |   __memcpy_fromio+0x80/0xf8\n  |   generic_access_phys+0x20c/0x2b8\n  |   __access_remote_vm+0x46c/0x5b8\n  |   access_remote_vm+0x18/0x30\n  |   environ_read+0x238/0x3e8\n  |   vfs_read+0xe4/0x2b0\n  |   ksys_read+0xcc/0x178\n  |   __arm64_sys_read+0x4c/0x68\n\nExtract only the memory type from the user 'pgprot_t' in ioremap_prot()\nand assert that we're being passed a user mapping, to protect us against\nany changes in future that may require additional handling. To avoid\nfalsely flagging users of ioremap(), provide our own ioremap() macro\nwhich simply wraps __ioremap_prot().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23346","epss":0.00127,"percentile":0.0272,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23346","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23348","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23348","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cxl: Fix race of nvdimm_bus object when creating nvdimm objects  Found issue during running of cxl-translate.sh unit test. Adding a 3s sleep right before the test seems to make the issue reproduce fairly consistently. The cxl_translate module has dependency on cxl_acpi and causes orphaned nvdimm objects to reprobe after cxl_acpi is removed. The nvdimm_bus object is registered by the cxl_nvb object when cxl_acpi_probe() is called. With the nvdimm_bus object missing, __nd_device_register() will trigger NULL pointer dereference when accessing the dev->parent that points to &nvdimm_bus->dev.  [  192.884510] BUG: kernel NULL pointer dereference, address: 000000000000006c [  192.895383] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20250812-19.fc42 08/12/2025 [  192.897721] Workqueue: cxl_port cxl_bus_rescan_queue [cxl_core] [  192.899459] RIP: 0010:kobject_get+0xc/0x90 [  192.924871] Call Trace: [  192.925959]  <TASK> [  192.926976]  ? pm_runtime_init+0xb9/0xe0 [  192.929712]  __nd_device_register.part.0+0x4d/0xc0 [libnvdimm] [  192.933314]  __nvdimm_create+0x206/0x290 [libnvdimm] [  192.936662]  cxl_nvdimm_probe+0x119/0x1d0 [cxl_pmem] [  192.940245]  cxl_bus_probe+0x1a/0x60 [cxl_core] [  192.943349]  really_probe+0xde/0x380  This patch also relies on the previous change where devm_cxl_add_nvdimm_bridge() is called from drivers/cxl/pmem.c instead of drivers/cxl/core.c to ensure the dependency of cxl_acpi on cxl_pmem.  1. Set probe_type of cxl_nvb to PROBE_FORCE_SYNCHRONOUS to ensure the    driver is probed synchronously when add_device() is called. 2. Add a check in __devm_cxl_add_nvdimm_bridge() to ensure that the    cxl_nvb driver is attached during cxl_acpi_probe(). 3. Take the cxl_root uport_dev lock and the cxl_nvb->dev lock in    devm_cxl_add_nvdimm() before checking nvdimm_bus is valid. 4. Set cxl_nvdimm flag to CXL_NVD_F_INVALIDATED so cxl_nvdimm_probe()    will exit with -EBUSY.  The removal of cxl_nvdimm devices should prevent any orphaned devices from probing once the nvdimm_bus is gone.  [ dj: Fixed 0-day reported kdoc issue. ] [ dj: Fix cxl_nvb reference leak on error. Gregory (kreview-0811365) ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23348","epss":0.00088,"percentile":0.00423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23348","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04268},"relatedVulnerabilities":[{"id":"CVE-2026-23348","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23348","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5b230daeee420833287cc77314439903e5312f10","https://git.kernel.org/stable/c/5fc4e150c5ada5f7d20d8f9f1b351f10481fbdf7","https://git.kernel.org/stable/c/96a1fd0d84b17360840f344826897fa71049870e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl: Fix race of nvdimm_bus object when creating nvdimm objects\n\nFound issue during running of cxl-translate.sh unit test. Adding a 3s\nsleep right before the test seems to make the issue reproduce fairly\nconsistently. The cxl_translate module has dependency on cxl_acpi and\ncauses orphaned nvdimm objects to reprobe after cxl_acpi is removed.\nThe nvdimm_bus object is registered by the cxl_nvb object when\ncxl_acpi_probe() is called. With the nvdimm_bus object missing,\n__nd_device_register() will trigger NULL pointer dereference when\naccessing the dev->parent that points to &nvdimm_bus->dev.\n\n[  192.884510] BUG: kernel NULL pointer dereference, address: 000000000000006c\n[  192.895383] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20250812-19.fc42 08/12/2025\n[  192.897721] Workqueue: cxl_port cxl_bus_rescan_queue [cxl_core]\n[  192.899459] RIP: 0010:kobject_get+0xc/0x90\n[  192.924871] Call Trace:\n[  192.925959]  <TASK>\n[  192.926976]  ? pm_runtime_init+0xb9/0xe0\n[  192.929712]  __nd_device_register.part.0+0x4d/0xc0 [libnvdimm]\n[  192.933314]  __nvdimm_create+0x206/0x290 [libnvdimm]\n[  192.936662]  cxl_nvdimm_probe+0x119/0x1d0 [cxl_pmem]\n[  192.940245]  cxl_bus_probe+0x1a/0x60 [cxl_core]\n[  192.943349]  really_probe+0xde/0x380\n\nThis patch also relies on the previous change where\ndevm_cxl_add_nvdimm_bridge() is called from drivers/cxl/pmem.c instead\nof drivers/cxl/core.c to ensure the dependency of cxl_acpi on cxl_pmem.\n\n1. Set probe_type of cxl_nvb to PROBE_FORCE_SYNCHRONOUS to ensure the\n   driver is probed synchronously when add_device() is called.\n2. Add a check in __devm_cxl_add_nvdimm_bridge() to ensure that the\n   cxl_nvb driver is attached during cxl_acpi_probe().\n3. Take the cxl_root uport_dev lock and the cxl_nvb->dev lock in\n   devm_cxl_add_nvdimm() before checking nvdimm_bus is valid.\n4. Set cxl_nvdimm flag to CXL_NVD_F_INVALIDATED so cxl_nvdimm_probe()\n   will exit with -EBUSY.\n\nThe removal of cxl_nvdimm devices should prevent any orphaned devices\nfrom probing once the nvdimm_bus is gone.\n\n[ dj: Fixed 0-day reported kdoc issue. ]\n[ dj: Fix cxl_nvb reference leak on error. Gregory (kreview-0811365) ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23348","epss":0.00088,"percentile":0.00423,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23348","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23348","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23361","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23361","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry  Endpoint drivers use dw_pcie_ep_raise_msix_irq() to raise an MSI-X interrupt to the host using a writel(), which generates a PCI posted write transaction.  There's no completion for posted writes, so the writel() may return before the PCI write completes.  dw_pcie_ep_raise_msix_irq() also unmaps the outbound ATU entry used for the PCI write, so the write races with the unmap.  If the PCI write loses the race with the ATU unmap, the write may corrupt host memory or cause IOMMU errors, e.g., these when running fio with a larger queue depth against nvmet-pci-epf:    arm-smmu-v3 fc900000.iommu:      0x0000010000000010   arm-smmu-v3 fc900000.iommu:      0x0000020000000000   arm-smmu-v3 fc900000.iommu:      0x000000090000f040   arm-smmu-v3 fc900000.iommu:      0x0000000000000000   arm-smmu-v3 fc900000.iommu: event: F_TRANSLATION client: 0000:01:00.0 sid: 0x100 ssid: 0x0 iova: 0x90000f040 ipa: 0x0   arm-smmu-v3 fc900000.iommu: unpriv data write s1 \"Input address caused fault\" stag: 0x0  Flush the write by performing a readl() of the same address to ensure that the write has reached the destination before the ATU entry is unmapped.  The same problem was solved for dw_pcie_ep_raise_msi_irq() in commit 8719c64e76bf (\"PCI: dwc: ep: Cache MSI outbound iATU mapping\"), but there it was solved by dedicating an outbound iATU only for MSI. We can't do the same for MSI-X because each vector can have a different msg_addr and the msg_addr may be changed while the vector is masked.  [bhelgaas: commit log]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23361","epss":0.00129,"percentile":0.02836,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23361","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-23361","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23361","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6f60a783860c77b309f7d81003b6a0c73feca49e","https://git.kernel.org/stable/c/a7afb8f810c04845fdfc58c57d9cf0cc5f23ced0","https://git.kernel.org/stable/c/c22533c66ccae10511ad6a7afc34bb26c47577e3","https://git.kernel.org/stable/c/eaa6a56801ddd2d9b4980f19e7fe002b00994804"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry\n\nEndpoint drivers use dw_pcie_ep_raise_msix_irq() to raise an MSI-X\ninterrupt to the host using a writel(), which generates a PCI posted write\ntransaction.  There's no completion for posted writes, so the writel() may\nreturn before the PCI write completes.  dw_pcie_ep_raise_msix_irq() also\nunmaps the outbound ATU entry used for the PCI write, so the write races\nwith the unmap.\n\nIf the PCI write loses the race with the ATU unmap, the write may corrupt\nhost memory or cause IOMMU errors, e.g., these when running fio with a\nlarger queue depth against nvmet-pci-epf:\n\n  arm-smmu-v3 fc900000.iommu:      0x0000010000000010\n  arm-smmu-v3 fc900000.iommu:      0x0000020000000000\n  arm-smmu-v3 fc900000.iommu:      0x000000090000f040\n  arm-smmu-v3 fc900000.iommu:      0x0000000000000000\n  arm-smmu-v3 fc900000.iommu: event: F_TRANSLATION client: 0000:01:00.0 sid: 0x100 ssid: 0x0 iova: 0x90000f040 ipa: 0x0\n  arm-smmu-v3 fc900000.iommu: unpriv data write s1 \"Input address caused fault\" stag: 0x0\n\nFlush the write by performing a readl() of the same address to ensure that\nthe write has reached the destination before the ATU entry is unmapped.\n\nThe same problem was solved for dw_pcie_ep_raise_msi_irq() in commit\n8719c64e76bf (\"PCI: dwc: ep: Cache MSI outbound iATU mapping\"), but there\nit was solved by dedicating an outbound iATU only for MSI. We can't do the\nsame for MSI-X because each vector can have a different msg_addr and the\nmsg_addr may be changed while the vector is masked.\n\n[bhelgaas: commit log]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23361","epss":0.00129,"percentile":0.02836,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23361","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23361","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23371","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23371","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting  Running stress-ng --schedpolicy 0 on an RT kernel on a big machine might lead to the following WARNINGs (edited).   sched: DL de-boosted task PID 22725: REPLENISH flag missing   WARNING: CPU: 93 PID: 0 at kernel/sched/deadline.c:239 dequeue_task_dl+0x15c/0x1f8  ... (running_bw underflow)  Call trace:   dequeue_task_dl+0x15c/0x1f8 (P)   dequeue_task+0x80/0x168   deactivate_task+0x24/0x50   push_dl_task+0x264/0x2e0   dl_task_timer+0x1b0/0x228   __hrtimer_run_queues+0x188/0x378   hrtimer_interrupt+0xfc/0x260   ...  The problem is that when a SCHED_DEADLINE task (lock holder) is changed to a lower priority class via sched_setscheduler(), it may fail to properly inherit the parameters of potential DEADLINE donors if it didn't already inherit them in the past (shorter deadline than donor's at that time). This might lead to bandwidth accounting corruption, as enqueue_task_dl() won't recognize the lock holder as boosted.  The scenario occurs when: 1. A DEADLINE task (donor) blocks on a PI mutex held by another    DEADLINE task (holder), but the holder doesn't inherit parameters    (e.g., it already has a shorter deadline) 2. sched_setscheduler() changes the holder from DEADLINE to a lower    class while still holding the mutex 3. The holder should now inherit DEADLINE parameters from the donor    and be enqueued with ENQUEUE_REPLENISH, but this doesn't happen  Fix the issue by introducing __setscheduler_dl_pi(), which detects when a DEADLINE (proper or boosted) task gets setscheduled to a lower priority class. In case, the function makes the task inherit DEADLINE parameters of the donoer (pi_se) and sets ENQUEUE_REPLENISH flag to ensure proper bandwidth accounting during the next enqueue operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23371","epss":0.00117,"percentile":0.01902,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.061425},"relatedVulnerabilities":[{"id":"CVE-2026-23371","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23371","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0638bf16b7a73a2fe63624bd0d16d9fd904805c3","https://git.kernel.org/stable/c/ba1c22924ddcc280672a2a06a9ca99ee3a1b92c3","https://git.kernel.org/stable/c/d658686a1331db3bb108ca079d76deb3208ed949"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting\n\nRunning stress-ng --schedpolicy 0 on an RT kernel on a big machine\nmight lead to the following WARNINGs (edited).\n\n sched: DL de-boosted task PID 22725: REPLENISH flag missing\n\n WARNING: CPU: 93 PID: 0 at kernel/sched/deadline.c:239 dequeue_task_dl+0x15c/0x1f8\n ... (running_bw underflow)\n Call trace:\n  dequeue_task_dl+0x15c/0x1f8 (P)\n  dequeue_task+0x80/0x168\n  deactivate_task+0x24/0x50\n  push_dl_task+0x264/0x2e0\n  dl_task_timer+0x1b0/0x228\n  __hrtimer_run_queues+0x188/0x378\n  hrtimer_interrupt+0xfc/0x260\n  ...\n\nThe problem is that when a SCHED_DEADLINE task (lock holder) is\nchanged to a lower priority class via sched_setscheduler(), it may\nfail to properly inherit the parameters of potential DEADLINE donors\nif it didn't already inherit them in the past (shorter deadline than\ndonor's at that time). This might lead to bandwidth accounting\ncorruption, as enqueue_task_dl() won't recognize the lock holder as\nboosted.\n\nThe scenario occurs when:\n1. A DEADLINE task (donor) blocks on a PI mutex held by another\n   DEADLINE task (holder), but the holder doesn't inherit parameters\n   (e.g., it already has a shorter deadline)\n2. sched_setscheduler() changes the holder from DEADLINE to a lower\n   class while still holding the mutex\n3. The holder should now inherit DEADLINE parameters from the donor\n   and be enqueued with ENQUEUE_REPLENISH, but this doesn't happen\n\nFix the issue by introducing __setscheduler_dl_pi(), which detects when\na DEADLINE (proper or boosted) task gets setscheduled to a lower\npriority class. In case, the function makes the task inherit DEADLINE\nparameters of the donoer (pi_se) and sets ENQUEUE_REPLENISH flag to\nensure proper bandwidth accounting during the next enqueue operation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23371","epss":0.00117,"percentile":0.01902,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23371","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23374","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  blktrace: fix __this_cpu_read/write in preemptible context  tracing_record_cmdline() internally uses __this_cpu_read() and __this_cpu_write() on the per-CPU variable trace_cmdline_save, and trace_save_cmdline() explicitly asserts preemption is disabled via lockdep_assert_preemption_disabled(). These operations are only safe when preemption is off, as they were designed to be called from the scheduler context (probe_wakeup_sched_switch() / probe_wakeup()).  __blk_add_trace() was calling tracing_record_cmdline(current) early in the blk_tracer path, before ring buffer reservation, from process context where preemption is fully enabled. This triggers the following using blktests/blktrace/002:  blktrace/002 (blktrace ftrace corruption with sysfs trace)   [failed]     runtime  0.367s  ...  0.437s     something found in dmesg:     [   81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33     [   81.239580] null_blk: disk nullb1 created     [   81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516     [   81.362842] caller is tracing_record_cmdline+0x10/0x40     [   81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G                 N  7.0.0-rc1lblk+ #84 PREEMPT(full)     [   81.362877] Tainted: [N]=TEST     [   81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014     [   81.362881] Call Trace:     [   81.362884]  <TASK>     [   81.362886]  dump_stack_lvl+0x8d/0xb0     ...     (See '/mnt/sda/blktests/results/nodev/blktrace/002.dmesg' for the entire message)  [   81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33 [   81.239580] null_blk: disk nullb1 created [   81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516 [   81.362842] caller is tracing_record_cmdline+0x10/0x40 [   81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G                 N  7.0.0-rc1lblk+ #84 PREEMPT(full) [   81.362877] Tainted: [N]=TEST [   81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 [   81.362881] Call Trace: [   81.362884]  <TASK> [   81.362886]  dump_stack_lvl+0x8d/0xb0 [   81.362895]  check_preemption_disabled+0xce/0xe0 [   81.362902]  tracing_record_cmdline+0x10/0x40 [   81.362923]  __blk_add_trace+0x307/0x5d0 [   81.362934]  ? lock_acquire+0xe0/0x300 [   81.362940]  ? iov_iter_extract_pages+0x101/0xa30 [   81.362959]  blk_add_trace_bio+0x106/0x1e0 [   81.362968]  submit_bio_noacct_nocheck+0x24b/0x3a0 [   81.362979]  ? lockdep_init_map_type+0x58/0x260 [   81.362988]  submit_bio_wait+0x56/0x90 [   81.363009]  __blkdev_direct_IO_simple+0x16c/0x250 [   81.363026]  ? __pfx_submit_bio_wait_endio+0x10/0x10 [   81.363038]  ? rcu_read_lock_any_held+0x73/0xa0 [   81.363051]  blkdev_read_iter+0xc1/0x140 [   81.363059]  vfs_read+0x20b/0x330 [   81.363083]  ksys_read+0x67/0xe0 [   81.363090]  do_syscall_64+0xbf/0xf00 [   81.363102]  entry_SYSCALL_64_after_hwframe+0x76/0x7e [   81.363106] RIP: 0033:0x7f281906029d [   81.363111] Code: 31 c0 e9 c6 fe ff ff 50 48 8d 3d 66 63 0a 00 e8 59 ff 01 00 66 0f 1f 84 00 00 00 00 00 80 3d 41 33 0e 00 00 74 17 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 5b c3 66 2e 0f 1f 84 00 00 00 00 00 48 83 ec [   81.363113] RSP: 002b:00007ffca127dd48 EFLAGS: 00000246 ORIG_RAX: 0000000000000000 [   81.363120] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f281906029d [   81.363122] RDX: 0000000000001000 RSI: 0000559f8bfae000 RDI: 0000000000000000 [   81.363123] RBP: 0000000000001000 R08: 0000002863a10a81 R09: 00007f281915f000 [   81.363124] R10: 00007f2818f77b60 R11: 0000000000000246 R12: 0000559f8bfae000 [   81.363126] R13: 0000000000000000 R14: 0000000000000000 R15: 000000000000000a [   81.363142]  </TASK>  The same BUG fires from blk_add_trace_plug(), blk_add_trace_unplug(), and blk_add_trace_rq() paths as well.  The purpose of tracin ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23374","epss":0.00119,"percentile":0.01971,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-23374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23374","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/59efa088752b1c380a0475974679850cc8aef907","https://git.kernel.org/stable/c/aaba6ee63ba65b026401c94e2dd16b9f6e895934","https://git.kernel.org/stable/c/da46b5dfef48658d03347cda21532bcdbb521e67","https://git.kernel.org/stable/c/e5584932ac1dacc182c430d09e2b5490d1d4372b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nblktrace: fix __this_cpu_read/write in preemptible context\n\ntracing_record_cmdline() internally uses __this_cpu_read() and\n__this_cpu_write() on the per-CPU variable trace_cmdline_save, and\ntrace_save_cmdline() explicitly asserts preemption is disabled via\nlockdep_assert_preemption_disabled(). These operations are only safe\nwhen preemption is off, as they were designed to be called from the\nscheduler context (probe_wakeup_sched_switch() / probe_wakeup()).\n\n__blk_add_trace() was calling tracing_record_cmdline(current) early in\nthe blk_tracer path, before ring buffer reservation, from process\ncontext where preemption is fully enabled. This triggers the following\nusing blktests/blktrace/002:\n\nblktrace/002 (blktrace ftrace corruption with sysfs trace)   [failed]\n    runtime  0.367s  ...  0.437s\n    something found in dmesg:\n    [   81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33\n    [   81.239580] null_blk: disk nullb1 created\n    [   81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516\n    [   81.362842] caller is tracing_record_cmdline+0x10/0x40\n    [   81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G                 N  7.0.0-rc1lblk+ #84 PREEMPT(full)\n    [   81.362877] Tainted: [N]=TEST\n    [   81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n    [   81.362881] Call Trace:\n    [   81.362884]  <TASK>\n    [   81.362886]  dump_stack_lvl+0x8d/0xb0\n    ...\n    (See '/mnt/sda/blktests/results/nodev/blktrace/002.dmesg' for the entire message)\n\n[   81.211018] run blktests blktrace/002 at 2026-02-25 22:24:33\n[   81.239580] null_blk: disk nullb1 created\n[   81.357294] BUG: using __this_cpu_read() in preemptible [00000000] code: dd/2516\n[   81.362842] caller is tracing_record_cmdline+0x10/0x40\n[   81.362872] CPU: 16 UID: 0 PID: 2516 Comm: dd Tainted: G                 N  7.0.0-rc1lblk+ #84 PREEMPT(full)\n[   81.362877] Tainted: [N]=TEST\n[   81.362878] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[   81.362881] Call Trace:\n[   81.362884]  <TASK>\n[   81.362886]  dump_stack_lvl+0x8d/0xb0\n[   81.362895]  check_preemption_disabled+0xce/0xe0\n[   81.362902]  tracing_record_cmdline+0x10/0x40\n[   81.362923]  __blk_add_trace+0x307/0x5d0\n[   81.362934]  ? lock_acquire+0xe0/0x300\n[   81.362940]  ? iov_iter_extract_pages+0x101/0xa30\n[   81.362959]  blk_add_trace_bio+0x106/0x1e0\n[   81.362968]  submit_bio_noacct_nocheck+0x24b/0x3a0\n[   81.362979]  ? lockdep_init_map_type+0x58/0x260\n[   81.362988]  submit_bio_wait+0x56/0x90\n[   81.363009]  __blkdev_direct_IO_simple+0x16c/0x250\n[   81.363026]  ? __pfx_submit_bio_wait_endio+0x10/0x10\n[   81.363038]  ? rcu_read_lock_any_held+0x73/0xa0\n[   81.363051]  blkdev_read_iter+0xc1/0x140\n[   81.363059]  vfs_read+0x20b/0x330\n[   81.363083]  ksys_read+0x67/0xe0\n[   81.363090]  do_syscall_64+0xbf/0xf00\n[   81.363102]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[   81.363106] RIP: 0033:0x7f281906029d\n[   81.363111] Code: 31 c0 e9 c6 fe ff ff 50 48 8d 3d 66 63 0a 00 e8 59 ff 01 00 66 0f 1f 84 00 00 00 00 00 80 3d 41 33 0e 00 00 74 17 31 c0 0f 05 <48> 3d 00 f0 ff ff 77 5b c3 66 2e 0f 1f 84 00 00 00 00 00 48 83 ec\n[   81.363113] RSP: 002b:00007ffca127dd48 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n[   81.363120] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f281906029d\n[   81.363122] RDX: 0000000000001000 RSI: 0000559f8bfae000 RDI: 0000000000000000\n[   81.363123] RBP: 0000000000001000 R08: 0000002863a10a81 R09: 00007f281915f000\n[   81.363124] R10: 00007f2818f77b60 R11: 0000000000000246 R12: 0000559f8bfae000\n[   81.363126] R13: 0000000000000000 R14: 0000000000000000 R15: 000000000000000a\n[   81.363142]  </TASK>\n\nThe same BUG fires from blk_add_trace_plug(), blk_add_trace_unplug(),\nand blk_add_trace_rq() paths as well.\n\nThe purpose of tracin\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23374","epss":0.00119,"percentile":0.01971,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23383","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23383","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing  struct bpf_plt contains a u64 target field. Currently, the BPF JIT allocator requests an alignment of 4 bytes (sizeof(u32)) for the JIT buffer.  Because the base address of the JIT buffer can be 4-byte aligned (e.g., ending in 0x4 or 0xc), the relative padding logic in build_plt() fails to ensure that target lands on an 8-byte boundary.  This leads to two issues: 1. UBSAN reports misaligned-access warnings when dereferencing the    structure. 2. More critically, target is updated concurrently via WRITE_ONCE() in    bpf_arch_text_poke() while the JIT'd code executes ldr. On arm64,    64-bit loads/stores are only guaranteed to be single-copy atomic if    they are 64-bit aligned. A misaligned target risks a torn read,    causing the JIT to jump to a corrupted address.  Fix this by increasing the allocation alignment requirement to 8 bytes (sizeof(u64)) in bpf_jit_binary_pack_alloc(). This anchors the base of the JIT buffer to an 8-byte boundary, allowing the relative padding math in build_plt() to correctly align the target field.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23383","epss":0.00129,"percentile":0.02821,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-23383","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23383","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/519b1ad91de5bf7a496f2b858e9212db6328e1de","https://git.kernel.org/stable/c/66959ed481a474eaae278c7f6860a2a9b188a4d6","https://git.kernel.org/stable/c/80ad264da02cc4aee718e799c2b79f0f834673dc","https://git.kernel.org/stable/c/ef06fd16d48704eac868441d98d4ef083d8f3d07"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing\n\nstruct bpf_plt contains a u64 target field. Currently, the BPF JIT\nallocator requests an alignment of 4 bytes (sizeof(u32)) for the JIT\nbuffer.\n\nBecause the base address of the JIT buffer can be 4-byte aligned (e.g.,\nending in 0x4 or 0xc), the relative padding logic in build_plt() fails\nto ensure that target lands on an 8-byte boundary.\n\nThis leads to two issues:\n1. UBSAN reports misaligned-access warnings when dereferencing the\n   structure.\n2. More critically, target is updated concurrently via WRITE_ONCE() in\n   bpf_arch_text_poke() while the JIT'd code executes ldr. On arm64,\n   64-bit loads/stores are only guaranteed to be single-copy atomic if\n   they are 64-bit aligned. A misaligned target risks a torn read,\n   causing the JIT to jump to a corrupted address.\n\nFix this by increasing the allocation alignment requirement to 8 bytes\n(sizeof(u64)) in bpf_jit_binary_pack_alloc(). This anchors the base of\nthe JIT buffer to an 8-byte boundary, allowing the relative padding math\nin build_plt() to correctly align the target field.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23383","epss":0.00129,"percentile":0.02821,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23383","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23393","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23393","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bridge: cfm: Fix race condition in peer_mep deletion  When a peer MEP is being deleted, cancel_delayed_work_sync() is called on ccm_rx_dwork before freeing. However, br_cfm_frame_rx() runs in softirq context under rcu_read_lock (without RTNL) and can re-schedule ccm_rx_dwork via ccm_rx_timer_start() between cancel_delayed_work_sync() returning and kfree_rcu() being called.  The following is a simple race scenario:             cpu0                                     cpu1  mep_delete_implementation()   cancel_delayed_work_sync(ccm_rx_dwork);                                            br_cfm_frame_rx()                                              // peer_mep still in hlist                                              if (peer_mep->ccm_defect)                                                ccm_rx_timer_start()                                                  queue_delayed_work(ccm_rx_dwork)   hlist_del_rcu(&peer_mep->head);   kfree_rcu(peer_mep, rcu);                                            ccm_rx_work_expired()                                              // on freed peer_mep  To prevent this, cancel_delayed_work_sync() is replaced with disable_delayed_work_sync() in both peer MEP deletion paths, so that subsequent queue_delayed_work() calls from br_cfm_frame_rx() are silently rejected.  The cc_peer_disable() helper retains cancel_delayed_work_sync() because it is also used for the CC enable/disable toggle path where the work must remain re-schedulable.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23393","epss":0.001,"percentile":0.00917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23393","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07650000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-23393","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23393","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1fd81151f65927fd9edb8ecd12ad45527dbbe5ab","https://git.kernel.org/stable/c/3715a00855316066cdda69d43648336367422127","https://git.kernel.org/stable/c/d8f35767bacb3c7769d470a41cf161e3f3c07e70","https://git.kernel.org/stable/c/e89dbd2736a45f0507949af4748cbbf3ff793146"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: cfm: Fix race condition in peer_mep deletion\n\nWhen a peer MEP is being deleted, cancel_delayed_work_sync() is called\non ccm_rx_dwork before freeing. However, br_cfm_frame_rx() runs in\nsoftirq context under rcu_read_lock (without RTNL) and can re-schedule\nccm_rx_dwork via ccm_rx_timer_start() between cancel_delayed_work_sync()\nreturning and kfree_rcu() being called.\n\nThe following is a simple race scenario:\n\n           cpu0                                     cpu1\n\nmep_delete_implementation()\n  cancel_delayed_work_sync(ccm_rx_dwork);\n                                           br_cfm_frame_rx()\n                                             // peer_mep still in hlist\n                                             if (peer_mep->ccm_defect)\n                                               ccm_rx_timer_start()\n                                                 queue_delayed_work(ccm_rx_dwork)\n  hlist_del_rcu(&peer_mep->head);\n  kfree_rcu(peer_mep, rcu);\n                                           ccm_rx_work_expired()\n                                             // on freed peer_mep\n\nTo prevent this, cancel_delayed_work_sync() is replaced with\ndisable_delayed_work_sync() in both peer MEP deletion paths, so\nthat subsequent queue_delayed_work() calls from br_cfm_frame_rx()\nare silently rejected.\n\nThe cc_peer_disable() helper retains cancel_delayed_work_sync()\nbecause it is also used for the CC enable/disable toggle path where\nthe work must remain re-schedulable.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23393","epss":0.001,"percentile":0.00917,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23393","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23393","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23394","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23394","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  af_unix: Give up GC if MSG_PEEK intervened.  Igor Ushakov reported that GC purged the receive queue of an alive socket due to a race with MSG_PEEK with a nice repro.  This is the exact same issue previously fixed by commit cbcf01128d0a (\"af_unix: fix garbage collect vs MSG_PEEK\").  After GC was replaced with the current algorithm, the cited commit removed the locking dance in unix_peek_fds() and reintroduced the same issue.  The problem is that MSG_PEEK bumps a file refcount without interacting with GC.  Consider an SCC containing sk-A and sk-B, where sk-A is close()d but can be recv()ed via sk-B.  The bad thing happens if sk-A is recv()ed with MSG_PEEK from sk-B and sk-B is close()d while GC is checking unix_vertex_dead() for sk-A and sk-B.    GC thread                    User thread   ---------                    -----------   unix_vertex_dead(sk-A)   -> true   <------.                     \\                      `------   recv(sk-B, MSG_PEEK)               invalidate !!    -> sk-A's file refcount : 1 -> 2                                 close(sk-B)                                -> sk-B's file refcount : 2 -> 1   unix_vertex_dead(sk-B)   -> true  Initially, sk-A's file refcount is 1 by the inflight fd in sk-B recvq.  GC thinks sk-A is dead because the file refcount is the same as the number of its inflight fds.  However, sk-A's file refcount is bumped silently by MSG_PEEK, which invalidates the previous evaluation.  At this moment, sk-B's file refcount is 2; one by the open fd, and one by the inflight fd in sk-A.  The subsequent close() releases one refcount by the former.  Finally, GC incorrectly concludes that both sk-A and sk-B are dead.  One option is to restore the locking dance in unix_peek_fds(), but we can resolve this more elegantly thanks to the new algorithm.  The point is that the issue does not occur without the subsequent close() and we actually do not need to synchronise MSG_PEEK with the dead SCC detection.  When the issue occurs, close() and GC touch the same file refcount. If GC sees the refcount being decremented by close(), it can just give up garbage-collecting the SCC.  Therefore, we only need to signal the race during MSG_PEEK with a proper memory barrier to make it visible to the GC.  Let's use seqcount_t to notify GC when MSG_PEEK occurs and let it defer the SCC to the next run.  This way no locking is needed on the MSG_PEEK side, and we can avoid imposing a penalty on every MSG_PEEK unnecessarily.  Note that we can retry within unix_scc_dead() if MSG_PEEK is detected, but we do not do so to avoid hung task splat from abusive MSG_PEEK calls.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23394","epss":0.00093,"percentile":0.00604,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23394","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.045105000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-23394","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23394","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3106f326f67c03dd9da4ca64663d11e40138cf40","https://git.kernel.org/stable/c/37dd7ab332396eb8dd80b2dc7ea4b61abf767436","https://git.kernel.org/stable/c/72cf49ad50c16270b52bc512d9c2df5743922968","https://git.kernel.org/stable/c/980999a96e1ad043f1197606e5d637219cb102b9","https://git.kernel.org/stable/c/e3dd56fb5683ba80bf8d7a2f9aa21cfa53f05202","https://git.kernel.org/stable/c/e5b31d988a41549037b8d8721a3c3cae893d8670"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Give up GC if MSG_PEEK intervened.\n\nIgor Ushakov reported that GC purged the receive queue of\nan alive socket due to a race with MSG_PEEK with a nice repro.\n\nThis is the exact same issue previously fixed by commit\ncbcf01128d0a (\"af_unix: fix garbage collect vs MSG_PEEK\").\n\nAfter GC was replaced with the current algorithm, the cited\ncommit removed the locking dance in unix_peek_fds() and\nreintroduced the same issue.\n\nThe problem is that MSG_PEEK bumps a file refcount without\ninteracting with GC.\n\nConsider an SCC containing sk-A and sk-B, where sk-A is\nclose()d but can be recv()ed via sk-B.\n\nThe bad thing happens if sk-A is recv()ed with MSG_PEEK from\nsk-B and sk-B is close()d while GC is checking unix_vertex_dead()\nfor sk-A and sk-B.\n\n  GC thread                    User thread\n  ---------                    -----------\n  unix_vertex_dead(sk-A)\n  -> true   <------.\n                    \\\n                     `------   recv(sk-B, MSG_PEEK)\n              invalidate !!    -> sk-A's file refcount : 1 -> 2\n\n                               close(sk-B)\n                               -> sk-B's file refcount : 2 -> 1\n  unix_vertex_dead(sk-B)\n  -> true\n\nInitially, sk-A's file refcount is 1 by the inflight fd in sk-B\nrecvq.  GC thinks sk-A is dead because the file refcount is the\nsame as the number of its inflight fds.\n\nHowever, sk-A's file refcount is bumped silently by MSG_PEEK,\nwhich invalidates the previous evaluation.\n\nAt this moment, sk-B's file refcount is 2; one by the open fd,\nand one by the inflight fd in sk-A.  The subsequent close()\nreleases one refcount by the former.\n\nFinally, GC incorrectly concludes that both sk-A and sk-B are dead.\n\nOne option is to restore the locking dance in unix_peek_fds(),\nbut we can resolve this more elegantly thanks to the new algorithm.\n\nThe point is that the issue does not occur without the subsequent\nclose() and we actually do not need to synchronise MSG_PEEK with\nthe dead SCC detection.\n\nWhen the issue occurs, close() and GC touch the same file refcount.\nIf GC sees the refcount being decremented by close(), it can just\ngive up garbage-collecting the SCC.\n\nTherefore, we only need to signal the race during MSG_PEEK with\na proper memory barrier to make it visible to the GC.\n\nLet's use seqcount_t to notify GC when MSG_PEEK occurs and let\nit defer the SCC to the next run.\n\nThis way no locking is needed on the MSG_PEEK side, and we can\navoid imposing a penalty on every MSG_PEEK unnecessarily.\n\nNote that we can retry within unix_scc_dead() if MSG_PEEK is\ndetected, but we do not do so to avoid hung task splat from\nabusive MSG_PEEK calls.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23394","epss":0.00093,"percentile":0.00604,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23394","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23394","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23419","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23419","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/rds: Fix circular locking dependency in rds_tcp_tune  syzbot reported a circular locking dependency in rds_tcp_tune() where sk_net_refcnt_upgrade() is called while holding the socket lock:  ====================================================== WARNING: possible circular locking dependency detected ====================================================== kworker/u10:8/15040 is trying to acquire lock: ffffffff8e9aaf80 (fs_reclaim){+.+.}-{0:0}, at: __kmalloc_cache_noprof+0x4b/0x6f0  but task is already holding lock: ffff88805a3c1ce0 (k-sk_lock-AF_INET6){+.+.}-{0:0}, at: rds_tcp_tune+0xd7/0x930  The issue occurs because sk_net_refcnt_upgrade() performs memory allocation (via get_net_track() -> ref_tracker_alloc()) while the socket lock is held, creating a circular dependency with fs_reclaim.  Fix this by moving sk_net_refcnt_upgrade() outside the socket lock critical section. This is safe because the fields modified by the sk_net_refcnt_upgrade() call (sk_net_refcnt, ns_tracker) are not accessed by any concurrent code path at this point.  v2:   - Corrected fixes tag   - check patch line wrap nits   - ai commentary nits","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23419","epss":0.00175,"percentile":0.07161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23419","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09187500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-23419","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23419","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/026bbaeeab9e04534ee58882b6447300629b42f6","https://git.kernel.org/stable/c/6a877ececd6daa002a9a0002cd0fbca6592a9244","https://git.kernel.org/stable/c/6ce948fa54599f369ff7fe8b793a6aae4b0762b2","https://git.kernel.org/stable/c/8519e6883a942e510f33a0e634e27bcc3a844a40","https://git.kernel.org/stable/c/8babb271403378ba6836f6c8599c5313d0e2355d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: Fix circular locking dependency in rds_tcp_tune\n\nsyzbot reported a circular locking dependency in rds_tcp_tune() where\nsk_net_refcnt_upgrade() is called while holding the socket lock:\n\n======================================================\nWARNING: possible circular locking dependency detected\n======================================================\nkworker/u10:8/15040 is trying to acquire lock:\nffffffff8e9aaf80 (fs_reclaim){+.+.}-{0:0},\nat: __kmalloc_cache_noprof+0x4b/0x6f0\n\nbut task is already holding lock:\nffff88805a3c1ce0 (k-sk_lock-AF_INET6){+.+.}-{0:0},\nat: rds_tcp_tune+0xd7/0x930\n\nThe issue occurs because sk_net_refcnt_upgrade() performs memory\nallocation (via get_net_track() -> ref_tracker_alloc()) while the\nsocket lock is held, creating a circular dependency with fs_reclaim.\n\nFix this by moving sk_net_refcnt_upgrade() outside the socket lock\ncritical section. This is safe because the fields modified by the\nsk_net_refcnt_upgrade() call (sk_net_refcnt, ns_tracker) are not\naccessed by any concurrent code path at this point.\n\nv2:\n  - Corrected fixes tag\n  - check patch line wrap nits\n  - ai commentary nits","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23419","epss":0.00175,"percentile":0.07161,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23419","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23419","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23447","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23447","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check  The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against the total skb length without accounting for ndpoffset, allowing out-of-bounds reads when the NDP32 is placed near the end of the NTB.  Add ndpoffset to the nframes bounds check and use struct_size_t() to express the NDP-plus-DPE-array size more clearly.  Compile-tested only.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23447","epss":0.00129,"percentile":0.02832,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23447","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-23447","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23447","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/125f932a76a97904ef8a555f1dd53e5d0e288c54","https://git.kernel.org/stable/c/77914255155e68a20aa41175edeecf8121dac391","https://git.kernel.org/stable/c/a5bd5a2710310c965ea4153cba4210988a3454e2","https://git.kernel.org/stable/c/af0d1613d6751489dbf9f69aac1123f0b1e566e5","https://git.kernel.org/stable/c/de70da1fb1d152e981ecb3157f7ec2b633005c16"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check\n\nThe same bounds-check bug fixed for NDP16 in the previous patch also\nexists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated\nagainst the total skb length without accounting for ndpoffset, allowing\nout-of-bounds reads when the NDP32 is placed near the end of the NTB.\n\nAdd ndpoffset to the nframes bounds check and use struct_size_t() to\nexpress the NDP-plus-DPE-array size more clearly.\n\nCompile-tested only.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23447","epss":0.00129,"percentile":0.02832,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23447","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23447","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23448","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23448","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check  cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE entries fit within the skb. The first check correctly accounts for ndpoffset:    if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in->len)  but the second check omits it:    if ((sizeof(struct usb_cdc_ncm_ndp16) +        ret * (sizeof(struct usb_cdc_ncm_dpe16))) > skb_in->len)  This validates the DPE array size against the total skb length as if the NDP were at offset 0, rather than at ndpoffset. When the NDP is placed near the end of the NTB (large wNdpIndex), the DPE entries can extend past the skb data buffer even though the check passes. cdc_ncm_rx_fixup() then reads out-of-bounds memory when iterating the DPE array.  Add ndpoffset to the nframes bounds check and use struct_size_t() to express the NDP-plus-DPE-array size more clearly.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23448","epss":0.00129,"percentile":0.02833,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23448","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-23448","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23448","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2aa8a4fa8d5b7d0e1ebcec100e1a4d80a1f4b21a","https://git.kernel.org/stable/c/403f94ddcb36c552fbef51dea735b131e3dcde8b","https://git.kernel.org/stable/c/789204f980730258c983102c027c375238009c80","https://git.kernel.org/stable/c/dce9dda0e3707e887977db44407989e9ead26611","https://git.kernel.org/stable/c/f1c7701d3ac91b62d672c13690cf295821f0d5c3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check\n\ncdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE\nentries fit within the skb. The first check correctly accounts for\nndpoffset:\n\n  if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in->len)\n\nbut the second check omits it:\n\n  if ((sizeof(struct usb_cdc_ncm_ndp16) +\n       ret * (sizeof(struct usb_cdc_ncm_dpe16))) > skb_in->len)\n\nThis validates the DPE array size against the total skb length as if\nthe NDP were at offset 0, rather than at ndpoffset. When the NDP is\nplaced near the end of the NTB (large wNdpIndex), the DPE entries can\nextend past the skb data buffer even though the check passes.\ncdc_ncm_rx_fixup() then reads out-of-bounds memory when iterating\nthe DPE array.\n\nAdd ndpoffset to the nframes bounds check and use struct_size_t() to\nexpress the NDP-plus-DPE-array size more clearly.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23448","epss":0.00129,"percentile":0.02833,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23448","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23448","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23465","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23465","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: log new dentries when logging parent dir of a conflicting inode  If we log the parent directory of a conflicting inode, we are not logging the new dentries of the directory, so when we finish we have the parent directory's inode marked as logged but we did not log its new dentries. As a consequence if the parent directory is explicitly fsynced later and it does not have any new changes since we logged it, the fsync is a no-op and after a power failure the new dentries are missing.  Example scenario:    $ mkdir foo    $ sync    $rmdir foo    $ mkdir dir1   $ mkdir dir2    # A file with the same name and parent as the directory we just deleted   # and was persisted in a past transaction. So the deleted directory's   # inode is a conflicting inode of this new file's inode.   $ touch foo    $ ln foo dir2/link    # The fsync on dir2 will log the parent directory (\".\") because the   # conflicting inode (deleted directory) does not exists anymore, but it   # it does not log its new dentries (dir1).   $ xfs_io -c \"fsync\" dir2    # This fsync on the parent directory is no-op, since the previous fsync   # logged it (but without logging its new dentries).   $ xfs_io -c \"fsync\" .    <power failure>    # After log replay dir1 is missing.  Fix this by ensuring we log new dir dentries whenever we log the parent directory of a no longer existing conflicting inode.  A test case for fstests will follow soon.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23465","epss":0.00122,"percentile":0.02298,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-23465","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23465","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1cf30c73602c69d750c9345c47f2c0e9d0cfb578","https://git.kernel.org/stable/c/56e72c8b02d982be775d9df025357c152383ee84","https://git.kernel.org/stable/c/6f5a51969b1deb79aefd2194b48fe7e78e72ff7e","https://git.kernel.org/stable/c/9573a365ff9ff45da9222d3fe63695ce562beb24","https://git.kernel.org/stable/c/f556b1e09d054e31f464c0fd37280c2b5a393fee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: log new dentries when logging parent dir of a conflicting inode\n\nIf we log the parent directory of a conflicting inode, we are not logging\nthe new dentries of the directory, so when we finish we have the parent\ndirectory's inode marked as logged but we did not log its new dentries.\nAs a consequence if the parent directory is explicitly fsynced later and\nit does not have any new changes since we logged it, the fsync is a no-op\nand after a power failure the new dentries are missing.\n\nExample scenario:\n\n  $ mkdir foo\n\n  $ sync\n\n  $rmdir foo\n\n  $ mkdir dir1\n  $ mkdir dir2\n\n  # A file with the same name and parent as the directory we just deleted\n  # and was persisted in a past transaction. So the deleted directory's\n  # inode is a conflicting inode of this new file's inode.\n  $ touch foo\n\n  $ ln foo dir2/link\n\n  # The fsync on dir2 will log the parent directory (\".\") because the\n  # conflicting inode (deleted directory) does not exists anymore, but it\n  # it does not log its new dentries (dir1).\n  $ xfs_io -c \"fsync\" dir2\n\n  # This fsync on the parent directory is no-op, since the previous fsync\n  # logged it (but without logging its new dentries).\n  $ xfs_io -c \"fsync\" .\n\n  <power failure>\n\n  # After log replay dir1 is missing.\n\nFix this by ensuring we log new dir dentries whenever we log the parent\ndirectory of a no longer existing conflicting inode.\n\nA test case for fstests will follow soon.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23465","epss":0.00122,"percentile":0.02298,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23465","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-23472","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23472","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN  uart_write_room() and uart_write() behave inconsistently when xmit_buf is NULL (which happens for PORT_UNKNOWN ports that were never properly initialized):  - uart_write_room() returns kfifo_avail() which can be > 0 - uart_write() checks xmit_buf and returns 0 if NULL  This inconsistency causes an infinite loop in drivers that rely on tty_write_room() to determine if they can write:    while (tty_write_room(tty) > 0) {       written = tty->ops->write(...);       // written is always 0, loop never exits   }  For example, caif_serial's handle_tx() enters an infinite loop when used with PORT_UNKNOWN serial ports, causing system hangs.  Fix by making uart_write_room() also check xmit_buf and return 0 if it's NULL, consistent with uart_write().  Reproducer: https://gist.github.com/mrpre/d9a694cc0e19828ee3bc3b37983fde13","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23472","epss":0.00121,"percentile":0.02187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23472","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-23472","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23472","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/455ce986fa356ff43a43c0d363ba95fa152f21d5","https://git.kernel.org/stable/c/bc70f2b36cf474d5cc8ecbcaf57f3e326fdec67c","https://git.kernel.org/stable/c/efe85a557186b7fe915572ae93a8f3f78bfd9a22"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN\n\nuart_write_room() and uart_write() behave inconsistently when\nxmit_buf is NULL (which happens for PORT_UNKNOWN ports that were\nnever properly initialized):\n\n- uart_write_room() returns kfifo_avail() which can be > 0\n- uart_write() checks xmit_buf and returns 0 if NULL\n\nThis inconsistency causes an infinite loop in drivers that rely on\ntty_write_room() to determine if they can write:\n\n  while (tty_write_room(tty) > 0) {\n      written = tty->ops->write(...);\n      // written is always 0, loop never exits\n  }\n\nFor example, caif_serial's handle_tx() enters an infinite loop when\nused with PORT_UNKNOWN serial ports, causing system hangs.\n\nFix by making uart_write_room() also check xmit_buf and return 0 if\nit's NULL, consistent with uart_write().\n\nReproducer: https://gist.github.com/mrpre/d9a694cc0e19828ee3bc3b37983fde13","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-23472","epss":0.00121,"percentile":0.02187,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-23472","cwe":"CWE-835","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-23472","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31410","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION  Use sb->s_uuid for a proper volume identifier as the primary choice. For filesystems that do not provide a UUID, fall back to stfs.f_fsid obtained from vfs_statfs().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31410","epss":0.00164,"percentile":0.05929,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0861},"relatedVulnerabilities":[{"id":"CVE-2026-31410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31410","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3a64125730cabc34fccfbc230c2667c2e14f7308","https://git.kernel.org/stable/c/3d80ebe6d1b7bc9ad20fd9b0c1a0c56d804f8a0a","https://git.kernel.org/stable/c/c283a6ffe6d5d6e5594d991286b9ce15951572e1","https://git.kernel.org/stable/c/ce00616bc1df675bfdacc968f2bf7c51f4669227"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION\n\nUse sb->s_uuid for a proper volume identifier as the primary choice.\nFor filesystems that do not provide a UUID, fall back to stfs.f_fsid\nobtained from vfs_statfs().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31410","epss":0.00164,"percentile":0.05929,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31410","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31419","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31419","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: bonding: fix use-after-free in bond_xmit_broadcast()  bond_xmit_broadcast() reuses the original skb for the last slave (determined by bond_is_last_slave()) and clones it for others. Concurrent slave enslave/release can mutate the slave list during RCU-protected iteration, changing which slave is \"last\" mid-loop. This causes the original skb to be double-consumed (double-freed).  Replace the racy bond_is_last_slave() check with a simple index comparison (i + 1 == slaves_count) against the pre-snapshot slave count taken via READ_ONCE() before the loop.  This preserves the zero-copy optimization for the last slave while making the \"last\" determination stable against concurrent list mutations.  The UAF can trigger the following crash:  ================================================================== BUG: KASAN: slab-use-after-free in skb_clone Read of size 8 at addr ffff888100ef8d40 by task exploit/147  CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY Call Trace:  <TASK>  dump_stack_lvl (lib/dump_stack.c:123)  print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)  kasan_report (mm/kasan/report.c:597)  skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)  bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)  bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)  dev_hard_start_xmit (include/linux/netdevice.h:5325 include/linux/netdevice.h:5334 net/core/dev.c:3871 net/core/dev.c:3887)  __dev_queue_xmit (include/linux/netdevice.h:3601 net/core/dev.c:4838)  ip6_finish_output2 (include/net/neighbour.h:540 include/net/neighbour.h:554 net/ipv6/ip6_output.c:136)  ip6_finish_output (net/ipv6/ip6_output.c:208 net/ipv6/ip6_output.c:219)  ip6_output (net/ipv6/ip6_output.c:250)  ip6_send_skb (net/ipv6/ip6_output.c:1985)  udp_v6_send_skb (net/ipv6/udp.c:1442)  udpv6_sendmsg (net/ipv6/udp.c:1733)  __sys_sendto (net/socket.c:730 net/socket.c:742 net/socket.c:2206)  __x64_sys_sendto (net/socket.c:2209)  do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)  </TASK>  Allocated by task 147:  Freed by task 147:  The buggy address belongs to the object at ffff888100ef8c80  which belongs to the cache skbuff_head_cache of size 224 The buggy address is located 192 bytes inside of  freed 224-byte region [ffff888100ef8c80, ffff888100ef8d60)  Memory state around the buggy address:  ffff888100ef8c00: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc  ffff888100ef8c80: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb >ffff888100ef8d00: fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc                                                     ^  ffff888100ef8d80: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb  ffff888100ef8e00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb ==================================================================","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31419","epss":0.00124,"percentile":0.0248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31419","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-31419","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-31419","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31419","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/00752893f96b344f258c9c6de18b33171ac4872c","https://git.kernel.org/stable/c/2884bf72fb8f03409e423397319205de48adca16","https://git.kernel.org/stable/c/2de5c8eea0a9db99dae7c36f4b541b74b41d3a04","https://git.kernel.org/stable/c/a0f661918edc79d7a75e468128af8d41e2a1a83a","https://git.kernel.org/stable/c/d4cc7e4c80b1634c7b1497574a2fdb18df6c026c","https://git.kernel.org/stable/c/f5b94654a4a19891a8108d66ef166de6c028c6cd","https://access.redhat.com/errata/RHSA-2026:13566","https://access.redhat.com/errata/RHSA-2026:19521","https://access.redhat.com/errata/RHSA-2026:21209","https://access.redhat.com/errata/RHSA-2026:22334","https://access.redhat.com/errata/RHSA-2026:22900","https://access.redhat.com/errata/RHSA-2026:22940","https://access.redhat.com/errata/RHSA-2026:23224","https://access.redhat.com/errata/RHSA-2026:25191","https://access.redhat.com/errata/RHSA-2026:25217","https://access.redhat.com/errata/RHSA-2026:27353","https://access.redhat.com/errata/RHSA-2026:27354","https://access.redhat.com/errata/RHSA-2026:35870","https://access.redhat.com/errata/RHSA-2026:36172","https://access.redhat.com/errata/RHSA-2026:36530","https://access.redhat.com/errata/RHSA-2026:36531","https://access.redhat.com/errata/RHSA-2026:36532","https://access.redhat.com/errata/RHSA-2026:36533","https://access.redhat.com/errata/RHSA-2026:36534","https://access.redhat.com/security/cve/CVE-2026-31419","https://bugzilla.redhat.com/show_bug.cgi?id=2457829","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31419.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bonding: fix use-after-free in bond_xmit_broadcast()\n\nbond_xmit_broadcast() reuses the original skb for the last slave\n(determined by bond_is_last_slave()) and clones it for others.\nConcurrent slave enslave/release can mutate the slave list during\nRCU-protected iteration, changing which slave is \"last\" mid-loop.\nThis causes the original skb to be double-consumed (double-freed).\n\nReplace the racy bond_is_last_slave() check with a simple index\ncomparison (i + 1 == slaves_count) against the pre-snapshot slave\ncount taken via READ_ONCE() before the loop.  This preserves the\nzero-copy optimization for the last slave while making the \"last\"\ndetermination stable against concurrent list mutations.\n\nThe UAF can trigger the following crash:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in skb_clone\nRead of size 8 at addr ffff888100ef8d40 by task exploit/147\n\nCPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY\nCall Trace:\n <TASK>\n dump_stack_lvl (lib/dump_stack.c:123)\n print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)\n kasan_report (mm/kasan/report.c:597)\n skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)\n bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)\n bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)\n dev_hard_start_xmit (include/linux/netdevice.h:5325 include/linux/netdevice.h:5334 net/core/dev.c:3871 net/core/dev.c:3887)\n __dev_queue_xmit (include/linux/netdevice.h:3601 net/core/dev.c:4838)\n ip6_finish_output2 (include/net/neighbour.h:540 include/net/neighbour.h:554 net/ipv6/ip6_output.c:136)\n ip6_finish_output (net/ipv6/ip6_output.c:208 net/ipv6/ip6_output.c:219)\n ip6_output (net/ipv6/ip6_output.c:250)\n ip6_send_skb (net/ipv6/ip6_output.c:1985)\n udp_v6_send_skb (net/ipv6/udp.c:1442)\n udpv6_sendmsg (net/ipv6/udp.c:1733)\n __sys_sendto (net/socket.c:730 net/socket.c:742 net/socket.c:2206)\n __x64_sys_sendto (net/socket.c:2209)\n do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n </TASK>\n\nAllocated by task 147:\n\nFreed by task 147:\n\nThe buggy address belongs to the object at ffff888100ef8c80\n which belongs to the cache skbuff_head_cache of size 224\nThe buggy address is located 192 bytes inside of\n freed 224-byte region [ffff888100ef8c80, ffff888100ef8d60)\n\nMemory state around the buggy address:\n ffff888100ef8c00: fb fb fb fb fc fc fc fc fc fc fc fc fc fc fc fc\n ffff888100ef8c80: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n>ffff888100ef8d00: fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n                                                    ^\n ffff888100ef8d80: fc fc fc fc fc fc fc fc fa fb fb fb fb fb fb fb\n ffff888100ef8e00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n==================================================================","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31419","epss":0.00124,"percentile":0.0248,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31419","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-31419","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31419","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31420","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31420","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bridge: mrp: reject zero test interval to avoid OOM panic  br_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied interval value from netlink without validation. When interval is 0, usecs_to_jiffies(0) yields 0, causing the delayed work (br_mrp_test_work_expired / br_mrp_in_test_work_expired) to reschedule itself with zero delay. This creates a tight loop on system_percpu_wq that allocates and transmits MRP test frames at maximum rate, exhausting all system memory and causing a kernel panic via OOM deadlock.  The same zero-interval issue applies to br_mrp_start_in_test_parse() for interconnect test frames.  Use NLA_POLICY_MIN(NLA_U32, 1) in the nla_policy tables for both IFLA_BRIDGE_MRP_START_TEST_INTERVAL and IFLA_BRIDGE_MRP_START_IN_TEST_INTERVAL, so zero is rejected at the netlink attribute parsing layer before the value ever reaches the workqueue scheduling code. This is consistent with how other bridge subsystems (br_fdb, br_mst) enforce range constraints on netlink attributes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31420","epss":0.00091,"percentile":0.00522,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31420","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.047775000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-31420","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31420","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/630a15a31c2034b5b697f4aabc769b9d80d82446","https://git.kernel.org/stable/c/c9bc352f716d1bebfe43354bce539ec2d0223b30","https://git.kernel.org/stable/c/e8ec80430bfa520e7352155d6ac632e527cba7aa","https://git.kernel.org/stable/c/fa6e24963342de4370e3a3c9af41e38277b74cf3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: mrp: reject zero test interval to avoid OOM panic\n\nbr_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied\ninterval value from netlink without validation. When interval is 0,\nusecs_to_jiffies(0) yields 0, causing the delayed work\n(br_mrp_test_work_expired / br_mrp_in_test_work_expired) to reschedule\nitself with zero delay. This creates a tight loop on system_percpu_wq\nthat allocates and transmits MRP test frames at maximum rate, exhausting\nall system memory and causing a kernel panic via OOM deadlock.\n\nThe same zero-interval issue applies to br_mrp_start_in_test_parse()\nfor interconnect test frames.\n\nUse NLA_POLICY_MIN(NLA_U32, 1) in the nla_policy tables for both\nIFLA_BRIDGE_MRP_START_TEST_INTERVAL and\nIFLA_BRIDGE_MRP_START_IN_TEST_INTERVAL, so zero is rejected at the\nnetlink attribute parsing layer before the value ever reaches the\nworkqueue scheduling code. This is consistent with how other bridge\nsubsystems (br_fdb, br_mst) enforce range constraints on netlink\nattributes.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31420","epss":0.00091,"percentile":0.00522,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31420","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31420","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31432","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31432","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix OOB write in QUERY_INFO for compound requests  When a compound request such as READ + QUERY_INFO(Security) is received, and the first command (READ) consumes most of the response buffer, ksmbd could write beyond the allocated buffer while building a security descriptor.  The root cause was that smb2_get_info_sec() checked buffer space using ppntsd_size from xattr, while build_sec_desc() often synthesized a significantly larger descriptor from POSIX ACLs.  This patch introduces smb_acl_sec_desc_scratch_len() to accurately compute the final descriptor size beforehand, performs proper buffer checking with smb2_calc_max_out_buf_len(), and uses exact-sized allocation + iov pinning.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31432","epss":0.00507,"percentile":0.41609,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31432","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.413205},"relatedVulnerabilities":[{"id":"CVE-2026-31432","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31432","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/075ea208c648cc2bcd616295b711d3637c61de45","https://git.kernel.org/stable/c/515c2daab46021221bdf406bef19bc90a44ec617","https://git.kernel.org/stable/c/850452af77f55d185f9445e1f7a1db53c5e4aad4","https://git.kernel.org/stable/c/d48c64fb80ad78b3dd29fb7d79b6ec7bd72bfc09","https://git.kernel.org/stable/c/fda9522ed6afaec45cabc198d8492270c394c7bc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix OOB write in QUERY_INFO for compound requests\n\nWhen a compound request such as READ + QUERY_INFO(Security) is received,\nand the first command (READ) consumes most of the response buffer,\nksmbd could write beyond the allocated buffer while building a security\ndescriptor.\n\nThe root cause was that smb2_get_info_sec() checked buffer space using\nppntsd_size from xattr, while build_sec_desc() often synthesized a\nsignificantly larger descriptor from POSIX ACLs.\n\nThis patch introduces smb_acl_sec_desc_scratch_len() to accurately\ncompute the final descriptor size beforehand, performs proper buffer\nchecking with smb2_calc_max_out_buf_len(), and uses exact-sized\nallocation + iov pinning.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31432","epss":0.00507,"percentile":0.41609,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31432","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31432","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31458","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/damon/sysfs: check contexts->nr before accessing contexts_arr[0]  Multiple sysfs command paths dereference contexts_arr[0] without first verifying that kdamond->contexts->nr == 1.  A user can set nr_contexts to 0 via sysfs while DAMON is running, causing NULL pointer dereferences.  In more detail, the issue can be triggered by privileged users like below.  First, start DAMON and make contexts directory empty (kdamond->contexts->nr == 0).      # damo start     # cd /sys/kernel/mm/damon/admin/kdamonds/0     # echo 0 > contexts/nr_contexts  Then, each of below commands will cause the NULL pointer dereference.      # echo update_schemes_stats > state     # echo update_schemes_tried_regions > state     # echo update_schemes_tried_bytes > state     # echo update_schemes_effective_quotas > state     # echo update_tuned_intervals > state  Guard all commands (except OFF) at the entry point of damon_sysfs_handle_cmd().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31458","epss":0.00122,"percentile":0.02245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31458","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31458","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1bfe9fb5ed2667fb075682408b776b5273162615","https://git.kernel.org/stable/c/1e8da792672481d603fa7cd0d815577220a3ee27","https://git.kernel.org/stable/c/708033c231bd782858f4ddbb46ee874a5a5fbdab","https://git.kernel.org/stable/c/aba546061341b56e9ffb37e1eb661a3628b6ec12","https://git.kernel.org/stable/c/bbe03ad3fb9e714191757ca7b41582f930be7be2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs: check contexts->nr before accessing contexts_arr[0]\n\nMultiple sysfs command paths dereference contexts_arr[0] without first\nverifying that kdamond->contexts->nr == 1.  A user can set nr_contexts to\n0 via sysfs while DAMON is running, causing NULL pointer dereferences.\n\nIn more detail, the issue can be triggered by privileged users like\nbelow.\n\nFirst, start DAMON and make contexts directory empty\n(kdamond->contexts->nr == 0).\n\n    # damo start\n    # cd /sys/kernel/mm/damon/admin/kdamonds/0\n    # echo 0 > contexts/nr_contexts\n\nThen, each of below commands will cause the NULL pointer dereference.\n\n    # echo update_schemes_stats > state\n    # echo update_schemes_tried_regions > state\n    # echo update_schemes_tried_bytes > state\n    # echo update_schemes_effective_quotas > state\n    # echo update_tuned_intervals > state\n\nGuard all commands (except OFF) at the entry point of\ndamon_sysfs_handle_cmd().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31458","epss":0.00122,"percentile":0.02245,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31458","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31458","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31462","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31462","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: prevent immediate PASID reuse case  PASID resue could cause interrupt issue when process immediately runs into hw state left by previous process exited with the same PASID, it's possible that page faults are still pending in the IH ring buffer when the process exits and frees up its PASID. To prevent the case, it uses idr cyclic allocator same as kernel pid's.  (cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31462","epss":0.00122,"percentile":0.02246,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31462","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31462","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/14b81abe7bdc25f8097906fc2f91276ffedb2d26","https://git.kernel.org/stable/c/51ccaf0e30c303149244c34820def83d74c86288","https://git.kernel.org/stable/c/9e5ebfe99b223bb0eb9c50a125c9c02f4ef4c71b","https://git.kernel.org/stable/c/c0b3882836de8ac991b626823966f385555bbcff"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: prevent immediate PASID reuse case\n\nPASID resue could cause interrupt issue when process\nimmediately runs into hw state left by previous\nprocess exited with the same PASID, it's possible that\npage faults are still pending in the IH ring buffer when\nthe process exits and frees up its PASID. To prevent the\ncase, it uses idr cyclic allocator same as kernel pid's.\n\n(cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31462","epss":0.00122,"percentile":0.02246,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31462","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31486","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31486","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (pmbus/core) Protect regulator operations with mutex  The regulator operations pmbus_regulator_get_voltage(), pmbus_regulator_set_voltage(), and pmbus_regulator_list_voltage() access PMBus registers and shared data but were not protected by the update_lock mutex. This could lead to race conditions.  However, adding mutex protection directly to these functions causes a deadlock because pmbus_regulator_notify() (which calls regulator_notifier_call_chain()) is often called with the mutex already held (e.g., from pmbus_fault_handler()). If a regulator callback then calls one of the now-protected voltage functions, it will attempt to acquire the same mutex.  Rework pmbus_regulator_notify() to utilize a worker function to send notifications outside of the mutex protection. Events are stored as atomics in a per-page bitmask and processed by the worker.  Initialize the worker and its associated data during regulator registration, and ensure it is cancelled on device removal using devm_add_action_or_reset().  While at it, remove the unnecessary include of linux/of.h.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31486","epss":0.00099,"percentile":0.00886,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31486","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07227},"relatedVulnerabilities":[{"id":"CVE-2026-31486","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31486","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2c77ae315f3ce9d2c8e1609be74c9358c1fe4e07","https://git.kernel.org/stable/c/4e9d723d9f198b86f6882a84c501ba1f39e8d055","https://git.kernel.org/stable/c/754bd2b4a084b90b5e7b630e1f423061a9b9b761","https://git.kernel.org/stable/c/acf04e2863132f6d9222f71f3a76fb9782cbe061","https://git.kernel.org/stable/c/b26849cffaa7c43355b82e9bef3725e786973a1a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/core) Protect regulator operations with mutex\n\nThe regulator operations pmbus_regulator_get_voltage(),\npmbus_regulator_set_voltage(), and pmbus_regulator_list_voltage()\naccess PMBus registers and shared data but were not protected by\nthe update_lock mutex. This could lead to race conditions.\n\nHowever, adding mutex protection directly to these functions causes\na deadlock because pmbus_regulator_notify() (which calls\nregulator_notifier_call_chain()) is often called with the mutex\nalready held (e.g., from pmbus_fault_handler()). If a regulator\ncallback then calls one of the now-protected voltage functions,\nit will attempt to acquire the same mutex.\n\nRework pmbus_regulator_notify() to utilize a worker function to\nsend notifications outside of the mutex protection. Events are\nstored as atomics in a per-page bitmask and processed by the worker.\n\nInitialize the worker and its associated data during regulator\nregistration, and ensure it is cancelled on device removal using\ndevm_add_action_or_reset().\n\nWhile at it, remove the unnecessary include of linux/of.h.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31486","epss":0.00099,"percentile":0.00886,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31486","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31486","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31487","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31487","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: use generic driver_override infrastructure  When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF.  Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally.  Note that calling match() from __driver_attach() without the device lock held is intentional. [1]  Also note that we do not enable the driver_override feature of struct bus_type, as SPI - in contrast to most other buses - passes \"\" to sysfs_emit() when the driver_override pointer is NULL. Thus, printing \"\\n\" instead of \"(null)\\n\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31487","epss":0.00094,"percentile":0.00667,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31487","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.049350000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-31487","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31487","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/c73a58661a760373d08a6883af4f0bb5cc991a67","https://git.kernel.org/stable/c/cc34d77dd48708d810c12bfd6f5bf03304f6c824","https://git.kernel.org/stable/c/e0ae367a2de06c49aa1de6ec9b1ab6860bbb2cf0","https://git.kernel.org/stable/c/eedf220442d13b6d97294e5b0ac8a2c38ee1a1a0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]\n\nAlso note that we do not enable the driver_override feature of struct\nbus_type, as SPI - in contrast to most other buses - passes \"\" to\nsysfs_emit() when the driver_override pointer is NULL. Thus, printing\n\"\\n\" instead of \"(null)\\n\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31487","epss":0.00094,"percentile":0.00667,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31487","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31487","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31493","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31493","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/efa: Fix use of completion ctx after free  On admin queue completion handling, if the admin command completed with error we print data from the completion context. The issue is that we already freed the completion context in polling/interrupts handler which means we print data from context in an unknown state (it might be already used again). Change the admin submission flow so alloc/dealloc of the context will be symmetric and dealloc will be called after any potential use of the context.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31493","epss":0.00127,"percentile":0.02689,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31493","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097155},"relatedVulnerabilities":[{"id":"CVE-2026-31493","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31493","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0dd98aea1c0c45987fa2dd92f988b0eb1a72c125","https://git.kernel.org/stable/c/1cf95fe5dc5471efea947b4c6f8913da6bc7976e","https://git.kernel.org/stable/c/ef3b06742c8a201d0e83edc9a33a89a4fe3009f8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/efa: Fix use of completion ctx after free\n\nOn admin queue completion handling, if the admin command completed with\nerror we print data from the completion context. The issue is that we\nalready freed the completion context in polling/interrupts handler which\nmeans we print data from context in an unknown state (it might be\nalready used again).\nChange the admin submission flow so alloc/dealloc of the context will be\nsymmetric and dealloc will be called after any potential use of the\ncontext.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31493","epss":0.00127,"percentile":0.02689,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31493","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31493","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31502","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31502","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  team: fix header_ops type confusion with non-Ethernet ports  Similar to commit 950803f72547 (\"bonding: fix type confusion in bond_setup_by_slave()\") team has the same class of header_ops type confusion.  For non-Ethernet ports, team_setup_by_port() copies port_dev->header_ops directly. When the team device later calls dev_hard_header() or dev_parse_header(), these callbacks can run with the team net_device instead of the real lower device, so netdev_priv(dev) is interpreted as the wrong private type and can crash.  The syzbot report shows a crash in bond_header_create(), but the root cause is in team: the topology is gre -> bond -> team, and team calls the inherited header_ops with its own net_device instead of the lower device, so bond_header_create() receives a team device and interprets netdev_priv() as bonding private data, causing a type confusion crash.  Fix this by introducing team header_ops wrappers for create/parse, selecting a team port under RCU, and calling the lower device callbacks with port->dev, so each callback always sees the correct net_device context.  Also pass the selected lower device to the lower parse callback, so recursion is bounded in stacked non-Ethernet topologies and parse callbacks always run with the correct device context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31502","epss":0.00129,"percentile":0.02833,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31502","cwe":"CWE-843","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-31502","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31502","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0a7468ed49a6b65d34abcc6eb60e15f7f6d34da0","https://git.kernel.org/stable/c/20491d384d973a63fbdaf7a71e38d69b0659ea55","https://git.kernel.org/stable/c/420e5aad7ba89e8f79e2dc8327b0c0c24c1c1d53","https://git.kernel.org/stable/c/425000dbf17373a4ab8be9428f5dc055ef870a56","https://git.kernel.org/stable/c/6d3161fa3eee64d46b766fb0db33ec7f300ef52d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nteam: fix header_ops type confusion with non-Ethernet ports\n\nSimilar to commit 950803f72547 (\"bonding: fix type confusion in\nbond_setup_by_slave()\") team has the same class of header_ops type\nconfusion.\n\nFor non-Ethernet ports, team_setup_by_port() copies port_dev->header_ops\ndirectly. When the team device later calls dev_hard_header() or\ndev_parse_header(), these callbacks can run with the team net_device\ninstead of the real lower device, so netdev_priv(dev) is interpreted as\nthe wrong private type and can crash.\n\nThe syzbot report shows a crash in bond_header_create(), but the root\ncause is in team: the topology is gre -> bond -> team, and team calls\nthe inherited header_ops with its own net_device instead of the lower\ndevice, so bond_header_create() receives a team device and interprets\nnetdev_priv() as bonding private data, causing a type confusion crash.\n\nFix this by introducing team header_ops wrappers for create/parse,\nselecting a team port under RCU, and calling the lower device callbacks\nwith port->dev, so each callback always sees the correct net_device\ncontext.\n\nAlso pass the selected lower device to the lower parse callback, so\nrecursion is bounded in stacked non-Ethernet topologies and parse\ncallbacks always run with the correct device context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31502","epss":0.00129,"percentile":0.02833,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31502","cwe":"CWE-843","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31502","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31505","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31505","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()  iavf incorrectly uses real_num_tx_queues for ETH_SS_STATS. Since the value could change in runtime, we should use num_tx_queues instead.  Moreover iavf_get_ethtool_stats() uses num_active_queues while iavf_get_sset_count() and iavf_get_stat_strings() use real_num_tx_queues, which triggers out-of-bounds writes when we do \"ethtool -L\" and \"ethtool -S\" simultaneously [1].  For example when we change channels from 1 to 8, Thread 3 could be scheduled before Thread 2, and out-of-bounds writes could be triggered in Thread 3:  Thread 1 (ethtool -L)       Thread 2 (work)        Thread 3 (ethtool -S) iavf_set_channels() ... iavf_alloc_queues() -> num_active_queues = 8 iavf_schedule_finish_config()                                                    iavf_get_sset_count()                                                    real_num_tx_queues: 1                                                    -> buffer for 1 queue                                                    iavf_get_ethtool_stats()                                                    num_active_queues: 8                                                    -> out-of-bounds!                             iavf_finish_config()                             -> real_num_tx_queues = 8  Use immutable num_tx_queues in all related functions to avoid the issue.  [1]  BUG: KASAN: vmalloc-out-of-bounds in iavf_add_one_ethtool_stat+0x200/0x270  Write of size 8 at addr ffffc900031c9080 by task ethtool/5800   CPU: 1 UID: 0 PID: 5800 Comm: ethtool Not tainted 6.19.0-enjuk-08403-g8137e3db7f1c #241 PREEMPT(full)  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014  Call Trace:   <TASK>   dump_stack_lvl+0x6f/0xb0   print_report+0x170/0x4f3   kasan_report+0xe1/0x180   iavf_add_one_ethtool_stat+0x200/0x270   iavf_get_ethtool_stats+0x14c/0x2e0   __dev_ethtool+0x3d0c/0x5830   dev_ethtool+0x12d/0x270   dev_ioctl+0x53c/0xe30   sock_do_ioctl+0x1a9/0x270   sock_ioctl+0x3d4/0x5e0   __x64_sys_ioctl+0x137/0x1c0   do_syscall_64+0xf3/0x690   entry_SYSCALL_64_after_hwframe+0x77/0x7f  RIP: 0033:0x7f7da0e6e36d  ...   </TASK>   The buggy address belongs to a 1-page vmalloc region starting at 0xffffc900031c9000 allocated at __dev_ethtool+0x3cc9/0x5830  The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000  index:0xffff88813a013de0 pfn:0x13a013  flags: 0x200000000000000(node=0|zone=2)  raw: 0200000000000000 0000000000000000 dead000000000122 0000000000000000  raw: ffff88813a013de0 0000000000000000 00000001ffffffff 0000000000000000  page dumped because: kasan: bad access detected   Memory state around the buggy address:   ffffc900031c8f80: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8   ffffc900031c9000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  >ffffc900031c9080: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8                     ^   ffffc900031c9100: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8   ffffc900031c9180: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31505","epss":0.00129,"percentile":0.02835,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31505","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-31505","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31505","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1f931dee5b726df1940348ec31614d64bac03aa6","https://git.kernel.org/stable/c/bb85741d2dc2be207353a412f51b83697fcbefcf","https://git.kernel.org/stable/c/fdf902bf86a80bf15792a1d20a67a5302498d7f1","https://git.kernel.org/stable/c/fecacfc95f195b99c71c579a472120d0b4ed65fa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niavf: fix out-of-bounds writes in iavf_get_ethtool_stats()\n\niavf incorrectly uses real_num_tx_queues for ETH_SS_STATS. Since the\nvalue could change in runtime, we should use num_tx_queues instead.\n\nMoreover iavf_get_ethtool_stats() uses num_active_queues while\niavf_get_sset_count() and iavf_get_stat_strings() use\nreal_num_tx_queues, which triggers out-of-bounds writes when we do\n\"ethtool -L\" and \"ethtool -S\" simultaneously [1].\n\nFor example when we change channels from 1 to 8, Thread 3 could be\nscheduled before Thread 2, and out-of-bounds writes could be triggered\nin Thread 3:\n\nThread 1 (ethtool -L)       Thread 2 (work)        Thread 3 (ethtool -S)\niavf_set_channels()\n...\niavf_alloc_queues()\n-> num_active_queues = 8\niavf_schedule_finish_config()\n                                                   iavf_get_sset_count()\n                                                   real_num_tx_queues: 1\n                                                   -> buffer for 1 queue\n                                                   iavf_get_ethtool_stats()\n                                                   num_active_queues: 8\n                                                   -> out-of-bounds!\n                            iavf_finish_config()\n                            -> real_num_tx_queues = 8\n\nUse immutable num_tx_queues in all related functions to avoid the issue.\n\n[1]\n BUG: KASAN: vmalloc-out-of-bounds in iavf_add_one_ethtool_stat+0x200/0x270\n Write of size 8 at addr ffffc900031c9080 by task ethtool/5800\n\n CPU: 1 UID: 0 PID: 5800 Comm: ethtool Not tainted 6.19.0-enjuk-08403-g8137e3db7f1c #241 PREEMPT(full)\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n Call Trace:\n  <TASK>\n  dump_stack_lvl+0x6f/0xb0\n  print_report+0x170/0x4f3\n  kasan_report+0xe1/0x180\n  iavf_add_one_ethtool_stat+0x200/0x270\n  iavf_get_ethtool_stats+0x14c/0x2e0\n  __dev_ethtool+0x3d0c/0x5830\n  dev_ethtool+0x12d/0x270\n  dev_ioctl+0x53c/0xe30\n  sock_do_ioctl+0x1a9/0x270\n  sock_ioctl+0x3d4/0x5e0\n  __x64_sys_ioctl+0x137/0x1c0\n  do_syscall_64+0xf3/0x690\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n RIP: 0033:0x7f7da0e6e36d\n ...\n  </TASK>\n\n The buggy address belongs to a 1-page vmalloc region starting at 0xffffc900031c9000 allocated at __dev_ethtool+0x3cc9/0x5830\n The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000\n index:0xffff88813a013de0 pfn:0x13a013\n flags: 0x200000000000000(node=0|zone=2)\n raw: 0200000000000000 0000000000000000 dead000000000122 0000000000000000\n raw: ffff88813a013de0 0000000000000000 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n  ffffc900031c8f80: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n  ffffc900031c9000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n >ffffc900031c9080: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n                    ^\n  ffffc900031c9100: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n  ffffc900031c9180: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31505","epss":0.00129,"percentile":0.02835,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31505","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31505","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31516","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31516","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: prevent policy_hthresh.work from racing with netns teardown  A XFRM_MSG_NEWSPDINFO request can queue the per-net work item policy_hthresh.work onto the system workqueue.  The queued callback, xfrm_hash_rebuild(), retrieves the enclosing struct net via container_of(). If the net namespace is torn down before that work runs, the associated struct net may already have been freed, and xfrm_hash_rebuild() may then dereference stale memory.  xfrm_policy_fini() already flushes policy_hash_work during teardown, but it does not synchronize policy_hthresh.work.  Synchronize policy_hthresh.work in xfrm_policy_fini() as well, so the queued work cannot outlive the net namespace teardown and access a freed struct net.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31516","epss":0.00099,"percentile":0.00905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31516","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07573500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-31516","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31516","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/29fe3a61bcdce398ee3955101c39f89c01a8a77e","https://git.kernel.org/stable/c/4e2e77843fef473ef47e322d52436d8308582a96","https://git.kernel.org/stable/c/56ea2257b83ee29a543f158159e3d1abc1e3e4fe","https://git.kernel.org/stable/c/8854e9367465d784046362698731c1111e3b39b8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: prevent policy_hthresh.work from racing with netns teardown\n\nA XFRM_MSG_NEWSPDINFO request can queue the per-net work item\npolicy_hthresh.work onto the system workqueue.\n\nThe queued callback, xfrm_hash_rebuild(), retrieves the enclosing\nstruct net via container_of(). If the net namespace is torn down\nbefore that work runs, the associated struct net may already have\nbeen freed, and xfrm_hash_rebuild() may then dereference stale memory.\n\nxfrm_policy_fini() already flushes policy_hash_work during teardown,\nbut it does not synchronize policy_hthresh.work.\n\nSynchronize policy_hthresh.work in xfrm_policy_fini() as well, so the\nqueued work cannot outlive the net namespace teardown and access a\nfreed struct net.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31516","epss":0.00099,"percentile":0.00905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31516","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31516","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31527","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31527","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  driver core: platform: use generic driver_override infrastructure  When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF.  Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally.  Note that calling match() from __driver_attach() without the device lock held is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31527","epss":0.00129,"percentile":0.02829,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31527","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-31527","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31527","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2b38efc05bf7a8568ec74bfffea0f5cfa62bc01d","https://git.kernel.org/stable/c/492349e5e4a369a8b62781100a3ade470bf1ce6b","https://git.kernel.org/stable/c/7c02a9bd7d14a89065fcf672b86d8e1d1a41d3b1","https://git.kernel.org/stable/c/9a6086d2a828dd2ff74cf9abcae456670febd71f","https://git.kernel.org/stable/c/edee7ee5a14c3b33f6d54641f5af5c5e9180992d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: platform: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31527","epss":0.00129,"percentile":0.02829,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31527","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31527","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31531","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31531","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()  When querying a nexthop object via RTM_GETNEXTHOP, the kernel currently allocates a fixed-size skb using NLMSG_GOODSIZE. While sufficient for single nexthops and small Equal-Cost Multi-Path groups, this fixed allocation fails for large nexthop groups like 512 nexthops.  This results in the following warning splat:   WARNING: net/ipv4/nexthop.c:3395 at rtm_get_nexthop+0x176/0x1c0, CPU#20: rep/4608  [...]  RIP: 0010:rtm_get_nexthop (net/ipv4/nexthop.c:3395)  [...]  Call Trace:   <TASK>   rtnetlink_rcv_msg (net/core/rtnetlink.c:6989)   netlink_rcv_skb (net/netlink/af_netlink.c:2550)   netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)   netlink_sendmsg (net/netlink/af_netlink.c:1894)   ____sys_sendmsg (net/socket.c:721 net/socket.c:736 net/socket.c:2585)   ___sys_sendmsg (net/socket.c:2641)   __sys_sendmsg (net/socket.c:2671)   do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)   </TASK>  Fix this by allocating the size dynamically using nh_nlmsg_size() and using nlmsg_new(), this is consistent with nexthop_notify() behavior. In addition, adjust nh_nlmsg_size_grp() so it calculates the size needed based on flags passed. While at it, also add the size of NHA_FDB for nexthop group size calculation as it was missing too.  This cannot be reproduced via iproute2 as the group size is currently limited and the command fails as follows:  addattr_l ERROR: message exceeded bound of 1048","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31531","epss":0.00164,"percentile":0.05931,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0861},"relatedVulnerabilities":[{"id":"CVE-2026-31531","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31531","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/14cf0cd35361f4e94824bf8a42f72713d7702a73","https://git.kernel.org/stable/c/40bd39e383a0478fd5c221f393df05fd9d70cfbc","https://git.kernel.org/stable/c/615517f3f8d53b0cf41507c7599971e17adfdfa5","https://git.kernel.org/stable/c/635038fe19db391117e66b46bdc2b6e447ac801d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()\n\nWhen querying a nexthop object via RTM_GETNEXTHOP, the kernel currently\nallocates a fixed-size skb using NLMSG_GOODSIZE. While sufficient for\nsingle nexthops and small Equal-Cost Multi-Path groups, this fixed\nallocation fails for large nexthop groups like 512 nexthops.\n\nThis results in the following warning splat:\n\n WARNING: net/ipv4/nexthop.c:3395 at rtm_get_nexthop+0x176/0x1c0, CPU#20: rep/4608\n [...]\n RIP: 0010:rtm_get_nexthop (net/ipv4/nexthop.c:3395)\n [...]\n Call Trace:\n  <TASK>\n  rtnetlink_rcv_msg (net/core/rtnetlink.c:6989)\n  netlink_rcv_skb (net/netlink/af_netlink.c:2550)\n  netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344)\n  netlink_sendmsg (net/netlink/af_netlink.c:1894)\n  ____sys_sendmsg (net/socket.c:721 net/socket.c:736 net/socket.c:2585)\n  ___sys_sendmsg (net/socket.c:2641)\n  __sys_sendmsg (net/socket.c:2671)\n  do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n  </TASK>\n\nFix this by allocating the size dynamically using nh_nlmsg_size() and\nusing nlmsg_new(), this is consistent with nexthop_notify() behavior. In\naddition, adjust nh_nlmsg_size_grp() so it calculates the size needed\nbased on flags passed. While at it, also add the size of NHA_FDB for\nnexthop group size calculation as it was missing too.\n\nThis cannot be reproduced via iproute2 as the group size is currently\nlimited and the command fails as follows:\n\naddattr_l ERROR: message exceeded bound of 1048","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31531","epss":0.00164,"percentile":0.05931,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31531","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31536","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31536","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: server: let send_done handle a completion without IB_SEND_SIGNALED  With smbdirect_send_batch processing we likely have requests without IB_SEND_SIGNALED, which will be destroyed in the final request that has IB_SEND_SIGNALED set.  If the connection is broken all requests are signaled even without explicit IB_SEND_SIGNALED.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31536","epss":0.00442,"percentile":0.37271,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.41548},"relatedVulnerabilities":[{"id":"CVE-2026-31536","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31536","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/24082642654f3e5149913946e89c00a297a8868f","https://git.kernel.org/stable/c/9da82dc73cb03e85d716a2609364572367a5ff47","https://git.kernel.org/stable/c/e38b415c024bc3b6321bf8650dbf3f4aab8e74b3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: server: let send_done handle a completion without IB_SEND_SIGNALED\n\nWith smbdirect_send_batch processing we likely have requests without\nIB_SEND_SIGNALED, which will be destroyed in the final request\nthat has IB_SEND_SIGNALED set.\n\nIf the connection is broken all requests are signaled\neven without explicit IB_SEND_SIGNALED.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31536","epss":0.00442,"percentile":0.37271,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31536","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31537","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31537","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: server: make use of smbdirect_socket.send_io.bcredits  It turns out that our code will corrupt the stream of reassabled data transfer messages when we trigger an immendiate (empty) send.  In order to fix this we'll have a single 'batch' credit per connection. And code getting that credit is free to use as much messages until remaining_length reaches 0, then the batch credit it given back and the next logical send can happen.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31537","epss":0.00121,"percentile":0.02134,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-31537","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31537","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/34abd408c8ba24d7c97bd02ba874d8c714f49db1","https://git.kernel.org/stable/c/5ef18a2e66f2f33fdac64437bddfb9fe6389fdc7","https://git.kernel.org/stable/c/79242e7b6bc63efec28b7c235bc320806afce6c0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: server: make use of smbdirect_socket.send_io.bcredits\n\nIt turns out that our code will corrupt the stream of\nreassabled data transfer messages when we trigger an\nimmendiate (empty) send.\n\nIn order to fix this we'll have a single 'batch' credit per\nconnection. And code getting that credit is free to use\nas much messages until remaining_length reaches 0, then\nthe batch credit it given back and the next logical send can\nhappen.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31537","epss":0.00121,"percentile":0.02134,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31537","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31557","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31557","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet: move async event work off nvmet-wq  For target nvmet_ctrl_free() flushes ctrl->async_event_work. If nvmet_ctrl_free() runs on nvmet-wq, the flush re-enters workqueue completion for the same worker:-  A. Async event work queued on nvmet-wq (prior to disconnect):   nvmet_execute_async_event()      queue_work(nvmet_wq, &ctrl->async_event_work)    nvmet_add_async_event()      queue_work(nvmet_wq, &ctrl->async_event_work)  B. Full pre-work chain (RDMA CM path):   nvmet_rdma_cm_handler()      nvmet_rdma_queue_disconnect()        __nvmet_rdma_queue_disconnect()          queue_work(nvmet_wq, &queue->release_work)            process_one_work()              lock((wq_completion)nvmet-wq)  <--------- 1st              nvmet_rdma_release_queue_work()  C. Recursive path (same worker):   nvmet_rdma_release_queue_work()      nvmet_rdma_free_queue()        nvmet_sq_destroy()          nvmet_ctrl_put()            nvmet_ctrl_free()              flush_work(&ctrl->async_event_work)                __flush_work()                  touch_wq_lockdep_map()                  lock((wq_completion)nvmet-wq) <--------- 2nd  Lockdep splat:    ============================================   WARNING: possible recursive locking detected   6.19.0-rc3nvme+ #14 Tainted: G                 N   --------------------------------------------   kworker/u192:42/44933 is trying to acquire lock:   ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90    but task is already holding lock:   ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660    3 locks held by kworker/u192:42/44933:    #0: ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660    #1: ffffc9000e6cbe28 ((work_completion)(&queue->release_work)){+.+.}-{0:0}, at: process_one_work+0x1c5/0x660    #2: ffffffff82d4db60 (rcu_read_lock){....}-{1:3}, at: __flush_work+0x62/0x530    Workqueue: nvmet-wq nvmet_rdma_release_queue_work [nvmet_rdma]   Call Trace:    __flush_work+0x268/0x530    nvmet_ctrl_free+0x140/0x310 [nvmet]    nvmet_cq_put+0x74/0x90 [nvmet]    nvmet_rdma_free_queue+0x23/0xe0 [nvmet_rdma]    nvmet_rdma_release_queue_work+0x19/0x50 [nvmet_rdma]    process_one_work+0x206/0x660    worker_thread+0x184/0x320    kthread+0x10c/0x240    ret_from_fork+0x319/0x390  Move async event work to a dedicated nvmet-aen-wq to avoid reentrant flush on nvmet-wq.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31557","epss":0.00441,"percentile":0.37129,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33075},"relatedVulnerabilities":[{"id":"CVE-2026-31557","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31557","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/25ceffc1dabec3b93f458b437aae26f4da293f87","https://git.kernel.org/stable/c/2922e3507f6d5caa7f1d07f145e186fc6f317a4e","https://git.kernel.org/stable/c/49c7c50ee6325a084216e94395e067ecde8088fa","https://git.kernel.org/stable/c/ca111c9d8d6c9d5735878d933a1716c4be86c2d1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: move async event work off nvmet-wq\n\nFor target nvmet_ctrl_free() flushes ctrl->async_event_work.\nIf nvmet_ctrl_free() runs on nvmet-wq, the flush re-enters workqueue\ncompletion for the same worker:-\n\nA. Async event work queued on nvmet-wq (prior to disconnect):\n  nvmet_execute_async_event()\n     queue_work(nvmet_wq, &ctrl->async_event_work)\n\n  nvmet_add_async_event()\n     queue_work(nvmet_wq, &ctrl->async_event_work)\n\nB. Full pre-work chain (RDMA CM path):\n  nvmet_rdma_cm_handler()\n     nvmet_rdma_queue_disconnect()\n       __nvmet_rdma_queue_disconnect()\n         queue_work(nvmet_wq, &queue->release_work)\n           process_one_work()\n             lock((wq_completion)nvmet-wq)  <--------- 1st\n             nvmet_rdma_release_queue_work()\n\nC. Recursive path (same worker):\n  nvmet_rdma_release_queue_work()\n     nvmet_rdma_free_queue()\n       nvmet_sq_destroy()\n         nvmet_ctrl_put()\n           nvmet_ctrl_free()\n             flush_work(&ctrl->async_event_work)\n               __flush_work()\n                 touch_wq_lockdep_map()\n                 lock((wq_completion)nvmet-wq) <--------- 2nd\n\nLockdep splat:\n\n  ============================================\n  WARNING: possible recursive locking detected\n  6.19.0-rc3nvme+ #14 Tainted: G                 N\n  --------------------------------------------\n  kworker/u192:42/44933 is trying to acquire lock:\n  ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: touch_wq_lockdep_map+0x26/0x90\n\n  but task is already holding lock:\n  ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660\n\n  3 locks held by kworker/u192:42/44933:\n   #0: ffff888118a00948 ((wq_completion)nvmet-wq){+.+.}-{0:0}, at: process_one_work+0x53e/0x660\n   #1: ffffc9000e6cbe28 ((work_completion)(&queue->release_work)){+.+.}-{0:0}, at: process_one_work+0x1c5/0x660\n   #2: ffffffff82d4db60 (rcu_read_lock){....}-{1:3}, at: __flush_work+0x62/0x530\n\n  Workqueue: nvmet-wq nvmet_rdma_release_queue_work [nvmet_rdma]\n  Call Trace:\n   __flush_work+0x268/0x530\n   nvmet_ctrl_free+0x140/0x310 [nvmet]\n   nvmet_cq_put+0x74/0x90 [nvmet]\n   nvmet_rdma_free_queue+0x23/0xe0 [nvmet_rdma]\n   nvmet_rdma_release_queue_work+0x19/0x50 [nvmet_rdma]\n   process_one_work+0x206/0x660\n   worker_thread+0x184/0x320\n   kthread+0x10c/0x240\n   ret_from_fork+0x319/0x390\n\nMove async event work to a dedicated nvmet-aen-wq to avoid reentrant\nflush on nvmet-wq.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31557","epss":0.00441,"percentile":0.37129,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31557","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31560","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31560","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: spi-dw-dma: fix print error log when wait finish transaction  If an error occurs, the device may not have a current message. In this case, the system will crash.  In this case, it's better to use dev from the struct ctlr (struct spi_controller*).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31560","epss":0.00122,"percentile":0.02267,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31560","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31560","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/184f5aaf72f1f1c73e66bae0b8d28e81c2f2a72f","https://git.kernel.org/stable/c/3b46d61890632c8f8b117147b6923bff4b42ccb7","https://git.kernel.org/stable/c/aae4a47073b12c23eb1d2c5401bda442fbe27bd1","https://git.kernel.org/stable/c/b8188ff3cfaa5621212b08473488cdbe41f86531"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-dw-dma: fix print error log when wait finish transaction\n\nIf an error occurs, the device may not have a current message. In this\ncase, the system will crash.\n\nIn this case, it's better to use dev from the struct ctlr (struct spi_controller*).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31560","epss":0.00122,"percentile":0.02267,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31560","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31568","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31568","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/mm: Add missing secure storage access fixups for donated memory  There are special cases where secure storage access exceptions happen in a kernel context for pages that don't have the PG_arch_1 bit set. That bit is set for non-exported guest secure storage (memory) but is absent on storage donated to the Ultravisor since the kernel isn't allowed to export donated pages.  Prior to this patch we would try to export the page by calling arch_make_folio_accessible() which would instantly return since the arch bit is absent signifying that the page was already exported and no further action is necessary. This leads to secure storage access exception loops which can never be resolved.  With this patch we unconditionally try to export and if that fails we fixup.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31568","epss":0.00124,"percentile":0.02426,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31568","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09052},"relatedVulnerabilities":[{"id":"CVE-2026-31568","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31568","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/43ac2d18db1131df0a89993f709131ebfc29f3bd","https://git.kernel.org/stable/c/b00be77302d7ec4ad0367bb236494fce7172b730","https://git.kernel.org/stable/c/b36b0e804aee5f20c6798dbeaeaa7cfdb7c6cf88"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Add missing secure storage access fixups for donated memory\n\nThere are special cases where secure storage access exceptions happen\nin a kernel context for pages that don't have the PG_arch_1 bit\nset. That bit is set for non-exported guest secure storage (memory)\nbut is absent on storage donated to the Ultravisor since the kernel\nisn't allowed to export donated pages.\n\nPrior to this patch we would try to export the page by calling\narch_make_folio_accessible() which would instantly return since the\narch bit is absent signifying that the page was already exported and\nno further action is necessary. This leads to secure storage access\nexception loops which can never be resolved.\n\nWith this patch we unconditionally try to export and if that fails we\nfixup.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31568","epss":0.00124,"percentile":0.02426,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31568","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31568","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31579","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31579","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit  wg_netns_pre_exit() manually acquires rtnl_lock() inside the pernet .pre_exit callback.  This causes a hung task when another thread holds rtnl_mutex - the cleanup_net workqueue (or the setup_net failure rollback path) blocks indefinitely in wg_netns_pre_exit() waiting to acquire the lock.  Convert to .exit_rtnl, introduced in commit 7a60d91c690b (\"net: Add ->exit_rtnl() hook to struct pernet_operations.\"), where the framework already holds RTNL and batches all callbacks under a single rtnl_lock()/rtnl_unlock() pair, eliminating the contention window.  The rcu_assign_pointer(wg->creating_net, NULL) is safe to move from .pre_exit to .exit_rtnl (which runs after synchronize_rcu()) because all RCU readers of creating_net either use maybe_get_net() - which returns NULL for a dying namespace with zero refcount - or access net->user_ns which remains valid throughout the entire ops_undo_list sequence.  [ Jason: added __net_exit and __read_mostly annotations that were missing. ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31579","epss":0.00122,"percentile":0.02259,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31579","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31579","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31579","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1c52ef00e391144334f10995985c2f256d4be982","https://git.kernel.org/stable/c/60a25ef8dacb3566b1a8c4de00572a498e2a3bf9","https://git.kernel.org/stable/c/9a9e69155b2091b8297afaf1533b8d68a3096841","https://git.kernel.org/stable/c/a1d0f6cbb962af29586e3e65a4bced1a5e39221f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit\n\nwg_netns_pre_exit() manually acquires rtnl_lock() inside the\npernet .pre_exit callback.  This causes a hung task when another\nthread holds rtnl_mutex - the cleanup_net workqueue (or the\nsetup_net failure rollback path) blocks indefinitely in\nwg_netns_pre_exit() waiting to acquire the lock.\n\nConvert to .exit_rtnl, introduced in commit 7a60d91c690b (\"net:\nAdd ->exit_rtnl() hook to struct pernet_operations.\"), where the\nframework already holds RTNL and batches all callbacks under a\nsingle rtnl_lock()/rtnl_unlock() pair, eliminating the contention\nwindow.\n\nThe rcu_assign_pointer(wg->creating_net, NULL) is safe to move\nfrom .pre_exit to .exit_rtnl (which runs after synchronize_rcu())\nbecause all RCU readers of creating_net either use maybe_get_net()\n- which returns NULL for a dying namespace with zero refcount - or\naccess net->user_ns which remains valid throughout the entire\nops_undo_list sequence.\n\n[ Jason: added __net_exit and __read_mostly annotations that were missing. ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31579","epss":0.00122,"percentile":0.02259,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31579","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31579","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31592","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31592","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock  Take and hold kvm->lock for before checking sev_guest() in sev_mem_enc_register_region(), as sev_guest() isn't stable unless kvm->lock is held (or KVM can guarantee KVM_SEV_INIT{2} has completed and can't rollack state).  If KVM_SEV_INIT{2} fails, KVM can end up trying to add to a not-yet-initialized sev->regions_list, e.g. triggering a #GP    Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI   KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]   CPU: 110 UID: 0 PID: 72717 Comm: syz.15.11462 Tainted: G     U  W  O        6.16.0-smp-DEV #1 NONE   Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE   Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.52.0-0 10/28/2024   RIP: 0010:sev_mem_enc_register_region+0x3f0/0x4f0 ../include/linux/list.h:83   Code: <41> 80 3c 04 00 74 08 4c 89 ff e8 f1 c7 a2 00 49 39 ed 0f 84 c6 00   RSP: 0018:ffff88838647fbb8 EFLAGS: 00010256   RAX: dffffc0000000000 RBX: 1ffff92015cf1e0b RCX: dffffc0000000000   RDX: 0000000000000000 RSI: 0000000000001000 RDI: ffff888367870000   RBP: ffffc900ae78f050 R08: ffffea000d9e0007 R09: 1ffffd4001b3c000   R10: dffffc0000000000 R11: fffff94001b3c001 R12: 0000000000000000   R13: ffff8982ab0bde00 R14: ffffc900ae78f058 R15: 0000000000000000   FS:  00007f34e9dc66c0(0000) GS:ffff89ee64d33000(0000) knlGS:0000000000000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   CR2: 00007fe180adef98 CR3: 000000047210e000 CR4: 0000000000350ef0   Call Trace:    <TASK>    kvm_arch_vm_ioctl+0xa72/0x1240 ../arch/x86/kvm/x86.c:7371    kvm_vm_ioctl+0x649/0x990 ../virt/kvm/kvm_main.c:5363    __se_sys_ioctl+0x101/0x170 ../fs/ioctl.c:51    do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline]    do_syscall_64+0x6f/0x1f0 ../arch/x86/entry/syscall_64.c:94    entry_SYSCALL_64_after_hwframe+0x76/0x7e   RIP: 0033:0x7f34e9f7e9a9   Code: <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48   RSP: 002b:00007f34e9dc6038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010   RAX: ffffffffffffffda RBX: 00007f34ea1a6080 RCX: 00007f34e9f7e9a9   RDX: 0000200000000280 RSI: 000000008010aebb RDI: 0000000000000007   RBP: 00007f34ea000d69 R08: 0000000000000000 R09: 0000000000000000   R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000   R13: 0000000000000000 R14: 00007f34ea1a6080 R15: 00007ffce77197a8    </TASK>  with a syzlang reproducer that looks like:    syz_kvm_add_vcpu$x86(0x0, &(0x7f0000000040)={0x0, &(0x7f0000000180)=ANY=[], 0x70}) (async)   syz_kvm_add_vcpu$x86(0x0, &(0x7f0000000080)={0x0, &(0x7f0000000180)=ANY=[@ANYBLOB=\"...\"], 0x4f}) (async)   r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000200), 0x0, 0x0)   r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0)   r2 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0)   r3 = ioctl$KVM_CREATE_VM(r2, 0xae01, 0x0)   ioctl$KVM_SET_CLOCK(r3, 0xc008aeba, &(0x7f0000000040)={0x1, 0x8, 0x0, 0x5625e9b0}) (async)   ioctl$KVM_SET_PIT2(r3, 0x8010aebb, &(0x7f0000000280)={[...], 0x5}) (async)   ioctl$KVM_SET_PIT2(r1, 0x4070aea0, 0x0) (async)   r4 = ioctl$KVM_CREATE_VM(0xffffffffffffffff, 0xae01, 0x0)   openat$kvm(0xffffffffffffff9c, 0x0, 0x0, 0x0) (async)   ioctl$KVM_SET_USER_MEMORY_REGION(r4, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x2000, &(0x7f0000001000/0x2000)=nil}) (async)   r5 = ioctl$KVM_CREATE_VCPU(r4, 0xae41, 0x2)   close(r0) (async)   openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x8000, 0x0) (async)   ioctl$KVM_SET_GUEST_DEBUG(r5, 0x4048ae9b, &(0x7f0000000300)={0x4376ea830d46549b, 0x0, [0x46, 0x0, 0x0, 0x0, 0x0, 0x1000]}) (async)   ioctl$KVM_RUN(r5, 0xae80, 0x0)  Opportunistically use guard() to avoid having to define a new error label and goto usage.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31592","epss":0.00122,"percentile":0.02251,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31592","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31592","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31592","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0ff93ff0ba82e9511770e175fa50682a1ab14fb6","https://git.kernel.org/stable/c/35a0963d361f98bba798fd15d229dcb166c04684","https://git.kernel.org/stable/c/ab725ac3022469ecd4d7aa7d5646712e98b249d8","https://git.kernel.org/stable/c/b6408b6cec5df76a165575777800ef2aba12b109"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock\n\nTake and hold kvm->lock for before checking sev_guest() in\nsev_mem_enc_register_region(), as sev_guest() isn't stable unless kvm->lock\nis held (or KVM can guarantee KVM_SEV_INIT{2} has completed and can't\nrollack state).  If KVM_SEV_INIT{2} fails, KVM can end up trying to add to\na not-yet-initialized sev->regions_list, e.g. triggering a #GP\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  CPU: 110 UID: 0 PID: 72717 Comm: syz.15.11462 Tainted: G     U  W  O        6.16.0-smp-DEV #1 NONE\n  Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE\n  Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.52.0-0 10/28/2024\n  RIP: 0010:sev_mem_enc_register_region+0x3f0/0x4f0 ../include/linux/list.h:83\n  Code: <41> 80 3c 04 00 74 08 4c 89 ff e8 f1 c7 a2 00 49 39 ed 0f 84 c6 00\n  RSP: 0018:ffff88838647fbb8 EFLAGS: 00010256\n  RAX: dffffc0000000000 RBX: 1ffff92015cf1e0b RCX: dffffc0000000000\n  RDX: 0000000000000000 RSI: 0000000000001000 RDI: ffff888367870000\n  RBP: ffffc900ae78f050 R08: ffffea000d9e0007 R09: 1ffffd4001b3c000\n  R10: dffffc0000000000 R11: fffff94001b3c001 R12: 0000000000000000\n  R13: ffff8982ab0bde00 R14: ffffc900ae78f058 R15: 0000000000000000\n  FS:  00007f34e9dc66c0(0000) GS:ffff89ee64d33000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007fe180adef98 CR3: 000000047210e000 CR4: 0000000000350ef0\n  Call Trace:\n   <TASK>\n   kvm_arch_vm_ioctl+0xa72/0x1240 ../arch/x86/kvm/x86.c:7371\n   kvm_vm_ioctl+0x649/0x990 ../virt/kvm/kvm_main.c:5363\n   __se_sys_ioctl+0x101/0x170 ../fs/ioctl.c:51\n   do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline]\n   do_syscall_64+0x6f/0x1f0 ../arch/x86/entry/syscall_64.c:94\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  RIP: 0033:0x7f34e9f7e9a9\n  Code: <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\n  RSP: 002b:00007f34e9dc6038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n  RAX: ffffffffffffffda RBX: 00007f34ea1a6080 RCX: 00007f34e9f7e9a9\n  RDX: 0000200000000280 RSI: 000000008010aebb RDI: 0000000000000007\n  RBP: 00007f34ea000d69 R08: 0000000000000000 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n  R13: 0000000000000000 R14: 00007f34ea1a6080 R15: 00007ffce77197a8\n   </TASK>\n\nwith a syzlang reproducer that looks like:\n\n  syz_kvm_add_vcpu$x86(0x0, &(0x7f0000000040)={0x0, &(0x7f0000000180)=ANY=[], 0x70}) (async)\n  syz_kvm_add_vcpu$x86(0x0, &(0x7f0000000080)={0x0, &(0x7f0000000180)=ANY=[@ANYBLOB=\"...\"], 0x4f}) (async)\n  r0 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000200), 0x0, 0x0)\n  r1 = ioctl$KVM_CREATE_VM(r0, 0xae01, 0x0)\n  r2 = openat$kvm(0xffffffffffffff9c, &(0x7f0000000240), 0x0, 0x0)\n  r3 = ioctl$KVM_CREATE_VM(r2, 0xae01, 0x0)\n  ioctl$KVM_SET_CLOCK(r3, 0xc008aeba, &(0x7f0000000040)={0x1, 0x8, 0x0, 0x5625e9b0}) (async)\n  ioctl$KVM_SET_PIT2(r3, 0x8010aebb, &(0x7f0000000280)={[...], 0x5}) (async)\n  ioctl$KVM_SET_PIT2(r1, 0x4070aea0, 0x0) (async)\n  r4 = ioctl$KVM_CREATE_VM(0xffffffffffffffff, 0xae01, 0x0)\n  openat$kvm(0xffffffffffffff9c, 0x0, 0x0, 0x0) (async)\n  ioctl$KVM_SET_USER_MEMORY_REGION(r4, 0x4020ae46, &(0x7f0000000400)={0x0, 0x0, 0x0, 0x2000, &(0x7f0000001000/0x2000)=nil}) (async)\n  r5 = ioctl$KVM_CREATE_VCPU(r4, 0xae41, 0x2)\n  close(r0) (async)\n  openat$kvm(0xffffffffffffff9c, &(0x7f0000000000), 0x8000, 0x0) (async)\n  ioctl$KVM_SET_GUEST_DEBUG(r5, 0x4048ae9b, &(0x7f0000000300)={0x4376ea830d46549b, 0x0, [0x46, 0x0, 0x0, 0x0, 0x0, 0x1000]}) (async)\n  ioctl$KVM_RUN(r5, 0xae80, 0x0)\n\nOpportunistically use guard() to avoid having to define a new error label\nand goto usage.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31592","epss":0.00122,"percentile":0.02251,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31592","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31592","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31606","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31606","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_hid: don't call cdev_init while cdev in use  When calling unbind, then bind again, cdev_init reinitialized the cdev, even though there may still be references to it. That's the case when the /dev/hidg* device is still opened. This obviously unsafe behavior like oopes.  This fixes this by using cdev_alloc to put the cdev on the heap. That way, we can simply allocate a new one in hidg_bind.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31606","epss":0.00122,"percentile":0.02297,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31606","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31606","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5a229016ca3ac551294ec59770be9da94ec4bf63","https://git.kernel.org/stable/c/75ecc46828ec377dd5692c677168ef6d64fd7123","https://git.kernel.org/stable/c/81ebd43cc0d6d106ce7b6ccbf7b5e40ca7f5503d","https://git.kernel.org/stable/c/c6c0d13db5d0f8d465eabc14bd23d2b6a7247a43","https://git.kernel.org/stable/c/eb6ef6185f2054a341ec70d7e2165f5381744215"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_hid: don't call cdev_init while cdev in use\n\nWhen calling unbind, then bind again, cdev_init reinitialized the cdev,\neven though there may still be references to it. That's the case when\nthe /dev/hidg* device is still opened. This obviously unsafe behavior\nlike oopes.\n\nThis fixes this by using cdev_alloc to put the cdev on the heap. That\nway, we can simply allocate a new one in hidg_bind.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31606","epss":0.00122,"percentile":0.02297,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31606","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31648","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm: filemap: fix nr_pages calculation overflow in filemap_map_pages()  When running stress-ng on my Arm64 machine with v7.0-rc3 kernel, I encountered some very strange crash issues showing up as \"Bad page state\":  \" [  734.496287] BUG: Bad page state in process stress-ng-env  pfn:415735fb [  734.496427] page: refcount:0 mapcount:1 mapping:0000000000000000 index:0x4cf316 pfn:0x415735fb [  734.496434] flags: 0x57fffe000000800(owner_2|node=1|zone=2|lastcpupid=0x3ffff) [  734.496439] raw: 057fffe000000800 0000000000000000 dead000000000122 0000000000000000 [  734.496440] raw: 00000000004cf316 0000000000000000 0000000000000000 0000000000000000 [  734.496442] page dumped because: nonzero mapcount \"  After analyzing this page’s state, it is hard to understand why the mapcount is not 0 while the refcount is 0, since this page is not where the issue first occurred.  By enabling the CONFIG_DEBUG_VM config, I can reproduce the crash as well and captured the first warning where the issue appears:  \" [  734.469226] page: refcount:33 mapcount:0 mapping:00000000bef2d187 index:0x81a0 pfn:0x415735c0 [  734.469304] head: order:5 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [  734.469315] memcg:ffff000807a8ec00 [  734.469320] aops:ext4_da_aops ino:100b6f dentry name(?):\"stress-ng-mmaptorture-9397-0-2736200540\" [  734.469335] flags: 0x57fffe400000069(locked|uptodate|lru|head|node=1|zone=2|lastcpupid=0x3ffff) ...... [  734.469364] page dumped because: VM_WARN_ON_FOLIO((_Generic((page + nr_pages - 1), const struct page *: (const struct folio *)_compound_head(page + nr_pages - 1), struct page *: (struct folio *)_compound_head(page + nr_pages - 1))) != folio) [  734.469390] ------------[ cut here ]------------ [  734.469393] WARNING: ./include/linux/rmap.h:351 at folio_add_file_rmap_ptes+0x3b8/0x468, CPU#90: stress-ng-mlock/9430 [  734.469551]  folio_add_file_rmap_ptes+0x3b8/0x468 (P) [  734.469555]  set_pte_range+0xd8/0x2f8 [  734.469566]  filemap_map_folio_range+0x190/0x400 [  734.469579]  filemap_map_pages+0x348/0x638 [  734.469583]  do_fault_around+0x140/0x198 ...... [  734.469640]  el0t_64_sync+0x184/0x188 \"  The code that triggers the warning is: \"VM_WARN_ON_FOLIO(page_folio(page + nr_pages - 1) != folio, folio)\", which indicates that set_pte_range() tried to map beyond the large folio’s size.  By adding more debug information, I found that 'nr_pages' had overflowed in filemap_map_pages(), causing set_pte_range() to establish mappings for a range exceeding the folio size, potentially corrupting fields of pages that do not belong to this folio (e.g., page->_mapcount).  After above analysis, I think the possible race is as follows:  CPU 0                                                  CPU 1 filemap_map_pages()                                   ext4_setattr()    //get and lock folio with old inode->i_size    next_uptodate_folio()                                                            .......                                                           //shrink the inode->i_size                                                           i_size_write(inode, attr->ia_size);     //calculate the end_pgoff with the new inode->i_size    file_end = DIV_ROUND_UP(i_size_read(mapping->host), PAGE_SIZE) - 1;    end_pgoff = min(end_pgoff, file_end);     ......    //nr_pages can be overflowed, cause xas.xa_index > end_pgoff    end = folio_next_index(folio) - 1;    nr_pages = min(end, end_pgoff) - xas.xa_index + 1;     ......    //map large folio    filemap_map_folio_range()                                                           ......                                                           //truncate folios                                                           truncate_pagecache(inode, inode->i_size);  To fix this issue, move the 'end_pgoff' calculation before next_uptodate_folio(), so the retrieved folio stays consistent with the file end to avoid  ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31648","epss":0.0012,"percentile":0.02046,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31648","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-31648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31648","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/576543bedd616254032d4ebe54a90076f9e31740","https://git.kernel.org/stable/c/633ab680c405ac390e6bec5b74aaf46197c837b6","https://git.kernel.org/stable/c/88591194df736a508dd5461ab2167a61e98caac1","https://git.kernel.org/stable/c/9316a820b9aae07d44469d6485376dad824c5b3f","https://git.kernel.org/stable/c/f58df566524ebcdfa394329c64f47e3c9257516e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: filemap: fix nr_pages calculation overflow in filemap_map_pages()\n\nWhen running stress-ng on my Arm64 machine with v7.0-rc3 kernel, I\nencountered some very strange crash issues showing up as \"Bad page state\":\n\n\"\n[  734.496287] BUG: Bad page state in process stress-ng-env  pfn:415735fb\n[  734.496427] page: refcount:0 mapcount:1 mapping:0000000000000000 index:0x4cf316 pfn:0x415735fb\n[  734.496434] flags: 0x57fffe000000800(owner_2|node=1|zone=2|lastcpupid=0x3ffff)\n[  734.496439] raw: 057fffe000000800 0000000000000000 dead000000000122 0000000000000000\n[  734.496440] raw: 00000000004cf316 0000000000000000 0000000000000000 0000000000000000\n[  734.496442] page dumped because: nonzero mapcount\n\"\n\nAfter analyzing this page’s state, it is hard to understand why the\nmapcount is not 0 while the refcount is 0, since this page is not where\nthe issue first occurred.  By enabling the CONFIG_DEBUG_VM config, I can\nreproduce the crash as well and captured the first warning where the issue\nappears:\n\n\"\n[  734.469226] page: refcount:33 mapcount:0 mapping:00000000bef2d187 index:0x81a0 pfn:0x415735c0\n[  734.469304] head: order:5 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n[  734.469315] memcg:ffff000807a8ec00\n[  734.469320] aops:ext4_da_aops ino:100b6f dentry name(?):\"stress-ng-mmaptorture-9397-0-2736200540\"\n[  734.469335] flags: 0x57fffe400000069(locked|uptodate|lru|head|node=1|zone=2|lastcpupid=0x3ffff)\n......\n[  734.469364] page dumped because: VM_WARN_ON_FOLIO((_Generic((page + nr_pages - 1),\nconst struct page *: (const struct folio *)_compound_head(page + nr_pages - 1), struct page *:\n(struct folio *)_compound_head(page + nr_pages - 1))) != folio)\n[  734.469390] ------------[ cut here ]------------\n[  734.469393] WARNING: ./include/linux/rmap.h:351 at folio_add_file_rmap_ptes+0x3b8/0x468,\nCPU#90: stress-ng-mlock/9430\n[  734.469551]  folio_add_file_rmap_ptes+0x3b8/0x468 (P)\n[  734.469555]  set_pte_range+0xd8/0x2f8\n[  734.469566]  filemap_map_folio_range+0x190/0x400\n[  734.469579]  filemap_map_pages+0x348/0x638\n[  734.469583]  do_fault_around+0x140/0x198\n......\n[  734.469640]  el0t_64_sync+0x184/0x188\n\"\n\nThe code that triggers the warning is: \"VM_WARN_ON_FOLIO(page_folio(page +\nnr_pages - 1) != folio, folio)\", which indicates that set_pte_range()\ntried to map beyond the large folio’s size.\n\nBy adding more debug information, I found that 'nr_pages' had overflowed\nin filemap_map_pages(), causing set_pte_range() to establish mappings for\na range exceeding the folio size, potentially corrupting fields of pages\nthat do not belong to this folio (e.g., page->_mapcount).\n\nAfter above analysis, I think the possible race is as follows:\n\nCPU 0                                                  CPU 1\nfilemap_map_pages()                                   ext4_setattr()\n   //get and lock folio with old inode->i_size\n   next_uptodate_folio()\n\n                                                          .......\n                                                          //shrink the inode->i_size\n                                                          i_size_write(inode, attr->ia_size);\n\n   //calculate the end_pgoff with the new inode->i_size\n   file_end = DIV_ROUND_UP(i_size_read(mapping->host), PAGE_SIZE) - 1;\n   end_pgoff = min(end_pgoff, file_end);\n\n   ......\n   //nr_pages can be overflowed, cause xas.xa_index > end_pgoff\n   end = folio_next_index(folio) - 1;\n   nr_pages = min(end, end_pgoff) - xas.xa_index + 1;\n\n   ......\n   //map large folio\n   filemap_map_folio_range()\n                                                          ......\n                                                          //truncate folios\n                                                          truncate_pagecache(inode, inode->i_size);\n\nTo fix this issue, move the 'end_pgoff' calculation before\nnext_uptodate_folio(), so the retrieved folio stays consistent with the\nfile end to avoid \n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31648","epss":0.0012,"percentile":0.02046,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31648","cwe":"CWE-190","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31648","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31655","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31655","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled  Keep the NOC_HDCP clock always enabled to fix the potential hang caused by the NoC ADB400 port power down handshake.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31655","epss":0.00114,"percentile":0.01634,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-31655","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31655","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3086374e8bc7fd65f2cc62ef52351c6d662f1543","https://git.kernel.org/stable/c/80fd0de89805a3f92dc320f5ab5a18007c260374","https://git.kernel.org/stable/c/d1ef779d02b5df4e8bff4083b20bfea587b43c4b","https://git.kernel.org/stable/c/e44919669f07b8f113ad49a248b44ca4f119bc94","https://git.kernel.org/stable/c/e91d5f94acf68618ea3ad9c92ac28614e791ae7d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled\n\nKeep the NOC_HDCP clock always enabled to fix the potential hang\ncaused by the NoC ADB400 port power down handshake.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31655","epss":0.00114,"percentile":0.01634,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31655","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31663","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31663","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: hold dev ref until after transport_finish NF_HOOK  After async crypto completes, xfrm_input_resume() calls dev_put() immediately on re-entry before the skb reaches transport_finish. The skb->dev pointer is then used inside NF_HOOK and its okfn, which can race with device teardown.  Remove the dev_put from the async resumption entry and instead drop the reference after the NF_HOOK call in transport_finish, using a saved device pointer since NF_HOOK may consume the skb. This covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip the okfn.  For non-transport exits (decaps, gro, drop) and secondary async return points, release the reference inline when async is set.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31663","epss":0.00124,"percentile":0.0241,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31663","cwe":"CWE-826","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0899},"relatedVulnerabilities":[{"id":"CVE-2026-31663","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31663","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0f451b43c88bf2b9c038b414be580efee42e031b","https://git.kernel.org/stable/c/1c428b03840094410c5fb6a5db30640486bbbfcb","https://git.kernel.org/stable/c/4236c30b437b80f673b9e08c8fae38b8d471ac9e","https://git.kernel.org/stable/c/5002beda5cac69d522dc54da0d5d463ed9c963d2","https://access.redhat.com/security/cve/CVE-2026-31663","https://bugzilla.redhat.com/show_bug.cgi?id=2461462","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31663.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: hold dev ref until after transport_finish NF_HOOK\n\nAfter async crypto completes, xfrm_input_resume() calls dev_put()\nimmediately on re-entry before the skb reaches transport_finish.\nThe skb->dev pointer is then used inside NF_HOOK and its okfn,\nwhich can race with device teardown.\n\nRemove the dev_put from the async resumption entry and instead\ndrop the reference after the NF_HOOK call in transport_finish,\nusing a saved device pointer since NF_HOOK may consume the skb.\nThis covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip\nthe okfn.\n\nFor non-transport exits (decaps, gro, drop) and secondary\nasync return points, release the reference inline when\nasync is set.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31663","epss":0.00124,"percentile":0.0241,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31663","cwe":"CWE-826","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31663","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31675","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31675","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: sch_netem: fix out-of-bounds access in packet corruption  In netem_enqueue(), the packet corruption logic uses get_random_u32_below(skb_headlen(skb)) to select an index for modifying skb->data. When an AF_PACKET TX_RING sends fully non-linear packets over an IPIP tunnel, skb_headlen(skb) evaluates to 0.  Passing 0 to get_random_u32_below() takes the variable-ceil slow path which returns an unconstrained 32-bit random integer. Using this unconstrained value as an offset into skb->data results in an out-of-bounds memory access.  Fix this by verifying skb_headlen(skb) is non-zero before attempting to corrupt the linear data area. Fully non-linear packets will silently bypass the corruption logic.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31675","epss":0.00126,"percentile":0.02628,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31675","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-31675","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31675","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/13a66ca1e235d4bcd53d12d4c68490cad7f8e46f","https://git.kernel.org/stable/c/3a2999704ac36cfb4041fed3652d26a3373e8d12","https://git.kernel.org/stable/c/4fd258e281fa8bc15e9ce2c7691941537e9258ad","https://git.kernel.org/stable/c/a14b56863348686dd0387eea8ce66b85cf455908","https://git.kernel.org/stable/c/d64cb81dcbd54927515a7f65e5e24affdc73c14b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_netem: fix out-of-bounds access in packet corruption\n\nIn netem_enqueue(), the packet corruption logic uses\nget_random_u32_below(skb_headlen(skb)) to select an index for\nmodifying skb->data. When an AF_PACKET TX_RING sends fully non-linear\npackets over an IPIP tunnel, skb_headlen(skb) evaluates to 0.\n\nPassing 0 to get_random_u32_below() takes the variable-ceil slow path\nwhich returns an unconstrained 32-bit random integer. Using this\nunconstrained value as an offset into skb->data results in an\nout-of-bounds memory access.\n\nFix this by verifying skb_headlen(skb) is non-zero before attempting\nto corrupt the linear data area. Fully non-linear packets will silently\nbypass the corruption logic.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31675","epss":0.00126,"percentile":0.02628,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31675","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31675","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31677","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31677","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: af_alg - limit RX SG extraction by receive buffer budget  Make af_alg_get_rsgl() limit each RX scatterlist extraction to the remaining receive buffer budget.  af_alg_get_rsgl() currently uses af_alg_readable() only as a gate before extracting data into the RX scatterlist. Limit each extraction to the remaining af_alg_rcvbuf(sk) budget so that receive-side accounting matches the amount of data attached to the request.  If skcipher cannot obtain enough RX space for at least one chunk while more data remains to be processed, reject the recvmsg call instead of rounding the request length down to zero.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31677","epss":0.00114,"percentile":0.01658,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-31677","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31677","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/07c6f6ffe29009426f0bd4d3cfbb6308b8ea8453","https://git.kernel.org/stable/c/4a264b2614c73c96666e196bbabe0cead52bdba7","https://git.kernel.org/stable/c/8eceab19eba9dcbfd2a0daec72e1bf48aa100170","https://git.kernel.org/stable/c/9bf3e6ccfdcfe56ae3190d1ae987dacf1cfef4f9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: af_alg - limit RX SG extraction by receive buffer budget\n\nMake af_alg_get_rsgl() limit each RX scatterlist extraction to the\nremaining receive buffer budget.\n\naf_alg_get_rsgl() currently uses af_alg_readable() only as a gate\nbefore extracting data into the RX scatterlist. Limit each extraction\nto the remaining af_alg_rcvbuf(sk) budget so that receive-side\naccounting matches the amount of data attached to the request.\n\nIf skcipher cannot obtain enough RX space for at least one chunk while\nmore data remains to be processed, reject the recvmsg call instead of\nrounding the request length down to zero.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31677","epss":0.00114,"percentile":0.01658,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31677","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31692","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31692","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rtnetlink: add missing netlink_ns_capable() check for peer netns  rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the peer network namespace when creating paired devices (veth, vxcan, netkit). This allows an unprivileged user with a user namespace to create interfaces in arbitrary network namespaces, including init_net.  Add a netlink_ns_capable() check for CAP_NET_ADMIN in the peer namespace before allowing device creation to proceed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31692","epss":0.00119,"percentile":0.0199,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-31692","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31692","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0975b64ffb34560042090a5986c3a02e6c80f36f","https://git.kernel.org/stable/c/7b735ef81286007794a227ce2539419479c02a5f","https://git.kernel.org/stable/c/d04cc16d3624218a5458b2b664ae431f1b3b334d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrtnetlink: add missing netlink_ns_capable() check for peer netns\n\nrtnl_newlink() lacks a CAP_NET_ADMIN capability check on the peer\nnetwork namespace when creating paired devices (veth, vxcan,\nnetkit). This allows an unprivileged user with a user namespace\nto create interfaces in arbitrary network namespaces, including\ninit_net.\n\nAdd a netlink_ns_capable() check for CAP_NET_ADMIN in the peer\nnamespace before allowing device creation to proceed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31692","epss":0.00119,"percentile":0.0199,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31692","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31706","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31706","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()  smb_inherit_dacl() trusts the on-disk num_aces value from the parent directory's DACL xattr and uses it to size a heap allocation:    aces_base = kmalloc(sizeof(struct smb_ace) * num_aces * 2, ...);  num_aces is a u16 read from le16_to_cpu(parent_pdacl->num_aces) without checking that it is consistent with the declared pdacl_size. An authenticated client whose parent directory's security.NTACL is tampered (e.g. via offline xattr corruption or a concurrent path that bypasses parse_dacl()) can present num_aces = 65535 with minimal actual ACE data.  This causes a ~8 MB allocation (not kzalloc, so uninitialized) that the subsequent loop only partially populates, and may also overflow the three-way size_t multiply on 32-bit kernels.  Additionally, the ACE walk loop uses the weaker offsetof(struct smb_ace, access_req) minimum size check rather than the minimum valid on-wire ACE size, and does not reject ACEs whose declared size is below the minimum.  Reproduced on UML + KASAN + LOCKDEP against the real ksmbd code path. A legitimate mount.cifs client creates a parent directory over SMB (ksmbd writes a valid security.NTACL xattr), then the NTACL blob on the backing filesystem is rewritten to set num_aces = 0xFFFF while keeping the posix_acl_hash bytes intact so ksmbd_vfs_get_sd_xattr()'s hash check still passes.  A subsequent SMB2 CREATE of a child under that parent drives smb2_open() into smb_inherit_dacl() (share has \"vfs objects = acl_xattr\" set), which fails the page allocator:    WARNING: mm/page_alloc.c:5226 at __alloc_frozen_pages_noprof+0x46c/0x9c0   Workqueue: ksmbd-io handle_ksmbd_work    __alloc_frozen_pages_noprof+0x46c/0x9c0    ___kmalloc_large_node+0x68/0x130    __kmalloc_large_node_noprof+0x24/0x70    __kmalloc_noprof+0x4c9/0x690    smb_inherit_dacl+0x394/0x2430    smb2_open+0x595d/0xabe0    handle_ksmbd_work+0x3d3/0x1140  With the patch applied the added guard rejects the tampered value with -EINVAL before any large allocation runs, smb2_open() falls back to smb2_create_sd_buffer(), and the child is created with a default SD.  No warning, no splat.  Fix by:    1. Validating num_aces against pdacl_size using the same formula      applied in parse_dacl().    2. Replacing the raw kmalloc(sizeof * num_aces * 2) with      kmalloc_array(num_aces * 2, sizeof(...)) for overflow-safe      allocation.    3. Tightening the per-ACE loop guard to require the minimum valid      ACE size (offsetof(smb_ace, sid) + CIFS_SID_BASE_SIZE) and      rejecting under-sized ACEs, matching the hardening in      smb_check_perm_dacl() and parse_dacl().  v1 -> v2:   - Replace the synthetic test-module splat in the changelog with a     real-path UML + KASAN reproduction driven through mount.cifs and     SMB2 CREATE; Namjae flagged the kcifs3_test_inherit_dacl_old name     in v1 since it does not exist in ksmbd.   - Drop the commit-hash citation from the code comment per Namjae's     review; keep the parse_dacl() pointer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31706","epss":0.00369,"percentile":0.30157,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.30073500000000003},"relatedVulnerabilities":[{"id":"CVE-2026-31706","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31706","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/063a7409b0de46d7c770b65bb0338e6fdb3b1f0a","https://git.kernel.org/stable/c/3e4e2ea2a781018ed5d75f969e3e5606beb66e48","https://git.kernel.org/stable/c/3e5360b422dd741cb315654a191fa73869a37414","https://git.kernel.org/stable/c/59c32abaaec9cdd6164811c7e864e72f7554b82d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()\n\nsmb_inherit_dacl() trusts the on-disk num_aces value from the parent\ndirectory's DACL xattr and uses it to size a heap allocation:\n\n  aces_base = kmalloc(sizeof(struct smb_ace) * num_aces * 2, ...);\n\nnum_aces is a u16 read from le16_to_cpu(parent_pdacl->num_aces)\nwithout checking that it is consistent with the declared pdacl_size.\nAn authenticated client whose parent directory's security.NTACL is\ntampered (e.g. via offline xattr corruption or a concurrent path that\nbypasses parse_dacl()) can present num_aces = 65535 with minimal\nactual ACE data.  This causes a ~8 MB allocation (not kzalloc, so\nuninitialized) that the subsequent loop only partially populates, and\nmay also overflow the three-way size_t multiply on 32-bit kernels.\n\nAdditionally, the ACE walk loop uses the weaker\noffsetof(struct smb_ace, access_req) minimum size check rather than\nthe minimum valid on-wire ACE size, and does not reject ACEs whose\ndeclared size is below the minimum.\n\nReproduced on UML + KASAN + LOCKDEP against the real ksmbd code path.\nA legitimate mount.cifs client creates a parent directory over SMB\n(ksmbd writes a valid security.NTACL xattr), then the NTACL blob on\nthe backing filesystem is rewritten to set num_aces = 0xFFFF while\nkeeping the posix_acl_hash bytes intact so ksmbd_vfs_get_sd_xattr()'s\nhash check still passes.  A subsequent SMB2 CREATE of a child under\nthat parent drives smb2_open() into smb_inherit_dacl() (share has\n\"vfs objects = acl_xattr\" set), which fails the page allocator:\n\n  WARNING: mm/page_alloc.c:5226 at __alloc_frozen_pages_noprof+0x46c/0x9c0\n  Workqueue: ksmbd-io handle_ksmbd_work\n   __alloc_frozen_pages_noprof+0x46c/0x9c0\n   ___kmalloc_large_node+0x68/0x130\n   __kmalloc_large_node_noprof+0x24/0x70\n   __kmalloc_noprof+0x4c9/0x690\n   smb_inherit_dacl+0x394/0x2430\n   smb2_open+0x595d/0xabe0\n   handle_ksmbd_work+0x3d3/0x1140\n\nWith the patch applied the added guard rejects the tampered value\nwith -EINVAL before any large allocation runs, smb2_open() falls back\nto smb2_create_sd_buffer(), and the child is created with a default\nSD.  No warning, no splat.\n\nFix by:\n\n  1. Validating num_aces against pdacl_size using the same formula\n     applied in parse_dacl().\n\n  2. Replacing the raw kmalloc(sizeof * num_aces * 2) with\n     kmalloc_array(num_aces * 2, sizeof(...)) for overflow-safe\n     allocation.\n\n  3. Tightening the per-ACE loop guard to require the minimum valid\n     ACE size (offsetof(smb_ace, sid) + CIFS_SID_BASE_SIZE) and\n     rejecting under-sized ACEs, matching the hardening in\n     smb_check_perm_dacl() and parse_dacl().\n\nv1 -> v2:\n  - Replace the synthetic test-module splat in the changelog with a\n    real-path UML + KASAN reproduction driven through mount.cifs and\n    SMB2 CREATE; Namjae flagged the kcifs3_test_inherit_dacl_old name\n    in v1 since it does not exist in ksmbd.\n  - Drop the commit-hash citation from the code comment per Namjae's\n    review; keep the parse_dacl() pointer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31706","epss":0.00369,"percentile":0.30157,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31706","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31707","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31707","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate response sizes in ipc_validate_msg()  ipc_validate_msg() computes the expected message size for each response type by adding (or multiplying) attacker-controlled fields from the daemon response to a fixed struct size in unsigned int arithmetic.  Three cases can overflow:    KSMBD_EVENT_RPC_REQUEST:       msg_sz = sizeof(struct ksmbd_rpc_command) + resp->payload_sz;   KSMBD_EVENT_SHARE_CONFIG_REQUEST:       msg_sz = sizeof(struct ksmbd_share_config_response) +                resp->payload_sz;   KSMBD_EVENT_LOGIN_REQUEST_EXT:       msg_sz = sizeof(struct ksmbd_login_response_ext) +                resp->ngroups * sizeof(gid_t);  resp->payload_sz is __u32 and resp->ngroups is __s32.  Each addition can wrap in unsigned int; the multiplication by sizeof(gid_t) mixes signed and size_t, so a negative ngroups is converted to SIZE_MAX before the multiply.  A wrapped value of msg_sz that happens to equal entry->msg_sz bypasses the size check on the next line, and downstream consumers (smb2pdu.c:6742 memcpy using rpc_resp->payload_sz, kmemdup in ksmbd_alloc_user using resp_ext->ngroups) then trust the unverified length.  Use check_add_overflow() on the RPC_REQUEST and SHARE_CONFIG_REQUEST paths to detect integer overflow without constraining functional payload size; userspace ksmbd-tools grows NDR responses in 4096-byte chunks for calls like NetShareEnumAll, so a hard transport cap is unworkable on the response side.  For LOGIN_REQUEST_EXT, reject resp->ngroups outside the signed [0, NGROUPS_MAX] range up front and report the error from ipc_validate_msg() so it fires at the IPC boundary; with that bound the subsequent multiplication and addition stay well below UINT_MAX.  The now-redundant ngroups check and pr_err in ksmbd_alloc_user() are removed.  This is the response-side analogue of aab98e2dbd64 (\"ksmbd: fix integer overflows on 32 bit systems\"), which hardened the request side.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31707","epss":0.00125,"percentile":0.02509,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31707","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09125},"relatedVulnerabilities":[{"id":"CVE-2026-31707","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31707","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/299db777ea0cfa5c407e41b045c24a14c034c27b","https://git.kernel.org/stable/c/7dd0c858e1909769a4c91842724315ee74f1a5f1","https://git.kernel.org/stable/c/99c631d0366c1eab8fb188fe66425f4581ebdde4","https://git.kernel.org/stable/c/bf396208418371174869baba9434535cd3288e80","https://git.kernel.org/stable/c/d6a6aa81eac2c9bff66dc6e191179cb69a14426b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate response sizes in ipc_validate_msg()\n\nipc_validate_msg() computes the expected message size for each\nresponse type by adding (or multiplying) attacker-controlled fields\nfrom the daemon response to a fixed struct size in unsigned int\narithmetic.  Three cases can overflow:\n\n  KSMBD_EVENT_RPC_REQUEST:\n      msg_sz = sizeof(struct ksmbd_rpc_command) + resp->payload_sz;\n  KSMBD_EVENT_SHARE_CONFIG_REQUEST:\n      msg_sz = sizeof(struct ksmbd_share_config_response) +\n               resp->payload_sz;\n  KSMBD_EVENT_LOGIN_REQUEST_EXT:\n      msg_sz = sizeof(struct ksmbd_login_response_ext) +\n               resp->ngroups * sizeof(gid_t);\n\nresp->payload_sz is __u32 and resp->ngroups is __s32.  Each addition\ncan wrap in unsigned int; the multiplication by sizeof(gid_t) mixes\nsigned and size_t, so a negative ngroups is converted to SIZE_MAX\nbefore the multiply.  A wrapped value of msg_sz that happens to\nequal entry->msg_sz bypasses the size check on the next line, and\ndownstream consumers (smb2pdu.c:6742 memcpy using rpc_resp->payload_sz,\nkmemdup in ksmbd_alloc_user using resp_ext->ngroups) then trust the\nunverified length.\n\nUse check_add_overflow() on the RPC_REQUEST and SHARE_CONFIG_REQUEST\npaths to detect integer overflow without constraining functional\npayload size; userspace ksmbd-tools grows NDR responses in 4096-byte\nchunks for calls like NetShareEnumAll, so a hard transport cap is\nunworkable on the response side.  For LOGIN_REQUEST_EXT, reject\nresp->ngroups outside the signed [0, NGROUPS_MAX] range up front and\nreport the error from ipc_validate_msg() so it fires at the IPC\nboundary; with that bound the subsequent multiplication and addition\nstay well below UINT_MAX.  The now-redundant ngroups check and\npr_err in ksmbd_alloc_user() are removed.\n\nThis is the response-side analogue of aab98e2dbd64 (\"ksmbd: fix\ninteger overflows on 32 bit systems\"), which hardened the request\nside.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31707","epss":0.00125,"percentile":0.02509,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31707","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31707","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31722","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31722","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_rndis: Fix net_device lifecycle with device_move  The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks:    console:/ # ls -l /sys/class/net/usb0   lrwxrwxrwx ... /sys/class/net/usb0 ->   /sys/devices/platform/.../gadget.0/net/usb0   console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0   ls: .../gadget.0/net/usb0: No such file or directory  Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering.  To maintain compatibility with legacy composite drivers (e.g., multi.c), the borrowed_net flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31722","epss":0.00122,"percentile":0.0226,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31722","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31722","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/18ada801899f2b13ef0ceff42427ad980a41e619","https://git.kernel.org/stable/c/1ef251aa63972fe6c0f107f5abd139b7d0f7987a","https://git.kernel.org/stable/c/6045ea5ca6e3fa13f8a9fafb1c535c86e124c14d","https://git.kernel.org/stable/c/e367599529dc42578545a7f85fde517b35b3cda7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_rndis: Fix net_device lifecycle with device_move\n\nThe net_device is allocated during function instance creation and\nregistered during the bind phase with the gadget device as its sysfs\nparent. When the function unbinds, the parent device is destroyed, but\nthe net_device survives, resulting in dangling sysfs symlinks:\n\n  console:/ # ls -l /sys/class/net/usb0\n  lrwxrwxrwx ... /sys/class/net/usb0 ->\n  /sys/devices/platform/.../gadget.0/net/usb0\n  console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0\n  ls: .../gadget.0/net/usb0: No such file or directory\n\nUse device_move() to reparent the net_device between the gadget device\ntree and /sys/devices/virtual across bind and unbind cycles. During the\nfinal unbind, calling device_move(NULL) moves the net_device to the\nvirtual device tree before the gadget device is destroyed. On rebinding,\ndevice_move() reparents the device back under the new gadget, ensuring\nproper sysfs topology and power management ordering.\n\nTo maintain compatibility with legacy composite drivers (e.g., multi.c),\nthe borrowed_net flag is used to indicate whether the network device is\nshared and pre-registered during the legacy driver's bind phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31722","epss":0.00122,"percentile":0.0226,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31722","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31723","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31723","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_subset: Fix net_device lifecycle with device_move  The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks:    console:/ # ls -l /sys/class/net/usb0   lrwxrwxrwx ... /sys/class/net/usb0 ->   /sys/devices/platform/.../gadget.0/net/usb0   console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0   ls: .../gadget.0/net/usb0: No such file or directory  Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering.  To maintain compatibility with legacy composite drivers (e.g., multi.c), the bound flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31723","epss":0.00122,"percentile":0.0225,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31723","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31723","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/06524cd1c9011bee141a87e43ab878641ed3652b","https://git.kernel.org/stable/c/70707ce668494c4d35fe070dfbc7cc541b293107","https://git.kernel.org/stable/c/9cbc4f109bb216623894d8819fb930210ed34b21","https://git.kernel.org/stable/c/fde29916e4cc736c4ca6c78f331e12b2c73ccafd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_subset: Fix net_device lifecycle with device_move\n\nThe net_device is allocated during function instance creation and\nregistered during the bind phase with the gadget device as its sysfs\nparent. When the function unbinds, the parent device is destroyed, but\nthe net_device survives, resulting in dangling sysfs symlinks:\n\n  console:/ # ls -l /sys/class/net/usb0\n  lrwxrwxrwx ... /sys/class/net/usb0 ->\n  /sys/devices/platform/.../gadget.0/net/usb0\n  console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0\n  ls: .../gadget.0/net/usb0: No such file or directory\n\nUse device_move() to reparent the net_device between the gadget device\ntree and /sys/devices/virtual across bind and unbind cycles. During the\nfinal unbind, calling device_move(NULL) moves the net_device to the\nvirtual device tree before the gadget device is destroyed. On rebinding,\ndevice_move() reparents the device back under the new gadget, ensuring\nproper sysfs topology and power management ordering.\n\nTo maintain compatibility with legacy composite drivers (e.g., multi.c),\nthe bound flag is used to indicate whether the network device is shared\nand pre-registered during the legacy driver's bind phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31723","epss":0.00122,"percentile":0.0225,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31723","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31724","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31724","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_eem: Fix net_device lifecycle with device_move  The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks:  console:/ # ls -l /sys/class/net/usb0 lrwxrwxrwx ... /sys/class/net/usb0 -> /sys/devices/platform/.../gadget.0/net/usb0 console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0 ls: .../gadget.0/net/usb0: No such file or directory  Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering.  To maintain compatibility with legacy composite drivers (e.g., multi.c), the bound flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31724","epss":0.00122,"percentile":0.0225,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31724","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31724","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/14730506b9e2a09d10c963a57a72ed528482fc15","https://git.kernel.org/stable/c/4ccdccff8febc5456aff684627f9a4c5c83b9346","https://git.kernel.org/stable/c/a6b8bce01a30a8c05c034bbc36c34845d65d644f","https://git.kernel.org/stable/c/d9270c9a8118c1535409db926ac1e2545dc97b81"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_eem: Fix net_device lifecycle with device_move\n\nThe net_device is allocated during function instance creation and\nregistered during the bind phase with the gadget device as its sysfs\nparent. When the function unbinds, the parent device is destroyed, but\nthe net_device survives, resulting in dangling sysfs symlinks:\n\nconsole:/ # ls -l /sys/class/net/usb0\nlrwxrwxrwx ... /sys/class/net/usb0 ->\n/sys/devices/platform/.../gadget.0/net/usb0\nconsole:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0\nls: .../gadget.0/net/usb0: No such file or directory\n\nUse device_move() to reparent the net_device between the gadget device\ntree and /sys/devices/virtual across bind and unbind cycles. During the\nfinal unbind, calling device_move(NULL) moves the net_device to the\nvirtual device tree before the gadget device is destroyed. On rebinding,\ndevice_move() reparents the device back under the new gadget, ensuring\nproper sysfs topology and power management ordering.\n\nTo maintain compatibility with legacy composite drivers (e.g., multi.c),\nthe bound flag is used to indicate whether the network device is shared\nand pre-registered during the legacy driver's bind phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31724","epss":0.00122,"percentile":0.0225,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31724","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31725","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31725","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_ecm: Fix net_device lifecycle with device_move  The net_device is allocated during function instance creation and registered during the bind phase with the gadget device as its sysfs parent. When the function unbinds, the parent device is destroyed, but the net_device survives, resulting in dangling sysfs symlinks:    console:/ # ls -l /sys/class/net/usb0   lrwxrwxrwx ... /sys/class/net/usb0 ->   /sys/devices/platform/.../gadget.0/net/usb0   console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0   ls: .../gadget.0/net/usb0: No such file or directory  Use device_move() to reparent the net_device between the gadget device tree and /sys/devices/virtual across bind and unbind cycles. During the final unbind, calling device_move(NULL) moves the net_device to the virtual device tree before the gadget device is destroyed. On rebinding, device_move() reparents the device back under the new gadget, ensuring proper sysfs topology and power management ordering.  To maintain compatibility with legacy composite drivers (e.g., multi.c), the bound flag is used to indicate whether the network device is shared and pre-registered during the legacy driver's bind phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31725","epss":0.00122,"percentile":0.0225,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31725","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31725","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4e34f3f491fd731809b57ddb5329ec763bd39553","https://git.kernel.org/stable/c/5eaeac22240d965d24c3bd0c54ded64efd8f6ca1","https://git.kernel.org/stable/c/9b1e5589593293c78a2ab8bb118a41e2271a2af8","https://git.kernel.org/stable/c/b2cc4fae67a51f60d81d6af2678696accb07c656"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ecm: Fix net_device lifecycle with device_move\n\nThe net_device is allocated during function instance creation and\nregistered during the bind phase with the gadget device as its sysfs\nparent. When the function unbinds, the parent device is destroyed, but\nthe net_device survives, resulting in dangling sysfs symlinks:\n\n  console:/ # ls -l /sys/class/net/usb0\n  lrwxrwxrwx ... /sys/class/net/usb0 ->\n  /sys/devices/platform/.../gadget.0/net/usb0\n  console:/ # ls -l /sys/devices/platform/.../gadget.0/net/usb0\n  ls: .../gadget.0/net/usb0: No such file or directory\n\nUse device_move() to reparent the net_device between the gadget device\ntree and /sys/devices/virtual across bind and unbind cycles. During the\nfinal unbind, calling device_move(NULL) moves the net_device to the\nvirtual device tree before the gadget device is destroyed. On rebinding,\ndevice_move() reparents the device back under the new gadget, ensuring\nproper sysfs topology and power management ordering.\n\nTo maintain compatibility with legacy composite drivers (e.g., multi.c),\nthe bound flag is used to indicate whether the network device is shared\nand pre-registered during the legacy driver's bind phase.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31725","epss":0.00122,"percentile":0.0225,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31725","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31729","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31729","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: typec: ucsi: validate connector number in ucsi_notify_common()  The connector number extracted from CCI via UCSI_CCI_CONNECTOR() is a 7-bit field (0-127) that is used to index into the connector array in ucsi_connector_change(). However, the array is only allocated for the number of connectors reported by the device (typically 2-4 entries).  A malicious or malfunctioning device could report an out-of-range connector number in the CCI, causing an out-of-bounds array access in ucsi_connector_change().  Add a bounds check in ucsi_notify_common(), the central point where CCI is parsed after arriving from hardware, so that bogus connector numbers are rejected before they propagate further.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31729","epss":0.00129,"percentile":0.02827,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31729","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-31729","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31729","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/98429e9ec89a5e3a204112dfaa2dbe6ca28493a0","https://git.kernel.org/stable/c/d2d8c17ac01a1b1f638ea5d340a884ccc5015186","https://git.kernel.org/stable/c/f4e608fe12b7ac6a4a57176ab0296bb5a110a078","https://git.kernel.org/stable/c/f6dcbf2b024d55549959402f1db6c614e51d52cb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: validate connector number in ucsi_notify_common()\n\nThe connector number extracted from CCI via UCSI_CCI_CONNECTOR() is a\n7-bit field (0-127) that is used to index into the connector array in\nucsi_connector_change(). However, the array is only allocated for the\nnumber of connectors reported by the device (typically 2-4 entries).\n\nA malicious or malfunctioning device could report an out-of-range\nconnector number in the CCI, causing an out-of-bounds array access in\nucsi_connector_change().\n\nAdd a bounds check in ucsi_notify_common(), the central point where CCI\nis parsed after arriving from hardware, so that bogus connector numbers\nare rejected before they propagate further.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31729","epss":0.00129,"percentile":0.02827,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31729","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31729","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31767","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31767","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode  Stop adjusting the horizontal timing values based on the compression ratio in command mode. Bspec seems to be telling us to do this only in video mode, and this is also how the Windows driver does things.  This should also fix a div-by-zero on some machines because the adjusted htotal ends up being so small that we end up with line_time_us==0 when trying to determine the vtotal value in command mode.  Note that this doesn't actually make the display on the Huawei Matebook E work, but at least the kernel no longer explodes when the driver loads.  (cherry picked from commit 0b475e91ecc2313207196c6d7fd5c53e1a878525)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31767","epss":0.00122,"percentile":0.02249,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31767","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-31767","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31767","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/33b5336e4fd8ba0e40a12989cadb3f5534a0f9e4","https://git.kernel.org/stable/c/4dfce79e098915d8e5fc2b9e1d980bc3251dd32c","https://git.kernel.org/stable/c/55efe8402f46af8399c8b634a18b130a05fd7820","https://git.kernel.org/stable/c/86e926b108880c0109b8635e459450447156aeb7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode\n\nStop adjusting the horizontal timing values based on the\ncompression ratio in command mode. Bspec seems to be telling\nus to do this only in video mode, and this is also how the\nWindows driver does things.\n\nThis should also fix a div-by-zero on some machines because\nthe adjusted htotal ends up being so small that we end up with\nline_time_us==0 when trying to determine the vtotal value in\ncommand mode.\n\nNote that this doesn't actually make the display on the\nHuawei Matebook E work, but at least the kernel no longer\nexplodes when the driver loads.\n\n(cherry picked from commit 0b475e91ecc2313207196c6d7fd5c53e1a878525)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31767","epss":0.00122,"percentile":0.02249,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-31767","cwe":"CWE-369","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31767","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31771","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31771","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_event: move wake reason storage into validated event handlers  hci_store_wake_reason() is called from hci_event_packet() immediately after stripping the HCI event header but before hci_event_func() enforces the per-event minimum payload length from hci_ev_table. This means a short HCI event frame can reach bacpy() before any bounds check runs.  Rather than duplicating skb parsing and per-event length checks inside hci_store_wake_reason(), move wake-address storage into the individual event handlers after their existing event-length validation has succeeded. Convert hci_store_wake_reason() into a small helper that only stores an already-validated bdaddr while the caller holds hci_dev_lock(). Use the same helper after hci_event_func() with a NULL address to preserve the existing unexpected-wake fallback semantics when no validated event handler records a wake address.  Annotate the helper with __must_hold(&hdev->lock) and add lockdep_assert_held(&hdev->lock) so future call paths keep the lock contract explicit.  Call the helper from hci_conn_request_evt(), hci_conn_complete_evt(), hci_sync_conn_complete_evt(), le_conn_complete_evt(), hci_le_adv_report_evt(), hci_le_ext_adv_report_evt(), hci_le_direct_adv_report_evt(), hci_le_pa_sync_established_evt(), and hci_le_past_received_evt().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31771","epss":0.00205,"percentile":0.10544,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.15990000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-31771","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31771","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2b2bf47cd75518c36fa2d41380e4a40641cc89cd","https://git.kernel.org/stable/c/86c8d07a64d553c41e213b52650020010f9ef23e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: move wake reason storage into validated event handlers\n\nhci_store_wake_reason() is called from hci_event_packet() immediately\nafter stripping the HCI event header but before hci_event_func()\nenforces the per-event minimum payload length from hci_ev_table.\nThis means a short HCI event frame can reach bacpy() before any bounds\ncheck runs.\n\nRather than duplicating skb parsing and per-event length checks inside\nhci_store_wake_reason(), move wake-address storage into the individual\nevent handlers after their existing event-length validation has\nsucceeded. Convert hci_store_wake_reason() into a small helper that only\nstores an already-validated bdaddr while the caller holds hci_dev_lock().\nUse the same helper after hci_event_func() with a NULL address to\npreserve the existing unexpected-wake fallback semantics when no\nvalidated event handler records a wake address.\n\nAnnotate the helper with __must_hold(&hdev->lock) and add\nlockdep_assert_held(&hdev->lock) so future call paths keep the lock\ncontract explicit.\n\nCall the helper from hci_conn_request_evt(), hci_conn_complete_evt(),\nhci_sync_conn_complete_evt(), le_conn_complete_evt(),\nhci_le_adv_report_evt(), hci_le_ext_adv_report_evt(),\nhci_le_direct_adv_report_evt(), hci_le_pa_sync_established_evt(), and\nhci_le_past_received_evt().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31771","epss":0.00205,"percentile":0.10544,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31771","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-31777","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31777","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: ctxfi: Check the error for index mapping  The ctxfi driver blindly assumed a proper value returned from daio_device_index(), but it's not always true.  Add a proper error check to deal with the error from the function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31777","epss":0.00107,"percentile":0.01279,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-31777","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31777","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/277c6960d4ddb94d16198afd70c92c3d4593d131","https://git.kernel.org/stable/c/d4d3b8cbb70a2de247cbfe99bdb232aef9ed59bc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ctxfi: Check the error for index mapping\n\nThe ctxfi driver blindly assumed a proper value returned from\ndaio_device_index(), but it's not always true.  Add a proper error\ncheck to deal with the error from the function.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-31777","epss":0.00107,"percentile":0.01279,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-31777","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43009","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43009","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix incorrect pruning due to atomic fetch precision tracking  When backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC and BPF_FETCH, the src register (or r0 for BPF_CMPXCHG) also acts as a destination, thus receiving the old value from the memory location.  The current backtracking logic does not account for this. It treats atomic fetch operations the same as regular stores where the src register is only an input. This leads the backtrack_insn to fail to propagate precision to the stack location, which is then not marked as precise!  Later, the verifier's path pruning can incorrectly consider two states equivalent when they differ in terms of stack state. Meaning, two branches can be treated as equivalent and thus get pruned when they should not be seen as such.  Fix it as follows: Extend the BPF_LDX handling in backtrack_insn to also cover atomic fetch operations via is_atomic_fetch_insn() helper. When the fetch dst register is being tracked for precision, clear it, and propagate precision over to the stack slot. For non-stack memory, the precision walk stops at the atomic instruction, same as regular BPF_LDX. This covers all fetch variants.  Before:    0: (b7) r1 = 8                        ; R1=8   1: (7b) *(u64 *)(r10 -8) = r1         ; R1=8 R10=fp0 fp-8=8   2: (b7) r2 = 0                        ; R2=0   3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)          ; R2=8 R10=fp0 fp-8=mmmmmmmm   4: (bf) r3 = r10                      ; R3=fp0 R10=fp0   5: (0f) r3 += r2   mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1   mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10   mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)   mark_precise: frame0: regs=r2 stack= before 2: (b7) r2 = 0   6: R2=8 R3=fp8   6: (b7) r0 = 0                        ; R0=0   7: (95) exit  After:    0: (b7) r1 = 8                        ; R1=8   1: (7b) *(u64 *)(r10 -8) = r1         ; R1=8 R10=fp0 fp-8=8   2: (b7) r2 = 0                        ; R2=0   3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)          ; R2=8 R10=fp0 fp-8=mmmmmmmm   4: (bf) r3 = r10                      ; R3=fp0 R10=fp0   5: (0f) r3 += r2   mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1   mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10   mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)   mark_precise: frame0: regs= stack=-8 before 2: (b7) r2 = 0   mark_precise: frame0: regs= stack=-8 before 1: (7b) *(u64 *)(r10 -8) = r1   mark_precise: frame0: regs=r1 stack= before 0: (b7) r1 = 8   6: R2=8 R3=fp8   6: (b7) r0 = 0                        ; R0=0   7: (95) exit","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43009","epss":0.00127,"percentile":0.02693,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097155},"relatedVulnerabilities":[{"id":"CVE-2026-43009","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43009","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/179ee84a89114b854ac2dd1d293633a7f6c8dac1","https://git.kernel.org/stable/c/7ffbe45b1d227e24659998a91cfd4c27af457e71","https://git.kernel.org/stable/c/ea150ffa9fc9f78c5cf22e1f7b06b6d016b1017c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix incorrect pruning due to atomic fetch precision tracking\n\nWhen backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC\nand BPF_FETCH, the src register (or r0 for BPF_CMPXCHG) also acts as\na destination, thus receiving the old value from the memory location.\n\nThe current backtracking logic does not account for this. It treats\natomic fetch operations the same as regular stores where the src\nregister is only an input. This leads the backtrack_insn to fail to\npropagate precision to the stack location, which is then not marked\nas precise!\n\nLater, the verifier's path pruning can incorrectly consider two states\nequivalent when they differ in terms of stack state. Meaning, two\nbranches can be treated as equivalent and thus get pruned when they\nshould not be seen as such.\n\nFix it as follows: Extend the BPF_LDX handling in backtrack_insn to\nalso cover atomic fetch operations via is_atomic_fetch_insn() helper.\nWhen the fetch dst register is being tracked for precision, clear it,\nand propagate precision over to the stack slot. For non-stack memory,\nthe precision walk stops at the atomic instruction, same as regular\nBPF_LDX. This covers all fetch variants.\n\nBefore:\n\n  0: (b7) r1 = 8                        ; R1=8\n  1: (7b) *(u64 *)(r10 -8) = r1         ; R1=8 R10=fp0 fp-8=8\n  2: (b7) r2 = 0                        ; R2=0\n  3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)          ; R2=8 R10=fp0 fp-8=mmmmmmmm\n  4: (bf) r3 = r10                      ; R3=fp0 R10=fp0\n  5: (0f) r3 += r2\n  mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1\n  mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10\n  mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)\n  mark_precise: frame0: regs=r2 stack= before 2: (b7) r2 = 0\n  6: R2=8 R3=fp8\n  6: (b7) r0 = 0                        ; R0=0\n  7: (95) exit\n\nAfter:\n\n  0: (b7) r1 = 8                        ; R1=8\n  1: (7b) *(u64 *)(r10 -8) = r1         ; R1=8 R10=fp0 fp-8=8\n  2: (b7) r2 = 0                        ; R2=0\n  3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)          ; R2=8 R10=fp0 fp-8=mmmmmmmm\n  4: (bf) r3 = r10                      ; R3=fp0 R10=fp0\n  5: (0f) r3 += r2\n  mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1\n  mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10\n  mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)\n  mark_precise: frame0: regs= stack=-8 before 2: (b7) r2 = 0\n  mark_precise: frame0: regs= stack=-8 before 1: (7b) *(u64 *)(r10 -8) = r1\n  mark_precise: frame0: regs=r1 stack= before 0: (b7) r1 = 8\n  6: R2=8 R3=fp8\n  6: (b7) r0 = 0                        ; R0=0\n  7: (95) exit","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43009","epss":0.00127,"percentile":0.02693,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43009","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43010","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43010","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Reject sleepable kprobe_multi programs at attach time  kprobe.multi programs run in atomic/RCU context and cannot sleep. However, bpf_kprobe_multi_link_attach() did not validate whether the program being attached had the sleepable flag set, allowing sleepable helpers such as bpf_copy_from_user() to be invoked from a non-sleepable context.  This causes a \"sleeping function called from invalid context\" splat:    BUG: sleeping function called from invalid context at ./include/linux/uaccess.h:169   in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1787, name: sudo   preempt_count: 1, expected: 0   RCU nest depth: 2, expected: 0  Fix this by rejecting sleepable programs early in bpf_kprobe_multi_link_attach(), before any further processing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43010","epss":0.00122,"percentile":0.02259,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43010","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43010","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/89327ed787746a7aa4db3c97f91d2e294228932b","https://git.kernel.org/stable/c/d97b19fe5265f7901b2c862f88a4eb1b129a0b61","https://git.kernel.org/stable/c/dc9a060d76c12b23c5f378ee115d5e5d03d8bbf3","https://git.kernel.org/stable/c/eb7024bfcc5f68ed11ed9dd4891a3073c15f04a8","https://git.kernel.org/stable/c/f952157e695fd434bdc05af63a703bb082a78717"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject sleepable kprobe_multi programs at attach time\n\nkprobe.multi programs run in atomic/RCU context and cannot sleep.\nHowever, bpf_kprobe_multi_link_attach() did not validate whether the\nprogram being attached had the sleepable flag set, allowing sleepable\nhelpers such as bpf_copy_from_user() to be invoked from a non-sleepable\ncontext.\n\nThis causes a \"sleeping function called from invalid context\" splat:\n\n  BUG: sleeping function called from invalid context at ./include/linux/uaccess.h:169\n  in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1787, name: sudo\n  preempt_count: 1, expected: 0\n  RCU nest depth: 2, expected: 0\n\nFix this by rejecting sleepable programs early in\nbpf_kprobe_multi_link_attach(), before any further processing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43010","epss":0.00122,"percentile":0.02259,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43010","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43016","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43016","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready().  syzbot reported use-after-free of AF_UNIX socket's sk->sk_socket in sk_psock_verdict_data_ready(). [0]  In unix_stream_sendmsg(), the peer socket's ->sk_data_ready() is called after dropping its unix_state_lock().  Although the sender socket holds the peer's refcount, it does not prevent the peer's sock_orphan(), and the peer's sk_socket might be freed after one RCU grace period.  Let's fetch the peer's sk->sk_socket and sk->sk_socket->ops under RCU in sk_psock_verdict_data_ready().  [0]: BUG: KASAN: slab-use-after-free in sk_psock_verdict_data_ready+0xec/0x590 net/core/skmsg.c:1278 Read of size 8 at addr ffff8880594da860 by task syz.4.1842/11013  CPU: 1 UID: 0 PID: 11013 Comm: syz.4.1842 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026 Call Trace:  <TASK>  dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:378 [inline]  print_report+0xba/0x230 mm/kasan/report.c:482  kasan_report+0x117/0x150 mm/kasan/report.c:595  sk_psock_verdict_data_ready+0xec/0x590 net/core/skmsg.c:1278  unix_stream_sendmsg+0x8a3/0xe80 net/unix/af_unix.c:2482  sock_sendmsg_nosec net/socket.c:721 [inline]  __sock_sendmsg net/socket.c:736 [inline]  ____sys_sendmsg+0x972/0x9f0 net/socket.c:2585  ___sys_sendmsg+0x2a5/0x360 net/socket.c:2639  __sys_sendmsg net/socket.c:2671 [inline]  __do_sys_sendmsg net/socket.c:2676 [inline]  __se_sys_sendmsg net/socket.c:2674 [inline]  __x64_sys_sendmsg+0x1bd/0x2a0 net/socket.c:2674  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7facf899c819 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007facf9827028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007facf8c15fa0 RCX: 00007facf899c819 RDX: 0000000000000000 RSI: 0000200000000500 RDI: 0000000000000004 RBP: 00007facf8a32c91 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007facf8c16038 R14: 00007facf8c15fa0 R15: 00007ffd41b01c78  </TASK>  Allocated by task 11013:  kasan_save_stack mm/kasan/common.c:57 [inline]  kasan_save_track+0x3e/0x80 mm/kasan/common.c:78  unpoison_slab_object mm/kasan/common.c:340 [inline]  __kasan_slab_alloc+0x6c/0x80 mm/kasan/common.c:366  kasan_slab_alloc include/linux/kasan.h:253 [inline]  slab_post_alloc_hook mm/slub.c:4538 [inline]  slab_alloc_node mm/slub.c:4866 [inline]  kmem_cache_alloc_lru_noprof+0x2b8/0x640 mm/slub.c:4885  sock_alloc_inode+0x28/0xc0 net/socket.c:316  alloc_inode+0x6a/0x1b0 fs/inode.c:347  new_inode_pseudo include/linux/fs.h:3003 [inline]  sock_alloc net/socket.c:631 [inline]  __sock_create+0x12d/0x9d0 net/socket.c:1562  sock_create net/socket.c:1656 [inline]  __sys_socketpair+0x1c4/0x560 net/socket.c:1803  __do_sys_socketpair net/socket.c:1856 [inline]  __se_sys_socketpair net/socket.c:1853 [inline]  __x64_sys_socketpair+0x9b/0xb0 net/socket.c:1853  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Freed by task 15:  kasan_save_stack mm/kasan/common.c:57 [inline]  kasan_save_track+0x3e/0x80 mm/kasan/common.c:78  kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:584  poison_slab_object mm/kasan/common.c:253 [inline]  __kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285  kasan_slab_free include/linux/kasan.h:235 [inline]  slab_free_hook mm/slub.c:2685 [inline]  slab_free mm/slub.c:6165 [inline]  kmem_cache_free+0x187/0x630 mm/slub.c:6295  rcu_do_batch kernel/rcu/tree.c: ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43016","epss":0.00125,"percentile":0.02521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43016","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-43016","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43016","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/18861f87a043e78b1f901cae4237e755ed7ef095","https://git.kernel.org/stable/c/68187f18a89be4b6237d28ae1313b5adf76238c6","https://git.kernel.org/stable/c/8d597e3e74027900ffa81b8ff47ab51999a3e110","https://git.kernel.org/stable/c/ad8391d37f334ee73ba91926f8b4e4cf6d31ea04","https://git.kernel.org/stable/c/af95bc39a83d82ae6ad253986335037256888b3f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready().\n\nsyzbot reported use-after-free of AF_UNIX socket's sk->sk_socket\nin sk_psock_verdict_data_ready(). [0]\n\nIn unix_stream_sendmsg(), the peer socket's ->sk_data_ready() is\ncalled after dropping its unix_state_lock().\n\nAlthough the sender socket holds the peer's refcount, it does not\nprevent the peer's sock_orphan(), and the peer's sk_socket might\nbe freed after one RCU grace period.\n\nLet's fetch the peer's sk->sk_socket and sk->sk_socket->ops under\nRCU in sk_psock_verdict_data_ready().\n\n[0]:\nBUG: KASAN: slab-use-after-free in sk_psock_verdict_data_ready+0xec/0x590 net/core/skmsg.c:1278\nRead of size 8 at addr ffff8880594da860 by task syz.4.1842/11013\n\nCPU: 1 UID: 0 PID: 11013 Comm: syz.4.1842 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2026\nCall Trace:\n <TASK>\n dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xba/0x230 mm/kasan/report.c:482\n kasan_report+0x117/0x150 mm/kasan/report.c:595\n sk_psock_verdict_data_ready+0xec/0x590 net/core/skmsg.c:1278\n unix_stream_sendmsg+0x8a3/0xe80 net/unix/af_unix.c:2482\n sock_sendmsg_nosec net/socket.c:721 [inline]\n __sock_sendmsg net/socket.c:736 [inline]\n ____sys_sendmsg+0x972/0x9f0 net/socket.c:2585\n ___sys_sendmsg+0x2a5/0x360 net/socket.c:2639\n __sys_sendmsg net/socket.c:2671 [inline]\n __do_sys_sendmsg net/socket.c:2676 [inline]\n __se_sys_sendmsg net/socket.c:2674 [inline]\n __x64_sys_sendmsg+0x1bd/0x2a0 net/socket.c:2674\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7facf899c819\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007facf9827028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007facf8c15fa0 RCX: 00007facf899c819\nRDX: 0000000000000000 RSI: 0000200000000500 RDI: 0000000000000004\nRBP: 00007facf8a32c91 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007facf8c16038 R14: 00007facf8c15fa0 R15: 00007ffd41b01c78\n </TASK>\n\nAllocated by task 11013:\n kasan_save_stack mm/kasan/common.c:57 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:78\n unpoison_slab_object mm/kasan/common.c:340 [inline]\n __kasan_slab_alloc+0x6c/0x80 mm/kasan/common.c:366\n kasan_slab_alloc include/linux/kasan.h:253 [inline]\n slab_post_alloc_hook mm/slub.c:4538 [inline]\n slab_alloc_node mm/slub.c:4866 [inline]\n kmem_cache_alloc_lru_noprof+0x2b8/0x640 mm/slub.c:4885\n sock_alloc_inode+0x28/0xc0 net/socket.c:316\n alloc_inode+0x6a/0x1b0 fs/inode.c:347\n new_inode_pseudo include/linux/fs.h:3003 [inline]\n sock_alloc net/socket.c:631 [inline]\n __sock_create+0x12d/0x9d0 net/socket.c:1562\n sock_create net/socket.c:1656 [inline]\n __sys_socketpair+0x1c4/0x560 net/socket.c:1803\n __do_sys_socketpair net/socket.c:1856 [inline]\n __se_sys_socketpair net/socket.c:1853 [inline]\n __x64_sys_socketpair+0x9b/0xb0 net/socket.c:1853\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 15:\n kasan_save_stack mm/kasan/common.c:57 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:78\n kasan_save_free_info+0x46/0x50 mm/kasan/generic.c:584\n poison_slab_object mm/kasan/common.c:253 [inline]\n __kasan_slab_free+0x5c/0x80 mm/kasan/common.c:285\n kasan_slab_free include/linux/kasan.h:235 [inline]\n slab_free_hook mm/slub.c:2685 [inline]\n slab_free mm/slub.c:6165 [inline]\n kmem_cache_free+0x187/0x630 mm/slub.c:6295\n rcu_do_batch kernel/rcu/tree.c:\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43016","epss":0.00125,"percentile":0.02521,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43016","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43016","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43022","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43022","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists  hci_cmd_sync_queue_once() needs to indicate whether a queue item was added, so caller can know if callbacks are called, so it can avoid leaking resources.  Change the function to return -EEXIST if queue item already exists.  Modify all callsites to handle that.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43022","epss":0.00107,"percentile":0.01277,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-43022","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43022","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0ad2ce230b38cd4b3f6732cc609e270461e626e5","https://git.kernel.org/stable/c/2969554bcfccb5c609f6b6cd4a014933f3a66dd0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists\n\nhci_cmd_sync_queue_once() needs to indicate whether a queue item was\nadded, so caller can know if callbacks are called, so it can avoid\nleaking resources.\n\nChange the function to return -EEXIST if queue item already exists.\n\nModify all callsites to handle that.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43022","epss":0.00107,"percentile":0.01277,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43022","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43036","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43036","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: use skb_header_pointer() for TCPv4 GSO frag_off check  Syzbot reported a KMSAN uninit-value warning in gso_features_check() called from netif_skb_features() [1].  gso_features_check() reads iph->frag_off to decide whether to clear mangleid_features. Accessing the IPv4 header via ip_hdr()/inner_ip_hdr() can rely on skb header offsets that are not always safe for direct dereference on packets injected from PF_PACKET paths.  Use skb_header_pointer() for the TCPv4 frag_off check so the header read is robust whether data is already linear or needs copying.  [1] https://syzkaller.appspot.com/bug?extid=1543a7d954d9c6d00407","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43036","epss":0.00122,"percentile":0.02263,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43036","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43036","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43036","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/cc91202fc20a44aab4c206f12a2bfe05da936051","https://git.kernel.org/stable/c/d970341cfa5594614c7a6634886c7688b4f5cafd","https://git.kernel.org/stable/c/ddc748a391dd8642ba6b2e4fe22e7f2ddf84b7f0","https://git.kernel.org/stable/c/f7a6cd508e9e825a2c69fa9e13d41ee156852f25"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: use skb_header_pointer() for TCPv4 GSO frag_off check\n\nSyzbot reported a KMSAN uninit-value warning in gso_features_check()\ncalled from netif_skb_features() [1].\n\ngso_features_check() reads iph->frag_off to decide whether to clear\nmangleid_features. Accessing the IPv4 header via ip_hdr()/inner_ip_hdr()\ncan rely on skb header offsets that are not always safe for direct\ndereference on packets injected from PF_PACKET paths.\n\nUse skb_header_pointer() for the TCPv4 frag_off check so the header read\nis robust whether data is already linear or needs copying.\n\n[1] https://syzkaller.appspot.com/bug?extid=1543a7d954d9c6d00407","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43036","epss":0.00122,"percentile":0.02263,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43036","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43036","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43042","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43042","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mpls: add seqcount to protect the platform_label{,s} pair  The RCU-protected codepaths (mpls_forward, mpls_dump_routes) can have an inconsistent view of platform_labels vs platform_label in case of a concurrent resize (resize_platform_label_table, under platform_mutex). This can lead to OOB accesses.  This patch adds a seqcount, so that we get a consistent snapshot.  Note that mpls_label_ok is also susceptible to this, so the check against RTA_DST in rtm_to_route_config, done outside platform_mutex, is not sufficient. This value gets passed to mpls_label_ok once more in both mpls_route_add and mpls_route_del, so there is no issue, but that additional check must not be removed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43042","epss":0.0011,"percentile":0.01383,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43042","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0803},"relatedVulnerabilities":[{"id":"CVE-2026-43042","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43042","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5bb3caf0bbfb56f1a00d2af072ac3d8395a3b9ef","https://git.kernel.org/stable/c/629ec78ef8608d955ce217880cdc3e1873af3a15"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: add seqcount to protect the platform_label{,s} pair\n\nThe RCU-protected codepaths (mpls_forward, mpls_dump_routes) can have\nan inconsistent view of platform_labels vs platform_label in case of a\nconcurrent resize (resize_platform_label_table, under\nplatform_mutex). This can lead to OOB accesses.\n\nThis patch adds a seqcount, so that we get a consistent snapshot.\n\nNote that mpls_label_ok is also susceptible to this, so the check\nagainst RTA_DST in rtm_to_route_config, done outside platform_mutex,\nis not sufficient. This value gets passed to mpls_label_ok once more\nin both mpls_route_add and mpls_route_del, so there is no issue, but\nthat additional check must not be removed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43042","epss":0.0011,"percentile":0.01383,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43042","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43042","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43048","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43048","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: core: Mitigate potential OOB by removing bogus memset()  The memset() in hid_report_raw_event() has the good intention of clearing out bogus data by zeroing the area from the end of the incoming data string to the assumed end of the buffer.  However, as we have previously seen, doing so can easily result in OOB reads and writes in the subsequent thread of execution.  The current suggestion from one of the HID maintainers is to remove the memset() and simply return if the incoming event buffer size is not large enough to fill the associated report.  Suggested-by Benjamin Tissoires <bentiss@kernel.org>  [bentiss: changed the return value]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43048","epss":0.00241,"percentile":0.15151,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43048","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.196415},"relatedVulnerabilities":[{"id":"CVE-2026-43048","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43048","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0a3fe972a7cb1404f693d6f1711f32bc1d244b1c","https://git.kernel.org/stable/c/8f71034649738fdeb6859b8d6cddf132024fac06","https://git.kernel.org/stable/c/bd6e1d0230cca9575f5d118148f51e2a56b5373f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: Mitigate potential OOB by removing bogus memset()\n\nThe memset() in hid_report_raw_event() has the good intention of\nclearing out bogus data by zeroing the area from the end of the incoming\ndata string to the assumed end of the buffer.  However, as we have\npreviously seen, doing so can easily result in OOB reads and writes in\nthe subsequent thread of execution.\n\nThe current suggestion from one of the HID maintainers is to remove the\nmemset() and simply return if the incoming event buffer size is not\nlarge enough to fill the associated report.\n\nSuggested-by Benjamin Tissoires <bentiss@kernel.org>\n\n[bentiss: changed the return value]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43048","epss":0.00241,"percentile":0.15151,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43048","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43048","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43049","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43049","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure  Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number will be returned and propagated before the userspace infrastructure (sysfs and /dev/input) has been torn down.  If userspace ignores the errors and continues to use its references to these dangling entities, a UAF will promptly follow.  We have 2 options; continue to return the error, but ensure that all of the infrastructure is torn down accordingly or continue to treat this condition as a warning by emitting the message but returning success. It is thought that the original author's intention was to emit the warning but keep the device functional, less the force feedback feature, so let's go with that.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43049","epss":0.00116,"percentile":0.01829,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43049","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08874},"relatedVulnerabilities":[{"id":"CVE-2026-43049","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43049","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/772f99cc8d6e5d95613bce93c9624e154c1abe88","https://git.kernel.org/stable/c/9a793ac19eb84f44ed759c0fce80cf29bc2a2453","https://git.kernel.org/stable/c/b846fb0a73e99174f08238e083e284c0463a2102","https://git.kernel.org/stable/c/f7a4c78bfeb320299c1b641500fe7761eadbd101"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure\n\nPresently, if the force feedback initialisation fails when probing the\nLogitech G920 Driving Force Racing Wheel for Xbox One, an error number\nwill be returned and propagated before the userspace infrastructure\n(sysfs and /dev/input) has been torn down.  If userspace ignores the\nerrors and continues to use its references to these dangling entities, a\nUAF will promptly follow.\n\nWe have 2 options; continue to return the error, but ensure that all of\nthe infrastructure is torn down accordingly or continue to treat this\ncondition as a warning by emitting the message but returning success.\nIt is thought that the original author's intention was to emit the\nwarning but keep the device functional, less the force feedback feature,\nso let's go with that.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43049","epss":0.00116,"percentile":0.01829,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43049","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43049","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43053","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43053","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfs: close crash window in attr dabtree inactivation  When inactivating an inode with node-format extended attributes, xfs_attr3_node_inactive() invalidates all child leaf/node blocks via xfs_trans_binval(), but intentionally does not remove the corresponding entries from their parent node blocks.  The implicit assumption is that xfs_attr_inactive() will truncate the entire attr fork to zero extents afterwards, so log recovery will never reach the root node and follow those stale pointers.  However, if a log shutdown occurs after the leaf/node block cancellations commit but before the attr bmap truncation commits, this assumption breaks.  Recovery replays the attr bmap intact (the inode still has attr fork extents), but suppresses replay of all cancelled leaf/node blocks, maybe leaving them as stale data on disk.  On the next mount, xlog_recover_process_iunlinks() retries inactivation and attempts to read the root node via the attr bmap. If the root node was not replayed, reading the unreplayed root block triggers a metadata verification failure immediately; if it was replayed, following its child pointers to unreplayed child blocks triggers the same failure:   XFS (pmem0): Metadata corruption detected at  xfs_da3_node_read_verify+0x53/0x220, xfs_da3_node block 0x78  XFS (pmem0): Unmount and run xfs_repair  XFS (pmem0): First 128 bytes of corrupted metadata buffer:  00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................  00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................  00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................  00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................  00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................  00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................  00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................  00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................  XFS (pmem0): metadata I/O error in \"xfs_da_read_buf+0x104/0x190\" at daddr 0x78 len 8 error 117  Fix this in two places:  In xfs_attr3_node_inactive(), after calling xfs_trans_binval() on a child block, immediately remove the entry that references it from the parent node in the same transaction.  This eliminates the window where the parent holds a pointer to a cancelled block.  Once all children are removed, the now-empty root node is converted to a leaf block within the same transaction. This node-to-leaf conversion is necessary for crash safety. If the system shutdown after the empty node is written to the log but before the second-phase bmap truncation commits, log recovery will attempt to verify the root block on disk. xfs_da3_node_verify() does not permit a node block with count == 0; such a block will fail verification and trigger a metadata corruption shutdown. on the other hand, leaf blocks are allowed to have this transient state.  In xfs_attr_inactive(), split the attr fork truncation into two explicit phases.  First, truncate all extents beyond the root block (the child extents whose parent references have already been removed above). Second, invalidate the root block and truncate the attr bmap to zero in a single transaction.  The two operations in the second phase must be atomic: as long as the attr bmap has any non-zero length, recovery can follow it to the root block, so the root block invalidation must commit together with the bmap-to-zero truncation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43053","epss":0.00074,"percentile":0.00075,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43053","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.03589},"relatedVulnerabilities":[{"id":"CVE-2026-43053","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43053","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/b854e1c4eff3473b6d3a9ae74129ac5c48bc0b61","https://git.kernel.org/stable/c/e5a3e3cdd9b3015ae79456c81beebfdbb5246c0f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: close crash window in attr dabtree inactivation\n\nWhen inactivating an inode with node-format extended attributes,\nxfs_attr3_node_inactive() invalidates all child leaf/node blocks via\nxfs_trans_binval(), but intentionally does not remove the corresponding\nentries from their parent node blocks.  The implicit assumption is that\nxfs_attr_inactive() will truncate the entire attr fork to zero extents\nafterwards, so log recovery will never reach the root node and follow\nthose stale pointers.\n\nHowever, if a log shutdown occurs after the leaf/node block cancellations\ncommit but before the attr bmap truncation commits, this assumption\nbreaks.  Recovery replays the attr bmap intact (the inode still has\nattr fork extents), but suppresses replay of all cancelled leaf/node\nblocks, maybe leaving them as stale data on disk.  On the next mount,\nxlog_recover_process_iunlinks() retries inactivation and attempts to\nread the root node via the attr bmap. If the root node was not replayed,\nreading the unreplayed root block triggers a metadata verification\nfailure immediately; if it was replayed, following its child pointers\nto unreplayed child blocks triggers the same failure:\n\n XFS (pmem0): Metadata corruption detected at\n xfs_da3_node_read_verify+0x53/0x220, xfs_da3_node block 0x78\n XFS (pmem0): Unmount and run xfs_repair\n XFS (pmem0): First 128 bytes of corrupted metadata buffer:\n 00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n 00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n XFS (pmem0): metadata I/O error in \"xfs_da_read_buf+0x104/0x190\" at daddr 0x78 len 8 error 117\n\nFix this in two places:\n\nIn xfs_attr3_node_inactive(), after calling xfs_trans_binval() on a\nchild block, immediately remove the entry that references it from the\nparent node in the same transaction.  This eliminates the window where\nthe parent holds a pointer to a cancelled block.  Once all children are\nremoved, the now-empty root node is converted to a leaf block within the\nsame transaction. This node-to-leaf conversion is necessary for crash\nsafety. If the system shutdown after the empty node is written to the\nlog but before the second-phase bmap truncation commits, log recovery\nwill attempt to verify the root block on disk. xfs_da3_node_verify()\ndoes not permit a node block with count == 0; such a block will fail\nverification and trigger a metadata corruption shutdown. on the other\nhand, leaf blocks are allowed to have this transient state.\n\nIn xfs_attr_inactive(), split the attr fork truncation into two explicit\nphases.  First, truncate all extents beyond the root block (the child\nextents whose parent references have already been removed above).\nSecond, invalidate the root block and truncate the attr bmap to zero in\na single transaction.  The two operations in the second phase must be\natomic: as long as the attr bmap has any non-zero length, recovery can\nfollow it to the root block, so the root block invalidation must commit\ntogether with the bmap-to-zero truncation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43053","epss":0.00074,"percentile":0.00075,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43053","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43053","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43073","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43073","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  x86-64: rename misleadingly named '__copy_user_nocache()' function  This function was a masterclass in bad naming, for various historical reasons.  It claimed to be a non-cached user copy.  It is literally _neither_ of those things.  It's a specialty memory copy routine that uses non-temporal stores for the destination (but not the source), and that does exception handling for both source and destination accesses.  Also note that while it works for unaligned targets, any unaligned parts (whether at beginning or end) will not use non-temporal stores, since only words and quadwords can be non-temporal on x86.  The exception handling means that it _can_ be used for user space accesses, but not on its own - it needs all the normal \"start user space access\" logic around it.  But typically the user space access would be the source, not the non-temporal destination.  That was the original intention of this, where the destination was some fragile persistent memory target that needed non-temporal stores in order to catch machine check exceptions synchronously and deal with them gracefully.  Thus that non-descriptive name: one use case was to copy from user space into a non-cached kernel buffer.  However, the existing users are a mix of that intended use-case, and a couple of random drivers that just did this as a performance tweak.  Some of those random drivers then actively misused the user copying version (with STAC/CLAC and all) to do kernel copies without ever even caring about the exception handling, _just_ for the non-temporal destination.  Rename it as a first small step to actually make it halfway sane, and change the prototype to be more normal: it doesn't take a user pointer unless the caller has done the proper conversion, and the argument size is the full size_t (it still won't actually copy more than 4GB in one go, but there's also no reason to silently truncate the size argument in the caller).  Finally, use this now sanely named function in the NTB code, which mis-used a user copy version (with STAC/CLAC and all) of this interface despite it not actually being a user copy at all.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43073","epss":0.00117,"percentile":0.01838,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.061425},"relatedVulnerabilities":[{"id":"CVE-2026-43073","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43073","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/14b9194db4a28421a4dbe5d6e519efbaa7c5f3cd","https://git.kernel.org/stable/c/c6d4e0599e7e73abc04e2488dfeb7940c4039660","https://git.kernel.org/stable/c/d187a86de793f84766ea40b9ade7ac60aabbb4fe","https://git.kernel.org/stable/c/d993e1723aa2a085aa0d72e70ea889031fc225b4","https://git.kernel.org/stable/c/efea91ad1729ff1853d7418e4d3bc27d085e72d0","https://project-zero.issues.chromium.org/issues/496923375"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86-64: rename misleadingly named '__copy_user_nocache()' function\n\nThis function was a masterclass in bad naming, for various historical\nreasons.\n\nIt claimed to be a non-cached user copy.  It is literally _neither_ of\nthose things.  It's a specialty memory copy routine that uses\nnon-temporal stores for the destination (but not the source), and that\ndoes exception handling for both source and destination accesses.\n\nAlso note that while it works for unaligned targets, any unaligned parts\n(whether at beginning or end) will not use non-temporal stores, since\nonly words and quadwords can be non-temporal on x86.\n\nThe exception handling means that it _can_ be used for user space\naccesses, but not on its own - it needs all the normal \"start user space\naccess\" logic around it.\n\nBut typically the user space access would be the source, not the\nnon-temporal destination.  That was the original intention of this,\nwhere the destination was some fragile persistent memory target that\nneeded non-temporal stores in order to catch machine check exceptions\nsynchronously and deal with them gracefully.\n\nThus that non-descriptive name: one use case was to copy from user space\ninto a non-cached kernel buffer.  However, the existing users are a mix\nof that intended use-case, and a couple of random drivers that just did\nthis as a performance tweak.\n\nSome of those random drivers then actively misused the user copying\nversion (with STAC/CLAC and all) to do kernel copies without ever even\ncaring about the exception handling, _just_ for the non-temporal\ndestination.\n\nRename it as a first small step to actually make it halfway sane, and\nchange the prototype to be more normal: it doesn't take a user pointer\nunless the caller has done the proper conversion, and the argument size\nis the full size_t (it still won't actually copy more than 4GB in one\ngo, but there's also no reason to silently truncate the size argument in\nthe caller).\n\nFinally, use this now sanely named function in the NTB code, which\nmis-used a user copy version (with STAC/CLAC and all) of this interface\ndespite it not actually being a user copy at all.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43073","epss":0.00117,"percentile":0.01838,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43073","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43083","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ioam6: fix OOB and missing lock  When trace->type.bit6 is set:      if (trace->type.bit6) {         ...         queue = skb_get_tx_queue(dev, skb);         qdisc = rcu_dereference(queue->qdisc);  This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the RX path and skb->queue_mapping contains the RX queue index of the ingress device. If the ingress device has more RX queues than the egress device (dev) has TX queues, skb_get_queue_mapping(skb) will exceed dev->num_tx_queues. Add a check to avoid this situation since skb_get_tx_queue() does not clamp the index. This issue has also revealed that per queue visibility cannot be accurate and will be replaced later as a new feature.  While at it, add missing lock around qdisc_qstats_qlen_backlog(). The function __ioam6_fill_trace_data() is called from both softirq and process contexts, hence the use of spin_lock_bh() here.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43083","epss":0.00442,"percentile":0.37272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43083","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.40001000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-43083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43083","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/6d1d9ed9b409e0662241e3d245d574a18f643494","https://git.kernel.org/stable/c/95a1334748c95dd15546056280ade0c4b8dd7b78","https://git.kernel.org/stable/c/b30b1675aa2bcf0491fd3830b051df4e08a7c8ca"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ioam6: fix OOB and missing lock\n\nWhen trace->type.bit6 is set:\n\n    if (trace->type.bit6) {\n        ...\n        queue = skb_get_tx_queue(dev, skb);\n        qdisc = rcu_dereference(queue->qdisc);\n\nThis code can lead to an out-of-bounds access of the dev->_tx[] array\nwhen is_input is true. In such a case, the packet is on the RX path and\nskb->queue_mapping contains the RX queue index of the ingress device. If\nthe ingress device has more RX queues than the egress device (dev) has\nTX queues, skb_get_queue_mapping(skb) will exceed dev->num_tx_queues.\nAdd a check to avoid this situation since skb_get_tx_queue() does not\nclamp the index. This issue has also revealed that per queue visibility\ncannot be accurate and will be replaced later as a new feature.\n\nWhile at it, add missing lock around qdisc_qstats_qlen_backlog(). The\nfunction __ioam6_fill_trace_data() is called from both softirq and\nprocess contexts, hence the use of spin_lock_bh() here.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43083","epss":0.00442,"percentile":0.37272,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43083","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43088","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43088","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: af_key: zero aligned sockaddr tail in PF_KEY exports  PF_KEY export paths use `pfkey_sockaddr_size()` when reserving sockaddr payload space, so IPv6 addresses occupy 32 bytes on the wire. However, `pfkey_sockaddr_fill()` initializes only the first 28 bytes of `struct sockaddr_in6`, leaving the final 4 aligned bytes uninitialized.  Not every PF_KEY message is affected. The state and policy dump builders already zero the whole message buffer before filling the sockaddr payloads. Keep the fix to the export paths that still append aligned sockaddr payloads with plain `skb_put()`:    - `SADB_ACQUIRE`   - `SADB_X_NAT_T_NEW_MAPPING`   - `SADB_X_MIGRATE`  Fix those paths by clearing only the aligned sockaddr tail after `pfkey_sockaddr_fill()`.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43088","epss":0.00122,"percentile":0.02255,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43088","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43088","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/11cbf294bac623bd57296f231199193087f57b4a","https://git.kernel.org/stable/c/2e74f974359b5382ecbe8536abbb5b837eb6c724","https://git.kernel.org/stable/c/3c19cb8a84ef709d57943bd6664cf31cb91ba6ec","https://git.kernel.org/stable/c/426c355742f02cf743b347d9d7dbdc1bfbfa31ef","https://git.kernel.org/stable/c/edd446ee7cd3d02cac246168063d5b3e9ea68460"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: zero aligned sockaddr tail in PF_KEY exports\n\nPF_KEY export paths use `pfkey_sockaddr_size()` when reserving sockaddr\npayload space, so IPv6 addresses occupy 32 bytes on the wire. However,\n`pfkey_sockaddr_fill()` initializes only the first 28 bytes of\n`struct sockaddr_in6`, leaving the final 4 aligned bytes uninitialized.\n\nNot every PF_KEY message is affected. The state and policy dump builders\nalready zero the whole message buffer before filling the sockaddr\npayloads. Keep the fix to the export paths that still append aligned\nsockaddr payloads with plain `skb_put()`:\n\n  - `SADB_ACQUIRE`\n  - `SADB_X_NAT_T_NEW_MAPPING`\n  - `SADB_X_MIGRATE`\n\nFix those paths by clearing only the aligned sockaddr tail after\n`pfkey_sockaddr_fill()`.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43088","epss":0.00122,"percentile":0.02255,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43088","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43091","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43091","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: Wait for RCU readers during policy netns exit  xfrm_policy_fini() frees the policy_bydst hash tables after flushing the policy work items and deleting all policies, but it does not wait for concurrent RCU readers to leave their read-side critical sections first.  The policy_bydst tables are published via rcu_assign_pointer() and are looked up through rcu_dereference_check(), so netns teardown must also wait for an RCU grace period before freeing the table memory.  Fix this by adding synchronize_rcu() before freeing the policy hash tables.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43091","epss":0.00129,"percentile":0.02837,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-43091","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43091","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/069daad4f2ae9c5c108131995529d5f02392c446","https://git.kernel.org/stable/c/33a3149dd81a1e2f52b80ee1e0fc380b39f3d028","https://git.kernel.org/stable/c/3733fce2871c9bca9dd18a1a23b1432ea215a094","https://git.kernel.org/stable/c/438b1f668ad58f46ce699bb48e4698a7839e3f9e","https://git.kernel.org/stable/c/b66920a3348c0f63ba18365248fa21fbf0b3a937"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Wait for RCU readers during policy netns exit\n\nxfrm_policy_fini() frees the policy_bydst hash tables after flushing the\npolicy work items and deleting all policies, but it does not wait for\nconcurrent RCU readers to leave their read-side critical sections first.\n\nThe policy_bydst tables are published via rcu_assign_pointer() and are\nlooked up through rcu_dereference_check(), so netns teardown must also\nwait for an RCU grace period before freeing the table memory.\n\nFix this by adding synchronize_rcu() before freeing the policy hash tables.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43091","epss":0.00129,"percentile":0.02837,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43091","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43101","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43101","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()  We need to check __in6_dev_get() for possible NULL value, as suggested by Yiming Qian.  Also add skb_dst_dev_rcu() instead of skb_dst_dev(), and two missing READ_ONCE().  Note that @dev can't be NULL.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43101","epss":0.00426,"percentile":0.35925,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43101","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3195},"relatedVulnerabilities":[{"id":"CVE-2026-43101","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43101","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3719c234fa94c37c955b1ecd3742ef280ec135e6","https://git.kernel.org/stable/c/4198aab6f000b4febb18ea820fea20634dd789c7","https://git.kernel.org/stable/c/4e65a8b8daa18d63255ec58964dd192c7fdd9f8b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()\n\nWe need to check __in6_dev_get() for possible NULL value, as\nsuggested by Yiming Qian.\n\nAlso add skb_dst_dev_rcu() instead of skb_dst_dev(),\nand two missing READ_ONCE().\n\nNote that @dev can't be NULL.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43101","epss":0.00426,"percentile":0.35925,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43101","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43101","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43107","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43107","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: account XFRMA_IF_ID in aevent size calculation  xfrm_get_ae() allocates the reply skb with xfrm_aevent_msgsize(), then build_aevent() appends attributes including XFRMA_IF_ID when x->if_id is set.  xfrm_aevent_msgsize() does not include space for XFRMA_IF_ID. For states with if_id, build_aevent() can fail with -EMSGSIZE and hit BUG_ON(err < 0) in xfrm_get_ae(), turning a malformed netlink interaction into a kernel panic.  Account XFRMA_IF_ID in the size calculation unconditionally and replace the BUG_ON with normal error unwinding.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43107","epss":0.00114,"percentile":0.01629,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43107","cwe":"CWE-131","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-43107","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43107","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2c41283d94af943a05f7f2cc1a01f0c872f3cf43","https://git.kernel.org/stable/c/58e5735d1a5373652f405a0c16e54ac04aaab0ad","https://git.kernel.org/stable/c/7081d46d32312f1a31f0e0e99c6835a394037599","https://git.kernel.org/stable/c/e62e322ea20be78e346e4b49f9a6b9f03313af4c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: account XFRMA_IF_ID in aevent size calculation\n\nxfrm_get_ae() allocates the reply skb with xfrm_aevent_msgsize(), then\nbuild_aevent() appends attributes including XFRMA_IF_ID when x->if_id is\nset.\n\nxfrm_aevent_msgsize() does not include space for XFRMA_IF_ID. For states\nwith if_id, build_aevent() can fail with -EMSGSIZE and hit BUG_ON(err < 0)\nin xfrm_get_ae(), turning a malformed netlink interaction into a kernel\npanic.\n\nAccount XFRMA_IF_ID in the size calculation unconditionally and replace\nthe BUG_ON with normal error unwinding.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43107","epss":0.00114,"percentile":0.01629,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43107","cwe":"CWE-131","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43107","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43115","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43115","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  srcu: Use irq_work to start GP in tiny SRCU  Tiny SRCU's srcu_gp_start_if_needed() directly calls schedule_work(), which acquires the workqueue pool->lock.  This causes a lockdep splat when call_srcu() is called with a scheduler lock held, due to:    call_srcu() [holding pi_lock]     srcu_gp_start_if_needed()       schedule_work() -> pool->lock    workqueue_init() / create_worker() [holding pool->lock]     wake_up_process() -> try_to_wake_up() -> pi_lock  Also add irq_work_sync() to cleanup_srcu_struct() to prevent a use-after-free if a queued irq_work fires after cleanup begins.  Tested with rcutorture SRCU-T and no lockdep warnings.  [ Thanks to Boqun for similar fix in patch \"rcu: Use an intermediate irq_work to start process_srcu()\" ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43115","epss":0.001,"percentile":0.0093,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.052500000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-43115","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43115","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/a6fc88b22bc8d12ad52e8412c667ec0f5bf055af","https://git.kernel.org/stable/c/bb37286db65368cb72ba8757ad86299c4e4a73fc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsrcu: Use irq_work to start GP in tiny SRCU\n\nTiny SRCU's srcu_gp_start_if_needed() directly calls schedule_work(),\nwhich acquires the workqueue pool->lock.\n\nThis causes a lockdep splat when call_srcu() is called with a scheduler\nlock held, due to:\n\n  call_srcu() [holding pi_lock]\n    srcu_gp_start_if_needed()\n      schedule_work() -> pool->lock\n\n  workqueue_init() / create_worker() [holding pool->lock]\n    wake_up_process() -> try_to_wake_up() -> pi_lock\n\nAlso add irq_work_sync() to cleanup_srcu_struct() to prevent a\nuse-after-free if a queued irq_work fires after cleanup begins.\n\nTested with rcutorture SRCU-T and no lockdep warnings.\n\n[ Thanks to Boqun for similar fix in patch \"rcu: Use an intermediate irq_work\nto start process_srcu()\" ]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43115","epss":0.001,"percentile":0.0093,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43115","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43118","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43118","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix zero size inode with non-zero size after log replay  When logging that an inode exists, as part of logging a new name or logging new dir entries for a directory, we always set the generation of the logged inode item to 0. This is to signal during log replay (in overwrite_item()), that we should not set the i_size since we only logged that an inode exists, so the i_size of the inode in the subvolume tree must be preserved (as when we log new names or that an inode exists, we don't log extents).  This works fine except when we have already logged an inode in full mode or it's the first time we are logging an inode created in a past transaction, that inode has a new i_size of 0 and then we log a new name for the inode (due to a new hardlink or a rename), in which case we log an i_size of 0 for the inode and a generation of 0, which causes the log replay code to not update the inode's i_size to 0 (in overwrite_item()).  An example scenario:    mkdir /mnt/dir   xfs_io -f -c \"pwrite 0 64K\" /mnt/dir/foo    sync    xfs_io -c \"truncate 0\" -c \"fsync\" /mnt/dir/foo    ln /mnt/dir/foo /mnt/dir/bar    xfs_io -c \"fsync\" /mnt/dir    <power fail>  After log replay the file remains with a size of 64K. This is because when we first log the inode, when we fsync file foo, we log its current i_size of 0, and then when we create a hard link we log again the inode in exists mode (LOG_INODE_EXISTS) but we set a generation of 0 for the inode item we add to the log tree, so during log replay overwrite_item() sees that the generation is 0 and i_size is 0 so we skip updating the inode's i_size from 64K to 0.  Fix this by making sure at fill_inode_item() we always log the real generation of the inode if it was logged in the current transaction with the i_size we logged before. Also if an inode created in a previous transaction is logged in exists mode only, make sure we log the i_size stored in the inode item located from the commit root, so that if we log multiple times that the inode exists we get the correct i_size.  A test case for fstests will follow soon.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43118","epss":0.00112,"percentile":0.01545,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-43118","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43118","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/03e966b63df5b06790310c1faaf3e0cb43adea8b","https://git.kernel.org/stable/c/5254d4181add9dfaa5e3519edd71cc8f752b2f85","https://git.kernel.org/stable/c/fddb157536e67a055597f00a8b4922d5f5ed0826"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix zero size inode with non-zero size after log replay\n\nWhen logging that an inode exists, as part of logging a new name or\nlogging new dir entries for a directory, we always set the generation of\nthe logged inode item to 0. This is to signal during log replay (in\noverwrite_item()), that we should not set the i_size since we only logged\nthat an inode exists, so the i_size of the inode in the subvolume tree\nmust be preserved (as when we log new names or that an inode exists, we\ndon't log extents).\n\nThis works fine except when we have already logged an inode in full mode\nor it's the first time we are logging an inode created in a past\ntransaction, that inode has a new i_size of 0 and then we log a new name\nfor the inode (due to a new hardlink or a rename), in which case we log\nan i_size of 0 for the inode and a generation of 0, which causes the log\nreplay code to not update the inode's i_size to 0 (in overwrite_item()).\n\nAn example scenario:\n\n  mkdir /mnt/dir\n  xfs_io -f -c \"pwrite 0 64K\" /mnt/dir/foo\n\n  sync\n\n  xfs_io -c \"truncate 0\" -c \"fsync\" /mnt/dir/foo\n\n  ln /mnt/dir/foo /mnt/dir/bar\n\n  xfs_io -c \"fsync\" /mnt/dir\n\n  <power fail>\n\nAfter log replay the file remains with a size of 64K. This is because when\nwe first log the inode, when we fsync file foo, we log its current i_size\nof 0, and then when we create a hard link we log again the inode in exists\nmode (LOG_INODE_EXISTS) but we set a generation of 0 for the inode item we\nadd to the log tree, so during log replay overwrite_item() sees that the\ngeneration is 0 and i_size is 0 so we skip updating the inode's i_size\nfrom 64K to 0.\n\nFix this by making sure at fill_inode_item() we always log the real\ngeneration of the inode if it was logged in the current transaction with\nthe i_size we logged before. Also if an inode created in a previous\ntransaction is logged in exists mode only, make sure we log the i_size\nstored in the inode item located from the commit root, so that if we log\nmultiple times that the inode exists we get the correct i_size.\n\nA test case for fstests will follow soon.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43118","epss":0.00112,"percentile":0.01545,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43118","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43119","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43119","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_sync: annotate data-races around hdev->req_status  __hci_cmd_sync_sk() sets hdev->req_status under hdev->req_lock:      hdev->req_status = HCI_REQ_PEND;  However, several other functions read or write hdev->req_status without holding any lock:    - hci_send_cmd_sync() reads req_status in hci_cmd_work (workqueue)   - hci_cmd_sync_complete() reads/writes from HCI event completion   - hci_cmd_sync_cancel() / hci_cmd_sync_cancel_sync() read/write   - hci_abort_conn() reads in connection abort path  Since __hci_cmd_sync_sk() runs on hdev->req_workqueue while hci_send_cmd_sync() runs on hdev->workqueue, these are different workqueues that can execute concurrently on different CPUs. The plain C accesses constitute a data race.  Add READ_ONCE()/WRITE_ONCE() annotations on all concurrent accesses to hdev->req_status to prevent potential compiler optimizations that could affect correctness (e.g., load fusing in the wait_event condition or store reordering).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43119","epss":0.00114,"percentile":0.01636,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-43119","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43119","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/40734ce8efc34c4a0d0222855798c0dc14b65f2e","https://git.kernel.org/stable/c/6e539907c0d11f514c5e0b049b27b04dff48a5b1","https://git.kernel.org/stable/c/a7a1cdb4a64ca74eb95cc46648fccb8cd3f9af27","https://git.kernel.org/stable/c/b6807cfc195ef99e1ac37b2e1e60df40295daa8c","https://git.kernel.org/stable/c/e51042ddc0b20d9bda5eb6dcf85a2668f9c5dae4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: annotate data-races around hdev->req_status\n\n__hci_cmd_sync_sk() sets hdev->req_status under hdev->req_lock:\n\n    hdev->req_status = HCI_REQ_PEND;\n\nHowever, several other functions read or write hdev->req_status without\nholding any lock:\n\n  - hci_send_cmd_sync() reads req_status in hci_cmd_work (workqueue)\n  - hci_cmd_sync_complete() reads/writes from HCI event completion\n  - hci_cmd_sync_cancel() / hci_cmd_sync_cancel_sync() read/write\n  - hci_abort_conn() reads in connection abort path\n\nSince __hci_cmd_sync_sk() runs on hdev->req_workqueue while\nhci_send_cmd_sync() runs on hdev->workqueue, these are different\nworkqueues that can execute concurrently on different CPUs. The plain\nC accesses constitute a data race.\n\nAdd READ_ONCE()/WRITE_ONCE() annotations on all concurrent accesses\nto hdev->req_status to prevent potential compiler optimizations that\ncould affect correctness (e.g., load fusing in the wait_event\ncondition or store reordering).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43119","epss":0.00114,"percentile":0.01636,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43119","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43125","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43125","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dlm: validate length in dlm_search_rsb_tree  The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree().  Add length validation to prevent potential buffer overflow.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43125","epss":0.00426,"percentile":0.3594,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43125","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-43125","cwe":"CWE-130","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.30884999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-43125","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43125","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/080e5563f878c64e697b89e7439d730d0daad882","https://git.kernel.org/stable/c/082083c9fbd99422a0370fe2102144a231c9f5d6","https://git.kernel.org/stable/c/5f053a2e7209d326cbbc07738fa6d6893d307438","https://git.kernel.org/stable/c/67288113c5e6cf9e659b4065c0ed6f16100e0c71","https://access.redhat.com/errata/RHSA-2026:25120","https://access.redhat.com/errata/RHSA-2026:25121","https://access.redhat.com/errata/RHSA-2026:25217","https://access.redhat.com/errata/RHSA-2026:33899","https://access.redhat.com/errata/RHSA-2026:33900","https://access.redhat.com/errata/RHSA-2026:34094","https://access.redhat.com/errata/RHSA-2026:34095","https://access.redhat.com/errata/RHSA-2026:35844","https://access.redhat.com/errata/RHSA-2026:35863","https://access.redhat.com/errata/RHSA-2026:36767","https://access.redhat.com/errata/RHSA-2026:41236","https://access.redhat.com/errata/RHSA-2026:55761","https://access.redhat.com/errata/RHSA-2026:55762","https://access.redhat.com/errata/RHSA-2026:55763","https://access.redhat.com/errata/RHSA-2026:55837","https://access.redhat.com/errata/RHSA-2026:56224","https://access.redhat.com/errata/RHSA-2026:56225","https://access.redhat.com/errata/RHSA-2026:59091","https://access.redhat.com/security/cve/CVE-2026-43125","https://bugzilla.redhat.com/show_bug.cgi?id=2467234","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43125.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: validate length in dlm_search_rsb_tree\n\nThe len parameter in dlm_dump_rsb_name() is not validated and comes\nfrom network messages. When it exceeds DLM_RESNAME_MAXLEN, it can\ncause out-of-bounds write in dlm_search_rsb_tree().\n\nAdd length validation to prevent potential buffer overflow.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43125","epss":0.00426,"percentile":0.3594,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43125","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-43125","cwe":"CWE-130","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43125","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43126","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43126","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: mixer: oss: Add card disconnect checkpoints  ALSA OSS mixer layer calls the kcontrol ops rather individually, and pending calls might be not always caught at disconnecting the device.  For avoiding the potential UAF scenarios, add sanity checks of the card disconnection at each entry point of OSS mixer accesses.  The rwsem is taken just before that check, hence the rest context should be covered by that properly.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43126","epss":0.00129,"percentile":0.02827,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-43126","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43126","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/084d5d44418148662365eced3e126ad1a81ee3e2","https://git.kernel.org/stable/c/8c097cf736993454acf3f711a3b376d6c7ad8965","https://git.kernel.org/stable/c/ae583f113d15fa97e5234133c20d09f8e6214e47","https://git.kernel.org/stable/c/e6645e625480cdf1079a4265f758d13b70721029"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mixer: oss: Add card disconnect checkpoints\n\nALSA OSS mixer layer calls the kcontrol ops rather individually, and\npending calls might be not always caught at disconnecting the device.\n\nFor avoiding the potential UAF scenarios, add sanity checks of the\ncard disconnection at each entry point of OSS mixer accesses.  The\nrwsem is taken just before that check, hence the rest context should\nbe covered by that properly.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43126","epss":0.00129,"percentile":0.02827,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43126","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43129","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43129","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ima: verify the previous kernel's IMA buffer lies in addressable RAM  Patch series \"Address page fault in ima_restore_measurement_list()\", v3.  When the second-stage kernel is booted via kexec with a limiting command line such as \"mem=<size>\" we observe a pafe fault that happens.      BUG: unable to handle page fault for address: ffff97793ff47000     RIP: ima_restore_measurement_list+0xdc/0x45a     #PF: error_code(0x0000)  not-present page  This happens on x86_64 only, as this is already fixed in aarch64 in commit: cbf9c4b9617b (\"of: check previous kernel's ima-kexec-buffer against memory bounds\")   This patch (of 3):  When the second-stage kernel is booted with a limiting command line (e.g.  \"mem=<size>\"), the IMA measurement buffer handed over from the previous kernel may fall outside the addressable RAM of the new kernel.  Accessing such a buffer can fault during early restore.  Introduce a small generic helper, ima_validate_range(), which verifies that a physical [start, end] range for the previous-kernel IMA buffer lies within addressable memory: \t- On x86, use pfn_range_is_mapped(). \t- On OF based architectures, use page_is_ram().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43129","epss":0.00122,"percentile":0.02247,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43129","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43129","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/10d1c75ed4382a8e79874379caa2ead8952734f9","https://git.kernel.org/stable/c/43308106a1762b72f3b20a44b75b2df5cb25b77b","https://git.kernel.org/stable/c/5366ec7d2f793ce703c403d7fd4c25a3db365b9d","https://git.kernel.org/stable/c/9e1f51c1ad57cc76a0e8b5eb27038f8973fff4fa","https://git.kernel.org/stable/c/f11d7d088f5ed54b31c6735854c12845eb60eb4a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nima: verify the previous kernel's IMA buffer lies in addressable RAM\n\nPatch series \"Address page fault in ima_restore_measurement_list()\", v3.\n\nWhen the second-stage kernel is booted via kexec with a limiting command\nline such as \"mem=<size>\" we observe a pafe fault that happens.\n\n    BUG: unable to handle page fault for address: ffff97793ff47000\n    RIP: ima_restore_measurement_list+0xdc/0x45a\n    #PF: error_code(0x0000)  not-present page\n\nThis happens on x86_64 only, as this is already fixed in aarch64 in\ncommit: cbf9c4b9617b (\"of: check previous kernel's ima-kexec-buffer\nagainst memory bounds\")\n\n\nThis patch (of 3):\n\nWhen the second-stage kernel is booted with a limiting command line (e.g. \n\"mem=<size>\"), the IMA measurement buffer handed over from the previous\nkernel may fall outside the addressable RAM of the new kernel.  Accessing\nsuch a buffer can fault during early restore.\n\nIntroduce a small generic helper, ima_validate_range(), which verifies\nthat a physical [start, end] range for the previous-kernel IMA buffer lies\nwithin addressable memory:\n\t- On x86, use pfn_range_is_mapped().\n\t- On OF based architectures, use page_is_ram().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43129","epss":0.00122,"percentile":0.02247,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43129","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43137","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43137","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: SOF: Intel: hda: Fix NULL pointer dereference  If there's a mismatch between the DAI links in the machine driver and the topology, it is possible that the playback/capture widget is not set, especially in the case of loopback capture for echo reference where we use the dummy DAI link. Return the error when the widget is not set to avoid a null pointer dereference like below when the topology is broken.  RIP: 0010:hda_dai_get_ops.isra.0+0x14/0xa0 [snd_sof_intel_hda_common]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43137","epss":0.00127,"percentile":0.02721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43137","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2026-43137","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43137","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/10411f1f2c76be67103b1f95822ff629aa25e2aa","https://git.kernel.org/stable/c/16c589567a956d46a7c1363af3f64de3d420af20","https://git.kernel.org/stable/c/42068f7dd42b559c4eeae645e1455ff36518866a","https://git.kernel.org/stable/c/7750d78b4014902bc0ac03d4bb30faa076a913ab","https://git.kernel.org/stable/c/a1d4f3d3c0dc86527da6a19f6901a6a48375500d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: Intel: hda: Fix NULL pointer dereference\n\nIf there's a mismatch between the DAI links in the machine driver and\nthe topology, it is possible that the playback/capture widget is not\nset, especially in the case of loopback capture for echo reference\nwhere we use the dummy DAI link. Return the error when the widget is not\nset to avoid a null pointer dereference like below when the topology is\nbroken.\n\nRIP: 0010:hda_dai_get_ops.isra.0+0x14/0xa0 [snd_sof_intel_hda_common]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43137","epss":0.00127,"percentile":0.02721,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43137","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43137","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43153","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfs: remove xfs_attr_leaf_hasname  The calling convention of xfs_attr_leaf_hasname() is problematic, because it returns a NULL buffer when xfs_attr3_leaf_read fails, a valid buffer when xfs_attr3_leaf_lookup_int returns -ENOATTR or -EEXIST, and a non-NULL buffer pointer for an already released buffer when xfs_attr3_leaf_lookup_int fails with other error values.  Fix this by simply open coding xfs_attr_leaf_hasname in the callers, so that the buffer release code is done by each caller of xfs_attr3_leaf_read.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43153","epss":0.00138,"percentile":0.03511,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43153","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-43153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43153","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2fbc8421d1db102c0e5458607e042a23a03648b1","https://git.kernel.org/stable/c/3a65ea768b8094e4699e72f9ab420eb9e0f3f568","https://git.kernel.org/stable/c/457121c01f609b9934addbb04d5c1ef638c71c61","https://git.kernel.org/stable/c/530082df991903f3330354e99e0cb7b05debfa86"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: remove xfs_attr_leaf_hasname\n\nThe calling convention of xfs_attr_leaf_hasname() is problematic, because\nit returns a NULL buffer when xfs_attr3_leaf_read fails, a valid buffer\nwhen xfs_attr3_leaf_lookup_int returns -ENOATTR or -EEXIST, and a\nnon-NULL buffer pointer for an already released buffer when\nxfs_attr3_leaf_lookup_int fails with other error values.\n\nFix this by simply open coding xfs_attr_leaf_hasname in the callers, so\nthat the buffer release code is done by each caller of\nxfs_attr3_leaf_read.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43153","epss":0.00138,"percentile":0.03511,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43153","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43161","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43161","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode  PCIe endpoints with ATS enabled and passed through to userspace (e.g., QEMU, DPDK) can hard-lock the host when their link drops, either by surprise removal or by a link fault.  Commit 4fc82cd907ac (\"iommu/vt-d: Don't issue ATS Invalidation request when device is disconnected\") adds pci_dev_is_disconnected() to devtlb_invalidation_with_pasid() so ATS invalidation is skipped only when the device is being safely removed, but it applies only when Intel IOMMU scalable mode is enabled.  With scalable mode disabled or unsupported, a system hard-lock occurs when a PCIe endpoint's link drops because the Intel IOMMU waits indefinitely for an ATS invalidation that cannot complete.  Call Trace:  qi_submit_sync  qi_flush_dev_iotlb  __context_flush_dev_iotlb.part.0  domain_context_clear_one_cb  pci_for_each_dma_alias  device_block_translation  blocking_domain_attach_dev  iommu_deinit_device  __iommu_group_remove_device  iommu_release_device  iommu_bus_notifier  blocking_notifier_call_chain  bus_notify  device_del  pci_remove_bus_device  pci_stop_and_remove_bus_device  pciehp_unconfigure_device  pciehp_disable_slot  pciehp_handle_presence_or_link_change  pciehp_ist  Commit 81e921fd3216 (\"iommu/vt-d: Fix NULL domain on device release\") adds intel_pasid_teardown_sm_context() to intel_iommu_release_device(), which calls qi_flush_dev_iotlb() and can also hard-lock the system when a PCIe endpoint's link drops.  Call Trace:  qi_submit_sync  qi_flush_dev_iotlb  __context_flush_dev_iotlb.part.0  intel_context_flush_no_pasid  device_pasid_table_teardown  pci_pasid_table_teardown  pci_for_each_dma_alias  intel_pasid_teardown_sm_context  intel_iommu_release_device  iommu_deinit_device  __iommu_group_remove_device  iommu_release_device  iommu_bus_notifier  blocking_notifier_call_chain  bus_notify  device_del  pci_remove_bus_device  pci_stop_and_remove_bus_device  pciehp_unconfigure_device  pciehp_disable_slot  pciehp_handle_presence_or_link_change  pciehp_ist  Sometimes the endpoint loses connection without a link-down event (e.g., due to a link fault); killing the process (virsh destroy) then hard-locks the host.  Call Trace:  qi_submit_sync  qi_flush_dev_iotlb  __context_flush_dev_iotlb.part.0  domain_context_clear_one_cb  pci_for_each_dma_alias  device_block_translation  blocking_domain_attach_dev  __iommu_attach_device  __iommu_device_set_domain  __iommu_group_set_domain_internal  iommu_detach_group  vfio_iommu_type1_detach_group  vfio_group_detach_container  vfio_group_fops_release  __fput  pci_dev_is_disconnected() only covers safe-removal paths; pci_device_is_present() tests accessibility by reading vendor/device IDs and internally calls pci_dev_is_disconnected(). On a ConnectX-5 (8 GT/s, x2) this costs ~70 µs.  Since __context_flush_dev_iotlb() is only called on {attach,release}_dev paths (not hot), add pci_device_is_present() there to skip inaccessible devices and avoid the hard-lock.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43161","epss":0.00122,"percentile":0.02244,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43161","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43161","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/42662d19839f34735b718129ea200e3734b07e50","https://git.kernel.org/stable/c/48b3f08e68b29a79527869cdde7298ca2a9b9646","https://git.kernel.org/stable/c/bc0490ad9edf5c6f98e39fbbee2877b85261a5ae","https://git.kernel.org/stable/c/e70d5feb10c5ba2bbf7ca400b8f39a2f82d653e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode\n\nPCIe endpoints with ATS enabled and passed through to userspace\n(e.g., QEMU, DPDK) can hard-lock the host when their link drops,\neither by surprise removal or by a link fault.\n\nCommit 4fc82cd907ac (\"iommu/vt-d: Don't issue ATS Invalidation\nrequest when device is disconnected\") adds pci_dev_is_disconnected()\nto devtlb_invalidation_with_pasid() so ATS invalidation is skipped\nonly when the device is being safely removed, but it applies only\nwhen Intel IOMMU scalable mode is enabled.\n\nWith scalable mode disabled or unsupported, a system hard-lock\noccurs when a PCIe endpoint's link drops because the Intel IOMMU\nwaits indefinitely for an ATS invalidation that cannot complete.\n\nCall Trace:\n qi_submit_sync\n qi_flush_dev_iotlb\n __context_flush_dev_iotlb.part.0\n domain_context_clear_one_cb\n pci_for_each_dma_alias\n device_block_translation\n blocking_domain_attach_dev\n iommu_deinit_device\n __iommu_group_remove_device\n iommu_release_device\n iommu_bus_notifier\n blocking_notifier_call_chain\n bus_notify\n device_del\n pci_remove_bus_device\n pci_stop_and_remove_bus_device\n pciehp_unconfigure_device\n pciehp_disable_slot\n pciehp_handle_presence_or_link_change\n pciehp_ist\n\nCommit 81e921fd3216 (\"iommu/vt-d: Fix NULL domain on device release\")\nadds intel_pasid_teardown_sm_context() to intel_iommu_release_device(),\nwhich calls qi_flush_dev_iotlb() and can also hard-lock the system\nwhen a PCIe endpoint's link drops.\n\nCall Trace:\n qi_submit_sync\n qi_flush_dev_iotlb\n __context_flush_dev_iotlb.part.0\n intel_context_flush_no_pasid\n device_pasid_table_teardown\n pci_pasid_table_teardown\n pci_for_each_dma_alias\n intel_pasid_teardown_sm_context\n intel_iommu_release_device\n iommu_deinit_device\n __iommu_group_remove_device\n iommu_release_device\n iommu_bus_notifier\n blocking_notifier_call_chain\n bus_notify\n device_del\n pci_remove_bus_device\n pci_stop_and_remove_bus_device\n pciehp_unconfigure_device\n pciehp_disable_slot\n pciehp_handle_presence_or_link_change\n pciehp_ist\n\nSometimes the endpoint loses connection without a link-down event\n(e.g., due to a link fault); killing the process (virsh destroy)\nthen hard-locks the host.\n\nCall Trace:\n qi_submit_sync\n qi_flush_dev_iotlb\n __context_flush_dev_iotlb.part.0\n domain_context_clear_one_cb\n pci_for_each_dma_alias\n device_block_translation\n blocking_domain_attach_dev\n __iommu_attach_device\n __iommu_device_set_domain\n __iommu_group_set_domain_internal\n iommu_detach_group\n vfio_iommu_type1_detach_group\n vfio_group_detach_container\n vfio_group_fops_release\n __fput\n\npci_dev_is_disconnected() only covers safe-removal paths;\npci_device_is_present() tests accessibility by reading\nvendor/device IDs and internally calls pci_dev_is_disconnected().\nOn a ConnectX-5 (8 GT/s, x2) this costs ~70 µs.\n\nSince __context_flush_dev_iotlb() is only called on\n{attach,release}_dev paths (not hot), add pci_device_is_present()\nthere to skip inaccessible devices and avoid the hard-lock.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43161","epss":0.00122,"percentile":0.02244,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43161","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43167","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43167","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: always flush state and policy upon NETDEV_UNREGISTER event  syzbot is reporting that \"struct xfrm_state\" refcount is leaking.    unregister_netdevice: waiting for netdevsim0 to become free. Usage count = 2   ref_tracker: netdev@ffff888052f24618 has 1/1 users at        __netdev_tracker_alloc include/linux/netdevice.h:4400 [inline]        netdev_tracker_alloc include/linux/netdevice.h:4412 [inline]        xfrm_dev_state_add+0x3a5/0x1080 net/xfrm/xfrm_device.c:316        xfrm_state_construct net/xfrm/xfrm_user.c:986 [inline]        xfrm_add_sa+0x34ff/0x5fa0 net/xfrm/xfrm_user.c:1022        xfrm_user_rcv_msg+0x58e/0xc00 net/xfrm/xfrm_user.c:3507        netlink_rcv_skb+0x158/0x420 net/netlink/af_netlink.c:2550        xfrm_netlink_rcv+0x71/0x90 net/xfrm/xfrm_user.c:3529        netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]        netlink_unicast+0x5aa/0x870 net/netlink/af_netlink.c:1344        netlink_sendmsg+0x8c8/0xdd0 net/netlink/af_netlink.c:1894        sock_sendmsg_nosec net/socket.c:727 [inline]        __sock_sendmsg net/socket.c:742 [inline]        ____sys_sendmsg+0xa5d/0xc30 net/socket.c:2592        ___sys_sendmsg+0x134/0x1d0 net/socket.c:2646        __sys_sendmsg+0x16d/0x220 net/socket.c:2678        do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]        do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94        entry_SYSCALL_64_after_hwframe+0x77/0x7f  This is because commit d77e38e612a0 (\"xfrm: Add an IPsec hardware offloading API\") implemented xfrm_dev_unregister() as no-op despite xfrm_dev_state_add() from xfrm_state_construct() acquires a reference to \"struct net_device\". I guess that that commit expected that NETDEV_DOWN event is fired before NETDEV_UNREGISTER event fires, and also assumed that xfrm_dev_state_add() is called only if (dev->features & NETIF_F_HW_ESP) != 0.  Sabrina Dubroca identified steps to reproduce the same symptoms as below.    echo 0 > /sys/bus/netdevsim/new_device   dev=$(ls -1 /sys/bus/netdevsim/devices/netdevsim0/net/)   ip xfrm state add src 192.168.13.1 dst 192.168.13.2 proto esp \\      spi 0x1000 mode tunnel aead 'rfc4106(gcm(aes))' $key 128   \\      offload crypto dev $dev dir out   ethtool -K $dev esp-hw-offload off   echo 0 > /sys/bus/netdevsim/del_device  Like these steps indicate, the NETIF_F_HW_ESP bit can be cleared after xfrm_dev_state_add() acquired a reference to \"struct net_device\". Also, xfrm_dev_state_add() does not check for the NETIF_F_HW_ESP bit when acquiring a reference to \"struct net_device\".  Commit 03891f820c21 (\"xfrm: handle NETDEV_UNREGISTER for xfrm device\") re-introduced the NETDEV_UNREGISTER event to xfrm_dev_event(), but that commit for unknown reason chose to share xfrm_dev_down() between the NETDEV_DOWN event and the NETDEV_UNREGISTER event. I guess that that commit missed the behavior in the previous paragraph.  Therefore, we need to re-introduce xfrm_dev_unregister() in order to release the reference to \"struct net_device\" by unconditionally flushing state and policy.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43167","epss":0.00122,"percentile":0.02247,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43167","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43167","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/166801e49a5b5fc127b8c9e2f110f303cfddfbc3","https://git.kernel.org/stable/c/4efa91a28576054aae0e6dad9cba8fed8293aef8","https://git.kernel.org/stable/c/59581778792cbaf8ad788f4a21dc663ce986050e","https://git.kernel.org/stable/c/8c75c455ecd3bfd2f36abf66edb7021c4fa19ec4","https://git.kernel.org/stable/c/a3c8fede034fa27892f87c863cbd5493167d17ed"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: always flush state and policy upon NETDEV_UNREGISTER event\n\nsyzbot is reporting that \"struct xfrm_state\" refcount is leaking.\n\n  unregister_netdevice: waiting for netdevsim0 to become free. Usage count = 2\n  ref_tracker: netdev@ffff888052f24618 has 1/1 users at\n       __netdev_tracker_alloc include/linux/netdevice.h:4400 [inline]\n       netdev_tracker_alloc include/linux/netdevice.h:4412 [inline]\n       xfrm_dev_state_add+0x3a5/0x1080 net/xfrm/xfrm_device.c:316\n       xfrm_state_construct net/xfrm/xfrm_user.c:986 [inline]\n       xfrm_add_sa+0x34ff/0x5fa0 net/xfrm/xfrm_user.c:1022\n       xfrm_user_rcv_msg+0x58e/0xc00 net/xfrm/xfrm_user.c:3507\n       netlink_rcv_skb+0x158/0x420 net/netlink/af_netlink.c:2550\n       xfrm_netlink_rcv+0x71/0x90 net/xfrm/xfrm_user.c:3529\n       netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]\n       netlink_unicast+0x5aa/0x870 net/netlink/af_netlink.c:1344\n       netlink_sendmsg+0x8c8/0xdd0 net/netlink/af_netlink.c:1894\n       sock_sendmsg_nosec net/socket.c:727 [inline]\n       __sock_sendmsg net/socket.c:742 [inline]\n       ____sys_sendmsg+0xa5d/0xc30 net/socket.c:2592\n       ___sys_sendmsg+0x134/0x1d0 net/socket.c:2646\n       __sys_sendmsg+0x16d/0x220 net/socket.c:2678\n       do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n       do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94\n       entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nThis is because commit d77e38e612a0 (\"xfrm: Add an IPsec hardware\noffloading API\") implemented xfrm_dev_unregister() as no-op despite\nxfrm_dev_state_add() from xfrm_state_construct() acquires a reference\nto \"struct net_device\".\nI guess that that commit expected that NETDEV_DOWN event is fired before\nNETDEV_UNREGISTER event fires, and also assumed that xfrm_dev_state_add()\nis called only if (dev->features & NETIF_F_HW_ESP) != 0.\n\nSabrina Dubroca identified steps to reproduce the same symptoms as below.\n\n  echo 0 > /sys/bus/netdevsim/new_device\n  dev=$(ls -1 /sys/bus/netdevsim/devices/netdevsim0/net/)\n  ip xfrm state add src 192.168.13.1 dst 192.168.13.2 proto esp \\\n     spi 0x1000 mode tunnel aead 'rfc4106(gcm(aes))' $key 128   \\\n     offload crypto dev $dev dir out\n  ethtool -K $dev esp-hw-offload off\n  echo 0 > /sys/bus/netdevsim/del_device\n\nLike these steps indicate, the NETIF_F_HW_ESP bit can be cleared after\nxfrm_dev_state_add() acquired a reference to \"struct net_device\".\nAlso, xfrm_dev_state_add() does not check for the NETIF_F_HW_ESP bit\nwhen acquiring a reference to \"struct net_device\".\n\nCommit 03891f820c21 (\"xfrm: handle NETDEV_UNREGISTER for xfrm device\")\nre-introduced the NETDEV_UNREGISTER event to xfrm_dev_event(), but that\ncommit for unknown reason chose to share xfrm_dev_down() between the\nNETDEV_DOWN event and the NETDEV_UNREGISTER event.\nI guess that that commit missed the behavior in the previous paragraph.\n\nTherefore, we need to re-introduce xfrm_dev_unregister() in order to\nrelease the reference to \"struct net_device\" by unconditionally flushing\nstate and policy.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43167","epss":0.00122,"percentile":0.02247,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43167","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43170","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43170","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: dwc3: gadget: Move vbus draw to workqueue context  Currently dwc3_gadget_vbus_draw() can be called from atomic context, which in turn invokes power-supply-core APIs. And some these PMIC APIs have operations that may sleep, leading to kernel panic.  Fix this by moving the vbus_draw into a workqueue context.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43170","epss":0.00125,"percentile":0.02488,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.065625},"relatedVulnerabilities":[{"id":"CVE-2026-43170","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43170","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2333653ef854c2cc124077f71a8526f03bf6e06a","https://git.kernel.org/stable/c/54aaa3b387c2f580a99dc86a9cc2eb6dfaf599a7","https://git.kernel.org/stable/c/74a231e3d99d310497ab0ccb359539a6063b316a","https://git.kernel.org/stable/c/76c1123ffccfaba95cf4ecc2a50f95504a522424","https://git.kernel.org/stable/c/a7a80c25b65112768eeba58a7af129d3c52a6d90"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: gadget: Move vbus draw to workqueue context\n\nCurrently dwc3_gadget_vbus_draw() can be called from atomic\ncontext, which in turn invokes power-supply-core APIs. And\nsome these PMIC APIs have operations that may sleep, leading\nto kernel panic.\n\nFix this by moving the vbus_draw into a workqueue context.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43170","epss":0.00125,"percentile":0.02488,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43170","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43172","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43172","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: iwlwifi: fix 22000 series SMEM parsing  If the firmware were to report three LMACs (which doesn't exist in hardware) then using \"fwrt->smem_cfg.lmac[2]\" is an overrun of the array. Reject such and use IWL_FW_CHECK instead of WARN_ON in this function.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43172","epss":0.00256,"percentile":0.17256,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.20864000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-43172","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43172","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1d49a42717bdc8de77eabeb5b7d3e88d141ffea9","https://git.kernel.org/stable/c/2b4b1510aaaf5b9fb57327ecffc20c055f61f205","https://git.kernel.org/stable/c/58192b9ce09b0f0f86e2036683bd542130b91a98"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: fix 22000 series SMEM parsing\n\nIf the firmware were to report three LMACs (which doesn't\nexist in hardware) then using \"fwrt->smem_cfg.lmac[2]\" is\nan overrun of the array. Reject such and use IWL_FW_CHECK\ninstead of WARN_ON in this function.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43172","epss":0.00256,"percentile":0.17256,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43172","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43173","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43173","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ethernet: xscale: Check for PTP support properly  In ixp4xx_get_ts_info() ixp46x_ptp_find() is called unconditionally despite this feature only existing on ixp46x, leading to the following splat from tcpdump:  root@OpenWrt:~# tcpdump -vv -X -i eth0 (...) Unable to handle kernel NULL pointer dereference at virtual address   00000238 when read (...) Call trace:  ptp_clock_index from ixp46x_ptp_find+0x1c/0x38  ixp46x_ptp_find from ixp4xx_get_ts_info+0x4c/0x64  ixp4xx_get_ts_info from __ethtool_get_ts_info+0x90/0x108  __ethtool_get_ts_info from __dev_ethtool+0xa00/0x2648  __dev_ethtool from dev_ethtool+0x160/0x234  dev_ethtool from dev_ioctl+0x2cc/0x460  dev_ioctl from sock_ioctl+0x1ec/0x524  sock_ioctl from sys_ioctl+0x51c/0xa94  sys_ioctl from ret_fast_syscall+0x0/0x44  (...) Segmentation fault  Check for ixp46x in ixp46x_ptp_find() before trying to set up PTP to avoid this.  To avoid altering the returned error code from ixp4xx_hwtstamp_set() which before this patch was -EOPNOTSUPP, we return -EOPNOTSUPP from ixp4xx_hwtstamp_set() if ixp46x_ptp_find() fails no matter the error code. The helper function ixp46x_ptp_find() helper returns -ENODEV.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43173","epss":0.00122,"percentile":0.02249,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43173","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43173","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43173","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/21d1e80d0d6e7d0c3cd8b1e001ed1fa92fb9f3f5","https://git.kernel.org/stable/c/2d74412dfd3621552a394d55cc3dd26a7cbf608e","https://git.kernel.org/stable/c/322437972f0a712767f6920ad34aba25f2e9b942","https://git.kernel.org/stable/c/594163ea88a03bdb412063af50fc7177ef3cbeae","https://git.kernel.org/stable/c/cbecebd35909f6cd0f6fb773f0fb73da99e02f8c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: xscale: Check for PTP support properly\n\nIn ixp4xx_get_ts_info() ixp46x_ptp_find() is called\nunconditionally despite this feature only existing on\nixp46x, leading to the following splat from tcpdump:\n\nroot@OpenWrt:~# tcpdump -vv -X -i eth0\n(...)\nUnable to handle kernel NULL pointer dereference at virtual address\n  00000238 when read\n(...)\nCall trace:\n ptp_clock_index from ixp46x_ptp_find+0x1c/0x38\n ixp46x_ptp_find from ixp4xx_get_ts_info+0x4c/0x64\n ixp4xx_get_ts_info from __ethtool_get_ts_info+0x90/0x108\n __ethtool_get_ts_info from __dev_ethtool+0xa00/0x2648\n __dev_ethtool from dev_ethtool+0x160/0x234\n dev_ethtool from dev_ioctl+0x2cc/0x460\n dev_ioctl from sock_ioctl+0x1ec/0x524\n sock_ioctl from sys_ioctl+0x51c/0xa94\n sys_ioctl from ret_fast_syscall+0x0/0x44\n (...)\nSegmentation fault\n\nCheck for ixp46x in ixp46x_ptp_find() before trying to set up\nPTP to avoid this.\n\nTo avoid altering the returned error code from ixp4xx_hwtstamp_set()\nwhich before this patch was -EOPNOTSUPP, we return -EOPNOTSUPP\nfrom ixp4xx_hwtstamp_set() if ixp46x_ptp_find() fails no matter\nthe error code. The helper function ixp46x_ptp_find() helper\nreturns -ENODEV.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43173","epss":0.00122,"percentile":0.02249,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43173","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43173","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43185","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43185","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix signededness bug in smb_direct_prepare_negotiation()  smb_direct_prepare_negotiation() casts an unsigned __u32 value from sp->max_recv_size and req->preferred_send_size to a signed int before computing min_t(int, ...). A maliciously provided preferred_send_size of 0x80000000 will return as smaller than max_recv_size, and then be used to set the maximum allowed alowed receive size for the next message.  By sending a second message with a large value (>1420 bytes) the attacker can then achieve a heap buffer overflow.  This fix replaces min_t(int, ...) with min_t(u32)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43185","epss":0.00622,"percentile":0.47795,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43185","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.58468},"relatedVulnerabilities":[{"id":"CVE-2026-43185","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43185","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/55abc475d096da4a5356b6efb0cfdc6156bc1550","https://git.kernel.org/stable/c/6b4f875aac344cdd52a1f34cc70ed2f874a65757","https://git.kernel.org/stable/c/ceae058eb707ddd0d68f0872f9d9f23b7c30c37b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix signededness bug in smb_direct_prepare_negotiation()\n\nsmb_direct_prepare_negotiation() casts an unsigned __u32 value\nfrom sp->max_recv_size and req->preferred_send_size to a signed\nint before computing min_t(int, ...). A maliciously provided\npreferred_send_size of 0x80000000 will return as smaller than\nmax_recv_size, and then be used to set the maximum allowed\nalowed receive size for the next message.\n\nBy sending a second message with a large value (>1420 bytes)\nthe attacker can then achieve a heap buffer overflow.\n\nThis fix replaces min_t(int, ...) with min_t(u32)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43185","epss":0.00622,"percentile":0.47795,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43185","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43185","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43198","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tcp: fix potential race in tcp_v6_syn_recv_sock()  Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late.  After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it.  Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found.  Move the problematic code in tcp_v6_mapped_child_init() and call this new helper from tcp_v4_syn_recv_sock() before the ehash insertion.  This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the correct context.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43198","epss":0.00298,"percentile":0.22267,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43198","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-43198","cwe":"CWE-821","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.21605000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-43198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43198","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7178e2a8027423b2af17ab95df73a749a5b72e5b","https://git.kernel.org/stable/c/858d2a4f67ff69e645a43487ef7ea7f28f06deae","https://git.kernel.org/stable/c/fe89b2f05b854847784f91127319172945c1fadd","https://access.redhat.com/errata/RHSA-2026:30129","https://access.redhat.com/errata/RHSA-2026:33215","https://access.redhat.com/errata/RHSA-2026:33285","https://access.redhat.com/errata/RHSA-2026:34094","https://access.redhat.com/errata/RHSA-2026:34443","https://access.redhat.com/errata/RHSA-2026:35863","https://access.redhat.com/errata/RHSA-2026:35894","https://access.redhat.com/errata/RHSA-2026:35896","https://access.redhat.com/errata/RHSA-2026:35904","https://access.redhat.com/errata/RHSA-2026:36073","https://access.redhat.com/errata/RHSA-2026:36216","https://access.redhat.com/errata/RHSA-2026:36348","https://access.redhat.com/errata/RHSA-2026:36349","https://access.redhat.com/errata/RHSA-2026:41236","https://access.redhat.com/security/cve/CVE-2026-43198","https://bugzilla.redhat.com/show_bug.cgi?id=2467228","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43198.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix potential race in tcp_v6_syn_recv_sock()\n\nCode in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock()\nis done too late.\n\nAfter tcp_v4_syn_recv_sock(), the child socket is already visible\nfrom TCP ehash table and other cpus might use it.\n\nSince newinet->pinet6 is still pointing to the listener ipv6_pinfo\nbad things can happen as syzbot found.\n\nMove the problematic code in tcp_v6_mapped_child_init()\nand call this new helper from tcp_v4_syn_recv_sock() before\nthe ehash insertion.\n\nThis allows the removal of one tcp_sync_mss(), since\ntcp_v4_syn_recv_sock() will call it with the correct\ncontext.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43198","epss":0.00298,"percentile":0.22267,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43198","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-43198","cwe":"CWE-821","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43204","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43204","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: qcom: q6asm: drop DSP responses for closed data streams  'Commit a354f030dbce (\"ASoC: qcom: q6asm: handle the responses after closing\")' attempted to ignore DSP responses arriving after a stream had been closed.  However, those responses were still handled, causing lockups.  Fix this by unconditionally dropping all DSP responses associated with closed data streams.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43204","epss":0.00112,"percentile":0.01521,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-43204","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43204","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3249251eac6081d5169ba09f2d9cca66ab0cab0d","https://git.kernel.org/stable/c/8a066a81ee0c1b6cdbd81393536c3b2d19ccef25"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: q6asm: drop DSP responses for closed data streams\n\n'Commit a354f030dbce (\"ASoC: qcom: q6asm: handle the responses\nafter closing\")' attempted to ignore DSP responses arriving\nafter a stream had been closed.\n\nHowever, those responses were still handled, causing lockups.\n\nFix this by unconditionally dropping all DSP responses associated with\nclosed data streams.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43204","epss":0.00112,"percentile":0.01521,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43204","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43213","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43213","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw89: pci: validate sequence number of TX release report  Hardware rarely reports abnormal sequence number in TX release report, which will access out-of-bounds of wd_ring->pages array, causing NULL pointer dereference.    BUG: kernel NULL pointer dereference, address: 0000000000000000   #PF: supervisor read access in kernel mode   #PF: error_code(0x0000) - not-present page   PGD 0 P4D 0   Oops: 0000 [#1] PREEMPT SMP NOPTI   CPU: 1 PID: 1085 Comm: irq/129-rtw89_p Tainted: G S   U              6.1.145-17510-g2f3369c91536 #1 (HASH:69e8 1)   Call Trace:    <IRQ>    rtw89_pci_release_tx+0x18f/0x300 [rtw89_pci (HASH:4c83 2)]    rtw89_pci_napi_poll+0xc2/0x190 [rtw89_pci (HASH:4c83 2)]    net_rx_action+0xfc/0x460 net/core/dev.c:6578 net/core/dev.c:6645 net/core/dev.c:6759    handle_softirqs+0xbe/0x290 kernel/softirq.c:601    ? rtw89_pci_interrupt_threadfn+0xc5/0x350 [rtw89_pci (HASH:4c83 2)]    __local_bh_enable_ip+0xeb/0x120 kernel/softirq.c:499 kernel/softirq.c:423    </IRQ>    <TASK>    rtw89_pci_interrupt_threadfn+0xf8/0x350 [rtw89_pci (HASH:4c83 2)]    ? irq_thread+0xa7/0x340 kernel/irq/manage.c:0    irq_thread+0x177/0x340 kernel/irq/manage.c:1205 kernel/irq/manage.c:1314    ? thaw_kernel_threads+0xb0/0xb0 kernel/irq/manage.c:1202    ? irq_forced_thread_fn+0x80/0x80 kernel/irq/manage.c:1220    kthread+0xea/0x110 kernel/kthread.c:376    ? synchronize_irq+0x1a0/0x1a0 kernel/irq/manage.c:1287    ? kthread_associate_blkcg+0x80/0x80 kernel/kthread.c:331    ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295    </TASK>  To prevent crash, validate rpp_info.seq before using.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43213","epss":0.0022,"percentile":0.12524,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43213","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.165},"relatedVulnerabilities":[{"id":"CVE-2026-43213","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43213","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/957eda596c7665f2966970fd1dcc35fe299b38e8","https://git.kernel.org/stable/c/b342dd13aedccb0dd27365f6cc63a262f42394ce","https://git.kernel.org/stable/c/ef7fa19809b2d892d45da53f90ac698d13c367fd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: pci: validate sequence number of TX release report\n\nHardware rarely reports abnormal sequence number in TX release report,\nwhich will access out-of-bounds of wd_ring->pages array, causing NULL\npointer dereference.\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  PGD 0 P4D 0\n  Oops: 0000 [#1] PREEMPT SMP NOPTI\n  CPU: 1 PID: 1085 Comm: irq/129-rtw89_p Tainted: G S   U\n             6.1.145-17510-g2f3369c91536 #1 (HASH:69e8 1)\n  Call Trace:\n   <IRQ>\n   rtw89_pci_release_tx+0x18f/0x300 [rtw89_pci (HASH:4c83 2)]\n   rtw89_pci_napi_poll+0xc2/0x190 [rtw89_pci (HASH:4c83 2)]\n   net_rx_action+0xfc/0x460 net/core/dev.c:6578 net/core/dev.c:6645 net/core/dev.c:6759\n   handle_softirqs+0xbe/0x290 kernel/softirq.c:601\n   ? rtw89_pci_interrupt_threadfn+0xc5/0x350 [rtw89_pci (HASH:4c83 2)]\n   __local_bh_enable_ip+0xeb/0x120 kernel/softirq.c:499 kernel/softirq.c:423\n   </IRQ>\n   <TASK>\n   rtw89_pci_interrupt_threadfn+0xf8/0x350 [rtw89_pci (HASH:4c83 2)]\n   ? irq_thread+0xa7/0x340 kernel/irq/manage.c:0\n   irq_thread+0x177/0x340 kernel/irq/manage.c:1205 kernel/irq/manage.c:1314\n   ? thaw_kernel_threads+0xb0/0xb0 kernel/irq/manage.c:1202\n   ? irq_forced_thread_fn+0x80/0x80 kernel/irq/manage.c:1220\n   kthread+0xea/0x110 kernel/kthread.c:376\n   ? synchronize_irq+0x1a0/0x1a0 kernel/irq/manage.c:1287\n   ? kthread_associate_blkcg+0x80/0x80 kernel/kthread.c:331\n   ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295\n   </TASK>\n\nTo prevent crash, validate rpp_info.seq before using.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43213","epss":0.0022,"percentile":0.12524,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43213","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43213","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43215","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43215","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cifs: Fix locking usage for tcon fields  We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lock and tc_lock to protect fields within the corresponding structs. This was done to provide a more granular protection and avoid unnecessary serialization.  There were still a couple of uses of cifs_tcp_ses_lock to provide tcon fields. In this patch, I've replaced them with tc_lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43215","epss":0.00298,"percentile":0.22276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43215","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24287000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-43215","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43215","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3969db6b22e3d90d8c5f22ac1a7fe0350a94c136","https://git.kernel.org/stable/c/601dd3b79769b38d30b693c40afdb2a4b7edf9d0","https://git.kernel.org/stable/c/8c59eeeeffa1524ef57e173a89a1a3ff539888d5","https://git.kernel.org/stable/c/953953abb66e52c224057ab91e404284fefeab62","https://git.kernel.org/stable/c/96c4af418586ee9a6aab61738644366426e05316"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix locking usage for tcon fields\n\nWe used to use the cifs_tcp_ses_lock to protect a lot of objects\nthat are not just the server, ses or tcon lists. We later introduced\nsrv_lock, ses_lock and tc_lock to protect fields within the\ncorresponding structs. This was done to provide a more granular\nprotection and avoid unnecessary serialization.\n\nThere were still a couple of uses of cifs_tcp_ses_lock to provide\ntcon fields. In this patch, I've replaced them with tc_lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43215","epss":0.00298,"percentile":0.22276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43215","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43215","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43234","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43234","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  team: avoid NETDEV_CHANGEMTU event when unregistering slave  syzbot is reporting    unregister_netdevice: waiting for netdevsim0 to become free. Usage count = 3   ref_tracker: netdev@ffff88807dcf8618 has 1/2 users at        __netdev_tracker_alloc include/linux/netdevice.h:4400 [inline]        netdev_hold include/linux/netdevice.h:4429 [inline]        inetdev_init+0x201/0x4e0 net/ipv4/devinet.c:286        inetdev_event+0x251/0x1610 net/ipv4/devinet.c:1600        notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85        call_netdevice_notifiers_mtu net/core/dev.c:2318 [inline]        netif_set_mtu_ext+0x5aa/0x800 net/core/dev.c:9886        netif_set_mtu+0xd7/0x1b0 net/core/dev.c:9907        dev_set_mtu+0x126/0x260 net/core/dev_api.c:248        team_port_del+0xb07/0xcb0 drivers/net/team/team_core.c:1333        team_del_slave drivers/net/team/team_core.c:1936 [inline]        team_device_event+0x207/0x5b0 drivers/net/team/team_core.c:2929        notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85        call_netdevice_notifiers_extack net/core/dev.c:2281 [inline]        call_netdevice_notifiers net/core/dev.c:2295 [inline]        __dev_change_net_namespace+0xcb7/0x2050 net/core/dev.c:12592        do_setlink+0x2ce/0x4590 net/core/rtnetlink.c:3060        rtnl_changelink net/core/rtnetlink.c:3776 [inline]        __rtnl_newlink net/core/rtnetlink.c:3935 [inline]        rtnl_newlink+0x15a9/0x1be0 net/core/rtnetlink.c:4072        rtnetlink_rcv_msg+0x7d5/0xbe0 net/core/rtnetlink.c:6958        netlink_rcv_skb+0x232/0x4b0 net/netlink/af_netlink.c:2550        netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]        netlink_unicast+0x80f/0x9b0 net/netlink/af_netlink.c:1344        netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1894  problem. Ido Schimmel found steps to reproduce    ip link add name team1 type team   ip link add name dummy1 mtu 1499 master team1 type dummy   ip netns add ns1   ip link set dev dummy1 netns ns1   ip -n ns1 link del dev dummy1  and also found that the same issue was fixed in the bond driver in commit f51048c3e07b (\"bonding: avoid NETDEV_CHANGEMTU event when unregistering slave\").  Let's do similar thing for the team driver, with commit ad7c7b2172c3 (\"net: hold netdev instance lock during sysfs operations\") and commit 303a8487a657 (\"net: s/__dev_set_mtu/__netif_set_mtu/\") also applied.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43234","epss":0.00121,"percentile":0.02146,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-43234","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43234","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5268892de70f0b29bde341db863b234aa9259c08","https://git.kernel.org/stable/c/bb4c698633c0e19717586a6524a33196cff01a32","https://git.kernel.org/stable/c/bce42728ac4887060a24a585c5122fbd24939db7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nteam: avoid NETDEV_CHANGEMTU event when unregistering slave\n\nsyzbot is reporting\n\n  unregister_netdevice: waiting for netdevsim0 to become free. Usage count = 3\n  ref_tracker: netdev@ffff88807dcf8618 has 1/2 users at\n       __netdev_tracker_alloc include/linux/netdevice.h:4400 [inline]\n       netdev_hold include/linux/netdevice.h:4429 [inline]\n       inetdev_init+0x201/0x4e0 net/ipv4/devinet.c:286\n       inetdev_event+0x251/0x1610 net/ipv4/devinet.c:1600\n       notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85\n       call_netdevice_notifiers_mtu net/core/dev.c:2318 [inline]\n       netif_set_mtu_ext+0x5aa/0x800 net/core/dev.c:9886\n       netif_set_mtu+0xd7/0x1b0 net/core/dev.c:9907\n       dev_set_mtu+0x126/0x260 net/core/dev_api.c:248\n       team_port_del+0xb07/0xcb0 drivers/net/team/team_core.c:1333\n       team_del_slave drivers/net/team/team_core.c:1936 [inline]\n       team_device_event+0x207/0x5b0 drivers/net/team/team_core.c:2929\n       notifier_call_chain+0x19d/0x3a0 kernel/notifier.c:85\n       call_netdevice_notifiers_extack net/core/dev.c:2281 [inline]\n       call_netdevice_notifiers net/core/dev.c:2295 [inline]\n       __dev_change_net_namespace+0xcb7/0x2050 net/core/dev.c:12592\n       do_setlink+0x2ce/0x4590 net/core/rtnetlink.c:3060\n       rtnl_changelink net/core/rtnetlink.c:3776 [inline]\n       __rtnl_newlink net/core/rtnetlink.c:3935 [inline]\n       rtnl_newlink+0x15a9/0x1be0 net/core/rtnetlink.c:4072\n       rtnetlink_rcv_msg+0x7d5/0xbe0 net/core/rtnetlink.c:6958\n       netlink_rcv_skb+0x232/0x4b0 net/netlink/af_netlink.c:2550\n       netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]\n       netlink_unicast+0x80f/0x9b0 net/netlink/af_netlink.c:1344\n       netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1894\n\nproblem. Ido Schimmel found steps to reproduce\n\n  ip link add name team1 type team\n  ip link add name dummy1 mtu 1499 master team1 type dummy\n  ip netns add ns1\n  ip link set dev dummy1 netns ns1\n  ip -n ns1 link del dev dummy1\n\nand also found that the same issue was fixed in the bond driver in\ncommit f51048c3e07b (\"bonding: avoid NETDEV_CHANGEMTU event when\nunregistering slave\").\n\nLet's do similar thing for the team driver, with commit ad7c7b2172c3 (\"net:\nhold netdev instance lock during sysfs operations\") and commit 303a8487a657\n(\"net: s/__dev_set_mtu/__netif_set_mtu/\") also applied.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43234","epss":0.00121,"percentile":0.02146,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43234","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43239","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43239","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: prevent races in ->query_interfaces()  It was possible for two query interface works to be concurrently trying to update the interfaces.  Prevent this by checking and updating iface_last_update under iface_lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43239","epss":0.00354,"percentile":0.28604,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.28851000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-43239","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43239","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6287eefaf21ec805d42f941bd368018cf397a7f5","https://git.kernel.org/stable/c/76cc4faba0343c6db945b8dc75425b33d633e1b8","https://git.kernel.org/stable/c/93e8e3ee165ae4609a1222b516b573837103d2c3","https://git.kernel.org/stable/c/ab6564f416a6eaf1199200b6100952407b438f7d","https://git.kernel.org/stable/c/c3c06e42e1527716c54f3ad2ced6a034b5f3a489"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: prevent races in ->query_interfaces()\n\nIt was possible for two query interface works to be concurrently trying\nto update the interfaces.\n\nPrevent this by checking and updating iface_last_update under\niface_lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43239","epss":0.00354,"percentile":0.28604,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43239","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43244","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  kcm: fix zero-frag skb in frag_list on partial sendmsg error  Syzkaller reported a warning in kcm_write_msgs() when processing a message with a zero-fragment skb in the frag_list.  When kcm_sendmsg() fills MAX_SKB_FRAGS fragments in the current skb, it allocates a new skb (tskb) and links it into the frag_list before copying data. If the copy subsequently fails (e.g. -EFAULT from user memory), tskb remains in the frag_list with zero fragments:    head skb (msg being assembled, NOT yet in sk_write_queue)   +-----------+   | frags[17] |  (MAX_SKB_FRAGS, all filled with data)   | frag_list-+--> tskb   +-----------+    +----------+                    | frags[0] |  (empty! copy failed before filling)                    +----------+  For SOCK_SEQPACKET with partial data already copied, the error path saves this message via partial_message for later completion. For SOCK_SEQPACKET, sock_write_iter() automatically sets MSG_EOR, so a subsequent zero-length write(fd, NULL, 0) completes the message and queues it to sk_write_queue. kcm_write_msgs() then walks the frag_list and hits:    WARN_ON(!skb_shinfo(skb)->nr_frags)  TCP has a similar pattern where skbs are enqueued before data copy and cleaned up on failure via tcp_remove_empty_skb(). KCM was missing the equivalent cleanup.  Fix this by tracking the predecessor skb (frag_prev) when allocating a new frag_list entry. On error, if the tail skb has zero frags, use frag_prev to unlink and free it in O(1) without walking the singly-linked frag_list. frag_prev is safe to dereference because the entire message chain is only held locally (or in kcm->seq_skb) and is not added to sk_write_queue until MSG_EOR, so the send path cannot free it underneath us.  Also change the WARN_ON to WARN_ON_ONCE to avoid flooding the log if the condition is somehow hit repeatedly.  There are currently no KCM selftests in the kernel tree; a simple reproducer is available at [1].  [1] https://gist.github.com/mrpre/a94d431c757e8d6f168f4dd1a3749daa","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43244","epss":0.00122,"percentile":0.02253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43244","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43244","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7af58f76e4b404a74c836881a845e6652db8a09f","https://git.kernel.org/stable/c/9ea3671d70ee07480d80bebe86696397c4e99fb7","https://git.kernel.org/stable/c/b1e3edf688a88c1a3ac41657055d9c136a08cd25","https://git.kernel.org/stable/c/ca220141fa8ebae09765a242076b2b77338106b0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: fix zero-frag skb in frag_list on partial sendmsg error\n\nSyzkaller reported a warning in kcm_write_msgs() when processing a\nmessage with a zero-fragment skb in the frag_list.\n\nWhen kcm_sendmsg() fills MAX_SKB_FRAGS fragments in the current skb,\nit allocates a new skb (tskb) and links it into the frag_list before\ncopying data. If the copy subsequently fails (e.g. -EFAULT from\nuser memory), tskb remains in the frag_list with zero fragments:\n\n  head skb (msg being assembled, NOT yet in sk_write_queue)\n  +-----------+\n  | frags[17] |  (MAX_SKB_FRAGS, all filled with data)\n  | frag_list-+--> tskb\n  +-----------+    +----------+\n                   | frags[0] |  (empty! copy failed before filling)\n                   +----------+\n\nFor SOCK_SEQPACKET with partial data already copied, the error path\nsaves this message via partial_message for later completion. For\nSOCK_SEQPACKET, sock_write_iter() automatically sets MSG_EOR, so a\nsubsequent zero-length write(fd, NULL, 0) completes the message and\nqueues it to sk_write_queue. kcm_write_msgs() then walks the\nfrag_list and hits:\n\n  WARN_ON(!skb_shinfo(skb)->nr_frags)\n\nTCP has a similar pattern where skbs are enqueued before data copy\nand cleaned up on failure via tcp_remove_empty_skb(). KCM was\nmissing the equivalent cleanup.\n\nFix this by tracking the predecessor skb (frag_prev) when allocating\na new frag_list entry. On error, if the tail skb has zero frags,\nuse frag_prev to unlink and free it in O(1) without walking the\nsingly-linked frag_list. frag_prev is safe to dereference because\nthe entire message chain is only held locally (or in kcm->seq_skb)\nand is not added to sk_write_queue until MSG_EOR, so the send path\ncannot free it underneath us.\n\nAlso change the WARN_ON to WARN_ON_ONCE to avoid flooding the log\nif the condition is somehow hit repeatedly.\n\nThere are currently no KCM selftests in the kernel tree; a simple\nreproducer is available at [1].\n\n[1] https://gist.github.com/mrpre/a94d431c757e8d6f168f4dd1a3749daa","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43244","epss":0.00122,"percentile":0.02253,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43244","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43244","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43248","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43248","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vhost: move vdpa group bound check to vhost_vdpa  Remove duplication by consolidating these here.  This reduces the posibility of a parent driver missing them.  While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43248","epss":0.00129,"percentile":0.0283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43248","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-43248","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43248","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/406db68f9cb976a8ddfafd631197264f2307e9c9","https://git.kernel.org/stable/c/7441d35d14d9a3d66d925d90cb73c75394e6d454","https://git.kernel.org/stable/c/cd025c1e876b4e262e71398236a1550486a73ede","https://git.kernel.org/stable/c/ddb57354634b6ba851b79da45f1de42c646f27d0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost: move vdpa group bound check to vhost_vdpa\n\nRemove duplication by consolidating these here.  This reduces the\nposibility of a parent driver missing them.\n\nWhile we're at it, fix a bug in vdpa_sim where a valid ASID can be\nassigned to a group equal to ngroups, causing an out of bound write.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43248","epss":0.00129,"percentile":0.0283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43248","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43248","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43249","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43249","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  9p/xen: protect xen_9pfs_front_free against concurrent calls  The xenwatch thread can race with other back-end change notifications and call xen_9pfs_front_free() twice, hitting the observed general protection fault due to a double-free. Guard the teardown path so only one caller can release the front-end state at a time, preventing the crash.  This is a fix for the following double-free:  [   27.052347] Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b6b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI [   27.052357] CPU: 0 UID: 0 PID: 32 Comm: xenwatch Not tainted 6.18.0-02087-g51ab33fc0a8b-dirty #60 PREEMPT(none) [   27.052363] RIP: e030:xen_9pfs_front_free+0x1d/0x150 [   27.052368] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 41 55 41 54 55 48 89 fd 48 c7 c7 48 d0 92 85 53 e8 cb cb 05 00 48 8b 45 08 48 8b 55 00 <48> 3b 28 0f 85 f9 28 35 fe 48 3b 6a 08 0f 85 ef 28 35 fe 48 89 42 [   27.052377] RSP: e02b:ffffc9004016fdd0 EFLAGS: 00010246 [   27.052381] RAX: 6b6b6b6b6b6b6b6b RBX: ffff88800d66e400 RCX: 0000000000000000 [   27.052385] RDX: 6b6b6b6b6b6b6b6b RSI: 0000000000000000 RDI: 0000000000000000 [   27.052389] RBP: ffff88800a887040 R08: 0000000000000000 R09: 0000000000000000 [   27.052393] R10: 0000000000000000 R11: 0000000000000000 R12: ffff888009e46b68 [   27.052397] R13: 0000000000000200 R14: 0000000000000000 R15: ffff88800a887040 [   27.052404] FS:  0000000000000000(0000) GS:ffff88808ca57000(0000) knlGS:0000000000000000 [   27.052408] CS:  e030 DS: 0000 ES: 0000 CR0: 0000000080050033 [   27.052412] CR2: 00007f9714004360 CR3: 0000000004834000 CR4: 0000000000050660 [   27.052418] Call Trace: [   27.052420]  <TASK> [   27.052422]  xen_9pfs_front_changed+0x5d5/0x720 [   27.052426]  ? xenbus_otherend_changed+0x72/0x140 [   27.052430]  ? __pfx_xenwatch_thread+0x10/0x10 [   27.052434]  xenwatch_thread+0x94/0x1c0 [   27.052438]  ? __pfx_autoremove_wake_function+0x10/0x10 [   27.052442]  kthread+0xf8/0x240 [   27.052445]  ? __pfx_kthread+0x10/0x10 [   27.052449]  ? __pfx_kthread+0x10/0x10 [   27.052452]  ret_from_fork+0x16b/0x1a0 [   27.052456]  ? __pfx_kthread+0x10/0x10 [   27.052459]  ret_from_fork_asm+0x1a/0x30 [   27.052463]  </TASK> [   27.052465] Modules linked in: [   27.052471] ---[ end trace 0000000000000000 ]---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43249","epss":0.00241,"percentile":0.15282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43249","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.196415},"relatedVulnerabilities":[{"id":"CVE-2026-43249","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43249","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/59e7707492576bdbfa8c1dbe7d90791df31e4773","https://git.kernel.org/stable/c/a5d00dff97118a32fcf5fec7a4c3f864c4620c4e","https://git.kernel.org/stable/c/bf841d43f7a33d75675ba7f4e214ac1c67913065","https://git.kernel.org/stable/c/ce8ded2e61f47747e31eeefb44dc24a2160a7e32"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\n9p/xen: protect xen_9pfs_front_free against concurrent calls\n\nThe xenwatch thread can race with other back-end change notifications\nand call xen_9pfs_front_free() twice, hitting the observed general\nprotection fault due to a double-free. Guard the teardown path so only\none caller can release the front-end state at a time, preventing the\ncrash.\n\nThis is a fix for the following double-free:\n\n[   27.052347] Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b6b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI\n[   27.052357] CPU: 0 UID: 0 PID: 32 Comm: xenwatch Not tainted 6.18.0-02087-g51ab33fc0a8b-dirty #60 PREEMPT(none)\n[   27.052363] RIP: e030:xen_9pfs_front_free+0x1d/0x150\n[   27.052368] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 41 55 41 54 55 48 89 fd 48 c7 c7 48 d0 92 85 53 e8 cb cb 05 00 48 8b 45 08 48 8b 55 00 <48> 3b 28 0f 85 f9 28 35 fe 48 3b 6a 08 0f 85 ef 28 35 fe 48 89 42\n[   27.052377] RSP: e02b:ffffc9004016fdd0 EFLAGS: 00010246\n[   27.052381] RAX: 6b6b6b6b6b6b6b6b RBX: ffff88800d66e400 RCX: 0000000000000000\n[   27.052385] RDX: 6b6b6b6b6b6b6b6b RSI: 0000000000000000 RDI: 0000000000000000\n[   27.052389] RBP: ffff88800a887040 R08: 0000000000000000 R09: 0000000000000000\n[   27.052393] R10: 0000000000000000 R11: 0000000000000000 R12: ffff888009e46b68\n[   27.052397] R13: 0000000000000200 R14: 0000000000000000 R15: ffff88800a887040\n[   27.052404] FS:  0000000000000000(0000) GS:ffff88808ca57000(0000) knlGS:0000000000000000\n[   27.052408] CS:  e030 DS: 0000 ES: 0000 CR0: 0000000080050033\n[   27.052412] CR2: 00007f9714004360 CR3: 0000000004834000 CR4: 0000000000050660\n[   27.052418] Call Trace:\n[   27.052420]  <TASK>\n[   27.052422]  xen_9pfs_front_changed+0x5d5/0x720\n[   27.052426]  ? xenbus_otherend_changed+0x72/0x140\n[   27.052430]  ? __pfx_xenwatch_thread+0x10/0x10\n[   27.052434]  xenwatch_thread+0x94/0x1c0\n[   27.052438]  ? __pfx_autoremove_wake_function+0x10/0x10\n[   27.052442]  kthread+0xf8/0x240\n[   27.052445]  ? __pfx_kthread+0x10/0x10\n[   27.052449]  ? __pfx_kthread+0x10/0x10\n[   27.052452]  ret_from_fork+0x16b/0x1a0\n[   27.052456]  ? __pfx_kthread+0x10/0x10\n[   27.052459]  ret_from_fork_asm+0x1a/0x30\n[   27.052463]  </TASK>\n[   27.052465] Modules linked in:\n[   27.052471] ---[ end trace 0000000000000000 ]---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43249","epss":0.00241,"percentile":0.15282,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43249","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43249","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43250","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43250","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()  The ChipIdea UDC driver can encounter \"not page aligned sg buffer\" errors when a USB device is reconnected after being disconnected during an active transfer. This occurs because _ep_nuke() returns requests to the gadget layer without properly unmapping DMA buffers or cleaning up scatter-gather bounce buffers.  Root cause: When a disconnect happens during a multi-segment DMA transfer, the request's num_mapped_sgs field and sgt.sgl pointer remain set with stale values. The request is returned to the gadget driver with status -ESHUTDOWN but still has active DMA state. If the gadget driver reuses this request on reconnect without reinitializing it, the stale DMA state causes _hardware_enqueue() to skip DMA mapping (seeing non-zero num_mapped_sgs) and attempt to use freed/invalid DMA addresses, leading to alignment errors and potential memory corruption.  The normal completion path via _hardware_dequeue() properly calls usb_gadget_unmap_request_by_dev() and sglist_do_debounce() before returning the request. The _ep_nuke() path must do the same cleanup to ensure requests are returned in a clean, reusable state.  Fix: Add DMA unmapping and bounce buffer cleanup to _ep_nuke() to mirror the cleanup sequence in _hardware_dequeue(): - Call usb_gadget_unmap_request_by_dev() if num_mapped_sgs is set - Call sglist_do_debounce() with copy=false if bounce buffer exists  This ensures that when requests are returned due to endpoint shutdown, they don't retain stale DMA mappings. The 'false' parameter to sglist_do_debounce() prevents copying data back (appropriate for shutdown path where transfer was aborted).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43250","epss":0.00129,"percentile":0.0283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43250","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-43250","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43250","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1b72b834511d17f4d069d512f78671f3f210a2f1","https://git.kernel.org/stable/c/cea2a1257a3b5ea3e769a445b34af13e6aa5a123","https://git.kernel.org/stable/c/e74c436f8568af1c60942469d0a2300b3ada3857","https://git.kernel.org/stable/c/f4fbf2d4750d12ac8525d2efac1016fa0d84d4ec"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()\n\nThe ChipIdea UDC driver can encounter \"not page aligned sg buffer\"\nerrors when a USB device is reconnected after being disconnected\nduring an active transfer. This occurs because _ep_nuke() returns\nrequests to the gadget layer without properly unmapping DMA buffers\nor cleaning up scatter-gather bounce buffers.\n\nRoot cause:\nWhen a disconnect happens during a multi-segment DMA transfer, the\nrequest's num_mapped_sgs field and sgt.sgl pointer remain set with\nstale values. The request is returned to the gadget driver with status\n-ESHUTDOWN but still has active DMA state. If the gadget driver reuses\nthis request on reconnect without reinitializing it, the stale DMA\nstate causes _hardware_enqueue() to skip DMA mapping (seeing non-zero\nnum_mapped_sgs) and attempt to use freed/invalid DMA addresses,\nleading to alignment errors and potential memory corruption.\n\nThe normal completion path via _hardware_dequeue() properly calls\nusb_gadget_unmap_request_by_dev() and sglist_do_debounce() before\nreturning the request. The _ep_nuke() path must do the same cleanup\nto ensure requests are returned in a clean, reusable state.\n\nFix:\nAdd DMA unmapping and bounce buffer cleanup to _ep_nuke() to mirror\nthe cleanup sequence in _hardware_dequeue():\n- Call usb_gadget_unmap_request_by_dev() if num_mapped_sgs is set\n- Call sglist_do_debounce() with copy=false if bounce buffer exists\n\nThis ensures that when requests are returned due to endpoint shutdown,\nthey don't retain stale DMA mappings. The 'false' parameter to\nsglist_do_debounce() prevents copying data back (appropriate for\nshutdown path where transfer was aborted).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43250","epss":0.00129,"percentile":0.0283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43250","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43250","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43253","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43253","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/amd: move wait_on_sem() out of spinlock  With iommu.strict=1, the existing completion wait path can cause soft lockups under stressed environment, as wait_on_sem() busy-waits under the spinlock with interrupts disabled.  Move the completion wait in iommu_completion_wait() out of the spinlock. wait_on_sem() only polls the hardware-updated cmd_sem and does not require iommu->lock, so holding the lock during the busy wait unnecessarily increases contention and extends the time with interrupts disabled.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43253","epss":0.0034,"percentile":0.27084,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43253","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25499999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-43253","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43253","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/496269d12072ecb219826485bdbec70c92a8eef5","https://git.kernel.org/stable/c/715c263119fd1b918a9fcbd8a36ea5b604a46324","https://git.kernel.org/stable/c/d2a0cac10597068567d336e85fa3cbdbe8ca62bf","https://git.kernel.org/stable/c/e15768e68820142077bbca402d8e902f64ade1b0","https://git.kernel.org/stable/c/f2f65b28d802a667119147444ec2ae33eebf9a58"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: move wait_on_sem() out of spinlock\n\nWith iommu.strict=1, the existing completion wait path can cause soft\nlockups under stressed environment, as wait_on_sem() busy-waits under the\nspinlock with interrupts disabled.\n\nMove the completion wait in iommu_completion_wait() out of the spinlock.\nwait_on_sem() only polls the hardware-updated cmd_sem and does not require\niommu->lock, so holding the lock during the busy wait unnecessarily\nincreases contention and extends the time with interrupts disabled.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43253","epss":0.0034,"percentile":0.27084,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43253","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43253","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43258","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  alpha: fix user-space corruption during memory compaction  Alpha systems can suffer sporadic user-space crashes and heap corruption when memory compaction is enabled.  Symptoms include SIGSEGV, glibc allocator failures (e.g. \"unaligned tcache chunk\"), and compiler internal errors. The failures disappear when compaction is disabled or when using global TLB invalidation.  The root cause is insufficient TLB shootdown during page migration. Alpha relies on ASN-based MM context rollover for instruction cache coherency, but this alone is not sufficient to prevent stale data or instruction translations from surviving migration.  Fix this by introducing a migration-specific helper that combines:   - MM context invalidation (ASN rollover),   - immediate per-CPU TLB invalidation (TBI),   - synchronous cross-CPU shootdown when required.  The helper is used only by migration/compaction paths to avoid changing global TLB semantics.  Additionally, update flush_tlb_other(), pte_clear(), to use READ_ONCE()/WRITE_ONCE() for correct SMP memory ordering.  This fixes observed crashes on both UP and SMP Alpha systems.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43258","epss":0.00138,"percentile":0.03513,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43258","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-43258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43258","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/03e42b5f7ad4c2c3db8bd384bab7990d5d53c90f","https://git.kernel.org/stable/c/bab8d762a8dbb816b10011e13b87d1bca91e5f77","https://git.kernel.org/stable/c/d4ca6ca2c6f5a1d19d9014c5b36d96637846b5d6","https://git.kernel.org/stable/c/dd5712f3379cfe760267cdd28ff957d9ab4e51c7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nalpha: fix user-space corruption during memory compaction\n\nAlpha systems can suffer sporadic user-space crashes and heap\ncorruption when memory compaction is enabled.\n\nSymptoms include SIGSEGV, glibc allocator failures (e.g. \"unaligned\ntcache chunk\"), and compiler internal errors. The failures disappear\nwhen compaction is disabled or when using global TLB invalidation.\n\nThe root cause is insufficient TLB shootdown during page migration.\nAlpha relies on ASN-based MM context rollover for instruction cache\ncoherency, but this alone is not sufficient to prevent stale data or\ninstruction translations from surviving migration.\n\nFix this by introducing a migration-specific helper that combines:\n  - MM context invalidation (ASN rollover),\n  - immediate per-CPU TLB invalidation (TBI),\n  - synchronous cross-CPU shootdown when required.\n\nThe helper is used only by migration/compaction paths to avoid changing\nglobal TLB semantics.\n\nAdditionally, update flush_tlb_other(), pte_clear(), to use\nREAD_ONCE()/WRITE_ONCE() for correct SMP memory ordering.\n\nThis fixes observed crashes on both UP and SMP Alpha systems.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43258","epss":0.00138,"percentile":0.03513,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43258","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43271","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43271","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md-cluster: fix NULL pointer dereference in process_metadata_update  The function process_metadata_update() blindly dereferences the 'thread' pointer (acquired via rcu_dereference_protected) within the wait_event() macro.  While the code comment states \"daemon thread must exist\", there is a valid race condition window during the MD array startup sequence (md_run):  1. bitmap_load() is called, which invokes md_cluster_ops->join(). 2. join() starts the \"cluster_recv\" thread (recv_daemon). 3. At this point, recv_daemon is active and processing messages. 4. However, mddev->thread (the main MD thread) is not initialized until    later in md_run().  If a METADATA_UPDATED message is received from a remote node during this specific window, process_metadata_update() will be called while mddev->thread is still NULL, leading to a kernel panic.  To fix this, we must validate the 'thread' pointer. If it is NULL, we release the held lock (no_new_dev_lockres) and return early, safely ignoring the update request as the array is not yet fully ready to process it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43271","epss":0.00116,"percentile":0.01813,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43271","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0609},"relatedVulnerabilities":[{"id":"CVE-2026-43271","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43271","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/721599e837d3f4c0e6cc14da059612c017b6d3ec","https://git.kernel.org/stable/c/a61c1bc84c4a0f1e7c2fe55b0f43d7d94af4adf1","https://git.kernel.org/stable/c/dceb5a843910004cb118148e267036104fc3ee43","https://git.kernel.org/stable/c/dec123825c1ed74d98fd5fc7571a851dea4f46ff","https://git.kernel.org/stable/c/f150e753cb8dd756085f46e86f2c35ce472e0a3c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd-cluster: fix NULL pointer dereference in process_metadata_update\n\nThe function process_metadata_update() blindly dereferences the 'thread'\npointer (acquired via rcu_dereference_protected) within the wait_event()\nmacro.\n\nWhile the code comment states \"daemon thread must exist\", there is a valid\nrace condition window during the MD array startup sequence (md_run):\n\n1. bitmap_load() is called, which invokes md_cluster_ops->join().\n2. join() starts the \"cluster_recv\" thread (recv_daemon).\n3. At this point, recv_daemon is active and processing messages.\n4. However, mddev->thread (the main MD thread) is not initialized until\n   later in md_run().\n\nIf a METADATA_UPDATED message is received from a remote node during this\nspecific window, process_metadata_update() will be called while\nmddev->thread is still NULL, leading to a kernel panic.\n\nTo fix this, we must validate the 'thread' pointer. If it is NULL, we\nrelease the held lock (no_new_dev_lockres) and return early, safely\nignoring the update request as the array is not yet fully ready to\nprocess it.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43271","epss":0.00116,"percentile":0.01813,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43271","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43271","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43288","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43288","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: move ext4_percpu_param_init() before ext4_mb_init()  When running `kvm-xfstests -c ext4/1k -C 1 generic/383` with the `DOUBLE_CHECK` macro defined, the following panic is triggered:  ================================================================== EXT4-fs error (device vdc): ext4_validate_block_bitmap:423:                         comm mount: bg 0: bad block bitmap checksum BUG: unable to handle page fault for address: ff110000fa2cc000 PGD 3e01067 P4D 3e02067 PUD 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 0 UID: 0 PID: 2386 Comm: mount Tainted: G W                         6.18.0-gba65a4e7120a-dirty #1152 PREEMPT(none) RIP: 0010:percpu_counter_add_batch+0x13/0xa0 Call Trace:  <TASK>  ext4_mark_group_bitmap_corrupted+0xcb/0xe0  ext4_validate_block_bitmap+0x2a1/0x2f0  ext4_read_block_bitmap+0x33/0x50  mb_group_bb_bitmap_alloc+0x33/0x80  ext4_mb_add_groupinfo+0x190/0x250  ext4_mb_init_backend+0x87/0x290  ext4_mb_init+0x456/0x640  __ext4_fill_super+0x1072/0x1680  ext4_fill_super+0xd3/0x280  get_tree_bdev_flags+0x132/0x1d0  vfs_get_tree+0x29/0xd0  vfs_cmd_create+0x59/0xe0  __do_sys_fsconfig+0x4f6/0x6b0  do_syscall_64+0x50/0x1f0  entry_SYSCALL_64_after_hwframe+0x76/0x7e ==================================================================  This issue can be reproduced using the following commands:         mkfs.ext4 -F -q -b 1024 /dev/sda 5G         tune2fs -O quota,project /dev/sda         mount /dev/sda /tmp/test  With DOUBLE_CHECK defined, mb_group_bb_bitmap_alloc() reads and validates the block bitmap. When the validation fails, ext4_mark_group_bitmap_corrupted() attempts to update sbi->s_freeclusters_counter. However, this percpu_counter has not been initialized yet at this point, which leads to the panic described above.  Fix this by moving the execution of ext4_percpu_param_init() to occur before ext4_mb_init(), ensuring the per-CPU counters are initialized before they are used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43288","epss":0.0013,"percentile":0.02936,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43288","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06824999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-43288","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43288","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0d5fcb063cdabb9aeaa8554b7fedad2092c4150e","https://git.kernel.org/stable/c/270564513489d98b721a1e4a10017978d5213bff","https://git.kernel.org/stable/c/9e9fb259bcddf459a0168f4a964e979e500a68a5","https://git.kernel.org/stable/c/aec095f3cc6cf209effd93278ce35be27db81d73","https://git.kernel.org/stable/c/bf5b609524497c195f801cd5707252384aed8149"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: move ext4_percpu_param_init() before ext4_mb_init()\n\nWhen running `kvm-xfstests -c ext4/1k -C 1 generic/383` with the\n`DOUBLE_CHECK` macro defined, the following panic is triggered:\n\n==================================================================\nEXT4-fs error (device vdc): ext4_validate_block_bitmap:423:\n                        comm mount: bg 0: bad block bitmap checksum\nBUG: unable to handle page fault for address: ff110000fa2cc000\nPGD 3e01067 P4D 3e02067 PUD 0\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 0 UID: 0 PID: 2386 Comm: mount Tainted: G W\n                        6.18.0-gba65a4e7120a-dirty #1152 PREEMPT(none)\nRIP: 0010:percpu_counter_add_batch+0x13/0xa0\nCall Trace:\n <TASK>\n ext4_mark_group_bitmap_corrupted+0xcb/0xe0\n ext4_validate_block_bitmap+0x2a1/0x2f0\n ext4_read_block_bitmap+0x33/0x50\n mb_group_bb_bitmap_alloc+0x33/0x80\n ext4_mb_add_groupinfo+0x190/0x250\n ext4_mb_init_backend+0x87/0x290\n ext4_mb_init+0x456/0x640\n __ext4_fill_super+0x1072/0x1680\n ext4_fill_super+0xd3/0x280\n get_tree_bdev_flags+0x132/0x1d0\n vfs_get_tree+0x29/0xd0\n vfs_cmd_create+0x59/0xe0\n __do_sys_fsconfig+0x4f6/0x6b0\n do_syscall_64+0x50/0x1f0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n==================================================================\n\nThis issue can be reproduced using the following commands:\n        mkfs.ext4 -F -q -b 1024 /dev/sda 5G\n        tune2fs -O quota,project /dev/sda\n        mount /dev/sda /tmp/test\n\nWith DOUBLE_CHECK defined, mb_group_bb_bitmap_alloc() reads\nand validates the block bitmap. When the validation fails,\next4_mark_group_bitmap_corrupted() attempts to update\nsbi->s_freeclusters_counter. However, this percpu_counter has not been\ninitialized yet at this point, which leads to the panic described above.\n\nFix this by moving the execution of ext4_percpu_param_init() to occur\nbefore ext4_mb_init(), ensuring the per-CPU counters are initialized\nbefore they are used.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43288","epss":0.0013,"percentile":0.02936,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43288","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43288","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43299","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43299","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()  [BUG] There is a bug report that when btrfs hits ENOSPC error in a critical path, btrfs flips RO (this part is expected, although the ENOSPC bug still needs to be addressed).  The problem is after the RO flip, if there is a read repair pending, we can hit the ASSERT() inside btrfs_repair_io_failure() like the following:    BTRFS info (device vdc): relocating block group 30408704 flags metadata|raid1   ------------[ cut here ]------------   BTRFS: Transaction aborted (error -28)   WARNING: fs/btrfs/extent-tree.c:3235 at __btrfs_free_extent.isra.0+0x453/0xfd0, CPU#1: btrfs/383844   Modules linked in: kvm_intel kvm irqbypass   [...]   ---[ end trace 0000000000000000 ]---   BTRFS info (device vdc state EA): 2 enospc errors during balance   BTRFS info (device vdc state EA): balance: ended with status: -30   BTRFS error (device vdc state EA): parent transid verify failed on logical 30556160 mirror 2 wanted 8 found 6   BTRFS error (device vdc state EA): bdev /dev/nvme0n1 errs: wr 0, rd 0, flush 0, corrupt 10, gen 0   [...]   assertion failed: !(fs_info->sb->s_flags & SB_RDONLY) :: 0, in fs/btrfs/bio.c:938   ------------[ cut here ]------------   assertion failed: !(fs_info->sb->s_flags & SB_RDONLY) :: 0, in fs/btrfs/bio.c:938   kernel BUG at fs/btrfs/bio.c:938!   Oops: invalid opcode: 0000 [#1] SMP NOPTI   CPU: 0 UID: 0 PID: 868 Comm: kworker/u8:13 Tainted: G        W        N  6.19.0-rc6+ #4788 PREEMPT(full)   Tainted: [W]=WARN, [N]=TEST   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014   Workqueue: btrfs-endio simple_end_io_work   RIP: 0010:btrfs_repair_io_failure.cold+0xb2/0x120   RSP: 0000:ffffc90001d2bcf0 EFLAGS: 00010246   RAX: 0000000000000051 RBX: 0000000000001000 RCX: 0000000000000000   RDX: 0000000000000000 RSI: ffffffff8305cf42 RDI: 00000000ffffffff   RBP: 0000000000000002 R08: 00000000fffeffff R09: ffffffff837fa988   R10: ffffffff8327a9e0 R11: 6f69747265737361 R12: ffff88813018d310   R13: ffff888168b8a000 R14: ffffc90001d2bd90 R15: ffff88810a169000   FS:  0000000000000000(0000) GS:ffff8885e752c000(0000) knlGS:0000000000000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   ------------[ cut here ]------------  [CAUSE] The cause of -ENOSPC error during the test case btrfs/124 is still unknown, although it's known that we still have cases where metadata can be over-committed but can not be fulfilled correctly, thus if we hit such ENOSPC error inside a critical path, we have no choice but abort the current transaction.  This will mark the fs read-only.  The problem is inside the btrfs_repair_io_failure() path that we require the fs not to be mount read-only. This is normally fine, but if we are doing a read-repair meanwhile the fs flips RO due to a critical error, we can enter btrfs_repair_io_failure() with super block set to read-only, thus triggering the above crash.  [FIX] Just replace the ASSERT() with a proper return if the fs is already read-only.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43299","epss":0.00117,"percentile":0.01899,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.061425},"relatedVulnerabilities":[{"id":"CVE-2026-43299","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43299","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/8ceaad6cd6e7fa5f73b0b2796a2e85d75d37e9f3","https://git.kernel.org/stable/c/f6df18c001e3dcebc08482d0adeacd0cfea08593"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()\n\n[BUG]\nThere is a bug report that when btrfs hits ENOSPC error in a critical\npath, btrfs flips RO (this part is expected, although the ENOSPC bug\nstill needs to be addressed).\n\nThe problem is after the RO flip, if there is a read repair pending, we\ncan hit the ASSERT() inside btrfs_repair_io_failure() like the following:\n\n  BTRFS info (device vdc): relocating block group 30408704 flags metadata|raid1\n  ------------[ cut here ]------------\n  BTRFS: Transaction aborted (error -28)\n  WARNING: fs/btrfs/extent-tree.c:3235 at __btrfs_free_extent.isra.0+0x453/0xfd0, CPU#1: btrfs/383844\n  Modules linked in: kvm_intel kvm irqbypass\n  [...]\n  ---[ end trace 0000000000000000 ]---\n  BTRFS info (device vdc state EA): 2 enospc errors during balance\n  BTRFS info (device vdc state EA): balance: ended with status: -30\n  BTRFS error (device vdc state EA): parent transid verify failed on logical 30556160 mirror 2 wanted 8 found 6\n  BTRFS error (device vdc state EA): bdev /dev/nvme0n1 errs: wr 0, rd 0, flush 0, corrupt 10, gen 0\n  [...]\n  assertion failed: !(fs_info->sb->s_flags & SB_RDONLY) :: 0, in fs/btrfs/bio.c:938\n  ------------[ cut here ]------------\n  assertion failed: !(fs_info->sb->s_flags & SB_RDONLY) :: 0, in fs/btrfs/bio.c:938\n  kernel BUG at fs/btrfs/bio.c:938!\n  Oops: invalid opcode: 0000 [#1] SMP NOPTI\n  CPU: 0 UID: 0 PID: 868 Comm: kworker/u8:13 Tainted: G        W        N  6.19.0-rc6+ #4788 PREEMPT(full)\n  Tainted: [W]=WARN, [N]=TEST\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n  Workqueue: btrfs-endio simple_end_io_work\n  RIP: 0010:btrfs_repair_io_failure.cold+0xb2/0x120\n  RSP: 0000:ffffc90001d2bcf0 EFLAGS: 00010246\n  RAX: 0000000000000051 RBX: 0000000000001000 RCX: 0000000000000000\n  RDX: 0000000000000000 RSI: ffffffff8305cf42 RDI: 00000000ffffffff\n  RBP: 0000000000000002 R08: 00000000fffeffff R09: ffffffff837fa988\n  R10: ffffffff8327a9e0 R11: 6f69747265737361 R12: ffff88813018d310\n  R13: ffff888168b8a000 R14: ffffc90001d2bd90 R15: ffff88810a169000\n  FS:  0000000000000000(0000) GS:ffff8885e752c000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  ------------[ cut here ]------------\n\n[CAUSE]\nThe cause of -ENOSPC error during the test case btrfs/124 is still\nunknown, although it's known that we still have cases where metadata can\nbe over-committed but can not be fulfilled correctly, thus if we hit\nsuch ENOSPC error inside a critical path, we have no choice but abort\nthe current transaction.\n\nThis will mark the fs read-only.\n\nThe problem is inside the btrfs_repair_io_failure() path that we require\nthe fs not to be mount read-only. This is normally fine, but if we are\ndoing a read-repair meanwhile the fs flips RO due to a critical error,\nwe can enter btrfs_repair_io_failure() with super block set to\nread-only, thus triggering the above crash.\n\n[FIX]\nJust replace the ASSERT() with a proper return if the fs is already\nread-only.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43299","epss":0.00117,"percentile":0.01899,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43299","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43308","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()  There is no need to BUG(), we can just return an error and log an error message.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43308","epss":0.00107,"percentile":0.0128,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-43308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43308","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5549743e11c06da23cfa7712a994b9f1e69064c6","https://git.kernel.org/stable/c/c7d1d4ff56744074e005771aff193b927392d51f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()\n\nThere is no need to BUG(), we can just return an error and log an error\nmessage.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43308","epss":0.00107,"percentile":0.0128,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43309","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43309","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md raid: fix hang when stopping arrays with metadata through dm-raid  When using device-mapper's dm-raid target, stopping a RAID array can cause the system to hang under specific conditions.  This occurs when:  - A dm-raid managed device tree is suspended from top to bottom    (the top-level RAID device is suspended first, followed by its     underlying metadata and data devices)  - The top-level RAID device is then removed  Removing the top-level device triggers a hang in the following sequence: the dm-raid destructor calls md_stop(), which tries to flush the write-intent bitmap by writing to the metadata sub-devices. However, these devices are already suspended, making them unable to complete the write-intent operations and causing an indefinite block.  Fix:  - Prevent bitmap flushing when md_stop() is called from dm-raid destructor context   and avoid a quiescing/unquescing cycle which could also cause I/O  - Still allow write-intent bitmap flushing when called from dm-raid suspend context  This ensures that RAID array teardown can complete successfully even when the underlying devices are in a suspended state.  This second patch uses md_is_rdwr() to distinguish between suspend and destructor paths as elaborated on above.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43309","epss":0.00121,"percentile":0.0214,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-43309","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43309","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/24783dd06de870d646c25207bae186f78195f912","https://git.kernel.org/stable/c/338378dfffbdbb8d37a18f0a0c0358812671f91e","https://git.kernel.org/stable/c/cefcb9297fbdb6d94b61787b4f8d84f55b741470"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd raid: fix hang when stopping arrays with metadata through dm-raid\n\nWhen using device-mapper's dm-raid target, stopping a RAID array can cause\nthe system to hang under specific conditions.\n\nThis occurs when:\n\n- A dm-raid managed device tree is suspended from top to bottom\n   (the top-level RAID device is suspended first, followed by its\n    underlying metadata and data devices)\n\n- The top-level RAID device is then removed\n\nRemoving the top-level device triggers a hang in the following sequence:\nthe dm-raid destructor calls md_stop(), which tries to flush the\nwrite-intent bitmap by writing to the metadata sub-devices. However, these\ndevices are already suspended, making them unable to complete the write-intent\noperations and causing an indefinite block.\n\nFix:\n\n- Prevent bitmap flushing when md_stop() is called from dm-raid\ndestructor context\n  and avoid a quiescing/unquescing cycle which could also cause I/O\n\n- Still allow write-intent bitmap flushing when called from dm-raid\nsuspend context\n\nThis ensures that RAID array teardown can complete successfully even when the\nunderlying devices are in a suspended state.\n\nThis second patch uses md_is_rdwr() to distinguish between suspend and\ndestructor paths as elaborated on above.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43309","epss":0.00121,"percentile":0.0214,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43309","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43310","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC  For the i.MX8MQ platform, there is a hardware limitation: the g1 VPU and g2 VPU cannot decode simultaneously; otherwise, it will cause below bus error and produce corrupted pictures, even potentially lead to system hang.  [  110.527986] hantro-vpu 38310000.video-codec: frame decode timed out. [  110.583517] hantro-vpu 38310000.video-codec: bus error detected.  Therefore, it is necessary to ensure that g1 and g2 operate alternately. This allows for successful multi-instance decoding of H.264 and HEVC.  To achieve this, g1 and g2 share the same v4l2_m2m_dev, and then the v4l2_m2m_dev can handle the scheduling.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43310","epss":0.00107,"percentile":0.0128,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-43310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43310","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/286d629d10640bc22f3bf46aa4f356eb7975e862","https://git.kernel.org/stable/c/e0203ddf9af7c8e170e1e99ce83b4dc07f0cd765"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC\n\nFor the i.MX8MQ platform, there is a hardware limitation: the g1 VPU and\ng2 VPU cannot decode simultaneously; otherwise, it will cause below bus\nerror and produce corrupted pictures, even potentially lead to system hang.\n\n[  110.527986] hantro-vpu 38310000.video-codec: frame decode timed out.\n[  110.583517] hantro-vpu 38310000.video-codec: bus error detected.\n\nTherefore, it is necessary to ensure that g1 and g2 operate alternately.\nThis allows for successful multi-instance decoding of H.264 and HEVC.\n\nTo achieve this, g1 and g2 share the same v4l2_m2m_dev, and then the\nv4l2_m2m_dev can handle the scheduling.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43310","epss":0.00107,"percentile":0.0128,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43310","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43317","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43317","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  most: core: fix leak on early registration failure  A recent commit fixed a resource leak on early registration failures but for some reason left out the first error path which still leaks the resources associated with the interface.  Fix up also the first error path so that the interface is always released on errors.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43317","epss":0.00122,"percentile":0.02263,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43317","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43317","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43317","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2c198c272f9c9213b0fdf6b4a879f445c574f416","https://git.kernel.org/stable/c/5fd4396c2e48e90cc2597a86c18227d56ea845f0","https://git.kernel.org/stable/c/bbfe49ffb892bddf32c34bea95b7ff0fc30affb5","https://git.kernel.org/stable/c/f1ba620f9e8d7291f80c0554e4b820f5fb30e819"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmost: core: fix leak on early registration failure\n\nA recent commit fixed a resource leak on early registration failures but\nfor some reason left out the first error path which still leaks the\nresources associated with the interface.\n\nFix up also the first error path so that the interface is always\nreleased on errors.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43317","epss":0.00122,"percentile":0.02263,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43317","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43317","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43318","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43318","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify  Invalidating a dmabuf will impact other users of the shared BO. In the scenario where process A moves the BO, it needs to inform process B about the move and process B will need to update its page table.  The commit fixes a synchronisation bug caused by the use of the ticket: it made amdgpu_vm_handle_moved behave as if updating the page table immediately was correct but in this case it's not.  An example is the following scenario, with 2 GPUs and glxgears running on GPU0 and Xorg running on GPU1, on a system where P2P PCI isn't supported:  glxgears:   export linear buffer from GPU0 and import using GPU1   submit frame rendering to GPU0   submit tiled->linear blit Xorg:   copy of linear buffer  The sequence of jobs would be:   drm_sched_job_run                       # GPU0, frame rendering   drm_sched_job_queue                     # GPU0, blit   drm_sched_job_done                      # GPU0, frame rendering   drm_sched_job_run                       # GPU0, blit   move linear buffer for GPU1 access      #   amdgpu_dma_buf_move_notify -> update pt # GPU0  It this point the blit job on GPU0 is still running and would likely produce a page fault.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43318","epss":0.00122,"percentile":0.0224,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43318","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43318","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3307459eb3583115264421e859858d1f90f3694a","https://git.kernel.org/stable/c/82a7ea35a1526bef8ae170c33ff80e5db7728961","https://git.kernel.org/stable/c/89a9389ad70d3c69538e59d87df67d407aef4c26","https://git.kernel.org/stable/c/b18fc0ab837381c1a6ef28386602cd888f2d9edf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify\n\nInvalidating a dmabuf will impact other users of the shared BO.\nIn the scenario where process A moves the BO, it needs to inform\nprocess B about the move and process B will need to update its\npage table.\n\nThe commit fixes a synchronisation bug caused by the use of the\nticket: it made amdgpu_vm_handle_moved behave as if updating\nthe page table immediately was correct but in this case it's not.\n\nAn example is the following scenario, with 2 GPUs and glxgears\nrunning on GPU0 and Xorg running on GPU1, on a system where P2P\nPCI isn't supported:\n\nglxgears:\n  export linear buffer from GPU0 and import using GPU1\n  submit frame rendering to GPU0\n  submit tiled->linear blit\nXorg:\n  copy of linear buffer\n\nThe sequence of jobs would be:\n  drm_sched_job_run                       # GPU0, frame rendering\n  drm_sched_job_queue                     # GPU0, blit\n  drm_sched_job_done                      # GPU0, frame rendering\n  drm_sched_job_run                       # GPU0, blit\n  move linear buffer for GPU1 access      #\n  amdgpu_dma_buf_move_notify -> update pt # GPU0\n\nIt this point the blit job on GPU0 is still running and would\nlikely produce a page fault.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43318","epss":0.00122,"percentile":0.0224,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43318","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43338","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43338","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: reserve enough transaction items for qgroup ioctls  Currently our qgroup ioctls don't reserve any space, they just do a transaction join, which does not reserve any space, neither for the quota tree updates nor for the delayed refs generated when updating the quota tree. The quota root uses the global block reserve, which is fine most of the time since we don't expect a lot of updates to the quota root, or to be too close to -ENOSPC such that other critical metadata updates need to resort to the global reserve.  However this is not optimal, as not reserving proper space may result in a transaction abort due to not reserving space for delayed refs and then abusing the use of the global block reserve.  For example, the following reproducer (which is unlikely to model any real world use case, but just to illustrate the problem), triggers such a transaction abort due to -ENOSPC when running delayed refs:    $ cat test.sh   #!/bin/bash    DEV=/dev/nullb0   MNT=/mnt/nullb0    umount $DEV &> /dev/null   # Limit device to 1G so that it's much faster to reproduce the issue.   mkfs.btrfs -f -b 1G $DEV   mount -o commit=600 $DEV $MNT    fallocate -l 800M $MNT/filler   btrfs quota enable $MNT    for ((i = 1; i <= 400000; i++)); do       btrfs qgroup create 1/$i $MNT   done    umount $MNT  When running this, we can see in dmesg/syslog that a transaction abort happened:    [436.490] BTRFS error (device nullb0): failed to run delayed ref for logical 30408704 num_bytes 16384 type 176 action 1 ref_mod 1: -28   [436.493] ------------[ cut here ]------------   [436.494] BTRFS: Transaction aborted (error -28)   [436.495] WARNING: fs/btrfs/extent-tree.c:2247 at btrfs_run_delayed_refs+0xd9/0x110 [btrfs], CPU#4: umount/2495372   [436.497] Modules linked in: btrfs loop (...)   [436.508] CPU: 4 UID: 0 PID: 2495372 Comm: umount Tainted: G        W           6.19.0-rc8-btrfs-next-225+ #1 PREEMPT(full)   [436.510] Tainted: [W]=WARN   [436.511] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014   [436.513] RIP: 0010:btrfs_run_delayed_refs+0xdf/0x110 [btrfs]   [436.514] Code: 0f 82 ea (...)   [436.518] RSP: 0018:ffffd511850b7d78 EFLAGS: 00010292   [436.519] RAX: 00000000ffffffe4 RBX: ffff8f120dad37e0 RCX: 0000000002040001   [436.520] RDX: 0000000000000002 RSI: 00000000ffffffe4 RDI: ffffffffc090fd80   [436.522] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffffffc04d1867   [436.523] R10: ffff8f18dc1fffa8 R11: 0000000000000003 R12: ffff8f173aa89400   [436.524] R13: 0000000000000000 R14: ffff8f173aa89400 R15: 0000000000000000   [436.526] FS:  00007fe59045d840(0000) GS:ffff8f192e22e000(0000) knlGS:0000000000000000   [436.527] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   [436.528] CR2: 00007fe5905ff2b0 CR3: 000000060710a002 CR4: 0000000000370ef0   [436.530] Call Trace:   [436.530]  <TASK>   [436.530]  btrfs_commit_transaction+0x73/0xc00 [btrfs]   [436.531]  ? btrfs_attach_transaction_barrier+0x1e/0x70 [btrfs]   [436.532]  sync_filesystem+0x7a/0x90   [436.533]  generic_shutdown_super+0x28/0x180   [436.533]  kill_anon_super+0x12/0x40   [436.534]  btrfs_kill_super+0x12/0x20 [btrfs]   [436.534]  deactivate_locked_super+0x2f/0xb0   [436.534]  cleanup_mnt+0xea/0x180   [436.535]  task_work_run+0x58/0xa0   [436.535]  exit_to_user_mode_loop+0xed/0x480   [436.536]  ? __x64_sys_umount+0x68/0x80   [436.536]  do_syscall_64+0x2a5/0xf20   [436.537]  entry_SYSCALL_64_after_hwframe+0x76/0x7e   [436.537] RIP: 0033:0x7fe5906b6217   [436.538] Code: 0d 00 f7 (...)   [436.540] RSP: 002b:00007ffcd87a61f8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6   [436.541] RAX: 0000000000000000 RBX: 00005618b9ecadc8 RCX: 00007fe5906b6217   [436.541] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 00005618b9ecb100   [436.542] RBP: 0000000000000000 R08: 00007ffcd87a4fe0 R09: 00000000ffffffff   [436.544] R10: 0000000000000103 R11:  ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43338","epss":0.00114,"percentile":0.01634,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-43338","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43338","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/386f5e16a383101a68e195c806b4eedb233cd1d3","https://git.kernel.org/stable/c/bb6eb33c908edbbb4d92abdc0c6c87f21b4952e8","https://git.kernel.org/stable/c/cf930a651eef6f8d915bf0ccd60c2045974f870c","https://git.kernel.org/stable/c/f9a4e3015db1aeafbef407650eb8555445ca943e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reserve enough transaction items for qgroup ioctls\n\nCurrently our qgroup ioctls don't reserve any space, they just do a\ntransaction join, which does not reserve any space, neither for the quota\ntree updates nor for the delayed refs generated when updating the quota\ntree. The quota root uses the global block reserve, which is fine most of\nthe time since we don't expect a lot of updates to the quota root, or to\nbe too close to -ENOSPC such that other critical metadata updates need to\nresort to the global reserve.\n\nHowever this is not optimal, as not reserving proper space may result in a\ntransaction abort due to not reserving space for delayed refs and then\nabusing the use of the global block reserve.\n\nFor example, the following reproducer (which is unlikely to model any\nreal world use case, but just to illustrate the problem), triggers such a\ntransaction abort due to -ENOSPC when running delayed refs:\n\n  $ cat test.sh\n  #!/bin/bash\n\n  DEV=/dev/nullb0\n  MNT=/mnt/nullb0\n\n  umount $DEV &> /dev/null\n  # Limit device to 1G so that it's much faster to reproduce the issue.\n  mkfs.btrfs -f -b 1G $DEV\n  mount -o commit=600 $DEV $MNT\n\n  fallocate -l 800M $MNT/filler\n  btrfs quota enable $MNT\n\n  for ((i = 1; i <= 400000; i++)); do\n      btrfs qgroup create 1/$i $MNT\n  done\n\n  umount $MNT\n\nWhen running this, we can see in dmesg/syslog that a transaction abort\nhappened:\n\n  [436.490] BTRFS error (device nullb0): failed to run delayed ref for logical 30408704 num_bytes 16384 type 176 action 1 ref_mod 1: -28\n  [436.493] ------------[ cut here ]------------\n  [436.494] BTRFS: Transaction aborted (error -28)\n  [436.495] WARNING: fs/btrfs/extent-tree.c:2247 at btrfs_run_delayed_refs+0xd9/0x110 [btrfs], CPU#4: umount/2495372\n  [436.497] Modules linked in: btrfs loop (...)\n  [436.508] CPU: 4 UID: 0 PID: 2495372 Comm: umount Tainted: G        W           6.19.0-rc8-btrfs-next-225+ #1 PREEMPT(full)\n  [436.510] Tainted: [W]=WARN\n  [436.511] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014\n  [436.513] RIP: 0010:btrfs_run_delayed_refs+0xdf/0x110 [btrfs]\n  [436.514] Code: 0f 82 ea (...)\n  [436.518] RSP: 0018:ffffd511850b7d78 EFLAGS: 00010292\n  [436.519] RAX: 00000000ffffffe4 RBX: ffff8f120dad37e0 RCX: 0000000002040001\n  [436.520] RDX: 0000000000000002 RSI: 00000000ffffffe4 RDI: ffffffffc090fd80\n  [436.522] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffffffc04d1867\n  [436.523] R10: ffff8f18dc1fffa8 R11: 0000000000000003 R12: ffff8f173aa89400\n  [436.524] R13: 0000000000000000 R14: ffff8f173aa89400 R15: 0000000000000000\n  [436.526] FS:  00007fe59045d840(0000) GS:ffff8f192e22e000(0000) knlGS:0000000000000000\n  [436.527] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  [436.528] CR2: 00007fe5905ff2b0 CR3: 000000060710a002 CR4: 0000000000370ef0\n  [436.530] Call Trace:\n  [436.530]  <TASK>\n  [436.530]  btrfs_commit_transaction+0x73/0xc00 [btrfs]\n  [436.531]  ? btrfs_attach_transaction_barrier+0x1e/0x70 [btrfs]\n  [436.532]  sync_filesystem+0x7a/0x90\n  [436.533]  generic_shutdown_super+0x28/0x180\n  [436.533]  kill_anon_super+0x12/0x40\n  [436.534]  btrfs_kill_super+0x12/0x20 [btrfs]\n  [436.534]  deactivate_locked_super+0x2f/0xb0\n  [436.534]  cleanup_mnt+0xea/0x180\n  [436.535]  task_work_run+0x58/0xa0\n  [436.535]  exit_to_user_mode_loop+0xed/0x480\n  [436.536]  ? __x64_sys_umount+0x68/0x80\n  [436.536]  do_syscall_64+0x2a5/0xf20\n  [436.537]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  [436.537] RIP: 0033:0x7fe5906b6217\n  [436.538] Code: 0d 00 f7 (...)\n  [436.540] RSP: 002b:00007ffcd87a61f8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6\n  [436.541] RAX: 0000000000000000 RBX: 00005618b9ecadc8 RCX: 00007fe5906b6217\n  [436.541] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 00005618b9ecb100\n  [436.542] RBP: 0000000000000000 R08: 00007ffcd87a4fe0 R09: 00000000ffffffff\n  [436.544] R10: 0000000000000103 R11: \n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43338","epss":0.00114,"percentile":0.01634,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43338","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43344","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43344","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf/x86/intel/uncore: Fix die ID init and look up bugs  In snbep_pci2phy_map_init(), in the nr_node_ids > 8 path, uncore_device_to_die() may return -1 when all CPUs associated with the UBOX device are offline.  Remove the WARN_ON_ONCE(die_id == -1) check for two reasons:  - The current code breaks out of the loop. This is incorrect because   pci_get_device() does not guarantee iteration in domain or bus order,   so additional UBOX devices may be skipped during the scan.  - Returning -EINVAL is incorrect, since marking offline buses with   die_id == -1 is expected and should not be treated as an error.  Separately, when NUMA is disabled on a NUMA-capable platform, pcibus_to_node() returns NUMA_NO_NODE, causing uncore_device_to_die() to return -1 for all PCI devices.  As a result, spr_update_device_location(), used on Intel SPR and EMR, ignores the corresponding PMON units and does not add them to the RB tree.  Fix this by using uncore_pcibus_to_dieid(), which retrieves topology from the UBOX GIDNIDMAP register and works regardless of whether NUMA is enabled in Linux.  This requires snbep_pci2phy_map_init() to be added in spr_uncore_pci_init().  Keep uncore_device_to_die() only for the nr_node_ids > 8 case, where NUMA is expected to be enabled.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43344","epss":0.00116,"percentile":0.0181,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43344","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0609},"relatedVulnerabilities":[{"id":"CVE-2026-43344","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43344","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6a5dc3ee97581da2907fc7acd62853f07184de67","https://git.kernel.org/stable/c/a16d1ec4dd0cdcf689f324adde6067083bce9099","https://git.kernel.org/stable/c/bdb35811ff41a1678620a407056b6372f350028a","https://git.kernel.org/stable/c/c79ef3342632e71ac8612a2a1cc17ac84dd258b4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel/uncore: Fix die ID init and look up bugs\n\nIn snbep_pci2phy_map_init(), in the nr_node_ids > 8 path,\nuncore_device_to_die() may return -1 when all CPUs associated\nwith the UBOX device are offline.\n\nRemove the WARN_ON_ONCE(die_id == -1) check for two reasons:\n\n- The current code breaks out of the loop. This is incorrect because\n  pci_get_device() does not guarantee iteration in domain or bus order,\n  so additional UBOX devices may be skipped during the scan.\n\n- Returning -EINVAL is incorrect, since marking offline buses with\n  die_id == -1 is expected and should not be treated as an error.\n\nSeparately, when NUMA is disabled on a NUMA-capable platform,\npcibus_to_node() returns NUMA_NO_NODE, causing uncore_device_to_die()\nto return -1 for all PCI devices.  As a result,\nspr_update_device_location(), used on Intel SPR and EMR, ignores the\ncorresponding PMON units and does not add them to the RB tree.\n\nFix this by using uncore_pcibus_to_dieid(), which retrieves topology\nfrom the UBOX GIDNIDMAP register and works regardless of whether NUMA\nis enabled in Linux.  This requires snbep_pci2phy_map_init() to be\nadded in spr_uncore_pci_init().\n\nKeep uncore_device_to_die() only for the nr_node_ids > 8 case, where\nNUMA is expected to be enabled.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43344","epss":0.00116,"percentile":0.0181,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43344","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43344","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43352","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43352","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue  The logic used to abort the DMA ring contains several flaws:   1. The driver unconditionally issues a ring abort even when the ring has     already stopped.  2. The completion used to wait for abort completion is never     re-initialized, resulting in incorrect wait behavior.  3. The abort sequence unintentionally clears RING_CTRL_ENABLE, which     resets hardware ring pointers and disrupts the controller state.  4. If the ring is already stopped, the abort operation should be     considered successful without attempting further action.  Fix the abort handling by checking whether the ring is running before issuing an abort, re-initializing the completion when needed, ensuring that RING_CTRL_ENABLE remains asserted during abort, and treating an already stopped ring as a successful condition.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43352","epss":0.00128,"percentile":0.02736,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09792000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-43352","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43352","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/003df94bcc9227e8e930abd03ac7f63ac10033dc","https://git.kernel.org/stable/c/5549611888f5ca2db5e8e692b57f30626ddf9898","https://git.kernel.org/stable/c/b795e68bf3073d67bebbb5a44d93f49efc5b8cc7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue\n\nThe logic used to abort the DMA ring contains several flaws:\n\n 1. The driver unconditionally issues a ring abort even when the ring has\n    already stopped.\n 2. The completion used to wait for abort completion is never\n    re-initialized, resulting in incorrect wait behavior.\n 3. The abort sequence unintentionally clears RING_CTRL_ENABLE, which\n    resets hardware ring pointers and disrupts the controller state.\n 4. If the ring is already stopped, the abort operation should be\n    considered successful without attempting further action.\n\nFix the abort handling by checking whether the ring is running before\nissuing an abort, re-initializing the completion when needed, ensuring that\nRING_CTRL_ENABLE remains asserted during abort, and treating an already\nstopped ring as a successful condition.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43352","epss":0.00128,"percentile":0.02736,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43352","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43353","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43353","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i3c: mipi-i3c-hci: Fix race in DMA ring dequeue  The HCI DMA dequeue path (hci_dma_dequeue_xfer()) may be invoked for multiple transfers that timeout around the same time.  However, the function is not serialized and can race with itself.  When a timeout occurs, hci_dma_dequeue_xfer() stops the ring, processes incomplete transfers, and then restarts the ring.  If another timeout triggers a parallel call into the same function, the two instances may interfere with each other - stopping or restarting the ring at unexpected times.  Add a mutex so that hci_dma_dequeue_xfer() is serialized with respect to itself.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43353","epss":0.00099,"percentile":0.00867,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43353","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07573500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-43353","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43353","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1dca8aee80eea76d2aae21265de5dd64f6ba0f09","https://git.kernel.org/stable/c/4faa1e9c67a2229f6749190aedaf88ce0391efd2","https://git.kernel.org/stable/c/b684b420a5bb0ea1b0e13abfdb8ce41c5266e62e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Fix race in DMA ring dequeue\n\nThe HCI DMA dequeue path (hci_dma_dequeue_xfer()) may be invoked for\nmultiple transfers that timeout around the same time.  However, the\nfunction is not serialized and can race with itself.\n\nWhen a timeout occurs, hci_dma_dequeue_xfer() stops the ring, processes\nincomplete transfers, and then restarts the ring.  If another timeout\ntriggers a parallel call into the same function, the two instances may\ninterfere with each other - stopping or restarting the ring at unexpected\ntimes.\n\nAdd a mutex so that hci_dma_dequeue_xfer() is serialized with respect to\nitself.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43353","epss":0.00099,"percentile":0.00867,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43353","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43353","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43362","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43362","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix in-place encryption corruption in SMB2_write()  SMB2_write() places write payload in iov[1..n] as part of rq_iov. smb3_init_transform_rq() pointer-shares rq_iov, so crypt_message() encrypts iov[1] in-place, replacing the original plaintext with ciphertext. On a replayable error, the retry sends the same iov[1] which now contains ciphertext instead of the original data, resulting in corruption.  The corruption is most likely to be observed when connections are unstable, as reconnects trigger write retries that re-send the already-encrypted data.  This affects SFU mknod, MF symlinks, etc. On kernels before 6.10 (prior to the netfs conversion), sync writes also used this path and were similarly affected. The async write path wasn't unaffected as it uses rq_iter which gets deep-copied.  Fix by moving the write payload into rq_iter via iov_iter_kvec(), so smb3_init_transform_rq() deep-copies it before encryption.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43362","epss":0.00217,"percentile":0.12138,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43362","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16926},"relatedVulnerabilities":[{"id":"CVE-2026-43362","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43362","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/438e77435aee2894d5edf90be5c87004a57f6258","https://git.kernel.org/stable/c/52327268224fb9ccc7ecfbbdfdfff54b6e93c518","https://git.kernel.org/stable/c/92e64f1852f455f57d0850989e57c30d7fac7d95","https://git.kernel.org/stable/c/aea5e37388a080361110ab5790f57ae0af383650","https://git.kernel.org/stable/c/d78840a6a38d312dc1a51a65317bb67e46f0b929"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix in-place encryption corruption in SMB2_write()\n\nSMB2_write() places write payload in iov[1..n] as part of rq_iov.\nsmb3_init_transform_rq() pointer-shares rq_iov, so crypt_message()\nencrypts iov[1] in-place, replacing the original plaintext with\nciphertext. On a replayable error, the retry sends the same iov[1]\nwhich now contains ciphertext instead of the original data,\nresulting in corruption.\n\nThe corruption is most likely to be observed when connections are\nunstable, as reconnects trigger write retries that re-send the\nalready-encrypted data.\n\nThis affects SFU mknod, MF symlinks, etc. On kernels before\n6.10 (prior to the netfs conversion), sync writes also used\nthis path and were similarly affected. The async write path\nwasn't unaffected as it uses rq_iter which gets deep-copied.\n\nFix by moving the write payload into rq_iter via iov_iter_kvec(),\nso smb3_init_transform_rq() deep-copies it before encryption.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43362","epss":0.00217,"percentile":0.12138,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43362","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43362","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43409","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  kprobes: avoid crash when rmmod/insmod after ftrace killed  After we hit ftrace is killed by some errors, the kernel crash if we remove modules in which kprobe probes.  BUG: unable to handle page fault for address: fffffbfff805000d PGD 817fcc067 P4D 817fcc067 PUD 817fc8067 PMD 101555067 PTE 0 Oops: Oops: 0000 [#1] SMP KASAN PTI CPU: 4 UID: 0 PID: 2012 Comm: rmmod Tainted: G        W  OE Tainted: [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE RIP: 0010:kprobes_module_callback+0x89/0x790 RSP: 0018:ffff88812e157d30 EFLAGS: 00010a02 RAX: 1ffffffff805000d RBX: dffffc0000000000 RCX: ffffffff86a8de90 RDX: ffffed1025c2af9b RSI: 0000000000000008 RDI: ffffffffc0280068 RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1025c2af9a R10: ffff88812e157cd7 R11: 205d323130325420 R12: 0000000000000002 R13: ffffffffc0290488 R14: 0000000000000002 R15: ffffffffc0280040 FS:  00007fbc450dd740(0000) GS:ffff888420331000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: fffffbfff805000d CR3: 000000010f624000 CR4: 00000000000006f0 Call Trace:  <TASK>  notifier_call_chain+0xc6/0x280  blocking_notifier_call_chain+0x60/0x90  __do_sys_delete_module.constprop.0+0x32a/0x4e0  do_syscall_64+0x5d/0xfa0  entry_SYSCALL_64_after_hwframe+0x76/0x7e  This is because the kprobe on ftrace does not correctly handles the kprobe_ftrace_disabled flag set by ftrace_kill().  To prevent this error, check kprobe_ftrace_disabled in __disarm_kprobe_ftrace() and skip all ftrace related operations.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43409","epss":0.00122,"percentile":0.02261,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43409","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43409","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/8b6767e4141b2a42745b544d4555cf1614ba1a2d","https://git.kernel.org/stable/c/9edc79d664832a842012ad105b1521c1a3c35ab3","https://git.kernel.org/stable/c/b0ca81616a010807e91fc31db9be242b96326adc","https://git.kernel.org/stable/c/cae928e3178c75602c21d67e21255d73e7e9ed4f","https://git.kernel.org/stable/c/e113f0b46d19626ec15388bcb91432c9a4fd6261"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nkprobes: avoid crash when rmmod/insmod after ftrace killed\n\nAfter we hit ftrace is killed by some errors, the kernel crash if\nwe remove modules in which kprobe probes.\n\nBUG: unable to handle page fault for address: fffffbfff805000d\nPGD 817fcc067 P4D 817fcc067 PUD 817fc8067 PMD 101555067 PTE 0\nOops: Oops: 0000 [#1] SMP KASAN PTI\nCPU: 4 UID: 0 PID: 2012 Comm: rmmod Tainted: G        W  OE\nTainted: [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nRIP: 0010:kprobes_module_callback+0x89/0x790\nRSP: 0018:ffff88812e157d30 EFLAGS: 00010a02\nRAX: 1ffffffff805000d RBX: dffffc0000000000 RCX: ffffffff86a8de90\nRDX: ffffed1025c2af9b RSI: 0000000000000008 RDI: ffffffffc0280068\nRBP: 0000000000000000 R08: 0000000000000001 R09: ffffed1025c2af9a\nR10: ffff88812e157cd7 R11: 205d323130325420 R12: 0000000000000002\nR13: ffffffffc0290488 R14: 0000000000000002 R15: ffffffffc0280040\nFS:  00007fbc450dd740(0000) GS:ffff888420331000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: fffffbfff805000d CR3: 000000010f624000 CR4: 00000000000006f0\nCall Trace:\n <TASK>\n notifier_call_chain+0xc6/0x280\n blocking_notifier_call_chain+0x60/0x90\n __do_sys_delete_module.constprop.0+0x32a/0x4e0\n do_syscall_64+0x5d/0xfa0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThis is because the kprobe on ftrace does not correctly handles\nthe kprobe_ftrace_disabled flag set by ftrace_kill().\n\nTo prevent this error, check kprobe_ftrace_disabled in\n__disarm_kprobe_ftrace() and skip all ftrace related operations.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43409","epss":0.00122,"percentile":0.02261,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43409","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43413","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: hisi_sas: Fix NULL pointer exception during user_scan()  user_scan() invokes updated sas_user_scan() for channel 0, and if successful, iteratively scans remaining channels (1 to shost->max_channel) via scsi_scan_host_selected() in commit 37c4e72b0651 (\"scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans\"). However, hisi_sas supports only one channel, and the current value of max_channel is 1. sas_user_scan() for channel 1 will trigger the following NULL pointer exception:  [  441.554662] Unable to handle kernel NULL pointer dereference at virtual address 00000000000008b0 [  441.554699] Mem abort info: [  441.554710]   ESR = 0x0000000096000004 [  441.554718]   EC = 0x25: DABT (current EL), IL = 32 bits [  441.554723]   SET = 0, FnV = 0 [  441.554726]   EA = 0, S1PTW = 0 [  441.554730]   FSC = 0x04: level 0 translation fault [  441.554735] Data abort info: [  441.554737]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [  441.554742]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [  441.554747]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [  441.554752] user pgtable: 4k pages, 48-bit VAs, pgdp=00000828377a6000 [  441.554757] [00000000000008b0] pgd=0000000000000000, p4d=0000000000000000 [  441.554769] Internal error: Oops: 0000000096000004 [#1]  SMP [  441.629589] Modules linked in: arm_spe_pmu arm_smmuv3_pmu tpm_tis_spi hisi_uncore_sllc_pmu hisi_uncore_pa_pmu hisi_uncore_l3c_pmu hisi_uncore_hha_pmu hisi_uncore_ddrc_pmu hisi_uncore_cpa_pmu hns3_pmu hisi_ptt hisi_pcie_pmu tpm_tis_core spidev spi_hisi_sfc_v3xx hisi_uncore_pmu spi_dw_mmio fuse hclge hclge_common hisi_sec2 hisi_hpre hisi_zip hisi_qm hns3 hisi_sas_v3_hw sm3_ce sbsa_gwdt hnae3 hisi_sas_main uacce hisi_dma i2c_hisi dm_mirror dm_region_hash dm_log dm_mod [  441.670819] CPU: 46 UID: 0 PID: 6994 Comm: bash Kdump: loaded Not tainted 7.0.0-rc2+ #84 PREEMPT [  441.691327] pstate: 81400009 (Nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) [  441.698277] pc : sas_find_dev_by_rphy+0x44/0x118 [  441.702896] lr : sas_find_dev_by_rphy+0x3c/0x118 [  441.707502] sp : ffff80009abbba40 [  441.710805] x29: ffff80009abbba40 x28: ffff082819a40008 x27: ffff082810c37c08 [  441.717930] x26: ffff082810c37c28 x25: ffff082819a40290 x24: ffff082810c37c00 [  441.725054] x23: 0000000000000000 x22: 0000000000000001 x21: ffff082819a40000 [  441.732179] x20: ffff082819a40290 x19: 0000000000000000 x18: 0000000000000020 [  441.739304] x17: 0000000000000000 x16: ffffb5dad6bda690 x15: 00000000ffffffff [  441.746428] x14: ffff082814c3b26c x13: 00000000ffffffff x12: ffff082814c3b26a [  441.753553] x11: 00000000000000c0 x10: 000000000000003a x9 : ffffb5dad5ea94f4 [  441.760678] x8 : 000000000000003a x7 : ffff80009abbbab0 x6 : 0000000000000030 [  441.767802] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 [  441.774926] x2 : ffff08280f35a300 x1 : ffffb5dad7127180 x0 : 0000000000000000 [  441.782053] Call trace: [  441.784488]  sas_find_dev_by_rphy+0x44/0x118 (P) [  441.789095]  sas_target_alloc+0x24/0xb0 [  441.792920]  scsi_alloc_target+0x290/0x330 [  441.797010]  __scsi_scan_target+0x88/0x258 [  441.801096]  scsi_scan_channel+0x74/0xb8 [  441.805008]  scsi_scan_host_selected+0x170/0x188 [  441.809615]  sas_user_scan+0xfc/0x148 [  441.813267]  store_scan+0x10c/0x180 [  441.816743]  dev_attr_store+0x20/0x40 [  441.820398]  sysfs_kf_write+0x84/0xa8 [  441.824054]  kernfs_fop_write_iter+0x130/0x1c8 [  441.828487]  vfs_write+0x2c0/0x370 [  441.831880]  ksys_write+0x74/0x118 [  441.835271]  __arm64_sys_write+0x24/0x38 [  441.839182]  invoke_syscall+0x50/0x120 [  441.842919]  el0_svc_common.constprop.0+0xc8/0xf0 [  441.847611]  do_el0_svc+0x24/0x38 [  441.850913]  el0_svc+0x38/0x158 [  441.854043]  el0t_64_sync_handler+0xa0/0xe8 [  441.858214]  el0t_64_sync+0x1ac/0x1b0 [  441.861865] Code: aa1303e0 97ff70a8 34ffff80 d10a4273 (f9445a75) [  441.867946] ---[ end trace 0000000000000000 ]---  Therefore ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43413","epss":0.00122,"percentile":0.02254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43413","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43413","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/21a13db8d449b9c7eda4471da7f12417602dbbc7","https://git.kernel.org/stable/c/40119a21d9769bf8fdab5c93c6c878296e628abf","https://git.kernel.org/stable/c/70c78429ef383e35f9c58848994aeeac8083ae35","https://git.kernel.org/stable/c/8ddc0c26916574395447ebf4cff684314f6873a9","https://git.kernel.org/stable/c/beadac156610a4f3bb15cb7bb4b07b6ac06f6567"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Fix NULL pointer exception during user_scan()\n\nuser_scan() invokes updated sas_user_scan() for channel 0, and if\nsuccessful, iteratively scans remaining channels (1 to shost->max_channel)\nvia scsi_scan_host_selected() in commit 37c4e72b0651 (\"scsi: Fix\nsas_user_scan() to handle wildcard and multi-channel scans\"). However,\nhisi_sas supports only one channel, and the current value of max_channel is\n1. sas_user_scan() for channel 1 will trigger the following NULL pointer\nexception:\n\n[  441.554662] Unable to handle kernel NULL pointer dereference at virtual address 00000000000008b0\n[  441.554699] Mem abort info:\n[  441.554710]   ESR = 0x0000000096000004\n[  441.554718]   EC = 0x25: DABT (current EL), IL = 32 bits\n[  441.554723]   SET = 0, FnV = 0\n[  441.554726]   EA = 0, S1PTW = 0\n[  441.554730]   FSC = 0x04: level 0 translation fault\n[  441.554735] Data abort info:\n[  441.554737]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[  441.554742]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[  441.554747]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[  441.554752] user pgtable: 4k pages, 48-bit VAs, pgdp=00000828377a6000\n[  441.554757] [00000000000008b0] pgd=0000000000000000, p4d=0000000000000000\n[  441.554769] Internal error: Oops: 0000000096000004 [#1]  SMP\n[  441.629589] Modules linked in: arm_spe_pmu arm_smmuv3_pmu tpm_tis_spi hisi_uncore_sllc_pmu hisi_uncore_pa_pmu hisi_uncore_l3c_pmu hisi_uncore_hha_pmu hisi_uncore_ddrc_pmu hisi_uncore_cpa_pmu hns3_pmu hisi_ptt hisi_pcie_pmu tpm_tis_core spidev spi_hisi_sfc_v3xx hisi_uncore_pmu spi_dw_mmio fuse hclge hclge_common hisi_sec2 hisi_hpre hisi_zip hisi_qm hns3 hisi_sas_v3_hw sm3_ce sbsa_gwdt hnae3 hisi_sas_main uacce hisi_dma i2c_hisi dm_mirror dm_region_hash dm_log dm_mod\n[  441.670819] CPU: 46 UID: 0 PID: 6994 Comm: bash Kdump: loaded Not tainted 7.0.0-rc2+ #84 PREEMPT\n[  441.691327] pstate: 81400009 (Nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n[  441.698277] pc : sas_find_dev_by_rphy+0x44/0x118\n[  441.702896] lr : sas_find_dev_by_rphy+0x3c/0x118\n[  441.707502] sp : ffff80009abbba40\n[  441.710805] x29: ffff80009abbba40 x28: ffff082819a40008 x27: ffff082810c37c08\n[  441.717930] x26: ffff082810c37c28 x25: ffff082819a40290 x24: ffff082810c37c00\n[  441.725054] x23: 0000000000000000 x22: 0000000000000001 x21: ffff082819a40000\n[  441.732179] x20: ffff082819a40290 x19: 0000000000000000 x18: 0000000000000020\n[  441.739304] x17: 0000000000000000 x16: ffffb5dad6bda690 x15: 00000000ffffffff\n[  441.746428] x14: ffff082814c3b26c x13: 00000000ffffffff x12: ffff082814c3b26a\n[  441.753553] x11: 00000000000000c0 x10: 000000000000003a x9 : ffffb5dad5ea94f4\n[  441.760678] x8 : 000000000000003a x7 : ffff80009abbbab0 x6 : 0000000000000030\n[  441.767802] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000\n[  441.774926] x2 : ffff08280f35a300 x1 : ffffb5dad7127180 x0 : 0000000000000000\n[  441.782053] Call trace:\n[  441.784488]  sas_find_dev_by_rphy+0x44/0x118 (P)\n[  441.789095]  sas_target_alloc+0x24/0xb0\n[  441.792920]  scsi_alloc_target+0x290/0x330\n[  441.797010]  __scsi_scan_target+0x88/0x258\n[  441.801096]  scsi_scan_channel+0x74/0xb8\n[  441.805008]  scsi_scan_host_selected+0x170/0x188\n[  441.809615]  sas_user_scan+0xfc/0x148\n[  441.813267]  store_scan+0x10c/0x180\n[  441.816743]  dev_attr_store+0x20/0x40\n[  441.820398]  sysfs_kf_write+0x84/0xa8\n[  441.824054]  kernfs_fop_write_iter+0x130/0x1c8\n[  441.828487]  vfs_write+0x2c0/0x370\n[  441.831880]  ksys_write+0x74/0x118\n[  441.835271]  __arm64_sys_write+0x24/0x38\n[  441.839182]  invoke_syscall+0x50/0x120\n[  441.842919]  el0_svc_common.constprop.0+0xc8/0xf0\n[  441.847611]  do_el0_svc+0x24/0x38\n[  441.850913]  el0_svc+0x38/0x158\n[  441.854043]  el0t_64_sync_handler+0xa0/0xe8\n[  441.858214]  el0t_64_sync+0x1ac/0x1b0\n[  441.861865] Code: aa1303e0 97ff70a8 34ffff80 d10a4273 (f9445a75)\n[  441.867946] ---[ end trace 0000000000000000 ]---\n\nTherefore\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43413","epss":0.00122,"percentile":0.02254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43413","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43414","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: qla2xxx: Completely fix fcport double free  In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is called by qla2x00_sp_release(), when kref_put() releases the first and the last reference.  qla2x00_els_dcmd_sp_free() frees fcport by calling qla2x00_free_fcport(). Doing it one more time after kref_put() is a bad idea.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43414","epss":0.0038,"percentile":0.31291,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43414","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3572},"relatedVulnerabilities":[{"id":"CVE-2026-43414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43414","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/c0b7da13a04bd70ef6070bfb9ea85f582294560a","https://git.kernel.org/stable/c/d48ea85463f5b34f7b92ea0a13eddf1ab993da7b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Completely fix fcport double free\n\nIn qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free().\nWhen an error happens, this function is called by qla2x00_sp_release(),\nwhen kref_put() releases the first and the last reference.\n\nqla2x00_els_dcmd_sp_free() frees fcport by calling qla2x00_free_fcport().\nDoing it one more time after kref_put() is a bad idea.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43414","epss":0.0038,"percentile":0.31291,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43414","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43414","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43416","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43416","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  powerpc, perf: Check that current->mm is alive before getting user callchain  It may happen that mm is already released, which leads to kernel panic. This adds the NULL check for current->mm, similarly to commit 20afc60f892d (\"x86, perf: Check that current->mm is alive before getting user callchain\").  I was getting this panic when running a profiling BPF program (profile.py from bcc-tools):      [26215.051935] Kernel attempted to read user page (588) - exploit attempt? (uid: 0)     [26215.051950] BUG: Kernel NULL pointer dereference on read at 0x00000588     [26215.051952] Faulting instruction address: 0xc00000000020fac0     [26215.051957] Oops: Kernel access of bad area, sig: 11 [#1]     [...]     [26215.052049] Call Trace:     [26215.052050] [c000000061da6d30] [c00000000020fc10] perf_callchain_user_64+0x2d0/0x490 (unreliable)     [26215.052054] [c000000061da6dc0] [c00000000020f92c] perf_callchain_user+0x1c/0x30     [26215.052057] [c000000061da6de0] [c0000000005ab2a0] get_perf_callchain+0x100/0x360     [26215.052063] [c000000061da6e70] [c000000000573bc8] bpf_get_stackid+0x88/0xf0     [26215.052067] [c000000061da6ea0] [c008000000042258] bpf_prog_16d4ab9ab662f669_do_perf_event+0xf8/0x274     [...]  In addition, move storing the top-level stack entry to generic perf_callchain_user to make sure the top-evel entry is always captured, even if current->mm is NULL.  [Maddy: fixed message to avoid checkpatch format style error]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43416","epss":0.00121,"percentile":0.0215,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43416","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-43416","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43416","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7e5f60b8cfc02a2b23a40a5f5fd2fa81d010e737","https://git.kernel.org/stable/c/98074e16742ae87fb82e234b419783c5ffc9baea","https://git.kernel.org/stable/c/e9bbfb4bfa86c6b5515b868d6982ac60505d7e39"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc, perf: Check that current->mm is alive before getting user callchain\n\nIt may happen that mm is already released, which leads to kernel panic.\nThis adds the NULL check for current->mm, similarly to\ncommit 20afc60f892d (\"x86, perf: Check that current->mm is alive before getting user callchain\").\n\nI was getting this panic when running a profiling BPF program\n(profile.py from bcc-tools):\n\n    [26215.051935] Kernel attempted to read user page (588) - exploit attempt? (uid: 0)\n    [26215.051950] BUG: Kernel NULL pointer dereference on read at 0x00000588\n    [26215.051952] Faulting instruction address: 0xc00000000020fac0\n    [26215.051957] Oops: Kernel access of bad area, sig: 11 [#1]\n    [...]\n    [26215.052049] Call Trace:\n    [26215.052050] [c000000061da6d30] [c00000000020fc10] perf_callchain_user_64+0x2d0/0x490 (unreliable)\n    [26215.052054] [c000000061da6dc0] [c00000000020f92c] perf_callchain_user+0x1c/0x30\n    [26215.052057] [c000000061da6de0] [c0000000005ab2a0] get_perf_callchain+0x100/0x360\n    [26215.052063] [c000000061da6e70] [c000000000573bc8] bpf_get_stackid+0x88/0xf0\n    [26215.052067] [c000000061da6ea0] [c008000000042258] bpf_prog_16d4ab9ab662f669_do_perf_event+0xf8/0x274\n    [...]\n\nIn addition, move storing the top-level stack entry to generic\nperf_callchain_user to make sure the top-evel entry is always captured,\neven if current->mm is NULL.\n\n[Maddy: fixed message to avoid checkpatch format style error]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43416","epss":0.00121,"percentile":0.0215,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43416","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43416","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43419","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43419","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ceph: fix memory leaks in ceph_mdsc_build_path()  Add __putname() calls to error code paths that did not free the \"path\" pointer obtained by __getname().  If ownership of this pointer is not passed to the caller via path_info.path, the function must free it before returning.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43419","epss":0.00122,"percentile":0.02246,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43419","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-43419","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43419","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/040d159a45ded7f33201421a81df0aa2a86e5a0b","https://git.kernel.org/stable/c/097cd68f46686391a98f2618188f0cb7b7570de2","https://git.kernel.org/stable/c/13b8b9d6f59ef17fb96c298c3a0d62a8306950cc","https://git.kernel.org/stable/c/5895d0164c84d7fec6abc198920c257f55c51899","https://git.kernel.org/stable/c/657dc653b06a3cc0282aea447a3f137fa94066a4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix memory leaks in ceph_mdsc_build_path()\n\nAdd __putname() calls to error code paths that did not free the \"path\"\npointer obtained by __getname().  If ownership of this pointer is not\npassed to the caller via path_info.path, the function must free it\nbefore returning.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43419","epss":0.00122,"percentile":0.02246,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43419","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43419","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43443","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43443","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: amd: acp-mach-common: Add missing error check for clock acquisition  The acp_card_rt5682_init() and acp_card_rt5682s_init() functions did not check the return values of clk_get(). This could lead to a kernel crash when the invalid pointers are later dereferenced by clock core functions.  Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding IS_ERR() checks immediately after each clock acquisition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43443","epss":0.00107,"percentile":0.01283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43443","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-43443","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43443","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0cee68fb7f4cf1562e067c5a82d25062a973b0d0","https://git.kernel.org/stable/c/30c64fb9839949f085c8eb55b979cbd8a4c51f00"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: amd: acp-mach-common: Add missing error check for clock acquisition\n\nThe acp_card_rt5682_init() and acp_card_rt5682s_init() functions did not\ncheck the return values of clk_get(). This could lead to a kernel crash\nwhen the invalid pointers are later dereferenced by clock core\nfunctions.\n\nFix this by:\n1. Changing clk_get() to the device-managed devm_clk_get().\n2. Adding IS_ERR() checks immediately after each clock acquisition.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43443","epss":0.00107,"percentile":0.01283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43443","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43443","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43456","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bonding: fix type confusion in bond_setup_by_slave()  kernel BUG at net/core/skbuff.c:2306! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:pskb_expand_head+0xa08/0xfe0 net/core/skbuff.c:2306 RSP: 0018:ffffc90004aff760 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88807e3c8780 RCX: ffffffff89593e0e RDX: ffff88807b7c4900 RSI: ffffffff89594747 RDI: ffff88807b7c4900 RBP: 0000000000000820 R08: 0000000000000005 R09: 0000000000000000 R10: 00000000961a63e0 R11: 0000000000000000 R12: ffff88807e3c8780 R13: 00000000961a6560 R14: dffffc0000000000 R15: 00000000961a63e0 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fe1a0ed8df0 CR3: 000000002d816000 CR4: 00000000003526f0 Call Trace:  <TASK>  ipgre_header+0xdd/0x540 net/ipv4/ip_gre.c:900  dev_hard_header include/linux/netdevice.h:3439 [inline]  packet_snd net/packet/af_packet.c:3028 [inline]  packet_sendmsg+0x3ae5/0x53c0 net/packet/af_packet.c:3108  sock_sendmsg_nosec net/socket.c:727 [inline]  __sock_sendmsg net/socket.c:742 [inline]  ____sys_sendmsg+0xa54/0xc30 net/socket.c:2592  ___sys_sendmsg+0x190/0x1e0 net/socket.c:2646  __sys_sendmsg+0x170/0x220 net/socket.c:2678  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0x106/0xf80 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe1a0e6c1a9  When a non-Ethernet device (e.g. GRE tunnel) is enslaved to a bond, bond_setup_by_slave() directly copies the slave's header_ops to the bond device:      bond_dev->header_ops = slave_dev->header_ops;  This causes a type confusion when dev_hard_header() is later called on the bond device. Functions like ipgre_header(), ip6gre_header(),all use netdev_priv(dev) to access their device-specific private data. When called with the bond device, netdev_priv() returns the bond's private data (struct bonding) instead of the expected type (e.g. struct ip_tunnel), leading to garbage values being read and kernel crashes.  Fix this by introducing bond_header_ops with wrapper functions that delegate to the active slave's header_ops using the slave's own device. This ensures netdev_priv() in the slave's header functions always receives the correct device.  The fix is placed in the bonding driver rather than individual device drivers, as the root cause is bond blindly inheriting header_ops from the slave without considering that these callbacks expect a specific netdev_priv() layout.  The type confusion can be observed by adding a printk in ipgre_header() and running the following commands:      ip link add dummy0 type dummy     ip addr add 10.0.0.1/24 dev dummy0     ip link set dummy0 up     ip link add gre1 type gre local 10.0.0.1     ip link add bond1 type bond mode active-backup     ip link set gre1 master bond1     ip link set gre1 up     ip link set bond1 up     ip addr add fe80::1/64 dev bond1","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43456","epss":0.0016,"percentile":0.05534,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43456","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12240000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-43456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43456","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5d0fb9806ab6cf2c3cfba0e1b8c701da65e25af8","https://git.kernel.org/stable/c/6ac890f1d60ac3707ee8dae15a67d9a833e49956","https://git.kernel.org/stable/c/950803f7254721c1c15858fbbfae3deaaeeecb11","https://git.kernel.org/stable/c/95597d11dc8bddb2b9a051c9232000bfbb5e43ba","https://git.kernel.org/stable/c/9baf26a91565b7bb2b1d9f99aaf884a2b28c2f6d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix type confusion in bond_setup_by_slave()\n\nkernel BUG at net/core/skbuff.c:2306!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nRIP: 0010:pskb_expand_head+0xa08/0xfe0 net/core/skbuff.c:2306\nRSP: 0018:ffffc90004aff760 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffff88807e3c8780 RCX: ffffffff89593e0e\nRDX: ffff88807b7c4900 RSI: ffffffff89594747 RDI: ffff88807b7c4900\nRBP: 0000000000000820 R08: 0000000000000005 R09: 0000000000000000\nR10: 00000000961a63e0 R11: 0000000000000000 R12: ffff88807e3c8780\nR13: 00000000961a6560 R14: dffffc0000000000 R15: 00000000961a63e0\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fe1a0ed8df0 CR3: 000000002d816000 CR4: 00000000003526f0\nCall Trace:\n <TASK>\n ipgre_header+0xdd/0x540 net/ipv4/ip_gre.c:900\n dev_hard_header include/linux/netdevice.h:3439 [inline]\n packet_snd net/packet/af_packet.c:3028 [inline]\n packet_sendmsg+0x3ae5/0x53c0 net/packet/af_packet.c:3108\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg net/socket.c:742 [inline]\n ____sys_sendmsg+0xa54/0xc30 net/socket.c:2592\n ___sys_sendmsg+0x190/0x1e0 net/socket.c:2646\n __sys_sendmsg+0x170/0x220 net/socket.c:2678\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x106/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fe1a0e6c1a9\n\nWhen a non-Ethernet device (e.g. GRE tunnel) is enslaved to a bond,\nbond_setup_by_slave() directly copies the slave's header_ops to the\nbond device:\n\n    bond_dev->header_ops = slave_dev->header_ops;\n\nThis causes a type confusion when dev_hard_header() is later called\non the bond device. Functions like ipgre_header(), ip6gre_header(),all use\nnetdev_priv(dev) to access their device-specific private data. When\ncalled with the bond device, netdev_priv() returns the bond's private\ndata (struct bonding) instead of the expected type (e.g. struct\nip_tunnel), leading to garbage values being read and kernel crashes.\n\nFix this by introducing bond_header_ops with wrapper functions that\ndelegate to the active slave's header_ops using the slave's own\ndevice. This ensures netdev_priv() in the slave's header functions\nalways receives the correct device.\n\nThe fix is placed in the bonding driver rather than individual device\ndrivers, as the root cause is bond blindly inheriting header_ops from\nthe slave without considering that these callbacks expect a specific\nnetdev_priv() layout.\n\nThe type confusion can be observed by adding a printk in\nipgre_header() and running the following commands:\n\n    ip link add dummy0 type dummy\n    ip addr add 10.0.0.1/24 dev dummy0\n    ip link set dummy0 up\n    ip link add gre1 type gre local 10.0.0.1\n    ip link add bond1 type bond mode active-backup\n    ip link set gre1 master bond1\n    ip link set gre1 up\n    ip link set bond1 up\n    ip addr add fe80::1/64 dev bond1","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43456","epss":0.0016,"percentile":0.05534,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43456","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43456","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43490","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43490","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate inherited ACE SID length  smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify that the variable-length SID described by sid.num_subauth is fully contained in the ACE.  A malformed inheritable ACE can advertise more subauthorities than are present in the ACE. compare_sids() may then read past the ACE. smb_set_ace() also clamps the copied destination SID, but used the unchecked source SID count to compute the inherited ACE size. That could advance the temporary inherited ACE buffer pointer and nt_size accounting past the allocated buffer.  Fix this by validating the parent ACE SID count and SID length before using the SID during inheritance. Compute the inherited ACE size from the copied SID so the size matches the bounded destination SID. Reject the inherited DACL if size accumulation would overflow smb_acl.size or the security descriptor allocation size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43490","epss":0.00408,"percentile":0.34235,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43490","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33252000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-43490","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43490","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1aa60fea7f637c071f529ad6784aecca2f2f0c5f","https://git.kernel.org/stable/c/47c6e37a77b10e74f70d845ba4ea5d3cafa00336","https://git.kernel.org/stable/c/996454bc0da84d5a1dedb1a7861823087e01a7ae","https://git.kernel.org/stable/c/a7fb771314fb3a265d30f8ac245869a367ab065c","https://git.kernel.org/stable/c/c1d95c995d5bcb24b639200a899eda59cb1e6d64"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate inherited ACE SID length\n\nsmb_inherit_dacl() walks the parent directory DACL loaded from the\nsecurity descriptor xattr. It verifies that each ACE contains the fixed\nSID header before using it, but does not verify that the variable-length\nSID described by sid.num_subauth is fully contained in the ACE.\n\nA malformed inheritable ACE can advertise more subauthorities than are\npresent in the ACE. compare_sids() may then read past the ACE.\nsmb_set_ace() also clamps the copied destination SID, but used the\nunchecked source SID count to compute the inherited ACE size. That could\nadvance the temporary inherited ACE buffer pointer and nt_size accounting\npast the allocated buffer.\n\nFix this by validating the parent ACE SID count and SID length before\nusing the SID during inheritance. Compute the inherited ACE size from the\ncopied SID so the size matches the bounded destination SID. Reject the\ninherited DACL if size accumulation would overflow smb_acl.size or the\nsecurity descriptor allocation size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43490","epss":0.00408,"percentile":0.34235,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-43490","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43490","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-43491","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-43491","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: qrtr: ns: Limit the maximum server registration per node  Current code does no bound checking on the number of servers added per node. A malicious client can flood NEW_SERVER messages and exhaust memory.  Fix this issue by limiting the maximum number of server registrations to 256 per node. If the NEW_SERVER message is received for an old port, then don't restrict it as it will get replaced. While at it, also rate limit the error messages in the failure path of qrtr_ns_worker().  Note that the limit of 256 is chosen based on the current platform requirements. If requirement changes in the future, this limit can be increased.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43491","epss":0.00149,"percentile":0.04421,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.078225},"relatedVulnerabilities":[{"id":"CVE-2026-43491","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43491","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/35fb4a0c077c5d1049c2628b769e0a1b1e65df0d","https://git.kernel.org/stable/c/3efaad55cad1ded429e3a873bfece389058a526b","https://git.kernel.org/stable/c/868202aa2adae427060a42d5bd663b4d782ec02c","https://git.kernel.org/stable/c/94914731ca0b99899dceadd80d2df00584a688ca","https://git.kernel.org/stable/c/991c431077b19176d3fe3bb54054c063776a8cdc","https://git.kernel.org/stable/c/b48fc702b20233b809f01053232c3cd5083c97b4","https://git.kernel.org/stable/c/d5ee2ff98322337951c56398e79d51815acbf955","https://git.kernel.org/stable/c/e6f6cd501fb54060940a6eb3f4103eeb5e426ae7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: ns: Limit the maximum server registration per node\n\nCurrent code does no bound checking on the number of servers added per\nnode. A malicious client can flood NEW_SERVER messages and exhaust memory.\n\nFix this issue by limiting the maximum number of server registrations to\n256 per node. If the NEW_SERVER message is received for an old port, then\ndon't restrict it as it will get replaced. While at it, also rate limit\nthe error messages in the failure path of qrtr_ns_worker().\n\nNote that the limit of 256 is chosen based on the current platform\nrequirements. If requirement changes in the future, this limit can be\nincreased.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-43491","epss":0.00149,"percentile":0.04421,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-43491","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45855","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45855","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ata: libata-scsi: avoid Non-NCQ command starvation  When a non-NCQ command is issued while NCQ commands are being executed, ata_scsi_qc_issue() indicates to the SCSI layer that the command issuing should be deferred by returning SCSI_MLQUEUE_XXX_BUSY.  This command deferring is correct and as mandated by the ACS specifications since NCQ and non-NCQ commands cannot be mixed.  However, in the case of a host adapter using multiple submission queues, when the target device is under a constant load of NCQ commands, there are no guarantees that requeueing the non-NCQ command will be executed later and it may be deferred again repeatedly as other submission queues can constantly issue NCQ commands from different CPUs ahead of the non-NCQ command. This can lead to very long delays for the execution of non-NCQ commands, and even complete starvation for these commands in the worst case scenario.  Since the block layer and the SCSI layer do not distinguish between queueable (NCQ) and non queueable (non-NCQ) commands, libata-scsi SAT implementation must ensure forward progress for non-NCQ commands in the presence of NCQ command traffic. This is similar to what SAS HBAs with a hardware/firmware based SAT implementation do.  Implement such forward progress guarantee by limiting requeueing of non-NCQ commands from ata_scsi_qc_issue(): when a non-NCQ command is received and NCQ commands are in-flight, do not force a requeue of the non-NCQ command by returning SCSI_MLQUEUE_XXX_BUSY and instead return 0 to indicate that the command was accepted but hold on to the qc using the new deferred_qc field of struct ata_port.  This deferred qc will be issued using the work item deferred_qc_work running the function ata_scsi_deferred_qc_work() once all in-flight commands complete, which is checked with the port qc_defer() callback return value indicating that no further delay is necessary. This check is done using the helper function ata_scsi_schedule_deferred_qc() which is called from ata_scsi_qc_complete(). This thus excludes this mechanism from all internal non-NCQ commands issued by ATA EH.  When a port deferred_qc is non NULL, that is, the port has a command waiting for the device queue to drain, the issuing of all incoming commands (both NCQ and non-NCQ) is deferred using the regular busy mechanism. This simplifies the code and also avoids potential denial of service problems if a user issues too many non-NCQ commands.  Finally, whenever ata EH is scheduled, regardless of the reason, a deferred qc is always requeued so that it can be retried once EH completes. This is done by calling the function ata_scsi_requeue_deferred_qc() from ata_eh_set_pending(). This avoids the need for any special processing for the deferred qc in case of NCQ error, link or device reset, or device timeout.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45855","epss":0.00165,"percentile":0.06015,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08662500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-45855","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45855","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0ea84089dbf62a92dc7889c79e6b18fc89260808","https://git.kernel.org/stable/c/5d61a38a60e62750526d94663b69b7ac5c7f07a5","https://git.kernel.org/stable/c/888cd7e40adb2ef4af1b4d3b6e2e83ad409ae8c2","https://git.kernel.org/stable/c/ce22aaed011206fed9cbd8c9c2d44718607f31ee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-scsi: avoid Non-NCQ command starvation\n\nWhen a non-NCQ command is issued while NCQ commands are being executed,\nata_scsi_qc_issue() indicates to the SCSI layer that the command issuing\nshould be deferred by returning SCSI_MLQUEUE_XXX_BUSY.  This command\ndeferring is correct and as mandated by the ACS specifications since\nNCQ and non-NCQ commands cannot be mixed.\n\nHowever, in the case of a host adapter using multiple submission queues,\nwhen the target device is under a constant load of NCQ commands, there\nare no guarantees that requeueing the non-NCQ command will be executed\nlater and it may be deferred again repeatedly as other submission queues\ncan constantly issue NCQ commands from different CPUs ahead of the\nnon-NCQ command. This can lead to very long delays for the execution of\nnon-NCQ commands, and even complete starvation for these commands in the\nworst case scenario.\n\nSince the block layer and the SCSI layer do not distinguish between\nqueueable (NCQ) and non queueable (non-NCQ) commands, libata-scsi SAT\nimplementation must ensure forward progress for non-NCQ commands in the\npresence of NCQ command traffic. This is similar to what SAS HBAs with a\nhardware/firmware based SAT implementation do.\n\nImplement such forward progress guarantee by limiting requeueing of\nnon-NCQ commands from ata_scsi_qc_issue(): when a non-NCQ command is\nreceived and NCQ commands are in-flight, do not force a requeue of the\nnon-NCQ command by returning SCSI_MLQUEUE_XXX_BUSY and instead return 0\nto indicate that the command was accepted but hold on to the qc using\nthe new deferred_qc field of struct ata_port.\n\nThis deferred qc will be issued using the work item deferred_qc_work\nrunning the function ata_scsi_deferred_qc_work() once all in-flight\ncommands complete, which is checked with the port qc_defer() callback\nreturn value indicating that no further delay is necessary. This check\nis done using the helper function ata_scsi_schedule_deferred_qc() which\nis called from ata_scsi_qc_complete(). This thus excludes this mechanism\nfrom all internal non-NCQ commands issued by ATA EH.\n\nWhen a port deferred_qc is non NULL, that is, the port has a command\nwaiting for the device queue to drain, the issuing of all incoming\ncommands (both NCQ and non-NCQ) is deferred using the regular busy\nmechanism. This simplifies the code and also avoids potential denial of\nservice problems if a user issues too many non-NCQ commands.\n\nFinally, whenever ata EH is scheduled, regardless of the reason, a\ndeferred qc is always requeued so that it can be retried once EH\ncompletes. This is done by calling the function\nata_scsi_requeue_deferred_qc() from ata_eh_set_pending(). This avoids\nthe need for any special processing for the deferred qc in case of NCQ\nerror, link or device reset, or device timeout.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45855","epss":0.00165,"percentile":0.06015,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45855","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45858","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45858","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1  When allocating initialized blocks from a large unwritten extent, or when splitting an unwritten extent during end I/O and converting it to initialized, there is currently a potential issue of stale data if the extent needs to be split in the middle.         0  A      B  N        [UUUUUUUUUUUU]    U: unwritten extent        [--DDDDDDDD--]    D: valid data           |<-  ->| ----> this range needs to be initialized  ext4_split_extent() first try to split this extent at B with EXT4_EXT_DATA_ENTIRE_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but ext4_split_extent_at() failed to split this extent due to temporary lack of space. It zeroout B to N and mark the entire extent from 0 to N as written.         0  A      B  N        [WWWWWWWWWWWW]    W: written extent        [SSDDDDDDDDZZ]    Z: zeroed, S: stale data  ext4_split_extent() then try to split this extent at A with EXT4_EXT_DATA_VALID2 flag set. This time, it split successfully and left a stale written extent from 0 to A.         0  A      B   N        [WW|WWWWWWWWWW]        [SS|DDDDDDDDZZ]  Fix this by pass EXT4_EXT_DATA_PARTIAL_VALID1 to ext4_split_extent_at() when splitting at B, don't convert the entire extent to written and left it as unwritten after zeroing out B to N. The remaining work is just like the standard two-part split. ext4_split_extent() will pass the EXT4_EXT_DATA_VALID2 flag when it calls ext4_split_extent_at() for the second time, allowing it to properly handle the split. If the split is successful, it will keep extent from 0 to A as unwritten.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45858","epss":0.0016,"percentile":0.05486,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-45858","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45858","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1bf6974822d1dba86cf11b5f05498581cf3488a2","https://git.kernel.org/stable/c/58ddae5d77b1db3a27b891c75a8fa120239ac092","https://git.kernel.org/stable/c/7015fcf473796e1d2d876f241bd9e0c36f3d4eef","https://git.kernel.org/stable/c/d17857b4fb9ba5745b59be0ef38fd532991fccbf","https://git.kernel.org/stable/c/d67c8ecf3d8fda9b8ef80e6f665d84b6d6ac9d88"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1\n\nWhen allocating initialized blocks from a large unwritten extent, or\nwhen splitting an unwritten extent during end I/O and converting it to\ninitialized, there is currently a potential issue of stale data if the\nextent needs to be split in the middle.\n\n       0  A      B  N\n       [UUUUUUUUUUUU]    U: unwritten extent\n       [--DDDDDDDD--]    D: valid data\n          |<-  ->| ----> this range needs to be initialized\n\next4_split_extent() first try to split this extent at B with\nEXT4_EXT_DATA_ENTIRE_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but\next4_split_extent_at() failed to split this extent due to temporary lack\nof space. It zeroout B to N and mark the entire extent from 0 to N\nas written.\n\n       0  A      B  N\n       [WWWWWWWWWWWW]    W: written extent\n       [SSDDDDDDDDZZ]    Z: zeroed, S: stale data\n\next4_split_extent() then try to split this extent at A with\nEXT4_EXT_DATA_VALID2 flag set. This time, it split successfully and left\na stale written extent from 0 to A.\n\n       0  A      B   N\n       [WW|WWWWWWWWWW]\n       [SS|DDDDDDDDZZ]\n\nFix this by pass EXT4_EXT_DATA_PARTIAL_VALID1 to ext4_split_extent_at()\nwhen splitting at B, don't convert the entire extent to written and left\nit as unwritten after zeroing out B to N. The remaining work is just\nlike the standard two-part split. ext4_split_extent() will pass the\nEXT4_EXT_DATA_VALID2 flag when it calls ext4_split_extent_at() for the\nsecond time, allowing it to properly handle the split. If the split is\nsuccessful, it will keep extent from 0 to A as unwritten.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45858","epss":0.0016,"percentile":0.05486,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45858","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45859","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45859","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation  Ulrich reports a regression with nfqueue:  If an application did not set the 'F_GSO' capability flag and a gso packet with an unconfirmed nf_conn entry is received all packets are now dropped instead of queued, because the check happens after skb_gso_segment().  In that case, we did have exclusive ownership of the skb and its associated conntrack entry.  The elevated use count is due to skb_clone happening via skb_gso_segment().  Move the check so that its peformed vs. the aggregated packet.  Then, annotate the individual segments except the first one so we can do a 2nd check at reinject time.  For the normal case, where userspace does in-order reinjects, this avoids packet drops: first reinjected segment continues traversal and confirms entry, remaining segments observe the confirmed entry.  While at it, simplify nf_ct_drop_unconfirmed(): We only care about unconfirmed entries with a refcnt > 1, there is no need to special-case dying entries.  This only happens with UDP.  With TCP, the only unconfirmed packet will be the TCP SYN, those aren't aggregated by GRO.  Next patch adds a udpgro test case to cover this scenario.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45859","epss":0.00612,"percentile":0.47269,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.45899999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-45859","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45859","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/207b3ebacb6113acaaec0d171d5307032c690004","https://git.kernel.org/stable/c/23901aa6b8a2f294c4b774436b4691f3ff863a8f","https://git.kernel.org/stable/c/79b713ef4261a8ead96af4703f89d0b5f25532e2","https://git.kernel.org/stable/c/b740e7ddd7ca0dbfeafca3f5e52717206cf28524"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation\n\nUlrich reports a regression with nfqueue:\n\nIf an application did not set the 'F_GSO' capability flag and a gso\npacket with an unconfirmed nf_conn entry is received all packets are\nnow dropped instead of queued, because the check happens after\nskb_gso_segment().  In that case, we did have exclusive ownership\nof the skb and its associated conntrack entry.  The elevated use\ncount is due to skb_clone happening via skb_gso_segment().\n\nMove the check so that its peformed vs. the aggregated packet.\n\nThen, annotate the individual segments except the first one so we\ncan do a 2nd check at reinject time.\n\nFor the normal case, where userspace does in-order reinjects, this avoids\npacket drops: first reinjected segment continues traversal and confirms\nentry, remaining segments observe the confirmed entry.\n\nWhile at it, simplify nf_ct_drop_unconfirmed(): We only care about\nunconfirmed entries with a refcnt > 1, there is no need to special-case\ndying entries.\n\nThis only happens with UDP.  With TCP, the only unconfirmed packet will\nbe the TCP SYN, those aren't aggregated by GRO.\n\nNext patch adds a udpgro test case to cover this scenario.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45859","epss":0.00612,"percentile":0.47269,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45859","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45877","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45877","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients  During a warm reset flow, the cl->device pointer may be NULL if the reset occurs while clients are still being enumerated. Accessing cl->device->reference_count without a NULL check leads to a kernel panic.  This issue was identified during multi-unit warm reboot stress clycles. Add a defensive NULL check for cl->device to ensure stability under such intensive testing conditions.  KASAN: null-ptr-deref in range [0000000000000000-0000000000000007] Workqueue: ish_fw_update_wq fw_reset_work_fn  Call Trace:  ishtp_bus_remove_all_clients+0xbe/0x130 [intel_ishtp]  ishtp_reset_handler+0x85/0x1a0 [intel_ishtp]  fw_reset_work_fn+0x8a/0xc0 [intel_ish_ipc]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45877","epss":0.0016,"percentile":0.05486,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45877","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-45877","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45877","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0b605e8ce60698c27a26f512968a597fd620d2e8","https://git.kernel.org/stable/c/272dac57caa981718e7188c80c703e7bb1998054","https://git.kernel.org/stable/c/56f7db581ee73af53cd512e00a6261a025bf1d58","https://git.kernel.org/stable/c/feb4bcfd405282de60aba321f13a1272b30c5af4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients\n\nDuring a warm reset flow, the cl->device pointer may be NULL if the\nreset occurs while clients are still being enumerated. Accessing\ncl->device->reference_count without a NULL check leads to a kernel panic.\n\nThis issue was identified during multi-unit warm reboot stress clycles.\nAdd a defensive NULL check for cl->device to ensure stability under\nsuch intensive testing conditions.\n\nKASAN: null-ptr-deref in range [0000000000000000-0000000000000007]\nWorkqueue: ish_fw_update_wq fw_reset_work_fn\n\nCall Trace:\n ishtp_bus_remove_all_clients+0xbe/0x130 [intel_ishtp]\n ishtp_reset_handler+0x85/0x1a0 [intel_ishtp]\n fw_reset_work_fn+0x8a/0xc0 [intel_ish_ipc]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45877","epss":0.0016,"percentile":0.05486,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45877","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45877","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45892","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45892","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: drop extent cache after doing PARTIAL_VALID1 zeroout  When splitting an unwritten extent in the middle and converting it to initialized in ext4_split_extent() with the EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_DATA_VALID2 flags set, it could leave a stale unwritten extent.  Assume we have an unwritten file and buffered write in the middle of it without dioread_nolock enabled, it will allocate blocks as written extent.         0  A      B  N        [UUUUUUUUUUUU] on-disk extent      U: unwritten extent        [UUUUUUUUUUUU] extent status tree        [--DDDDDDDD--]                     D: valid data           |<-  ->| ----> this range needs to be initialized  ext4_split_extent() first try to split this extent at B with EXT4_EXT_DATA_PARTIAL_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but ext4_split_extent_at() failed to split this extent due to temporary lack of space. It zeroout B to N and leave the entire extent as unwritten.         0  A      B  N        [UUUUUUUUUUUU] on-disk extent        [UUUUUUUUUUUU] extent status tree        [--DDDDDDDDZZ]                     Z: zeroed data  ext4_split_extent() then try to split this extent at A with EXT4_EXT_DATA_VALID2 flag set. This time, it split successfully and leave an written extent from A to N.         0  A      B  N        [UUWWWWWWWWWW] on-disk extent      W: written extent        [UUUUUUUUUUUU] extent status tree        [--DDDDDDDDZZ]  Finally ext4_map_create_blocks() only insert extent A to B to the extent status tree, and leave an stale unwritten extent in the status tree.         0  A      B  N        [UUWWWWWWWWWW] on-disk extent      W: written extent        [UUWWWWWWWWUU] extent status tree        [--DDDDDDDDZZ]  Fix this issue by always cached extent status entry after zeroing out the second part.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45892","epss":0.0016,"percentile":0.05557,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-45892","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45892","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/28db4bfc6f82fd20e2aadb7fc162244109a4eb31","https://git.kernel.org/stable/c/6d882ea3b0931b43530d44149b79fcd4ffc13030","https://git.kernel.org/stable/c/a1b962a821e7a52d48212ae269b45808b4411267","https://git.kernel.org/stable/c/c2ee51d684adca7645e4aa74adca13f6750390bc","https://git.kernel.org/stable/c/d8ee559fccdef713f058cfe5f2c03dc9b18be3b1","https://git.kernel.org/stable/c/f0931a5c17005a0c4fc35bd1a001245effc3354b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: drop extent cache after doing PARTIAL_VALID1 zeroout\n\nWhen splitting an unwritten extent in the middle and converting it to\ninitialized in ext4_split_extent() with the EXT4_EXT_MAY_ZEROOUT and\nEXT4_EXT_DATA_VALID2 flags set, it could leave a stale unwritten extent.\n\nAssume we have an unwritten file and buffered write in the middle of it\nwithout dioread_nolock enabled, it will allocate blocks as written\nextent.\n\n       0  A      B  N\n       [UUUUUUUUUUUU] on-disk extent      U: unwritten extent\n       [UUUUUUUUUUUU] extent status tree\n       [--DDDDDDDD--]                     D: valid data\n          |<-  ->| ----> this range needs to be initialized\n\next4_split_extent() first try to split this extent at B with\nEXT4_EXT_DATA_PARTIAL_VALID1 and EXT4_EXT_MAY_ZEROOUT flag set, but\next4_split_extent_at() failed to split this extent due to temporary lack\nof space. It zeroout B to N and leave the entire extent as unwritten.\n\n       0  A      B  N\n       [UUUUUUUUUUUU] on-disk extent\n       [UUUUUUUUUUUU] extent status tree\n       [--DDDDDDDDZZ]                     Z: zeroed data\n\next4_split_extent() then try to split this extent at A with\nEXT4_EXT_DATA_VALID2 flag set. This time, it split successfully and\nleave an written extent from A to N.\n\n       0  A      B  N\n       [UUWWWWWWWWWW] on-disk extent      W: written extent\n       [UUUUUUUUUUUU] extent status tree\n       [--DDDDDDDDZZ]\n\nFinally ext4_map_create_blocks() only insert extent A to B to the extent\nstatus tree, and leave an stale unwritten extent in the status tree.\n\n       0  A      B  N\n       [UUWWWWWWWWWW] on-disk extent      W: written extent\n       [UUWWWWWWWWUU] extent status tree\n       [--DDDDDDDDZZ]\n\nFix this issue by always cached extent status entry after zeroing out\nthe second part.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45892","epss":0.0016,"percentile":0.05557,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45892","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45893","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45893","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  apparmor: Fix & Optimize table creation from possibly unaligned memory  Source blob may come from userspace and might be unaligned. Try to optize the copying process by avoiding unaligned memory accesses.  - Added Fixes tag - Added \"Fix &\" to description as this doesn't just optimize but fixes         a potential unaligned memory access [jj: remove duplicate word \"convert\" in comment trigger checkpatch warning]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45893","epss":0.00126,"percentile":0.02573,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45893","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09198},"relatedVulnerabilities":[{"id":"CVE-2026-45893","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45893","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/226c3b10aab23f73b03c47e7773107de56ba3a4e","https://git.kernel.org/stable/c/47e351dfef60ab0e3285133556e1a9c7f646a969","https://git.kernel.org/stable/c/6fc367bfd4c8886e6b1742aabbd1c0bdc310db3a","https://git.kernel.org/stable/c/e027999049c493fb728ead5a90db76942181a935"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: Fix & Optimize table creation from possibly unaligned memory\n\nSource blob may come from userspace and might be unaligned.\nTry to optize the copying process by avoiding unaligned memory accesses.\n\n- Added Fixes tag\n- Added \"Fix &\" to description as this doesn't just optimize but fixes\n        a potential unaligned memory access\n[jj: remove duplicate word \"convert\" in comment trigger checkpatch warning]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45893","epss":0.00126,"percentile":0.02573,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45893","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45893","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45894","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45894","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/vt-d: Clear Present bit before tearing down PASID entry  The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64 bytes). When tearing down an entry, the current implementation zeros the entire 64-byte structure immediately using multiple 64-bit writes.  Since the IOMMU hardware may fetch these 64 bytes using multiple internal transactions (e.g., four 128-bit bursts), updating or zeroing the entire entry while it is active (P=1) risks a \"torn\" read. If a hardware fetch occurs simultaneously with the CPU zeroing the entry, the hardware could observe an inconsistent state, leading to unpredictable behavior or spurious faults.  Follow the \"Guidance to Software for Invalidations\" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake:  1. Clear only the 'Present' (P) bit of the PASID entry. 2. Use a dma_wmb() to ensure the cleared bit is visible to hardware    before proceeding. 3. Execute the required invalidation sequence (PASID cache, IOTLB, and    Device-TLB flush) to ensure the hardware has released all cached    references. 4. Only after the flushes are complete, zero out the remaining fields    of the PASID entry.  Also, add a dma_wmb() in pasid_set_present() to ensure that all other fields of the PASID entry are visible to the hardware before the Present bit is set.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.2,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45894","epss":0.00149,"percentile":0.04427,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.113985},"relatedVulnerabilities":[{"id":"CVE-2026-45894","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45894","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/75ed00055c059dedc47b5daaaa2f8a7a019138ff","https://git.kernel.org/stable/c/821807c167b7b48a41b95b6607c6b9f97600f7d9","https://git.kernel.org/stable/c/949d71666e9dd19f21e7b4b53a88cd2c5b902858","https://git.kernel.org/stable/c/a84d30e8d2bacd21782a6481158b7c9c552f4868"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Clear Present bit before tearing down PASID entry\n\nThe Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64\nbytes). When tearing down an entry, the current implementation zeros the\nentire 64-byte structure immediately using multiple 64-bit writes.\n\nSince the IOMMU hardware may fetch these 64 bytes using multiple\ninternal transactions (e.g., four 128-bit bursts), updating or zeroing\nthe entire entry while it is active (P=1) risks a \"torn\" read. If a\nhardware fetch occurs simultaneously with the CPU zeroing the entry, the\nhardware could observe an inconsistent state, leading to unpredictable\nbehavior or spurious faults.\n\nFollow the \"Guidance to Software for Invalidations\" in the VT-d spec\n(Section 6.5.3.3) by implementing the recommended ownership handshake:\n\n1. Clear only the 'Present' (P) bit of the PASID entry.\n2. Use a dma_wmb() to ensure the cleared bit is visible to hardware\n   before proceeding.\n3. Execute the required invalidation sequence (PASID cache, IOTLB, and\n   Device-TLB flush) to ensure the hardware has released all cached\n   references.\n4. Only after the flushes are complete, zero out the remaining fields\n   of the PASID entry.\n\nAlso, add a dma_wmb() in pasid_set_present() to ensure that all other\nfields of the PASID entry are visible to the hardware before the Present\nbit is set.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.2,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45894","epss":0.00149,"percentile":0.04427,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45894","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45897","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45897","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_counter: serialize reset with spinlock  Add a global static spinlock to serialize counter fetch+reset operations, preventing concurrent dump-and-reset from underrunning values.  The lock is taken before fetching the total so that two parallel resets cannot both read the same counter values and then both subtract them.  A global lock is used for simplicity since resets are infrequent. If this becomes a bottleneck, it can be replaced with a per-net lock later.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45897","epss":0.00156,"percentile":0.05037,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0819},"relatedVulnerabilities":[{"id":"CVE-2026-45897","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45897","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0cdc6d5a26f2d1f7f15a43526841b679445c32e2","https://git.kernel.org/stable/c/48cf7918d10c66cb6b05226fa3fa5daf0c891089","https://git.kernel.org/stable/c/779c60a5190c42689534172f4b49e927c9959e4e","https://git.kernel.org/stable/c/cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_counter: serialize reset with spinlock\n\nAdd a global static spinlock to serialize counter fetch+reset\noperations, preventing concurrent dump-and-reset from underrunning\nvalues.\n\nThe lock is taken before fetching the total so that two parallel\nresets cannot both read the same counter values and then both\nsubtract them.\n\nA global lock is used for simplicity since resets are infrequent.\nIf this becomes a bottleneck, it can be replaced with a per-net\nlock later.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45897","epss":0.00156,"percentile":0.05037,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45897","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45899","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45899","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: drop extent cache when splitting extent fails  When the split extent fails, we might leave some extents still being processed and return an error directly, which will result in stale extent entries remaining in the extent status tree. So drop all of the remaining potentially stale extents if the splitting fails.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45899","epss":0.0016,"percentile":0.05555,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-45899","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45899","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/120c6bd7ca9d3e80a968b758cbb3fbd67570f132","https://git.kernel.org/stable/c/31bf37cf53ede8145e2bc62da803d4506da92975","https://git.kernel.org/stable/c/337506dc652383c80839edb8d8dcdd8ff2129b4f","https://git.kernel.org/stable/c/6e54f8dfee359bbd58086c883ea8cffd5312999d","https://git.kernel.org/stable/c/79b592e8f1b435796cbc2722190368e3e8ffd7a1","https://git.kernel.org/stable/c/808f3191498f300174523c54cab101e18795ae4e","https://git.kernel.org/stable/c/dc7c9b9d03a59a7fe483574531327e650a4b4adc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: drop extent cache when splitting extent fails\n\nWhen the split extent fails, we might leave some extents still being\nprocessed and return an error directly, which will result in stale\nextent entries remaining in the extent status tree. So drop all of the\nremaining potentially stale extents if the splitting fails.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45899","epss":0.0016,"percentile":0.05555,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45899","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45901","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45901","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: revert commit_mutex usage in reset path  It causes circular lock dependency between commit_mutex, nfnl_subsys_ipset and nlk_cb_mutex when nft reset, ipset list, and iptables-nft with '-m set' rule run at the same time.  Previous patches made it safe to run individual reset handlers concurrently so commit_mutex is no longer required to prevent this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45901","epss":0.0016,"percentile":0.05486,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-45901","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45901","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7f261bb906bf527c4a6e2a646e2d5f3679f2a8bc","https://git.kernel.org/stable/c/d66bedfe97a2bc321fa8118e669aae988038f729","https://git.kernel.org/stable/c/ee3978b6a0dcd4215cb7cedcba705a12174786a7","https://git.kernel.org/stable/c/f6410d18c1e2da325df02be989d5bca5ed38b086"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: revert commit_mutex usage in reset path\n\nIt causes circular lock dependency between commit_mutex, nfnl_subsys_ipset\nand nlk_cb_mutex when nft reset, ipset list, and iptables-nft with '-m set'\nrule run at the same time.\n\nPrevious patches made it safe to run individual reset handlers concurrently\nso commit_mutex is no longer required to prevent this.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45901","epss":0.0016,"percentile":0.05486,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45901","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45917","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45917","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipvs: do not keep dest_dst if dev is going down  There is race between the netdev notifier ip_vs_dst_event() and the code that caches dst with dev that is going down. As the FIB can be notified for the closed device after our handler finishes, it is possible valid route to be returned and cached resuling in a leaked dev reference until the dest is not removed.  To prevent new dest_dst to be attached to dest just after the handler dropped the old one, add a netif_running() check to make sure the notifier handler is not currently running for device that is closing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45917","epss":0.00122,"percentile":0.02297,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-45917","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45917","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/024eb0bd19f507e6e7f0c7a7e5506d66b5dc1d3e","https://git.kernel.org/stable/c/64af43033503458c46023e56d6ae7bb0f824b55f","https://git.kernel.org/stable/c/8fde939b0206afc1d5846217a01a16b9bc8c7896","https://git.kernel.org/stable/c/bae53b3baf2ff2f45f9205c438818fc055601a54"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: do not keep dest_dst if dev is going down\n\nThere is race between the netdev notifier ip_vs_dst_event()\nand the code that caches dst with dev that is going down.\nAs the FIB can be notified for the closed device after our\nhandler finishes, it is possible valid route to be returned\nand cached resuling in a leaked dev reference until the dest\nis not removed.\n\nTo prevent new dest_dst to be attached to dest just after the\nhandler dropped the old one, add a netif_running() check\nto make sure the notifier handler is not currently running\nfor device that is closing.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45917","epss":0.00122,"percentile":0.02297,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45917","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45934","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45934","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation  I have been observing a number of systems aborting at insert_dev_extents() in btrfs_create_pending_block_groups(). The following is a sample stack trace of such an abort coming from forced chunk allocation (typically behind CONFIG_BTRFS_EXPERIMENTAL) but this can theoretically happen to any DUP chunk allocation.    [81.801] ------------[ cut here ]------------   [81.801] BTRFS: Transaction aborted (error -17)   [81.801] WARNING: fs/btrfs/block-group.c:2876 at btrfs_create_pending_block_groups+0x721/0x770 [btrfs], CPU#1: bash/319   [81.802] Modules linked in: virtio_net btrfs xor zstd_compress raid6_pq null_blk   [81.803] CPU: 1 UID: 0 PID: 319 Comm: bash Kdump: loaded Not tainted 6.19.0-rc6+ #319 NONE   [81.803] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.17.0-2-2 04/01/2014   [81.804] RIP: 0010:btrfs_create_pending_block_groups+0x723/0x770 [btrfs]   [81.806] RSP: 0018:ffffa36241a6bce8 EFLAGS: 00010282   [81.806] RAX: 000000000000000d RBX: ffff8e699921e400 RCX: 0000000000000000   [81.807] RDX: 0000000002040001 RSI: 00000000ffffffef RDI: ffffffffc0608bf0   [81.807] RBP: 00000000ffffffef R08: ffff8e69830f6000 R09: 0000000000000007   [81.808] R10: ffff8e699921e5e8 R11: 0000000000000000 R12: ffff8e6999228000   [81.808] R13: ffff8e6984d82000 R14: ffff8e69966a69c0 R15: ffff8e69aa47b000   [81.809] FS:  00007fec6bdd9740(0000) GS:ffff8e6b1b379000(0000) knlGS:0000000000000000   [81.809] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   [81.810] CR2: 00005604833670f0 CR3: 0000000116679000 CR4: 00000000000006f0   [81.810] Call Trace:   [81.810]  <TASK>   [81.810]  __btrfs_end_transaction+0x3e/0x2b0 [btrfs]   [81.811]  btrfs_force_chunk_alloc_store+0xcd/0x140 [btrfs]   [81.811]  kernfs_fop_write_iter+0x15f/0x240   [81.812]  vfs_write+0x264/0x500   [81.812]  ksys_write+0x6c/0xe0   [81.812]  do_syscall_64+0x66/0x770   [81.812]  entry_SYSCALL_64_after_hwframe+0x76/0x7e   [81.813] RIP: 0033:0x7fec6be66197   [81.814] RSP: 002b:00007fffb159dd30 EFLAGS: 00000202 ORIG_RAX: 0000000000000001   [81.815] RAX: ffffffffffffffda RBX: 00007fec6bdd9740 RCX: 00007fec6be66197   [81.815] RDX: 0000000000000002 RSI: 0000560483374f80 RDI: 0000000000000001   [81.816] RBP: 0000560483374f80 R08: 0000000000000000 R09: 0000000000000000   [81.816] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000002   [81.817] R13: 00007fec6bfb85c0 R14: 00007fec6bfb5ee0 R15: 00005604833729c0   [81.817]  </TASK>   [81.817] irq event stamp: 20039   [81.818] hardirqs last  enabled at (20047): [<ffffffff99a68302>] __up_console_sem+0x52/0x60   [81.818] hardirqs last disabled at (20056): [<ffffffff99a682e7>] __up_console_sem+0x37/0x60   [81.819] softirqs last  enabled at (19470): [<ffffffff999d2b46>] __irq_exit_rcu+0x96/0xc0   [81.819] softirqs last disabled at (19463): [<ffffffff999d2b46>] __irq_exit_rcu+0x96/0xc0   [81.820] ---[ end trace 0000000000000000 ]---   [81.820] BTRFS: error (device dm-7 state A) in btrfs_create_pending_block_groups:2876: errno=-17 Object already exists  Inspecting these aborts with drgn, I observed a pattern of overlapping chunk_maps. Note how stripe 1 of the first chunk overlaps in physical address with stripe 0 of the second chunk.  Physical Start     Physical End       Length       Logical            Type                 Stripe ---------------------------------------------------------------------------------------------------- 0x0000000102500000 0x0000000142500000 1.0G         0x0000000641d00000 META|DUP             0/2 0x0000000142500000 0x0000000182500000 1.0G         0x0000000641d00000 META|DUP             1/2 0x0000000142500000 0x0000000182500000 1.0G         0x0000000601d00000 META|DUP             0/2 0x0000000182500000 0x00000001c2500000 1.0G         0x0000000601d00000 META|DUP             1/2  Now how could this possibly happen? All chunk allocation is ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45934","epss":0.00121,"percentile":0.02187,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-45934","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45934","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/156cac365e27a82b64ae510c5f463fd81f0265b1","https://git.kernel.org/stable/c/7d4eadee7042d27fcea659fcdd738f463a7d2e70","https://git.kernel.org/stable/c/b14c5e04bd0f722ed631845599d52d03fcae1bc1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation\n\nI have been observing a number of systems aborting at\ninsert_dev_extents() in btrfs_create_pending_block_groups(). The\nfollowing is a sample stack trace of such an abort coming from forced\nchunk allocation (typically behind CONFIG_BTRFS_EXPERIMENTAL) but this\ncan theoretically happen to any DUP chunk allocation.\n\n  [81.801] ------------[ cut here ]------------\n  [81.801] BTRFS: Transaction aborted (error -17)\n  [81.801] WARNING: fs/btrfs/block-group.c:2876 at btrfs_create_pending_block_groups+0x721/0x770 [btrfs], CPU#1: bash/319\n  [81.802] Modules linked in: virtio_net btrfs xor zstd_compress raid6_pq null_blk\n  [81.803] CPU: 1 UID: 0 PID: 319 Comm: bash Kdump: loaded Not tainted 6.19.0-rc6+ #319 NONE\n  [81.803] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.17.0-2-2 04/01/2014\n  [81.804] RIP: 0010:btrfs_create_pending_block_groups+0x723/0x770 [btrfs]\n  [81.806] RSP: 0018:ffffa36241a6bce8 EFLAGS: 00010282\n  [81.806] RAX: 000000000000000d RBX: ffff8e699921e400 RCX: 0000000000000000\n  [81.807] RDX: 0000000002040001 RSI: 00000000ffffffef RDI: ffffffffc0608bf0\n  [81.807] RBP: 00000000ffffffef R08: ffff8e69830f6000 R09: 0000000000000007\n  [81.808] R10: ffff8e699921e5e8 R11: 0000000000000000 R12: ffff8e6999228000\n  [81.808] R13: ffff8e6984d82000 R14: ffff8e69966a69c0 R15: ffff8e69aa47b000\n  [81.809] FS:  00007fec6bdd9740(0000) GS:ffff8e6b1b379000(0000) knlGS:0000000000000000\n  [81.809] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  [81.810] CR2: 00005604833670f0 CR3: 0000000116679000 CR4: 00000000000006f0\n  [81.810] Call Trace:\n  [81.810]  <TASK>\n  [81.810]  __btrfs_end_transaction+0x3e/0x2b0 [btrfs]\n  [81.811]  btrfs_force_chunk_alloc_store+0xcd/0x140 [btrfs]\n  [81.811]  kernfs_fop_write_iter+0x15f/0x240\n  [81.812]  vfs_write+0x264/0x500\n  [81.812]  ksys_write+0x6c/0xe0\n  [81.812]  do_syscall_64+0x66/0x770\n  [81.812]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  [81.813] RIP: 0033:0x7fec6be66197\n  [81.814] RSP: 002b:00007fffb159dd30 EFLAGS: 00000202 ORIG_RAX: 0000000000000001\n  [81.815] RAX: ffffffffffffffda RBX: 00007fec6bdd9740 RCX: 00007fec6be66197\n  [81.815] RDX: 0000000000000002 RSI: 0000560483374f80 RDI: 0000000000000001\n  [81.816] RBP: 0000560483374f80 R08: 0000000000000000 R09: 0000000000000000\n  [81.816] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000002\n  [81.817] R13: 00007fec6bfb85c0 R14: 00007fec6bfb5ee0 R15: 00005604833729c0\n  [81.817]  </TASK>\n  [81.817] irq event stamp: 20039\n  [81.818] hardirqs last  enabled at (20047): [<ffffffff99a68302>] __up_console_sem+0x52/0x60\n  [81.818] hardirqs last disabled at (20056): [<ffffffff99a682e7>] __up_console_sem+0x37/0x60\n  [81.819] softirqs last  enabled at (19470): [<ffffffff999d2b46>] __irq_exit_rcu+0x96/0xc0\n  [81.819] softirqs last disabled at (19463): [<ffffffff999d2b46>] __irq_exit_rcu+0x96/0xc0\n  [81.820] ---[ end trace 0000000000000000 ]---\n  [81.820] BTRFS: error (device dm-7 state A) in btrfs_create_pending_block_groups:2876: errno=-17 Object already exists\n\nInspecting these aborts with drgn, I observed a pattern of overlapping\nchunk_maps. Note how stripe 1 of the first chunk overlaps in physical\naddress with stripe 0 of the second chunk.\n\nPhysical Start     Physical End       Length       Logical            Type                 Stripe\n----------------------------------------------------------------------------------------------------\n0x0000000102500000 0x0000000142500000 1.0G         0x0000000641d00000 META|DUP             0/2\n0x0000000142500000 0x0000000182500000 1.0G         0x0000000641d00000 META|DUP             1/2\n0x0000000142500000 0x0000000182500000 1.0G         0x0000000601d00000 META|DUP             0/2\n0x0000000182500000 0x00000001c2500000 1.0G         0x0000000601d00000 META|DUP             1/2\n\nNow how could this possibly happen? All chunk allocation is\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45934","epss":0.00121,"percentile":0.02187,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45934","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45940","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: stmmac: fix oops when split header is enabled  For GMAC4, when split header is enabled, in some rare cases, the hardware does not fill buf2 of the first descriptor with payload. Thus we cannot assume buf2 is always fully filled if it is not the last descriptor. Otherwise, the length of buf2 of the second descriptor will be calculated wrong and cause an oops:  Unable to handle kernel paging request at virtual address ffff00019246bfc0 ... x2 : 0000000000000040 x1 : ffff00019246bfc0 x0 : ffff00009246c000 Call trace:  dcache_inval_poc+0x28/0x58 (P)  dma_direct_sync_single_for_cpu+0x38/0x6c  __dma_sync_single_for_cpu+0x34/0x6c  stmmac_napi_poll_rx+0x8f0/0xb60  __napi_poll.constprop.0+0x30/0x144  net_rx_action+0x160/0x274  handle_softirqs+0x1b8/0x1fc ...  To fix this, the PL bit-field in RDES3 register is used for all descriptors, whether it is the last descriptor or not.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45940","epss":0.00158,"percentile":0.05286,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08295000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-45940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45940","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/36f81cb7d82e9614a7058da6abdf2e3a03993df1","https://git.kernel.org/stable/c/b1f23df09e7dbf4c86b6908dff7efb8cb2b7d609","https://git.kernel.org/stable/c/babab1b42ed68877ef669a08384becf281ad2582"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: fix oops when split header is enabled\n\nFor GMAC4, when split header is enabled, in some rare cases, the\nhardware does not fill buf2 of the first descriptor with payload.\nThus we cannot assume buf2 is always fully filled if it is not\nthe last descriptor. Otherwise, the length of buf2 of the second\ndescriptor will be calculated wrong and cause an oops:\n\nUnable to handle kernel paging request at virtual address ffff00019246bfc0\n...\nx2 : 0000000000000040 x1 : ffff00019246bfc0 x0 : ffff00009246c000\nCall trace:\n dcache_inval_poc+0x28/0x58 (P)\n dma_direct_sync_single_for_cpu+0x38/0x6c\n __dma_sync_single_for_cpu+0x34/0x6c\n stmmac_napi_poll_rx+0x8f0/0xb60\n __napi_poll.constprop.0+0x30/0x144\n net_rx_action+0x160/0x274\n handle_softirqs+0x1b8/0x1fc\n...\n\nTo fix this, the PL bit-field in RDES3 register is used for all\ndescriptors, whether it is the last descriptor or not.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45940","epss":0.00158,"percentile":0.05286,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45942","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45942","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: fix e4b bitmap inconsistency reports  A bitmap inconsistency issue was observed during stress tests under mixed huge-page workloads. Ext4 reported multiple e4b bitmap check failures like:  ext4_mb_complex_scan_group:2508: group 350, 8179 free clusters as per group info. But got 8192 blocks  Analysis and experimentation confirmed that the issue is caused by a race condition between page migration and bitmap modification. Although this timing window is extremely narrow, it is still hit in practice:  folio_lock                        ext4_mb_load_buddy __migrate_folio   check ref count   folio_mc_copy                     __filemap_get_folio                                       folio_try_get(folio)                                   ......                                   mb_mark_used                                   ext4_mb_unload_buddy   __folio_migrate_mapping     folio_ref_freeze folio_unlock  The root cause of this issue is that the fast path of load_buddy only increments the folio's reference count, which is insufficient to prevent concurrent folio migration. We observed that the folio migration process acquires the folio lock. Therefore, we can determine whether to take the fast path in load_buddy by checking the lock status. If the folio is locked, we opt for the slow path (which acquires the lock) to close this concurrency window.  Additionally, this change addresses the following issues:  When the DOUBLE_CHECK macro is enabled to inspect bitmap-related issues, the following error may be triggered:  corruption in group 324 at byte 784(6272): f in copy != ff on disk/prealloc  Analysis reveals that this is a false positive. There is a specific race window where the bitmap and the group descriptor become momentarily inconsistent, leading to this error report:  ext4_mb_load_buddy                   ext4_mb_load_buddy   __filemap_get_folio(create|lock)     folio_lock   ext4_mb_init_cache     folio_mark_uptodate                                      __filemap_get_folio(no lock)                                      ......                                      mb_mark_used                                        mb_mark_used_double   mb_cmp_bitmaps                                        mb_set_bits(e4b->bd_bitmap)   folio_unlock  The original logic assumed that since mb_cmp_bitmaps is called when the bitmap is newly loaded from disk, the folio lock would be sufficient to prevent concurrent access. However, this overlooks a specific race condition: if another process attempts to load buddy and finds the folio is already in an uptodate state, it will immediately begin using it without holding folio lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45942","epss":0.001,"percentile":0.0092,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45942","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07650000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-45942","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45942","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/29a07d691d282faf38c33d4b61839b89399110f9","https://git.kernel.org/stable/c/57e83bfbe1e412ac42daced2086f3c6f9a17bba0","https://git.kernel.org/stable/c/bdc56a9c46b2a99c12313122b9352b619a2e719e","https://git.kernel.org/stable/c/c05033cfc5c7699cd4df8d48cef94d01da755f24","https://git.kernel.org/stable/c/f29709a7a3fc38f5015d850504762cdef0e151f9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix e4b bitmap inconsistency reports\n\nA bitmap inconsistency issue was observed during stress tests under\nmixed huge-page workloads. Ext4 reported multiple e4b bitmap check\nfailures like:\n\next4_mb_complex_scan_group:2508: group 350, 8179 free clusters as\nper group info. But got 8192 blocks\n\nAnalysis and experimentation confirmed that the issue is caused by a\nrace condition between page migration and bitmap modification. Although\nthis timing window is extremely narrow, it is still hit in practice:\n\nfolio_lock                        ext4_mb_load_buddy\n__migrate_folio\n  check ref count\n  folio_mc_copy                     __filemap_get_folio\n                                      folio_try_get(folio)\n                                  ......\n                                  mb_mark_used\n                                  ext4_mb_unload_buddy\n  __folio_migrate_mapping\n    folio_ref_freeze\nfolio_unlock\n\nThe root cause of this issue is that the fast path of load_buddy only\nincrements the folio's reference count, which is insufficient to prevent\nconcurrent folio migration. We observed that the folio migration process\nacquires the folio lock. Therefore, we can determine whether to take the\nfast path in load_buddy by checking the lock status. If the folio is\nlocked, we opt for the slow path (which acquires the lock) to close this\nconcurrency window.\n\nAdditionally, this change addresses the following issues:\n\nWhen the DOUBLE_CHECK macro is enabled to inspect bitmap-related\nissues, the following error may be triggered:\n\ncorruption in group 324 at byte 784(6272): f in copy != ff on\ndisk/prealloc\n\nAnalysis reveals that this is a false positive. There is a specific race\nwindow where the bitmap and the group descriptor become momentarily\ninconsistent, leading to this error report:\n\next4_mb_load_buddy                   ext4_mb_load_buddy\n  __filemap_get_folio(create|lock)\n    folio_lock\n  ext4_mb_init_cache\n    folio_mark_uptodate\n                                     __filemap_get_folio(no lock)\n                                     ......\n                                     mb_mark_used\n                                       mb_mark_used_double\n  mb_cmp_bitmaps\n                                       mb_set_bits(e4b->bd_bitmap)\n  folio_unlock\n\nThe original logic assumed that since mb_cmp_bitmaps is called when the\nbitmap is newly loaded from disk, the folio lock would be sufficient to\nprevent concurrent access. However, this overlooks a specific race\ncondition: if another process attempts to load buddy and finds the folio\nis already in an uptodate state, it will immediately begin using it without\nholding folio lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45942","epss":0.001,"percentile":0.0092,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45942","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45942","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45943","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45943","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  erofs: fix inline data read failure for ztailpacking pclusters  Compressed folios for ztailpacking pclusters must be valid before adding these pclusters to I/O chains. Otherwise, z_erofs_decompress_pcluster() may assume they are already valid and then trigger a NULL pointer dereference.  It is somewhat hard to reproduce because the inline data is in the same block as the tail of the compressed indexes, which are usually read just before. However, it may still happen if a fatal signal arrives while read_mapping_folio() is running, as shown below:   erofs: (device dm-1): z_erofs_pcluster_begin: failed to get inline data -4  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008   ...   pc : z_erofs_decompress_queue+0x4c8/0xa14  lr : z_erofs_decompress_queue+0x160/0xa14  sp : ffffffc08b3eb3a0  x29: ffffffc08b3eb570 x28: ffffffc08b3eb418 x27: 0000000000001000  x26: ffffff8086ebdbb8 x25: ffffff8086ebdbb8 x24: 0000000000000001  x23: 0000000000000008 x22: 00000000fffffffb x21: dead000000000700  x20: 00000000000015e7 x19: ffffff808babb400 x18: ffffffc089edc098  x17: 00000000c006287d x16: 00000000c006287d x15: 0000000000000004  x14: ffffff80ba8f8000 x13: 0000000000000004 x12: 00000006589a77c9  x11: 0000000000000015 x10: 0000000000000000 x9 : 0000000000000000  x8 : 0000000000000000 x7 : 0000000000000000 x6 : 000000000000003f  x5 : 0000000000000040 x4 : ffffffffffffffe0 x3 : 0000000000000020  x2 : 0000000000000008 x1 : 0000000000000000 x0 : 0000000000000000  Call trace:   z_erofs_decompress_queue+0x4c8/0xa14   z_erofs_runqueue+0x908/0x97c   z_erofs_read_folio+0x128/0x228   filemap_read_folio+0x68/0x128   filemap_get_pages+0x44c/0x8b4   filemap_read+0x12c/0x5b8   generic_file_read_iter+0x4c/0x15c   do_iter_readv_writev+0x188/0x1e0   vfs_iter_read+0xac/0x1a4   backing_file_read_iter+0x170/0x34c   ovl_read_iter+0xf0/0x140   vfs_read+0x28c/0x344   ksys_read+0x80/0xf0   __arm64_sys_read+0x24/0x34   invoke_syscall+0x60/0x114   el0_svc_common+0x88/0xe4   do_el0_svc+0x24/0x30   el0_svc+0x40/0xa8   el0t_64_sync_handler+0x70/0xbc   el0t_64_sync+0x1bc/0x1c0  Fix this by reading the inline data before allocating and adding the pclusters to the I/O chains.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45943","epss":0.00126,"percentile":0.02573,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45943","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09198},"relatedVulnerabilities":[{"id":"CVE-2026-45943","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45943","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5de1aa0bf3a5db0b3cbf61959da5ac61250833ed","https://git.kernel.org/stable/c/92088bd9aa2a7246bba8b9648fbc64edd173cf17","https://git.kernel.org/stable/c/ad07ea069f924465061cfee40ef2861bb99f4dd8","https://git.kernel.org/stable/c/c134a40f86efb8d6b5a949ef70e06d5752209be5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix inline data read failure for ztailpacking pclusters\n\nCompressed folios for ztailpacking pclusters must be valid before adding\nthese pclusters to I/O chains. Otherwise, z_erofs_decompress_pcluster()\nmay assume they are already valid and then trigger a NULL pointer\ndereference.\n\nIt is somewhat hard to reproduce because the inline data is in the same\nblock as the tail of the compressed indexes, which are usually read just\nbefore. However, it may still happen if a fatal signal arrives while\nread_mapping_folio() is running, as shown below:\n\n erofs: (device dm-1): z_erofs_pcluster_begin: failed to get inline data -4\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008\n\n ...\n\n pc : z_erofs_decompress_queue+0x4c8/0xa14\n lr : z_erofs_decompress_queue+0x160/0xa14\n sp : ffffffc08b3eb3a0\n x29: ffffffc08b3eb570 x28: ffffffc08b3eb418 x27: 0000000000001000\n x26: ffffff8086ebdbb8 x25: ffffff8086ebdbb8 x24: 0000000000000001\n x23: 0000000000000008 x22: 00000000fffffffb x21: dead000000000700\n x20: 00000000000015e7 x19: ffffff808babb400 x18: ffffffc089edc098\n x17: 00000000c006287d x16: 00000000c006287d x15: 0000000000000004\n x14: ffffff80ba8f8000 x13: 0000000000000004 x12: 00000006589a77c9\n x11: 0000000000000015 x10: 0000000000000000 x9 : 0000000000000000\n x8 : 0000000000000000 x7 : 0000000000000000 x6 : 000000000000003f\n x5 : 0000000000000040 x4 : ffffffffffffffe0 x3 : 0000000000000020\n x2 : 0000000000000008 x1 : 0000000000000000 x0 : 0000000000000000\n Call trace:\n  z_erofs_decompress_queue+0x4c8/0xa14\n  z_erofs_runqueue+0x908/0x97c\n  z_erofs_read_folio+0x128/0x228\n  filemap_read_folio+0x68/0x128\n  filemap_get_pages+0x44c/0x8b4\n  filemap_read+0x12c/0x5b8\n  generic_file_read_iter+0x4c/0x15c\n  do_iter_readv_writev+0x188/0x1e0\n  vfs_iter_read+0xac/0x1a4\n  backing_file_read_iter+0x170/0x34c\n  ovl_read_iter+0xf0/0x140\n  vfs_read+0x28c/0x344\n  ksys_read+0x80/0xf0\n  __arm64_sys_read+0x24/0x34\n  invoke_syscall+0x60/0x114\n  el0_svc_common+0x88/0xe4\n  do_el0_svc+0x24/0x30\n  el0_svc+0x40/0xa8\n  el0t_64_sync_handler+0x70/0xbc\n  el0t_64_sync+0x1bc/0x1c0\n\nFix this by reading the inline data before allocating and adding\nthe pclusters to the I/O chains.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45943","epss":0.00126,"percentile":0.02573,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45943","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45943","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45944","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45944","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/vt-d: Clear Present bit before tearing down context entry  When tearing down a context entry, the current implementation zeros the entire 128-bit entry using multiple 64-bit writes. This creates a window where the hardware can fetch a \"torn\" entry — where some fields are already zeroed while the 'Present' bit is still set — leading to unpredictable behavior or spurious faults.  While x86 provides strong write ordering, the compiler may reorder writes to the two 64-bit halves of the context entry. Even without compiler reordering, the hardware fetch is not guaranteed to be atomic with respect to multiple CPU writes.  Align with the \"Guidance to Software for Invalidations\" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake:  1. Clear only the 'Present' (P) bit of the context entry first to    signal the transition of ownership from hardware to software. 2. Use dma_wmb() to ensure the cleared bit is visible to the IOMMU. 3. Perform the required cache and context-cache invalidation to ensure    hardware no longer has cached references to the entry. 4. Fully zero out the entry only after the invalidation is complete.  Also, add a dma_wmb() to context_set_present() to ensure the entry is fully initialized before the 'Present' bit becomes visible.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":0.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45944","epss":0.00127,"percentile":0.02657,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09525},"relatedVulnerabilities":[{"id":"CVE-2026-45944","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45944","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/a922dbafb4a674d958d702038232d09a30daf770","https://git.kernel.org/stable/c/c1e4f1dccbe9d7656d1c6872ebeadb5992d0aaa2","https://git.kernel.org/stable/c/c716a59e9977d751e5eb54bcfa6a80124cb5067b","https://git.kernel.org/stable/c/d2138abc8f0a7fce4101b7229b43b06811ed083d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Clear Present bit before tearing down context entry\n\nWhen tearing down a context entry, the current implementation zeros the\nentire 128-bit entry using multiple 64-bit writes. This creates a window\nwhere the hardware can fetch a \"torn\" entry — where some fields are\nalready zeroed while the 'Present' bit is still set — leading to\nunpredictable behavior or spurious faults.\n\nWhile x86 provides strong write ordering, the compiler may reorder writes\nto the two 64-bit halves of the context entry. Even without compiler\nreordering, the hardware fetch is not guaranteed to be atomic with\nrespect to multiple CPU writes.\n\nAlign with the \"Guidance to Software for Invalidations\" in the VT-d spec\n(Section 6.5.3.3) by implementing the recommended ownership handshake:\n\n1. Clear only the 'Present' (P) bit of the context entry first to\n   signal the transition of ownership from hardware to software.\n2. Use dma_wmb() to ensure the cleared bit is visible to the IOMMU.\n3. Perform the required cache and context-cache invalidation to ensure\n   hardware no longer has cached references to the entry.\n4. Fully zero out the entry only after the invalidation is complete.\n\nAlso, add a dma_wmb() to context_set_present() to ensure the entry\nis fully initialized before the 'Present' bit becomes visible.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":0.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45944","epss":0.00127,"percentile":0.02657,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45944","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45949","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45949","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwrng: core - use RCU and work_struct to fix race condition  Currently, hwrng_fill is not cleared until the hwrng_fillfn() thread exits. Since hwrng_unregister() reads hwrng_fill outside the rng_mutex lock, a concurrent hwrng_unregister() may call kthread_stop() again on the same task.  Additionally, if hwrng_unregister() is called immediately after hwrng_register(), the stopped thread may have never been executed. Thus, hwrng_fill remains dirty even after hwrng_unregister() returns. In this case, subsequent calls to hwrng_register() will fail to start new threads, and hwrng_unregister() will call kthread_stop() on the same freed task. In both cases, a use-after-free occurs:  refcount_t: addition on 0; use-after-free. WARNING: ... at lib/refcount.c:25 refcount_warn_saturate+0xec/0x1c0 Call Trace:  kthread_stop+0x181/0x360  hwrng_unregister+0x288/0x380  virtrng_remove+0xe3/0x200  This patch fixes the race by protecting the global hwrng_fill pointer inside the rng_mutex lock, so that hwrng_fillfn() thread is stopped only once, and calls to kthread_run() and kthread_stop() are serialized with the lock held.  To avoid deadlock in hwrng_fillfn() while being stopped with the lock held, we convert current_rng to RCU, so that get_current_rng() can read current_rng without holding the lock. To remove the lock from put_rng(), we also delay the actual cleanup into a work_struct.  Since get_current_rng() no longer returns ERR_PTR values, the IS_ERR() checks are removed from its callers.  With hwrng_fill protected by the rng_mutex lock, hwrng_fillfn() can no longer clear hwrng_fill itself. Therefore, if hwrng_fillfn() returns directly after current_rng is dropped, kthread_stop() would be called on a freed task_struct later. To fix this, hwrng_fillfn() calls schedule() now to keep the task alive until being stopped. The kthread_stop() call is also moved from hwrng_unregister() to drop_current_rng(), ensuring kthread_stop() is called on all possible paths where current_rng becomes NULL, so that the thread would not wait forever.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45949","epss":0.00088,"percentile":0.0043,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45949","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.04268},"relatedVulnerabilities":[{"id":"CVE-2026-45949","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45949","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/ad38f2cdfef9a2f2899c30cad269baec5bfd4a5d","https://git.kernel.org/stable/c/cc2f39d6ac48e6e3cb2d6240bc0d6df839dd0828","https://git.kernel.org/stable/c/d5b7730f06994499632026c30e38e0317c4569e2","https://git.kernel.org/stable/c/dcf416eb88eafe1e3c0f920a14bdffd10bc4d259"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwrng: core - use RCU and work_struct to fix race condition\n\nCurrently, hwrng_fill is not cleared until the hwrng_fillfn() thread\nexits. Since hwrng_unregister() reads hwrng_fill outside the rng_mutex\nlock, a concurrent hwrng_unregister() may call kthread_stop() again on\nthe same task.\n\nAdditionally, if hwrng_unregister() is called immediately after\nhwrng_register(), the stopped thread may have never been executed. Thus,\nhwrng_fill remains dirty even after hwrng_unregister() returns. In this\ncase, subsequent calls to hwrng_register() will fail to start new\nthreads, and hwrng_unregister() will call kthread_stop() on the same\nfreed task. In both cases, a use-after-free occurs:\n\nrefcount_t: addition on 0; use-after-free.\nWARNING: ... at lib/refcount.c:25 refcount_warn_saturate+0xec/0x1c0\nCall Trace:\n kthread_stop+0x181/0x360\n hwrng_unregister+0x288/0x380\n virtrng_remove+0xe3/0x200\n\nThis patch fixes the race by protecting the global hwrng_fill pointer\ninside the rng_mutex lock, so that hwrng_fillfn() thread is stopped only\nonce, and calls to kthread_run() and kthread_stop() are serialized\nwith the lock held.\n\nTo avoid deadlock in hwrng_fillfn() while being stopped with the lock\nheld, we convert current_rng to RCU, so that get_current_rng() can read\ncurrent_rng without holding the lock. To remove the lock from put_rng(),\nwe also delay the actual cleanup into a work_struct.\n\nSince get_current_rng() no longer returns ERR_PTR values, the IS_ERR()\nchecks are removed from its callers.\n\nWith hwrng_fill protected by the rng_mutex lock, hwrng_fillfn() can no\nlonger clear hwrng_fill itself. Therefore, if hwrng_fillfn() returns\ndirectly after current_rng is dropped, kthread_stop() would be called on\na freed task_struct later. To fix this, hwrng_fillfn() calls schedule()\nnow to keep the task alive until being stopped. The kthread_stop() call\nis also moved from hwrng_unregister() to drop_current_rng(), ensuring\nkthread_stop() is called on all possible paths where current_rng becomes\nNULL, so that the thread would not wait forever.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45949","epss":0.00088,"percentile":0.0043,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45949","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45949","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45957","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45957","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rcu: Fix rcu_read_unlock() deadloop due to softirq  Commit 5f5fa7ea89dc (\"rcu: Don't use negative nesting depth in __rcu_read_unlock()\") removes the recursion-protection code from __rcu_read_unlock(). Therefore, we could invoke the deadloop in raise_softirq_irqoff() with ftrace enabled as follows:  WARNING: CPU: 0 PID: 0 at kernel/trace/trace.c:3021 __ftrace_trace_stack.constprop.0+0x172/0x180 Modules linked in: my_irq_work(O) CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Tainted: G O 6.18.0-rc7-dirty #23 PREEMPT(full) Tainted: [O]=OOT_MODULE Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:__ftrace_trace_stack.constprop.0+0x172/0x180 RSP: 0018:ffffc900000034a8 EFLAGS: 00010002 RAX: 0000000000000000 RBX: 0000000000000004 RCX: 0000000000000000 RDX: 0000000000000003 RSI: ffffffff826d7b87 RDI: ffffffff826e9329 RBP: 0000000000090009 R08: 0000000000000005 R09: ffffffff82afbc4c R10: 0000000000000008 R11: 0000000000011d7a R12: 0000000000000000 R13: ffff888003874100 R14: 0000000000000003 R15: ffff8880038c1054 FS:  0000000000000000(0000) GS:ffff8880fa8ea000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000055b31fa7f540 CR3: 00000000078f4005 CR4: 0000000000770ef0 PKRU: 55555554 Call Trace:  <IRQ>  trace_buffer_unlock_commit_regs+0x6d/0x220  trace_event_buffer_commit+0x5c/0x260  trace_event_raw_event_softirq+0x47/0x80  raise_softirq_irqoff+0x6e/0xa0  rcu_read_unlock_special+0xb1/0x160  unwind_next_frame+0x203/0x9b0  __unwind_start+0x15d/0x1c0  arch_stack_walk+0x62/0xf0  stack_trace_save+0x48/0x70  __ftrace_trace_stack.constprop.0+0x144/0x180  trace_buffer_unlock_commit_regs+0x6d/0x220  trace_event_buffer_commit+0x5c/0x260  trace_event_raw_event_softirq+0x47/0x80  raise_softirq_irqoff+0x6e/0xa0  rcu_read_unlock_special+0xb1/0x160  unwind_next_frame+0x203/0x9b0  __unwind_start+0x15d/0x1c0  arch_stack_walk+0x62/0xf0  stack_trace_save+0x48/0x70  __ftrace_trace_stack.constprop.0+0x144/0x180  trace_buffer_unlock_commit_regs+0x6d/0x220  trace_event_buffer_commit+0x5c/0x260  trace_event_raw_event_softirq+0x47/0x80  raise_softirq_irqoff+0x6e/0xa0  rcu_read_unlock_special+0xb1/0x160  unwind_next_frame+0x203/0x9b0  __unwind_start+0x15d/0x1c0  arch_stack_walk+0x62/0xf0  stack_trace_save+0x48/0x70  __ftrace_trace_stack.constprop.0+0x144/0x180  trace_buffer_unlock_commit_regs+0x6d/0x220  trace_event_buffer_commit+0x5c/0x260  trace_event_raw_event_softirq+0x47/0x80  raise_softirq_irqoff+0x6e/0xa0  rcu_read_unlock_special+0xb1/0x160  __is_insn_slot_addr+0x54/0x70  kernel_text_address+0x48/0xc0  __kernel_text_address+0xd/0x40  unwind_get_return_address+0x1e/0x40  arch_stack_walk+0x9c/0xf0  stack_trace_save+0x48/0x70  __ftrace_trace_stack.constprop.0+0x144/0x180  trace_buffer_unlock_commit_regs+0x6d/0x220  trace_event_buffer_commit+0x5c/0x260  trace_event_raw_event_softirq+0x47/0x80  __raise_softirq_irqoff+0x61/0x80  __flush_smp_call_function_queue+0x115/0x420  __sysvec_call_function_single+0x17/0xb0  sysvec_call_function_single+0x8c/0xc0  </IRQ>  Commit b41642c87716 (\"rcu: Fix rcu_read_unlock() deadloop due to IRQ work\") fixed the infinite loop in rcu_read_unlock_special() for IRQ work by setting a flag before calling irq_work_queue_on(). We fix this issue by setting the same flag before calling raise_softirq_irqoff() and rename the flag to defer_qs_pending for more common.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45957","epss":0.00125,"percentile":0.02511,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45957","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09125},"relatedVulnerabilities":[{"id":"CVE-2026-45957","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45957","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1f16679a5aa60238466ce339c35f5e82ece60337","https://git.kernel.org/stable/c/4a4a6e12c9c829be3f74b7206fa8640fc4e1c566","https://git.kernel.org/stable/c/979c708e6c9d7fc461daef2dad8b45f22e23464c","https://git.kernel.org/stable/c/c2932e16d8c354404b17123e64daa8e33191e145","https://git.kernel.org/stable/c/d41e37f26b3157b3f1d10223863519a943aa239b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrcu: Fix rcu_read_unlock() deadloop due to softirq\n\nCommit 5f5fa7ea89dc (\"rcu: Don't use negative nesting depth in\n__rcu_read_unlock()\") removes the recursion-protection code from\n__rcu_read_unlock(). Therefore, we could invoke the deadloop in\nraise_softirq_irqoff() with ftrace enabled as follows:\n\nWARNING: CPU: 0 PID: 0 at kernel/trace/trace.c:3021 __ftrace_trace_stack.constprop.0+0x172/0x180\nModules linked in: my_irq_work(O)\nCPU: 0 UID: 0 PID: 0 Comm: swapper/0 Tainted: G O 6.18.0-rc7-dirty #23 PREEMPT(full)\nTainted: [O]=OOT_MODULE\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nRIP: 0010:__ftrace_trace_stack.constprop.0+0x172/0x180\nRSP: 0018:ffffc900000034a8 EFLAGS: 00010002\nRAX: 0000000000000000 RBX: 0000000000000004 RCX: 0000000000000000\nRDX: 0000000000000003 RSI: ffffffff826d7b87 RDI: ffffffff826e9329\nRBP: 0000000000090009 R08: 0000000000000005 R09: ffffffff82afbc4c\nR10: 0000000000000008 R11: 0000000000011d7a R12: 0000000000000000\nR13: ffff888003874100 R14: 0000000000000003 R15: ffff8880038c1054\nFS:  0000000000000000(0000) GS:ffff8880fa8ea000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055b31fa7f540 CR3: 00000000078f4005 CR4: 0000000000770ef0\nPKRU: 55555554\nCall Trace:\n <IRQ>\n trace_buffer_unlock_commit_regs+0x6d/0x220\n trace_event_buffer_commit+0x5c/0x260\n trace_event_raw_event_softirq+0x47/0x80\n raise_softirq_irqoff+0x6e/0xa0\n rcu_read_unlock_special+0xb1/0x160\n unwind_next_frame+0x203/0x9b0\n __unwind_start+0x15d/0x1c0\n arch_stack_walk+0x62/0xf0\n stack_trace_save+0x48/0x70\n __ftrace_trace_stack.constprop.0+0x144/0x180\n trace_buffer_unlock_commit_regs+0x6d/0x220\n trace_event_buffer_commit+0x5c/0x260\n trace_event_raw_event_softirq+0x47/0x80\n raise_softirq_irqoff+0x6e/0xa0\n rcu_read_unlock_special+0xb1/0x160\n unwind_next_frame+0x203/0x9b0\n __unwind_start+0x15d/0x1c0\n arch_stack_walk+0x62/0xf0\n stack_trace_save+0x48/0x70\n __ftrace_trace_stack.constprop.0+0x144/0x180\n trace_buffer_unlock_commit_regs+0x6d/0x220\n trace_event_buffer_commit+0x5c/0x260\n trace_event_raw_event_softirq+0x47/0x80\n raise_softirq_irqoff+0x6e/0xa0\n rcu_read_unlock_special+0xb1/0x160\n unwind_next_frame+0x203/0x9b0\n __unwind_start+0x15d/0x1c0\n arch_stack_walk+0x62/0xf0\n stack_trace_save+0x48/0x70\n __ftrace_trace_stack.constprop.0+0x144/0x180\n trace_buffer_unlock_commit_regs+0x6d/0x220\n trace_event_buffer_commit+0x5c/0x260\n trace_event_raw_event_softirq+0x47/0x80\n raise_softirq_irqoff+0x6e/0xa0\n rcu_read_unlock_special+0xb1/0x160\n __is_insn_slot_addr+0x54/0x70\n kernel_text_address+0x48/0xc0\n __kernel_text_address+0xd/0x40\n unwind_get_return_address+0x1e/0x40\n arch_stack_walk+0x9c/0xf0\n stack_trace_save+0x48/0x70\n __ftrace_trace_stack.constprop.0+0x144/0x180\n trace_buffer_unlock_commit_regs+0x6d/0x220\n trace_event_buffer_commit+0x5c/0x260\n trace_event_raw_event_softirq+0x47/0x80\n __raise_softirq_irqoff+0x61/0x80\n __flush_smp_call_function_queue+0x115/0x420\n __sysvec_call_function_single+0x17/0xb0\n sysvec_call_function_single+0x8c/0xc0\n </IRQ>\n\nCommit b41642c87716 (\"rcu: Fix rcu_read_unlock() deadloop due to IRQ work\")\nfixed the infinite loop in rcu_read_unlock_special() for IRQ work by\nsetting a flag before calling irq_work_queue_on(). We fix this issue by\nsetting the same flag before calling raise_softirq_irqoff() and rename the\nflag to defer_qs_pending for more common.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45957","epss":0.00125,"percentile":0.02511,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45957","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45957","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45961","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gfs2: fix memory leaks in gfs2_fill_super error path  Fix two memory leaks in the gfs2_fill_super() error handling path when transitioning a filesystem to read-write mode fails.  First leak: kthread objects (thread_struct, task_struct, etc.) When gfs2_freeze_lock_shared() fails after init_threads() succeeds, the created kernel threads (logd and quotad) are never destroyed. This occurs because the fail_per_node label doesn't call gfs2_destroy_threads().  Second leak: quota bitmap buffer (8192 bytes) When gfs2_make_fs_rw() fails after gfs2_quota_init() succeeds but before other operations complete, the allocated quota bitmap is never freed.  The fix moves thread cleanup to the fail_per_node label to handle all error paths uniformly. gfs2_destroy_threads() is safe to call unconditionally as it checks for NULL pointers. Quota cleanup is added in gfs2_make_fs_rw() to properly handle the withdrawal case where quota initialization succeeds but the filesystem is then withdrawn.  Thread leak backtrace (gfs2_freeze_lock_shared failure):   unreferenced object 0xffff88801d7bca80 (size 4480):     copy_process+0x3a1/0x4670 kernel/fork.c:2422     kernel_clone+0xf3/0x6e0 kernel/fork.c:2779     kthread_create_on_node+0x100/0x150 kernel/kthread.c:478     init_threads+0xab/0x350 fs/gfs2/ops_fstype.c:611     gfs2_fill_super+0xe5c/0x1240 fs/gfs2/ops_fstype.c:1265  Quota leak backtrace (gfs2_make_fs_rw failure):   unreferenced object 0xffff88812de7c000 (size 8192):     gfs2_quota_init+0xe5/0x820 fs/gfs2/quota.c:1409     gfs2_make_fs_rw+0x7a/0xe0 fs/gfs2/super.c:149     gfs2_fill_super+0xfbb/0x1240 fs/gfs2/ops_fstype.c:1275","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45961","epss":0.00143,"percentile":0.0397,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45961","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07507500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-45961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45961","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/da6f5bbc2e7902f578b503f2a4c3d8d09ca4b102","https://git.kernel.org/stable/c/e54229ecf49add8451d5f765a32c86ab4446e06c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: fix memory leaks in gfs2_fill_super error path\n\nFix two memory leaks in the gfs2_fill_super() error handling path when\ntransitioning a filesystem to read-write mode fails.\n\nFirst leak: kthread objects (thread_struct, task_struct, etc.)\nWhen gfs2_freeze_lock_shared() fails after init_threads() succeeds, the\ncreated kernel threads (logd and quotad) are never destroyed. This\noccurs because the fail_per_node label doesn't call\ngfs2_destroy_threads().\n\nSecond leak: quota bitmap buffer (8192 bytes)\nWhen gfs2_make_fs_rw() fails after gfs2_quota_init() succeeds but\nbefore other operations complete, the allocated quota bitmap is never\nfreed.\n\nThe fix moves thread cleanup to the fail_per_node label to handle all\nerror paths uniformly. gfs2_destroy_threads() is safe to call\nunconditionally as it checks for NULL pointers. Quota cleanup is added\nin gfs2_make_fs_rw() to properly handle the withdrawal case where\nquota initialization succeeds but the filesystem is then withdrawn.\n\nThread leak backtrace (gfs2_freeze_lock_shared failure):\n  unreferenced object 0xffff88801d7bca80 (size 4480):\n    copy_process+0x3a1/0x4670 kernel/fork.c:2422\n    kernel_clone+0xf3/0x6e0 kernel/fork.c:2779\n    kthread_create_on_node+0x100/0x150 kernel/kthread.c:478\n    init_threads+0xab/0x350 fs/gfs2/ops_fstype.c:611\n    gfs2_fill_super+0xe5c/0x1240 fs/gfs2/ops_fstype.c:1265\n\nQuota leak backtrace (gfs2_make_fs_rw failure):\n  unreferenced object 0xffff88812de7c000 (size 8192):\n    gfs2_quota_init+0xe5/0x820 fs/gfs2/quota.c:1409\n    gfs2_make_fs_rw+0x7a/0xe0 fs/gfs2/super.c:149\n    gfs2_fill_super+0xfbb/0x1240 fs/gfs2/ops_fstype.c:1275","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45961","epss":0.00143,"percentile":0.0397,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45961","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45963","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45963","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: nau8821: Cancel delayed work on component remove  Attempting to unload the driver while a jack detection work is pending would likely crash the kernel when it is eventually scheduled for execution:  [ 1984.896308] BUG: unable to handle page fault for address: ffffffffc10c2a20 [...] [ 1984.896388] Hardware name: Valve Jupiter/Jupiter, BIOS F7A0131 01/30/2024 [ 1984.896396] Workqueue: events nau8821_jdet_work [snd_soc_nau8821] [ 1984.896414] RIP: 0010:__mutex_lock+0x9f/0x11d0 [...] [ 1984.896504] Call Trace: [ 1984.896511]  <TASK> [ 1984.896524]  ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896572]  ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896596]  snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core] [ 1984.896622]  nau8821_jdet_work+0xeb/0x1e0 [snd_soc_nau8821] [ 1984.896636]  process_one_work+0x211/0x590 [ 1984.896649]  ? srso_return_thunk+0x5/0x5f [ 1984.896670]  worker_thread+0x1cd/0x3a0  Cancel unscheduled jdet_work or wait for its execution to finish before the component driver gets removed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45963","epss":0.0013,"percentile":0.02966,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45963","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.06824999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-45963","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45963","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/13d20517bee1c9b69c7750026c61e7ec021080a4","https://git.kernel.org/stable/c/36fb28fa033f6544d81f1cc056b27d0c0bf26d4f","https://git.kernel.org/stable/c/3955767ec39dcc0358470ffe6535703e2b7fd815","https://git.kernel.org/stable/c/9210ae708ddead67f55610342ea03fe9d4de6005","https://git.kernel.org/stable/c/cd6b991de3e0b68560fe98dc739672747d2e4204","https://git.kernel.org/stable/c/dbd3fd05cddfdeec1e49b0a66269881c09eebd17"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: nau8821: Cancel delayed work on component remove\n\nAttempting to unload the driver while a jack detection work is pending\nwould likely crash the kernel when it is eventually scheduled for\nexecution:\n\n[ 1984.896308] BUG: unable to handle page fault for address: ffffffffc10c2a20\n[...]\n[ 1984.896388] Hardware name: Valve Jupiter/Jupiter, BIOS F7A0131 01/30/2024\n[ 1984.896396] Workqueue: events nau8821_jdet_work [snd_soc_nau8821]\n[ 1984.896414] RIP: 0010:__mutex_lock+0x9f/0x11d0\n[...]\n[ 1984.896504] Call Trace:\n[ 1984.896511]  <TASK>\n[ 1984.896524]  ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]\n[ 1984.896572]  ? snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]\n[ 1984.896596]  snd_soc_dapm_disable_pin+0x26/0x60 [snd_soc_core]\n[ 1984.896622]  nau8821_jdet_work+0xeb/0x1e0 [snd_soc_nau8821]\n[ 1984.896636]  process_one_work+0x211/0x590\n[ 1984.896649]  ? srso_return_thunk+0x5/0x5f\n[ 1984.896670]  worker_thread+0x1cd/0x3a0\n\nCancel unscheduled jdet_work or wait for its execution to finish before\nthe component driver gets removed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45963","epss":0.0013,"percentile":0.02966,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45963","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45963","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45981","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45981","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/cio: Fix device lifecycle handling in css_alloc_subchannel()  `css_alloc_subchannel()` calls `device_initialize()` before setting up the DMA masks. If `dma_set_coherent_mask()` or `dma_set_mask()` fails, the error path frees the subchannel structure directly, bypassing the device model reference counting.  Once `device_initialize()` has been called, the embedded struct device must be released via `put_device()`, allowing the release callback to free the container structure.  Fix the error path by dropping the initial device reference with `put_device()` instead of calling `kfree()` directly.  This ensures correct device lifetime handling and avoids potential use-after-free or double-free issues.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45981","epss":0.00126,"percentile":0.02624,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45981","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-45981","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45981","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6715560527e343a387e4a0d2e6c401748e89fa55","https://git.kernel.org/stable/c/abb6e07f46a740cda4f07d1b561ae4eaa7a1df42","https://git.kernel.org/stable/c/c35cfbb5341ba05ad1b4476ffc3c21cc3ff8f603","https://git.kernel.org/stable/c/f65c75b0b9b5a390bc3beadcde0a6fbc3ad118f7","https://git.kernel.org/stable/c/f96c5ccf95ae5f27218c1ce2d6a3ad2d3e105424"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/cio: Fix device lifecycle handling in css_alloc_subchannel()\n\n`css_alloc_subchannel()` calls `device_initialize()` before setting up\nthe DMA masks. If `dma_set_coherent_mask()` or `dma_set_mask()` fails,\nthe error path frees the subchannel structure directly, bypassing\nthe device model reference counting.\n\nOnce `device_initialize()` has been called, the embedded struct device\nmust be released via `put_device()`, allowing the release callback to\nfree the container structure.\n\nFix the error path by dropping the initial device reference with\n`put_device()` instead of calling `kfree()` directly.\n\nThis ensures correct device lifetime handling and avoids potential\nuse-after-free or double-free issues.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45981","epss":0.00126,"percentile":0.02624,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-45981","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45981","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45985","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45985","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O  When allocating blocks during within-EOF DIO and writeback with dioread_nolock enabled, EXT4_GET_BLOCKS_PRE_IO was set to split an existing large unwritten extent. However, EXT4_GET_BLOCKS_CONVERT was set when calling ext4_split_convert_extents(), which may potentially result in stale data issues.  Assume we have an unwritten extent, and then DIO writes the second half.     [UUUUUUUUUUUUUUUU] on-disk extent        U: unwritten extent    [UUUUUUUUUUUUUUUU] extent status tree             |<-   ->| ----> dio write this range  First, ext4_iomap_alloc() call ext4_map_blocks() with EXT4_GET_BLOCKS_PRE_IO, EXT4_GET_BLOCKS_UNWRIT_EXT and EXT4_GET_BLOCKS_CREATE flags set. ext4_map_blocks() find this extent and call ext4_split_convert_extents() with EXT4_GET_BLOCKS_CONVERT and the above flags set.  Then, ext4_split_convert_extents() calls ext4_split_extent() with EXT4_EXT_MAY_ZEROOUT, EXT4_EXT_MARK_UNWRIT2 and EXT4_EXT_DATA_VALID2 flags set, and it calls ext4_split_extent_at() to split the second half with EXT4_EXT_DATA_VALID2, EXT4_EXT_MARK_UNWRIT1, EXT4_EXT_MAY_ZEROOUT and EXT4_EXT_MARK_UNWRIT2 flags set. However, ext4_split_extent_at() failed to insert extent since a temporary lack -ENOSPC. It zeroes out the first half but convert the entire on-disk extent to written since the EXT4_EXT_DATA_VALID2 flag set, but left the second half as unwritten in the extent status tree.     [0000000000SSSSSS]  data                S: stale data, 0: zeroed    [WWWWWWWWWWWWWWWW]  on-disk extent      W: written extent    [WWWWWWWWWWUUUUUU]  extent status tree  Finally, if the DIO failed to write data to the disk, the stale data in the second half will be exposed once the cached extent entry is gone.  Fix this issue by not passing EXT4_GET_BLOCKS_CONVERT when splitting an unwritten extent before submitting I/O, and make ext4_split_convert_extents() to zero out the entire extent range to zero for this case, and also mark the extent in the extent status tree for consistency.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45985","epss":0.00123,"percentile":0.0235,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06457500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-45985","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45985","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2698731d25823267c29190cb578da9296a0c0d7b","https://git.kernel.org/stable/c/2920ec61c98b9476781359f05b94da84e80f54d4","https://git.kernel.org/stable/c/37555690f39f78ef69af347d9aff897e07445949","https://git.kernel.org/stable/c/67cdb7bd7442bd3cdc6d6088bbb2df9be2fe936c","https://git.kernel.org/stable/c/716e7439a5a9b18c3ff882c2f8c834b9ced1aaec","https://git.kernel.org/stable/c/77e407967cd872cd75d7e4a691908e49c8e6b4d4","https://git.kernel.org/stable/c/feaf2a80e78f89ee8a3464126077ba8683b62791"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O\n\nWhen allocating blocks during within-EOF DIO and writeback with\ndioread_nolock enabled, EXT4_GET_BLOCKS_PRE_IO was set to split an\nexisting large unwritten extent. However, EXT4_GET_BLOCKS_CONVERT was\nset when calling ext4_split_convert_extents(), which may potentially\nresult in stale data issues.\n\nAssume we have an unwritten extent, and then DIO writes the second half.\n\n   [UUUUUUUUUUUUUUUU] on-disk extent        U: unwritten extent\n   [UUUUUUUUUUUUUUUU] extent status tree\n            |<-   ->| ----> dio write this range\n\nFirst, ext4_iomap_alloc() call ext4_map_blocks() with\nEXT4_GET_BLOCKS_PRE_IO, EXT4_GET_BLOCKS_UNWRIT_EXT and\nEXT4_GET_BLOCKS_CREATE flags set. ext4_map_blocks() find this extent and\ncall ext4_split_convert_extents() with EXT4_GET_BLOCKS_CONVERT and the\nabove flags set.\n\nThen, ext4_split_convert_extents() calls ext4_split_extent() with\nEXT4_EXT_MAY_ZEROOUT, EXT4_EXT_MARK_UNWRIT2 and EXT4_EXT_DATA_VALID2\nflags set, and it calls ext4_split_extent_at() to split the second half\nwith EXT4_EXT_DATA_VALID2, EXT4_EXT_MARK_UNWRIT1, EXT4_EXT_MAY_ZEROOUT\nand EXT4_EXT_MARK_UNWRIT2 flags set. However, ext4_split_extent_at()\nfailed to insert extent since a temporary lack -ENOSPC. It zeroes out\nthe first half but convert the entire on-disk extent to written since\nthe EXT4_EXT_DATA_VALID2 flag set, but left the second half as unwritten\nin the extent status tree.\n\n   [0000000000SSSSSS]  data                S: stale data, 0: zeroed\n   [WWWWWWWWWWWWWWWW]  on-disk extent      W: written extent\n   [WWWWWWWWWWUUUUUU]  extent status tree\n\nFinally, if the DIO failed to write data to the disk, the stale data in\nthe second half will be exposed once the cached extent entry is gone.\n\nFix this issue by not passing EXT4_GET_BLOCKS_CONVERT when splitting\nan unwritten extent before submitting I/O, and make\next4_split_convert_extents() to zero out the entire extent range\nto zero for this case, and also mark the extent in the extent status\ntree for consistency.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45985","epss":0.00123,"percentile":0.0235,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45985","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45988","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45988","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix re-decryption of RESPONSE packets  If a RESPONSE packet gets a temporary failure during processing, it may end up in a partially decrypted state - and then get requeued for a retry.  Fix this by just discarding the packet; we will send another CHALLENGE packet and thereby elicit a further response.  Similarly, discard an incoming CHALLENGE packet if we get an error whilst generating a RESPONSE; the server will send another CHALLENGE.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45988","epss":0.00457,"percentile":0.3836,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.4295800000000001},"relatedVulnerabilities":[{"id":"CVE-2026-45988","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45988","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0422e7a4883f25101903f3e8105c0808aa5f4ce9","https://git.kernel.org/stable/c/76cb9a2d252274adfae6e293a292434631a7d472","https://git.kernel.org/stable/c/7b89868305052b94a91b708c462bc2281fa42a4a","https://git.kernel.org/stable/c/d61482be4aae1835b78875761206241835a7510e","https://git.kernel.org/stable/c/f55b383070170e988e4dec28be2af1714d258521"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix re-decryption of RESPONSE packets\n\nIf a RESPONSE packet gets a temporary failure during processing, it may end\nup in a partially decrypted state - and then get requeued for a retry.\n\nFix this by just discarding the packet; we will send another CHALLENGE\npacket and thereby elicit a further response.  Similarly, discard an\nincoming CHALLENGE packet if we get an error whilst generating a RESPONSE;\nthe server will send another CHALLENGE.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45988","epss":0.00457,"percentile":0.3836,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45988","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-45993","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45993","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Add spectre boundry for syscall dispatch table  The LoongArch syscall number is directly controlled by userspace, but does not have a array_index_nospec() boundry to prevent access past the syscall function pointer tables.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45993","epss":0.00142,"percentile":0.03821,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.07455},"relatedVulnerabilities":[{"id":"CVE-2026-45993","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45993","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/07040904ad217545be096d4280ed33c02f6a3750","https://git.kernel.org/stable/c/0c965d2784fbbd7f8e3b96d875c9cfdf7c00da3d","https://git.kernel.org/stable/c/108f2cd13577a410c0ad6ea00708596d9d0dfc90","https://git.kernel.org/stable/c/85cbf7fb568af5358aae61925c4e66b8f5e1439d","https://git.kernel.org/stable/c/bc84a109c2082dd0c4b38e8d923c046b41977533","https://git.kernel.org/stable/c/c8a8e863928424046b8fd328f02c359baa0a0c3f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Add spectre boundry for syscall dispatch table\n\nThe LoongArch syscall number is directly controlled by userspace, but\ndoes not have a array_index_nospec() boundry to prevent access past the\nsyscall function pointer tables.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-45993","epss":0.00142,"percentile":0.03821,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-45993","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46000","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46000","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix conn-level packet handling to unshare RESPONSE packets  The security operations that verify the RESPONSE packets decrypt bits of it in place - however, the sk_buff may be shared with a packet sniffer, which would lead to the sniffer seeing an apparently corrupt packet (actually decrypted).  Fix this by handing a copy of the packet off to the specific security handler if the packet was cloned.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46000","epss":0.00159,"percentile":0.05407,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08347500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46000","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46000","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/24481a7f573305706054c59e275371f8d0fe919f","https://git.kernel.org/stable/c/98a2046d155f73f6cf5d2c493c5e09b4963e2e12","https://git.kernel.org/stable/c/c0428a22daf69714dc042b67ea759956b74c74e5","https://git.kernel.org/stable/c/ca71ac2de389b01eecdc48bfafbdf073ec232044","https://git.kernel.org/stable/c/d9b93a0f57ca5f6831bfaa34014b6cd705564a00"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix conn-level packet handling to unshare RESPONSE packets\n\nThe security operations that verify the RESPONSE packets decrypt bits of it\nin place - however, the sk_buff may be shared with a packet sniffer, which\nwould lead to the sniffer seeing an apparently corrupt packet (actually\ndecrypted).\n\nFix this by handing a copy of the packet off to the specific security\nhandler if the packet was cloned.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46000","epss":0.00159,"percentile":0.05407,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46000","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46012","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46012","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix memory leaks in rxkad_verify_response()  Fix rxkad_verify_response() to free the ticket and the server key under all circumstances by initialising the ticket pointer to NULL and then making all paths through the function after the first allocation has been done go through a single common epilogue that just releases everything - where all the releases skip on a NULL pointer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46012","epss":0.00122,"percentile":0.02266,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46012","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-46012","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46012","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/34f61a07e0cdefaecd3ec03bb5fb22215643678f","https://git.kernel.org/stable/c/852b9d64cea421336579b2de3d1338dfa677e2dd","https://git.kernel.org/stable/c/861b9a0a1823bf064a7b810d29502a9ef043f40f","https://git.kernel.org/stable/c/c4b8f32e73eafd4a5076be890c7c8506ec04567c","https://git.kernel.org/stable/c/c91f33fb8356dedc82bc56ce210f1a5dbee62a52"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix memory leaks in rxkad_verify_response()\n\nFix rxkad_verify_response() to free the ticket and the server key under all\ncircumstances by initialising the ticket pointer to NULL and then making\nall paths through the function after the first allocation has been done go\nthrough a single common epilogue that just releases everything - where all\nthe releases skip on a NULL pointer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46012","epss":0.00122,"percentile":0.02266,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46012","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46012","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46014","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46014","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: SVM: Add missing save/restore handling of LBR MSRs  MSR_IA32_DEBUGCTLMSR and LBR MSRs are currently not enumerated by KVM_GET_MSR_INDEX_LIST, and LBR MSRs cannot be set with KVM_SET_MSRS. So save/restore is completely broken.  Fix it by adding the MSRs to msrs_to_save_base, and allowing writes to LBR MSRs from userspace only (as they are read-only MSRs) if LBR virtualization is enabled.  Additionally, to correctly restore L1's LBRs while L2 is running, make sure the LBRs are copied from the captured VMCB01 save area in svm_copy_vmrun_state().  Note, for VMX, this also fixes a flaw where MSR_IA32_DEBUGCTLMSR isn't reported as an MSR to save/restore.  Note #2, over-reporting MSR_IA32_LASTxxx on Intel is ok, as KVM already handles unsupported reads and writes thanks to commit b5e2fec0ebc3 (\"KVM: Ignore DEBUGCTL MSRs with no effect\") (kvm_do_msr_access() will morph the unsupported userspace write into a nop).  [sean: guard with lbrv checks, massage changelog]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46014","epss":0.00093,"percentile":0.00628,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46014","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.048825},"relatedVulnerabilities":[{"id":"CVE-2026-46014","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46014","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/13a89ada5dcfc2539514c83ba5a2c61157f1ec6c","https://git.kernel.org/stable/c/2b922a42b531a82d7881add14a7698dcdc5e1f0a","https://git.kernel.org/stable/c/3700f0788da6acf73b2df56690f4b201aa4aefd2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Add missing save/restore handling of LBR MSRs\n\nMSR_IA32_DEBUGCTLMSR and LBR MSRs are currently not enumerated by\nKVM_GET_MSR_INDEX_LIST, and LBR MSRs cannot be set with KVM_SET_MSRS. So\nsave/restore is completely broken.\n\nFix it by adding the MSRs to msrs_to_save_base, and allowing writes to\nLBR MSRs from userspace only (as they are read-only MSRs) if LBR\nvirtualization is enabled.  Additionally, to correctly restore L1's LBRs\nwhile L2 is running, make sure the LBRs are copied from the captured\nVMCB01 save area in svm_copy_vmrun_state().\n\nNote, for VMX, this also fixes a flaw where MSR_IA32_DEBUGCTLMSR isn't\nreported as an MSR to save/restore.\n\nNote #2, over-reporting MSR_IA32_LASTxxx on Intel is ok, as KVM already\nhandles unsupported reads and writes thanks to commit b5e2fec0ebc3 (\"KVM:\nIgnore DEBUGCTL MSRs with no effect\") (kvm_do_msr_access() will morph the\nunsupported userspace write into a nop).\n\n[sean: guard with lbrv checks, massage changelog]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46014","epss":0.00093,"percentile":0.00628,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46014","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46014","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46017","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm: fix deferred split queue races during migration  migrate_folio_move() records the deferred split queue state from src and replays it on dst.  Replaying it after remove_migration_ptes(src, dst, 0) makes dst visible before it is requeued, so a concurrent rmap-removal path can mark dst partially mapped and trip the WARN in deferred_split_folio().  Move the requeue before remove_migration_ptes() so dst is back on the deferred split queue before it becomes visible again.  Because migration still holds dst locked at that point, teach deferred_split_scan() to requeue a folio when folio_trylock() fails.  Otherwise a fully mapped underused folio can be dequeued by the shrinker and silently lost from split_queue.  [ziy@nvidia.com: move the comment]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46017","epss":0.00105,"percentile":0.01153,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46017","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.05092499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-46017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46017","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3bac01168982ec3e3bf87efdc1807c7933590a85","https://git.kernel.org/stable/c/cbf75cf212ee6e499abc1757fb4b5ae6d70ed0aa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix deferred split queue races during migration\n\nmigrate_folio_move() records the deferred split queue state from src and\nreplays it on dst.  Replaying it after remove_migration_ptes(src, dst, 0)\nmakes dst visible before it is requeued, so a concurrent rmap-removal path\ncan mark dst partially mapped and trip the WARN in deferred_split_folio().\n\nMove the requeue before remove_migration_ptes() so dst is back on the\ndeferred split queue before it becomes visible again.\n\nBecause migration still holds dst locked at that point, teach\ndeferred_split_scan() to requeue a folio when folio_trylock() fails. \nOtherwise a fully mapped underused folio can be dequeued by the shrinker\nand silently lost from split_queue.\n\n[ziy@nvidia.com: move the comment]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46017","epss":0.00105,"percentile":0.01153,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46017","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46032","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46032","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT  If loading L1's CR3 fails on a nested #VMEXIT, nested_svm_vmexit() returns an error code that is ignored by most callers, and continues to run L1 with corrupted state. A sane recovery is not possible in this case, and HW behavior is to cause a shutdown. Inject a triple fault instead, and do not return early from nested_svm_vmexit(). Continue cleaning up the vCPU state (e.g. clear pending exceptions), to handle the failure as gracefully as possible.  From the APM:    Upon #VMEXIT, the processor performs the following actions in order to   return to the host execution context:    ...    if (illegal host state loaded, or exception while loading host state)       shutdown   else       execute first host instruction following the VMRUN  Remove the return value of nested_svm_vmexit(), which is mostly unchecked anyway.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46032","epss":0.00116,"percentile":0.01795,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0609},"relatedVulnerabilities":[{"id":"CVE-2026-46032","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46032","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5d291ef0585ed880ed4dd71ea1a5965e0a65fb53","https://git.kernel.org/stable/c/9a738cf170a4a2332ea3a15e23ec65b5757fe4a1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT\n\nIf loading L1's CR3 fails on a nested #VMEXIT, nested_svm_vmexit()\nreturns an error code that is ignored by most callers, and continues to\nrun L1 with corrupted state. A sane recovery is not possible in this\ncase, and HW behavior is to cause a shutdown. Inject a triple fault\ninstead, and do not return early from nested_svm_vmexit(). Continue\ncleaning up the vCPU state (e.g. clear pending exceptions), to handle\nthe failure as gracefully as possible.\n\nFrom the APM:\n\n  Upon #VMEXIT, the processor performs the following actions in order to\n  return to the host execution context:\n\n  ...\n\n  if (illegal host state loaded, or exception while loading host state)\n      shutdown\n  else\n      execute first host instruction following the VMRUN\n\nRemove the return value of nested_svm_vmexit(), which is mostly\nunchecked anyway.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46032","epss":0.00116,"percentile":0.01795,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46032","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46054","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46054","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: fix overlayfs mmap() and mprotect() access checks  The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the \"user\" file) and the mounter's credentials are sufficient to access the lower level file (the \"backing\" file).  Unfortunately, the current code does not properly enforce these access controls for both mmap() and mprotect() operations on overlayfs filesystems.  This patch makes use of the newly created security_mmap_backing_file() LSM hook to provide the missing backing file enforcement for mmap() operations, and leverages the backing file API and new LSM blob to provide the necessary information to properly enforce the mprotect() access controls.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46054","epss":0.00123,"percentile":0.02382,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46054","cwe":"CWE-280","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08917499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-46054","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46054","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/82544d36b1729153c8aeb179e84750f0c085d3b1","https://git.kernel.org/stable/c/8bacd09f12c27710228562e4d13163e58c5f4a45","https://git.kernel.org/stable/c/bc6c380c1159de52a252ed11f19a42c47f60a735","https://git.kernel.org/stable/c/cd0e707a927a70cdfd8bc5a512a9719a87f5ed51","https://git.kernel.org/stable/c/d844702198395d3f80222777030f69db6be6b709","https://access.redhat.com/errata/RHSA-2026:25191","https://access.redhat.com/errata/RHSA-2026:27811","https://access.redhat.com/errata/RHSA-2026:27812","https://access.redhat.com/errata/RHSA-2026:30848","https://access.redhat.com/errata/RHSA-2026:51746","https://access.redhat.com/errata/RHSA-2026:52649","https://access.redhat.com/errata/RHSA-2026:52667","https://access.redhat.com/errata/RHSA-2026:52764","https://access.redhat.com/errata/RHSA-2026:59091","https://access.redhat.com/errata/RHSA-2026:59473","https://access.redhat.com/security/cve/CVE-2026-46054","https://bugzilla.redhat.com/show_bug.cgi?id=2482025","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46054.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: fix overlayfs mmap() and mprotect() access checks\n\nThe existing SELinux security model for overlayfs is to allow access if\nthe current task is able to access the top level file (the \"user\" file)\nand the mounter's credentials are sufficient to access the lower\nlevel file (the \"backing\" file).  Unfortunately, the current code does\nnot properly enforce these access controls for both mmap() and mprotect()\noperations on overlayfs filesystems.\n\nThis patch makes use of the newly created security_mmap_backing_file()\nLSM hook to provide the missing backing file enforcement for mmap()\noperations, and leverages the backing file API and new LSM blob to\nprovide the necessary information to properly enforce the mprotect()\naccess controls.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46054","epss":0.00123,"percentile":0.02382,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46054","cwe":"CWE-280","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46054","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46059","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46059","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN  For guests with NRIPS disabled, L1 does not provide NextRIP when running an L2 with an injected soft interrupt, instead it advances the current RIP before running it. KVM uses the current RIP as the NextRIP in vmcb02 to emulate a CPU without NRIPS.  However, after L2 runs the first time, NextRIP will be updated by the CPU and/or KVM, and the current RIP is no longer the correct value to use in vmcb02.  Hence, after save/restore, use the current RIP if and only if a nested run is pending, otherwise use NextRIP.  Give soft_int_next_rip the same treatment, as it's the same logic, just for a narrower use case.  [sean: give soft_int_next_rip the same treatment]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46059","epss":0.00121,"percentile":0.02147,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-46059","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46059","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3428ed1529a1af4cce5aff6c5bd2fcc39ad726bb","https://git.kernel.org/stable/c/69fe1411a5ce678b4da6489b5d2282b4e1d13acf","https://git.kernel.org/stable/c/8d397582f6b5e9fbcf09781c7c934b4910e94a50"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN\n\nFor guests with NRIPS disabled, L1 does not provide NextRIP when running\nan L2 with an injected soft interrupt, instead it advances the current RIP\nbefore running it. KVM uses the current RIP as the NextRIP in vmcb02 to\nemulate a CPU without NRIPS.\n\nHowever, after L2 runs the first time, NextRIP will be updated by the CPU\nand/or KVM, and the current RIP is no longer the correct value to use in\nvmcb02.  Hence, after save/restore, use the current RIP if and only if a\nnested run is pending, otherwise use NextRIP.  Give soft_int_next_rip the\nsame treatment, as it's the same logic, just for a narrower use case.\n\n[sean: give soft_int_next_rip the same treatment]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46059","epss":0.00121,"percentile":0.02147,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46059","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46068","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46068","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx  The bounce buffers are allocated with __get_free_pages() using BOUNCE_BUFFER_ORDER (order 2 = 4 pages), but both the allocation error path and nx842_crypto_free_ctx() release the buffers with free_page(). Use free_pages() with the matching order instead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46068","epss":0.00129,"percentile":0.02826,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46068","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46068","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46068","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5c07962fed66e1238fad7635fa150570bd38b4c5","https://git.kernel.org/stable/c/80fd99d7c30ea889662d21f1b44d8fea4c83138d","https://git.kernel.org/stable/c/910bb34b801d39794e656f7d48414844b2bd354e","https://git.kernel.org/stable/c/adb3faf2db1a66d0f015b44ac909a32dfc7f2f9c","https://git.kernel.org/stable/c/f17a4850d1ce7c11cba8b1830b9bfedfede878bb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx\n\nThe bounce buffers are allocated with __get_free_pages() using\nBOUNCE_BUFFER_ORDER (order 2 = 4 pages), but both the allocation error\npath and nx842_crypto_free_ctx() release the buffers with free_page().\nUse free_pages() with the matching order instead.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46068","epss":0.00129,"percentile":0.02826,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46068","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46068","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46071","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46071","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12  svm_copy_lbrs() always marks VMCB_LBR dirty in the destination VMCB. However, nested_svm_vmexit() uses it to copy LBRs to vmcb12, and clearing clean bits in vmcb12 is not architecturally defined.  Move vmcb_mark_dirty() to callers and drop it for vmcb12.  This also facilitates incoming refactoring that does not pass the entire VMCB to svm_copy_lbrs().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46071","epss":0.00121,"percentile":0.02158,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-46071","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46071","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/9efe23568806d1cd06f7d146f9b3037b8d585a9f","https://git.kernel.org/stable/c/a3f0981a5a0e0bd51ad74cc7d9eed32294b24002","https://git.kernel.org/stable/c/b53ab5167a81537777ac780bbd93d32613aa3bda"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Avoid clearing VMCB_LBR in vmcb12\n\nsvm_copy_lbrs() always marks VMCB_LBR dirty in the destination VMCB.\nHowever, nested_svm_vmexit() uses it to copy LBRs to vmcb12, and\nclearing clean bits in vmcb12 is not architecturally defined.\n\nMove vmcb_mark_dirty() to callers and drop it for vmcb12.\n\nThis also facilitates incoming refactoring that does not pass the entire\nVMCB to svm_copy_lbrs().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46071","epss":0.00121,"percentile":0.02158,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46071","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46090","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46090","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: aloop: Fix peer runtime UAF during format-change stop  loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 (\"ALSA: aloop: Fix racy access at PCM trigger\") moved the peer lookup under cable->lock, but the actual snd_pcm_stop() still runs after dropping that lock.  A concurrent close can clear the capture entry from cable->streams[] and detach or free its runtime while the playback trigger path still holds a stale peer substream pointer.  Keep a per-cable count of in-flight peer stops before dropping cable->lock, and make free_cable() wait for those stops before detaching the runtime. This preserves the existing behavior while making the peer runtime lifetime explicit.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46090","epss":0.00103,"percentile":0.01084,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46090","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-46090","cwe":"CWE-364","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.074675},"relatedVulnerabilities":[{"id":"CVE-2026-46090","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46090","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/03f52a9c170431e8f10e156b9dc0dae80b3e9198","https://git.kernel.org/stable/c/345c24b2bcf0923dfae1ab41497351c68214ff76","https://git.kernel.org/stable/c/5d45e34bf001344e2966dabca1897561bbc9e913","https://git.kernel.org/stable/c/83bd62fa9620ac98d5d694bde14c50f98c8e7189","https://git.kernel.org/stable/c/bdd9503c3d222d2735b56c7a8b4422ccf3de6e5c","https://git.kernel.org/stable/c/e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff","https://access.redhat.com/errata/RHSA-2026:27353","https://access.redhat.com/errata/RHSA-2026:27354","https://access.redhat.com/errata/RHSA-2026:30848","https://access.redhat.com/errata/RHSA-2026:33215","https://access.redhat.com/errata/RHSA-2026:33685","https://access.redhat.com/errata/RHSA-2026:33899","https://access.redhat.com/errata/RHSA-2026:33900","https://access.redhat.com/errata/RHSA-2026:34094","https://access.redhat.com/errata/RHSA-2026:34095","https://access.redhat.com/errata/RHSA-2026:34443","https://access.redhat.com/errata/RHSA-2026:35844","https://access.redhat.com/errata/RHSA-2026:35863","https://access.redhat.com/errata/RHSA-2026:35896","https://access.redhat.com/errata/RHSA-2026:41236","https://access.redhat.com/security/cve/CVE-2026-46090","https://bugzilla.redhat.com/show_bug.cgi?id=2481980","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46090.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Fix peer runtime UAF during format-change stop\n\nloopback_check_format() may stop the capture side when playback starts\nwith parameters that no longer match a running capture stream. Commit\n826af7fa62e3 (\"ALSA: aloop: Fix racy access at PCM trigger\") moved\nthe peer lookup under cable->lock, but the actual snd_pcm_stop() still\nruns after dropping that lock.\n\nA concurrent close can clear the capture entry from cable->streams[] and\ndetach or free its runtime while the playback trigger path still holds a\nstale peer substream pointer.\n\nKeep a per-cable count of in-flight peer stops before dropping\ncable->lock, and make free_cable() wait for those stops before\ndetaching the runtime. This preserves the existing behavior while\nmaking the peer runtime lifetime explicit.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46090","epss":0.00103,"percentile":0.01084,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46090","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-46090","cwe":"CWE-364","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46090","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46111","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46111","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_conn: fix potential UAF in create_big_sync  Add hci_conn_valid() check in create_big_sync() to detect stale connections before proceeding with BIG creation. Handle the resulting -ECANCELED in create_big_complete() and re-validate the connection under hci_dev_lock() before dereferencing, matching the pattern used by create_le_conn_complete() and create_pa_complete().  Keep the hci_conn object alive across the async boundary by taking a reference via hci_conn_get() when queueing create_big_sync(), and dropping it in the completion callback. The refcount and the lock are complementary: the refcount keeps the object allocated, while hci_dev_lock() serializes hci_conn_hash_del()'s list_del_rcu() on hdev->conn_hash, as required by hci_conn_del().  hci_conn_put() is called outside hci_dev_unlock() so the final put (which resolves to kfree() via bt_link_release) does not run under hdev->lock, though the release path would be safe either way.  Without this, create_big_complete() would unconditionally dereference the conn pointer on error, causing a use-after-free via hci_connect_cfm() and hci_conn_del().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46111","epss":0.00126,"percentile":0.02571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46111","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-46111","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46111","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0beddb0c380bed5f5b8e61ddbe14635bb73d0b41","https://git.kernel.org/stable/c/1750a2df0eab61dc421a7afae74abdd239a44b85","https://git.kernel.org/stable/c/6823f730bf195fc296d9edd09e2ca94bc1ff5584","https://git.kernel.org/stable/c/d41093723e47255d7d74df86e2736711c1b8486e","https://git.kernel.org/stable/c/dc34f8d8240f25dd137dc2758ebbcc75e3779142","https://git.kernel.org/stable/c/f8eaf92c57ad99358dd372580d5ff87623343a72"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: fix potential UAF in create_big_sync\n\nAdd hci_conn_valid() check in create_big_sync() to detect stale\nconnections before proceeding with BIG creation. Handle the\nresulting -ECANCELED in create_big_complete() and re-validate the\nconnection under hci_dev_lock() before dereferencing, matching the\npattern used by create_le_conn_complete() and create_pa_complete().\n\nKeep the hci_conn object alive across the async boundary by taking\na reference via hci_conn_get() when queueing create_big_sync(), and\ndropping it in the completion callback. The refcount and the lock\nare complementary: the refcount keeps the object allocated, while\nhci_dev_lock() serializes hci_conn_hash_del()'s list_del_rcu() on\nhdev->conn_hash, as required by hci_conn_del().\n\nhci_conn_put() is called outside hci_dev_unlock() so the final put\n(which resolves to kfree() via bt_link_release) does not run under\nhdev->lock, though the release path would be safe either way.\n\nWithout this, create_big_complete() would unconditionally\ndereference the conn pointer on error, causing a use-after-free\nvia hci_connect_cfm() and hci_conn_del().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46111","epss":0.00126,"percentile":0.02571,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46111","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46111","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46130","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46130","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm-verity-fec: fix reading parity bytes split across blocks (take 3)  fec_decode_bufs() assumes that the parity bytes of the first RS codeword it decodes are never split across parity blocks.  This assumption is false.  Consider v->fec->block_size == 4096 && v->fec->roots == 17 && fio->nbufs == 1, for example.  In that case, each call to fec_decode_bufs() consumes v->fec->roots * (fio->nbufs << DM_VERITY_FEC_BUF_RS_BITS) = 272 parity bytes.  Considering that the parity data for each message block starts on a block boundary, the byte alignment in the parity data will iterate through 272*i mod 4096 until the 3 parity blocks have been consumed.  On the 16th call (i=15), the alignment will be 4080 bytes into the first block.  Only 16 bytes remain in that block, but 17 parity bytes will be needed.  The code reads out-of-bounds from the parity block buffer.  Fortunately this doesn't normally happen, since it can occur only for certain non-default values of fec_roots *and* when the maximum number of buffers couldn't be allocated due to low memory.  For example with block_size=4096 only the following cases are affected:      fec_roots=17: nbufs in [1, 3, 5, 15]     fec_roots=19: nbufs in [1, 229]     fec_roots=21: nbufs in [1, 3, 5, 13, 15, 39, 65, 195]     fec_roots=23: nbufs in [1, 89]  Regardless, fix it by refactoring how the parity blocks are read.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46130","epss":0.00124,"percentile":0.02424,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46130","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09052},"relatedVulnerabilities":[{"id":"CVE-2026-46130","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46130","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3d1b4e2d8ac0a1a1390a117f61ce0ca1c47e3bcb","https://git.kernel.org/stable/c/430a05cb926f6bdf53e81460a2c3a553257f3f61","https://git.kernel.org/stable/c/d47281b9a4472cfd73122393e79fbe76b651e46a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity-fec: fix reading parity bytes split across blocks (take 3)\n\nfec_decode_bufs() assumes that the parity bytes of the first RS codeword\nit decodes are never split across parity blocks.\n\nThis assumption is false.  Consider v->fec->block_size == 4096 &&\nv->fec->roots == 17 && fio->nbufs == 1, for example.  In that case, each\ncall to fec_decode_bufs() consumes v->fec->roots * (fio->nbufs <<\nDM_VERITY_FEC_BUF_RS_BITS) = 272 parity bytes.\n\nConsidering that the parity data for each message block starts on a\nblock boundary, the byte alignment in the parity data will iterate\nthrough 272*i mod 4096 until the 3 parity blocks have been consumed.  On\nthe 16th call (i=15), the alignment will be 4080 bytes into the first\nblock.  Only 16 bytes remain in that block, but 17 parity bytes will be\nneeded.  The code reads out-of-bounds from the parity block buffer.\n\nFortunately this doesn't normally happen, since it can occur only for\ncertain non-default values of fec_roots *and* when the maximum number of\nbuffers couldn't be allocated due to low memory.  For example with\nblock_size=4096 only the following cases are affected:\n\n    fec_roots=17: nbufs in [1, 3, 5, 15]\n    fec_roots=19: nbufs in [1, 229]\n    fec_roots=21: nbufs in [1, 3, 5, 13, 15, 39, 65, 195]\n    fec_roots=23: nbufs in [1, 89]\n\nRegardless, fix it by refactoring how the parity blocks are read.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46130","epss":0.00124,"percentile":0.02424,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46130","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46130","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46147","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()  Two bugs exist in the vCPU initialisation path:  1. If a check fails after hyp_pin_shared_mem() succeeds, the cleanup    path jumps to 'unlock' without calling unpin_host_vcpu() or    unpin_host_sve_state(), permanently leaking pin references on the    host vCPU and SVE state pages.     Extract a register_hyp_vcpu() helper that performs the checks and    the store. When register_hyp_vcpu() returns an error, call    unpin_host_vcpu() and unpin_host_sve_state() inline before falling    through to the existing 'unlock' label.  2. register_hyp_vcpu() publishes the new vCPU pointer into    'hyp_vm->vcpus[]' with a bare store, allowing a concurrent caller    of pkvm_load_hyp_vcpu() to observe a partially initialised vCPU    object.     Ensure the store uses smp_store_release() and the load uses    smp_load_acquire(). While 'vm_table_lock' currently serialises the    store and the load, these barriers ensure the reader sees the fully    initialised 'hyp_vcpu' object even if there were a lockless path or    if the lock's own ordering guarantees were insufficient for nested    object initialization.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46147","epss":0.00126,"percentile":0.02614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46147","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06615000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46147","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6d69c0ed978f7f0efd053fc98390f25ab77c1aea","https://git.kernel.org/stable/c/73b9c1e5da84cd69b1a86e374e450817cd051371","https://git.kernel.org/stable/c/7d3c27b54253cda91dc4d2c1bfc109c490837ab9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()\n\nTwo bugs exist in the vCPU initialisation path:\n\n1. If a check fails after hyp_pin_shared_mem() succeeds, the cleanup\n   path jumps to 'unlock' without calling unpin_host_vcpu() or\n   unpin_host_sve_state(), permanently leaking pin references on the\n   host vCPU and SVE state pages.\n\n   Extract a register_hyp_vcpu() helper that performs the checks and\n   the store. When register_hyp_vcpu() returns an error, call\n   unpin_host_vcpu() and unpin_host_sve_state() inline before falling\n   through to the existing 'unlock' label.\n\n2. register_hyp_vcpu() publishes the new vCPU pointer into\n   'hyp_vm->vcpus[]' with a bare store, allowing a concurrent caller\n   of pkvm_load_hyp_vcpu() to observe a partially initialised vCPU\n   object.\n\n   Ensure the store uses smp_store_release() and the load uses\n   smp_load_acquire(). While 'vm_table_lock' currently serialises the\n   store and the load, these barriers ensure the reader sees the fully\n   initialised 'hyp_vcpu' object even if there were a lockless path or\n   if the lock's own ordering guarantees were insufficient for nested\n   object initialization.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46147","epss":0.00126,"percentile":0.02614,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46147","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46148","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: microchip-core-qspi: control built-in cs manually  The coreQSPI IP supports only a single chip select, which is automagically operated by the hardware - set low when the transmit buffer first gets written to and set high when the number of bytes written to the TOTALBYTES field of the FRAMES register have been sent on the bus. Additional devices must use GPIOs for their chip selects. It was reported to me that if there are two devices attached to this QSPI controller that the in-built chip select is set low while linux tries to access the device attached to the GPIO.  This went undetected as the boards that connected multiple devices to the SPI controller all exclusively used GPIOs for chip selects, not relying on the built-in chip select at all. It turns out that this was because the built-in chip select, when controlled automagically, is set low when active and high when inactive, thereby ruling out its use for active-high devices or devices that need to transmit with the chip select disabled.  Modify the driver so that it controls chip select directly, retaining the behaviour for mem_ops of setting the chip select active for the entire duration of the transfer in the exec_op callback. For regular transfers, implement the set_cs callback for the core to use.  As part of this, the existing setup callback, mchp_coreqspi_setup_op(), is removed. Modifying the CLKIDLE field is not safe to do during operation when there are multiple devices, so this code is removed entirely. Setting the MASTER and ENABLE fields is something that can be done once at probe, it doesn't need to be re-run for each device. Instead the new setup callback sets the built-in chip select to its inactive state for active-low devices, as the reset value of the chip select in software controlled mode is low.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46148","epss":0.00121,"percentile":0.02123,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-46148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46148","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7672749e1496215e8683ce57cf323119033954cf","https://git.kernel.org/stable/c/998f43196d732f20f9b71eb6ebd973736c9fa911","https://git.kernel.org/stable/c/ee3c99aa102212ad59dc2c19595515c4a6729307"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: microchip-core-qspi: control built-in cs manually\n\nThe coreQSPI IP supports only a single chip select, which is\nautomagically operated by the hardware - set low when the transmit\nbuffer first gets written to and set high when the number of bytes\nwritten to the TOTALBYTES field of the FRAMES register have been sent on\nthe bus. Additional devices must use GPIOs for their chip selects.\nIt was reported to me that if there are two devices attached to this\nQSPI controller that the in-built chip select is set low while linux\ntries to access the device attached to the GPIO.\n\nThis went undetected as the boards that connected multiple devices to\nthe SPI controller all exclusively used GPIOs for chip selects, not\nrelying on the built-in chip select at all. It turns out that this was\nbecause the built-in chip select, when controlled automagically, is set\nlow when active and high when inactive, thereby ruling out its use for\nactive-high devices or devices that need to transmit with the chip\nselect disabled.\n\nModify the driver so that it controls chip select directly, retaining\nthe behaviour for mem_ops of setting the chip select active for the\nentire duration of the transfer in the exec_op callback. For regular\ntransfers, implement the set_cs callback for the core to use.\n\nAs part of this, the existing setup callback, mchp_coreqspi_setup_op(),\nis removed. Modifying the CLKIDLE field is not safe to do during\noperation when there are multiple devices, so this code is removed\nentirely. Setting the MASTER and ENABLE fields is something that can be\ndone once at probe, it doesn't need to be re-run for each device.\nInstead the new setup callback sets the built-in chip select to its\ninactive state for active-low devices, as the reset value of the chip\nselect in software controlled mode is low.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46148","epss":0.00121,"percentile":0.02123,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46148","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46153","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  8021q: delete cleared egress QoS mappings  vlan_dev_set_egress_priority() currently keeps cleared egress priority mappings in the hash as tombstones. Repeated set/clear cycles with distinct skb priorities therefore accumulate mapping nodes until device teardown and leak memory.  Delete mappings when vlan_prio is cleared instead of keeping tombstones. Now that the egress mapping lists are RCU protected, the node can be unlinked safely and freed after a grace period.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46153","epss":0.00112,"percentile":0.01516,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-46153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46153","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7dddc74af369478ba7f9bc136d0fc1dc4570cb66","https://git.kernel.org/stable/c/a52e122c9e4d56ad9a03b32c915a199276d989c3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\n8021q: delete cleared egress QoS mappings\n\nvlan_dev_set_egress_priority() currently keeps cleared egress\npriority mappings in the hash as tombstones. Repeated set/clear cycles\nwith distinct skb priorities therefore accumulate mapping nodes until\ndevice teardown and leak memory.\n\nDelete mappings when vlan_prio is cleared instead of keeping tombstones.\nNow that the egress mapping lists are RCU protected, the node can be\nunlinked safely and freed after a grace period.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46153","epss":0.00112,"percentile":0.01516,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46153","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46156","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46156","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()  The switch case in loongson_gpu_fixup_dma_hang() may not DC2 or DC3, and readl(crtc_reg) will access with random address, because the \"device\" is from \"base+PCI_DEVICE_ID\", \"base\" is from \"pdev->devfn+1\". This is wrong when my platform inserts a discrete GPU:  lspci -tv -[0000:00]-+-00.0  Loongson Technology LLC Hyper Transport Bridge Controller ...            +-06.0  Loongson Technology LLC LG100 GPU            +-06.2  Loongson Technology LLC Device 7a37 ...  Add a default switch case to fix the panic as below:   Kernel ade access[#1]:  CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.6.136-loong64-desktop-hwe+ #4  pc 90000000017e5534 ra 90000000017e54c0 tp 90000001002f8000 sp 90000001002fb6c0  a0 80000efe00003100 a1 0000000000003100 a2 0000000000000000 a3 0000000000000002  a4 90000001002fb6b4 a5 900000087cdb58fd a6 90000000027af000 a7 0000000000000001  t0 00000000000085b9 t1 000000000000ffff t2 0000000000000000 t3 0000000000000000  t4 fffffffffffffffd t5 00000000fffb6d9c t6 0000000000083b00 t7 00000000000070c0  t8 900000087cdb4d94 u0 900000087cdb58fd s9 90000001002fb826 s0 90000000031c12c8  s1 7fffffffffffff00 s2 90000000031c12d0 s3 0000000000002710 s4 0000000000000000  s5 0000000000000000 s6 9000000100053000 s7 7fffffffffffff00 s8 90000000030d4000     ra: 90000000017e54c0 loongson_gpu_fixup_dma_hang+0x40/0x210    ERA: 90000000017e5534 loongson_gpu_fixup_dma_hang+0xb4/0x210   CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)   PRMD: 00000004 (PPLV0 +PIE -PWE)   EUEN: 00000000 (-FPE -SXE -ASXE -BTE)   ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)  ESTAT: 00480000 [ADEM] (IS= ECode=8 EsubCode=1)   BADV: 7fffffffffffff00   PRID: 0014d000 (Loongson-64bit, Loongson-3A6000-HV)  Modules linked in:  Process swapper/0 (pid: 1, threadinfo=(____ptrval____), task=(____ptrval____))  Stack : 0000000000000006 90000001002fb778 90000001002fb704 0000000000000007          0000000016a65700 90000000017e5690 000000000000ffff ffffffffffffffff          900000000209f7c0 9000000100053000 900000000209f7a8 9000000000eebc08          0000000000000000 0000000000000000 0000000000000006 90000001002fb778          90000001000530b8 90000000027af000 0000000000000000 9000000100054000          9000000100053000 9000000000ebb70c 9000000100004c00 9000000004000001          90000001002fb7e4 bae765461f31cb12 0000000000000000 0000000000000000          0000000000000006 90000000027af000 0000000000000030 90000000027af000          900000087cd6f800 9000000100053000 0000000000000000 9000000000ebc560          7a2500147cdaf720 bae765461f31cb12 0000000000000001 0000000000000030          ...  Call Trace:  [<90000000017e5534>] loongson_gpu_fixup_dma_hang+0xb4/0x210  [<9000000000eebc08>] pci_fixup_device+0x108/0x280  [<9000000000ebb70c>] pci_setup_device+0x24c/0x690  [<9000000000ebc560>] pci_scan_single_device+0xe0/0x140  [<9000000000ebc684>] pci_scan_slot+0xc4/0x280  [<9000000000ebdd00>] pci_scan_child_bus_extend+0x60/0x3f0  [<9000000000f5bc94>] acpi_pci_root_create+0x2b4/0x420  [<90000000017e5e74>] pci_acpi_scan_root+0x2d4/0x440  [<9000000000f5b02c>] acpi_pci_root_add+0x21c/0x3a0  [<9000000000f4ee54>] acpi_bus_attach+0x1a4/0x3c0  [<90000000010e200c>] device_for_each_child+0x6c/0xe0  [<9000000000f4bbf4>] acpi_dev_for_each_child+0x44/0x70  [<9000000000f4ef40>] acpi_bus_attach+0x290/0x3c0  [<90000000010e200c>] device_for_each_child+0x6c/0xe0  [<9000000000f4bbf4>] acpi_dev_for_each_child+0x44/0x70  [<9000000000f4ef40>] acpi_bus_attach+0x290/0x3c0  [<9000000000f5211c>] acpi_bus_scan+0x6c/0x280  [<900000000189c028>] acpi_scan_init+0x194/0x310  [<900000000189bc6c>] acpi_init+0xcc/0x140  [<9000000000220cdc>] do_one_initcall+0x4c/0x310  [<90000000018618fc>] kernel_init_freeable+0x258/0x2d4  [<900000000184326c>] kernel_init+0x28/0x13c  [<9000000000222008>] ret_from_kernel_thread+0xc/0xa4","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46156","epss":0.00095,"percentile":0.00679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46156","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.049875},"relatedVulnerabilities":[{"id":"CVE-2026-46156","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46156","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/07d190e4ec689d6478f7f5e36099fb9bf457e7c5","https://git.kernel.org/stable/c/2cb19b06c09983727573bbe7d7430cbad480a714","https://git.kernel.org/stable/c/81fef1c278436e6bd68ee4ca05a0acb96e256561","https://git.kernel.org/stable/c/8dfa2f8780e486d05b9a0ffce70b8f5fbd62053e","https://git.kernel.org/stable/c/9e1aed63a5552958ef2a9bfd699a3f990e52a77f","https://git.kernel.org/stable/c/bfde8accc3e3260c0ecbb8cc34361739e1e16f31"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()\n\nThe switch case in loongson_gpu_fixup_dma_hang() may not DC2 or DC3, and\nreadl(crtc_reg) will access with random address, because the \"device\" is\nfrom \"base+PCI_DEVICE_ID\", \"base\" is from \"pdev->devfn+1\". This is wrong\nwhen my platform inserts a discrete GPU:\n\nlspci -tv\n-[0000:00]-+-00.0  Loongson Technology LLC Hyper Transport Bridge Controller\n...\n           +-06.0  Loongson Technology LLC LG100 GPU\n           +-06.2  Loongson Technology LLC Device 7a37\n...\n\nAdd a default switch case to fix the panic as below:\n\n Kernel ade access[#1]:\n CPU: 0 PID: 1 Comm: swapper/0 Not tainted 6.6.136-loong64-desktop-hwe+ #4\n pc 90000000017e5534 ra 90000000017e54c0 tp 90000001002f8000 sp 90000001002fb6c0\n a0 80000efe00003100 a1 0000000000003100 a2 0000000000000000 a3 0000000000000002\n a4 90000001002fb6b4 a5 900000087cdb58fd a6 90000000027af000 a7 0000000000000001\n t0 00000000000085b9 t1 000000000000ffff t2 0000000000000000 t3 0000000000000000\n t4 fffffffffffffffd t5 00000000fffb6d9c t6 0000000000083b00 t7 00000000000070c0\n t8 900000087cdb4d94 u0 900000087cdb58fd s9 90000001002fb826 s0 90000000031c12c8\n s1 7fffffffffffff00 s2 90000000031c12d0 s3 0000000000002710 s4 0000000000000000\n s5 0000000000000000 s6 9000000100053000 s7 7fffffffffffff00 s8 90000000030d4000\n    ra: 90000000017e54c0 loongson_gpu_fixup_dma_hang+0x40/0x210\n   ERA: 90000000017e5534 loongson_gpu_fixup_dma_hang+0xb4/0x210\n  CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)\n  PRMD: 00000004 (PPLV0 +PIE -PWE)\n  EUEN: 00000000 (-FPE -SXE -ASXE -BTE)\n  ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)\n ESTAT: 00480000 [ADEM] (IS= ECode=8 EsubCode=1)\n  BADV: 7fffffffffffff00\n  PRID: 0014d000 (Loongson-64bit, Loongson-3A6000-HV)\n Modules linked in:\n Process swapper/0 (pid: 1, threadinfo=(____ptrval____), task=(____ptrval____))\n Stack : 0000000000000006 90000001002fb778 90000001002fb704 0000000000000007\n         0000000016a65700 90000000017e5690 000000000000ffff ffffffffffffffff\n         900000000209f7c0 9000000100053000 900000000209f7a8 9000000000eebc08\n         0000000000000000 0000000000000000 0000000000000006 90000001002fb778\n         90000001000530b8 90000000027af000 0000000000000000 9000000100054000\n         9000000100053000 9000000000ebb70c 9000000100004c00 9000000004000001\n         90000001002fb7e4 bae765461f31cb12 0000000000000000 0000000000000000\n         0000000000000006 90000000027af000 0000000000000030 90000000027af000\n         900000087cd6f800 9000000100053000 0000000000000000 9000000000ebc560\n         7a2500147cdaf720 bae765461f31cb12 0000000000000001 0000000000000030\n         ...\n Call Trace:\n [<90000000017e5534>] loongson_gpu_fixup_dma_hang+0xb4/0x210\n [<9000000000eebc08>] pci_fixup_device+0x108/0x280\n [<9000000000ebb70c>] pci_setup_device+0x24c/0x690\n [<9000000000ebc560>] pci_scan_single_device+0xe0/0x140\n [<9000000000ebc684>] pci_scan_slot+0xc4/0x280\n [<9000000000ebdd00>] pci_scan_child_bus_extend+0x60/0x3f0\n [<9000000000f5bc94>] acpi_pci_root_create+0x2b4/0x420\n [<90000000017e5e74>] pci_acpi_scan_root+0x2d4/0x440\n [<9000000000f5b02c>] acpi_pci_root_add+0x21c/0x3a0\n [<9000000000f4ee54>] acpi_bus_attach+0x1a4/0x3c0\n [<90000000010e200c>] device_for_each_child+0x6c/0xe0\n [<9000000000f4bbf4>] acpi_dev_for_each_child+0x44/0x70\n [<9000000000f4ef40>] acpi_bus_attach+0x290/0x3c0\n [<90000000010e200c>] device_for_each_child+0x6c/0xe0\n [<9000000000f4bbf4>] acpi_dev_for_each_child+0x44/0x70\n [<9000000000f4ef40>] acpi_bus_attach+0x290/0x3c0\n [<9000000000f5211c>] acpi_bus_scan+0x6c/0x280\n [<900000000189c028>] acpi_scan_init+0x194/0x310\n [<900000000189bc6c>] acpi_init+0xcc/0x140\n [<9000000000220cdc>] do_one_initcall+0x4c/0x310\n [<90000000018618fc>] kernel_init_freeable+0x258/0x2d4\n [<900000000184326c>] kernel_init+0x28/0x13c\n [<9000000000222008>] ret_from_kernel_thread+0xc/0xa4","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46156","epss":0.00095,"percentile":0.00679,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46156","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46156","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46157","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46157","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger  Currently the runtime.oss.trigger field may be accessed concurrently without protection, which may lead to the data race.  And, in this case, it may lead to more severe problem because it's a bit field; as writing the data, it may overwrite other bit fields as well, which confuses the operation completely, as spotted by fuzzing.  Fix it by covering runtime.oss.trigger bit fled also with the existing params_lock mutex in both snd_pcm_oss_get_trigger() and snd_pcm_oss_poll().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46157","epss":0.00099,"percentile":0.00905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46157","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07573500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46157","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46157","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/49f9d048845be874df7997e4b1ce662de450c4b6","https://git.kernel.org/stable/c/6b01c1bc9a4748ab37548a700a8aaff910e298e6","https://git.kernel.org/stable/c/901ac0ff15edf9503162e2cf6579bd11a30f1ed4","https://git.kernel.org/stable/c/ac3e9b55b7da6f0be51720bd330a0edc1a8b61f1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger\n\nCurrently the runtime.oss.trigger field may be accessed concurrently\nwithout protection, which may lead to the data race.  And, in this\ncase, it may lead to more severe problem because it's a bit field; as\nwriting the data, it may overwrite other bit fields as well, which\nconfuses the operation completely, as spotted by fuzzing.\n\nFix it by covering runtime.oss.trigger bit fled also with the existing\nparams_lock mutex in both snd_pcm_oss_get_trigger() and\nsnd_pcm_oss_poll().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46157","epss":0.00099,"percentile":0.00905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46157","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46157","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46158","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46158","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mptcp: pm: ADD_ADDR rtx: always decrease sk refcount  When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(). It should then be released in all cases at the end.  Some (unlikely) checks were returning directly instead of calling sock_put() to decrease the refcount. Jump to a new 'exit' label to call __sock_put() (which will become sock_put() in the next commit) to fix this potential leak.  While at it, drop the '!msk' check which cannot happen because it is never reset, and explicitly mark the remaining one as \"unlikely\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46158","epss":0.00128,"percentile":0.02761,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.06720000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46158","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46158","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/25e37407442b8766ec2cf52fb4e31b5c3d3aeeae","https://git.kernel.org/stable/c/81d8142148164176385c279c7c1e1d581867423d","https://git.kernel.org/stable/c/9426265e157dd77ec237c795901ed4dea6d69b5c","https://git.kernel.org/stable/c/9634cb35af17019baec21ca648516ce376fa10e6","https://git.kernel.org/stable/c/acd3d3562315c99f3c0db16f0fcc5f0306638982","https://git.kernel.org/stable/c/b41dd76f3b9735096c21d3e799a2b9fe36498d57","https://git.kernel.org/stable/c/e9ba34301d2e90f63f97c76ad9eb98e5250fe961"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: always decrease sk refcount\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer().\nIt should then be released in all cases at the end.\n\nSome (unlikely) checks were returning directly instead of calling\nsock_put() to decrease the refcount. Jump to a new 'exit' label to call\n__sock_put() (which will become sock_put() in the next commit) to fix\nthis potential leak.\n\nWhile at it, drop the '!msk' check which cannot happen because it is\nnever reset, and explicitly mark the remaining one as \"unlikely\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46158","epss":0.00128,"percentile":0.02761,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46158","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46170","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46170","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mptcp: pm: ADD_ADDR rtx: free sk if last  When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(), and released at the end.  If at that moment, it was the last reference being held, the sk would not be freed. sock_put() should then be called instead of __sock_put().  But that's not enough: if it is the last reference, sock_put() will call sk_free(), which will end up calling sk_stop_timer_sync() on the same timer, and waiting indefinitely to finish. So it is needed to mark that the timer is done at the end of the timer handler when it has not been rescheduled, not to call sk_stop_timer_sync() on \"itself\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46170","epss":0.00128,"percentile":0.02768,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.06720000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46170","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46170","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1f26487e83e69462540bb1047139472957c913c6","https://git.kernel.org/stable/c/531c537b8fb620beabccfb1594e8d43cbebbb87a","https://git.kernel.org/stable/c/5da972efed3dc7599da6e2b5e8d906d1b7b1a728","https://git.kernel.org/stable/c/6a3af482188f6db4186d1605f64d911d7330abb3","https://git.kernel.org/stable/c/8143a224785ceaf2b0856e08d4498916f38228fb","https://git.kernel.org/stable/c/b74ad20198652b6b39a761c277ba65ae82b1e107","https://git.kernel.org/stable/c/b7b9a461569734d33d3259d58d2507adfac107ed"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: free sk if last\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(),\nand released at the end.\n\nIf at that moment, it was the last reference being held, the sk would\nnot be freed. sock_put() should then be called instead of __sock_put().\n\nBut that's not enough: if it is the last reference, sock_put() will call\nsk_free(), which will end up calling sk_stop_timer_sync() on the same\ntimer, and waiting indefinitely to finish. So it is needed to mark that\nthe timer is done at the end of the timer handler when it has not been\nrescheduled, not to call sk_stop_timer_sync() on \"itself\".","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46170","epss":0.00128,"percentile":0.02768,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46170","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46175","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46175","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix fsck inconsistency caused by FGGC of node block  During FGGC node block migration, fsck may incorrectly treat the migrated node block as fsync-written data.  The reproduction scenario: root@vm:/mnt/f2fs# seq 1 2048 | xargs -n 1 ./test_sync // write inline inode and sync root@vm:/mnt/f2fs# rm -f 1 root@vm:/mnt/f2fs# sync root@vm:/mnt/f2fs# f2fs_io gc_range // move data block in sync mode and not write CP   SPO, \"fsck --dry-run\" find inode has already checkpointed but still   with DENT_BIT_SHIFT set  The root cause is that GC does not clear the dentry mark and fsync mark during node block migration, leading fsck to misinterpret them as user-issued fsync writes.  In BGGC mode, node block migration is handled by f2fs_sync_node_pages(), which guarantees the dentry and fsync marks are cleared before writing.  This patch move the set/clear of the fsync|dentry marks into __write_node_folio to make the logic clearer, and ensures the fsync|dentry mark is cleared in FGGC.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46175","epss":0.00124,"percentile":0.02439,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09052},"relatedVulnerabilities":[{"id":"CVE-2026-46175","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46175","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/8be551f538dc5b64183e27bd45a7a0795263f760","https://git.kernel.org/stable/c/c3e238bd1f56993f205ef83889d406dfeaf717a8","https://git.kernel.org/stable/c/e7c6d30169b03307d27c4479563df79c08f3a746"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix fsck inconsistency caused by FGGC of node block\n\nDuring FGGC node block migration, fsck may incorrectly treat the\nmigrated node block as fsync-written data.\n\nThe reproduction scenario:\nroot@vm:/mnt/f2fs# seq 1 2048 | xargs -n 1 ./test_sync // write inline inode and sync\nroot@vm:/mnt/f2fs# rm -f 1\nroot@vm:/mnt/f2fs# sync\nroot@vm:/mnt/f2fs# f2fs_io gc_range // move data block in sync mode and not write CP\n  SPO, \"fsck --dry-run\" find inode has already checkpointed but still\n  with DENT_BIT_SHIFT set\n\nThe root cause is that GC does not clear the dentry mark and fsync mark\nduring node block migration, leading fsck to misinterpret them as\nuser-issued fsync writes.\n\nIn BGGC mode, node block migration is handled by f2fs_sync_node_pages(),\nwhich guarantees the dentry and fsync marks are cleared before writing.\n\nThis patch move the set/clear of the fsync|dentry marks into\n__write_node_folio to make the logic clearer, and ensures the\nfsync|dentry mark is cleared in FGGC.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46175","epss":0.00124,"percentile":0.02439,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46175","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46181","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()  Sashiko points out the radix_tree itself is RCU safe, but nothing ever frees the mlx4_srq struct with RCU, and it isn't even accessed within the RCU critical section. It also will crash if an event is delivered before the srq object is finished initializing.  Use the spinlock since it isn't easy to make RCU work, use refcount_inc_not_zero() to protect against partially initialized objects, and order the refcount_set() to be after the srq is fully initialized.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46181","epss":0.00114,"percentile":0.01617,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46181","cwe":"CWE-366","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08265},"relatedVulnerabilities":[{"id":"CVE-2026-46181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46181","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1e2a44875b6afb4add1115f7f3351dcbeb6f273d","https://git.kernel.org/stable/c/8b7833f3bce35cb0d01c1503781523c099c675f0","https://git.kernel.org/stable/c/c9341307ea16b9395c2e4c9c94d8499d91fe31d0","https://access.redhat.com/errata/RHSA-2026:25120","https://access.redhat.com/errata/RHSA-2026:25121","https://access.redhat.com/errata/RHSA-2026:25217","https://access.redhat.com/errata/RHSA-2026:33900","https://access.redhat.com/errata/RHSA-2026:34094","https://access.redhat.com/errata/RHSA-2026:34095","https://access.redhat.com/errata/RHSA-2026:34443","https://access.redhat.com/errata/RHSA-2026:35863","https://access.redhat.com/errata/RHSA-2026:35894","https://access.redhat.com/errata/RHSA-2026:35896","https://access.redhat.com/errata/RHSA-2026:36216","https://access.redhat.com/errata/RHSA-2026:41236","https://access.redhat.com/security/cve/CVE-2026-46181","https://bugzilla.redhat.com/show_bug.cgi?id=2482532","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46181.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()\n\nSashiko points out the radix_tree itself is RCU safe, but nothing ever\nfrees the mlx4_srq struct with RCU, and it isn't even accessed within the\nRCU critical section. It also will crash if an event is delivered before\nthe srq object is finished initializing.\n\nUse the spinlock since it isn't easy to make RCU work, use\nrefcount_inc_not_zero() to protect against partially initialized objects,\nand order the refcount_set() to be after the srq is fully initialized.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46181","epss":0.00114,"percentile":0.01617,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46181","cwe":"CWE-366","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46181","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46200","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46200","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: mpc52xx: fix controller deregistration  Make sure to deregister the controller before disabling and releasing underlying resources like interrupts and gpios during driver unbind.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46200","epss":0.00127,"percentile":0.02721,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2026-46200","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46200","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0f997fdae819a8c2cc83bd4ff7d935ad76c727c9","https://git.kernel.org/stable/c/28f28a0f4e327f792c230493a0ea00389ff68ff5","https://git.kernel.org/stable/c/7fea80d93bfd34051b2ac1cec07766c87d8d28be","https://git.kernel.org/stable/c/a3669f678d0ee8b686d3eea4c0ed9817c9374945"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mpc52xx: fix controller deregistration\n\nMake sure to deregister the controller before disabling and releasing\nunderlying resources like interrupts and gpios during driver unbind.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46200","epss":0.00127,"percentile":0.02721,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46200","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46204","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46204","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn4: Prevent OOB reads when parsing IB  Rewrite the IB parsing to use amdgpu_ib_get_value() which handles the bounds checks.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46204","epss":0.00131,"percentile":0.03023,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46204","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09562999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-46204","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46204","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1dc005775fb5b3f86464406452b17364f85581d3","https://git.kernel.org/stable/c/2444eb0ec8283f4a3845eb7febad378476e1ba3c","https://git.kernel.org/stable/c/5c3e8ebad0c9e2354ddfa8f2148dc4f70a3b4bd1","https://git.kernel.org/stable/c/a6d5563ba1f03a049561cd347574613167294e8d","https://git.kernel.org/stable/c/d0802a8877d730260d4af4dd4e0b6cde7e0e593f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn4: Prevent OOB reads when parsing IB\n\nRewrite the IB parsing to use amdgpu_ib_get_value() which handles the\nbounds checks.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46204","epss":0.00131,"percentile":0.03023,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46204","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46204","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46219","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46219","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: mpc52xx: fix use-after-free on unbind  The state machine work is scheduled by the interrupt handler and therefore needs to be cancelled after disabling interrupts to avoid a potential use-after-free.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46219","epss":0.00135,"percentile":0.03286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46219","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.103275},"relatedVulnerabilities":[{"id":"CVE-2026-46219","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46219","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0944b20e9dfa2917bd70eb5b301cbb67fe54a718","https://git.kernel.org/stable/c/6c3e413919a12627d04a31a4a5fccb9fc129bb02","https://git.kernel.org/stable/c/706b3dc2ac7a998c55e14b3fd2e8f934c367e6e0","https://git.kernel.org/stable/c/ac8316c896c79f32c1d0a38cb41fd2b14cf8112e","https://git.kernel.org/stable/c/bb6b50f709c5a01906ff72a07fdc070bb3357188","https://git.kernel.org/stable/c/bbcd6dd8e9f264440eaf6167382bf404911c1c46","https://git.kernel.org/stable/c/ed929d40963073f23cfb50219ccbcc6e0c3ea641","https://git.kernel.org/stable/c/ee52da0dd83ebcd89ecbbe2660c57b15a25489f2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mpc52xx: fix use-after-free on unbind\n\nThe state machine work is scheduled by the interrupt handler and\ntherefore needs to be cancelled after disabling interrupts to avoid a\npotential use-after-free.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46219","epss":0.00135,"percentile":0.03286,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46219","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46219","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46225","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46225","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: rspi: fix controller deregistration  Make sure to deregister the controller before releasing underlying resources like DMA during driver unbind.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46225","epss":0.00119,"percentile":0.01972,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46225","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46225","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/77defd64b405b680db73d767313fce770d368368","https://git.kernel.org/stable/c/9944fa6726afb1e6eb7e2212764e7da0c97f2dcc","https://git.kernel.org/stable/c/aee76c1dd189562c6678313caec12761f78a9ef3","https://git.kernel.org/stable/c/c5090db1b31de3ef4db0cda7e822ab49cb572292","https://git.kernel.org/stable/c/fee6abd9845c3edd217b0e429d09f764f9a5690e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: rspi: fix controller deregistration\n\nMake sure to deregister the controller before releasing underlying\nresources like DMA during driver unbind.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46225","epss":0.00119,"percentile":0.01972,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46225","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46226","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46226","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: fsl: fix controller deregistration  Make sure to deregister the controller before releasing underlying resources like DMA during driver unbind.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46226","epss":0.00119,"percentile":0.01963,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46226","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46226","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/562d954a144950ec2aa6a874ae657cb3fa31fe53","https://git.kernel.org/stable/c/5750743a39c9d46ac9fcf57ffe000956da4942cf","https://git.kernel.org/stable/c/9b7abfed4c3754062d1f3ffd452e65a38667f586","https://git.kernel.org/stable/c/ca3195c7b88362d7c81efe685948663a9f9db0e6","https://git.kernel.org/stable/c/e888308222375ac28bae69134dae288178718a96"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: fsl: fix controller deregistration\n\nMake sure to deregister the controller before releasing underlying\nresources like DMA during driver unbind.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46226","epss":0.00119,"percentile":0.01963,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46226","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46229","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46229","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure  KFD VRAM allocations set AMDGPU_GEM_CREATE_VRAM_WIPE_ON_RELEASE but not AMDGPU_GEM_CREATE_VRAM_CLEARED, leaving freshly allocated VRAM with stale data from prior use observable by compute kernels.  The GEM ioctl path already sets VRAM_CLEARED for all userspace allocations via amdgpu_gem_create_ioctl() and amdgpu_mode_dumb_create(). The KFD path was missing this flag, allowing stale page table remnants to leak into user buffers.  This causes crashes in RCCL P2P transport where non-zero data in ptrExchange/head/tail fields corrupts the protocol handshake.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46229","epss":0.00119,"percentile":0.01972,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-46229","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46229","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/047d44d8d29a6a1a5757256837aa9dd78e3cd0b5","https://git.kernel.org/stable/c/1db431380879fd9d28b763a88a0c0431be5be8df","https://git.kernel.org/stable/c/32b153658f017ad2f5bf8aab479e8d16ac95bc3a","https://git.kernel.org/stable/c/77d0b5d11387071770246fd0185a69fa28e8e109","https://git.kernel.org/stable/c/ad52d61d82181dbdb7f05826de38352d5e550cc2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Clear VRAM on allocation to prevent stale data exposure\n\nKFD VRAM allocations set AMDGPU_GEM_CREATE_VRAM_WIPE_ON_RELEASE\nbut not AMDGPU_GEM_CREATE_VRAM_CLEARED, leaving freshly allocated\nVRAM with stale data from prior use observable by compute kernels.\n\nThe GEM ioctl path already sets VRAM_CLEARED for all userspace\nallocations via amdgpu_gem_create_ioctl() and\namdgpu_mode_dumb_create(). The KFD path was missing this flag,\nallowing stale page table remnants to leak into user buffers.\n\nThis causes crashes in RCCL P2P transport where non-zero data in\nptrExchange/head/tail fields corrupts the protocol handshake.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46229","epss":0.00119,"percentile":0.01972,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46229","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46241","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46241","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  spi: mpc52xx: fix use-after-free on registration failure  Make sure to disable and free the interrupts in case controller registration fails to avoid a potential use-after-free and resource leak.  This issue was flagged by Sashiko when reviewing a controller deregistration fix.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46241","epss":0.00125,"percentile":0.02504,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46241","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-46241","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46241","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/336d9ad7560b3baba17af06727a888040ee93390","https://git.kernel.org/stable/c/5c77f11b9b5f1ad5a704dad875260c44016ede10","https://git.kernel.org/stable/c/8b49b6aadd0c622ca7d68b4a53ae10362e221cf3","https://git.kernel.org/stable/c/f62c060272b9d7423b1650b844e8e4e7b8f9f925"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mpc52xx: fix use-after-free on registration failure\n\nMake sure to disable and free the interrupts in case controller\nregistration fails to avoid a potential use-after-free and resource\nleak.\n\nThis issue was flagged by Sashiko when reviewing a controller\nderegistration fix.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46241","epss":0.00125,"percentile":0.02504,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46241","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46241","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46245","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46245","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix dc_link NULL handling in HPD init  amdgpu_dm_hpd_init() may see connectors without a valid dc_link.  The code already checks dc_link for the polling decision, but later unconditionally dereferences it when setting up HPD interrupts.  Assign dc_link early and skip connectors where it is NULL.  Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_irq.c:940 amdgpu_dm_hpd_init() error: we previously assumed 'dc_link' could be null (see line 931)  drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_irq.c     923                 /*     924                  * Analog connectors may be hot-plugged unlike other connector     925                  * types that don't support HPD. Only poll analog connectors.     926                  */     927                 use_polling |=     928                         amdgpu_dm_connector->dc_link &&                                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ The patch adds this NULL check but hopefully it can be removed      929                         dc_connector_supports_analog(amdgpu_dm_connector->dc_link->link_id.id);     930     931                 dc_link = amdgpu_dm_connector->dc_link;  dc_link assigned here.      932     933                 /*     934                  * Get a base driver irq reference for hpd ints for the lifetime     935                  * of dm. Note that only hpd interrupt types are registered with     936                  * base driver; hpd_rx types aren't. IOW, amdgpu_irq_get/put on     937                  * hpd_rx isn't available. DM currently controls hpd_rx     938                  * explicitly with dc_interrupt_set()     939                  */ --> 940                 if (dc_link->irq_source_hpd != DC_IRQ_SOURCE_INVALID) {                             ^^^^^^^^^^^^^^^^^^^^^^^ If it's NULL then we are trouble because we dereference it here.      941                         irq_type = dc_link->irq_source_hpd - DC_IRQ_SOURCE_HPD1;     942                         /*     943                          * TODO: There's a mismatch between mode_info.num_hpd     944                          * and what bios reports as the # of connectors with hpd","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46245","epss":0.00108,"percentile":0.01303,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46245","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0567},"relatedVulnerabilities":[{"id":"CVE-2026-46245","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46245","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/226a40c06a183abaeb7529a4f54d6c203bd14407","https://git.kernel.org/stable/c/a490e4d3c9fed1e690c8de348416eea3a9f054ff"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix dc_link NULL handling in HPD init\n\namdgpu_dm_hpd_init() may see connectors without a valid dc_link.\n\nThe code already checks dc_link for the polling decision, but later\nunconditionally dereferences it when setting up HPD interrupts.\n\nAssign dc_link early and skip connectors where it is NULL.\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_irq.c:940 amdgpu_dm_hpd_init()\nerror: we previously assumed 'dc_link' could be null (see line 931)\n\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_irq.c\n    923                 /*\n    924                  * Analog connectors may be hot-plugged unlike other connector\n    925                  * types that don't support HPD. Only poll analog connectors.\n    926                  */\n    927                 use_polling |=\n    928                         amdgpu_dm_connector->dc_link &&\n                                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ The patch adds this NULL check but hopefully it can be removed\n\n    929                         dc_connector_supports_analog(amdgpu_dm_connector->dc_link->link_id.id);\n    930\n    931                 dc_link = amdgpu_dm_connector->dc_link;\n\ndc_link assigned here.\n\n    932\n    933                 /*\n    934                  * Get a base driver irq reference for hpd ints for the lifetime\n    935                  * of dm. Note that only hpd interrupt types are registered with\n    936                  * base driver; hpd_rx types aren't. IOW, amdgpu_irq_get/put on\n    937                  * hpd_rx isn't available. DM currently controls hpd_rx\n    938                  * explicitly with dc_interrupt_set()\n    939                  */\n--> 940                 if (dc_link->irq_source_hpd != DC_IRQ_SOURCE_INVALID) {\n                            ^^^^^^^^^^^^^^^^^^^^^^^ If it's NULL then we are trouble because we dereference it here.\n\n    941                         irq_type = dc_link->irq_source_hpd - DC_IRQ_SOURCE_HPD1;\n    942                         /*\n    943                          * TODO: There's a mismatch between mode_info.num_hpd\n    944                          * and what bios reports as the # of connectors with hpd","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46245","epss":0.00108,"percentile":0.01303,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46245","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46245","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46254","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46254","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  AppArmor: Allow apparmor to handle unaligned dfa tables  The dfa tables can originate from kernel or userspace and 8-byte alignment isn't always guaranteed and as such may trigger unaligned memory accesses on various architectures. Resulting in the following  [   73.901376] WARNING: CPU: 0 PID: 341 at security/apparmor/match.c:316 aa_dfa_unpack+0x6cc/0x720 [   74.015867] Modules linked in: binfmt_misc evdev flash sg drm drm_panel_orientation_quirks backlight i2c_core configfs nfnetlink autofs4 ext4 crc16 mbcache jbd2 hid_generic usbhid sr_mod hid cdrom sd_mod ata_generic ohci_pci ehci_pci ehci_hcd ohci_hcd pata_ali libata sym53c8xx scsi_transport_spi tg3 scsi_mod usbcore libphy scsi_common mdio_bus usb_common [   74.428977] CPU: 0 UID: 0 PID: 341 Comm: apparmor_parser Not tainted 6.18.0-rc6+ #9 NONE [   74.536543] Call Trace: [   74.568561] [<0000000000434c24>] dump_stack+0x8/0x18 [   74.633757] [<0000000000476438>] __warn+0xd8/0x100 [   74.696664] [<00000000004296d4>] warn_slowpath_fmt+0x34/0x74 [   74.771006] [<00000000008db28c>] aa_dfa_unpack+0x6cc/0x720 [   74.843062] [<00000000008e643c>] unpack_pdb+0xbc/0x7e0 [   74.910545] [<00000000008e7740>] unpack_profile+0xbe0/0x1300 [   74.984888] [<00000000008e82e0>] aa_unpack+0xe0/0x6a0 [   75.051226] [<00000000008e3ec4>] aa_replace_profiles+0x64/0x1160 [   75.130144] [<00000000008d4d90>] policy_update+0xf0/0x280 [   75.201057] [<00000000008d4fc8>] profile_replace+0xa8/0x100 [   75.274258] [<0000000000766bd0>] vfs_write+0x90/0x420 [   75.340594] [<00000000007670cc>] ksys_write+0x4c/0xe0 [   75.406932] [<0000000000767174>] sys_write+0x14/0x40 [   75.472126] [<0000000000406174>] linux_sparc_syscall+0x34/0x44 [   75.548802] ---[ end trace 0000000000000000 ]--- [   75.609503] dfa blob stream 0xfff0000008926b96 not aligned. [   75.682695] Kernel unaligned access at TPC[8db2a8] aa_dfa_unpack+0x6e8/0x720  Work around it by using the get_unaligned_xx() helpers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46254","epss":0.00114,"percentile":0.01658,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-46254","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46254","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/23f112bd6144e815153462e12d313ac3e7027168","https://git.kernel.org/stable/c/64802f731214a51dfe3c6c27636b3ddafd003eb0","https://git.kernel.org/stable/c/cded636008bde2b397a7cf63b8299d7c303aaf6a","https://git.kernel.org/stable/c/ec737e7fdf2f0ba7b203d4ec72cc915978b10e7e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nAppArmor: Allow apparmor to handle unaligned dfa tables\n\nThe dfa tables can originate from kernel or userspace and 8-byte alignment\nisn't always guaranteed and as such may trigger unaligned memory accesses\non various architectures. Resulting in the following\n\n[   73.901376] WARNING: CPU: 0 PID: 341 at security/apparmor/match.c:316 aa_dfa_unpack+0x6cc/0x720\n[   74.015867] Modules linked in: binfmt_misc evdev flash sg drm drm_panel_orientation_quirks backlight i2c_core configfs nfnetlink autofs4 ext4 crc16 mbcache jbd2 hid_generic usbhid sr_mod hid cdrom\nsd_mod ata_generic ohci_pci ehci_pci ehci_hcd ohci_hcd pata_ali libata sym53c8xx scsi_transport_spi tg3 scsi_mod usbcore libphy scsi_common mdio_bus usb_common\n[   74.428977] CPU: 0 UID: 0 PID: 341 Comm: apparmor_parser Not tainted 6.18.0-rc6+ #9 NONE\n[   74.536543] Call Trace:\n[   74.568561] [<0000000000434c24>] dump_stack+0x8/0x18\n[   74.633757] [<0000000000476438>] __warn+0xd8/0x100\n[   74.696664] [<00000000004296d4>] warn_slowpath_fmt+0x34/0x74\n[   74.771006] [<00000000008db28c>] aa_dfa_unpack+0x6cc/0x720\n[   74.843062] [<00000000008e643c>] unpack_pdb+0xbc/0x7e0\n[   74.910545] [<00000000008e7740>] unpack_profile+0xbe0/0x1300\n[   74.984888] [<00000000008e82e0>] aa_unpack+0xe0/0x6a0\n[   75.051226] [<00000000008e3ec4>] aa_replace_profiles+0x64/0x1160\n[   75.130144] [<00000000008d4d90>] policy_update+0xf0/0x280\n[   75.201057] [<00000000008d4fc8>] profile_replace+0xa8/0x100\n[   75.274258] [<0000000000766bd0>] vfs_write+0x90/0x420\n[   75.340594] [<00000000007670cc>] ksys_write+0x4c/0xe0\n[   75.406932] [<0000000000767174>] sys_write+0x14/0x40\n[   75.472126] [<0000000000406174>] linux_sparc_syscall+0x34/0x44\n[   75.548802] ---[ end trace 0000000000000000 ]---\n[   75.609503] dfa blob stream 0xfff0000008926b96 not aligned.\n[   75.682695] Kernel unaligned access at TPC[8db2a8] aa_dfa_unpack+0x6e8/0x720\n\nWork around it by using the get_unaligned_xx() helpers.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46254","epss":0.00114,"percentile":0.01658,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46254","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46266","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46266","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP  Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous.    socket(AF_INET, SOCK_RAW, 255);  A malicious incoming ICMP packet can set the protocol field to 255 and match this socket, leading to FNHE cache changes.  inner = IP(src=\"192.168.2.1\", dst=\"8.8.8.8\", proto=255)/Raw(\"TEST\") pkt = IP(src=\"192.168.1.1\", dst=\"192.168.2.1\")/ICMP(type=3, code=4, nexthopmtu=576)/inner  \"man 7 raw\" states:    A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able   to send any IP protocol that is specified in the passed header.   Receiving of all IP protocols via IPPROTO_RAW is not possible   using raw sockets.  Make sure we drop these malicious packets.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46266","epss":0.00371,"percentile":0.30442,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.335755},"relatedVulnerabilities":[{"id":"CVE-2026-46266","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46266","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/19e42490c89bac9a388f28179e66bebbef350f99","https://git.kernel.org/stable/c/47276297140ee6712646f9b19fb04fe26daedd01","https://git.kernel.org/stable/c/531c1aec81bfe19d00af13da5531fbb8209e4bd2","https://git.kernel.org/stable/c/719d3932b8f6e3348ce2f0ac58e278301fc17575","https://git.kernel.org/stable/c/c89477ad79446867394360b29bb801010fc3ff22","https://git.kernel.org/stable/c/db76b75ede3810e7cf9cfea5067d4f3e0993768b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ninet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP\n\nYizhou Zhao reported that simply having one RAW socket on protocol\nIPPROTO_RAW (255) was dangerous.\n\n  socket(AF_INET, SOCK_RAW, 255);\n\nA malicious incoming ICMP packet can set the protocol field to 255\nand match this socket, leading to FNHE cache changes.\n\ninner = IP(src=\"192.168.2.1\", dst=\"8.8.8.8\", proto=255)/Raw(\"TEST\")\npkt = IP(src=\"192.168.1.1\", dst=\"192.168.2.1\")/ICMP(type=3, code=4, nexthopmtu=576)/inner\n\n\"man 7 raw\" states:\n\n  A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able\n  to send any IP protocol that is specified in the passed header.\n  Receiving of all IP protocols via IPPROTO_RAW is not possible\n  using raw sockets.\n\nMake sure we drop these malicious packets.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46266","epss":0.00371,"percentile":0.30442,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46266","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46274","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46274","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  io-wq: check that the predecessor is hashed in io_wq_remove_pending()  io_wq_remove_pending() needs to fix up wq->hash_tail[] if the cancelled work was the tail of its hash bucket. When doing this, it checks whether the preceding entry in acct->work_list has the same hash value, but never checks that the predecessor is hashed at all. io_get_work_hash() is simply atomic_read(&work->flags) >> IO_WQ_HASH_SHIFT, and the hash bits are never set for non-hashed work, so it returns 0. Thus, when a hashed bucket-0 work is cancelled while a non-hashed work is its list predecessor, the check spuriously passes and a pointer to the non-hashed io_kiocb is stored in wq->hash_tail[0].  Because non-hashed work is dequeued via the fast path in io_get_next_work(), which never touches hash_tail[], the stale pointer is never cleared. Therefore, after the non-hashed io_kiocb completes and is freed back to req_cachep, wq->hash_tail[0] is a dangling pointer. The io_wq is per-task (tctx->io_wq) and survives ring open/close, so the dangling pointer persists for the lifetime of the task; the next hashed bucket-0 enqueue dereferences it in io_wq_insert_work() and wq_list_add_after() writes through freed memory.  Add the missing io_wq_is_hashed() check so a non-hashed predecessor never inherits a hash_tail[] slot.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46274","epss":0.00138,"percentile":0.03513,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46274","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-46274","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46274","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/252c5051dba9c709b6a72f2866f93e5e618b3f06","https://git.kernel.org/stable/c/5a20ebf0c81b61f5ea3b1b529c100cad69b9f603","https://git.kernel.org/stable/c/d376c131af7c7739a87ff037ed2fdb67c2542c8a","https://git.kernel.org/stable/c/d6a2d7b04b5a093021a7a0e2e69e9d5237dfa8cc","https://git.kernel.org/stable/c/d6bda9df0c0a3080804181464d5c0f4d78a4e769"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nio-wq: check that the predecessor is hashed in io_wq_remove_pending()\n\nio_wq_remove_pending() needs to fix up wq->hash_tail[] if the cancelled\nwork was the tail of its hash bucket. When doing this, it checks whether\nthe preceding entry in acct->work_list has the same hash value, but\nnever checks that the predecessor is hashed at all. io_get_work_hash()\nis simply atomic_read(&work->flags) >> IO_WQ_HASH_SHIFT, and the hash\nbits are never set for non-hashed work, so it returns 0. Thus, when a\nhashed bucket-0 work is cancelled while a non-hashed work is its list\npredecessor, the check spuriously passes and a pointer to the non-hashed\nio_kiocb is stored in wq->hash_tail[0].\n\nBecause non-hashed work is dequeued via the fast path in\nio_get_next_work(), which never touches hash_tail[], the stale pointer\nis never cleared. Therefore, after the non-hashed io_kiocb completes and\nis freed back to req_cachep, wq->hash_tail[0] is a dangling pointer. The\nio_wq is per-task (tctx->io_wq) and survives ring open/close, so the\ndangling pointer persists for the lifetime of the task; the next hashed\nbucket-0 enqueue dereferences it in io_wq_insert_work() and\nwq_list_add_after() writes through freed memory.\n\nAdd the missing io_wq_is_hashed() check so a non-hashed predecessor\nnever inherits a hash_tail[] slot.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46274","epss":0.00138,"percentile":0.03513,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46274","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46274","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46282","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46282","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iio: frequency: admv1013: fix NULL pointer dereference on str  When device_property_read_string() fails, str is left uninitialized but the code falls through to strcmp(str, ...), dereferencing a garbage pointer. Replace manual read/strcmp with device_property_match_property_string() and consolidate the SE mode enums into a single sequential enum, mapping to hardware register values via a switch consistent with other bitfields in the driver.  Several cleanup patches have been applied to this driver recently so this will need a manual backport.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46282","epss":0.00122,"percentile":0.02266,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46282","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-46282","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46282","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2dc8d26690bf4e7226409563221c37bc095c94ff","https://git.kernel.org/stable/c/3a9d8ec2051c2d80158ed7bded5e158c42870037","https://git.kernel.org/stable/c/5e9f1bad26df3d3afb3cbbfa408b6d6e809708ac","https://git.kernel.org/stable/c/aac0a51b16700b403a55b67ba495de021db78763"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: frequency: admv1013: fix NULL pointer dereference on str\n\nWhen device_property_read_string() fails, str is left uninitialized\nbut the code falls through to strcmp(str, ...), dereferencing a garbage\npointer. Replace manual read/strcmp with\ndevice_property_match_property_string() and consolidate the SE mode\nenums into a single sequential enum, mapping to hardware register\nvalues via a switch consistent with other bitfields in the driver.\n\nSeveral cleanup patches have been applied to this driver recently so\nthis will need a manual backport.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46282","epss":0.00122,"percentile":0.02266,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46282","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46282","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46293","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46293","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  clk: microchip: mpfs-ccc: fix out of bounds access during output registration  UBSAN reported an out of bounds access during registration of the last two outputs. This out of bounds access occurs because space is only allocated in the hws array for two PLLs and the four output dividers that each has, but the defined IDs contain two DLLS and their two outputs each, which are not supported by the driver. The ID order is PLLs -> DLLs -> PLL outputs -> DLL outputs. Decrement the PLL output IDs by two while adding them to the array to avoid the problem.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46293","epss":0.00126,"percentile":0.02581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46293","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.09198},"relatedVulnerabilities":[{"id":"CVE-2026-46293","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46293","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2f7ae8ab6aa73daaf080d5332110357c29df9c36","https://git.kernel.org/stable/c/47bc7a03449c39805bc2665d3e57c73195d5bcf8","https://git.kernel.org/stable/c/9ed9b580a814773482c0a4f1be045636e68cc109","https://git.kernel.org/stable/c/a0780aeea166a7cf4706c45af4cadbb2a43a1fc9","https://git.kernel.org/stable/c/dbfcb09656cb30439577325c9dea2250203c2e3c","https://git.kernel.org/stable/c/f24efd415455b98a1f1cfc6071fe6fde71986706"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nclk: microchip: mpfs-ccc: fix out of bounds access during output registration\n\nUBSAN reported an out of bounds access during registration of the last\ntwo outputs. This out of bounds access occurs because space is only\nallocated in the hws array for two PLLs and the four output dividers\nthat each has, but the defined IDs contain two DLLS and their two\noutputs each, which are not supported by the driver. The ID order is\nPLLs -> DLLs -> PLL outputs -> DLL outputs. Decrement the PLL output IDs\nby two while adding them to the array to avoid the problem.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46293","epss":0.00126,"percentile":0.02581,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46293","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46293","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46302","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46302","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: allow multiple opens of /sys/fs/selinux/policy  Currently there can only be a single open of /sys/fs/selinux/policy at any time. This allows any process to block any other process from reading the kernel policy. The original motivation seems to have been a mix of preventing an inconsistent view of the policy size and preventing userspace from allocating kernel memory without bound, but this is arguably equally bad. Eliminate the policy_opened flag and shrink the critical section that the policy mutex is held. While we are making changes here, drop a couple of extraneous BUG_ONs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46302","epss":0.001,"percentile":0.00938,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.052500000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-46302","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46302","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/714362f3779dfa453a78ced32396a72726962a41","https://git.kernel.org/stable/c/a02cd6805562305f936e807da83e253b719dd965"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: allow multiple opens of /sys/fs/selinux/policy\n\nCurrently there can only be a single open of /sys/fs/selinux/policy at\nany time. This allows any process to block any other process from\nreading the kernel policy. The original motivation seems to have been\na mix of preventing an inconsistent view of the policy size and\npreventing userspace from allocating kernel memory without bound, but\nthis is arguably equally bad. Eliminate the policy_opened flag and\nshrink the critical section that the policy mutex is held. While we\nare making changes here, drop a couple of extraneous BUG_ONs.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46302","epss":0.001,"percentile":0.00938,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46302","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46312","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46312","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: videobuf2: Set vma_flags in vb2_dma_sg_mmap  vb2_dma_contig sets VMA flags VM_DONTEXPAND and VM_DONTDUMP and I do not see a reason why vb2_dma_sg should behave differently. This avoids hitting `WARN_ON(!(vma->vm_flags & VM_DONTEXPAND));` in drm_gem_mmap_obj() during mmap() of an imported dma-buf from the out of tree Apple ISP camera capture driver which uses vb2_dma_sg_memops.  gst-launch-1.0 v4l2src ! gtk4paintablesink  [   38.201528] ------------[ cut here ]------------ [   38.202135] WARNING: CPU: 7 PID: 2362 at drivers/gpu/drm/drm_gem.c:1144 drm_gem_mmap_obj+0x1f8/0x210 [   38.203278] Modules linked in: rfcomm snd_seq_dummy snd_hrtimer snd_seq snd_seq_device uinput nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables qrtr bnep nls_ascii i2c_dev loop fuse dm_multipath nfnetlink brcmfmac_wcc hid_magicmouse hci_bcm4377 brcmfmac brcmutil bluetooth ecdh_generic cfg80211 ecc btrfs xor xor_neon rfkill hid_apple raid6_pq joydev aop_als apple_nvmem_spmi industrialio snd_soc_aop apple_z2 snd_soc_cs42l84 tps6598x snd_soc_tas2764 macsmc_reboot spi_nor macsmc_hwmon rtc_macsmc gpio_macsmc macsmc_power regmap_spmi macsmc_input dockchannel_hid panel_summit appledrm nvme_apple dwc3 snd_soc_macaudio drm_client_lib nvme_core phy_apple_atc hwmon apple_sart apple_dockchannel macsmc apple_rtkit_helper spmi_apple_controller aop apple_wdt mfd_core nvmem_apple_efuses pinctrl_apple_gpio apple_isp apple_dcp videobuf2_dma_sg mux_core spi_apple [   38.203300]  videobuf2_memops i2c_pasemi_platform snd_soc_apple_mca videobuf2_v4l2 videodev clk_apple_nco videobuf2_common snd_pcm_dmaengine adpdrm asahi apple_admac adpdrm_mipi drm_dma_helper pwm_apple i2c_pasemi_core drm_display_helper mc cec apple_dart ofpart apple_soc_cpufreq leds_pwm phram [   38.217677] CPU: 7 UID: 1000 PID: 2362 Comm: gst-launch-1.0 Tainted: G        W           6.17.6+ #asahi-dev PREEMPT(full) [   38.219040] Tainted: [W]=WARN [   38.219398] Hardware name: Apple MacBook Pro (13-inch, M2, 2022) (DT) [   38.220213] pstate: 21400005 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) [   38.221088] pc : drm_gem_mmap_obj+0x1f8/0x210 [   38.221643] lr : drm_gem_mmap_obj+0x78/0x210 [   38.222178] sp : ffffc0008dc678e0 [   38.222579] x29: ffffc0008dc678e0 x28: 0000000000042a97 x27: ffff8000b701b480 [   38.223465] x26: 00000000000000fb x25: ffffc0008dc67d20 x24: ffffc0008dc67968 [   38.224402] x23: ffff8000e3ca5600 x22: ffff8000265b7800 x21: ffff80003000c0c0 [   38.225279] x20: 0000000000000000 x19: ffff8000b68c5200 x18: ffffc0008dc67968 [   38.226151] x17: 0000000000000000 x16: 0000000000000000 x15: ffffc000810a30a8 [   38.227042] x14: 00007fff637effff x13: 00005555de91ffff x12: 00007fff63293fff [   38.227942] x11: 0000000000000000 x10: ffff8000184ecf08 x9 : ffffc0007a1900c8 [   38.228824] x8 : ffffc0008dc67968 x7 : 0000000000000012 x6 : ffffc0015cf1c000 [   38.229703] x5 : ffffc0008dc676a0 x4 : ffffc00081a27dc0 x3 : 0000000000000038 [   38.230607] x2 : 0000000000000003 x1 : 0000000000000003 x0 : 00000000100000fb [   38.231488] Call trace: [   38.231806]  drm_gem_mmap_obj+0x1f8/0x210 (P) [   38.232342]  drm_gem_mmap+0x140/0x260 [   38.232813]  __mmap_region+0x488/0x9a0 [   38.233277]  mmap_region+0xd0/0x148 [   38.233703]  do_mmap+0x350/0x5c0 [   38.234148]  vm_mmap_pgoff+0x14c/0x200 [   38.234612]  ksys_mmap_pgoff+0x150/0x208 [   38.235107]  __arm64_sys_mmap+0x34/0x50 [   38.235611]  invoke_syscall+0x50/0x120 [   38.236075]  el0_svc_common.constprop.0+0x48/0xf0 [   38.236680]  do_el0_svc+0x24/0x38 [   38.237113]  el0_svc+0x38/0x168 [   38.237507]  el0t_64_sync_handler+0xa0/0xe8 [   38.238034]  el0t_64_sync+0x198/0x1a0 [   38.238491] ---[ end trace 0000000000000000 ]---  There were discussions in [1] at the end of 2023 that mmap() on imported ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46312","epss":0.00114,"percentile":0.01637,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-46312","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46312","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1a1360264f699521e001e7739009ee3ee3c6a4f5","https://git.kernel.org/stable/c/21fade52ab9fb13368a5709e60b0d9909197aeae","https://git.kernel.org/stable/c/7254b31a13aaa0c2c0f9ffbc335b718656117ff4","https://git.kernel.org/stable/c/b4cf91658a636618f1437beec971dec25dec28eb","https://git.kernel.org/stable/c/feb17524aa4ec337749344be0db52b88663e25ab"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: videobuf2: Set vma_flags in vb2_dma_sg_mmap\n\nvb2_dma_contig sets VMA flags VM_DONTEXPAND and VM_DONTDUMP and I do not\nsee a reason why vb2_dma_sg should behave differently. This avoids\nhitting `WARN_ON(!(vma->vm_flags & VM_DONTEXPAND));` in\ndrm_gem_mmap_obj() during mmap() of an imported dma-buf from the out of\ntree Apple ISP camera capture driver which uses vb2_dma_sg_memops.\n\ngst-launch-1.0 v4l2src ! gtk4paintablesink\n\n[   38.201528] ------------[ cut here ]------------\n[   38.202135] WARNING: CPU: 7 PID: 2362 at drivers/gpu/drm/drm_gem.c:1144 drm_gem_mmap_obj+0x1f8/0x210\n[   38.203278] Modules linked in: rfcomm snd_seq_dummy snd_hrtimer\nsnd_seq snd_seq_device uinput nf_conntrack_netbios_ns\nnf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib\nnft_reject_inet nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat\nnf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables qrtr bnep\nnls_ascii i2c_dev loop fuse dm_multipath nfnetlink brcmfmac_wcc\nhid_magicmouse hci_bcm4377 brcmfmac brcmutil bluetooth ecdh_generic\ncfg80211 ecc btrfs xor xor_neon rfkill hid_apple raid6_pq joydev\naop_als apple_nvmem_spmi industrialio snd_soc_aop apple_z2\nsnd_soc_cs42l84 tps6598x snd_soc_tas2764 macsmc_reboot spi_nor\nmacsmc_hwmon rtc_macsmc gpio_macsmc macsmc_power regmap_spmi\nmacsmc_input dockchannel_hid panel_summit appledrm nvme_apple dwc3\nsnd_soc_macaudio drm_client_lib nvme_core phy_apple_atc hwmon\napple_sart apple_dockchannel macsmc apple_rtkit_helper\nspmi_apple_controller aop apple_wdt mfd_core nvmem_apple_efuses\npinctrl_apple_gpio apple_isp apple_dcp videobuf2_dma_sg mux_core\nspi_apple\n[   38.203300]  videobuf2_memops i2c_pasemi_platform snd_soc_apple_mca videobuf2_v4l2 videodev clk_apple_nco videobuf2_common snd_pcm_dmaengine adpdrm asahi apple_admac adpdrm_mipi drm_dma_helper pwm_apple i2c_pasemi_core drm_display_helper mc cec apple_dart ofpart apple_soc_cpufreq leds_pwm phram\n[   38.217677] CPU: 7 UID: 1000 PID: 2362 Comm: gst-launch-1.0 Tainted: G        W           6.17.6+ #asahi-dev PREEMPT(full)\n[   38.219040] Tainted: [W]=WARN\n[   38.219398] Hardware name: Apple MacBook Pro (13-inch, M2, 2022) (DT)\n[   38.220213] pstate: 21400005 (nzCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n[   38.221088] pc : drm_gem_mmap_obj+0x1f8/0x210\n[   38.221643] lr : drm_gem_mmap_obj+0x78/0x210\n[   38.222178] sp : ffffc0008dc678e0\n[   38.222579] x29: ffffc0008dc678e0 x28: 0000000000042a97 x27: ffff8000b701b480\n[   38.223465] x26: 00000000000000fb x25: ffffc0008dc67d20 x24: ffffc0008dc67968\n[   38.224402] x23: ffff8000e3ca5600 x22: ffff8000265b7800 x21: ffff80003000c0c0\n[   38.225279] x20: 0000000000000000 x19: ffff8000b68c5200 x18: ffffc0008dc67968\n[   38.226151] x17: 0000000000000000 x16: 0000000000000000 x15: ffffc000810a30a8\n[   38.227042] x14: 00007fff637effff x13: 00005555de91ffff x12: 00007fff63293fff\n[   38.227942] x11: 0000000000000000 x10: ffff8000184ecf08 x9 : ffffc0007a1900c8\n[   38.228824] x8 : ffffc0008dc67968 x7 : 0000000000000012 x6 : ffffc0015cf1c000\n[   38.229703] x5 : ffffc0008dc676a0 x4 : ffffc00081a27dc0 x3 : 0000000000000038\n[   38.230607] x2 : 0000000000000003 x1 : 0000000000000003 x0 : 00000000100000fb\n[   38.231488] Call trace:\n[   38.231806]  drm_gem_mmap_obj+0x1f8/0x210 (P)\n[   38.232342]  drm_gem_mmap+0x140/0x260\n[   38.232813]  __mmap_region+0x488/0x9a0\n[   38.233277]  mmap_region+0xd0/0x148\n[   38.233703]  do_mmap+0x350/0x5c0\n[   38.234148]  vm_mmap_pgoff+0x14c/0x200\n[   38.234612]  ksys_mmap_pgoff+0x150/0x208\n[   38.235107]  __arm64_sys_mmap+0x34/0x50\n[   38.235611]  invoke_syscall+0x50/0x120\n[   38.236075]  el0_svc_common.constprop.0+0x48/0xf0\n[   38.236680]  do_el0_svc+0x24/0x38\n[   38.237113]  el0_svc+0x38/0x168\n[   38.237507]  el0t_64_sync_handler+0xa0/0xe8\n[   38.238034]  el0t_64_sync+0x198/0x1a0\n[   38.238491] ---[ end trace 0000000000000000 ]---\n\nThere were discussions in [1] at the end of 2023 that mmap() on imported\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46312","epss":0.00114,"percentile":0.01637,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46312","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46324","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46324","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: use list_del_rcu for netlink hooks  nft_netdev_unregister_hooks and __nft_unregister_flowtable_net_hooks need to use list_del_rcu(), this list can be walked by concurrent dumpers.  Add a new helper and use it consistently.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46324","epss":0.00119,"percentile":0.01958,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.091035},"relatedVulnerabilities":[{"id":"CVE-2026-46324","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46324","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0bd93ce4f3c35e845532184331d7917d7e562c80","https://git.kernel.org/stable/c/0f33e8ad6ac563ae2233dd7f75884e0ee010521d","https://git.kernel.org/stable/c/f3224ee463f8f6f6ced7dcdf6081add4f8128527"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: use list_del_rcu for netlink hooks\n\nnft_netdev_unregister_hooks and __nft_unregister_flowtable_net_hooks need\nto use list_del_rcu(), this list can be walked by concurrent dumpers.\n\nAdd a new helper and use it consistently.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46324","epss":0.00119,"percentile":0.01958,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46324","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-46330","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46330","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Revert \"net/smc: Introduce TCP ULP support\"  This reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40.  As reported by Al Viro, the TCP ULP support for SMC is fundamentally broken. The implementation attempts to convert an active TCP socket into an SMC socket by modifying the underlying `struct file`, dentry, and inode in-place, which violates core VFS invariants that assume these structures are immutable for an open file, creating a risk of use after free errors and general system instability.  Given the severity of this design flaw and the fact that cleaner alternatives (e.g., LD_PRELOAD, BPF) exist for legacy application transparency, the correct course of action is to remove this feature entirely.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46330","epss":0.00112,"percentile":0.01524,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46330","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08567999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-46330","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46330","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6c505d95c69e27dbf28fea29dc84d2498d69515c","https://git.kernel.org/stable/c/df31a6b0a3057e66994ad6ccf5d95b9b9514f033"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"net/smc: Introduce TCP ULP support\"\n\nThis reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40.\n\nAs reported by Al Viro, the TCP ULP support for SMC is fundamentally\nbroken. The implementation attempts to convert an active TCP socket\ninto an SMC socket by modifying the underlying `struct file`, dentry,\nand inode in-place, which violates core VFS invariants that assume\nthese structures are immutable for an open file, creating a risk of\nuse after free errors and general system instability.\n\nGiven the severity of this design flaw and the fact that cleaner\nalternatives (e.g., LD_PRELOAD, BPF) exist for legacy application\ntransparency, the correct course of action is to remove this feature\nentirely.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-46330","epss":0.00112,"percentile":0.01524,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-46330","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-46330","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-52936","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52936","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: jitterentropy - replace long-held spinlock with mutex  jent_kcapi_random() serializes the shared jitterentropy state, but it currently holds a spinlock across the jent_read_entropy() call. That path performs expensive jitter collection and SHA3 conditioning, so parallel readers can trigger stalls as contending waiters spin for the same lock.  To prevent non-preemptible lock hold, replace rng->jent_lock with a mutex so contended readers sleep instead of spinning on a shared lock held across expensive entropy generation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52936","epss":0.00114,"percentile":0.0163,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-52936","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52936","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/01d798e9feb30212952d4e992801ba6bd6a82351","https://git.kernel.org/stable/c/18216b8ab6904753eaf31baf453cb02ecd202ba4","https://git.kernel.org/stable/c/4c03e6eb98443dc4d6d422a9780034a5b75376b4","https://git.kernel.org/stable/c/ec427dc5286da1ed08f2d510e2147a7581b0cb02","https://git.kernel.org/stable/c/ff734dbd9e2432601a6dcd167cfb0bf8a36d1880"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: jitterentropy - replace long-held spinlock with mutex\n\njent_kcapi_random() serializes the shared jitterentropy state, but it\ncurrently holds a spinlock across the jent_read_entropy() call. That\npath performs expensive jitter collection and SHA3 conditioning, so\nparallel readers can trigger stalls as contending waiters spin for\nthe same lock.\n\nTo prevent non-preemptible lock hold, replace rng->jent_lock with a\nmutex so contended readers sleep instead of spinning on a shared lock\nheld across expensive entropy generation.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52936","epss":0.00114,"percentile":0.0163,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52936","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-52937","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52937","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR  In the SIOCGIFHWADDR path, tap_ioctl() copies 16 bytes of an uninitialised on-stack struct sockaddr_storage to userspace via ifr_hwaddr, but netif_get_mac_address() only writes sa_family and dev->addr_len (6 for Ethernet) bytes, leaving sa_data[6..13] uninitialised.  Those 8 trailing bytes leak kernel stack contents; SIOCGIFHWADDR on a macvtap chardev returns kernel .text and direct-map pointers, defeating KASLR.  Initialise ss at declaration.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52937","epss":0.00112,"percentile":0.01545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52937","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-52937","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52937","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/05305e832be7b9d65b2b72caacf7d850b3942b2a","https://git.kernel.org/stable/c/719007c3492f0f1f9e9cdbed8ac45ba45bb13eeb","https://git.kernel.org/stable/c/bddc09212c24934643bd44fc794748d2bbb3b6cd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR\n\nIn the SIOCGIFHWADDR path, tap_ioctl() copies 16 bytes of an\nuninitialised on-stack struct sockaddr_storage to userspace via\nifr_hwaddr, but netif_get_mac_address() only writes sa_family and\ndev->addr_len (6 for Ethernet) bytes, leaving sa_data[6..13] uninitialised.\n\nThose 8 trailing bytes leak kernel stack contents; SIOCGIFHWADDR on a\nmacvtap chardev returns kernel .text and direct-map pointers, defeating\nKASLR.\n\nInitialise ss at declaration.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52937","epss":0.00112,"percentile":0.01545,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52937","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52937","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-52944","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52944","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE  FSCTL_SET_SPARSE in fsctl_set_sparse() modifies the file's sparse attribute and saves it through xattr without any permission checks.  This exposes two issues:  1) A client on a read-only share can change the sparse attribute    on files it opened, even though the share is read-only.    Other FSCTL write operations already check    test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE),    but FSCTL_SET_SPARSE does not.  2) Even on writable shares, clients without FILE_WRITE_DATA or    FILE_WRITE_ATTRIBUTES access should not modify the sparse    attribute. Similar handle-level checks exist in other functions    but are missing here.  Add both share-level writable check and per-handle access check. Use goto out on error to avoid leaking file references.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52944","epss":0.00121,"percentile":0.02201,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-52944","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52944","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3127a884525dc8ca4def73254bfcd3ccef0bf812","https://git.kernel.org/stable/c/aef151bcfa494bfe983669de2726734b534adb73","https://git.kernel.org/stable/c/cc57232cae23c0df91b4a59d0f519141ce9b5b02","https://git.kernel.org/stable/c/de9eb0b44fa9123170e6245b49638e0e453c10f8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE\n\nFSCTL_SET_SPARSE in fsctl_set_sparse() modifies the file's sparse\nattribute and saves it through xattr without any permission checks.\n\nThis exposes two issues:\n\n1) A client on a read-only share can change the sparse attribute\n   on files it opened, even though the share is read-only.\n   Other FSCTL write operations already check\n   test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE),\n   but FSCTL_SET_SPARSE does not.\n\n2) Even on writable shares, clients without FILE_WRITE_DATA or\n   FILE_WRITE_ATTRIBUTES access should not modify the sparse\n   attribute. Similar handle-level checks exist in other functions\n   but are missing here.\n\nAdd both share-level writable check and per-handle access check.\nUse goto out on error to avoid leaking file references.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52944","epss":0.00121,"percentile":0.02201,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52944","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-52956","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52956","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()  In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct is accessed. This happens without any guarantee that the buffer is large enough to hold this struct. The function parameter ciphertext_len represents the length of the ciphertext to decrypt and is guaranteed to be at most the remaining size of the allocated buffer p. However, this value is not necessarily greater than sizeof(ceph_x_encrypt_header). E.g., a message frame of type FRAME_TAG_AUTH_REPLY_MORE, that is just as long to hold the ciphertext at its end with a ciphertext_len of 8 or less, can trigger an out-of-bounds memory access when accessing hdr->magic.  This patch fixes the issue by adding a check to ensure that the decrypted plaintext in the buffer is large enough to represent at least the ceph_x_encrypt_header.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52956","epss":0.00359,"percentile":0.2916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52956","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26925},"relatedVulnerabilities":[{"id":"CVE-2026-52956","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52956","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/821365487aa58d06bda65c676ba215d506ba9768","https://git.kernel.org/stable/c/c7e9b53aebe401970f1b5f5a01b4e021b18e8bb2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix potential out-of-bounds access in __ceph_x_decrypt()\n\nIn __ceph_x_decrypt(), a part of the buffer p is interpreted as a\nceph_x_encrypt_header, and the magic field of this struct is accessed.\nThis happens without any guarantee that the buffer is large enough to\nhold this struct. The function parameter ciphertext_len represents the\nlength of the ciphertext to decrypt and is guaranteed to be at most the\nremaining size of the allocated buffer p. However, this value is not\nnecessarily greater than sizeof(ceph_x_encrypt_header). E.g., a message\nframe of type FRAME_TAG_AUTH_REPLY_MORE, that is just as long to hold\nthe ciphertext at its end with a ciphertext_len of 8 or less, can\ntrigger an out-of-bounds memory access when accessing hdr->magic.\n\nThis patch fixes the issue by adding a check to ensure that the\ndecrypted plaintext in the buffer is large enough to represent at least\nthe ceph_x_encrypt_header.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52956","epss":0.00359,"percentile":0.2916,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52956","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52956","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-52961","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52961","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size  The generic/642 test-case can reproduce the kernel crash:  [40243.605254] ------------[ cut here ]------------ [40243.605956] kernel BUG at fs/ceph/xattr.c:918! [40243.607142] Oops: invalid opcode: 0000 [#1] SMP PTI [40243.608067] CPU: 7 UID: 0 PID: 498762 Comm: kworker/7:1 Not tainted 7.0.0-rc7+ #3 PREEMPT(full) [40243.609700] Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [40243.611820] Workqueue: ceph-msgr ceph_con_workfn [40243.612715] RIP: 0010:__ceph_build_xattrs_blob+0x1b8/0x1e0 [40243.613731] Code: 0f 84 82 fe ff ff e9 cf 8e 56 ff 48 8d 65 e8 31 c0 5b 41 5c 41 5d 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 c3 cc cc cc cc <0f> 0b 4c 8b 62 08 41 8b 85 24 07 00 00 49 83 c4 04 41 89 44 24 fc [40243.616888] RSP: 0018:ffffcc80c4d4b688 EFLAGS: 00010287 [40243.617773] RAX: 0000000000010026 RBX: 0000000000000001 RCX: 0000000000000000 [40243.618928] RDX: ffff8a773798dee0 RSI: 0000000000000000 RDI: 0000000000000000 [40243.620158] RBP: ffffcc80c4d4b6a0 R08: 0000000000000000 R09: 0000000000000000 [40243.621573] R10: 0000000000000000 R11: 0000000000000000 R12: ffff8a75f3b58000 [40243.622907] R13: ffff8a75f3b58000 R14: 0000000000000080 R15: 000000000000bffd [40243.624054] FS:  0000000000000000(0000) GS:ffff8a787d1b4000(0000) knlGS:0000000000000000 [40243.625331] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [40243.626269] CR2: 000072f390b623c0 CR3: 000000011c02a003 CR4: 0000000000372ef0 [40243.627408] Call Trace: [40243.627839]  <TASK> [40243.628188]  __prep_cap+0x3fd/0x4a0 [40243.628789]  ? do_raw_spin_unlock+0x4e/0xe0 [40243.629474]  ceph_check_caps+0x46a/0xc80 [40243.630094]  ? __lock_acquire+0x4a2/0x2650 [40243.630773]  ? find_held_lock+0x31/0x90 [40243.631347]  ? handle_cap_grant+0x79f/0x1060 [40243.632068]  ? lock_release+0xd9/0x300 [40243.632696]  ? __mutex_unlock_slowpath+0x3e/0x340 [40243.633429]  ? lock_release+0xd9/0x300 [40243.634052]  handle_cap_grant+0xcf6/0x1060 [40243.634745]  ceph_handle_caps+0x122b/0x2110 [40243.635415]  mds_dispatch+0x5bd/0x2160 [40243.636034]  ? ceph_con_process_message+0x65/0x190 [40243.636828]  ? lock_release+0xd9/0x300 [40243.637431]  ceph_con_process_message+0x7a/0x190 [40243.638184]  ? kfree+0x311/0x4f0 [40243.638749]  ? kfree+0x311/0x4f0 [40243.639268]  process_message+0x16/0x1a0 [40243.639915]  ? sg_free_table+0x39/0x90 [40243.640572]  ceph_con_v2_try_read+0xf58/0x2120 [40243.641255]  ? lock_acquire+0xc8/0x300 [40243.641863]  ceph_con_workfn+0x151/0x820 [40243.642493]  process_one_work+0x22f/0x630 [40243.643093]  ? process_one_work+0x254/0x630 [40243.643770]  worker_thread+0x1e2/0x400 [40243.644332]  ? __pfx_worker_thread+0x10/0x10 [40243.645020]  kthread+0x109/0x140 [40243.645560]  ? __pfx_kthread+0x10/0x10 [40243.646125]  ret_from_fork+0x3f8/0x480 [40243.646752]  ? __pfx_kthread+0x10/0x10 [40243.647316]  ? __pfx_kthread+0x10/0x10 [40243.647919]  ret_from_fork_asm+0x1a/0x30 [40243.648556]  </TASK> [40243.648902] Modules linked in: overlay hctr2 libpolyval chacha libchacha adiantum libnh libpoly1305 essiv intel_rapl_msr intel_rapl_common intel_uncore_frequency_common skx_edac_common nfit kvm_intel kvm irqbypass joydev ghash_clmulni_intel aesni_intel rapl input_leds mac_hid psmouse vga16fb serio_raw vgastate floppy i2c_piix4 pata_acpi bochs qemu_fw_cfg i2c_smbus sch_fq_codel rbd dm_crypt msr parport_pc ppdev lp parport efi_pstore [40243.654766] ---[ end trace 0000000000000000 ]---  Commit d93231a6bc8a (\"ceph: prevent a client from exceeding the MDS maximum xattr size\") moved the required_blob_size computation to before the __build_xattrs() call, introducing a race.  __build_xattrs() releases and reacquires i_ceph_lock during execution. In that window, handle_cap_grant() may update i_xattrs.blob with a newer MDS-provided blob and bump i_xattrs.version.  When __bui ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52961","epss":0.00144,"percentile":0.04001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52961","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0756},"relatedVulnerabilities":[{"id":"CVE-2026-52961","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52961","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0c22d9511cbde746622f8e4c11aaa63fe76d45f9","https://git.kernel.org/stable/c/368d21ae9081c93497b1c8163bed3eddcb2443ff","https://git.kernel.org/stable/c/7eb72425c4e3234926502eb262f9d6193ccd572c","https://git.kernel.org/stable/c/d5bd8b4e39cfa8b087448adcd48088065cd629d5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size\n\nThe generic/642 test-case can reproduce the kernel crash:\n\n[40243.605254] ------------[ cut here ]------------\n[40243.605956] kernel BUG at fs/ceph/xattr.c:918!\n[40243.607142] Oops: invalid opcode: 0000 [#1] SMP PTI\n[40243.608067] CPU: 7 UID: 0 PID: 498762 Comm: kworker/7:1 Not tainted 7.0.0-rc7+ #3 PREEMPT(full)\n[40243.609700] Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[40243.611820] Workqueue: ceph-msgr ceph_con_workfn\n[40243.612715] RIP: 0010:__ceph_build_xattrs_blob+0x1b8/0x1e0\n[40243.613731] Code: 0f 84 82 fe ff ff e9 cf 8e 56 ff 48 8d 65 e8 31 c0 5b 41 5c 41 5d 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 c3 cc cc cc cc <0f> 0b 4c 8b 62 08 41 8b 85 24 07 00 00 49 83 c4 04 41 89 44 24 fc\n[40243.616888] RSP: 0018:ffffcc80c4d4b688 EFLAGS: 00010287\n[40243.617773] RAX: 0000000000010026 RBX: 0000000000000001 RCX: 0000000000000000\n[40243.618928] RDX: ffff8a773798dee0 RSI: 0000000000000000 RDI: 0000000000000000\n[40243.620158] RBP: ffffcc80c4d4b6a0 R08: 0000000000000000 R09: 0000000000000000\n[40243.621573] R10: 0000000000000000 R11: 0000000000000000 R12: ffff8a75f3b58000\n[40243.622907] R13: ffff8a75f3b58000 R14: 0000000000000080 R15: 000000000000bffd\n[40243.624054] FS:  0000000000000000(0000) GS:ffff8a787d1b4000(0000) knlGS:0000000000000000\n[40243.625331] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[40243.626269] CR2: 000072f390b623c0 CR3: 000000011c02a003 CR4: 0000000000372ef0\n[40243.627408] Call Trace:\n[40243.627839]  <TASK>\n[40243.628188]  __prep_cap+0x3fd/0x4a0\n[40243.628789]  ? do_raw_spin_unlock+0x4e/0xe0\n[40243.629474]  ceph_check_caps+0x46a/0xc80\n[40243.630094]  ? __lock_acquire+0x4a2/0x2650\n[40243.630773]  ? find_held_lock+0x31/0x90\n[40243.631347]  ? handle_cap_grant+0x79f/0x1060\n[40243.632068]  ? lock_release+0xd9/0x300\n[40243.632696]  ? __mutex_unlock_slowpath+0x3e/0x340\n[40243.633429]  ? lock_release+0xd9/0x300\n[40243.634052]  handle_cap_grant+0xcf6/0x1060\n[40243.634745]  ceph_handle_caps+0x122b/0x2110\n[40243.635415]  mds_dispatch+0x5bd/0x2160\n[40243.636034]  ? ceph_con_process_message+0x65/0x190\n[40243.636828]  ? lock_release+0xd9/0x300\n[40243.637431]  ceph_con_process_message+0x7a/0x190\n[40243.638184]  ? kfree+0x311/0x4f0\n[40243.638749]  ? kfree+0x311/0x4f0\n[40243.639268]  process_message+0x16/0x1a0\n[40243.639915]  ? sg_free_table+0x39/0x90\n[40243.640572]  ceph_con_v2_try_read+0xf58/0x2120\n[40243.641255]  ? lock_acquire+0xc8/0x300\n[40243.641863]  ceph_con_workfn+0x151/0x820\n[40243.642493]  process_one_work+0x22f/0x630\n[40243.643093]  ? process_one_work+0x254/0x630\n[40243.643770]  worker_thread+0x1e2/0x400\n[40243.644332]  ? __pfx_worker_thread+0x10/0x10\n[40243.645020]  kthread+0x109/0x140\n[40243.645560]  ? __pfx_kthread+0x10/0x10\n[40243.646125]  ret_from_fork+0x3f8/0x480\n[40243.646752]  ? __pfx_kthread+0x10/0x10\n[40243.647316]  ? __pfx_kthread+0x10/0x10\n[40243.647919]  ret_from_fork_asm+0x1a/0x30\n[40243.648556]  </TASK>\n[40243.648902] Modules linked in: overlay hctr2 libpolyval chacha libchacha adiantum libnh libpoly1305 essiv intel_rapl_msr intel_rapl_common intel_uncore_frequency_common skx_edac_common nfit kvm_intel kvm irqbypass joydev ghash_clmulni_intel aesni_intel rapl input_leds mac_hid psmouse vga16fb serio_raw vgastate floppy i2c_piix4 pata_acpi bochs qemu_fw_cfg i2c_smbus sch_fq_codel rbd dm_crypt msr parport_pc ppdev lp parport efi_pstore\n[40243.654766] ---[ end trace 0000000000000000 ]---\n\nCommit d93231a6bc8a (\"ceph: prevent a client from exceeding the MDS\nmaximum xattr size\") moved the required_blob_size computation to before\nthe __build_xattrs() call, introducing a race.\n\n__build_xattrs() releases and reacquires i_ceph_lock during execution.\nIn that window, handle_cap_grant() may update i_xattrs.blob with a\nnewer MDS-provided blob and bump i_xattrs.version.  When\n__bui\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52961","epss":0.00144,"percentile":0.04001,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52961","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52961","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-52988","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52988","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase  Publish new hooks in the list into the basechain/flowtable using splice_list_rcu() to ensure netlink dump list traversal via rcu is safe while concurrent ruleset update is going on.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52988","epss":0.00122,"percentile":0.02293,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08906},"relatedVulnerabilities":[{"id":"CVE-2026-52988","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52988","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1346be9379639c30877083b12747d4eacb83c24f","https://git.kernel.org/stable/c/a6134e62dba2ea4f760b29d5226907f447c92400"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: join hook list via splice_list_rcu() in commit phase\n\nPublish new hooks in the list into the basechain/flowtable using\nsplice_list_rcu() to ensure netlink dump list traversal via rcu is safe\nwhile concurrent ruleset update is going on.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52988","epss":0.00122,"percentile":0.02293,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52988","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-52990","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52990","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fsnotify: fix inode reference leak in fsnotify_recalc_mask()  fsnotify_recalc_mask() fails to handle the return value of __fsnotify_recalc_mask(), which may return an inode pointer that needs to be released via fsnotify_drop_object() when the connector's HAS_IREF flag transitions from set to cleared.  This manifests as a hung task with the following call trace:    INFO: task umount:1234 blocked for more than 120 seconds.   Call Trace:    __schedule    schedule    fsnotify_sb_delete    generic_shutdown_super    kill_anon_super    cleanup_mnt    task_work_run    do_exit    do_group_exit  The race window that triggers the iref leak:    Thread A (adding mark)              Thread B (removing mark)   ──────────────────────              ────────────────────────   fsnotify_add_mark_locked():     fsnotify_add_mark_list():       spin_lock(conn->lock)       add mark_B(evictable) to list       spin_unlock(conn->lock)     return      /* ---- gap: no lock held ---- */                                        fsnotify_detach_mark(mark_A):                                         spin_lock(mark_A->lock)                                         clear ATTACHED flag on mark_A                                         spin_unlock(mark_A->lock)                                         fsnotify_put_mark(mark_A)      fsnotify_recalc_mask():       spin_lock(conn->lock)       __fsnotify_recalc_mask():         /* mark_A skipped: ATTACHED cleared */         /* only mark_B(evictable) remains */         want_iref = false         has_iref = true  /* not yet cleared */         -> HAS_IREF transitions true -> false         -> returns inode pointer       spin_unlock(conn->lock)       /* BUG: return value discarded!        * iput() and fsnotify_put_sb_watched_objects()        * are never called */  Fix this by deferring the transition true -> false of HAS_IREF flag from fsnotify_recalc_mask() (Thread A) to fsnotify_put_mark() (thread B).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52990","epss":0.00127,"percentile":0.02723,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52990","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2026-52990","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52990","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4aca914ac152f5d055ddcb36704d1e539ac08977","https://git.kernel.org/stable/c/5c80289503da3658e3df80280598c68d181eadbd","https://git.kernel.org/stable/c/8c8afa6444e6bdc145d2bf2f3aeeca6da3e36b42","https://git.kernel.org/stable/c/b740cc86816bbc87902ae9db74cd21abde3c8d63"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfsnotify: fix inode reference leak in fsnotify_recalc_mask()\n\nfsnotify_recalc_mask() fails to handle the return value of\n__fsnotify_recalc_mask(), which may return an inode pointer that needs\nto be released via fsnotify_drop_object() when the connector's HAS_IREF\nflag transitions from set to cleared.\n\nThis manifests as a hung task with the following call trace:\n\n  INFO: task umount:1234 blocked for more than 120 seconds.\n  Call Trace:\n   __schedule\n   schedule\n   fsnotify_sb_delete\n   generic_shutdown_super\n   kill_anon_super\n   cleanup_mnt\n   task_work_run\n   do_exit\n   do_group_exit\n\nThe race window that triggers the iref leak:\n\n  Thread A (adding mark)              Thread B (removing mark)\n  ──────────────────────              ────────────────────────\n  fsnotify_add_mark_locked():\n    fsnotify_add_mark_list():\n      spin_lock(conn->lock)\n      add mark_B(evictable) to list\n      spin_unlock(conn->lock)\n    return\n\n    /* ---- gap: no lock held ---- */\n\n                                      fsnotify_detach_mark(mark_A):\n                                        spin_lock(mark_A->lock)\n                                        clear ATTACHED flag on mark_A\n                                        spin_unlock(mark_A->lock)\n                                        fsnotify_put_mark(mark_A)\n\n    fsnotify_recalc_mask():\n      spin_lock(conn->lock)\n      __fsnotify_recalc_mask():\n        /* mark_A skipped: ATTACHED cleared */\n        /* only mark_B(evictable) remains */\n        want_iref = false\n        has_iref = true  /* not yet cleared */\n        -> HAS_IREF transitions true -> false\n        -> returns inode pointer\n      spin_unlock(conn->lock)\n      /* BUG: return value discarded!\n       * iput() and fsnotify_put_sb_watched_objects()\n       * are never called */\n\nFix this by deferring the transition true -> false of HAS_IREF flag from\nfsnotify_recalc_mask() (Thread A) to fsnotify_put_mark() (thread B).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52990","epss":0.00127,"percentile":0.02723,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52990","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52990","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-52991","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52991","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sched/psi: fix race between file release and pressure write  A potential race condition exists between pressure write and cgroup file release regarding the priv member of struct kernfs_open_file, which triggers the uaf reported in [1].  Consider the following scenario involving execution on two separate CPUs:     CPU0\t\t\t\t\tCPU1    ====\t\t\t\t\t==== \t\t\t\t\tvfs_rmdir() \t\t\t\t\tkernfs_iop_rmdir() \t\t\t\t\tcgroup_rmdir() \t\t\t\t\tcgroup_kn_lock_live() \t\t\t\t\tcgroup_destroy_locked() \t\t\t\t\tcgroup_addrm_files() \t\t\t\t\tcgroup_rm_file() \t\t\t\t\tkernfs_remove_by_name() \t\t\t\t\tkernfs_remove_by_name_ns()  vfs_write()\t\t\t\t__kernfs_remove()  new_sync_write()\t\t\tkernfs_drain()  kernfs_fop_write_iter()\t\tkernfs_drain_open_files()  cgroup_file_write()\t\t\tkernfs_release_file()  pressure_write()\t\t\tcgroup_file_release()  ctx = of->priv; \t\t\t\t\tkfree(ctx);  \t\t\t\t\tof->priv = NULL; \t\t\t\t\tcgroup_kn_unlock()  cgroup_kn_lock_live()  cgroup_get(cgrp)  cgroup_kn_unlock()  if (ctx->psi.trigger)  // here, trigger uaf for ctx, that is of->priv  The cgroup_rmdir() is protected by the cgroup_mutex, it also safeguards the memory deallocation of of->priv performed within cgroup_file_release(). However, the operations involving of->priv executed within pressure_write() are not entirely covered by the protection of cgroup_mutex. Consequently, if the code in pressure_write(), specifically the section handling the ctx variable executes after cgroup_file_release() has completed, a uaf vulnerability involving of->priv is triggered.  Therefore, the issue can be resolved by extending the scope of the cgroup_mutex lock within pressure_write() to encompass all code paths involving of->priv, thereby properly synchronizing the race condition occurring between cgroup_file_release() and pressure_write().  And, if an live kn lock can be successfully acquired while executing the pressure write operation, it indicates that the cgroup deletion process has not yet reached its final stage; consequently, the priv pointer within open_file cannot be NULL. Therefore, the operation to retrieve the ctx value must be moved to a point *after* the live kn lock has been successfully acquired.  In another situation, specifically after entering cgroup_kn_lock_live() but before acquiring cgroup_mutex, there exists a different class of race condition:  CPU0: write memory.pressure               CPU1: write cgroup.pressure=0 ===========================\t\t  =============================  kernfs_fop_write_iter()  kernfs_get_active_of(of)  pressure_write()    cgroup_kn_lock_live(memory.pressure)      cgroup_tryget(cgrp)      kernfs_break_active_protection(kn)      ... blocks on cgroup_mutex                                       \t  cgroup_pressure_write()                                      \t  cgroup_kn_lock_live(cgroup.pressure)                                      \t  cgroup_file_show(memory.pressure, false)                                      \t    kernfs_show(false)                                      \t      kernfs_drain_open_files()                                      \t        cgroup_file_release(of)                                      \t          kfree(ctx)                                      \t            of->priv = NULL                                      \t  cgroup_kn_unlock()     ... acquires cgroup_mutex    ctx = of->priv;        // may now be NULL    if (ctx->psi.trigger)  // NULL dereference  Consequently, there is a possibility that of->priv is NULL, the pressure write needs to check for this.  Now that the scope of the cgroup_mutex has been expanded, the original explicit cgroup_get/put operations are no longer necessary, this is because acquiring/releasing the live kn lock inherently executes a cgroup get/put operation.  [1] BUG: KASAN: slab-use-after-free in pressure_write+0xa4/0x210 kernel/cgroup/cgroup.c:4011 Call Trace:  pressure_write+0xa4/0x210 kernel/cgroup/cgroup.c:4011  cgroup_file_write+0x36f/0x790 kernel/cgroup/cgroup.c:43 ---truncated---","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52991","epss":0.00115,"percentile":0.01744,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52991","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-52991","cwe":"CWE-367","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08337499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-52991","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52991","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/03dc070fa0fc3cb4068693f468ccd5f8a7e58282","https://git.kernel.org/stable/c/a5b98009f16d8a5fb4a8ff9a193f5735515c38fa","https://git.kernel.org/stable/c/d4352c0709bfd38c752fccbde7fd72a82ac78f23","https://access.redhat.com/errata/RHSA-2026:57251","https://access.redhat.com/errata/RHSA-2026:57252","https://access.redhat.com/errata/RHSA-2026:57253","https://access.redhat.com/errata/RHSA-2026:57254","https://access.redhat.com/security/cve/CVE-2026-52991","https://bugzilla.redhat.com/show_bug.cgi?id=2492403","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52991.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/psi: fix race between file release and pressure write\n\nA potential race condition exists between pressure write and cgroup file\nrelease regarding the priv member of struct kernfs_open_file, which\ntriggers the uaf reported in [1].\n\nConsider the following scenario involving execution on two separate CPUs:\n\n   CPU0\t\t\t\t\tCPU1\n   ====\t\t\t\t\t====\n\t\t\t\t\tvfs_rmdir()\n\t\t\t\t\tkernfs_iop_rmdir()\n\t\t\t\t\tcgroup_rmdir()\n\t\t\t\t\tcgroup_kn_lock_live()\n\t\t\t\t\tcgroup_destroy_locked()\n\t\t\t\t\tcgroup_addrm_files()\n\t\t\t\t\tcgroup_rm_file()\n\t\t\t\t\tkernfs_remove_by_name()\n\t\t\t\t\tkernfs_remove_by_name_ns()\n vfs_write()\t\t\t\t__kernfs_remove()\n new_sync_write()\t\t\tkernfs_drain()\n kernfs_fop_write_iter()\t\tkernfs_drain_open_files()\n cgroup_file_write()\t\t\tkernfs_release_file()\n pressure_write()\t\t\tcgroup_file_release()\n ctx = of->priv;\n\t\t\t\t\tkfree(ctx);\n \t\t\t\t\tof->priv = NULL;\n\t\t\t\t\tcgroup_kn_unlock()\n cgroup_kn_lock_live()\n cgroup_get(cgrp)\n cgroup_kn_unlock()\n if (ctx->psi.trigger)  // here, trigger uaf for ctx, that is of->priv\n\nThe cgroup_rmdir() is protected by the cgroup_mutex, it also safeguards\nthe memory deallocation of of->priv performed within cgroup_file_release().\nHowever, the operations involving of->priv executed within pressure_write()\nare not entirely covered by the protection of cgroup_mutex. Consequently,\nif the code in pressure_write(), specifically the section handling the\nctx variable executes after cgroup_file_release() has completed, a uaf\nvulnerability involving of->priv is triggered.\n\nTherefore, the issue can be resolved by extending the scope of the\ncgroup_mutex lock within pressure_write() to encompass all code paths\ninvolving of->priv, thereby properly synchronizing the race condition\noccurring between cgroup_file_release() and pressure_write().\n\nAnd, if an live kn lock can be successfully acquired while executing\nthe pressure write operation, it indicates that the cgroup deletion\nprocess has not yet reached its final stage; consequently, the priv\npointer within open_file cannot be NULL. Therefore, the operation to\nretrieve the ctx value must be moved to a point *after* the live kn\nlock has been successfully acquired.\n\nIn another situation, specifically after entering cgroup_kn_lock_live()\nbut before acquiring cgroup_mutex, there exists a different class of\nrace condition:\n\nCPU0: write memory.pressure               CPU1: write cgroup.pressure=0\n===========================\t\t  =============================\n\nkernfs_fop_write_iter()\n kernfs_get_active_of(of)\n pressure_write()\n   cgroup_kn_lock_live(memory.pressure)\n     cgroup_tryget(cgrp)\n     kernfs_break_active_protection(kn)\n     ... blocks on cgroup_mutex\n\n                                     \t  cgroup_pressure_write()\n                                     \t  cgroup_kn_lock_live(cgroup.pressure)\n                                     \t  cgroup_file_show(memory.pressure, false)\n                                     \t    kernfs_show(false)\n                                     \t      kernfs_drain_open_files()\n                                     \t        cgroup_file_release(of)\n                                     \t          kfree(ctx)\n                                     \t            of->priv = NULL\n                                     \t  cgroup_kn_unlock()\n\n   ... acquires cgroup_mutex\n   ctx = of->priv;        // may now be NULL\n   if (ctx->psi.trigger)  // NULL dereference\n\nConsequently, there is a possibility that of->priv is NULL, the pressure\nwrite needs to check for this.\n\nNow that the scope of the cgroup_mutex has been expanded, the original\nexplicit cgroup_get/put operations are no longer necessary, this is\nbecause acquiring/releasing the live kn lock inherently executes a\ncgroup get/put operation.\n\n[1]\nBUG: KASAN: slab-use-after-free in pressure_write+0xa4/0x210 kernel/cgroup/cgroup.c:4011\nCall Trace:\n pressure_write+0xa4/0x210 kernel/cgroup/cgroup.c:4011\n cgroup_file_write+0x36f/0x790 kernel/cgroup/cgroup.c:43\n---truncated---","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-52991","epss":0.00115,"percentile":0.01744,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-52991","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-52991","cwe":"CWE-367","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-52991","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53000","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53000","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nat: use kfree_rcu to release ops  Florian Westphal says:  \"Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_ops that are used to register the callbacks.  However, in v5.14 I added the ability to dump the active netfilter hooks from userspace.  This code will peek back into the nf_hook_ops that are available at the tail of the pointer-array blob used by the datapath.  The nat hooks are special, because they are called indirectly from the central nat dispatcher hook. They are currently invisible to the nfnl hook dump subsystem though.  But once that changes the nat ops structures have to be deferred too.\"  Update nf_nat_register_fn() to deal with partial exposition of the hooks from error path which can be also an issue for nfnetlink_hook.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53000","epss":0.00129,"percentile":0.02914,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53000","cwe":"CWE-763","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-53000","cwe":"CWE-763","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09352499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-53000","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53000","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/32fdd2e38e7435a368d88f5977a7d6585ebc8b0e","https://git.kernel.org/stable/c/3c7511f38ab511b791196b13ae48bf4973bf7dfd","https://git.kernel.org/stable/c/6eda0d771f94267f73f57c94630aa47e90957915","https://access.redhat.com/errata/RHSA-2026:55445","https://access.redhat.com/errata/RHSA-2026:64808","https://access.redhat.com/security/cve/CVE-2026-53000","https://bugzilla.redhat.com/show_bug.cgi?id=2492273","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53000.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nat: use kfree_rcu to release ops\n\nFlorian Westphal says:\n\n\"Historically this is not an issue, even for normal base hooks: the data\npath doesn't use the original nf_hook_ops that are used to register the\ncallbacks.\n\nHowever, in v5.14 I added the ability to dump the active netfilter\nhooks from userspace.\n\nThis code will peek back into the nf_hook_ops that are available\nat the tail of the pointer-array blob used by the datapath.\n\nThe nat hooks are special, because they are called indirectly from\nthe central nat dispatcher hook. They are currently invisible to\nthe nfnl hook dump subsystem though.\n\nBut once that changes the nat ops structures have to be deferred too.\"\n\nUpdate nf_nat_register_fn() to deal with partial exposition of the hooks\nfrom error path which can be also an issue for nfnetlink_hook.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53000","epss":0.00129,"percentile":0.02914,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53000","cwe":"CWE-763","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-53000","cwe":"CWE-763","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53000","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53005","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53005","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  af_unix: Drop all SCM attributes for SOCKMAP.  SOCKMAP can hide inflight fd from AF_UNIX GC.  When a socket in SOCKMAP receives skb with inflight fd, sk_psock_verdict_data_ready() looks up the mapped socket and enqueue skb to its psock->ingress_skb.  Since neither the old nor the new GC can inspect the psock queue, the hidden skb leaks the inflight sockets.  Note that this cannot be detected via kmemleak because inflight sockets are linked to a global list.  In addition, SOCKMAP redirect breaks the Tarjan-based GC's assumption that unix_edge.successor is always alive, which is no longer true once skb is redirected, resulting in use-after-free below. [0]  Moreover, SOCKMAP does not call scm_stat_del() properly, so unix_show_fdinfo() could report an incorrect fd count.  sk_msg_recvmsg() does not support any SCM attributes in the first place.  Let's drop all SCM attributes before passing skb to the SOCKMAP layer.  [0]: BUG: KASAN: slab-use-after-free in unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251) Read of size 8 at addr ffff888125362670 by task kworker/56:1/496  CPU: 56 UID: 0 PID: 496 Comm: kworker/56:1 Not tainted 7.0.0-rc7-00263-gb9d8b856689d #3 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 Workqueue: events sk_psock_backlog Call Trace:  <TASK>  dump_stack_lvl (lib/dump_stack.c:122)  print_report (mm/kasan/report.c:379)  kasan_report (mm/kasan/report.c:597)  unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251)  unix_destroy_fpl (net/unix/garbage.c:317)  unix_destruct_scm (./include/net/scm.h:80 ./include/net/scm.h:86 net/unix/af_unix.c:1976)  sk_psock_backlog (./include/linux/skbuff.h:?)  process_scheduled_works (kernel/workqueue.c:?)  worker_thread (kernel/workqueue.c:?)  kthread (kernel/kthread.c:438)  ret_from_fork (arch/x86/kernel/process.c:164)  ret_from_fork_asm (arch/x86/entry/entry_64.S:258)  </TASK>  Allocated by task 955:  kasan_save_track (mm/kasan/common.c:58 mm/kasan/common.c:78)  __kasan_slab_alloc (mm/kasan/common.c:369)  kmem_cache_alloc_noprof (mm/slub.c:4539)  sk_prot_alloc (net/core/sock.c:2240)  sk_alloc (net/core/sock.c:2301)  unix_create1 (net/unix/af_unix.c:1099)  unix_create (net/unix/af_unix.c:1169)  __sock_create (net/socket.c:1606)  __sys_socketpair (net/socket.c:1811)  __x64_sys_socketpair (net/socket.c:1863 net/socket.c:1860 net/socket.c:1860)  do_syscall_64 (arch/x86/entry/syscall_64.c:?)  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)  Freed by task 496:  kasan_save_track (mm/kasan/common.c:58 mm/kasan/common.c:78)  kasan_save_free_info (mm/kasan/generic.c:587)  __kasan_slab_free (mm/kasan/common.c:287)  kmem_cache_free (mm/slub.c:6165)  __sk_destruct (net/core/sock.c:2282 net/core/sock.c:2384)  sk_psock_destroy (./include/net/sock.h:?)  process_scheduled_works (kernel/workqueue.c:?)  worker_thread (kernel/workqueue.c:?)  kthread (kernel/kthread.c:438)  ret_from_fork (arch/x86/kernel/process.c:164)  ret_from_fork_asm (arch/x86/entry/entry_64.S:258)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53005","epss":0.00134,"percentile":0.03254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53005","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10251000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-53005","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53005","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/48c41cd2e04af4b2cdef19e2d00994ae82952f14","https://git.kernel.org/stable/c/965dc93481d1b80d341bdd16c27b16fe197175ee","https://git.kernel.org/stable/c/b34a1d83c74a124c968b5adb25c809db3e2eb86a","https://git.kernel.org/stable/c/e0a71cbf0c1906a2eccbe69dd7d7f36fd1511d66"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Drop all SCM attributes for SOCKMAP.\n\nSOCKMAP can hide inflight fd from AF_UNIX GC.\n\nWhen a socket in SOCKMAP receives skb with inflight fd,\nsk_psock_verdict_data_ready() looks up the mapped socket and\nenqueue skb to its psock->ingress_skb.\n\nSince neither the old nor the new GC can inspect the psock\nqueue, the hidden skb leaks the inflight sockets.  Note that\nthis cannot be detected via kmemleak because inflight sockets\nare linked to a global list.\n\nIn addition, SOCKMAP redirect breaks the Tarjan-based GC's\nassumption that unix_edge.successor is always alive, which\nis no longer true once skb is redirected, resulting in\nuse-after-free below. [0]\n\nMoreover, SOCKMAP does not call scm_stat_del() properly,\nso unix_show_fdinfo() could report an incorrect fd count.\n\nsk_msg_recvmsg() does not support any SCM attributes in the\nfirst place.\n\nLet's drop all SCM attributes before passing skb to the\nSOCKMAP layer.\n\n[0]:\nBUG: KASAN: slab-use-after-free in unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251)\nRead of size 8 at addr ffff888125362670 by task kworker/56:1/496\n\nCPU: 56 UID: 0 PID: 496 Comm: kworker/56:1 Not tainted 7.0.0-rc7-00263-gb9d8b856689d #3 PREEMPT(lazy)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\nWorkqueue: events sk_psock_backlog\nCall Trace:\n <TASK>\n dump_stack_lvl (lib/dump_stack.c:122)\n print_report (mm/kasan/report.c:379)\n kasan_report (mm/kasan/report.c:597)\n unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251)\n unix_destroy_fpl (net/unix/garbage.c:317)\n unix_destruct_scm (./include/net/scm.h:80 ./include/net/scm.h:86 net/unix/af_unix.c:1976)\n sk_psock_backlog (./include/linux/skbuff.h:?)\n process_scheduled_works (kernel/workqueue.c:?)\n worker_thread (kernel/workqueue.c:?)\n kthread (kernel/kthread.c:438)\n ret_from_fork (arch/x86/kernel/process.c:164)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:258)\n </TASK>\n\nAllocated by task 955:\n kasan_save_track (mm/kasan/common.c:58 mm/kasan/common.c:78)\n __kasan_slab_alloc (mm/kasan/common.c:369)\n kmem_cache_alloc_noprof (mm/slub.c:4539)\n sk_prot_alloc (net/core/sock.c:2240)\n sk_alloc (net/core/sock.c:2301)\n unix_create1 (net/unix/af_unix.c:1099)\n unix_create (net/unix/af_unix.c:1169)\n __sock_create (net/socket.c:1606)\n __sys_socketpair (net/socket.c:1811)\n __x64_sys_socketpair (net/socket.c:1863 net/socket.c:1860 net/socket.c:1860)\n do_syscall_64 (arch/x86/entry/syscall_64.c:?)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nFreed by task 496:\n kasan_save_track (mm/kasan/common.c:58 mm/kasan/common.c:78)\n kasan_save_free_info (mm/kasan/generic.c:587)\n __kasan_slab_free (mm/kasan/common.c:287)\n kmem_cache_free (mm/slub.c:6165)\n __sk_destruct (net/core/sock.c:2282 net/core/sock.c:2384)\n sk_psock_destroy (./include/net/sock.h:?)\n process_scheduled_works (kernel/workqueue.c:?)\n worker_thread (kernel/workqueue.c:?)\n kthread (kernel/kthread.c:438)\n ret_from_fork (arch/x86/kernel/process.c:164)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:258)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53005","epss":0.00134,"percentile":0.03254,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53005","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53005","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53009","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53009","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ice: fix double-free of tx_buf skb  If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time.  The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path.  The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch.  I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN.  I looked for similar bugs in related Intel drivers and did not find any.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53009","epss":0.00129,"percentile":0.02914,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53009","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-53009","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09352499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-53009","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53009","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1a303baa715e6b78d6a406aaf335f87ff35acfcd","https://git.kernel.org/stable/c/4c08fc2119ef0281cfa2cee007acf0a251be55f2","https://access.redhat.com/errata/RHSA-2026:42919","https://access.redhat.com/errata/RHSA-2026:54246","https://access.redhat.com/errata/RHSA-2026:54247","https://access.redhat.com/errata/RHSA-2026:65711","https://access.redhat.com/errata/RHSA-2026:65712","https://access.redhat.com/security/cve/CVE-2026-53009","https://bugzilla.redhat.com/show_bug.cgi?id=2492390","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53009.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix double-free of tx_buf skb\n\nIf ice_tso() or ice_tx_csum() fail, the error path in\nice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points\nto it and is marked as valid (ICE_TX_BUF_SKB).\n'next_to_use' remains unchanged, so the potential problem will\nlikely fix itself when the next packet is transmitted and the tx_buf\ngets overwritten. But if there is no next packet and the interface is\nbrought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf()\nwill find the tx_buf and free the skb for the second time.\n\nThe fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error\npath, so that ice_unmap_and_free_tx_buf().\nMove the initialization of 'first' up, to ensure it's already valid in\ncase we hit the linearization error path.\n\nThe bug was spotted by AI while I had it looking for something else.\nIt also proposed an initial version of the patch.\n\nI reproduced the bug and tested the fix by adding code to inject\nfailures, on a build with KASAN.\n\nI looked for similar bugs in related Intel drivers and did not find any.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53009","epss":0.00129,"percentile":0.02914,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53009","cwe":"CWE-415","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-53009","cwe":"CWE-416","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53009","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53015","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53015","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  erofs: unify lcn as u64 for 32-bit platforms  As sashiko reported [1], `lcn` was typed as `unsigned long` (or `unsigned int` sometimes), which is only 32 bits wide on 32-bit platforms, which causes `(lcn << lclusterbits)` to be truncated at 4 GiB.  In order to consolidate the logic, just use `u64` consistently around the codebase.  [1] https://sashiko.dev/r/20260420034612.1899973-1-hsiangkao%40linux.alibaba.com","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53015","epss":0.00122,"percentile":0.02267,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-53015","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53015","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2d8c7edcb661812249469f4a5b62e9339118846f","https://git.kernel.org/stable/c/4fc9b12e43a3f19a01a8fb61f7961be79de20253","https://git.kernel.org/stable/c/582b0bf201157632cb5474c885989a6ebda46521","https://git.kernel.org/stable/c/858e4d98a86adf34584767388deb6c9b217f70c5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: unify lcn as u64 for 32-bit platforms\n\nAs sashiko reported [1], `lcn` was typed as `unsigned long` (or\n`unsigned int` sometimes), which is only 32 bits wide on 32-bit\nplatforms, which causes `(lcn << lclusterbits)` to be truncated\nat 4 GiB.\n\nIn order to consolidate the logic, just use `u64` consistently\naround the codebase.\n\n[1] https://sashiko.dev/r/20260420034612.1899973-1-hsiangkao%40linux.alibaba.com","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53015","epss":0.00122,"percentile":0.02267,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53015","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53017","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix data loss caused by incorrect use of nat_entry flag  Data loss can occur when fsync is performed on a newly created file (before any checkpoint has been written) concurrently with a checkpoint operation. The scenario is as follows:  create & write & fsync 'file A'                 write checkpoint - f2fs_do_sync_file // inline inode  - f2fs_write_inode // inode folio is dirty                                                 - f2fs_write_checkpoint                                                  - f2fs_flush_merged_writes                                                  - f2fs_sync_node_pages                                                  - f2fs_flush_nat_entries  - f2fs_fsync_node_pages // no dirty node  - f2fs_need_inode_block_update // return false  SPO and lost 'file A'  f2fs_flush_nat_entries() sets the IS_CHECKPOINTED and HAS_LAST_FSYNC flags for the nat_entry, but this does not mean that the checkpoint has actually completed successfully. However, f2fs_need_inode_block_update() checks these flags and incorrectly assumes that the checkpoint has finished.  The root cause is that the semantics of IS_CHECKPOINTED and HAS_LAST_FSYNC are only guaranteed after the checkpoint write fully completes.  This patch modifies f2fs_need_inode_block_update() to acquire the sbi->node_write lock before reading the nat_entry flags, ensuring that once IS_CHECKPOINTED and HAS_LAST_FSYNC are observed to be set, the checkpoint operation has already completed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53017","epss":0.00112,"percentile":0.01523,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-53017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53017","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/20cedb4d9f6b230d0ee469690b8f868f06a07c29","https://git.kernel.org/stable/c/238e14eb7226f883b72caccd2d37bf5707df066b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix data loss caused by incorrect use of nat_entry flag\n\nData loss can occur when fsync is performed on a newly created file\n(before any checkpoint has been written) concurrently with a checkpoint\noperation. The scenario is as follows:\n\ncreate & write & fsync 'file A'                 write checkpoint\n- f2fs_do_sync_file // inline inode\n - f2fs_write_inode // inode folio is dirty\n                                                - f2fs_write_checkpoint\n                                                 - f2fs_flush_merged_writes\n                                                 - f2fs_sync_node_pages\n                                                 - f2fs_flush_nat_entries\n - f2fs_fsync_node_pages // no dirty node\n - f2fs_need_inode_block_update // return false\n SPO and lost 'file A'\n\nf2fs_flush_nat_entries() sets the IS_CHECKPOINTED and HAS_LAST_FSYNC\nflags for the nat_entry, but this does not mean that the checkpoint has\nactually completed successfully. However, f2fs_need_inode_block_update()\nchecks these flags and incorrectly assumes that the checkpoint has\nfinished.\n\nThe root cause is that the semantics of IS_CHECKPOINTED and\nHAS_LAST_FSYNC are only guaranteed after the checkpoint write fully\ncompletes.\n\nThis patch modifies f2fs_need_inode_block_update() to acquire the\nsbi->node_write lock before reading the nat_entry flags, ensuring that\nonce IS_CHECKPOINTED and HAS_LAST_FSYNC are observed to be set, the\ncheckpoint operation has already completed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53017","epss":0.00112,"percentile":0.01523,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53018","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53018","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: avoid reading already updated pages during GC  We found the following issue during fuzz testing:  page: refcount:3 mapcount:0 mapping:00000000b6e89c65 index:0x18b2dc pfn:0x161ba9 memcg:f8ffff800e269c00 aops:f2fs_meta_aops ino:2 flags: 0x52880000000080a9(locked|waiters|uptodate|lru|private|zone=1|kasantag=0x4a) raw: 52880000000080a9 fffffffec6e17588 fffffffec0ccc088 a7ffff8067063618 raw: 000000000018b2dc 0000000000000009 00000003ffffffff f8ffff800e269c00 page dumped because: VM_BUG_ON_FOLIO(folio_test_uptodate(folio)) page_owner tracks the page as allocated  post_alloc_hook+0x58c/0x5ec  prep_new_page+0x34/0x284  get_page_from_freelist+0x2dcc/0x2e8c  __alloc_pages_noprof+0x280/0x76c  __folio_alloc_noprof+0x18/0xac  __filemap_get_folio+0x6bc/0xdc4  pagecache_get_page+0x3c/0x104  do_garbage_collect+0x5c78/0x77a4  f2fs_gc+0xd74/0x25f0  gc_thread_func+0xb28/0x2930  kthread+0x464/0x5d8  ret_from_fork+0x10/0x20 ------------[ cut here ]------------ kernel BUG at mm/filemap.c:1563!  folio_end_read+0x140/0x168  f2fs_finish_read_bio+0x5c4/0xb80  f2fs_read_end_io+0x64c/0x708  bio_endio+0x85c/0x8c0  blk_update_request+0x690/0x127c  scsi_end_request+0x9c/0xb8c  scsi_io_completion+0xf0/0x250  scsi_finish_command+0x430/0x45c  scsi_complete+0x178/0x6d4  blk_mq_complete_request+0xcc/0x104  scsi_done_internal+0x214/0x454  scsi_done+0x24/0x34  which is similar to the problem reported by syzbot: https://syzkaller.appspot.com/bug?extid=3686758660f980b402dc  This case is consistent with the description in commit 9bf1a3f (\"f2fs: avoid GC causing encrypted file corrupted\"): Page 1 is moved from blkaddr A to blkaddr B by move_data_block, and after being written it is marked as uptodate. Then, Page 1 is moved from blkaddr B to blkaddr C, VM_BUG_ON_FOLIO was triggered in the endio initiated by ra_data_block.  There is no need to read Page 1 again from blkaddr B, since it has already been updated. Therefore, avoid initiating I/O in this case.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53018","epss":0.00121,"percentile":0.02136,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-53018","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53018","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4623c251496b99c530ce225c05334f4eac8b933a","https://git.kernel.org/stable/c/570e2ccc7cb35fe720106964e65060602d3d2ac4","https://git.kernel.org/stable/c/b663ebb8a340eae5442e605b6acd2cff5677f016"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: avoid reading already updated pages during GC\n\nWe found the following issue during fuzz testing:\n\npage: refcount:3 mapcount:0 mapping:00000000b6e89c65 index:0x18b2dc pfn:0x161ba9\nmemcg:f8ffff800e269c00\naops:f2fs_meta_aops ino:2\nflags: 0x52880000000080a9(locked|waiters|uptodate|lru|private|zone=1|kasantag=0x4a)\nraw: 52880000000080a9 fffffffec6e17588 fffffffec0ccc088 a7ffff8067063618\nraw: 000000000018b2dc 0000000000000009 00000003ffffffff f8ffff800e269c00\npage dumped because: VM_BUG_ON_FOLIO(folio_test_uptodate(folio))\npage_owner tracks the page as allocated\n post_alloc_hook+0x58c/0x5ec\n prep_new_page+0x34/0x284\n get_page_from_freelist+0x2dcc/0x2e8c\n __alloc_pages_noprof+0x280/0x76c\n __folio_alloc_noprof+0x18/0xac\n __filemap_get_folio+0x6bc/0xdc4\n pagecache_get_page+0x3c/0x104\n do_garbage_collect+0x5c78/0x77a4\n f2fs_gc+0xd74/0x25f0\n gc_thread_func+0xb28/0x2930\n kthread+0x464/0x5d8\n ret_from_fork+0x10/0x20\n------------[ cut here ]------------\nkernel BUG at mm/filemap.c:1563!\n folio_end_read+0x140/0x168\n f2fs_finish_read_bio+0x5c4/0xb80\n f2fs_read_end_io+0x64c/0x708\n bio_endio+0x85c/0x8c0\n blk_update_request+0x690/0x127c\n scsi_end_request+0x9c/0xb8c\n scsi_io_completion+0xf0/0x250\n scsi_finish_command+0x430/0x45c\n scsi_complete+0x178/0x6d4\n blk_mq_complete_request+0xcc/0x104\n scsi_done_internal+0x214/0x454\n scsi_done+0x24/0x34\n\nwhich is similar to the problem reported by syzbot:\nhttps://syzkaller.appspot.com/bug?extid=3686758660f980b402dc\n\nThis case is consistent with the description in commit 9bf1a3f\n(\"f2fs: avoid GC causing encrypted file corrupted\"):\nPage 1 is moved from blkaddr A to blkaddr B by move_data_block, and after\nbeing written it is marked as uptodate. Then, Page 1 is moved from blkaddr\nB to blkaddr C, VM_BUG_ON_FOLIO was triggered in the endio initiated by\nra_data_block.\n\nThere is no need to read Page 1 again from blkaddr B, since it has already\nbeen updated. Therefore, avoid initiating I/O in this case.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53018","epss":0.00121,"percentile":0.02136,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53018","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53024","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53024","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  greybus: raw: fix use-after-free if write is called after disconnect  If a user writes to the chardev after disconnect has been called, the kernel panics with the following trace (with CONFIG_INIT_ON_FREE_DEFAULT_ON=y):          BUG: kernel NULL pointer dereference, address: 0000000000000218          ...         Call Trace:          <TASK>          gb_operation_create_common+0x61/0x180          gb_operation_create_flags+0x28/0xa0          gb_operation_sync_timeout+0x6f/0x100          raw_write+0x7b/0xc7 [gb_raw]          vfs_write+0xcf/0x420          ? task_mm_cid_work+0x136/0x220          ksys_write+0x63/0xe0          do_syscall_64+0xa4/0x290          entry_SYSCALL_64_after_hwframe+0x77/0x7f  Disconnect calls gb_connection_destroy, which ends up freeing the connection object. When gb_operation_sync is called in the write file operations, its gets a freed connection as parameter and the kernel panics.  The gb_connection_destroy cannot be moved out of the disconnect function, as the Greybus subsystem expect all connections belonging to a bundle to be destroyed when disconnect returns.  To prevent this bug, use a rw lock to synchronize access between write and disconnect. This guarantees that the write function doesn't try to use a disconnected connection.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53024","epss":0.00129,"percentile":0.02919,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53024","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-53024","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53024","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/48d6c32bc049abd114e8f0836c0e7d7cbfba7827","https://git.kernel.org/stable/c/84265cbd96b97058ef67e3f8be3933667a000835"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngreybus: raw: fix use-after-free if write is called after disconnect\n\nIf a user writes to the chardev after disconnect has been called, the\nkernel panics with the following trace (with\nCONFIG_INIT_ON_FREE_DEFAULT_ON=y):\n\n        BUG: kernel NULL pointer dereference, address: 0000000000000218\n         ...\n        Call Trace:\n         <TASK>\n         gb_operation_create_common+0x61/0x180\n         gb_operation_create_flags+0x28/0xa0\n         gb_operation_sync_timeout+0x6f/0x100\n         raw_write+0x7b/0xc7 [gb_raw]\n         vfs_write+0xcf/0x420\n         ? task_mm_cid_work+0x136/0x220\n         ksys_write+0x63/0xe0\n         do_syscall_64+0xa4/0x290\n         entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nDisconnect calls gb_connection_destroy, which ends up freeing the\nconnection object. When gb_operation_sync is called in the write file\noperations, its gets a freed connection as parameter and the kernel\npanics.\n\nThe gb_connection_destroy cannot be moved out of the disconnect\nfunction, as the Greybus subsystem expect all connections belonging to a\nbundle to be destroyed when disconnect returns.\n\nTo prevent this bug, use a rw lock to synchronize access between write\nand disconnect. This guarantees that the write function doesn't try\nto use a disconnected connection.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53024","epss":0.00129,"percentile":0.02919,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53024","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53024","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53025","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  greybus: raw: fix use-after-free on cdev close  This addresses a use-after-free bug when a raw bundle is disconnected but its chardev is still opened by an application. When the application releases the cdev, it causes the following panic when init on free is enabled (CONFIG_INIT_ON_FREE_DEFAULT_ON=y):          refcount_t: underflow; use-after-free.         WARNING: CPU: 0 PID: 139 at lib/refcount.c:28 refcount_warn_saturate+0xd0/0x130          ...         Call Trace:          <TASK>          cdev_put+0x18/0x30          __fput+0x255/0x2a0          __x64_sys_close+0x3d/0x80          do_syscall_64+0xa4/0x290          entry_SYSCALL_64_after_hwframe+0x77/0x7f  The cdev is contained in the \"gb_raw\" structure, which is freed in the disconnect operation. When the cdev is released at a later time, cdev_put gets an address that points to freed memory.  To fix this use-after-free, convert the struct device from a pointer to being embedded, that makes the lifetime of the cdev and of this device the same. Then, use cdev_device_add, which guarantees that the device won't be released until all references to the cdev have been released. Finally, delegate the freeing of the structure to the device release function, instead of freeing immediately in the disconnect callback.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53025","epss":0.00129,"percentile":0.02918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53025","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-53025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53025","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/983cc2c7efbce04ecbf6328448d895044dd6ab31","https://git.kernel.org/stable/c/ef2d97c15b19b3489de01695bce478601e236c3e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngreybus: raw: fix use-after-free on cdev close\n\nThis addresses a use-after-free bug when a raw bundle is disconnected\nbut its chardev is still opened by an application. When the application\nreleases the cdev, it causes the following panic when init on free is\nenabled (CONFIG_INIT_ON_FREE_DEFAULT_ON=y):\n\n        refcount_t: underflow; use-after-free.\n        WARNING: CPU: 0 PID: 139 at lib/refcount.c:28 refcount_warn_saturate+0xd0/0x130\n         ...\n        Call Trace:\n         <TASK>\n         cdev_put+0x18/0x30\n         __fput+0x255/0x2a0\n         __x64_sys_close+0x3d/0x80\n         do_syscall_64+0xa4/0x290\n         entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nThe cdev is contained in the \"gb_raw\" structure, which is freed in the\ndisconnect operation. When the cdev is released at a later time,\ncdev_put gets an address that points to freed memory.\n\nTo fix this use-after-free, convert the struct device from a pointer to\nbeing embedded, that makes the lifetime of the cdev and of this device\nthe same. Then, use cdev_device_add, which guarantees that the device\nwon't be released until all references to the cdev have been released.\nFinally, delegate the freeing of the structure to the device release\nfunction, instead of freeing immediately in the disconnect callback.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53025","epss":0.00129,"percentile":0.02918,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53025","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53027","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53027","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()  When a compressed or sparse attribute has its clusters frame-aligned, vcn is rounded down to the frame start using cmask, which can result in vcn != vcn0. In this case, vcn and vcn0 may reside in different attribute segments.  The code already handles the case where vcn is in a different segment by loading its runs before allocation. However, it fails to load runs for vcn0 when vcn0 resides in a different segment than vcn. This causes run_lookup_entry() to return SPARSE_LCN for vcn0 since its segment was never loaded into the in-memory run list, triggering the WARN_ON(1).  Fix this by adding a missing check for vcn0 after the existing vcn segment check. If vcn0 falls outside the current segment range [svcn, evcn1), find and load the attribute segment containing vcn0 before performing the run lookup.  The following scenario triggers the bug:   attr_data_get_block_locked()     vcn = vcn0 & cmask        <- vcn != vcn0 after frame alignment     load runs for vcn segment <- vcn0 segment not loaded!     attr_allocate_clusters()  <- allocation succeeds     run_lookup_entry(vcn0)    <- vcn0 not in run -> SPARSE_LCN     WARN_ON(1)                <- bug fires here!","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53027","epss":0.00122,"percentile":0.02243,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-53027","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53027","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/08fad5d5a26cc55c0ecb68ac59ba3be5e31f4147","https://git.kernel.org/stable/c/2b4ae1ce613ade8a7e118fba4a5a77cd23e97e54","https://git.kernel.org/stable/c/d68a14450783ecc5fddae957ac4e1c546dfcfb73","https://git.kernel.org/stable/c/d7ea8495fd307b58f8867acd81a1b40075b1d3ba","https://git.kernel.org/stable/c/ea59d9dbc5504e29d420ac4aab774cbce39b0e69"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()\n\nWhen a compressed or sparse attribute has its clusters frame-aligned,\nvcn is rounded down to the frame start using cmask, which can result\nin vcn != vcn0. In this case, vcn and vcn0 may reside in different\nattribute segments.\n\nThe code already handles the case where vcn is in a different segment\nby loading its runs before allocation. However, it fails to load runs\nfor vcn0 when vcn0 resides in a different segment than vcn. This causes\nrun_lookup_entry() to return SPARSE_LCN for vcn0 since its segment was\nnever loaded into the in-memory run list, triggering the WARN_ON(1).\n\nFix this by adding a missing check for vcn0 after the existing vcn\nsegment check. If vcn0 falls outside the current segment range\n[svcn, evcn1), find and load the attribute segment containing vcn0\nbefore performing the run lookup.\n\nThe following scenario triggers the bug:\n  attr_data_get_block_locked()\n    vcn = vcn0 & cmask        <- vcn != vcn0 after frame alignment\n    load runs for vcn segment <- vcn0 segment not loaded!\n    attr_allocate_clusters()  <- allocation succeeds\n    run_lookup_entry(vcn0)    <- vcn0 not in run -> SPARSE_LCN\n    WARN_ON(1)                <- bug fires here!","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53027","epss":0.00122,"percentile":0.02243,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53027","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53053","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53053","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/amd: Fix clone_alias() to use the original device's devid  Currently clone_alias() assumes first argument (pdev) is always the original device pointer. This function is called by pci_for_each_dma_alias() which based on topology decides to send original or alias device details in first argument.  This meant that the source devid used to look up and copy the DTE may be incorrect, leading to wrong or stale DTE entries being propagated to alias device.  Fix this by passing the original pdev as the opaque data argument to both the direct clone_alias() call and pci_for_each_dma_alias(). Inside clone_alias(), retrieve the original device from data and compute devid from it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53053","epss":0.00129,"percentile":0.02837,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53053","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53053","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/20b3c566e2702e5d4d0545be8a97029a2eebcc0e","https://git.kernel.org/stable/c/dae251ff11d2d2208a029f98923756831cefec46","https://git.kernel.org/stable/c/dbd76a537d8cb814e7f5b795ab21ecb7949c821d","https://git.kernel.org/stable/c/faad224fe0f0857a04ff2eb3c90f0de57f47d0f3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Fix clone_alias() to use the original device's devid\n\nCurrently clone_alias() assumes first argument (pdev) is always the\noriginal device pointer. This function is called by\npci_for_each_dma_alias() which based on topology decides to send\noriginal or alias device details in first argument.\n\nThis meant that the source devid used to look up and copy the DTE\nmay be incorrect, leading to wrong or stale DTE entries being\npropagated to alias device.\n\nFix this by passing the original pdev as the opaque data argument to\nboth the direct clone_alias() call and pci_for_each_dma_alias(). Inside\nclone_alias(), retrieve the original device from data and compute devid\nfrom it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53053","epss":0.00129,"percentile":0.02837,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53053","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53070","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53070","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: disable BH before calling udp_tunnel_xmit_skb()  udp_tunnel_xmit_skb() / udp_tunnel6_xmit_skb() are expected to run with BH disabled.  After commit 6f1a9140ecda (\"add xmit recursion limit to tunnel xmit functions\"), on the path:    udp(6)_tunnel_xmit_skb() -> ip(6)tunnel_xmit()  dev_xmit_recursion_inc()/dec() must stay balanced on the same CPU.  Without local_bh_disable(), the context may move between CPUs, which can break the inc/dec pairing. This may lead to incorrect recursion level detection and cause packets to be dropped in ip(6)_tunnel_xmit() or __dev_queue_xmit().  Fix it by disabling BH around both IPv4 and IPv6 SCTP UDP xmit paths.  In my testing, after enabling the SCTP over UDP:    # ip net exec ha sysctl -w net.sctp.udp_port=9899   # ip net exec ha sysctl -w net.sctp.encap_port=9899   # ip net exec hb sysctl -w net.sctp.udp_port=9899   # ip net exec hb sysctl -w net.sctp.encap_port=9899    # ip net exec ha iperf3 -s  - without this patch:    # ip net exec hb iperf3 -c 192.168.0.1 --sctp   [  5]   0.00-10.00  sec  37.2 MBytes  31.2 Mbits/sec  sender   [  5]   0.00-10.00  sec  37.1 MBytes  31.1 Mbits/sec  receiver  - with this patch:    # ip net exec hb iperf3 -c 192.168.0.1 --sctp   [  5]   0.00-10.00  sec  3.14 GBytes  2.69 Gbits/sec  sender   [  5]   0.00-10.00  sec  3.14 GBytes  2.69 Gbits/sec  receiver","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53070","epss":0.00346,"percentile":0.27713,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.2595},"relatedVulnerabilities":[{"id":"CVE-2026-53070","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53070","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0de7db2eb27e82b983157016fa604b1ba664ae5f","https://git.kernel.org/stable/c/2cd7e6971fc2787408ceef17906ea152791448cf","https://git.kernel.org/stable/c/790093245e35040c2adb15f48970020425aa3f47","https://git.kernel.org/stable/c/be3bfcb34bda04f6a350710db471d4133f950f2c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: disable BH before calling udp_tunnel_xmit_skb()\n\nudp_tunnel_xmit_skb() / udp_tunnel6_xmit_skb() are expected to run with\nBH disabled.  After commit 6f1a9140ecda (\"add xmit recursion limit to\ntunnel xmit functions\"), on the path:\n\n  udp(6)_tunnel_xmit_skb() -> ip(6)tunnel_xmit()\n\ndev_xmit_recursion_inc()/dec() must stay balanced on the same CPU.\n\nWithout local_bh_disable(), the context may move between CPUs, which can\nbreak the inc/dec pairing. This may lead to incorrect recursion level\ndetection and cause packets to be dropped in ip(6)_tunnel_xmit() or\n__dev_queue_xmit().\n\nFix it by disabling BH around both IPv4 and IPv6 SCTP UDP xmit paths.\n\nIn my testing, after enabling the SCTP over UDP:\n\n  # ip net exec ha sysctl -w net.sctp.udp_port=9899\n  # ip net exec ha sysctl -w net.sctp.encap_port=9899\n  # ip net exec hb sysctl -w net.sctp.udp_port=9899\n  # ip net exec hb sysctl -w net.sctp.encap_port=9899\n\n  # ip net exec ha iperf3 -s\n\n- without this patch:\n\n  # ip net exec hb iperf3 -c 192.168.0.1 --sctp\n  [  5]   0.00-10.00  sec  37.2 MBytes  31.2 Mbits/sec  sender\n  [  5]   0.00-10.00  sec  37.1 MBytes  31.1 Mbits/sec  receiver\n\n- with this patch:\n\n  # ip net exec hb iperf3 -c 192.168.0.1 --sctp\n  [  5]   0.00-10.00  sec  3.14 GBytes  2.69 Gbits/sec  sender\n  [  5]   0.00-10.00  sec  3.14 GBytes  2.69 Gbits/sec  receiver","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53070","epss":0.00346,"percentile":0.27713,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53070","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53076","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53076","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix OOB in pcpu_init_value  An out-of-bounds read occurs when copying element from a BPF_MAP_TYPE_CGROUP_STORAGE map to another pcpu map with the same value_size that is not rounded up to 8 bytes.  The issue happens when: 1. A CGROUP_STORAGE map is created with value_size not aligned to    8 bytes (e.g., 4 bytes) 2. A pcpu map is created with the same value_size (e.g., 4 bytes) 3. Update element in 2 with data in 1  pcpu_init_value assumes that all sources are rounded up to 8 bytes, and invokes copy_map_value_long to make a data copy, However, the assumption doesn't stand since there are some cases where the source may not be rounded up to 8 bytes, e.g., CGROUP_STORAGE, skb->data. the verifier verifies exactly the size that the source claims, not the size rounded up to 8 bytes by kernel, an OOB happens when the source has only 4 bytes while the copy size(4) is rounded up to 8.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53076","epss":0.00117,"percentile":0.01841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53076","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08541},"relatedVulnerabilities":[{"id":"CVE-2026-53076","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53076","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/576afddfee8d1108ee299bf10f581593540d1a36","https://git.kernel.org/stable/c/6086079e6d1c32ba4c4b422612b8aebb1129a96c","https://git.kernel.org/stable/c/634a793d0e1c822412095d25a1338f8831ad894c","https://git.kernel.org/stable/c/e0378419b0e20178b5d100b27c9cc7e51064202e","https://git.kernel.org/stable/c/e19c5ed9f1922a6854073f8651a63fa7be26e9e9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix OOB in pcpu_init_value\n\nAn out-of-bounds read occurs when copying element from a\nBPF_MAP_TYPE_CGROUP_STORAGE map to another pcpu map with the\nsame value_size that is not rounded up to 8 bytes.\n\nThe issue happens when:\n1. A CGROUP_STORAGE map is created with value_size not aligned to\n   8 bytes (e.g., 4 bytes)\n2. A pcpu map is created with the same value_size (e.g., 4 bytes)\n3. Update element in 2 with data in 1\n\npcpu_init_value assumes that all sources are rounded up to 8 bytes,\nand invokes copy_map_value_long to make a data copy, However, the\nassumption doesn't stand since there are some cases where the source\nmay not be rounded up to 8 bytes, e.g., CGROUP_STORAGE, skb->data.\nthe verifier verifies exactly the size that the source claims, not\nthe size rounded up to 8 bytes by kernel, an OOB happens when the\nsource has only 4 bytes while the copy size(4) is rounded up to 8.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53076","epss":0.00117,"percentile":0.01841,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53076","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53076","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53078","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53078","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops  When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the destination register in the !fullsock / !locked_tcp_sock path.  Both macros borrow a temporary register to check is_fullsock / is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with a request_sock), dst_reg should be zeroed but is not, leaving the stale ctx pointer:   - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks    as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer,    leading to stack-out-of-bounds access in helpers like    bpf_skc_to_tcp6_sock().   - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the    verifier believes is a SCALAR_VALUE, leaking a kernel pointer.  Fix both macros by:  - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the    added instruction.  - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register    restore in the !fullsock path, placed after the restore because    dst_reg == src_reg means we need src_reg intact to read ctx->temp.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53078","epss":0.0012,"percentile":0.02045,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53078","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53078","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53078","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/10f86a2a5c91fc4c4d001960f1c21abe52545ef6","https://git.kernel.org/stable/c/18e3ffde1822f0b48b1753bf34aa97ce839df1d8","https://git.kernel.org/stable/c/22400725de070b787cd6d806c5795370ab46d269","https://git.kernel.org/stable/c/2a2c98141e0a75f2d4a7d78b0316c88b3da784ac"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix same-register dst/src OOB read and pointer leak in sock_ops\n\nWhen a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,\nthe SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the\ndestination register in the !fullsock / !locked_tcp_sock path.\n\nBoth macros borrow a temporary register to check is_fullsock /\nis_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the\nctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with\na request_sock), dst_reg should be zeroed but is not, leaving the stale\nctx pointer:\n\n - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks\n   as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer,\n   leading to stack-out-of-bounds access in helpers like\n   bpf_skc_to_tcp6_sock().\n\n - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the\n   verifier believes is a SCALAR_VALUE, leaking a kernel pointer.\n\nFix both macros by:\n - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the\n   added instruction.\n - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register\n   restore in the !fullsock path, placed after the restore because\n   dst_reg == src_reg means we need src_reg intact to read ctx->temp.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53078","epss":0.0012,"percentile":0.02045,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53078","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53078","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53083","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix RCU stall in bpf_fd_array_map_clear()  Add a missing cond_resched() in bpf_fd_array_map_clear() loop.  For PROG_ARRAY maps with many entries this loop calls prog_array_map_poke_run() per entry which can be expensive, and without yielding this can cause RCU stalls under load:    rcu: Stack dump where RCU GP kthread last ran:   CPU: 0 UID: 0 PID: 30932 Comm: kworker/0:2 Not tainted 6.14.0-13195-g967e8def1100 #2 PREEMPT(undef)   Workqueue: events prog_array_map_clear_deferred   RIP: 0010:write_comp_data+0x38/0x90 kernel/kcov.c:246   Call Trace:    <TASK>    prog_array_map_poke_run+0x77/0x380 kernel/bpf/arraymap.c:1096    __fd_array_map_delete_elem+0x197/0x310 kernel/bpf/arraymap.c:925    bpf_fd_array_map_clear kernel/bpf/arraymap.c:1000 [inline]    prog_array_map_clear_deferred+0x119/0x1b0 kernel/bpf/arraymap.c:1141    process_one_work+0x898/0x19d0 kernel/workqueue.c:3238    process_scheduled_works kernel/workqueue.c:3319 [inline]    worker_thread+0x770/0x10b0 kernel/workqueue.c:3400    kthread+0x465/0x880 kernel/kthread.c:464    ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:153    ret_from_fork_asm+0x19/0x30 arch/x86/entry/entry_64.S:245    </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53083","epss":0.00114,"percentile":0.01629,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-53083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53083","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4406942e65ca128c56c67443832988873c21d2e9","https://git.kernel.org/stable/c/67bdb4b0d26f2d6bbf1798a925ef5a3b9ed7357a","https://git.kernel.org/stable/c/71ddb7defc442ab38c53123c384fedbfd8410a15","https://git.kernel.org/stable/c/b1f7158a86f3cbac4d5a32beb55ca0f8027d44cd","https://git.kernel.org/stable/c/e1ed678855e315f90c70c1723e94157a9a82e660"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix RCU stall in bpf_fd_array_map_clear()\n\nAdd a missing cond_resched() in bpf_fd_array_map_clear() loop.\n\nFor PROG_ARRAY maps with many entries this loop calls\nprog_array_map_poke_run() per entry which can be expensive, and\nwithout yielding this can cause RCU stalls under load:\n\n  rcu: Stack dump where RCU GP kthread last ran:\n  CPU: 0 UID: 0 PID: 30932 Comm: kworker/0:2 Not tainted 6.14.0-13195-g967e8def1100 #2 PREEMPT(undef)\n  Workqueue: events prog_array_map_clear_deferred\n  RIP: 0010:write_comp_data+0x38/0x90 kernel/kcov.c:246\n  Call Trace:\n   <TASK>\n   prog_array_map_poke_run+0x77/0x380 kernel/bpf/arraymap.c:1096\n   __fd_array_map_delete_elem+0x197/0x310 kernel/bpf/arraymap.c:925\n   bpf_fd_array_map_clear kernel/bpf/arraymap.c:1000 [inline]\n   prog_array_map_clear_deferred+0x119/0x1b0 kernel/bpf/arraymap.c:1141\n   process_one_work+0x898/0x19d0 kernel/workqueue.c:3238\n   process_scheduled_works kernel/workqueue.c:3319 [inline]\n   worker_thread+0x770/0x10b0 kernel/workqueue.c:3400\n   kthread+0x465/0x880 kernel/kthread.c:464\n   ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:153\n   ret_from_fork_asm+0x19/0x30 arch/x86/entry/entry_64.S:245\n   </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53083","epss":0.00114,"percentile":0.01629,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53089","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53089","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix use-after-free in offloaded map/prog info fill  When querying info for an offloaded BPF map or program, bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() obtain the network namespace with get_net(dev_net(offmap->netdev)). However, the associated netdev's netns may be racing with teardown during netns destruction. If the netns refcount has already reached 0, get_net() performs a refcount_t increment on 0, triggering:    refcount_t: addition on 0; use-after-free.  Although rtnl_lock and bpf_devs_lock ensure the netdev pointer remains valid, they cannot prevent the netns refcount from reaching zero.  Fix this by using maybe_get_net() instead of get_net(). maybe_get_net() uses refcount_inc_not_zero() and returns NULL if the refcount is already zero, which causes ns_get_path_cb() to fail and the caller to return -ENOENT -- the correct behavior when the netns is being destroyed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53089","epss":0.00117,"percentile":0.01868,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53089","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-53089","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53089","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1a2dc103e16448d022a77ad5fc3234641436c4b7","https://git.kernel.org/stable/c/43d6848a2a6c92ccfd614d9f0bb6fd85b95dfa9d","https://git.kernel.org/stable/c/5662dac41a3442aa378d7c405164903eb109fc05","https://git.kernel.org/stable/c/642943ae5bdacabc8109dc4a5e0ebb4a6b99ef3e","https://git.kernel.org/stable/c/85dc711f742b192eb97c0e00b521312f5a7a415e","https://git.kernel.org/stable/c/a0c584fc18056709c8e047a82a6045d6c209f4ce","https://git.kernel.org/stable/c/a51e7fbe94a87e236631a83973d4f558310b2cd2","https://git.kernel.org/stable/c/fea55b034328feaafef75aee252f305e6f85a991"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix use-after-free in offloaded map/prog info fill\n\nWhen querying info for an offloaded BPF map or program,\nbpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns()\nobtain the network namespace with get_net(dev_net(offmap->netdev)).\nHowever, the associated netdev's netns may be racing with teardown\nduring netns destruction. If the netns refcount has already reached 0,\nget_net() performs a refcount_t increment on 0, triggering:\n\n  refcount_t: addition on 0; use-after-free.\n\nAlthough rtnl_lock and bpf_devs_lock ensure the netdev pointer remains\nvalid, they cannot prevent the netns refcount from reaching zero.\n\nFix this by using maybe_get_net() instead of get_net(). maybe_get_net()\nuses refcount_inc_not_zero() and returns NULL if the refcount is already\nzero, which causes ns_get_path_cb() to fail and the caller to return\n-ENOENT -- the correct behavior when the netns is being destroyed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53089","epss":0.00117,"percentile":0.01868,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53089","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53089","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53090","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53090","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix ld_{abs,ind} failure path analysis in subprogs  Usage of ld_{abs,ind} instructions got extended into subprogs some time ago via commit 09b28d76eac4 (\"bpf: Add abnormal return checks.\"). These are only allowed in subprograms when the latter are BTF annotated and have scalar return types.  The code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 + exit) from legacy cBPF times. While the enforcement is on scalar return types, the verifier must also simulate the path of abnormal exit if the packet data load via ld_{abs,ind} failed.  This is currently not the case. Fix it by having the verifier simulate both success and failure paths, and extend it in similar ways as we do for tail calls. The success path (r0=unknown, continue to next insn) is pushed onto stack for later validation and the r0=0 and return to the caller is done on the fall-through side.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"exploitabilityScore":0.5,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53090","epss":0.00141,"percentile":0.03724,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53090","cwe":"CWE-253","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08037000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-53090","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53090","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/37ad2bb11e9de92cb7b94548705eeedd87f7d392","https://git.kernel.org/stable/c/8674e2db06cff6b50f2216eed9a761d15425bb34","https://git.kernel.org/stable/c/8a800497d9f6c2ec9c2c1ba7b71d0ac2ea7f7bbe","https://git.kernel.org/stable/c/928d354ae3557e8f755a227e67be88034eb3cd7f","https://git.kernel.org/stable/c/ce01a4e5cfac7adbe0be565f90cd32ecbb2f8337","https://git.kernel.org/stable/c/d846d83bdacbd8f14fc45c63b8c1d22608452e1c","https://git.kernel.org/stable/c/de1055e7f9e67af32b1f3376066272b04e5223c0","https://git.kernel.org/stable/c/ee861486e377edc55361c08dcbceab3f6b6577bd","https://access.redhat.com/security/cve/CVE-2026-53090","https://bugzilla.redhat.com/show_bug.cgi?id=2492305","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53090.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix ld_{abs,ind} failure path analysis in subprogs\n\nUsage of ld_{abs,ind} instructions got extended into subprogs some time\nago via commit 09b28d76eac4 (\"bpf: Add abnormal return checks.\"). These\nare only allowed in subprograms when the latter are BTF annotated and\nhave scalar return types.\n\nThe code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 +\nexit) from legacy cBPF times. While the enforcement is on scalar return\ntypes, the verifier must also simulate the path of abnormal exit if the\npacket data load via ld_{abs,ind} failed.\n\nThis is currently not the case. Fix it by having the verifier simulate\nboth success and failure paths, and extend it in similar ways as we do\nfor tail calls. The success path (r0=unknown, continue to next insn) is\npushed onto stack for later validation and the r0=0 and return to the\ncaller is done on the fall-through side.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"exploitabilityScore":0.5,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53090","epss":0.00141,"percentile":0.03724,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53090","cwe":"CWE-253","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53090","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53091","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53091","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: pull headers in qdisc_pkt_len_segs_init()  Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head.  net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb->data, hdr_len);  qdisc_pkt_len_segs_init() already does a dissection of gso packets.  Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reimplement this.  Some malicious packets could be fed, detect them so that we can drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53091","epss":0.00129,"percentile":0.02839,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53091","cwe":"CWE-131","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09352499999999998},"relatedVulnerabilities":[{"id":"CVE-2026-53091","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53091","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7fb4c19670110f052c04e1ec1d2b953b9f4f57e4","https://git.kernel.org/stable/c/9d4f5c68f5ad4ab425f3ce1500c97c9f9743999a","https://access.redhat.com/errata/RHSA-2026:65334","https://access.redhat.com/security/cve/CVE-2026-53091","https://bugzilla.redhat.com/show_bug.cgi?id=2492270","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53091.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: pull headers in qdisc_pkt_len_segs_init()\n\nMost ndo_start_xmit() methods expects headers of gso packets\nto be already in skb->head.\n\nnet/core/tso.c users are particularly at risk, because tso_build_hdr()\ndoes a memcpy(hdr, skb->data, hdr_len);\n\nqdisc_pkt_len_segs_init() already does a dissection of gso packets.\n\nUse pskb_may_pull() instead of skb_header_pointer() to make\nsure drivers do not have to reimplement this.\n\nSome malicious packets could be fed, detect them so that we can\ndrop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.1,"impactScore":5.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53091","epss":0.00129,"percentile":0.02839,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53091","cwe":"CWE-131","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53091","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53102","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53102","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()  mt76_connac_mcu_alloc_sta_req() allocates an skb which is expected to be freed eventually by mt76_mcu_skb_send_msg(). However, currently if an intermediate function fails before sending, the allocated skb is leaked.  Specifically, mt76_connac_mcu_sta_wed_update() and mt76_connac_mcu_sta_key_tlv() may fail, leading to an immediate memory leak in the error path.  Fix this by explicitly freeing the skb in these error paths. Commit 7c0f63fe37a5 (\"wifi: mt76: mt7996: fix memory leak on mt7996_mcu_sta_key_tlv error\") made a similar change.  Compile tested only. Issue found using a prototype static analysis tool and code review.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53102","epss":0.00122,"percentile":0.02297,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53102","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06405},"relatedVulnerabilities":[{"id":"CVE-2026-53102","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53102","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/7de35b99503012e57bec027e98ed53f881518b5b","https://git.kernel.org/stable/c/8527ac1bce87aaabde6755e8e6eb2a9f439d1292","https://git.kernel.org/stable/c/c41075ce8cf05ed8c0e7b7efef000dce548ffc42","https://git.kernel.org/stable/c/eb466406d2094deefadc2cd6ddb4f6eeb086d1b4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()\n\nmt76_connac_mcu_alloc_sta_req() allocates an skb which is expected to\nbe freed eventually by mt76_mcu_skb_send_msg(). However, currently if\nan intermediate function fails before sending, the allocated skb is\nleaked.\n\nSpecifically, mt76_connac_mcu_sta_wed_update() and\nmt76_connac_mcu_sta_key_tlv() may fail, leading to an immediate memory\nleak in the error path.\n\nFix this by explicitly freeing the skb in these error paths.\nCommit 7c0f63fe37a5 (\"wifi: mt76: mt7996: fix memory leak on\nmt7996_mcu_sta_key_tlv error\") made a similar change.\n\nCompile tested only. Issue found using a prototype static analysis tool\nand code review.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53102","epss":0.00122,"percentile":0.02297,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53102","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53102","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53106","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53106","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Do not allow deleting local storage in NMI  Currently, local storage may deadlock when deferring freeing selem or local storage through kfree_rcu(), call_rcu() or call_rcu_tasks_trace() in NMI or reentrant. Since deleting selem in NMI is an unlikely use case, partially mitigate it by returning error when calling from bpf_xxx_storage_delete() helpers in NMI. Note that, it is still possible to deadlock through reentrant. A full mitigation requires returning error when irqs_disabled() is true, which, however is too heavy-handed for bpf_xxx_storage_delete().  The long-term solution requires _nolock versions of call_rcu. Another possible solution is to defer the free through irq_work [0], but it would grow the size of selem, which is non-ideal.  The check is only needed in bpf_selem_unlink(), which is used by helpers and syscalls. bpf_selem_unlink_nofail() is fine as it is called during map and owner tear down that never run in NMI or reentrant.  [0] https://lore.kernel.org/bpf/20260205190233.912-1-alexei.starovoitov@gmail.com/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53106","epss":0.001,"percentile":0.00965,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53106","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.052500000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-53106","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53106","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/350de5b8a9befaa2a68861c51f671d4f5f751ca5","https://git.kernel.org/stable/c/e84acaf936970b5b0be2c93bbf255295ba9406df"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Do not allow deleting local storage in NMI\n\nCurrently, local storage may deadlock when deferring freeing selem or\nlocal storage through kfree_rcu(), call_rcu() or call_rcu_tasks_trace()\nin NMI or reentrant. Since deleting selem in NMI is an unlikely use\ncase, partially mitigate it by returning error when calling from\nbpf_xxx_storage_delete() helpers in NMI. Note that, it is still possible\nto deadlock through reentrant. A full mitigation requires returning\nerror when irqs_disabled() is true, which, however is too heavy-handed\nfor bpf_xxx_storage_delete().\n\nThe long-term solution requires _nolock versions of call_rcu. Another\npossible solution is to defer the free through irq_work [0], but it\nwould grow the size of selem, which is non-ideal.\n\nThe check is only needed in bpf_selem_unlink(), which is used by helpers\nand syscalls. bpf_selem_unlink_nofail() is fine as it is called during\nmap and owner tear down that never run in NMI or reentrant.\n\n[0] https://lore.kernel.org/bpf/20260205190233.912-1-alexei.starovoitov@gmail.com/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53106","epss":0.001,"percentile":0.00965,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53106","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53106","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53107","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53107","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: libertas: don't kill URBs in interrupt context  Serialization for the TX path was enforced by calling usb_kill_urb()/usb_kill_anchored_urbs(), to prevent transmission before a previous URB was completed. usb_tx_block() can be called from interrupt context (e.g. in the HCD giveback path), so we can't always use it to kill in-flight URBs.  Prevent sleeping during interrupt context by checking the tx_submitted anchor for existing URBs. We now return -EBUSY, to indicate there's a pending request.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53107","epss":0.00113,"percentile":0.01578,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059325},"relatedVulnerabilities":[{"id":"CVE-2026-53107","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53107","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/00c0317cebf44151df18fb647781f315268cdd98","https://git.kernel.org/stable/c/4f273d3f98ebc60c30bbfb3ed4a7f0477d3eaed2","https://git.kernel.org/stable/c/7c5c2b661bdb78c1472b8833265c9ed1ee880039"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas: don't kill URBs in interrupt context\n\nSerialization for the TX path was enforced by calling\nusb_kill_urb()/usb_kill_anchored_urbs(), to prevent transmission before\na previous URB was completed. usb_tx_block() can be called from\ninterrupt context (e.g. in the HCD giveback path), so we can't always\nuse it to kill in-flight URBs.\n\nPrevent sleeping during interrupt context by checking the tx_submitted\nanchor for existing URBs. We now return -EBUSY, to indicate there's\na pending request.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53107","epss":0.00113,"percentile":0.01578,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53107","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53108","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53108","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  powerpc/64s: Fix unmap race with PMD migration entries  The following race is possible with migration swap entries or device-private THP entries. e.g. when move_pages is called on a PMD THP page, then there maybe an intermediate state, where PMD entry acts as a migration swap entry (pmd_present() is true). Then if an munmap happens at the same time, then this VM_BUG_ON() can happen in pmdp_huge_get_and_clear_full().  This patch fixes that.  Thread A: move_pages() syscall   add_folio_for_migration()     mmap_read_lock(mm)     folio_isolate_lru(folio)     mmap_read_unlock(mm)    do_move_pages_to_node()     migrate_pages()       try_to_migrate_one()         spin_lock(ptl)         set_pmd_migration_entry()           pmdp_invalidate()     # PMD: _PAGE_INVALID | _PAGE_PTE | pfn           set_pmd_at()          # PMD: migration swap entry (pmd_present=0)         spin_unlock(ptl)         [page copy phase]       # <--- RACE WINDOW -->  Thread B: munmap()   mmap_write_downgrade(mm)   unmap_vmas() -> zap_pmd_range()     zap_huge_pmd()       __pmd_trans_huge_lock()         pmd_is_huge():          # !pmd_present && !pmd_none -> TRUE (swap entry)         pmd_lock() -> \t\t# spin_lock(ptl), waits for Thread A to release ptl       pmdp_huge_get_and_clear_full()         VM_BUG_ON(!pmd_present(*pmdp))  # HITS!  [  287.738700][ T1867] ------------[ cut here ]------------ [  287.743843][ T1867] kernel BUG at arch/powerpc/mm/book3s64/pgtable.c:187! cpu 0x0: Vector: 700 (Program Check) at [c00000044037f4f0]     pc: c000000000094ca4: pmdp_huge_get_and_clear_full+0x6c/0x23c     lr: c000000000645dec: zap_huge_pmd+0xb0/0x868     sp: c00000044037f790    msr: 800000000282b033   current = 0xc0000004032c1a00   paca    = 0xc000000004fe0000   irqmask: 0x03   irq_happened: 0x09     pid   = 1867, comm = a.out kernel BUG at :187! Linux version 6.19.0-12136-g14360d4f917c-dirty (powerpc64le-linux-gnu-gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40) #27 SMP PREEMPT Sun Feb 22 10:38:56 IST 2026 enter ? for help [link register   ] c000000000645dec zap_huge_pmd+0xb0/0x868 [c00000044037f790] c00000044037f7d0 (unreliable) [c00000044037f7d0] c000000000645dcc zap_huge_pmd+0x90/0x868 [c00000044037f840] c0000000005724cc unmap_page_range+0x176c/0x1f40 [c00000044037fa00] c000000000572ea0 unmap_vmas+0xb0/0x1d8 [c00000044037fa90] c0000000005af254 unmap_region+0xb4/0x128 [c00000044037fb50] c0000000005af400 vms_complete_munmap_vmas+0x138/0x310 [c00000044037fbe0] c0000000005b0f1c do_vmi_align_munmap+0x1ec/0x238 [c00000044037fd30] c0000000005b3688 __vm_munmap+0x170/0x1f8 [c00000044037fdf0] c000000000587f74 sys_munmap+0x2c/0x40 [c00000044037fe10] c000000000032668 system_call_exception+0x128/0x350 [c00000044037fe50] c00000000000d05c system_call_vectored_common+0x15c/0x2ec ---- Exception: 3000 (System Call Vectored) at 0000000010064a2c SP (7fff9b1ee9c0) is in userspace 0:mon> zh  commit a30b48bf1b24 (\"mm/migrate_device: implement THP migration of zone device pages\"), enabled migration for device-private PMD entries. Hence this is one other path where this warning could get trigger from.   ------------[ cut here ]------------  WARNING: arch/powerpc/mm/book3s64/hash_pgtable.c:199 at hash__pmd_hugepage_update+0x48/0x284, CPU#3: hmm-tests/1905  Modules linked in: test_hmm  CPU: 3 UID: 0 PID: 1905 Comm: hmm-tests Tainted: G    B   W    L   N  7.0.0-rc1-01438-g7e2f0ee7581c #21 PREEMPT  Tainted: [B]=BAD_PAGE, [W]=WARN, [L]=SOFTLOCKUP, [N]=TEST  Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected) 0x801200 0xf000006 of:SLOF,git-ee03ae pSeries  NIP [c000000000096b70] hash__pmd_hugepage_update+0x48/0x284  LR [c000000000096e7c] hash__pmdp_huge_get_and_clear+0xd0/0xd4  Call Trace:  [c000000604707670] [c000000004e102b8] 0xc000000004e102b8 (unreliable)  [c000000604707700] [c00000000064ec3c] set_pmd_migration_entry+0x414/0x498  [c000000604707760] [c00000000063e5a4] migrate_vma_col ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53108","epss":0.00077,"percentile":0.00119,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53108","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.037345},"relatedVulnerabilities":[{"id":"CVE-2026-53108","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53108","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/829367e55012c053738ebe7db20c4a90d6609ece","https://git.kernel.org/stable/c/bbcbf045d6c778e82b47a35fc8728387708e9a3d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/64s: Fix unmap race with PMD migration entries\n\nThe following race is possible with migration swap entries or\ndevice-private THP entries. e.g. when move_pages is called on a PMD THP\npage, then there maybe an intermediate state, where PMD entry acts as\na migration swap entry (pmd_present() is true). Then if an munmap\nhappens at the same time, then this VM_BUG_ON() can happen in\npmdp_huge_get_and_clear_full().\n\nThis patch fixes that.\n\nThread A: move_pages() syscall\n  add_folio_for_migration()\n    mmap_read_lock(mm)\n    folio_isolate_lru(folio)\n    mmap_read_unlock(mm)\n\n  do_move_pages_to_node()\n    migrate_pages()\n      try_to_migrate_one()\n        spin_lock(ptl)\n        set_pmd_migration_entry()\n          pmdp_invalidate()     # PMD: _PAGE_INVALID | _PAGE_PTE | pfn\n          set_pmd_at()          # PMD: migration swap entry (pmd_present=0)\n        spin_unlock(ptl)\n        [page copy phase]       # <--- RACE WINDOW -->\n\nThread B: munmap()\n  mmap_write_downgrade(mm)\n  unmap_vmas() -> zap_pmd_range()\n    zap_huge_pmd()\n      __pmd_trans_huge_lock()\n        pmd_is_huge():          # !pmd_present && !pmd_none -> TRUE (swap entry)\n        pmd_lock() -> \t\t# spin_lock(ptl), waits for Thread A to release ptl\n      pmdp_huge_get_and_clear_full()\n        VM_BUG_ON(!pmd_present(*pmdp))  # HITS!\n\n[  287.738700][ T1867] ------------[ cut here ]------------\n[  287.743843][ T1867] kernel BUG at arch/powerpc/mm/book3s64/pgtable.c:187!\ncpu 0x0: Vector: 700 (Program Check) at [c00000044037f4f0]\n    pc: c000000000094ca4: pmdp_huge_get_and_clear_full+0x6c/0x23c\n    lr: c000000000645dec: zap_huge_pmd+0xb0/0x868\n    sp: c00000044037f790\n   msr: 800000000282b033\n  current = 0xc0000004032c1a00\n  paca    = 0xc000000004fe0000   irqmask: 0x03   irq_happened: 0x09\n    pid   = 1867, comm = a.out\nkernel BUG at :187!\nLinux version 6.19.0-12136-g14360d4f917c-dirty (powerpc64le-linux-gnu-gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40) #27 SMP PREEMPT Sun Feb 22 10:38:56 IST 2026\nenter ? for help\n[link register   ] c000000000645dec zap_huge_pmd+0xb0/0x868\n[c00000044037f790] c00000044037f7d0 (unreliable)\n[c00000044037f7d0] c000000000645dcc zap_huge_pmd+0x90/0x868\n[c00000044037f840] c0000000005724cc unmap_page_range+0x176c/0x1f40\n[c00000044037fa00] c000000000572ea0 unmap_vmas+0xb0/0x1d8\n[c00000044037fa90] c0000000005af254 unmap_region+0xb4/0x128\n[c00000044037fb50] c0000000005af400 vms_complete_munmap_vmas+0x138/0x310\n[c00000044037fbe0] c0000000005b0f1c do_vmi_align_munmap+0x1ec/0x238\n[c00000044037fd30] c0000000005b3688 __vm_munmap+0x170/0x1f8\n[c00000044037fdf0] c000000000587f74 sys_munmap+0x2c/0x40\n[c00000044037fe10] c000000000032668 system_call_exception+0x128/0x350\n[c00000044037fe50] c00000000000d05c system_call_vectored_common+0x15c/0x2ec\n---- Exception: 3000 (System Call Vectored) at 0000000010064a2c\nSP (7fff9b1ee9c0) is in userspace\n0:mon> zh\n\ncommit a30b48bf1b24 (\"mm/migrate_device: implement THP migration of zone device pages\"),\nenabled migration for device-private PMD entries. Hence this is one\nother path where this warning could get trigger from.\n\n ------------[ cut here ]------------\n WARNING: arch/powerpc/mm/book3s64/hash_pgtable.c:199 at hash__pmd_hugepage_update+0x48/0x284, CPU#3: hmm-tests/1905\n Modules linked in: test_hmm\n CPU: 3 UID: 0 PID: 1905 Comm: hmm-tests Tainted: G    B   W    L   N  7.0.0-rc1-01438-g7e2f0ee7581c #21 PREEMPT\n Tainted: [B]=BAD_PAGE, [W]=WARN, [L]=SOFTLOCKUP, [N]=TEST\n Hardware name: IBM pSeries (emulated by qemu) POWER10 (architected) 0x801200 0xf000006 of:SLOF,git-ee03ae pSeries\n NIP [c000000000096b70] hash__pmd_hugepage_update+0x48/0x284\n LR [c000000000096e7c] hash__pmdp_huge_get_and_clear+0xd0/0xd4\n Call Trace:\n [c000000604707670] [c000000004e102b8] 0xc000000004e102b8 (unreliable)\n [c000000604707700] [c00000000064ec3c] set_pmd_migration_entry+0x414/0x498\n [c000000604707760] [c00000000063e5a4] migrate_vma_col\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"exploitabilityScore":1.1,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53108","epss":0.00077,"percentile":0.00119,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53108","cwe":"CWE-362","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53108","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53115","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53115","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bus: fsl-mc: use generic driver_override infrastructure  When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF.  Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally.  Note that calling match() from __driver_attach() without the device lock held is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53115","epss":0.0012,"percentile":0.02079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53115","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53115","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53115","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4911b836f35c034c36f102db4ecbe339b38e7d1d","https://git.kernel.org/stable/c/60bfb563a399c4597dc80588a1109758a8908b97","https://git.kernel.org/stable/c/6c8dfb0362732bf1e4829867a2a5239fedc592d0","https://git.kernel.org/stable/c/8139ce66b52a4a5638bfb445b037c07d4abeb08e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbus: fsl-mc: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53115","epss":0.0012,"percentile":0.02079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53115","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53115","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53117","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/cio: use generic driver_override infrastructure  When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF.  Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally.  Note that calling match() from __driver_attach() without the device lock held is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53117","epss":0.00122,"percentile":0.02288,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53117","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09333},"relatedVulnerabilities":[{"id":"CVE-2026-53117","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53117","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/106d594711e97762788046c5bbb94f580abc4bf4","https://git.kernel.org/stable/c/2081957d8c323ffb58a10bc64837717ac5a042a1","https://git.kernel.org/stable/c/ac4d8bb6e2e13e8684a76ea48d13ebaaaf5c24c4","https://git.kernel.org/stable/c/b660ba045b2b22cf3b4be72773de00cb48f47be5","https://git.kernel.org/stable/c/c4295487124f461405e1ef64dfa8c4ab0cb7ebcf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/cio: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53117","epss":0.00122,"percentile":0.02288,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53117","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53117","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53118","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53118","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vdpa: use generic driver_override infrastructure  When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF.  Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally.  Note that calling match() from __driver_attach() without the device lock held is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53118","epss":0.00119,"percentile":0.01984,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53118","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.091035},"relatedVulnerabilities":[{"id":"CVE-2026-53118","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53118","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/654ef9c33e138ede6734ac286282df9faf83cd11","https://git.kernel.org/stable/c/85bb534ff12aab6916058897b39c748940a7a4c6","https://git.kernel.org/stable/c/fb5cb4913ce333cc4647722e8c2b8378e12f2464"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53118","epss":0.00119,"percentile":0.01984,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53118","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53118","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53120","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53120","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  PCI: use generic driver_override infrastructure  When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF.  Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally.  Note that calling match() from __driver_attach() without the device lock held is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53120","epss":0.0012,"percentile":0.02079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53120","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53120","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53120","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/10a4206a24013be4d558d476010cbf2eb4c9fa64","https://git.kernel.org/stable/c/58a42be0d70307d765594fc581f5f5e5ef059712","https://git.kernel.org/stable/c/c5b2c5755495507e14f310c2653c85de0a309b1f","https://git.kernel.org/stable/c/dfe950d9464cad609f3b118c6203e2708055bc61"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53120","epss":0.0012,"percentile":0.02079,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53120","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53120","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53122","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53122","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix deadlock between reflink and transaction commit when using flushoncommit  When using the flushoncommit mount option, we can have a deadlock between a transaction commit and a reflink operation that copied an inline extent to an offset beyond the current i_size of the destination node.  The deadlock happens like this:  1) Task A clones an inline extent from inode X to an offset of inode Y    that is beyond Y's current i_size. This means we copied the inline    extent's data to a folio of inode Y that is beyond its EOF, using a    call to copy_inline_to_page();  2) Task B starts a transaction commit and calls    btrfs_start_delalloc_flush() to flush delalloc;  3) The delalloc flushing sees the new dirty folio of inode Y and when it    attempts to flush it, it ends up at extent_writepage() and sees that    the offset of the folio is beyond the i_size of inode Y, so it attempts    to invalidate the folio by calling folio_invalidate(), which ends up at    btrfs' folio invalidate callback - btrfs_invalidate_folio(). There it    tries to lock the folio's range in inode Y's extent io tree, but it    blocks since it's currently locked by task A - during a reflink we lock    the inodes and the source and destination ranges after flushing all    delalloc and waiting for ordered extent completion - after that we    don't expect to have dirty folios in the ranges, the exception is if    we have to copy an inline extent's data (because the destination offset    is not zero);  4) Task A then attempts to start a transaction to update the inode item,    and then it's blocked since the current transaction is in the    TRANS_STATE_COMMIT_START state. Therefore task A has to wait for the    current transaction to become unblocked (its state >=    TRANS_STATE_UNBLOCKED).     So task A is waiting for the transaction commit done by task B, and    the later waiting on the extent lock of inode Y that is currently    held by task A.  Syzbot recently reported this with the following stack traces:    INFO: task kworker/u8:7:1053 blocked for more than 143 seconds.         Not tainted syzkaller #0   \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.   task:kworker/u8:7    state:D stack:23520 pid:1053  tgid:1053  ppid:2      task_flags:0x4208060 flags:0x00080000   Workqueue: writeback wb_workfn (flush-btrfs-46)   Call Trace:    <TASK>    context_switch kernel/sched/core.c:5298 [inline]    __schedule+0x1553/0x5240 kernel/sched/core.c:6911    __schedule_loop kernel/sched/core.c:6993 [inline]    schedule+0x164/0x360 kernel/sched/core.c:7008    wait_extent_bit fs/btrfs/extent-io-tree.c:811 [inline]    btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:1914    btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline]    btrfs_invalidate_folio+0x43d/0xc40 fs/btrfs/inode.c:7704    extent_writepage fs/btrfs/extent_io.c:1852 [inline]    extent_write_cache_pages fs/btrfs/extent_io.c:2580 [inline]    btrfs_writepages+0x12ff/0x2440 fs/btrfs/extent_io.c:2713    do_writepages+0x32e/0x550 mm/page-writeback.c:2554    __writeback_single_inode+0x133/0x11a0 fs/fs-writeback.c:1750    writeback_sb_inodes+0x995/0x19d0 fs/fs-writeback.c:2042    wb_writeback+0x456/0xb70 fs/fs-writeback.c:2227    wb_do_writeback fs/fs-writeback.c:2374 [inline]    wb_workfn+0x41a/0xf60 fs/fs-writeback.c:2414    process_one_work kernel/workqueue.c:3276 [inline]    process_scheduled_works+0xb6e/0x18c0 kernel/workqueue.c:3359    worker_thread+0xa53/0xfc0 kernel/workqueue.c:3440    kthread+0x388/0x470 kernel/kthread.c:436    ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245    </TASK>   INFO: task syz.4.64:6910 blocked for more than 143 seconds.         Not tainted syzkaller #0   \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.   task:syz.4.64        state:D stack:22752 pid:6910  tgid: ---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53122","epss":0.00093,"percentile":0.00606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53122","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.048825},"relatedVulnerabilities":[{"id":"CVE-2026-53122","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53122","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6f0f9c0a368aa1fe078109091322d3b0632d9380","https://git.kernel.org/stable/c/73be4a08306bb84f4d5d16f62cb80e1543109ffa","https://git.kernel.org/stable/c/9a24f0000876b8755cf21972b41632f4d6f3dafb","https://git.kernel.org/stable/c/b48c980b6a7e409050bb3067165db31cc6205e3e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock between reflink and transaction commit when using flushoncommit\n\nWhen using the flushoncommit mount option, we can have a deadlock between\na transaction commit and a reflink operation that copied an inline extent\nto an offset beyond the current i_size of the destination node.\n\nThe deadlock happens like this:\n\n1) Task A clones an inline extent from inode X to an offset of inode Y\n   that is beyond Y's current i_size. This means we copied the inline\n   extent's data to a folio of inode Y that is beyond its EOF, using a\n   call to copy_inline_to_page();\n\n2) Task B starts a transaction commit and calls\n   btrfs_start_delalloc_flush() to flush delalloc;\n\n3) The delalloc flushing sees the new dirty folio of inode Y and when it\n   attempts to flush it, it ends up at extent_writepage() and sees that\n   the offset of the folio is beyond the i_size of inode Y, so it attempts\n   to invalidate the folio by calling folio_invalidate(), which ends up at\n   btrfs' folio invalidate callback - btrfs_invalidate_folio(). There it\n   tries to lock the folio's range in inode Y's extent io tree, but it\n   blocks since it's currently locked by task A - during a reflink we lock\n   the inodes and the source and destination ranges after flushing all\n   delalloc and waiting for ordered extent completion - after that we\n   don't expect to have dirty folios in the ranges, the exception is if\n   we have to copy an inline extent's data (because the destination offset\n   is not zero);\n\n4) Task A then attempts to start a transaction to update the inode item,\n   and then it's blocked since the current transaction is in the\n   TRANS_STATE_COMMIT_START state. Therefore task A has to wait for the\n   current transaction to become unblocked (its state >=\n   TRANS_STATE_UNBLOCKED).\n\n   So task A is waiting for the transaction commit done by task B, and\n   the later waiting on the extent lock of inode Y that is currently\n   held by task A.\n\nSyzbot recently reported this with the following stack traces:\n\n  INFO: task kworker/u8:7:1053 blocked for more than 143 seconds.\n        Not tainted syzkaller #0\n  \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n  task:kworker/u8:7    state:D stack:23520 pid:1053  tgid:1053  ppid:2      task_flags:0x4208060 flags:0x00080000\n  Workqueue: writeback wb_workfn (flush-btrfs-46)\n  Call Trace:\n   <TASK>\n   context_switch kernel/sched/core.c:5298 [inline]\n   __schedule+0x1553/0x5240 kernel/sched/core.c:6911\n   __schedule_loop kernel/sched/core.c:6993 [inline]\n   schedule+0x164/0x360 kernel/sched/core.c:7008\n   wait_extent_bit fs/btrfs/extent-io-tree.c:811 [inline]\n   btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:1914\n   btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline]\n   btrfs_invalidate_folio+0x43d/0xc40 fs/btrfs/inode.c:7704\n   extent_writepage fs/btrfs/extent_io.c:1852 [inline]\n   extent_write_cache_pages fs/btrfs/extent_io.c:2580 [inline]\n   btrfs_writepages+0x12ff/0x2440 fs/btrfs/extent_io.c:2713\n   do_writepages+0x32e/0x550 mm/page-writeback.c:2554\n   __writeback_single_inode+0x133/0x11a0 fs/fs-writeback.c:1750\n   writeback_sb_inodes+0x995/0x19d0 fs/fs-writeback.c:2042\n   wb_writeback+0x456/0xb70 fs/fs-writeback.c:2227\n   wb_do_writeback fs/fs-writeback.c:2374 [inline]\n   wb_workfn+0x41a/0xf60 fs/fs-writeback.c:2414\n   process_one_work kernel/workqueue.c:3276 [inline]\n   process_scheduled_works+0xb6e/0x18c0 kernel/workqueue.c:3359\n   worker_thread+0xa53/0xfc0 kernel/workqueue.c:3440\n   kthread+0x388/0x470 kernel/kthread.c:436\n   ret_from_fork+0x51e/0xb90 arch/x86/kernel/process.c:158\n   ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n   </TASK>\n  INFO: task syz.4.64:6910 blocked for more than 143 seconds.\n        Not tainted syzkaller #0\n  \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n  task:syz.4.64        state:D stack:22752 pid:6910  tgid:\n---truncated---","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53122","epss":0.00093,"percentile":0.00606,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53122","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53122","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53129","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53129","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/mbcache: cancel shrink work before destroying the cache  mb_cache_destroy() calls shrinker_free() and then frees all cache entries and the cache itself, but it does not cancel the pending c_shrink_work work item first.  If mb_cache_entry_create() schedules c_shrink_work via schedule_work() and the work item is still pending or running when mb_cache_destroy() runs, mb_cache_shrink_worker() will access the cache after its memory has been freed, causing a use-after-free.  This is only reachable by a privileged user (root or CAP_SYS_ADMIN) who can trigger the last put of a mounted ext2/ext4/ocfs2 filesystem.  Cancel the work item with cancel_work_sync() before calling shrinker_free(), ensuring the worker has finished and will not be rescheduled before the cache is torn down.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53129","epss":0.00117,"percentile":0.01864,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53129","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-53129","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53129","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0e4eff315d799f5842b95872199b0f0fb8ef5f51","https://git.kernel.org/stable/c/a88d39a74a208e197c03bffaa2df34de732af19f","https://git.kernel.org/stable/c/b25fd3523bef88fb7ffd4c5b63bbe9c08f73bb4c","https://git.kernel.org/stable/c/d227786ab1119669df4dc333a61510c52047cce4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/mbcache: cancel shrink work before destroying the cache\n\nmb_cache_destroy() calls shrinker_free() and then frees all cache\nentries and the cache itself, but it does not cancel the pending\nc_shrink_work work item first.\n\nIf mb_cache_entry_create() schedules c_shrink_work via schedule_work()\nand the work item is still pending or running when mb_cache_destroy()\nruns, mb_cache_shrink_worker() will access the cache after its memory\nhas been freed, causing a use-after-free.\n\nThis is only reachable by a privileged user (root or CAP_SYS_ADMIN)\nwho can trigger the last put of a mounted ext2/ext4/ocfs2 filesystem.\n\nCancel the work item with cancel_work_sync() before calling\nshrinker_free(), ensuring the worker has finished and will not be\nrescheduled before the cache is torn down.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53129","epss":0.00117,"percentile":0.01864,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53129","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53129","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53132","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53132","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vsock/virtio: fix potential unbounded skb queue  virtio_transport_inc_rx_pkt() checks vvs->rx_bytes + len > vvs->buf_alloc.  virtio_transport_recv_enqueue() skips coalescing for packets with VIRTIO_VSOCK_SEQ_EOM.  If fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM, a very large number of packets can be queued because vvs->rx_bytes stays at 0.  Fix this by estimating the skb metadata size:  \t(Number of skbs in the queue) * SKB_TRUESIZE(0)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.6,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53132","epss":0.00138,"percentile":0.03538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53132","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10073999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-53132","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53132","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/059b7dbd20a6f0c539a45ddff1573cb8946685b5","https://git.kernel.org/stable/c/100d5b2ffdc6468b9e48532641f29e83efdcb63c","https://git.kernel.org/stable/c/1eca304f97a34ed5e921e1f0e06c8b241f25bf12","https://git.kernel.org/stable/c/9bdc637fde66b63d6cad0caacd034888bb7bf5f5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: fix potential unbounded skb queue\n\nvirtio_transport_inc_rx_pkt() checks vvs->rx_bytes + len > vvs->buf_alloc.\n\nvirtio_transport_recv_enqueue() skips coalescing for packets\nwith VIRTIO_VSOCK_SEQ_EOM.\n\nIf fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM,\na very large number of packets can be queued\nbecause vvs->rx_bytes stays at 0.\n\nFix this by estimating the skb metadata size:\n\n\t(Number of skbs in the queue) * SKB_TRUESIZE(0)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.6,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53132","epss":0.00138,"percentile":0.03538,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53132","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53132","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53143","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11  The v11 MQD manager incorrectly assigned the CP-compute variants of checkpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions use sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct v11_sdma_mqd) (512 bytes), causing a 1536-byte overflow.  During CRIU checkpoint of an SDMA queue on Navi3x: - checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer,   leaking 1536 bytes of adjacent GTT memory to userspace  During CRIU restore: - restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer,   corrupting 1536 bytes of adjacent GTT memory (often the ring buffer   or neighboring MQDs)  This is a copy-paste regression unique to v11. All other ASIC backends (cik, vi, v9, v10, v12) correctly use the SDMA-specific variants.  Add checkpoint_mqd_sdma() and restore_mqd_sdma() functions that properly handle the smaller v11_sdma_mqd structure, matching the pattern used in other MQD managers.  (cherry picked from commit 6fa41db7ffdec97d62433adf03b7b9b759af8c2c)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53143","epss":0.00153,"percentile":0.04745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53143","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-53143","cwe":"CWE-131","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.117045},"relatedVulnerabilities":[{"id":"CVE-2026-53143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53143","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/16dad1fb0d783a4008de30e32d0038c393de05b1","https://git.kernel.org/stable/c/2c5b66c9b4057b385566940935ebc32f6e6ebfd2","https://git.kernel.org/stable/c/352ea59028ea48a6fff77f19ae28f98f71946a80","https://git.kernel.org/stable/c/d02f05d30f35b036f7cbaf72de634affb5b38ec6","https://git.kernel.org/stable/c/d3efcadfe3eea5b4263b8f2d4463b15c9fc46a64","https://access.redhat.com/errata/RHSA-2026:57251","https://access.redhat.com/errata/RHSA-2026:57252","https://access.redhat.com/security/cve/CVE-2026-53143","https://bugzilla.redhat.com/show_bug.cgi?id=2492719","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53143.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11\n\nThe v11 MQD manager incorrectly assigned the CP-compute variants of\ncheckpoint_mqd/restore_mqd for KFD_MQD_TYPE_SDMA queues. These functions\nuse sizeof(struct v11_compute_mqd) (2048 bytes) instead of sizeof(struct\nv11_sdma_mqd) (512 bytes), causing a 1536-byte overflow.\n\nDuring CRIU checkpoint of an SDMA queue on Navi3x:\n- checkpoint_mqd() reads 2048 bytes from a 512-byte SDMA MQD buffer,\n  leaking 1536 bytes of adjacent GTT memory to userspace\n\nDuring CRIU restore:\n- restore_mqd() writes 2048 bytes into a 512-byte SDMA MQD buffer,\n  corrupting 1536 bytes of adjacent GTT memory (often the ring buffer\n  or neighboring MQDs)\n\nThis is a copy-paste regression unique to v11. All other ASIC backends\n(cik, vi, v9, v10, v12) correctly use the SDMA-specific variants.\n\nAdd checkpoint_mqd_sdma() and restore_mqd_sdma() functions that properly\nhandle the smaller v11_sdma_mqd structure, matching the pattern used in\nother MQD managers.\n\n(cherry picked from commit 6fa41db7ffdec97d62433adf03b7b9b759af8c2c)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53143","epss":0.00153,"percentile":0.04745,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53143","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-53143","cwe":"CWE-131","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53143","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53156","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53156","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmem: core: fix use-after-free bugs in error paths  Fix several instances of error paths in which we call __nvmem_device_put() - which may end up freeing the underlying memory and other resources - and then keep on using the nvmem structure. Always put the reference to the nvmem device as the last step before returning the error code.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53156","epss":0.0017,"percentile":0.066,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53156","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13005},"relatedVulnerabilities":[{"id":"CVE-2026-53156","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53156","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/40e2a459c0dd1333b2343831480a0ad80dc07614","https://git.kernel.org/stable/c/5b6b6fc491899d583eaa75344e094796ae9b530b","https://git.kernel.org/stable/c/cb85ef5a227b3662b88f4d849a1aad43bfe7f5ae","https://git.kernel.org/stable/c/e0d38bf47a72da2f02c9fa6f752cd66d977cd7f7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmem: core: fix use-after-free bugs in error paths\n\nFix several instances of error paths in which we call\n__nvmem_device_put() - which may end up freeing the underlying memory\nand other resources - and then keep on using the nvmem structure. Always\nput the reference to the nvmem device as the last step before returning\nthe error code.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53156","epss":0.0017,"percentile":0.066,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53156","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53156","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53178","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53178","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction  Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prevent unsigned integer underflow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53178","epss":0.00311,"percentile":0.2367,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53178","cwe":"CWE-191","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.24258000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-53178","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53178","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/542d65a6dbd9733baab96313c9fe76a76e93f484","https://git.kernel.org/stable/c/88e994c57a79f62d5338231d8d37ee8dd98baffe"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction\n\nAdd guards to ensure ie_length is large enough before subtracting\nfixed IE offsets to prevent unsigned integer underflow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53178","epss":0.00311,"percentile":0.2367,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53178","cwe":"CWE-191","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53178","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53179","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53179","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: fix buffer over-read in rtw_update_protection  rtw_update_protection() is called with a pointer offset into the ies buffer but the full ie_length is passed, causing a potential buffer over-read.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53179","epss":0.00166,"percentile":0.06125,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53179","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12118000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-53179","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53179","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/303f65af819f6d5aa302e82bce72b57a8575faea","https://git.kernel.org/stable/c/514ab98364595007d4557ecc85d7e5f012c504d3","https://git.kernel.org/stable/c/735dabdf21561a24d8bcae456c9c32f7f961a029","https://git.kernel.org/stable/c/c35ce55b12bb8fcd365daeb516e9782048119b36"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix buffer over-read in rtw_update_protection\n\nrtw_update_protection() is called with a pointer offset into the\nies buffer but the full ie_length is passed, causing a potential\nbuffer over-read.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53179","epss":0.00166,"percentile":0.06125,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53179","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53179","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53185","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53185","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  zram: fix use-after-free in zram_bvec_write_partial()  zram_read_page() picks the sync or async backing device read path based on whether the parent bio is NULL.  zram_bvec_write_partial() passes its parent bio down, so for ZRAM_WB slots the read is dispatched asynchronously and zram_read_page() returns 0 while the bio is still in flight.  The caller then runs memcpy_from_bvec(), zram_write_page() and __free_page() on the buffer, leaving the async read to write into a freed page.  zram_bvec_read_partial() was switched to NULL in commit 4e3c87b9421d (\"zram: fix synchronous reads\") for the same reason; the write_partial counterpart was missed.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53185","epss":0.00102,"percentile":0.01043,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53185","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-53185","cwe":"CWE-364","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07395},"relatedVulnerabilities":[{"id":"CVE-2026-53185","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53185","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0c2821665ff71be3f4b07ecece384669f2877f6a","https://git.kernel.org/stable/c/198b5a14cca27263b9c14b20114c8092de15dfcb","https://git.kernel.org/stable/c/732fd9f0b9c1cdc6dfd77162ded60df005182cc0","https://git.kernel.org/stable/c/77a602b505ce4802915853cfc435a4722fab3e64","https://git.kernel.org/stable/c/c96786d6ff1acc1d54d9241e97767554c1dfdd5b","https://access.redhat.com/errata/RHSA-2026:59723","https://access.redhat.com/errata/RHSA-2026:61887","https://access.redhat.com/errata/RHSA-2026:63013","https://access.redhat.com/errata/RHSA-2026:63014","https://access.redhat.com/errata/RHSA-2026:65708","https://access.redhat.com/security/cve/CVE-2026-53185","https://bugzilla.redhat.com/show_bug.cgi?id=2492735","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53185.json"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nzram: fix use-after-free in zram_bvec_write_partial()\n\nzram_read_page() picks the sync or async backing device read path based on\nwhether the parent bio is NULL.  zram_bvec_write_partial() passes its\nparent bio down, so for ZRAM_WB slots the read is dispatched\nasynchronously and zram_read_page() returns 0 while the bio is still in\nflight.  The caller then runs memcpy_from_bvec(), zram_write_page() and\n__free_page() on the buffer, leaving the async read to write into a freed\npage.\n\nzram_bvec_read_partial() was switched to NULL in commit 4e3c87b9421d\n(\"zram: fix synchronous reads\") for the same reason; the write_partial\ncounterpart was missed.","cvss":[{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"exploitabilityScore":1.1,"impactScore":5.9},"vendorMetadata":{}},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53185","epss":0.00102,"percentile":0.01043,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53185","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"},{"cve":"CVE-2026-53185","cwe":"CWE-364","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53185","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53220","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53220","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: revalidate bridge ports  ebt_redirect_tg() dereferences br_port_get_rcu() return without a NULL check, causing a kernel panic when the bridge port has been removed between the original hook invocation and an NFQUEUE reinject.  A mere NULL check isn't sufficient, however.  As sashiko review points out userspace can not only remove the port from the bridge, it could also place the device in a different virtual device, e.g. macvlan.  If this happens, we must drop the packet, there is no way for us to reinject it into the bridge path.  Switch to _upper API, we don't need the bridge port structure. Also, this fix keeps another bug intact:  Both nfnetlink_log and nfnetlink_queue use CONFIG_BRIDGE_NETFILTER too aggressive, which prevents certain logging features when queueing in bridge family: NETFILTER_FAMILY_BRIDGE can be enabled while the old CONFIG_BRIDGE_NETFILTER cruft is off.  Fixes tag is a common ancestor, this was always broken.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53220","epss":0.00162,"percentile":0.05689,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53220","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08505},"relatedVulnerabilities":[{"id":"CVE-2026-53220","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53220","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/43330a1e8aace6b5a8de9aba127e9e394ab49b0f","https://git.kernel.org/stable/c/4beffcd726e2a731cea4dc18e1fbc55c8d76f1a0","https://git.kernel.org/stable/c/ccb9fd4b87538ccf19ccff78ee26700526d94867","https://git.kernel.org/stable/c/d4b1301fd3c9e5e105fd3767c68bc4ba558bb228"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: revalidate bridge ports\n\nebt_redirect_tg() dereferences br_port_get_rcu() return without a\nNULL check, causing a kernel panic when the bridge port has been\nremoved between the original hook invocation and an NFQUEUE\nreinject.\n\nA mere NULL check isn't sufficient, however.  As sashiko review\npoints out userspace can not only remove the port from the bridge,\nit could also place the device in a different virtual device, e.g.\nmacvlan.\n\nIf this happens, we must drop the packet, there is no way for us to\nreinject it into the bridge path.\n\nSwitch to _upper API, we don't need the bridge port structure.\nAlso, this fix keeps another bug intact:\n\nBoth nfnetlink_log and nfnetlink_queue use CONFIG_BRIDGE_NETFILTER\ntoo aggressive, which prevents certain logging features when queueing\nin bridge family: NETFILTER_FAMILY_BRIDGE can be enabled while the old\nCONFIG_BRIDGE_NETFILTER cruft is off.\n\nFixes tag is a common ancestor, this was always broken.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53220","epss":0.00162,"percentile":0.05689,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53220","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53220","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53224","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53224","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: validate embedded INIT chunk and address list lengths in cookie  sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remaining cookie payload, but did not ensure that the INIT chunk is large enough to contain a complete INIT header.  A malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose length field is smaller than sizeof(struct sctp_init_chunk).  Later, sctp_process_init() accesses INIT parameters unconditionally, which may lead to out-of-bounds reads.  In addition, raw_addr_list_len is not fully validated against the remaining cookie payload. When cookie authentication is disabled, an attacker can supply an oversized raw_addr_list_len and cause sctp_raw_to_bind_addrs() to read beyond the end of the cookie. The address parser also lacks sufficient bounds checks for parameter headers and lengths, allowing malformed address parameters to trigger out-of-bounds reads.  Fix this by:  - requiring the embedded INIT chunk length to be at least sizeof(struct   sctp_init_chunk); - validating that the INIT chunk and raw address list together fit   within the cookie payload; - verifying sufficient data exists for each address parameter header and   payload before parsing it.  Note that sctp_verify_init() must be called after sctp_unpack_cookie() and before sctp_process_init() when cookie authentication is disabled. This will be addressed in a separate patch.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53224","epss":0.00517,"percentile":0.42338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53224","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.467885},"relatedVulnerabilities":[{"id":"CVE-2026-53224","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53224","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/512a9bb77c04ac9927648ea58af617e472be96e6","https://git.kernel.org/stable/c/6f4c80a2a7e6d06753b89a578b710a2499a5e62b","https://git.kernel.org/stable/c/7560afb8cddafd829e709d7ea09230e45a825557"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate embedded INIT chunk and address list lengths in cookie\n\nsctp_unpack_cookie() only checked that the embedded INIT chunk length\ndid not exceed the remaining cookie payload, but did not ensure that the\nINIT chunk is large enough to contain a complete INIT header.\n\nA malformed COOKIE_ECHO can therefore carry a truncated INIT chunk whose\nlength field is smaller than sizeof(struct sctp_init_chunk).  Later,\nsctp_process_init() accesses INIT parameters unconditionally, which may\nlead to out-of-bounds reads.\n\nIn addition, raw_addr_list_len is not fully validated against the\nremaining cookie payload. When cookie authentication is disabled, an\nattacker can supply an oversized raw_addr_list_len and cause\nsctp_raw_to_bind_addrs() to read beyond the end of the cookie. The\naddress parser also lacks sufficient bounds checks for parameter headers\nand lengths, allowing malformed address parameters to trigger\nout-of-bounds reads.\n\nFix this by:\n\n- requiring the embedded INIT chunk length to be at least sizeof(struct\n  sctp_init_chunk);\n- validating that the INIT chunk and raw address list together fit\n  within the cookie payload;\n- verifying sufficient data exists for each address parameter header and\n  payload before parsing it.\n\nNote that sctp_verify_init() must be called after sctp_unpack_cookie()\nand before sctp_process_init() when cookie authentication is disabled.\nThis will be addressed in a separate patch.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53224","epss":0.00517,"percentile":0.42338,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53224","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53224","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53226","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53226","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: rockchip: fix generic IRQ chip leak on remove  The driver allocates domain generic chips using irq_alloc_domain_generic_chips() during probe. However, on driver remove/teardown, the generic chips are not automatically freed when the IRQ domain is removed because the domain flags do not include IRQ_DOMAIN_FLAG_DESTROY_GC.  This causes both the domain generic chips structure and the associated generic chips to be leaked. Additionally, the generic chips remain on the global gc_list and may later be visited by generic IRQ chip suspend, resume, or shutdown callbacks after the GPIO bank has been removed, potentially resulting in a use-after-free and kernel crash.  Fix the resource leak by explicitly calling irq_domain_remove_generic_chips() before removing the IRQ domain in rockchip_gpio_remove().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53226","epss":0.00119,"percentile":0.01963,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53226","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-53226","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53226","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1c1e0fc88d6ef65bf15d517853251f75ab9d18c3","https://git.kernel.org/stable/c/1f34ea5f6114011092d9a5c8b901ad6741144a1d","https://git.kernel.org/stable/c/50c7a6d2bf179588ba2daee97be93d19c96a94af","https://git.kernel.org/stable/c/bace7b99bfa555fe833aee8827b8004c43666d02"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: rockchip: fix generic IRQ chip leak on remove\n\nThe driver allocates domain generic chips using\nirq_alloc_domain_generic_chips() during probe. However, on driver\nremove/teardown, the generic chips are not automatically freed when the\nIRQ domain is removed because the domain flags do not include\nIRQ_DOMAIN_FLAG_DESTROY_GC.\n\nThis causes both the domain generic chips structure and the associated\ngeneric chips to be leaked. Additionally, the generic chips remain on\nthe global gc_list and may later be visited by generic IRQ chip suspend,\nresume, or shutdown callbacks after the GPIO bank has been removed,\npotentially resulting in a use-after-free and kernel crash.\n\nFix the resource leak by explicitly calling\nirq_domain_remove_generic_chips() before removing the IRQ domain in\nrockchip_gpio_remove().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53226","epss":0.00119,"percentile":0.01963,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53226","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53226","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53229","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53229","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure  In the XSK branch of mlx5e_xmit_xdp_buff(), when sq->xmit_xdp_frame() returns false (e.g. XDPSQ is full), the function returns without unmapping the DMA address or freeing the xdp_frame allocated by xdp_convert_zc_to_xdp_frame(). The xdpi_fifo push only happens on success, so the completion path cannot recover these entries.  With CONFIG_DMA_API_DEBUG=y, the leak surfaces on driver unbind:    DMA-API: pci 0000:08:00.0: device driver has pending DMA   allocations while released from device [count=1116]   One of leaked entries details: [device address=0x000000010ffd7028]   [size=1534 bytes] [mapped with DMA_TO_DEVICE] [mapped as phy]   WARNING: kernel/dma/debug.c:881 at dma_debug_device_change+0x127/0x180   ...   DMA-API: Mapped at:    debug_dma_map_phys+0x4b/0xd0    dma_map_phys+0xfd/0x2d0    mlx5e_xdp_handle+0x5ae/0xac0 [mlx5_core]    mlx5e_xsk_skb_from_cqe_mpwrq_linear+0xc4/0x170 [mlx5_core]    mlx5e_handle_rx_cqe_mpwrq+0xc1/0x290 [mlx5_core]  Add the missing unmap + xdp_return_frame, matching the cleanup already done in mlx5e_xdp_xmit(). has_frags is rejected earlier in this branch, so no per-frag unmap is needed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53229","epss":0.0063,"percentile":0.48117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53229","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.47250000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-53229","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53229","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0aabca726b43d833721034e97d99efcc8237b22a","https://git.kernel.org/stable/c/2789b74ae1f4b68333c9d5eec2f3354d07b16e61","https://git.kernel.org/stable/c/7b3eeba50fbc3b45f279037c29a87a90e8bac1e1","https://git.kernel.org/stable/c/b69004f5a6ad32da84d8aa5b23b9c0caafe6252e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure\n\nIn the XSK branch of mlx5e_xmit_xdp_buff(), when sq->xmit_xdp_frame()\nreturns false (e.g. XDPSQ is full), the function returns without\nunmapping the DMA address or freeing the xdp_frame allocated by\nxdp_convert_zc_to_xdp_frame(). The xdpi_fifo push only happens on\nsuccess, so the completion path cannot recover these entries.\n\nWith CONFIG_DMA_API_DEBUG=y, the leak surfaces on driver unbind:\n\n  DMA-API: pci 0000:08:00.0: device driver has pending DMA\n  allocations while released from device [count=1116]\n  One of leaked entries details: [device address=0x000000010ffd7028]\n  [size=1534 bytes] [mapped with DMA_TO_DEVICE] [mapped as phy]\n  WARNING: kernel/dma/debug.c:881 at dma_debug_device_change+0x127/0x180\n  ...\n  DMA-API: Mapped at:\n   debug_dma_map_phys+0x4b/0xd0\n   dma_map_phys+0xfd/0x2d0\n   mlx5e_xdp_handle+0x5ae/0xac0 [mlx5_core]\n   mlx5e_xsk_skb_from_cqe_mpwrq_linear+0xc4/0x170 [mlx5_core]\n   mlx5e_handle_rx_cqe_mpwrq+0xc1/0x290 [mlx5_core]\n\nAdd the missing unmap + xdp_return_frame, matching the cleanup already\ndone in mlx5e_xdp_xmit(). has_frags is rejected earlier in this branch,\nso no per-frag unmap is needed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53229","epss":0.0063,"percentile":0.48117,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53229","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53229","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53230","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53230","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list  mlx5_query_nic_vport_mac_list() sizes its firmware command buffer using the PF's log_max_current_uc/mc_list capabilities. When querying a VF vport with a larger configured max (via devlink), the firmware response can overflow this buffer:   BUG: KASAN: slab-out-of-bounds in mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core]  Read of size 4 at addr ff1100013ffc8a12 by task kworker/u96:2/385   CPU: 12 UID: 0 PID: 385 Comm: kworker/u96:2 Not tainted 7.0.0-rc6+ #1 PREEMPT  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009)  Workqueue: mlx5_esw_wq esw_vport_change_handler [mlx5_core]  Call Trace:   <TASK>   dump_stack_lvl+0x69/0xa0   print_report+0x176/0x4e4   kasan_report+0xc8/0x100   mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core]   esw_update_vport_addr_list+0x2e3/0xda0 [mlx5_core]   esw_vport_change_handle_locked+0xa1f/0x1060 [mlx5_core]   esw_vport_change_handler+0x6a/0x90 [mlx5_core]   process_one_work+0x87f/0x15e0   worker_thread+0x62b/0x1020   kthread+0x375/0x490   ret_from_fork+0x4dc/0x810   ret_from_fork_asm+0x11/0x20   </TASK>  Fix by querying the vport's own HCA caps to size the buffer correctly. Refactor the function to allocate and return the MAC list internally, removing the caller's dependency on knowing the correct max.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:H","metrics":{"baseScore":8.7,"exploitabilityScore":2.1,"impactScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53230","epss":0.00125,"percentile":0.02528,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53230","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10124999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53230","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53230","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0f807764bb122fd63aa45f4229cb1ef2679fbd40","https://git.kernel.org/stable/c/2398e497389ed4be43f7cfbab499b49cec7dae1a","https://git.kernel.org/stable/c/41781f2789309462520a93822e946521ed78f97f","https://git.kernel.org/stable/c/537d87784e81c3d7037525b99416455cee088cdc","https://git.kernel.org/stable/c/894e036a24a26a6dd7b17d8d3fb5c53ab48a6074"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list\n\nmlx5_query_nic_vport_mac_list() sizes its firmware command buffer using\nthe PF's log_max_current_uc/mc_list capabilities. When querying a VF\nvport with a larger configured max (via devlink), the firmware response\ncan overflow this buffer:\n\n BUG: KASAN: slab-out-of-bounds in mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core]\n Read of size 4 at addr ff1100013ffc8a12 by task kworker/u96:2/385\n\n CPU: 12 UID: 0 PID: 385 Comm: kworker/u96:2 Not tainted 7.0.0-rc6+ #1 PREEMPT\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009)\n Workqueue: mlx5_esw_wq esw_vport_change_handler [mlx5_core]\n Call Trace:\n  <TASK>\n  dump_stack_lvl+0x69/0xa0\n  print_report+0x176/0x4e4\n  kasan_report+0xc8/0x100\n  mlx5_query_nic_vport_mac_list+0x453/0x4c0 [mlx5_core]\n  esw_update_vport_addr_list+0x2e3/0xda0 [mlx5_core]\n  esw_vport_change_handle_locked+0xa1f/0x1060 [mlx5_core]\n  esw_vport_change_handler+0x6a/0x90 [mlx5_core]\n  process_one_work+0x87f/0x15e0\n  worker_thread+0x62b/0x1020\n  kthread+0x375/0x490\n  ret_from_fork+0x4dc/0x810\n  ret_from_fork_asm+0x11/0x20\n  </TASK>\n\nFix by querying the vport's own HCA caps to size the buffer correctly.\nRefactor the function to allocate and return the MAC list internally,\nremoving the caller's dependency on knowing the correct max.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:H","metrics":{"baseScore":8.7,"exploitabilityScore":2.1,"impactScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53230","epss":0.00125,"percentile":0.02528,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53230","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53230","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53232","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53232","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: phy: clean the sfp upstream if phy probing fails  Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events.  This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53232","epss":0.00398,"percentile":0.3328,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.32437000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-53232","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53232","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b27701ce93161d7bbf4b25fa20ca59963b0e20c","https://git.kernel.org/stable/c/12fb84dc4dc8eb47ebe2b27f7de6255a4a205e1b","https://git.kernel.org/stable/c/3a254779c169954fe23328a1db51f67be374f913","https://git.kernel.org/stable/c/48774e87bbaa0056819d4b52301e4692e50e3252","https://git.kernel.org/stable/c/9326b654f90a09eadeb796c82801a5609d57f0c8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: clean the sfp upstream if phy probing fails\n\nSashiko reported that we don't call sfp_bus_del_upstream() in the probe\nfailure path, so let's add it, otherwise the sfp-bus is left with a\ndangling 'upstream' field, that may be used later on during SFP events.\n\nThis issue existed before the generic phylib sfp support, back when\ndrivers were calling phy_sfp_probe themselves.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53232","epss":0.00398,"percentile":0.3328,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53232","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53237","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53237","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: mvebu: fix NULL pointer dereference in suspend/resume  mvebu_pwm_suspend() and mvebu_pwm_resume() are called for all GPIO banks during suspend/resume, but not all banks have PWM functionality. GPIO banks without PWM have mvchip->mvpwm set to NULL.  Calling mvebu_pwm_suspend() with mvpwm == NULL causes a NULL pointer dereference when it tries to access mvpwm->blink_select.    Unable to handle kernel NULL pointer dereference at virtual address 00000020 when write   [00000020] *pgd=00000000   Internal error: Oops: 815 [#1] PREEMPT ARM   Modules linked in:   CPU: 0 UID: 0 PID: 406 Comm: sh Not tainted 6.12.74-rt12-yocto-standard-g4e96f98fb7db-dirty #353   Hardware name: Marvell Armada 370/XP (Device Tree)   PC is at regmap_mmio_read+0x38/0x54   LR is at regmap_mmio_read+0x38/0x54   pc : [<c05fd2ac>]    lr : [<c05fd2ac>]    psr: 200f0013   sp : f0c11d10  ip : 00000000  fp : c100d2f0   r10: c14fb854  r9 : 00000000  r8 : 00000000   r7 : c1799c00  r6 : 00000020  r5 : 00000020  r4 : c179c7c0   r3 : f0a231a0  r2 : 00000020  r1 : 00000020  r0 : 00000000   Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment none   Control: 10c5387d  Table: 135ec059  DAC: 00000051   Call trace:    regmap_mmio_read from _regmap_bus_reg_read+0x78/0xac    _regmap_bus_reg_read from _regmap_read+0x60/0x154    _regmap_read from regmap_read+0x3c/0x60    regmap_read from mvebu_gpio_suspend+0xa4/0x14c    mvebu_gpio_suspend from dpm_run_callback+0x54/0x180    dpm_run_callback from device_suspend+0x124/0x630    device_suspend from dpm_suspend+0x124/0x270    dpm_suspend from dpm_suspend_start+0x64/0x6c    dpm_suspend_start from suspend_devices_and_enter+0x140/0x8e8    suspend_devices_and_enter from pm_suspend+0x2fc/0x308    pm_suspend from state_store+0x6c/0xc8    state_store from kernfs_fop_write_iter+0x10c/0x1f8    kernfs_fop_write_iter from vfs_write+0x270/0x468    vfs_write from ksys_write+0x70/0xf0    ksys_write from ret_fast_syscall+0x0/0x54  Add a NULL check for mvchip->mvpwm before calling the PWM suspend/resume functions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53237","epss":0.00162,"percentile":0.05691,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53237","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08505},"relatedVulnerabilities":[{"id":"CVE-2026-53237","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53237","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/4ef24338eda3c7e96d6f94a988266ff16ed3985d","https://git.kernel.org/stable/c/6136c1474db88272231573e222896e1998d34662","https://git.kernel.org/stable/c/7db09011ce62162d72897fc4856b4425245dfe35","https://git.kernel.org/stable/c/b9ad50d7505ebd48282ec3630258dc820fc85c81","https://git.kernel.org/stable/c/c9677a9274ffb44987ec209dc8ec9f2d34946956"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mvebu: fix NULL pointer dereference in suspend/resume\n\nmvebu_pwm_suspend() and mvebu_pwm_resume() are called for all GPIO\nbanks during suspend/resume, but not all banks have PWM functionality.\nGPIO banks without PWM have mvchip->mvpwm set to NULL.\n\nCalling mvebu_pwm_suspend() with mvpwm == NULL causes a NULL pointer\ndereference when it tries to access mvpwm->blink_select.\n\n  Unable to handle kernel NULL pointer dereference at virtual address 00000020 when write\n  [00000020] *pgd=00000000\n  Internal error: Oops: 815 [#1] PREEMPT ARM\n  Modules linked in:\n  CPU: 0 UID: 0 PID: 406 Comm: sh Not tainted 6.12.74-rt12-yocto-standard-g4e96f98fb7db-dirty #353\n  Hardware name: Marvell Armada 370/XP (Device Tree)\n  PC is at regmap_mmio_read+0x38/0x54\n  LR is at regmap_mmio_read+0x38/0x54\n  pc : [<c05fd2ac>]    lr : [<c05fd2ac>]    psr: 200f0013\n  sp : f0c11d10  ip : 00000000  fp : c100d2f0\n  r10: c14fb854  r9 : 00000000  r8 : 00000000\n  r7 : c1799c00  r6 : 00000020  r5 : 00000020  r4 : c179c7c0\n  r3 : f0a231a0  r2 : 00000020  r1 : 00000020  r0 : 00000000\n  Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment none\n  Control: 10c5387d  Table: 135ec059  DAC: 00000051\n  Call trace:\n   regmap_mmio_read from _regmap_bus_reg_read+0x78/0xac\n   _regmap_bus_reg_read from _regmap_read+0x60/0x154\n   _regmap_read from regmap_read+0x3c/0x60\n   regmap_read from mvebu_gpio_suspend+0xa4/0x14c\n   mvebu_gpio_suspend from dpm_run_callback+0x54/0x180\n   dpm_run_callback from device_suspend+0x124/0x630\n   device_suspend from dpm_suspend+0x124/0x270\n   dpm_suspend from dpm_suspend_start+0x64/0x6c\n   dpm_suspend_start from suspend_devices_and_enter+0x140/0x8e8\n   suspend_devices_and_enter from pm_suspend+0x2fc/0x308\n   pm_suspend from state_store+0x6c/0xc8\n   state_store from kernfs_fop_write_iter+0x10c/0x1f8\n   kernfs_fop_write_iter from vfs_write+0x270/0x468\n   vfs_write from ksys_write+0x70/0xf0\n   ksys_write from ret_fast_syscall+0x0/0x54\n\nAdd a NULL check for mvchip->mvpwm before calling the PWM\nsuspend/resume functions.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53237","epss":0.00162,"percentile":0.05691,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53237","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53237","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53246","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53246","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing  When a listening SCTP server processes a COOKIE_ECHO chunk, the cached peer INIT chunk embedded after the cookie is parsed and its parameters are later walked by sctp_process_init() using sctp_walk_params().  However, the chunk header length of this cached INIT chunk was not validated against the remaining buffer in the COOKIE_ECHO payload. If the length field is inflated, the parameter walk can run beyond the actual received data, leading to out-of-bounds reads and potential memory corruption during later parameter handling (e.g. STATE_COOKIE processing and kmemdup() copies).  Add a bounds check in sctp_unpack_cookie() to ensure the cached INIT chunk length does not exceed the available data in the COOKIE_ECHO buffer before it is used.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53246","epss":0.00442,"percentile":0.37274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53246","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.41548},"relatedVulnerabilities":[{"id":"CVE-2026-53246","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53246","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0861615c28de668669d748ef4eb913ea9262d13b","https://git.kernel.org/stable/c/cc272185c9a9a4b7febc2de52eeaa3d00f19091e","https://git.kernel.org/stable/c/edccbf3d63b0a3362bc916ea72edacc1e1ca456a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate cached peer INIT chunk length in COOKIE_ECHO processing\n\nWhen a listening SCTP server processes a COOKIE_ECHO chunk, the cached\npeer INIT chunk embedded after the cookie is parsed and its parameters\nare later walked by sctp_process_init() using sctp_walk_params().\n\nHowever, the chunk header length of this cached INIT chunk was not\nvalidated against the remaining buffer in the COOKIE_ECHO payload. If\nthe length field is inflated, the parameter walk can run beyond the\nactual received data, leading to out-of-bounds reads and potential\nmemory corruption during later parameter handling (e.g. STATE_COOKIE\nprocessing and kmemdup() copies).\n\nAdd a bounds check in sctp_unpack_cookie() to ensure the cached INIT\nchunk length does not exceed the available data in the COOKIE_ECHO\nbuffer before it is used.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53246","epss":0.00442,"percentile":0.37274,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53246","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53246","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53258","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: fix leak if split 6 GHz scanning fails  rdev->int_scan_req is leaked if cfg80211_scan() fails.  Note that it's supposed to be released at ___cfg80211_scan_done() but this doesn't happen as rdev->scan_req is NULL at that point, too, leading to the early return from the freeing function.  unreferenced object 0xffff8881161d0800 (size 512):   comm \"wpa_supplicant\", pid 379, jiffies 4294749765   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     00 00 00 00 00 00 00 00 f0 81 13 16 81 88 ff ff  ................   backtrace (crc c867fdb6):     kmemleak_alloc+0x89/0x90     __kmalloc_noprof+0x2fd/0x410     cfg80211_scan+0x133/0x730     nl80211_trigger_scan+0xc69/0x1cc0     genl_family_rcv_msg_doit+0x204/0x2f0     genl_rcv_msg+0x431/0x6b0     netlink_rcv_skb+0x143/0x3f0     genl_rcv+0x27/0x40     netlink_unicast+0x4f6/0x820     netlink_sendmsg+0x797/0xce0     __sock_sendmsg+0xc4/0x160     ____sys_sendmsg+0x5e4/0x890     ___sys_sendmsg+0xf8/0x180     __sys_sendmsg+0x136/0x1e0     __x64_sys_sendmsg+0x76/0xc0     x64_sys_call+0x13f0/0x17d0  Found by Linux Verification Center (linuxtesting.org).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53258","epss":0.0016,"percentile":0.05506,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53258","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-53258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53258","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/a24134ddc18b4d440714365637d440b7121447b9","https://git.kernel.org/stable/c/e8694f7cc29287e843648d1075177b9a2000d957","https://git.kernel.org/stable/c/fb8db813eba2e56ee001c9fb5c2ce2cb78c42642"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: fix leak if split 6 GHz scanning fails\n\nrdev->int_scan_req is leaked if cfg80211_scan() fails.  Note that it's\nsupposed to be released at ___cfg80211_scan_done() but this doesn't happen\nas rdev->scan_req is NULL at that point, too, leading to the early return\nfrom the freeing function.\n\nunreferenced object 0xffff8881161d0800 (size 512):\n  comm \"wpa_supplicant\", pid 379, jiffies 4294749765\n  hex dump (first 32 bytes):\n    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n    00 00 00 00 00 00 00 00 f0 81 13 16 81 88 ff ff  ................\n  backtrace (crc c867fdb6):\n    kmemleak_alloc+0x89/0x90\n    __kmalloc_noprof+0x2fd/0x410\n    cfg80211_scan+0x133/0x730\n    nl80211_trigger_scan+0xc69/0x1cc0\n    genl_family_rcv_msg_doit+0x204/0x2f0\n    genl_rcv_msg+0x431/0x6b0\n    netlink_rcv_skb+0x143/0x3f0\n    genl_rcv+0x27/0x40\n    netlink_unicast+0x4f6/0x820\n    netlink_sendmsg+0x797/0xce0\n    __sock_sendmsg+0xc4/0x160\n    ____sys_sendmsg+0x5e4/0x890\n    ___sys_sendmsg+0xf8/0x180\n    __sys_sendmsg+0x136/0x1e0\n    __x64_sys_sendmsg+0x76/0xc0\n    x64_sys_call+0x13f0/0x17d0\n\nFound by Linux Verification Center (linuxtesting.org).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53258","epss":0.0016,"percentile":0.05506,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53258","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53262","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53262","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()  pppol2tp_ioctl() read sock->sk->sk_user_data directly without any locks or reference counting.  If a controllable sleep was induced during copy_from_user() (e.g. via a userfaultfd page fault sleep), a concurrent socket close could trigger pppol2tp_session_close() asynchronously.  This frees the l2tp_session structure via the l2tp_session_del_work workqueue. Upon resuming, the ioctl thread dereferences the stale session pointer, resulting in a Use-After-Free (UAF).  Fix this by securely fetching the session reference using the RCU-safe, refcounted helper pppol2tp_sock_to_session(sk) on entry.  This locks the session's refcount across the sleep.  We structured the function to exit via standard err breaks, guaranteeing that l2tp_session_put() is cleanly called on all return paths to drop the reference.  To preserve existing behavior we validate the session and its magic signature only for the specific L2TP commands that require it.  This ensures that generic/unknown ioctls called on an unconnected socket still return -ENOIOCTLCMD and correctly fall back to generic handlers (e.g. in sock_do_ioctl()).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53262","epss":0.00119,"percentile":0.01982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53262","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.091035},"relatedVulnerabilities":[{"id":"CVE-2026-53262","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53262","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/62f327e287cf7b595ae3f73ba72f5cd2a9e9f39f","https://git.kernel.org/stable/c/78cdfdca88cbf731a92f3b9ee5427c633dd94e28","https://git.kernel.org/stable/c/a213a8950414c684999dcf03edeea6c46ede172e","https://git.kernel.org/stable/c/e251d4cdfc725c9e7d686161e3b775a0e7d95053"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()\n\npppol2tp_ioctl() read sock->sk->sk_user_data directly without any\nlocks or reference counting.  If a controllable sleep was induced during\ncopy_from_user() (e.g. via a userfaultfd page fault sleep), a concurrent\nsocket close could trigger pppol2tp_session_close() asynchronously.  This\nfrees the l2tp_session structure via the l2tp_session_del_work workqueue.\nUpon resuming, the ioctl thread dereferences the stale session pointer,\nresulting in a Use-After-Free (UAF).\n\nFix this by securely fetching the session reference using the RCU-safe,\nrefcounted helper pppol2tp_sock_to_session(sk) on entry.  This locks the\nsession's refcount across the sleep.  We structured the function to exit\nvia standard err breaks, guaranteeing that l2tp_session_put() is cleanly\ncalled on all return paths to drop the reference.\n\nTo preserve existing behavior we validate the session and its magic\nsignature only for the specific L2TP commands that require it.  This\nensures that generic/unknown ioctls called on an unconnected socket\nstill return -ENOIOCTLCMD and correctly fall back to generic handlers\n(e.g. in sock_do_ioctl()).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53262","epss":0.00119,"percentile":0.01982,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53262","cwe":"NVD-CWE-Other","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53262","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53265","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53265","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm cache policy smq: check allocation under invalidate lock  commit 2d1f7b65f5de (\"dm cache policy smq: fix missing locks in invalidating cache blocks\") added mq->lock around the destructive part of smq_invalidate_mapping(), but left the e->allocated check outside the critical section.  That leaves a check-then-act race. Two concurrent invalidators can both observe e->allocated as true before either of them takes mq->lock. The first invalidator that acquires the lock removes the entry from the queues and hash table and then calls free_entry(), which clears e->allocated and puts the entry back on the free list. The second invalidator can then acquire mq->lock and continue with the stale result of the unlocked check.  This can corrupt the SMQ queues or hash table by deleting an entry that is no longer on those structures. It can also hit the allocation check in free_entry() when the same entry is freed again.  Move the allocation check under mq->lock so the predicate and the destructive operations are serialized by the same lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53265","epss":0.0012,"percentile":0.02091,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53265","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53265","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/03ffe1112ed88bb3a9bd0b971549bf4d64bfc59a","https://git.kernel.org/stable/c/13da856c86fb8c2ccab95034fd77da1bb2c2a17c","https://git.kernel.org/stable/c/42ff6774ecd9d7f70d599cb71ff64373a1da4948","https://git.kernel.org/stable/c/b4892561552d671bd8c4da5ebb70e9fbb1ec446e","https://git.kernel.org/stable/c/c242c7af2aecf0b538b8623bdb86b8b441da38d9","https://git.kernel.org/stable/c/c57570fba24016ec25ec046ab44db39143fb7a64","https://git.kernel.org/stable/c/d3f0a606b9f278ece8a0df626ded9c4044071235","https://git.kernel.org/stable/c/d886945fcb0f8c9dc6b39928d7a96c95c587346c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache policy smq: check allocation under invalidate lock\n\ncommit 2d1f7b65f5de (\"dm cache policy smq: fix missing locks in\ninvalidating cache blocks\") added mq->lock around the destructive part of\nsmq_invalidate_mapping(), but left the e->allocated check outside the\ncritical section.\n\nThat leaves a check-then-act race. Two concurrent invalidators can both\nobserve e->allocated as true before either of them takes mq->lock. The\nfirst invalidator that acquires the lock removes the entry from the\nqueues and hash table and then calls free_entry(), which clears\ne->allocated and puts the entry back on the free list. The second\ninvalidator can then acquire mq->lock and continue with the stale result\nof the unlocked check.\n\nThis can corrupt the SMQ queues or hash table by deleting an entry that\nis no longer on those structures. It can also hit the allocation check in\nfree_entry() when the same entry is freed again.\n\nMove the allocation check under mq->lock so the predicate and the\ndestructive operations are serialized by the same lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53265","epss":0.0012,"percentile":0.02091,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53265","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53267","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53267","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_ct: bail out on template ct in get eval  I noticed this issue while looking at a historic syzbot report [1].  A rule like the one below is enough to trigger the bug:      table ip t {         chain pre {             type filter hook prerouting priority raw;             ct zone set 1             ct original saddr 1.2.3.4 accept         }     }  The first expression attaches a per-cpu template ct via nft_ct_set_zone_eval() (nf_ct_tmpl_alloc -> kzalloc, tuple is all zero, nf_ct_l3num(ct) == 0). The next expression then calls nft_ct_get_eval() on the same skb, treats the template as a real ct and hits the 16-byte memcpy path. With dreg at NFT_REG32_15 this overflows past struct nft_regs on the kernel stack; with smaller dreg values it silently clobbers adjacent registers.  Reject template ct at the eval entry and in nft_ct_get_fast_eval(), mirroring the check nft_ct_set_eval() already has. Additionally, bound the address copy in NFT_CT_SRC / NFT_CT_DST by priv->len instead of by nf_ct_l3num(ct): nf_ct_get_tuple() zeroes the tuple before pkt_to_tuple() fills in only the protocol-relevant leading bytes, so the trailing bytes of tuple->{src,dst}.u3.all are well-defined zero. priv->len is validated at rule load, so the copy size is now bounded by the destination register rather than by an untrusted field on the conntrack.  [1]: https://syzkaller.appspot.com/bug?id=389cf09cb72926114fce90dc85a2c3231dcb647c","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53267","epss":0.0012,"percentile":0.02044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53267","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53267","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53267","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2e154b5f53f1b0b490c7b8b02499f90feb86b1d5","https://git.kernel.org/stable/c/3027ecbdb5fdf9200251c21d4818e4c447ef78e1","https://git.kernel.org/stable/c/8470f676eadeab99132708acb1a85915664d6115","https://git.kernel.org/stable/c/af80f78ce984649e1698b841cd33f4fa505ad828","https://git.kernel.org/stable/c/f071b0bf078146368d18e4eec386bf2ddc0ab7e0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: bail out on template ct in get eval\n\nI noticed this issue while looking at a historic syzbot report [1].\n\nA rule like the one below is enough to trigger the bug:\n\n    table ip t {\n        chain pre {\n            type filter hook prerouting priority raw;\n            ct zone set 1\n            ct original saddr 1.2.3.4 accept\n        }\n    }\n\nThe first expression attaches a per-cpu template ct via\nnft_ct_set_zone_eval() (nf_ct_tmpl_alloc -> kzalloc, tuple is all\nzero, nf_ct_l3num(ct) == 0). The next expression then calls\nnft_ct_get_eval() on the same skb, treats the template as a real ct\nand hits the 16-byte memcpy path. With dreg at NFT_REG32_15 this\noverflows past struct nft_regs on the kernel stack; with smaller\ndreg values it silently clobbers adjacent registers.\n\nReject template ct at the eval entry and in nft_ct_get_fast_eval(),\nmirroring the check nft_ct_set_eval() already has. Additionally,\nbound the address copy in NFT_CT_SRC / NFT_CT_DST by priv->len\ninstead of by nf_ct_l3num(ct): nf_ct_get_tuple() zeroes the tuple\nbefore pkt_to_tuple() fills in only the protocol-relevant leading\nbytes, so the trailing bytes of tuple->{src,dst}.u3.all are\nwell-defined zero. priv->len is validated at rule load, so the\ncopy size is now bounded by the destination register rather than\nby an untrusted field on the conntrack.\n\n[1]: https://syzkaller.appspot.com/bug?id=389cf09cb72926114fce90dc85a2c3231dcb647c","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53267","epss":0.0012,"percentile":0.02044,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53267","cwe":"CWE-674","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53267","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53272","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53272","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  erofs: fix use-after-free on sbi->sync_decompress  z_erofs_decompress_kickoff() can race with filesystem unmount, causing a use-after-free on sbi->sync_decompress.  When I/O completes, z_erofs_endio() calls z_erofs_decompress_kickoff() to queue z_erofs_decompressqueue_work() asynchronously. Then, after all folios are unlocked, unmount workflow can proceed and sbi will be freed before accessing to sbi->sync_decompress.  Thread (unmount)        I/O completion        kworker                         queue_work                                               z_erofs_decompressqueue_work                                                (all folios are unlocked) cleanup_mnt  ..  erofs_kill_sb   erofs_sb_free    kfree(sbi)                         access sbi->sync_decompress  // UAF!!","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53272","epss":0.0017,"percentile":0.066,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53272","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13005},"relatedVulnerabilities":[{"id":"CVE-2026-53272","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53272","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/00bf6868df65fa95b3854996246d15759fdc7070","https://git.kernel.org/stable/c/1aee05e814d292064bf5fa15733741040cdc48ba","https://git.kernel.org/stable/c/86ab00cf81d44b675bb23db62b88fd76c8ac8cea","https://git.kernel.org/stable/c/95caf60da33d87ed26c28993620f0d92487b0296"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix use-after-free on sbi->sync_decompress\n\nz_erofs_decompress_kickoff() can race with filesystem unmount, causing\na use-after-free on sbi->sync_decompress.\n\nWhen I/O completes, z_erofs_endio() calls z_erofs_decompress_kickoff()\nto queue z_erofs_decompressqueue_work() asynchronously. Then, after all\nfolios are unlocked, unmount workflow can proceed and sbi will be freed\nbefore accessing to sbi->sync_decompress.\n\nThread (unmount)        I/O completion        kworker\n                        queue_work\n                                              z_erofs_decompressqueue_work\n                                               (all folios are unlocked)\ncleanup_mnt\n ..\n erofs_kill_sb\n  erofs_sb_free\n   kfree(sbi)\n                        access sbi->sync_decompress  // UAF!!","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53272","epss":0.0017,"percentile":0.066,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53272","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53272","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53284","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53284","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: only release the dirty pages io tree after successful writes  [WARNING] With extra warning on dirty extent buffers at umount (aka, the next patch in the series), test case generic/388 can trigger the following warning about dirty extent buffers at unmount time:    BTRFS critical (device dm-2 state E): emergency shutdown   BTRFS error (device dm-2 state E): error while writing out transaction: -30   BTRFS warning (device dm-2 state E): Skipping commit of aborted transaction.   BTRFS error (device dm-2 state EA): Transaction 9 aborted (error -30)   BTRFS: error (device dm-2 state EA) in cleanup_transaction:2068: errno=-30 Readonly filesystem   BTRFS info (device dm-2 state EA): forced readonly   BTRFS info (device dm-2 state EA): last unmount of filesystem 4fbf2e15-f941-49a0-bc7c-716315d2777c   ------------[ cut here ]------------   WARNING: disk-io.c:3311 at invalidate_and_check_btree_folios+0xfd/0x1ca [btrfs], CPU#8: umount/914368   CPU: 8 UID: 0 PID: 914368 Comm: umount Tainted: G           OE       7.1.0-rc1-custom+ #372 PREEMPT(full)  2de38db8d1deae71fde295430a0ff3ab98ccf596   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022   RIP: 0010:invalidate_and_check_btree_folios+0xfd/0x1ca [btrfs]   Call Trace:    <TASK>    close_ctree+0x52e/0x574 [btrfs d2f0b1cd330d1287e7a9919d112eadfc0e914efd]    generic_shutdown_super+0x89/0x1a0    kill_anon_super+0x16/0x40    btrfs_kill_super+0x16/0x20 [btrfs d2f0b1cd330d1287e7a9919d112eadfc0e914efd]    deactivate_locked_super+0x2d/0xb0    cleanup_mnt+0xdc/0x140    task_work_run+0x5a/0xa0    exit_to_user_mode_loop+0x123/0x4b0    do_syscall_64+0x243/0x7c0    entry_SYSCALL_64_after_hwframe+0x4b/0x53    </TASK>   ---[ end trace 0000000000000000 ]---   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30539776 owner 9 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30621696 owner 257 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30638080 owner 258 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30654464 owner 7 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30703616 owner 2 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30720000 owner 10 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30736384 owner 4 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30752768 owner 11 gen 9 refs 2 flags 0x7  I'm using a stripped down version, which seems to trigger the warning more reliably:    _fsstress_pid=\"\"   workload()   {   \tdmesg -C   \tmkfs.btrfs -f -K $dev > /dev/null   \techo 1 > /sys/kernel/debug/clear_warn_once   \tmount $dev $mnt   \t$fsstress -w -n 1024 -p 4 -d $mnt &   \t_fsstress_pid=$!   \tsleep 0   \t$godown $mnt   \tpkill --echo -PIPE fsstress > /dev/null   \twait $_fsstress_pid   \tunset _fsstress_pid   \tumount $mnt    \tif dmesg | grep -q \"WARNING\"; then   \t\tfail   \tfi   }    for (( i = 0; i < $runtime; i++ )); do   \techo \"=== $i/$runtime ===\"   \tworkload   done  [CAUSE] Inside btrfs_write_and_wait_transaction(), we first try to write all dirty ebs, then wait for them to finish.  After that we call btrfs_extent_io_tree_release() to free all extent states from dirty_pages io tree.  However if we hit an error from btrfs_write_marked_extent(), then we still call btrfs_extent_io_tree_release() to clear that dirty_pages io tree, which may contain dirty records that we haven't yet submitted.  Furthermore, the later transaction cleanup path will utilize that dirty_pages io tree to properly cleanup those dirty ebs, but since it's already empty, no dirty ebs are properly cleaned up, thus will later trigger the warnings inside invalidate_btree_folios(). ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53284","epss":0.00426,"percentile":0.35924,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53284","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3195},"relatedVulnerabilities":[{"id":"CVE-2026-53284","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53284","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4066c55e109475a06d18a1f127c939d551211956","https://git.kernel.org/stable/c/9ebb7eba1237dc198768b9c76506a79f924c82bb","https://git.kernel.org/stable/c/df03d67dc63722845cb9fe59d815d1225b04fd54"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: only release the dirty pages io tree after successful writes\n\n[WARNING]\nWith extra warning on dirty extent buffers at umount (aka, the next\npatch in the series), test case generic/388 can trigger the following\nwarning about dirty extent buffers at unmount time:\n\n  BTRFS critical (device dm-2 state E): emergency shutdown\n  BTRFS error (device dm-2 state E): error while writing out transaction: -30\n  BTRFS warning (device dm-2 state E): Skipping commit of aborted transaction.\n  BTRFS error (device dm-2 state EA): Transaction 9 aborted (error -30)\n  BTRFS: error (device dm-2 state EA) in cleanup_transaction:2068: errno=-30 Readonly filesystem\n  BTRFS info (device dm-2 state EA): forced readonly\n  BTRFS info (device dm-2 state EA): last unmount of filesystem 4fbf2e15-f941-49a0-bc7c-716315d2777c\n  ------------[ cut here ]------------\n  WARNING: disk-io.c:3311 at invalidate_and_check_btree_folios+0xfd/0x1ca [btrfs], CPU#8: umount/914368\n  CPU: 8 UID: 0 PID: 914368 Comm: umount Tainted: G           OE       7.1.0-rc1-custom+ #372 PREEMPT(full)  2de38db8d1deae71fde295430a0ff3ab98ccf596\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022\n  RIP: 0010:invalidate_and_check_btree_folios+0xfd/0x1ca [btrfs]\n  Call Trace:\n   <TASK>\n   close_ctree+0x52e/0x574 [btrfs d2f0b1cd330d1287e7a9919d112eadfc0e914efd]\n   generic_shutdown_super+0x89/0x1a0\n   kill_anon_super+0x16/0x40\n   btrfs_kill_super+0x16/0x20 [btrfs d2f0b1cd330d1287e7a9919d112eadfc0e914efd]\n   deactivate_locked_super+0x2d/0xb0\n   cleanup_mnt+0xdc/0x140\n   task_work_run+0x5a/0xa0\n   exit_to_user_mode_loop+0x123/0x4b0\n   do_syscall_64+0x243/0x7c0\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n   </TASK>\n  ---[ end trace 0000000000000000 ]---\n  BTRFS warning (device dm-2 state EA): unable to release extent buffer 30539776 owner 9 gen 9 refs 2 flags 0x7\n  BTRFS warning (device dm-2 state EA): unable to release extent buffer 30621696 owner 257 gen 9 refs 2 flags 0x7\n  BTRFS warning (device dm-2 state EA): unable to release extent buffer 30638080 owner 258 gen 9 refs 2 flags 0x7\n  BTRFS warning (device dm-2 state EA): unable to release extent buffer 30654464 owner 7 gen 9 refs 2 flags 0x7\n  BTRFS warning (device dm-2 state EA): unable to release extent buffer 30703616 owner 2 gen 9 refs 2 flags 0x7\n  BTRFS warning (device dm-2 state EA): unable to release extent buffer 30720000 owner 10 gen 9 refs 2 flags 0x7\n  BTRFS warning (device dm-2 state EA): unable to release extent buffer 30736384 owner 4 gen 9 refs 2 flags 0x7\n  BTRFS warning (device dm-2 state EA): unable to release extent buffer 30752768 owner 11 gen 9 refs 2 flags 0x7\n\nI'm using a stripped down version, which seems to trigger the warning\nmore reliably:\n\n  _fsstress_pid=\"\"\n  workload()\n  {\n  \tdmesg -C\n  \tmkfs.btrfs -f -K $dev > /dev/null\n  \techo 1 > /sys/kernel/debug/clear_warn_once\n  \tmount $dev $mnt\n  \t$fsstress -w -n 1024 -p 4 -d $mnt &\n  \t_fsstress_pid=$!\n  \tsleep 0\n  \t$godown $mnt\n  \tpkill --echo -PIPE fsstress > /dev/null\n  \twait $_fsstress_pid\n  \tunset _fsstress_pid\n  \tumount $mnt\n\n  \tif dmesg | grep -q \"WARNING\"; then\n  \t\tfail\n  \tfi\n  }\n\n  for (( i = 0; i < $runtime; i++ )); do\n  \techo \"=== $i/$runtime ===\"\n  \tworkload\n  done\n\n[CAUSE]\nInside btrfs_write_and_wait_transaction(), we first try to write all\ndirty ebs, then wait for them to finish.\n\nAfter that we call btrfs_extent_io_tree_release() to free all\nextent states from dirty_pages io tree.\n\nHowever if we hit an error from btrfs_write_marked_extent(), then we\nstill call btrfs_extent_io_tree_release() to clear that dirty_pages io\ntree, which may contain dirty records that we haven't yet submitted.\n\nFurthermore, the later transaction cleanup path will utilize that\ndirty_pages io tree to properly cleanup those dirty ebs, but since it's\nalready empty, no dirty ebs are properly cleaned up, thus will later\ntrigger the warnings inside invalidate_btree_folios().\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53284","epss":0.00426,"percentile":0.35924,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53284","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53284","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53285","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53285","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED  [Why] dcn32_validate_bandwidth() wraps dcn32_internal_validate_bw() with DC_FP_START()/DC_FP_END(). In x86 non-RT, DC_FP_START takes fpregs_lock(), which disables local softirqs.  The DML1 path through dcn32_enable_phantom_plane() calls kvzalloc() to allocate ~335 KiB for dc_plane_state. This triggers the vmalloc path, which calls BUG_ON(in_interrupt()) because it's invoked within the FPU-enabled (softirq disabled) region, leading to a kernel crash.  [How] Wrap the dc_state_create_phantom_plane() call with the DC_RUN_WITH_PREEMPTION_ENABLED() macro to allow preemption during this memory allocation.  (cherry picked from commit 885ccbef7b94a8b38f69c4211c679021aa27ad11)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53285","epss":0.00107,"percentile":0.01276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53285","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-53285","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53285","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/183182235f6d53bac62c6c39014738a54a68dfa6","https://git.kernel.org/stable/c/30bb2ec6695d62f63db4aa6179c4626834ed0cd6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED\n\n[Why]\ndcn32_validate_bandwidth() wraps dcn32_internal_validate_bw() with\nDC_FP_START()/DC_FP_END(). In x86 non-RT, DC_FP_START takes fpregs_lock(),\nwhich disables local softirqs.\n\nThe DML1 path through dcn32_enable_phantom_plane() calls kvzalloc() to\nallocate ~335 KiB for dc_plane_state. This triggers the vmalloc path,\nwhich calls BUG_ON(in_interrupt()) because it's invoked within the\nFPU-enabled (softirq disabled) region, leading to a kernel crash.\n\n[How]\nWrap the dc_state_create_phantom_plane() call with the\nDC_RUN_WITH_PREEMPTION_ENABLED() macro to allow preemption during\nthis memory allocation.\n\n(cherry picked from commit 885ccbef7b94a8b38f69c4211c679021aa27ad11)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53285","epss":0.00107,"percentile":0.01276,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53285","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53285","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53292","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53292","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind  syzbot reported a kernel BUG triggered from pn_socket_sendmsg() via pn_socket_autobind():    kernel BUG at net/phonet/socket.c:213!   RIP: 0010:pn_socket_autobind net/phonet/socket.c:213 [inline]   RIP: 0010:pn_socket_sendmsg+0x240/0x250 net/phonet/socket.c:421   Call Trace:    sock_sendmsg_nosec+0x112/0x150 net/socket.c:797    __sock_sendmsg net/socket.c:812 [inline]    __sys_sendto+0x402/0x590 net/socket.c:2280    ...  pn_socket_autobind() calls pn_socket_bind() with port 0 and, on -EINVAL, assumes the socket was already bound and asserts that the port is non-zero:    err = pn_socket_bind(sock, ..., sizeof(struct sockaddr_pn));   if (err != -EINVAL)           return err;   BUG_ON(!pn_port(pn_sk(sock->sk)->sobject));   return 0; /* socket was already bound */  However pn_socket_bind() also returns -EINVAL when sk->sk_state is not TCP_CLOSE, even when the socket has never been bound and pn_port() is still 0.  In that case the BUG_ON() fires and panics the kernel from a user-triggerable path.  Treat the \"bind returned -EINVAL but pn_port() is still 0\" case as a regular error and propagate -EINVAL to the caller instead of crashing. Existing callers already translate a non-zero return from pn_socket_autobind() into -ENOBUFS/-EAGAIN, so returning -EINVAL here only changes behaviour from panic to a normal errno.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53292","epss":0.00107,"percentile":0.01283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53292","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-53292","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53292","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/5b0c911bcdbd982f7748d11c0b39ec5808eae2de","https://git.kernel.org/stable/c/6db58ee730bf434d1afca91b91826e26688856ed"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind\n\nsyzbot reported a kernel BUG triggered from pn_socket_sendmsg() via\npn_socket_autobind():\n\n  kernel BUG at net/phonet/socket.c:213!\n  RIP: 0010:pn_socket_autobind net/phonet/socket.c:213 [inline]\n  RIP: 0010:pn_socket_sendmsg+0x240/0x250 net/phonet/socket.c:421\n  Call Trace:\n   sock_sendmsg_nosec+0x112/0x150 net/socket.c:797\n   __sock_sendmsg net/socket.c:812 [inline]\n   __sys_sendto+0x402/0x590 net/socket.c:2280\n   ...\n\npn_socket_autobind() calls pn_socket_bind() with port 0 and, on\n-EINVAL, assumes the socket was already bound and asserts that the\nport is non-zero:\n\n  err = pn_socket_bind(sock, ..., sizeof(struct sockaddr_pn));\n  if (err != -EINVAL)\n          return err;\n  BUG_ON(!pn_port(pn_sk(sock->sk)->sobject));\n  return 0; /* socket was already bound */\n\nHowever pn_socket_bind() also returns -EINVAL when sk->sk_state is not\nTCP_CLOSE, even when the socket has never been bound and pn_port() is\nstill 0.  In that case the BUG_ON() fires and panics the kernel from a\nuser-triggerable path.\n\nTreat the \"bind returned -EINVAL but pn_port() is still 0\" case as a\nregular error and propagate -EINVAL to the caller instead of crashing.\nExisting callers already translate a non-zero return from\npn_socket_autobind() into -ENOBUFS/-EAGAIN, so returning -EINVAL here\nonly changes behaviour from panic to a normal errno.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53292","epss":0.00107,"percentile":0.01283,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53292","cwe":"CWE-617","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53292","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53297","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53297","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: mana: Guard mana_remove against double invocation  If PM resume fails (e.g., mana_attach() returns an error), mana_probe() calls mana_remove(), which tears down the device and sets gd->gdma_context = NULL and gd->driver_data = NULL.  However, a failed resume callback does not automatically unbind the driver. When the device is eventually unbound, mana_remove() is invoked a second time. Without a NULL check, it dereferences gc->dev with gc == NULL, causing a kernel panic.  Add an early return if gdma_context or driver_data is NULL so the second invocation is harmless. Move the dev = gc->dev assignment after the guard so it cannot dereference NULL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53297","epss":0.00121,"percentile":0.02154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53297","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-53297","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53297","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/50271d7ec95144d26808025b508f463780517d3c","https://git.kernel.org/stable/c/a1ddfd2c0b7a48e5239fadd2a24cc4bc2cda90e6","https://git.kernel.org/stable/c/bbe5c3c570645a4ceb120979d3ee203a1583d775"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Guard mana_remove against double invocation\n\nIf PM resume fails (e.g., mana_attach() returns an error), mana_probe()\ncalls mana_remove(), which tears down the device and sets\ngd->gdma_context = NULL and gd->driver_data = NULL.\n\nHowever, a failed resume callback does not automatically unbind the\ndriver. When the device is eventually unbound, mana_remove() is invoked\na second time. Without a NULL check, it dereferences gc->dev with\ngc == NULL, causing a kernel panic.\n\nAdd an early return if gdma_context or driver_data is NULL so the second\ninvocation is harmless. Move the dev = gc->dev assignment after the\nguard so it cannot dereference NULL.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53297","epss":0.00121,"percentile":0.02154,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53297","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53297","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53313","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53313","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths  In dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace().  Both functions check:    if (!dc_dmub_srv || !dc_dmub_srv->dmub)  and then call DC_LOG_ERROR() inside that block.  DC_LOG_ERROR() uses dc_dmub_srv->ctx internally. So if dc_dmub_srv is NULL, the logging itself can dereference a NULL pointer and cause a crash.  Fix this by splitting the checks.  First check if dc_dmub_srv is NULL and return immediately. Then check dc_dmub_srv->dmub and log the error only when dc_dmub_srv is valid.  Fixes the below: ../display/dc/dc_dmub_srv.c:962 dc_dmub_srv_log_diagnostic_data() error: we previously assumed 'dc_dmub_srv' could be null (see line 961) ../display/dc/dc_dmub_srv.c:1167 dc_dmub_srv_enable_dpia_trace() error: we previously assumed 'dc_dmub_srv' could be null (see line 1166)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53313","epss":0.00114,"percentile":0.01655,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53313","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-53313","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53313","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2ab18de5ebb11c76bfc8087c5a09fbcccd0dea8a","https://git.kernel.org/stable/c/4ae3e16f4b3bf64140f773629b765d605ee079a9","https://git.kernel.org/stable/c/a71fdbd6e8289e2725d33a9873833459f3b1824f","https://git.kernel.org/stable/c/b37a978e6d8c33fbfa4abc5dcca4c7cfc6d01f22"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths\n\nIn dc_dmub_srv_log_diagnostic_data() and\ndc_dmub_srv_enable_dpia_trace().\n\nBoth functions check:\n\n  if (!dc_dmub_srv || !dc_dmub_srv->dmub)\n\nand then call DC_LOG_ERROR() inside that block.\n\nDC_LOG_ERROR() uses dc_dmub_srv->ctx internally. So if\ndc_dmub_srv is NULL, the logging itself can dereference a\nNULL pointer and cause a crash.\n\nFix this by splitting the checks.\n\nFirst check if dc_dmub_srv is NULL and return immediately.\nThen check dc_dmub_srv->dmub and log the error only when\ndc_dmub_srv is valid.\n\nFixes the below:\n../display/dc/dc_dmub_srv.c:962 dc_dmub_srv_log_diagnostic_data() error: we previously assumed 'dc_dmub_srv' could be null (see line 961)\n../display/dc/dc_dmub_srv.c:1167 dc_dmub_srv_enable_dpia_trace() error: we previously assumed 'dc_dmub_srv' could be null (see line 1166)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53313","epss":0.00114,"percentile":0.01655,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53313","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53313","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53317","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53317","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7921: Place upper limit on station AID  Any station configured with an AID over 20 causes a firmware crash. This situation occurred in our testing using an AP interface on 7922 hardware, with a modified hostapd, sourced from Mediatek's OpenWRT feeds.  In stock hostapd, station AIDs begin counting at 1, and this configuration is prevented with an upper limit on associated stations. However, the modified hostapd began allocation at 65, which caused the firmware to crash. This fix does not allow these AIDs to work, but will prevent the firmware crash.  This crash was only seen on IFTYPE_AP interfaces, and the fix does not appear to have an effect on IFTYPE_STATION behavior.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53317","epss":0.00114,"percentile":0.01655,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-53317","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53317","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/1a4b802afe15c5b33b2dcb37a594aba2fa215d52","https://git.kernel.org/stable/c/35835ff71e6e618155578b8e3905597edd5f601c","https://git.kernel.org/stable/c/4d0bf21e3e20619d51d06c0c36207aabab8b712c","https://git.kernel.org/stable/c/6dbe70f9ef14d8ac1c24bf19fd9510978a3ab952"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: Place upper limit on station AID\n\nAny station configured with an AID over 20 causes a firmware crash.\nThis situation occurred in our testing using an AP interface on 7922\nhardware, with a modified hostapd, sourced from Mediatek's OpenWRT\nfeeds.\n\nIn stock hostapd, station AIDs begin counting at 1, and this\nconfiguration is prevented with an upper limit on associated stations.\nHowever, the modified hostapd began allocation at 65, which caused the\nfirmware to crash. This fix does not allow these AIDs to work, but will\nprevent the firmware crash.\n\nThis crash was only seen on IFTYPE_AP interfaces, and the fix does not\nappear to have an effect on IFTYPE_STATION behavior.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53317","epss":0.00114,"percentile":0.01655,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53317","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53330","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53330","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()  [Why & How] The aux_rd_interval array in struct dc_lttpr_caps is declared with MAX_REPEATER_CNT - 1 (7) elements, indexed 0..6. However, the offset parameter passed to dp_get_eq_aux_rd_interval() can be as large as MAX_REPEATER_CNT (8) when a sink reports 8 LTTPR repeaters via DPCD. This leads to an out-of-bounds read of aux_rd_interval[7] when offset is 8.  Fix this by growing aux_rd_interval to MAX_REPEATER_CNT elements to accommodate the full range of valid repeater counts defined by the DP spec.  (cherry picked from commit a55a458a8df37a65ffda5cf721d554a8f74f6b04)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53330","epss":0.00164,"percentile":0.05915,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53330","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11972000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-53330","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53330","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/454d3b3d499c18373f8960d31aea48338a3ca9e0","https://git.kernel.org/stable/c/dc1490927d79fe9621e29f4a4f5d7b5ccb6aea3e","https://git.kernel.org/stable/c/e8b4d37eba05141ee01794fc6b7f2da808cee83b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()\n\n[Why & How]\nThe aux_rd_interval array in struct dc_lttpr_caps is declared with\nMAX_REPEATER_CNT - 1 (7) elements, indexed 0..6. However, the offset\nparameter passed to dp_get_eq_aux_rd_interval() can be as large as\nMAX_REPEATER_CNT (8) when a sink reports 8 LTTPR repeaters via DPCD.\nThis leads to an out-of-bounds read of aux_rd_interval[7] when offset\nis 8.\n\nFix this by growing aux_rd_interval to MAX_REPEATER_CNT elements to\naccommodate the full range of valid repeater counts defined by the DP\nspec.\n\n(cherry picked from commit a55a458a8df37a65ffda5cf721d554a8f74f6b04)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53330","epss":0.00164,"percentile":0.05915,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53330","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53330","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53345","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53345","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying  When marking a page dirty, complain about not having a running/loaded vCPU if and only if the VM is still alive, i.e. its refcount is non-zero.  This will allow fixing a memory leak for x86 SEV-ES guests without hitting what is effectively a false positive on the WARN.  For some SEV-ES VM-Exits, KVM keeps a writable mapping of a guest page across an exit to userspace, and typically unmaps the page on the next KVM_RUN.  But if userspace never calls KVM_RUN after such an exit, then KVM needs to unmap the page when the vCPU is destroyed, which in turn triggers the WARN about not having a running vCPU.  Alternatively, SEV-ES could temporarily load the vCPU to suppress the WARN, as is done in nested_vmx_free_vcpu() (but for completely unrelated reasons; suppressing WARN from nested_put_vmcs12_pages() is pure happenstance).  But loading a vCPU during destruction is gross (ideally nVMX code would be cleaned up), risks complicating the SEV-ES code (KVM would need to ensure the temporarily load()+put() only runs when the vCPU isn't already loaded), and is ultimately pointless.  The motivation for the WARN is to guard against KVM dirtying guest memory without pushing the corresponding GFN to the active vCPU's dirty ring, e.g. to ensure userspace doesn't miss a dirty page.  But for the VM's refcount to reach zero, there can't be _any_ userspace mappings to the dirty ring, as mapping the dirty ring requires doing mmap() on the vCPU FD.  I.e. if userspace had a valid mapping for the dirty ring, then the vCPU file and thus the owning VM would still be alive.  And so since userspace can't possibly reach the dirty ring, whether or not KVM technically \"misses\" a push to the dirty ring is irrelevant.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53345","epss":0.0012,"percentile":0.02059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53345","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06299999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53345","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53345","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/033d39e41fc30f484f4e4f37fb4cd76b12cbb18e","https://git.kernel.org/stable/c/343e95c8ecc40e0738975ef4ee24c0c35e800e6b","https://git.kernel.org/stable/c/66a8e7ddd901023c89a2733494d827eca3f9c1b0","https://git.kernel.org/stable/c/8618004d3e897c0f1b71d9a9ab860461289bb89a","https://git.kernel.org/stable/c/99d7d43784ae3235026581e9bf892c036e04c8e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying\n\nWhen marking a page dirty, complain about not having a running/loaded vCPU\nif and only if the VM is still alive, i.e. its refcount is non-zero.  This\nwill allow fixing a memory leak for x86 SEV-ES guests without hitting what\nis effectively a false positive on the WARN.\n\nFor some SEV-ES VM-Exits, KVM keeps a writable mapping of a guest page\nacross an exit to userspace, and typically unmaps the page on the next\nKVM_RUN.  But if userspace never calls KVM_RUN after such an exit, then KVM\nneeds to unmap the page when the vCPU is destroyed, which in turn triggers\nthe WARN about not having a running vCPU.\n\nAlternatively, SEV-ES could temporarily load the vCPU to suppress the WARN,\nas is done in nested_vmx_free_vcpu() (but for completely unrelated reasons;\nsuppressing WARN from nested_put_vmcs12_pages() is pure happenstance).  But\nloading a vCPU during destruction is gross (ideally nVMX code would be\ncleaned up), risks complicating the SEV-ES code (KVM would need to ensure\nthe temporarily load()+put() only runs when the vCPU isn't already loaded),\nand is ultimately pointless.\n\nThe motivation for the WARN is to guard against KVM dirtying guest memory\nwithout pushing the corresponding GFN to the active vCPU's dirty ring, e.g.\nto ensure userspace doesn't miss a dirty page.  But for the VM's refcount\nto reach zero, there can't be _any_ userspace mappings to the dirty ring,\nas mapping the dirty ring requires doing mmap() on the vCPU FD.  I.e. if\nuserspace had a valid mapping for the dirty ring, then the vCPU file and\nthus the owning VM would still be alive.  And so since userspace can't\npossibly reach the dirty ring, whether or not KVM technically \"misses\" a\npush to the dirty ring is irrelevant.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53345","epss":0.0012,"percentile":0.02059,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53345","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53345","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53353","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53353","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hsr: Remove WARN_ONCE() in hsr_addr_is_self().  syzbot reported the warning [0] in hsr_addr_is_self(), whose assumption is simply wrong.  hsr->self_node is cleared in hsr_del_self_node(), which is called from hsr_dellink().  Since dev->rtnl_link_ops->dellink() is called before unregister_netdevice_many(), there is a window when user can find the device but without hsr->self_node.  Let's remove WARN_ONCE() in hsr_addr_is_self().  [0]: HSR: No self node WARNING: net/hsr/hsr_framereg.c:39 at hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39, CPU#0: syz.4.16848/17220 Modules linked in: CPU: 0 UID: 0 PID: 17220 Comm: syz.4.16848 Tainted: G             L      syzkaller #0 PREEMPT_{RT,(full)} Tainted: [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026 RIP: 0010:hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39 Code: 33 2f 41 0f b7 dd 89 ee 09 de 31 ff e8 c8 b4 c6 f6 09 dd 74 54 e8 0f b0 c6 f6 31 ed eb 53 e8 06 b0 c6 f6 48 8d 3d 2f 50 9c 04 <67> 48 0f b9 3a 31 ed eb 42 e8 c1 13 1f 00 89 c5 31 ff 89 c6 e8 96 RSP: 0018:ffffc900041c70e0 EFLAGS: 00010283 RAX: ffffffff8afdc6ca RBX: ffffffff8afdc4e6 RCX: 0000000000080000 RDX: ffffc90010493000 RSI: 0000000000000948 RDI: ffffffff8f9a1700 RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000 R10: ffffc900041c71e8 R11: fffff52000838e3f R12: dffffc0000000000 R13: ffff888041f9e3c0 R14: ffff888086ee3802 R15: 0000000000000000 FS:  00007f6fe985d6c0(0000) GS:ffff888126176000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f80bd437dac CR3: 0000000025096000 CR4: 00000000003526f0 DR0: ffffffffffffffff DR1: 00000000000001f8 DR2: 0000000000000002 DR3: ffffffffefffff15 DR6: 00000000ffff0ff0 DR7: 0000000000000400 Call Trace:  <TASK>  check_local_dest net/hsr/hsr_forward.c:592 [inline]  fill_frame_info net/hsr/hsr_forward.c:728 [inline]  hsr_forward_skb+0xa11/0x2a80 net/hsr/hsr_forward.c:739  hsr_dev_xmit+0x253/0x370 net/hsr/hsr_device.c:236  __netdev_start_xmit include/linux/netdevice.h:5368 [inline]  netdev_start_xmit include/linux/netdevice.h:5377 [inline]  xmit_one net/core/dev.c:3888 [inline]  dev_hard_start_xmit+0x2df/0x860 net/core/dev.c:3904  __dev_queue_xmit+0x1428/0x3900 net/core/dev.c:4870  neigh_output include/net/neighbour.h:556 [inline]  ip_finish_output2+0xcec/0x10b0 net/ipv4/ip_output.c:237  ip_send_skb net/ipv4/ip_output.c:1510 [inline]  ip_push_pending_frames+0x8b/0x110 net/ipv4/ip_output.c:1530  raw_sendmsg+0x1547/0x1a50 net/ipv4/raw.c:659  sock_sendmsg_nosec net/socket.c:787 [inline]  __sock_sendmsg net/socket.c:802 [inline]  ____sys_sendmsg+0x7da/0x9c0 net/socket.c:2698  ___sys_sendmsg+0x2a5/0x360 net/socket.c:2752  __sys_sendmsg net/socket.c:2784 [inline]  __do_sys_sendmsg net/socket.c:2789 [inline]  __se_sys_sendmsg net/socket.c:2787 [inline]  __x64_sys_sendmsg+0x1c3/0x2a0 net/socket.c:2787  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f6feb62ce59 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f6fe985d028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f6feb8a6090 RCX: 00007f6feb62ce59 RDX: 0000000000000000 RSI: 0000200000000000 RDI: 0000000000000004 RBP: 00007f6feb6c2d6f R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f6feb8a6128 R14: 00007f6feb8a6090 R15: 00007ffcf01cc488  </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53353","epss":0.00162,"percentile":0.05688,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08505},"relatedVulnerabilities":[{"id":"CVE-2026-53353","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53353","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0232b6fcb7615fb7fecfe0727a23065a53e228b8","https://git.kernel.org/stable/c/271355c2ef6171dbc815e7ae653eed63444bbd58","https://git.kernel.org/stable/c/66a46e22396fd5d09606f37f73643eb20e99aa42","https://git.kernel.org/stable/c/afd0f17ca46258cec3a5cc48b8df9327fe772490","https://git.kernel.org/stable/c/d71bb171661ec0225bf4babdd4d296d744982fb3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: Remove WARN_ONCE() in hsr_addr_is_self().\n\nsyzbot reported the warning [0] in hsr_addr_is_self(),\nwhose assumption is simply wrong.\n\nhsr->self_node is cleared in hsr_del_self_node(), which\nis called from hsr_dellink().\n\nSince dev->rtnl_link_ops->dellink() is called before\nunregister_netdevice_many(), there is a window when\nuser can find the device but without hsr->self_node.\n\nLet's remove WARN_ONCE() in hsr_addr_is_self().\n\n[0]:\nHSR: No self node\nWARNING: net/hsr/hsr_framereg.c:39 at hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39, CPU#0: syz.4.16848/17220\nModules linked in:\nCPU: 0 UID: 0 PID: 17220 Comm: syz.4.16848 Tainted: G             L      syzkaller #0 PREEMPT_{RT,(full)}\nTainted: [L]=SOFTLOCKUP\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026\nRIP: 0010:hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39\nCode: 33 2f 41 0f b7 dd 89 ee 09 de 31 ff e8 c8 b4 c6 f6 09 dd 74 54 e8 0f b0 c6 f6 31 ed eb 53 e8 06 b0 c6 f6 48 8d 3d 2f 50 9c 04 <67> 48 0f b9 3a 31 ed eb 42 e8 c1 13 1f 00 89 c5 31 ff 89 c6 e8 96\nRSP: 0018:ffffc900041c70e0 EFLAGS: 00010283\nRAX: ffffffff8afdc6ca RBX: ffffffff8afdc4e6 RCX: 0000000000080000\nRDX: ffffc90010493000 RSI: 0000000000000948 RDI: ffffffff8f9a1700\nRBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000\nR10: ffffc900041c71e8 R11: fffff52000838e3f R12: dffffc0000000000\nR13: ffff888041f9e3c0 R14: ffff888086ee3802 R15: 0000000000000000\nFS:  00007f6fe985d6c0(0000) GS:ffff888126176000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f80bd437dac CR3: 0000000025096000 CR4: 00000000003526f0\nDR0: ffffffffffffffff DR1: 00000000000001f8 DR2: 0000000000000002\nDR3: ffffffffefffff15 DR6: 00000000ffff0ff0 DR7: 0000000000000400\nCall Trace:\n <TASK>\n check_local_dest net/hsr/hsr_forward.c:592 [inline]\n fill_frame_info net/hsr/hsr_forward.c:728 [inline]\n hsr_forward_skb+0xa11/0x2a80 net/hsr/hsr_forward.c:739\n hsr_dev_xmit+0x253/0x370 net/hsr/hsr_device.c:236\n __netdev_start_xmit include/linux/netdevice.h:5368 [inline]\n netdev_start_xmit include/linux/netdevice.h:5377 [inline]\n xmit_one net/core/dev.c:3888 [inline]\n dev_hard_start_xmit+0x2df/0x860 net/core/dev.c:3904\n __dev_queue_xmit+0x1428/0x3900 net/core/dev.c:4870\n neigh_output include/net/neighbour.h:556 [inline]\n ip_finish_output2+0xcec/0x10b0 net/ipv4/ip_output.c:237\n ip_send_skb net/ipv4/ip_output.c:1510 [inline]\n ip_push_pending_frames+0x8b/0x110 net/ipv4/ip_output.c:1530\n raw_sendmsg+0x1547/0x1a50 net/ipv4/raw.c:659\n sock_sendmsg_nosec net/socket.c:787 [inline]\n __sock_sendmsg net/socket.c:802 [inline]\n ____sys_sendmsg+0x7da/0x9c0 net/socket.c:2698\n ___sys_sendmsg+0x2a5/0x360 net/socket.c:2752\n __sys_sendmsg net/socket.c:2784 [inline]\n __do_sys_sendmsg net/socket.c:2789 [inline]\n __se_sys_sendmsg net/socket.c:2787 [inline]\n __x64_sys_sendmsg+0x1c3/0x2a0 net/socket.c:2787\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f6feb62ce59\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f6fe985d028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f6feb8a6090 RCX: 00007f6feb62ce59\nRDX: 0000000000000000 RSI: 0000200000000000 RDI: 0000000000000004\nRBP: 00007f6feb6c2d6f R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007f6feb8a6128 R14: 00007f6feb8a6090 R15: 00007ffcf01cc488\n </TASK>","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53353","epss":0.00162,"percentile":0.05688,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53353","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53358","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53358","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()  l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock.  cleanup_listen() runs under the parent sk_lock, so acquiring conn->lock would invert the established conn->lock -> chan->lock -> sk_lock order.  Instead of calling l2cap_chan_close() directly, schedule l2cap_chan_timeout with delay 0 to close the channel asynchronously.  The timeout handler already acquires conn->lock and chan->lock in the correct order.  The timer is only armed when chan->conn is still set: if it is already NULL, l2cap_conn_del() has already processed this channel (l2cap_chan_del + l2cap_sock_teardown_cb + l2cap_sock_close_cb), so there is nothing left to do.  If l2cap_conn_del() races in after the timer is armed, __clear_chan_timer() inside l2cap_chan_del() cancels it; if the timer has already fired, the handler returns harmlessly because chan->conn was cleared.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53358","epss":0.00215,"percentile":0.11821,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53358","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17522500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-53358","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53358","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3634cbdc2eb414b69ffa752ddbe5e0458518e321","https://git.kernel.org/stable/c/50dfec218808b148ab4247b1858031b7a32015c5","https://git.kernel.org/stable/c/7555fd885a0603f50e49a655850a1f2bd8a25398","https://git.kernel.org/stable/c/859d3ace791ed878ae9ba5522c7844d960da8f88","https://git.kernel.org/stable/c/89dec92041717b027216e110599e4f6d6c921b79","https://git.kernel.org/stable/c/8c8e620467a7b51562dbcefbd1f09f288d7d710d","https://git.kernel.org/stable/c/deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9","https://git.kernel.org/stable/c/e1c100e2d61bd8c718b7d91fe3e050780a9bf72d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: use chan timer to close channels in cleanup_listen()\n\nl2cap_chan_close() removes the channel from conn->chan_l, which\nmust be done under conn->lock.  cleanup_listen() runs under the\nparent sk_lock, so acquiring conn->lock would invert the\nestablished conn->lock -> chan->lock -> sk_lock order.\n\nInstead of calling l2cap_chan_close() directly, schedule\nl2cap_chan_timeout with delay 0 to close the channel\nasynchronously.  The timeout handler already acquires conn->lock\nand chan->lock in the correct order.\n\nThe timer is only armed when chan->conn is still set: if it is\nalready NULL, l2cap_conn_del() has already processed this channel\n(l2cap_chan_del + l2cap_sock_teardown_cb + l2cap_sock_close_cb),\nso there is nothing left to do.  If l2cap_conn_del() races in\nafter the timer is armed, __clear_chan_timer() inside\nl2cap_chan_del() cancels it; if the timer has already fired, the\nhandler returns harmlessly because chan->conn was cleared.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53358","epss":0.00215,"percentile":0.11821,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53358","cwe":"CWE-667","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53358","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53361","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53361","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  af_unix: Set gc_in_progress to true in unix_gc().  Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running:    Thread 1         Thread 2                     Thread 3   --------         --------                     --------                    unix_schedule_gc()           unix_schedule_gc()                    `- if (!gc_in_progress)      `- if (!gc_in_progress)                       |- gc_in_progress = true     |                       `- queue_work()              |   unix_gc() <----------------/                     |   |                                                |- gc_in_progress = true   ...                                              `- queue_work()   |                                                       |   `- gc_in_progress = false                               |                                                           |   unix_gc() <---------------------------------------------'   |   ... /* gc_in_progress == false */   |   `- gc_in_progress = false  unix_peek_fpl() relies on gc_in_progress not to confuse GC by MSG_PEEK.  Let's set gc_in_progress to true in unix_gc().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53361","epss":0.00193,"percentile":0.09047,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.14089000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-53361","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53361","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0cfa78c050662784fc8e3ab26dbfd1dc632b2082","https://git.kernel.org/stable/c/20aa894d475bd8086b25c1113ec4ca70f70c7a98","https://git.kernel.org/stable/c/591f1ac217428a6d2b32a8ac14aac0fab44f155a","https://git.kernel.org/stable/c/82c17e13d404f686e164590483fd6c1abaa675d0","https://git.kernel.org/stable/c/d82ba05263c69fa2437fe93e4e561cc40f4c03af"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Set gc_in_progress to true in unix_gc().\n\nIgor Ushakov reported that unix_gc() could run with gc_in_progress\nbeing false if the work is scheduled while running:\n\n  Thread 1         Thread 2                     Thread 3\n  --------         --------                     --------\n                   unix_schedule_gc()           unix_schedule_gc()\n                   `- if (!gc_in_progress)      `- if (!gc_in_progress)\n                      |- gc_in_progress = true     |\n                      `- queue_work()              |\n  unix_gc() <----------------/                     |\n  |                                                |- gc_in_progress = true\n  ...                                              `- queue_work()\n  |                                                       |\n  `- gc_in_progress = false                               |\n                                                          |\n  unix_gc() <---------------------------------------------'\n  |\n  ... /* gc_in_progress == false */\n  |\n  `- gc_in_progress = false\n\nunix_peek_fpl() relies on gc_in_progress not to confuse GC\nby MSG_PEEK.\n\nLet's set gc_in_progress to true in unix_gc().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53361","epss":0.00193,"percentile":0.09047,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53361","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53368","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53368","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage  f2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion with the checkpoint path, which can result in an incorrect inode block marking state. The scenario is as follows:  create & write & fsync 'file A'                 write checkpoint - f2fs_do_sync_file // inline inode  - f2fs_write_inode // inode folio is dirty                                                 - f2fs_write_checkpoint                                                  - f2fs_flush_merged_writes                                                  - f2fs_sync_node_pages  - f2fs_fsync_node_pages // no dirty node  - f2fs_need_inode_block_update // return true  - f2fs_fsync_node_pages // inode dirtied   - f2fs_need_dentry_mark //return true                                                  - f2fs_flush_nat_entries                                                 - f2fs_write_checkpoint end   - __write_node_folio // inode with DENT_BIT_SHIFT set   SPO, \"fsck --dry-run\" find inode has already checkpointed but still   with DENT_BIT_SHIFT set  The state observed by f2fs_need_dentry_mark() can differ from the state observed in __write_node_folio() after acquiring sbi->node_write. The root cause is that the semantics of IS_CHECKPOINTED and HAS_FSYNCED_INODE are only guaranteed after the checkpoint write has fully completed.  This patch moves set_dentry_mark() into __write_node_folio() and protects it with the sbi->node_write lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53368","epss":0.00127,"percentile":0.02699,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09271},"relatedVulnerabilities":[{"id":"CVE-2026-53368","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53368","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/019f9dda7f66e55eb94cd32e1d3fff5835f73fbc","https://git.kernel.org/stable/c/b28a83ea4934215b5de906c3ee4fbfbc651573e0","https://git.kernel.org/stable/c/bedb710b63ae1bd617e65d0a8cf6cea1200b3753"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage\n\nf2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion\nwith the checkpoint path, which can result in an incorrect inode block\nmarking state. The scenario is as follows:\n\ncreate & write & fsync 'file A'                 write checkpoint\n- f2fs_do_sync_file // inline inode\n - f2fs_write_inode // inode folio is dirty\n                                                - f2fs_write_checkpoint\n                                                 - f2fs_flush_merged_writes\n                                                 - f2fs_sync_node_pages\n - f2fs_fsync_node_pages // no dirty node\n - f2fs_need_inode_block_update // return true\n - f2fs_fsync_node_pages // inode dirtied\n  - f2fs_need_dentry_mark //return true\n                                                 - f2fs_flush_nat_entries\n                                                - f2fs_write_checkpoint end\n  - __write_node_folio // inode with DENT_BIT_SHIFT set\n  SPO, \"fsck --dry-run\" find inode has already checkpointed but still\n  with DENT_BIT_SHIFT set\n\nThe state observed by f2fs_need_dentry_mark() can differ from the state\nobserved in __write_node_folio() after acquiring sbi->node_write. The\nroot cause is that the semantics of IS_CHECKPOINTED and\nHAS_FSYNCED_INODE are only guaranteed after the checkpoint write has\nfully completed.\n\nThis patch moves set_dentry_mark() into __write_node_folio() and\nprotects it with the sbi->node_write lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53368","epss":0.00127,"percentile":0.02699,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53368","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53376","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Add upper bound check for num_of_nodes  drm/amdkfd: Add upper bound check for num_of_nodes in kfd_ioctl_get_process_apertures_new.  (cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53376","epss":0.0012,"percentile":0.02059,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06299999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-53376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53376","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/44d5a450c04d3d734c13a03561c3131020d66edf","https://git.kernel.org/stable/c/4a8093c7def141cc6e854fbe3f9693867982418f","https://git.kernel.org/stable/c/6ba6ec5fcbb0d03ca11ed1cc38d57a7deb6c6b20","https://git.kernel.org/stable/c/74b73fa56a395d46745e4f245225963e9f8be7f1","https://git.kernel.org/stable/c/7b80137eb8aa9d1cbfe7ccf3eeb1faa94ae35d7e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Add upper bound check for num_of_nodes\n\ndrm/amdkfd: Add upper bound check for num_of_nodes\nin kfd_ioctl_get_process_apertures_new.\n\n(cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53376","epss":0.0012,"percentile":0.02059,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53377","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53377","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/msm: always recover the gpu  Previously, in case there was no more work to do, recover worker wouldn't trigger recovery and would instead rely on the gpu going to sleep and then resuming when more work is submitted.  Recover_worker will first increment the fence of the hung ring so, if there's only one job submitted to a ring and that causes an hang, it will early out.  There's no guarantee that the gpu will suspend and resume before more work is submitted and if the gpu is in a hung state it will stay in that state and probably trigger a timeout again.  Just stop checking and always recover the gpu.  Patchwork: https://patchwork.freedesktop.org/patch/704066/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53377","epss":0.00123,"percentile":0.024,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06457500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-53377","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53377","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/01a0d6cd7032e9993feea19fadb03ef9d5b488f2","https://git.kernel.org/stable/c/132b8d51f0ffbee6e4e1ebbe1a50330aaf2dbd5d","https://git.kernel.org/stable/c/2f5c90478749dfd9a32386100b6078a364298b01"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: always recover the gpu\n\nPreviously, in case there was no more work to do, recover worker\nwouldn't trigger recovery and would instead rely on the gpu going to\nsleep and then resuming when more work is submitted.\n\nRecover_worker will first increment the fence of the hung ring so, if\nthere's only one job submitted to a ring and that causes an hang, it\nwill early out.\n\nThere's no guarantee that the gpu will suspend and resume before more\nwork is submitted and if the gpu is in a hung state it will stay in that\nstate and probably trigger a timeout again.\n\nJust stop checking and always recover the gpu.\n\nPatchwork: https://patchwork.freedesktop.org/patch/704066/","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53377","epss":0.00123,"percentile":0.024,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53377","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-53401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53401","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: omap2: fix use-after-free in omapfb_mmap  omapfb_mmap() has a race condition with OMAPFB_SETUP_PLANE ioctl that can lead to use-after-free:  The fb_mmap() entry point holds mm_lock but not lock (fb_info->lock), while ioctl handlers like OMAPFB_SETUP_PLANE hold lock but not mm_lock. This allows concurrent execution.  In omapfb_mmap(): 1. rg = omapfb_get_mem_region(ofbi->region);      // Get old region ref 2. start = omapfb_get_region_paddr(ofbi);          // Read from NEW region 3. len = fix->smem_len;                             // Read from NEW region 4. vm_iomap_memory(vma, start, len);               // Map NEW region memory 5. atomic_inc(&rg->map_count);                      // Increment OLD region!  Concurrently, OMAPFB_SETUP_PLANE can: - Reassign ofbi->region = new_rg - Update fix->smem_len - OMAPFB_SETUP_MEM then checks NEW region's map_count (0!) and frees it  This leaves userspace with a mapping to freed physical memory.  The fix is to read all required values (start, len) from the same region reference (rg) that will have its map_count incremented, preventing the region from being freed while still mapped.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53401","epss":0.00177,"percentile":0.07345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53401","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.135405},"relatedVulnerabilities":[{"id":"CVE-2026-53401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53401","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6eb6ebcc8590007ad59ddccc8b5f9201655b33f8","https://git.kernel.org/stable/c/7958e67375aa111522086286bba13cfc0816ce8d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: omap2: fix use-after-free in omapfb_mmap\n\nomapfb_mmap() has a race condition with OMAPFB_SETUP_PLANE ioctl that\ncan lead to use-after-free:\n\nThe fb_mmap() entry point holds mm_lock but not lock (fb_info->lock),\nwhile ioctl handlers like OMAPFB_SETUP_PLANE hold lock but not mm_lock.\nThis allows concurrent execution.\n\nIn omapfb_mmap():\n1. rg = omapfb_get_mem_region(ofbi->region);      // Get old region ref\n2. start = omapfb_get_region_paddr(ofbi);          // Read from NEW region\n3. len = fix->smem_len;                             // Read from NEW region\n4. vm_iomap_memory(vma, start, len);               // Map NEW region memory\n5. atomic_inc(&rg->map_count);                      // Increment OLD region!\n\nConcurrently, OMAPFB_SETUP_PLANE can:\n- Reassign ofbi->region = new_rg\n- Update fix->smem_len\n- OMAPFB_SETUP_MEM then checks NEW region's map_count (0!) and frees it\n\nThis leaves userspace with a mapping to freed physical memory.\n\nThe fix is to read all required values (start, len) from the same\nregion reference (rg) that will have its map_count incremented,\npreventing the region from being freed while still mapped.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-53401","epss":0.00177,"percentile":0.07345,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-53401","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-53401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63805","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63805","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: nx - fix nx_crypto_ctx_exit argument  nx_crypto_ctx_shash_exit calls nx_crypto_ctx_exit with crypto_shash_ctx(...) but crypto_shash_ctx gives a nx_crypto_ctx *, not a crypto_tfm *.  Fix the type in nx_crypto_ctx_exit and drop the bogus crypto_tfm_ctx call.  This fixes the following oops:    BUG: Unable to handle kernel data access at 0xc0403effffffffc8   Faulting instruction address: 0xc000000000396cb4   Oops: Kernel access of bad area, sig: 11 [#15]   Call Trace:    nx_crypto_ctx_shash_exit+0x24/0x60    crypto_shash_exit_tfm+0x28/0x40    crypto_destroy_tfm+0x98/0x140    crypto_exit_ahash_using_shash+0x20/0x40    crypto_destroy_tfm+0x98/0x140    hash_release+0x1c/0x30    alg_sock_destruct+0x38/0x60    __sk_destruct+0x48/0x2b0    af_alg_release+0x58/0xb0    __sock_release+0x68/0x150    sock_close+0x20/0x40    __fput+0x110/0x3a0    sys_close+0x48/0xa0    system_call_exception+0x140/0x2d0    system_call_common+0xf4/0x258  .. which came from hardlink(1) opportunistically using AF_ALG.  The same problem exists with nx_crypto_ctx_skcipher_exit getting a context it wasn't expecting, but apparently nobody hit that for years.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63805","epss":0.00173,"percentile":0.06896,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13234500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-63805","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63805","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4e67f504ee9ded15e256b64f4fde150e917381d7","https://git.kernel.org/stable/c/833033e6e55acf11304ff7bbbdf18351d139c281","https://git.kernel.org/stable/c/8d8507a457667f23477a15496b91908a5b5b7cf3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: nx - fix nx_crypto_ctx_exit argument\n\nnx_crypto_ctx_shash_exit calls nx_crypto_ctx_exit with crypto_shash_ctx(...)\nbut crypto_shash_ctx gives a nx_crypto_ctx *, not a crypto_tfm *.\n\nFix the type in nx_crypto_ctx_exit and drop the bogus crypto_tfm_ctx\ncall.\n\nThis fixes the following oops:\n\n  BUG: Unable to handle kernel data access at 0xc0403effffffffc8\n  Faulting instruction address: 0xc000000000396cb4\n  Oops: Kernel access of bad area, sig: 11 [#15]\n  Call Trace:\n   nx_crypto_ctx_shash_exit+0x24/0x60\n   crypto_shash_exit_tfm+0x28/0x40\n   crypto_destroy_tfm+0x98/0x140\n   crypto_exit_ahash_using_shash+0x20/0x40\n   crypto_destroy_tfm+0x98/0x140\n   hash_release+0x1c/0x30\n   alg_sock_destruct+0x38/0x60\n   __sk_destruct+0x48/0x2b0\n   af_alg_release+0x58/0xb0\n   __sock_release+0x68/0x150\n   sock_close+0x20/0x40\n   __fput+0x110/0x3a0\n   sys_close+0x48/0xa0\n   system_call_exception+0x140/0x2d0\n   system_call_common+0xf4/0x258\n\n.. which came from hardlink(1) opportunistically using AF_ALG.\n\nThe same problem exists with nx_crypto_ctx_skcipher_exit getting a context\nit wasn't expecting, but apparently nobody hit that for years.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63805","epss":0.00173,"percentile":0.06896,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63805","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63816","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63816","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode  - ioctl(F2FS_IOC_GARBAGE_COLLECT_RANGE)\t\t- shrink  - f2fs_gc   - gc_data_segment    - ra_data_block(cow_inode)     - mapping = F2FS_I(inode)->atomic_inode->i_mapping     : f2fs_is_cow_file(cow_inode) is true \t\t\t\t\t\t - f2fs_evict_inode(atomic_inode) \t\t\t\t\t\t  - clear_inode_flag(fi->cow_inode, FI_COW_FILE) \t\t\t\t\t\t  - F2FS_I(fi->cow_inode)->atomic_inode = NULL \t\t\t\t\t\t  ... \t\t\t\t\t\t  - truncate_inode_pages_final(atomic_inode)     - f2fs_grab_cache_folio(mapping)     : create folio in atomic_inode->mapping \t\t\t\t\t\t  - clear_inode(atomic_inode) \t\t\t\t\t\t   - BUG_ON(atomic_inode->i_data.nrpages)  We need to add a reference on fi->atomic_inode before using its mapping field during garbage collection, otherwise, it will cause UAF issue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63816","epss":0.00126,"percentile":0.02641,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-63816","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63816","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/56038756aae68312df00d4aa1d97e51ef3aca725","https://git.kernel.org/stable/c/7d3ae21783e5914c1761ac7d63f882d3d70800e9","https://git.kernel.org/stable/c/a499f77c06050a28c897bdbd86cd2f0721ae0743","https://git.kernel.org/stable/c/a805fec35c201c59643ddcde713bce4051c8ee27","https://git.kernel.org/stable/c/e0288584baa5dc41df4a829a023c4c1b33fe53d7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode\n\n- ioctl(F2FS_IOC_GARBAGE_COLLECT_RANGE)\t\t- shrink\n - f2fs_gc\n  - gc_data_segment\n   - ra_data_block(cow_inode)\n    - mapping = F2FS_I(inode)->atomic_inode->i_mapping\n    : f2fs_is_cow_file(cow_inode) is true\n\t\t\t\t\t\t - f2fs_evict_inode(atomic_inode)\n\t\t\t\t\t\t  - clear_inode_flag(fi->cow_inode, FI_COW_FILE)\n\t\t\t\t\t\t  - F2FS_I(fi->cow_inode)->atomic_inode = NULL\n\t\t\t\t\t\t  ...\n\t\t\t\t\t\t  - truncate_inode_pages_final(atomic_inode)\n    - f2fs_grab_cache_folio(mapping)\n    : create folio in atomic_inode->mapping\n\t\t\t\t\t\t  - clear_inode(atomic_inode)\n\t\t\t\t\t\t   - BUG_ON(atomic_inode->i_data.nrpages)\n\nWe need to add a reference on fi->atomic_inode before using its mapping\nfield during garbage collection, otherwise, it will cause UAF issue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63816","epss":0.00126,"percentile":0.02641,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63816","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63819","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63819","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  f2fs: fix to do sanity check on f2fs_get_node_folio_ra()  kernel BUG at fs/f2fs/file.c:845! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 5336 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:f2fs_do_truncate_blocks+0x1115/0x1140 fs/f2fs/file.c:845 Code: fc fc 90 0f 0b e8 8b 9d 9a fd 90 0f 0b e8 83 9d 9a fd 48 89 df 48 c7 c6 60 d1 1a 8c e8 54 f1 fc fc 90 0f 0b e8 6c 9d 9a fd 90 <0f> 0b e8 64 9d 9a fd 90 0f 0b 90 e9 93 fd ff ff e8 56 9d 9a fd 90 RSP: 0018:ffffc9000e4474c0 EFLAGS: 00010283 RAX: ffffffff842b1d34 RBX: 0000000000000003 RCX: 0000000000100000 RDX: ffffc9000f03a000 RSI: 0000000000035503 RDI: 0000000000035504 RBP: ffffc9000e447608 R08: ffff8880123b0000 R09: 0000000000000002 R10: 00000000fffffffe R11: 0000000000000002 R12: 0000000000000001 R13: 0000000000000000 R14: 1ffff92001c88ea0 R15: 00000000ffff039c FS:  00007f7e02ee36c0(0000) GS:ffff88808c887000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007ff0305c4000 CR3: 0000000012d4c000 CR4: 0000000000352ef0 Call Trace:  <TASK>  f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:882  f2fs_truncate+0x471/0x7c0 fs/f2fs/file.c:940  f2fs_evict_inode+0xa3f/0x1ac0 fs/f2fs/inode.c:907  evict+0x61e/0xb10 fs/inode.c:841  f2fs_fill_super+0x5f43/0x78f0 fs/f2fs/super.c:5224  get_tree_bdev_flags+0x431/0x4f0 fs/super.c:1694  vfs_get_tree+0x92/0x2a0 fs/super.c:1754  fc_mount fs/namespace.c:1193 [inline]  do_new_mount_fc fs/namespace.c:3758 [inline]  do_new_mount+0x341/0xd30 fs/namespace.c:3834  do_mount fs/namespace.c:4167 [inline]  __do_sys_mount fs/namespace.c:4383 [inline]  __se_sys_mount+0x31d/0x420 fs/namespace.c:4360  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f  \tcount = ADDRS_PER_PAGE(dn.node_folio, inode);  \tcount -= dn.ofs_in_node; \tf2fs_bug_on(sbi, count < 0);  The fuzz test will trigger above bug_on in f2fs.  The root cause should be: in the corrupted inode, there is a direct node which has the same ino and nid in its footer, so in f2fs_do_truncate_blocks(), after f2fs_get_dnode_of_data() finds such dnode: 1) ADDRS_PER_PAGE(dn.node_folio, inode) will return 923 2) once dn.ofs_in_node points to addr[923, 1017] Then it will trigger the system panic.  Let's introduce NODE_TYPE_NON_IXNODE to indicate current node should not be an inode or xattr node, and then use it in below path to detect inconsistent node chain in inode mapping table:  - f2fs_do_truncate_blocks  - f2fs_get_dnode_of_data   - f2fs_get_node_folio_ra    -  __get_node_folio     - f2fs_sanity_check_node_footer      - case NODE_TYPE_NON_IXNODE -> check whether it is inode|xnode","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63819","epss":0.00173,"percentile":0.06896,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13234500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-63819","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63819","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0cc21c1ffe15b4156b0bf744f32fd1faef0b7c73","https://git.kernel.org/stable/c/406c28af75123432d38cf9bbaa6f1476f7b14770","https://git.kernel.org/stable/c/8712353ed80f87271d732297567dcdbe4b84e8c7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on f2fs_get_node_folio_ra()\n\nkernel BUG at fs/f2fs/file.c:845!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nCPU: 0 UID: 0 PID: 5336 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:f2fs_do_truncate_blocks+0x1115/0x1140 fs/f2fs/file.c:845\nCode: fc fc 90 0f 0b e8 8b 9d 9a fd 90 0f 0b e8 83 9d 9a fd 48 89 df 48 c7 c6 60 d1 1a 8c e8 54 f1 fc fc 90 0f 0b e8 6c 9d 9a fd 90 <0f> 0b e8 64 9d 9a fd 90 0f 0b 90 e9 93 fd ff ff e8 56 9d 9a fd 90\nRSP: 0018:ffffc9000e4474c0 EFLAGS: 00010283\nRAX: ffffffff842b1d34 RBX: 0000000000000003 RCX: 0000000000100000\nRDX: ffffc9000f03a000 RSI: 0000000000035503 RDI: 0000000000035504\nRBP: ffffc9000e447608 R08: ffff8880123b0000 R09: 0000000000000002\nR10: 00000000fffffffe R11: 0000000000000002 R12: 0000000000000001\nR13: 0000000000000000 R14: 1ffff92001c88ea0 R15: 00000000ffff039c\nFS:  00007f7e02ee36c0(0000) GS:ffff88808c887000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ff0305c4000 CR3: 0000000012d4c000 CR4: 0000000000352ef0\nCall Trace:\n <TASK>\n f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:882\n f2fs_truncate+0x471/0x7c0 fs/f2fs/file.c:940\n f2fs_evict_inode+0xa3f/0x1ac0 fs/f2fs/inode.c:907\n evict+0x61e/0xb10 fs/inode.c:841\n f2fs_fill_super+0x5f43/0x78f0 fs/f2fs/super.c:5224\n get_tree_bdev_flags+0x431/0x4f0 fs/super.c:1694\n vfs_get_tree+0x92/0x2a0 fs/super.c:1754\n fc_mount fs/namespace.c:1193 [inline]\n do_new_mount_fc fs/namespace.c:3758 [inline]\n do_new_mount+0x341/0xd30 fs/namespace.c:3834\n do_mount fs/namespace.c:4167 [inline]\n __do_sys_mount fs/namespace.c:4383 [inline]\n __se_sys_mount+0x31d/0x420 fs/namespace.c:4360\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n\tcount = ADDRS_PER_PAGE(dn.node_folio, inode);\n\n\tcount -= dn.ofs_in_node;\n\tf2fs_bug_on(sbi, count < 0);\n\nThe fuzz test will trigger above bug_on in f2fs.\n\nThe root cause should be: in the corrupted inode, there is a direct node\nwhich has the same ino and nid in its footer, so in f2fs_do_truncate_blocks(),\nafter f2fs_get_dnode_of_data() finds such dnode:\n1) ADDRS_PER_PAGE(dn.node_folio, inode) will return 923\n2) once dn.ofs_in_node points to addr[923, 1017]\nThen it will trigger the system panic.\n\nLet's introduce NODE_TYPE_NON_IXNODE to indicate current node should\nnot be an inode or xattr node, and then use it in below path to detect\ninconsistent node chain in inode mapping table:\n\n- f2fs_do_truncate_blocks\n - f2fs_get_dnode_of_data\n  - f2fs_get_node_folio_ra\n   -  __get_node_folio\n    - f2fs_sanity_check_node_footer\n     - case NODE_TYPE_NON_IXNODE -> check whether it is inode|xnode","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63819","epss":0.00173,"percentile":0.06896,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63819","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63825","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63825","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gcov: use atomic counter updates to fix concurrent access crashes  GCC's GCOV instrumentation can merge global branch counters with loop induction variables as an optimization.  In inflate_fast(), the inner copy loops get transformed so that the GCOV counter value is loaded multiple times to compute the loop base address, start index, and end bound.  Since GCOV counters are global (not per-CPU), concurrent execution on different CPUs causes the counter to change between loads, producing inconsistent values and out-of-bounds memory writes.  The crash manifests during IPComp (IP Payload Compression) processing when inflate_fast() runs concurrently on multiple CPUs:    BUG: unable to handle page fault for address: ffffd0a3c0902ffa   RIP: inflate_fast+1431   Call Trace:    zlib_inflate    __deflate_decompress    crypto_comp_decompress    ipcomp_decompress [xfrm_ipcomp]    ipcomp_input [xfrm_ipcomp]    xfrm_input  At the crash point, the compiler generated three loads from the same global GCOV counter (__gcov0.inflate_fast+216) to compute base, start, and end for an indexed loop.  Another CPU modified the counter between loads, making the values inconsistent - the write went 3.4 MB past a 65 KB buffer.  Add -fprofile-update=prefer-atomic to CFLAGS_GCOV at the global level in the top-level Makefile, guarded by a try-run compile test.  The test compiles a minimal program with and without -fprofile-update=prefer-atomic using the full KBUILD_CFLAGS, then compares undefined symbols in the resulting object files.  If prefer-atomic introduces new undefined references (such as __atomic_fetch_add_8 on i386 or __aarch64_ldadd8_relax on arm64 with outline-atomics), the flag is not added -- the kernel does not link against libatomic.  On architectures where GCC inlines 64-bit atomic counter updates (x86_64, s390, ...) the test passes and the flag is enabled, preventing the compiler from merging counters with loop induction variables and fixing the observed concurrent-access crash.  On architectures where the flag would introduce libatomic dependencies, it is silently omitted and behaviour is no worse than before this patch.  Move the CFLAGS_GCOV block from its original position (before the arch Makefile include) to after the core KBUILD_CFLAGS assignments but before the scripts/Makefile.gcc-plugins include.  This placement ensures the try-run test sees arch-specific flags (-m32, -march=, -mno-outline-atomics) while avoiding GCC plugin flags (-fplugin=) that would break the test on clean builds when plugin shared objects do not yet exist.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63825","epss":0.00775,"percentile":0.53626,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.7285},"relatedVulnerabilities":[{"id":"CVE-2026-63825","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63825","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/49d893b9cbcfc5802a32e53a64c6c6956670d65b","https://git.kernel.org/stable/c/56cb9b7d96b28a1173a510ab25354b6599ad3a33","https://git.kernel.org/stable/c/5b959c1dbb4522b9e3ac4e26ad638b8784869841"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngcov: use atomic counter updates to fix concurrent access crashes\n\nGCC's GCOV instrumentation can merge global branch counters with loop\ninduction variables as an optimization.  In inflate_fast(), the inner copy\nloops get transformed so that the GCOV counter value is loaded multiple\ntimes to compute the loop base address, start index, and end bound.  Since\nGCOV counters are global (not per-CPU), concurrent execution on different\nCPUs causes the counter to change between loads, producing inconsistent\nvalues and out-of-bounds memory writes.\n\nThe crash manifests during IPComp (IP Payload Compression) processing when\ninflate_fast() runs concurrently on multiple CPUs:\n\n  BUG: unable to handle page fault for address: ffffd0a3c0902ffa\n  RIP: inflate_fast+1431\n  Call Trace:\n   zlib_inflate\n   __deflate_decompress\n   crypto_comp_decompress\n   ipcomp_decompress [xfrm_ipcomp]\n   ipcomp_input [xfrm_ipcomp]\n   xfrm_input\n\nAt the crash point, the compiler generated three loads from the same\nglobal GCOV counter (__gcov0.inflate_fast+216) to compute base, start, and\nend for an indexed loop.  Another CPU modified the counter between loads,\nmaking the values inconsistent - the write went 3.4 MB past a 65 KB\nbuffer.\n\nAdd -fprofile-update=prefer-atomic to CFLAGS_GCOV at the global level in\nthe top-level Makefile, guarded by a try-run compile test.  The test\ncompiles a minimal program with and without -fprofile-update=prefer-atomic\nusing the full KBUILD_CFLAGS, then compares undefined symbols in the\nresulting object files.  If prefer-atomic introduces new undefined\nreferences (such as __atomic_fetch_add_8 on i386 or __aarch64_ldadd8_relax\non arm64 with outline-atomics), the flag is not added -- the kernel does\nnot link against libatomic.\n\nOn architectures where GCC inlines 64-bit atomic counter updates (x86_64,\ns390, ...) the test passes and the flag is enabled, preventing the\ncompiler from merging counters with loop induction variables and fixing\nthe observed concurrent-access crash.\n\nOn architectures where the flag would introduce libatomic dependencies, it\nis silently omitted and behaviour is no worse than before this patch.\n\nMove the CFLAGS_GCOV block from its original position (before the arch\nMakefile include) to after the core KBUILD_CFLAGS assignments but before\nthe scripts/Makefile.gcc-plugins include.  This placement ensures the\ntry-run test sees arch-specific flags (-m32, -march=,\n-mno-outline-atomics) while avoiding GCC plugin flags (-fplugin=) that\nwould break the test on clean builds when plugin shared objects do not yet\nexist.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63825","epss":0.00775,"percentile":0.53626,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63825","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63826","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63826","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: fix use-after-free in store_modes()  store_modes() replaces a framebuffer's modelist with modes from userspace. On success it frees the old modelist with fb_destroy_modelist(). Two fields still point into that freed list.  One pointer is fb_display[i].mode, the mode a console is using. fbcon_new_modelist() moves these pointers to the new list. It only does so for consoles still mapped to the framebuffer. An unmapped console is skipped and keeps its stale pointer. Unbinding fbcon, for example, sets con2fb_map[i] to -1 but leaves fb_display[i].mode set. An FBIOPUT_VSCREENINFO ioctl with FB_ACTIVATE_INV_MODE later reaches fbcon_mode_deleted(). That function reads the stale fb_display[i].mode through fb_mode_is_equal(). The read is a use-after-free.  The other pointer is fb_info->mode, the current mode. It is set through the mode sysfs attribute. store_modes() does not update fb_info->mode, so it is left pointing into the freed list. show_mode(), the attribute's read handler, dereferences the stale fb_info->mode through mode_string(). The read is a use-after-free.  Clear both pointers before freeing the list. Commit a1f305893074 (\"fbcon: Set fb_display[i]->mode to NULL when the mode is released\") added the helper fbcon_delete_modelist(). It clears every fb_display[i].mode that points into a given list. So far it is called only from the unregister path. Call it from store_modes() too, and set fb_info->mode to NULL.","cvss":[],"epss":[{"cve":"CVE-2026-63826","epss":0.00166,"percentile":0.06104,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-63826","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63826","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0d35f9f194a858567a21017d69318a51e3a822b9","https://git.kernel.org/stable/c/2c1c805c65fb7dc7524e20376d6987721e73a0b1","https://git.kernel.org/stable/c/5267eab88fa4c684459504b8be577ad64953b9a6","https://git.kernel.org/stable/c/70f1e000b88cfa8ca3fd7f4d082647fc089a7769","https://git.kernel.org/stable/c/c6765f39ed27014ff877b00a2efa494233404e17"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: fix use-after-free in store_modes()\n\nstore_modes() replaces a framebuffer's modelist with modes from userspace.\nOn success it frees the old modelist with fb_destroy_modelist(). Two\nfields still point into that freed list.\n\nOne pointer is fb_display[i].mode, the mode a console is using.\nfbcon_new_modelist() moves these pointers to the new list. It only does so\nfor consoles still mapped to the framebuffer. An unmapped console is\nskipped and keeps its stale pointer. Unbinding fbcon, for example, sets\ncon2fb_map[i] to -1 but leaves fb_display[i].mode set. An\nFBIOPUT_VSCREENINFO ioctl with FB_ACTIVATE_INV_MODE later reaches\nfbcon_mode_deleted(). That function reads the stale fb_display[i].mode\nthrough fb_mode_is_equal(). The read is a use-after-free.\n\nThe other pointer is fb_info->mode, the current mode. It is set through\nthe mode sysfs attribute. store_modes() does not update fb_info->mode, so\nit is left pointing into the freed list. show_mode(), the attribute's read\nhandler, dereferences the stale fb_info->mode through mode_string(). The\nread is a use-after-free.\n\nClear both pointers before freeing the list. Commit a1f305893074 (\"fbcon:\nSet fb_display[i]->mode to NULL when the mode is released\") added the\nhelper fbcon_delete_modelist(). It clears every fb_display[i].mode that\npoints into a given list. So far it is called only from the unregister\npath. Call it from store_modes() too, and set fb_info->mode to NULL.","cvss":[],"epss":[{"cve":"CVE-2026-63826","epss":0.00166,"percentile":0.06104,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63826","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63845","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63845","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring  JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences.  (cherry picked from commit 8d0cac9478a3f046279c657d6a2545de49ae675a)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63845","epss":0.00142,"percentile":0.03796,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10863},"relatedVulnerabilities":[{"id":"CVE-2026-63845","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63845","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6876d05b899102f4dfdb9ad560132126144c1c72","https://git.kernel.org/stable/c/a676f16ea9a7df96d69f405afb6eb349571b3382","https://git.kernel.org/stable/c/af4b458daa597dae707bf3f1f74745f5fc133ca2","https://git.kernel.org/stable/c/d4e0172a1b614373385e9b7111b580f8d2e0b98f","https://git.kernel.org/stable/c/e7e90b5839aeb8805ec83bb4da610b8dab8e184d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 8d0cac9478a3f046279c657d6a2545de49ae675a)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63845","epss":0.00142,"percentile":0.03796,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63845","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63846","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring  JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences.  (cherry picked from commit 4d7d774f100efb5089c86a1fb8c5bf47c63fc9ef)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63846","epss":0.00142,"percentile":0.03795,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10863},"relatedVulnerabilities":[{"id":"CVE-2026-63846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63846","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/303da8279f195cc741adc52c1b44d6b64de63bb0","https://git.kernel.org/stable/c/48ce00787e3fddd2b45692fc991b8ab128343da5","https://git.kernel.org/stable/c/5ada37d7f736f9feeaa06a25e470a4c74e67a61a","https://git.kernel.org/stable/c/a2baf12eec41f246689e6a3f8619af1200031576","https://git.kernel.org/stable/c/ee035a9d3eed3a9f5a3e83c31a10b321c9598861"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 4d7d774f100efb5089c86a1fb8c5bf47c63fc9ef)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63846","epss":0.00142,"percentile":0.03795,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63846","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63847","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63847","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring  JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences.  (cherry picked from commit 3216a7f4e2642bda5fd14f57586e835ae9202587)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63847","epss":0.00141,"percentile":0.03769,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.107865},"relatedVulnerabilities":[{"id":"CVE-2026-63847","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63847","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3a96fee676fc0caf08f03ad915bec6fcd144d551","https://git.kernel.org/stable/c/4d96e3cbfc66e4d66ea0096bde858e28ab62da00","https://git.kernel.org/stable/c/63691e396105611173072ad548fc2b68831ecf23","https://git.kernel.org/stable/c/694fe016969c5e5a24b9e0ef7c1307eedec8ddf8","https://git.kernel.org/stable/c/79405e774ede411c6b47ed41c651e40b92de64a2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 3216a7f4e2642bda5fd14f57586e835ae9202587)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63847","epss":0.00141,"percentile":0.03769,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63847","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63848","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63848","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring  JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences.  (cherry picked from commit 96179da0c6b059eb31706a0abe8dd6381c533143)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63848","epss":0.00142,"percentile":0.03795,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10863},"relatedVulnerabilities":[{"id":"CVE-2026-63848","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63848","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2e216c2ff159b2eb1da6e9c716d727efc73c64b5","https://git.kernel.org/stable/c/41c4f3f68a343d62bd352a95ace93a11c4ad92ed","https://git.kernel.org/stable/c/b41248d1c18384835f6532e68592ee07605da283","https://git.kernel.org/stable/c/e5f612dc91650561fe2b5b76dd6d2898ec9ad480","https://git.kernel.org/stable/c/f675801889b265634aefd30aa4503fc2b9e6ce1c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 96179da0c6b059eb31706a0abe8dd6381c533143)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63848","epss":0.00142,"percentile":0.03795,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63848","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63853","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63853","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring  VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences.  (cherry picked from commit fd852c048b46f9825e904a4f3f4538fe9d8827d9)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63853","epss":0.0013,"percentile":0.03002,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09945},"relatedVulnerabilities":[{"id":"CVE-2026-63853","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63853","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1286b6872de0aee1feeeaa6dbac86369806de9a5","https://git.kernel.org/stable/c/51f694221047c84fa185be98210eb2c354ffb8c6","https://git.kernel.org/stable/c/6bdd2ed6458d35c368fbe9550a4d7f342abd3a92"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit fd852c048b46f9825e904a4f3f4538fe9d8827d9)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63853","epss":0.0013,"percentile":0.03002,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63853","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63854","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63854","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings  VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences.  (cherry picked from commit 663bed3c7b8b9a7624b0d95d300ddae034ad0614)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63854","epss":0.00132,"percentile":0.03106,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10097999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-63854","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63854","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/26c4f38529ac78930c9c4713e16ebc5b689bb0a3","https://git.kernel.org/stable/c/2d6525e7b2504f5bbfe9417cddc1e8da858791dd","https://git.kernel.org/stable/c/b076e45e6f757a2829e80d0144c1b5f201bee5af","https://git.kernel.org/stable/c/e74fc9c72c1ba78d0de0b849f5929c3b39a8e20c","https://git.kernel.org/stable/c/f1e5a6660d7cbf006079126d9babbf0ccf538c6b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit 663bed3c7b8b9a7624b0d95d300ddae034ad0614)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63854","epss":0.00132,"percentile":0.03106,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63854","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63855","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63855","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings  VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences.  (cherry picked from commit efc9dd5590894109bce9a0bfe1fa5592dd6b20b1)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63855","epss":0.00132,"percentile":0.03106,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10097999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-63855","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63855","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2c6fb056567efb49f8674108b86088a1cfaa86d0","https://git.kernel.org/stable/c/4f317863a3ab212a027d8c8c3cc3af4e3fb95704","https://git.kernel.org/stable/c/5a3c6f76cab164a5d803084908d7050f649ab7f9","https://git.kernel.org/stable/c/602d4c5872b25ddd4d82fb2025efb9a05b187bb3","https://git.kernel.org/stable/c/8f0ea4524dc71c6c9ec97f2711f46e12f624140f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit efc9dd5590894109bce9a0bfe1fa5592dd6b20b1)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63855","epss":0.00132,"percentile":0.03106,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63855","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63856","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63856","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings  VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences.  (cherry picked from commit e2b5499fca55f1a32960a311bbb62e35891eaf73)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63856","epss":0.00132,"percentile":0.03107,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10097999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-63856","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63856","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5e777bc4cbe928ac0fd95e368fee1540f2ce4db2","https://git.kernel.org/stable/c/8d80b293b41fcb5e9396db93e788b0f4ebcbafb7","https://git.kernel.org/stable/c/ac06ce5cac9e711281585d09d00c6efcd9b86396","https://git.kernel.org/stable/c/c71aecae98e42dcf2baf462df50b3a2cf1a93fe4","https://git.kernel.org/stable/c/f264019be80de79f84f464846451445923bffea0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit e2b5499fca55f1a32960a311bbb62e35891eaf73)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63856","epss":0.00132,"percentile":0.03107,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63856","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63858","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63858","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: add hook transactions for device deletions  Restore the flag that indicates that the hook is going away, ie. NFT_HOOK_REMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase.  The existing approach that moves the hook from the basechain/flowtable hook_list to transaction hook_list breaks netlink dump path readers of this RCU-protected list.  It should be possible use an array for nft_trans_hook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place.  Note that the nft_trans_chain_hooks() list contains a list of struct nft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nft_trans_hook for consistency.  This patch also adapts the event notification path to deal with the list of hook transactions.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63858","epss":0.00123,"percentile":0.02389,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.094095},"relatedVulnerabilities":[{"id":"CVE-2026-63858","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63858","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/10f79dbd7719d1da9f5884d13060322d8729f091","https://git.kernel.org/stable/c/4e69bfb32b2db323d9205fdb30e284481b37817c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: add hook transactions for device deletions\n\nRestore the flag that indicates that the hook is going away, ie.\nNFT_HOOK_REMOVE, but add a new transaction object to track deletion\nof hooks without altering the basechain/flowtable hook_list during\nthe preparation phase.\n\nThe existing approach that moves the hook from the basechain/flowtable\nhook_list to transaction hook_list breaks netlink dump path readers\nof this RCU-protected list.\n\nIt should be possible use an array for nft_trans_hook to store the\ndeleted hooks to compact the representation but I am not expecting\nmany hook object, specially now that wildcard support for devices\nis in place.\n\nNote that the nft_trans_chain_hooks() list contains a list of struct\nnft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while\nthis list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE.\nNote that new commands can be updated to use nft_trans_hook for\nconsistency.\n\nThis patch also adapts the event notification path to deal with the list\nof hook transactions.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63858","epss":0.00123,"percentile":0.02389,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63858","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63871","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63871","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls  iso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and iso_conn_big_sync() call hci_get_route() using iso_pi(sk)->dst, iso_pi(sk)->src, and iso_pi(sk)->src_type without holding lock_sock().  These fields may be modified concurrently by connect() or setsockopt() on the same socket, resulting in data-races reported by KCSAN.  Fix this by snapshotting the required fields under lock_sock() before calling hci_get_route().  BUG: KCSAN: data-race in memcmp+0x45/0xb0  race at unknown origin, with read to 0xffff8880122135cf of 1 bytes by task 333 on cpu 1:  memcmp+0x45/0xb0  hci_get_route+0x27e/0x490  iso_connect_cis+0x4c/0xa10  iso_sock_connect+0x60e/0xb30  __sys_connect_file+0xbd/0xe0  __sys_connect+0xe0/0x110  __x64_sys_connect+0x40/0x50  x64_sys_call+0xcad/0x1c60  do_syscall_64+0x133/0x590  entry_SYSCALL_64_after_hwframe+0x77/0x7f","cvss":[],"epss":[{"cve":"CVE-2026-63871","epss":0.00209,"percentile":0.11074,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1045},"relatedVulnerabilities":[{"id":"CVE-2026-63871","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63871","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/859bb1f4cb615d98c9c1ab2bd76ebb0b8fe46020","https://git.kernel.org/stable/c/9798f7d41d85ff763afd1f1cc0533b5c416c8348","https://git.kernel.org/stable/c/9ca7053d6215d89c33f28893bfd1625a32919d3f","https://git.kernel.org/stable/c/ab84fd7779a2a7ff5d2c8eac212c43733f56216e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls\n\niso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and\niso_conn_big_sync() call hci_get_route() using iso_pi(sk)->dst,\niso_pi(sk)->src, and iso_pi(sk)->src_type without holding lock_sock().\n\nThese fields may be modified concurrently by connect() or setsockopt()\non the same socket, resulting in data-races reported by KCSAN.\n\nFix this by snapshotting the required fields under lock_sock() before\ncalling hci_get_route().\n\nBUG: KCSAN: data-race in memcmp+0x45/0xb0\n\nrace at unknown origin, with read to 0xffff8880122135cf of 1 bytes\nby task 333 on cpu 1:\n memcmp+0x45/0xb0\n hci_get_route+0x27e/0x490\n iso_connect_cis+0x4c/0xa10\n iso_sock_connect+0x60e/0xb30\n __sys_connect_file+0xbd/0xe0\n __sys_connect+0xe0/0x110\n __x64_sys_connect+0x40/0x50\n x64_sys_call+0xcad/0x1c60\n do_syscall_64+0x133/0x590\n entry_SYSCALL_64_after_hwframe+0x77/0x7f","cvss":[],"epss":[{"cve":"CVE-2026-63871","epss":0.00209,"percentile":0.11074,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63871","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63940","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63940","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: SEV: Ignore Port I/O requests of length '0'  Explicitly ignore Port I/O requests of length '0' (or count '0'), so that setting up the software scratch area (and other code) doesn't have to worry about underflowing the length, and to allow for WARNing on trying to configure the scratch area with len==0.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63940","epss":0.00185,"percentile":0.08196,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16927500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-63940","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63940","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/2254972d4d69e279ba4e87bf0968eb08ad0d3c92","https://git.kernel.org/stable/c/3988bd2723de407ae90fa7a6f6029b4e60238c58","https://git.kernel.org/stable/c/3b6035bc6bff20e89752ce4358bc4c9a9d5883f2","https://git.kernel.org/stable/c/c30cde934c7813b4e3069765dac64ce3d31e34f2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Ignore Port I/O requests of length '0'\n\nExplicitly ignore Port I/O requests of length '0' (or count '0'), so that\nsetting up the software scratch area (and other code) doesn't have to\nworry about underflowing the length, and to allow for WARNing on trying\nto configure the scratch area with len==0.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63940","epss":0.00185,"percentile":0.08196,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63940","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63959","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63959","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT  A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that.  Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory.","cvss":[],"epss":[{"cve":"CVE-2026-63959","epss":0.00206,"percentile":0.10671,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-63959","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63959","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0af00f1459f5dd757f0d392f8caa38039561ac62","https://git.kernel.org/stable/c/9b496e3371c04f0a03b7faa5d2442536d00e3998","https://git.kernel.org/stable/c/aa2f716327be1818e1cb156da8a2844804aaec2f","https://git.kernel.org/stable/c/c4ab8e2d4432abb646c5c0687f8dab173da901f9","https://git.kernel.org/stable/c/dc17721d42e6d89f63572e63add8306a0e15eb3c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT\n\nA broken/malicious port can transmit a CRC-valid frame whose header\nadvertises up to seven data objects but whose body carries fewer than\nthat.  Check for this, and rightfully reject the message, instead of\nreading from uninitialized stack memory.","cvss":[],"epss":[{"cve":"CVE-2026-63959","epss":0.00206,"percentile":0.10671,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63959","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63962","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63962","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()  svdm_consume_modes() checks pmdata->altmodes against the array size once before the loop over the count, but forgot to check the bound at every point in the loop.  In the well-behaved SVDM discovery flow this is harmless because each of at most SVID_DISCOVERY_MAX SVIDs contributes at most MODE_DISCOVERY_MAX modes, exactly filling altmode_desc[ALTMODE_DISCOVERY_MAX].  But the CMDT_RSP_ACK handler in tcpm_pd_svdm() does not correlate an incoming ACK with any request the port actually sent.  Once port->partner is set, an unsolicited Discover Modes ACK is consumed unconditionally.  A broken or malicious port partner can therefore drive altmodes to ALTMODE_DISCOVERY_MAX - 1 via the normal flow, and then send one extra Discover Modes ACK with seven VDOs.  Because the pre-loop check passes, the loop could then writes up to five entries past altmode_desc[].  For mode_data_prime the next field in struct tcpm_port is the partner_altmode[] pointer array, which then receives partner-chosen SVID/VDO bytes.  Move the bound check inside the loop so the array can never be indexed past ALTMODE_DISCOVERY_MAX regardless of how many VDOs the partner supplies or how the function was reached.","cvss":[],"epss":[{"cve":"CVE-2026-63962","epss":0.00206,"percentile":0.10672,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-63962","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63962","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3389c149c68c3fea61910ad5d34f7bf3bff44e32","https://git.kernel.org/stable/c/4505f33dab56c274e82f47f94bf60a8cbf8f4b42","https://git.kernel.org/stable/c/845598b154b9a92e9d279fafafa9405c121ae805","https://git.kernel.org/stable/c/cbad85b446c06adbc5e5bed565871bb918ce9d32"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()\n\nsvdm_consume_modes() checks pmdata->altmodes against the array size once\nbefore the loop over the count, but forgot to check the bound at every\npoint in the loop.\n\nIn the well-behaved SVDM discovery flow this is harmless because each of\nat most SVID_DISCOVERY_MAX SVIDs contributes at most MODE_DISCOVERY_MAX\nmodes, exactly filling altmode_desc[ALTMODE_DISCOVERY_MAX].  But the\nCMDT_RSP_ACK handler in tcpm_pd_svdm() does not correlate an incoming\nACK with any request the port actually sent.  Once port->partner is set,\nan unsolicited Discover Modes ACK is consumed unconditionally.  A broken\nor malicious port partner can therefore drive altmodes to\nALTMODE_DISCOVERY_MAX - 1 via the normal flow, and then send one extra\nDiscover Modes ACK with seven VDOs.  Because the pre-loop check passes,\nthe loop could then writes up to five entries past altmode_desc[].  For\nmode_data_prime the next field in struct tcpm_port is the\npartner_altmode[] pointer array, which then receives partner-chosen\nSVID/VDO bytes.\n\nMove the bound check inside the loop so the array can never be indexed\npast ALTMODE_DISCOVERY_MAX regardless of how many VDOs the partner\nsupplies or how the function was reached.","cvss":[],"epss":[{"cve":"CVE-2026-63962","epss":0.00206,"percentile":0.10672,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63962","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63963","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63963","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers  Properly validate the count passed from a device when calling svdm_consume_identity() or svdm_consume_identity_sop_prime() as the device-controlled value could index off of the static arrays, which could leak data.","cvss":[],"epss":[{"cve":"CVE-2026-63963","epss":0.002,"percentile":0.09936,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-63963","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63963","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/569f7971542eb10025d8a0989b83f28a29d8ba20","https://git.kernel.org/stable/c/8fbc349e8383125dd2d8de1c1e926279d398ab17","https://git.kernel.org/stable/c/ed8649f3822e211d025bcab5158af6f8a38c8705","https://git.kernel.org/stable/c/f9d787fbe83127105e42088cca40e5118db0d810"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: validate VDO count in Discover Identity ACK handlers\n\nProperly validate the count passed from a device when calling\nsvdm_consume_identity() or svdm_consume_identity_sop_prime() as the\ndevice-controlled value could index off of the static arrays, which\ncould leak data.","cvss":[],"epss":[{"cve":"CVE-2026-63963","epss":0.002,"percentile":0.09936,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63963","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63974","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63974","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close  Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63974","epss":0.00317,"percentile":0.24414,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25835500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-63974","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63974","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/47330cc875b36a1cf7b3543cb2cf90a7c603ce0e","https://git.kernel.org/stable/c/525daaea459fc215f432de1b8debbd9144bf97b0","https://git.kernel.org/stable/c/60bceb9a4c693e68cc90ba4b2dfb9e000e8638ff","https://git.kernel.org/stable/c/9cebe4680bb9a72f80c6541eb24af06db7a1fbc9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close\n\nSince hci_dev_close_sync() can now be called during the reset path, we\nshould also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts\nwhile the hdev workqueue is being drained.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-63974","epss":0.00317,"percentile":0.24414,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63974","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63983","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63983","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: fix packet loop on netem when duplicate is on  When netem duplicates a packet it re-enqueues the copy at the root qdisc. If another netem sits in the tree the copy can be duplicated again, recursing until the stack or memory is exhausted.  The original duplication guard temporarily zeroed q->duplicate around the re-enqueue, but that does not cover all cases because it is per-qdisc state shared across all concurrent enqueue paths and is not safe without additional locking.  Use the skb tc_depth field introduced in an earlier patch:  - increment it on the duplicate before re-enqueue  - skip duplication for any skb whose tc_depth is already non-zero.  This marks the packet itself rather than mutating qdisc state, therefore it is safe regardless of tree topology or concurrency.","cvss":[],"epss":[{"cve":"CVE-2026-63983","epss":0.00166,"percentile":0.06156,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-63983","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63983","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1a298a514ce766c6d0c232991a390fec67af81ad","https://git.kernel.org/stable/c/9552b11e3edabc97cfcd9f29103d5afbce7ae183","https://git.kernel.org/stable/c/cfb2616042767ab31260d4f39190c381bec8b12e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix packet loop on netem when duplicate is on\n\nWhen netem duplicates a packet it re-enqueues the copy at the root qdisc.\nIf another netem sits in the tree the copy can be duplicated\nagain, recursing until the stack or memory is exhausted.\n\nThe original duplication guard temporarily zeroed q->duplicate around\nthe re-enqueue, but that does not cover all cases because it is\nper-qdisc state shared across all concurrent enqueue paths\nand is not safe without additional locking.\n\nUse the skb tc_depth field introduced in an earlier patch:\n - increment it on the duplicate before re-enqueue\n - skip duplication for any skb whose tc_depth is already non-zero.\n\nThis marks the packet itself rather than mutating qdisc state,\ntherefore it is safe regardless of tree topology or concurrency.","cvss":[],"epss":[{"cve":"CVE-2026-63983","epss":0.00166,"percentile":0.06156,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63983","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-63999","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63999","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ethtool: rss: fix indir_table and hkey leak on get_rxfh failure  rss_prepare_get() allocates the indirection table and hash key buffer via rss_get_data_alloc(), then calls ops->get_rxfh() to populate them. If get_rxfh() fails, the function returns an error without freeing the allocation.","cvss":[],"epss":[{"cve":"CVE-2026-63999","epss":0.00166,"percentile":0.06155,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-63999","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63999","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/266297692f97008ca48bc311775c087c59bd7fe3","https://git.kernel.org/stable/c/33d05c22d6f227c5ae171c46df2f6f8bf48047ea","https://git.kernel.org/stable/c/80d95d92f828cfcace955d673637d944178b435f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: rss: fix indir_table and hkey leak on get_rxfh failure\n\nrss_prepare_get() allocates the indirection table and hash key buffer\nvia rss_get_data_alloc(), then calls ops->get_rxfh() to populate them.\nIf get_rxfh() fails, the function returns an error without freeing\nthe allocation.","cvss":[],"epss":[{"cve":"CVE-2026-63999","epss":0.00166,"percentile":0.06155,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-63999","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64001","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64001","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: pcm: oss: Fix setup list UAF on proc write error  snd_pcm_oss_proc_write() links a newly allocated setup entry into the OSS setup list before duplicating the task name. If the task-name allocation fails, the error path frees the already linked entry and leaves setup_list pointing at freed memory.  A later OSS device open can then walk the stale list entry in snd_pcm_oss_look_for_setup() and dereference freed memory.  Allocate the task name and initialize the setup entry before publishing the entry on setup_list. Also fetch the initial proc read iterator only after taking setup_mutex, so all setup_list traversal follows the same list lifetime rules.","cvss":[],"epss":[{"cve":"CVE-2026-64001","epss":0.00168,"percentile":0.0634,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-64001","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64001","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4cc54bdd54b337e77115be5b55577d1c58608eae","https://git.kernel.org/stable/c/8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce","https://git.kernel.org/stable/c/be387230dc22d870afd0e5d35912b07c2bc323bd","https://git.kernel.org/stable/c/e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix setup list UAF on proc write error\n\nsnd_pcm_oss_proc_write() links a newly allocated setup entry into the\nOSS setup list before duplicating the task name. If the task-name\nallocation fails, the error path frees the already linked entry and\nleaves setup_list pointing at freed memory.\n\nA later OSS device open can then walk the stale list entry in\nsnd_pcm_oss_look_for_setup() and dereference freed memory.\n\nAllocate the task name and initialize the setup entry before publishing\nthe entry on setup_list. Also fetch the initial proc read iterator only\nafter taking setup_mutex, so all setup_list traversal follows the same\nlist lifetime rules.","cvss":[],"epss":[{"cve":"CVE-2026-64001","epss":0.00168,"percentile":0.0634,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64001","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64006","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64006","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: fix dst corruption in same register operation  For lshift and rshift, the shift operations are performed in a loop over 32-bit words. The loop calculates the shifted value and write it to dst, and then immediately reads from src to calculate the carry for the next iteration. Because src and dst could point to the same memory location, the carry is incorrectly calculated using the newly modified dst value instead of the original src value.  Adding a temporary local variable to cache the original value before writing to dst and using it for the carry calculation solves the problem. In addition, partial overlap is rejected from control plane for all kind of operations including byteorder. This was tested with the following bytecode:  table test_table ip flags 0 use 1 handle 1 ip test_table test_chain use 3 type filter hook input prio 0 policy accept packets 0 bytes 0 flags 1 ip test_table test_chain 2   [ immediate reg 1 0x44332211 0x88776655 ]   [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]   [ cmp eq reg 1 0x66443322 0x00887766 ]   [ counter pkts 0 bytes 0 ] ip test_table test_chain 4 3   [ immediate reg 1 0x44332211 0x88776655 ]   [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]   [ cmp eq reg 1 0x55443322 0x00887766 ]   [ counter pkts 21794 bytes 1917798 ]","cvss":[],"epss":[{"cve":"CVE-2026-64006","epss":0.00171,"percentile":0.06713,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08549999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-64006","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64006","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/18014147d3ee7831dce53fe65d7fc8d428b02552","https://git.kernel.org/stable/c/96bea2a7baac4a1137c188dc7610184487ab30a7","https://git.kernel.org/stable/c/a391afe74398b70107f111aa731eab608624949d","https://git.kernel.org/stable/c/b80ef316e978de2ef81d5bee9c19800b4cf96fb8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix dst corruption in same register operation\n\nFor lshift and rshift, the shift operations are performed in a loop over\n32-bit words. The loop calculates the shifted value and write it to dst,\nand then immediately reads from src to calculate the carry for the next\niteration. Because src and dst could point to the same memory location,\nthe carry is incorrectly calculated using the newly modified dst value\ninstead of the original src value.\n\nAdding a temporary local variable to cache the original value before\nwriting to dst and using it for the carry calculation solves the\nproblem. In addition, partial overlap is rejected from control plane for\nall kind of operations including byteorder. This was tested with the\nfollowing bytecode:\n\ntable test_table ip flags 0 use 1 handle 1\nip test_table test_chain use 3 type filter hook input prio 0 policy accept packets 0 bytes 0 flags 1\nip test_table test_chain 2\n  [ immediate reg 1 0x44332211 0x88776655 ]\n  [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]\n  [ cmp eq reg 1 0x66443322 0x00887766 ]\n  [ counter pkts 0 bytes 0 ]\nip test_table test_chain 4 3\n  [ immediate reg 1 0x44332211 0x88776655 ]\n  [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]\n  [ cmp eq reg 1 0x55443322 0x00887766 ]\n  [ counter pkts 21794 bytes 1917798 ]","cvss":[],"epss":[{"cve":"CVE-2026-64006","epss":0.00171,"percentile":0.06713,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64006","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64017","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  blk-mq: pop cached request if it is usable  When submitting a bio to blk-mq, if the task should sleep after peeking a cached request, but before it pops it, the plug flushes and calls blk_mq_free_plug_rqs, freeing the cached_rqs. This creates a use-after-free bug. Fix this by popping the cached request before any possible blocking calls if it is suitable for use.  Popping this request first holds a queue reference, so avoid any serialization races with queue freezes and can safely proceed with dispatching that request to the driver. This potentially increases a timing window from when a driver wants to freeze its queue to when requests stop being dispatched. That scenario is off the fast path though, and drivers need to appropriately handle requests during a freeze request anyway.  The downside is the popped element needs to be individually freed when we performed a bio plug merge. The cached request would have had to be freed later anyway, but this patch does it inline with building the plug list instead of after flushing it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64017","epss":0.00125,"percentile":0.0252,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-64017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64017","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/23d8ea1e303b5f32d883757a4a707e791dbc9808","https://git.kernel.org/stable/c/388468f7e7d1eab092cf2a39fdfb502e52019ec6","https://git.kernel.org/stable/c/97e2d08de282ef76f84ab4ccd00f1acb3f5f999e","https://git.kernel.org/stable/c/dc278e9bf2b9513a763353e6b9cc21e0f532954e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: pop cached request if it is usable\n\nWhen submitting a bio to blk-mq, if the task should sleep after peeking\na cached request, but before it pops it, the plug flushes and calls\nblk_mq_free_plug_rqs, freeing the cached_rqs. This creates a\nuse-after-free bug. Fix this by popping the cached request before any\npossible blocking calls if it is suitable for use.\n\nPopping this request first holds a queue reference, so avoid any\nserialization races with queue freezes and can safely proceed with\ndispatching that request to the driver. This potentially increases a\ntiming window from when a driver wants to freeze its queue to when\nrequests stop being dispatched. That scenario is off the fast path\nthough, and drivers need to appropriately handle requests during a\nfreeze request anyway.\n\nThe downside is the popped element needs to be individually freed when\nwe performed a bio plug merge. The cached request would have had to be\nfreed later anyway, but this patch does it inline with building the plug\nlist instead of after flushing it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64017","epss":0.00125,"percentile":0.0252,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64017","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64025","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64025","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf, skmsg: fix verdict sk_data_ready racing with ktls rx  sk_psock_strp_data_ready() already checks tls_sw_has_ctx_rx() and defers to psock->saved_data_ready when a TLS RX context is present, avoiding a conflict with the TLS strparser's ownership of the receive queue (commit e91de6afa81c, \"bpf: Fix running sk_skb program types with ktls\").  sk_psock_verdict_data_ready() has no equivalent guard.  When a socket is inserted into a sockmap (BPF_SK_SKB_VERDICT) before TLS RX is configured, tls_sw_strparser_arm() saves sk_psock_verdict_data_ready as rx_ctx->saved_data_ready.  On data arrival:    tls_data_ready -> tls_strp_data_ready -> tls_rx_msg_ready     -> saved_data_ready() = sk_psock_verdict_data_ready()       -> tcp_read_skb() drains sk_receive_queue via __skb_unlink()          without calling tcp_eat_skb(), so copied_seq is not advanced.  tls_strp_msg_load() then finds tcp_inq() >= full_len (stale), calls tcp_recv_skb() on the now-empty queue, hits WARN_ON_ONCE(!first), and returns with rx_ctx->strp.anchor.frag_list pointing at a psock-owned (potentially freed) skb.  tls_decrypt_sg() subsequently walks that frag_list: use-after-free.  Apply the same fix as sk_psock_strp_data_ready(): if a TLS RX context is present, call psock->saved_data_ready (sock_def_readable) to wake recv() waiters and return immediately, leaving the receive queue untouched.  TLS retains sole ownership of the queue and decrypts the record normally through tls_sw_recvmsg().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64025","epss":0.00444,"percentile":0.37457,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.41736000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-64025","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64025","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1861d369efd62d67796563bf3e01fc22e5626f8b","https://git.kernel.org/stable/c/7c8cf21bc4efb4af18d6096db3f8bd06d622251c","https://git.kernel.org/stable/c/8a52139560f833c3975032e1f5762611e3a36d71","https://git.kernel.org/stable/c/c9ea01768903ae47f210cd457af1dead6de7a9c3","https://git.kernel.org/stable/c/ddf8029623a1af20e984c040e89ff918158397ab"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, skmsg: fix verdict sk_data_ready racing with ktls rx\n\nsk_psock_strp_data_ready() already checks tls_sw_has_ctx_rx() and\ndefers to psock->saved_data_ready when a TLS RX context is present,\navoiding a conflict with the TLS strparser's ownership of the receive\nqueue (commit e91de6afa81c, \"bpf: Fix running sk_skb program types\nwith ktls\").\n\nsk_psock_verdict_data_ready() has no equivalent guard.  When a socket\nis inserted into a sockmap (BPF_SK_SKB_VERDICT) before TLS RX is\nconfigured, tls_sw_strparser_arm() saves sk_psock_verdict_data_ready\nas rx_ctx->saved_data_ready.  On data arrival:\n\n  tls_data_ready -> tls_strp_data_ready -> tls_rx_msg_ready\n    -> saved_data_ready() = sk_psock_verdict_data_ready()\n      -> tcp_read_skb() drains sk_receive_queue via __skb_unlink()\n         without calling tcp_eat_skb(), so copied_seq is not advanced.\n\ntls_strp_msg_load() then finds tcp_inq() >= full_len (stale), calls\ntcp_recv_skb() on the now-empty queue, hits WARN_ON_ONCE(!first), and\nreturns with rx_ctx->strp.anchor.frag_list pointing at a psock-owned\n(potentially freed) skb.  tls_decrypt_sg() subsequently walks that\nfrag_list: use-after-free.\n\nApply the same fix as sk_psock_strp_data_ready(): if a TLS RX context\nis present, call psock->saved_data_ready (sock_def_readable) to wake\nrecv() waiters and return immediately, leaving the receive queue\nuntouched.  TLS retains sole ownership of the queue and decrypts the\nrecord normally through tls_sw_recvmsg().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64025","epss":0.00444,"percentile":0.37457,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64025","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64026","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64026","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg  This improves the fix for CVE-2026-43500.  Fix the pagecache corruption from in-place decryption of a DATA packet transmitted locally by splice() by getting rid of the packet sharing in the I/O thread and unconditionally extracting the packet content into a bounce buffer in which the buffer is decrypted.  recvmsg() (or the kernel equivalent) then copies the data from the bounce buffer to the destination buffer.  The sk_buff then remains unmodified.  This has an additional advantage in that the packet is then arranged in the buffer with the correct alignment required for the crypto algorithms to process directly.  The performance of the crypto does seem to be a little faster and, surprisingly, the unencrypted performance doesn't seem to change much - possibly due to removing complexity from the I/O thread.  Yet another advantage is that the I/O thread doesn't have to copy packets which would slow down packet distribution, ACK generation, etc..  The buffer belongs to the call and is allocated initially at 2K, sufficiently large to hold a whole jumbo subpacket, but the buffer will be increased in size if needed.  However, to take this work, MSG_PEEK may cause a later packet to be decrypted into the buffer, in which case the earlier one will need re-decrypting for a subsequent recvmsg().  Note that rx_pkt_offset may legitimately see 0 as a valid offset now, so switch to using USHRT_MAX to indicate an invalid offset.  Note also that I would generally prefer to replace the buffers of the current sk_buff with a new kmalloc'd buffer of the right size, ditching the old data and frags as this makes the handling of MSG_PEEK easier and removes the re-decryption issue, but this looks like quite a complicated thing to achieve.  skb_morph() looks half way to what I want, but I don't want to have to allocate a new sk_buff.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64026","epss":0.00141,"percentile":0.03769,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.107865},"relatedVulnerabilities":[{"id":"CVE-2026-64026","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64026","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/46cb765e2e5ad52303ea157e10d370bb6b7acbbf","https://git.kernel.org/stable/c/a05bf6d9e621fa71e89ccebe3047ba45218d7b38","https://git.kernel.org/stable/c/b94a6ccbaf1104dd980150a65fdeb2f69d17d2f5","https://git.kernel.org/stable/c/c580087743712112778a06d65a4074053072d7bf","https://git.kernel.org/stable/c/d2bc90cf6c75cb96d2ce549be6c35efa3099d25b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg\n\nThis improves the fix for CVE-2026-43500.\n\nFix the pagecache corruption from in-place decryption of a DATA packet\ntransmitted locally by splice() by getting rid of the packet sharing in the\nI/O thread and unconditionally extracting the packet content into a bounce\nbuffer in which the buffer is decrypted.  recvmsg() (or the kernel\nequivalent) then copies the data from the bounce buffer to the destination\nbuffer.  The sk_buff then remains unmodified.\n\nThis has an additional advantage in that the packet is then arranged in the\nbuffer with the correct alignment required for the crypto algorithms to\nprocess directly.  The performance of the crypto does seem to be a little\nfaster and, surprisingly, the unencrypted performance doesn't seem to\nchange much - possibly due to removing complexity from the I/O thread.\n\nYet another advantage is that the I/O thread doesn't have to copy packets\nwhich would slow down packet distribution, ACK generation, etc..\n\nThe buffer belongs to the call and is allocated initially at 2K,\nsufficiently large to hold a whole jumbo subpacket, but the buffer will be\nincreased in size if needed.  However, to take this work, MSG_PEEK may\ncause a later packet to be decrypted into the buffer, in which case the\nearlier one will need re-decrypting for a subsequent recvmsg().\n\nNote that rx_pkt_offset may legitimately see 0 as a valid offset now, so\nswitch to using USHRT_MAX to indicate an invalid offset.\n\nNote also that I would generally prefer to replace the buffers of the\ncurrent sk_buff with a new kmalloc'd buffer of the right size, ditching the\nold data and frags as this makes the handling of MSG_PEEK easier and\nremoves the re-decryption issue, but this looks like quite a complicated\nthing to achieve.  skb_morph() looks half way to what I want, but I don't\nwant to have to allocate a new sk_buff.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64026","epss":0.00141,"percentile":0.03769,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64026","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64036","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64036","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cgroup/rstat: validate cpu before css_rstat_cpu() access  css_rstat_updated() is exposed as a BPF kfunc and accepts a caller-provided cpu argument. The function uses cpu for per-cpu rstat lookups without checking whether it refers to a valid possible CPU.  A BPF iter/cgroup program with CAP_BPF and CAP_PERFMON can pass an invalid cpu value. On an unfixed UBSCAN_BOUNDS test kernel, cpu == 0x7fffffff triggers:    UBSAN: array-index-out-of-bounds in kernel/cgroup/rstat.c:31:9   index 2147483647 is out of range for type 'long unsigned int [64]'   Call Trace:     css_rstat_updated     bpf_iter_run_prog     cgroup_iter_seq_show     bpf_seq_read  Add cpu validation to the BPF-facing css_rstat_updated() kfunc and move the common implementation to __css_rstat_updated() for in-kernel callers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64036","epss":0.00127,"percentile":0.02696,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097155},"relatedVulnerabilities":[{"id":"CVE-2026-64036","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64036","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6a01413a4e8fcb0263d7bef5075c5f8f4eb3a8b6","https://git.kernel.org/stable/c/8817005efbdfdf5d4e4814cb5dc52b53d12917d7","https://git.kernel.org/stable/c/fd2bd9fa7700ddf28296486b2598cff2f80cc819"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/rstat: validate cpu before css_rstat_cpu() access\n\ncss_rstat_updated() is exposed as a BPF kfunc and accepts a\ncaller-provided cpu argument. The function uses cpu for per-cpu rstat\nlookups without checking whether it refers to a valid possible CPU.\n\nA BPF iter/cgroup program with CAP_BPF and CAP_PERFMON can pass an\ninvalid cpu value. On an unfixed UBSCAN_BOUNDS test kernel, cpu ==\n0x7fffffff triggers:\n\n  UBSAN: array-index-out-of-bounds in kernel/cgroup/rstat.c:31:9\n  index 2147483647 is out of range for type 'long unsigned int [64]'\n  Call Trace:\n    css_rstat_updated\n    bpf_iter_run_prog\n    cgroup_iter_seq_show\n    bpf_seq_read\n\nAdd cpu validation to the BPF-facing css_rstat_updated() kfunc and\nmove the common implementation to __css_rstat_updated() for in-kernel\ncallers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64036","epss":0.00127,"percentile":0.02696,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64036","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64038","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64038","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (lm90) Stop work before releasing hwmon device  Sashiko reports:  In lm90_probe(), the devm action to cancel the alert_work and report_work (lm90_restore_conf) is registered in lm90_init_client() before devm_hwmon_device_register_with_info() is called.  Because devm executes cleanup actions in reverse order during module unbind or probe failure, the hwmon device is unregistered and freed first.  If lm90_alert_work() or lm90_report_alarms() runs in the window between the hwmon device being freed and the delayed works being cancelled, lm90_update_alarms() will dereference the freed data->hwmon_dev here.  Fix the problem by canceling the workers separately after registering the hwmon device and before registering the interrupt handler. This ensures that the workers are canceled after interrupts are disabled and before the hwmon device is released. Add \"shutdown\" flag to indicate that device shutdown is in progress to prevent workers from being re-armed.","cvss":[],"epss":[{"cve":"CVE-2026-64038","epss":0.00166,"percentile":0.06149,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-64038","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64038","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/479e297526aeb19c745eac5c1897f455f83dc5f8","https://git.kernel.org/stable/c/b09a45601094c7f4ec4db8090b825fa61e169d93","https://git.kernel.org/stable/c/c98107817b0f6cdf51adc5e84e75c39ee25d8b28"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Stop work before releasing hwmon device\n\nSashiko reports:\n\nIn lm90_probe(), the devm action to cancel the alert_work and report_work\n(lm90_restore_conf) is registered in lm90_init_client() before\ndevm_hwmon_device_register_with_info() is called.\n\nBecause devm executes cleanup actions in reverse order during module\nunbind or probe failure, the hwmon device is unregistered and freed first.\n\nIf lm90_alert_work() or lm90_report_alarms() runs in the window between\nthe hwmon device being freed and the delayed works being cancelled,\nlm90_update_alarms() will dereference the freed data->hwmon_dev here.\n\nFix the problem by canceling the workers separately after registering\nthe hwmon device and before registering the interrupt handler. This ensures\nthat the workers are canceled after interrupts are disabled and before\nthe hwmon device is released. Add \"shutdown\" flag to indicate that device\nshutdown is in progress to prevent workers from being re-armed.","cvss":[],"epss":[{"cve":"CVE-2026-64038","epss":0.00166,"percentile":0.06149,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64038","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64060","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64060","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfs: Fix leak of request in netfs_write_begin() error handling  Fix netfs_write_begin() to not leak our ref on the request in the event that we get an error from netfs_wait_for_read().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64060","epss":0.00121,"percentile":0.02149,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64060","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-64060","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64060","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/22ae28aae43623be235ff455558cdd13fbe2daeb","https://git.kernel.org/stable/c/28686d6d8b60dc5bbae9ef6023ab2051d6c66cdf","https://git.kernel.org/stable/c/5046a34f0643441f05b0253ea64e1a3af87efe14"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix leak of request in netfs_write_begin() error handling\n\nFix netfs_write_begin() to not leak our ref on the request in the event\nthat we get an error from netfs_wait_for_read().","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64060","epss":0.00121,"percentile":0.02149,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64060","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64060","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64076","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64076","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: bridge: eb_tables: close module init race  sashiko reports for unrelated patch:  Does the core ebtables initialization in ebtables.c suffer from a similar race?  Once nf_register_sockopt() completes, the sockopts are exposed globally.  sockopt has to be registered last, just like in ip/ip6/arptables.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64076","epss":0.00127,"percentile":0.02694,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097155},"relatedVulnerabilities":[{"id":"CVE-2026-64076","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64076","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/02d999dc69b3918dba2414932b5d95f1f75c76cb","https://git.kernel.org/stable/c/27414ff1b287ea9a2a11675149ec28e05539f3cc","https://git.kernel.org/stable/c/c647e2a21bbbaceda6cdb8a44a56f44d231dc4b4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: eb_tables: close module init race\n\nsashiko reports for unrelated patch:\n Does the core ebtables initialization in ebtables.c suffer from a similar race?\n Once nf_register_sockopt() completes, the sockopts are exposed globally.\n\nsockopt has to be registered last, just like in ip/ip6/arptables.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64076","epss":0.00127,"percentile":0.02694,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64076","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64077","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64077","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: ebtables: move to two-stage removal scheme  Like previous patches for x_tables, follow same pattern in ebtables. We can't reuse xt helpers: ebt_table struct layout is incompatible.  table->ops assignment is now done while still holding the ebt mutex to make sure we never expose partially-filled table struct.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64077","epss":0.00127,"percentile":0.02696,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097155},"relatedVulnerabilities":[{"id":"CVE-2026-64077","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64077","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/739d5dac7b2da44a756aa4d758ee3f1ccf5a27f1","https://git.kernel.org/stable/c/b7f0544d86d439cb946515d2ef6a0a75e8626710","https://git.kernel.org/stable/c/ef395579a7631a06d61969fc712eb80402231b89"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: move to two-stage removal scheme\n\nLike previous patches for x_tables, follow same pattern in ebtables.\nWe can't reuse xt helpers: ebt_table struct layout is incompatible.\n\ntable->ops assignment is now done while still holding the ebt mutex\nto make sure we never expose partially-filled table struct.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64077","epss":0.00127,"percentile":0.02696,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64077","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64078","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64078","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: x_tables: add and use xtables_unregister_table_exit  Previous change added xtables_unregister_table_pre_exit to detach the table from the packetpath and to unlink it from the active table list. In case of rmmod, userspace that is doing set/getsockopt for this table will not be able to re-instantiate the table:  1. The larval table has been removed already  2. existing instantiated table is no longer on the xt pernet table list.  This adds the second stage helper:  unlink the table from the dying list, free the hook ops (if any) and do the audit notification.  It replaces xt_unregister_table().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64078","epss":0.00127,"percentile":0.0269,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097155},"relatedVulnerabilities":[{"id":"CVE-2026-64078","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64078","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/8026e5163cca1d1db436c7bfb89ddea8b5e8c2cf","https://git.kernel.org/stable/c/86ee5bc9c0f0e652e19f395675a432de11b75514","https://git.kernel.org/stable/c/b4597d5fd7d2f8cebfffd40dffb5e003cc78964c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: add and use xtables_unregister_table_exit\n\nPrevious change added xtables_unregister_table_pre_exit to detach the\ntable from the packetpath and to unlink it from the active table list.\nIn case of rmmod, userspace that is doing set/getsockopt for this table\nwill not be able to re-instantiate the table:\n 1. The larval table has been removed already\n 2. existing instantiated table is no longer on the xt pernet table list.\n\nThis adds the second stage helper:\n\nunlink the table from the dying list, free the hook ops (if any) and do\nthe audit notification.  It replaces xt_unregister_table().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64078","epss":0.00127,"percentile":0.0269,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64078","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64079","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64079","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: x_tables: allocate hook ops while under mutex  arp/ip(6)t_register_table() add the table to the per-netns list via xt_register_table() before allocating the per-netns hook ops copy via kmemdup_array().  This leaves a window where the table is visible in the list with ops=NULL.  If the pernet exit happens runs concurrently the pre_exit callback finds the table via xt_find_table() and passes the NULL ops pointer to nf_unregister_net_hooks(), causing a NULL dereference:    general protection fault in nf_unregister_net_hooks+0xbc/0x150   RIP: nf_unregister_net_hooks (net/netfilter/core.c:613)   Call Trace:     ipt_unregister_table_pre_exit     iptable_mangle_net_pre_exit     ops_pre_exit_list     cleanup_net  Fix by moving the ops allocation into the xtables core so the table is never in the list without valid ops.  Also ensure the table is no longer processing packets before its torn down on error unwind. nf_register_net_hooks might have published at least one hook; call synchronize_rcu() if there was an error.  audit log register message gets deferred until all operations have passed, this avoids need to emit another ureg message in case of error unwinding.  Based on earlier patch by Tristan Madani.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64079","epss":0.00107,"percentile":0.01285,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64079","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.056174999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-64079","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64079","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/2f92c5f923979f37ab1d5445381e4b8378a196cc","https://git.kernel.org/stable/c/b62eb8dcf2c47d4d676a434efbd57c4f776f7829"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: allocate hook ops while under mutex\n\narp/ip(6)t_register_table() add the table to the per-netns list via\nxt_register_table() before allocating the per-netns hook ops copy\nvia kmemdup_array().  This leaves a window where the table is\nvisible in the list with ops=NULL.\n\nIf the pernet exit happens runs concurrently the pre_exit callback finds\nthe table via xt_find_table() and passes the NULL ops pointer to\nnf_unregister_net_hooks(), causing a NULL dereference:\n\n  general protection fault in nf_unregister_net_hooks+0xbc/0x150\n  RIP: nf_unregister_net_hooks (net/netfilter/core.c:613)\n  Call Trace:\n    ipt_unregister_table_pre_exit\n    iptable_mangle_net_pre_exit\n    ops_pre_exit_list\n    cleanup_net\n\nFix by moving the ops allocation into the xtables core so the table is\nnever in the list without valid ops.  Also ensure the table is no longer\nprocessing packets before its torn down on error unwind.\nnf_register_net_hooks might have published at least one hook; call\nsynchronize_rcu() if there was an error.\n\naudit log register message gets deferred until all operations have\npassed, this avoids need to emit another ureg message in case of\nerror unwinding.\n\nBased on earlier patch by Tristan Madani.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64079","epss":0.00107,"percentile":0.01285,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64079","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64079","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64082","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  riscv: Fix register corruption from uninitialized cregs on error  compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Since cregs is an uninitialized stack variable, a copyin failure causes uninitialized stack data to be written into the target task's pt_regs, corrupting its register state and potentially leaking kernel stack contents.  compat_restore_sigcontext() has the same issue: it calls cregs_to_regs() even when __copy_from_user() fails, leading to the same corruption of the signal-returning task's register state on error.  Only call cregs_to_regs() when the user copy succeeds.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64082","epss":0.00129,"percentile":0.02899,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64082","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-64082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64082","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0599aa23734c48de9bce36d043a9ec90c23945a1","https://git.kernel.org/stable/c/2a7d1daf2674fe7d5b1cc99a4e3b5f0f72d5958f","https://git.kernel.org/stable/c/66dedb6028c3df6c6a3372dd935b823917e150d5","https://git.kernel.org/stable/c/6ebcbb53fc9bc30843054ed99fd60b8e542628f4","https://git.kernel.org/stable/c/9e020156833f1ad0d425a1e3d85b65639f1c1c50","https://git.kernel.org/stable/c/f2d88b0d7aebfa4643fc58bbae57210c6daff9c6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Fix register corruption from uninitialized cregs on error\n\ncompat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when\nuser_regset_copyin() fails. Since cregs is an uninitialized stack\nvariable, a copyin failure causes uninitialized stack data to be written\ninto the target task's pt_regs, corrupting its register state and\npotentially leaking kernel stack contents.\n\ncompat_restore_sigcontext() has the same issue: it calls cregs_to_regs()\neven when __copy_from_user() fails, leading to the same corruption of\nthe signal-returning task's register state on error.\n\nOnly call cregs_to_regs() when the user copy succeeds.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64082","epss":0.00129,"percentile":0.02899,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64082","cwe":"CWE-908","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64082","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64109","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64109","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  af_unix: Fix UAF read of tail->len in unix_stream_data_wait()  unix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without holding any lock that prevents SKBs on that queue from being dequeued and freed. This has been the case since commit 79f632c71bea (\"unix/stream: fix peeking with an offset larger than data in queue\"). The first consequence of this is that the pointer comparison `tail != last` can be false even if `last` semantically refers to an already-freed SKB while `tail` is a new SKB allocated at the same address; which can cause unix_stream_data_wait() to wrongly keep blocking after new data has arrived, but only in a weird scenario where a peeking recv() and a normal recv() on the same socket are racing, which is probably not a real problem.  But since commit 2b514574f7e8 (\"net: af_unix: implement splice for stream af_unix sockets\"), `tail` is actually dereferenced, which can cause UAF in the following race scenario (where test_setup() runs single-threaded, and afterwards, test_thread1() and test_thread2() run concurrently in two threads: ``` static int socks[2]; void test_setup(void) {   socketpair(AF_UNIX, SOCK_STREAM, 0, socks);   send(socks[1], \"A\", 1, 0);   int peekoff = 1;   setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, &peekoff, sizeof(peekoff)); } void test_thread1(void) {   char dummy;   recv(socks[0], &dummy, 1, MSG_PEEK); } void test_thread2(void) {   char dummy;   recv(socks[0], &dummy, 1, 0);   shutdown(socks[1], SHUT_WR); } ```  when racing like this: ``` thread1                       thread2 unix_stream_read_generic   mutex_lock(&u->iolock)   skb_peek(&sk->sk_receive_queue)   skb_peek_next(skb, &sk->sk_receive_queue)   mutex_unlock(&u->iolock)                               unix_stream_read_generic                                 unix_state_lock(sk)                                 skb_peek(&sk->sk_receive_queue)                                 unix_state_unlock(sk)   unix_stream_data_wait     unix_state_lock(sk)     tail = skb_peek_tail(&sk->sk_receive_queue)                                 spin_lock(&sk->sk_receive_queue.lock)                                 __skb_unlink(skb, &sk->sk_receive_queue)                                 spin_unlock(&sk->sk_receive_queue.lock)                                 consume_skb(skb) [frees the SKB]     `tail != last`: false     `tail`: true     `tail->len != last_len` ***UAF*** ```  Fix the UAF by removing the read of tail->len; checking tail->len would only make sense if SKBs in the receive queue of a UNIX socket could grow, which can no longer happen.  Kuniyuki explained:  > When commit 869e7c62486e (\"net: af_unix: implement stream sendpage > support\") added sendpage() support, data could be appended to the last > skb in the receiver's queue. > > That's why we needed to check if the length of the last skb was changed > while waiting for new data in unix_stream_data_wait(). > > However, commit a0dbf5f818f9 (\"af_unix: Support MSG_SPLICE_PAGES\") and > commit 57d44a354a43 (\"unix: Convert unix_stream_sendpage() to use > MSG_SPLICE_PAGES\") refactored sendmsg(), and now data is always added > to a new skb.  That means this fix is not suitable for kernels before 6.5.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64109","epss":0.00129,"percentile":0.02832,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64109","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-64109","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64109","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/26342087fac93b3932e6af61dc91ec029cb8a623","https://git.kernel.org/stable/c/38bccb927d83d7d52e5b20015a172a0b6101d11e","https://git.kernel.org/stable/c/5f162f95a95834f06a8ec6140889272ad12e842f","https://git.kernel.org/stable/c/acdff9907478e82208475b1151700d0b71dcdc63","https://git.kernel.org/stable/c/be309f8eae8b474a4a617eaae01324da996fc719"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Fix UAF read of tail->len in unix_stream_data_wait()\n\nunix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without\nholding any lock that prevents SKBs on that queue from being dequeued and\nfreed.\nThis has been the case since commit 79f632c71bea (\"unix/stream: fix\npeeking with an offset larger than data in queue\").\nThe first consequence of this is that the pointer comparison\n`tail != last` can be false even if `last` semantically refers to an\nalready-freed SKB while `tail` is a new SKB allocated at the same address;\nwhich can cause unix_stream_data_wait() to wrongly keep blocking after new\ndata has arrived, but only in a weird scenario where a peeking recv() and\na normal recv() on the same socket are racing, which is probably not a\nreal problem.\n\nBut since commit 2b514574f7e8 (\"net: af_unix: implement splice for stream\naf_unix sockets\"), `tail` is actually dereferenced, which can cause UAF in\nthe following race scenario (where test_setup() runs single-threaded,\nand afterwards, test_thread1() and test_thread2() run concurrently in\ntwo threads:\n```\nstatic int socks[2];\nvoid test_setup(void) {\n  socketpair(AF_UNIX, SOCK_STREAM, 0, socks);\n  send(socks[1], \"A\", 1, 0);\n  int peekoff = 1;\n  setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, &peekoff, sizeof(peekoff));\n}\nvoid test_thread1(void) {\n  char dummy;\n  recv(socks[0], &dummy, 1, MSG_PEEK);\n}\nvoid test_thread2(void) {\n  char dummy;\n  recv(socks[0], &dummy, 1, 0);\n  shutdown(socks[1], SHUT_WR);\n}\n```\n\nwhen racing like this:\n```\nthread1                       thread2\nunix_stream_read_generic\n  mutex_lock(&u->iolock)\n  skb_peek(&sk->sk_receive_queue)\n  skb_peek_next(skb, &sk->sk_receive_queue)\n  mutex_unlock(&u->iolock)\n                              unix_stream_read_generic\n                                unix_state_lock(sk)\n                                skb_peek(&sk->sk_receive_queue)\n                                unix_state_unlock(sk)\n  unix_stream_data_wait\n    unix_state_lock(sk)\n    tail = skb_peek_tail(&sk->sk_receive_queue)\n                                spin_lock(&sk->sk_receive_queue.lock)\n                                __skb_unlink(skb, &sk->sk_receive_queue)\n                                spin_unlock(&sk->sk_receive_queue.lock)\n                                consume_skb(skb) [frees the SKB]\n    `tail != last`: false\n    `tail`: true\n    `tail->len != last_len` ***UAF***\n```\n\nFix the UAF by removing the read of tail->len; checking tail->len would\nonly make sense if SKBs in the receive queue of a UNIX socket could grow,\nwhich can no longer happen.\n\nKuniyuki explained:\n\n> When commit 869e7c62486e (\"net: af_unix: implement stream sendpage\n> support\") added sendpage() support, data could be appended to the last\n> skb in the receiver's queue.\n>\n> That's why we needed to check if the length of the last skb was changed\n> while waiting for new data in unix_stream_data_wait().\n>\n> However, commit a0dbf5f818f9 (\"af_unix: Support MSG_SPLICE_PAGES\") and\n> commit 57d44a354a43 (\"unix: Convert unix_stream_sendpage() to use\n> MSG_SPLICE_PAGES\") refactored sendmsg(), and now data is always added\n> to a new skb.\n\nThat means this fix is not suitable for kernels before 6.5.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64109","epss":0.00129,"percentile":0.02832,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64109","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64109","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64112","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64112","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rbd: eliminate a race in lock_dwork draining on unmap  Given how rbd_lock_add_request() and rbd_img_exclusive_lock() are written, lock_dwork may be (re)queued more than it's actually needed: for example in case a new I/O request comes in while we are in the middle of rbd_acquire_lock() on behalf of another I/O request.  This is expected and with rbd_release_lock() preemptively canceling lock_dwork is benign under normal operation.  A more problematic example is maybe_kick_acquire():      if (have_requests || delayed_work_pending(&rbd_dev->lock_dwork)) {             dout(\"%s rbd_dev %p kicking lock_dwork\\n\", __func__, rbd_dev);             mod_delayed_work(rbd_dev->task_wq, &rbd_dev->lock_dwork, 0);     }  It's not unrealistic for lock_dwork to get canceled right after delayed_work_pending() returns true and for mod_delayed_work() to requeue it right there anyway.  This is a classic TOCTOU race.  When it comes to unmapping the image, there is an implicit assumption of no self-initiated exclusive lock activity past the point of return from rbd_dev_image_unlock() which unlocks the lock if it happens to be held.  This unlock is assumed to be final and lock_dwork (as well as all other exclusive lock tasks, really) isn't expected to get queued again.  However, lock_dwork is canceled only in cancel_tasks_sync() (i.e. later in the unmap sequence) and on top of that the cancellation can get in effect nullified by maybe_kick_acquire().  This may result in rbd_acquire_lock() executing after rbd_dev_device_release() and rbd_dev_image_release() run and free and/or reset a bunch of things. One of the possible failure modes then is a violated      rbd_assert(rbd_image_format_valid(rbd_dev->image_format));  in rbd_dev_header_info() which is called via rbd_dev_refresh() from rbd_post_acquire_action().  Redo exclusive lock task draining to provide saner semantics and try to meet the assumptions around rbd_dev_image_unlock().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64112","epss":0.00099,"percentile":0.00905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64112","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07573500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-64112","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64112","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3427d7ae38337066ce88b68302e285d344ab756b","https://git.kernel.org/stable/c/9400efc76b42c751211974a25c91d2c19c65b01b","https://git.kernel.org/stable/c/9dcd4f5c99b491c37be90b0bd9988db48225fb75","https://git.kernel.org/stable/c/9fc75b71fdd38465c76c6f6a884cdd4ae3c72d90"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrbd: eliminate a race in lock_dwork draining on unmap\n\nGiven how rbd_lock_add_request() and rbd_img_exclusive_lock() are\nwritten, lock_dwork may be (re)queued more than it's actually needed:\nfor example in case a new I/O request comes in while we are in the\nmiddle of rbd_acquire_lock() on behalf of another I/O request.  This is\nexpected and with rbd_release_lock() preemptively canceling lock_dwork\nis benign under normal operation.\n\nA more problematic example is maybe_kick_acquire():\n\n    if (have_requests || delayed_work_pending(&rbd_dev->lock_dwork)) {\n            dout(\"%s rbd_dev %p kicking lock_dwork\\n\", __func__, rbd_dev);\n            mod_delayed_work(rbd_dev->task_wq, &rbd_dev->lock_dwork, 0);\n    }\n\nIt's not unrealistic for lock_dwork to get canceled right after\ndelayed_work_pending() returns true and for mod_delayed_work() to\nrequeue it right there anyway.  This is a classic TOCTOU race.\n\nWhen it comes to unmapping the image, there is an implicit assumption\nof no self-initiated exclusive lock activity past the point of return\nfrom rbd_dev_image_unlock() which unlocks the lock if it happens to be\nheld.  This unlock is assumed to be final and lock_dwork (as well as\nall other exclusive lock tasks, really) isn't expected to get queued\nagain.  However, lock_dwork is canceled only in cancel_tasks_sync()\n(i.e. later in the unmap sequence) and on top of that the cancellation\ncan get in effect nullified by maybe_kick_acquire().  This may result\nin rbd_acquire_lock() executing after rbd_dev_device_release() and\nrbd_dev_image_release() run and free and/or reset a bunch of things.\nOne of the possible failure modes then is a violated\n\n    rbd_assert(rbd_image_format_valid(rbd_dev->image_format));\n\nin rbd_dev_header_info() which is called via rbd_dev_refresh() from\nrbd_post_acquire_action().\n\nRedo exclusive lock task draining to provide saner semantics and try\nto meet the assumptions around rbd_dev_image_unlock().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64112","epss":0.00099,"percentile":0.00905,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64112","cwe":"CWE-367","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64112","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64138","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64138","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate SID in parent security descriptor during ACL inheritance  Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64138","epss":0.00415,"percentile":0.34897,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33822500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-64138","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64138","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/18d8db24b0a5b7be4829238dd4022236df02d421","https://git.kernel.org/stable/c/1c9d0646a9959752f11ca1080dc1ff26bd1756cb","https://git.kernel.org/stable/c/69f030cf95488ae1186c72ac8c66fd279664ea7f","https://git.kernel.org/stable/c/f0e5c9c663badc9982e6941322eef1cb17de0f11"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate SID in parent security descriptor during ACL inheritance\n\nIntroduce smb_validate_ntsd_sid() helper to safely validate Owner SID\nand Group SID inside the NT Security Descriptor (smb_ntsd) retrieved\nfrom the parent directory.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64138","epss":0.00415,"percentile":0.34897,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64138","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64139","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64139","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow  Commit 299f962c0b02 (\"ksmbd: use check_add_overflow() to prevent u16 DACL size overflow\") added check_add_overflow() guards that break out of the ACE-building loops in set_posix_acl_entries_dacl() when the accumulated DACL size would wrap past 65535.  However, each iteration allocates a struct smb_sid via kmalloc_obj() at the top of the loop and relies on the kfree(sid) call at the end of the loop body (the 'pass_same_sid' label in the first loop, and the explicit kfree at the tail of the second loop) to release it. The newly introduced 'break' statements bypass those kfree() calls, leaking the sid buffer every time an overflow is detected.  A malicious or malformed file with enough POSIX ACL entries to trip the overflow check will leak one or more struct smb_sid allocations on every request that touches the file's DACL, providing a trivial kernel memory exhaustion vector.  Free sid before breaking out of the loops to plug the leak.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64139","epss":0.00136,"percentile":0.03379,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64139","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0714},"relatedVulnerabilities":[{"id":"CVE-2026-64139","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64139","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0e198f09cb2a554c04de0fea4e790f1250a943ca","https://git.kernel.org/stable/c/519fb0a42ce5d7e46935577309fb282a5f2c6ea3","https://git.kernel.org/stable/c/9b0a8985b419a71ee1cc9c0cc6a9e1bb7815a2c5","https://git.kernel.org/stable/c/9d378e17c864da08c3a4df41dae92cfa6468b00a","https://git.kernel.org/stable/c/af92ee994cc7f7e83a41c2025f32257a2f82a7ef","https://git.kernel.org/stable/c/eced48cb08f07393a5ea770fdd1026452883c3ad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow\n\nCommit 299f962c0b02 (\"ksmbd: use check_add_overflow() to prevent u16\nDACL size overflow\") added check_add_overflow() guards that break out\nof the ACE-building loops in set_posix_acl_entries_dacl() when the\naccumulated DACL size would wrap past 65535.\n\nHowever, each iteration allocates a struct smb_sid via kmalloc_obj()\nat the top of the loop and relies on the kfree(sid) call at the end\nof the loop body (the 'pass_same_sid' label in the first loop, and\nthe explicit kfree at the tail of the second loop) to release it.\nThe newly introduced 'break' statements bypass those kfree() calls,\nleaking the sid buffer every time an overflow is detected.\n\nA malicious or malformed file with enough POSIX ACL entries to trip\nthe overflow check will leak one or more struct smb_sid allocations\non every request that touches the file's DACL, providing a trivial\nkernel memory exhaustion vector.\n\nFree sid before breaking out of the loops to plug the leak.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64139","epss":0.00136,"percentile":0.03379,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64139","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64139","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64144","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: btmtk: fix urb->setup_packet leak in error paths  The setup_packet of control urb is not freed if usb_submit_urb fails or the submitted urb is killed. Add free in these two paths.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64144","epss":0.00127,"percentile":0.02723,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64144","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.066675},"relatedVulnerabilities":[{"id":"CVE-2026-64144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64144","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/0d2572bafea33c7cd1d77c6a25f25ff31a432482","https://git.kernel.org/stable/c/2a1905730e0c771b999906a7b509722f795563c6","https://git.kernel.org/stable/c/68c027c2003b0a8a1439d0301c59c6fd1eb3b844","https://git.kernel.org/stable/c/a0f5268c77eb73f84ba7c210ddfc54b1c73ff80c","https://git.kernel.org/stable/c/dd1dda6b8d6e1f4376a5b3055a04f0ecbdb4d6bd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: fix urb->setup_packet leak in error paths\n\nThe setup_packet of control urb is not freed if usb_submit_urb fails or\nthe submitted urb is killed. Add free in these two paths.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64144","epss":0.00127,"percentile":0.02723,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64144","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64144","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64146","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64146","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  erofs: fix metabuf leak in inode xattr initialization  commit bb88e8da0025 (\"erofs: use meta buffers for xattr operations\") converted xattr operations to use on-stack erofs_buf instances. erofs_init_inode_xattrs() uses such a metabuf while reading the inline xattr header and shared xattr id array.  Some error paths after erofs_read_metabuf() leave through out_unlock without dropping the metabuf, so the folio reference can leak.  Consolidate the cleanup at out_unlock. erofs_put_metabuf() is a no-op if no folio has been acquired, and this keeps all paths after taking EROFS_I_BL_XATTR_BIT covered by a single cleanup site.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64146","epss":0.00112,"percentile":0.01523,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64146","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0588},"relatedVulnerabilities":[{"id":"CVE-2026-64146","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64146","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/492c73b21fefa36f3869cb2b188ffb7fe37b3a9b","https://git.kernel.org/stable/c/79b09c54c6563df9846ca3094bcfd72082c3e1d7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix metabuf leak in inode xattr initialization\n\ncommit bb88e8da0025 (\"erofs: use meta buffers for xattr operations\")\nconverted xattr operations to use on-stack erofs_buf instances.\nerofs_init_inode_xattrs() uses such a metabuf while reading the inline\nxattr header and shared xattr id array.\n\nSome error paths after erofs_read_metabuf() leave through out_unlock\nwithout dropping the metabuf, so the folio reference can leak.\n\nConsolidate the cleanup at out_unlock. erofs_put_metabuf() is a\nno-op if no folio has been acquired, and this keeps all paths after\ntaking EROFS_I_BL_XATTR_BIT covered by a single cleanup site.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64146","epss":0.00112,"percentile":0.01523,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64146","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64146","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64160","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64160","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfs: Fix potential for tearing in ->remote_i_size and ->zero_point  Fix potential tearing in using ->remote_i_size and ->zero_point by copying i_size_read() and i_size_write() and using the same seqcount as for i_size.  We need to make sure that netfslib and the filesystems that use it always hold i_lock whilst updating any of the sizes to prevent i_size_seqcount from getting corrupted.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64160","epss":0.00407,"percentile":0.34184,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.38258000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-64160","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64160","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/2c8f4742bb76117d735f92a3932d85239b16c494","https://git.kernel.org/stable/c/55970f238d495517edc961d55c44c772594d0969"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix potential for tearing in ->remote_i_size and ->zero_point\n\nFix potential tearing in using ->remote_i_size and ->zero_point by copying\ni_size_read() and i_size_write() and using the same seqcount as for i_size.\n\nWe need to make sure that netfslib and the filesystems that use it always\nhold i_lock whilst updating any of the sizes to prevent i_size_seqcount\nfrom getting corrupted.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64160","epss":0.00407,"percentile":0.34184,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64160","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64163","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64163","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  test_kprobes: clear kprobes between test runs  Running the kprobes sanity tests twice makes all tests fail and eventually crashes the kernel.  [root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run ...    # Totals: pass:5 fail:0 skip:0 total:5    ok 1 kprobes_test [root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run ...   # test_kprobe: EXPECTATION FAILED at lib/tests/test_kprobes.c:64   Expected 0 == register_kprobe(&kp), but       register_kprobe(&kp) == -22 (0xffffffffffffffea) ...   Unable to handle kernel paging request ...  The testsuite defines several kprobes and kretprobes as static variables that are preserved across test runs.  After register_kprobe and unregister_kprobe, a kprobe contains some leftover data that must be cleared before the kprobe can be registered again. The tests are setting symbol_name to define the probe location. Address and flags must be cleared.  The existing code clears some of the probes between subsequent tests, but not between two test runs. The leftover data from a previous test run makes the registrations fail in the next run.  Move the cleanups for all kprobes into kprobes_test_init, this function is called before each single test (including the first test of a test run).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64163","epss":0.00119,"percentile":0.01994,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06247500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-64163","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64163","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/08d355936fcf70c81c94f9fe7310450b65c53399","https://git.kernel.org/stable/c/1c24cf1fd67f6702c719ab73499392cb7af956ae","https://git.kernel.org/stable/c/96515819d79f356f40da5540968d838ea570fab9","https://git.kernel.org/stable/c/accc0004c501a9918313142282b094d408af06fb","https://git.kernel.org/stable/c/ef5581bb30efb939cc2bf093475c6cc85258e5cd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntest_kprobes: clear kprobes between test runs\n\nRunning the kprobes sanity tests twice makes all tests fail and\neventually crashes the kernel.\n\n[root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run\n...\n   # Totals: pass:5 fail:0 skip:0 total:5\n   ok 1 kprobes_test\n[root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run\n...\n  # test_kprobe: EXPECTATION FAILED at lib/tests/test_kprobes.c:64\n  Expected 0 == register_kprobe(&kp), but\n      register_kprobe(&kp) == -22 (0xffffffffffffffea)\n...\n  Unable to handle kernel paging request ...\n\nThe testsuite defines several kprobes and kretprobes as static variables\nthat are preserved across test runs.\n\nAfter register_kprobe and unregister_kprobe, a kprobe contains some\nleftover data that must be cleared before the kprobe can be registered\nagain. The tests are setting symbol_name to define the probe location.\nAddress and flags must be cleared.\n\nThe existing code clears some of the probes between subsequent tests, but\nnot between two test runs. The leftover data from a previous test run\nmakes the registrations fail in the next run.\n\nMove the cleanups for all kprobes into kprobes_test_init, this function\nis called before each single test (including the first test of a test\nrun).","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64163","epss":0.00119,"percentile":0.01994,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64163","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64190","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64190","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: team: fix NULL pointer dereference in team_xmit during mode change  __team_change_mode() clears team->ops with memset() before restoring safe dummy handlers via team_adjust_ops(). A concurrent team_xmit() running under RCU on another CPU can read team->ops.transmit during this window and call a NULL function pointer, crashing the kernel.  The race requires a mode change (CAP_NET_ADMIN) concurrent with transmit on the team device.   BUG: kernel NULL pointer dereference, address: 0000000000000000  Oops: 0010 [#1] SMP KASAN NOPTI  RIP: 0010:0x0  Call Trace:   team_xmit (drivers/net/team/team_core.c:1853)   dev_hard_start_xmit (net/core/dev.c:3904)   __dev_queue_xmit (net/core/dev.c:4871)   packet_sendmsg (net/packet/af_packet.c:3109)   __sys_sendto (net/socket.c:2265)  The original code assumed that no ports means no traffic, so mode changes could freely memset()/memcpy() the ops.  AF_PACKET with forced carrier breaks that assumption.  Prevent the race instead of making it safe: replace memset()/memcpy() with per-field updates that never touch transmit or receive.  Those two handlers are managed solely by team_adjust_ops(), which already installs dummies when tx_en_port_count == 0 (always true during mode change since no ports are present).  WRITE_ONCE/READ_ONCE prevent store/load tearing on the handler pointers.  synchronize_net() before exit_op() drains in-flight readers that may still reference old mode state from before port removal switched the handlers to dummies.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64190","epss":0.00143,"percentile":0.03947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64190","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.07507500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-64190","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64190","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/03e9405c518c4d61f28079492f252d6d4e2bac5c","https://git.kernel.org/stable/c/25fe708bbc59289d3d1ea4b126fbc1b460a072a5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: team: fix NULL pointer dereference in team_xmit during mode change\n\n__team_change_mode() clears team->ops with memset() before restoring\nsafe dummy handlers via team_adjust_ops(). A concurrent team_xmit()\nrunning under RCU on another CPU can read team->ops.transmit during\nthis window and call a NULL function pointer, crashing the kernel.\n\nThe race requires a mode change (CAP_NET_ADMIN) concurrent with\ntransmit on the team device.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n Oops: 0010 [#1] SMP KASAN NOPTI\n RIP: 0010:0x0\n Call Trace:\n  team_xmit (drivers/net/team/team_core.c:1853)\n  dev_hard_start_xmit (net/core/dev.c:3904)\n  __dev_queue_xmit (net/core/dev.c:4871)\n  packet_sendmsg (net/packet/af_packet.c:3109)\n  __sys_sendto (net/socket.c:2265)\n\nThe original code assumed that no ports means no traffic, so mode\nchanges could freely memset()/memcpy() the ops.  AF_PACKET with\nforced carrier breaks that assumption.\n\nPrevent the race instead of making it safe: replace memset()/memcpy()\nwith per-field updates that never touch transmit or receive.  Those\ntwo handlers are managed solely by team_adjust_ops(), which already\ninstalls dummies when tx_en_port_count == 0 (always true during mode\nchange since no ports are present).  WRITE_ONCE/READ_ONCE prevent\nstore/load tearing on the handler pointers.\n\nsynchronize_net() before exit_op() drains in-flight readers that may\nstill reference old mode state from before port removal switched the\nhandlers to dummies.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64190","epss":0.00143,"percentile":0.03947,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64190","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64190","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64192","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized  When CONFIG_BPF_LSM=y is set, BPF inode storage maps (BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However, if the BPF LSM is not explicitly enabled at boot time (e.g. omitted from the \"lsm=\" boot parameter), lsm_prepare() is never executed for the BPF LSM.  Consequently, the BPF inode security blob offset (bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at its default compiled size of 8 bytes instead of being updated to a valid offset past the reserved struct rcu_head (typically 16 bytes or more).  When a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE map, bpf_inode() evaluates inode->i_security + 8. This erroneously aliases the struct rcu_head.func callback pointer at the beginning of the inode->i_security blob. During subsequent map element cleanup or inode destruction, writing NULL to owner_storage clears the queued RCU callback pointer. When rcu_do_batch() later executes the queued callback, it attempts an instruction fetch at address 0x0, triggering an immediate kernel panic.  Fix this by introducing a global bpf_lsm_initialized boolean flag marked with __ro_after_init. Set this flag to true inside bpf_lsm_init() when the LSM framework successfully registers the BPF LSM. Gate map allocation in inode_storage_map_alloc() on this flag, returning -EOPNOTSUPP if the BPF LSM is in turn uninitialized.  This fail-fast approach prevents userspace from allocating inode storage maps when the supporting BPF LSM infrastructure is absent, avoiding zombie map states.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64192","epss":0.00118,"percentile":0.0195,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64192","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.061950000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-64192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64192","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/267fdd9b6530c399dfd996e1a0a7628b45baf9f0","https://git.kernel.org/stable/c/413b14b9623a2e6ee131c2b2152b304aeb04e378","https://git.kernel.org/stable/c/5337eebdf8c5d4810b1913047f078d2815d5645f","https://git.kernel.org/stable/c/721f669853bdbf46b475a81bb5d05d610f8c19de","https://git.kernel.org/stable/c/a6d634f794c808a261eac7d5af023a7e06b9ecd8","https://git.kernel.org/stable/c/a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4","https://git.kernel.org/stable/c/c76b8abce575e0c6e4096957220b4515ed847d89","https://git.kernel.org/stable/c/de984ea883405420fdc416ae8964b752df586970"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized\n\nWhen CONFIG_BPF_LSM=y is set, BPF inode storage maps\n(BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However,\nif the BPF LSM is not explicitly enabled at boot time (e.g. omitted\nfrom the \"lsm=\" boot parameter), lsm_prepare() is never executed for\nthe BPF LSM.\n\nConsequently, the BPF inode security blob offset\n(bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at\nits default compiled size of 8 bytes instead of being updated to a\nvalid offset past the reserved struct rcu_head (typically 16 bytes\nor more).\n\nWhen a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE\nmap, bpf_inode() evaluates inode->i_security + 8. This erroneously\naliases the struct rcu_head.func callback pointer at the beginning\nof the inode->i_security blob. During subsequent map element cleanup\nor inode destruction, writing NULL to owner_storage clears the queued\nRCU callback pointer. When rcu_do_batch() later executes the queued\ncallback, it attempts an instruction fetch at address 0x0, triggering\nan immediate kernel panic.\n\nFix this by introducing a global bpf_lsm_initialized boolean flag\nmarked with __ro_after_init. Set this flag to true inside bpf_lsm_init()\nwhen the LSM framework successfully registers the BPF LSM. Gate map\nallocation in inode_storage_map_alloc() on this flag, returning\n-EOPNOTSUPP if the BPF LSM is in turn uninitialized.\n\nThis fail-fast approach prevents userspace from allocating inode\nstorage maps when the supporting BPF LSM infrastructure is absent,\navoiding zombie map states.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64192","epss":0.00118,"percentile":0.0195,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64192","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64192","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: xsk: Fix unlocked writing to ICOSQ  During napi poll, when the affinity changes and there's still XSK work to be done, we trigger an ICOSQ interrupt on the new CPU. However, this triggering on the ICOSQ is done unprotected.  There are 2 such races:  A) mlx5e_trigger_irq() is called while mlx5e_xsk_alloc_rx_mpwqe() is running from a different CPU due to affinity change. This can happen because IRQ triggering is done after napi_complete_done(). At this point the NAPI can be scheduled on a different CPU. Like this:    CPU A (old affinity, NAPI tail)    CPU B (new affinity, fresh NAPI)   -------------------------------    --------------------------------   napi_complete_done()  clears SCHED   mlx5e_cq_arm(...)                                      napi_schedule_prep() sets SCHED                                      mlx5e_napi_poll()                                        mlx5e_xsk_alloc_rx_mpwqe()                                          mlx5e_icosq_sync_lock() // noop                                          memcpy 640 B UMR body                                          advance sq->pc by 10   mlx5e_trigger_irq(&c->icosq)     wqe_info[pi] = {NOP, 1}     mlx5e_post_nop() advances sq->pc  B) mlx5e_trigger_irq() is called on the ICOSQ when mlx5e_trigger_napi_icosq() is running.  The obvious fix would be to lock the ICOSQ. But ICOSQ has an optimized locking scheme that doesn't work for this scenario. Kick the async ICOSQ instead which is always locked.  This issue was noticed in the wild with the following splat:    netdevice: ge-0-0-1: Bad OP in ICOSQ CQE: 0xd   WARNING: drivers/net/ethernet/mellanox/mlx5/core/en_rx.c:826 [...]   [...]   Call Trace:    <IRQ>    mlx5e_napi_poll+0x11d/0x7f0 [mlx5_core]    __napi_poll+0x30/0x200    ? skb_defer_free_flush+0x9c/0xc0    net_rx_action+0x2fe/0x3f0    handle_softirqs+0xd8/0x340    __irq_exit_rcu+0xbc/0xe0    common_interrupt+0x85/0xa0    </IRQ>    <TASK>    asm_common_interrupt+0x26/0x40   [...]   ---[ end trace 0000000000000000 ]---   mlx5_core 0000:08:00.0 ge-0-0-1: Error cqe on cqn 0x548, ci 0x2022, qn 0x8f4,   opcode 0xd, syndrome 0x2, vendor syndrome 0x68   00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   00000030: 00 00 00 00 01 00 68 02 01 00 08 f4 de 14 59 d2   WQE DUMP: WQ size 16384 WQ cur size 0, WQE index 0x1e14, len: 64   00000000: 00 00 00 01 d9 ed 80 02 00 00 00 01 d9 ed 90 02   00000010: 00 00 00 01 d9 ed a0 02 00 00 00 01 d9 ed b0 02   00000020: 00 00 00 01 d9 ed c0 02 00 00 00 01 d9 ed d0 02   00000030: 00 00 00 01 d9 ed e0 02 00 00 00 01 d9 ed f0 02   mlx5_core 0000:08:00.0 ge-0-0-1: Error cqe on cqn 0x548, ci 0x2023, qn 0x8f4,   opcode 0xd, syndrome 0x5, vendor syndrome 0xf9   00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   00000030: 00 00 00 00 01 00 f9 05 01 00 08 f4 de 15 cf d2","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64210","epss":0.00344,"percentile":0.27477,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.258},"relatedVulnerabilities":[{"id":"CVE-2026-64210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64210","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/8d3b91e7d81000d295cd914d4d9d6f860252e2bf","https://git.kernel.org/stable/c/c326f9c68921e2f14dfcecb2f6b4216313d50248"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: xsk: Fix unlocked writing to ICOSQ\n\nDuring napi poll, when the affinity changes and there's still XSK work\nto be done, we trigger an ICOSQ interrupt on the new CPU. However, this\ntriggering on the ICOSQ is done unprotected.\n\nThere are 2 such races:\n\nA) mlx5e_trigger_irq() is called while mlx5e_xsk_alloc_rx_mpwqe() is\nrunning from a different CPU due to affinity change. This can happen\nbecause IRQ triggering is done after napi_complete_done(). At this point\nthe NAPI can be scheduled on a different CPU. Like this:\n\n  CPU A (old affinity, NAPI tail)    CPU B (new affinity, fresh NAPI)\n  -------------------------------    --------------------------------\n  napi_complete_done()  clears SCHED\n  mlx5e_cq_arm(...)\n                                     napi_schedule_prep() sets SCHED\n                                     mlx5e_napi_poll()\n                                       mlx5e_xsk_alloc_rx_mpwqe()\n                                         mlx5e_icosq_sync_lock() // noop\n                                         memcpy 640 B UMR body\n                                         advance sq->pc by 10\n  mlx5e_trigger_irq(&c->icosq)\n    wqe_info[pi] = {NOP, 1}\n    mlx5e_post_nop() advances sq->pc\n\nB) mlx5e_trigger_irq() is called on the ICOSQ when\nmlx5e_trigger_napi_icosq() is running.\n\nThe obvious fix would be to lock the ICOSQ. But ICOSQ has an optimized\nlocking scheme that doesn't work for this scenario. Kick the async ICOSQ\ninstead which is always locked.\n\nThis issue was noticed in the wild with the following splat:\n\n  netdevice: ge-0-0-1: Bad OP in ICOSQ CQE: 0xd\n  WARNING: drivers/net/ethernet/mellanox/mlx5/core/en_rx.c:826 [...]\n  [...]\n  Call Trace:\n   <IRQ>\n   mlx5e_napi_poll+0x11d/0x7f0 [mlx5_core]\n   __napi_poll+0x30/0x200\n   ? skb_defer_free_flush+0x9c/0xc0\n   net_rx_action+0x2fe/0x3f0\n   handle_softirqs+0xd8/0x340\n   __irq_exit_rcu+0xbc/0xe0\n   common_interrupt+0x85/0xa0\n   </IRQ>\n   <TASK>\n   asm_common_interrupt+0x26/0x40\n  [...]\n  ---[ end trace 0000000000000000 ]---\n  mlx5_core 0000:08:00.0 ge-0-0-1: Error cqe on cqn 0x548, ci 0x2022, qn 0x8f4,\n  opcode 0xd, syndrome 0x2, vendor syndrome 0x68\n  00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n  00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n  00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n  00000030: 00 00 00 00 01 00 68 02 01 00 08 f4 de 14 59 d2\n  WQE DUMP: WQ size 16384 WQ cur size 0, WQE index 0x1e14, len: 64\n  00000000: 00 00 00 01 d9 ed 80 02 00 00 00 01 d9 ed 90 02\n  00000010: 00 00 00 01 d9 ed a0 02 00 00 00 01 d9 ed b0 02\n  00000020: 00 00 00 01 d9 ed c0 02 00 00 00 01 d9 ed d0 02\n  00000030: 00 00 00 01 d9 ed e0 02 00 00 00 01 d9 ed f0 02\n  mlx5_core 0000:08:00.0 ge-0-0-1: Error cqe on cqn 0x548, ci 0x2023, qn 0x8f4,\n  opcode 0xd, syndrome 0x5, vendor syndrome 0xf9\n  00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n  00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n  00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n  00000030: 00 00 00 00 01 00 f9 05 01 00 08 f4 de 15 cf d2","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64210","epss":0.00344,"percentile":0.27477,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64210","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64212","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64212","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it  In iwl_mld_remove_link, the link->fw_id is saved at the beginning of the function so we have it after we freed the link.  But the link pointer can be NULL, and is not checked when the fw_id is stored.  Fix it by simply freeing the link at the end of the function.  fFixes: 0e66a39f4f0e (\"wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link()\")","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64212","epss":0.00117,"percentile":0.01892,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64212","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.061425},"relatedVulnerabilities":[{"id":"CVE-2026-64212","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64212","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/3a74aaad047353da3344aed32e9042d4f334f926","https://git.kernel.org/stable/c/b6b4db85c7baf0788c5e7ec61350c1ff2bb775e0","https://git.kernel.org/stable/c/d733ed481fd20a8e7bfe5119c4e77761ba3f87ee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mld: don't dereference a pointer before NULL checking it\n\nIn iwl_mld_remove_link, the link->fw_id is saved at the beginning of the\nfunction so we have it after we freed the link.\n\nBut the link pointer can be NULL, and is not checked when the fw_id is\nstored.\n\nFix it by simply freeing the link at the end of the function.\n\nfFixes: 0e66a39f4f0e (\"wifi: iwlwifi: fix potential use after free in iwl_mld_remove_link()\")","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64212","epss":0.00117,"percentile":0.01892,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64212","cwe":"CWE-476","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64212","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64213","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64213","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (lm90) Add lock protection to lm90_alert  Sashiko reports:  lm90_alert() executes in the smbus alert context and calls lm90_update_confreg() to disable the hardware alert line, without acquiring hwmon_lock.  Concurrently, sysfs write operations (such as lm90_write_convrate) hold the hwmon_lock, temporarily modify data->config, and then restore it.  If an alert interrupt occurs concurrently with a sysfs write, the sysfs path will overwrite the alert handler's modifications to data->config and the hardware register.  This unintentionally re-enables the hardware alert line while the alarm is still active, causing an interrupt storm.  Add the missing lock to lm90_alert() to solve the problem.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64213","epss":0.00121,"percentile":0.02132,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.063525},"relatedVulnerabilities":[{"id":"CVE-2026-64213","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64213","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/873e919e3101063a7a75989510ccfc125a4391cf","https://git.kernel.org/stable/c/b0b66aae8a94c3663d47e4000b0e81b89ce32186","https://git.kernel.org/stable/c/bed1fc32e0eb653806fa98afcf55f9a311fc4ce2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Add lock protection to lm90_alert\n\nSashiko reports:\n\nlm90_alert() executes in the smbus alert context and calls\nlm90_update_confreg() to disable the hardware alert line, without\nacquiring hwmon_lock.\n\nConcurrently, sysfs write operations (such as lm90_write_convrate) hold\nthe hwmon_lock, temporarily modify data->config, and then restore it.\n\nIf an alert interrupt occurs concurrently with a sysfs write, the sysfs\npath will overwrite the alert handler's modifications to data->config\nand the hardware register.\n\nThis unintentionally re-enables the hardware alert line while the alarm is\nstill active, causing an interrupt storm.\n\nAdd the missing lock to lm90_alert() to solve the problem.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64213","epss":0.00121,"percentile":0.02132,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64213","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64241","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64241","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: rockchip: teardown bugs and resource leaks  Address several teardown issues and resource leaks in the driver's remove path and error handling:  1. Debounce clock reference leak: The debounce clock (bank->db_clk) is    obtained using of_clk_get() which increments the clock's reference    count, but clk_put() is never called. Register a devm action to    cleanly release it on unbind. Note that of_clk_get(..., 1) remains    necessary over devm_clk_get() because the DT binding does not define    clock-names, precluding name-based lookup.  2. Unregistered chained IRQ handler: The chained IRQ handler is not    disconnected in remove(). If a stray interrupt fires after the driver    is removed, the kernel attempts to execute a stale handler, leading    to a panic. Fix this by clearing the handler in remove().  3. IRQ domain leak: The linear IRQ domain and its generic chips are    allocated manually during probe but never removed. Remove the IRQ    domain during driver teardown to free the associated generic chips    and mappings.  [Bartosz: don't emit an error message on devres allocation failure]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64241","epss":0.00114,"percentile":0.01633,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64241","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.059849999999999993},"relatedVulnerabilities":[{"id":"CVE-2026-64241","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64241","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/6be81e77e1748665d7ddab9128ff1d35eb75b87d","https://git.kernel.org/stable/c/7f945f7f10f442270518dfd768d230227c495fcf","https://git.kernel.org/stable/c/9500077678230e36d22bf16d2b9539c13e59a801","https://git.kernel.org/stable/c/cdc603ce3118232712ba443dd8b414d8f25ca467"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: rockchip: teardown bugs and resource leaks\n\nAddress several teardown issues and resource leaks in the driver's remove\npath and error handling:\n\n1. Debounce clock reference leak: The debounce clock (bank->db_clk) is\n   obtained using of_clk_get() which increments the clock's reference\n   count, but clk_put() is never called. Register a devm action to\n   cleanly release it on unbind. Note that of_clk_get(..., 1) remains\n   necessary over devm_clk_get() because the DT binding does not define\n   clock-names, precluding name-based lookup.\n\n2. Unregistered chained IRQ handler: The chained IRQ handler is not\n   disconnected in remove(). If a stray interrupt fires after the driver\n   is removed, the kernel attempts to execute a stale handler, leading\n   to a panic. Fix this by clearing the handler in remove().\n\n3. IRQ domain leak: The linear IRQ domain and its generic chips are\n   allocated manually during probe but never removed. Remove the IRQ\n   domain during driver teardown to free the associated generic chips\n   and mappings.\n\n[Bartosz: don't emit an error message on devres allocation failure]","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64241","epss":0.00114,"percentile":0.01633,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64241","cwe":"CWE-401","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64241","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64270","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64270","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: mms114 - reject an oversized device packet size  mms114_interrupt() reads a packet of touch data from the device into a fixed-size on-stack buffer  \tstruct mms114_touch touch[MMS114_MAX_TOUCH];  which holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes, i.e. 80 bytes. The length of the I2C read into it is taken verbatim from the device:  \tpacket_size = mms114_read_reg(data, MMS114_PACKET_SIZE); \tif (packet_size <= 0) \t\tgoto out; \t... \terror = __mms114_read_reg(data, MMS114_INFORMATION, packet_size, \t\t\t(u8 *)touch);  packet_size is a single device register byte (0x0F) and the only check is the lower bound packet_size <= 0; it is never bounded against the size of touch[]. A malfunctioning, malicious or counterfeit controller (or an attacker tampering with the I2C bus) can report a packet_size of up to 255, so __mms114_read_reg() writes up to 175 bytes past the end of touch[] on the IRQ-thread stack: a stack out-of-bounds write that can overwrite the stack canary, saved registers and the return address.  A well-formed device never reports more than the buffer holds, so reject an oversized packet and drop the report, consistent with the handler's other error paths, rather than reading past the buffer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64270","epss":0.00169,"percentile":0.06453,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64270","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.129285},"relatedVulnerabilities":[{"id":"CVE-2026-64270","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64270","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/040843281eebfa110d08fd7fb083fe6cb55cea14","https://git.kernel.org/stable/c/39b12daf1adb80f9595fdfe584961deb80860cbb","https://git.kernel.org/stable/c/5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6","https://git.kernel.org/stable/c/66725039f7090afe14c31bd259e2059a68f04023","https://git.kernel.org/stable/c/8301c335305344d4da4ab9442b6a399dacfe5b8d","https://git.kernel.org/stable/c/b78150729762d47c14fe29a2582bdca5568e62b8","https://git.kernel.org/stable/c/d99ba93c35ff2d5276e9c2632967481bd53a79d0","https://git.kernel.org/stable/c/f3d5e77b27fded71dcb97f409262bf0abba0410e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - reject an oversized device packet size\n\nmms114_interrupt() reads a packet of touch data from the device into a\nfixed-size on-stack buffer\n\n\tstruct mms114_touch touch[MMS114_MAX_TOUCH];\n\nwhich holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes,\ni.e. 80 bytes. The length of the I2C read into it is taken verbatim from\nthe device:\n\n\tpacket_size = mms114_read_reg(data, MMS114_PACKET_SIZE);\n\tif (packet_size <= 0)\n\t\tgoto out;\n\t...\n\terror = __mms114_read_reg(data, MMS114_INFORMATION, packet_size,\n\t\t\t(u8 *)touch);\n\npacket_size is a single device register byte (0x0F) and the only check\nis the lower bound packet_size <= 0; it is never bounded against the\nsize of touch[]. A malfunctioning, malicious or counterfeit controller\n(or an attacker tampering with the I2C bus) can report a packet_size of\nup to 255, so __mms114_read_reg() writes up to 175 bytes past the end of\ntouch[] on the IRQ-thread stack: a stack out-of-bounds write that can\noverwrite the stack canary, saved registers and the return address.\n\nA well-formed device never reports more than the buffer holds, so reject\nan oversized packet and drop the report, consistent with the handler's\nother error paths, rather than reading past the buffer.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64270","epss":0.00169,"percentile":0.06453,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64270","cwe":"CWE-787","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64270","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64272","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64272","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: mms114 - fix touch indexing for MMS134S and MMS136  The MMS134S and MMS136 touch controllers have an event size of 6 bytes rather than 8 bytes. When __mms114_read_reg() reads the touch data packet from the device into the touch buffer, the events are packed tightly at 6-byte intervals. However, the driver iterates through the events using standard C array indexing (touch[index]), where each element is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any touch events beyond the first one are read from incorrect offsets and parsed improperly.  Fix this by explicitly calculating the byte offset for each touch event based on the device's specific event size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64272","epss":0.00169,"percentile":0.06448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64272","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.129285},"relatedVulnerabilities":[{"id":"CVE-2026-64272","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64272","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/062bbe55a1f6d77b89d07135ba3b09f97bfac1cb","https://git.kernel.org/stable/c/112666835071d935fef764aab590339e97216d4a","https://git.kernel.org/stable/c/38de2979d90d8cd94f18e0567be4c8342d0e0410","https://git.kernel.org/stable/c/75b12874b4172533b9efc349db328cb1a59c3981","https://git.kernel.org/stable/c/7c00a0787af7164438bdbc97fcae9733cfc58d21","https://git.kernel.org/stable/c/a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d","https://git.kernel.org/stable/c/a747c4eb02656afdbd92eea83b88e92715a23977"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - fix touch indexing for MMS134S and MMS136\n\nThe MMS134S and MMS136 touch controllers have an event size of 6 bytes\nrather than 8 bytes. When __mms114_read_reg() reads the touch data\npacket from the device into the touch buffer, the events are packed\ntightly at 6-byte intervals. However, the driver iterates through the\nevents using standard C array indexing (touch[index]), where each\nelement is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any\ntouch events beyond the first one are read from incorrect offsets and\nparsed improperly.\n\nFix this by explicitly calculating the byte offset for each touch event\nbased on the device's specific event size.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64272","epss":0.00169,"percentile":0.06448,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64272","cwe":"CWE-129","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64272","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64280","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64280","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()  afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int nr_pages, causing implicit truncation if length is very large.  Validate map.length at the ioctl entry point before calling afu_dma_map_region(), rejecting values whose page count exceeds INT_MAX.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64280","epss":0.00169,"percentile":0.06451,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13773500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-64280","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64280","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/16381bda90b261a656ded0568630c1b857b2ebc8","https://git.kernel.org/stable/c/5352d488ce4ae5e8c68c080ad4c3a5f084ad5fbc","https://git.kernel.org/stable/c/59070040fd12e0b78d7b4d341d9f9a183237c5ff","https://git.kernel.org/stable/c/a6a3884ff500f04f3088d6d09eec803cd35331a2","https://git.kernel.org/stable/c/b50e6cd2395cde615f59b624819998d28c0668d6","https://git.kernel.org/stable/c/d7e787eee2ea619b6dbb98890472ee73daf2e7fd","https://git.kernel.org/stable/c/fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231","https://git.kernel.org/stable/c/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()\n\nafu_ioctl_dma_map() accepts a 64-bit length from userspace via\nDFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value\nis passed to afu_dma_pin_pages() where npages is derived as\nlength >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes\nint nr_pages, causing implicit truncation if length is very large.\n\nValidate map.length at the ioctl entry point before calling\nafu_dma_map_region(), rejecting values whose page count exceeds\nINT_MAX.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64280","epss":0.00169,"percentile":0.06451,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64280","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64294","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64294","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm: do file ownership checks with the proper mount idmap  Ever since idmapped mounts were introduced, inode ownership checks (for side-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done against the nop_mnt_idmap, which completely ignores the file's mount's idmap.  This results in odd edgecases like:  1) mount/bind-mount with an idmap userA:userB:1 2) userB runs an owner_or_capable() check on file that is owned by userA on-disk/in-memory, but owned by userB after idmap translation 3) owner_or_capable() mysteriously fails as the correct idmap wasn't supplied  In the case of mincore/madvise MADV_PAGEOUT, this is usually benign, because file_permission(file, MAY_WRITE) will probably succeed, as it uses the proper idmap internally, but it does not need to be the case on e.g a 0444 file where even the owner itself doesn't have permissions to write to it.  Since this is clearly not trivial to get right, introduce a file_owner_or_capable() that can carry the correct semantics, and switch the various users in mm to it.  The issue was found by manual code inspection & an off-list discussion with Jan Kara.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64294","epss":0.0016,"percentile":0.05501,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-64294","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64294","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/04ba248d02d9eaa3d9077b00a6134caa75fa3e90","https://git.kernel.org/stable/c/5c942ad7df75925ee166e7f0fb36892d8dde376b","https://git.kernel.org/stable/c/7368bec565bac3e536cd43579dbde1e715e6ba61","https://git.kernel.org/stable/c/744b23aa430d52f5c8e4dbff7d71496d6643bed2","https://git.kernel.org/stable/c/8344bdf0629457e532797b42d9d2bbf2a2900bbf","https://git.kernel.org/stable/c/b2f3d94ea310bea9d36d53e9d9b3f45e86c1d893","https://git.kernel.org/stable/c/e187bc02f8fa4226d62814592cf064ee4557c470"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: do file ownership checks with the proper mount idmap\n\nEver since idmapped mounts were introduced, inode ownership checks (for\nside-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done\nagainst the nop_mnt_idmap, which completely ignores the file's mount's\nidmap.  This results in odd edgecases like:\n\n1) mount/bind-mount with an idmap userA:userB:1\n2) userB runs an owner_or_capable() check on file that is owned by userA\non-disk/in-memory, but owned by userB after idmap translation\n3) owner_or_capable() mysteriously fails as the correct idmap wasn't supplied\n\nIn the case of mincore/madvise MADV_PAGEOUT, this is usually benign,\nbecause file_permission(file, MAY_WRITE) will probably succeed, as it uses\nthe proper idmap internally, but it does not need to be the case on e.g a\n0444 file where even the owner itself doesn't have permissions to write to\nit.\n\nSince this is clearly not trivial to get right, introduce a\nfile_owner_or_capable() that can carry the correct semantics, and switch\nthe various users in mm to it.\n\nThe issue was found by manual code inspection & an off-list discussion\nwith Jan Kara.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64294","epss":0.0016,"percentile":0.05501,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64294","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64305","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64305","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: qat - protect service table iterations with service_lock  The service_table list is protected by service_lock when entries are added or removed (in adf_service_add() and adf_service_remove()), but several functions iterate over the list without holding this lock.  A concurrent adf_service_register() or adf_service_unregister() call could modify the list during traversal, leading to list corruption or a use-after-free.  Fix this by holding service_lock across all list_for_each_entry() iterations of service_table in adf_dev_init(), adf_dev_start(), adf_dev_stop(), adf_dev_shutdown(), adf_dev_restarting_notify(), adf_dev_restarted_notify(), and adf_error_notifier().  The lock ordering is safe: callers of the static helpers (adf_dev_up() and adf_dev_down()) acquire state_lock before service_lock, and no event_hld callback or service_lock holder ever acquires state_lock in the reverse order.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64305","epss":0.00125,"percentile":0.02517,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64305","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-64305","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64305","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0dbcecea740d943002c1cbdafa39bdfc108e32a5","https://git.kernel.org/stable/c/222fa7b453b612f4407f260146d89a2ce2bc831d","https://git.kernel.org/stable/c/5c6f845e77ec35f9b7b047cc8f9789bf397cdd3e","https://git.kernel.org/stable/c/c3c5925791cff3b84d313293fd60f384d877d793"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - protect service table iterations with service_lock\n\nThe service_table list is protected by service_lock when entries are\nadded or removed (in adf_service_add() and adf_service_remove()), but\nseveral functions iterate over the list without holding this lock.\n\nA concurrent adf_service_register() or adf_service_unregister() call\ncould modify the list during traversal, leading to list corruption or\na use-after-free.\n\nFix this by holding service_lock across all list_for_each_entry()\niterations of service_table in adf_dev_init(), adf_dev_start(),\nadf_dev_stop(), adf_dev_shutdown(), adf_dev_restarting_notify(),\nadf_dev_restarted_notify(), and adf_error_notifier().\n\nThe lock ordering is safe: callers of the static helpers (adf_dev_up()\nand adf_dev_down()) acquire state_lock before service_lock, and no\nevent_hld callback or service_lock holder ever acquires state_lock in\nthe reverse order.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64305","epss":0.00125,"percentile":0.02517,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64305","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64305","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64319","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64319","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet-auth: validate reply message payload bounds against transfer length  nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes.  A malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a small transfer length but large hl/dhvlen values, causing out-of-bounds heap reads when the target processes the DH public key (rval + 2*hl) or performs the host response memcmp.  With DH authentication configured, the OOB pointer is passed directly to sg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching up to 526 bytes past the buffer. This is exploitable pre-authentication.  Add bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before any access to the variable-length fields.  Discovered by Atuin - Automated Vulnerability Discovery Engine.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64319","epss":0.00524,"percentile":0.42752,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64319","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.47422000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-64319","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64319","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9","https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26","https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0","https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d","https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: validate reply message payload bounds against transfer length\n\nnvmet_auth_reply() accesses the variable-length rval[] array using\nattacker-controlled hl (hash length) and dhvlen (DH value length) fields\nwithout verifying they fit within the allocated buffer of tl bytes.\n\nA malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a\nsmall transfer length but large hl/dhvlen values, causing out-of-bounds\nheap reads when the target processes the DH public key (rval + 2*hl) or\nperforms the host response memcmp.\n\nWith DH authentication configured, the OOB pointer is passed directly to\nsg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching\nup to 526 bytes past the buffer. This is exploitable pre-authentication.\n\nAdd bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before\nany access to the variable-length fields.\n\nDiscovered by Atuin - Automated Vulnerability Discovery Engine.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64319","epss":0.00524,"percentile":0.42752,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64319","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64319","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64320","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64320","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page  nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo).  The 64-bit offset is then added to a small kzalloc'd buffer that holds the discovery log page and the result is passed straight to nvmet_copy_to_sgl(), which memcpy()s data_len bytes out to the host with no source-side bound check:      u64 offset      = nvmet_get_log_page_offset(req->cmd);  /* 64-bit host */     size_t data_len = nvmet_get_log_page_len(req->cmd);     /* 32-bit host */     ...     if (offset & 0x3) { ... }                               /* only check */     ...     alloc_len = sizeof(*hdr) + entry_size * discovery_log_entries(req);     buffer = kzalloc(alloc_len, GFP_KERNEL);     ...     status = nvmet_copy_to_sgl(req, 0, buffer + offset, data_len);  The Discovery controller is unauthenticated -- nvmet_host_allowed() returns true unconditionally for the discovery subsystem -- so the call is reachable pre-authentication by any TCP/RDMA/FC peer that can reach the nvmet target.  With a discovery log page of ~1 KiB, an attacker requesting up to 4 KiB starting at offset == alloc_len reads the next slab page out and gets its content returned over the fabric (an empirical run on a default nvmet-tcp loopback target leaked 81 canonical kernel pointers in one Get Log Page response).  Pointing the offset at unmapped kernel memory faults the in-kernel memcpy and crashes (or panics, on panic_on_oops=1) the target host instead.  The attacker-controlled source-side offset pattern \"nvmet_copy_to_sgl(req, 0, buffer + ATTACKER_OFFSET, ...)\" is unique to nvmet_execute_disc_get_log_page in the entire nvmet codebase: every other Get Log Page handler in admin-cmd.c either ignores lpo (and silently starts every response at offset 0) or tracks a local destination offset with a fixed source pointer.  Validate the host-supplied offset against the log page size, cap the copy length to what is actually available, and zero-fill any remainder of the host transfer buffer.  The zero-fill matches the existing short-response pattern in nvmet_execute_get_log_changed_ns() (admin-cmd.c) and prevents leaking transport SGL contents when the host asks for more bytes than the log page contains.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64320","epss":0.00748,"percentile":0.52724,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64320","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.67694},"relatedVulnerabilities":[{"id":"CVE-2026-64320","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64320","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/33b974eb626154ae9348f2bac7de84cb2a3d9dd4","https://git.kernel.org/stable/c/53cd102a7a56079b11b897835bd9b94c14e6322c","https://git.kernel.org/stable/c/56c021a0869260d04c4b65d1471936aaf9177114","https://git.kernel.org/stable/c/a29b316b9bbfd269f323ab4ba9906a894025680f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page\n\nnvmet_execute_disc_get_log_page() validates only the dword alignment\nof the host-supplied Log Page Offset (lpo).  The 64-bit offset is then\nadded to a small kzalloc'd buffer that holds the discovery log page\nand the result is passed straight to nvmet_copy_to_sgl(), which\nmemcpy()s data_len bytes out to the host with no source-side bound\ncheck:\n\n    u64 offset      = nvmet_get_log_page_offset(req->cmd);  /* 64-bit host */\n    size_t data_len = nvmet_get_log_page_len(req->cmd);     /* 32-bit host */\n    ...\n    if (offset & 0x3) { ... }                               /* only check */\n    ...\n    alloc_len = sizeof(*hdr) + entry_size * discovery_log_entries(req);\n    buffer = kzalloc(alloc_len, GFP_KERNEL);\n    ...\n    status = nvmet_copy_to_sgl(req, 0, buffer + offset, data_len);\n\nThe Discovery controller is unauthenticated -- nvmet_host_allowed()\nreturns true unconditionally for the discovery subsystem -- so the call\nis reachable pre-authentication by any TCP/RDMA/FC peer that can reach\nthe nvmet target.  With a discovery log page of ~1 KiB, an attacker\nrequesting up to 4 KiB starting at offset == alloc_len reads the next\nslab page out and gets its content returned over the fabric (an\nempirical run on a default nvmet-tcp loopback target leaked 81\ncanonical kernel pointers in one Get Log Page response).  Pointing the\noffset at unmapped kernel memory faults the in-kernel memcpy and\ncrashes (or panics, on panic_on_oops=1) the target host instead.\n\nThe attacker-controlled source-side offset pattern\n\"nvmet_copy_to_sgl(req, 0, buffer + ATTACKER_OFFSET, ...)\" is unique\nto nvmet_execute_disc_get_log_page in the entire nvmet codebase: every\nother Get Log Page handler in admin-cmd.c either ignores lpo (and\nsilently starts every response at offset 0) or tracks a local\ndestination offset with a fixed source pointer.\n\nValidate the host-supplied offset against the log page size, cap the\ncopy length to what is actually available, and zero-fill any remainder\nof the host transfer buffer.  The zero-fill matches the existing\nshort-response pattern in nvmet_execute_get_log_changed_ns()\n(admin-cmd.c) and prevents leaking transport SGL contents when the\nhost asks for more bytes than the log page contains.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64320","epss":0.00748,"percentile":0.52724,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64320","cwe":"CWE-125","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64320","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64341","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64341","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  USB: iowarrior: fix use-after-free on disconnect race  mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of objects directly (unlike spinlocks and refcounts). [1][2]  Use a kref to release the driver data to avoid use-after-free in mutex_unlock() when release() races with disconnect().  [1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is non-atomic\") [2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most                    other sleeping locks, can still use the lock object                    after it's unlocked\")","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64341","epss":0.00124,"percentile":0.02414,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64341","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09486},"relatedVulnerabilities":[{"id":"CVE-2026-64341","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64341","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3c0a7b29ebb391d5f50b115e86f842b709195b08","https://git.kernel.org/stable/c/71590982700fdeb39a37a500c877228b0140978e","https://git.kernel.org/stable/c/c602254ba4c10f60a73cd99d147874f86a3f485c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: iowarrior: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64341","epss":0.00124,"percentile":0.02414,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64341","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64341","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64345","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64345","namespace":"debian:distro:debian:12","severity":"Medium","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_printer: take kref only for successful open  printer_open() returns -EBUSY when the character device is already open, but it increments dev->kref regardless of the return value. VFS does not call ->release() for a failed open, so every rejected second open permanently leaks one reference.  Move kref_get() into the successful-open branch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64345","epss":0.00123,"percentile":0.02323,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.06457500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-64345","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64345","namespace":"nvd:cpe","severity":"Medium","urls":["https://git.kernel.org/stable/c/30adce93d5c4a5a1ec29d9249e3fdfcc391d406b","https://git.kernel.org/stable/c/75c0ad13e136961328253742501b4efc3988a587","https://git.kernel.org/stable/c/7f1f24c367938c5537e2308bf9a965f051d14774","https://git.kernel.org/stable/c/8a5eba992c862b0c94411eecf9b7121e8636db38","https://git.kernel.org/stable/c/94ec20d97aa51547965a539f660a1fe79c6929a3","https://git.kernel.org/stable/c/bf20c94fa6aaff945f0ae3a23f3212cd299f28d9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_printer: take kref only for successful open\n\nprinter_open() returns -EBUSY when the character device is already\nopen, but it increments dev->kref regardless of the return value. VFS\ndoes not call ->release() for a failed open, so every rejected second\nopen permanently leaks one reference.\n\nMove kref_get() into the successful-open branch.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"exploitabilityScore":1.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64345","epss":0.00123,"percentile":0.02323,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64345","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64348","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64348","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: free iso schedules on failed submit  EHCI and FOTG210 isochronous submits build an ehci_iso_sched before linking the URB to the endpoint queue, and keep the staged schedule in urb->hcpriv until iso_stream_schedule() and the link helpers consume it. If the controller is no longer accessible, or usb_hcd_link_urb_to_ep() fails, submit jumps to done_not_linked before that handoff happens and leaks the staged schedule still attached to urb->hcpriv.  Free the staged schedule from done_not_linked when submit fails before the URB is linked and clear urb->hcpriv after the free.  The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.  An x86_64 allyesconfig build showed no new warnings. As we do not have an EHCI host controller with a USB isochronous device to test with, no runtime testing was able to be performed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64348","epss":0.00129,"percentile":0.0291,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64348","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-64348","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64348","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4bb88aee6b868cbf73bf453f62497802f5fe4769","https://git.kernel.org/stable/c/6bc17a78a05671d303820224fb37ca339c1dc2cb","https://git.kernel.org/stable/c/8890699eea19027ef6e4f9cbcf27cba5e789793f","https://git.kernel.org/stable/c/b0d00d077f9738d215af9b50c74dffab7a1de19f","https://git.kernel.org/stable/c/b9399d25fbb34a05bbe76eeedd730f62ff2670e9","https://git.kernel.org/stable/c/be5004395dfd0b6ec310db359f887fa396fd0dd2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: free iso schedules on failed submit\n\nEHCI and FOTG210 isochronous submits build an ehci_iso_sched before\nlinking the URB to the endpoint queue, and keep the staged schedule in\nurb->hcpriv until iso_stream_schedule() and the link helpers consume it.\nIf the controller is no longer accessible, or usb_hcd_link_urb_to_ep()\nfails, submit jumps to done_not_linked before that handoff happens and\nleaks the staged schedule still attached to urb->hcpriv.\n\nFree the staged schedule from done_not_linked when submit fails before\nthe URB is linked and clear urb->hcpriv after the free.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nEHCI host controller with a USB isochronous device to test with, no\nruntime testing was able to be performed.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64348","epss":0.00129,"percentile":0.0291,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64348","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64348","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64388","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64388","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb/client: fix chown/chgrp with SMB3 POSIX Extensions  Ownership (chown) and group (chgrp) modifications were being ignored when mounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or CIFS_MOUNT_MODE_FROM_SID were also explicitly set.  Fix this by checking for posix_extensions in cifs_setattr_nounix() when updating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map and set the ownership/group information on the server.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64388","epss":0.0012,"percentile":0.02111,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-64388","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64388","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/550cfb8a81181331d4d0f76ab75ee58a0bf41e3e","https://git.kernel.org/stable/c/760ef2c579c2609cf17fb1cd5392f64d42d43d33"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: fix chown/chgrp with SMB3 POSIX Extensions\n\nOwnership (chown) and group (chgrp) modifications were being ignored when\nmounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or\nCIFS_MOUNT_MODE_FROM_SID were also explicitly set.\n\nFix this by checking for posix_extensions in cifs_setattr_nounix() when\nupdating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map\nand set the ownership/group information on the server.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64388","epss":0.0012,"percentile":0.02111,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64388","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64389","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64389","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate NTLMv2 response before updating session key  ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmssp_auth_blob() then continues into KEY_XCH even when ksmbd_auth_ntlmv2() failed.  With SMB3 multichannel binding, the failed authentication operates on an existing session and the session setup error path does not expire binding sessions. A client can send a binding session setup with a bad NT proof and KEY_XCH and still modify sess->sess_key before STATUS_LOGON_FAILURE is returned.  Relevant path:    smb2_sess_setup()     -> conn->binding = true     -> ntlm_authenticate()        -> session_user()        -> ksmbd_decode_ntlmssp_auth_blob()           -> ksmbd_auth_ntlmv2()              -> calc_ntlmv2_hash()              -> hmac_md5_usingrawkey(..., sess->sess_key)              -> crypto_memneq() returns mismatch           -> KEY_XCH arc4_crypt(..., sess->sess_key, ...)     -> out_err without expiring the binding session  Derive the base session key into a local buffer and copy it to sess->sess_key only after the proof matches. Return immediately on authentication failure so KEY_XCH is only processed after successful authentication.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64389","epss":0.00453,"percentile":0.38092,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.355605},"relatedVulnerabilities":[{"id":"CVE-2026-64389","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64389","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/89ca7756d5566ba636bb9092cdbe57dab095e136","https://git.kernel.org/stable/c/954d196bebb2b50151cb96454c72dc113b2af1ac","https://git.kernel.org/stable/c/b56400364aed5c34d6e1a0b493081290a5328a9c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate NTLMv2 response before updating session key\n\nksmbd_auth_ntlmv2() derives the NTLMv2 session key into\nsess->sess_key before it verifies the NTLMv2 response.\nksmbd_decode_ntlmssp_auth_blob() then continues into KEY_XCH even\nwhen ksmbd_auth_ntlmv2() failed.\n\nWith SMB3 multichannel binding, the failed authentication operates on\nan existing session and the session setup error path does not expire\nbinding sessions. A client can send a binding session setup with a\nbad NT proof and KEY_XCH and still modify sess->sess_key before\nSTATUS_LOGON_FAILURE is returned.\n\nRelevant path:\n\n  smb2_sess_setup()\n    -> conn->binding = true\n    -> ntlm_authenticate()\n       -> session_user()\n       -> ksmbd_decode_ntlmssp_auth_blob()\n          -> ksmbd_auth_ntlmv2()\n             -> calc_ntlmv2_hash()\n             -> hmac_md5_usingrawkey(..., sess->sess_key)\n             -> crypto_memneq() returns mismatch\n          -> KEY_XCH arc4_crypt(..., sess->sess_key, ...)\n    -> out_err without expiring the binding session\n\nDerive the base session key into a local buffer and copy it to\nsess->sess_key only after the proof matches. Return immediately on\nauthentication failure so KEY_XCH is only processed after successful\nauthentication.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64389","epss":0.00453,"percentile":0.38092,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64389","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64391","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64391","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: use opener credentials for ADS I/O  Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials.  Run ADS I/O with the credentials captured when the SMB handle was opened.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64391","epss":0.00457,"percentile":0.38359,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.4295800000000001},"relatedVulnerabilities":[{"id":"CVE-2026-64391","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64391","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/2b4592cea214683de0f2ce6f8c22c097fb0ea1ab","https://git.kernel.org/stable/c/52a56cf53ec834c44ac1b4d16d585f26613ee5ce","https://git.kernel.org/stable/c/a8f5d39971bbad9340d49cd41b0e2da9452a649d","https://git.kernel.org/stable/c/baa5e094886fffa7e6272edcb5e08be5ce28262c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use opener credentials for ADS I/O\n\nAlternate data streams are stored as xattrs. Unlike regular file I/O,\ntheir read and write paths therefore call VFS xattr helpers which recheck\ninode permissions and LSM policy using the current task credentials.\n\nRun ADS I/O with the credentials captured when the SMB handle was opened.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64391","epss":0.00457,"percentile":0.38359,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64391","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64392","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: use opener credentials for delete-on-close  Delete-on-close can be completed by deferred or durable handle teardown, where no request work is available. Both the base-file unlink and the ADS xattr removal consequently run with the ksmbd worker credentials and can bypass filesystem permission checks.  Run both operations with the credentials captured in struct file when the handle was opened. This preserves the authenticated user's fsuid, fsgid, supplementary groups and capability restrictions at final close.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64392","epss":0.00469,"percentile":0.39112,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.424445},"relatedVulnerabilities":[{"id":"CVE-2026-64392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64392","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/18c59109bb6fb816d5102171666f87cf1e29901d","https://git.kernel.org/stable/c/4b7059974549d278e30fe70e2a4e421f9839817d","https://git.kernel.org/stable/c/52e2f21911158ec961cd5aae19c56460db382af0","https://git.kernel.org/stable/c/e72c15085b6d86f45d224d98aa75b5cace4aaab9","https://git.kernel.org/stable/c/f08b3f451f12eee4abd8a5981803bc36db84458b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use opener credentials for delete-on-close\n\nDelete-on-close can be completed by deferred or durable handle teardown,\nwhere no request work is available. Both the base-file unlink and the ADS\nxattr removal consequently run with the ksmbd worker credentials and can\nbypass filesystem permission checks.\n\nRun both operations with the credentials captured in struct file when the\nhandle was opened. This preserves the authenticated user's fsuid, fsgid,\nsupplementary groups and capability restrictions at final close.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64392","epss":0.00469,"percentile":0.39112,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64392","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64400","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64400","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: prevent path traversal bypass by restricting caseless retry  ksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path resolution within the share root. When a crafted path attempts to escape the share boundary using parent-directory components ('..'), vfs_path_parent_lookup() detects this and immediately fails, returning -EXDEV.  However, a bug exists in __ksmbd_vfs_kern_path() under caseless mode. The function fails to intercept the -EXDEV error and erroneously falls through to the caseless retry logic, which is intended only for genuinely missing files. During this retry process, the path is reconstructed, leading to an unintended LOOKUP_BENEATH bypass that allows write-capable users to create zero-length files or directories outside the exported share.  Fix this by ensuring that the execution only proceeds to the caseless lookup retry when the error is specifically -ENOENT. Any other errors, such as -EXDEV from a path traversal attempt, must be returned immediately.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64400","epss":0.00357,"percentile":0.28915,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.287385},"relatedVulnerabilities":[{"id":"CVE-2026-64400","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64400","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/54bab9ba5a9f156ffa9324fcbe5a356fd0242f95","https://git.kernel.org/stable/c/8c9a4f1327eb71efbf14842e7b8a6d965077eb67"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent path traversal bypass by restricting caseless retry\n\nksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path\nresolution within the share root. When a crafted path attempts to\nescape the share boundary using parent-directory components ('..'),\nvfs_path_parent_lookup() detects this and immediately fails,\nreturning -EXDEV.\n\nHowever, a bug exists in __ksmbd_vfs_kern_path() under caseless mode.\nThe function fails to intercept the -EXDEV error and erroneously\nfalls through to the caseless retry logic, which is intended only\nfor genuinely missing files. During this retry process, the path\nis reconstructed, leading to an unintended LOOKUP_BENEATH bypass\nthat allows write-capable users to create zero-length files or\ndirectories outside the exported share.\n\nFix this by ensuring that the execution only proceeds to the caseless\nlookup retry when the error is specifically -ENOENT. Any other errors,\nsuch as -EXDEV from a path traversal attempt, must be returned immediately.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64400","epss":0.00357,"percentile":0.28915,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64400","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64424","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64424","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netpoll: fix a use-after-free on shutdown path  There is a use-after-free error on netpoll, which is clearly detected by KASAN.        BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0x3b/0x80       Read of size 1 at addr ... by task kworker/9:1       Workqueue: events queue_process       Call Trace:        skb_dequeue+0x1e/0xb0        queue_process+0x2c/0x600        process_scheduled_works+0x4b6/0x850        worker_thread+0x414/0x5a0       Allocated by task 242:        __netpoll_setup+0x201/0x4a0        netpoll_setup+0x249/0x550        enabled_store+0x32f/0x380       Freed by task 0:        kfree+0x1b7/0x540        rcu_core+0x3f8/0x7a0  The problem happens when there is a pending TX worker running in parallel with the cleanup path.  This is what happens on netpoll shutdown path:  1) __netpoll_cleanup() is called 2) set dev->npinfo to NULL 3) call_rcu() with rcu_cleanup_netpoll_info()   3.1) rcu_cleanup_netpoll_info() tries to cancel all workers with        cancel_delayed_work(), but doesn't wait for the worker to finish 4) and kfree(npinfo);  Because 3.1) doesn't really cancel the work, as the comment says \"we can't call cancel_delayed_work_sync here, as we are in softirq\", the TX worker can run after 4).  Tl;DR: queue_process() is not an RCU reader, it reaches npinfo through the work item via container_of().  Use disable_delayed_work_sync() to ensure the worker is completely stopped and prevent any future re-arming attempts. Once npinfo is set to NULL, senders will bail out and not queue new work. The disable flag ensures any in-flight re-arming attempts also fail silently.  In the future, we can do the cleanup inline here without needing the npinfo->rcu rcu_head, but that is net-next material.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64424","epss":0.00125,"percentile":0.02515,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64424","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-64424","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64424","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/45f1458a85017a023f138b22ac5c76abd477db42","https://git.kernel.org/stable/c/5ed09a108d93a3b002cc79823d9455b50c4a8be7","https://git.kernel.org/stable/c/95ecc5b58042f6b6743b589e6588f1cd7ba336aa","https://git.kernel.org/stable/c/a33f37f8d079da7236ed7b7e2aed2a34ab81e7cf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetpoll: fix a use-after-free on shutdown path\n\nThere is a use-after-free error on netpoll, which is clearly detected by\nKASAN.\n\n      BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0x3b/0x80\n      Read of size 1 at addr ... by task kworker/9:1\n      Workqueue: events queue_process\n      Call Trace:\n       skb_dequeue+0x1e/0xb0\n       queue_process+0x2c/0x600\n       process_scheduled_works+0x4b6/0x850\n       worker_thread+0x414/0x5a0\n      Allocated by task 242:\n       __netpoll_setup+0x201/0x4a0\n       netpoll_setup+0x249/0x550\n       enabled_store+0x32f/0x380\n      Freed by task 0:\n       kfree+0x1b7/0x540\n       rcu_core+0x3f8/0x7a0\n\nThe problem happens when there is a pending TX worker running in\nparallel with the cleanup path.\n\nThis is what happens on netpoll shutdown path:\n\n1) __netpoll_cleanup() is called\n2) set dev->npinfo to NULL\n3) call_rcu() with rcu_cleanup_netpoll_info()\n  3.1) rcu_cleanup_netpoll_info() tries to cancel all workers with\n       cancel_delayed_work(), but doesn't wait for the worker to finish\n4) and kfree(npinfo);\n\nBecause 3.1) doesn't really cancel the work, as the comment says \"we\ncan't call cancel_delayed_work_sync here, as we are in softirq\", the TX\nworker can run after 4).\n\nTl;DR: queue_process() is not an RCU reader, it reaches npinfo through\nthe work item via container_of().\n\nUse disable_delayed_work_sync() to ensure the worker is completely\nstopped and prevent any future re-arming attempts. Once npinfo is set\nto NULL, senders will bail out and not queue new work. The disable flag\nensures any in-flight re-arming attempts also fail silently.\n\nIn the future, we can do the cleanup inline here without needing the\nnpinfo->rcu rcu_head, but that is net-next material.","cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64424","epss":0.00125,"percentile":0.02515,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64424","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64424","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64434","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64434","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref  l2cap_chan_timeout() runs asynchronously and accesses chan->conn. If the connection is torn down while the timer is running or pending, chan->conn can be freed, leading to a use-after-free when the timer worker attempts to lock conn->lock:  | BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline] | BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline] | BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline] | BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318 | Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83 | | CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full) | Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 | Workqueue: events l2cap_chan_timeout | Call Trace: |  <TASK> |  instrument_atomic_read_write include/linux/instrumented.h:112 [inline] |  atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline] |  __mutex_trylock_fast kernel/locking/mutex.c:161 [inline] |  mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318 |  l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422 |  process_one_work kernel/workqueue.c:3326 [inline] |  process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409 |  worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490 |  kthread+0x346/0x430 kernel/kthread.c:436 |  ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158 |  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 |  </TASK> | | Allocated by task 320: |  l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075 |  l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452 |  hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline] |  hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760 |  hci_event_func net/bluetooth/hci_event.c:7796 [inline] |  hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847 |  hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040 |  process_one_work kernel/workqueue.c:3326 [inline] |  process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409 |  worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490 |  kthread+0x346/0x430 kernel/kthread.c:436 |  ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158 |  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 | | Freed by task 322: |  hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline] |  hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736 |  hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405 |  hci_dev_do_close net/bluetooth/hci_core.c:502 [inline] |  hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679 |  vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690 |  __fput+0x369/0x890 fs/file_table.c:510 |  task_work_run+0x160/0x1d0 kernel/task_work.c:233 |  get_signal+0xf5b/0x1120 kernel/signal.c:2810 |  arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337 |  __exit_to_user_mode_loop kernel/entry/common.c:64 [inline] |  exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98 |  do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100 |  entry_SYSCALL_64_after_hwframe+0x77/0x7f | | The buggy address belongs to the object at ffff8881298d9400 |  which belongs to the cache kmalloc-512 of size 512 | The buggy address is located 336 bytes inside of |  freed 512-byte region [ffff8881298d9400, ffff8881298d9600)  Fix it by having chan->conn hold a reference to l2cap_conn (via l2cap_conn_get) when the channel is added to the connection, and releasing it in the channel destructor. This ensures the l2cap_conn remains alive as long as the channel exists.  A new FLAG_DEL channel flag is introduced to indicate that the ch ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64434","epss":0.00255,"percentile":0.17067,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64434","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.20782500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-64434","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64434","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b0e2bf39cf99e458d991b9df253727e036a7d7d","https://git.kernel.org/stable/c/32d783cafb46ff3ca58e6f9fd62c9c5f35eaf26b","https://git.kernel.org/stable/c/50c38d9f42a529691e4e67ea9cedf4f0bfc8d277","https://git.kernel.org/stable/c/8922c7940bae9ce4b1736dddb6362370793835c2","https://git.kernel.org/stable/c/8f90405a4a6f1f1880dc07996b47bf57c712bd8a","https://git.kernel.org/stable/c/91047a4396a8b1857a6f712a90cf33ec0012b189","https://git.kernel.org/stable/c/b66774b48dd98f07254951f74ea6f513efe7ff8b","https://git.kernel.org/stable/c/d3b739db5dc6f688a60d56da872fabaf65246032"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref\n\nl2cap_chan_timeout() runs asynchronously and accesses chan->conn. If\nthe connection is torn down while the timer is running or pending,\nchan->conn can be freed, leading to a use-after-free when the timer\nworker attempts to lock conn->lock:\n\n| BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n| BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n| BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n| BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n| Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83\n|\n| CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full)\n| Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n| Workqueue: events l2cap_chan_timeout\n| Call Trace:\n|  <TASK>\n|  instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n|  atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n|  __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n|  mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n|  l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422\n|  process_one_work kernel/workqueue.c:3326 [inline]\n|  process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409\n|  worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490\n|  kthread+0x346/0x430 kernel/kthread.c:436\n|  ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158\n|  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n|  </TASK>\n|\n| Allocated by task 320:\n|  l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075\n|  l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452\n|  hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline]\n|  hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760\n|  hci_event_func net/bluetooth/hci_event.c:7796 [inline]\n|  hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847\n|  hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040\n|  process_one_work kernel/workqueue.c:3326 [inline]\n|  process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409\n|  worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490\n|  kthread+0x346/0x430 kernel/kthread.c:436\n|  ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158\n|  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n|\n| Freed by task 322:\n|  hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline]\n|  hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736\n|  hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405\n|  hci_dev_do_close net/bluetooth/hci_core.c:502 [inline]\n|  hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679\n|  vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690\n|  __fput+0x369/0x890 fs/file_table.c:510\n|  task_work_run+0x160/0x1d0 kernel/task_work.c:233\n|  get_signal+0xf5b/0x1120 kernel/signal.c:2810\n|  arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337\n|  __exit_to_user_mode_loop kernel/entry/common.c:64 [inline]\n|  exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98\n|  do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100\n|  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n|\n| The buggy address belongs to the object at ffff8881298d9400\n|  which belongs to the cache kmalloc-512 of size 512\n| The buggy address is located 336 bytes inside of\n|  freed 512-byte region [ffff8881298d9400, ffff8881298d9600)\n\nFix it by having chan->conn hold a reference to l2cap_conn (via\nl2cap_conn_get) when the channel is added to the connection, and\nreleasing it in the channel destructor. This ensures the l2cap_conn\nremains alive as long as the channel exists.\n\nA new FLAG_DEL channel flag is introduced to indicate that the ch\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64434","epss":0.00255,"percentile":0.17067,"date":"2026-09-09"}],"cwes":[{"cve":"CVE-2026-64434","cwe":"CWE-416","source":"nvd@nist.gov","type":"Primary"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64434","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64463","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64463","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: typec: tcpci_rt1711h: unregister TCPCI port with devres  rt1711h_probe() registers the TCPCI port before requesting the interrupt and enabling alert interrupts. If either of those later steps fails, the probe function returns without unregistering the TCPCI port. The explicit unregister currently only happens from the remove callback.  Register a devres action immediately after tcpci_register_port() succeeds, so tcpci_unregister_port() runs on later probe failures and on driver detach. Drop the remove callback to avoid unregistering the same port twice.  This issue was identified during our ongoing static-analysis research while reviewing kernel code.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64463","epss":0.00138,"percentile":0.03513,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-64463","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64463","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/569f18a83eed0b0be4615f0c7bed40fb5c50e2e6","https://git.kernel.org/stable/c/94b1abf1af94aa5a355e9f03675e07bccfc41c4b","https://git.kernel.org/stable/c/ce2e36e8759dfbfe546723810c306f42f484866d","https://git.kernel.org/stable/c/e5406c8fb71cd2f89a46300a746f6e7972e621e8","https://git.kernel.org/stable/c/e8da46d99d3710106e7c44db14566bf9b57386b5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpci_rt1711h: unregister TCPCI port with devres\n\nrt1711h_probe() registers the TCPCI port before requesting the interrupt\nand enabling alert interrupts. If either of those later steps fails, the\nprobe function returns without unregistering the TCPCI port. The explicit\nunregister currently only happens from the remove callback.\n\nRegister a devres action immediately after tcpci_register_port() succeeds,\nso tcpci_unregister_port() runs on later probe failures and on driver\ndetach. Drop the remove callback to avoid unregistering the same port\ntwice.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64463","epss":0.00138,"percentile":0.03513,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64463","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64481","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64481","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: hda/cs35l41: Fix firmware load work teardown  cs35l41_hda creates ALSA controls whose private data points at the cs35l41_hda object. The firmware load control can also queue fw_load_work.  Those controls are not removed on component unbind, and device remove only cancels fw_load_work through cs35l41_remove_dsp(). That helper is skipped when halo_initialized is false. With firmware_autostart disabled, a firmware load can be requested before the DSP has been initialized. If the component or device is removed before the queued work runs, the worker can run after teardown and dereference driver state that is no longer valid.  Track the created controls and remove them on unbind so no new control callback can reach the driver data or queue more work. Then cancel fw_load_work to drain any request that was already queued. Also cancel the work unconditionally during device remove before runtime PM teardown.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64481","epss":0.00138,"percentile":0.03561,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-64481","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64481","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/8947215c0136c9d905e4a46d824824f8b48a2e5b","https://git.kernel.org/stable/c/b65020d5398f499c09498c9786dba6d67ae57664","https://git.kernel.org/stable/c/ce0a903d0591e3e2c790c5b628802b08d1b287cc","https://git.kernel.org/stable/c/d6a40a4d083ef74d00c8f9516cb5ff07ac70720b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/cs35l41: Fix firmware load work teardown\n\ncs35l41_hda creates ALSA controls whose private data points at the\ncs35l41_hda object. The firmware load control can also queue\nfw_load_work.\n\nThose controls are not removed on component unbind, and device remove\nonly cancels fw_load_work through cs35l41_remove_dsp(). That helper is\nskipped when halo_initialized is false. With firmware_autostart\ndisabled, a firmware load can be requested before the DSP has been\ninitialized. If the component or device is removed before the queued\nwork runs, the worker can run after teardown and dereference driver\nstate that is no longer valid.\n\nTrack the created controls and remove them on unbind so no new control\ncallback can reach the driver data or queue more work. Then cancel\nfw_load_work to drain any request that was already queued. Also cancel\nthe work unconditionally during device remove before runtime PM teardown.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64481","epss":0.00138,"percentile":0.03561,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64481","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64507","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64507","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  x86/bugs: Enable IBPB flush on BPF JIT allocation  Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence.  This hardening applies only when BPF-JIT is in use. Guard the enabling under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.","cvss":[],"epss":[{"cve":"CVE-2026-64507","epss":0.00161,"percentile":0.05648,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-64507","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64507","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/25dbcd31781e2bc3cd63d873af1fcd06f863a126","https://git.kernel.org/stable/c/52440e15d9628f8f239373c0f2e5e8f92feea2df","https://git.kernel.org/stable/c/8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1","https://git.kernel.org/stable/c/9354248fc1c33a844ca1872761f6668b393e8c37","https://git.kernel.org/stable/c/a3af84b0fa00ead01fcd0e28b5d773ff25990a0d","https://git.kernel.org/stable/c/cb27f3bf915cc0f20fc0c48da9059304e39ebd35"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Enable IBPB flush on BPF JIT allocation\n\nEnable hardening against JIT spraying when Spectre-v2 mitigations are in\nuse. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip\nenabling the IBPB flush if the BPF dispatcher is already using a retpoline\nsequence.\n\nThis hardening applies only when BPF-JIT is in use. Guard the enabling\nunder CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.","cvss":[],"epss":[{"cve":"CVE-2026-64507","epss":0.00161,"percentile":0.05648,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64507","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64508","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64508","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Support for hardening against JIT spraying  The BPF JIT allocator packs many small programs into larger executable allocations and reuses space within those allocations as programs are loaded and freed. When fresh code is written into space that a previous program occupied, an indirect jump into the new program can reuse a branch prediction left behind by the old one.  Flush the indirect branch predictors before reusing JIT memory so that indirect jumps into a newly written program don't reuse predictions from an old program that occupied the same space.  Introduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush static call for flushing the branch predictors on JIT memory reuse. Architectures that need a flush, can update it to a predictor flush function. By default, its a NOP and does not emit any CALL.  Allocations larger than a pack are not covered by this flush. That is safe because cBPF programs (the unprivileged attack surface) are bounded well below a pack size. Issue a warning if this assumption is ever violated while the flush is active.","cvss":[],"epss":[{"cve":"CVE-2026-64508","epss":0.00161,"percentile":0.05646,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-64508","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64508","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1fbafd5235ca897b322161659ebe8ba651b00b3b","https://git.kernel.org/stable/c/6e52c240c43a601b681e3a4e58fc5685114d4726","https://git.kernel.org/stable/c/7a6c171c6a1ac6d1509752dac131d941a3de0b37","https://git.kernel.org/stable/c/8ff183ee4d8c452960df58175a094828c0513b2e","https://git.kernel.org/stable/c/96cce16e26dd02a8678f1e87f88a4b5cdb63b995","https://git.kernel.org/stable/c/eed774da601268dae674e14d54a15e3624691f52"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Support for hardening against JIT spraying\n\nThe BPF JIT allocator packs many small programs into larger executable\nallocations and reuses space within those allocations as programs are\nloaded and freed. When fresh code is written into space that a previous\nprogram occupied, an indirect jump into the new program can reuse a branch\nprediction left behind by the old one.\n\nFlush the indirect branch predictors before reusing JIT memory so that\nindirect jumps into a newly written program don't reuse predictions from an\nold program that occupied the same space.\n\nIntroduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush\nstatic call for flushing the branch predictors on JIT memory reuse.\nArchitectures that need a flush, can update it to a predictor flush\nfunction. By default, its a NOP and does not emit any CALL.\n\nAllocations larger than a pack are not covered by this flush. That is safe\nbecause cBPF programs (the unprivileged attack surface) are bounded well\nbelow a pack size. Issue a warning if this assumption is ever violated\nwhile the flush is active.","cvss":[],"epss":[{"cve":"CVE-2026-64508","epss":0.00161,"percentile":0.05646,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64508","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64513","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64513","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: x86: Unconditionally recompute CR8 intercept on PPR update  The TPR_THRESHOLD field in the VMCS is used by VMX to induce VM exits when the guest's virtual TPR falls under the specified threshold, allowing KVM to inject previously masked interrupts.  KVM handles these VM exits in handle_tpr_below_threshold(). Commit eb90f3417a0c (\"KVM: vmx: speed up TPR below threshold vmexits\") optimized this function by calling apic_update_ppr() instead of raising KVM_REQ_EVENT. apic_update_ppr() then raises KVM_REQ_EVENT if there is a pending, deliverable interrupt.  However, if there are no new interrupts pending, apic_update_ppr() does not issue the request. Thus, kvm_lapic_update_cr8_intercept() and vmx_update_cr8_intercept() are not called before VM entry, which results in a high, stale TPR_THRESHOLD. This is problematic due to the following sentence in 28.2.1.1 \"VM-Execution Control Fields\" in the SDM:    The following check is performed if the “use TPR shadow” VM-execution   control is 1 and the “virtualize APIC accesses” and “virtual-interrupt   delivery” VM-execution controls are both 0: the value of bits 3:0 of   the TPR threshold VM-execution control field should not be greater   than the value of bits 7:4 of VTPR.  This error condition is typically not observed when KVM runs on a bare metal system because modern processors support APICv, which enables virtual-interrupt delivery, and which KVM uses when possible. This causes the processor to no longer generate TPR-below-threshold exits and to no longer check TPR_THRESHOLD on entry. However, when running on older platforms, or under nested virtualization on a hypervisor that does not support virtual-interrupt delivery and enforces this check (like Hyper-V) this can cause a VM entry failure with hardware error 0x7, as seen in [1].  Call kvm_lapic_update_cr8_intercept() if apic_update_ppr() does not find a deliverable interrupt (and thus does not raise KVM_REQ_EVENT). Remove calls to kvm_lapic_update_cr8_intercept() on paths that end up in apic_update_ppr(), as they now become redundant. This ensures that any path that updates the guest's PPR also figures out if KVM needs to wait for a TPR change (using TPR_THRESHOLD on VMX or CR8 intercepts on SVM).","cvss":[],"epss":[{"cve":"CVE-2026-64513","epss":0.00176,"percentile":0.0729,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-64513","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64513","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/8c8e8ac22ee17d52f9eb2bc814bca7fab90fb8df","https://git.kernel.org/stable/c/bb365a506b1e6fb050c0fceaad354fe395385ef0","https://git.kernel.org/stable/c/ff9c4c6428883182960cfe5c78928f0896d80ebc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Unconditionally recompute CR8 intercept on PPR update\n\nThe TPR_THRESHOLD field in the VMCS is used by VMX to induce VM exits\nwhen the guest's virtual TPR falls under the specified threshold,\nallowing KVM to inject previously masked interrupts.\n\nKVM handles these VM exits in handle_tpr_below_threshold().\nCommit eb90f3417a0c (\"KVM: vmx: speed up TPR below threshold vmexits\")\noptimized this function by calling apic_update_ppr() instead of raising\nKVM_REQ_EVENT. apic_update_ppr() then raises KVM_REQ_EVENT if there is\na pending, deliverable interrupt.\n\nHowever, if there are no new interrupts pending, apic_update_ppr() does\nnot issue the request. Thus, kvm_lapic_update_cr8_intercept() and\nvmx_update_cr8_intercept() are not called before VM entry, which results\nin a high, stale TPR_THRESHOLD. This is problematic due to the following\nsentence in 28.2.1.1 \"VM-Execution Control Fields\" in the SDM:\n\n  The following check is performed if the “use TPR shadow” VM-execution\n  control is 1 and the “virtualize APIC accesses” and “virtual-interrupt\n  delivery” VM-execution controls are both 0: the value of bits 3:0 of\n  the TPR threshold VM-execution control field should not be greater\n  than the value of bits 7:4 of VTPR.\n\nThis error condition is typically not observed when KVM runs on a bare\nmetal system because modern processors support APICv, which enables\nvirtual-interrupt delivery, and which KVM uses when possible. This\ncauses the processor to no longer generate TPR-below-threshold exits\nand to no longer check TPR_THRESHOLD on entry. However, when running\non older platforms, or under nested virtualization on a hypervisor that\ndoes not support virtual-interrupt delivery and enforces this check\n(like Hyper-V) this can cause a VM entry failure with hardware error\n0x7, as seen in [1].\n\nCall kvm_lapic_update_cr8_intercept() if apic_update_ppr() does not\nfind a deliverable interrupt (and thus does not raise KVM_REQ_EVENT).\nRemove calls to kvm_lapic_update_cr8_intercept() on paths that end up in\napic_update_ppr(), as they now become redundant. This ensures that any\npath that updates the guest's PPR also figures out if KVM needs to wait\nfor a TPR change (using TPR_THRESHOLD on VMX or CR8 intercepts on SVM).","cvss":[],"epss":[{"cve":"CVE-2026-64513","epss":0.00176,"percentile":0.0729,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64513","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64542","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64542","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: ndisc: fix NULL deref in accept_untracked_na()  accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev) and dereferences idev->cnf.accept_untracked_na without a NULL check, even though its only caller ndisc_recv_na() already fetched and NULL-checked idev for the same device.  Both reads of dev->ip6_ptr run in the same RCU read-side critical section, but a concurrent addrconf_ifdown() can clear dev->ip6_ptr between them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown() without the synchronize_net() that orders the unregister path, so the re-fetch returns NULL and oopses:   BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974)  Read of size 4 at addr 0000000000000364  Call Trace:   <IRQ>   ndisc_recv_na (net/ipv6/ndisc.c:974)   icmpv6_rcv (net/ipv6/icmp.c:1193)   ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479)   ip6_input_finish (net/ipv6/ip6_input.c:534)   ip6_input (net/ipv6/ip6_input.c:545)   ip6_mc_input (net/ipv6/ip6_input.c:635)   ipv6_rcv (net/ipv6/ip6_input.c:351)   </IRQ>  It is reachable by an unprivileged user via a network namespace.  Pass the caller's already validated idev instead of re-fetching it; the idev stays alive for the whole RCU critical section, so it is safe even after dev->ip6_ptr has been cleared.","cvss":[],"epss":[{"cve":"CVE-2026-64542","epss":0.00173,"percentile":0.06837,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-64542","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64542","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/160d3f0d7a556ceae505dcab521a37057b4ce28f","https://git.kernel.org/stable/c/62c719203cb521b64fab74da94a81bdde5c18808","https://git.kernel.org/stable/c/63d1c23764de2309cedbb779c75188d257a09d9b","https://git.kernel.org/stable/c/a6450f7cfae57b382cbaf66a577765c9a88b3c58","https://git.kernel.org/stable/c/d186e942365acece7c56d39da05dd63bf95b280a","https://git.kernel.org/stable/c/e5ba3017e46f275ad347e762e8eecacec5efa41d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ndisc: fix NULL deref in accept_untracked_na()\n\naccept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev)\nand dereferences idev->cnf.accept_untracked_na without a NULL check,\neven though its only caller ndisc_recv_na() already fetched and\nNULL-checked idev for the same device.\n\nBoth reads of dev->ip6_ptr run in the same RCU read-side critical\nsection, but a concurrent addrconf_ifdown() can clear dev->ip6_ptr\nbetween them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown()\nwithout the synchronize_net() that orders the unregister path, so the\nre-fetch returns NULL and oopses:\n\n BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974)\n Read of size 4 at addr 0000000000000364\n Call Trace:\n  <IRQ>\n  ndisc_recv_na (net/ipv6/ndisc.c:974)\n  icmpv6_rcv (net/ipv6/icmp.c:1193)\n  ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479)\n  ip6_input_finish (net/ipv6/ip6_input.c:534)\n  ip6_input (net/ipv6/ip6_input.c:545)\n  ip6_mc_input (net/ipv6/ip6_input.c:635)\n  ipv6_rcv (net/ipv6/ip6_input.c:351)\n  </IRQ>\n\nIt is reachable by an unprivileged user via a network namespace.\n\nPass the caller's already validated idev instead of re-fetching it; the\nidev stays alive for the whole RCU critical section, so it is safe even\nafter dev->ip6_ptr has been cleared.","cvss":[],"epss":[{"cve":"CVE-2026-64542","epss":0.00173,"percentile":0.06837,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64542","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64543","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64543","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: fix use-after-free of the discoverer in tipc_disc_rcv()  bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(), but tipc_disc_rcv() still dereferences b->disc in RX softirq under rcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).  L2 bearers are safe thanks to the synchronize_net() in tipc_disable_l2_media(), but the UDP bearer defers that call to the cleanup_bearer() workqueue, so the discoverer is freed with no grace period:   BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)  Read of size 8 at addr ffff88802348b728 by task poc_tipc/184  <IRQ>   tipc_disc_rcv (net/tipc/discover.c:149)   tipc_rcv (net/tipc/node.c:2126)   tipc_udp_recv (net/tipc/udp_media.c:391)   udp_rcv (net/ipv4/udp.c:2643)   ip_local_deliver_finish (net/ipv4/ip_input.c:241)  </IRQ>  Freed by task 181:   kfree (mm/slub.c:6565)   bearer_disable (net/tipc/bearer.c:418)   tipc_nl_bearer_disable (net/tipc/bearer.c:1001)  The bearer is freed with kfree_rcu(); free the discoverer the same way. Add an rcu_head to struct tipc_discoverer and free it and its skb from an RCU callback.  Because the RCU callback (tipc_disc_free_rcu) lives in module text, a call_rcu() that is still pending when the tipc module is unloaded would invoke a freed function. Add an rcu_barrier() to tipc_exit() after the bearer subsystem has been torn down, so all pending discoverer callbacks have run before the module text goes away.  Reachable from an unprivileged user namespace: the TIPCv2 genl family is netnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC and CONFIG_TIPC_MEDIA_UDP.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64543","epss":0.00126,"percentile":0.02572,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-64543","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64543","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1579342d71133da7f00daa02c75cebec7372097b","https://git.kernel.org/stable/c/380413cdfd29fb9fa486c82889132b680c4983c5","https://git.kernel.org/stable/c/4da2ac7749411971e1b222b992da5a172ce45f98","https://git.kernel.org/stable/c/5e215bf1c47fdddf8203a0fe80a0ed594065f101","https://git.kernel.org/stable/c/a0c5fdeb5fa257f8c6d469af266bc087cb5de6a2","https://git.kernel.org/stable/c/b65289e1c3f352a9f92c6e19713ddd647e033253","https://git.kernel.org/stable/c/ec7d54d8cc1723921d671e3272b427c96366506f","https://git.kernel.org/stable/c/f05b3f4c78370469286879c765f5a1dd39dbcd32"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix use-after-free of the discoverer in tipc_disc_rcv()\n\nbearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),\nbut tipc_disc_rcv() still dereferences b->disc in RX softirq under\nrcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).\n\nL2 bearers are safe thanks to the synchronize_net() in\ntipc_disable_l2_media(), but the UDP bearer defers that call to the\ncleanup_bearer() workqueue, so the discoverer is freed with no grace\nperiod:\n\n BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)\n Read of size 8 at addr ffff88802348b728 by task poc_tipc/184\n <IRQ>\n  tipc_disc_rcv (net/tipc/discover.c:149)\n  tipc_rcv (net/tipc/node.c:2126)\n  tipc_udp_recv (net/tipc/udp_media.c:391)\n  udp_rcv (net/ipv4/udp.c:2643)\n  ip_local_deliver_finish (net/ipv4/ip_input.c:241)\n </IRQ>\n Freed by task 181:\n  kfree (mm/slub.c:6565)\n  bearer_disable (net/tipc/bearer.c:418)\n  tipc_nl_bearer_disable (net/tipc/bearer.c:1001)\n\nThe bearer is freed with kfree_rcu(); free the discoverer the same way.\nAdd an rcu_head to struct tipc_discoverer and free it and its skb from an\nRCU callback.\n\nBecause the RCU callback (tipc_disc_free_rcu) lives in module text, a\ncall_rcu() that is still pending when the tipc module is unloaded would\ninvoke a freed function. Add an rcu_barrier() to tipc_exit() after the\nbearer subsystem has been torn down, so all pending discoverer callbacks\nhave run before the module text goes away.\n\nReachable from an unprivileged user namespace: the TIPCv2 genl family is\nnetnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC\nand CONFIG_TIPC_MEDIA_UDP.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64543","epss":0.00126,"percentile":0.02572,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64543","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64556","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64556","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf/core: Detach event groups during remove_on_exec  perf_event_remove_on_exec() removes events by calling perf_event_exit_event(). For top-level events, this removes the event from the context with DETACH_EXIT only.  This can leave inconsistent group state when a removed event is a group leader and the group contains siblings without remove_on_exec. If the group was active, the surviving siblings can remain active and attached to the removed leader's sibling list, but are no longer represented by a valid group leader on the PMU context active lists.  A later close of the removed leader uses DETACH_GROUP and can promote the still-active siblings from this stale group state. The next schedule-in can then add an already-linked active_list entry again, corrupting the PMU context active list.  With DEBUG_LIST enabled, this is caught as a list_add double-add in merge_sched_in().  Fix this by detaching group relationships when remove_on_exec removes an event. This preserves the existing task-exit and revoke behavior, while ensuring surviving siblings are ungrouped before the removed event leaves the context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64556","epss":0.00124,"percentile":0.02467,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09486},"relatedVulnerabilities":[{"id":"CVE-2026-64556","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64556","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/037a3c43edfb597665dd34457cd22b14692f2ba3","https://git.kernel.org/stable/c/06ccef0434e98058ddae7bcebc901f93d22b7653","https://git.kernel.org/stable/c/39358e856fb89e62e3c8d7389a2dc4ec33dbe90e","https://git.kernel.org/stable/c/4cdb1b3ab96eb1b7eb70bc5c82fede334bd60df2","https://git.kernel.org/stable/c/a2d5d3ee7b6e3953114726b1521e62123ab5b043"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Detach event groups during remove_on_exec\n\nperf_event_remove_on_exec() removes events by calling\nperf_event_exit_event(). For top-level events, this removes the event from\nthe context with DETACH_EXIT only.\n\nThis can leave inconsistent group state when a removed event is a group\nleader and the group contains siblings without remove_on_exec. If the group\nwas active, the surviving siblings can remain active and attached to the\nremoved leader's sibling list, but are no longer represented by a valid\ngroup leader on the PMU context active lists.\n\nA later close of the removed leader uses DETACH_GROUP and can promote the\nstill-active siblings from this stale group state. The next schedule-in can\nthen add an already-linked active_list entry again, corrupting the PMU\ncontext active list.\n\nWith DEBUG_LIST enabled, this is caught as a list_add double-add in\nmerge_sched_in().\n\nFix this by detaching group relationships when remove_on_exec removes an\nevent. This preserves the existing task-exit and revoke behavior, while\nensuring surviving siblings are ungrouped before the removed event leaves\nthe context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64556","epss":0.00124,"percentile":0.02467,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64556","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64561","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64561","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: x86: Check for invalid/obsolete root *after* making MMU pages available  Check for a \"stale\" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU.  If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root.  On its own, populating an invalid root is \"fine\", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages.  Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, \"KVM: MMU: ignore zapped root pagetables\"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages.  Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64561","epss":0.00347,"percentile":0.27834,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.28280500000000003},"relatedVulnerabilities":[{"id":"CVE-2026-64561","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64561","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0026dbb7de8ea76e97d6edf42fc3cc084564e2bf","https://git.kernel.org/stable/c/2abd5287f08319fa35764566b15c6e22cb1068db","https://git.kernel.org/stable/c/35e77467610c4a37cb0ff54ee56b85f73b1f5700","https://git.kernel.org/stable/c/62ef67af1878fa2cd066642f2f59e33ade95f637","https://git.kernel.org/stable/c/65c4f7a1028cf01a93a2762d679c289810ede990","https://git.kernel.org/stable/c/bce0d3c26e2c761a4bf43c8949f333fc7374eb2d","https://git.kernel.org/stable/c/f3477a6a4164f15287444eda685b5f6405dbd1e5","https://github.com/V4bel/Zapscape"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Check for invalid/obsolete root *after* making MMU pages available\n\nCheck for a \"stale\" page fault, i.e. for an invalid and/or obsolete root,\nafter making MMU pages available for the shadow MMU.  If reclaiming shadow\npages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to\nmap memory into an invalid root.  On its own, populating an invalid root is\n\"fine\", but because child shadow pages inherit their parent's role, any\nchildren created during the map/fetch will be created as invalid pages,\nthus violating KVM's invariant that invalid pages are never on the list of\nactive MMU pages.\n\nNote, the underlying flaw has existed since KVM first started tracking\ninvalid roots in 2008 (commit 2e53d63acba7, \"KVM: MMU: ignore zapped root\npagetables\"), but the true badness only came along in 2020 (Linux 5.9)\nwith the invariant that invalid shadow pages can't be on the list of\nactive pages.\n\nNote #2, inheriting role.invalid when creating child shadow pages is also\nfar from ideal; that flaw will be addressed separately.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64561","epss":0.00347,"percentile":0.27834,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64561","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64562","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64562","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: nVMX: Hide shadow VMCS right after VMCLEAR  free_nested() frees the shadow VMCS while vmcs01 still points to it. But because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU might migrate before the pointer is cleared and __loaded_vmcs_clear() may then execute VMCLEAR.  The VMCS needs to stay attached until its explicit VMCLEAR completes, but then it can be hidden and the page safely freed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64562","epss":0.00125,"percentile":0.02504,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10187500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-64562","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64562","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1dabef6e206568bf9d9ade74f6e56a48ea35695d","https://git.kernel.org/stable/c/4f50e6aec16f69627dbad5704d1e90a255d766a7","https://git.kernel.org/stable/c/589419470030a89f16cf19300658b6dc644ca946","https://git.kernel.org/stable/c/622ebfac01ba4f9c0060cebd41257fe46fc4a0b3","https://git.kernel.org/stable/c/8001d2ce9d9bd09118ce523aef595aa094573ae3","https://git.kernel.org/stable/c/af56298e9d86e6098cd1d2e155cb2949b7c45412","https://git.kernel.org/stable/c/b82c3144d8264265448292ca406f60bafeba3b6f","https://git.kernel.org/stable/c/dc3eecfa219ebc9d01eaf7d1abd1441efe884dab"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Hide shadow VMCS right after VMCLEAR\n\nfree_nested() frees the shadow VMCS while vmcs01 still points to it. But\nbecause it is asynchronous with respect to loaded_vmcs_clear(), the vCPU\nmight migrate before the pointer is cleared and __loaded_vmcs_clear()\nmay then execute VMCLEAR.\n\nThe VMCS needs to stay attached until its explicit VMCLEAR completes, but\nthen it can be hidden and the page safely freed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64562","epss":0.00125,"percentile":0.02504,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64562","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64563","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rhashtable: clear stale iter->p on table restart  rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-validates iter->p against the table and sets iter->p = NULL if the object is gone.  When iter->walker.tbl is NULL (table was freed during resize), it resets slot and skip but forgets to clear iter->p.  rhashtable_walk_next() then dereferences the stale iter->p, reading freed memory.  This is a use-after-free.  Any caller that does multi-fragment rhashtable walks across walk_stop/walk_start boundaries is affected.  Concrete cases include netlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC (tipc_nl_sk_walk in net/tipc/socket.c).  Crash stack (netlink_diag):   BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0   Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)   Call Trace:    rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)    __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)    netlink_diag_dump+0xc2/0x240    netlink_dump+0x5bc/0x1270    netlink_recvmsg+0x7a3/0x980    sock_recvmsg+0x1bc/0x200    __sys_recvfrom+0x1d4/0x2c0","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64563","epss":0.00117,"percentile":0.01896,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-64563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64563","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/042fda5c088015f18838e5c692659a7be60aeb26","https://git.kernel.org/stable/c/0955b65c2b47c30b439e2cf1b1e375073aa0413a","https://git.kernel.org/stable/c/3ff7c1dbf722cf3fa538672452ba182318e0fcc3","https://git.kernel.org/stable/c/4169d9fb92f313ff8e7e83d733c1ecdcc93eebd3","https://git.kernel.org/stable/c/8173f7e2ce67e6ca1d4763f3da14e5b01ce77456","https://git.kernel.org/stable/c/a0406c40c6638c5ae50257db6297b2fba6c9ba16","https://git.kernel.org/stable/c/ba510b5e9fe396497d31162acb579f210adfe6c8","https://git.kernel.org/stable/c/c39643ad99fea749be50615550e8f0e6d6e60694"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrhashtable: clear stale iter->p on table restart\n\nrhashtable_walk_start_check() has two restart paths when resuming a walk.\nWhen iter->walker.tbl is valid, it re-validates iter->p against the table\nand sets iter->p = NULL if the object is gone.  When iter->walker.tbl is\nNULL (table was freed during resize), it resets slot and skip but forgets\nto clear iter->p.\n\nrhashtable_walk_next() then dereferences the stale iter->p, reading\nfreed memory.  This is a use-after-free.\n\nAny caller that does multi-fragment rhashtable walks across\nwalk_stop/walk_start boundaries is affected.  Concrete cases include\nnetlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC\n(tipc_nl_sk_walk in net/tipc/socket.c).\n\nCrash stack (netlink_diag):\n  BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0\n  Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)\n  Call Trace:\n   rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)\n   __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)\n   netlink_diag_dump+0xc2/0x240\n   netlink_dump+0x5bc/0x1270\n   netlink_recvmsg+0x7a3/0x980\n   sock_recvmsg+0x1bc/0x200\n   __sys_recvfrom+0x1d4/0x2c0","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64563","epss":0.00117,"percentile":0.01896,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64563","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64564","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64564","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: don't free the ASCONF's own transport in DEL-IP processing  sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address.  sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order:      [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]  where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed transport (->ipaddr, ->state) and plants the dangling pointer into asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping only the pointer that is no longer on the list, removes every real transport, leaving the association with a transport_count of 0 and primary_path/active_path pointing at freed memory.  Reject a DEL-IP that targets the transport the ASCONF is being processed against, mirroring the existing source-address guard, so the wildcard branch can never reuse a freed transport.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64564","epss":0.01482,"percentile":0.72399,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":1.39308},"relatedVulnerabilities":[{"id":"CVE-2026-64564","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64564","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/2b324ba3494ae958cba16a453e3e71489b4de7fc","https://git.kernel.org/stable/c/74e8f3e7114f0e26d1b2c4c048044db9fcc27603","https://git.kernel.org/stable/c/85aca407c560aba81b5ce9d3d6cf94c74077d19b","https://git.kernel.org/stable/c/9b2854f86f0b56e9027d68e7a3fc909d1a9b566f","https://git.kernel.org/stable/c/a63afa1f9b12d5293cbe0b77fd45dc0632533a13","https://git.kernel.org/stable/c/a9ce31be4cb1a5dd82b3e0a1d0c3e7cbdcd31293","https://git.kernel.org/stable/c/d136b29bf91dd8e3161281b87de597b7311d9462","https://git.kernel.org/stable/c/fedeb4468987bcaff85fe3061de5ae052d414740","https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564","http://www.openwall.com/lists/oss-security/2026/08/06/13","http://www.openwall.com/lists/oss-security/2026/08/06/3","http://www.openwall.com/lists/oss-security/2026/08/06/4","http://www.openwall.com/lists/oss-security/2026/08/07/1","http://www.openwall.com/lists/oss-security/2026/08/07/2","http://www.openwall.com/lists/oss-security/2026/08/07/8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: don't free the ASCONF's own transport in DEL-IP processing\n\nsctp_process_asconf() caches the transport the ASCONF chunk is processed\nagainst in asconf->transport (== chunk->transport, set once in sctp_rcv()).\nFor an ASCONF located through its Address Parameter by\n__sctp_rcv_asconf_lookup(), that cached transport corresponds to the\nAddress Parameter, which need not be the packet's source address.\n\nsctp_process_asconf_param() rejects a DEL-IP for the packet source address\n(ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport.\nA single ASCONF can therefore carry, in order:\n\n    [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0]\n\nwhere L differs from the source. The DEL-IP for L passes the D8 check and\ncalls sctp_assoc_rm_peer() on the transport that asconf->transport still\npoints at, freeing it (RCU-deferred). The following wildcard DEL-IP then\nreuses the now-dangling asconf->transport in sctp_assoc_set_primary() and\nsctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed\ntransport (->ipaddr, ->state) and plants the dangling pointer into\nasoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping\nonly the pointer that is no longer on the list, removes every real\ntransport, leaving the association with a transport_count of 0 and\nprimary_path/active_path pointing at freed memory.\n\nReject a DEL-IP that targets the transport the ASCONF is being processed\nagainst, mirroring the existing source-address guard, so the wildcard\nbranch can never reuse a freed transport.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64564","epss":0.01482,"percentile":0.72399,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64564","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64565","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64565","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()  The `ims_pcu_process_data()` processes incoming URB data byte by byte. However, it fails to check if the `read_pos` index exceeds IMS_PCU_BUF_SIZE.  If a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE, `read_pos` will increment indefinitely. Moreover, since `read_pos` is located immediately after `read_buf`, the attacker can overwrite `read_pos` itself to arbitrarily control the index.  This manipulated `read_pos` is subsequently used in `ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a heap buffer overflow.  Specifically, an attacker can overwrite the `cmd_done.wait.head` located at offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`. Consequently, when the driver calls `complete(&pcu->cmd_done)`, it triggers a control flow hijack by using the manipulated pointer.  Fix this by adding a bounds check for `read_pos` before writing to `read_buf`. If the packet is too long, discard it, log a warning, and reset the parser state.  [dtor: factor out resetting packet state, reset checksum as well]","cvss":[],"epss":[{"cve":"CVE-2026-64565","epss":0.00184,"percentile":0.08112,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-64565","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64565","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/06cfff93fd40441292567b999091beab11c74504","https://git.kernel.org/stable/c/3a801bc75ba1d121d0ed60e7234f93ba5651d87d","https://git.kernel.org/stable/c/40bbbf2e91fd60715525bf0405c67876af817edf","https://git.kernel.org/stable/c/875115b82c295277b81b6dfee7debc725f44e854","https://git.kernel.org/stable/c/992a7173364dcf63e30012af43da3c2f279839f9","https://git.kernel.org/stable/c/ca9f8c09845fb8c51b6d447f6428eecd1b8b0a49","https://git.kernel.org/stable/c/d03a740e087de7dcb2a26dc1123377bd3d1d84ca"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()\n\nThe `ims_pcu_process_data()` processes incoming URB data byte by byte.\nHowever, it fails to check if the `read_pos` index exceeds\nIMS_PCU_BUF_SIZE.\n\nIf a malicious USB device sends a packet larger than IMS_PCU_BUF_SIZE,\n`read_pos` will increment indefinitely. Moreover, since `read_pos` is\nlocated immediately after `read_buf`, the attacker can overwrite\n`read_pos` itself to arbitrarily control the index.\n\nThis manipulated `read_pos` is subsequently used in\n`ims_pcu_handle_response()` to copy data into `cmd_buf`, leading to a\nheap buffer overflow.\n\nSpecifically, an attacker can overwrite the `cmd_done.wait.head` located\nat offset 136 relative to `cmd_buf` in the `ims_pcu_handle_response()`.\nConsequently, when the driver calls `complete(&pcu->cmd_done)`, it\ntriggers a control flow hijack by using the manipulated pointer.\n\nFix this by adding a bounds check for `read_pos` before writing to\n`read_buf`. If the packet is too long, discard it, log a warning,\nand reset the parser state.\n\n[dtor: factor out resetting packet state, reset checksum as well]","cvss":[],"epss":[{"cve":"CVE-2026-64565","epss":0.00184,"percentile":0.08112,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64565","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64567","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64567","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: reject free space cache with more entries than pages  When loading a v1 free space cache, __load_free_space_cache() takes num_entries and num_bitmaps straight from the on-disk btrfs_free_space_header. That header is stored in the tree_root under a key with type 0, which the tree-checker has no case for, so neither count is validated before the load trusts it.  The load loops num_entries times and maps the next page whenever the current one runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which does io_ctl->pages[io_ctl->index++]. But pages[] is allocated in io_ctl_init() from the cache inode's i_size, not from num_entries:  \tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE); \tio_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);  So if num_entries claims more records than the pages can hold, io_ctl->index runs off the end of pages[]. The write side never hits this because io_ctl_add_entry() and io_ctl_add_bitmap() both stop once io_ctl->index >= io_ctl->num_pages; the read side just never had the same check.  To trigger it, take a clean cache (num_entries = <N> here), set num_entries in the header to 0x10000, and fix up the leaf checksum so it still passes the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read 65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the array:    BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)   Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58    io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)    __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)    load_free_space_cache (fs/btrfs/free-space-cache.c:1017)    caching_thread (fs/btrfs/block-group.c:880)    btrfs_work_helper (fs/btrfs/async-thread.c:312)    process_one_work    worker_thread    kthread    ret_from_fork  free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc() at line 565, which is why that is the frame KASAN names. The out-of-bounds slot is then treated as a struct page and handed to crc32c(), so the bad read turns into a GP fault.  Add the missing check to io_ctl_check_crc(), which is where both the entry loop and the bitmap loop end up. When num_entries is too large the load now fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds the free space from the extent tree, so a valid cache is never rejected.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64567","epss":0.0012,"percentile":0.02094,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-64567","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64567","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/094734c7aaa2b36751dc32480a680a4952685e78","https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039","https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2","https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f","https://git.kernel.org/stable/c/8ded74c654a982dc8581a17b0caa7fcedb20de69","https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350","https://git.kernel.org/stable/c/c9c38066b6446e83668c041702bb639b0ca49363","https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject free space cache with more entries than pages\n\nWhen loading a v1 free space cache, __load_free_space_cache() takes\nnum_entries and num_bitmaps straight from the on-disk\nbtrfs_free_space_header. That header is stored in the tree_root under a key\nwith type 0, which the tree-checker has no case for, so neither count is\nvalidated before the load trusts it.\n\nThe load loops num_entries times and maps the next page whenever the current\none runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which\ndoes io_ctl->pages[io_ctl->index++]. But pages[] is allocated in\nio_ctl_init() from the cache inode's i_size, not from num_entries:\n\n\tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);\n\tio_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);\n\nSo if num_entries claims more records than the pages can hold, io_ctl->index\nruns off the end of pages[]. The write side never hits this because\nio_ctl_add_entry() and io_ctl_add_bitmap() both stop once\nio_ctl->index >= io_ctl->num_pages; the read side just never had the same\ncheck.\n\nTo trigger it, take a clean cache (num_entries = <N> here), set num_entries\nin the header to 0x10000, and fix up the leaf checksum so it still passes\nthe tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and\npages[] is a 16-pointer (kmalloc-128) array. The load now tries to read\n65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the\narray:\n\n  BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n  Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58\n   io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n   __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)\n   load_free_space_cache (fs/btrfs/free-space-cache.c:1017)\n   caching_thread (fs/btrfs/block-group.c:880)\n   btrfs_work_helper (fs/btrfs/async-thread.c:312)\n   process_one_work\n   worker_thread\n   kthread\n   ret_from_fork\n\nfree-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()\nat line 565, which is why that is the frame KASAN names. The out-of-bounds\nslot is then treated as a struct page and handed to crc32c(), so the bad\nread turns into a GP fault.\n\nAdd the missing check to io_ctl_check_crc(), which is where both the entry\nloop and the bitmap loop end up. When num_entries is too large the load now\nfails like any corrupt cache: __load_free_space_cache() drops it and rebuilds\nthe free space from the extent tree, so a valid cache is never rejected.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64567","epss":0.0012,"percentile":0.02094,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64567","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64569","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64569","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n  On CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed attribute table itself instead of calling ip_valid_fib_dump_req(). The RTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is present, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no RTA_OIF hits a NULL dereference.  RTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without CAP_NET_ADMIN, so an unprivileged user can trigger it.    Oops: general protection fault, probably for non-canonical address         0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI   KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]   RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)   Call Trace:    mpls_dump_routes (net/mpls/af_mpls.c:2236)    netlink_dump (net/netlink/af_netlink.c:2331)    __netlink_dump_start (net/netlink/af_netlink.c:2446)    rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)    netlink_rcv_skb (net/netlink/af_netlink.c:2556)    netlink_unicast (net/netlink/af_netlink.c:1345)    netlink_sendmsg (net/netlink/af_netlink.c:1900)    __sock_sendmsg (net/socket.c:790)    ____sys_sendmsg (net/socket.c:2684)    ___sys_sendmsg (net/socket.c:2738)    __sys_sendmsg (net/socket.c:2770)    do_syscall_64 (arch/x86/entry/syscall_64.c:94)    entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)  Skip unset attributes, as ip_valid_fib_dump_req() does.","cvss":[],"epss":[{"cve":"CVE-2026-64569","epss":0.00171,"percentile":0.0666,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08549999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-64569","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64569","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/03b5a2c29afc8e634924c75d6ee94140e70de88d","https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502","https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3","https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a","https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce","https://git.kernel.org/stable/c/bfc1cb5d6a8308e493e307f1c823d2107abc0a47","https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71","https://git.kernel.org/stable/c/e796ce9ef4356dc7cbbaa8373843f77852f2814d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n  Oops: general protection fault, probably for non-canonical address\n        0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n  Call Trace:\n   mpls_dump_routes (net/mpls/af_mpls.c:2236)\n   netlink_dump (net/netlink/af_netlink.c:2331)\n   __netlink_dump_start (net/netlink/af_netlink.c:2446)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n   netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n   netlink_unicast (net/netlink/af_netlink.c:1345)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n   __sock_sendmsg (net/socket.c:790)\n   ____sys_sendmsg (net/socket.c:2684)\n   ___sys_sendmsg (net/socket.c:2738)\n   __sys_sendmsg (net/socket.c:2770)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does.","cvss":[],"epss":[{"cve":"CVE-2026-64569","epss":0.00171,"percentile":0.0666,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64569","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64571","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64571","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: p54: validate RX frame length in p54_rx_eeprom_readback()  p54_rx_eeprom_readback() copies the requested EEPROM slice out of a device-supplied readback frame without checking that the skb actually holds that many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()\") closed the destination overflow by copying a fixed priv->eeprom_slice_size (and rejecting a mismatched advertised len), but the source side is still unbounded: nothing verifies the frame is long enough to supply that many bytes.  A malicious USB device can send a short frame whose advertised len matches priv->eeprom_slice_size while the payload is truncated. The equality check passes and memcpy() reads past the end of the skb, leaking adjacent heap:    BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)   Read of size 1016 at addr ffff88800f077114 by task swapper/0/0   Call Trace:    <IRQ>    ...    __asan_memcpy (mm/kasan/shadow.c:105)    p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)    p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)    __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)    dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)    ...    </IRQ>    The buggy address belongs to the object at ffff88800f0770c0    which belongs to the cache skbuff_small_head of size 704   The buggy address is located 84 bytes inside of    allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)  Check that the slice fits in the skb before copying.","cvss":[],"epss":[{"cve":"CVE-2026-64571","epss":0.00171,"percentile":0.06661,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08549999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-64571","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64571","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48","https://git.kernel.org/stable/c/7a456ffcd20bd92ad0ef46c1aaa0e39e3be1f7e7","https://git.kernel.org/stable/c/88f7044f92b8326fbfab26d0d8ed297c367ebb76","https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d","https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509","https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea","https://git.kernel.org/stable/c/f21b7e096fe5371bf697cd410537fb434a763f5e","https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate RX frame length in p54_rx_eeprom_readback()\n\np54_rx_eeprom_readback() copies the requested EEPROM slice out of a\ndevice-supplied readback frame without checking that the skb actually holds\nthat many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in\np54_rx_eeprom_readback()\") closed the destination overflow by copying a\nfixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),\nbut the source side is still unbounded: nothing verifies the frame is long\nenough to supply that many bytes.\n\nA malicious USB device can send a short frame whose advertised len matches\npriv->eeprom_slice_size while the payload is truncated. The equality check\npasses and memcpy() reads past the end of the skb, leaking adjacent heap:\n\n  BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n  Read of size 1016 at addr ffff88800f077114 by task swapper/0/0\n  Call Trace:\n   <IRQ>\n   ...\n   __asan_memcpy (mm/kasan/shadow.c:105)\n   p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n   p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)\n   ...\n   </IRQ>\n\n  The buggy address belongs to the object at ffff88800f0770c0\n   which belongs to the cache skbuff_small_head of size 704\n  The buggy address is located 84 bytes inside of\n   allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)\n\nCheck that the slice fits in the skb before copying.","cvss":[],"epss":[{"cve":"CVE-2026-64571","epss":0.00171,"percentile":0.06661,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64571","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64572","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64572","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: fib: free fib_alias with kfree_rcu() on insert error path  fib_table_insert() publishes new_fa into the leaf's fa_list with fib_insert_alias() before calling the fib entry notifiers. When a notifier fails, the error path removes new_fa with fib_remove_alias() (hlist_del_rcu) and frees it right away with kmem_cache_free().  fib_table_lookup() walks that list under rcu_read_lock() only, so a concurrent lookup that already reached new_fa keeps reading it after the free:   BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)  Read of size 1 at addr ffff88810676d4eb by task exploit/297  Call Trace:   fib_table_lookup (net/ipv4/fib_trie.c:1601)   ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)   ip_route_output_key_hash (net/ipv4/route.c:2705)   __ip4_datagram_connect (net/ipv4/datagram.c:49)   udp_connect (net/ipv4/udp.c:2144)   __sys_connect (net/socket.c:2167)   __x64_sys_connect (net/socket.c:2173)   do_syscall_64   entry_SYSCALL_64_after_hwframe  which belongs to the cache ip_fib_alias of size 56  Triggering the error path needs CAP_NET_ADMIN and a registered fib notifier that can reject a route; a netdevsim device whose IPv4 FIB resource is exhausted is enough.  Free new_fa with alias_free_mem_rcu(), as fib_table_delete() already does for a fib_alias removed from the trie.","cvss":[],"epss":[{"cve":"CVE-2026-64572","epss":0.00201,"percentile":0.10119,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1005},"relatedVulnerabilities":[{"id":"CVE-2026-64572","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64572","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/6429c9cfd941e62acd7bb0bc64d631574d4c3b2a","https://git.kernel.org/stable/c/8150b5365f026e72250cacc527ea00be30f40105","https://git.kernel.org/stable/c/9d0778571def598c31e84a38ae5a7ebc6f65e6d8","https://git.kernel.org/stable/c/b8d2ea75c76abcd0d72679c2f488271f573e32fb","https://git.kernel.org/stable/c/bb03350f974aec352b660d032a1d283eb462165a","https://git.kernel.org/stable/c/cb8be318b4432abd88d3172ec157330f27a5f7a7","https://git.kernel.org/stable/c/d007056868723de9c0cc3f5ffaad47a8d468b9a4","https://git.kernel.org/stable/c/f2f152e94a67bc746afaf05a1b2702c195553112"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf's fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n  fib_table_lookup (net/ipv4/fib_trie.c:1601)\n  ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n  ip_route_output_key_hash (net/ipv4/route.c:2705)\n  __ip4_datagram_connect (net/ipv4/datagram.c:49)\n  udp_connect (net/ipv4/udp.c:2144)\n  __sys_connect (net/socket.c:2167)\n  __x64_sys_connect (net/socket.c:2173)\n  do_syscall_64\n  entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie.","cvss":[],"epss":[{"cve":"CVE-2026-64572","epss":0.00201,"percentile":0.10119,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64572","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64573","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64573","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: qca: fix NVM tag length underflow in TLV parser  In the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is \"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed int from the firmware TLV header and sizeof(struct tlv_type_nvm) is a size_t (12), so \"length\" is converted to size_t and any firmware-supplied \"length\" < 12 makes the subtraction wrap to a huge value. The loop body then reads a 12-byte struct tlv_type_nvm past the end of the short vmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).  Rewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both operands are non-negative, so it no longer underflows and a \"length\" too small for one record correctly skips the loop.    BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)   Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52   Workqueue: hci0 hci_power_on   Call Trace:    ...    kasan_report (mm/kasan/report.c:595)    qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)    qca_uart_setup (drivers/bluetooth/btqca.c:948)    qca_setup (drivers/bluetooth/hci_qca.c:2029)    hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)    hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)    hci_power_on (net/bluetooth/hci_core.c:920)    process_one_work (kernel/workqueue.c:3322)    worker_thread (kernel/workqueue.c:3486)    kthread (kernel/kthread.c:436)    ret_from_fork (arch/x86/kernel/process.c:158)    ret_from_fork_asm (arch/x86/entry/entry_64.S:245)","cvss":[],"epss":[{"cve":"CVE-2026-64573","epss":0.00161,"percentile":0.056,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-64573","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64573","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85","https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690","https://git.kernel.org/stable/c/5d34e537755d2f9eba2d4e54d70126f987ef20b4","https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a","https://git.kernel.org/stable/c/a7ee11441d71ab036a705d110a415421f5a4a898","https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" < 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n  Workqueue: hci0 hci_power_on\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n   qca_uart_setup (drivers/bluetooth/btqca.c:948)\n   qca_setup (drivers/bluetooth/hci_qca.c:2029)\n   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n   hci_power_on (net/bluetooth/hci_core.c:920)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)","cvss":[],"epss":[{"cve":"CVE-2026-64573","epss":0.00161,"percentile":0.056,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64573","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64576","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64576","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nexthop: initialize extack in nh_res_bucket_migrate()  nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to call_nexthop_res_bucket_notifiers(). When nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns -ENOMEM), the error is propagated back before any notifier sets extack._msg, and the error path formats the stale pointer with pr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE this dereferences uninitialized stack memory:    Oops: general protection fault, probably for non-canonical address ...   KASAN: maybe wild-memory-access in range [...]   RIP: 0010:string (lib/vsprintf.c:730)    vsnprintf (lib/vsprintf.c:2945)    _printk (kernel/printk/printk.c:2504)    nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)    nh_res_table_upkeep (net/ipv4/nexthop.c:1866)    rtm_new_nexthop (net/ipv4/nexthop.c:3323)    rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)    netlink_sendmsg (net/netlink/af_netlink.c:1900)   Kernel panic - not syncing: Fatal exception  Zero-initialize extack so _msg is NULL on error paths that never set it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64576","epss":0.00117,"percentile":0.01877,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08541},"relatedVulnerabilities":[{"id":"CVE-2026-64576","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64576","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66","https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d","https://git.kernel.org/stable/c/37bbd7e1d8df0bec3d187e961783e20c30533d2c","https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e","https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1","https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715","https://git.kernel.org/stable/c/eacd2e2117e8682f937967fda1022e7f1c22d91a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: initialize extack in nh_res_bucket_migrate()\n\nnh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to\ncall_nexthop_res_bucket_notifiers(). When\nnh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns\n-ENOMEM), the error is propagated back before any notifier sets\nextack._msg, and the error path formats the stale pointer with\npr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE\nthis dereferences uninitialized stack memory:\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: maybe wild-memory-access in range [...]\n  RIP: 0010:string (lib/vsprintf.c:730)\n   vsnprintf (lib/vsprintf.c:2945)\n   _printk (kernel/printk/printk.c:2504)\n   nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)\n   nh_res_table_upkeep (net/ipv4/nexthop.c:1866)\n   rtm_new_nexthop (net/ipv4/nexthop.c:3323)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n  Kernel panic - not syncing: Fatal exception\n\nZero-initialize extack so _msg is NULL on error paths that never set it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64576","epss":0.00117,"percentile":0.01877,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64576","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64577","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64577","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gtp: check skb_pull_data() return in gtp1u_send_echo_resp()  gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr + gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For a 16-19 byte echo request the pull fails and returns NULL without advancing skb->data; execution continues, and the following skb_push() plus the IP header pushed by iptunnel_xmit() move skb->data below skb->head, tripping skb_under_panic().  Fix it by dropping the packet when skb_pull_data() fails.    skbuff: skb_under_panic: ...   kernel BUG at net/core/skbuff.c:214!   Call Trace:    skb_push (net/core/skbuff.c:2648)    iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)    gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)    udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)    ...   Kernel panic - not syncing: Fatal exception in interrupt","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64577","epss":0.00576,"percentile":0.45554,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.432},"relatedVulnerabilities":[{"id":"CVE-2026-64577","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64577","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed","https://git.kernel.org/stable/c/9033fe49926f0e7421fefee922dc086417e905cf","https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b","https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c","https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa","https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: check skb_pull_data() return in gtp1u_send_echo_resp()\n\ngtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its\ncaller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +\ngtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For\na 16-19 byte echo request the pull fails and returns NULL without\nadvancing skb->data; execution continues, and the following skb_push()\nplus the IP header pushed by iptunnel_xmit() move skb->data below\nskb->head, tripping skb_under_panic().\n\nFix it by dropping the packet when skb_pull_data() fails.\n\n  skbuff: skb_under_panic: ...\n  kernel BUG at net/core/skbuff.c:214!\n  Call Trace:\n   skb_push (net/core/skbuff.c:2648)\n   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)\n   gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)\n   udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64577","epss":0.00576,"percentile":0.45554,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64577","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64578","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64578","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate compound request size before reading StructureSize2  When ksmbd validates a compound (chained) SMB2 request, ksmbd_smb2_check_message() reads pdu->StructureSize2 without first checking that the compound element is large enough to contain it. StructureSize2 is a 2-byte field at offset 64 (__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.  The compound-walking logic only guarantees that a full 64-byte SMB2 header is present for the trailing element: when NextCommand is 0, len is reduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A remote client can craft a compound request whose last element has exactly 64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte past the receive buffer, producing a slab-out-of-bounds read.    BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)   Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14   The buggy address is located 172 bytes inside of allocated 173-byte region   Workqueue: ksmbd-io handle_ksmbd_work   Call Trace:    ...    kasan_report (mm/kasan/report.c:595)    ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)    handle_ksmbd_work (fs/smb/server/server.c:119)    process_one_work (kernel/workqueue.c:3314)    worker_thread (kernel/workqueue.c:3397)    kthread (kernel/kthread.c:436)    ret_from_fork (arch/x86/kernel/process.c:158)    ret_from_fork_asm (arch/x86/entry/entry_64.S:245)  Reject any compound element that is too small to hold StructureSize2 before dereferencing it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64578","epss":0.00336,"percentile":0.26579,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.26376},"relatedVulnerabilities":[{"id":"CVE-2026-64578","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64578","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/15b38176fd1530372905c602fde51fe89ec8c877","https://git.kernel.org/stable/c/1b6740525f5af90868d557c31b496ae689c8c549","https://git.kernel.org/stable/c/2c307126ed8e7adddab82b8e31d962d3a2156ab1","https://git.kernel.org/stable/c/415d0fff0451ad7ad4caa910f2bb0f562f0fd60f","https://git.kernel.org/stable/c/ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a","https://git.kernel.org/stable/c/f0e337e7db67cc1c832958bbb6c4026bdceacfdb","https://git.kernel.org/stable/c/f7550a91ab211726f59cb137523b7a9eae1ac6eb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate compound request size before reading StructureSize2\n\nWhen ksmbd validates a compound (chained) SMB2 request,\nksmbd_smb2_check_message() reads pdu->StructureSize2 without first\nchecking that the compound element is large enough to contain it.\nStructureSize2 is a 2-byte field at offset 64\n(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.\n\nThe compound-walking logic only guarantees that a full 64-byte SMB2\nheader is present for the trailing element: when NextCommand is 0, len is\nreduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A\nremote client can craft a compound request whose last element has exactly\n64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte\npast the receive buffer, producing a slab-out-of-bounds read.\n\n  BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n  Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14\n  The buggy address is located 172 bytes inside of allocated 173-byte region\n  Workqueue: ksmbd-io handle_ksmbd_work\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n   handle_ksmbd_work (fs/smb/server/server.c:119)\n   process_one_work (kernel/workqueue.c:3314)\n   worker_thread (kernel/workqueue.c:3397)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\nReject any compound element that is too small to hold StructureSize2\nbefore dereferencing it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64578","epss":0.00336,"percentile":0.26579,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64578","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64579","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64579","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert  xfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert loop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or fail. But its guard is inverted: it skips policies with prefixlen < threshold and preallocates for the rest.  prefixlen < threshold is exactly when policy_hash_bysel() returns NULL and the reinsert takes the allocating xfrm_policy_inexact_insert() path. So the loop preallocates for the exact policies (which never allocate) and skips the inexact ones, whose bin/node is then allocated GFP_ATOMIC during reinsert. On failure the error path only WARN_ONCE()s and continues, leaving a poisoned bydst node; the next rebuild's hlist_del_rcu() dereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure, deterministic via failslab.  Invert the guard so preallocation covers exactly the reinserted policies; the reinsert then allocates nothing and cannot fail.  Crash:   Oops: general protection fault, probably for non-canonical address   0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI   KASAN: maybe wild-memory-access in range [0xdead...]   ...   Workqueue: events xfrm_hash_rebuild   RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190   RAX: dead000000000122   (LIST_POISON2 + offset)   ...   Call Trace:    hlist_del_rcu (include/linux/rculist.h:599)    xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)    process_one_work (kernel/workqueue.c:3322)    worker_thread (kernel/workqueue.c:3486)    kthread (kernel/kthread.c:436)    ret_from_fork (arch/x86/kernel/process.c:158)    ret_from_fork_asm (arch/x86/entry/entry_64.S:245)    ...   Kernel panic - not syncing: Fatal exception in interrupt","cvss":[],"epss":[{"cve":"CVE-2026-64579","epss":0.00171,"percentile":0.06661,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08549999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-64579","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64579","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1cdeed9df1306f1a277e715600772640d63defa9","https://git.kernel.org/stable/c/43a4d510523779891cf8eca7ffb4a086b0b5d8bf","https://git.kernel.org/stable/c/6aa3796d18a9fda953ad76a62b57bf6c145cb9ef","https://git.kernel.org/stable/c/7acc5ed2f33608a3d83b64f50a5766843b6e2485","https://git.kernel.org/stable/c/94c00391a5117530188334f740ce26d3f1256190","https://git.kernel.org/stable/c/d9d9cc21cc90014724a14c447e3d587be9447107","https://git.kernel.org/stable/c/e48f4c3e3df35b34be719d72d737bbeaca77cf0c","https://git.kernel.org/stable/c/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert\n\nxfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert\nloop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or\nfail. But its guard is inverted: it skips policies with prefixlen <\nthreshold and preallocates for the rest.\n\nprefixlen < threshold is exactly when policy_hash_bysel() returns NULL and\nthe reinsert takes the allocating xfrm_policy_inexact_insert() path. So the\nloop preallocates for the exact policies (which never allocate) and skips\nthe inexact ones, whose bin/node is then allocated GFP_ATOMIC during\nreinsert. On failure the error path only WARN_ONCE()s and continues,\nleaving a poisoned bydst node; the next rebuild's hlist_del_rcu()\ndereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,\ndeterministic via failslab.\n\nInvert the guard so preallocation covers exactly the reinserted policies;\nthe reinsert then allocates nothing and cannot fail.\n\nCrash:\n  Oops: general protection fault, probably for non-canonical address\n  0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n  KASAN: maybe wild-memory-access in range [0xdead...]\n  ...\n  Workqueue: events xfrm_hash_rebuild\n  RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190\n  RAX: dead000000000122   (LIST_POISON2 + offset)\n  ...\n  Call Trace:\n   hlist_del_rcu (include/linux/rculist.h:599)\n   xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt","cvss":[],"epss":[{"cve":"CVE-2026-64579","epss":0.00171,"percentile":0.06661,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64579","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64580","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64580","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()  On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst() releases the device reference with netdev_put() but leaves xdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev) again, so the same net_device reference is released twice, underflowing its refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for <dev> to become free\").  Clear xdst->u.dst.dev after the netdev_put(), the same way the XFRM device-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in net/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error.    ref_tracker: reference already released.   ref_tracker: allocated in:    xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)    ...    udpv6_sendmsg (net/ipv6/udp.c:1696)    ...   ref_tracker: freed in:    xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)    ...   WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780    dst_destroy (net/core/dst.c:115)    rcu_core    handle_softirqs    ...","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64580","epss":0.0012,"percentile":0.02093,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-64580","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64580","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/136992de9bb91871084ae52d172610541c76e4d2","https://git.kernel.org/stable/c/43de8a49335e611adb271bbd52e84dfbc11fc185","https://git.kernel.org/stable/c/97e032e5733e49471fb73de117ea2ac1ac7c479a","https://git.kernel.org/stable/c/df6856c2dda9187601d29b5fbd7a81b3b178cedf","https://git.kernel.org/stable/c/e078da1b4e11390cff3201c19a9a1fe70c5b934f","https://git.kernel.org/stable/c/ff636d7b7cba6dea82ecf580415ea57f2c1a11b6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()\n\nOn the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()\nreleases the device reference with netdev_put() but leaves\nxdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev)\nagain, so the same net_device reference is released twice, underflowing\nits refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for\n<dev> to become free\").\n\nClear xdst->u.dst.dev after the netdev_put(), the same way the XFRM\ndevice-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in\nnet/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error.\n\n  ref_tracker: reference already released.\n  ref_tracker: allocated in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)\n   ...\n   udpv6_sendmsg (net/ipv6/udp.c:1696)\n   ...\n  ref_tracker: freed in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)\n   ...\n  WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780\n   dst_destroy (net/core/dst.c:115)\n   rcu_core\n   handle_softirqs\n   ...","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64580","epss":0.0012,"percentile":0.02093,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64580","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64581","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64581","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: fix sk_dst_cache double-free in xfrm_user_policy()  xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with rcu_dereference_protected(), stores NULL and dst_release()s the old dst. That is only safe if no other thread modifies sk_dst_cache concurrently.  For a connected UDP socket that does not hold: the transmit fast path (udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly with an atomic xchg(). A per-socket policy change racing a send can make both sides observe the same old dst and each dst_release() it, dropping the socket's single reference twice and freeing the xfrm_dst bundle while it is still referenced:    BUG: KASAN: slab-use-after-free in dst_release   Write of size 4 at addr ffff88801897b6c0 by task exploit/155   Call Trace:    ...    dst_release (... ./include/linux/rcuref.h:109)    xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)    do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)    ip_setsockopt (net/ipv4/ip_sockglue.c:1417)    do_sock_setsockopt (net/socket.c:2368)    __sys_setsockopt (net/socket.c:2393)    __x64_sys_setsockopt (net/socket.c:2396)    do_syscall_64 (arch/x86/entry/syscall_64.c:94)    entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)  Reachable by an unprivileged user via a user+network namespace.  Use the atomic sk_dst_reset() so the cache is cleared and released with a single xchg(): whichever side wins releases the dst once, the other sees NULL and does nothing. Behaviour is otherwise unchanged.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64581","epss":0.00117,"percentile":0.01895,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-64581","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64581","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0ea8f06454012d9e7f9c6e6253df710949bf6294","https://git.kernel.org/stable/c/8dd8929b71c4f06c614f8f54c2cc070453faae16","https://git.kernel.org/stable/c/96b678d08268b5f5c6fc99d4289d9b7e334fc683","https://git.kernel.org/stable/c/a9340ebdc13f8bb5063c0bc0b037ee7e640d4ae9","https://git.kernel.org/stable/c/c283e9ada7fcb7dd4b10592623086b2e6d2f9925","https://git.kernel.org/stable/c/e8686fd8d18b99f3a9038683045b2f2338a7706d","https://git.kernel.org/stable/c/f0ab9a71167bae308e05ab13b65e2007504a603f","https://git.kernel.org/stable/c/f833821e4b52ab6335d443ede5fb79c38e61d19a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket's single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n  BUG: KASAN: slab-use-after-free in dst_release\n  Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n  Call Trace:\n   ...\n   dst_release (... ./include/linux/rcuref.h:109)\n   xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n   do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n   do_sock_setsockopt (net/socket.c:2368)\n   __sys_setsockopt (net/socket.c:2393)\n   __x64_sys_setsockopt (net/socket.c:2396)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64581","epss":0.00117,"percentile":0.01895,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64581","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64582","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64582","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Fix a use-after-free problem in rxe_mmap  rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1:     list_del_init(&ip->pending_mmaps);    spin_unlock_bh(&rxe->pending_lock);   /* ref == 1, no lock held */    ret = remap_vmalloc_range(vma, ip->obj, 0);  /* walks PTEs */    [...]    rxe_vma_open(vma);                    /* kref_get, ref → 2 */    remap_vmalloc_range_partial() walks PTEs without any lock.  A concurrent DESTROY_CQ ioctl on another CPU calls:      kref_put(&q->ip->ref, rxe_mmap_release)   /* ref 1→0 */     vfree(ip->obj)   /* clears vmalloc PTEs mid-walk */     kfree(ip)        /* frees rxe_mmap_info */  This yields:     1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the    per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert     2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears    it. User VMA holds a PTE to a free'd page which might eventually get    reallocated later by vmalloc which allows the attacker to get a clean    page-level UAF.     It is worth noting that even though a page-level UAF is possible given    the strong primitive, it is statistically very difficult to achieve    given the very short time window (after the last insert_page and before    the kref_get).  The call trace are as below:    Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI   KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]   CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014   RIP: 0010:validate_page_before_insert+0x32/0x300   Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5   RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202   RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000   RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008   RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000   R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00   R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20   FS:  00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0   Call Trace:    <TASK>    insert_page+0x8f/0x190    ? __pfx_insert_page+0x10/0x10    ? kasan_save_alloc_info+0x38/0x60    vm_insert_page+0x2e7/0x400    remap_vmalloc_range_partial+0x212/0x3e0    remap_vmalloc_range+0x6e/0xb0    ? __kasan_check_write+0x14/0x30    rxe_mmap+0x2e9/0x5d0    ib_uverbs_mmap+0x1ad/0x2c0    __mmap_region+0x12c2/0x2ad0    ? __pfx___mmap_region+0x10/0x10    ? __sanitizer_cov_trace_switch+0x58/0xb0    ? mas_prev_slot+0x360/0x39c0    ? __sanitizer_cov_trace_switch+0x58/0xb0    ? mas_next_slot+0x1e5b/0x2f40    ? __sanitizer_cov_trace_cmp8+0x18/0x30    ? unmapped_area_topdown+0x4dd/0x610    ? kfree+0x1b1/0x440    ? free_cpumask_var+0x16/0x30    ? __kasan_slab_free+0x7d/0xa0    ? __sanitizer_cov_trace_cmp8+0x18/0x30    mmap_region+0x2e6/0x3c0    do_mmap+0xa3e/0x12a0    ? __pfx_do_mmap+0x10/0x10    ? __kasan_check_write+0x14/0x30    ? down_write_killable+0xba/0x160    ? __pfx_down_write_killable+0x10/0x10    ? __sanitizer_cov_trace_cmp4+0x16/0x30    vm_mmap_pgoff+0x2d4/0x4a0    ? __pfx_vm_mmap_pgoff+0x10/0x10    ? fget+0x1bf/0x270    ksys_mmap_pgoff+0x40c/0x690    ? __sanitizer_cov_trace_const_cmp4+0x16/0x30    ? __pfx_ksys_mmap_pgoff+0x10/0x10    ? __kasan_check_write+0x14/0x30    ? _raw_spin_trylock+0xbb/0x130    ? __pfx__raw_spin_trylock+0x10/0x10    __x64_sys_mmap+0x135/0x1e0    x64_sys_c ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64582","epss":0.0013,"percentile":0.02947,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09945},"relatedVulnerabilities":[{"id":"CVE-2026-64582","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64582","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3371f2036e0f970166bbb624e25bba46d32fa18e","https://git.kernel.org/stable/c/3525987a392536f31a484833af258971af63b24c","https://git.kernel.org/stable/c/35744ab3d03c5fca8c1752f53fc8fc674e14c561","https://git.kernel.org/stable/c/665fb7d22a700c66a78db0cf88c6e6a649aba9d0","https://git.kernel.org/stable/c/aef5ea8578f97f2701039600846a8bcf5f21e863","https://git.kernel.org/stable/c/b810352d0916796dabe633cdb9adee9863ab4911","https://git.kernel.org/stable/c/e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e","https://git.kernel.org/stable/c/e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix a use-after-free problem in rxe_mmap\n\nrxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list\nand releases pending_lock while the struct's kref is still at 1:\n\n   list_del_init(&ip->pending_mmaps);\n   spin_unlock_bh(&rxe->pending_lock);   /* ref == 1, no lock held */\n   ret = remap_vmalloc_range(vma, ip->obj, 0);  /* walks PTEs */\n   [...]\n   rxe_vma_open(vma);                    /* kref_get, ref → 2 */\n   remap_vmalloc_range_partial() walks PTEs without any lock.\n\nA concurrent DESTROY_CQ ioctl on another CPU calls:\n\n    kref_put(&q->ip->ref, rxe_mmap_release)   /* ref 1→0 */\n    vfree(ip->obj)   /* clears vmalloc PTEs mid-walk */\n    kfree(ip)        /* frees rxe_mmap_info */\n\nThis yields:\n\n   1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the\n   per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert\n\n   2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears\n   it. User VMA holds a PTE to a free'd page which might eventually get\n   reallocated later by vmalloc which allows the attacker to get a clean\n   page-level UAF.\n\n   It is worth noting that even though a page-level UAF is possible given\n   the strong primitive, it is statistically very difficult to achieve\n   given the very short time window (after the last insert_page and before\n   the kref_get).\n\nThe call trace are as below:\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n  CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n  RIP: 0010:validate_page_before_insert+0x32/0x300\n  Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5\n  RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202\n  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\n  RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008\n  RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00\n  R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20\n  FS:  00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0\n  Call Trace:\n   <TASK>\n   insert_page+0x8f/0x190\n   ? __pfx_insert_page+0x10/0x10\n   ? kasan_save_alloc_info+0x38/0x60\n   vm_insert_page+0x2e7/0x400\n   remap_vmalloc_range_partial+0x212/0x3e0\n   remap_vmalloc_range+0x6e/0xb0\n   ? __kasan_check_write+0x14/0x30\n   rxe_mmap+0x2e9/0x5d0\n   ib_uverbs_mmap+0x1ad/0x2c0\n   __mmap_region+0x12c2/0x2ad0\n   ? __pfx___mmap_region+0x10/0x10\n   ? __sanitizer_cov_trace_switch+0x58/0xb0\n   ? mas_prev_slot+0x360/0x39c0\n   ? __sanitizer_cov_trace_switch+0x58/0xb0\n   ? mas_next_slot+0x1e5b/0x2f40\n   ? __sanitizer_cov_trace_cmp8+0x18/0x30\n   ? unmapped_area_topdown+0x4dd/0x610\n   ? kfree+0x1b1/0x440\n   ? free_cpumask_var+0x16/0x30\n   ? __kasan_slab_free+0x7d/0xa0\n   ? __sanitizer_cov_trace_cmp8+0x18/0x30\n   mmap_region+0x2e6/0x3c0\n   do_mmap+0xa3e/0x12a0\n   ? __pfx_do_mmap+0x10/0x10\n   ? __kasan_check_write+0x14/0x30\n   ? down_write_killable+0xba/0x160\n   ? __pfx_down_write_killable+0x10/0x10\n   ? __sanitizer_cov_trace_cmp4+0x16/0x30\n   vm_mmap_pgoff+0x2d4/0x4a0\n   ? __pfx_vm_mmap_pgoff+0x10/0x10\n   ? fget+0x1bf/0x270\n   ksys_mmap_pgoff+0x40c/0x690\n   ? __sanitizer_cov_trace_const_cmp4+0x16/0x30\n   ? __pfx_ksys_mmap_pgoff+0x10/0x10\n   ? __kasan_check_write+0x14/0x30\n   ? _raw_spin_trylock+0xbb/0x130\n   ? __pfx__raw_spin_trylock+0x10/0x10\n   __x64_sys_mmap+0x135/0x1e0\n   x64_sys_c\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64582","epss":0.0013,"percentile":0.02947,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64582","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64583","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown  The Broadcom BDC UDC driver registers its IRQ handler with devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm only after bdc_remove() returns.  devm releases resources in reverse LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -> bdc_mem_free() manually before returning: bdc_udc_exit() tears down individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -> bdc_mem_free() frees and NULLs the DMA-coherent status-report ring (bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array.  Both happen while the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED) remains deliverable in the window up to the post-remove devm free_irq().  On receipt of a shared interrupt in that window, bdc_udc_interrupt() dereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA) and dispatches sr_handler callbacks that index into bdc_ep_array, causing a NULL-deref or use-after-free.  The same window affects the delayed_work bdc->func_wake_notify, which is armed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change() -> schedule_delayed_work() and may self-rearm from its own callback bdc_func_wake_timer().  No cancel exists anywhere in the driver, so a queued work item that fires after bdc_remove() returns and the bdc structure is devm-freed dereferences freed memory.  Replace devm_request_irq() with request_irq() and add an explicit free_irq(bdc->irq, bdc) in bdc_remove().  Clear BDC_GIE before free_irq() to stop the device from asserting interrupts, then free_irq() drains any in-flight handler, then cancel_delayed_work_sync() drains the func_wake_notify delayed work.  This ordering ensures the IRQ handler and delayed work cannot interfere with the subsequent endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit().  Wire the matching free_irq() into the bdc_udc_init() error path so the IRQ is released on probe failure, and route the bdc_init_ep() failure through err0 instead of returning directly.  This issue was found by an in-house static analysis tool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64583","epss":0.00117,"percentile":0.0187,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-64583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64583","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0583f2fbf8f86ae3a0ce054f96783dd83e65d9bb","https://git.kernel.org/stable/c/0b0b76e31b3991a899ae724eb97d359de0c0f1b1","https://git.kernel.org/stable/c/1a1d7158420df6b8fa1efc0cdd6ab704801a4fc8","https://git.kernel.org/stable/c/3fe181952b8a1aeb167d4503c794c0f5050f08ed","https://git.kernel.org/stable/c/d4964a74717107697999f48bcb4e80a9c0679a27","https://git.kernel.org/stable/c/dcf3e2f164435b5844706cb8eefef29ebee0eedb","https://git.kernel.org/stable/c/eac1107e54679db2df2c36d8bba3b66d3ab6cbcd","https://git.kernel.org/stable/c/f6fc21ec7ccd83726ba766d73d0b8cc03e726475"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown\n\nThe Broadcom BDC UDC driver registers its IRQ handler with\ndevm_request_irq() in bdc_udc_init(), so the IRQ is released by devm\nonly after bdc_remove() returns.  devm releases resources in reverse\nLIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() ->\nbdc_mem_free() manually before returning: bdc_udc_exit() tears down\nindividual endpoint objects via bdc_free_ep(), while bdc_hw_exit() ->\nbdc_mem_free() frees and NULLs the DMA-coherent status-report ring\n(bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array.  Both happen while\nthe IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED)\nremains deliverable in the window up to the post-remove devm\nfree_irq().\n\nOn receipt of a shared interrupt in that window, bdc_udc_interrupt()\ndereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA)\nand dispatches sr_handler callbacks that index into bdc_ep_array,\ncausing a NULL-deref or use-after-free.\n\nThe same window affects the delayed_work bdc->func_wake_notify, which is\narmed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change()\n-> schedule_delayed_work() and may self-rearm from its own callback\nbdc_func_wake_timer().  No cancel exists anywhere in the driver, so a\nqueued work item that fires after bdc_remove() returns and the bdc\nstructure is devm-freed dereferences freed memory.\n\nReplace devm_request_irq() with request_irq() and add an explicit\nfree_irq(bdc->irq, bdc) in bdc_remove().  Clear BDC_GIE before\nfree_irq() to stop the device from asserting interrupts, then\nfree_irq() drains any in-flight handler, then cancel_delayed_work_sync()\ndrains the func_wake_notify delayed work.  This ordering ensures the\nIRQ handler and delayed work cannot interfere with the subsequent\nendpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit().  Wire the\nmatching free_irq() into the bdc_udc_init() error path so the IRQ is\nreleased on probe failure, and route the bdc_init_ep() failure through\nerr0 instead of returning directly.\n\nThis issue was found by an in-house static analysis tool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64583","epss":0.00117,"percentile":0.0187,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64583","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64584","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64584","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_midi: cancel pending IN work before freeing the midi object  The f_midi driver embeds a work item (midi->work) whose handler, f_midi_in_work(), dereferences the enclosing struct f_midi through container_of().  This work is armed from two sites: f_midi_complete(), on a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA rawmidi output-stream start.  Neither f_midi_disable() nor f_midi_unbind() cancels midi->work. f_midi_disable() only disables the endpoints and drains the in_req_fifo; it does not synchronize the work item, and the sound card is released asynchronously to the final free of the midi object.  The midi object is reference-counted (midi->free_ref) and is freed in f_midi_free() only once both the usb_function reference and the rawmidi private_data reference have been dropped.  In f_midi_unbind(), f_midi_disable() runs before the sound card is released, so while the USB endpoints are already disabled the rawmidi device is still usable by an open substream.  A concurrent userspace write on such a substream can reach f_midi_in_trigger() and queue midi->work again after f_midi_disable() has returned.  A work item armed this way may still be pending when the last reference drops and f_midi_free() proceeds to kfree(midi), letting f_midi_in_work() dereference the struct after it has been freed, a use-after-free.  For this reason cancelling midi->work in f_midi_disable() would not be sufficient: the ALSA trigger path can rearm the work after disable() returns.  Cancelling at the refcount-zero free site is the boundary after which neither arming source can survive, because by then both references that keep the midi object alive have been dropped: the USB endpoints are already disabled and the rawmidi device has been released.  Fix this by calling cancel_work_sync(&midi->work) in the refcount-zero block of f_midi_free(), before the embedded work_struct is freed along with the rest of the structure.  opts->lock is a sleeping mutex, so calling cancel_work_sync() under it is permitted, and the handler takes midi->transmit_lock rather than opts->lock, so no self-deadlock can occur while it waits for a running instance of the work to finish.  This issue was found by an in-house static analysis tool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64584","epss":0.00117,"percentile":0.0187,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-64584","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64584","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/380b4bef46c2eb260c7a9c6bb2c5be33ce5a38f9","https://git.kernel.org/stable/c/5650c18d93a1db7e27cb5a40b394747eb4686d5b","https://git.kernel.org/stable/c/620955b222c47332297d6bf38f78541aa699238a","https://git.kernel.org/stable/c/87bc316dd6fc90072297c635e10b9aa6075ecda1","https://git.kernel.org/stable/c/ac9a51d910bb7465c554c45320cb6c09f3d0b49d","https://git.kernel.org/stable/c/df18150126f66817e4d3f79f309e9c92d6ff384e","https://git.kernel.org/stable/c/f3c6f2c38062703d3dc7f86958bb0790c6959add","https://git.kernel.org/stable/c/f45089eaad0a083d71d84ff175741d7e157d9b69"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_midi: cancel pending IN work before freeing the midi object\n\nThe f_midi driver embeds a work item (midi->work) whose handler,\nf_midi_in_work(), dereferences the enclosing struct f_midi through\ncontainer_of().  This work is armed from two sites: f_midi_complete(),\non a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA\nrawmidi output-stream start.\n\nNeither f_midi_disable() nor f_midi_unbind() cancels midi->work.\nf_midi_disable() only disables the endpoints and drains the in_req_fifo;\nit does not synchronize the work item, and the sound card is released\nasynchronously to the final free of the midi object.\n\nThe midi object is reference-counted (midi->free_ref) and is freed in\nf_midi_free() only once both the usb_function reference and the rawmidi\nprivate_data reference have been dropped.  In f_midi_unbind(),\nf_midi_disable() runs before the sound card is released, so while the\nUSB endpoints are already disabled the rawmidi device is still usable by\nan open substream.  A concurrent userspace write on such a substream can\nreach f_midi_in_trigger() and queue midi->work again after\nf_midi_disable() has returned.  A work item armed this way may still be\npending when the last reference drops and f_midi_free() proceeds to\nkfree(midi), letting f_midi_in_work() dereference the struct after it\nhas been freed, a use-after-free.\n\nFor this reason cancelling midi->work in f_midi_disable() would not be\nsufficient: the ALSA trigger path can rearm the work after disable()\nreturns.  Cancelling at the refcount-zero free site is the boundary\nafter which neither arming source can survive, because by then both\nreferences that keep the midi object alive have been dropped: the USB\nendpoints are already disabled and the rawmidi device has been released.\n\nFix this by calling cancel_work_sync(&midi->work) in the refcount-zero\nblock of f_midi_free(), before the embedded work_struct is freed along\nwith the rest of the structure.  opts->lock is a sleeping mutex, so\ncalling cancel_work_sync() under it is permitted, and the handler takes\nmidi->transmit_lock rather than opts->lock, so no self-deadlock can\noccur while it waits for a running instance of the work to finish.\n\nThis issue was found by an in-house static analysis tool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64584","epss":0.00117,"percentile":0.0187,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64584","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64586","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64586","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: brcmfmac: drain bus_reset work on device removal  brcmf_fw_crashed() and the debugfs \"reset\" entry both schedule drvr->bus_reset, whose callback recovers drvr through container_of() and dereferences it.  The removal path frees drvr (brcmf_free -> wiphy_free) without draining the work, so a bus_reset callback pending or running during removal can outlive drvr.  Cancellation cannot live in brcmf_detach() or brcmf_free(): the work callback reaches teardown through the bus .reset op (PCIe brcmf_pcie_reset -> brcmf_detach; SDIO brcmf_sdio_bus_reset -> brcmf_sdiod_remove -> brcmf_free), so cancelling there would wait for the running work and deadlock.  Add a per-bus mutex (bus_reset_lock) and route all arming through brcmf_bus_schedule_reset(), which under the lock skips when the bus is marked removing.  Each bus remove entry calls brcmf_bus_cancel_reset_work(), which under the same lock sets removing and cancels the work.  Holding the mutex across cancel_work_sync() makes the set-removing + drain step atomic.  Every producer reaches the arming path from process context -- the PCIe firmware-halt notification runs in the threaded IRQ handler (brcmf_pcie_isr_thread) and the SDIO hostmail path runs from the data workqueue -- so the mutex is taken only in sleepable contexts.  Where applicable the remove entry first stops the firmware-crash producer: on PCIe mask the mailbox and synchronize_irq; on SDIO unregister the bus interrupt and cancel the data worker, which also reports firmware halts through brcmf_fw_crashed().  The mutex is initialized at bus allocation.  The SDIO suspend power-off path frees drvr through the same brcmf_sdiod_remove() and takes the same lock; resume re-allows the work only on a successful re-probe.  Also guard brcmf_fw_crashed() against a NULL bus_if/drvr: it can fire before brcmf_attach() wires up drvr, and it dereferences drvr (bphy_err/brcmf_dev_coredump) before reaching the arming gate.  The bus_reset work is shared across buses, so the drain is applied to every remove path: PCIe (the .reset op introduced by the Fixes commit), SDIO (arms the same work through brcmf_fw_crashed()), and USB (via the debugfs \"reset\" entry).  cancel_work_sync() drains a running or pending bus_reset work item before removal frees drvr, and patch 1/2 makes the scratch-buffer release safe when reset teardown has already released those DMA buffers.  This patch fixes the lifetime of the bus_reset work item itself.  It does not attempt to address the separate, pre-existing lifetime of the asynchronous firmware completion started by the PCIe reset path.  That callback needs its own lifetime/ownership protocol and is being tracked separately.  This issue was found by an in-house static analysis tool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64586","epss":0.00249,"percentile":0.16298,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.202935},"relatedVulnerabilities":[{"id":"CVE-2026-64586","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64586","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/02d378828af8bb74f6c2f4d2bee3c77cf16c861e","https://git.kernel.org/stable/c/177a25be1195f8bdc6160ba5f1a5699f7041c985","https://git.kernel.org/stable/c/43b25879f004c98defa2776bedc6ca4763c51945","https://git.kernel.org/stable/c/4824e3bcc68f8d678b409039d1bb48c7b5ea73dc","https://git.kernel.org/stable/c/61127dd20920bf28460a1609aabb0dafa2f54fac","https://git.kernel.org/stable/c/9dfb09cb0abbf92a06f93e0715e163aa188a84da","https://git.kernel.org/stable/c/c268331845ee00dbdbccb000826bb612dff2bee7","https://git.kernel.org/stable/c/e3815d1ffbb9be4f1605ddc3b427557893461683"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: drain bus_reset work on device removal\n\nbrcmf_fw_crashed() and the debugfs \"reset\" entry both schedule\ndrvr->bus_reset, whose callback recovers drvr through container_of()\nand dereferences it.  The removal path frees drvr (brcmf_free ->\nwiphy_free) without draining the work, so a bus_reset callback pending\nor running during removal can outlive drvr.\n\nCancellation cannot live in brcmf_detach() or brcmf_free(): the work\ncallback reaches teardown through the bus .reset op (PCIe\nbrcmf_pcie_reset -> brcmf_detach; SDIO brcmf_sdio_bus_reset ->\nbrcmf_sdiod_remove -> brcmf_free), so cancelling there would wait for\nthe running work and deadlock.\n\nAdd a per-bus mutex (bus_reset_lock) and route all arming through\nbrcmf_bus_schedule_reset(), which under the lock skips when the bus is\nmarked removing.  Each bus remove entry calls\nbrcmf_bus_cancel_reset_work(), which under the same lock sets removing\nand cancels the work.  Holding the mutex across cancel_work_sync() makes\nthe set-removing + drain step atomic.  Every producer reaches the arming\npath from process context -- the PCIe firmware-halt notification runs in\nthe threaded IRQ handler (brcmf_pcie_isr_thread) and the SDIO hostmail\npath runs from the data workqueue -- so the mutex is taken only in\nsleepable contexts.  Where applicable the remove entry first stops the\nfirmware-crash producer: on PCIe mask the mailbox and synchronize_irq;\non SDIO unregister the bus interrupt and cancel the data worker, which\nalso reports firmware halts through brcmf_fw_crashed().  The mutex is\ninitialized at bus allocation.  The SDIO suspend power-off path frees\ndrvr through the same brcmf_sdiod_remove() and takes the same lock;\nresume re-allows the work only on a successful re-probe.\n\nAlso guard brcmf_fw_crashed() against a NULL bus_if/drvr: it can fire\nbefore brcmf_attach() wires up drvr, and it dereferences drvr\n(bphy_err/brcmf_dev_coredump) before reaching the arming gate.\n\nThe bus_reset work is shared across buses, so the drain is applied to\nevery remove path: PCIe (the .reset op introduced by the Fixes commit),\nSDIO (arms the same work through brcmf_fw_crashed()), and USB (via the\ndebugfs \"reset\" entry).  cancel_work_sync() drains a running or pending\nbus_reset work item before removal frees drvr, and patch 1/2 makes the\nscratch-buffer release safe when reset teardown has already released\nthose DMA buffers.\n\nThis patch fixes the lifetime of the bus_reset work item itself.  It does\nnot attempt to address the separate, pre-existing lifetime of the\nasynchronous firmware completion started by the PCIe reset path.  That\ncallback needs its own lifetime/ownership protocol and is being tracked\nseparately.\n\nThis issue was found by an in-house static analysis tool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-64586","epss":0.00249,"percentile":0.16298,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64586","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-64590","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64590","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning  When CONFIG_DMA_API_DEBUG_SG is enabled, importing a udmabuf into a DRM driver (e.g. amdgpu for video playback in GNOME Videos / Showtime) triggers a spurious warning:    DMA-API: amdgpu 0000:03:00.0: cacheline tracking EEXIST, \\       overlapping mappings aren't supported   WARNING: kernel/dma/debug.c:619 at add_dma_entry+0x473/0x5f0  The call chain is:    amdgpu_cs_ioctl    -> amdgpu_ttm_backend_bind     -> dma_buf_map_attachment      -> [udmabuf] map_udmabuf -> get_sg_table       -> dma_map_sgtable(dev, sg, direction, 0)  // attrs=0        -> debug_dma_map_sg -> add_dma_entry -> EEXIST  This happens because udmabuf builds a per-page scatter-gather list via sg_set_folio().  When begin_cpu_udmabuf() has already created an sg table mapped for the misc device, and an importer such as amdgpu maps the same pages for its own device via map_udmabuf(), the DMA debug infrastructure sees two active mappings whose physical addresses share cacheline boundaries and warns about the overlap.  The DMA_ATTR_SKIP_CPU_SYNC flag suppresses this check in add_dma_entry() because it signals that no CPU cache maintenance is performed at map/unmap time, making the cacheline overlap harmless.  All other major dma-buf exporters already pass this flag:   - drm_gem_map_dma_buf() passes DMA_ATTR_SKIP_CPU_SYNC   - amdgpu_dma_buf_map() passes DMA_ATTR_SKIP_CPU_SYNC  The CPU sync at map/unmap time is also redundant for udmabuf: begin_cpu_udmabuf() and end_cpu_udmabuf() already perform explicit cache synchronization via dma_sync_sgtable_for_cpu/device() when CPU access is requested through the dma-buf interface.  Pass DMA_ATTR_SKIP_CPU_SYNC to dma_map_sgtable() and dma_unmap_sgtable() in udmabuf to suppress the spurious warning and skip the redundant sync.","cvss":[],"epss":[{"cve":"CVE-2026-64590","epss":0.00165,"percentile":0.0598,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-64590","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64590","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/01126abc11bcc6a45b664293b0b5df715be911d7","https://git.kernel.org/stable/c/0449a6583c0ee76778d314e4e82f166fc97fa9d8","https://git.kernel.org/stable/c/0db56e7eae932f8e2f3eb44ad1a63633d8f504f8","https://git.kernel.org/stable/c/34696563461c9a23177feb6d8aff43f4c0510278","https://git.kernel.org/stable/c/4a7c644e632741c2a3116a0d3da6c11de957a6ba","https://git.kernel.org/stable/c/504e2b4ab97a51d56d966cd36d0997ad30b65b2d","https://git.kernel.org/stable/c/d6552f5cff795d60e629f37513ecf23d88fd2f82","https://git.kernel.org/stable/c/dd7f1e572f44d3d039dc77e3989f537196c3bf52"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning\n\nWhen CONFIG_DMA_API_DEBUG_SG is enabled, importing a udmabuf into a DRM\ndriver (e.g. amdgpu for video playback in GNOME Videos / Showtime)\ntriggers a spurious warning:\n\n  DMA-API: amdgpu 0000:03:00.0: cacheline tracking EEXIST, \\\n      overlapping mappings aren't supported\n  WARNING: kernel/dma/debug.c:619 at add_dma_entry+0x473/0x5f0\n\nThe call chain is:\n\n  amdgpu_cs_ioctl\n   -> amdgpu_ttm_backend_bind\n    -> dma_buf_map_attachment\n     -> [udmabuf] map_udmabuf -> get_sg_table\n      -> dma_map_sgtable(dev, sg, direction, 0)  // attrs=0\n       -> debug_dma_map_sg -> add_dma_entry -> EEXIST\n\nThis happens because udmabuf builds a per-page scatter-gather list via\nsg_set_folio().  When begin_cpu_udmabuf() has already created an sg\ntable mapped for the misc device, and an importer such as amdgpu maps\nthe same pages for its own device via map_udmabuf(), the DMA debug\ninfrastructure sees two active mappings whose physical addresses share\ncacheline boundaries and warns about the overlap.\n\nThe DMA_ATTR_SKIP_CPU_SYNC flag suppresses this check in\nadd_dma_entry() because it signals that no CPU cache maintenance is\nperformed at map/unmap time, making the cacheline overlap harmless.\n\nAll other major dma-buf exporters already pass this flag:\n  - drm_gem_map_dma_buf() passes DMA_ATTR_SKIP_CPU_SYNC\n  - amdgpu_dma_buf_map() passes DMA_ATTR_SKIP_CPU_SYNC\n\nThe CPU sync at map/unmap time is also redundant for udmabuf:\nbegin_cpu_udmabuf() and end_cpu_udmabuf() already perform explicit\ncache synchronization via dma_sync_sgtable_for_cpu/device() when CPU\naccess is requested through the dma-buf interface.\n\nPass DMA_ATTR_SKIP_CPU_SYNC to dma_map_sgtable() and\ndma_unmap_sgtable() in udmabuf to suppress the spurious warning and\nskip the redundant sync.","cvss":[],"epss":[{"cve":"CVE-2026-64590","epss":0.00165,"percentile":0.0598,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-64590","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68081","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68081","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state  Put all vmcs12 pages if KVM synthesizes a nested VM-Exit due to invalid guest while emulating VMLAUNCH or VMRESUME.  The invalid guest state path doesn't use nested_vmx_vmexit() as that API is intended to be used if and only if L2 is active, and the open coded equivalent neglects to put the vmcs12 pages.  Failure to put the vmcs12 pages leaks any pinned pages (and/or mappings) if L1 retries VMLAUNCH/VMRESUME.  Note, the !from_vmenter scenario doesn't suffer the same problem, as vmx_get_nested_state_pages() only gets/pins/maps the vmcs12 pages if L2 is active, i.e. if a \"full\" VM-Exit is guaranteed before KVM will retry getting vmcs12 pages.","cvss":[],"epss":[{"cve":"CVE-2026-68081","epss":0.00155,"percentile":0.04966,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-68081","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68081","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2c87a087c20632d68920272173b5d7c47f9bcf70","https://git.kernel.org/stable/c/2f2312c422fd2695da772cecb30c69994b795964","https://git.kernel.org/stable/c/7996013b85687034d2e820cef94d6404192e3a3d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state\n\nPut all vmcs12 pages if KVM synthesizes a nested VM-Exit due to invalid\nguest while emulating VMLAUNCH or VMRESUME.  The invalid guest state path\ndoesn't use nested_vmx_vmexit() as that API is intended to be used if and\nonly if L2 is active, and the open coded equivalent neglects to put the\nvmcs12 pages.  Failure to put the vmcs12 pages leaks any pinned pages\n(and/or mappings) if L1 retries VMLAUNCH/VMRESUME.\n\nNote, the !from_vmenter scenario doesn't suffer the same problem, as\nvmx_get_nested_state_pages() only gets/pins/maps the vmcs12 pages if L2 is\nactive, i.e. if a \"full\" VM-Exit is guaranteed before KVM will retry\ngetting vmcs12 pages.","cvss":[],"epss":[{"cve":"CVE-2026-68081","epss":0.00155,"percentile":0.04966,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68081","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68082","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68082","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: fix two unsafe bare decodes in decode_lockers()  decode_lockers() in cls_lock_client.c contains two bare decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads:  1. ceph_decode_32(p) at the num_lockers field has no preceding bounds    check. ceph_start_decoding() accepts struct_len=0 as valid -- the    internal ceph_decode_need(p, end, 0, bad) always passes -- so when an    OSD sends struct_len=0, ceph_start_decoding() returns success with    p == end. The immediately following bare ceph_decode_32(p) then reads    4 bytes past the validated buffer boundary. The garbage value is    passed directly to kzalloc_objs() as the locker count.     The sibling function decode_watchers() in osd_client.c already uses    ceph_decode_32_safe() after its own ceph_start_decoding() call.    decode_lockers() was the only site using the bare variant.  2. ceph_decode_8(p) after the decode_locker() loop has no preceding    bounds check. If an OSD crafts num_lockers such that the loop    advances p exactly to end, the subsequent bare ceph_decode_8(p) reads    one byte past the validated buffer boundary. The result is passed    directly into *type, which is used as a lock type discriminator by    callers, giving an OSD-controlled one-byte OOB read with direct    influence over the lock type field.  Fix both by replacing bare operations with their safe variants:   ceph_decode_32(p) -> ceph_decode_32_safe(p, end, *num_lockers,                                            err_inval)   ceph_decode_8(p)  -> ceph_decode_8_safe(p, end, *type,                                           err_free_lockers)  The goto targets differ intentionally:   err_inval: is a new label returning -EINVAL directly. It is used for   the pre-allocation failure path where *lockers is not yet allocated   and must not be passed to ceph_free_lockers().    err_free_lockers: is the existing label. It is used for the   post-allocation failure path where *lockers is allocated and must   be freed.  ret is set to -EINVAL before ceph_decode_8_safe() so that err_free_lockers returns the correct error code on bounds violation. Without this, err_free_lockers would return a stale ret value (0 from the successful decode_locker() loop), silently swallowing the error.  -EINVAL is correct for both failure paths. The data received from the OSD is structurally malformed. -ENOMEM would misrepresent the failure class to callers and to stable@ backporters triaging error paths.  Attacker model: a malicious or compromised OSD in a multi-tenant Ceph deployment can trigger this against any kernel client that issues the lock.get_info class method (e.g. during RBD exclusive lock acquisition).  [ idryomov: trim changelog, formatting ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68082","epss":0.00399,"percentile":0.33347,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37505999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-68082","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68082","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/001835c599899ef1bd3506a815110a6374451554","https://git.kernel.org/stable/c/02430f6f729b297e803d0605871f0a670b4eafd6","https://git.kernel.org/stable/c/57ba829804fe6d34bbac3b826c4b15c1caa54862","https://git.kernel.org/stable/c/7c422364acd93d7da1dfc27d6b54635a269653a1","https://git.kernel.org/stable/c/89df5d71f83f8e2781286798fd8ae5e42cf5f1a7","https://git.kernel.org/stable/c/a109a556115271ca7896dcda7b4b7e45e156c227","https://git.kernel.org/stable/c/a54be593d0b749161b08a1e56189b2cb9114267a","https://git.kernel.org/stable/c/c8ade01170a27d8ede0d761c255268af81e417f8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix two unsafe bare decodes in decode_lockers()\n\ndecode_lockers() in cls_lock_client.c contains two bare decode operations\nthat allow a malicious or compromised OSD to trigger slab-out-of-bounds\nreads:\n\n1. ceph_decode_32(p) at the num_lockers field has no preceding bounds\n   check. ceph_start_decoding() accepts struct_len=0 as valid -- the\n   internal ceph_decode_need(p, end, 0, bad) always passes -- so when an\n   OSD sends struct_len=0, ceph_start_decoding() returns success with\n   p == end. The immediately following bare ceph_decode_32(p) then reads\n   4 bytes past the validated buffer boundary. The garbage value is\n   passed directly to kzalloc_objs() as the locker count.\n\n   The sibling function decode_watchers() in osd_client.c already uses\n   ceph_decode_32_safe() after its own ceph_start_decoding() call.\n   decode_lockers() was the only site using the bare variant.\n\n2. ceph_decode_8(p) after the decode_locker() loop has no preceding\n   bounds check. If an OSD crafts num_lockers such that the loop\n   advances p exactly to end, the subsequent bare ceph_decode_8(p) reads\n   one byte past the validated buffer boundary. The result is passed\n   directly into *type, which is used as a lock type discriminator by\n   callers, giving an OSD-controlled one-byte OOB read with direct\n   influence over the lock type field.\n\nFix both by replacing bare operations with their safe variants:\n  ceph_decode_32(p) -> ceph_decode_32_safe(p, end, *num_lockers,\n                                           err_inval)\n  ceph_decode_8(p)  -> ceph_decode_8_safe(p, end, *type,\n                                          err_free_lockers)\n\nThe goto targets differ intentionally:\n  err_inval: is a new label returning -EINVAL directly. It is used for\n  the pre-allocation failure path where *lockers is not yet allocated\n  and must not be passed to ceph_free_lockers().\n\n  err_free_lockers: is the existing label. It is used for the\n  post-allocation failure path where *lockers is allocated and must\n  be freed.\n\nret is set to -EINVAL before ceph_decode_8_safe() so that\nerr_free_lockers returns the correct error code on bounds violation.\nWithout this, err_free_lockers would return a stale ret value (0 from\nthe successful decode_locker() loop), silently swallowing the error.\n\n-EINVAL is correct for both failure paths. The data received from the\nOSD is structurally malformed. -ENOMEM would misrepresent the failure\nclass to callers and to stable@ backporters triaging error paths.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment can trigger this against any kernel client that issues the\nlock.get_info class method (e.g. during RBD exclusive lock acquisition).\n\n[ idryomov: trim changelog, formatting ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68082","epss":0.00399,"percentile":0.33347,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68082","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68083","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68083","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix path resolution in ksmbd_vfs_kern_path_create  The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the create/mkdir/hardlink sink is not: ksmbd_vfs_kern_path_create() builds an absolute path with convert_to_unix_name() and resolves it from AT_FDCWD via start_creating_path(), so a \"..\" component is walked from the real filesystem root and escapes the export.  An authenticated client races a missing path component so the rooted open lookup returns -ENOENT (taking the create branch) while the same component is present (a directory) when the create walk runs; the create then resolves \"..\" out of the share.  Root the create walk at the share like the lookup and rename paths already are: resolve the parent with vfs_path_parent_lookup(..., LOOKUP_BENEATH, &share_conf->vfs_path) and create the final component with start_creating_noperm(). convert_to_unix_name() then has no callers and is removed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68083","epss":0.00446,"percentile":0.37598,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.40363000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-68083","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68083","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1c8951963d8ed357f70f59e0ad4ddce2199d2016","https://git.kernel.org/stable/c/489d1ded01425c0fb33418172c0e4e588467526b","https://git.kernel.org/stable/c/98185b3025beeae92d1fe700d5db26b9ac4bf025","https://git.kernel.org/stable/c/c7c884a1305aa4540eb7942a50bd356b34120e1f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix path resolution in ksmbd_vfs_kern_path_create\n\nThe SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the\ncreate/mkdir/hardlink sink is not: ksmbd_vfs_kern_path_create() builds an\nabsolute path with convert_to_unix_name() and resolves it from AT_FDCWD\nvia start_creating_path(), so a \"..\" component is walked from the real\nfilesystem root and escapes the export.\n\nAn authenticated client races a missing path component so the rooted open\nlookup returns -ENOENT (taking the create branch) while the same component\nis present (a directory) when the create walk runs; the create then\nresolves \"..\" out of the share.\n\nRoot the create walk at the share like the lookup and rename paths already\nare: resolve the parent with vfs_path_parent_lookup(..., LOOKUP_BENEATH,\n&share_conf->vfs_path) and create the final component with\nstart_creating_noperm(). convert_to_unix_name() then has no callers and is\nremoved.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68083","epss":0.00446,"percentile":0.37598,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68083","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68085","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68085","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled  HCI_UART_SENDING bit in tx_state means write_work is pending and blocks queueing it again.  Currently this bit is not cleared when canceling the work in hci_uart_close(), which blocks future writes when device is reopened later if write_work was pending.  Fix by clearing HCI_UART_SENDING when canceling the work.  Also make clearing of tx_skb safe by using disable_work_sync + enable_work instead of just cancel_work_sync.  hci_uart_flush() purges the proto tx queue so we can cancel the pending write_work there, instead of doing it just in hci_uart_close().  Re-enable and possibly requeue the work after queue flush.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68085","epss":0.00251,"percentile":0.16511,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.194525},"relatedVulnerabilities":[{"id":"CVE-2026-68085","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68085","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1b0d946d6f08bd39211385bc703a440911b41e46","https://git.kernel.org/stable/c/714d861d35d937f23375a4517569b13917bbbe51","https://git.kernel.org/stable/c/b9dd39cf1667e378b25a082ca796d495d578c5d3","https://git.kernel.org/stable/c/d52446b3e735cfdbdc2a58342163803bc2e64249"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled\n\nHCI_UART_SENDING bit in tx_state means write_work is pending and blocks\nqueueing it again.  Currently this bit is not cleared when canceling the\nwork in hci_uart_close(), which blocks future writes when device is\nreopened later if write_work was pending.\n\nFix by clearing HCI_UART_SENDING when canceling the work.\n\nAlso make clearing of tx_skb safe by using disable_work_sync +\nenable_work instead of just cancel_work_sync.  hci_uart_flush() purges\nthe proto tx queue so we can cancel the pending write_work there,\ninstead of doing it just in hci_uart_close().  Re-enable and possibly\nrequeue the work after queue flush.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.1,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68085","epss":0.00251,"percentile":0.16511,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68085","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68086","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68086","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/khugepaged: write all dirty file folios when collapsing  [There is no upstream commit, as this code was removed by upstream  commit 044925f9b565 (\"mm: fs: remove filemap_nr_thps*() functions and their users\")]  As-is, khugepaged and writable-file opening exclude each other. A file cannot be open writeable and have THPs (because the filesystem is not aware of them). khugepaged will never collapse file pages for files that are opened writeable. On an open(O_RDWR/O_WRONLY), the page cache for that particular file is dropped. This is fine because nothing could've been dirtied.  However, there is an edge-case: collapse_file() might not be able to coexist with concurrent writers, but it can coexist with dirty folios (from previous writers). Therefore, the following can happen:  open(file, O_RDWR) write(file) close(file) madvise(file_mapping, MADV_COLLAPSE, some non-dirty range) open(file, O_RDWR)  nr_thps > 0   truncate_inode_pages()     /* THPs are cleared out, but so are the dirty folios */  When this edge-case happens, there is data loss, as the dirty folios are fully discarded.  Fix it by fully writing back the page cache (and waiting) when collapsing file THPs. Doing so provides the guarantee that no dirty folio will be observed while there are active THPs. To fully ensure this is safe, the invalidate_lock needs to be held while doing the writeout, so that do_dentry_open()'s page cache truncation excludes this write-and-wait.  As a side effect, move the nr_thps counter bumping outside the i_pages lock. This is correct since the counter itself is an atomic_t and the producer <-> consumer correctness is provided by a full memory barrier: smp_mb() in collapse_file()/memory barrier implied by full ordering in get_write_access() -> atomic_inc_unless_negative().","cvss":[],"epss":[{"cve":"CVE-2026-68086","epss":0.0015,"percentile":0.04472,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.075},"relatedVulnerabilities":[{"id":"CVE-2026-68086","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68086","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2dfe9f5c91d0963058f8a5e46e1c2a908382cc46"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/khugepaged: write all dirty file folios when collapsing\n\n[There is no upstream commit, as this code was removed by upstream\n commit 044925f9b565 (\"mm: fs: remove filemap_nr_thps*() functions and their users\")]\n\nAs-is, khugepaged and writable-file opening exclude each other. A file\ncannot be open writeable and have THPs (because the filesystem is not aware\nof them). khugepaged will never collapse file pages for files that are\nopened writeable. On an open(O_RDWR/O_WRONLY), the page cache for that\nparticular file is dropped. This is fine because nothing could've been\ndirtied.\n\nHowever, there is an edge-case: collapse_file() might not be able to\ncoexist with concurrent writers, but it can coexist with dirty folios\n(from previous writers). Therefore, the following can happen:\n\nopen(file, O_RDWR)\nwrite(file)\nclose(file)\nmadvise(file_mapping, MADV_COLLAPSE, some non-dirty range)\nopen(file, O_RDWR)\n nr_thps > 0\n  truncate_inode_pages()\n    /* THPs are cleared out, but so are the dirty folios */\n\nWhen this edge-case happens, there is data loss, as the dirty folios are\nfully discarded.\n\nFix it by fully writing back the page cache (and waiting) when collapsing\nfile THPs. Doing so provides the guarantee that no dirty folio will be\nobserved while there are active THPs. To fully ensure this is safe, the\ninvalidate_lock needs to be held while doing the writeout, so that\ndo_dentry_open()'s page cache truncation excludes this write-and-wait.\n\nAs a side effect, move the nr_thps counter bumping outside the i_pages\nlock. This is correct since the counter itself is an atomic_t and the\nproducer <-> consumer correctness is provided by a full memory barrier:\nsmp_mb() in collapse_file()/memory barrier implied by full ordering in\nget_write_access() -> atomic_inc_unless_negative().","cvss":[],"epss":[{"cve":"CVE-2026-68086","epss":0.0015,"percentile":0.04472,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68086","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68093","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68093","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug  If a vCPU stays scheduled out (or blocked) while the last pCPU it ran on goes through a hotplug cycle (online->offline->online), and the vCPU then resumes execution on the same pCPU, then it is possible for it to run with an ASID that has now been assigned to a different vCPU, resulting in stale TLB translations being used.  svm_enable_virtualization_cpu() resets asid_generation to 1 and sets next_asid to max_asid + 1 on every CPU online event, including hotplug cycles.  Because next_asid starts beyond the pool boundary, the first call to new_asid() after an online event always wraps the pool, incrementing asid_generation to 2 and assigning ASIDs starting from min_asid.  Consider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding asid_generation=2 and ASID=N from before the hotplug event:    1. CPU-X goes offline and back online: asid_generation resets to 1,      next_asid = max_asid + 1.    2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping      the pool and consuming ASIDs starting from min_asid.  Eventually      vCPU-B from a different VM is assigned asid_generation=2, ASID=N      — the same ASID that vCPU-A held before the hotplug.    3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb->cpu is      unchanged so the migration branch is skipped.  Its saved      asid_generation=2 matches sd->asid_generation=2, so the generation      check silently passes and vCPU-A continues running with ASID=N —      the same ASID just freshly assigned to vCPU-B.  Both vCPUs from different VMs now run on CPU-X with the same ASID, causing them to share NPT TLB entries and producing stale translations.  The collision manifests as a KVM internal error (Suberror: 1, emulation failure).  The NPT page fault reports a faulting GPA far outside the VM's physical memory range — a sign of stale TLB translations being used.  KVM falls back to instruction emulation, which fails on FPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not implement.  Fix this by incrementing asid_generation instead of resetting it to 1 in svm_enable_virtualization_cpu().  On module load, asid_generation starts at 0 (memset) and the increment produces 1, identical to the old behaviour.  On subsequent hotplug cycles the generation advances beyond any value a vCPU previously observed on this CPU, so the generation check in pre_svm_run() reliably forces new_asid() on every vCPU after every hotplug cycle.","cvss":[],"epss":[{"cve":"CVE-2026-68093","epss":0.00186,"percentile":0.08254,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.093},"relatedVulnerabilities":[{"id":"CVE-2026-68093","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68093","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0f33b1c457c2199ed130b92cc2ff363a3f7b9415","https://git.kernel.org/stable/c/2028b81321dc757b6875b99c10d908e349c141e2","https://git.kernel.org/stable/c/25f744ffa0c8e799e06250ce2e618367b166b0d4","https://git.kernel.org/stable/c/60283726f2845bd78b95efbd0e50b93944780477","https://git.kernel.org/stable/c/6b542d116acecb83a1ca34e8eace304cff6a4ec9","https://git.kernel.org/stable/c/7508916b4b55d6f5ecc68cd09774dabd3a6b4440"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug\n\nIf a vCPU stays scheduled out (or blocked) while the last pCPU it ran\non goes through a hotplug cycle (online->offline->online), and the vCPU\nthen resumes execution on the same pCPU, then it is possible for it to\nrun with an ASID that has now been assigned to a different vCPU,\nresulting in stale TLB translations being used.\n\nsvm_enable_virtualization_cpu() resets asid_generation to 1 and sets\nnext_asid to max_asid + 1 on every CPU online event, including hotplug\ncycles.  Because next_asid starts beyond the pool boundary, the first\ncall to new_asid() after an online event always wraps the pool,\nincrementing asid_generation to 2 and assigning ASIDs starting from\nmin_asid.\n\nConsider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding\nasid_generation=2 and ASID=N from before the hotplug event:\n\n  1. CPU-X goes offline and back online: asid_generation resets to 1,\n     next_asid = max_asid + 1.\n\n  2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping\n     the pool and consuming ASIDs starting from min_asid.  Eventually\n     vCPU-B from a different VM is assigned asid_generation=2, ASID=N\n     — the same ASID that vCPU-A held before the hotplug.\n\n  3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb->cpu is\n     unchanged so the migration branch is skipped.  Its saved\n     asid_generation=2 matches sd->asid_generation=2, so the generation\n     check silently passes and vCPU-A continues running with ASID=N —\n     the same ASID just freshly assigned to vCPU-B.\n\nBoth vCPUs from different VMs now run on CPU-X with the same ASID,\ncausing them to share NPT TLB entries and producing stale translations.\n\nThe collision manifests as a KVM internal error (Suberror: 1, emulation\nfailure).  The NPT page fault reports a faulting GPA far outside the\nVM's physical memory range — a sign of stale TLB translations being\nused.  KVM falls back to instruction emulation, which fails on\nFPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not\nimplement.\n\nFix this by incrementing asid_generation instead of resetting it to 1\nin svm_enable_virtualization_cpu().  On module load, asid_generation\nstarts at 0 (memset) and the increment produces 1, identical to the\nold behaviour.  On subsequent hotplug cycles the generation advances\nbeyond any value a vCPU previously observed on this CPU, so the\ngeneration check in pre_svm_run() reliably forces new_asid() on every\nvCPU after every hotplug cycle.","cvss":[],"epss":[{"cve":"CVE-2026-68093","epss":0.00186,"percentile":0.08254,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68093","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68096","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68096","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  audit: fix recursive locking deadlock in audit_dupe_exe()  A deadlock occurs in the audit subsystem when duplicating executable-related rules.  When a file is moved (e.g., via do_renameat2()), the VFS layer locks the parent directory (I_MUTEX_PARENT), which synchronously triggers an fsnotify_move event. If an existing executable audit rule matches the file being moved, the audit subsystem catches this event and calls audit_dupe_exe() to duplicate the watch and update the rule. Then, audit_alloc_mark() would call kern_path_parent() to resolve the path, leading to a blind attempt to acquire the exact same I_MUTEX_PARENT lock already held by the task, resulting in the following recursive locking deadlock:   ============================================  WARNING: possible recursive locking detected  6.12.0-55.27.1.el10_0.x86_64+debug #1 Not tainted  --------------------------------------------  mv/5099 is trying to acquire lock:  ffff888132845358 (&inode->i_sb->s_type->i_mutex_dir_key/1){+.+.}-{3:3},  at: __kern_path_locked+0x10a/0x2f0   but task is already holding lock:  ffff888132846b58 (&inode->i_sb->s_type->i_mutex_dir_key/1){+.+.}-{3:3},  at: lock_two_directories+0x13f/0x2b0   other info that might help us debug this:   Possible unsafe locking scenario:          CPU0         ----    lock(&inode->i_sb->s_type->i_mutex_dir_key/1);    lock(&inode->i_sb->s_type->i_mutex_dir_key/1);    *** DEADLOCK ***    May be due to missing lock nesting notation    6 locks held by mv/5099:   #0: ffff888112a9c440 (sb_writers#13)   at: do_renameat2+0x34c/0xbc0   #1: ffff888112a9c790 (&type->s_vfs_rename_key#3)   at: do_renameat2+0x415/0xbc0   #2: ffff888132846b58 (&inode->i_sb->s_type->i_mutex_dir_key/1)   at: lock_two_directories+0x13f/0x2b0   #3: ffff888132845358 (&inode->i_sb->s_type->i_mutex_dir_key/5)   at: lock_two_directories+0x175/0x2b0   #4: ffffffffb3a1fb10 (&fsnotify_mark_srcu)   at: fsnotify+0x454/0x28a0   #5: ffffffffaf886230 (audit_filter_mutex)   at: audit_update_watch+0x36/0x11e0   stack backtrace:  Call Trace:   <TASK>   dump_stack_lvl+0x6f/0xb0   print_deadlock_bug.cold+0xbd/0xca   validate_chain+0x83a/0xf00   __lock_acquire+0xcac/0x1d20   lock_acquire.part.0+0x11b/0x360   down_write_nested+0x9f/0x230   __kern_path_locked+0x10a/0x2f0   kern_path_locked+0x26/0x40   audit_alloc_mark+0xfb/0x4f0   audit_dupe_exe+0x6c/0xe0   audit_dupe_rule+0x6c2/0xc00   audit_update_watch+0x4cc/0x11e0   audit_watch_handle_event+0x12c/0x1b0   send_to_group+0x5d0/0x8b0   fsnotify+0x615/0x28a0   fsnotify_move+0x1d8/0x630   vfs_rename+0xdcd/0x1df0   do_renameat2+0x9d4/0xbc0   __x64_sys_renameat+0x192/0x260   do_syscall_64+0x92/0x180   entry_SYSCALL_64_after_hwframe+0x76/0x7e  RIP: 0033:0x7f0491fe8c4e  Code: 0f 1f 40 00 48 8b 15 c1 e1 16 00 f7 d8 64 89 02 b8 ff ff ff ff  c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 08 01 00 00 0f 05 <48>  3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 89  RSP: 002b:00007ffc7210bf38 EFLAGS: 00000246 ORIG_RAX: 0000000000000108  RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0491fe8c4e  RDX: 0000000000000003 RSI: 00007ffc7210e6c8 RDI: 00000000ffffff9c  RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001  R10: 00005575eb2dae2a R11: 0000000000000246 R12: 00005575eb2dae2a  R13: 00007ffc7210e6c8 R14: 0000000000000003 R15: 00000000ffffff9c   </TASK>  The aforementioned deadlock can be consistently reproduced by running the script below:   audit-dupe-exe-deadlock.sh  --------------------------  #!/bin/bash  auditctl -D  mkdir -p /tmp/foo  touch /tmp/file  auditctl -a always,exit -F exe=/tmp/file -F path=/tmp/file -S all -k dr  mv /tmp/file /tmp/foo/file  rm -Rf /tmp/foo  This patch fixes the issue by introducing struct audit_watch_ctx to pass the fsnotify event context down to audit_alloc_mark(). By utilizing the already-resolved directory inode provided by the event, we bypass the kern_path_parent() path resol ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68096","epss":0.0054,"percentile":0.43677,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.40499999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-68096","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68096","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/36eb77f14b4e6f2dc1008c1fabe31236397be27a","https://git.kernel.org/stable/c/3b601938314c24fcd1afb6659cad92fe96c9c2f8","https://git.kernel.org/stable/c/3bbb4931f7cd84cecf29ec222c0732bf9ad4da9f","https://git.kernel.org/stable/c/40879c39d6740f3dddfb52b5d6ba7fb8cceb84d8","https://git.kernel.org/stable/c/6114c3f21eb2ae175401736da744b684705e7ed9","https://git.kernel.org/stable/c/7d1f66c69898ffb1a718926c32a777ecc471caca","https://git.kernel.org/stable/c/81905b5acbe77284734438df3fbec1158e6429a3","https://git.kernel.org/stable/c/f6fda0ac6661c23b8356dfb1cc423960cc6f0593"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix recursive locking deadlock in audit_dupe_exe()\n\nA deadlock occurs in the audit subsystem when duplicating\nexecutable-related rules.\n\nWhen a file is moved (e.g., via do_renameat2()), the VFS layer locks\nthe parent directory (I_MUTEX_PARENT), which synchronously triggers an\nfsnotify_move event. If an existing executable audit rule matches the\nfile being moved, the audit subsystem catches this event and calls\naudit_dupe_exe() to duplicate the watch and update the rule. Then,\naudit_alloc_mark() would call kern_path_parent() to resolve the path,\nleading to a blind attempt to acquire the exact same I_MUTEX_PARENT lock\nalready held by the task, resulting in the following recursive locking\ndeadlock:\n\n ============================================\n WARNING: possible recursive locking detected\n 6.12.0-55.27.1.el10_0.x86_64+debug #1 Not tainted\n --------------------------------------------\n mv/5099 is trying to acquire lock:\n ffff888132845358 (&inode->i_sb->s_type->i_mutex_dir_key/1){+.+.}-{3:3},\n at: __kern_path_locked+0x10a/0x2f0\n\n but task is already holding lock:\n ffff888132846b58 (&inode->i_sb->s_type->i_mutex_dir_key/1){+.+.}-{3:3},\n at: lock_two_directories+0x13f/0x2b0\n\n other info that might help us debug this:\n  Possible unsafe locking scenario:\n\n        CPU0\n        ----\n   lock(&inode->i_sb->s_type->i_mutex_dir_key/1);\n   lock(&inode->i_sb->s_type->i_mutex_dir_key/1);\n\n  *** DEADLOCK ***\n\n  May be due to missing lock nesting notation\n\n  6 locks held by mv/5099:\n  #0: ffff888112a9c440 (sb_writers#13)\n  at: do_renameat2+0x34c/0xbc0\n  #1: ffff888112a9c790 (&type->s_vfs_rename_key#3)\n  at: do_renameat2+0x415/0xbc0\n  #2: ffff888132846b58 (&inode->i_sb->s_type->i_mutex_dir_key/1)\n  at: lock_two_directories+0x13f/0x2b0\n  #3: ffff888132845358 (&inode->i_sb->s_type->i_mutex_dir_key/5)\n  at: lock_two_directories+0x175/0x2b0\n  #4: ffffffffb3a1fb10 (&fsnotify_mark_srcu)\n  at: fsnotify+0x454/0x28a0\n  #5: ffffffffaf886230 (audit_filter_mutex)\n  at: audit_update_watch+0x36/0x11e0\n\n stack backtrace:\n Call Trace:\n  <TASK>\n  dump_stack_lvl+0x6f/0xb0\n  print_deadlock_bug.cold+0xbd/0xca\n  validate_chain+0x83a/0xf00\n  __lock_acquire+0xcac/0x1d20\n  lock_acquire.part.0+0x11b/0x360\n  down_write_nested+0x9f/0x230\n  __kern_path_locked+0x10a/0x2f0\n  kern_path_locked+0x26/0x40\n  audit_alloc_mark+0xfb/0x4f0\n  audit_dupe_exe+0x6c/0xe0\n  audit_dupe_rule+0x6c2/0xc00\n  audit_update_watch+0x4cc/0x11e0\n  audit_watch_handle_event+0x12c/0x1b0\n  send_to_group+0x5d0/0x8b0\n  fsnotify+0x615/0x28a0\n  fsnotify_move+0x1d8/0x630\n  vfs_rename+0xdcd/0x1df0\n  do_renameat2+0x9d4/0xbc0\n  __x64_sys_renameat+0x192/0x260\n  do_syscall_64+0x92/0x180\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7f0491fe8c4e\n Code: 0f 1f 40 00 48 8b 15 c1 e1 16 00 f7 d8 64 89 02 b8 ff ff ff ff\n c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 08 01 00 00 0f 05 <48>\n 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 89\n RSP: 002b:00007ffc7210bf38 EFLAGS: 00000246 ORIG_RAX: 0000000000000108\n RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0491fe8c4e\n RDX: 0000000000000003 RSI: 00007ffc7210e6c8 RDI: 00000000ffffff9c\n RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001\n R10: 00005575eb2dae2a R11: 0000000000000246 R12: 00005575eb2dae2a\n R13: 00007ffc7210e6c8 R14: 0000000000000003 R15: 00000000ffffff9c\n  </TASK>\n\nThe aforementioned deadlock can be consistently reproduced by running\nthe script below:\n\n audit-dupe-exe-deadlock.sh\n --------------------------\n #!/bin/bash\n auditctl -D\n mkdir -p /tmp/foo\n touch /tmp/file\n auditctl -a always,exit -F exe=/tmp/file -F path=/tmp/file -S all -k dr\n mv /tmp/file /tmp/foo/file\n rm -Rf /tmp/foo\n\nThis patch fixes the issue by introducing struct audit_watch_ctx to pass\nthe fsnotify event context down to audit_alloc_mark(). By utilizing the\nalready-resolved directory inode provided by the event, we bypass the\nkern_path_parent() path resol\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68096","epss":0.0054,"percentile":0.43677,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68096","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68097","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68097","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate ACE size against SID sub-authorities  set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but does not verify that the declared ACE size contains all sub-authorities described by that field. An undersized ACE can therefore be copied and later make the POSIX ACL deduplication walk inspect data beyond the copied ACE boundary.  The existing initial bound check is also too small. It only ensures that the ACE size field is accessible before set_ntacl_dacl() reads sid.num_subauth farther into the input buffer.  Require enough input for the fixed SID header before accessing num_subauth, reject ACEs smaller than that header, and skip ACEs whose declared size cannot contain the complete SID. This makes the validation consistent with the other ACE walk paths.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68097","epss":0.00414,"percentile":0.34858,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33741},"relatedVulnerabilities":[{"id":"CVE-2026-68097","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68097","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/337022d9dfac441c3b35e4455a51aa981996e02e","https://git.kernel.org/stable/c/5152c6d49e3fd4e9f2e857c57527aead752f1f87","https://git.kernel.org/stable/c/61fd3559199f7fa693dcbff35e59477e24af041a","https://git.kernel.org/stable/c/62d80d7c2d9428085e7458ad4c06ca8c0984039b","https://git.kernel.org/stable/c/b7cb5bf0855470799f12da825de91e48951b3876"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate ACE size against SID sub-authorities\n\nset_ntacl_dacl() validates sid.num_subauth before copying an ACE, but\ndoes not verify that the declared ACE size contains all sub-authorities\ndescribed by that field. An undersized ACE can therefore be copied\nand later make the POSIX ACL deduplication walk inspect data beyond\nthe copied ACE boundary.\n\nThe existing initial bound check is also too small. It only ensures\nthat the ACE size field is accessible before set_ntacl_dacl() reads\nsid.num_subauth farther into the input buffer.\n\nRequire enough input for the fixed SID header before accessing\nnum_subauth, reject ACEs smaller than that header, and skip ACEs\nwhose declared size cannot contain the complete SID. This makes the\nvalidation consistent with the other ACE walk paths.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68097","epss":0.00414,"percentile":0.34858,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68097","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68098","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68098","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: bound DACL dedup walk to copied ACEs  set_ntacl_dacl() can stop copying ACEs before consuming the full input DACL when size accounting overflows.  When that happens, num_aces reflects only the ACEs that were actually copied into the output DACL, but set_posix_acl_entries_dacl() still receives nt_num_aces and uses it to walk the existing ACE array during dedup.  That makes the dedup walk scan past the copied ACE array and inspect buffer tail that does not contain valid ACEs.  Split the two meanings currently carried by the NT ACE count. Pass the number of copied NT ACEs to bound the dedup walk, and preserve the original \"input DACL had NT ACEs\" state separately for the Everyone/default ACL fallback.  This keeps the dedup walk aligned with the ACEs that are actually present in the rebuilt DACL.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68098","epss":0.00414,"percentile":0.34858,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.33741},"relatedVulnerabilities":[{"id":"CVE-2026-68098","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68098","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/58d97fcd0bf1aee694e244cc28635b9df95b543b","https://git.kernel.org/stable/c/6d9d7aa4a2c99c31acfa28921c30b684110cf66c","https://git.kernel.org/stable/c/a0ebdaa79e10210d4e8ed9fe138e8f4d569719e3","https://git.kernel.org/stable/c/b057a851129c6a084e7e393b62ca3abf6c2660bc","https://git.kernel.org/stable/c/f1eba60db813ec28732bf18b5f0a67ebac9c3100"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: bound DACL dedup walk to copied ACEs\n\nset_ntacl_dacl() can stop copying ACEs before consuming the full input\nDACL when size accounting overflows.\n\nWhen that happens, num_aces reflects only the ACEs that were actually\ncopied into the output DACL, but set_posix_acl_entries_dacl() still\nreceives nt_num_aces and uses it to walk the existing ACE array during\ndedup.\n\nThat makes the dedup walk scan past the copied ACE array and inspect\nbuffer tail that does not contain valid ACEs.\n\nSplit the two meanings currently carried by the NT ACE count. Pass the\nnumber of copied NT ACEs to bound the dedup walk, and preserve the\noriginal \"input DACL had NT ACEs\" state separately for the\nEveryone/default ACL fallback.\n\nThis keeps the dedup walk aligned with the ACEs that are actually\npresent in the rebuilt DACL.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68098","epss":0.00414,"percentile":0.34858,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68098","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68099","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68099","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL  check_add_overflow() unconditionally writes the truncated sum into *d even on overflow, per its contract in include/linux/overflow.h. The four check_add_overflow() guards in set_posix_acl_entries_dacl() and set_ntacl_dacl() break out of the ACE-building loops on overflow, but the truncated *size is then consumed downstream at the end of set_ntacl_dacl():      pndacl->size = cpu_to_le16(le16_to_cpu(pndacl->size) + size);  This produces an on-wire NT ACL whose pndacl->size under-reports the bytes actually written by the preceding fill_ace_for_sid()/memcpy() calls, yielding a malformed ACL that can trigger out-of-bounds reads when re-parsed by clients or ksmbd itself.  Restore *size to its pre-addition value on each overflow branch (via `*size -= ace_sz` / `size -= nt_ace_size`) so that after the break, *size once again holds the cumulative size of the successfully-written ACEs. The committed ACL is then truncated-but-self-consistent rather than malformed.  The ksmbd DACL builders are the only check_add_overflow() sites found where an overflow path breaks out of a loop and the destination value is consumed afterward. The other nearby break-style cases either return -EINVAL on overflow (transport_ipc.c) or break without consuming the overflowed destination value afterward (buildid.c).","cvss":[],"epss":[{"cve":"CVE-2026-68099","epss":0.00173,"percentile":0.06831,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-68099","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68099","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0bf38372821b1526f31538a7d9811844c55c7f38","https://git.kernel.org/stable/c/847ecd4eb3c117c3d2f13f1e7ab506543aad8183","https://git.kernel.org/stable/c/8f3a7a499a7d9bb1c0f33fe78c4a4594d7e307f4","https://git.kernel.org/stable/c/bbf0a8e931204ecdab494a88d43b0a24a04285c5","https://git.kernel.org/stable/c/bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13","https://git.kernel.org/stable/c/f4fcd0c1a243d449307b887fafee23921e9db5ab"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL\n\ncheck_add_overflow() unconditionally writes the truncated sum into *d\neven on overflow, per its contract in include/linux/overflow.h.\nThe four check_add_overflow() guards in set_posix_acl_entries_dacl()\nand set_ntacl_dacl() break out of the ACE-building loops on overflow,\nbut the truncated *size is then consumed downstream at the end of\nset_ntacl_dacl():\n\n    pndacl->size = cpu_to_le16(le16_to_cpu(pndacl->size) + size);\n\nThis produces an on-wire NT ACL whose pndacl->size under-reports the\nbytes actually written by the preceding fill_ace_for_sid()/memcpy()\ncalls, yielding a malformed ACL that can trigger out-of-bounds reads\nwhen re-parsed by clients or ksmbd itself.\n\nRestore *size to its pre-addition value on each overflow branch (via\n`*size -= ace_sz` / `size -= nt_ace_size`) so that after the break,\n*size once again holds the cumulative size of the successfully-written\nACEs. The committed ACL is then truncated-but-self-consistent rather\nthan malformed.\n\nThe ksmbd DACL builders are the only check_add_overflow() sites found\nwhere an overflow path breaks out of a loop and the destination value\nis consumed afterward. The other nearby break-style cases either\nreturn -EINVAL on overflow (transport_ipc.c) or break without\nconsuming the overflowed destination value afterward (buildid.c).","cvss":[],"epss":[{"cve":"CVE-2026-68099","epss":0.00173,"percentile":0.06831,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68099","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68100","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68100","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl  set_ntacl_dacl() copies each ACE from the attacker-controlled stored security descriptor verbatim into the response DACL without checking sid.num_subauth. The ACE bytes (including an unchecked num_subauth) originate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is stored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE with `break` rather than an error, so parse_sec_desc() still returns success and the malformed SD reaches the xattr intact.  On a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a POSIX access ACL, build_sec_desc() -> set_ntacl_dacl() -> set_posix_acl_entries_dacl() walks the copied ACEs and reads      ntace->sid.sub_auth[ntace->sid.num_subauth - 1]  with num_subauth taken straight from the stored SD. Since sub_auth[] is fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g. 255) drives an out-of-bounds heap read of ~1 KB with an offset fully controlled by an authenticated client.  The sibling functions already gate this field:   parse_dacl()    -- num_subauth == 0 || > SID_MAX_SUB_AUTHORITIES   parse_sid()     -- num_subauth > SID_MAX_SUB_AUTHORITIES   smb_copy_sid()  -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES) set_ntacl_dacl() is the lone inconsistent path that omits the check.  Add the same num_subauth validation in set_ntacl_dacl() before copying the ACE, matching the gate already enforced by parse_dacl().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68100","epss":0.00435,"percentile":0.3672,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3393},"relatedVulnerabilities":[{"id":"CVE-2026-68100","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68100","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/26cb845e22a00c85bf566337417fa33492395f10","https://git.kernel.org/stable/c/47f0b34f6bc98ed85bfdc293e8f3e432ec24958d","https://git.kernel.org/stable/c/5acbd3012fd4a7ccfebd91ea6f784120084eb897","https://git.kernel.org/stable/c/b6d3cc6a524416dfdb2b47e4bba2e7e20011d056","https://git.kernel.org/stable/c/e31fada5143784bc05c7ae44c79eed9b7a2e147e","https://git.kernel.org/stable/c/fb3dc8e6da46a1ccad1956cda57de29d9b3033e0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate num_subauth when copying ACE in set_ntacl_dacl\n\nset_ntacl_dacl() copies each ACE from the attacker-controlled stored\nsecurity descriptor verbatim into the response DACL without checking\nsid.num_subauth. The ACE bytes (including an unchecked num_subauth)\noriginate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is\nstored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE\nwith `break` rather than an error, so parse_sec_desc() still returns\nsuccess and the malformed SD reaches the xattr intact.\n\nOn a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a\nPOSIX access ACL, build_sec_desc() -> set_ntacl_dacl() ->\nset_posix_acl_entries_dacl() walks the copied ACEs and reads\n\n    ntace->sid.sub_auth[ntace->sid.num_subauth - 1]\n\nwith num_subauth taken straight from the stored SD. Since sub_auth[]\nis fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g.\n255) drives an out-of-bounds heap read of ~1 KB with an offset fully\ncontrolled by an authenticated client.\n\nThe sibling functions already gate this field:\n  parse_dacl()    -- num_subauth == 0 || > SID_MAX_SUB_AUTHORITIES\n  parse_sid()     -- num_subauth > SID_MAX_SUB_AUTHORITIES\n  smb_copy_sid()  -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES)\nset_ntacl_dacl() is the lone inconsistent path that omits the check.\n\nAdd the same num_subauth validation in set_ntacl_dacl() before copying\nthe ACE, matching the gate already enforced by parse_dacl().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68100","epss":0.00435,"percentile":0.3672,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68100","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68102","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68102","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: fix aperture mapping leak  amdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver fini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to always return false, so iounmap(aper_base_kaddr) never runs on normal driver unload, leaving an orphaned entry in the x86 PAT interval tree.  On connected_to_cpu hardware, the aperture is mapped write-back (WB) via ioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC) over the same range. The WC vs WB conflict causes:    ioremap error for 0x..., requested 0x1, got 0x0   amdgpu: discovery failed: -2  Fix by switching to devres-managed mappings so cleanup is guaranteed regardless of drm_dev_enter() state:  - connected_to_cpu path: devm_memremap(MEMREMAP_WB). For   IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut,   returning __va(offset) from the existing kernel direct map. No new   ioremap VA or PAT entry is created, so there is nothing to orphan.  - dGPU path: devm_ioremap_wc() registers iounmap() as a devres action,   guaranteeing cleanup at device_del() time.  Also remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio() since the mapping is now devres-owned.  v2: Remove redundant x86_64 guard (Lijo)  (cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)","cvss":[],"epss":[{"cve":"CVE-2026-68102","epss":0.00168,"percentile":0.06311,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-68102","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68102","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/6405c4e75b3bcf0e72bd7a0ff5f1ed0c475e23aa","https://git.kernel.org/stable/c/67bc3647e418e23dc0d17604bdba634a73de809f","https://git.kernel.org/stable/c/a343d028ad6c174da8dc6af560c51e6d140a6727","https://git.kernel.org/stable/c/ea772a440d56b285f4d491affac50ecd41f6b402","https://git.kernel.org/stable/c/f5988b5c300a32ff751724ffd33d5a8d5873e4a7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix aperture mapping leak\n\namdgpu_pci_remove() calls drm_dev_unplug() before invoking the driver\nfini routines. This causes drm_dev_enter() in amdgpu_ttm_fini() to\nalways return false, so iounmap(aper_base_kaddr) never runs on normal\ndriver unload, leaving an orphaned entry in the x86 PAT interval tree.\n\nOn connected_to_cpu hardware, the aperture is mapped write-back (WB) via\nioremap_cache(). On reload, IP discovery calls memremap(..., MEMREMAP_WC)\nover the same range. The WC vs WB conflict causes:\n\n  ioremap error for 0x..., requested 0x1, got 0x0\n  amdgpu: discovery failed: -2\n\nFix by switching to devres-managed mappings so cleanup is guaranteed\nregardless of drm_dev_enter() state:\n\n- connected_to_cpu path: devm_memremap(MEMREMAP_WB). For\n  IORESOURCE_SYSTEM_RAM ranges this takes the try_ram_remap() shortcut,\n  returning __va(offset) from the existing kernel direct map. No new\n  ioremap VA or PAT entry is created, so there is nothing to orphan.\n\n- dGPU path: devm_ioremap_wc() registers iounmap() as a devres action,\n  guaranteeing cleanup at device_del() time.\n\nAlso remove iounmap(aper_base_kaddr) from amdgpu_device_unmap_mmio()\nsince the mapping is now devres-owned.\n\nv2: Remove redundant x86_64 guard (Lijo)\n\n(cherry picked from commit d871e99879cb5fd1fa798b006b4888887e63a17a)","cvss":[],"epss":[{"cve":"CVE-2026-68102","epss":0.00168,"percentile":0.06311,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68102","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68104","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68104","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: invoke pm_genpd_remove() before freeing genpd  Call pm_genpd_remove() to unregister from global list prior to releasing acp_genpd memory, and clear the pointer after free.  (cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68104","epss":0.00129,"percentile":0.02895,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68104","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68104","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/08fee493e0261f9e4120a5c8e7e42e8a723574e8","https://git.kernel.org/stable/c/28c9b3c5dc35cc790d11e26ca3fc6e068be63998","https://git.kernel.org/stable/c/2e406b86144c1f732eb344f1f1e09043856cfc33","https://git.kernel.org/stable/c/493adf29d66f23888f0e29888b6bc9512acd0825","https://git.kernel.org/stable/c/4d7c10b0bf09d90c81818752decbdb1966b62702","https://git.kernel.org/stable/c/5c0a82283271759fff445ac27182072f200a888c","https://git.kernel.org/stable/c/930a5dc3df4aa5e10393134bd5313d616dbebaf6","https://git.kernel.org/stable/c/bdfc7f1e0900ef1361b828c4f69b72701f8a0a86"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: invoke pm_genpd_remove() before freeing genpd\n\nCall pm_genpd_remove() to unregister from global list prior to releasing\nacp_genpd memory, and clear the pointer after free.\n\n(cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68104","epss":0.00129,"percentile":0.02895,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68104","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68106","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68106","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: fix division by zero with invalid uvd dimensions  When width or height is less than 16, width_in_mb or height_in_mb becomes 0, leading to fs_in_mb being 0. This causes a division by zero when calculating num_dpb_buffer in H264 and H264 Perf decode paths.  Add validation to reject frames with width < 16 or height < 16 before performing any calculations that depend on these values.  V2: Format change - move up all vaiable definitions. V3: Use warn_once to avoid spam.  (cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68106","epss":0.00129,"percentile":0.02912,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68106","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68106","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/004d0453cfef16f056cb7b8bc04f69f19cf9df32","https://git.kernel.org/stable/c/00ee64910ecf748cc15b23bbcbea472c203ec1e8","https://git.kernel.org/stable/c/0c01c811be47e6b146552dd59bfedbea8f09b8f4","https://git.kernel.org/stable/c/52f9a588296432accf2982f7d258192a37562f4f","https://git.kernel.org/stable/c/81c9b4921f62d1642b9d775524ae9240e521a5ed","https://git.kernel.org/stable/c/a00946b5ab7c25da5685ca9c58f50ff6f43c0fdf","https://git.kernel.org/stable/c/be725ab23aa45c11a5afef3e2a9f6d8c084ae5dc","https://git.kernel.org/stable/c/ffb33d466a68cea3e8a3dbed04d79037a3cbabd1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix division by zero with invalid uvd dimensions\n\nWhen width or height is less than 16, width_in_mb or height_in_mb\nbecomes 0, leading to fs_in_mb being 0. This causes a division by\nzero when calculating num_dpb_buffer in H264 and H264 Perf decode\npaths.\n\nAdd validation to reject frames with width < 16 or height < 16\nbefore performing any calculations that depend on these values.\n\nV2: Format change - move up all vaiable definitions.\nV3: Use warn_once to avoid spam.\n\n(cherry picked from commit 3e41d26c70b0a459d041cc19482a226c4b7423cb)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68106","epss":0.00129,"percentile":0.02912,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68106","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68108","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68108","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vce: fix integer overflow in image size  Fix a security vulnerability where malicious VCE command streams with oversized dimensions (e.g. 65536×65536) cause 32-bit integer overflow, wrapping the calculated buffer size to 0. This bypasses validation and allows GPU firmware to perform out-of-bound memory access.  The fix uses 64-bit arithmetic to detect overflow and rejects invalid dimensions before they reach the hardware.  V2: remove redundant check V3: modify max height value V4: remove size64  (cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68108","epss":0.00136,"percentile":0.03338,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11084000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68108","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68108","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/00c311a13d225266800c712f2b7db2711c6897de","https://git.kernel.org/stable/c/186bfdc4e26d019b2e7570cb121964a1d89b2e5b","https://git.kernel.org/stable/c/7eebef042c12dfe0568593ee6a8926d16505925e","https://git.kernel.org/stable/c/893db20383800cfe92e638705984eebb13bc81a5","https://git.kernel.org/stable/c/a07430abd556de3707adfcadcc60db3fa64e4b2b","https://git.kernel.org/stable/c/a6d7065b91a14790980ce6f4960db0ca8c3c9940"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vce: fix integer overflow in image size\n\nFix a security vulnerability where malicious VCE command streams\nwith oversized dimensions (e.g. 65536×65536) cause 32-bit integer\noverflow, wrapping the calculated buffer size to 0. This bypasses\nvalidation and allows GPU firmware to perform out-of-bound memory\naccess.\n\nThe fix uses 64-bit arithmetic to detect overflow and rejects\ninvalid dimensions before they reach the hardware.\n\nV2: remove redundant check\nV3: modify max height value\nV4: remove size64\n\n(cherry picked from commit cbe408dba581755ad1279a487ec786d8927d778d)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68108","epss":0.00136,"percentile":0.03338,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68108","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68111","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68111","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()  There's no need to crash the kernel for these cases.  (cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)","cvss":[],"epss":[{"cve":"CVE-2026-68111","epss":0.00177,"percentile":0.07335,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68111","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68111","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/042c047e8bc9c9ada7574028a8e4592102e2e1fd","https://git.kernel.org/stable/c/43768ad42b8f1a91652b86e0731ac14d6853cebb","https://git.kernel.org/stable/c/6302be10b521f5106ce01eb5a724b9e7945a5061","https://git.kernel.org/stable/c/67965f576f9337e387dc8efaf9a46cb6b7ea12cb","https://git.kernel.org/stable/c/6978b10861850b93292fcd6b22a5495d69fce276","https://git.kernel.org/stable/c/6c8b9c1f03c7169c9577098b0c3035617606f8d4","https://git.kernel.org/stable/c/9b5e4fa18fea1e7f6017e1af02fa10276628d9a0","https://git.kernel.org/stable/c/d74a6351d3f64e1f8a0fba28b369c0eeecf517f1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()\n\nThere's no need to crash the kernel for these cases.\n\n(cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)","cvss":[],"epss":[{"cve":"CVE-2026-68111","epss":0.00177,"percentile":0.07335,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68111","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68112","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68112","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()  There's no need to crash the kernel for these cases.  (cherry picked from commit 5676593d08998d7a6d9e2d51d6b54b3820e3755c)","cvss":[],"epss":[{"cve":"CVE-2026-68112","epss":0.00168,"percentile":0.0631,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-68112","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68112","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/00f4050f7c367d7bdce347ca279ce467c434cf15","https://git.kernel.org/stable/c/05aea3344c422fe95299bb1b21a04de30c7ea198","https://git.kernel.org/stable/c/ac89ea915e8b848c7cbe97b1aad2dc4f5770c6d7","https://git.kernel.org/stable/c/c59b57c2e0c8cced4350ff7792361ba2a79ee85c","https://git.kernel.org/stable/c/cfb02825277526bd216b56be555a97a9e8612682"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()\n\nThere's no need to crash the kernel for these cases.\n\n(cherry picked from commit 5676593d08998d7a6d9e2d51d6b54b3820e3755c)","cvss":[],"epss":[{"cve":"CVE-2026-68112","epss":0.00168,"percentile":0.0631,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68112","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68115","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68115","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()  There's no need to crash the kernel for these cases.  (cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)","cvss":[],"epss":[{"cve":"CVE-2026-68115","epss":0.00177,"percentile":0.07337,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68115","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68115","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2929a932b0d70f481dbcb6994181544b07913de0","https://git.kernel.org/stable/c/5c23b018c64f9e8f28e407f313616dccd51b684f","https://git.kernel.org/stable/c/6c8cfdc2321c1284dc4320ac148867ea8f6419bd","https://git.kernel.org/stable/c/793cdf17ddf9dc662a94cae86ce005565ef3c1c2","https://git.kernel.org/stable/c/7e22de67e545d0f72595514d3a66675e9d074adc","https://git.kernel.org/stable/c/a5de4c9065db8653a3af8a1d4cf5f3c0024c480a","https://git.kernel.org/stable/c/d06c4173a7c38c7a39e98859f839ce714c7af2c9","https://git.kernel.org/stable/c/e994f4391b574bd57e7ac183ab93c3d60e8d4d55"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()\n\nThere's no need to crash the kernel for these cases.\n\n(cherry picked from commit ac6f00beb658239bced4aaed9efbb04a35348d48)","cvss":[],"epss":[{"cve":"CVE-2026-68115","epss":0.00177,"percentile":0.07337,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68115","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68117","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: clear sock->sk on the failed-insert path in tipc_sk_create()  When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves sock->sk pointing at the freed object:  \tif (tipc_sk_insert(tsk)) { \t\tsk_free(sk); \t\tpr_warn(\"Socket create failed; port number exhausted\\n\"); \t\treturn -EINVAL; \t}  This is harmless for plain socket(): the syscall layer clears sock->ops before releasing, so tipc_release() is never called. It is not harmless on the accept() path. tipc_accept() creates the pre-allocated child socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves new_sock->sk dangling and new_sock->ops non-NULL, and do_accept() then fput()s the new file, so __sock_release() -> tipc_release() runs lock_sock(new_sock->sk) on the freed sk -- a use-after-free write of the sk_lock spinlock.  tipc_release() already guards this exact \"failed accept() releases a pre-allocated child\" case with \"if (sk == NULL) return 0;\", but the guard is bypassed because tipc_sk_create() left sock->sk non-NULL (dangling) rather than NULL.  Clear sock->sk on the failed-insert path so the existing tipc_release() NULL check fires and the use-after-free is avoided.  The tipc_sk_insert() failure is reached when the per-netns socket rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M elements) -- i.e. once a netns holds ~2M TIPC sockets every insert returns -E2BIG.    BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)   Write of size 8 at addr ffff8880047cdc38 by task init/1    lock_sock_nested (net/core/sock.c:3839)    tipc_release (net/tipc/socket.c:638)    __sock_release (net/socket.c:710)    sock_close (net/socket.c:1501)    __fput (fs/file_table.c:512)   Allocated by task 1:    sk_alloc (net/core/sock.c:2308)    tipc_sk_create (net/tipc/socket.c:487)    tipc_accept (net/tipc/socket.c:2744)    do_accept (net/socket.c:2034)   Freed by task 1:    __sk_destruct (net/core/sock.c:2391)    tipc_sk_create (net/tipc/socket.c:504)    tipc_accept (net/tipc/socket.c:2744)    do_accept (net/socket.c:2034)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68117","epss":0.00531,"percentile":0.43192,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.49914000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-68117","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68117","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/5f5a41a48dbf9eda57b67ce23e548602cf7195a6","https://git.kernel.org/stable/c/82f59aa27f33bd014a7d8739371ab5712d15e33b","https://git.kernel.org/stable/c/8d6f26d48e61ef34f1921289401dbf36b10816af","https://git.kernel.org/stable/c/b07d87b31631edb6529e6cdcca790a7489d1250d","https://git.kernel.org/stable/c/ba0533fc163f905fe817cfabdf8ed4058da44800","https://git.kernel.org/stable/c/dd29891ed840f6b8d020b759d0dc4a00b1d6e4ea","https://git.kernel.org/stable/c/efebc23e9b29e3e5a9e2127dd066929f7f0d315e","https://git.kernel.org/stable/c/f9596b1566616a8be0592dbceccb6344a7c6f6bb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: clear sock->sk on the failed-insert path in tipc_sk_create()\n\nWhen tipc_sk_create() fails to insert the new socket (tipc_sk_insert()\nreturns non-zero), its error path frees the sk with sk_free() but leaves\nsock->sk pointing at the freed object:\n\n\tif (tipc_sk_insert(tsk)) {\n\t\tsk_free(sk);\n\t\tpr_warn(\"Socket create failed; port number exhausted\\n\");\n\t\treturn -EINVAL;\n\t}\n\nThis is harmless for plain socket(): the syscall layer clears sock->ops\nbefore releasing, so tipc_release() is never called. It is not harmless\non the accept() path. tipc_accept() creates the pre-allocated child\nsocket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves\nnew_sock->sk dangling and new_sock->ops non-NULL, and do_accept() then\nfput()s the new file, so __sock_release() -> tipc_release() runs\nlock_sock(new_sock->sk) on the freed sk -- a use-after-free write of the\nsk_lock spinlock.\n\ntipc_release() already guards this exact \"failed accept() releases a\npre-allocated child\" case with \"if (sk == NULL) return 0;\", but the\nguard is bypassed because tipc_sk_create() left sock->sk non-NULL\n(dangling) rather than NULL.\n\nClear sock->sk on the failed-insert path so the existing tipc_release()\nNULL check fires and the use-after-free is avoided.\n\nThe tipc_sk_insert() failure is reached when the per-netns socket\nrhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M\nelements) -- i.e. once a netns holds ~2M TIPC sockets every insert\nreturns -E2BIG.\n\n  BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)\n  Write of size 8 at addr ffff8880047cdc38 by task init/1\n   lock_sock_nested (net/core/sock.c:3839)\n   tipc_release (net/tipc/socket.c:638)\n   __sock_release (net/socket.c:710)\n   sock_close (net/socket.c:1501)\n   __fput (fs/file_table.c:512)\n  Allocated by task 1:\n   sk_alloc (net/core/sock.c:2308)\n   tipc_sk_create (net/tipc/socket.c:487)\n   tipc_accept (net/tipc/socket.c:2744)\n   do_accept (net/socket.c:2034)\n  Freed by task 1:\n   __sk_destruct (net/core/sock.c:2391)\n   tipc_sk_create (net/tipc/socket.c:504)\n   tipc_accept (net/tipc/socket.c:2744)\n   do_accept (net/socket.c:2034)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68117","epss":0.00531,"percentile":0.43192,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68117","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68118","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68118","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tcp: challenge ACK for non-exact RST in SYN-RECEIVED  The SYN-RECEIVED request-socket path in tcp_check_req() accepts an in-window RST without requiring SEG.SEQ to exactly match RCV.NXT.  A non-exact RST therefore removes the request instead of eliciting a challenge ACK.  RFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in SYN-RECEIVED: an exact RST resets the connection, while a non-exact in-window RST must trigger a challenge ACK and be dropped.  Apply that check before the ACK-field validation, following the RFC sequence-number, RST, then ACK processing order.  Factor the per-netns challenge ACK quota out of tcp_send_challenge_ack() so request sockets can share it.  Use the request socket's send_ack() callback and its own out-of-window ACK timestamp to send and rate-limit the response.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68118","epss":0.00391,"percentile":0.32539,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.30693499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-68118","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68118","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0fe4636665d14a258de70b4f3e8248e6d42038f1","https://git.kernel.org/stable/c/22cec809b048495310f206d9abbcdbbfbdce3ae3","https://git.kernel.org/stable/c/234f9ffbd9b2c1b24ec67200ea3cff07401bec48","https://git.kernel.org/stable/c/8b0a3a094f4cae2fb92e4d08d4eef7246a9d9c49","https://git.kernel.org/stable/c/a28c4fcbf774e23b4779cae468e3497a5ad1f4a1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: challenge ACK for non-exact RST in SYN-RECEIVED\n\nThe SYN-RECEIVED request-socket path in tcp_check_req() accepts an\nin-window RST without requiring SEG.SEQ to exactly match RCV.NXT.  A\nnon-exact RST therefore removes the request instead of eliciting a\nchallenge ACK.\n\nRFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in\nSYN-RECEIVED: an exact RST resets the connection, while a non-exact\nin-window RST must trigger a challenge ACK and be dropped.\n\nApply that check before the ACK-field validation, following the RFC\nsequence-number, RST, then ACK processing order.  Factor the per-netns\nchallenge ACK quota out of tcp_send_challenge_ack() so request sockets\ncan share it.  Use the request socket's send_ack() callback and its own\nout-of-window ACK timestamp to send and rate-limit the response.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68118","epss":0.00391,"percentile":0.32539,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68118","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68121","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68121","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pppoe: reload header pointer after dev_hard_header()  pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it.  This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head.  Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68121","epss":0.00138,"percentile":0.03556,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-68121","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68121","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6866abf59976d273164a6624234d96a967280223","https://git.kernel.org/stable/c/6eed5ae7887a93160803d2b81ff88e75eefd4a4c","https://git.kernel.org/stable/c/7a56e7c9b08e08fd55a1bcada24cf4fe3782b722","https://git.kernel.org/stable/c/7e9fbd7f96bcde63a7c798fe16b38cedee7a1501","https://git.kernel.org/stable/c/ba3409369c5413cdf0dcbf3a928f76b48e8c3e6a","https://git.kernel.org/stable/c/bed4caecd723693f750e13adbb2c42ca1249a3fd","https://git.kernel.org/stable/c/e6493a4d1ee17595766165fa446d45b7e0c318d0","https://git.kernel.org/stable/c/e9c238f6fe42fb1b4dba3a578277de32cb487937"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npppoe: reload header pointer after dev_hard_header()\n\npppoe_sendmsg() saves a pointer to the PPPoE header before calling\ndev_hard_header(). Device header callbacks are allowed to reallocate the\nskb head, invalidating pointers into it.\n\nThis can happen when a send is blocked in copy_from_user() while the first\nnon-Ethernet port is added to an empty team device. The team's delegated\nGRE header callback then expands the skb head. PPPoE subsequently writes\nsix bytes through the stale pointer into the freed head.\n\nReload the PPPoE header through the skb's network-header offset after\ndevice header creation. pskb_expand_head() updates that offset when it\nrelocates the head.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68121","epss":0.00138,"percentile":0.03556,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68121","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68123","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68123","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  openvswitch: fix GSO userspace truncation underflow  OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb length in OVS_CB(skb)->cutlen. When a later userspace action segments a GSO skb, queue_gso_packets() reuses that delta for each smaller segment. A segment can then reach queue_userspace_packet() with cutlen greater than skb->len, underflowing the length passed to skb_zerocopy().  Store the maximum preserved length instead and bound each consumer against the current skb length. Use U32_MAX as the no-truncation sentinel so the value remains valid if skb geometry changes before a consumer handles it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68123","epss":0.00559,"percentile":0.44681,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.52546},"relatedVulnerabilities":[{"id":"CVE-2026-68123","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68123","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/100a23b1613e9218e0af654ef102352c713f0263","https://git.kernel.org/stable/c/2623c48cc3a8da9a1886fd8f65c0e348f4406fd6","https://git.kernel.org/stable/c/4032f8ed10fcb84d41c508dfb04be96589f78dfe","https://git.kernel.org/stable/c/50a6a85f3d6b1d22d8436848606cdef5d2c490b4","https://git.kernel.org/stable/c/a16eaaf7c0b0ccdef6166707d90ffbc6eebf6855","https://git.kernel.org/stable/c/e211b081901ffca76674082c73eeaed53524c369","https://git.kernel.org/stable/c/ea85dbcbe8d4056ecb54352f97743d138ea4c407","https://git.kernel.org/stable/c/fbfa3ad2ad6f3a5624aba5211c46290fb98cc9dc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: fix GSO userspace truncation underflow\n\nOVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb\nlength in OVS_CB(skb)->cutlen. When a later userspace action segments a\nGSO skb, queue_gso_packets() reuses that delta for each smaller segment.\nA segment can then reach queue_userspace_packet() with cutlen greater\nthan skb->len, underflowing the length passed to skb_zerocopy().\n\nStore the maximum preserved length instead and bound each consumer\nagainst the current skb length. Use U32_MAX as the no-truncation\nsentinel so the value remains valid if skb geometry changes before a\nconsumer handles it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68123","epss":0.00559,"percentile":0.44681,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68123","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68124","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68124","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mctp: serial: handle zero-length frames to prevent rx buffer overflow  The MCTP serial receive state machine reads a frame length byte in mctp_serial_push_header() case 2 and validates it upper-bound-only:  \tif (c > MCTP_SERIAL_FRAME_MTU) { \t\tdev->rxstate = STATE_ERR; \t} else { \t\tdev->rxlen = c; \t\tdev->rxpos = 0; \t\tdev->rxstate = STATE_DATA; \t\t... \t}  A length of zero passes this check, so rxlen is set to 0 and the state machine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the incoming byte is stored and rxpos incremented before the terminator is  \tdev->rxbuf[dev->rxpos] = c; \tdev->rxpos++; \tdev->rxstate = STATE_DATA; \tif (dev->rxpos == dev->rxlen) { \t\tdev->rxpos = 0; \t\tdev->rxstate = STATE_TRAILER; \t}  With rxlen == 0 the \"rxpos == rxlen\" terminator can never fire (rxpos is already 1 on the first data byte), so subsequent bytes are written past the end of the fixed 74-byte rxbuf, which is the last member of the netdev private area. Every following data byte is an attacker-controlled 1-byte out-of-bounds heap write, and the overflow continues until a frame (0x7e) or escape byte resets the parser -- effectively unbounded.  Reaching this requires CAP_NET_ADMIN to attach the N_MCTP line discipline and bring the resulting mctpserialN netdev up, after which the bytes arrive via the tty receive path.  Route a zero-length frame straight to STATE_TRAILER instead of STATE_DATA. The trailer/framing bytes are still consumed, and the frame resolves to a zero-length skb that the MCTP core rejects; the parser never enters STATE_DATA with rxlen == 0, so the out-of-bounds write can no longer occur.  KASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this change):    UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370   index 74 is out of range for type 'u8 [74]'   BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf   Write of size 1 at addr ... by task kworker/u16:0    mctp_serial_tty_receive_buf    tty_ldisc_receive_buf    flush_to_ldisc   Allocated by task 152:    alloc_netdev_mqs    mctp_serial_open  v2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so     the trailer/framing bytes are still consumed (Jeremy Kerr).  Found by 0sec automated security-research tooling (https://0sec.ai).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"exploitabilityScore":2.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68124","epss":0.00343,"percentile":0.27416,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.31899},"relatedVulnerabilities":[{"id":"CVE-2026-68124","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68124","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/06a6b606129c8a25cd457760f5370f3ff01fe05d","https://git.kernel.org/stable/c/36dc6d6964a3b90411cc7944cd9b8b6f67b9807b","https://git.kernel.org/stable/c/64b96ae7912244d55257aa330d9569ee0a8f8d99","https://git.kernel.org/stable/c/68819427bc07eca7963a9e8be19e5272cc29186c","https://git.kernel.org/stable/c/793b9b729f1e8de57be8c8daf1a9838be96cabed","https://git.kernel.org/stable/c/f80ba170d7b3a44e3d244a2c8e06031d61bf3b23"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmctp: serial: handle zero-length frames to prevent rx buffer overflow\n\nThe MCTP serial receive state machine reads a frame length byte in\nmctp_serial_push_header() case 2 and validates it upper-bound-only:\n\n\tif (c > MCTP_SERIAL_FRAME_MTU) {\n\t\tdev->rxstate = STATE_ERR;\n\t} else {\n\t\tdev->rxlen = c;\n\t\tdev->rxpos = 0;\n\t\tdev->rxstate = STATE_DATA;\n\t\t...\n\t}\n\nA length of zero passes this check, so rxlen is set to 0 and the state\nmachine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the\nincoming byte is stored and rxpos incremented before the terminator is\n\n\tdev->rxbuf[dev->rxpos] = c;\n\tdev->rxpos++;\n\tdev->rxstate = STATE_DATA;\n\tif (dev->rxpos == dev->rxlen) {\n\t\tdev->rxpos = 0;\n\t\tdev->rxstate = STATE_TRAILER;\n\t}\n\nWith rxlen == 0 the \"rxpos == rxlen\" terminator can never fire (rxpos is\nalready 1 on the first data byte), so subsequent bytes are written past\nthe end of the fixed 74-byte rxbuf, which is the last member of the\nnetdev private area. Every following data byte is an attacker-controlled\n1-byte out-of-bounds heap write, and the overflow continues until a\nframe (0x7e) or escape byte resets the parser -- effectively unbounded.\n\nReaching this requires CAP_NET_ADMIN to attach the N_MCTP line\ndiscipline and bring the resulting mctpserialN netdev up, after which\nthe bytes arrive via the tty receive path.\n\nRoute a zero-length frame straight to STATE_TRAILER instead of\nSTATE_DATA. The trailer/framing bytes are still consumed, and the frame\nresolves to a zero-length skb that the MCTP core rejects; the parser\nnever enters STATE_DATA with rxlen == 0, so the out-of-bounds write can\nno longer occur.\n\nKASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this\nchange):\n\n  UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370\n  index 74 is out of range for type 'u8 [74]'\n  BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf\n  Write of size 1 at addr ... by task kworker/u16:0\n   mctp_serial_tty_receive_buf\n   tty_ldisc_receive_buf\n   flush_to_ldisc\n  Allocated by task 152:\n   alloc_netdev_mqs\n   mctp_serial_open\n\nv2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so\n    the trailer/framing bytes are still consumed (Jeremy Kerr).\n\nFound by 0sec automated security-research tooling (https://0sec.ai).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"exploitabilityScore":2.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68124","epss":0.00343,"percentile":0.27416,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68124","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68125","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68125","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mac802154: llsec: reject frames shorter than the authentication tag  llsec_do_decrypt_auth() computes the associated-data length for the AEAD request as  \tassoclen += datalen - authlen;  where datalen is the number of bytes after the MAC header and authlen (4, 8 or 16) is the length of the authentication tag. Nothing verifies that the frame actually carries at least authlen payload bytes. A secured frame whose payload is shorter than the tag makes datalen - authlen negative; assoclen is then passed to aead_request_set_ad() as an unsigned value close to 4 GiB, so crypto_aead_decrypt() walks far off the end of the scatterlist that only spans the real frame.  The frame is fully attacker-controlled and reaches this path from any IEEE 802.15.4 peer in radio range. Reject frames whose payload is shorter than the authentication tag before the subtraction.  Dynamically reproduced on a KASAN kernel as a general-protection-fault in the AEAD scatterwalk, and the fix confirmed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68125","epss":0.00316,"percentile":0.24284,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.25754000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-68125","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68125","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2d6b42a61373144298070668fddf06efe79cf2ff","https://git.kernel.org/stable/c/5bbf0cd9b6a7076af86c75e87e180099be2e11ae","https://git.kernel.org/stable/c/de80808f37d99c6dc67bb6f97eea00c8f57a8821","https://git.kernel.org/stable/c/e09e0301d616c1ef38a5e64e8e4326fd39df13cc","https://git.kernel.org/stable/c/ec7e62d77193131227df49d654d118fdf5a59892","https://git.kernel.org/stable/c/f20dedce0429b293d4bad604e0d3f65d8ac96c83","https://git.kernel.org/stable/c/f27ce82eb04960465df71634b196a48a4ecafd50","https://git.kernel.org/stable/c/fd3a3f28ed60c6af4b2a39933b151d6b27842c3b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: llsec: reject frames shorter than the authentication tag\n\nllsec_do_decrypt_auth() computes the associated-data length for the\nAEAD request as\n\n\tassoclen += datalen - authlen;\n\nwhere datalen is the number of bytes after the MAC header and authlen\n(4, 8 or 16) is the length of the authentication tag. Nothing verifies\nthat the frame actually carries at least authlen payload bytes. A\nsecured frame whose payload is shorter than the tag makes\ndatalen - authlen negative; assoclen is then passed to\naead_request_set_ad() as an unsigned value close to 4 GiB, so\ncrypto_aead_decrypt() walks far off the end of the scatterlist that\nonly spans the real frame.\n\nThe frame is fully attacker-controlled and reaches this path from any\nIEEE 802.15.4 peer in radio range. Reject frames whose payload is\nshorter than the authentication tag before the subtraction.\n\nDynamically reproduced on a KASAN kernel as a general-protection-fault\nin the AEAD scatterwalk, and the fix confirmed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68125","epss":0.00316,"percentile":0.24284,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68125","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68127","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68127","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ila: reload IPv6 header after pskb_may_pull in checksum adjust  ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling pskb_may_pull(). On a non-linear skb whose transport header sits in a page fragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head() and free the old skb head, leaving ip6h dangling; the following get_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator() uses ip6h (and the iaddr derived from it) again after the csum-adjust call and additionally writes the new locator through that pointer.  Impact: a remote IPv6 packet routed through a configured ILA csum-adjust-transport route or receive-side mapping triggers a slab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or mapping requires CAP_NET_ADMIN to configure, but trigger packets are unauthenticated once it exists.  Reload ip6h after each pskb_may_pull() in ila_csum_adjust_transport() before the csum-diff read. In ila_update_ipv6_locator() only the ILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in that case alone before the destination-address write; the neutral-map modes never pull and keep their cached pointers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68127","epss":0.00543,"percentile":0.43852,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.5104200000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68127","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68127","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1eadcb43893b897ade85ac5bf5c618054bc3c655","https://git.kernel.org/stable/c/472aba2603ca74c4f7722cb0c0296942b0776b8d","https://git.kernel.org/stable/c/7097a0280b178237265681be66d1bef11d15894b","https://git.kernel.org/stable/c/896a9512d0d83c2a4b357e5585b7b62a8e3f95c1","https://git.kernel.org/stable/c/92d3817649df2b0b6a008a686c8275c88d7ef594","https://git.kernel.org/stable/c/ba353caafb06ccee57b78d3254e3cebf1dea4a93","https://git.kernel.org/stable/c/c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc","https://git.kernel.org/stable/c/e451a904606c571f731ef7a06b3398619dce5300"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nila: reload IPv6 header after pskb_may_pull in checksum adjust\n\nila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling\npskb_may_pull(). On a non-linear skb whose transport header sits in a page\nfragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()\nand free the old skb head, leaving ip6h dangling; the following\nget_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()\nuses ip6h (and the iaddr derived from it) again after the csum-adjust\ncall and additionally writes the new locator through that pointer.\n\nImpact: a remote IPv6 packet routed through a configured ILA\ncsum-adjust-transport route or receive-side mapping triggers a\nslab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or\nmapping requires CAP_NET_ADMIN to configure, but trigger packets are\nunauthenticated once it exists.\n\nReload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()\nbefore the csum-diff read. In ila_update_ipv6_locator() only the\nILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in\nthat case alone before the destination-address write; the neutral-map\nmodes never pull and keep their cached pointers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68127","epss":0.00543,"percentile":0.43852,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68127","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68129","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68129","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gve: fix Rx queue stall on alloc failure  When the system is under extreme memory pressure, page allocations can fail during the Rx buffer refill loop. If the number of buffers posted to hardware falls below a critical low threshold and the refill loop exits due to allocation failures, the queue can stall:  1. The device drops incoming packets because there are no descriptors. 2. Since no packets are processed, no Rx completions are generated. 3. Because no completions occur, NAPI is never scheduled, preventing    the refill loop from running again even after memory is freed.  This results in a permanent queue stall.  Resolve this by introducing a starvation recovery timer for each Rx queue. If the number of buffers posted to hardware falls below a critical low threshold, start a timer to periodically reschedule NAPI. Once NAPI runs and successfully refills the queue above the threshold, the timer is not rescheduled.  The threshold is set to 32 because a single maximum-sized Receive Segment Coalescing (RSC) packet can consume up to 19 descriptors in the Rx path. Lower thresholds (such as 8 or 16) would be insufficient to process a complete maximum-sized RSC packet, risking packet drops or unexpected hardware behavior under memory pressure. Setting the threshold to 32 guarantees a safe margin to handle at least one full RSC packet.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68129","epss":0.00511,"percentile":0.41946,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.38325},"relatedVulnerabilities":[{"id":"CVE-2026-68129","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68129","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0c317349b4baa5038d1fc373bf46d5a2419d1710","https://git.kernel.org/stable/c/299d5728a7312fdd02059b074aebbe4ebbd391e4","https://git.kernel.org/stable/c/42d525e751c61b876b2b0ae4e71ba7a8ab0c2777","https://git.kernel.org/stable/c/689b9f588d2d7323dc66293fe594a68d030f400f","https://git.kernel.org/stable/c/91e0249f3ef62b75fe8c9c9372eaba32876e4b3a","https://git.kernel.org/stable/c/9db46e19e5d6bdcd4bf811284a5b0df1b984ef80","https://git.kernel.org/stable/c/b65352a1bac64442ad95e64f385b40ccb9f1b0db"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngve: fix Rx queue stall on alloc failure\n\nWhen the system is under extreme memory pressure, page allocations can\nfail during the Rx buffer refill loop. If the number of buffers posted\nto hardware falls below a critical low threshold and the refill loop\nexits due to allocation failures, the queue can stall:\n\n1. The device drops incoming packets because there are no descriptors.\n2. Since no packets are processed, no Rx completions are generated.\n3. Because no completions occur, NAPI is never scheduled, preventing\n   the refill loop from running again even after memory is freed.\n\nThis results in a permanent queue stall.\n\nResolve this by introducing a starvation recovery timer for each Rx queue.\nIf the number of buffers posted to hardware falls below a critical low\nthreshold, start a timer to periodically reschedule NAPI. Once NAPI runs\nand successfully refills the queue above the threshold, the timer is\nnot rescheduled.\n\nThe threshold is set to 32 because a single maximum-sized Receive Segment\nCoalescing (RSC) packet can consume up to 19 descriptors in the Rx path.\nLower thresholds (such as 8 or 16) would be insufficient to process a\ncomplete maximum-sized RSC packet, risking packet drops or unexpected\nhardware behavior under memory pressure. Setting the threshold to 32\nguarantees a safe margin to handle at least one full RSC packet.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68129","epss":0.00511,"percentile":0.41946,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68129","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68130","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68130","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: defer destroy_previous_session() until after NTLM authentication  In ntlm_authenticate(), destroy_previous_session() is called using a user pointer resolved from the client-supplied NTLM blob username field before the NTLMv2 response is validated. An authenticated attacker can set the NTLM blob username to match a victim account and set PreviousSessionId to the victim's session ID; destroy_previous_session() destroys the victim's session while ksmbd_decode_ntlmssp_auth_blob() subsequently rejects the request with -EPERM.  Move destroy_previous_session() and the prev_id assignment to after ksmbd_decode_ntlmssp_auth_blob() returns success and use sess->user rather than the pre-authentication lookup result. This matches the ordering already used by krb5_authenticate(), where destroy_previous_session() is called only after ksmbd_krb5_authenticate() returns success.","cvss":[],"epss":[{"cve":"CVE-2026-68130","epss":0.00216,"percentile":0.12014,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.108},"relatedVulnerabilities":[{"id":"CVE-2026-68130","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68130","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0ff12308c8a6c16ab68f0a487ffa93d69001dc18","https://git.kernel.org/stable/c/18705cace0619fd2123737dcd028147774f38181","https://git.kernel.org/stable/c/243f1614ef2aca2d62a744575f1c24b07cd42757","https://git.kernel.org/stable/c/370b0ec8822b69c9073265e16b7daaa8201c9a4f","https://git.kernel.org/stable/c/5c833074b549e5db125436a6f681af682261f785","https://git.kernel.org/stable/c/ab0230257ebdf48b07eaa679a8c92bc842fe3498","https://git.kernel.org/stable/c/c74801ee524f477c174a1899782b6c3b6918d407"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: defer destroy_previous_session() until after NTLM authentication\n\nIn ntlm_authenticate(), destroy_previous_session() is called using a\nuser pointer resolved from the client-supplied NTLM blob username field\nbefore the NTLMv2 response is validated. An authenticated attacker can\nset the NTLM blob username to match a victim account and set\nPreviousSessionId to the victim's session ID; destroy_previous_session()\ndestroys the victim's session while ksmbd_decode_ntlmssp_auth_blob()\nsubsequently rejects the request with -EPERM.\n\nMove destroy_previous_session() and the prev_id assignment to after\nksmbd_decode_ntlmssp_auth_blob() returns success and use sess->user\nrather than the pre-authentication lookup result. This matches the\nordering already used by krb5_authenticate(), where\ndestroy_previous_session() is called only after\nksmbd_krb5_authenticate() returns success.","cvss":[],"epss":[{"cve":"CVE-2026-68130","epss":0.00216,"percentile":0.12014,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68130","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68131","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68131","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rbd: Reset positive result codes to zero in object map update path  In a reply message to an RBD request, a positive result code indicates a data payload, which is not allowed for writes. While rbd_osd_req_callback() already resets a positive result code for writes to zero, rbd_object_map_callback() does not. This allows a corrupted reply to an object map update to trigger the rbd_assert(*result < 0) in __rbd_obj_handle_request(). This happens, because rbd_object_map_callback() calls rbd_obj_handle_request() -> __rbd_obj_handle_request() and passes this positive result code. From __rbd_obj_handle_request(), rbd_obj_advance_write() is called, which leaves the positive result code unchanged and returns true. Therefore, the if(done && *result) branch is executed in __rbd_obj_handle_request() and the assertion triggers.  This patch fixes the issue by adjusting the logic in the rbd_object_map_callback() path. A positive result code for an object map update is now reset to zero (similar to rbd_osd_req_callback()), and the message is subsequently handled the same way as if the result code was zero from the beginning. Additionally, a WARN_ON_ONCE() is added for this case.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68131","epss":0.00523,"percentile":0.42727,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.39225000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-68131","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68131","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/14995c4250f04b58bf6fc00e0e973a2e1b3cfb9b","https://git.kernel.org/stable/c/2419aa74081007dc4d14ff5640659052dfdfd69a","https://git.kernel.org/stable/c/34f2a2f32af570dfcc532ad70c080629ee1c32b0","https://git.kernel.org/stable/c/6f33d9d539fb94e5a17589c2dfe271ff9bb64904","https://git.kernel.org/stable/c/a6c4250b81bd30beae94e1b7a4b26fa1193ad2e4","https://git.kernel.org/stable/c/b1a61366933224b3ad80975c4d01ac2cc6931ecf","https://git.kernel.org/stable/c/cf1167292f606deaddac35ec384eba48f08a68d2","https://git.kernel.org/stable/c/da926959bf791441ba06a80571708c3d0d3cc08f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrbd: Reset positive result codes to zero in object map update path\n\nIn a reply message to an RBD request, a positive result code indicates\na data payload, which is not allowed for writes. While\nrbd_osd_req_callback() already resets a positive result code for writes\nto zero, rbd_object_map_callback() does not. This allows a corrupted\nreply to an object map update to trigger the rbd_assert(*result < 0) in\n__rbd_obj_handle_request(). This happens, because\nrbd_object_map_callback() calls rbd_obj_handle_request() ->\n__rbd_obj_handle_request() and passes this positive result code. From\n__rbd_obj_handle_request(), rbd_obj_advance_write() is called, which\nleaves the positive result code unchanged and returns true. Therefore,\nthe if(done && *result) branch is executed in __rbd_obj_handle_request()\nand the assertion triggers.\n\nThis patch fixes the issue by adjusting the logic in the\nrbd_object_map_callback() path. A positive result code for an object map\nupdate is now reset to zero (similar to rbd_osd_req_callback()), and the\nmessage is subsequently handled the same way as if the result code was\nzero from the beginning. Additionally, a WARN_ON_ONCE() is added for\nthis case.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68131","epss":0.00523,"percentile":0.42727,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68131","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68132","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68132","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  super: fix emergency thaw deadlock on frozen block devices  do_thaw_all_callback() calls bdev_thaw() while holding sb->s_umount exclusively. If the block device was frozen via bdev_freeze() dropping the last block layer freeze reference calls fs_bdev_thaw() which reacquires s_umount:    do_thaw_all_callback(sb)     super_lock_excl(sb)                     # holds sb->s_umount     bdev_thaw(sb->s_bdev)       mutex_lock(&bdev->bd_fsfreeze_mutex)       # bd_fsfreeze_count drops 1 -> 0       bd_holder_ops->thaw == fs_bdev_thaw         get_bdev_super(bdev)           bdev_super_lock(bdev, true)             super_lock(sb, true)               down_write(&sb->s_umount)     # same task: deadlock  The emergency thaw worker deadlocks against itself holding both s_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount, freeze, or thaw of that filesystem and block device.    [   81.878470] sysrq: Show Blocked State   [   81.880140] task:kworker/0:1     state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208060 flags:0x00080000   [   81.884876] Workqueue: events do_thaw_all   [   81.886656] Call Trace:   [   81.887759]  <TASK>   [   81.888763]  __schedule+0x579/0x1420   [   81.890372]  schedule+0x3a/0x100   [   81.891794]  schedule_preempt_disabled+0x15/0x30   [   81.893848]  rwsem_down_write_slowpath+0x1ea/0x900   [   81.895191]  ? __pfx_do_thaw_all_callback+0x10/0x10   [   81.896528]  down_write+0xbd/0xc0   [   81.897505]  super_lock+0x91/0x180   [   81.898457]  ? __mutex_lock+0xa99/0x1140   [   81.900748]  ? __mutex_unlock_slowpath+0x1f/0x400   [   81.902069]  bdev_super_lock+0x5b/0x150   [   81.903132]  get_bdev_super+0x10/0x60   [   81.904042]  fs_bdev_thaw+0x23/0xf0   [   81.904755]  bdev_thaw+0x82/0x100   [   81.905484]  do_thaw_all_callback+0x2c/0x50   [   81.906298]  __iterate_supers+0x5d/0x130   [   81.907067]  do_thaw_all+0x20/0x40   [   81.907739]  process_one_work+0x206/0x5e0   [   81.908545]  worker_thread+0x1e2/0x3c0   [   81.909339]  ? __pfx_worker_thread+0x10/0x10   [   81.910171]  kthread+0xf4/0x130   [   81.910799]  ? __pfx_kthread+0x10/0x10   [   81.911528]  ret_from_fork+0x2e2/0x3b0   [   81.912259]  ? __pfx_kthread+0x10/0x10   [   81.913010]  ret_from_fork_asm+0x1a/0x30   [   81.913806]  </TASK>  bdev_super_lock() even documents the violated requirement with lockdep_assert_not_held(&sb->s_umount).  Acquiring bd_fsfreeze_mutex under s_umount also inverts the bd_fsfreeze_mutex vs. s_umount ordering established by bdev_{freeze,thaw}() and can thus ABBA against a concurrent block-layer freeze even when the recursive path isn't hit.  Fix this by not holding s_umount around the bdev_thaw() loop at all. Pin the superblock with an active reference instead as filesystems_freeze_callback() does. The active reference keeps the superblock from being shut down and so ->s_bdev stays valid without holding s_umount. The block-layer-held freeze is dropped by fs_bdev_thaw() with FREEZE_MAY_NEST | FREEZE_HOLDER_USERSPACE exactly as a regular unfreeze would and thaw_super_locked() handles filesystem-level freezes as before.  The emergency thaw path has deadlocked like this in one form or another for a long long time but the current exclusively-held shape dates back to commit [1] where thaw_bdev() already ended in thaw_super() with s_umount held by do_thaw_all_callback().","cvss":[],"epss":[{"cve":"CVE-2026-68132","epss":0.00184,"percentile":0.08141,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68132","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68132","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/05536cad35f27b520d4b6f0e57c8cc5bfb6b0502","https://git.kernel.org/stable/c/2a1127c1c58b4f15a93f2fd56ff7c2c3d611d5c5","https://git.kernel.org/stable/c/4c483644d1a7709efe7d1be7dbf88cf4008a7864","https://git.kernel.org/stable/c/63d78b546eefc38ad9898dc839bfc94811ede547","https://git.kernel.org/stable/c/749d7aa0377aae32af8c0a4ad43371e7bf830ab5","https://git.kernel.org/stable/c/96248aeddde794227a49af1a332a1e21b3c15d56","https://git.kernel.org/stable/c/99719b5da9320ed344daee87d9c73d321a98f252","https://git.kernel.org/stable/c/c202aa03388fd1889b7aa4f7d677c49e22cd9700"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsuper: fix emergency thaw deadlock on frozen block devices\n\ndo_thaw_all_callback() calls bdev_thaw() while holding sb->s_umount\nexclusively. If the block device was frozen via bdev_freeze() dropping\nthe last block layer freeze reference calls fs_bdev_thaw() which\nreacquires s_umount:\n\n  do_thaw_all_callback(sb)\n    super_lock_excl(sb)                     # holds sb->s_umount\n    bdev_thaw(sb->s_bdev)\n      mutex_lock(&bdev->bd_fsfreeze_mutex)\n      # bd_fsfreeze_count drops 1 -> 0\n      bd_holder_ops->thaw == fs_bdev_thaw\n        get_bdev_super(bdev)\n          bdev_super_lock(bdev, true)\n            super_lock(sb, true)\n              down_write(&sb->s_umount)     # same task: deadlock\n\nThe emergency thaw worker deadlocks against itself holding both\ns_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount,\nfreeze, or thaw of that filesystem and block device.\n\n  [   81.878470] sysrq: Show Blocked State\n  [   81.880140] task:kworker/0:1     state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208060 flags:0x00080000\n  [   81.884876] Workqueue: events do_thaw_all\n  [   81.886656] Call Trace:\n  [   81.887759]  <TASK>\n  [   81.888763]  __schedule+0x579/0x1420\n  [   81.890372]  schedule+0x3a/0x100\n  [   81.891794]  schedule_preempt_disabled+0x15/0x30\n  [   81.893848]  rwsem_down_write_slowpath+0x1ea/0x900\n  [   81.895191]  ? __pfx_do_thaw_all_callback+0x10/0x10\n  [   81.896528]  down_write+0xbd/0xc0\n  [   81.897505]  super_lock+0x91/0x180\n  [   81.898457]  ? __mutex_lock+0xa99/0x1140\n  [   81.900748]  ? __mutex_unlock_slowpath+0x1f/0x400\n  [   81.902069]  bdev_super_lock+0x5b/0x150\n  [   81.903132]  get_bdev_super+0x10/0x60\n  [   81.904042]  fs_bdev_thaw+0x23/0xf0\n  [   81.904755]  bdev_thaw+0x82/0x100\n  [   81.905484]  do_thaw_all_callback+0x2c/0x50\n  [   81.906298]  __iterate_supers+0x5d/0x130\n  [   81.907067]  do_thaw_all+0x20/0x40\n  [   81.907739]  process_one_work+0x206/0x5e0\n  [   81.908545]  worker_thread+0x1e2/0x3c0\n  [   81.909339]  ? __pfx_worker_thread+0x10/0x10\n  [   81.910171]  kthread+0xf4/0x130\n  [   81.910799]  ? __pfx_kthread+0x10/0x10\n  [   81.911528]  ret_from_fork+0x2e2/0x3b0\n  [   81.912259]  ? __pfx_kthread+0x10/0x10\n  [   81.913010]  ret_from_fork_asm+0x1a/0x30\n  [   81.913806]  </TASK>\n\nbdev_super_lock() even documents the violated requirement with\nlockdep_assert_not_held(&sb->s_umount).\n\nAcquiring bd_fsfreeze_mutex under s_umount also inverts the\nbd_fsfreeze_mutex vs. s_umount ordering established by\nbdev_{freeze,thaw}() and can thus ABBA against a concurrent block-layer\nfreeze even when the recursive path isn't hit.\n\nFix this by not holding s_umount around the bdev_thaw() loop at all. Pin\nthe superblock with an active reference instead as\nfilesystems_freeze_callback() does. The active reference keeps the\nsuperblock from being shut down and so ->s_bdev stays valid without\nholding s_umount. The block-layer-held freeze is dropped by\nfs_bdev_thaw() with FREEZE_MAY_NEST | FREEZE_HOLDER_USERSPACE exactly as\na regular unfreeze would and thaw_super_locked() handles\nfilesystem-level freezes as before.\n\nThe emergency thaw path has deadlocked like this in one form or\nanother for a long long time but the current exclusively-held\nshape dates back to commit [1] where thaw_bdev() already ended in\nthaw_super() with s_umount held by do_thaw_all_callback().","cvss":[],"epss":[{"cve":"CVE-2026-68132","epss":0.00184,"percentile":0.08141,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68132","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68135","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68135","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: hip04: fix RX buffer leak on build_skb failure  When build_skb() fails in hip04_rx_poll(), the driver jumps to the refill path without releasing the current RX buffer and its DMA mapping. Installing a replacement buffer then overwrites the slot references and leaks both resources.  Keep the current slot intact and return budget so NAPI retries the same buffer.  Also free a newly allocated RX fragment when dma_map_single() fails.  This issue was found by an in-house static analysis tool.","cvss":[],"epss":[{"cve":"CVE-2026-68135","epss":0.00184,"percentile":0.08143,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68135","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68135","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/14fa65d10f5696b063a7d8d26e8291ea84a2c6ed","https://git.kernel.org/stable/c/2b19fe277645fd1aeb18fd4ecdcf31966080dee7","https://git.kernel.org/stable/c/67a7614bde310da006ab259f4f163d3fb0f9e253","https://git.kernel.org/stable/c/690ecc13a4032e5cae1dc6659512f32b033533b0","https://git.kernel.org/stable/c/80d977f280b4eccd4ac5369871d0ecb2b9c9a49d","https://git.kernel.org/stable/c/a0f247d63489a107bbc3b712a77b302af2a2a173","https://git.kernel.org/stable/c/bcd43ee1f25b682151df213c06a99b2e1c1cf2e5","https://git.kernel.org/stable/c/e054dcd990d8180cde529ea28ce0838e76a5ad5e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hip04: fix RX buffer leak on build_skb failure\n\nWhen build_skb() fails in hip04_rx_poll(), the driver jumps to the\nrefill path without releasing the current RX buffer and its DMA mapping.\nInstalling a replacement buffer then overwrites the slot references and\nleaks both resources.\n\nKeep the current slot intact and return budget so NAPI retries the same\nbuffer.  Also free a newly allocated RX fragment when dma_map_single()\nfails.\n\nThis issue was found by an in-house static analysis tool.","cvss":[],"epss":[{"cve":"CVE-2026-68135","epss":0.00184,"percentile":0.08143,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68135","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68136","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68136","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: gro: fix double aggregation of flush-marked skbs  Commit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO packet.\") added a flush check to skb_gro_receive(), but skb_gro_receive_list() lacks the same validation.  As a result, packets marked with NAPI_GRO_CB(skb)->flush may still be re-aggregated.  This allows already-GRO'd packets with existing frag_list to be re-aggregated into a new GRO session, corrupting the frag_list chain structure. When skb_segment() attempts to unpack these malformed packets, it encounters invalid state and triggers a kernel panic.  Scenario (Tethering/Device forwarding):   1. Driver: Generated aggregated packet P1 via LRO with frag_list   2. Dev A: Receives aggregated fraglist packet and flush flag set   3. Dev A: Re-enters GRO, skb_gro_receive_list() is called   4. Missing flush check allows re-aggregation despite flush flag   5. Frag_list chain becomes corrupted (loops or dangling refs)   6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list  Root cause in skb_segment():   The check at line ~4891:     if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&         (skb_headlen(list_skb) == len || sg)) {    When frag_list is corrupted by double aggregation, when list_skb is   a NULL pointer from skb->next, skb_headlen(list_skb) dereference   NULL/corrupted pointers occurs.  Call Trace:  skb_headlen(NULL skb)  skb_segment  tcp_gso_segment  tcp4_gso_segment  inet_gso_segment  skb_mac_gso_segment  __skb_gso_segment  skb_gso_segment  validate_xmit_skb  validate_xmit_skb_list  sch_direct_xmit  qdisc_restart  __qdisc_run  qdisc_run  net_tx_action  Fix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in skb_gro_receive_list(), matching the defensive programming pattern of skb_gro_receive().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68136","epss":0.00546,"percentile":0.44011,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.5132399999999999},"relatedVulnerabilities":[{"id":"CVE-2026-68136","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68136","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/107e1a469f53a2a70874f3f12bf6fcd23925da1d","https://git.kernel.org/stable/c/7fc7e35212cf58c134310fb47566a844297ceae9","https://git.kernel.org/stable/c/a4dfd46cc8f08a29c6183794790547d0945f3d45","https://git.kernel.org/stable/c/d1fb23f8f794ac4683127bd49a6422bd87e0ac02","https://git.kernel.org/stable/c/db3e82da616f52e2b27e25e7be3fde2f2a5e54d6","https://git.kernel.org/stable/c/e751256486d0ded20f5a9f9863467f1dce65142f","https://git.kernel.org/stable/c/fc0c0f7a207f0cd2d2aa725696c907f7d03af9e0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: fix double aggregation of flush-marked skbs\n\nCommit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO\npacket.\") added a flush check to skb_gro_receive(), but\nskb_gro_receive_list() lacks the same validation.\n\nAs a result, packets marked with NAPI_GRO_CB(skb)->flush may still be\nre-aggregated.\n\nThis allows already-GRO'd packets with existing frag_list to be\nre-aggregated into a new GRO session, corrupting the frag_list chain\nstructure. When skb_segment() attempts to unpack these malformed packets,\nit encounters invalid state and triggers a kernel panic.\n\nScenario (Tethering/Device forwarding):\n  1. Driver: Generated aggregated packet P1 via LRO with frag_list\n  2. Dev A: Receives aggregated fraglist packet and flush flag set\n  3. Dev A: Re-enters GRO, skb_gro_receive_list() is called\n  4. Missing flush check allows re-aggregation despite flush flag\n  5. Frag_list chain becomes corrupted (loops or dangling refs)\n  6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list\n\nRoot cause in skb_segment():\n  The check at line ~4891:\n    if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&\n        (skb_headlen(list_skb) == len || sg)) {\n\n  When frag_list is corrupted by double aggregation, when list_skb is\n  a NULL pointer from skb->next, skb_headlen(list_skb) dereference\n  NULL/corrupted pointers occurs.\n\nCall Trace:\n skb_headlen(NULL skb)\n skb_segment\n tcp_gso_segment\n tcp4_gso_segment\n inet_gso_segment\n skb_mac_gso_segment\n __skb_gso_segment\n skb_gso_segment\n validate_xmit_skb\n validate_xmit_skb_list\n sch_direct_xmit\n qdisc_restart\n __qdisc_run\n qdisc_run\n net_tx_action\n\nFix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in\nskb_gro_receive_list(), matching the defensive programming pattern of\nskb_gro_receive().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68136","epss":0.00546,"percentile":0.44011,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68136","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68137","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68137","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/x25: fix use-after-free in x25_kill_by_neigh()  x25_kill_by_neigh() walks the global X.25 socket list looking for sockets attached to a terminating neighbour. x25_list_lock protects list membership while the lookup is in progress, but it does not pin a socket's lifetime after the lock is dropped.  The function currently drops x25_list_lock before calling lock_sock(s). A concurrent close can run x25_release(), remove the same socket from x25_list, and drop the last socket reference in that window. The neighbour teardown path can then lock or inspect a freed struct sock/struct x25_sock.  Take sock_hold(s) while x25_list_lock still proves that the list entry is live, then drop the temporary reference after the socket has been locked, rechecked, and released. Recheck x25_sk(s)->neighbour after lock_sock(), because another path may have disconnected the socket before this path acquired the socket lock. Restart the list walk after each disconnect because the list lock was dropped and the previous iterator state may no longer be valid.  A QEMU/KASAN run against origin/master reproduced a slab-use-after-free in x25_kill_by_neigh().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68137","epss":0.00536,"percentile":0.43477,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.5038400000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68137","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68137","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/3f4fe26c20c30bd5a2e2583e80685def0b27858c","https://git.kernel.org/stable/c/5499e0602d2faafd42c580d25f615903c3fbe11b","https://git.kernel.org/stable/c/5e8a754ac2009a88a7b99ab61eab6296eed360f3","https://git.kernel.org/stable/c/610678d4be94b619c751572e8a58de705592cd07","https://git.kernel.org/stable/c/9aabda553184346f74810e2ee1d96920b4612e3f","https://git.kernel.org/stable/c/c98a454d1a9e1bd09d5fd55a7aa589b199340b88","https://git.kernel.org/stable/c/db6b04f6d65549bb1c7bc8e64a92e7b7d03be676","https://git.kernel.org/stable/c/ec6d91a1bf2ebd767d3d43f6d249ee0ed3f4558a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/x25: fix use-after-free in x25_kill_by_neigh()\n\nx25_kill_by_neigh() walks the global X.25 socket list looking for sockets\nattached to a terminating neighbour. x25_list_lock protects list membership\nwhile the lookup is in progress, but it does not pin a socket's lifetime\nafter the lock is dropped.\n\nThe function currently drops x25_list_lock before calling lock_sock(s). A\nconcurrent close can run x25_release(), remove the same socket from\nx25_list, and drop the last socket reference in that window. The neighbour\nteardown path can then lock or inspect a freed struct sock/struct x25_sock.\n\nTake sock_hold(s) while x25_list_lock still proves that the list entry is\nlive, then drop the temporary reference after the socket has been locked,\nrechecked, and released. Recheck x25_sk(s)->neighbour after lock_sock(),\nbecause another path may have disconnected the socket before this path\nacquired the socket lock. Restart the list walk after each disconnect\nbecause the list lock was dropped and the previous iterator state may no\nlonger be valid.\n\nA QEMU/KASAN run against origin/master reproduced a slab-use-after-free in\nx25_kill_by_neigh().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68137","epss":0.00536,"percentile":0.43477,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68137","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68138","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68138","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: serialize qdisc_rtab_list against concurrent get/put  qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no lock. This was only safe because every caller historically held the RTNL mutex, which serialized all rate-table lookups, inserts and frees.  That invariant no longer holds. cls_flower sets TCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false for it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through tcf_exts_validate_ex() -> tcf_action_init() -> tcf_action_init_1() -> tcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the RTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each adding a flower filter with a police action carrying the same rate, then race on qdisc_rtab_list and on the non-atomic refcnt, leading to a use-after-free / double-free of the kmalloc-2k struct qdisc_rate_table. qdisc_rtab_list is a single global (not per-netns), so the corrupted object is shared system-wide.    BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160    qdisc_put_rtab+0x12f/0x160    tcf_police_init+0xda9/0x1590    tcf_action_init_1+0x460/0x6b0    tcf_action_init+0x439/0xa40    tcf_exts_validate_ex+0x42d/0x550    fl_change+0xddd/0x7da0    tc_new_tfilter+0xaa7/0x2420    rtnetlink_rcv_msg+0x95e/0xe90   which belongs to the cache kmalloc-2k of size 2048  Protect qdisc_rtab_list and the refcount with a dedicated spinlock. The (sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before taking the lock; if a concurrent inserter added an identical table in the meantime the freshly allocated one is freed under the lock, so no duplicate is leaked. qdisc_put_rtab() now decrements the refcount and unlinks under the same lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68138","epss":0.00283,"percentile":0.20603,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.21649500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-68138","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68138","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1b050d09dd1a0ddae83bf012cf4956b7a960235f","https://git.kernel.org/stable/c/4131dd0b6f67acddd616ed7c244e1d3eedd46e7b","https://git.kernel.org/stable/c/6e0241f6cbb149d926ee8efee2c734fea71452cf","https://git.kernel.org/stable/c/8ddc2eb0d2da9c83f54f1e5720525b461b8480c4","https://git.kernel.org/stable/c/d981098b76756ed71666a27518eeb69883657c43","https://git.kernel.org/stable/c/f43ee0c0730d6191629b5ee1ceae27b1ebfdc047","https://git.kernel.org/stable/c/f93c89392bd3b180b5b7abc6fdae8e3dd667a313","https://git.kernel.org/stable/c/fb29e1b41052488ee3f2d115d4a870497ebd7f7d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: serialize qdisc_rtab_list against concurrent get/put\n\nqdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly\nlinked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no\nlock. This was only safe because every caller historically held the RTNL\nmutex, which serialized all rate-table lookups, inserts and frees.\n\nThat invariant no longer holds. cls_flower sets\nTCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false\nfor it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through\ntcf_exts_validate_ex() -> tcf_action_init() -> tcf_action_init_1() ->\ntcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the\nRTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each\nadding a flower filter with a police action carrying the same rate, then\nrace on qdisc_rtab_list and on the non-atomic refcnt, leading to a\nuse-after-free / double-free of the kmalloc-2k struct qdisc_rate_table.\nqdisc_rtab_list is a single global (not per-netns), so the corrupted\nobject is shared system-wide.\n\n  BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160\n   qdisc_put_rtab+0x12f/0x160\n   tcf_police_init+0xda9/0x1590\n   tcf_action_init_1+0x460/0x6b0\n   tcf_action_init+0x439/0xa40\n   tcf_exts_validate_ex+0x42d/0x550\n   fl_change+0xddd/0x7da0\n   tc_new_tfilter+0xaa7/0x2420\n   rtnetlink_rcv_msg+0x95e/0xe90\n  which belongs to the cache kmalloc-2k of size 2048\n\nProtect qdisc_rtab_list and the refcount with a dedicated spinlock. The\n(sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before\ntaking the lock; if a concurrent inserter added an identical table in the\nmeantime the freshly allocated one is freed under the lock, so no\nduplicate is leaked. qdisc_put_rtab() now decrements the refcount and\nunlinks under the same lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68138","epss":0.00283,"percentile":0.20603,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68138","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68140","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68140","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/iucv: fix use-after-free of a severed iucv_path  af_iucv queues not-yet-received message notifications on iucv->message_q, each holding a raw pointer to the connection's iucv_path.  When the peer severs the connection, iucv_sever_path() frees that path with iucv_path_free() but leaves the notifications queued.  A later recvmsg() drains message_q via iucv_process_message_q() and hands the stale path to message_receive() -- a use-after-free of the freed iucv_path.  Drop the queued notifications when the path is severed; once the path is gone they can no longer be received.  This also frees the notifications leaked when a socket is closed with messages still queued.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68140","epss":0.00274,"percentile":0.19585,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.22331},"relatedVulnerabilities":[{"id":"CVE-2026-68140","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68140","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/23658b350b4107e8292045c2044983fd426fa15d","https://git.kernel.org/stable/c/5f08c5e50bcb4680069bd3f9edd5728308816ded","https://git.kernel.org/stable/c/900cd6d8119b7f3ae5c4bf82f922ff5957df43db","https://git.kernel.org/stable/c/99ddb33748698296a6f17b9b34aa3d16a406bb3c","https://git.kernel.org/stable/c/a5bbaddf69853117f28173c3f5c8fc14c6b2ec82","https://git.kernel.org/stable/c/be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a","https://git.kernel.org/stable/c/c24faf11bd31bfe0500aca12cbdd5a573a954a5d","https://git.kernel.org/stable/c/f579582c03ed526281a8450159baf1d35099a85f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: fix use-after-free of a severed iucv_path\n\naf_iucv queues not-yet-received message notifications on iucv->message_q,\neach holding a raw pointer to the connection's iucv_path.  When the peer\nsevers the connection, iucv_sever_path() frees that path with\niucv_path_free() but leaves the notifications queued.  A later recvmsg()\ndrains message_q via iucv_process_message_q() and hands the stale path to\nmessage_receive() -- a use-after-free of the freed iucv_path.\n\nDrop the queued notifications when the path is severed; once the path is\ngone they can no longer be received.  This also frees the notifications\nleaked when a socket is closed with messages still queued.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68140","epss":0.00274,"percentile":0.19585,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68140","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68141","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68141","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()  afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC. If the allocation fails, nsk is NULL.  The connection-refused path is entered when the listen state check fails, the accept backlog is full, or nsk is NULL. The code unconditionally calls iucv_sock_kill(nsk) in that path.  iucv_sock_kill() does not accept a NULL socket pointer and immediately dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL, calling iucv_sock_kill(nsk) results in a NULL pointer dereference.  Only call iucv_sock_kill() when a child socket was successfully allocated.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68141","epss":0.00523,"percentile":0.42727,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.39225000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-68141","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68141","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/07e21deb3664001995e0a456dd627ab7dbe127ec","https://git.kernel.org/stable/c/0e857185591fe79934427c9c0c1c31dc776be134","https://git.kernel.org/stable/c/33736ff5e7c97d3348ce812e8bd2e125d840743c","https://git.kernel.org/stable/c/46453b16f38ec7147351f7447e2aec6ea330f7b3","https://git.kernel.org/stable/c/47a5116e56a6b6fe1e909f244e39cd0fc26ceee4","https://git.kernel.org/stable/c/6a1eb5b46c19073f8153b7e2c19b408cf353aaf1","https://git.kernel.org/stable/c/8bb111f87ded6acb9837ec9b45d6f02cda94c51f","https://git.kernel.org/stable/c/c0b6e2ae90613c2fea7eaf3faa20985c6c2a1953"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/af_iucv: fix NULL deref in afiucv_hs_callback_syn()\n\nafiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.\nIf the allocation fails, nsk is NULL.\n\nThe connection-refused path is entered when the listen state check\nfails, the accept backlog is full, or nsk is NULL. The code\nunconditionally calls iucv_sock_kill(nsk) in that path.\n\niucv_sock_kill() does not accept a NULL socket pointer and immediately\ndereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,\ncalling iucv_sock_kill(nsk) results in a NULL pointer dereference.\n\nOnly call iucv_sock_kill() when a child socket was successfully\nallocated.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68141","epss":0.00523,"percentile":0.42727,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68141","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68142","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68142","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  geneve: require CAP_NET_ADMIN in the device netns for changelink  A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns geneve->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in geneve->net can rewrite a geneve device whose underlay lives in geneve->net.  geneve_changelink() applies the new configuration against geneve->net: geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair reopen the underlay sockets in that netns (geneve_sock_add() uses geneve->net), so the same reasoning as the tunnel changelink series applies here.  Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the \"require CAP_NET_ADMIN in the device netns for changelink\" series.  Found by 0sec automated security-research tooling (https://0sec.ai).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68142","epss":0.00138,"percentile":0.03556,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11247},"relatedVulnerabilities":[{"id":"CVE-2026-68142","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68142","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/11a7d989d00160481a273eb4f7f05f64b5a6ffdf","https://git.kernel.org/stable/c/278c6a31ee27c931c722202c8c06cc3253923254","https://git.kernel.org/stable/c/2abdacc927c92fa6a9cc8341e8c9b88dcb561553","https://git.kernel.org/stable/c/8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01","https://git.kernel.org/stable/c/95f45e20f1b2cec13823f0f68060ab4b2261b2c1","https://git.kernel.org/stable/c/9de5518fc1fab583526a8f66b8e505c4864dc60a","https://git.kernel.org/stable/c/a5522963c57f12df5f9db804ebfc472b58eef0ae","https://git.kernel.org/stable/c/f8c498585d2a08aa623748353c3e61467b7e9fd2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns geneve->net. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in geneve->net can rewrite a geneve\ndevice whose underlay lives in geneve->net.\n\ngeneve_changelink() applies the new configuration against geneve->net:\ngeneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair\nreopen the underlay sockets in that netns (geneve_sock_add() uses\ngeneve->net), so the same reasoning as the tunnel changelink series\napplies here.\n\nGate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68142","epss":0.00138,"percentile":0.03556,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68142","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68143","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68143","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: slip: serialize receive against buffer reallocation  sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without holding the lock.  An MTU change can therefore race with receive processing. An MTU shrink can expose the new smaller rbuff with the old larger bound, causing an out-of-bounds write. A receive callback which already loaded the old rbuff can instead continue writing after that buffer has been freed.  Serialize receive processing with sl_realloc_bufs() by holding sl->lock while consuming each receive batch.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68143","epss":0.00138,"percentile":0.03557,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-68143","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68143","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0e37bbd6d617eb52bace49390e99eaedc1af73ce","https://git.kernel.org/stable/c/189a550eb7e1dc10018718ddfc46d003ffe58653","https://git.kernel.org/stable/c/1be09d175b627fad7f6bec7ad27b8a4a99863912","https://git.kernel.org/stable/c/44401f7dd9940ced7098930ef64f5a332f279fc2","https://git.kernel.org/stable/c/5d07b178bef511d69558cfc89fe1129258dc39f8","https://git.kernel.org/stable/c/8180daf2b66155f84ec4f9e3f95488c8a3421716","https://git.kernel.org/stable/c/eb3836eab47487823f362e6985e170a1e15f20fd","https://git.kernel.org/stable/c/ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: slip: serialize receive against buffer reallocation\n\nsl_realloc_bufs() replaces rbuff and updates buffsize while holding\nsl->lock. slip_receive_buf() reads those fields and writes through rbuff\nwithout holding the lock.\n\nAn MTU change can therefore race with receive processing. An MTU shrink\ncan expose the new smaller rbuff with the old larger bound, causing an\nout-of-bounds write. A receive callback which already loaded the old\nrbuff can instead continue writing after that buffer has been freed.\n\nSerialize receive processing with sl_realloc_bufs() by holding sl->lock\nwhile consuming each receive batch.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68143","epss":0.00138,"percentile":0.03557,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68143","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68144","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  phonet: pep: fix use-after-free in pep_get_sb()  pep_get_sb() doesn't consider that pskb_may_pull() might have relocated the skb data, and continue to access the older pointer, causing UAF.  Reproduced under KASAN:    BUG: KASAN: slab-use-after-free in pep_get_sb+0x234/0x3b0   Read of size 1 at addr ff11000105510f50 by task repro/157    pep_get_sb+0x234/0x3b0    pipe_handler_do_rcv+0x5f7/0xa10    pep_do_rcv+0x203/0x410    __sk_receive_skb+0x471/0x4a0    phonet_rcv+0x5b3/0x6c0    __netif_receive_skb+0xcc/0x1d0  Refetch the header with skb_header_pointer() after pskb_may_pull(), so the possibly stale pointer is no longer dereferenced. There are better ways to solve this, but, this is the less instrusive one.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68144","epss":0.00536,"percentile":0.43477,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.5038400000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68144","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0f71f852a96af9685858ce59fda34ecbf85c283d","https://git.kernel.org/stable/c/17f78c0c0d41d738ee236eb6e841e39395188054","https://git.kernel.org/stable/c/1d81e19fc57a5ee55b4497d01bc0510d76fb9578","https://git.kernel.org/stable/c/25e3641beb51333bfbb155af2fd2573a61113af2","https://git.kernel.org/stable/c/8d931a75a38b9bb584a4071f5ebbd52755fc35ee","https://git.kernel.org/stable/c/a48a889b60f73edb0399a8b08284a2ab0bd0295f","https://git.kernel.org/stable/c/c4a52cb4da8d57d060b1d52085d25147a238dac2","https://git.kernel.org/stable/c/df198743859fefba2f824115f8151dd62d7ad6d8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nphonet: pep: fix use-after-free in pep_get_sb()\n\npep_get_sb() doesn't consider that pskb_may_pull() might have relocated\nthe skb data, and continue to access the older pointer, causing UAF.\n\nReproduced under KASAN:\n\n  BUG: KASAN: slab-use-after-free in pep_get_sb+0x234/0x3b0\n  Read of size 1 at addr ff11000105510f50 by task repro/157\n   pep_get_sb+0x234/0x3b0\n   pipe_handler_do_rcv+0x5f7/0xa10\n   pep_do_rcv+0x203/0x410\n   __sk_receive_skb+0x471/0x4a0\n   phonet_rcv+0x5b3/0x6c0\n   __netif_receive_skb+0xcc/0x1d0\n\nRefetch the header with skb_header_pointer() after pskb_may_pull(), so\nthe possibly stale pointer is no longer dereferenced. There are better\nways to solve this, but, this is the less instrusive one.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68144","epss":0.00536,"percentile":0.43477,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68144","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68146","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68146","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ftrace: Add global mutex to serialize trace_parser access  In ftrace, the trace_parser structure is allocated and initialized when a trace file is opened, and is subsequently used across write and release handlers to parse user input.  The affected handler paths and their specific functions are:   - Open paths: ftrace_regex_open(), ftrace_graph_open()   - Write paths: ftrace_regex_write(), ftrace_graph_write()   - Release paths: ftrace_regex_release(), ftrace_graph_release()  If userspace opens a trace file descriptor and shares it across multiple threads, concurrent write calls will race on the parser's internal state, specifically the 'idx', 'cont', and 'buffer' fields, leading to corrupted input or undefined behavior.  Fix this by adding a global mutex, parser_lock, to serialize all access to trace_parser across write and release paths, preventing concurrent corruption of parser state.","cvss":[],"epss":[{"cve":"CVE-2026-68146","epss":0.00184,"percentile":0.08123,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68146","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68146","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1474fe4453505b6be720b5bb94be1c927de3314a","https://git.kernel.org/stable/c/3d0dd138a06c782f8b755cd1b6f9909494514ce1","https://git.kernel.org/stable/c/65bf73bee1a4f3722208ae46afc0fa5de76b9a0a","https://git.kernel.org/stable/c/7720b63bcef3f54c7fe288774b720a227d54a306","https://git.kernel.org/stable/c/90be137813e1a5bdfd671e40fe28004fb959d3e4","https://git.kernel.org/stable/c/a29bc20ea5f0cb79c6287f2c6182c5eeb8e6c01f","https://git.kernel.org/stable/c/db76744d588086695371ecdd982694395628ba48","https://git.kernel.org/stable/c/e807c9193d9493c7a0d039158ebb955050a76df1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Add global mutex to serialize trace_parser access\n\nIn ftrace, the trace_parser structure is allocated and initialized when\na trace file is opened, and is subsequently used across write and release\nhandlers to parse user input.\n\nThe affected handler paths and their specific functions are:\n  - Open paths: ftrace_regex_open(), ftrace_graph_open()\n  - Write paths: ftrace_regex_write(), ftrace_graph_write()\n  - Release paths: ftrace_regex_release(), ftrace_graph_release()\n\nIf userspace opens a trace file descriptor and shares it across multiple\nthreads, concurrent write calls will race on the parser's internal state,\nspecifically the 'idx', 'cont', and 'buffer' fields, leading to corrupted\ninput or undefined behavior.\n\nFix this by adding a global mutex, parser_lock, to serialize all access\nto trace_parser across write and release paths, preventing concurrent\ncorruption of parser state.","cvss":[],"epss":[{"cve":"CVE-2026-68146","epss":0.00184,"percentile":0.08123,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68146","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68147","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fscrypt: Avoid dynamic allocation in fscrypt_get_devices()  When a blk_crypto_key starts being used or is evicted, fs/crypto/ calls fscrypt_get_devices() to get the filesystem's list of block devices, then iterates over them and calls blk_crypto_config_supported(), blk_crypto_start_using_key(), or blk_crypto_evict_key() on each one.  Currently, the block device pointers are placed in a dynamically allocated array.  This dynamic allocation is problematic because:  - It can fail, especially at the fscrypt_destroy_inline_crypt_key() call   site when it's invoked for inode eviction under direct reclaim.  - fscrypt_destroy_inline_crypt_key() doesn't handle the failure.  It   just zeroizes and frees the blk_crypto_key without calling   blk_crypto_evict_key().  That causes a use-after-free.  For now, let's fix this in the straightforward and easily-backportable way by switching to an on-stack array.  Currently the fscrypt multi-device functionality is used only by f2fs, which has a hardcoded limit of 8 block devices.  An on-stack array works fine for that.  (Of course, this solution won't scale up to large number of block devices.  For that we'd need a different solution, like moving the block device iteration into the filesystem.  Or in the case of btrfs, which will only support blk-crypto-fallback, we should make it just call blk-crypto-fallback directly, so the block devices won't be needed.)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68147","epss":0.00135,"percentile":0.03285,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.103275},"relatedVulnerabilities":[{"id":"CVE-2026-68147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68147","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4462ac3d90e897dda52ce4b6af2d526ddae835a8","https://git.kernel.org/stable/c/6fe4e4b8259e1330945b5f3c9476e08473b8e0e8","https://git.kernel.org/stable/c/81ea8e8221853950c47dac7164f27c63a96f8f86","https://git.kernel.org/stable/c/97a688563be71ec6fefc071aff69a66c69dbe244","https://git.kernel.org/stable/c/bab016bb80d74a9d1f7d4121a7fc1cb529b470e0","https://git.kernel.org/stable/c/bc2d630296e0e049210ec05ff08459a6893ae749"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: Avoid dynamic allocation in fscrypt_get_devices()\n\nWhen a blk_crypto_key starts being used or is evicted, fs/crypto/ calls\nfscrypt_get_devices() to get the filesystem's list of block devices,\nthen iterates over them and calls blk_crypto_config_supported(),\nblk_crypto_start_using_key(), or blk_crypto_evict_key() on each one.\n\nCurrently, the block device pointers are placed in a dynamically\nallocated array.  This dynamic allocation is problematic because:\n\n- It can fail, especially at the fscrypt_destroy_inline_crypt_key() call\n  site when it's invoked for inode eviction under direct reclaim.\n\n- fscrypt_destroy_inline_crypt_key() doesn't handle the failure.  It\n  just zeroizes and frees the blk_crypto_key without calling\n  blk_crypto_evict_key().  That causes a use-after-free.\n\nFor now, let's fix this in the straightforward and easily-backportable\nway by switching to an on-stack array.  Currently the fscrypt\nmulti-device functionality is used only by f2fs, which has a hardcoded\nlimit of 8 block devices.  An on-stack array works fine for that.\n\n(Of course, this solution won't scale up to large number of block\ndevices.  For that we'd need a different solution, like moving the block\ndevice iteration into the filesystem.  Or in the case of btrfs, which\nwill only support blk-crypto-fallback, we should make it just call\nblk-crypto-fallback directly, so the block devices won't be needed.)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68147","epss":0.00135,"percentile":0.03285,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68147","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68148","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68148","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fscrypt: Add missing superblock check in find_or_insert_direct_key()  The legacy 'fscrypt_direct_keys' table caches master keys that are used by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY. It's just a global table for all filesystems (since the keys can be provided by the legacy process-subscribed keyrings mechanism, which makes it difficult to reuse super_block::s_master_keys).  The entries in it ('struct fscrypt_direct_key') do contain a super_block pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when the last inode that references the key is evicted.  However, when finding the fscrypt_direct_key for an inode, we weren't actually comparing the super_block pointer.  As a result, inodes with different super_blocks could point to the same fscrypt_direct_key.  That could extend the lifetime of a fscrypt_direct_key beyond the super_block it points to, causing a use-after-free later.  Fix this by creating distinct fscrypt_direct_key structs for distinct super_block structs.  Note that this problem doesn't exist in the v2 policy equivalent (\"per-mode keys\"), since the data structures there are per super_block.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68148","epss":0.00091,"percentile":0.00541,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.069615},"relatedVulnerabilities":[{"id":"CVE-2026-68148","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68148","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/330249609b70778094a7a36f5b6bcfa6362121d4","https://git.kernel.org/stable/c/466f187b501a5ac8e1ea2ccf3ccd5c46108d8830","https://git.kernel.org/stable/c/95376fe9c145be35566991df99c53134943d992f","https://git.kernel.org/stable/c/965b5bc8cf5031225e057979ce660fec2bd5fbfc","https://git.kernel.org/stable/c/b5fa40226e71c17847b9ff2816c6ca4133d0d994","https://git.kernel.org/stable/c/deff41898a5ae3a47db5fa1896a494aa95efda5d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: Add missing superblock check in find_or_insert_direct_key()\n\nThe legacy 'fscrypt_direct_keys' table caches master keys that are used\nby v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY.\nIt's just a global table for all filesystems (since the keys can be\nprovided by the legacy process-subscribed keyrings mechanism, which\nmakes it difficult to reuse super_block::s_master_keys).\n\nThe entries in it ('struct fscrypt_direct_key') do contain a super_block\npointer, though, for passing to fscrypt_destroy_inline_crypt_key() when\nthe last inode that references the key is evicted.\n\nHowever, when finding the fscrypt_direct_key for an inode, we weren't\nactually comparing the super_block pointer.  As a result, inodes with\ndifferent super_blocks could point to the same fscrypt_direct_key.  That\ncould extend the lifetime of a fscrypt_direct_key beyond the\nsuper_block it points to, causing a use-after-free later.\n\nFix this by creating distinct fscrypt_direct_key structs for distinct\nsuper_block structs.\n\nNote that this problem doesn't exist in the v2 policy equivalent\n(\"per-mode keys\"), since the data structures there are per super_block.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68148","epss":0.00091,"percentile":0.00541,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68148","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68151","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68151","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  binfmt_elf_fdpic: only honour the first PT_INTERP  The program header scan handles PT_INTERP from a switch nested in the scan loop, so its break leaves the switch and not the loop. A binary carrying more than one PT_INTERP runs the case again and overwrites both interpreter_name and interpreter. The previous name allocation leaks and so does the previous interpreter reference, along with the write denial open_exec() took on it. The denial is never released, so the file stays unwritable for as long as the system runs.  An unprivileged caller reaches this with a crafted binary and repeats it at will. binfmt_elf stops at the first PT_INTERP. Do the same here.  The flaw dates back to the driver's introduction in the pre-git history tree introduced in v2.6.11 by 91808d6ebe39 (\"[PATCH] FRV: Add FDPIC ELF binary format driver\").","cvss":[],"epss":[{"cve":"CVE-2026-68151","epss":0.00184,"percentile":0.08143,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68151","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68151","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/21eaf5594a33d16343a011c752624099c30e918f","https://git.kernel.org/stable/c/3349ef6a366a61d631f6a263d12cea240957719d","https://git.kernel.org/stable/c/3c31397b0a75310217f1f2f3c7bdfd8af67aec4c","https://git.kernel.org/stable/c/69ecc199880bf7e8d06224c82dc411d18f9285f8","https://git.kernel.org/stable/c/849a7bd9d266e43a457db5c6b322600f916a2127","https://git.kernel.org/stable/c/89b9121c3b0162655fc2f190b714ae64f1aa8cae","https://git.kernel.org/stable/c/9854538349aaf6fb88ed33b56987954ac1716151","https://git.kernel.org/stable/c/e4563e07ef5c938d5332c5c44721db976f214bc6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_elf_fdpic: only honour the first PT_INTERP\n\nThe program header scan handles PT_INTERP from a switch nested in the\nscan loop, so its break leaves the switch and not the loop. A binary\ncarrying more than one PT_INTERP runs the case again and overwrites both\ninterpreter_name and interpreter. The previous name allocation leaks and\nso does the previous interpreter reference, along with the write denial\nopen_exec() took on it. The denial is never released, so the file stays\nunwritable for as long as the system runs.\n\nAn unprivileged caller reaches this with a crafted binary and repeats it\nat will. binfmt_elf stops at the first PT_INTERP. Do the same here.\n\nThe flaw dates back to the driver's introduction in the pre-git history\ntree introduced in v2.6.11 by 91808d6ebe39 (\"[PATCH] FRV: Add FDPIC ELF\nbinary format driver\").","cvss":[],"epss":[{"cve":"CVE-2026-68151","epss":0.00184,"percentile":0.08143,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68151","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68152","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68152","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  amt: fix use-after-free in AMT delayed works  When an AMT device is removed, pending delayed works can still access the freed amt_dev structure, which may result in kernel crashes or memory corruption.  amt_dev_stop() cancels req_wq and discovery_wq with cancel_delayed_work_sync(), but these works can be scheduled again from event_wq after the cancellation. This allows delayed works to access the freed amt_dev structure after the netdev has been released.  The following is a simple race scenario:  CPU0                         CPU1  amt_dev_stop() cancel_delayed_work_sync()                              amt_event_work()                              mod_delayed_work(req_wq) free netdev                              req_wq accesses freed amt_dev  Use disable_delayed_work_sync() in amt_dev_stop() to prevent req_wq and discovery_wq from being queued again and wait for running work items to complete.  The delayed works are disabled after initialization in amt_newlink() and enabled only when the device is successfully opened. This keeps the delayed work lifecycle synchronized with the lifetime of the AMT device.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68152","epss":0.00134,"percentile":0.03244,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10251000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-68152","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68152","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/006340cf06881b6ff49767d8b6f3c4f7b892670c","https://git.kernel.org/stable/c/1a644db2cf59f164cdf3c75995bab5aadc097528","https://git.kernel.org/stable/c/a46bfa01e01df0f6f6dc4b0be18db002d6d2dbd2","https://git.kernel.org/stable/c/ea20c44935d6142daecfa9b39d635033a7553e1b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\namt: fix use-after-free in AMT delayed works\n\nWhen an AMT device is removed, pending delayed works can still access\nthe freed amt_dev structure, which may result in kernel crashes or\nmemory corruption.\n\namt_dev_stop() cancels req_wq and discovery_wq with\ncancel_delayed_work_sync(), but these works can be scheduled again\nfrom event_wq after the cancellation. This allows delayed works to\naccess the freed amt_dev structure after the netdev has been released.\n\nThe following is a simple race scenario:\n\nCPU0                         CPU1\n\namt_dev_stop()\ncancel_delayed_work_sync()\n                             amt_event_work()\n                             mod_delayed_work(req_wq)\nfree netdev\n                             req_wq accesses freed amt_dev\n\nUse disable_delayed_work_sync() in amt_dev_stop() to prevent req_wq and\ndiscovery_wq from being queued again and wait for running work items\nto complete.\n\nThe delayed works are disabled after initialization in\namt_newlink() and enabled only when the device is successfully opened.\nThis keeps the delayed work lifecycle synchronized with the lifetime\nof the AMT device.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68152","epss":0.00134,"percentile":0.03244,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68152","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68153","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68153","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: remove debugfs files before client teardown  ceph_destroy_client() tears down the monitor client before removing the per-client debugfs files. A concurrent read of the monmap debugfs file can enter monmap_show() after ceph_monc_stop() has freed monc->monmap, triggering a use-after-free.  Remove the debugfs files before stopping the OSD and monitor clients. debugfs_remove() drains active handlers and prevents new accesses, so the debugfs callbacks can no longer race the rest of client teardown.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68153","epss":0.00125,"percentile":0.02547,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-68153","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68153","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/463a264e9094384112a5c8b46f0a9ddaf8566904","https://git.kernel.org/stable/c/8f5a3abc54ba24dbceb14cc3a719908c4f688091","https://git.kernel.org/stable/c/ac78549d186090ee7125d28c3a8c376573b36194","https://git.kernel.org/stable/c/b9fedda2f628e030384228de0dafc574b7fb0c2f","https://git.kernel.org/stable/c/d3dc8889d39a676bf840132bd5c5c48cb0daba23","https://git.kernel.org/stable/c/e4c804726c4afce3ba648b982d564f6af2cfa328","https://git.kernel.org/stable/c/fc1010e7e0204ece6cc0f9af4f473e9553535eab","https://git.kernel.org/stable/c/fe46b7e06f14f6f94766832df309b249cb689d27"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: remove debugfs files before client teardown\n\nceph_destroy_client() tears down the monitor client before removing\nthe per-client debugfs files. A concurrent read of the monmap debugfs\nfile can enter monmap_show() after ceph_monc_stop() has freed\nmonc->monmap, triggering a use-after-free.\n\nRemove the debugfs files before stopping the OSD and monitor clients.\ndebugfs_remove() drains active handlers and prevents new accesses, so\nthe debugfs callbacks can no longer race the rest of client teardown.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68153","epss":0.00125,"percentile":0.02547,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68153","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68154","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68154","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: reject zero bucket types in crush_decode  CRUSH bucket type 0 is reserved for devices.  The mapper relies on that invariant and uses type 0 to identify leaf devices.  If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value.  Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68154","epss":0.00704,"percentile":0.51176,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.66176},"relatedVulnerabilities":[{"id":"CVE-2026-68154","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68154","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/05f90284223381005d6bcddab3fda4a97f9c3401","https://git.kernel.org/stable/c/146461f09565afe3665e65b0423d3d6b0fe806c5","https://git.kernel.org/stable/c/3b2f1937f5fce8b7dd5432e7693e3cc8b5eece56","https://git.kernel.org/stable/c/70998f91030ee083ecb336a1dff0701c20a38081","https://git.kernel.org/stable/c/80fc40e11cda1b5d990a3f69c6efa344fb5cd987","https://git.kernel.org/stable/c/826cd1de5802fd392922785f9b64d76e65d2a100","https://git.kernel.org/stable/c/952ca5dc99913d169263f59fd689f586729a13c1","https://git.kernel.org/stable/c/b8a9fb6bf806f9c4891e71ae1beab0c07c23a877"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: reject zero bucket types in crush_decode\n\nCRUSH bucket type 0 is reserved for devices.  The mapper relies on\nthat invariant and uses type 0 to identify leaf devices.\n\nIf crush_decode() accepts a bucket with type 0, a malformed CRUSH map\ncan make the mapper treat a negative bucket ID as a device and pass it\nto is_out(), which then indexes the OSD weight array with a negative\nvalue.\n\nReject zero bucket types while decoding the CRUSH map so the invalid\nstate never reaches the mapper.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68154","epss":0.00704,"percentile":0.51176,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68154","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68155","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68155","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: Reject monmaps advertising zero monitors  A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in the cluster. Currently, a monmap indicating that there are zero monitors in the cluster is treated as valid. However, it is impossible to have zero monitors in the cluster and still receive a valid monmap from a monitor. Therefore, such a monmap must be corrupted and should be treated as invalid. Furthermore, a monmap with a monitor count of zero can subsequently crash the client when attempting to open a session with a monitor in __open_session(). This happens because the \"BUG_ON(monc->monmap->num_mon < 1)\" assertion in pick_new_mon() is triggered.  This patch extends a check in ceph_monmap_decode() to also reject arriving mon_maps with num_mon == 0 rather than only with num_mon > CEPH_MAX_MON.  [ idryomov: drop \"log output for unusual values of num_mon\" part ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68155","epss":0.00662,"percentile":0.49548,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.4965},"relatedVulnerabilities":[{"id":"CVE-2026-68155","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68155","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0591a15815b498be628a937146e44487d599ba33","https://git.kernel.org/stable/c/3b249546f59c3d6d3592c10657f82bc3f1faa07c","https://git.kernel.org/stable/c/40480eee361ed9676b3f844d532ac28b47251634","https://git.kernel.org/stable/c/caf082ef8609a6ac26159ce115f55ab7d00231a3","https://git.kernel.org/stable/c/cd0d41bc569632eaaeccde9d2a6bc919ec00c407","https://git.kernel.org/stable/c/e3ccd4ecab09b22f507f49cb7ed9990c7158ceab","https://git.kernel.org/stable/c/e67e8b694872c9bc66996040f9de9242f6236ed9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Reject monmaps advertising zero monitors\n\nA message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a\nmonitor to the client. This monmap contains information about the\nexisting monitors in the cluster. Currently, a monmap indicating that\nthere are zero monitors in the cluster is treated as valid. However, it\nis impossible to have zero monitors in the cluster and still receive a\nvalid monmap from a monitor. Therefore, such a monmap must be corrupted\nand should be treated as invalid. Furthermore, a monmap with a monitor\ncount of zero can subsequently crash the client when attempting to open\na session with a monitor in __open_session(). This happens because the\n\"BUG_ON(monc->monmap->num_mon < 1)\" assertion in pick_new_mon() is\ntriggered.\n\nThis patch extends a check in ceph_monmap_decode() to also reject\narriving mon_maps with num_mon == 0 rather than only with\nnum_mon > CEPH_MAX_MON.\n\n[ idryomov: drop \"log output for unusual values of num_mon\" part ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68155","epss":0.00662,"percentile":0.49548,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68155","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68156","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68156","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: refresh auth->authorizer_buf{,_len} after authorizer update  ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake.  These cached values are then used by the messenger connect code when sending the authorizer.  ceph_x_update_authorizer() can rebuild the authorizer when a newer service ticket is available.  If the rebuilt authorizer no longer fits in the existing buffer, ceph_x_build_authorizer() drops its reference to au->buf and allocates a new one.  If this is the final reference, ceph_buffer_put() frees the old ceph_buffer and its vec.iov_base, but auth->authorizer_buf still points at that freed memory.  A subsequent msgr1 reconnect can therefore queue the stale pointer and trigger a KASAN slab-use-after-free in _copy_from_iter() while tcp_sendmsg() copies the authorizer.  Refresh auth->authorizer_buf and auth->authorizer_buf_len after a successful authorizer rebuild so the messenger sends the current buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68156","epss":0.00684,"percentile":0.50459,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.64296},"relatedVulnerabilities":[{"id":"CVE-2026-68156","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68156","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0060ec912292a550198d8d18ac95b433c92a7091","https://git.kernel.org/stable/c/2334e9997308305ee4fd508fdfe6086c4150ed60","https://git.kernel.org/stable/c/26f814187abceee90dbb29a02133adb4786fbb13","https://git.kernel.org/stable/c/5ecfcd5c05866f185357700b81b461dae4f5ebb2","https://git.kernel.org/stable/c/75e82e8944ac1efe9fdb88bd2f14d9a031282bdf","https://git.kernel.org/stable/c/79a273df64238a4ade8b709689a78589f755b8ef","https://git.kernel.org/stable/c/937d61f86d377a3aa578adae7a3dfcecdddf9d89","https://git.kernel.org/stable/c/9d37aec9ffe4e743dabc3f84502e9723e17a30d4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: refresh auth->authorizer_buf{,_len} after authorizer update\n\nceph_x_create_authorizer() caches au->buf->vec.iov_base and\nau->buf->vec.iov_len in struct ceph_auth_handshake.  These\ncached values are then used by the messenger connect code when\nsending the authorizer.\n\nceph_x_update_authorizer() can rebuild the authorizer when a newer\nservice ticket is available.  If the rebuilt authorizer no longer\nfits in the existing buffer, ceph_x_build_authorizer() drops its\nreference to au->buf and allocates a new one.  If this is the final\nreference, ceph_buffer_put() frees the old ceph_buffer and its\nvec.iov_base, but auth->authorizer_buf still points at that freed\nmemory.\n\nA subsequent msgr1 reconnect can therefore queue the stale pointer\nand trigger a KASAN slab-use-after-free in _copy_from_iter() while\ntcp_sendmsg() copies the authorizer.\n\nRefresh auth->authorizer_buf and auth->authorizer_buf_len after a\nsuccessful authorizer rebuild so the messenger sends the current\nbuffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68156","epss":0.00684,"percentile":0.50459,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68156","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68157","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68157","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: guard missing CRUSH type name lookup  Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_names. get_immediate_parent() then dereferences a NULL type_cn and passes an invalid pointer into strcmp(), causing a null-ptr-deref.  Skip such malformed parent buckets unless both the bucket name and type name metadata are present. This keeps malformed hierarchy data from crashing locality lookup and safely falls back to \"not local\".  [ idryomov: add WARN_ON_ONCE ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68157","epss":0.00686,"percentile":0.50546,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.5145000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68157","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68157","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50","https://git.kernel.org/stable/c/4716a64b7cc2797741f7be4e283ace78a9dff37d","https://git.kernel.org/stable/c/6a4b75d90f0cfbf22c14742ab35a803bc13f36ec","https://git.kernel.org/stable/c/8ff579ac03d6e9d17d6d9c8443110167c14a382d","https://git.kernel.org/stable/c/bbeae12fda3384a90fbebc8a19ba9d33f85b5361","https://git.kernel.org/stable/c/c46d82c47afc968d6ee8ef4470fa2dd35b765c21","https://git.kernel.org/stable/c/cbfcba275326c8c7dae9acd8f4a0d4c316fdafb0","https://git.kernel.org/stable/c/db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: guard missing CRUSH type name lookup\n\nLocalized read selection can walk a parent bucket whose name exists in\nthe CRUSH map while its type has no matching entry in type_names.\nget_immediate_parent() then dereferences a NULL type_cn and passes an\ninvalid pointer into strcmp(), causing a null-ptr-deref.\n\nSkip such malformed parent buckets unless both the bucket name and type\nname metadata are present. This keeps malformed hierarchy data from\ncrashing locality lookup and safely falls back to \"not local\".\n\n[ idryomov: add WARN_ON_ONCE ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68157","epss":0.00686,"percentile":0.50546,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68157","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68158","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68158","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: Fix multiplication overflow in decode_new_up_state_weight()  If a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted osdmap, out-of-bounds memory accesses may occur in decode_new_up_state_weight(). This happens because the bounds check for the new_state part is based on calculating its length depending on a len value read from the incoming message. This calculation may overflow leading to an incorrect bounds check. Subsequently, out-of-bounds reads may occur when decoding this part.  This patch switches the multiplication to use check_mul_overflow() to abort processing the osdmap if an overflow occurred. Therefore, osdmaps/messages containing large values for len that result in a multiplication overflow are treated as invalid.  [ idryomov: rename new_state_len -> new_state_item_size, formatting ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68158","epss":0.00704,"percentile":0.51176,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.66176},"relatedVulnerabilities":[{"id":"CVE-2026-68158","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68158","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/05c90e059269f087becfcce23348496085835c29","https://git.kernel.org/stable/c/143ba49ead77ec483c0326f8aaad8649874e99c4","https://git.kernel.org/stable/c/1732d89dfcd74f6fde9ce70900d316c4a151c153","https://git.kernel.org/stable/c/2ceee3b77b83052648c40fef965f836fd7699d26","https://git.kernel.org/stable/c/98917a499ec7064c14fc56d180a4fd636fc2784c","https://git.kernel.org/stable/c/bee4b5b53e7bff0467fd916cc44c9b190733c6bd","https://git.kernel.org/stable/c/e4473751cc37db41f3f7da25d64a23e0c74570f1","https://git.kernel.org/stable/c/f6961070c326bd158c38fa48756cde2bd78c4aaa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix multiplication overflow in decode_new_up_state_weight()\n\nIf a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted\nosdmap, out-of-bounds memory accesses may occur in\ndecode_new_up_state_weight(). This happens because the bounds check for\nthe new_state part is based on calculating its length depending on a len\nvalue read from the incoming message. This calculation may overflow\nleading to an incorrect bounds check. Subsequently, out-of-bounds reads\nmay occur when decoding this part.\n\nThis patch switches the multiplication to use check_mul_overflow() to\nabort processing the osdmap if an overflow occurred. Therefore,\nosdmaps/messages containing large values for len that result in a\nmultiplication overflow are treated as invalid.\n\n[ idryomov: rename new_state_len -> new_state_item_size, formatting ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68158","epss":0.00704,"percentile":0.51176,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68158","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68159","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68159","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE  __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it to CEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and apply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size on-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends an OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack out-of-bounds write.  An OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer entries at decode time. The bound is well below the old overflow threshold, so it also covers the allocation-size overflow the previous check guarded against.    BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds   Write of size 4 ... by task exploit    kasan_report (mm/kasan/report.c:595)    ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833)    calc_target (net/ceph/osd_client.c:1638)    __submit_request (net/ceph/osd_client.c:2394)    ceph_osdc_start_request (net/ceph/osd_client.c:2490)    ceph_osdc_call (net/ceph/osd_client.c:5164)    rbd_dev_image_probe (drivers/block/rbd.c:6899)    do_rbd_add (drivers/block/rbd.c:7138)    ...   kernel BUG at net/ceph/osdmap.c:2670!  [ idryomov: do the same in __decode_pg_upmap_items() ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68159","epss":0.00745,"percentile":0.52639,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.7003},"relatedVulnerabilities":[{"id":"CVE-2026-68159","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68159","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/42bc06c67d94d5f2a6b33294b0c4b07d8a47c515","https://git.kernel.org/stable/c/4daf06456677177f2a6044729abac59c1b49e87b","https://git.kernel.org/stable/c/590b07ceea138d49c9b64f65d263aa902d3b4730","https://git.kernel.org/stable/c/66eec4af1e080b695229c9a20635648a6d12fedf","https://git.kernel.org/stable/c/9f00f9cf2be293efe899db67dc5272e3a9c62717","https://git.kernel.org/stable/c/d5650ddbd4d42c1a916c8fe1a4c4cb573ef810a1","https://git.kernel.org/stable/c/e36663145abd7024f0281dfb22fdef65f185845b","https://git.kernel.org/stable/c/ebdf4b4f3b1474079980a2e5cd79ad65fb54db57"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE\n\n__decode_pg_temp() decodes an user-controlled length but only rejects\nvalues large enough to overflow the allocation; it does not bound it to\nCEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and\napply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size\non-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends\nan OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack\nout-of-bounds write.\n\nAn OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer\nentries at decode time. The bound is well below the old overflow threshold, so\nit also covers the allocation-size overflow the previous check guarded against.\n\n  BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds\n  Write of size 4 ... by task exploit\n   kasan_report (mm/kasan/report.c:595)\n   ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833)\n   calc_target (net/ceph/osd_client.c:1638)\n   __submit_request (net/ceph/osd_client.c:2394)\n   ceph_osdc_start_request (net/ceph/osd_client.c:2490)\n   ceph_osdc_call (net/ceph/osd_client.c:5164)\n   rbd_dev_image_probe (drivers/block/rbd.c:6899)\n   do_rbd_add (drivers/block/rbd.c:7138)\n   ...\n  kernel BUG at net/ceph/osdmap.c:2670!\n\n[ idryomov: do the same in __decode_pg_upmap_items() ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68159","epss":0.00745,"percentile":0.52639,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68159","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68160","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68160","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()  ceph_handle_caps() reads snap_trace_len from the wire-format ceph_mds_caps header and uses it unconditionally to build a fake end pointer (snaptrace + snaptrace_len) that is later handed to ceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:      snaptrace     = h + 1;     snaptrace_len = le32_to_cpu(h->snap_trace_len);     p             = snaptrace + snaptrace_len;     ...     case CEPH_CAP_OP_IMPORT:         if (snaptrace_len) {             ...             if (ceph_update_snap_trace(mdsc, snaptrace,                                        snaptrace + snaptrace_len,                                        false, &realm)) { ... }  ceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm from snaptrace using ceph_decode_need(&p, e, sizeof(*ri), bad) with the attacker-supplied fake end e == snaptrace + snaptrace_len. With snaptrace_len == 0xFFFFFFFF the bound check is trivially satisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past the legitimate msg->front buffer, and ri->num_snaps / ri->num_prior_parent_snaps then drive further out-of-bounds reads of the encoded snap arrays.  The eleven msg_version >= 2 .. msg_version >= 12 decoder blocks above the op switch each catch this OOB through their ceph_decode_*_safe() / ceph_decode_need() helpers, but they sit behind a hdr.version-gated if, so a malicious or compromised MDS that sets msg->hdr.version = 1 reaches the IMPORT path with no version-gated decoder having validated snap_trace_len. The shape has been present since ceph_handle_caps() was introduced.  Validate snap_trace_len against the message front buffer before consuming it, using the canonical ceph_decode_need() / ceph_has_room() helper.  The helper bounds the length with subtraction (n <= end - p, guarded by end >= p) rather than pointer addition, so it is wrap-safe for the attacker-controlled u32 length on 32-bit builds where p + snap_trace_len could overflow the address space.  This matches the rest of the ceph decode path (e.g. the pool_ns_len check a few lines below), and the existing goto bad cleanup already covers this exit path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68160","epss":0.00751,"percentile":0.52846,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.70594},"relatedVulnerabilities":[{"id":"CVE-2026-68160","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68160","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/03b417afce19ee6b6e61f1bbbbebac924c9f36d1","https://git.kernel.org/stable/c/0c011137194036424e974677e0f1592e22a33d8c","https://git.kernel.org/stable/c/4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02","https://git.kernel.org/stable/c/71893c342a26bcff92eaab0b2b75d64aed19308a","https://git.kernel.org/stable/c/9081c71796724ffe96cba253f68fbe42363c5295","https://git.kernel.org/stable/c/a4228b93706fb74a484e6ffb271c1cc2af3a2ddb","https://git.kernel.org/stable/c/cc93f68a31c9b831abf2db8647b5f5b10329d793","https://git.kernel.org/stable/c/f913192fc782288e060dafc329b2346934be34cc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()\n\nceph_handle_caps() reads snap_trace_len from the wire-format\nceph_mds_caps header and uses it unconditionally to build a fake\nend pointer (snaptrace + snaptrace_len) that is later handed to\nceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:\n\n    snaptrace     = h + 1;\n    snaptrace_len = le32_to_cpu(h->snap_trace_len);\n    p             = snaptrace + snaptrace_len;\n    ...\n    case CEPH_CAP_OP_IMPORT:\n        if (snaptrace_len) {\n            ...\n            if (ceph_update_snap_trace(mdsc, snaptrace,\n                                       snaptrace + snaptrace_len,\n                                       false, &realm)) { ... }\n\nceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm\nfrom snaptrace using ceph_decode_need(&p, e, sizeof(*ri), bad)\nwith the attacker-supplied fake end e == snaptrace + snaptrace_len.\nWith snaptrace_len == 0xFFFFFFFF the bound check is trivially\nsatisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past\nthe legitimate msg->front buffer, and ri->num_snaps /\nri->num_prior_parent_snaps then drive further out-of-bounds\nreads of the encoded snap arrays.\n\nThe eleven msg_version >= 2 .. msg_version >= 12 decoder blocks\nabove the op switch each catch this OOB through their\nceph_decode_*_safe() / ceph_decode_need() helpers, but they sit\nbehind a hdr.version-gated if, so a malicious or compromised\nMDS that sets msg->hdr.version = 1 reaches the IMPORT path with\nno version-gated decoder having validated snap_trace_len. The\nshape has been present since ceph_handle_caps() was introduced.\n\nValidate snap_trace_len against the message front buffer before\nconsuming it, using the canonical ceph_decode_need() / ceph_has_room()\nhelper.  The helper bounds the length with subtraction (n <= end - p,\nguarded by end >= p) rather than pointer addition, so it is wrap-safe\nfor the attacker-controlled u32 length on 32-bit builds where\np + snap_trace_len could overflow the address space.  This matches the\nrest of the ceph decode path (e.g. the pool_ns_len check a few lines\nbelow), and the existing goto bad cleanup already covers this exit\npath.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68160","epss":0.00751,"percentile":0.52846,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68160","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68161","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68161","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: close UDP tunnel sockets during netns teardown  proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when net.sctp.udp_port is set, and stops/restarts them when the sysctl value changes. The netns exit path does not stop these sockets, so a namespace can be torn down while its SCTP UDP tunnel sockets are still installed.  Close the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering the per-net sysctl table. This prevents new sysctl writes from racing in while the sockets are being released, and closes the sockets before the control socket is destroyed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68161","epss":0.00626,"percentile":0.47957,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.5884400000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68161","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68161","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/37ff9794be48d0caa37687e04d09675f9c849121","https://git.kernel.org/stable/c/3bf0e349cbb4f975f35eb22753acc346b89c66a0","https://git.kernel.org/stable/c/8ff78591d309c50a4fdab683b68dd8d512a270dd","https://git.kernel.org/stable/c/c6eb2d615210b80339548ab07c0230edaab9a6c7","https://git.kernel.org/stable/c/ffb2bd7ade36ec4da32c46a6eddbf4515316d08c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: close UDP tunnel sockets during netns teardown\n\nproc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when\nnet.sctp.udp_port is set, and stops/restarts them when the sysctl value\nchanges. The netns exit path does not stop these sockets, so a namespace\ncan be torn down while its SCTP UDP tunnel sockets are still installed.\n\nClose the UDP tunnel sockets from sctp_ctrlsock_exit() after unregistering\nthe per-net sysctl table. This prevents new sysctl writes from racing in\nwhile the sockets are being released, and closes the sockets before the\ncontrol socket is destroyed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68161","epss":0.00626,"percentile":0.47957,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68161","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68162","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68162","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: avoid auth_enable sysctl UAF during netns teardown  proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP state from ctl->data, so an already opened sysctl file can still target a network namespace while that namespace is being torn down.  SCTP previously registered its per-net sysctls from sctp_defaults_init(), while the control socket is created later from sctp_ctrlsock_init(). This exposed a window during initialization where auth_enable was writable before net->sctp.ctl_sock existed, and a teardown window where auth_enable stayed writable after inet_ctl_sock_destroy() had released the control socket.  Move the per-net SCTP sysctl registration into sctp_ctrlsock_init() after sctp_ctl_sock_init() succeeds, and unregister the sysctl table before destroying the control socket in sctp_ctrlsock_exit(). If sysctl registration fails after the control socket was created, destroy the control socket in the same init path.  Make sctp_sysctl_net_unregister() tolerate a missing header and clear the saved pointer so init-error and exit paths can safely share the unregister helper.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68162","epss":0.00184,"percentile":0.08054,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.14076000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-68162","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68162","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/158f3cc332dc53f43ec20060233d7c3cecd6d912","https://git.kernel.org/stable/c/19573dcddb8819fd68d6cd1f916c1c99c3fa4ff4","https://git.kernel.org/stable/c/626bda8cfe43dff19a9833ff6ba055a817b5455c","https://git.kernel.org/stable/c/66700c0719675e0e118ae83b2d7168dacd69dd3d","https://git.kernel.org/stable/c/a50e73488e0bbdd262b3be3c9a1d8dd078382381","https://git.kernel.org/stable/c/be6aae9d1b91c603adb35872d37d40e83daf8758","https://git.kernel.org/stable/c/ceb7190b5c873d4a1267a1600c5aa52c600e929f","https://git.kernel.org/stable/c/f8d5e7846025f4ab15a461235f8ebae9094a361a","https://git.kernel.org/stable/c/fd66854a22661929245f3d2b244c432bc8b1a150"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: avoid auth_enable sysctl UAF during netns teardown\n\nproc_sctp_do_auth() updates the SCTP control socket after changing\nnet.sctp.auth_enable. The handler gets the per-net SCTP state from\nctl->data, so an already opened sysctl file can still target a network\nnamespace while that namespace is being torn down.\n\nSCTP previously registered its per-net sysctls from sctp_defaults_init(),\nwhile the control socket is created later from sctp_ctrlsock_init(). This\nexposed a window during initialization where auth_enable was writable\nbefore net->sctp.ctl_sock existed, and a teardown window where auth_enable\nstayed writable after inet_ctl_sock_destroy() had released the control\nsocket.\n\nMove the per-net SCTP sysctl registration into sctp_ctrlsock_init() after\nsctp_ctl_sock_init() succeeds, and unregister the sysctl table before\ndestroying the control socket in sctp_ctrlsock_exit(). If sysctl\nregistration fails after the control socket was created, destroy the\ncontrol socket in the same init path.\n\nMake sctp_sysctl_net_unregister() tolerate a missing header and clear the\nsaved pointer so init-error and exit paths can safely share the unregister\nhelper.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68162","epss":0.00184,"percentile":0.08054,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68162","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68164","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68164","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/damon/core: disallow overlapping input ranges for damon_set_regions()  damon_set_regions() assumes the input ranges are sorted by the address and don't overlap each other.  Hence the assumption was initially to be explicitly validated.  But commit 97d482f4592f (\"mm/damon/sysfs: reuse damon_set_regions() for regions setting\") has mistakenly removed the validation.  This can make DAMON behave in unexpected ways.  At the best, the monitoring results snapshot will just look weird since there will be overlapping regions.  DAMOS will also work weirdly, applying the same action multiple times for overlapping regions, and make DAMOS quota weird. More seriously, depending on the setup and regions updates sequence, negative size regions can be made.  It will trigger WARN_ONCE() if the kernel is built with CONFIG_DAMON_DEBUG_SANITY=y.  Depending on the monitoring results, the negative size region can further trigger division by zero in damon_merge_two_regions().  Note that some of the consequences including the WARN_ONCE() and the divide by zero depend on commits that were introduced after the root cause commit 97d482f4592f (\"mm/damon/sysfs: reuse damon_set_regions() for regions setting\").  Fix the problems by checking the assumption and returning an error if the input ranges don't meet the assumption.  The issue was discovered [1] by Sashiko.","cvss":[],"epss":[{"cve":"CVE-2026-68164","epss":0.00215,"percentile":0.1181,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1075},"relatedVulnerabilities":[{"id":"CVE-2026-68164","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68164","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/06a4beeeec8f03f0b3e9c78a98f1ae4f0f18cfbd","https://git.kernel.org/stable/c/4b4a3e7ef7bb622237495db9ba4dfd7417d6530e","https://git.kernel.org/stable/c/6ce0db97fb37ab8cf8596edca0e3de8618ab009a","https://git.kernel.org/stable/c/954157679ec34661c2e87e7eb796104a797c32db","https://git.kernel.org/stable/c/a5c453fffb6f2ce75fc10b5d8bc475f1758010bd","https://git.kernel.org/stable/c/e33adf96afb5883f84b0d98747976bde293e33cb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: disallow overlapping input ranges for damon_set_regions()\n\ndamon_set_regions() assumes the input ranges are sorted by the address and\ndon't overlap each other.  Hence the assumption was initially to be\nexplicitly validated.  But commit 97d482f4592f (\"mm/damon/sysfs: reuse\ndamon_set_regions() for regions setting\") has mistakenly removed the\nvalidation.\n\nThis can make DAMON behave in unexpected ways.  At the best, the\nmonitoring results snapshot will just look weird since there will be\noverlapping regions.  DAMOS will also work weirdly, applying the same\naction multiple times for overlapping regions, and make DAMOS quota weird.\nMore seriously, depending on the setup and regions updates sequence,\nnegative size regions can be made.  It will trigger WARN_ONCE() if the\nkernel is built with CONFIG_DAMON_DEBUG_SANITY=y.  Depending on the\nmonitoring results, the negative size region can further trigger division\nby zero in damon_merge_two_regions().\n\nNote that some of the consequences including the WARN_ONCE() and the\ndivide by zero depend on commits that were introduced after the root cause\ncommit 97d482f4592f (\"mm/damon/sysfs: reuse damon_set_regions() for\nregions setting\").\n\nFix the problems by checking the assumption and returning an error if\nthe input ranges don't meet the assumption.\n\nThe issue was discovered [1] by Sashiko.","cvss":[],"epss":[{"cve":"CVE-2026-68164","epss":0.00215,"percentile":0.1181,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68164","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68165","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68165","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/damon/core: validate ranges in damon_set_regions()  DAMON core logic assumes zero length regions don't exist.  However, a few DAMON API callers including DAMON_SYSFS, DAMON_RECLAIM and DAMON_LRU_SORT allow users to set empty monitoring target regions.  This could result in WARN_ONCE() on CONFIG_DAMON_DEBUG_SANITY enabled kernel, and divide-by-zero from damon_merge_two_regions().  For example, the WANR_ONCE() can be triggered like below.      # grep DAMON_DEBUG_SANITY /boot/config-$(uname -r)     # CONFIG_DAMON_DEBUG_SANITY=y     # damo start     # cd /sys/kernel/mm/damon/admin/kdamonds/0     # echo 0 > contexts/0/targets/0/regions/0/start     # echo 0 > contexts/0/targets/0/regions/0/end     # echo commit > state     # dmesg     [....]     [   73.705780] ------------[ cut here ]------------     [   73.707552] start 0 >= end 0     [   73.708452] WARNING: mm/damon/core.c:359 at damon_new_region+0x6e/0x80, CPU#1: kdamond.0/758     [...]  All DAMON API callers eventually use damon_set_regions() to setup the regions.  Add the validation logic in the function.","cvss":[],"epss":[{"cve":"CVE-2026-68165","epss":0.00205,"percentile":0.10657,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10250000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68165","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68165","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1292c0ecb1caefb8ca064a3639d5673991e8810c","https://git.kernel.org/stable/c/43aaddd0fa92010a68adeda7744c7cf497a1c8e9","https://git.kernel.org/stable/c/4b6f1d6d5d07855bd1bb9e64922b049062138bfa","https://git.kernel.org/stable/c/71cf8a3ee1c18cfa8b88cc14bac9c2f43dd29f9b","https://git.kernel.org/stable/c/b585facbafbb5cf117b37b1c75819ac046646c27","https://git.kernel.org/stable/c/c927b73a5694c735314ea10e7c81c07f9bd51ad7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/core: validate ranges in damon_set_regions()\n\nDAMON core logic assumes zero length regions don't exist.  However, a few\nDAMON API callers including DAMON_SYSFS, DAMON_RECLAIM and DAMON_LRU_SORT\nallow users to set empty monitoring target regions.  This could result in\nWARN_ONCE() on CONFIG_DAMON_DEBUG_SANITY enabled kernel, and\ndivide-by-zero from damon_merge_two_regions().\n\nFor example, the WANR_ONCE() can be triggered like below.\n\n    # grep DAMON_DEBUG_SANITY /boot/config-$(uname -r)\n    # CONFIG_DAMON_DEBUG_SANITY=y\n    # damo start\n    # cd /sys/kernel/mm/damon/admin/kdamonds/0\n    # echo 0 > contexts/0/targets/0/regions/0/start\n    # echo 0 > contexts/0/targets/0/regions/0/end\n    # echo commit > state\n    # dmesg\n    [....]\n    [   73.705780] ------------[ cut here ]------------\n    [   73.707552] start 0 >= end 0\n    [   73.708452] WARNING: mm/damon/core.c:359 at damon_new_region+0x6e/0x80, CPU#1: kdamond.0/758\n    [...]\n\nAll DAMON API callers eventually use damon_set_regions() to setup the\nregions.  Add the validation logic in the function.","cvss":[],"epss":[{"cve":"CVE-2026-68165","epss":0.00205,"percentile":0.10657,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68165","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68169","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68169","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mptcp: pm: userspace: fix use-after-free in get_local_id  In mptcp_pm_userspace_get_local_id(), the address entry is looked up under spinlock, but its id is read after dropping the lock. A concurrent deletion can free the entry between the unlock and the read, leading to UAF.  The race window is narrow. It was reproduced only with a locally constructed stress test that repeatedly overlaps an MP_JOIN SYN with a MPTCP_PM_CMD_SUBFLOW_DESTROY request.  However, the KASAN report below confirms that the race is reachable:    [  666.319376] BUG: KASAN: slab-use-after-free in mptcp_userspace_pm_get_local_id+0x1dc/0x1f0   [  666.319386] Read of size 1 at addr ffff888124845610 by task swapper/0/0   ...   [  666.319401] Call Trace:   [  666.319405]  <IRQ>   [  666.319408]  dump_stack_lvl+0x53/0x70   [  666.319412]  print_address_description.constprop.0+0x2c/0x3b0   [  666.319418]  print_report+0xbe/0x2b0   [  666.319421]  ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0   [  666.319423]  kasan_report+0xce/0x100   [  666.319426]  ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0   [  666.319429]  mptcp_userspace_pm_get_local_id+0x1dc/0x1f0   [  666.319433]  mptcp_pm_get_local_id+0x371/0x440   ...   [  666.319821] Allocated by task 45539:   [  666.319844]  kasan_save_stack+0x33/0x60   [  666.319855]  kasan_save_track+0x14/0x30   [  666.319858]  __kasan_kmalloc+0x8f/0xa0   [  666.319863]  __kmalloc_noprof+0x1e7/0x520   [  666.319867]  sock_kmalloc+0xdf/0x130   [  666.319885]  sock_kmemdup+0x1b/0x40   [  666.319888]  mptcp_userspace_pm_append_new_local_addr+0x261/0x500   [  666.319910]  mptcp_pm_nl_announce_doit+0x16a/0x610   ...   [  666.319967] Freed by task 45560:   [  666.319988]  kasan_save_stack+0x33/0x60   [  666.319991]  kasan_save_track+0x14/0x30   [  666.319994]  kasan_save_free_info+0x3b/0x60   [  666.319998]  __kasan_slab_free+0x43/0x70   [  666.320000]  kfree+0x166/0x440   [  666.320003]  sock_kfree_s+0x1d/0x50   [  666.320007]  mptcp_userspace_pm_delete_local_addr.isra.0+0x157/0x200   [  666.320011]  mptcp_pm_nl_subflow_destroy_doit+0x51d/0xea0  Fix by copying the id into a local variable while still holding the lock, and use -1 as a \"not found\" sentinel.","cvss":[],"epss":[{"cve":"CVE-2026-68169","epss":0.00206,"percentile":0.10699,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68169","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68169","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/31ce5af66891f79998fb2e8b8df08e3c98fd72e3","https://git.kernel.org/stable/c/40dde4b5d98279471a70e5c8bb713182738c00d9","https://git.kernel.org/stable/c/8ce48d2879aafc0e7a6f8bfc3613c0ba979ec6f5","https://git.kernel.org/stable/c/9bc6d5e4ca9f3cbb41d43400b3a31cb0403796c9","https://git.kernel.org/stable/c/d2c3760b45f2f481a4dd4c5adef4a29dfabd948f","https://git.kernel.org/stable/c/d64f6c02495f3fad674038cfa7ec049671b59e7b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: userspace: fix use-after-free in get_local_id\n\nIn mptcp_pm_userspace_get_local_id(), the address entry is looked up under\nspinlock, but its id is read after dropping the lock. A concurrent deletion\ncan free the entry between the unlock and the read, leading to UAF.\n\nThe race window is narrow. It was reproduced only with a locally\nconstructed stress test that repeatedly overlaps an MP_JOIN SYN with a\nMPTCP_PM_CMD_SUBFLOW_DESTROY request.\n\nHowever, the KASAN report below confirms that the race is reachable:\n\n  [  666.319376] BUG: KASAN: slab-use-after-free in mptcp_userspace_pm_get_local_id+0x1dc/0x1f0\n  [  666.319386] Read of size 1 at addr ffff888124845610 by task swapper/0/0\n  ...\n  [  666.319401] Call Trace:\n  [  666.319405]  <IRQ>\n  [  666.319408]  dump_stack_lvl+0x53/0x70\n  [  666.319412]  print_address_description.constprop.0+0x2c/0x3b0\n  [  666.319418]  print_report+0xbe/0x2b0\n  [  666.319421]  ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0\n  [  666.319423]  kasan_report+0xce/0x100\n  [  666.319426]  ? mptcp_userspace_pm_get_local_id+0x1dc/0x1f0\n  [  666.319429]  mptcp_userspace_pm_get_local_id+0x1dc/0x1f0\n  [  666.319433]  mptcp_pm_get_local_id+0x371/0x440\n  ...\n  [  666.319821] Allocated by task 45539:\n  [  666.319844]  kasan_save_stack+0x33/0x60\n  [  666.319855]  kasan_save_track+0x14/0x30\n  [  666.319858]  __kasan_kmalloc+0x8f/0xa0\n  [  666.319863]  __kmalloc_noprof+0x1e7/0x520\n  [  666.319867]  sock_kmalloc+0xdf/0x130\n  [  666.319885]  sock_kmemdup+0x1b/0x40\n  [  666.319888]  mptcp_userspace_pm_append_new_local_addr+0x261/0x500\n  [  666.319910]  mptcp_pm_nl_announce_doit+0x16a/0x610\n  ...\n  [  666.319967] Freed by task 45560:\n  [  666.319988]  kasan_save_stack+0x33/0x60\n  [  666.319991]  kasan_save_track+0x14/0x30\n  [  666.319994]  kasan_save_free_info+0x3b/0x60\n  [  666.319998]  __kasan_slab_free+0x43/0x70\n  [  666.320000]  kfree+0x166/0x440\n  [  666.320003]  sock_kfree_s+0x1d/0x50\n  [  666.320007]  mptcp_userspace_pm_delete_local_addr.isra.0+0x157/0x200\n  [  666.320011]  mptcp_pm_nl_subflow_destroy_doit+0x51d/0xea0\n\nFix by copying the id into a local variable while still holding the lock,\nand use -1 as a \"not found\" sentinel.","cvss":[],"epss":[{"cve":"CVE-2026-68169","epss":0.00206,"percentile":0.10699,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68169","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68175","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68175","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing: Fix resource leak on mmiotrace trace_pipe close  The mmiotrace tracer was added May 12th 2008. At that time, resources created in pipe_open() could not be freed because there was not pipe_close function pointer of the tracer. The pipe_close function pointer was added in December 7th, 2009, but the mmiotrace tracer was not updated.  mmio_pipe_open() allocates a header_iter and takes a pci_dev reference when trace_pipe is opened. mmio_close() frees them, but it was only wired to the tracer's .close callback.  tracing_release_pipe() invokes .pipe_close, not .close, when the trace_pipe file is released. As a result, closing trace_pipe with the mmiotrace tracer active leaked the header_iter allocation and left a stale pci_dev reference.  Set .pipe_close to mmio_close, matching how function_graph wires both callbacks to the same handler.  Note, if the trace_pipe is read to completion, it will clean up the resources, but if one were to run:    # head -n 1 /sys/kernel/tracing/trace_pipe  VERSION 20070824  Over and over again, it would trigger a massive leak.","cvss":[],"epss":[{"cve":"CVE-2026-68175","epss":0.00211,"percentile":0.11306,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-68175","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68175","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1d0b59e2b203c02149d8f63607329debe36b3ec5","https://git.kernel.org/stable/c/581ac13e12e77d6c64f8719083bdf95209308919","https://git.kernel.org/stable/c/594e1cf3f736779a535873fd5988162d827bfe4f","https://git.kernel.org/stable/c/7871128ea41217fa6a58bbbcb44cb0d2e9e60966","https://git.kernel.org/stable/c/c1d87e724ae55e781b7cc7ccafb34d9e668582b2","https://git.kernel.org/stable/c/cb459fec4f7b13caf646101ff076e94ef38434d8","https://git.kernel.org/stable/c/cf5a82bef623b969a609f2b7e392d06dbae34aa6","https://git.kernel.org/stable/c/f9e6dfe341fb31c95b9655eb6b1db8b3ae090817"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix resource leak on mmiotrace trace_pipe close\n\nThe mmiotrace tracer was added May 12th 2008. At that time, resources\ncreated in pipe_open() could not be freed because there was not\npipe_close function pointer of the tracer. The pipe_close function pointer\nwas added in December 7th, 2009, but the mmiotrace tracer was not updated.\n\nmmio_pipe_open() allocates a header_iter and takes a pci_dev reference\nwhen trace_pipe is opened. mmio_close() frees them, but it was only\nwired to the tracer's .close callback.\n\ntracing_release_pipe() invokes .pipe_close, not .close, when the\ntrace_pipe file is released. As a result, closing trace_pipe with the\nmmiotrace tracer active leaked the header_iter allocation and left a\nstale pci_dev reference.\n\nSet .pipe_close to mmio_close, matching how function_graph wires both\ncallbacks to the same handler.\n\nNote, if the trace_pipe is read to completion, it will clean up the\nresources, but if one were to run:\n\n  # head -n 1 /sys/kernel/tracing/trace_pipe\n VERSION 20070824\n\nOver and over again, it would trigger a massive leak.","cvss":[],"epss":[{"cve":"CVE-2026-68175","epss":0.00211,"percentile":0.11306,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68175","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68176","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68176","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev  If the mmio_pipe_open() fails to find a PCI device, the hiter->dev will be assigned to NULL. The mmiotrace read() function dereferences the hiter->dev if hiter exists.  Change the test of the read to not only check hiter being NULL, but also the hiter->dev before dereferencing it.","cvss":[],"epss":[{"cve":"CVE-2026-68176","epss":0.00211,"percentile":0.11305,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-68176","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68176","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0d5aaf91a3d05f7f993401af27872a5fc0f26edc","https://git.kernel.org/stable/c/144f29e85702234b23d2a62abf723e6a17eb5427","https://git.kernel.org/stable/c/201a01102c529772168181190cb084471082cf5c","https://git.kernel.org/stable/c/3635a9e8b453e658a49b39d025f35bbc6e58d0e2","https://git.kernel.org/stable/c/724cd84b0546c07806840fa658714488553d13a2","https://git.kernel.org/stable/c/8464427e1c177809a9488a97dfa2807d9dcf323b","https://git.kernel.org/stable/c/c06470320f8156306986a831010cdc9f9f87cb50","https://git.kernel.org/stable/c/faaf95135184208ee3ac6f33175c8d1800669dfc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix mmiotrace possible NULL dereferencing of hiter->dev\n\nIf the mmio_pipe_open() fails to find a PCI device, the hiter->dev\nwill be assigned to NULL. The mmiotrace read() function dereferences the\nhiter->dev if hiter exists.\n\nChange the test of the read to not only check hiter being NULL, but also\nthe hiter->dev before dereferencing it.","cvss":[],"epss":[{"cve":"CVE-2026-68176","epss":0.00211,"percentile":0.11305,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68176","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68180","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68180","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  intel_th: fix MSC output device reference leak  intel_th_output_open() looks up the output device with bus_find_device_by_devt(), which returns the device with a reference that must be dropped after use.  commit 95fc36a234da (\"intel_th: fix device leak on output open()\") attempted to drop the reference from intel_th_output_release(). However, a successful open replaces file->f_op with the output driver file operations before returning, so close runs the output driver release callback instead.  For MSC outputs, close runs intel_th_msc_release(), which only removes the per-file iterator and does not drop the device reference taken by intel_th_output_open(). Consequently, every successful MSC output open leaks one device reference.  Drop the device reference from intel_th_msc_release(), which is the release path actually used for MSC output files. Remove the now-unused intel_th_output_release() callback from intel_th_output_fops.","cvss":[],"epss":[{"cve":"CVE-2026-68180","epss":0.00211,"percentile":0.11304,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-68180","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68180","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/12ad4fad748e6e563ff4480f03b89134a41b5c37","https://git.kernel.org/stable/c/141641a70ed337e54487f766ede745fc2ce44c42","https://git.kernel.org/stable/c/26e27b8dcef1e4df6f30d8f25b3304a506d482b3","https://git.kernel.org/stable/c/761b785a0cfbce43761227bc42a7f984f31f8921","https://git.kernel.org/stable/c/c3a28f9cb82425fe0835048ed3677f321e780691","https://git.kernel.org/stable/c/caba30eb8bd321c465ecfc7d850ee85f5b353496","https://git.kernel.org/stable/c/ddcf2064d7ec5a8c9afa7cb74442320e443502bc","https://git.kernel.org/stable/c/df55842fddbcdb80e6dd16680439c0f780ed592e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nintel_th: fix MSC output device reference leak\n\nintel_th_output_open() looks up the output device with\nbus_find_device_by_devt(), which returns the device with a reference that\nmust be dropped after use.\n\ncommit 95fc36a234da (\"intel_th: fix device leak on output open()\")\nattempted to drop the reference from intel_th_output_release(). However,\na successful open replaces file->f_op with the output driver file\noperations before returning, so close runs the output driver release\ncallback instead.\n\nFor MSC outputs, close runs intel_th_msc_release(), which only removes\nthe per-file iterator and does not drop the device reference taken by\nintel_th_output_open(). Consequently, every successful MSC output open\nleaks one device reference.\n\nDrop the device reference from intel_th_msc_release(), which is the\nrelease path actually used for MSC output files. Remove the now-unused\nintel_th_output_release() callback from intel_th_output_fops.","cvss":[],"epss":[{"cve":"CVE-2026-68180","epss":0.00211,"percentile":0.11304,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68180","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68181","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68181","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mei: bus: access mei_device under device_lock on cleanup  Fix couple of problems in mei_cl_bus_dev_release():  mei_cl_flush_queues() is running without lock. bus->file_list access after mei_dev_bus_put(bus) can become a use-after-free if this was the last reference to bus.  Protect queues cleanup and WARN traversal by device lock there to avoid the concurrent access problems. Move WARN traversal before mei_dev_bus_put(bus).  This file uses bus variable name for mei_device, adjust code of mei_cl_bus_dev_release() to use bus variable too.","cvss":[],"epss":[{"cve":"CVE-2026-68181","epss":0.00206,"percentile":0.10697,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68181","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68181","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/02e3a755086db847d795f2593ebc45e8ee4f1755","https://git.kernel.org/stable/c/441559d4c595f839b39f0ab6a4ae628427c2fd9e","https://git.kernel.org/stable/c/59dd34854202d9a3faaa87a85205e553fe7150e1","https://git.kernel.org/stable/c/7cf79e8d682fe93777268f029668ce5e214237fd","https://git.kernel.org/stable/c/c88c030a324c9018b77894a19b2564eb66862020","https://git.kernel.org/stable/c/f112ea910e554d58b4b39a4492b7d302f0f4204f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmei: bus: access mei_device under device_lock on cleanup\n\nFix couple of problems in mei_cl_bus_dev_release():\n\nmei_cl_flush_queues() is running without lock.\nbus->file_list access after mei_dev_bus_put(bus) can become a\nuse-after-free if this was the last reference to bus.\n\nProtect queues cleanup and WARN traversal by device lock there\nto avoid the concurrent access problems.\nMove WARN traversal before mei_dev_bus_put(bus).\n\nThis file uses bus variable name for mei_device, adjust\ncode of mei_cl_bus_dev_release() to use bus variable too.","cvss":[],"epss":[{"cve":"CVE-2026-68181","epss":0.00206,"percentile":0.10697,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68181","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68182","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68182","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  comedi: comedi_parport: deal with premature interrupt  Syzbot reported a general protection fault in `comedi_get_is_subdevice_running()`, which was called from the interrupt handler `parport_interrupt()` in the \"comedi_parport\" driver, but it does not currently have a C reproducer for the problem.  It's probably due to a premature interrupt for one of two reasons:  1. The driver sets up the interrupt handler before the comedi subdevices    used by the interrupt handler have been allocated, but does not    disable the interrupt in the parallel port's CTRL register first. 2. The driver uses a user-supplied I/O port base address which Syzbot    would have supplied, but it might not be backed by real parallel port    hardware.  Change the initialization order in the driver's comedi \"attach\" handler (`parport_attach()`) so that the hardware registers are initialized before the interrupt handler is requested.  This should prevent premature interrupts occurring for real hardware.  Also add a test to the interrupt handler to ensure the comedi device is fully attached and return early if it isn't.","cvss":[],"epss":[{"cve":"CVE-2026-68182","epss":0.00211,"percentile":0.11312,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-68182","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68182","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/086a9ae3c5df63ec11033a8c0b3f6a1fd295ddd1","https://git.kernel.org/stable/c/17221216ae8ce6a24e8a4e787382e3ebc81b88a8","https://git.kernel.org/stable/c/48ef18e5eb6b8a9c546038b2ab89a841fcd97fe7","https://git.kernel.org/stable/c/5d059ce0e6a2f6f8b97273499d47b8f917097b48","https://git.kernel.org/stable/c/6ed34611e569fc1a1169905c5228fd0eb2806c1b","https://git.kernel.org/stable/c/a88b25db815ff6edace81b0bb0f4a201133bd215","https://git.kernel.org/stable/c/b061bb4dca49fd93063359d3805387235818778c","https://git.kernel.org/stable/c/cf26dd2d841583c54a87005c4934b92fddb930c3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: comedi_parport: deal with premature interrupt\n\nSyzbot reported a general protection fault in\n`comedi_get_is_subdevice_running()`, which was called from the interrupt\nhandler `parport_interrupt()` in the \"comedi_parport\" driver, but it\ndoes not currently have a C reproducer for the problem.  It's\nprobably due to a premature interrupt for one of two reasons:\n\n1. The driver sets up the interrupt handler before the comedi subdevices\n   used by the interrupt handler have been allocated, but does not\n   disable the interrupt in the parallel port's CTRL register first.\n2. The driver uses a user-supplied I/O port base address which Syzbot\n   would have supplied, but it might not be backed by real parallel port\n   hardware.\n\nChange the initialization order in the driver's comedi \"attach\" handler\n(`parport_attach()`) so that the hardware registers are initialized\nbefore the interrupt handler is requested.  This should prevent\npremature interrupts occurring for real hardware.\n\nAlso add a test to the interrupt handler to ensure the comedi device is\nfully attached and return early if it isn't.","cvss":[],"epss":[{"cve":"CVE-2026-68182","epss":0.00211,"percentile":0.11312,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68182","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68183","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68183","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  firmware: stratix10-svc: fix memory leaks and list corruption bugs  Fix a memory leak when gen_pool_alloc() fails by freeing pmem on the error path. Switch pmem allocation from devm_kzalloc() to kzalloc() with explicit kfree() in the free path to match its list-managed lifetime. Remove the erroneous list_del(&svc_data_mem) which corrupted the list head on failed lookups.","cvss":[],"epss":[{"cve":"CVE-2026-68183","epss":0.00211,"percentile":0.11311,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-68183","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68183","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4f2db41a09eba7a45abd140bb86ffc519c191886","https://git.kernel.org/stable/c/5df709d59227994888d7dbb7ea6c83316f0b79c0","https://git.kernel.org/stable/c/76cff60d7fcb08da537f529bf32a0927bb17265f","https://git.kernel.org/stable/c/8e93a083456d78f6b0aa1f58d2b0c7071a2a7a47","https://git.kernel.org/stable/c/9119ceb76e987c2ec2b549ea100e3268ce3a1c7c","https://git.kernel.org/stable/c/95f702e372964aff486338783f49e28a40a53127","https://git.kernel.org/stable/c/b9206568e08424fd817a4aeca4f944e241d2f530","https://git.kernel.org/stable/c/fff6e5ff0318315998b540896537eaaa2ebf9f7b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: stratix10-svc: fix memory leaks and list corruption bugs\n\nFix a memory leak when gen_pool_alloc() fails by freeing pmem on the error\npath. Switch pmem allocation from devm_kzalloc() to kzalloc() with\nexplicit kfree() in the free path to match its list-managed lifetime.\nRemove the erroneous list_del(&svc_data_mem) which corrupted the list head\non failed lookups.","cvss":[],"epss":[{"cve":"CVE-2026-68183","epss":0.00211,"percentile":0.11311,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68183","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68184","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68184","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cdrom: fix stack out-of-bounds read in CDROMVOLCTRL  mmc_ioctl_cdrom_volume() first reads the audio control mode page into a 32-byte stack buffer with cgc->buflen set to 24.  If the device reports a block descriptor, the function increases cgc->buflen to include that descriptor and reads the page again.  For CDROMVOLCTRL, the function then builds a MODE SELECT parameter list by moving cgc->buffer forward by offset - 8 bytes.  This drops the block descriptor from the outgoing payload and leaves a new 8-byte mode parameter header in front of the audio control page.  However, cgc->buflen is left unchanged.  With a standard 8-byte block descriptor, cgc->buffer points at buffer + 8 but cgc->buflen remains 32.  cdrom_mode_select() therefore asks the low level packet path to write 32 bytes from that adjusted pointer, reading 8 bytes past the end of the 32-byte stack buffer.  This is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on drives that return a non-zero block descriptor length, which helps explain why it has gone unnoticed.  The overread is also sent to the device as extra MODE SELECT payload, so it may not produce an obvious local failure.  Reduce cgc->buflen by the same amount as the buffer pointer adjustment so the MODE SELECT transfer covers only the intended parameter list.","cvss":[],"epss":[{"cve":"CVE-2026-68184","epss":0.0021,"percentile":0.1127,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68184","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68184","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0329b661349f42f9616f2733da67edffbbb8455d","https://git.kernel.org/stable/c/35b68e24c5a69fa4545f46f05f6c849223034cb6","https://git.kernel.org/stable/c/45c65df5339deea3cf204902aac383fe995941a7","https://git.kernel.org/stable/c/7344c84e32413e5c8832f74b8a612b0194e5c051","https://git.kernel.org/stable/c/b27e195d4db8dea263050bdbeb11881b2999c9c6","https://git.kernel.org/stable/c/d43c5c0c935522deae7339e0c2399365f3bf0016","https://git.kernel.org/stable/c/e150c9a10baee55d3bfbc96dbe66b205e8b4fd44","https://git.kernel.org/stable/c/f3e2715a150066f09aa82c30fa983fb184ad6dd5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncdrom: fix stack out-of-bounds read in CDROMVOLCTRL\n\nmmc_ioctl_cdrom_volume() first reads the audio control mode page into a\n32-byte stack buffer with cgc->buflen set to 24.  If the device reports a\nblock descriptor, the function increases cgc->buflen to include that\ndescriptor and reads the page again.\n\nFor CDROMVOLCTRL, the function then builds a MODE SELECT parameter list\nby moving cgc->buffer forward by offset - 8 bytes.  This drops the block\ndescriptor from the outgoing payload and leaves a new 8-byte mode\nparameter header in front of the audio control page.  However, cgc->buflen\nis left unchanged.\n\nWith a standard 8-byte block descriptor, cgc->buffer points at buffer + 8\nbut cgc->buflen remains 32.  cdrom_mode_select() therefore asks the low\nlevel packet path to write 32 bytes from that adjusted pointer, reading 8\nbytes past the end of the 32-byte stack buffer.\n\nThis is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on\ndrives that return a non-zero block descriptor length, which helps explain\nwhy it has gone unnoticed.  The overread is also sent to the device as\nextra MODE SELECT payload, so it may not produce an obvious local failure.\n\nReduce cgc->buflen by the same amount as the buffer pointer adjustment so\nthe MODE SELECT transfer covers only the intended parameter list.","cvss":[],"epss":[{"cve":"CVE-2026-68184","epss":0.0021,"percentile":0.1127,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68184","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68185","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68185","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Move jump_label_init() before parse_early_param()  When enabling both CONFIG_MEM_ALLOC_PROFILING=y and CONFIG_MEM_ALLOC_PROFILING_ENABLED_BY_DEFAULT=y, then diabling memory profiling by adding the boot parameter 'sysctl.vm.mem_profiling=0' will cause the kernel failed to boot.  After analysis, this is because jump_label_init() must be called before parse_early_param(), the early param handlers may modify static keys by static_branch_enable/disable().  Fix this by moving jump_label_init() to before parse_early_param(). The solution is similar to other architectures.","cvss":[],"epss":[{"cve":"CVE-2026-68185","epss":0.002,"percentile":0.09908,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-68185","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68185","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/38b025fcdc45bdf5140a5726a1fbb2e694ea047b","https://git.kernel.org/stable/c/4b40e590efb350c54480d7e883f054d3609a94c6","https://git.kernel.org/stable/c/881e9f3c4e117b100880b1c5de3a0da8e455a78f","https://git.kernel.org/stable/c/ea68d444a658783234a06f05414e41cf93a18fb2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Move jump_label_init() before parse_early_param()\n\nWhen enabling both CONFIG_MEM_ALLOC_PROFILING=y and\nCONFIG_MEM_ALLOC_PROFILING_ENABLED_BY_DEFAULT=y, then diabling memory\nprofiling by adding the boot parameter 'sysctl.vm.mem_profiling=0' will\ncause the kernel failed to boot.\n\nAfter analysis, this is because jump_label_init() must be called before\nparse_early_param(), the early param handlers may modify static keys by\nstatic_branch_enable/disable().\n\nFix this by moving jump_label_init() to before parse_early_param(). The\nsolution is similar to other architectures.","cvss":[],"epss":[{"cve":"CVE-2026-68185","epss":0.002,"percentile":0.09908,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68185","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68186","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68186","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  binfmt_misc: set have_execfd only once the interpreter is opened  load_misc_binary() raises bprm->have_execfd as soon as it sees the 'O' (or 'C') flag. This happens well before it opens the interpreter. If that open fails the flag stays set on the bprm. binfmt_misc is at the head of the format list so an interpreter open failure that returns -ENOEXEC lets the search fall through to a later format. This means it runs the matched binary directly having never staged an interpreter. So bprm->executable is NULL while have_execfd falsely claims a descriptor is present.  Consequently, begin_new_exec() dereferences the missing executable:    would_dump(bprm, bprm->executable);  and NULL derefs. Had it not, the hand-off later in the same function would have failed anyway. FD_ADD(0, bprm->executable) rejects a NULL file with -ENOMEM. Both sites are past the point of no return so the exec cannot be unwound either way.  This can be reached by unprivileged users as binfmt_misc can be mounted in user namespaces. So a user can register an 'O' entry whose interpreter lives on a FUSE mount, have the FUSE server fail the open with -ENOEXEC and execute a native ELF file that matches the entry.  have_execfd only means anything alongside the executable it describes which is not set until the interpreter has been opened and staged. So lets raise it there, next to execfd_creds, which is already set at that point. An open failure now leaves it clear, so the fallback format derives credentials from the binary and emits no AT_EXECFD, as it would for any native exec. The argv rewrite load_misc_binary() performs before the open is still not undone. This means the binary sees the interpreter path in argv[0] and its own path in argv[1] but that predates this change and only became observable once the exec stopped faulting.","cvss":[],"epss":[{"cve":"CVE-2026-68186","epss":0.0021,"percentile":0.1127,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68186","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68186","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0f19d54e2524f0bf183b82f365ae4e49b4a2f788","https://git.kernel.org/stable/c/1cd4e9b7967dab48c9f79a00b06ffff7208c0993","https://git.kernel.org/stable/c/2dd0298905e97795a9c5ec30cf5b41975f821632","https://git.kernel.org/stable/c/40c09b7a1d4e0a4866042c87c2bd911bb57566c8","https://git.kernel.org/stable/c/5ccc99d58f94fad258c9c375715b3974e48620e8","https://git.kernel.org/stable/c/a261dc49d99681c9c71f38d16e31812dc3e30412","https://git.kernel.org/stable/c/a8e9e9450df44e9dd529ec5beff283f48f4f4b97","https://git.kernel.org/stable/c/bbf5f639918dc011aaf60aab8480218758ee68c5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: set have_execfd only once the interpreter is opened\n\nload_misc_binary() raises bprm->have_execfd as soon as it sees the 'O'\n(or 'C') flag. This happens well before it opens the interpreter. If\nthat open fails the flag stays set on the bprm. binfmt_misc is at the\nhead of the format list so an interpreter open failure that returns\n-ENOEXEC lets the search fall through to a later format. This means it\nruns the matched binary directly having never staged an interpreter. So\nbprm->executable is NULL while have_execfd falsely claims a descriptor\nis present.\n\nConsequently, begin_new_exec() dereferences the missing executable:\n\n  would_dump(bprm, bprm->executable);\n\nand NULL derefs. Had it not, the hand-off later in the same function\nwould have failed anyway. FD_ADD(0, bprm->executable) rejects a NULL\nfile with -ENOMEM. Both sites are past the point of no return so the\nexec cannot be unwound either way.\n\nThis can be reached by unprivileged users as binfmt_misc can be mounted\nin user namespaces. So a user can register an 'O' entry whose\ninterpreter lives on a FUSE mount, have the FUSE server fail the open\nwith -ENOEXEC and execute a native ELF file that matches the entry.\n\nhave_execfd only means anything alongside the executable it describes\nwhich is not set until the interpreter has been opened and staged.\nSo lets raise it there, next to execfd_creds, which is already set at\nthat point. An open failure now leaves it clear, so the fallback format\nderives credentials from the binary and emits no AT_EXECFD, as it would\nfor any native exec. The argv rewrite load_misc_binary() performs before\nthe open is still not undone. This means the binary sees the interpreter\npath in argv[0] and its own path in argv[1] but that predates this\nchange and only became observable once the exec stopped faulting.","cvss":[],"epss":[{"cve":"CVE-2026-68186","epss":0.0021,"percentile":0.1127,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68186","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68187","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68187","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  exec: fix unsigned loop counter wrap in transfer_args_to_stack()  The stop value is derived from bprm->p >> PAGE_SHIFT. The index variable is an unsigned long. If bprm->p drops below PAGE_SIZE and stop becomes zero the loop condition index >= stop is always true.  After the index == 0 iteration the decrement wraps to ULONG_MAX and bprm->page[ULONG_MAX] reads sizeof(void *) bytes in front of the array. The pointer has wrapped to -1. That garbage pointer is then passed to kmap_local_page() and PAGE_SIZE bytes are copied from wherever that lands into the stack of the process being created. And the loop doesn't terminate either...  Getting there only requires bprm->p < PAGE_SIZE. On !MMU bprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only constraint on how far bprm->p is pushed down is valid_arg_len(), i.e. that each individual string still fits in what is left.  bprm->p starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a single argument or environment string of a little over 31 pages leaves it in the first page:    Oops - load access fault [#1]   CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1   epc : __memcpy+0xd4/0xf8    ra : transfer_args_to_stack+0xaa/0xae    s4 : ffffffffffffffff   s2 : 0000000000000000    a1 : ffffffdc98000000   a2 : 0000000000001000   status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005   [<801a5324>] __memcpy+0xd4/0xf8   [<800d5f6a>] load_flat_binary+0x43a/0x65e   [<800a2de4>] bprm_execve+0x1d4/0x316   [<800a351a>] do_execveat_common+0x12e/0x138   [<800a3d44>] __riscv_sys_execve+0x38/0x4e   Kernel panic - not syncing: Fatal exception in interrupt  This is an arcane bug but we should still fix it.  Count down from MAX_ARG_PAGES so the loop ends when index reaches stop, stop == 0 included. The iterations performed are unchanged for every other value of stop.  Only CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used by binfmt_flat and binfmt_elf_fdpic on nommu only.  The loop predates git history. commit 7e7ec6a93434 (\"elf_fdpic_transfer_args_to_stack(): make it generic\") only moved it from binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used part of the first page. The condition and the decrement are unchanged from 2.6.12-rc2.","cvss":[],"epss":[{"cve":"CVE-2026-68187","epss":0.0022,"percentile":0.12415,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68187","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68187","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/16cc4f5c1c4b9e45eca7f7deefa5410a292db599","https://git.kernel.org/stable/c/2bc6bf70d41055377f390d06f0f3521deb62fd3b","https://git.kernel.org/stable/c/55fa2c7f2b15583d1a2fe1b5abcc24377359339f","https://git.kernel.org/stable/c/66e20942890a383eb39b2009a2ceb4c2ebec37ef","https://git.kernel.org/stable/c/67cf5cdad823afb0530d6d0341fbf4ca07e93a09","https://git.kernel.org/stable/c/a9eb5c4949008034909bc34ecfa0843ecc1d0ab3","https://git.kernel.org/stable/c/c62bb00caba66e01fb578d5f0302f247dc64930a","https://git.kernel.org/stable/c/dfc2a00742af4cb7251c1a8fbce4fbae3cc0de4e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nexec: fix unsigned loop counter wrap in transfer_args_to_stack()\n\nThe stop value is derived from bprm->p >> PAGE_SHIFT. The index variable\nis an unsigned long. If bprm->p drops below PAGE_SIZE and stop becomes\nzero the loop condition index >= stop is always true.\n\nAfter the index == 0 iteration the decrement wraps to ULONG_MAX and\nbprm->page[ULONG_MAX] reads sizeof(void *) bytes in front of the array.\nThe pointer has wrapped to -1. That garbage pointer is then passed to\nkmap_local_page() and PAGE_SIZE bytes are copied from wherever that\nlands into the stack of the process being created. And the loop doesn't\nterminate either...\n\nGetting there only requires bprm->p < PAGE_SIZE. On !MMU\nbprm_set_stack_limit() and bprm_hit_stack_limit() are empty. So the only\nconstraint on how far bprm->p is pushed down is valid_arg_len(), i.e.\nthat each individual string still fits in what is left.\n\nbprm->p starts at PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *) so a\nsingle argument or environment string of a little over 31 pages leaves\nit in the first page:\n\n  Oops - load access fault [#1]\n  CPU: 0 UID: 0 PID: 1 Comm: victim Not tainted 7.2.0-rc4 #1\n  epc : __memcpy+0xd4/0xf8\n   ra : transfer_args_to_stack+0xaa/0xae\n   s4 : ffffffffffffffff   s2 : 0000000000000000\n   a1 : ffffffdc98000000   a2 : 0000000000001000\n  status: 0000000a00001880 badaddr: ffffffdc98000000 cause: 0000000000000005\n  [<801a5324>] __memcpy+0xd4/0xf8\n  [<800d5f6a>] load_flat_binary+0x43a/0x65e\n  [<800a2de4>] bprm_execve+0x1d4/0x316\n  [<800a351a>] do_execveat_common+0x12e/0x138\n  [<800a3d44>] __riscv_sys_execve+0x38/0x4e\n  Kernel panic - not syncing: Fatal exception in interrupt\n\nThis is an arcane bug but we should still fix it.\n\nCount down from MAX_ARG_PAGES so the loop ends when index reaches stop,\nstop == 0 included. The iterations performed are unchanged for every\nother value of stop.\n\nOnly CONFIG_MMU=n builds are affected, transfer_args_to_stack() is used\nby binfmt_flat and binfmt_elf_fdpic on nommu only.\n\nThe loop predates git history. commit 7e7ec6a93434\n(\"elf_fdpic_transfer_args_to_stack(): make it generic\") only moved it\nfrom binfmt_elf_fdpic.c into fs/exec.c and narrowed the copy to the used\npart of the first page. The condition and the decrement are unchanged\nfrom 2.6.12-rc2.","cvss":[],"epss":[{"cve":"CVE-2026-68187","epss":0.0022,"percentile":0.12415,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68187","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68188","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68188","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: RFCOMM: Fix session UAF in set_termios  rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initiator and session->sock. Meanwhile, krfcommd can unlink the DLC and free the session while holding rfcomm_mutex.  The race can proceed as follows:    TTY ioctl task                 krfcommd   --------------                 --------   load dlc->session   enter rfcomm_send_rpn()                                  lock rfcomm_mutex                                  clear dlc->session                                  free session                                  unlock rfcomm_mutex   read session->initiator  KASAN reported:    BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0   Read of size 4 at addr ffff88810012a850 by task poc/92    Call Trace:    rfcomm_send_rpn+0x297/0x2a0    rfcomm_tty_set_termios+0x50d/0x850    tty_set_termios+0x596/0x950    set_termios+0x46a/0x6e0    tty_mode_ioctl+0x152/0xbd0    tty_ioctl+0x915/0x1240    __x64_sys_ioctl+0x134/0x1c0    Allocated by task 92:    rfcomm_session_add+0x9e/0x2e0    rfcomm_dlc_open+0x8b1/0xe00    rfcomm_dev_activate+0x85/0x1a0    rfcomm_tty_open+0x90/0x280    Freed by task 68:    kfree+0x131/0x3c0    rfcomm_session_del+0x119/0x180    rfcomm_run+0x737/0x4710  Add rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies that the DLC is still attached and sends the RPN frame. Have the TTY path use the helper and drop its unlocked session check. This keeps the session valid through both the frame construction and socket send.","cvss":[],"epss":[{"cve":"CVE-2026-68188","epss":0.0021,"percentile":0.11271,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68188","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68188","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2894bd8c68e97accd758ca6e5fc375d7e9e8882c","https://git.kernel.org/stable/c/4eac4576a072084b06459de6c054b4ebc764b4ea","https://git.kernel.org/stable/c/780b04d09c941262ee2a2b4a09906451b69df8a6","https://git.kernel.org/stable/c/82c383f9031f1ce919ac6c3c06bc5bd492a6b078","https://git.kernel.org/stable/c/98bc68194e37bfa5e8ddc80b5c1eb0be4dc607ea","https://git.kernel.org/stable/c/a82a9d3891f5607030b0672c255087a12bb9837b","https://git.kernel.org/stable/c/c5c060597247131f90f39ea7c8c978fa0c2e79d0","https://git.kernel.org/stable/c/c783399efc22d035443f1dfbf2a09bf9562aaa5e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: Fix session UAF in set_termios\n\nrfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and\nlater passes the pointer to rfcomm_send_rpn(). The latter dereferences\nboth session->initiator and session->sock. Meanwhile, krfcommd can\nunlink the DLC and free the session while holding rfcomm_mutex.\n\nThe race can proceed as follows:\n\n  TTY ioctl task                 krfcommd\n  --------------                 --------\n  load dlc->session\n  enter rfcomm_send_rpn()\n                                 lock rfcomm_mutex\n                                 clear dlc->session\n                                 free session\n                                 unlock rfcomm_mutex\n  read session->initiator\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0\n  Read of size 4 at addr ffff88810012a850 by task poc/92\n\n  Call Trace:\n   rfcomm_send_rpn+0x297/0x2a0\n   rfcomm_tty_set_termios+0x50d/0x850\n   tty_set_termios+0x596/0x950\n   set_termios+0x46a/0x6e0\n   tty_mode_ioctl+0x152/0xbd0\n   tty_ioctl+0x915/0x1240\n   __x64_sys_ioctl+0x134/0x1c0\n\n  Allocated by task 92:\n   rfcomm_session_add+0x9e/0x2e0\n   rfcomm_dlc_open+0x8b1/0xe00\n   rfcomm_dev_activate+0x85/0x1a0\n   rfcomm_tty_open+0x90/0x280\n\n  Freed by task 68:\n   kfree+0x131/0x3c0\n   rfcomm_session_del+0x119/0x180\n   rfcomm_run+0x737/0x4710\n\nAdd rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies\nthat the DLC is still attached and sends the RPN frame. Have the TTY\npath use the helper and drop its unlocked session check. This keeps the\nsession valid through both the frame construction and socket send.","cvss":[],"epss":[{"cve":"CVE-2026-68188","epss":0.0021,"percentile":0.11271,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68188","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68189","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68189","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_sync: Protect UUID list traversal  The hci_sync conversion moved class-of-device and EIR generation from an HCI request built under hdev->lock to asynchronous command sync work. The worker holds hdev->req_lock, but that lock does not serialize access to hdev->uuids against add_uuid() and remove_uuid(), which update the list under hdev->lock.  The following interleaving can therefore occur:    CPU0 (command sync work)       CPU1 (management socket)   fetch uuid from the list                                 list_del(&uuid->list)                                 kfree(uuid)   read uuid->size  KASAN reports the resulting use-after-free:    BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0   Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87   Workqueue: hci0 hci_cmd_sync_work   Call Trace:    eir_create+0xb8f/0xee0    hci_update_eir_sync+0x1c0/0x330    hci_cmd_sync_work+0x13c/0x290    process_one_work+0x63a/0x1070    worker_thread+0x45b/0xd10    Allocated by task 86:    __kasan_kmalloc+0x8f/0xa0    add_uuid+0x18a/0x4b0    hci_sock_sendmsg+0x1033/0x1ea0    Freed by task 92:    __kasan_slab_free+0x43/0x70    kfree+0x131/0x3c0    remove_uuid+0x25e/0x560    hci_sock_sendmsg+0x1033/0x1ea0  Hold hdev->lock while generating and committing the class-of-device and EIR snapshots.  Release it before sending an HCI command, so controller waits do not happen under the device lock.  This protects all UUID list walks in these paths and restores the serialization lost in the command sync conversion.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68189","epss":0.00159,"percentile":0.0542,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12163500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-68189","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68189","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/30bc6248f035a792d1b1f4cc761b32fd5827b55f","https://git.kernel.org/stable/c/a351f68fb24828b23a971e00b8238ee0e8a40380","https://git.kernel.org/stable/c/a42f5536ea9c00e13f0c0fbb330feed95e2365ca","https://git.kernel.org/stable/c/e4fa2c5c261d736b8e58759fdef3a968d510630c","https://git.kernel.org/stable/c/e9027ffbf5a0f3c12ca8900822e884eae9f0821b","https://git.kernel.org/stable/c/fe13adc258df88d95789e5673c7ba5178b5f8b28"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Protect UUID list traversal\n\nThe hci_sync conversion moved class-of-device and EIR generation from an\nHCI request built under hdev->lock to asynchronous command sync work.\nThe worker holds hdev->req_lock, but that lock does not serialize access\nto hdev->uuids against add_uuid() and remove_uuid(), which update the\nlist under hdev->lock.\n\nThe following interleaving can therefore occur:\n\n  CPU0 (command sync work)       CPU1 (management socket)\n  fetch uuid from the list\n                                list_del(&uuid->list)\n                                kfree(uuid)\n  read uuid->size\n\nKASAN reports the resulting use-after-free:\n\n  BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0\n  Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87\n  Workqueue: hci0 hci_cmd_sync_work\n  Call Trace:\n   eir_create+0xb8f/0xee0\n   hci_update_eir_sync+0x1c0/0x330\n   hci_cmd_sync_work+0x13c/0x290\n   process_one_work+0x63a/0x1070\n   worker_thread+0x45b/0xd10\n\n  Allocated by task 86:\n   __kasan_kmalloc+0x8f/0xa0\n   add_uuid+0x18a/0x4b0\n   hci_sock_sendmsg+0x1033/0x1ea0\n\n  Freed by task 92:\n   __kasan_slab_free+0x43/0x70\n   kfree+0x131/0x3c0\n   remove_uuid+0x25e/0x560\n   hci_sock_sendmsg+0x1033/0x1ea0\n\nHold hdev->lock while generating and committing the class-of-device and\nEIR snapshots.  Release it before sending an HCI command, so controller\nwaits do not happen under the device lock.  This protects all UUID list\nwalks in these paths and restores the serialization lost in the command\nsync conversion.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68189","epss":0.00159,"percentile":0.0542,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68189","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68190","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68190","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()  rtw_get_wps_ie() iterates over IE data from network frames without validating that the IE header and payload fit within the remaining buffer before reading them. Specifically:  - in_ie[cnt + 1] is read without checking cnt + 1 < in_len - memcmp(&in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check - in_ie[cnt + 1] is used as length without verifying payload fits  Add bounds checks at the top of the loop body to break early if fewer than 2 bytes remain for the IE header, or if the declared payload extends past the end of the buffer. Also require at least 4 bytes of payload before comparing the WPS OUI.","cvss":[],"epss":[{"cve":"CVE-2026-68190","epss":0.00206,"percentile":0.10696,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68190","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68190","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0e95ff792ae0aa6fbad9455943e9e1e4062670e9","https://git.kernel.org/stable/c/23b630e334f7e8f76bb22a18aca350da995af905","https://git.kernel.org/stable/c/23c31f107b4f8f420a754a45d12599bdb78f9bb8","https://git.kernel.org/stable/c/630fdca3f2437fee3ffd437c4b646ccf84c7be87","https://git.kernel.org/stable/c/875479f18835ac11e21a83e88f3d4dc7ccdcd0c4","https://git.kernel.org/stable/c/b9d9a4cd2e59df7281992a076464d2536e80c674","https://git.kernel.org/stable/c/c670efe69ec8a3360bfa596436f0250a3bf15d42"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()\n\nrtw_get_wps_ie() iterates over IE data from network frames without\nvalidating that the IE header and payload fit within the remaining\nbuffer before reading them. Specifically:\n\n- in_ie[cnt + 1] is read without checking cnt + 1 < in_len\n- memcmp(&in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check\n- in_ie[cnt + 1] is used as length without verifying payload fits\n\nAdd bounds checks at the top of the loop body to break early if fewer\nthan 2 bytes remain for the IE header, or if the declared payload\nextends past the end of the buffer. Also require at least 4 bytes of\npayload before comparing the WPS OUI.","cvss":[],"epss":[{"cve":"CVE-2026-68190","epss":0.00206,"percentile":0.10696,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68190","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68192","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68192","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: brcmfmac: make release_scratchbuffers idempotent  brcmf_pcie_release_scratchbuffers() frees the shared.scratch and shared.ringupd DMA buffers with dma_free_coherent() but does not clear the pointers afterwards, unlike the sibling release_ringbuffers() which NULLs commonrings/flowrings/idxbuf on release.  Both the bus_reset .reset callback (brcmf_pcie_reset) and brcmf_pcie_remove() call release_scratchbuffers.  When reset teardown has run before removal, remove's own teardown would call dma_free_coherent() a second time on the already-freed DMA allocation.  NULL the pointers after free, matching release_ringbuffers(), so a later release observes that the allocation has already been released.  This patch makes repeated sequential release safe; the reset-work lifetime is handled separately by the following patch.  This issue was found by an in-house static analysis tool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68192","epss":0.00412,"percentile":0.34613,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3357800000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68192","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68192","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/044fca8f45ba9ab6ca526163155234cf88287ff5","https://git.kernel.org/stable/c/0ca80328df23f851c86866720d4977783c919ee6","https://git.kernel.org/stable/c/382ee00b2d1e31869ae576a60d3fbe7a2153512f","https://git.kernel.org/stable/c/538c51e9d124cf656f2dd0c0394a8545efc7102d","https://git.kernel.org/stable/c/5a045c2f0fbf029873d2295178fa0785ade35af0","https://git.kernel.org/stable/c/739b686aecdb14a6065300ea53401f043e51fd22","https://git.kernel.org/stable/c/81c58a206d1deee01f4c29236d4154c0872f2a38","https://git.kernel.org/stable/c/b7d1d8cb1bdca56aecebacd2896615da0acc126a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: make release_scratchbuffers idempotent\n\nbrcmf_pcie_release_scratchbuffers() frees the shared.scratch and\nshared.ringupd DMA buffers with dma_free_coherent() but does not clear\nthe pointers afterwards, unlike the sibling release_ringbuffers() which\nNULLs commonrings/flowrings/idxbuf on release.\n\nBoth the bus_reset .reset callback (brcmf_pcie_reset) and\nbrcmf_pcie_remove() call release_scratchbuffers.  When reset teardown\nhas run before removal, remove's own teardown would call\ndma_free_coherent() a second time on the already-freed DMA allocation.\n\nNULL the pointers after free, matching release_ringbuffers(), so a later\nrelease observes that the allocation has already been released.  This\npatch makes repeated sequential release safe; the reset-work lifetime is\nhandled separately by the following patch.\n\nThis issue was found by an in-house static analysis tool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68192","epss":0.00412,"percentile":0.34613,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68192","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68194","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68194","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses  PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and mt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus. mt7921_mac_tx_free() cleans the DMA tx queues with mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the mmio queue ops implement that callback; on USB and SDIO it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX worker:    BUG: kernel NULL pointer dereference, address: 0000000000000000   RIP: 0010:0x0   Call Trace:    mt7921_mac_tx_free+0x64/0x310 [mt7921_common]    mt7921_rx_check+0x5f/0xf0 [mt7921_common]    mt76u_rx_worker+0x1b9/0x620 [mt76_usb]  Drop the event on non-mmio buses via mt76_is_mmio(), as in commit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for non-mmio devices\").","cvss":[],"epss":[{"cve":"CVE-2026-68194","epss":0.00205,"percentile":0.10657,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10250000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68194","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68194","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/24475d2ddc8d8dfd82f4d2be0d951401f86911a6","https://git.kernel.org/stable/c/263816e92e8d66c81c98ccab2b5d2191ed08ec71","https://git.kernel.org/stable/c/7003a2cbddd7917933c1f169c7874cfa6ab852c3","https://git.kernel.org/stable/c/da4082e91acabc1498611ed8ccc53f0610baefc6","https://git.kernel.org/stable/c/ecf995b828191829ba4a87169bccabcbeb5c9c32","https://git.kernel.org/stable/c/ef2ee5f820c3ef87643b51e960c20b4a14d8336b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7921_rx_check() and\nmt7921_queue_rx_skb() dispatch it to mt7921_mac_tx_free() on every bus.\nmt7921_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the\nmmio queue ops implement that callback; on USB and SDIO it is NULL, so\na TXRX_NOTIFY there calls a NULL pointer in the RX worker:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  RIP: 0010:0x0\n  Call Trace:\n   mt7921_mac_tx_free+0x64/0x310 [mt7921_common]\n   mt7921_rx_check+0x5f/0xf0 [mt7921_common]\n   mt76u_rx_worker+0x1b9/0x620 [mt76_usb]\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\").","cvss":[],"epss":[{"cve":"CVE-2026-68194","epss":0.00205,"percentile":0.10657,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68194","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68195","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68195","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses  PKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and mt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus. mt7615_mac_tx_free() cleans the DMA tx queues with mt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the mmio queue ops implement that callback; on the mt7663 USB and SDIO buses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX worker. Same defect as the mt7921 and mt7925 patches in this series.  Drop the event on non-mmio buses via mt76_is_mmio(), as in commit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for non-mmio devices\").","cvss":[],"epss":[{"cve":"CVE-2026-68195","epss":0.00211,"percentile":0.1131,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-68195","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68195","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1a099d630b8667fa622662b85e35a0ef659fb343","https://git.kernel.org/stable/c/39afc46c0243d10b7795e6e6cf4ae91f41732120","https://git.kernel.org/stable/c/664f8bbc61e45e062679da512bf12f8f6fb26a1b","https://git.kernel.org/stable/c/88c98ef247a3126fea9bbbda953a18a2f36c3ea7","https://git.kernel.org/stable/c/a0b3e8d8726c3830102a18946c766c94c953c7f2","https://git.kernel.org/stable/c/ab4d213393e846baa6437497f94dda7553cbeda7","https://git.kernel.org/stable/c/b2ab73b8123ce6cf2bc32634bfee4928676ffa66","https://git.kernel.org/stable/c/f2a72f47c5fb4ba6887e85bbe809d7e5b318d9d5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses\n\nPKT_TYPE_TXRX_NOTIFY is an mmio-only event, but mt7615_rx_check() and\nmt7615_queue_rx_skb() dispatch it to mt7615_mac_tx_free() on every bus.\nmt7615_mac_tx_free() cleans the DMA tx queues with\nmt76_queue_tx_cleanup(), which calls queue_ops->tx_cleanup(). Only the\nmmio queue ops implement that callback; on the mt7663 USB and SDIO\nbuses it is NULL, so a TXRX_NOTIFY there calls a NULL pointer in the RX\nworker. Same defect as the mt7921 and mt7925 patches in this series.\n\nDrop the event on non-mmio buses via mt76_is_mmio(), as in\ncommit 5683e1488aa9 (\"wifi: mt76: connac: do not check WED status for\nnon-mmio devices\").","cvss":[],"epss":[{"cve":"CVE-2026-68195","epss":0.00211,"percentile":0.1131,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68195","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68196","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68196","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: wilc1000: validate assoc response length before subtracting header  wilc_parse_assoc_resp_info() computes the trailing IE length as  \ties_len = buffer_len - sizeof(*res);  without first checking that buffer_len is at least sizeof(struct wilc_assoc_resp) (6 bytes). buffer_len is the length reported for a received association response (host_int_parse_assoc_resp_info() passes hif_drv->assoc_resp / assoc_resp_info_len straight in) and must be validated before the driver accesses the fixed header.  For a frame shorter than the 6-byte fixed header, the subtraction wraps. For a four-byte response the result is truncated to a u16 ies_len of 65534, so kmemdup() then attempts to copy 65534 bytes starting at buffer + sizeof(*res), beyond the valid association-response data (CWE-125). A response shorter than four bytes can also cause an out-of-bounds read of res->status_code at offsets 2 and 3.  Reject frames too short to hold the fixed header before touching the header or computing ies_len. Also set the connection status to a failure on this path: the caller falls through to a \"conn_info->status == WLAN_STATUS_SUCCESS\" check after the parser returns, so leaving the status untouched could let a malformed short response be treated as a successful association.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":8.3,"exploitabilityScore":2.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68196","epss":0.00413,"percentile":0.3476,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.32627000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-68196","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68196","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4c4c97b60a5e978121d9ee8cb0ab3916e5d6a8de","https://git.kernel.org/stable/c/4d410320e8ae5933e651660c9fadc1d380309e23","https://git.kernel.org/stable/c/584c8954ad55f8b09b475be6db710fe40ceb988c","https://git.kernel.org/stable/c/8ccdf8c8de87a9580df37c3c1ec53ba88cedef65","https://git.kernel.org/stable/c/8d50acf5420de0c4da99c2d634731c9d3164a755","https://git.kernel.org/stable/c/b81d0ea9e1daa215b3da68c1f4f6fb07940c2f6a","https://git.kernel.org/stable/c/d79b92417f33424ff23dad76716ed8f2cefb1083","https://git.kernel.org/stable/c/e511e93abd6eeedcd5b3c55516241f414fbde64a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: wilc1000: validate assoc response length before subtracting header\n\nwilc_parse_assoc_resp_info() computes the trailing IE length as\n\n\ties_len = buffer_len - sizeof(*res);\n\nwithout first checking that buffer_len is at least sizeof(struct\nwilc_assoc_resp) (6 bytes). buffer_len is the length reported for a\nreceived association response (host_int_parse_assoc_resp_info() passes\nhif_drv->assoc_resp / assoc_resp_info_len straight in) and must be\nvalidated before the driver accesses the fixed header.\n\nFor a frame shorter than the 6-byte fixed header, the subtraction wraps.\nFor a four-byte response the result is truncated to a u16 ies_len of\n65534, so kmemdup() then attempts to copy 65534 bytes starting at\nbuffer + sizeof(*res), beyond the valid association-response data\n(CWE-125). A response shorter than four bytes can also cause an\nout-of-bounds read of res->status_code at offsets 2 and 3.\n\nReject frames too short to hold the fixed header before touching the\nheader or computing ies_len. Also set the connection status to a failure\non this path: the caller falls through to a\n\"conn_info->status == WLAN_STATUS_SUCCESS\" check after the parser\nreturns, so leaving the status untouched could let a malformed short\nresponse be treated as a successful association.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":8.3,"exploitabilityScore":2.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68196","epss":0.00413,"percentile":0.3476,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68196","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68197","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68197","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper  mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on bss_desc->bcn_ht_cap being present, but then dereferences a different pointer, bss_desc->bcn_ht_oper:  \tif (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) && \t    bss_desc->bcn_ht_cap && \t    ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))  bcn_ht_cap and bcn_ht_oper are populated independently while parsing the associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that advertises an HT Capabilities element but no HT Operation element leaves bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a peer while associated to such an AP then dereferences the NULL bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the driver NULL-checks it first.  Guard on the pointer that is actually dereferenced.  Found by 0sec automated security-research tooling (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-68197","epss":0.0021,"percentile":0.11273,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68197","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68197","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/45011e4d9ba3f2182e5df64be65888044fa20771","https://git.kernel.org/stable/c/8c2058717fd06f05d421c2d3adf1dff3c3abcda1","https://git.kernel.org/stable/c/9375a4ea4121625ef27a46b74781cda66a5cc61b","https://git.kernel.org/stable/c/c3d68e294cbb6a4090bb219d3dcaca85a011809b","https://git.kernel.org/stable/c/cca4398aa305c22016d1714f388e2fa6ea4e5ad4","https://git.kernel.org/stable/c/e1770f7410b4232a0267924f99751dc9c5ca31af","https://git.kernel.org/stable/c/eb42c3c8fd479166c42984728754cd779c71fd60","https://git.kernel.org/stable/c/fba7eb7b248ea0618235f504158b685d752a153a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper\n\nmwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on\nbss_desc->bcn_ht_cap being present, but then dereferences a different\npointer, bss_desc->bcn_ht_oper:\n\n\tif (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) &&\n\t    bss_desc->bcn_ht_cap &&\n\t    ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))\n\nbcn_ht_cap and bcn_ht_oper are populated independently while parsing the\nassociated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that\nadvertises an HT Capabilities element but no HT Operation element leaves\nbcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a\npeer while associated to such an AP then dereferences the NULL\nbcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the\ndriver NULL-checks it first.\n\nGuard on the pointer that is actually dereferenced.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-68197","epss":0.0021,"percentile":0.11273,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68197","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68198","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath6kl: fix use-after-free in aggr_reset_state()  The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete TID state and before the structure is freed by callers like aggr_module_destroy().  If the timer callback (aggr_timeout) is executing when aggr_reset_state() is called, the callback will continue to access aggr_conn fields like rx_tid[] and stat[] which may be freed immediately after by kfree(aggr_info->aggr_conn) in aggr_module_destroy().  Additionally, the timer callback can re-arm itself via mod_timer() while aggr_reset_state() is running, creating a more complex race condition.  Use timer_delete_sync() instead to ensure any running timer callback has completed before returning.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68198","epss":0.00274,"percentile":0.19585,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.22331},"relatedVulnerabilities":[{"id":"CVE-2026-68198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68198","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/17ff29cd8dbc977c97788a5f7c011ec807b58242","https://git.kernel.org/stable/c/18965470d41e69d3fc10eb62afae29d10f4cdfd1","https://git.kernel.org/stable/c/2132a6db05846dd2318857d00e0c1291f9e41b29","https://git.kernel.org/stable/c/64af6534a085f49d6ed33338a19ab9cf0d0523c9","https://git.kernel.org/stable/c/a1bac650b2d6b1baab1f3e78e2e007a6e2948dde","https://git.kernel.org/stable/c/a3313111b5d9046af60b370c93eec105b27380c1","https://git.kernel.org/stable/c/b5d618fd61b9069b4c0a6b487022dd3117ad5acc","https://git.kernel.org/stable/c/ba7debb4dd6427386862220e8335a53a4bfc235d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix use-after-free in aggr_reset_state()\n\nThe aggr_reset_state() function uses timer_delete() (non-synchronous)\nfor the aggregation timer before proceeding to delete TID state and\nbefore the structure is freed by callers like aggr_module_destroy().\n\nIf the timer callback (aggr_timeout) is executing when aggr_reset_state()\nis called, the callback will continue to access aggr_conn fields like\nrx_tid[] and stat[] which may be freed immediately after by\nkfree(aggr_info->aggr_conn) in aggr_module_destroy().\n\nAdditionally, the timer callback can re-arm itself via mod_timer() while\naggr_reset_state() is running, creating a more complex race condition.\n\nUse timer_delete_sync() instead to ensure any running timer callback\nhas completed before returning.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68198","epss":0.00274,"percentile":0.19585,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68198","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68199","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68199","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath6kl: fix OOB access from firmware ADDBA window size  aggr_recv_addba_req_evt() logs a debug message when the firmware-supplied win_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not return. The out-of-range win_sz is then used in TID_WINDOW_SZ() to compute a kzalloc size and stored in rxtid->hold_q_sz, leading to zero-size or overflowed allocations and subsequent out-of-bounds access.  Clean up any previously active aggregation session for the TID first, then return early when win_sz is out of the valid range, instead of proceeding with a broken allocation size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68199","epss":0.00412,"percentile":0.34613,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3357800000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68199","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68199","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/44126b6994eeb28f2103b638e698f40a1244f327","https://git.kernel.org/stable/c/58c6c8dc2e022e1b4f3dc58725a1ca49ff470f9c","https://git.kernel.org/stable/c/5a65fd4722416061698b0a3277222381efbc4882","https://git.kernel.org/stable/c/67bc9af4f41f2bdba20404fbd753b2a1bd6dd352","https://git.kernel.org/stable/c/c8e3ca7954d8233fbc54bd370c1827670f43c538","https://git.kernel.org/stable/c/cec0a487cf38ac1f9bca240ffe8a94c5014b72f2","https://git.kernel.org/stable/c/d4558c140782180e2c80a7588a4af9f8675adfc4","https://git.kernel.org/stable/c/f480d9910fcfe326db3a6281df80e83af347193e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB access from firmware ADDBA window size\n\naggr_recv_addba_req_evt() logs a debug message when the firmware-supplied\nwin_sz is outside [AGGR_WIN_SZ_MIN, AGGR_WIN_SZ_MAX] but does not\nreturn. The out-of-range win_sz is then used in TID_WINDOW_SZ() to\ncompute a kzalloc size and stored in rxtid->hold_q_sz, leading to\nzero-size or overflowed allocations and subsequent out-of-bounds access.\n\nClean up any previously active aggregation session for the TID first,\nthen return early when win_sz is out of the valid range, instead of\nproceeding with a broken allocation size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68199","epss":0.00412,"percentile":0.34613,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68199","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68202","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68202","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: seq: close a re-opened queue timer in the destructor  queue_delete() closes the queue timer, then frees it. snd_seq_timer_close() clears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and snd_seq_timer_delete() frees q->timer.  A borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT that took a queueptr() use_lock reference before the queue was unlinked runs snd_seq_timer_open() after the close. Open refuses re-open only while timeri is set, and the close just cleared it, so it re-opens timeri.  snd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop() is a no-op, because running was cleared first. So it frees q->timer with the instance still live. The queue is freed next.  The instance stays on the global timer with callback_data pointing at the freed queue. A non-owner START on the unlocked queue arms it. The next tick derefs the freed queue in snd_seq_timer_interrupt().  Reachable by an unprivileged user with access to /dev/snd/seq. No CAP and no queue ownership required.  Close any lingering instance in the destructor. There, ->timeri can no longer change: the queue is unlinked and all use_lock borrowers have drained, so no snd_seq_queue_use() can re-open it. Close it before clearing q->timer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt() to finish, and that callback still reads q->timer (via snd_seq_check_queue()), so q->timer must stay valid until it drains.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68202","epss":0.00176,"percentile":0.07234,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13464},"relatedVulnerabilities":[{"id":"CVE-2026-68202","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68202","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/24f0cabf173539f048946c8fc221131dc221f277","https://git.kernel.org/stable/c/2c4dc0ed50b05cd847a4b34b8cebf0775f19aeb9","https://git.kernel.org/stable/c/31a6163e301d832060f8236f1ed17cbc1ca198df","https://git.kernel.org/stable/c/6a10025c7fd09a7d2af37a3ae1da188569fce470","https://git.kernel.org/stable/c/7478ef94b49bc9789cf1a003deec58b42283dde4","https://git.kernel.org/stable/c/9d9be6fc30f384f92c4e1b8ed40bd9d4796b7833","https://git.kernel.org/stable/c/b7feeaca1f53b10df9b4de9eaf611767ca70dc92","https://git.kernel.org/stable/c/fb40d03ed792a8a8bf77aa0ee15df57b0ff78b07"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: close a re-opened queue timer in the destructor\n\nqueue_delete() closes the queue timer, then frees it. snd_seq_timer_close()\nclears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and\nsnd_seq_timer_delete() frees q->timer.\n\nA borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT\nthat took a queueptr() use_lock reference before the queue was unlinked\nruns snd_seq_timer_open() after the close. Open refuses re-open only while\ntimeri is set, and the close just cleared it, so it re-opens timeri.\n\nsnd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()\nis a no-op, because running was cleared first. So it frees q->timer with the\ninstance still live. The queue is freed next.\n\nThe instance stays on the global timer with callback_data pointing at the\nfreed queue. A non-owner START on the unlocked queue arms it. The next tick\nderefs the freed queue in snd_seq_timer_interrupt().\n\nReachable by an unprivileged user with access to /dev/snd/seq. No CAP and\nno queue ownership required.\n\nClose any lingering instance in the destructor. There, ->timeri can no\nlonger change: the queue is unlinked and all use_lock borrowers have\ndrained, so no snd_seq_queue_use() can re-open it. Close it before clearing\nq->timer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()\nto finish, and that callback still reads q->timer (via snd_seq_check_queue()),\nso q->timer must stay valid until it drains.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68202","epss":0.00176,"percentile":0.07234,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68202","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68203","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68203","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: vivid: fix cleanup bugs in vivid_init()  When platform_device_register() fails in vivid_init(), the embedded struct device in vivid_pdev has already been initialized by device_initialize(), but the failure path jumps to free_output_strings without dropping the device reference for the current platform device:    vivid_init()     -> platform_device_register(&vivid_pdev)        -> device_initialize(&vivid_pdev.dev)        -> setup_pdev_dma_masks(&vivid_pdev)        -> platform_device_add(&vivid_pdev)  This leads to a reference leak when platform_device_register() fails. Fix this by calling platform_device_put() before jumping to the common cleanup path.  Also, the unreg_driver label incorrectly calls platform_driver_register() instead of platform_driver_unregister(), which breaks cleanup when workqueue creation fails after successful driver registration. Fix that as well.  The reference leak was identified by a static analysis tool I developed and confirmed by manual review. The incorrect cleanup call was found during code inspection.","cvss":[],"epss":[{"cve":"CVE-2026-68203","epss":0.00209,"percentile":0.11074,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1045},"relatedVulnerabilities":[{"id":"CVE-2026-68203","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68203","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1349af7f87df57940619f5b87990b799dac9ed8a","https://git.kernel.org/stable/c/4385092a86b94e1f332db35a3766108978c0722f","https://git.kernel.org/stable/c/6d51ad8f1c50c50d1abcc97fd243179967184c6a","https://git.kernel.org/stable/c/a07c179a92e949172ca52f6d4a13202ea88cd4b7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: fix cleanup bugs in vivid_init()\n\nWhen platform_device_register() fails in vivid_init(), the embedded\nstruct device in vivid_pdev has already been initialized by\ndevice_initialize(), but the failure path jumps to free_output_strings\nwithout dropping the device reference for the current platform device:\n\n  vivid_init()\n    -> platform_device_register(&vivid_pdev)\n       -> device_initialize(&vivid_pdev.dev)\n       -> setup_pdev_dma_masks(&vivid_pdev)\n       -> platform_device_add(&vivid_pdev)\n\nThis leads to a reference leak when platform_device_register() fails.\nFix this by calling platform_device_put() before jumping to the common\ncleanup path.\n\nAlso, the unreg_driver label incorrectly calls\nplatform_driver_register() instead of platform_driver_unregister(),\nwhich breaks cleanup when workqueue creation fails after successful\ndriver registration. Fix that as well.\n\nThe reference leak was identified by a static analysis tool I developed\nand confirmed by manual review. The incorrect cleanup call was found\nduring code inspection.","cvss":[],"epss":[{"cve":"CVE-2026-68203","epss":0.00209,"percentile":0.11074,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68203","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68204","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68204","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: vivid: check for vb2_is_busy() when toggling caps  The vivid_update_format_cap/out() functions must only be called if the capture/output queue are not busy. But for the controls that select the CROP/COMPOSE/SCALE capability that is not checked.  Only when streaming starts will they be set to 'grabbed' and it is impossible to change the control, but between REQBUFS and STREAMON you are still allowed to set these controls. Since vivid_update_format_cap/out will change the format, this can cause unexpected results.  Besides adding these checks, also add a WARN_ON in vivid_update_format_cap/out() if the queue is busy.  I'm 90% certain that this is the cause of this syzbot bug:  https://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89  But since we never have reproducers, it is hard to be certain. In any case, these checks are needed regardless.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68204","epss":0.00176,"percentile":0.07259,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13464},"relatedVulnerabilities":[{"id":"CVE-2026-68204","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68204","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0a820f03727b509b887f3216a574062948761f34","https://git.kernel.org/stable/c/492c97cb50feaa60ccd7792d3d6b904ed8ec61bf","https://git.kernel.org/stable/c/6a5bc8aea111ccbca71ef2b9c868d5c81f2e89de","https://git.kernel.org/stable/c/a9cd0e8fb0b21faaa71199d9d3feb305c18ff576","https://git.kernel.org/stable/c/abaec6747304581f8d4a9936352fa10e13325f07","https://git.kernel.org/stable/c/bbc96bc75de0fcd9bb6ac48798b206e3b09ec865","https://git.kernel.org/stable/c/c2d1a2130c93f6d758af58590b86b2254c7a1dec","https://git.kernel.org/stable/c/daf2d92669b4a659d805d88d811161c70cd325ee"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vivid: check for vb2_is_busy() when toggling caps\n\nThe vivid_update_format_cap/out() functions must only be called if the\ncapture/output queue are not busy. But for the controls that select\nthe CROP/COMPOSE/SCALE capability that is not checked.\n\nOnly when streaming starts will they be set to 'grabbed' and it is\nimpossible to change the control, but between REQBUFS and STREAMON you\nare still allowed to set these controls. Since vivid_update_format_cap/out\nwill change the format, this can cause unexpected results.\n\nBesides adding these checks, also add a WARN_ON in\nvivid_update_format_cap/out() if the queue is busy.\n\nI'm 90% certain that this is the cause of this syzbot bug:\n\nhttps://syzkaller.appspot.com/bug?extid=dac8f5eaa46837e97b89\n\nBut since we never have reproducers, it is hard to be certain. In any case,\nthese checks are needed regardless.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68204","epss":0.00176,"percentile":0.07259,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68204","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68205","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68205","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()  The v4l2 helper v4l2_async_register_subdev_sensor() calls v4l2_async_register_subdev(), which is a macro that expands to __v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded inside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module rather than the sensor driver module that originally set sd->owner. When v4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then overwrites the sensor driver's owner with NULL.  This causes the problem that the sensor module's reference count is never incremented during async registration, so the module can be removed while the subdevice is still in use by a notifier (e.g., a CSI-2 receiver bridge driver).  Fix this by renaming v4l2_async_register_subdev_sensor() to __v4l2_async_register_subdev_sensor() with an added explicit module argument and introducing a wrapper macro:     #define v4l2_async_register_subdev_sensor(sd) \\         __v4l2_async_register_subdev_sensor(sd, THIS_MODULE)  This ensures the sensor driver module is properly referenced even when the sensor driver does not init the owner field before calling v4l2_async_register_subdev_sensor() and prevents premature module removal.","cvss":[],"epss":[{"cve":"CVE-2026-68205","epss":0.00215,"percentile":0.11811,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1075},"relatedVulnerabilities":[{"id":"CVE-2026-68205","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68205","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/067887ff93fddbb3a3fb84c900bc654ecfe5ba61","https://git.kernel.org/stable/c/06cb687a5132fcffe624c0070576ab852ac6b568","https://git.kernel.org/stable/c/47ef04cd13d38010b580056a9d8840aaab944841","https://git.kernel.org/stable/c/c5e47cf9a6cffef73a1ed40b3648e6097aac165a","https://git.kernel.org/stable/c/caea6bc68c925d63ca33d21b2255f47181943d61","https://git.kernel.org/stable/c/cf9732fd6c4f2f803ccfc46d89489b6635590270","https://git.kernel.org/stable/c/f35e85a9d919d7954d9a7752e4644c0b403ad025"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()\n\nThe v4l2 helper v4l2_async_register_subdev_sensor() calls\nv4l2_async_register_subdev(), which is a macro that expands to\n__v4l2_async_register_subdev(sd,THIS_MODULE). Since the macro is expanded\ninside v4l2-fwnode.c, THIS_MODULE resolves to the v4l2-fwnode module\nrather than the sensor driver module that originally set sd->owner. When\nv4l2-fwnode is built-in, THIS_MODULE evaluates to NULL, which then\noverwrites the sensor driver's owner with NULL.\n\nThis causes the problem that the sensor module's reference count is never\nincremented during async registration, so the module can be removed while\nthe subdevice is still in use by a notifier (e.g., a CSI-2 receiver\nbridge driver).\n\nFix this by renaming v4l2_async_register_subdev_sensor() to\n__v4l2_async_register_subdev_sensor() with an added explicit module\nargument and introducing a wrapper macro:\n    #define v4l2_async_register_subdev_sensor(sd) \\\n        __v4l2_async_register_subdev_sensor(sd, THIS_MODULE)\n\nThis ensures the sensor driver module is properly referenced even when\nthe sensor driver does not init the owner field before calling\nv4l2_async_register_subdev_sensor() and prevents premature module removal.","cvss":[],"epss":[{"cve":"CVE-2026-68205","epss":0.00215,"percentile":0.11811,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68205","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68206","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68206","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: v4l2-ctrls: validate HEVC active reference counts  HEVC slice parameters are shared stateless V4L2 controls, but the common validation path does not verify the active L0/L1 reference counts before driver-specific code consumes them.  The original report came from Cedrus, but the active count bounds are not Cedrus-specific. Validate them in the common HEVC slice control path so stateless HEVC drivers get the same basic guarantees as soon as the control is queued.  Do not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may use out-of-range sentinel values such as 0xff for missing references, and some hardware can use that information for concealment. Keep this common check limited to the active reference counts.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68206","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13464},"relatedVulnerabilities":[{"id":"CVE-2026-68206","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68206","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3068ab802fc98b121dcb451e1f7f4d338ffc7a19","https://git.kernel.org/stable/c/3299c3905f3fb439ebd892658b87bc76c93ae116","https://git.kernel.org/stable/c/9a998cc1c348769262d433acb7d238c5fac4b2e0","https://git.kernel.org/stable/c/afbe4bc252d90a6f8fad869b06d5430f615f22f9","https://git.kernel.org/stable/c/b01df98a6669d2b67d8aed816021b327fd905998","https://git.kernel.org/stable/c/dbaf0e0023e2f9332c5164822def7f80b7d2c5ef"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-ctrls: validate HEVC active reference counts\n\nHEVC slice parameters are shared stateless V4L2 controls, but the common\nvalidation path does not verify the active L0/L1 reference counts before\ndriver-specific code consumes them.\n\nThe original report came from Cedrus, but the active count bounds are\nnot Cedrus-specific. Validate them in the common HEVC slice control path\nso stateless HEVC drivers get the same basic guarantees as soon as the\ncontrol is queued.\n\nDo not reject ref_idx_l0/ref_idx_l1 entries here. Existing userspace may\nuse out-of-range sentinel values such as 0xff for missing references, and\nsome hardware can use that information for concealment. Keep this common\ncheck limited to the active reference counts.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68206","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68206","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68207","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68207","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: ti: vpe: unwind v4l2 device registration on probe error  If the vpe_top resource is missing, vpe_probe() returns -ENODEV after v4l2_device_register() has succeeded. Probe failures do not call the driver's remove callback, so the v4l2 device remains registered on that error path.  Route that failure through the existing v4l2_device_unregister() unwind label, matching the other errors after v4l2_device_register().","cvss":[],"epss":[{"cve":"CVE-2026-68207","epss":0.00215,"percentile":0.11851,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1075},"relatedVulnerabilities":[{"id":"CVE-2026-68207","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68207","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0f0a60c000876bcd808a70d602c758c2e64c77d8","https://git.kernel.org/stable/c/4ecf0cc0cf59032a89bcdf36fbbb03bff5455fd9","https://git.kernel.org/stable/c/7d383357905de975e1dbde639e5fa7477075d104","https://git.kernel.org/stable/c/7e6521dd747eca3cb3d4cd3ddcf20f266494f63d","https://git.kernel.org/stable/c/e0f1c9a90ef665f2587c274a8fed59f2dfc575a6","https://git.kernel.org/stable/c/fcbbaf9cb9722a82f0221c56114037fc537f4ada"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ti: vpe: unwind v4l2 device registration on probe error\n\nIf the vpe_top resource is missing, vpe_probe() returns -ENODEV after\nv4l2_device_register() has succeeded. Probe failures do not call the\ndriver's remove callback, so the v4l2 device remains registered on that\nerror path.\n\nRoute that failure through the existing v4l2_device_unregister() unwind\nlabel, matching the other errors after v4l2_device_register().","cvss":[],"epss":[{"cve":"CVE-2026-68207","epss":0.00215,"percentile":0.11851,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68207","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68209","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68209","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: sun4i-csi: Return queued buffers on start_streaming() failure  The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming().  If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak.  sun4i_csi_start_streaming() returned -EINVAL when no matching CSI format could be found, before any setup (scratch buffer allocation, pipeline start) had been performed.  The remaining error paths already converge on the err_clear_dma_queue label, which calls return_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock.  Jump to that label directly: the intermediate err_disable_device / err_disable_pipeline / err_free_scratch_buffer labels are skipped, which is correct because nothing they would undo has happened yet.  This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68209","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13464},"relatedVulnerabilities":[{"id":"CVE-2026-68209","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68209","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/29fce7bcb3b959f6d4fdcdff7d26330152fdf98d","https://git.kernel.org/stable/c/3c0bd793b0083fd4639ba7f60d1e7db8c8ac459a","https://git.kernel.org/stable/c/4872161e6fbe4e1783daea8bff79caddfae0fb82","https://git.kernel.org/stable/c/668face37fdb6b6900645dc8777195498541c9a7","https://git.kernel.org/stable/c/7c2c30e282745a83d332c3cf92d1c0bcc491ac54","https://git.kernel.org/stable/c/a8abecc638a7feb20b78fabd563b05e30c071331","https://git.kernel.org/stable/c/b5184b3f0e9d4cc47059ba1138c9a73d43d2493f","https://git.kernel.org/stable/c/bbba3e260a62810a717b4442a3bb96d0ec0f6309"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: sun4i-csi: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming().  If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nsun4i_csi_start_streaming() returned -EINVAL when no matching CSI\nformat could be found, before any setup (scratch buffer allocation,\npipeline start) had been performed.  The remaining error paths already\nconverge on the err_clear_dma_queue label, which calls\nreturn_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock.  Jump\nto that label directly: the intermediate err_disable_device /\nerr_disable_pipeline / err_free_scratch_buffer labels are skipped,\nwhich is correct because nothing they would undo has happened yet.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68209","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68209","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68210","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68210","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: stm32: dcmi: unregister notifier on probe failure  dcmi_graph_init() registers the async notifier before dcmi_probe() toggles the reset line. If reset_control_assert() or reset_control_deassert() fails afterwards, probe returns through err_cleanup and the driver core will not call dcmi_remove().  Unregister the notifier before cleaning it up on that error path, matching the successful remove path and the V4L2 async notifier lifetime rules.  [hverkuil: added Fixes tag]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68210","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13464},"relatedVulnerabilities":[{"id":"CVE-2026-68210","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68210","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/084973ebd67b28f0945c5d45408f86c58b540110","https://git.kernel.org/stable/c/222a9301b086852b90d3b092fef436c3f4e927c4","https://git.kernel.org/stable/c/37ff63c5d7119cbc5c6bacdcc658add6008a8e1f","https://git.kernel.org/stable/c/4b7ee504969e074725e439c949f2483e5fa5572a","https://git.kernel.org/stable/c/6c6f22b7e6cbc4e8c1e359fc9b190419391c3db7","https://git.kernel.org/stable/c/931abe1deb65b919d23fa203d7f6d6fbd4fccd8e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: stm32: dcmi: unregister notifier on probe failure\n\ndcmi_graph_init() registers the async notifier before dcmi_probe() toggles\nthe reset line. If reset_control_assert() or reset_control_deassert()\nfails afterwards, probe returns through err_cleanup and the driver core\nwill not call dcmi_remove().\n\nUnregister the notifier before cleaning it up on that error path,\nmatching the successful remove path and the V4L2 async notifier lifetime\nrules.\n\n[hverkuil: added Fixes tag]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68210","epss":0.00176,"percentile":0.07257,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68210","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68212","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68212","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: saa7134: Fix a possible memory leak in saa7134_video_init1  In saa7134_video_init1(), the return value of the first saa7134_pgtable_alloc() is not checked. If it fails, the function continues as if successful, leaving the driver with an invalid page table. Additionally, if vb2_queue_init() for the VBI queue fails after the video queue page table has been allocated, the allocated memory is not freed before returning. The second saa7134_pgtable_alloc() also lacks a return value check. Errors occur during device probing before the device is fully registered, the normal cleanup path in saa7134_finidev() is not executed, leading to memory leaks and potential use of uninitialized DMA resources.  Check the return value of both saa7134_pgtable_alloc() calls and propagate errors. On failure of any later step, free allocated page tables to avoid memory leaks. Ensure control handlers are also released on error to prevent further resource leakage.  Found by code review.","cvss":[],"epss":[{"cve":"CVE-2026-68212","epss":0.0022,"percentile":0.12413,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68212","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68212","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/134c979dd721e22f196d71026432ee37d1f5cc38","https://git.kernel.org/stable/c/1731dd61b6c0b7435c139951d2b7eada6c9667a8","https://git.kernel.org/stable/c/34082a48376fd225a5c3d971c8962eb1320a54e0","https://git.kernel.org/stable/c/44e16e3e022bf4a26adf03bc05a6dd5ffc34ef6d","https://git.kernel.org/stable/c/b7936e8cbec1b96b126058eeb005e5b9111df38e","https://git.kernel.org/stable/c/e1ef361ee31d1dba5dcae2cdd50f9c1352df0c23","https://git.kernel.org/stable/c/e773b1d4bd191e7520bf9e02cb676d62c1b20556","https://git.kernel.org/stable/c/f86ed548386e3050e5f8f25b450d09dc009d9a88"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: saa7134: Fix a possible memory leak in saa7134_video_init1\n\nIn saa7134_video_init1(), the return value of the first\nsaa7134_pgtable_alloc() is not checked. If it fails, the function\ncontinues as if successful, leaving the driver with an invalid page\ntable. Additionally, if vb2_queue_init() for the VBI queue fails after\nthe video queue page table has been allocated, the allocated memory is\nnot freed before returning. The second saa7134_pgtable_alloc() also\nlacks a return value check. Errors occur during device probing before\nthe device is fully registered, the normal cleanup path in\nsaa7134_finidev() is not executed, leading to memory leaks and\npotential use of uninitialized DMA resources.\n\nCheck the return value of both saa7134_pgtable_alloc() calls and\npropagate errors. On failure of any later step, free allocated page\ntables to avoid memory leaks. Ensure control handlers are also\nreleased on error to prevent further resource leakage.\n\nFound by code review.","cvss":[],"epss":[{"cve":"CVE-2026-68212","epss":0.0022,"percentile":0.12413,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68212","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68213","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68213","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: rtl2832_sdr: Return queued buffers on start_streaming() failure  The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming().  If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak.  rtl2832_sdr_start_streaming() had multiple error paths that hit this trap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six `goto err` paths covering subdev s_power, tuner setup, ADC setup, stream-buffer allocation, urb allocation, and urb submission failures. None of them returned the queued buffers.  The original function had no distinct success exit and fell straight through into the err label, which previously only did mutex_unlock and \"return ret\".  Adding queued-buffer cleanup at err must therefore be paired with an explicit success return; otherwise every successful start would also drain the buffer queue and kill streaming.  Add that success return, then add rtl2832_sdr_cleanup_queued_bufs() at the err label and before each early return.  The cleanup helper takes a vb2_buffer_state argument so that the start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as expected by userspace on start_streaming failure) while stop_streaming keeps its existing VB2_BUF_STATE_ERROR semantics.  This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").  The err label still does not roll back power_ctrl(), frontend_ctrl(), the POWER_ON flag, or stream/URB allocations that may have happened before the failing step.  Those are pre-existing leaks of a different class and are not addressed here.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68213","epss":0.00176,"percentile":0.07234,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13464},"relatedVulnerabilities":[{"id":"CVE-2026-68213","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68213","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b08c0403cf672a121ace4eff647a9b240bd4e1b","https://git.kernel.org/stable/c/33ca0aab6f4bd90921fc1395478f38f72c4d19af","https://git.kernel.org/stable/c/465dc8e71d2db2ed603e749fa71392bcdccf07eb","https://git.kernel.org/stable/c/772f2550fe32357557d3b2f88e02f7cf477f0789","https://git.kernel.org/stable/c/894e83509c66910112b9eaeaa8cd66cd9806db91","https://git.kernel.org/stable/c/a248273f8af6e630a03e823274385725974009b5","https://git.kernel.org/stable/c/fc0b18782aab4e35078efe72863df8eab46560a8","https://git.kernel.org/stable/c/fd1e11fc3849169285e48b2d4ec441614ad2ea74"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832_sdr: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming().  If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nrtl2832_sdr_start_streaming() had multiple error paths that hit this\ntrap: two direct early returns (-ENODEV, -ERESTARTSYS), plus six\n`goto err` paths covering subdev s_power, tuner setup, ADC setup,\nstream-buffer allocation, urb allocation, and urb submission failures.\nNone of them returned the queued buffers.\n\nThe original function had no distinct success exit and fell straight\nthrough into the err label, which previously only did mutex_unlock and\n\"return ret\".  Adding queued-buffer cleanup at err must therefore be\npaired with an explicit success return; otherwise every successful\nstart would also drain the buffer queue and kill streaming.  Add that\nsuccess return, then add rtl2832_sdr_cleanup_queued_bufs() at the err\nlabel and before each early return.\n\nThe cleanup helper takes a vb2_buffer_state argument so that the\nstart_streaming error paths can pass VB2_BUF_STATE_QUEUED (as\nexpected by userspace on start_streaming failure) while stop_streaming\nkeeps its existing VB2_BUF_STATE_ERROR semantics.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").\n\nThe err label still does not roll back power_ctrl(), frontend_ctrl(),\nthe POWER_ON flag, or stream/URB allocations that may have happened\nbefore the failing step.  Those are pre-existing leaks of a different\nclass and are not addressed here.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68213","epss":0.00176,"percentile":0.07234,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68213","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68214","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68214","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: rtl2832: fix use-after-free in rtl2832_remove()  cancel_delayed_work_sync() is called before i2c_mux_del_adapters() in rtl2832_remove(). While the cancel waits for any running instance of i2c_gate_work to finish, it does not prevent the timer from being rescheduled by a concurrent thread.  During probe, the r820t_attach() call attempts I2C transfers through the mux adapter. These transfers go through i2c_mux_master_xfer(), which calls rtl2832_deselect() after the transfer completes, rescheduling i2c_gate_work via schedule_delayed_work(). If this transfer is still in flight when rtl2832_remove() runs, rtl2832_deselect() can reschedule i2c_gate_work after it has been cancelled, causing a use-after-free when kfree(dev) is called.  Fix this by calling i2c_mux_del_adapters() before cancel_delayed_work_sync(). Once the mux adapter is unregistered, no new I2C transfers can go through it, so rtl2832_deselect() can no longer reschedule i2c_gate_work. The subsequent cancel_delayed_work_sync() is then guaranteed to be final.","cvss":[],"epss":[{"cve":"CVE-2026-68214","epss":0.0022,"percentile":0.12448,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68214","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68214","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/13c06056699e66ff7109ba68658cc6ea4a23f516","https://git.kernel.org/stable/c/1e8a6bc19403661661fed5ae82f6eca6c9cdfad2","https://git.kernel.org/stable/c/24bef237eef8dd1ebcffb129ba21891ddad0d309","https://git.kernel.org/stable/c/2c71bda6edc630a1f8c3c45d8df5fc22d234e042","https://git.kernel.org/stable/c/680daf40a82d483949f87f0d8f98639dc47e610c","https://git.kernel.org/stable/c/68a9c0290897c1436ddceb8cea604c93377a0299","https://git.kernel.org/stable/c/90d781711418881f8c836c2a859cc2886625d750","https://git.kernel.org/stable/c/9acd5bbbe1df8e487e49488692c224496d4c9e16"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rtl2832: fix use-after-free in rtl2832_remove()\n\ncancel_delayed_work_sync() is called before i2c_mux_del_adapters()\nin rtl2832_remove(). While the cancel waits for any running instance\nof i2c_gate_work to finish, it does not prevent the timer from being\nrescheduled by a concurrent thread.\n\nDuring probe, the r820t_attach() call attempts I2C transfers through\nthe mux adapter. These transfers go through i2c_mux_master_xfer(),\nwhich calls rtl2832_deselect() after the transfer completes,\nrescheduling i2c_gate_work via schedule_delayed_work(). If this\ntransfer is still in flight when rtl2832_remove() runs,\nrtl2832_deselect() can reschedule i2c_gate_work after it has been\ncancelled, causing a use-after-free when kfree(dev) is called.\n\nFix this by calling i2c_mux_del_adapters() before\ncancel_delayed_work_sync(). Once the mux adapter is unregistered, no\nnew I2C transfers can go through it, so rtl2832_deselect() can no\nlonger reschedule i2c_gate_work. The subsequent\ncancel_delayed_work_sync() is then guaranteed to be final.","cvss":[],"epss":[{"cve":"CVE-2026-68214","epss":0.0022,"percentile":0.12448,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68214","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68215","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68215","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: radio-si476x: Unregister v4l2_device on probe failure  si476x_radio_probe() registers radio->v4l2dev before allocating the V4L2 controls and before registering the video device. If any of those later steps fails, probe returns through the exit label after freeing only the control handler.  A failed probe does not call si476x_radio_remove(), so the v4l2_device_unregister() there is not reached. This leaves the parent device reference taken by v4l2_device_register() behind on the error path.  Unregister the V4L2 device in the probe error path after freeing the controls.","cvss":[],"epss":[{"cve":"CVE-2026-68215","epss":0.0022,"percentile":0.12448,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68215","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68215","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/436a693af04ffb889aaf87cb69ec1f2b21d3569c","https://git.kernel.org/stable/c/4ca9c9f12b1bc341a0a3bbbd2090fd182db53771","https://git.kernel.org/stable/c/64cb15878b35e5574ff4f80a0b613a79e47867ba","https://git.kernel.org/stable/c/730c235d7d2c80a401dac56b0f5066c889aa442d","https://git.kernel.org/stable/c/7cf393f176317a126d71e88e4b6e25e83499b465","https://git.kernel.org/stable/c/7ef9f1659404544a8dddd68842bafcb4a38197af","https://git.kernel.org/stable/c/828f8d2181aa09ff3d8b67e1d9c92d0dfc81026f","https://git.kernel.org/stable/c/cac1c4f08cb2d8beaad16f7ddc7911f3711daa9f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: radio-si476x: Unregister v4l2_device on probe failure\n\nsi476x_radio_probe() registers radio->v4l2dev before allocating the V4L2\ncontrols and before registering the video device. If any of those later\nsteps fails, probe returns through the exit label after freeing only the\ncontrol handler.\n\nA failed probe does not call si476x_radio_remove(), so the\nv4l2_device_unregister() there is not reached. This leaves the parent\ndevice reference taken by v4l2_device_register() behind on the error path.\n\nUnregister the V4L2 device in the probe error path after freeing the\ncontrols.","cvss":[],"epss":[{"cve":"CVE-2026-68215","epss":0.0022,"percentile":0.12448,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68215","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68216","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68216","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: pwc: Return queued buffers on start_streaming() failure  The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming().  If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak.  pwc's start_streaming() had two early returns that hit this trap: -ENODEV when the USB device was already disconnected, and -ERESTARTSYS when mutex_lock_interruptible() was interrupted by a signal.  Call the existing pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED before returning (matching the state already used by the pwc_isoc_init() error path in the same function).  This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68216","epss":0.00176,"percentile":0.07258,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13464},"relatedVulnerabilities":[{"id":"CVE-2026-68216","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68216","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0362ae30b61b3053ee3095c1b8f179197ec4f539","https://git.kernel.org/stable/c/5d7cc2634c3843a1414a0f6407aa17f1f91dee60","https://git.kernel.org/stable/c/975b2ee20e569d47821e4f6c9761b4664d48a6a4","https://git.kernel.org/stable/c/a4f8f629983f643333e49df90557805469bcbb25","https://git.kernel.org/stable/c/cb16b79a2be2cec9c3ebe4147490817c4d8b1de3","https://git.kernel.org/stable/c/d552852bf76b7dfb35b4593fc874d8dd2f1b1bf3","https://git.kernel.org/stable/c/f2f9fcacd81953dde6cb86312ab13ca13e689664","https://git.kernel.org/stable/c/fa78e590852751d3ad32f33f6b4e210fe6ccbe9b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pwc: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming().  If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\npwc's start_streaming() had two early returns that hit this trap:\n-ENODEV when the USB device was already disconnected, and -ERESTARTSYS\nwhen mutex_lock_interruptible() was interrupted by a signal.  Call the\nexisting pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED\nbefore returning (matching the state already used by the\npwc_isoc_init() error path in the same function).\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68216","epss":0.00176,"percentile":0.07258,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68216","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68217","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68217","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: pwc: Drain fill_buf on start_streaming() failure  pwc_isoc_init() submits its isochronous URBs with usb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is submitted, its completion handler pwc_isoc_handler() can run on another CPU before the loop finishes:    start_streaming()     pwc_isoc_init()       usb_submit_urb(urbs[0], GFP_KERNEL)                                   pwc_isoc_handler(urbs[0])                                     pdev->fill_buf =                                       pwc_get_next_fill_buf(pdev)       usb_submit_urb(urbs[i>0], ..)  -> fails       pwc_isoc_cleanup(pdev)           /* kills URBs */       return ret;     pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)  pwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and stores it in pdev->fill_buf. The error path in start_streaming() only drains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is leaked. vb2_start_streaming() then triggers WARN_ON(owned_by_drv_count).  stop_streaming() already handles this since commit 80b0963e1698 (\"[media] pwc: fix WARN_ON\"), which added the fill_buf drain in the teardown path but not in the start_streaming() error path. Mirror that handling on failure so start_streaming() returns with no buffer owned by the driver.  Issue identified by automated review of the INV-003 series at https://sashiko.dev/","cvss":[],"epss":[{"cve":"CVE-2026-68217","epss":0.0022,"percentile":0.12415,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68217","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68217","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/5d4812668b03f823b5044789d6aa77fe56b42587","https://git.kernel.org/stable/c/906e410dcffbbd99fb4081abab817a830033aa28","https://git.kernel.org/stable/c/97f3c15957ec7e6d249f05407ad947c0644df24d","https://git.kernel.org/stable/c/9afd605dcd96c7a45f338eded1de16679b30e1df","https://git.kernel.org/stable/c/a4afffd148991a826e8995362fb10cf8705c1130","https://git.kernel.org/stable/c/a56e7641e09bd80b976e944ae759109b86fd5b38","https://git.kernel.org/stable/c/acc789b2173070638cad89c2b61d33ed338be0dd","https://git.kernel.org/stable/c/eabe9a59640698137d7382d5b549e95dc37f7565"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pwc: Drain fill_buf on start_streaming() failure\n\npwc_isoc_init() submits its isochronous URBs with\nusb_submit_urb(.., GFP_KERNEL) in a loop. After the first URB is\nsubmitted, its completion handler pwc_isoc_handler() can run on another\nCPU before the loop finishes:\n\n  start_streaming()\n    pwc_isoc_init()\n      usb_submit_urb(urbs[0], GFP_KERNEL)\n                                  pwc_isoc_handler(urbs[0])\n                                    pdev->fill_buf =\n                                      pwc_get_next_fill_buf(pdev)\n      usb_submit_urb(urbs[i>0], ..)  -> fails\n      pwc_isoc_cleanup(pdev)           /* kills URBs */\n      return ret;\n    pwc_cleanup_queued_bufs(pdev, VB2_BUF_STATE_QUEUED)\n\npwc_get_next_fill_buf() detaches a buffer from pdev->queued_bufs and\nstores it in pdev->fill_buf. The error path in start_streaming() only\ndrains pdev->queued_bufs, so the buffer parked in pdev->fill_buf is\nleaked. vb2_start_streaming() then triggers\nWARN_ON(owned_by_drv_count).\n\nstop_streaming() already handles this since commit 80b0963e1698\n(\"[media] pwc: fix WARN_ON\"), which added the fill_buf drain in the\nteardown path but not in the start_streaming() error path. Mirror that\nhandling on failure so start_streaming() returns with no buffer owned\nby the driver.\n\nIssue identified by automated review of the INV-003 series at\nhttps://sashiko.dev/","cvss":[],"epss":[{"cve":"CVE-2026-68217","epss":0.0022,"percentile":0.12415,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68217","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68218","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68218","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: pci: dm1105: Free allocated workqueue  Destroy allocated workqueue in remove() callback to free its resources, thus fixing memory leak.","cvss":[],"epss":[{"cve":"CVE-2026-68218","epss":0.0022,"percentile":0.12414,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68218","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68218","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/078e0750b5e60277e44d780d70c6997c46569df2","https://git.kernel.org/stable/c/08ddfd628a2dbd9d385da677afccd893d0ab37e1","https://git.kernel.org/stable/c/0c2b4c45fce012e88904b8c66b5cd786535c0b8c","https://git.kernel.org/stable/c/1a65db225b25bb8c8febf16974c060e0cc242eb9","https://git.kernel.org/stable/c/46715fecc38a2d341c3ff680f295de6e8aec72c0","https://git.kernel.org/stable/c/8d753c8c37afc0910ed5ddc014645b05d6266add","https://git.kernel.org/stable/c/d97f2e37516aa151582c8b2296021332db6da906","https://git.kernel.org/stable/c/df5cd8b30c750f4edd0766982437d3472a0dbbd4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: dm1105: Free allocated workqueue\n\nDestroy allocated workqueue in remove() callback to free its resources,\nthus fixing memory leak.","cvss":[],"epss":[{"cve":"CVE-2026-68218","epss":0.0022,"percentile":0.12414,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68218","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68222","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68222","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: msi2500: Return queued buffers on start_streaming() failure  The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming().  If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak.  msi2500_start_streaming() had five error paths that all hit this trap and were further tangled by ret-overwriting between calls:    - -ENODEV when the USB device was already disconnected   - -ERESTARTSYS when mutex_lock_interruptible() was interrupted   - msi2500_set_usb_adc() failure: ret was silently overwritten by     the next call (msi2500_isoc_init), so the error was lost entirely   - msi2500_isoc_init() failure: cleanup_queued_bufs was called, but     the function then fell through to msi2500_ctrl_msg() and again     masked the original error by overwriting ret   - msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all,     leaving isoc URBs submitted with no way for the driver to consume     them  Consolidate the error paths into a small goto chain.  Every failure now stops the function, drains the queued-buffer list, and returns the real error code.  The ctrl_msg failure path also rolls back the preceding msi2500_isoc_init() via msi2500_isoc_cleanup() before unlocking and draining.  The cleanup helper takes a vb2_buffer_state argument so that the start_streaming error paths can pass VB2_BUF_STATE_QUEUED (as expected by userspace on start_streaming failure) while stop_streaming keeps its existing VB2_BUF_STATE_ERROR semantics.  This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68222","epss":0.00139,"percentile":0.0357,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.106335},"relatedVulnerabilities":[{"id":"CVE-2026-68222","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68222","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1d58229b330b7f67fbfa07e0f2a8a51fbeafaa9a","https://git.kernel.org/stable/c/264b5380c4f8aa92dbc2983ecd2b627f1d5e0061","https://git.kernel.org/stable/c/2d10eedb786a13f91d76e11320fabb0bf712519f","https://git.kernel.org/stable/c/2de14ddb4fea04ca616403a6ba81c5e8099e9b9e","https://git.kernel.org/stable/c/3673cb0a5711e910074d69201da9e1535c03f97a","https://git.kernel.org/stable/c/7201c17786a498497bca57752883b90914d405ac","https://git.kernel.org/stable/c/bab9d5a67d4db96ae8c187b92b37979911302a10","https://git.kernel.org/stable/c/c74b680704baecea4620c0774de473069e0bc4e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: msi2500: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming().  If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nmsi2500_start_streaming() had five error paths that all hit this trap\nand were further tangled by ret-overwriting between calls:\n\n  - -ENODEV when the USB device was already disconnected\n  - -ERESTARTSYS when mutex_lock_interruptible() was interrupted\n  - msi2500_set_usb_adc() failure: ret was silently overwritten by\n    the next call (msi2500_isoc_init), so the error was lost entirely\n  - msi2500_isoc_init() failure: cleanup_queued_bufs was called, but\n    the function then fell through to msi2500_ctrl_msg() and again\n    masked the original error by overwriting ret\n  - msi2500_ctrl_msg(CMD_START_STREAMING) failure: no cleanup at all,\n    leaving isoc URBs submitted with no way for the driver to consume\n    them\n\nConsolidate the error paths into a small goto chain.  Every failure\nnow stops the function, drains the queued-buffer list, and returns\nthe real error code.  The ctrl_msg failure path also rolls back the\npreceding msi2500_isoc_init() via msi2500_isoc_cleanup() before\nunlocking and draining.\n\nThe cleanup helper takes a vb2_buffer_state argument so that the\nstart_streaming error paths can pass VB2_BUF_STATE_QUEUED (as\nexpected by userspace on start_streaming failure) while stop_streaming\nkeeps its existing VB2_BUF_STATE_ERROR semantics.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68222","epss":0.00139,"percentile":0.0357,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68222","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68223","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68223","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: meson: vdec: Fix memory leak in error path of vdec_open  The vdec_open() function previously jumped directly to err_m2m_release when vdec_init_ctrls() failed, skipping release of the m2m context. This caused a resource leak.  Fix it by introducing a proper err_m2m_ctx_release label that calls v4l2_m2m_ctx_release(sess->m2m_ctx) before releasing the m2m device.  This was identified via kmemleak: unreferenced object 0xffff0000205d6878 (size 8):   comm \"v4l_id\", pid 5289, jiffies 4294938580   hex dump (first 8 bytes):     40 d2 49 18 00 00 ff ff                          @.I.....   backtrace (crc d3204599):     kmemleak_alloc+0xc8/0xf0     __kvmalloc_node_noprof+0x60c/0x850     v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev]     vdec_open+0x1f4/0x788 [meson_vdec]     v4l2_open+0x144/0x460 [videodev]     chrdev_open+0x1ac/0x500     do_dentry_open+0x3f0/0xfe8     vfs_open+0x68/0x320     do_open+0x2d8/0x9a8     path_openat+0x1d0/0x4f0     do_filp_open+0x190/0x380     do_sys_openat2+0xf8/0x1b0     __arm64_sys_openat+0x13c/0x1e8     invoke_syscall+0xdc/0x268     el0_svc_common.constprop.0+0x178/0x258     do_el0_svc+0x4c/0x70","cvss":[],"epss":[{"cve":"CVE-2026-68223","epss":0.0022,"percentile":0.12445,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68223","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68223","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1391b75bf0119b5d37f1c1c3078d452a01967f9b","https://git.kernel.org/stable/c/2cf0171ad594860e31723c671e37824ce12c01ea","https://git.kernel.org/stable/c/5f97120d1a50c9efffe54425fac42bb7ef13ac86","https://git.kernel.org/stable/c/940f161f734b25f175a95d2684c2021f6323693a","https://git.kernel.org/stable/c/99f3527bd1a27ff798d59177ed045b0dd87deaef","https://git.kernel.org/stable/c/c6cd08a71a630f19b10c318e76e3c56e1dd10e00","https://git.kernel.org/stable/c/d9058a19731036c03a779bfe8c3ca0d9aa198599","https://git.kernel.org/stable/c/fb77d6f4580f316c9148b942af0028ee489d121e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: Fix memory leak in error path of vdec_open\n\nThe vdec_open() function previously jumped directly to\nerr_m2m_release when vdec_init_ctrls() failed, skipping\nrelease of the m2m context. This caused a resource leak.\n\nFix it by introducing a proper err_m2m_ctx_release label\nthat calls v4l2_m2m_ctx_release(sess->m2m_ctx) before\nreleasing the m2m device.\n\nThis was identified via kmemleak:\nunreferenced object 0xffff0000205d6878 (size 8):\n  comm \"v4l_id\", pid 5289, jiffies 4294938580\n  hex dump (first 8 bytes):\n    40 d2 49 18 00 00 ff ff                          @.I.....\n  backtrace (crc d3204599):\n    kmemleak_alloc+0xc8/0xf0\n    __kvmalloc_node_noprof+0x60c/0x850\n    v4l2_ctrl_handler_init_class+0x1b4/0x2e8 [videodev]\n    vdec_open+0x1f4/0x788 [meson_vdec]\n    v4l2_open+0x144/0x460 [videodev]\n    chrdev_open+0x1ac/0x500\n    do_dentry_open+0x3f0/0xfe8\n    vfs_open+0x68/0x320\n    do_open+0x2d8/0x9a8\n    path_openat+0x1d0/0x4f0\n    do_filp_open+0x190/0x380\n    do_sys_openat2+0xf8/0x1b0\n    __arm64_sys_openat+0x13c/0x1e8\n    invoke_syscall+0xdc/0x268\n    el0_svc_common.constprop.0+0x178/0x258\n    do_el0_svc+0x4c/0x70","cvss":[],"epss":[{"cve":"CVE-2026-68223","epss":0.0022,"percentile":0.12445,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68223","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68226","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68226","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: cx23885: add ioremap return check and cleanup  Add a check for the return value of pci_ioremap_bar() in cx23885_dev_setup(). If ioremap for BAR0 fails, release the already allocated PCI memory region, decrement the device count, and return -ENODEV.  This prevents a potential null pointer dereference and ensures proper cleanup on memory mapping failure.","cvss":[],"epss":[{"cve":"CVE-2026-68226","epss":0.0022,"percentile":0.12445,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68226","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68226","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/6a7636e3d5204fb18fdf1c3f909a3d9d9e24064c","https://git.kernel.org/stable/c/83540d86d717735b52a43e4ba1b784da5cc2310a","https://git.kernel.org/stable/c/8fbdca4c99f68734e9b6c030973fb61a11bede15","https://git.kernel.org/stable/c/9052fec0bb84eace81ac7bad071266052870cdf3","https://git.kernel.org/stable/c/a0701e387b46e2481c05b47f1235b954bfc2af3e","https://git.kernel.org/stable/c/c68c4ce72feb6fcccc843eb3baa7af60189ed567","https://git.kernel.org/stable/c/f58f4b571bd75c78bbf15441086ba0c2830c1aa5","https://git.kernel.org/stable/c/ff3c670a1de3a714f5644e37b9446fe7c3299fd3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx23885: add ioremap return check and cleanup\n\nAdd a check for the return value of pci_ioremap_bar()\nin cx23885_dev_setup().\nIf ioremap for BAR0 fails, release the already allocated\nPCI memory region,\ndecrement the device count, and return -ENODEV.\n\nThis prevents a potential null pointer dereference and\nensures proper cleanup\non memory mapping failure.","cvss":[],"epss":[{"cve":"CVE-2026-68226","epss":0.0022,"percentile":0.12445,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68226","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68227","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68227","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: cx231xx: fix devres lifetime  USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes).  Fix the driver state lifetime so that it is released on driver unbind.","cvss":[],"epss":[{"cve":"CVE-2026-68227","epss":0.0022,"percentile":0.12414,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68227","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68227","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0ea4b6fd49f7bed3a7e2b8734c15d9699dabe26f","https://git.kernel.org/stable/c/1770fc4e2b47b1185e6f688d4012bc91f7543854","https://git.kernel.org/stable/c/7d6358ab02866e5b7ed8d3a00805297617bbb0ec","https://git.kernel.org/stable/c/a373f1a5137e96549a795e7fb9efb5de0ae1d065","https://git.kernel.org/stable/c/c07f535bcdd3f956d4c32085535368f46ba99ba0","https://git.kernel.org/stable/c/c5ccb01eb1107acb6aab8ce8fe5a523f215c837e","https://git.kernel.org/stable/c/e797e252bfb3d0d4b3d38e4faef817e05869c240","https://git.kernel.org/stable/c/f468b7ee5d6332b01e6c538179a4c720e6dae93b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: fix devres lifetime\n\nUSB drivers bind to USB interfaces and any device managed resources\nshould have their lifetime tied to the interface rather than parent USB\ndevice. This avoids issues like memory leaks when drivers are unbound\nwithout their devices being physically disconnected (e.g. on probe\ndeferral or configuration changes).\n\nFix the driver state lifetime so that it is released on driver unbind.","cvss":[],"epss":[{"cve":"CVE-2026-68227","epss":0.0022,"percentile":0.12414,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68227","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68229","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68229","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: cedrus: skip invalid H.264 reference list entries  Cedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the stateless slice control and later uses their indices to look up decode->dpb[] in _cedrus_write_ref_list().  Rejecting such controls in cedrus_try_ctrl() would break existing userspace, since stateless H.264 reference lists may legitimately carry out-of-range indices for missing references. Instead, guard the actual DPB lookup in Cedrus and skip entries whose indices do not fit the fixed V4L2_H264_NUM_DPB_ENTRIES array.  This keeps the fix local to the driver use site and avoids out-of-bounds reads from malformed or unsupported reference list entries.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68229","epss":0.0016,"percentile":0.05465,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1168},"relatedVulnerabilities":[{"id":"CVE-2026-68229","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68229","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0af8945fcae742d099f59f3c725eb67235953a31","https://git.kernel.org/stable/c/10358ea986c3c85516d1c8206486464f79d36e76","https://git.kernel.org/stable/c/1db34683b0fbbcb3bc162380c11514ea0a44e8ab","https://git.kernel.org/stable/c/2ee8327c85b3ac7b532d2d6a1e3a295d5ad7414a","https://git.kernel.org/stable/c/7ff6f728a2433b420bb372cb0e8a4eea3f2e1a4b","https://git.kernel.org/stable/c/9924cb548ee7753a6473997949c3ec48092de0b0","https://git.kernel.org/stable/c/a6a109771c51920beb620f30778c29da823cc34c","https://git.kernel.org/stable/c/e53112c2de88982e66c369aee2120d5efd78df30"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cedrus: skip invalid H.264 reference list entries\n\nCedrus consumes H.264 ref_pic_list0/ref_pic_list1 entries from the\nstateless slice control and later uses their indices to look up\ndecode->dpb[] in _cedrus_write_ref_list().\n\nRejecting such controls in cedrus_try_ctrl() would break existing\nuserspace, since stateless H.264 reference lists may legitimately carry\nout-of-range indices for missing references. Instead, guard the actual\nDPB lookup in Cedrus and skip entries whose indices do not fit the fixed\nV4L2_H264_NUM_DPB_ENTRIES array.\n\nThis keeps the fix local to the driver use site and avoids out-of-bounds\nreads from malformed or unsupported reference list entries.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68229","epss":0.0016,"percentile":0.05465,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68229","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68231","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68231","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: airspy: Return queued buffers on start_streaming() failure  The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming().  If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak.  airspy_start_streaming() returned -ENODEV early when the USB device had been disconnected (s->udev == NULL) without returning any buffers that buf_queue() had already accepted.  Take v4l2_lock first and jump to the existing err_clear_bit label, which already drains s->queued_bufs via vb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.  This mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo: Return queued buffers on start_streaming() failure\").","cvss":[],"epss":[{"cve":"CVE-2026-68231","epss":0.0022,"percentile":0.12448,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68231","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68231","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/04344d0b4929caa94c0df72f767752aa0935ef5d","https://git.kernel.org/stable/c/122ce0c0af629a8765ddf1adf6fb85c6db3d47cb","https://git.kernel.org/stable/c/170fcc945bc094b1c956bf555c070692826a3eff","https://git.kernel.org/stable/c/73bd2779865372b1017d4f555b45270aa2d0d710","https://git.kernel.org/stable/c/877686a74ecdc93dcaee09dbac566e819059c9e7","https://git.kernel.org/stable/c/badceeb82a9d8d8e98d07859f3c89130ae1998b9","https://git.kernel.org/stable/c/bcdf261c4c29077fc3da6449f7eda77357046205","https://git.kernel.org/stable/c/cd42623d698b59f1fe5768f78a4101c28d5feb2e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: airspy: Return queued buffers on start_streaming() failure\n\nThe vb2 framework hands buffers to the driver via buf_queue() before\ncalling start_streaming().  If start_streaming() returns an error\nwithout first returning those buffers via vb2_buffer_done(),\nvb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued\nbuffers leak.\n\nairspy_start_streaming() returned -ENODEV early when the USB device had\nbeen disconnected (s->udev == NULL) without returning any buffers that\nbuf_queue() had already accepted.  Take v4l2_lock first and jump to the\nexisting err_clear_bit label, which already drains s->queued_bufs via\nvb2_buffer_done(..., VB2_BUF_STATE_QUEUED) before unlocking.\n\nThis mirrors the uvcvideo fix in commit 4cf3b6fd54eb (\"media: uvcvideo:\nReturn queued buffers on start_streaming() failure\").","cvss":[],"epss":[{"cve":"CVE-2026-68231","epss":0.0022,"percentile":0.12448,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68231","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68233","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68233","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vc4: Shut down BO cache timer before teardown  The BO cache timer callback schedules time_work, and time_work can rearm the timer through vc4_bo_cache_free_old().  vc4_bo_cache_destroy() deletes the timer and then cancels the work, which does not break that cycle: the work being cancelled can rearm the timer, and the timer then queues work again after teardown.  Use timer_shutdown_sync() instead, so the timer cannot be rearmed and the cycle ends with cancel_work_sync().","cvss":[],"epss":[{"cve":"CVE-2026-68233","epss":0.00166,"percentile":0.06132,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-68233","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68233","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/6273dd3ffb54ec581855b82ae77331b66028249c","https://git.kernel.org/stable/c/a38f2724eb93a78ba250b01e0caf3468df4d3956","https://git.kernel.org/stable/c/bac4c1a9af690b8635c6924872075c41d8763ed9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Shut down BO cache timer before teardown\n\nThe BO cache timer callback schedules time_work, and time_work can rearm\nthe timer through vc4_bo_cache_free_old().\n\nvc4_bo_cache_destroy() deletes the timer and then cancels the work, which\ndoes not break that cycle: the work being cancelled can rearm the timer,\nand the timer then queues work again after teardown.\n\nUse timer_shutdown_sync() instead, so the timer cannot be rearmed and the\ncycle ends with cancel_work_sync().","cvss":[],"epss":[{"cve":"CVE-2026-68233","epss":0.00166,"percentile":0.06132,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68233","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68234","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68234","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved  amdgpu_bo_create_reserved() only allocates a new BO when *bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is NULL, it simply skips creation when *bo_ptr is non-NULL. But it unconditionally reserves, pins, gart allocates and maps the BO afterwards.  When the same non-NULL BO pointer is passed in again, for example firmware buffers that live in adev and are re-loaded on every resume / cp_resume / start under AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases pin_count unconditionally, however the matching teardown only unpins once, so pin_count never drops to zero, so TTM is not able to move, swap or evict a BO, causing BO leaks.  This commit fixes this issue by only pinning the bo once at creation, and repeated calls no longer take additional pin references.  (cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)","cvss":[],"epss":[{"cve":"CVE-2026-68234","epss":0.00176,"percentile":0.07299,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68234","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68234","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2f390b4c83011452753fd84972f657d2b00a952b","https://git.kernel.org/stable/c/51eeef1949c11d3dcb5f422a5d9b3f09ebe8a1bc","https://git.kernel.org/stable/c/7aea619d9f186dcf0f1289879e9edb69d2b56639","https://git.kernel.org/stable/c/9743f60013273987abf415dc47474683d22aaee9","https://git.kernel.org/stable/c/a2f895f3c852063258d62e9f74b081de07ca95df","https://git.kernel.org/stable/c/b572d0814c1366701ca704286589fab025802566","https://git.kernel.org/stable/c/ba7b6444097a73ccd3d3ac9e2be4ebb73d226460","https://git.kernel.org/stable/c/e06e0885725a16304b7723aeb478a78cca9dc96a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved\n\namdgpu_bo_create_reserved() only allocates a new BO when\n*bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is\nNULL, it simply skips creation when *bo_ptr is non-NULL.\nBut it unconditionally reserves, pins, gart allocates\nand maps the BO afterwards.\n\nWhen the same non-NULL BO pointer is passed in again,\nfor example firmware buffers that live in adev and are\nre-loaded on every resume / cp_resume / start\nunder AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases\npin_count unconditionally, however the matching teardown only unpins\nonce, so pin_count never drops to zero, so TTM is not able\nto move, swap or evict a BO, causing BO leaks.\n\nThis commit fixes this issue by only pinning the bo\nonce at creation, and repeated calls no longer\ntake additional pin references.\n\n(cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)","cvss":[],"epss":[{"cve":"CVE-2026-68234","epss":0.00176,"percentile":0.07299,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68234","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68236","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68236","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: set new_stream to NULL after release  In dm_update_crtc_state(), the skip_modeset path releases new_stream via dc_stream_release() but does not set the pointer to NULL.  If a later error (e.g., color management failure) triggers the fail label, the error path calls dc_stream_release() again on the same dangling pointer, causing a double release and potential use-after-free.  Fix this by setting new_stream to NULL after the initial release.  (cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68236","epss":0.00125,"percentile":0.02507,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-68236","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68236","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0676fecbb5242aa22c057e78326d6d6041db034c","https://git.kernel.org/stable/c/5182e442e61397d446c36995b8f5676942d35b82","https://git.kernel.org/stable/c/679f23f0a3606afcef1ffabd72222f00a54ad9e3","https://git.kernel.org/stable/c/9fa26b9eed6195bf840f39ac183b9a6237548755","https://git.kernel.org/stable/c/ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: set new_stream to NULL after release\n\nIn dm_update_crtc_state(), the skip_modeset path releases new_stream\nvia dc_stream_release() but does not set the pointer to NULL.\n\nIf a later error (e.g., color management failure) triggers the fail\nlabel, the error path calls dc_stream_release() again on the same\ndangling pointer, causing a double release and potential use-after-free.\n\nFix this by setting new_stream to NULL after the initial release.\n\n(cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68236","epss":0.00125,"percentile":0.02507,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68236","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68238","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68238","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Release VFCT ACPI table reference  amdgpu_acpi_vfct_bios() fetches the VFCT table with acpi_get_table() but never releases it. acpi_get_table() takes a reference on the table (incrementing its validation_count and mapping it on the 0->1 transition); without a paired acpi_put_table() the mapping is leaked on every call, whether or not a matching VBIOS image is found.  Route all exit paths after the table is acquired through a common acpi_put_table(). The VBIOS image is copied out with kmemdup() before the table is released, so it remains valid for the caller.  (cherry picked from commit ca5988682b4cba4cd125a0fa99b2de1239164ae4)","cvss":[],"epss":[{"cve":"CVE-2026-68238","epss":0.00166,"percentile":0.06132,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-68238","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68238","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/312278b3091912fa56a6a587609f17dcb33465c2","https://git.kernel.org/stable/c/65bff26617607c1331283232016c0e89088c5b78","https://git.kernel.org/stable/c/9b7de3ee5d2c5ee2a706e5f7ca0126f4fbea4da8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Release VFCT ACPI table reference\n\namdgpu_acpi_vfct_bios() fetches the VFCT table with acpi_get_table()\nbut never releases it. acpi_get_table() takes a reference on the\ntable (incrementing its validation_count and mapping it on the 0->1\ntransition); without a paired acpi_put_table() the mapping is leaked\non every call, whether or not a matching VBIOS image is found.\n\nRoute all exit paths after the table is acquired through a common\nacpi_put_table(). The VBIOS image is copied out with kmemdup() before\nthe table is released, so it remains valid for the caller.\n\n(cherry picked from commit ca5988682b4cba4cd125a0fa99b2de1239164ae4)","cvss":[],"epss":[{"cve":"CVE-2026-68238","epss":0.00166,"percentile":0.06132,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68238","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68241","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68241","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/mst: limit DP MST ESI service loop  The loop in intel_dp_check_mst_status() keeps servicing interrupts originating from the sink without bound. Add an upper bound to the new interrupts occurring during interrupt processing to not get stuck on potentially stuck sink devices. Use arbitrary 32 tries to clear incoming interrupts in one go.  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  Note: The condition likely pre-dates the commit in the Fixes: tag, but this is about as far back as a backport has any chance of succeeding. Before that, the retry had a goto.  (cherry picked from commit b4ea5272133059acb493cc36599071a9e852ec2e)","cvss":[],"epss":[{"cve":"CVE-2026-68241","epss":0.00198,"percentile":0.0966,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.099},"relatedVulnerabilities":[{"id":"CVE-2026-68241","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68241","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/005771c18c5b2c98cb4e7517661aea460990fd3f","https://git.kernel.org/stable/c/9061fbf2230b6fcef042a6f637beae57c2fc93a5","https://git.kernel.org/stable/c/e3bcd3bf7eeca9570b9fa0b2f8a602c7bcc6b0d0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/mst: limit DP MST ESI service loop\n\nThe loop in intel_dp_check_mst_status() keeps servicing interrupts\noriginating from the sink without bound. Add an upper bound to the new\ninterrupts occurring during interrupt processing to not get stuck on\npotentially stuck sink devices. Use arbitrary 32 tries to clear incoming\ninterrupts in one go.\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\nNote: The condition likely pre-dates the commit in the Fixes: tag, but\nthis is about as far back as a backport has any chance of\nsucceeding. Before that, the retry had a goto.\n\n(cherry picked from commit b4ea5272133059acb493cc36599071a9e852ec2e)","cvss":[],"epss":[{"cve":"CVE-2026-68241","epss":0.00198,"percentile":0.0966,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68241","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68242","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68242","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/gt: Fix NULL deref on sched_engine alloc failure  Avoid using intel_context_put() before intel_context_init() in execlists_create_virtual() as the kref_put() inside would lead to NULL deref on the IOCTL path when sched_engine allocation fails.  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  (cherry picked from commit 4f2a12f2d50e9f48227656e4dcbd6423506be31d)","cvss":[],"epss":[{"cve":"CVE-2026-68242","epss":0.00189,"percentile":0.08657,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2026-68242","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68242","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/82ec992c404c3dc774c5e9f3d4aa858e97187675","https://git.kernel.org/stable/c/edd4804f07b8369ed472de19272974e2bf2a6271"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gt: Fix NULL deref on sched_engine alloc failure\n\nAvoid using intel_context_put() before intel_context_init() in\nexeclists_create_virtual() as the kref_put() inside would lead\nto NULL deref on the IOCTL path when sched_engine allocation fails.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 4f2a12f2d50e9f48227656e4dcbd6423506be31d)","cvss":[],"epss":[{"cve":"CVE-2026-68242","epss":0.00189,"percentile":0.08657,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68242","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68243","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68243","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU  Setting context engine slot N into I915_ENGINE_CLASS_INVALID / I915_ENGINE_CLASS_INVALID_NONE and attempting to apply I915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL. Fix that.  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  (cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)","cvss":[],"epss":[{"cve":"CVE-2026-68243","epss":0.00172,"percentile":0.06811,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68243","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68243","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2b56757a9a7456825eb668fde92299e01c5e2721","https://git.kernel.org/stable/c/726f27bca93e6c83b263542669132ee1d0eb693e","https://git.kernel.org/stable/c/97a4872ef927dee301d76085cb19f6e36d4a53a4","https://git.kernel.org/stable/c/97f236379f06a5082d37c6a764edd56bb58a94cd","https://git.kernel.org/stable/c/9923c223d38fcd9602f41cc31d480e5299d9a38e","https://git.kernel.org/stable/c/b226dee4ee1fff2909f79e8ad700b7082f8d3569","https://git.kernel.org/stable/c/edd2edaca52ada833c341c8b264aaea9dd93369c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU\n\nSetting context engine slot N into I915_ENGINE_CLASS_INVALID /\nI915_ENGINE_CLASS_INVALID_NONE and attempting to apply\nI915_CONTEXT_PARAM_SSEU to the same slot N will deref NULL.\nFix that.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 36eda5b5c2d40da41cc0a5403c26986237cf9e87)","cvss":[],"epss":[{"cve":"CVE-2026-68243","epss":0.00172,"percentile":0.06811,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68243","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68244","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68244","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/gem: Do not leak siblings[] on proto context error  After a successful BALANCE/PARALLEL_SUBMIT extension on context creation, error during processing of next user extension leaks the siblings[] array. Fix that.  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  (cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)","cvss":[],"epss":[{"cve":"CVE-2026-68244","epss":0.00172,"percentile":0.06809,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68244","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68244","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/37951ce1567ccf8c86c7a1b8fb7d55a32c821b87","https://git.kernel.org/stable/c/60b7d701ffae0c3a69e838f984cc80d8ca929f5d","https://git.kernel.org/stable/c/6cdbef8f60f313684e641628d64aa85960080d3f","https://git.kernel.org/stable/c/8431a4d7ff95c7f9c6fb1dbbbc9cdadf29d4f6d5","https://git.kernel.org/stable/c/e600672f11a1d9215f5432ca58f0b9823917a292","https://git.kernel.org/stable/c/eed3de2acf6aa5154d49098b026710b646db67ee","https://git.kernel.org/stable/c/f014702fbd48d06a3d7a06e4bb4075d406376cf0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Do not leak siblings[] on proto context error\n\nAfter a successful BALANCE/PARALLEL_SUBMIT extension on context\ncreation, error during processing of next user extension leaks\nthe siblings[] array. Fix that.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit aa65e0a4b51b3b54b53e4142aaa2d997aa1061ff)","cvss":[],"epss":[{"cve":"CVE-2026-68244","epss":0.00172,"percentile":0.06809,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68244","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68246","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68246","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()  There's no need to crash the kernel for these cases.  (cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)","cvss":[],"epss":[{"cve":"CVE-2026-68246","epss":0.00172,"percentile":0.06809,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68246","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68246","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0eebcab1ea2a77f086a04108f386f82ee3496022","https://git.kernel.org/stable/c/625f301e01bf89694466fdaa1f9904e2c62eb8f2","https://git.kernel.org/stable/c/7aeef42b657d930f3b639220e62120ac1bf058a1","https://git.kernel.org/stable/c/96b6d68f2b5a208e4d8f1e4a932ec424655e1267","https://git.kernel.org/stable/c/cac8002c675eda7d0d567871287201932857576c","https://git.kernel.org/stable/c/dfd9bf09fd8fe81f113a5c7e88bfd99f2499542f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()\n\nThere's no need to crash the kernel for these cases.\n\n(cherry picked from commit daa62107452d2451787c4248ca38fa2d1a0cbefd)","cvss":[],"epss":[{"cve":"CVE-2026-68246","epss":0.00172,"percentile":0.06809,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68246","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68247","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68247","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/bios: range check LFP Data Block panel_type2  While the panel_type from LFP Data Block is range checked, panel_type2 is not. Add a few helpers for range checking, and use them to not only check panel_type2, but also improve clarity and correctness in the panel type selection.  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  v2: - Fix commit message typo (Michał) - Add is_panel_type_pnp() (Ville)  (cherry picked from commit c9ebe5d2f25729d6cfbbb1235d640bf67f9275df)","cvss":[],"epss":[{"cve":"CVE-2026-68247","epss":0.00168,"percentile":0.0631,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-68247","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68247","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2084503f2d087bf956198e7f6eb25b03a7049cb2","https://git.kernel.org/stable/c/8887b94d2fc93071bf6ff09c39d474510e6f582f","https://git.kernel.org/stable/c/8b2da44446f9dce2ae50fee78bac2734d4277143","https://git.kernel.org/stable/c/e7b5694645b03e80830dc141b59fc65aac693c70"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/bios: range check LFP Data Block panel_type2\n\nWhile the panel_type from LFP Data Block is range checked, panel_type2\nis not. Add a few helpers for range checking, and use them to not only\ncheck panel_type2, but also improve clarity and correctness in the panel\ntype selection.\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\nv2:\n- Fix commit message typo (Michał)\n- Add is_panel_type_pnp() (Ville)\n\n(cherry picked from commit c9ebe5d2f25729d6cfbbb1235d640bf67f9275df)","cvss":[],"epss":[{"cve":"CVE-2026-68247","epss":0.00168,"percentile":0.0631,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68247","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68248","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68248","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915: Return NULL on error in active_instance  Avoid returning &node->base when node is NULL due to OOM during GFP_ATOMIC allocation.  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  (cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)","cvss":[],"epss":[{"cve":"CVE-2026-68248","epss":0.00172,"percentile":0.06808,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68248","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68248","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1e33f0de5fdcd09e51fdec1e5822448970b6420f","https://git.kernel.org/stable/c/2bc7c50ffca43e1824cf29738d0572f1eb21f261","https://git.kernel.org/stable/c/32c1a2afa90dd07df931f0b12578de1dbb751f0c","https://git.kernel.org/stable/c/58b7e63ca0cd964190957ddd169c899256acaee9","https://git.kernel.org/stable/c/a727a004d14580b2fc9bec9e1a9ea60a9016cfcf","https://git.kernel.org/stable/c/b238d86e7f43afde8e830ef5b8d89ffedbbc7613","https://git.kernel.org/stable/c/cbec6a57959ab503e3ad4ad6edd51efb585dce92"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Return NULL on error in active_instance\n\nAvoid returning &node->base when node is NULL due to OOM\nduring GFP_ATOMIC allocation.\n\nDiscovered using AI-assisted static analysis confirmed by\nIntel Product Security.\n\n(cherry picked from commit 6029bc064f0b1bac184203a50fbaaf070fa18832)","cvss":[],"epss":[{"cve":"CVE-2026-68248","epss":0.00172,"percentile":0.06808,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68248","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68249","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68249","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()  There's no need to crash the kernel for these cases.  (cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)","cvss":[],"epss":[{"cve":"CVE-2026-68249","epss":0.00176,"percentile":0.073,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68249","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68249","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0027cb19b0449ad6babedb1af285a713ab05c97f","https://git.kernel.org/stable/c/0c0dcc146f0c3091a9ef416cb8bbfdf5b5e169d5","https://git.kernel.org/stable/c/28337e5d7df429bac7de64b17f1a595147778caa","https://git.kernel.org/stable/c/5960a8b54a19367540d93980a4d0e9edbb8acf4e","https://git.kernel.org/stable/c/84254337df02406996068315c2b6f06d8cc64452","https://git.kernel.org/stable/c/9e98ed3113943257ad6e5c1e6beddbdb482a70ad","https://git.kernel.org/stable/c/d20b5c139b2906bcd8ab4bfe5b8be500318161d1","https://git.kernel.org/stable/c/f6212bc1bbd936fd9f7d77168b0c8b0019477b64"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()\n\nThere's no need to crash the kernel for these cases.\n\n(cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d)","cvss":[],"epss":[{"cve":"CVE-2026-68249","epss":0.00176,"percentile":0.073,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68249","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68250","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68250","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()  There's no need to crash the kernel for these cases.  (cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)","cvss":[],"epss":[{"cve":"CVE-2026-68250","epss":0.00211,"percentile":0.11305,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-68250","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68250","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/01dfea84df919cfbec4064151d327480ae5c120d","https://git.kernel.org/stable/c/09da54636bac146c1a3c461c4e7eb08d355bb86e","https://git.kernel.org/stable/c/2051bbbfbd44ff51637b01a5a3dbee6630f90d57","https://git.kernel.org/stable/c/55995d8da162acbadfd5fb0f08675e8e1c0bdb63","https://git.kernel.org/stable/c/6d27435df2a4ca4945f4313344a5da5bc6b54075","https://git.kernel.org/stable/c/b665c1845488c6cd869da3d31b5978015977f898","https://git.kernel.org/stable/c/b9dd618a635d39fbb211454b6e8837b2a7f10fb0","https://git.kernel.org/stable/c/f718334e4aa3768f6e68d235945eca2987c6687c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()\n\nThere's no need to crash the kernel for these cases.\n\n(cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af)","cvss":[],"epss":[{"cve":"CVE-2026-68250","epss":0.00211,"percentile":0.11305,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68250","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68251","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68251","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()  There's no need to crash the kernel for these cases.  (cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)","cvss":[],"epss":[{"cve":"CVE-2026-68251","epss":0.00215,"percentile":0.11851,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1075},"relatedVulnerabilities":[{"id":"CVE-2026-68251","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68251","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2eb06c88426b6c8de602c608959f3a56ac51861e","https://git.kernel.org/stable/c/51fd52087165180967cf7d5ee99badee7e172ea0","https://git.kernel.org/stable/c/9df8a7f09e305249872b536555793b28e77b7de9","https://git.kernel.org/stable/c/e7575e1e654a7ec8cc5e170f6dc30c81c708ddda","https://git.kernel.org/stable/c/e7f31c9a61533062a704f90b9f63064045249693","https://git.kernel.org/stable/c/ec42c96c322e5cc48099ab5e67b5cbe236cb1949"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()\n\nThere's no need to crash the kernel for these cases.\n\n(cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87)","cvss":[],"epss":[{"cve":"CVE-2026-68251","epss":0.00215,"percentile":0.11851,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68251","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68253","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68253","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/hdcp: check streams[] bounds before overflow  The data->streams[] overflow check is done after the buffer overflow has already happened. Move the overflow check before the write.  Side note, emitting a warning splat with a backtrace might be overkill here, but prefer not changing the behaviour other than not doing the overrun.  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  (cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68253","epss":0.00143,"percentile":0.03886,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.109395},"relatedVulnerabilities":[{"id":"CVE-2026-68253","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68253","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2106fb490b2c6003e23ad6ff36ce823a2170e138","https://git.kernel.org/stable/c/336cf6d80d41457442b659e7ba7a7badc0ffe79d","https://git.kernel.org/stable/c/389079bf04e6f0c6f10f5b879f6d7a9cf80f0567","https://git.kernel.org/stable/c/3d2ef8d389495e7889c6062d8bddc46d2a5fbdef","https://git.kernel.org/stable/c/84351f12390349ba010920fc247e1a0b12e41eb3","https://git.kernel.org/stable/c/984085c5b53572e2e03fd5fc4817e86ef1effc6e","https://git.kernel.org/stable/c/bbb15a6b042d02e5508a02b4847e02d2579ee7bc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: check streams[] bounds before overflow\n\nThe data->streams[] overflow check is done after the buffer overflow has\nalready happened. Move the overflow check before the write.\n\nSide note, emitting a warning splat with a backtrace might be overkill\nhere, but prefer not changing the behaviour other than not doing the\noverrun.\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\n(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68253","epss":0.00143,"percentile":0.03886,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68253","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68254","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68254","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/vrr: require valid min/max vfreq for VRR  Ensure the EDID provided min/max vfreq are valid. Most scenarios are already covered (by coincidence) through the checks in intel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit about it. At worst, a zero min_vfreq could lead to a division by zero in intel_vrr_compute_vmax().  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  (cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)","cvss":[],"epss":[{"cve":"CVE-2026-68254","epss":0.00173,"percentile":0.06839,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-68254","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68254","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2f9aa8d42b7fc17621894456433ac07689fb4a21","https://git.kernel.org/stable/c/5225122b9cad6b0c61e767fb2adea8c07da925be","https://git.kernel.org/stable/c/6598ac1721c3a5543efdbcab579a8561268d7ce1","https://git.kernel.org/stable/c/c726c8bbee5115dad37fa7867136ebaa50690331","https://git.kernel.org/stable/c/df1582c0a101e2e2f133dd331d2a3258bb6a7518","https://git.kernel.org/stable/c/f16218689b41efcbc491207cd7716477b1223879","https://git.kernel.org/stable/c/f8a9262c7a6fc2de9802e14b0228114f0333869e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/vrr: require valid min/max vfreq for VRR\n\nEnsure the EDID provided min/max vfreq are valid. Most scenarios are\nalready covered (by coincidence) through the checks in\nintel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit\nabout it. At worst, a zero min_vfreq could lead to a division by zero in\nintel_vrr_compute_vmax().\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\n(cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)","cvss":[],"epss":[{"cve":"CVE-2026-68254","epss":0.00173,"percentile":0.06839,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68254","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68255","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68255","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/virtio: bound EDID block reads to the response buffer  virtio_get_edid_block() validates the read offset only against the device-supplied resp->size field, never against the fixed-size resp->edid array. The EDID block index is driven by the device-supplied extension count, so a malicious virtio-gpu backend can advertise a large size together with a high block count and read far past the array into adjacent kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds read / info leak).  Also reject any read whose end exceeds the size of the edid array. Conforming EDID responses stay within the array and are unaffected.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":2.6,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68255","epss":0.0019,"percentile":0.08805,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1444},"relatedVulnerabilities":[{"id":"CVE-2026-68255","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68255","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2757e6e803092cf0aeaf4b735e16b5d3bdc705c5","https://git.kernel.org/stable/c/35be0e2c6862abcd5e5f5445261f1fd910d4a9b4","https://git.kernel.org/stable/c/375c1934ef0196d3b6d3a1eae3232bef8dae7bf7","https://git.kernel.org/stable/c/3f506a85a905b080cadc029a1651a310479090a6","https://git.kernel.org/stable/c/4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd","https://git.kernel.org/stable/c/64bedd2758eccbc74d39f7006a7ec16fa39dc901","https://git.kernel.org/stable/c/65ce911f341ad8ff0c08922eff5bb6db75666eb0","https://git.kernel.org/stable/c/9fc2a017c5d597937e0c28b9a9669844aa796c42"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: bound EDID block reads to the response buffer\n\nvirtio_get_edid_block() validates the read offset only against the\ndevice-supplied resp->size field, never against the fixed-size resp->edid\narray. The EDID block index is driven by the device-supplied extension\ncount, so a malicious virtio-gpu backend can advertise a large size\ntogether with a high block count and read far past the array into adjacent\nkernel memory, which is then surfaced in the parsed EDID (an out-of-bounds\nread / info leak).\n\nAlso reject any read whose end exceeds the size of the edid array.\nConforming EDID responses stay within the array and are unaffected.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":2.6,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68255","epss":0.0019,"percentile":0.08805,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68255","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68258","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68258","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Check bounds on CRIU restore queue type and mqd size  We weren't checking whether the values provided in the private data in kfd CRIU restore were within bounds.  For queue type, add a KFD_QUEUE_TYPE_MAX and ensure the provided type is less than it.  For mqd_size, add new function mqd_size_from_queue_type and confirm that the provided mqd_size matches expectations.  (cherry picked from commit f19d8086f6644083c913d70bfdeee20e1b6f46a5)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68258","epss":0.00129,"percentile":0.02886,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09416999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-68258","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68258","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/47ea05f246bebc81c7796f56265cffd812cf0601","https://git.kernel.org/stable/c/cc10a5839756982504ee8568fc1e1625962ab7f8","https://git.kernel.org/stable/c/fd1691ec62701c982ea32e749678988c67fd4c21"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Check bounds on CRIU restore queue type and mqd size\n\nWe weren't checking whether the values provided in the private\ndata in kfd CRIU restore were within bounds.\n\nFor queue type, add a KFD_QUEUE_TYPE_MAX and ensure the provided\ntype is less than it.\n\nFor mqd_size, add new function mqd_size_from_queue_type and confirm\nthat the provided mqd_size matches expectations.\n\n(cherry picked from commit f19d8086f6644083c913d70bfdeee20e1b6f46a5)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68258","epss":0.00129,"percentile":0.02886,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68258","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68259","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68259","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Check bounds in allocate_event_notification_slot  The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT  allocate_event_notification_slot has an option to specify an event id to allocate at, used by CRIU. We weren't checking the bounds on that value.  Check them.  v2: Lower bounds check is unecessary because of idr_alloc already rejecting negative numbers. Upper bounds check should be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might not yet exist  (cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)","cvss":[],"epss":[{"cve":"CVE-2026-68259","epss":0.00172,"percentile":0.06809,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68259","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68259","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4622214f0542f64b02c250db0f9c677eeb032d9b","https://git.kernel.org/stable/c/50319efb865f72db45f191c8709511746d58ee0a","https://git.kernel.org/stable/c/6884fc142b17f456caac50c14505f509bfbcd012","https://git.kernel.org/stable/c/85eedff5f0c4aba5a66bc37a1bd6bcecd0d77b53","https://git.kernel.org/stable/c/abeeb1947d81610c65349db4d89c6151f270e136","https://git.kernel.org/stable/c/bb52249fbbe948875155ccd45cd8d74bf4ae747b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Check bounds in allocate_event_notification_slot\n\nThe valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT\n\nallocate_event_notification_slot has an option to specify\nan event id to allocate at, used by CRIU. We weren't checking\nthe bounds on that value.\n\nCheck them.\n\nv2: Lower bounds check is unecessary because of idr_alloc\nalready rejecting negative numbers. Upper bounds check should\nbe KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might\nnot yet exist\n\n(cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)","cvss":[],"epss":[{"cve":"CVE-2026-68259","epss":0.00172,"percentile":0.06809,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68259","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68269","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68269","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/i915/gem: Add missing nospec on parallel submit slot  Add missing Spectre mitigation for userspace controlled parallel submission slot.  Discovered using AI-assisted static analysis confirmed by Intel Product Security.  (cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)","cvss":[],"epss":[{"cve":"CVE-2026-68269","epss":0.00205,"percentile":0.10656,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10250000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68269","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68269","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0ac3bab10c62997727a0a90f819a27d337347f93","https://git.kernel.org/stable/c/45db277b2e1e34bcc99a0852026791108339ec3e","https://git.kernel.org/stable/c/4a27275d275971c9ea29d3d240ea4a224ad368a2","https://git.kernel.org/stable/c/914a76a9f08366434bf595700f62026b7a19a9cc","https://git.kernel.org/stable/c/be393175306694de5da1d1a23a8ea4149baa09f1","https://git.kernel.org/stable/c/c41a54619e95f860bf2950dd679ab353380ecd2b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Add missing nospec on parallel submit slot\n\nAdd missing Spectre mitigation for userspace controlled parallel\nsubmission slot.\n\nDiscovered using AI-assisted static analysis confirmed by Intel\nProduct Security.\n\n(cherry picked from commit 15b9353deff3cf72331c387780de3cf9c316b643)","cvss":[],"epss":[{"cve":"CVE-2026-68269","epss":0.00205,"percentile":0.10656,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68269","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68273","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68273","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Fix context pstate override handling  There are several problems in the context pstate handling code.  The most serious ones are potential use-after-free and NULL pointer dereferences at context initialization time. Both are due amdgpu_ctx_init() not holding the adev->pm.stable_pstate_ctx_lock, which is otherwise used from both sysfs and the context code itself for modifying and clearing the stored context pointer.  Second issue is that context fini can trample over the pstate configuration set via sysfs. This is due the restore state (ctx->stable_pstate) being saved at context init time, and not if, or when the context actually changes the pstate. As the context exits it will therefore incorrectly restore to what was set before the sysfs override was requested.  The simplest fix is to drastically simplify how the state is tracked, by clearly defining the points at which pstate ownership is taken and released, and to handle all transitions under the correct lock.  Instead of at context init time, the previous state is saved only at the point the context overrides the current state, and is restored on context exit only if the context is still the owner of the current override state.  (cherry picked from commit 1b5e413713c0a93bc1818394d0ce49aaad21bd27)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68273","epss":0.00134,"percentile":0.03254,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10251000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-68273","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68273","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/23a8726e1d7597fe7c9a59d5dc42ba8b7d345b8a","https://git.kernel.org/stable/c/9f9c88eb298c54348be3ca4087f4f4c615065b87","https://git.kernel.org/stable/c/c1dc4ccb82c9e56325d8e7514ca4c90bd1efb351","https://git.kernel.org/stable/c/e06c39cc1c48dca68a5ffd971c23025a52d46634"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix context pstate override handling\n\nThere are several problems in the context pstate handling code.\n\nThe most serious ones are potential use-after-free and NULL pointer\ndereferences at context initialization time. Both are due\namdgpu_ctx_init() not holding the adev->pm.stable_pstate_ctx_lock, which\nis otherwise used from both sysfs and the context code itself for\nmodifying and clearing the stored context pointer.\n\nSecond issue is that context fini can trample over the pstate\nconfiguration set via sysfs. This is due the restore state\n(ctx->stable_pstate) being saved at context init time, and not if, or when\nthe context actually changes the pstate. As the context exits it will\ntherefore incorrectly restore to what was set before the sysfs override\nwas requested.\n\nThe simplest fix is to drastically simplify how the state is tracked, by\nclearly defining the points at which pstate ownership is taken and\nreleased, and to handle all transitions under the correct lock.\n\nInstead of at context init time, the previous state is saved only at the\npoint the context overrides the current state, and is restored on context\nexit only if the context is still the owner of the current override state.\n\n(cherry picked from commit 1b5e413713c0a93bc1818394d0ce49aaad21bd27)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68273","epss":0.00134,"percentile":0.03254,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68273","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68277","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68277","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers  Three sideband reply parsers read 16-bit fields as:    val = (raw->msg[idx] << 8) | (raw->msg[idx+1]);  and check bounds only after the fact. When idx == raw->curlen, raw->msg[idx+1] reads one byte past the received message data into the following struct fields (curchunk_len, curchunk_idx, curlen).  Affected functions:  - drm_dp_sideband_parse_enum_path_resources_ack()    full_payload_bw_number and avail_payload_bw_number fields  - drm_dp_sideband_parse_allocate_payload_ack()    allocated_pbn field  - drm_dp_sideband_parse_query_payload_ack()    allocated_pbn field  Fix by using a single combined check (idx + 2 > curlen) before each 2-byte read. Since the check is strictly tighter than idx > curlen, no separate step is needed.  [added fixes tag]","cvss":[],"epss":[{"cve":"CVE-2026-68277","epss":0.0022,"percentile":0.12416,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68277","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68277","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0bcd7675c69a2462a8531fcd9e4d096e9c7ec5df","https://git.kernel.org/stable/c/192e146c2d57ad033b0d418ec64ee390f8dc074e","https://git.kernel.org/stable/c/68a624416d1dd481b3e5b7ea0e8a070a9b8a2c73","https://git.kernel.org/stable/c/6b89ba3dba2f583626fb693e47e951ffb8bf591f","https://git.kernel.org/stable/c/6e3107e6522109a07fc9bb0fc4ec463f1982e113","https://git.kernel.org/stable/c/bdf0508b1e6785d4a8982c637e97e68d60b47d7b","https://git.kernel.org/stable/c/c1f72a13d54ffd16647d3fa540d961f5deba8790","https://git.kernel.org/stable/c/d5c70523cafa26ad2c7a37b612849abe2683baa8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers\n\nThree sideband reply parsers read 16-bit fields as:\n\n  val = (raw->msg[idx] << 8) | (raw->msg[idx+1]);\n\nand check bounds only after the fact. When idx == raw->curlen,\nraw->msg[idx+1] reads one byte past the received message data into\nthe following struct fields (curchunk_len, curchunk_idx, curlen).\n\nAffected functions:\n - drm_dp_sideband_parse_enum_path_resources_ack()\n   full_payload_bw_number and avail_payload_bw_number fields\n - drm_dp_sideband_parse_allocate_payload_ack()\n   allocated_pbn field\n - drm_dp_sideband_parse_query_payload_ack()\n   allocated_pbn field\n\nFix by using a single combined check (idx + 2 > curlen) before each\n2-byte read. Since the check is strictly tighter than idx > curlen,\nno separate step is needed.\n\n[added fixes tag]","cvss":[],"epss":[{"cve":"CVE-2026-68277","epss":0.0022,"percentile":0.12416,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68277","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68278","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68278","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/dp/mst: fix buffer overflows in sideband chunk accumulation  drm_dp_sideband_append_payload() has three related bugs when processing device-provided sideband reply data:  1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken    directly from the DP sideband header. If a device sends msg_len=0,    curchunk_len is set to zero. The condition (curchunk_idx >= curchunk_len)    is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).    drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()    writes 255 bytes into msg[], both far out of bounds.  2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is    only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks    until curchunk_idx reaches curchunk_len, writing up to 15 bytes past    the end of chunk[] into msg[].  3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to    msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],    so the memcpy can spill into adjacent struct fields.  All three are reachable from any DP MST device that can forge sideband reply messages on a physical connection.","cvss":[],"epss":[{"cve":"CVE-2026-68278","epss":0.00238,"percentile":0.14746,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11900000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68278","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68278","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1e5827839ad0ceb0079d1560c321fa3656b54f21","https://git.kernel.org/stable/c/4d5109075a787de28c9e89940f9dee45269f91fa","https://git.kernel.org/stable/c/53937a2787d29c7a460e984dc4f20ff6ac91dc65","https://git.kernel.org/stable/c/55bd5e685bda455b9b50c835f8c8442d52a344a3","https://git.kernel.org/stable/c/a6366b551079c79bf7bdbadd74c97358bcfe2d58","https://git.kernel.org/stable/c/d4e05dedb252ed3e540a0c9be511e427f098110a","https://git.kernel.org/stable/c/ef0dbcc200c3389f1f781ab181932a97e54b51af","https://git.kernel.org/stable/c/ef2ecb6cf268debf3890df99fea01b6452dcf78e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix buffer overflows in sideband chunk accumulation\n\ndrm_dp_sideband_append_payload() has three related bugs when processing\ndevice-provided sideband reply data:\n\n1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken\n   directly from the DP sideband header. If a device sends msg_len=0,\n   curchunk_len is set to zero. The condition (curchunk_idx >= curchunk_len)\n   is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow).\n   drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy()\n   writes 255 bytes into msg[], both far out of bounds.\n\n2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is\n   only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks\n   until curchunk_idx reaches curchunk_len, writing up to 15 bytes past\n   the end of chunk[] into msg[].\n\n3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to\n   msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256],\n   so the memcpy can spill into adjacent struct fields.\n\nAll three are reachable from any DP MST device that can forge sideband\nreply messages on a physical connection.","cvss":[],"epss":[{"cve":"CVE-2026-68278","epss":0.00238,"percentile":0.14746,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68278","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68279","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68279","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers  drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw message and then unconditionally does:    memcpy(bytes, &raw->msg[idx], num_bytes);  without checking that idx + num_bytes <= raw->curlen. raw->msg[] is 256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger than the remaining payload, the memcpy reads past the received data into whatever follows in raw->msg[].  drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted with a /* TODO check */ comment since the code was introduced).  Fix both functions by using a single combined check (idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8, it is always >= 0, so this strictly subsumes the simpler idx > curlen form and no separate step is needed.  [added missing fixes tag]","cvss":[],"epss":[{"cve":"CVE-2026-68279","epss":0.00184,"percentile":0.08121,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68279","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68279","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/04d953f50d61e542e94a5977822cc53735f8c0ce","https://git.kernel.org/stable/c/185de1d74e658e2edb723ba76fa61903f77d8a68","https://git.kernel.org/stable/c/1a8f537f5a1eeac941f262fe73078d6b08ba83c0","https://git.kernel.org/stable/c/22d9f7fc1aaabaf73d5f30e8b0c9aa814ecd6ed2","https://git.kernel.org/stable/c/533d9e2bede4aeefdc2a0561d7071cfede95958f","https://git.kernel.org/stable/c/c2fbda0fe0163c55ba3820ee6cea0c6b43622eda","https://git.kernel.org/stable/c/d7b9b1e33b4ed8c48d4db6e6e21c257ebbbb2586","https://git.kernel.org/stable/c/e6ef5455b06cb4e5d181aabcd723791587c79f12"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers\n\ndrm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw\nmessage and then unconditionally does:\n\n  memcpy(bytes, &raw->msg[idx], num_bytes);\n\nwithout checking that idx + num_bytes <= raw->curlen. raw->msg[] is\n256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger\nthan the remaining payload, the memcpy reads past the received data\ninto whatever follows in raw->msg[].\n\ndrm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted\nwith a /* TODO check */ comment since the code was introduced).\n\nFix both functions by using a single combined check\n(idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8,\nit is always >= 0, so this strictly subsumes the simpler idx > curlen\nform and no separate step is needed.\n\n[added missing fixes tag]","cvss":[],"epss":[{"cve":"CVE-2026-68279","epss":0.00184,"percentile":0.08121,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68279","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68280","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68280","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()  The deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks for both runtime PM and system sleep. This causes the DSI clocks to be disabled twice: once during runtime suspend and again during system suspend, resulting in a WARN message from the clock framework when attempting to disable already-disabled clocks.  [   84.384540] clk:231:5 already disabled [   84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac ... [   84.579183] Call trace: [   84.581624]  clk_core_disable+0xa4/0xac [   84.585457]  clk_disable+0x30/0x4c [   84.588857]  cdns_dsi_suspend+0x20/0x58 [cdns_dsi] [   84.593651]  pm_generic_suspend+0x2c/0x44 [   84.597661]  ti_sci_pd_suspend+0xbc/0x15c [   84.601670]  dpm_run_callback+0x8c/0x14c [   84.605588]  __device_suspend+0x1a0/0x56c [   84.609594]  dpm_suspend+0x17c/0x21c [   84.613165]  dpm_suspend_start+0xa0/0xa8 [   84.617083]  suspend_devices_and_enter+0x12c/0x634 [   84.621872]  pm_suspend+0x1fc/0x368  To address this issue, replace UNIVERSAL_DEV_PM_OPS() with RUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime PM, as the DRM framework manages system-wide power transitions through the bridge enable() and disable() hooks.","cvss":[],"epss":[{"cve":"CVE-2026-68280","epss":0.0018,"percentile":0.07726,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09},"relatedVulnerabilities":[{"id":"CVE-2026-68280","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68280","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1014b279264c0fc9f56324608754e36d33b7b5ae","https://git.kernel.org/stable/c/1f9c6b74e79639179e90ad0c0fbeae26e31e044b","https://git.kernel.org/stable/c/2d8b08844c0ecc6f2002fa68711e779aa18c8585","https://git.kernel.org/stable/c/347bc3a6a4d968c403d2292e5ad986294d919dfc","https://git.kernel.org/stable/c/c0384d6872f4dc2701960048a0be1a12a8d2dc6e","https://git.kernel.org/stable/c/c18d46d9830c29677be5213a067daafe1ac80e43"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()\n\nThe deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks\nfor both runtime PM and system sleep. This causes the DSI clocks to be\ndisabled twice: once during runtime suspend and again during system\nsuspend, resulting in a WARN message from the clock framework when\nattempting to disable already-disabled clocks.\n\n[   84.384540] clk:231:5 already disabled\n[   84.388314] WARNING: CPU: 2 PID: 531 at /drivers/clk/clk.c:1181 clk_core_disable+0xa4/0xac\n...\n[   84.579183] Call trace:\n[   84.581624]  clk_core_disable+0xa4/0xac\n[   84.585457]  clk_disable+0x30/0x4c\n[   84.588857]  cdns_dsi_suspend+0x20/0x58 [cdns_dsi]\n[   84.593651]  pm_generic_suspend+0x2c/0x44\n[   84.597661]  ti_sci_pd_suspend+0xbc/0x15c\n[   84.601670]  dpm_run_callback+0x8c/0x14c\n[   84.605588]  __device_suspend+0x1a0/0x56c\n[   84.609594]  dpm_suspend+0x17c/0x21c\n[   84.613165]  dpm_suspend_start+0xa0/0xa8\n[   84.617083]  suspend_devices_and_enter+0x12c/0x634\n[   84.621872]  pm_suspend+0x1fc/0x368\n\nTo address this issue, replace UNIVERSAL_DEV_PM_OPS() with\nRUNTIME_PM_OPS(). Bridge and panel drivers should only deal with runtime\nPM, as the DRM framework manages system-wide power transitions through\nthe bridge enable() and disable() hooks.","cvss":[],"epss":[{"cve":"CVE-2026-68280","epss":0.0018,"percentile":0.07726,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68280","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68284","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68284","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()  tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock.  Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock->cork.  This comparison is unsafe when two threads send on the same socket:    Thread A                         Thread B   msg_tx = psock->cork   sk_msg_alloc() fails   sk_stream_wait_memory()     releases the socket lock      acquires the socket lock                                   completes the cork                                   psock->cork = NULL                                   frees the cork     reacquires the socket lock   msg_tx != psock->cork   sk_msg_free(msg_tx)  The stale cork is therefore mistaken for the local temporary message and freed again.  KASAN reported:    BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50   Read of size 4 at addr ffff88810c908800 by task poc/90   Call Trace:    sk_msg_free+0x49/0x50    tcp_bpf_sendmsg+0x14f5/0x1cc0    __sys_sendto+0x32c/0x3a0    __x64_sys_sendto+0xdb/0x1b0   Allocated by task 89:    __kasan_kmalloc+0x8f/0xa0    tcp_bpf_sendmsg+0x16b3/0x1cc0   Freed by task 91:    __kasan_slab_free+0x43/0x70    kfree+0x131/0x3c0    tcp_bpf_sendmsg+0xec3/0x1cc0  msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock->cork cannot turn a shared message into an apparent local one.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68284","epss":0.00135,"percentile":0.03276,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.103275},"relatedVulnerabilities":[{"id":"CVE-2026-68284","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68284","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0688e6fe599d2d39147ae9ece97944c6e1815ebf","https://git.kernel.org/stable/c/2d66a033864e27ab8d5e44cb36f31d9d2413bee4","https://git.kernel.org/stable/c/54be47e7cbb936429c3bbdfc526ea943954aaf80","https://git.kernel.org/stable/c/752b1159ed5d0c48fe169a3721b96660a9822aa1","https://git.kernel.org/stable/c/786d690257ec7a0c839f8710456e444ce3f1348b","https://git.kernel.org/stable/c/b2bcbeabfd843d47468fa095b1bd08ddb90cf616","https://git.kernel.org/stable/c/cde4d6bcd9b73073c66498f6723c7b364c4dbc18","https://git.kernel.org/stable/c/ee762f684eefa59de34d9ed93cab08336e834f47"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()\n\ntcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which\ndrops and reacquires the socket lock.  Its error path tries to decide\nwhether msg_tx names the local temporary message by comparing it with\nthe current value of psock->cork.\n\nThis comparison is unsafe when two threads send on the same socket:\n\n  Thread A                         Thread B\n  msg_tx = psock->cork\n  sk_msg_alloc() fails\n  sk_stream_wait_memory()\n    releases the socket lock      acquires the socket lock\n                                  completes the cork\n                                  psock->cork = NULL\n                                  frees the cork\n    reacquires the socket lock\n  msg_tx != psock->cork\n  sk_msg_free(msg_tx)\n\nThe stale cork is therefore mistaken for the local temporary message\nand freed again.  KASAN reported:\n\n  BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50\n  Read of size 4 at addr ffff88810c908800 by task poc/90\n  Call Trace:\n   sk_msg_free+0x49/0x50\n   tcp_bpf_sendmsg+0x14f5/0x1cc0\n   __sys_sendto+0x32c/0x3a0\n   __x64_sys_sendto+0xdb/0x1b0\n  Allocated by task 89:\n   __kasan_kmalloc+0x8f/0xa0\n   tcp_bpf_sendmsg+0x16b3/0x1cc0\n  Freed by task 91:\n   __kasan_slab_free+0x43/0x70\n   kfree+0x131/0x3c0\n   tcp_bpf_sendmsg+0xec3/0x1cc0\n\nmsg_tx can only name the stack-local tmp or the shared cork. Check for\ntmp directly so a changed psock->cork cannot turn a shared message into\nan apparent local one.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68284","epss":0.00135,"percentile":0.03276,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68284","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68286","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68286","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drop_monitor: perform u64_stats updates under IRQ-disabled section  In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(), u64_stats_update_begin() / u64_stats_inc() / u64_stats_update_end() were called after spin_unlock_irqrestore(&...drop_queue.lock, flags), when local IRQs had already been re-enabled.  Tracepoint probes can execute in IRQ or softirq context. On 32-bit architectures, u64_stats_update_begin() disables preemption but not interrupts, relying on seqcount writes. If a nested interrupt occurs on the same CPU during the 64-bit stats update, the reentrant seqcount update can corrupt the seqcount state or stats value.  Fix this by performing the 64-bit per-CPU stats update before releasing drop_queue.lock via spin_unlock_irqrestore(), ensuring local interrupts remain disabled during the u64_stats update.","cvss":[],"epss":[{"cve":"CVE-2026-68286","epss":0.00189,"percentile":0.08658,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2026-68286","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68286","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/d5e2cd2bc8ae36617346b3a54ee9da61d866bf92","https://git.kernel.org/stable/c/fd098a23bf8fda7eae48db9b06e7c34fc4d228fa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrop_monitor: perform u64_stats updates under IRQ-disabled section\n\nIn net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(),\nu64_stats_update_begin() / u64_stats_inc() / u64_stats_update_end() were\ncalled after spin_unlock_irqrestore(&...drop_queue.lock, flags), when local\nIRQs had already been re-enabled.\n\nTracepoint probes can execute in IRQ or softirq context. On 32-bit\narchitectures, u64_stats_update_begin() disables preemption but not interrupts,\nrelying on seqcount writes. If a nested interrupt occurs on the same CPU during\nthe 64-bit stats update, the reentrant seqcount update can corrupt the\nseqcount state or stats value.\n\nFix this by performing the 64-bit per-CPU stats update before releasing\ndrop_queue.lock via spin_unlock_irqrestore(), ensuring local interrupts remain\ndisabled during the u64_stats update.","cvss":[],"epss":[{"cve":"CVE-2026-68286","epss":0.00189,"percentile":0.08658,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68286","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68287","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68287","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drop_monitor: fix size calculations for 64-bit attributes  net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use nla_put_u64_64bit() to append 64-bit attributes (NET_DM_ATTR_PC and NET_DM_ATTR_TIMESTAMP).  On 32-bit architectures without CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS, nla_put_u64_64bit() may append a 4-byte NET_DM_ATTR_PAD attribute for 64-bit alignment.  However, net_dm_packet_report_size() and net_dm_hw_packet_report_size() used nla_total_size(sizeof(u64)) instead of nla_total_size_64bit(sizeof(u64)), budgeting 12 bytes instead of up to 16 bytes.  This under-estimation of SKB size can lead to an skb_over_panic() when __nla_reserve() or skb_put() is subsequently called.  Fix this by using nla_total_size_64bit(sizeof(u64)) in both size calculations.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68287","epss":0.00488,"percentile":0.40437,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.366},"relatedVulnerabilities":[{"id":"CVE-2026-68287","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68287","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4a9e30764e80693bcf875c776170edce20f94fe0","https://git.kernel.org/stable/c/7089f7ab99c89f443c92d8fcc585e63f2727f0b3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrop_monitor: fix size calculations for 64-bit attributes\n\nnet_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use\nnla_put_u64_64bit() to append 64-bit attributes (NET_DM_ATTR_PC and\nNET_DM_ATTR_TIMESTAMP).\n\nOn 32-bit architectures without CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS,\nnla_put_u64_64bit() may append a 4-byte NET_DM_ATTR_PAD attribute for\n64-bit alignment.\n\nHowever, net_dm_packet_report_size() and net_dm_hw_packet_report_size()\nused nla_total_size(sizeof(u64)) instead of nla_total_size_64bit(sizeof(u64)),\nbudgeting 12 bytes instead of up to 16 bytes.\n\nThis under-estimation of SKB size can lead to an skb_over_panic() when\n__nla_reserve() or skb_put() is subsequently called.\n\nFix this by using nla_total_size_64bit(sizeof(u64)) in both size calculations.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68287","epss":0.00488,"percentile":0.40437,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68287","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68288","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68288","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD  net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload before overwriting it with skb_copy_bits().  skb_put() reserves nla_total_size(payload_len), i.e. the header plus the NLA_ALIGN() padding, but only payload_len bytes are copied in. When payload_len is not a multiple of 4 the 1-3 padding bytes are never initialized and are leaked to user space inside the netlink message.  KMSAN confirms the leak for the software path when the packet payload length is not 4-byte aligned:    BUG: KMSAN: kernel-infoleak in _copy_to_iter    _copy_to_iter    __skb_datagram_iter    skb_copy_datagram_iter    netlink_recvmsg    sock_recvmsg    __sys_recvfrom   Uninit was created at:    kmem_cache_alloc_node_noprof    __alloc_skb    net_dm_packet_work   Bytes 173-175 of 176 are uninitialized  Use __nla_reserve(), which sets up the attribute header and zeroes the padding, instead of open coding the attribute construction.","cvss":[],"epss":[{"cve":"CVE-2026-68288","epss":0.00162,"percentile":0.05748,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08099999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-68288","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68288","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/5e9c8baee0329fbefe7c67aea945e2a07f15e98b","https://git.kernel.org/stable/c/8fd6975d2aecc36b25ee82b6aef88e62a3527ccb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD\n\nnet_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code\nthe NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload\nbefore overwriting it with skb_copy_bits().\n\nskb_put() reserves nla_total_size(payload_len), i.e. the header plus the\nNLA_ALIGN() padding, but only payload_len bytes are copied in. When\npayload_len is not a multiple of 4 the 1-3 padding bytes are never\ninitialized and are leaked to user space inside the netlink message.\n\nKMSAN confirms the leak for the software path when the packet payload\nlength is not 4-byte aligned:\n\n  BUG: KMSAN: kernel-infoleak in _copy_to_iter\n   _copy_to_iter\n   __skb_datagram_iter\n   skb_copy_datagram_iter\n   netlink_recvmsg\n   sock_recvmsg\n   __sys_recvfrom\n  Uninit was created at:\n   kmem_cache_alloc_node_noprof\n   __alloc_skb\n   net_dm_packet_work\n  Bytes 173-175 of 176 are uninitialized\n\nUse __nla_reserve(), which sets up the attribute header and zeroes the\npadding, instead of open coding the attribute construction.","cvss":[],"epss":[{"cve":"CVE-2026-68288","epss":0.00162,"percentile":0.05748,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68288","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68289","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68289","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()  In tipc_recvmsg(), the copy length is computed as:    copy = min_t(int, dlen - offset, buflen);  buflen is size_t but min_t(int, ...) casts it to int. When buflen exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it wraps negative, wins the comparison, and the negative copy length propagates to simple_copy_to_iter() where int-to-size_t promotion makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the same pattern.    Kernel panic - not syncing: kernel: panic_on_warn set ...   RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521)   Call Trace:    __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402)    skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534)    tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934)    io_recvmsg+0x47e/0xda0  Fix by changing min_t(int, ...) to min_t(size_t, ...) in both functions. The result is always <= (dlen - offset), which is bounded by TIPC maximum message size (0x1ffff bytes), so the implicit narrowing on assignment to int copy is always safe.","cvss":[],"epss":[{"cve":"CVE-2026-68289","epss":0.00162,"percentile":0.05748,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08099999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-68289","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68289","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/47f42ff521b4eeb46e82f9a46a4783a99f7570d7","https://git.kernel.org/stable/c/fe9bf32bb18f2d35789d4960fb007d1059bbaa38"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()\n\nIn tipc_recvmsg(), the copy length is computed as:\n\n  copy = min_t(int, dlen - offset, buflen);\n\nbuflen is size_t but min_t(int, ...) casts it to int. When buflen\nexceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it\nwraps negative, wins the comparison, and the negative copy length\npropagates to simple_copy_to_iter() where int-to-size_t promotion\nmakes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the\nsame pattern.\n\n  Kernel panic - not syncing: kernel: panic_on_warn set ...\n  RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521)\n  Call Trace:\n   __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402)\n   skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534)\n   tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934)\n   io_recvmsg+0x47e/0xda0\n\nFix by changing min_t(int, ...) to min_t(size_t, ...) in both\nfunctions. The result is always <= (dlen - offset), which is bounded\nby TIPC maximum message size (0x1ffff bytes), so the implicit\nnarrowing on assignment to int copy is always safe.","cvss":[],"epss":[{"cve":"CVE-2026-68289","epss":0.00162,"percentile":0.05748,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68289","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68293","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68293","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5: Fix MCIA register buffer overflow on 32 dword reads  The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just 12 dwords (48 bytes) of data.  mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then memcpy()s that many bytes out of the register, potentially reading past the end of the 'out' buffer. On kernels built with FORTIFY_SOURCE this is caught as a buffer overflow while reading the module EEPROM via ethtool:    detected buffer overflow in memcpy   kernel BUG at lib/string_helpers.c:1048!   RIP: 0010:fortify_panic+0x13/0x20   Call Trace:    mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]    mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]    mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]    eeprom_prepare_data+0xf3/0x170    ethnl_default_doit+0xf1/0x3b0  Extend the mcia_reg layout to 32 dwords.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68293","epss":0.00138,"percentile":0.03509,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10073999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-68293","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68293","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/11c057d23465c7a5817a7284c896d19d54c0b616","https://git.kernel.org/stable/c/5be4eebd5a3a198dab0adcd550e1cadca79bdfed","https://git.kernel.org/stable/c/87b39a8c875ca744b7de69af0a8ef8874cffccf1","https://git.kernel.org/stable/c/88b2a16ddac3357e3f1d528e758b51e2c945d546"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix MCIA register buffer overflow on 32 dword reads\n\nThe MCIA register can return up to 32 dwords (128 bytes) when the device\nadvertises the mcia_32dwords capability, but struct\nmlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just\n12 dwords (48 bytes) of data.\n\nmlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then\nmemcpy()s that many bytes out of the register, potentially reading past\nthe end of the 'out' buffer. On kernels built with FORTIFY_SOURCE this\nis caught as a buffer overflow while reading the module EEPROM via\nethtool:\n\n  detected buffer overflow in memcpy\n  kernel BUG at lib/string_helpers.c:1048!\n  RIP: 0010:fortify_panic+0x13/0x20\n  Call Trace:\n   mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]\n   mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]\n   mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]\n   eeprom_prepare_data+0xf3/0x170\n   ethnl_default_doit+0xf1/0x3b0\n\nExtend the mcia_reg layout to 32 dwords.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68293","epss":0.00138,"percentile":0.03509,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68293","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68294","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68294","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: qrtr: restrict socket creation to the initial network namespace  QRTR keeps its entire port and node state in module-global variables that are not partitioned per network namespace: qrtr_local_nid is a single global node id (always 1) and qrtr_ports is a single global xarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that global state with no network-namespace check, and qrtr_create() places no restriction on the namespace a socket is created in.  As a result an unprivileged process that creates an AF_QIPCRTR socket in a separate network namespace, e.g. via unshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams - including control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR sockets owned by another namespace, and vice versa. The receiving socket sees such a message as coming from node id 1, indistinguishable from a legitimate local client, breaking the isolation that network namespaces are expected to provide.  QRTR is a transport to global hardware endpoints (the modem and other remote processors) and has no per-namespace semantics; its in-kernel name service already creates its socket in init_net only. Confine the socket family to the initial network namespace, as other non-namespace-aware socket families do (see llc_ui_create() and the ieee802154 socket code).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68294","epss":0.00164,"percentile":0.05903,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13366},"relatedVulnerabilities":[{"id":"CVE-2026-68294","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68294","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2d22b94a154ccb9755dddfff802fe3e2b1adbab5","https://git.kernel.org/stable/c/3b536db8fb32da9e9c62f2bb45e2e319331f0426","https://git.kernel.org/stable/c/4b95e1f0d6e6342c427cb341ee18a894b146b789","https://git.kernel.org/stable/c/659b9b4f194bb56b9903cc95e786ef1d438baa7d","https://git.kernel.org/stable/c/7814f6a3415cad38aa8d6dfc573df778260d66aa","https://git.kernel.org/stable/c/8150c48fb978e01689f94ed80148f8a7499ae571","https://git.kernel.org/stable/c/8d351fe0654a20c9f95a61b05d24ebe6d4be3fbb","https://git.kernel.org/stable/c/f488116df769bdaf89c93371350e49e12133e70f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qrtr: restrict socket creation to the initial network namespace\n\nQRTR keeps its entire port and node state in module-global variables\nthat are not partitioned per network namespace: qrtr_local_nid is a\nsingle global node id (always 1) and qrtr_ports is a single global\nxarray. qrtr_port_lookup() and qrtr_local_enqueue() operate on that\nglobal state with no network-namespace check, and qrtr_create() places\nno restriction on the namespace a socket is created in.\n\nAs a result an unprivileged process that creates an AF_QIPCRTR socket\nin a separate network namespace, e.g. via\nunshare(CLONE_NEWUSER | CLONE_NEWNET), can send QRTR datagrams -\nincluding control-plane messages such as QRTR_TYPE_NEW_SERVER - to QRTR\nsockets owned by another namespace, and vice versa. The receiving\nsocket sees such a message as coming from node id 1, indistinguishable\nfrom a legitimate local client, breaking the isolation that network\nnamespaces are expected to provide.\n\nQRTR is a transport to global hardware endpoints (the modem and other\nremote processors) and has no per-namespace semantics; its in-kernel\nname service already creates its socket in init_net only. Confine the\nsocket family to the initial network namespace, as other\nnon-namespace-aware socket families do (see llc_ui_create() and the\nieee802154 socket code).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68294","epss":0.00164,"percentile":0.05903,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68294","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68297","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68297","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: fix u16 MTU truncation in media and bearer MTU validation  Both TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied MTU values but only enforce a minimum bound, not a maximum. When a user sets the MTU to a value exceeding U16_MAX (65535), it passes validation but is silently truncated when assigned to u16 fields l->mtu and l->advertised_mtu in tipc_link_create(). Values like 65536 (0x10000) truncate to 0, causing a division by zero in tipc_link_set_queue_limits() which computes TIPC_MAX_PUBL / (l->mtu / ITEM_SIZE). Other overflowing values (e.g. 65537-131071) produce small incorrect MTU values, resulting in link malfunction behaviors.  Crash stack (triggered as unprivileged user via user namespace):    tipc_link_set_queue_limits  net/tipc/link.c:2531   tipc_link_create            net/tipc/link.c:520   tipc_node_check_dest        net/tipc/node.c:1279   tipc_disc_rcv               net/tipc/discover.c:252   tipc_rcv                    net/tipc/node.c:2129   tipc_udp_recv               net/tipc/udp_media.c:392  Two independent paths lack the upper bound check: 1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET) 2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)  Fix both by rejecting MTU values above U16_MAX.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68297","epss":0.00129,"percentile":0.0287,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68297","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68297","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1b8fb5a20508bfb0db854e01214888c761b3a911","https://git.kernel.org/stable/c/8bfdfe0dbb36a650b7c4dec1aeae078319938a0b","https://git.kernel.org/stable/c/9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8","https://git.kernel.org/stable/c/c1cda72f6acec02ebd45d913bf8527ff77336ba6","https://git.kernel.org/stable/c/dc4b577a083b361d25e118dc96d8281255ebe22c","https://git.kernel.org/stable/c/dfdfd987f1917c84766e097a6120a1f3f1634940","https://git.kernel.org/stable/c/f02334a9e378f7e07232b26dc3d2ab353339f040","https://git.kernel.org/stable/c/f4013598b69457dbea350df52e52daea6faef8eb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix u16 MTU truncation in media and bearer MTU validation\n\nBoth TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied\nMTU values but only enforce a minimum bound, not a maximum. When a user\nsets the MTU to a value exceeding U16_MAX (65535), it passes validation\nbut is silently truncated when assigned to u16 fields l->mtu and\nl->advertised_mtu in tipc_link_create(). Values like 65536 (0x10000)\ntruncate to 0, causing a division by zero in tipc_link_set_queue_limits()\nwhich computes TIPC_MAX_PUBL / (l->mtu / ITEM_SIZE). Other overflowing\nvalues (e.g. 65537-131071) produce small incorrect MTU values, resulting\nin link malfunction behaviors.\n\nCrash stack (triggered as unprivileged user via user namespace):\n\n  tipc_link_set_queue_limits  net/tipc/link.c:2531\n  tipc_link_create            net/tipc/link.c:520\n  tipc_node_check_dest        net/tipc/node.c:1279\n  tipc_disc_rcv               net/tipc/discover.c:252\n  tipc_rcv                    net/tipc/node.c:2129\n  tipc_udp_recv               net/tipc/udp_media.c:392\n\nTwo independent paths lack the upper bound check:\n1. tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET)\n2. inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)\n\nFix both by rejecting MTU values above U16_MAX.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68297","epss":0.00129,"percentile":0.0287,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68297","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68299","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68299","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets  vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers:  - BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer   protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner   IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).  Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68299","epss":0.00501,"percentile":0.41263,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37575},"relatedVulnerabilities":[{"id":"CVE-2026-68299","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68299","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/28cb5d8d13b4c1faf3f688f62e5df82fe7b438d8","https://git.kernel.org/stable/c/28e382646417c7e2be9c9a7079eddf627ff52b90","https://git.kernel.org/stable/c/2ddf51fcb6dd7d55ceef38e2e1a5ab2ab7fd47b0","https://git.kernel.org/stable/c/34a71f5361fc3adb5b7138da78750b0d535a8252","https://git.kernel.org/stable/c/4fdb0f162ccdbe9626863b10003855703253fa29","https://git.kernel.org/stable/c/667b6e52048eaf4dbcf1707ed87ffd44abb9cb38","https://git.kernel.org/stable/c/b28596baf87e25a078789f1c05817c8a3bf71257","https://git.kernel.org/stable/c/fbab6b73cc086e32698c86e43d1b16bf17d24c36"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets\n\nvmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the\nouter header, but for a Geneve-encapsulated packet the device can set\nthem based on the inner header instead, signalled by the\nVMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the\nfunction never skips the outer encapsulation, this mismatch triggers:\n\n- BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer\n  protocol is UDP (Geneve), not TCP.\n- BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner\n  IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).\n\nCheck VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the\nfunction cannot locate the inner header it would need to parse. Also\nconvert the remaining BUG_ON()s in this function to return 0\ndefensively.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68299","epss":0.00501,"percentile":0.41263,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68299","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68300","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68300","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: auth: verify auth requirement when auth_chunk is NULL  sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when:  1. skb_clone() failed in the BH receive path, leaving auth_chunk    NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new    connections, so the early sctp_auth_recv_cid() check cannot    catch this.  2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never    called and auth_chunk remains NULL.  Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68300","epss":0.00597,"percentile":0.46542,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.56118},"relatedVulnerabilities":[{"id":"CVE-2026-68300","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68300","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/18957373920caf5cdaf5cf32e5d1d7a99ca7700a","https://git.kernel.org/stable/c/28c5fdce9dd955d2baf5e28987819b6d7cfaf646","https://git.kernel.org/stable/c/5a022ac51ad83b4ce6c898f4b9eefc65bd26b247","https://git.kernel.org/stable/c/6caf0e8590c0bf05a76b0d387726adf3a6f3725c","https://git.kernel.org/stable/c/83f5031f2a6a49d696eb4cc0898345d12f9c6451","https://git.kernel.org/stable/c/8e04823c120b376ef7dab14b60ebf6823aa16c14","https://git.kernel.org/stable/c/a129792b3aef15002746c13522781d92ed3522c3","https://git.kernel.org/stable/c/ec2e157fc9678a9bc411305a25aec3fd337d7efb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: auth: verify auth requirement when auth_chunk is NULL\n\nsctp_auth_chunk_verify() returns true unconditionally when\nchunk->auth_chunk is NULL, silently skipping authentication.\nThis is incorrect when:\n\n1. skb_clone() failed in the BH receive path, leaving auth_chunk\n   NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new\n   connections, so the early sctp_auth_recv_cid() check cannot\n   catch this.\n\n2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never\n   called and auth_chunk remains NULL.\n\nFix by checking sctp_auth_recv_cid() when auth_chunk is NULL:\nif authentication is required, return false to drop the chunk;\notherwise continue normally.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68300","epss":0.00597,"percentile":0.46542,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68300","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68301","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68301","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: hsr: fix memory leak on slave unregistration by removing synced VLANs  When an HSR master device is brought UP, it auto-adds VLAN 0 via vlan_vid0_add(), which propagates VID 0 to its slave devices (slave A and B).  If a slave device is later unregistered while HSR is active (e.g., during netns cleanup or interface destruction), hsr_del_port() is called to detach the slave port from the HSR master. However, hsr_del_port() currently does not delete the VLAN IDs that were synced to the slave device by HSR.  As a result, the slave device retains a refcount on VID 0 (and any other synced VLANs). When the slave device is destroyed, its vlan_info / vlan_vid_info structure remains allocated, leading to a memory leak.  Fix this by calling vlan_vids_del_by_dev(port->dev, master->dev) in hsr_del_port() before unlinking slave A or slave B ports, matching the propagation logic in hsr_ndo_vlan_rx_add_vid() / hsr_ndo_vlan_rx_kill_vid() and the cleanup behavior in bonding and team drivers.","cvss":[],"epss":[{"cve":"CVE-2026-68301","epss":0.00173,"percentile":0.06838,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-68301","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68301","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/21d48408479a17eb65568a765930adea37e4d804","https://git.kernel.org/stable/c/79ff0547676acdeceda445c3fce4071b0a887b70","https://git.kernel.org/stable/c/ae995b8002d3af134560a706c0e111a89e26317c","https://git.kernel.org/stable/c/b5ded444621b6180df9f3d4e07045fc1fc1e8cd9","https://git.kernel.org/stable/c/ccc822e9e4f09a6c2ca73ad5334570441947f94f","https://git.kernel.org/stable/c/dcf15eaf5641812f1cfc5e96537380132a7da89d","https://git.kernel.org/stable/c/f72c312af6c7897ab0f8a2b5a63f917a207a4143"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: fix memory leak on slave unregistration by removing synced VLANs\n\nWhen an HSR master device is brought UP, it auto-adds VLAN 0 via\nvlan_vid0_add(), which propagates VID 0 to its slave devices (slave A and B).\n\nIf a slave device is later unregistered while HSR is active (e.g., during\nnetns cleanup or interface destruction), hsr_del_port() is called to\ndetach the slave port from the HSR master. However, hsr_del_port() currently\ndoes not delete the VLAN IDs that were synced to the slave device by HSR.\n\nAs a result, the slave device retains a refcount on VID 0 (and any other\nsynced VLANs). When the slave device is destroyed, its vlan_info /\nvlan_vid_info structure remains allocated, leading to a memory leak.\n\nFix this by calling vlan_vids_del_by_dev(port->dev, master->dev) in\nhsr_del_port() before unlinking slave A or slave B ports, matching the\npropagation logic in hsr_ndo_vlan_rx_add_vid() / hsr_ndo_vlan_rx_kill_vid()\nand the cleanup behavior in bonding and team drivers.","cvss":[],"epss":[{"cve":"CVE-2026-68301","epss":0.00173,"percentile":0.06838,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68301","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68302","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68302","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  amt: re-read skb header pointers after every pull  Several AMT receive and transmit paths cache a pointer into the skb head (ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call a helper that can reallocate that head before the cached pointer is used again.  pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(), iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all free the old head and move the data, so a pointer taken before the call dangles afterwards and the later access is a use-after-free of the freed head.  The affected sites are:    amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads   iph->saddr.    amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/   ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.    amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),   then writes the L2 header.    amt_membership_query_handler() caches the AMT header, the outer and   inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several   pulls, then reads and writes them.    amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache   ip_hdr()/ipv6_hdr() and the current group record and read the record   count from the report header inside the record loop, across the   *_mc_may_pull() calls.    amt_update_handler() caches ip_hdr() and the AMT membership-update   header before pskb_may_pull(), iptunnel_pull_header(),   ip_mc_check_igmp() and the report handler, then reads iph->daddr and   amtmu->nonce / amtmu->response_mac.  Fix each site by either snapshotting the scalar that is used after the pull before the first pull runs, or re-deriving the header pointer from the skb after the last pull that can move the head.  Values that are stable across the pull (source and group address, the response MAC and nonce, the record count, the outer source MAC) are snapshotted; pointers that are written through or read repeatedly are re-derived.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68302","epss":0.00477,"percentile":0.39723,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.44838000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-68302","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68302","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/3656a79f94c471827a08f2cacce5f94ad5e52c24","https://git.kernel.org/stable/c/37ff890f9c18dfbcf57e17199901d4fd1e4c174e","https://git.kernel.org/stable/c/7746d588d42a4ac0117b68ed8e9b22a9da53dfb7","https://git.kernel.org/stable/c/7f48e3ddad8e97545b25788b8203b3a539df1621","https://git.kernel.org/stable/c/9005b221cb1f9c3c1a2ef656fb0e8fa80c0a187e","https://git.kernel.org/stable/c/ca0e8b661957f777591efe874cd9d9a63619cd99"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\namt: re-read skb header pointers after every pull\n\nSeveral AMT receive and transmit paths cache a pointer into the skb head\n(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call\na helper that can reallocate that head before the cached pointer is used\nagain.  pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),\niptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all\nfree the old head and move the data, so a pointer taken before the call\ndangles afterwards and the later access is a use-after-free of the freed\nhead.\n\nThe affected sites are:\n\n  amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads\n  iph->saddr.\n\n  amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/\n  ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.\n\n  amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),\n  then writes the L2 header.\n\n  amt_membership_query_handler() caches the AMT header, the outer and\n  inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several\n  pulls, then reads and writes them.\n\n  amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache\n  ip_hdr()/ipv6_hdr() and the current group record and read the record\n  count from the report header inside the record loop, across the\n  *_mc_may_pull() calls.\n\n  amt_update_handler() caches ip_hdr() and the AMT membership-update\n  header before pskb_may_pull(), iptunnel_pull_header(),\n  ip_mc_check_igmp() and the report handler, then reads iph->daddr and\n  amtmu->nonce / amtmu->response_mac.\n\nFix each site by either snapshotting the scalar that is used after the\npull before the first pull runs, or re-deriving the header pointer from\nthe skb after the last pull that can move the head.  Values that are\nstable across the pull (source and group address, the response MAC and\nnonce, the record count, the outer source MAC) are snapshotted; pointers\nthat are written through or read repeatedly are re-derived.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68302","epss":0.00477,"percentile":0.39723,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68302","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68303","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68303","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vc4: hvs/v3d: Fix null dereference in unbind  The hvs and v3d drivers use dev_get_drvdata(master) in their unbind functions. Since the vc4-drm gets removed before its dependent drivers (vc4_hvs/vc4_v3d) the vc4_hvs_unbind/vc4_v3d_unbind functions try to get drvdata of its master and fails with a null dereference error.  Use the data pointer passed to the unbind functions directly instead of dev_get_drvdata(master). This avoids using potentially freed memory.","cvss":[],"epss":[{"cve":"CVE-2026-68303","epss":0.00189,"percentile":0.08656,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2026-68303","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68303","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/261f0a3f0ac03248284f5116d3258f89c9642215","https://git.kernel.org/stable/c/7dc3680b7ffe01add3e9299fde8471d2dd53a8ae"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: hvs/v3d: Fix null dereference in unbind\n\nThe hvs and v3d drivers use dev_get_drvdata(master) in their unbind\nfunctions. Since the vc4-drm gets removed before its dependent drivers\n(vc4_hvs/vc4_v3d) the vc4_hvs_unbind/vc4_v3d_unbind functions try to\nget drvdata of its master and fails with a null dereference error.\n\nUse the data pointer passed to the unbind functions directly instead of\ndev_get_drvdata(master). This avoids using potentially freed memory.","cvss":[],"epss":[{"cve":"CVE-2026-68303","epss":0.00189,"percentile":0.08656,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68303","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68304","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68304","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: brcmfmac: fix 802.1X-SHA256 call trace warning  Based on wpa_auth as 1x_256 mode, need to set up \"use_fwsup\" with BRCMF_PROFILE_FWSUP_1X. Or it will happen trace warning when call brcmf_cfg80211_set_pmk().  [ 4481.831101] ------------[ cut here ]------------ [ 4481.831102] WARNING: CPU: 1 PID: 2997 at drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac] [...] [ 4481.831202] Call Trace: [ 4481.831204]  <TASK> [ 4481.831205]  nl80211_set_pmk+0x183/0x250 [cfg80211] [ 4481.831233]  genl_family_rcv_msg_doit+0xea/0x150 [ 4481.831237]  genl_rcv_msg+0x104/0x240 [ 4481.831239]  ? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211] [ 4481.831257]  ? genl_family_rcv_msg_doit+0x150/0x150 [ 4481.831259]  netlink_rcv_skb+0x4e/0x100 [ 4481.831261]  genl_rcv+0x24/0x40 [ 4481.831262]  netlink_unicast+0x236/0x380 [ 4481.831264]  netlink_sendmsg+0x250/0x4b0 [ 4481.831266]  sock_sendmsg+0x5c/0x70 [ 4481.831269]  ____sys_sendmsg+0x236/0x2b0 [ 4481.831271]  ? copy_msghdr_from_user+0x6d/0xa0 [ 4481.831272]  ___sys_sendmsg+0x86/0xd0 [ 4481.831274]  ? avc_has_perm+0x8c/0x1a0 [ 4481.831276]  ? preempt_count_add+0x6a/0xa0 [ 4481.831279]  ? sock_has_perm+0x82/0xa0 [ 4481.831280]  __sys_sendmsg+0x57/0xa0 [ 4481.831282]  do_syscall_64+0x38/0x90 [ 4481.831284]  entry_SYSCALL_64_after_hwframe+0x63/0xcd [ 4481.831286] RIP: 0033:0x7fd270d369b4","cvss":[],"epss":[{"cve":"CVE-2026-68304","epss":0.0021,"percentile":0.11274,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68304","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68304","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/00ebbf030d8c4a1cb89cbbae15e28332373649db","https://git.kernel.org/stable/c/137e4710da626290495b174e2eb1d5e889a4b165","https://git.kernel.org/stable/c/47989a233df369c2c2263ab0a5cbd8c8dad253a5","https://git.kernel.org/stable/c/7cb34f6c4fe8a68af621d870abe63bfca2275dd6","https://git.kernel.org/stable/c/bd4fac033bb95fcad898cf6734e869991b2561cb","https://git.kernel.org/stable/c/d0395840e3266397de94ecd3c91e1c188c7667c6","https://git.kernel.org/stable/c/d3ac5b35ec85c41ccf8ec524d47b520e72edaca1","https://git.kernel.org/stable/c/fe27cc1feecde0e6a0a9a04b7ad3262ed5f99252"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: fix 802.1X-SHA256 call trace warning\n\nBased on wpa_auth as 1x_256 mode, need to set up\n\"use_fwsup\" with BRCMF_PROFILE_FWSUP_1X.\nOr it will happen trace warning when call brcmf_cfg80211_set_pmk().\n\n[ 4481.831101] ------------[ cut here ]------------\n[ 4481.831102] WARNING: CPU: 1 PID: 2997 at\ndrivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c:7242 brcmf_cfg80211_set_pmk+0x77/0xd0 [brcmfmac]\n[...]\n[ 4481.831202] Call Trace:\n[ 4481.831204]  <TASK>\n[ 4481.831205]  nl80211_set_pmk+0x183/0x250 [cfg80211]\n[ 4481.831233]  genl_family_rcv_msg_doit+0xea/0x150\n[ 4481.831237]  genl_rcv_msg+0x104/0x240\n[ 4481.831239]  ? cfg80211_probe_status+0x2c0/0x2c0 [cfg80211]\n[ 4481.831257]  ? genl_family_rcv_msg_doit+0x150/0x150\n[ 4481.831259]  netlink_rcv_skb+0x4e/0x100\n[ 4481.831261]  genl_rcv+0x24/0x40\n[ 4481.831262]  netlink_unicast+0x236/0x380\n[ 4481.831264]  netlink_sendmsg+0x250/0x4b0\n[ 4481.831266]  sock_sendmsg+0x5c/0x70\n[ 4481.831269]  ____sys_sendmsg+0x236/0x2b0\n[ 4481.831271]  ? copy_msghdr_from_user+0x6d/0xa0\n[ 4481.831272]  ___sys_sendmsg+0x86/0xd0\n[ 4481.831274]  ? avc_has_perm+0x8c/0x1a0\n[ 4481.831276]  ? preempt_count_add+0x6a/0xa0\n[ 4481.831279]  ? sock_has_perm+0x82/0xa0\n[ 4481.831280]  __sys_sendmsg+0x57/0xa0\n[ 4481.831282]  do_syscall_64+0x38/0x90\n[ 4481.831284]  entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 4481.831286] RIP: 0033:0x7fd270d369b4","cvss":[],"epss":[{"cve":"CVE-2026-68304","epss":0.0021,"percentile":0.11274,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68304","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68309","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68309","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()  mt76_connac_get_he_phy_cap routine can theoretically return NULL so check cap pointer before dereferencing it.","cvss":[],"epss":[{"cve":"CVE-2026-68309","epss":0.00172,"percentile":0.0681,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68309","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68309","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2afc2d5098866518a5c446a2e647b1b3f43daaf4","https://git.kernel.org/stable/c/2c1fb2335f5e3afb34f91bc07ecb63517c328090","https://git.kernel.org/stable/c/8709c66e665a2a09192853d4f3d0fb4bd0f76403","https://git.kernel.org/stable/c/91eb15c026debd8b7bfbd83f062e6245a4e69964","https://git.kernel.org/stable/c/b09508dd7bc4a8948ea00603041a918c09788502","https://git.kernel.org/stable/c/c058786b09cfab080125bc3ee7928a181dcbd37a","https://git.kernel.org/stable/c/d1f8705d6545d20950991785306d08884b0056fc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()\n\nmt76_connac_get_he_phy_cap routine can theoretically return NULL so\ncheck cap pointer before dereferencing it.","cvss":[],"epss":[{"cve":"CVE-2026-68309","epss":0.00172,"percentile":0.0681,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68309","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68310","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68310","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7915: guard HE capability lookups  mt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after checking HE support, then dereference the HE PHY capability returned by mt76_connac_get_he_phy_cap(). That helper can return NULL when no capability entry matches the vif type.  Fetch the capability before appending the TLV and skip the HE-specific setup when no matching capability is available.","cvss":[],"epss":[{"cve":"CVE-2026-68310","epss":0.00172,"percentile":0.0681,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68310","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68310","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/23a2b98e754da04e0e90314d5fa8ca44349590fb","https://git.kernel.org/stable/c/6f99a5667c6c7c3e0da1d3c4dc8dfb103042609e","https://git.kernel.org/stable/c/871549814eb4da081f1e93cc0c7ea626a310a966","https://git.kernel.org/stable/c/8d5f1f4d2ea2c9d626ccc28dba7ea0df862acc67","https://git.kernel.org/stable/c/8e9db062654a388d0fa587acbeeae68dd33eba41","https://git.kernel.org/stable/c/a031f454f14e3e76ad03bcb23918e1a82b4b0869"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: guard HE capability lookups\n\nmt7915_mcu_bss_he_tlv() and mt7915_mcu_sta_bfer_tlv() both run after\nchecking HE support, then dereference the HE PHY capability returned by\nmt76_connac_get_he_phy_cap(). That helper can return NULL when no\ncapability entry matches the vif type.\n\nFetch the capability before appending the TLV and skip the HE-specific\nsetup when no matching capability is available.","cvss":[],"epss":[{"cve":"CVE-2026-68310","epss":0.00172,"percentile":0.0681,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68310","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68312","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68312","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths  In cifs_close_deferred_file(), cifs_close_all_deferred_files(), and cifs_close_deferred_file_under_dentry(), when a pending deferred close is cancelled via cancel_delayed_work(), the subsequent kmalloc_obj() to add the file to the local processing list may fail under memory pressure. The loop breaks immediately, but the cancelled work is no longer pending (it would have called _cifsFileInfo_put()), and the cfile is never added to file_head for processing.  The cifsFileInfo reference and the open server handle both leak.  Fix by saving the cfile that failed allocation in a local variable, breaking as before, and calling _cifsFileInfo_put() on it after releasing the lock.  Any files later in the iteration are unaffected since their deferred work is still pending and will fire normally.","cvss":[],"epss":[{"cve":"CVE-2026-68312","epss":0.00189,"percentile":0.08657,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2026-68312","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68312","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/32390b3f06f26e366cfb27dbac4bc0196c321535","https://git.kernel.org/stable/c/c2f2e83e3bbc5483730fd4ee903182761f1ae50f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths\n\nIn cifs_close_deferred_file(), cifs_close_all_deferred_files(), and\ncifs_close_deferred_file_under_dentry(), when a pending deferred close\nis cancelled via cancel_delayed_work(), the subsequent kmalloc_obj() to\nadd the file to the local processing list may fail under memory pressure.\nThe loop breaks immediately, but the cancelled work is no longer pending\n(it would have called _cifsFileInfo_put()), and the cfile is never added\nto file_head for processing.  The cifsFileInfo reference and the open\nserver handle both leak.\n\nFix by saving the cfile that failed allocation in a local variable,\nbreaking as before, and calling _cifsFileInfo_put() on it after\nreleasing the lock.  Any files later in the iteration are unaffected\nsince their deferred work is still pending and will fire normally.","cvss":[],"epss":[{"cve":"CVE-2026-68312","epss":0.00189,"percentile":0.08657,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68312","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68313","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68313","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: fix infinite loop in __tipc_nl_compat_dumpit  cmd->dumpit callback can return a negative errno, causing an infinite loop due to the while(len) condition. As the loop never terminates, genl_mutex is never released, and other tasks waiting on it starve in D state.  Check dumpit's return value, propagate it and jump to err_out on error.","cvss":[],"epss":[{"cve":"CVE-2026-68313","epss":0.0021,"percentile":0.11272,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68313","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68313","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1ab78af2140189b735b8d3b889b0284128cb2013","https://git.kernel.org/stable/c/22f8aa35964e8f2ab026578f45befc9605fd1b28","https://git.kernel.org/stable/c/2a1c1397275f27e33b6a2a565d81cfef0deb6656","https://git.kernel.org/stable/c/98d09766cee3182aae292886e2fef0cbe8dba537","https://git.kernel.org/stable/c/9cd8c88e1336ec0fbe02af1ddf2b52838d30fae4","https://git.kernel.org/stable/c/b8f3b8efa5f99081b14de1a7ffa68a81bf01bd48","https://git.kernel.org/stable/c/e740e90ca8e7f70d9eac1aa31a8b3e0e4d32b2ef","https://git.kernel.org/stable/c/f9c669d9f4cac832fe31193cdbc24c6a9d99398b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix infinite loop in __tipc_nl_compat_dumpit\n\ncmd->dumpit callback can return a negative errno, causing an infinite\nloop due to the while(len) condition. As the loop never terminates,\ngenl_mutex is never released, and other tasks waiting on it starve in D\nstate.\n\nCheck dumpit's return value, propagate it and jump to err_out on error.","cvss":[],"epss":[{"cve":"CVE-2026-68313","epss":0.0021,"percentile":0.11272,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68313","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68315","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68315","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: validate stream count in sctp_process_strreset_inreq()  When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.  The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG:    net/core/skbuff.c:207         skb_panic   net/core/skbuff.c:2625        skb_put   net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk   net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req   net/sctp/stream.c:655         sctp_process_strreset_inreq  The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer.  Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an IN request that would require an oversized OUT request from the peer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68315","epss":0.00518,"percentile":0.42393,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.38849999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-68315","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68315","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/00ae679cb21a035491fdad8d58dc6d79cc68b675","https://git.kernel.org/stable/c/18ae07691d43183d270de8be9dc8e027906015d9","https://git.kernel.org/stable/c/1a10fe1aa9c01f41b389a31906a77d538637c9d9","https://git.kernel.org/stable/c/60c47dea5d320d2fc706e9aad1db38a04df0a056","https://git.kernel.org/stable/c/61327d8e7cfb0259d527be17202630f556213249","https://git.kernel.org/stable/c/6f0e39d180cd7cced647381b6fa14fd83d261047","https://git.kernel.org/stable/c/7cf7439948e3bf639119119922c88ec190874ca3","https://git.kernel.org/stable/c/b255d8cd6cc68045ae9eecbac3b3c14e1f176c9b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate stream count in sctp_process_strreset_inreq()\n\nWhen processing a RESET_IN_REQUEST from a peer,\nsctp_process_strreset_inreq() derives the stream count from the\nparameter length but does not check whether the resulting\nRESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.\n\nThe OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes\nlarger than the IN request header (sctp_strreset_inreq, 8 bytes).\nGenerally, the IP payload is bounded to 65535 bytes, so the stream\nlist cannot be large enough to trigger the overflow. However, on\ninterfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a\nstream list that fits within the incoming IN parameter can cause a\n__u16 overflow in sctp_make_strreset_req() when computing the OUT\nrequest size, leading to an undersized skb allocation and a kernel\nBUG:\n\n  net/core/skbuff.c:207         skb_panic\n  net/core/skbuff.c:2625        skb_put\n  net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk\n  net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req\n  net/sctp/stream.c:655         sctp_process_strreset_inreq\n\nThe local setsockopt path validates the generated reset request size.\nHowever, for an incoming-only reset, it accounts for the smaller IN\nrequest even though the peer must generate an OUT request with the same\nstream list. Such a request cannot be completed successfully by the\npeer.\n\nReject peer IN requests whose corresponding OUT request would exceed\nSCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an\nIN request that would require an oversized OUT request from the peer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68315","epss":0.00518,"percentile":0.42393,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68315","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68320","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68320","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid  sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the capacity limit for ep->auth_chunk_list, allowing it to hold up to 20 chunk entries (param_hdr.length up to 24). However, the copy destination asoc->c.auth_chunks in struct sctp_cookie is only SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctp_association_init() memcpy overflows the destination by up to 4 bytes.  Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching the destination capacity.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68320","epss":0.00127,"percentile":0.02705,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09398000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68320","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68320","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/11092d79eb2b7c0068382f72fc2416d1786bb2e0","https://git.kernel.org/stable/c/3d22a7da2e264f407c729f33a0a346ff76108bc6","https://git.kernel.org/stable/c/54bb4c03fa17cdcb157c26c33e60a78cf32960f5","https://git.kernel.org/stable/c/5a365f1e423444c5da7eb689a8661633dad43e48","https://git.kernel.org/stable/c/6837c1c19a259518974cbc5a52017646e3906564","https://git.kernel.org/stable/c/886e28e14ab655012779016d251fef53d103aa12","https://git.kernel.org/stable/c/b6ea3dda09eb4d5caf7bbc00f857688cf9e98255","https://git.kernel.org/stable/c/ff04b26794a16a8a879eb4fd2c02c2d6b03850e9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid\n\nsctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the\ncapacity limit for ep->auth_chunk_list, allowing it to hold up to\n20 chunk entries (param_hdr.length up to 24). However, the copy\ndestination asoc->c.auth_chunks in struct sctp_cookie is only\nSCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16\nchunks are added, sctp_association_init() memcpy overflows the\ndestination by up to 4 bytes.\n\nFix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching\nthe destination capacity.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68320","epss":0.00127,"percentile":0.02705,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68320","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68322","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68322","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled  When booting with the 'ipv6.disable=1' parameter, inet6_addr_lst is never initialized because inet6_init() exits before addrconf_init() is called to initialize it. An attempt to bind an RDS socket to an ipv6 address results in a crash in __ipv6_chk_addr_and_flags()  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] RIP: 0010:__ipv6_chk_addr_and_flags+0x1df/0x7e0 Call Trace:  <TASK>  ipv6_chk_addr+0x3b/0x50  rds_tcp_laddr_check+0x155/0x3b0 [rds_tcp]  rds_trans_get_preferred+0x15d/0x2d0 [rds]  ? trace_hardirqs_on+0x2d/0x110  rds_bind+0x1433/0x1d60 [rds]  ? rds_remove_bound+0xd50/0xd50 [rds]  ? aa_af_perm+0x250/0x250  ? __might_fault+0xde/0x190  ? __sys_bind+0x1dc/0x210  __sys_bind+0x1dc/0x210  ? __ia32_sys_socketpair+0x100/0x100  ? restore_fpregs_from_fpstate+0x53/0x100  __x64_sys_bind+0x73/0xb0  ? syscall_enter_from_user_mode+0x1c/0x50  do_syscall_64+0x34/0x80  entry_SYSCALL_64_after_hwframe+0x6e/0xd8 RIP: 0033:0x7f47f8269ea9  </TASK>  The following code reproduces the issue:  struct sockaddr_in6 addr; s = socket(PF_RDS, SOCK_SEQPACKET, 0);  memset(&addr, 0, sizeof(addr)); inet_pton(AF_INET6, ADDRESS, &addr.sin6_addr); addr.sin6_family = AF_INET6; addr.sin6_port = htons(PORT);  bind(s, &addr, sizeof(addr));  Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with Syzkaller.","cvss":[],"epss":[{"cve":"CVE-2026-68322","epss":0.00211,"percentile":0.11306,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-68322","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68322","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/00d5707217b5972554898ff734ae7b71bce704e6","https://git.kernel.org/stable/c/438dec9b0a06bd1f8db8c58539c655e735e17367","https://git.kernel.org/stable/c/7809344be3f0c1bbfdfdde1cefafeec14bf52d51","https://git.kernel.org/stable/c/8e48d7ab1e01936a172ff31531904b003895fd8c","https://git.kernel.org/stable/c/9c805e592a29be9e4e61ff1bd567da04aa8fd6f9","https://git.kernel.org/stable/c/a8302e758050e6a922765aee8d220a4fd350f52d","https://git.kernel.org/stable/c/b61c9eb5931bb7389bc104faacd8c17d910da65d","https://git.kernel.org/stable/c/f6787fdffcae5490c779f0f3f33b11597525d1ae"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled\n\nWhen booting with the 'ipv6.disable=1' parameter, inet6_addr_lst\nis never initialized because inet6_init() exits before addrconf_init()\nis called to initialize it. An attempt to bind an RDS socket to\nan ipv6 address results in a crash in __ipv6_chk_addr_and_flags()\n\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nRIP: 0010:__ipv6_chk_addr_and_flags+0x1df/0x7e0\nCall Trace:\n <TASK>\n ipv6_chk_addr+0x3b/0x50\n rds_tcp_laddr_check+0x155/0x3b0 [rds_tcp]\n rds_trans_get_preferred+0x15d/0x2d0 [rds]\n ? trace_hardirqs_on+0x2d/0x110\n rds_bind+0x1433/0x1d60 [rds]\n ? rds_remove_bound+0xd50/0xd50 [rds]\n ? aa_af_perm+0x250/0x250\n ? __might_fault+0xde/0x190\n ? __sys_bind+0x1dc/0x210\n __sys_bind+0x1dc/0x210\n ? __ia32_sys_socketpair+0x100/0x100\n ? restore_fpregs_from_fpstate+0x53/0x100\n __x64_sys_bind+0x73/0xb0\n ? syscall_enter_from_user_mode+0x1c/0x50\n do_syscall_64+0x34/0x80\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\nRIP: 0033:0x7f47f8269ea9\n </TASK>\n\nThe following code reproduces the issue:\n\nstruct sockaddr_in6 addr;\ns = socket(PF_RDS, SOCK_SEQPACKET, 0);\n\nmemset(&addr, 0, sizeof(addr));\ninet_pton(AF_INET6, ADDRESS, &addr.sin6_addr);\naddr.sin6_family = AF_INET6;\naddr.sin6_port = htons(PORT);\n\nbind(s, &addr, sizeof(addr));\n\nFound by InfoTeCS on behalf of Linux Verification Center\n(linuxtesting.org) with Syzkaller.","cvss":[],"epss":[{"cve":"CVE-2026-68322","epss":0.00211,"percentile":0.11306,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68322","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68323","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68323","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: serialize udp bearer replicast list updates  tipc_udp_rcast_add() and cleanup_bearer() both update ub->rcast.list with list_add_rcu() / list_del_rcu(), but nothing serializes them. The add runs from the encap receive softirq (via tipc_udp_rcast_disc()) without rtnl_lock(), so it can race the cleanup delete and corrupt the list:    list_del corruption. prev->next should be ffff8880298d7ab8,     but was ffff88802449ad38. (prev=ffff888027e3ec98)   kernel BUG at lib/list_debug.c:62!   RIP: __list_del_entry_valid_or_report+0x17a/0x200   Workqueue: events cleanup_bearer   Call Trace:    cleanup_bearer (net/tipc/udp_media.c:811)    process_one_work (kernel/workqueue.c:3302)    worker_thread (kernel/workqueue.c:3466)  The bearer can be enabled from an unprivileged user namespace, as the TIPCv2 generic-netlink ops carry no GENL_ADMIN_PERM.  Add a spinlock to struct udp_bearer and take it around the list_add_rcu() in tipc_udp_rcast_add() and the list_del_rcu() loop in cleanup_bearer() so the two writers can no longer corrupt the list.  Reject a duplicate peer under the same lock before allocating, and remove tipc_udp_is_known_peer(). The old lockless pre-check in tipc_udp_rcast_disc() was racy: two softirqs discovering the same peer could both find it absent and add it twice.  cleanup_bearer() runs from a workqueue after tipc_udp_disable() clears the bearer's up bit, so an encap softirq can still reach tipc_udp_rcast_add() and add a peer after cleanup_bearer() has already emptied the list, leaking that entry when the bearer is freed. Mark the bearer disabled under rcast_lock once the list is emptied and refuse further additions.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68323","epss":0.0012,"percentile":0.02088,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-68323","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68323","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/350e592ff4e30e48ffb55e142d11a73e63f4869c","https://git.kernel.org/stable/c/d70c81001df9320d3445e664428a1d408b5ba896"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: serialize udp bearer replicast list updates\n\ntipc_udp_rcast_add() and cleanup_bearer() both update ub->rcast.list with\nlist_add_rcu() / list_del_rcu(), but nothing serializes them. The add runs\nfrom the encap receive softirq (via tipc_udp_rcast_disc()) without\nrtnl_lock(), so it can race the cleanup delete and corrupt the list:\n\n  list_del corruption. prev->next should be ffff8880298d7ab8,\n    but was ffff88802449ad38. (prev=ffff888027e3ec98)\n  kernel BUG at lib/list_debug.c:62!\n  RIP: __list_del_entry_valid_or_report+0x17a/0x200\n  Workqueue: events cleanup_bearer\n  Call Trace:\n   cleanup_bearer (net/tipc/udp_media.c:811)\n   process_one_work (kernel/workqueue.c:3302)\n   worker_thread (kernel/workqueue.c:3466)\n\nThe bearer can be enabled from an unprivileged user namespace, as the\nTIPCv2 generic-netlink ops carry no GENL_ADMIN_PERM.\n\nAdd a spinlock to struct udp_bearer and take it around the list_add_rcu()\nin tipc_udp_rcast_add() and the list_del_rcu() loop in cleanup_bearer() so\nthe two writers can no longer corrupt the list.\n\nReject a duplicate peer under the same lock before allocating, and remove\ntipc_udp_is_known_peer(). The old lockless pre-check in\ntipc_udp_rcast_disc() was racy: two softirqs discovering the same peer\ncould both find it absent and add it twice.\n\ncleanup_bearer() runs from a workqueue after tipc_udp_disable() clears the\nbearer's up bit, so an encap softirq can still reach tipc_udp_rcast_add()\nand add a peer after cleanup_bearer() has already emptied the list, leaking\nthat entry when the bearer is freed. Mark the bearer disabled under\nrcast_lock once the list is emptied and refuse further additions.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68323","epss":0.0012,"percentile":0.02088,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68323","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68324","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68324","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()  dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from &lstat[type].  When type > 0, this writes beyond the end of the allocated array, corrupting adjacent memory.  Fix by using sizeof(*lstat) to clear only the target entry.","cvss":[],"epss":[{"cve":"CVE-2026-68324","epss":0.00173,"percentile":0.06832,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-68324","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68324","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0e28ca1c3204b51068579defc904a0dfba5e5c57","https://git.kernel.org/stable/c/104d89cf5b01cb66ff975d91ed42f61b3904df53","https://git.kernel.org/stable/c/3078d82e7fe9048a2b90a992e71af7cd7ef881fa","https://git.kernel.org/stable/c/754f8efe45f87e3a9c6871b645b2f9d46d1b407b","https://git.kernel.org/stable/c/80f3605991461679c298ea2045c350ee3cf36de3","https://git.kernel.org/stable/c/866a35735e56b9dc81cbc33899255134adf6d8b3","https://git.kernel.org/stable/c/d06fea9b85f038690f55e72fe0c45e113715a85a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/intel: Fix out-of-bounds memset in dmar_latency_disable()\n\ndmar_latency_disable() intends to zero out only the single\nlatency_statistic entry for the given type, but the memset size was\ncomputed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire\narray starting from &lstat[type].\n\nWhen type > 0, this writes beyond the end of the allocated array,\ncorrupting adjacent memory.\n\nFix by using sizeof(*lstat) to clear only the target entry.","cvss":[],"epss":[{"cve":"CVE-2026-68324","epss":0.00173,"percentile":0.06832,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68324","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68325","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68325","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/amd: Bound the early ACPI HID map  The ivrs_acpihid command-line parser appends entries to a fixed four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET parsers, it does not reject a fifth entry before incrementing the map size.  Check the capacity at the common found label before parsing the HID and UID or writing the entry.","cvss":[],"epss":[{"cve":"CVE-2026-68325","epss":0.00184,"percentile":0.08121,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68325","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68325","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/030a8e84f8f1b6e96f469c84a13a225c3699910b","https://git.kernel.org/stable/c/1e31d2394e0db69541b1591d46c5ad6431c81db3","https://git.kernel.org/stable/c/9ae6b1b972ce01d3316c8a5f7f58c8b3668cc6bb","https://git.kernel.org/stable/c/abe5d7962f09adada9c4fb25b816dddd3f97c55d","https://git.kernel.org/stable/c/afe7ea0520c49586703f210865ace2d70b017e48","https://git.kernel.org/stable/c/e5e0098f8cd82f8b3c8687a8f686309565d51745","https://git.kernel.org/stable/c/e5ebe8544df1a1c3611739a8622156094fe470df","https://git.kernel.org/stable/c/fb80117fddb5b477218dc99bb53911b72c3847f8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Bound the early ACPI HID map\n\nThe ivrs_acpihid command-line parser appends entries to a fixed\nfour-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET\nparsers, it does not reject a fifth entry before incrementing the map size.\n\nCheck the capacity at the common found label before parsing the HID and\nUID or writing the entry.","cvss":[],"epss":[{"cve":"CVE-2026-68325","epss":0.00184,"percentile":0.08121,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68325","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68326","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68326","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mwifiex: bound uAP association event IEs to the event buffer  mwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the (re)association request IEs that the firmware copies into the event:  \tsinfo->assoc_req_ies = &event->data[len]; \tlen = (u8 *)sinfo->assoc_req_ies - (u8 *)&event->frame_control; \tsinfo->assoc_req_ies_len = le16_to_cpu(event->len) - (u16)len;  event->len is supplied by the device firmware and is never validated, and the subtraction is unchecked.  assoc_req_ies points into adapter->event_body[MAX_EVENT_SIZE], a fixed-size array embedded in the kmalloc()'d struct mwifiex_adapter.  On the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with cfg80211_find_ie(), whose for_each_element() loop dereferences each element header.  A firmware-reported event->len larger than the bytes actually received makes assoc_req_ies_len describe IEs that extend past event_body, so the walk reads out of the adapter slab object, a slab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie). An event->len smaller than the header instead makes the int subtraction negative, which wraps to a huge size_t when stored in assoc_req_ies_len. The same length is handed to cfg80211_new_sta(), so a more modest over-claim can also copy stale event_body bytes into the NL80211_CMD_NEW_STATION notification.  A malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver such an event while the interface is in AP/uAP mode.  Validate event->len before use: reject a length that underflows the header or that would place the IEs outside the event_body[] buffer the event was copied into.  event->len here is struct mwifiex_assoc_event.len, a payload field internal to this event, not the transport frame length, so it is validated in this handler rather than at the generic MWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the transport frame length.  The bound is against event_body[MAX_EVENT_SIZE] rather than the actually-received length because the transports store the event differently (USB and SDIO leave the 4-byte event header in event_skb, PCIe strips it via skb_pull), whereas event_body is the single fixed buffer all of them copy the event into.  This is the event-path analogue of the receive-path bounds checks added in commit 119585281617 (\"wifi: mwifiex: Fix OOB and integer underflow when rx packets\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68326","epss":0.00262,"percentile":0.17993,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.21353000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-68326","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68326","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1ae00b6d9a6c82eb3de151d9b04ed59e06cc100f","https://git.kernel.org/stable/c/a3f47d7c75ddad1a14621a309286f9fae3cba191","https://git.kernel.org/stable/c/a616616b938f7922a93e79bef16b4643c57c0922","https://git.kernel.org/stable/c/ad26c75ae25749313248f06510ebe43b5bf4adcc","https://git.kernel.org/stable/c/b6766d7ea43edf5de9d5a572bc58b631d09efe4b","https://git.kernel.org/stable/c/d21464d93f8ba464dc3d7b4b31c6e0adcd9f659c","https://git.kernel.org/stable/c/e7e93d3e8c240bdb70c41e79d169d74dfb442843","https://git.kernel.org/stable/c/f0858bfc7d3cab411a447b88e3ef970e575032c9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: bound uAP association event IEs to the event buffer\n\nmwifiex_process_uap_event() handles EVENT_UAP_STA_ASSOC by exposing the\n(re)association request IEs that the firmware copies into the event:\n\n\tsinfo->assoc_req_ies = &event->data[len];\n\tlen = (u8 *)sinfo->assoc_req_ies - (u8 *)&event->frame_control;\n\tsinfo->assoc_req_ies_len = le16_to_cpu(event->len) - (u16)len;\n\nevent->len is supplied by the device firmware and is never validated,\nand the subtraction is unchecked.  assoc_req_ies points into\nadapter->event_body[MAX_EVENT_SIZE], a fixed-size array embedded in the\nkmalloc()'d struct mwifiex_adapter.\n\nOn the ap_11n_enabled path mwifiex_set_sta_ht_cap() walks these IEs with\ncfg80211_find_ie(), whose for_each_element() loop dereferences each\nelement header.  A firmware-reported event->len larger than the bytes\nactually received makes assoc_req_ies_len describe IEs that extend past\nevent_body, so the walk reads out of the adapter slab object, a\nslab-out-of-bounds read (KASAN: slab-out-of-bounds in cfg80211_find_ie).\nAn event->len smaller than the header instead makes the int subtraction\nnegative, which wraps to a huge size_t when stored in assoc_req_ies_len.\nThe same length is handed to cfg80211_new_sta(), so a more modest\nover-claim can also copy stale event_body bytes into the\nNL80211_CMD_NEW_STATION notification.\n\nA malicious or malfunctioning mwifiex device (USB/SDIO/PCIe) can deliver\nsuch an event while the interface is in AP/uAP mode.\n\nValidate event->len before use: reject a length that underflows the\nheader or that would place the IEs outside the event_body[] buffer the\nevent was copied into.  event->len here is struct mwifiex_assoc_event.len,\na payload field internal to this event, not the transport frame length,\nso it is validated in this handler rather than at the generic\nMWIFIEX_TYPE_EVENT receive path, which only sees the event cause and the\ntransport frame length.  The bound is against event_body[MAX_EVENT_SIZE]\nrather than the actually-received length because the transports store the\nevent differently (USB and SDIO leave the 4-byte event header in\nevent_skb, PCIe strips it via skb_pull), whereas event_body is the single\nfixed buffer all of them copy the event into.  This is the event-path\nanalogue of the receive-path bounds checks added in commit 119585281617\n(\"wifi: mwifiex: Fix OOB and integer underflow when rx packets\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68326","epss":0.00262,"percentile":0.17993,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68326","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68327","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68327","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wan: wanxl: Only reset hardware after BAR mapping  wanxl_pci_init_one() stores the freshly allocated card in driver data before the PLX BAR is mapped.  Several early probe failures then unwind through wanxl_pci_remove_one(), including failure to allocate the coherent status area or to restore the DMA mask.  wanxl_pci_remove_one() unconditionally calls wanxl_reset(), and wanxl_reset() dereferences card->plx.  On those early failures card->plx is still NULL, so the error path can dereference a NULL MMIO pointer.  Only issue the hardware reset once the BAR mapping exists.  The remaining cleanup in wanxl_pci_remove_one() already checks whether later resources were allocated.  This issue was found by a static analysis checker and confirmed by manual source review.","cvss":[],"epss":[{"cve":"CVE-2026-68327","epss":0.00177,"percentile":0.07334,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68327","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68327","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2fe22d58b3797d741570f9873b26653fd511576c","https://git.kernel.org/stable/c/3d9617d856ebddcdddbab0ce877c397420f59f55","https://git.kernel.org/stable/c/59cbe6cfa0fa23c192351cc284e30707309f6741","https://git.kernel.org/stable/c/897e289db1e4d00ca6419cfe733c646492147270","https://git.kernel.org/stable/c/91957b89da995607cb654b1f9a3c126ddbaee10f","https://git.kernel.org/stable/c/b9e2ff70e96acf83693b27987e0390bad9f83efa","https://git.kernel.org/stable/c/ef394eeb9d5ec6db8d979eec6d27f56c2ebc6523","https://git.kernel.org/stable/c/f4834132773f15ffb255127499c8443947fa7d0f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwan: wanxl: Only reset hardware after BAR mapping\n\nwanxl_pci_init_one() stores the freshly allocated card in driver data\nbefore the PLX BAR is mapped.  Several early probe failures then unwind\nthrough wanxl_pci_remove_one(), including failure to allocate the coherent\nstatus area or to restore the DMA mask.\n\nwanxl_pci_remove_one() unconditionally calls wanxl_reset(), and\nwanxl_reset() dereferences card->plx.  On those early failures card->plx\nis still NULL, so the error path can dereference a NULL MMIO pointer.\n\nOnly issue the hardware reset once the BAR mapping exists.  The remaining\ncleanup in wanxl_pci_remove_one() already checks whether later resources\nwere allocated.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review.","cvss":[],"epss":[{"cve":"CVE-2026-68327","epss":0.00177,"percentile":0.07334,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68327","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68328","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68328","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfp: Check resource mutex allocation  nfp_cpp_resource_find() allocates a CPP mutex handle for the matching resource-table entry and then reports success.  nfp_resource_try_acquire() immediately passes that handle to nfp_cpp_mutex_trylock().  However, nfp_cpp_mutex_alloc() returns NULL on failure.  If that happens for a matching table entry, the resource lookup still returns success and the following trylock dereferences a NULL mutex pointer while opening the resource.  nfp_resource_acquire() already treats failure to allocate the table mutex as -ENOMEM.  Do the same for the resource mutex and fail the lookup before publishing the rest of the resource handle.  This issue was found by a static analysis checker and confirmed by manual source review.","cvss":[],"epss":[{"cve":"CVE-2026-68328","epss":0.00177,"percentile":0.07334,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68328","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68328","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0dbd85a8cc35c14bd26e686fa5fae8c64a7958ae","https://git.kernel.org/stable/c/18737a48acc87e4cbe41d6fea9a3f44eae490e24","https://git.kernel.org/stable/c/3b1d4fc3b73ea6faf008a0996ce6190c6e43efc3","https://git.kernel.org/stable/c/423523f96a681428ce6e214eaf47f0d8242319de","https://git.kernel.org/stable/c/6dbd428119cb1fd1b73cf6968c711f4ea964dc8b","https://git.kernel.org/stable/c/a61b4db34a753bdf5c9e77a7f3d3dddd41dcfacc","https://git.kernel.org/stable/c/a7dc30b6828c3a30252892827b12b676749f250f","https://git.kernel.org/stable/c/cfa119aa781c4044dab5b4c1e5864600f53a26bc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfp: Check resource mutex allocation\n\nnfp_cpp_resource_find() allocates a CPP mutex handle for the matching\nresource-table entry and then reports success.  nfp_resource_try_acquire()\nimmediately passes that handle to nfp_cpp_mutex_trylock().\n\nHowever, nfp_cpp_mutex_alloc() returns NULL on failure.  If that happens\nfor a matching table entry, the resource lookup still returns success and\nthe following trylock dereferences a NULL mutex pointer while opening the\nresource.\n\nnfp_resource_acquire() already treats failure to allocate the table mutex\nas -ENOMEM.  Do the same for the resource mutex and fail the lookup before\npublishing the rest of the resource handle.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review.","cvss":[],"epss":[{"cve":"CVE-2026-68328","epss":0.00177,"percentile":0.07334,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68328","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68329","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68329","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()  need_sync is a per-IOMMU flag shared by all domains and devices behind that IOMMU. It is set whenever a command is queued with sync == true and cleared when a completion-wait (CWAIT) command is queued. However, a cleared need_sync only means that a covering CWAIT has been queued, not that all previously queued commands have actually completed in hardware.  iommu_completion_wait() read need_sync locklessly and returned early when it was false. This breaks the \"block until all previously queued commands have completed\" contract in a multi-CPU scenario:    CPU2: queue inv-B                  => need_sync = true   CPU1: queue CWAIT(N); need_sync = false; then wait_on_sem(N)   CPU2: read need_sync == false      => return 0 (no wait!)  CPU2 returns without waiting for any sequence number even though its inv-B may not have completed yet (CWAIT(N), queued after inv-B, has not been signaled). CPU2 then proceeds to, for example, free page-table pages while the IOMMU can still walk stale translations, opening a use-after-free window. This is a logical race in the meaning of the flag, not a memory-visibility issue, so barriers alone do not help.  Fix it without losing the optimization of avoiding redundant CWAIT commands: take iommu->lock before testing need_sync, and when it is false do not return early but wait for the last allocated sequence number (cmd_sem_val). Since need_sync == false implies no sync command was queued after the last CWAIT, that CWAIT is FIFO-ordered after every not-yet-completed command, so waiting for its sequence number guarantees all prior commands (possibly queued by another CPU) have completed. The common path with pending work is unchanged and no extra hardware command is issued.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68329","epss":0.00159,"percentile":0.05361,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.129585},"relatedVulnerabilities":[{"id":"CVE-2026-68329","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68329","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/02f8cefa2ad95ea3754f0cfd6fbae7f866202ccb","https://git.kernel.org/stable/c/1e75a8255f11c81fb07e81e5029cfd75804350a0","https://git.kernel.org/stable/c/93494bd446396c257fb589f59894577e96e406e2","https://git.kernel.org/stable/c/ab7faf5a172ebfdc423ebb3eea4d472740de82f9","https://git.kernel.org/stable/c/d053eb7e09e10cbdca3fca8b35c1017d438091b2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Wait for completion instead of returning early in iommu_completion_wait()\n\nneed_sync is a per-IOMMU flag shared by all domains and devices behind\nthat IOMMU. It is set whenever a command is queued with sync == true and\ncleared when a completion-wait (CWAIT) command is queued. However, a\ncleared need_sync only means that a covering CWAIT has been queued, not\nthat all previously queued commands have actually completed in hardware.\n\niommu_completion_wait() read need_sync locklessly and returned early\nwhen it was false. This breaks the \"block until all previously queued\ncommands have completed\" contract in a multi-CPU scenario:\n\n  CPU2: queue inv-B                  => need_sync = true\n  CPU1: queue CWAIT(N); need_sync = false; then wait_on_sem(N)\n  CPU2: read need_sync == false      => return 0 (no wait!)\n\nCPU2 returns without waiting for any sequence number even though its\ninv-B may not have completed yet (CWAIT(N), queued after inv-B, has not\nbeen signaled). CPU2 then proceeds to, for example, free page-table\npages while the IOMMU can still walk stale translations, opening a\nuse-after-free window. This is a logical race in the meaning of the\nflag, not a memory-visibility issue, so barriers alone do not help.\n\nFix it without losing the optimization of avoiding redundant CWAIT\ncommands: take iommu->lock before testing need_sync, and when it is\nfalse do not return early but wait for the last allocated sequence\nnumber (cmd_sem_val). Since need_sync == false implies no sync command\nwas queued after the last CWAIT, that CWAIT is FIFO-ordered after every\nnot-yet-completed command, so waiting for its sequence number guarantees\nall prior commands (possibly queued by another CPU) have completed. The\ncommon path with pending work is unchanged and no extra hardware command\nis issued.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68329","epss":0.00159,"percentile":0.05361,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68329","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68331","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68331","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dpaa2-eth: put MAC endpoint device on disconnect  fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The Ethernet connect path stores that device in mac->mc_dev and keeps it for the lifetime of the connected MAC object.  However, the disconnect path only disconnects and closes the MAC before freeing the dpaa2_mac object. It does not drop the endpoint device reference stored in mac->mc_dev, so every successful connect leaks that device reference when the MAC is later disconnected.  Drop the endpoint device reference after closing the MAC and before freeing the dpaa2_mac object.","cvss":[],"epss":[{"cve":"CVE-2026-68331","epss":0.00173,"percentile":0.06832,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-68331","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68331","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1974127776da46a000c61f36d4946799ea6d4f51","https://git.kernel.org/stable/c/6b6ffdb9ca4547a3c4c274aa3e25b6c68dbc62e1","https://git.kernel.org/stable/c/915012e923316b8b5d5bf8fc771617b47bd7572d","https://git.kernel.org/stable/c/a3cecf169cc652b558d08661bb6ce55e4c933ec0","https://git.kernel.org/stable/c/b4b201cc93ff70150853aba03e14d314d1980ca0","https://git.kernel.org/stable/c/e23e4a3b9dfd893469c731318d409cdf04fb1ddf","https://git.kernel.org/stable/c/f112df0744e2d77baa68eeebb860021bbaaa022a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-eth: put MAC endpoint device on disconnect\n\nfsl_mc_get_endpoint() returns the MAC endpoint device with a reference\ntaken through device_find_child(). The Ethernet connect path stores that\ndevice in mac->mc_dev and keeps it for the lifetime of the connected MAC\nobject.\n\nHowever, the disconnect path only disconnects and closes the MAC before\nfreeing the dpaa2_mac object. It does not drop the endpoint device\nreference stored in mac->mc_dev, so every successful connect leaks that\ndevice reference when the MAC is later disconnected.\n\nDrop the endpoint device reference after closing the MAC and before\nfreeing the dpaa2_mac object.","cvss":[],"epss":[{"cve":"CVE-2026-68331","epss":0.00173,"percentile":0.06832,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68331","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68333","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68333","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dpaa2-switch: put MAC endpoint device on disconnect  fsl_mc_get_endpoint() returns the MAC endpoint device with a reference taken through device_find_child(). The switch port connect path stores that device in mac->mc_dev and keeps it for the lifetime of the connected MAC object.  However, the disconnect path only closes the MAC and frees the dpaa2_mac object. It does not drop the endpoint device reference stored in mac->mc_dev, so every successful connect leaks that device reference when the MAC is later disconnected.  Drop the endpoint device reference before freeing the dpaa2_mac object.","cvss":[],"epss":[{"cve":"CVE-2026-68333","epss":0.0018,"percentile":0.07726,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09},"relatedVulnerabilities":[{"id":"CVE-2026-68333","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68333","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0e9a6811eb6198ab17538cd01fa155d133b238ed","https://git.kernel.org/stable/c/196f7301537814bef0f5915f87cd73d6d1235c19","https://git.kernel.org/stable/c/1f4ca61b7a93de3dfa5161bcd38ecb99bb091c38","https://git.kernel.org/stable/c/26ac2d3602347f0377fbcd5214bc28a9d735ae68","https://git.kernel.org/stable/c/4c1eabbef7a1707635652e956e39db1269c3af2b","https://git.kernel.org/stable/c/680eecc850d36a280df9780496bc603fec17b2d6","https://git.kernel.org/stable/c/c27694ff6748e08fcd2fdba89018439d75b8198f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndpaa2-switch: put MAC endpoint device on disconnect\n\nfsl_mc_get_endpoint() returns the MAC endpoint device with a reference\ntaken through device_find_child(). The switch port connect path stores\nthat device in mac->mc_dev and keeps it for the lifetime of the connected\nMAC object.\n\nHowever, the disconnect path only closes the MAC and frees the dpaa2_mac\nobject. It does not drop the endpoint device reference stored in\nmac->mc_dev, so every successful connect leaks that device reference when\nthe MAC is later disconnected.\n\nDrop the endpoint device reference before freeing the dpaa2_mac object.","cvss":[],"epss":[{"cve":"CVE-2026-68333","epss":0.0018,"percentile":0.07726,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68333","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68335","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68335","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rds: drop incoming messages that cross network namespace boundaries  rds_find_bound() looks up the destination socket using a global rhashtable keyed solely on (addr, port, scope_id).  Network namespaces are not part of the key, so a sender in netns A can deliver an incoming message (inc) to a socket that lives in a different netns B.  When this happens, inc->i_conn points to an rds_connection whose c_net is netns A, but the receiving rs lives in netns B.  Once the child process that created netns A exits, cleanup_net() calls rds_loop_exit_net() -> rds_loop_kill_conns() -> rds_conn_destroy(), freeing that connection.  If the survivor socket in netns B still holds the inc, any subsequent dereference of inc->i_conn is a use-after-free.  There are two dangerous sites in rds_clear_recv_queue():   1. inc->i_conn->c_lcong (offset 88 of freed rds_connection, size 200)      read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.   2. inc->i_conn->c_trans->inc_free(inc) (function pointer at offset 80)      called via rds_inc_put() when the inc refcount reaches zero -- same      race window, potential call-through-freed-object primitive.  The bug is reachable from unprivileged user namespaces (CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.  Fix this by rejecting the delivery in rds_recv_incoming() when the socket returned by rds_find_bound() belongs to a different network namespace than the connection that carried the message.  Use the existing rds_conn_net() / sock_net() helpers and net_eq() for the comparison.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68335","epss":0.00135,"percentile":0.03287,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.103275},"relatedVulnerabilities":[{"id":"CVE-2026-68335","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68335","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/03c574112e5d066df0ddce36d7438e850bcf3050","https://git.kernel.org/stable/c/0f8690e3869109cd5803ccb400889d20a0b54e0e","https://git.kernel.org/stable/c/1e2e2d9806944fe485824d617c8b7c78116c22db","https://git.kernel.org/stable/c/5521ae71e32a8069ed4ca6e792179dc57bc43ab2","https://git.kernel.org/stable/c/742ff6f02545212e991cd8b45011e40d2c2ef25a","https://git.kernel.org/stable/c/9591042533140dfe6608d9344806d567dcd39d02","https://git.kernel.org/stable/c/abff41fd928328bbf3dda1140beb2e61fa424ccd","https://git.kernel.org/stable/c/cfb3ce07b705e486e022a2f2b1242b48f13981ff"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrds: drop incoming messages that cross network namespace boundaries\n\nrds_find_bound() looks up the destination socket using a global\nrhashtable keyed solely on (addr, port, scope_id).  Network namespaces\nare not part of the key, so a sender in netns A can deliver an incoming\nmessage (inc) to a socket that lives in a different netns B.\n\nWhen this happens, inc->i_conn points to an rds_connection whose c_net\nis netns A, but the receiving rs lives in netns B.  Once the child\nprocess that created netns A exits, cleanup_net() calls\nrds_loop_exit_net() -> rds_loop_kill_conns() -> rds_conn_destroy(),\nfreeing that connection.  If the survivor socket in netns B still holds\nthe inc, any subsequent dereference of inc->i_conn is a use-after-free.\n\nThere are two dangerous sites in rds_clear_recv_queue():\n  1. inc->i_conn->c_lcong (offset 88 of freed rds_connection, size 200)\n     read via rds_recv_rcvbuf_delta() -- confirmed by KASAN.\n  2. inc->i_conn->c_trans->inc_free(inc) (function pointer at offset 80)\n     called via rds_inc_put() when the inc refcount reaches zero -- same\n     race window, potential call-through-freed-object primitive.\n\nThe bug is reachable from unprivileged user namespaces\n(CLONE_NEWUSER + CLONE_NEWNET), available since Linux 3.8.\n\nFix this by rejecting the delivery in rds_recv_incoming() when the\nsocket returned by rds_find_bound() belongs to a different network\nnamespace than the connection that carried the message.  Use the\nexisting rds_conn_net() / sock_net() helpers and net_eq() for the\ncomparison.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68335","epss":0.00135,"percentile":0.03287,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68335","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68336","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68336","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bonding: fix devconf_all NULL dereference when IPv6 is disabled  When booting with the 'ipv6.disable=1' parameter, the devconf_all is never initialized because inet6_init() exits before addrconf_init() is called which initializes it. bond_send_validate(), however, will still call bond_ns_send_all() even ipv6 is indeed disabled. It will lead to NULL derefence of net->ipv6.devconf_all in ip6_pol_route().   BUG: kernel NULL pointer dereference, address: 000000000000000c  [...]  Workqueue: bond0 bond_arp_monitor [bonding]  RIP: 0010:ip6_pol_route+0x69/0x480  [...]  Call Trace:   <TASK>   ? srso_return_thunk+0x5/0x5f   ? __pfx_ip6_pol_route_output+0x10/0x10   fib6_rule_lookup+0xfe/0x260   ? wakeup_preempt+0x8a/0x90   ? srso_return_thunk+0x5/0x5f   ? srso_return_thunk+0x5/0x5f   ? sched_balance_rq+0x369/0x810   ip6_route_output_flags+0xd7/0x170   bond_ns_send_all+0xde/0x280 [bonding]   bond_ab_arp_probe+0x296/0x320 [bonding]   ? srso_return_thunk+0x5/0x5f   bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]   process_one_work+0x196/0x370   worker_thread+0x1af/0x320   ? srso_return_thunk+0x5/0x5f   ? __pfx_worker_thread+0x10/0x10   kthread+0xe3/0x120   ? __pfx_kthread+0x10/0x10   ret_from_fork+0x199/0x260   ? __pfx_kthread+0x10/0x10   ret_from_fork_asm+0x1a/0x30   </TASK>  Fix this by adding ipv6_mod_enabled() condition check in the caller.","cvss":[],"epss":[{"cve":"CVE-2026-68336","epss":0.0018,"percentile":0.07698,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09},"relatedVulnerabilities":[{"id":"CVE-2026-68336","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68336","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1c975de3343cdef506f2eecc833cc1f14b0401c4","https://git.kernel.org/stable/c/2a4bad24ac5296b262ad821aa5e08bb265e6b154","https://git.kernel.org/stable/c/451c2d5422a309393aa8ae161fc1a527c2f19ab2","https://git.kernel.org/stable/c/690ce66782778e8c4b1fdd79c0b0890a100e9522","https://git.kernel.org/stable/c/738039ad21e20ca2c5bbde2f5a4f5ad5fb718038","https://git.kernel.org/stable/c/992dce02bdabbd9883255ea9b36494e34a7821d7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix devconf_all NULL dereference when IPv6 is disabled\n\nWhen booting with the 'ipv6.disable=1' parameter, the devconf_all is\nnever initialized because inet6_init() exits before addrconf_init() is\ncalled which initializes it. bond_send_validate(), however, will still\ncall bond_ns_send_all() even ipv6 is indeed disabled. It will lead to\nNULL derefence of net->ipv6.devconf_all in ip6_pol_route().\n\n BUG: kernel NULL pointer dereference, address: 000000000000000c\n [...]\n Workqueue: bond0 bond_arp_monitor [bonding]\n RIP: 0010:ip6_pol_route+0x69/0x480\n [...]\n Call Trace:\n  <TASK>\n  ? srso_return_thunk+0x5/0x5f\n  ? __pfx_ip6_pol_route_output+0x10/0x10\n  fib6_rule_lookup+0xfe/0x260\n  ? wakeup_preempt+0x8a/0x90\n  ? srso_return_thunk+0x5/0x5f\n  ? srso_return_thunk+0x5/0x5f\n  ? sched_balance_rq+0x369/0x810\n  ip6_route_output_flags+0xd7/0x170\n  bond_ns_send_all+0xde/0x280 [bonding]\n  bond_ab_arp_probe+0x296/0x320 [bonding]\n  ? srso_return_thunk+0x5/0x5f\n  bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]\n  process_one_work+0x196/0x370\n  worker_thread+0x1af/0x320\n  ? srso_return_thunk+0x5/0x5f\n  ? __pfx_worker_thread+0x10/0x10\n  kthread+0xe3/0x120\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork+0x199/0x260\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork_asm+0x1a/0x30\n  </TASK>\n\nFix this by adding ipv6_mod_enabled() condition check in the caller.","cvss":[],"epss":[{"cve":"CVE-2026-68336","epss":0.0018,"percentile":0.07698,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68336","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68337","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68337","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Reject redirect helpers without a bpf_net_context  The bpf_redirect*() helpers and skb_do_redirect() obtain the per-task bpf_redirect_info via bpf_net_ctx_get_ri(), which dereferences the current->bpf_net_context unconditionally. That context is established on the paths that run tc BPF such as sch_handle_{ingress,egress}(), *except* for the case where {cls,act}_bpf was attached to a proper qdisc. A program running from there reaches the NULL deref in two ways:  * It calls bpf_redirect() directly, which dereferences the context at   the top of the helper:       tc qdisc add dev eth0 root handle 1: red limit 1MB min 10KB max 20KB \\         avpkt 1000 burst 100 qevent early_drop block 10      tc filter add block 10 pref 1 bpf obj redirect.o  * It simply returns TC_ACT_REDIRECT without helper call: tcf_qevent_handle()   then dispatches to skb_do_redirect(), which dereferences the context  Rather than extending bpf_net_context management into the qdisc path, make the redirect helpers refuse to operate when no context exists, and have tcf_qevent_handle() drop a TC_ACT_REDIRECT verdict instead of calling skb_do_redirect(). Previous behaviour was a crash, so nothing regresses by not supporting it.","cvss":[],"epss":[{"cve":"CVE-2026-68337","epss":0.00155,"percentile":0.04989,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-68337","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68337","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3f4920d165b29052255527d8ae7619e7ec132ece","https://git.kernel.org/stable/c/cabfacbd5af09d3ae898ca224c4a1459e9bba15d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject redirect helpers without a bpf_net_context\n\nThe bpf_redirect*() helpers and skb_do_redirect() obtain the per-task\nbpf_redirect_info via bpf_net_ctx_get_ri(), which dereferences the\ncurrent->bpf_net_context unconditionally. That context is established\non the paths that run tc BPF such as sch_handle_{ingress,egress}(),\n*except* for the case where {cls,act}_bpf was attached to a proper\nqdisc. A program running from there reaches the NULL deref in two ways:\n\n* It calls bpf_redirect() directly, which dereferences the context at\n  the top of the helper:\n\n     tc qdisc add dev eth0 root handle 1: red limit 1MB min 10KB max 20KB \\\n        avpkt 1000 burst 100 qevent early_drop block 10\n     tc filter add block 10 pref 1 bpf obj redirect.o\n\n* It simply returns TC_ACT_REDIRECT without helper call: tcf_qevent_handle()\n  then dispatches to skb_do_redirect(), which dereferences the context\n\nRather than extending bpf_net_context management into the qdisc path,\nmake the redirect helpers refuse to operate when no context exists, and\nhave tcf_qevent_handle() drop a TC_ACT_REDIRECT verdict instead of\ncalling skb_do_redirect(). Previous behaviour was a crash, so nothing\nregresses by not supporting it.","cvss":[],"epss":[{"cve":"CVE-2026-68337","epss":0.00155,"percentile":0.04989,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68337","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68338","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68338","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/packet: avoid fanout hook re-registration after unregister  packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bind_lock, and later restores po->num and re-registers the hook from the saved was_running value.  That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregister_prot_hook(), and invalidate the per-socket binding by setting po->ifindex to -1 and clearing po->prot_hook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packet_set_ring() resumes, re-registering solely from the stale was_running state can re-add the fanout hook after the device has been unregistered.  Treat po->ifindex == -1 as an invalidated binding after reacquiring po->bind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po->num as before, but do not re-register the hook if device unregister already detached the socket.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68338","epss":0.00176,"percentile":0.07256,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13464},"relatedVulnerabilities":[{"id":"CVE-2026-68338","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68338","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0a052e0808e015e68144a9877e6ef42b952c49fa","https://git.kernel.org/stable/c/1bc55c29cd85818e9052f17deb287d5a11fb817f","https://git.kernel.org/stable/c/4628efbdc7affd094181f5263e65c1062e31f15f","https://git.kernel.org/stable/c/50aff80475abd3533eef4320477037e6fcc6b56e","https://git.kernel.org/stable/c/80ec024d53a05c60ad1d08968dcf745f10c1665c","https://git.kernel.org/stable/c/a885387dae7986a55bae5c77a15bdd447f64e9b9","https://git.kernel.org/stable/c/acb40ebfa5c4d62f84339fcbf713f2a9fd033a71","https://git.kernel.org/stable/c/c820f4b7f2fa38f8769db0d0cefdd94e2721504d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: avoid fanout hook re-registration after unregister\n\npacket_set_ring() temporarily detaches a socket from packet delivery while\nreconfiguring its ring. It records the previous running state, clears\npo->num, unregisters the protocol hook when needed, drops po->bind_lock,\nand later restores po->num and re-registers the hook from the saved\nwas_running value.\n\nThat unlocked window can race with NETDEV_UNREGISTER. The notifier can\nobserve the socket as not running, skip __unregister_prot_hook(), and\ninvalidate the per-socket binding by setting po->ifindex to -1 and clearing\npo->prot_hook.dev. A one-member fanout group can still retain its shared\nfanout hook device pointer. When packet_set_ring() resumes, re-registering\nsolely from the stale was_running state can re-add the fanout hook after\nthe device has been unregistered.\n\nTreat po->ifindex == -1 as an invalidated binding after reacquiring\npo->bind_lock. This is distinct from ifindex 0, the normal\nunbound/wildcard state: ifindex -1 marks an existing device binding that\nwas invalidated when the device was unregistered. Restore po->num as\nbefore, but do not re-register the hook if device unregister already\ndetached the socket.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68338","epss":0.00176,"percentile":0.07256,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68338","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68340","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68340","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: occ: validate poll response sensor blocks  The OCC poll response parser walks a counted list of sensor data blocks. It used the static backing-array capacity as the parse boundary, but a transport response makes only data_length bytes current and valid. A truncated response can therefore make the parser consume a block header or block extent outside the current response.  Use data_length as the parent boundary, prove the fixed poll header and each current block header before reading them, and prove the complete block before advancing. Keep parsed sensor metadata local until the complete response has passed validation, then publish it. Propagate malformed-response errors before publishing the OCC as active.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":2.6,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68340","epss":0.00148,"percentile":0.04343,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11248},"relatedVulnerabilities":[{"id":"CVE-2026-68340","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68340","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/112525534ab5cff482d35897ca4ca11fd3a76f46","https://git.kernel.org/stable/c/1902e9572901d37901e3db1f3f6b0885f4e49a66","https://git.kernel.org/stable/c/538d862cc0dbd5c732fe26d5aad98eae039e6676","https://git.kernel.org/stable/c/54cb78eceb4e286ccd5a5c01a4632157860d47f0","https://git.kernel.org/stable/c/6e6c72c37433640514db325408bd6913ad28fe69","https://git.kernel.org/stable/c/70e76e700fc6c46afb4e17aec099a1ea089b4a22","https://git.kernel.org/stable/c/b042e538e98b939fccfffc464e2c34c29f0e96ef"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: occ: validate poll response sensor blocks\n\nThe OCC poll response parser walks a counted list of sensor data blocks.\nIt used the static backing-array capacity as the parse boundary, but a\ntransport response makes only data_length bytes current and valid. A\ntruncated response can therefore make the parser consume a block header or\nblock extent outside the current response.\n\nUse data_length as the parent boundary, prove the fixed poll header and\neach current block header before reading them, and prove the complete block\nbefore advancing. Keep parsed sensor metadata local until the complete\nresponse has passed validation, then publish it. Propagate\nmalformed-response errors before publishing the OCC as active.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.7,"exploitabilityScore":2.6,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68340","epss":0.00148,"percentile":0.04343,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68340","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68343","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68343","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: validate DFS referral PathConsumed  parse_dfs_referrals() validates that the response contains the fixed referral entry array and, on for-next, the per-referral string offsets. However, the response also contains a PathConsumed value that is later used for DFS path parsing.  If a malformed response provides a PathConsumed value larger than the search name, later DFS parsing can advance beyond the end of the path.  Validate PathConsumed against the search name length before storing it in the parsed referral.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68343","epss":0.00513,"percentile":0.42033,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.464265},"relatedVulnerabilities":[{"id":"CVE-2026-68343","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68343","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/285bd4a5f3f156aa5869843b47a1b1380b774241","https://git.kernel.org/stable/c/2fdd6d196c656b376cc251e1e9ff110b3ed522e1","https://git.kernel.org/stable/c/5b439f39f33ec15d319ced3b025e122346fba987","https://git.kernel.org/stable/c/9f88a99ed511651b2dc2177d6854b2d1b8322e75","https://git.kernel.org/stable/c/bfebe5110fd135d86d65a0a346e14c106b02028b","https://git.kernel.org/stable/c/f6f5ee2aa33b350c671721b965251c42cebb962e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate DFS referral PathConsumed\n\nparse_dfs_referrals() validates that the response contains the fixed\nreferral entry array and, on for-next, the per-referral string offsets.\nHowever, the response also contains a PathConsumed value that is later\nused for DFS path parsing.\n\nIf a malformed response provides a PathConsumed value larger than the\nsearch name, later DFS parsing can advance beyond the end of the path.\n\nValidate PathConsumed against the search name length before storing it in\nthe parsed referral.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68343","epss":0.00513,"percentile":0.42033,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68343","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68344","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68344","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect  uea_probe() distinguishes a pre-firmware device from a post-firmware one using the USB id (UEA_IS_PREFIRM()), and stores a different object as the interface data in each case: a 'struct completion' for a pre-firmware device (to be waited on in .disconnect()), or a 'struct usbatm_data' for a post-firmware one.  uea_disconnect() instead tells the two apart by the number of interfaces of the active configuration (a pre-firmware device exposes a single interface, ADI930 has 2 and eagle has 3), and casts the interface data accordingly.  Because the two handlers use different criteria, a crafted device that advertises a pre-firmware id together with a multi-interface descriptor (or a post-firmware id with a single interface) makes them disagree: the small 'struct completion' stored by uea_probe() is then passed to usbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes instance->serialize, reading past the end of the allocation:    BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80   Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982   ...    __mutex_lock+0x152a/0x1b80    usbatm_usb_disconnect+0x70/0x820    uea_disconnect+0x133/0x2c0    usb_unbind_interface+0x1dd/0x9e0   ...   which belongs to the cache kmalloc-96 of size 96   The buggy address is located 0 bytes to the right of    allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)  Reject such inconsistent descriptors in uea_probe() so that both handlers always make the same pre/post-firmware decision.","cvss":[],"epss":[{"cve":"CVE-2026-68344","epss":0.0021,"percentile":0.11271,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68344","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68344","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce","https://git.kernel.org/stable/c/71132cedd1ecbc4032d76e9928c18a10f7e39b80","https://git.kernel.org/stable/c/9904a46401198872ab3de34fd11f383831ef3428","https://git.kernel.org/stable/c/9e7312844429379108ea9523a5ed934f142bb177","https://git.kernel.org/stable/c/c035b1198906dd5bd3df9a3045b59254bad1ea7a","https://git.kernel.org/stable/c/d0a57f19fe2865b9747484f5f9c631f944ed9a0f","https://git.kernel.org/stable/c/e814ae925f6f575325124c29dde518b92c822b83","https://git.kernel.org/stable/c/f92832262718443feb4e5df2bf70424ba842629e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect\n\nuea_probe() distinguishes a pre-firmware device from a post-firmware one\nusing the USB id (UEA_IS_PREFIRM()), and stores a different object as the\ninterface data in each case: a 'struct completion' for a pre-firmware\ndevice (to be waited on in .disconnect()), or a 'struct usbatm_data' for a\npost-firmware one.\n\nuea_disconnect() instead tells the two apart by the number of interfaces\nof the active configuration (a pre-firmware device exposes a single\ninterface, ADI930 has 2 and eagle has 3), and casts the interface data\naccordingly.\n\nBecause the two handlers use different criteria, a crafted device that\nadvertises a pre-firmware id together with a multi-interface descriptor\n(or a post-firmware id with a single interface) makes them disagree: the\nsmall 'struct completion' stored by uea_probe() is then passed to\nusbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes\ninstance->serialize, reading past the end of the allocation:\n\n  BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80\n  Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982\n  ...\n   __mutex_lock+0x152a/0x1b80\n   usbatm_usb_disconnect+0x70/0x820\n   uea_disconnect+0x133/0x2c0\n   usb_unbind_interface+0x1dd/0x9e0\n  ...\n  which belongs to the cache kmalloc-96 of size 96\n  The buggy address is located 0 bytes to the right of\n   allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)\n\nReject such inconsistent descriptors in uea_probe() so that both handlers\nalways make the same pre/post-firmware decision.","cvss":[],"epss":[{"cve":"CVE-2026-68344","epss":0.0021,"percentile":0.11271,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68344","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68349","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68349","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: carl9170: fix buffer overflow in rx_stream failover path  The failover continuation in carl9170_rx_stream() copies the full tlen from the second USB transfer instead of capping at rx_failover_missing bytes. When both transfers are near maximum size, the total exceeds the 65535-byte failover SKB, triggering skb_over_panic.  Limit the copy size to the missing byte count.  [Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]","cvss":[],"epss":[{"cve":"CVE-2026-68349","epss":0.00203,"percentile":0.10375,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1015},"relatedVulnerabilities":[{"id":"CVE-2026-68349","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68349","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/21f59906ea75618fdd46a7e32754d54fbee083ea","https://git.kernel.org/stable/c/4503829843353dbb18b879c35be1cdfc9af677b7","https://git.kernel.org/stable/c/48c81fb523ecdc6a4b8654944ff32e499f21e6d0","https://git.kernel.org/stable/c/5acfa18de66b6089b81c1c0bf1a3ae3c940ec39e","https://git.kernel.org/stable/c/5fb00a09e9b0375e1ad9d4fefc4a62a67e7ea658","https://git.kernel.org/stable/c/a1a21995c2e1cc2ca6b2226cfe4f5f018370182a","https://git.kernel.org/stable/c/a1ce01764a812c22a47d30aea78e347aebd3eea1","https://git.kernel.org/stable/c/b9dfee5e63ee9b5c47be9e344ebc5bd3f43fca78"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: fix buffer overflow in rx_stream failover path\n\nThe failover continuation in carl9170_rx_stream() copies the full tlen\nfrom the second USB transfer instead of capping at rx_failover_missing\nbytes. When both transfers are near maximum size, the total exceeds the\n65535-byte failover SKB, triggering skb_over_panic.\n\nLimit the copy size to the missing byte count.\n\n[Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]","cvss":[],"epss":[{"cve":"CVE-2026-68349","epss":0.00203,"percentile":0.10375,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68349","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68350","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68350","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: carl9170: fix OOB read from off-by-two in TX status handler  The bounds check in carl9170_tx_process_status() uses `i > ((cmd->hdr.len / 2) + 1)` which is off by two, allowing 2 extra iterations past valid _tx_status entries when the firmware- controlled hdr.ext exceeds hdr.len/2. Fix by using the correct comparison `i >= (cmd->hdr.len / 2)`.","cvss":[],"epss":[{"cve":"CVE-2026-68350","epss":0.00184,"percentile":0.08123,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68350","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68350","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2c030c20f112bd8f6aa59d09501835605f01bf9d","https://git.kernel.org/stable/c/423c836f934814b8fdbe53b24a79d021a0ee8454","https://git.kernel.org/stable/c/73462e8e602047a03e538d971a79ad67a4ba9a5d","https://git.kernel.org/stable/c/7ed0dce8613c92111d2a3836ced2ab03190ba20e","https://git.kernel.org/stable/c/9bf8d8510b7bed20320dead0f8cdcf8e610ec8db","https://git.kernel.org/stable/c/a3f42f1049ad80c65560d2b078ad426c3134f78d","https://git.kernel.org/stable/c/e8a862a3da457ddc50633c346dc645d559da09ae","https://git.kernel.org/stable/c/fab6ff91d5b8c4af62e2ced42fb357fa3eb9fd59"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: fix OOB read from off-by-two in TX status handler\n\nThe bounds check in carl9170_tx_process_status() uses\n`i > ((cmd->hdr.len / 2) + 1)` which is off by two, allowing\n2 extra iterations past valid _tx_status entries when the firmware-\ncontrolled hdr.ext exceeds hdr.len/2. Fix by using the correct\ncomparison `i >= (cmd->hdr.len / 2)`.","cvss":[],"epss":[{"cve":"CVE-2026-68350","epss":0.00184,"percentile":0.08123,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68350","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68351","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68351","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read  When the firmware sends a command response with a length mismatch, carl9170_cmd_callback() logs the mismatch and calls carl9170_restart() but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4). Since len comes from the firmware and can exceed ar->readlen, this copies more data than the readbuf was allocated for.  Bound the memcpy to min(len - 4, ar->readlen) so that the response is still completed -- avoiding repeated restarts from queued garbage -- while preventing an overread past the response buffer.","cvss":[],"epss":[{"cve":"CVE-2026-68351","epss":0.0022,"percentile":0.12413,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68351","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68351","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2d05c321d27624c413c950278d2dc8e0f44a8950","https://git.kernel.org/stable/c/38e240996a6a78c94ab07d461fd66e361d55c3c4","https://git.kernel.org/stable/c/4cde55b2feff9504d1f993ab80e84e7ccb62791c","https://git.kernel.org/stable/c/500c36649f270de05a56591fcc1aaaa36687958e","https://git.kernel.org/stable/c/525036b20ef01d814a7fcd0567d123992e4479fa","https://git.kernel.org/stable/c/9aee949c68dc6dccbc54333537b109c53fe2079f","https://git.kernel.org/stable/c/cb7a38810cf25738176dac32dec7a146b3f959cf","https://git.kernel.org/stable/c/f74e34e66379e487a09009a4f2d42470051672bd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: carl9170: bound memcpy length in cmd callback to prevent OOB read\n\nWhen the firmware sends a command response with a length mismatch,\ncarl9170_cmd_callback() logs the mismatch and calls carl9170_restart()\nbut then falls through to memcpy(ar->readbuf, buffer + 4, len - 4).\nSince len comes from the firmware and can exceed ar->readlen, this\ncopies more data than the readbuf was allocated for.\n\nBound the memcpy to min(len - 4, ar->readlen) so that the response\nis still completed -- avoiding repeated restarts from queued garbage --\nwhile preventing an overread past the response buffer.","cvss":[],"epss":[{"cve":"CVE-2026-68351","epss":0.0022,"percentile":0.12413,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68351","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68352","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68352","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath6kl: fix OOB read from firmware IE lengths in connect event  The firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len fields in ath6kl_wmi_connect_event_rx() are not validated against the buffer length. Their sum (up to 765) can exceed the actual WMI event data, causing out-of-bounds reads during IE parsing and state corruption of wmi->is_wmm_enabled.  Add a check that the total IE length fits within the buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":8.3,"exploitabilityScore":2.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68352","epss":0.00413,"percentile":0.3476,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.32627000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-68352","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68352","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1c690f7c4c5b37108ac8c98b94ce1b3c655a4f5e","https://git.kernel.org/stable/c/1eeed9efc9a40e0635e910c37fee86543041b4e1","https://git.kernel.org/stable/c/33b5342d2080657054ddf89ef1199b426a37dae8","https://git.kernel.org/stable/c/6b47b29730de3232b919d8362749f6814c5f2a33","https://git.kernel.org/stable/c/7cae33e3e09a080db96e3a8980c2c8d288318320","https://git.kernel.org/stable/c/94e1bfcefe8264a207c2fda2febb954e70a34b42","https://git.kernel.org/stable/c/a38d7d6376b295245b53bc98b7ca682c027abaf7","https://git.kernel.org/stable/c/d70c0a850c21b57a6f46ce363860203389bbeaa6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB read from firmware IE lengths in connect event\n\nThe firmware-controlled beacon_ie_len, assoc_req_len, and assoc_resp_len\nfields in ath6kl_wmi_connect_event_rx() are not validated against the\nbuffer length. Their sum (up to 765) can exceed the actual WMI event\ndata, causing out-of-bounds reads during IE parsing and state corruption\nof wmi->is_wmm_enabled.\n\nAdd a check that the total IE length fits within the buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":8.3,"exploitabilityScore":2.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68352","epss":0.00413,"percentile":0.3476,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68352","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68353","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68353","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler  The firmware-controlled num_msg field (u8, 0-255) drives the loop in ath6kl_wmi_tx_complete_event_rx() without validation against the buffer length. This allows out-of-bounds reads of up to 1020 bytes past the WMI event buffer when the firmware sends an inflated num_msg.  Add a check that the buffer is large enough to hold the fixed struct and the num_msg variable-length entries.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68353","epss":0.0029,"percentile":0.2134,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.2262},"relatedVulnerabilities":[{"id":"CVE-2026-68353","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68353","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0e0fc04af9b443c6b425f00fb604ff599bc80d1d","https://git.kernel.org/stable/c/289edc3c71344b89e6522891147cfb8f61b088bb","https://git.kernel.org/stable/c/35196a07603f8c94a4943093bc26d5b5826285f8","https://git.kernel.org/stable/c/3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495","https://git.kernel.org/stable/c/5297299c3fa6133275db0be99d69cd759b6cbfe9","https://git.kernel.org/stable/c/69ac7ba3a3df6654e7daa82674575a8c4a1a63ea","https://git.kernel.org/stable/c/c38b0d5c661951b5dd082bdf31f8a57a0ce6e540","https://git.kernel.org/stable/c/eb636fbc443149b3501c3f97e26225ddcb314a0f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler\n\nThe firmware-controlled num_msg field (u8, 0-255) drives the loop in\nath6kl_wmi_tx_complete_event_rx() without validation against the buffer\nlength. This allows out-of-bounds reads of up to 1020 bytes past the\nWMI event buffer when the firmware sends an inflated num_msg.\n\nAdd a check that the buffer is large enough to hold the fixed struct\nand the num_msg variable-length entries.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68353","epss":0.0029,"percentile":0.2134,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68353","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68354","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68354","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  firewire: net: Fix fragmented datagram reassembly  fwnet_frag_new() keeps a sorted list of received fragments for a partial datagram. When a new fragment is adjacent to an existing fragment, the code checks whether the new fragment also closes the gap to the next or previous list entry.  Those neighbor lookups currently assume that the current fragment always has a real next or previous fragment. At a list edge, the next or previous entry is the list head, not a struct fwnet_fragment_info.  The gap checks also compare against the old edge of the current fragment instead of the edge after adding the new fragment. As a result, a fragment that bridges two existing ranges may leave two adjacent ranges unmerged, so fwnet_pd_is_complete() can miss a complete datagram.  Check for the list head before looking up the neighboring fragment, and compare the neighbor against the new fragment's far edge when deciding whether to merge all three ranges.  This issue was found by a static analysis checker and confirmed by manual source review.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68354","epss":0.00285,"percentile":0.20876,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.232275},"relatedVulnerabilities":[{"id":"CVE-2026-68354","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68354","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0177e578d7a885037b0fb82286c12e9d0360cc10","https://git.kernel.org/stable/c/0a219b2a01b4fe93706717e3bcacf7f62967b26f","https://git.kernel.org/stable/c/1aaf16031d65ccd4576451a79f7dabbec994c111","https://git.kernel.org/stable/c/22e05b8ddbcf7d22c7f1598786e86635547e554d","https://git.kernel.org/stable/c/268cea3800eda5fa3ee04a49ee2973b8766a8df3","https://git.kernel.org/stable/c/2a5aa4e9b89227d1a1690fb8d5b81e5f3b261999","https://git.kernel.org/stable/c/b7d633c7c92321be98724b1d365e8ce507f2f349","https://git.kernel.org/stable/c/d52a13adbb8ccbab99cd3bad36804e87d8b5c052"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: net: Fix fragmented datagram reassembly\n\nfwnet_frag_new() keeps a sorted list of received fragments for a partial\ndatagram. When a new fragment is adjacent to an existing fragment, the\ncode checks whether the new fragment also closes the gap to the next or\nprevious list entry.\n\nThose neighbor lookups currently assume that the current fragment always\nhas a real next or previous fragment. At a list edge, the next or\nprevious entry is the list head, not a struct fwnet_fragment_info.\n\nThe gap checks also compare against the old edge of the current fragment\ninstead of the edge after adding the new fragment. As a result, a\nfragment that bridges two existing ranges may leave two adjacent ranges\nunmerged, so fwnet_pd_is_complete() can miss a complete datagram.\n\nCheck for the list head before looking up the neighboring fragment, and\ncompare the neighbor against the new fragment's far edge when deciding\nwhether to merge all three ranges.\n\nThis issue was found by a static analysis checker and confirmed by\nmanual source review.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68354","epss":0.00285,"percentile":0.20876,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68354","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68355","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68355","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()  When the first entry in msdu_details has a zero buffer address, the code accesses msdu_details[i - 1] with i == 0, causing a buffer underflow.  Fix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding a separate check for i == 0 before the main condition to prevent the out-of-bounds access.  Found by Linux Verification Center (linuxtesting.org) with SVACE.","cvss":[],"epss":[{"cve":"CVE-2026-68355","epss":0.00184,"percentile":0.08122,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68355","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68355","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/085a5fde5bac29c01059e69399b417e91c0a6c18","https://git.kernel.org/stable/c/20d18a5ec6ec364fcaf0d03af6fc43dcc42c6591","https://git.kernel.org/stable/c/31ea4b175bc3ab430be15834d9ee8a1ce65bee15","https://git.kernel.org/stable/c/69a6a4f60b2da92c0bdfd9264b8ffe053f51f52a","https://git.kernel.org/stable/c/725c1c3a8c5d920a7d3f5887412f2ad8e95a74f5","https://git.kernel.org/stable/c/7f11e70629650ff6ea140984e5ce188b775b2683","https://git.kernel.org/stable/c/904367381a922aa2dc3e8bd2488e6c9180516c7a","https://git.kernel.org/stable/c/a154ca3c441a67d36b3a9ea63a4f11b06abe6223"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()\n\nWhen the first entry in msdu_details has a zero buffer address,\nthe code accesses msdu_details[i - 1] with i == 0, causing a\nbuffer underflow.\n\nFix similarly to ath12k_wifi7_hal_rx_msdu_list_get() by adding\na separate check for i == 0 before the main condition to prevent\nthe out-of-bounds access.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.","cvss":[],"epss":[{"cve":"CVE-2026-68355","epss":0.00184,"percentile":0.08122,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68355","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68357","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68357","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()  When a watchdog governor is unregistered, it updates existing watchdog devices that were using this governor by falling back to `default_gov`.  If the governor being unregistered is currently set as `default_gov`, the `default_gov` is never cleared.  This leads to 2 use-after-free issues: 1. New watchdog devices registered after this point will inherit the    dangling `default_gov`. 2. Existing watchdog devices using the unregistered governor will have    their `wdd->gov` reassigned to the dangling `default_gov`.  Fix the UAF by clearing `default_gov` if it matches the governor being unregistered.","cvss":[],"epss":[{"cve":"CVE-2026-68357","epss":0.00176,"percentile":0.07303,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68357","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68357","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0ca252720f0e38411cfec3431db9bb1aed0a412c","https://git.kernel.org/stable/c/2e47b91b9b4020fcc01def14d6b6556d66074cf4","https://git.kernel.org/stable/c/472ec1e34ff0bb26379805cae808f658cce58c35","https://git.kernel.org/stable/c/7362ba0f9c96ac3ad6a2ca3995bd9fc9a28a8661","https://git.kernel.org/stable/c/7993d626983cc58fbde9607333cfd2d57725c197","https://git.kernel.org/stable/c/7a2ee3ec6f208307eca1119a343c7b5d39c03708","https://git.kernel.org/stable/c/7d1658b066de30f4b23afc14814d22416a971e6e","https://git.kernel.org/stable/c/b9ae33faa96bdec6bc60e4c5f8f53786182e4207"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: pretimeout: Fix UAF in watchdog_unregister_governor()\n\nWhen a watchdog governor is unregistered, it updates existing watchdog\ndevices that were using this governor by falling back to `default_gov`.\n\nIf the governor being unregistered is currently set as `default_gov`,\nthe `default_gov` is never cleared.  This leads to 2 use-after-free\nissues:\n1. New watchdog devices registered after this point will inherit the\n   dangling `default_gov`.\n2. Existing watchdog devices using the unregistered governor will have\n   their `wdd->gov` reassigned to the dangling `default_gov`.\n\nFix the UAF by clearing `default_gov` if it matches the governor being\nunregistered.","cvss":[],"epss":[{"cve":"CVE-2026-68357","epss":0.00176,"percentile":0.07303,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68357","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68359","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68359","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop  Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after \"io start\" has been initiated, this race condition will result in a UAF vulnerability.  Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().","cvss":[],"epss":[{"cve":"CVE-2026-68359","epss":0.00231,"percentile":0.13909,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1155},"relatedVulnerabilities":[{"id":"CVE-2026-68359","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68359","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/185c0880397aee9def0af5a59ea65f22f37ad658","https://git.kernel.org/stable/c/18d7c523891004226bccdba39dd681eca22ceb8a","https://git.kernel.org/stable/c/205cff797a94757ec88ba299c8e2bf2e1e3f4bbf","https://git.kernel.org/stable/c/59d104b54b0b42e30fd2a68d24ee5c49dcc54d1e","https://git.kernel.org/stable/c/761249a3d92db83ae19670c4ecdf73c0a85bcb61","https://git.kernel.org/stable/c/a2a15de020597efbff84b4281dd472e5860b7e3e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop().","cvss":[],"epss":[{"cve":"CVE-2026-68359","epss":0.00231,"percentile":0.13909,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68359","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68360","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68360","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop  Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after \"io start\" has been initiated, this race condition will result in a UAF vulnerability.  Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().","cvss":[],"epss":[{"cve":"CVE-2026-68360","epss":0.00236,"percentile":0.1461,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68360","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68360","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0975c42ed2a3bf32125a920e5d19194289126210","https://git.kernel.org/stable/c/1a634f464d6153dfa4d7e73a3d78236b65a64ee9","https://git.kernel.org/stable/c/3df2b67793babbea7951b5f601d6df891c63b5d8","https://git.kernel.org/stable/c/56d2deb6448378118dbe68c4fbb3fbae5f65b18c","https://git.kernel.org/stable/c/5e07f292ab5591bf4f588aa7abd22ec86c25d076","https://git.kernel.org/stable/c/6c5f31fdf28455a7fd573bda452c80b7b6700247","https://git.kernel.org/stable/c/94c87871b051d7ad758828a805215a2ec194512a","https://git.kernel.org/stable/c/c7757db58957ac20cdec6ce575dbd44a6375664e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop\n\nCalling hid_hw_stop() does not stop the device IO.\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\nthe driver probe function. If the probe operation fails after \"io start\"\nhas been initiated, this race condition will result in a UAF vulnerability.\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop().","cvss":[],"epss":[{"cve":"CVE-2026-68360","epss":0.00236,"percentile":0.1461,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68360","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68361","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68361","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop  hid_hw_stop() does not stop the device IO.  This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within corsairpsu_probe(). If the probe operation fails after \"io start\" has been initiated, this race condition will result in a uaf vulnerability [1].  CPU0\t\t\t\tCPU1 ====\t\t\t\t==== corsairpsu_probe()  hid_device_io_start()   ... unlock driver_input_lock  hid_hw_stop()   kfree(hidraw)\t\t\t__hid_input_report() \t\t\t\t ... acquire driver_input_lock \t\t\t\t hid_report_raw_event() \t\t\t\t  hidraw_report_event() \t\t\t\t   ... access hidraw's list_lock // trigger uaf  Consequently, when corsairpsu_probe() fails and hid_hw_stop() needs to be executed, the io_started flag is first cleared while holding the driver_input_lock to prevent potential race conditions involving input reports.  [1] BUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56 Call Trace:  hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577  hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076  __hid_input_report drivers/hid/hid-core.c:2152 [inline]  hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174  hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286  __usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657  dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005  Allocated by task 10:  hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606  hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277  hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387  corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782  Freed by task 10:  hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662  hid_disconnect drivers/hid/hid-core.c:2362 [inline]  hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407  corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826  Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().  [groeck: Updated subject and description;  call hid_device_io_stop() only if IO has been started]","cvss":[],"epss":[{"cve":"CVE-2026-68361","epss":0.00194,"percentile":0.0918,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.097},"relatedVulnerabilities":[{"id":"CVE-2026-68361","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68361","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/45dcd8a63069197f64dbda30509b9e224b74c0d8","https://git.kernel.org/stable/c/9ab8656548cd737b98d0b19c4253aff8d68e97f4","https://git.kernel.org/stable/c/bb25bd980f2d9bd34558e1b1d16636e4945baf14","https://git.kernel.org/stable/c/c0aae8d24f5e52d6910f97d59bc624e131f3ae1a","https://git.kernel.org/stable/c/c80ed058f31bb0251a748034d69feb376741dcb2","https://git.kernel.org/stable/c/e6e1e0f3050d1a1a3ea1c9d6253363e87fdad67a","https://git.kernel.org/stable/c/ec477af3a7e8d3964e62fd24ef01cdebb96b8e4e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (corsair-psu) Stop device IO before calling hid_hw_stop\n\nhid_hw_stop() does not stop the device IO.\n\nThis results in a race condition between hid_input_report() and the point\nimmediately following the execution of hid_device_io_start() within\ncorsairpsu_probe(). If the probe operation fails after \"io start\" has\nbeen initiated, this race condition will result in a uaf vulnerability\n[1].\n\nCPU0\t\t\t\tCPU1\n====\t\t\t\t====\ncorsairpsu_probe()\n hid_device_io_start()\n  ... unlock driver_input_lock\n hid_hw_stop()\n  kfree(hidraw)\t\t\t__hid_input_report()\n\t\t\t\t ... acquire driver_input_lock\n\t\t\t\t hid_report_raw_event()\n\t\t\t\t  hidraw_report_event()\n\t\t\t\t   ... access hidraw's list_lock // trigger uaf\n\nConsequently, when corsairpsu_probe() fails and hid_hw_stop() needs to\nbe executed, the io_started flag is first cleared while holding the\ndriver_input_lock to prevent potential race conditions involving input\nreports.\n\n[1]\nBUG: KASAN: slab-use-after-free in rt_spin_lock+0x83/0x400 kernel/locking/spinlock_rt.c:56\nCall Trace:\n hidraw_report_event+0x5d/0x3a0 drivers/hid/hidraw.c:577\n hid_report_raw_event+0x311/0x1730 drivers/hid/hid-core.c:2076\n __hid_input_report drivers/hid/hid-core.c:2152 [inline]\n hid_input_report+0x44e/0x580 drivers/hid/hid-core.c:2174\n hid_irq_in+0x47e/0x6d0 drivers/hid/usbhid/hid-core.c:286\n __usb_hcd_giveback_urb+0x3b3/0x5e0 drivers/usb/core/hcd.c:1657\n dummy_timer+0x8a9/0x47d0 drivers/usb/gadget/udc/dummy_hcd.c:2005\n\nAllocated by task 10:\n hidraw_connect+0x57/0x430 drivers/hid/hidraw.c:606\n hid_connect+0x5bf/0x19d0 drivers/hid/hid-core.c:2277\n hid_hw_start+0xa8/0x120 drivers/hid/hid-core.c:2387\n corsairpsu_probe+0xd9/0x3c0 drivers/hwmon/corsair-psu.c:782\n\nFreed by task 10:\n hidraw_disconnect+0x4f/0x60 drivers/hid/hidraw.c:662\n hid_disconnect drivers/hid/hid-core.c:2362 [inline]\n hid_hw_stop+0x101/0x1e0 drivers/hid/hid-core.c:2407\n corsairpsu_probe+0x327/0x3c0 drivers/hwmon/corsair-psu.c:826\n\nFix the problem by calling hid_device_io_stop() before calling\nhid_hw_stop().\n\n[groeck: Updated subject and description;\n call hid_device_io_stop() only if IO has been started]","cvss":[],"epss":[{"cve":"CVE-2026-68361","epss":0.00194,"percentile":0.0918,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68361","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68362","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68362","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin  In ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set unconditionally even when ath11k_core_qmi_firmware_ready() fails. This leaves the driver in an inconsistent state where initialization is considered complete although the firmware ready handling did not finish successfully. During the subsequent SSR, the driver enters the restart path based on this incorrect state and dereferences uninitialized srng members, resulting in a NULL pointer dereference.  Call trace:   ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)   ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]   ath11k_core_restart+0x40/0x168 [ath11k]  Fix this by: - skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set - setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds - setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling on error  Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1","cvss":[],"epss":[{"cve":"CVE-2026-68362","epss":0.00172,"percentile":0.06809,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68362","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68362","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4abb4e284d8897176e91d7a3168ee29ed876bb41","https://git.kernel.org/stable/c/66bf998b18334ca97321433e4ab783b6ff267e9d","https://git.kernel.org/stable/c/d6bba659ac30d862ee7bab92862cd6e514f07521","https://git.kernel.org/stable/c/e517e207300edcf7f3a8f6c45f9155c0e419ffb9","https://git.kernel.org/stable/c/e5394605f9a985cc3a8263e610ba84b33cbe7b0c","https://git.kernel.org/stable/c/e8d85672dd7e2523f774caafba8f858384e18df7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin\n\nIn ATH11K_QMI_EVENT_FW_READY, ATH11K_FLAG_REGISTERED is set\nunconditionally even when ath11k_core_qmi_firmware_ready() fails.\nThis leaves the driver in an inconsistent state where\ninitialization is considered complete although the firmware ready\nhandling did not finish successfully. During the subsequent SSR,\nthe driver enters the restart path based on this incorrect state\nand dereferences uninitialized srng members, resulting in a NULL\npointer dereference.\n\nCall trace:\n  ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] (P)\n  ath11k_ce_cleanup_pipes+0x17c/0x180 [ath11k]\n  ath11k_core_restart+0x40/0x168 [ath11k]\n\nFix this by:\n- skipping firmware_ready if ATH11K_FLAG_REGISTERED is already set\n- setting ATH11K_FLAG_REGISTERED only when firmware_ready succeeds\n- setting ATH11K_FLAG_QMI_FAIL and aborting the FW_READY handling\non error\n\nTested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1","cvss":[],"epss":[{"cve":"CVE-2026-68362","epss":0.00172,"percentile":0.06809,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68362","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68363","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68363","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request  ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completion context, and then still dereferences hif_dev:  \tdev_info(&hif_dev->udev->dev, \"ath9k_htc: Firmware %s requested\\n\", \t\t hif_dev->fw_name);  The re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\" workqueue and, when the firmware is missing, walks the retry chain into ath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That releases the wait_for_completion(&hif_dev->fw_done) in a concurrent ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing dev_info() in the frame that re-armed the request can therefore read freed memory (hif_dev->udev, the first field of struct hif_device_usb):    BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware   Read of size 8 ... by task kworker/...    ath9k_hif_request_firmware    ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247    request_firmware_work_func   Allocated by ...:    ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c   Freed by ...:    ath9k_hif_usb_disconnect -> kfree   drivers/net/wireless/ath/ath9k/hif_usb.c  The fw_done barrier only makes disconnect wait for the firmware chain to *terminate*; it does not protect the outer ath9k_hif_request_firmware() frame that re-armed the request and keeps touching hif_dev afterwards.  Drop the post-request dev_info(): it is the only use of hif_dev after the async request is armed, and it is purely informational (the dev_err() on the failure path runs only when request_firmware_nowait() did not arm a callback, so hif_dev is still alive there).  This was first reported by syzbot as a single, non-reproduced crash that was later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer, which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc device whose firmware download fails). The vulnerable code is unchanged and still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN once the (sub-microsecond) race window is widened.","cvss":[],"epss":[{"cve":"CVE-2026-68363","epss":0.00184,"percentile":0.08141,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68363","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68363","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/063497cc9f320ab71a7a937c3bc0a23e630aefe2","https://git.kernel.org/stable/c/10b0ce629123a3737b4eda50188f73bb7be7b68b","https://git.kernel.org/stable/c/47ed81aaa7f94d9808f4719e78a760c2ec1e6c86","https://git.kernel.org/stable/c/48a69cedde7388294e4ea6fd804156cd62bc04fc","https://git.kernel.org/stable/c/48de0c6952192b0771fca468df4364d11ec74ad9","https://git.kernel.org/stable/c/7c9046d92c4b9789c9d9d775e4fd5f34be64cb0a","https://git.kernel.org/stable/c/7f184ca38a90889f3f6665ff96748b95da39dbee","https://git.kernel.org/stable/c/dad9f96945d77ecd4708f730c06ef54dcd8cc057"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request\n\nath9k_hif_request_firmware() re-arms an asynchronous firmware load via\nrequest_firmware_nowait(), passing hif_dev as the completion context, and\nthen still dereferences hif_dev:\n\n\tdev_info(&hif_dev->udev->dev, \"ath9k_htc: Firmware %s requested\\n\",\n\t\t hif_dev->fw_name);\n\nThe re-armed callback ath9k_hif_usb_firmware_cb() runs on the \"events\"\nworkqueue and, when the firmware is missing, walks the retry chain into\nath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That\nreleases the wait_for_completion(&hif_dev->fw_done) in a concurrent\nath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing\ndev_info() in the frame that re-armed the request can therefore read freed\nmemory (hif_dev->udev, the first field of struct hif_device_usb):\n\n  BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware\n  Read of size 8 ... by task kworker/...\n   ath9k_hif_request_firmware\n   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247\n   request_firmware_work_func\n  Allocated by ...:\n   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c\n  Freed by ...:\n   ath9k_hif_usb_disconnect -> kfree   drivers/net/wireless/ath/ath9k/hif_usb.c\n\nThe fw_done barrier only makes disconnect wait for the firmware chain to\n*terminate*; it does not protect the outer ath9k_hif_request_firmware()\nframe that re-armed the request and keeps touching hif_dev afterwards.\n\nDrop the post-request dev_info(): it is the only use of hif_dev after the\nasync request is armed, and it is purely informational (the dev_err() on the\nfailure path runs only when request_firmware_nowait() did not arm a callback,\nso hif_dev is still alive there).\n\nThis was first reported by syzbot as a single, non-reproduced crash that was\nlater auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer,\nwhich produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc\ndevice whose firmware download fails). The vulnerable code is unchanged and\nstill present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN\nonce the (sub-microsecond) race window is widened.","cvss":[],"epss":[{"cve":"CVE-2026-68363","epss":0.00184,"percentile":0.08141,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68363","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68365","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68365","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  USB: serial: io_edgeport: cap received transmit credits  The interrupt-status packet reports transmit credits returned by the device. edge_interrupt_callback() adds the 16-bit value to txCredits without checking maxTxCredits.  edge_write() uses txCredits minus the software FIFO count as the amount of data that fits. Since the FIFO is allocated with maxTxCredits bytes, txCredits exceeding maxTxCredits can cause OOB write in ring buffer.  Cap accumulated credits at maxTxCredits. Conforming devices should never hit the cap.","cvss":[],"epss":[{"cve":"CVE-2026-68365","epss":0.00184,"percentile":0.08122,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68365","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68365","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1e47d8228b8767c8ac722aedb388f70adeeda43d","https://git.kernel.org/stable/c/5b39d3da15344b87ef54a0a04f65b52622747e99","https://git.kernel.org/stable/c/63c4e55d0741cfaf00515e807cad9293445cd348","https://git.kernel.org/stable/c/64b687f9694777754285d489abbefa3784bc78da","https://git.kernel.org/stable/c/cbe00048b69d67c8a78293cb7681b4c9963b26c7","https://git.kernel.org/stable/c/d9dd87bc1d7e8476d29d68883542ec6198d385c6","https://git.kernel.org/stable/c/ee57992c053a6d395e98ced2d4c9cc3b42d8c27a","https://git.kernel.org/stable/c/faaddd811c5099f11a5f52e68a6b31a5898cda4f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_edgeport: cap received transmit credits\n\nThe interrupt-status packet reports transmit credits returned by the\ndevice. edge_interrupt_callback() adds the 16-bit value to txCredits\nwithout checking maxTxCredits.\n\nedge_write() uses txCredits minus the software FIFO count as the amount\nof data that fits. Since the FIFO is allocated with maxTxCredits bytes,\ntxCredits exceeding maxTxCredits can cause OOB write in ring buffer.\n\nCap accumulated credits at maxTxCredits. Conforming devices should never\nhit the cap.","cvss":[],"epss":[{"cve":"CVE-2026-68365","epss":0.00184,"percentile":0.08122,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68365","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68366","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68366","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer  uvc_send_response() builds the UVC control response from a user-supplied struct uvc_request_data:  \treq->length = min_t(unsigned int, uvc->event_length, data->length); \t... \tmemcpy(req->buf, data->data, req->length);  req->length is clamped to uvc->event_length, which is taken from the host control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to data->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is only checked for being negative.  The source buffer data->data is only 60 bytes, so a response with uvc->event_length and data->length both greater than 60 makes memcpy() read past the end of data->data.  Clamp req->length to sizeof(data->data) as well.","cvss":[],"epss":[{"cve":"CVE-2026-68366","epss":0.00184,"percentile":0.08123,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68366","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68366","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1f03658f3e9b2f8fd1d1003ba389a0390b49a350","https://git.kernel.org/stable/c/4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796","https://git.kernel.org/stable/c/568e68d8f80395a64848aa2946af8ade72da0ffb","https://git.kernel.org/stable/c/662f6c6c6ff8a6c508e1646c09cae74e28f3cca6","https://git.kernel.org/stable/c/82ec2c1e456b17451f0736c3983402642f961733","https://git.kernel.org/stable/c/b70dc75e85ba968b7b76eebfe5d63000080b875b","https://git.kernel.org/stable/c/c8510fbbea09ef0170b56b14dc2b5890dc75be07","https://git.kernel.org/stable/c/eaf783c005299a702f2cc96b08cd21ede081f098"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer\n\nuvc_send_response() builds the UVC control response from a user-supplied\nstruct uvc_request_data:\n\n\treq->length = min_t(unsigned int, uvc->event_length, data->length);\n\t...\n\tmemcpy(req->buf, data->data, req->length);\n\nreq->length is clamped to uvc->event_length, which is taken from the\nhost control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to\ndata->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is\nonly checked for being negative.  The source buffer data->data is only\n60 bytes, so a response with uvc->event_length and data->length both\ngreater than 60 makes memcpy() read past the end of data->data.\n\nClamp req->length to sizeof(data->data) as well.","cvss":[],"epss":[{"cve":"CVE-2026-68366","epss":0.00184,"percentile":0.08123,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68366","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68367","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68367","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_tcm: synchronize delayed set_alt with teardown  The f_tcm set_alt() path defers endpoint setup to a work item and completes the delayed status response from process context. The delayed work uses f_tcm private state and may complete the setup request after disconnect or function teardown has already moved on.  Cancel and drain the delayed set_alt work when the function is unbound or freed. For disable paths, which are reached under the composite device lock, use a small state machine and a non-sleeping cancellation path instead of cancel_work_sync(). If the work is already running, mark it cancelled and let the worker own the cleanup; otherwise tcm_disable() can cancel the queued work and clean up immediately.  Also serialize the final delayed-status completion with the cancellation check while holding the composite device lock. This prevents a disconnect from clearing delayed_status while the worker is about to complete the control request.  Validation reproduced this kernel report: BUG: KASAN: slab-use-after-free in tcm_delayed_set_alt+0x6c/0xef0  Call Trace:  <TASK>  dump_stack_lvl+0x66/0xa0  print_report+0xce/0x630  ? tcm_delayed_set_alt+0x6c/0xef0  ? srso_alias_return_thunk+0x5/0xfbef5  ? __virt_addr_valid+0x188/0x320  ? tcm_delayed_set_alt+0x6c/0xef0  kasan_report+0xe0/0x110  ? tcm_delayed_set_alt+0x6c/0xef0  tcm_delayed_set_alt+0x6c/0xef0  ? __pfx_tcm_delayed_set_alt+0x10/0x10  ? process_one_work+0x4cb/0xb90  ? rcu_is_watching+0x20/0x50  ? tcm_delayed_set_alt+0x9/0xef0  process_one_work+0x4d7/0xb90  ? __pfx_process_one_work+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  ? __list_add_valid_or_report+0x37/0xf0  ? __pfx_tcm_delayed_set_alt+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  worker_thread+0x2d8/0x570  ? __pfx_worker_thread+0x10/0x10  kthread+0x1ad/0x1f0  ? __pfx_kthread+0x10/0x10  ret_from_fork+0x3c9/0x540  ? __pfx_ret_from_fork+0x10/0x10  ? srso_alias_return_thunk+0x5/0xfbef5  ? __switch_to+0x2e9/0x730  ? __pfx_kthread+0x10/0x10  ret_from_fork_asm+0x1a/0x30  </TASK>  Allocated by task 544:  kasan_save_stack+0x33/0x60  kasan_save_track+0x14/0x30  __kasan_kmalloc+0x8f/0xa0  tcm_alloc+0x68/0x180  usb_get_function+0x36/0x60  config_usb_cfg_link+0x125/0x1b0  configfs_symlink+0x322/0x890  vfs_symlink+0xc2/0x270  filename_symlinkat+0x295/0x2f0  __x64_sys_symlinkat+0x62/0x90  do_syscall_64+0x115/0x6a0  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Freed by task 661:  kasan_save_stack+0x33/0x60  kasan_save_track+0x14/0x30  kasan_save_free_info+0x3b/0x60  __kasan_slab_free+0x43/0x70  kfree+0x2f9/0x530  config_usb_cfg_unlink+0x173/0x1e0  configfs_unlink+0x1fa/0x340  vfs_unlink+0x15c/0x510  filename_unlinkat+0x2ba/0x450  __x64_sys_unlinkat+0x63/0x90  do_syscall_64+0x115/0x6a0  entry_SYSCALL_64_after_hwframe+0x77/0x7f","cvss":[],"epss":[{"cve":"CVE-2026-68367","epss":0.00184,"percentile":0.0814,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68367","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68367","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3118bb872c7dff653294f193d5328a476619e04d","https://git.kernel.org/stable/c/4c6c6a5588b9a2f8437fb794e852d05fa60ebe53","https://git.kernel.org/stable/c/79e2d75725c85607f8a9d87ae9cace62a19f767d","https://git.kernel.org/stable/c/8fb317058d165c88f3344f59439c14872c162b3c","https://git.kernel.org/stable/c/90431d8523c0c1c9f8e3e3f0895727063f93da85","https://git.kernel.org/stable/c/a6eb5a0ae7cd313cfd7df78decd8f43b64c68703","https://git.kernel.org/stable/c/ee07d09419f1c59c74f73107aa08444f2f2fc6c8","https://git.kernel.org/stable/c/f282242906c12fd476b86757afba51f211d4f959"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: synchronize delayed set_alt with teardown\n\nThe f_tcm set_alt() path defers endpoint setup to a work item and\ncompletes the delayed status response from process context. The delayed\nwork uses f_tcm private state and may complete the setup request after\ndisconnect or function teardown has already moved on.\n\nCancel and drain the delayed set_alt work when the function is unbound or\nfreed. For disable paths, which are reached under the composite device\nlock, use a small state machine and a non-sleeping cancellation path\ninstead of cancel_work_sync(). If the work is already running, mark it\ncancelled and let the worker own the cleanup; otherwise tcm_disable() can\ncancel the queued work and clean up immediately.\n\nAlso serialize the final delayed-status completion with the cancellation\ncheck while holding the composite device lock. This prevents a disconnect\nfrom clearing delayed_status while the worker is about to complete the\ncontrol request.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in tcm_delayed_set_alt+0x6c/0xef0\n\nCall Trace:\n <TASK>\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n ? tcm_delayed_set_alt+0x6c/0xef0\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __virt_addr_valid+0x188/0x320\n ? tcm_delayed_set_alt+0x6c/0xef0\n kasan_report+0xe0/0x110\n ? tcm_delayed_set_alt+0x6c/0xef0\n tcm_delayed_set_alt+0x6c/0xef0\n ? __pfx_tcm_delayed_set_alt+0x10/0x10\n ? process_one_work+0x4cb/0xb90\n ? rcu_is_watching+0x20/0x50\n ? tcm_delayed_set_alt+0x9/0xef0\n process_one_work+0x4d7/0xb90\n ? __pfx_process_one_work+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __list_add_valid_or_report+0x37/0xf0\n ? __pfx_tcm_delayed_set_alt+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n worker_thread+0x2d8/0x570\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x1ad/0x1f0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x3c9/0x540\n ? __pfx_ret_from_fork+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __switch_to+0x2e9/0x730\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nAllocated by task 544:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n tcm_alloc+0x68/0x180\n usb_get_function+0x36/0x60\n config_usb_cfg_link+0x125/0x1b0\n configfs_symlink+0x322/0x890\n vfs_symlink+0xc2/0x270\n filename_symlinkat+0x295/0x2f0\n __x64_sys_symlinkat+0x62/0x90\n do_syscall_64+0x115/0x6a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 661:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x43/0x70\n kfree+0x2f9/0x530\n config_usb_cfg_unlink+0x173/0x1e0\n configfs_unlink+0x1fa/0x340\n vfs_unlink+0x15c/0x510\n filename_unlinkat+0x2ba/0x450\n __x64_sys_unlinkat+0x63/0x90\n do_syscall_64+0x115/0x6a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f","cvss":[],"epss":[{"cve":"CVE-2026-68367","epss":0.00184,"percentile":0.0814,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68367","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68368","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68368","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()  When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length against frame_max but does not verify that the datagram fits within the declared block length. Additionally, when decoding multiple NTBs from a single socket buffer, subsequent block lengths are not checked against the actual remaining buffer data.  With these checks missing, a malicious USB host can specify datagram offsets and lengths that point beyond the block, or supply secondary NTB headers declaring lengths larger than the buffer. skb_put_data() then copies adjacent kernel memory from skb_shared_info into the network skb.  Fix this by verifying that sufficient buffer space remains for the NTB header before parsing, handling zero-length block declarations, ensuring that block lengths never exceed the remaining buffer space, and verifying that each datagram payload stays strictly within the block boundary.","cvss":[],"epss":[{"cve":"CVE-2026-68368","epss":0.0021,"percentile":0.11272,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68368","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68368","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1febec7e47cdcd01f43fb0211094e3010474666e","https://git.kernel.org/stable/c/35d15bbaec0557330e774ec31412ef508de6e0e0","https://git.kernel.org/stable/c/40c706a0224bde194667e3378c689b542fec4b44","https://git.kernel.org/stable/c/41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c","https://git.kernel.org/stable/c/6b2be489eaa6293e60549005d91f15ceb150510f","https://git.kernel.org/stable/c/e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f","https://git.kernel.org/stable/c/f87ed889f0f7417b8938c98d8833f559b755373c","https://git.kernel.org/stable/c/fff1059d139ef798bab917990524faaf25854ca8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()\n\nWhen unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length\nagainst frame_max but does not verify that the datagram fits within the\ndeclared block length. Additionally, when decoding multiple NTBs from a\nsingle socket buffer, subsequent block lengths are not checked against the\nactual remaining buffer data.\n\nWith these checks missing, a malicious USB host can specify datagram\noffsets and lengths that point beyond the block, or supply secondary NTB\nheaders declaring lengths larger than the buffer. skb_put_data() then\ncopies adjacent kernel memory from skb_shared_info into the network skb.\n\nFix this by verifying that sufficient buffer space remains for the NTB\nheader before parsing, handling zero-length block declarations, ensuring\nthat block lengths never exceed the remaining buffer space, and verifying\nthat each datagram payload stays strictly within the block boundary.","cvss":[],"epss":[{"cve":"CVE-2026-68368","epss":0.0021,"percentile":0.11272,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68368","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68369","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68369","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: printer: fix infinite loop in printer_read()  printer_read() uses the same variable for the requested copy size and the number of bytes actually copied to user space. copy_to_user() returns the number of bytes not copied, so when it fails to copy anything, the computed copied length becomes zero.  In that case len, buf, current_rx_bytes and current_rx_buf are left unchanged. If RX data is available and the user buffer remains unwritable, the read loop can repeat indefinitely.  Track the copied length separately and return -EFAULT, or the number of bytes already copied, if an iteration makes no progress.","cvss":[],"epss":[{"cve":"CVE-2026-68369","epss":0.0021,"percentile":0.11273,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68369","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68369","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3081b0e187065c3b9577e393ad664b12854aeaf3","https://git.kernel.org/stable/c/3f81197364b57e5318620c75f3bd63f405f60552","https://git.kernel.org/stable/c/4cde0b38cc0cb8b7dc17295801015148de37d1d2","https://git.kernel.org/stable/c/994afccfdcceb73be33f69a8a8ea71e260c9eca5","https://git.kernel.org/stable/c/c2e819be6a5c7f34344926b4bd7e3dfca58cf48a","https://git.kernel.org/stable/c/e03597ad9494b500344076589aeaa6c6d2d381d3","https://git.kernel.org/stable/c/e225e2998e5a9b83c838dbbe4511fb0d63f88daf","https://git.kernel.org/stable/c/e41bbbbb1740ce4d7270ab1cdeca13892d6a8d2e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: printer: fix infinite loop in printer_read()\n\nprinter_read() uses the same variable for the requested copy size and\nthe number of bytes actually copied to user space. copy_to_user()\nreturns the number of bytes not copied, so when it fails to copy\nanything, the computed copied length becomes zero.\n\nIn that case len, buf, current_rx_bytes and current_rx_buf are left\nunchanged. If RX data is available and the user buffer remains\nunwritable, the read loop can repeat indefinitely.\n\nTrack the copied length separately and return -EFAULT, or the number of\nbytes already copied, if an iteration makes no progress.","cvss":[],"epss":[{"cve":"CVE-2026-68369","epss":0.0021,"percentile":0.11273,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68369","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68370","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68370","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback  dummy_hcd embeds a single shared usb_request (dum->fifo_req) that the \"emulated single-request FIFO\" fast-path in dummy_queue() reuses for small IN transfers: it copies the caller's request into it (req->req = *_req) and queues it, treating list_empty(&fifo_req.queue) as \"the slot is free\".  The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows the standard pattern: list_del_init(&req->queue) unlinks the request, then the lock is dropped and usb_gadget_giveback_request() invokes req->complete().  But list_del_init() makes fifo_req.queue look empty *before* the completion callback returns, so a concurrent dummy_queue() on another CPU sees the slot as free, reuses fifo_req and runs req->req = *_req -- overwriting req->complete while dummy_timer is mid-calling it.  The indirect call then jumps to a clobbered pointer, causing a general protection fault / page fault in dummy_timer (syzkaller extid faf3a6cf579fc65591ca).  The clobbering write is an in-bounds memcpy on a live shared object, so KASAN cannot flag it.  Add a fifo_req_busy bit covering the shared request's whole lifetime: set it in dummy_queue() when the FIFO fast-path takes fifo_req (making it the fast-path guard, replacing the list_empty(&fifo_req.queue) test), and clear it after the completion callback has returned, via a dummy_giveback() helper used at all four gadget-request giveback sites.  The shared slot can no longer be reused until its completion callback has finished.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68370","epss":0.00138,"percentile":0.03556,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-68370","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68370","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/16a685172abc9233728830e27d26ffa778975b51","https://git.kernel.org/stable/c/3cab0e5498d0fbb21fe1a9181f7bda9a844a697e","https://git.kernel.org/stable/c/67b589d09a96882d56842dced5698ed8dd06ce45","https://git.kernel.org/stable/c/95f30a21612cc65761c58ba044b1767699437317","https://git.kernel.org/stable/c/d5e5cd3654d2b5359a12ea6586120f05b28634ee","https://git.kernel.org/stable/c/e239ea91b48180ed48a86ac25643832a02c88456","https://git.kernel.org/stable/c/e24b33618231034bf01dfaff4fd3409d4b4d5b2e","https://git.kernel.org/stable/c/e2b2740f1242bc70b5b46da2cdbbaa419f490e59"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: dummy_hcd: prevent fifo_req reuse during giveback\n\ndummy_hcd embeds a single shared usb_request (dum->fifo_req) that the\n\"emulated single-request FIFO\" fast-path in dummy_queue() reuses for\nsmall IN transfers: it copies the caller's request into it\n(req->req = *_req) and queues it, treating list_empty(&fifo_req.queue)\nas \"the slot is free\".\n\nThe completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows\nthe standard pattern: list_del_init(&req->queue) unlinks the request,\nthen the lock is dropped and usb_gadget_giveback_request() invokes\nreq->complete().  But list_del_init() makes fifo_req.queue look empty\n*before* the completion callback returns, so a concurrent dummy_queue()\non another CPU sees the slot as free, reuses fifo_req and runs\nreq->req = *_req -- overwriting req->complete while dummy_timer is\nmid-calling it.  The indirect call then jumps to a clobbered pointer,\ncausing a general protection fault / page fault in dummy_timer\n(syzkaller extid faf3a6cf579fc65591ca).  The clobbering write is an\nin-bounds memcpy on a live shared object, so KASAN cannot flag it.\n\nAdd a fifo_req_busy bit covering the shared request's whole lifetime:\nset it in dummy_queue() when the FIFO fast-path takes fifo_req (making\nit the fast-path guard, replacing the list_empty(&fifo_req.queue)\ntest), and clear it after the completion callback has returned, via a\ndummy_giveback() helper used at all four gadget-request giveback\nsites.  The shared slot can no longer be reused until its completion\ncallback has finished.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68370","epss":0.00138,"percentile":0.03556,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68370","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68371","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68371","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: musb: omap2430: Do not put borrowed of_node in probe  omap2430_probe() stores pdev->dev.of_node in a local np variable. This is a borrowed pointer and the probe function does not take a reference to it.  The success and error paths nevertheless call of_node_put(np). This drops a reference that is owned by the platform device, and can leave pdev->dev.of_node with an unbalanced reference count.  Do not put the borrowed platform device node from omap2430_probe(). References taken for the child MUSB device are handled by the device core, and the ctrl-module phandle reference is still released separately.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68371","epss":0.00182,"percentile":0.07928,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.14469},"relatedVulnerabilities":[{"id":"CVE-2026-68371","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68371","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0950ac52426b0ab32d3b8cf4afe1711668b19cb8","https://git.kernel.org/stable/c/58d1c81c0b54a0b9aa6d6af077b09aa2f1bd2193","https://git.kernel.org/stable/c/6c525c851e5912b9753622d796f2bc55c4913b04","https://git.kernel.org/stable/c/c947360ae63eee1c9eacc030dd6f5a53f717addf","https://git.kernel.org/stable/c/eed56f105a7f70cbcfceb4df6deb6870fc58214d","https://git.kernel.org/stable/c/f0e68402d13cd9ffb289da50e65d4429d0002174"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: musb: omap2430: Do not put borrowed of_node in probe\n\nomap2430_probe() stores pdev->dev.of_node in a local np variable. This is\na borrowed pointer and the probe function does not take a reference to\nit.\n\nThe success and error paths nevertheless call of_node_put(np). This drops\na reference that is owned by the platform device, and can leave\npdev->dev.of_node with an unbalanced reference count.\n\nDo not put the borrowed platform device node from omap2430_probe().\nReferences taken for the child MUSB device are handled by the device core,\nand the ctrl-module phandle reference is still released separately.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68371","epss":0.00182,"percentile":0.07928,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68371","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68373","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68373","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()  at76_guess_freq() checks only that the received frame is at least a bare 802.11 header (24 bytes) before subtracting the fixed management-body offset:  \tlen -= el_off;  For both beacon and probe response frames, el_off is 36. If the frame is shorter than el_off, subtracting it causes the calculated IE length to wrap. The length is eventually passed to cfg80211_find_elem_match() as a very large unsigned value, so the element walk runs beyond the RX skb.  This path is reached from at76_rx_tasklet() while scanning. If the device delivers a truncated beacon or probe response, the oversized IE length causes an out-of-bounds read during scanning.  Skip the IE lookup if the frame does not reach the variable elements, before subtracting el_off.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68373","epss":0.00277,"percentile":0.20022,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.21606},"relatedVulnerabilities":[{"id":"CVE-2026-68373","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68373","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4875680d1703f56afa6257ba30244f2fb44ed205","https://git.kernel.org/stable/c/61a799ffd1e5a4fd3702d547828b7ff3d161468e","https://git.kernel.org/stable/c/b406f33d234f98c8b310fdab5cbb492d85e98e49","https://git.kernel.org/stable/c/bcde7249d45f52f994a9872bedf45994472ade77","https://git.kernel.org/stable/c/cb831aff2f850f72bc5ff5ad77d0a70bb5a84061","https://git.kernel.org/stable/c/e165a1d295e7e814e13b0f92c86e5d48309509ce","https://git.kernel.org/stable/c/f742d9c98b5c504fc9e6744eef13a721c2aea486","https://git.kernel.org/stable/c/fb1b50ab699211e777dca5ccfb648788b6a6e519"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: at76c50x-usb: avoid length underflow in at76_guess_freq()\n\nat76_guess_freq() checks only that the received frame is at least a bare\n802.11 header (24 bytes) before subtracting the fixed management-body\noffset:\n\n\tlen -= el_off;\n\nFor both beacon and probe response frames, el_off is 36. If the frame is\nshorter than el_off, subtracting it causes the calculated IE length to\nwrap. The length is eventually passed to cfg80211_find_elem_match() as a\nvery large unsigned value, so the element walk runs beyond the RX skb.\n\nThis path is reached from at76_rx_tasklet() while scanning. If the device\ndelivers a truncated beacon or probe response, the oversized IE length\ncauses an out-of-bounds read during scanning.\n\nSkip the IE lookup if the frame does not reach the variable elements,\nbefore subtracting el_off.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68373","epss":0.00277,"percentile":0.20022,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68373","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68376","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: fix auth_hmacs array size in struct sctp_cookie  The auth_hmacs array in struct sctp_cookie is supposed to store a complete SCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr followed by N HMAC identifiers.  However, the array size was calculated using an extra 2 bytes instead of sizeof(struct sctp_paramhdr), which is 4 bytes. When four HMAC identifiers are configured, the HMAC-ALGO parameter stored in the endpoint is larger than the auth_hmacs buffer in the cookie.  As a result, sctp_association_init() copies beyond the end of auth_hmacs when initializing the association, corrupting the adjacent auth_chunks field. This can lead to an invalid HMAC identifier being accepted and later cause an out-of-bounds read in sctp_auth_get_hmac().  Fix the array size calculation by including the full SCTP parameter header size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68376","epss":0.00475,"percentile":0.39584,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3705},"relatedVulnerabilities":[{"id":"CVE-2026-68376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68376","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0528485f27016a42804abe01aa61b39d85fa803e","https://git.kernel.org/stable/c/0b4414e43e0861d67276031cc21401d7e87de3da","https://git.kernel.org/stable/c/317731d01b03c529809df36d3a7d149677a8729d","https://git.kernel.org/stable/c/3aa40c3bccac2312ea7cf97f329190637f972b5d","https://git.kernel.org/stable/c/a8d20ba0ab518c9ccbcde258f25fc1ee6e51d5db","https://git.kernel.org/stable/c/d0a59ba58578e2b330fff80a44fe519f3ba7d8c7","https://git.kernel.org/stable/c/e0b5252a59383b77d1b8dbeda00b7184dd95f4d3","https://git.kernel.org/stable/c/ee5e65964f456adfe14d526fba0bd055de98ecf3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix auth_hmacs array size in struct sctp_cookie\n\nThe auth_hmacs array in struct sctp_cookie is supposed to store a complete\nSCTP_AUTH_HMAC_ALGO parameter, which consists of a struct sctp_paramhdr\nfollowed by N HMAC identifiers.\n\nHowever, the array size was calculated using an extra 2 bytes instead of\nsizeof(struct sctp_paramhdr), which is 4 bytes. When four HMAC identifiers\nare configured, the HMAC-ALGO parameter stored in the endpoint is larger\nthan the auth_hmacs buffer in the cookie.\n\nAs a result, sctp_association_init() copies beyond the end of auth_hmacs\nwhen initializing the association, corrupting the adjacent auth_chunks\nfield. This can lead to an invalid HMAC identifier being accepted and later\ncause an out-of-bounds read in sctp_auth_get_hmac().\n\nFix the array size calculation by including the full SCTP parameter header\nsize.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.3,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68376","epss":0.00475,"percentile":0.39584,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68376","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68377","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68377","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: act_tunnel_key: Defer dst_release to RCU callback  Fix a race-condition use-after-free in tunnel_key_release_params().  The function releases the metadata_dst of the old params synchronously via dst_release() while deferring the params struct free with kfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may still hold the old params pointer (under rcu_read_lock_bh) and proceed to call dst_clone(&params->tcft_enc_metadata->dst) after the writer's dst_release has already pushed the dst's rcuref to RCUREF_DEAD.  zdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified that KASAN reports:  ================================================================== BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 BUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326 BUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109 BUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173 BUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168 Write of size 4 at addr ffff88806158de40 by task poc/9388  CPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G        W           7.1.0-rc7 #7 PREEMPT(lazy) Tainted: [W]=WARN Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace:  <TASK>  __dump_stack lib/dump_stack.c:94  dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:378  print_report+0x139/0x4ad mm/kasan/report.c:482  kasan_report+0xe4/0x1d0 mm/kasan/report.c:595  check_region_inline mm/kasan/generic.c:186  kasan_check_range+0x125/0x200 mm/kasan/generic.c:200  instrument_atomic_read_write include/linux/instrumented.h:112  atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326  __rcuref_put include/linux/rcuref.h:109  rcuref_put include/linux/rcuref.h:173  dst_release+0x5b/0x370 net/core/dst.c:168  refdst_drop include/net/dst.h:272  skb_dst_drop include/net/dst.h:284  skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163  skb_release_all net/core/skbuff.c:1187 [..] Allocated by task 9391:  kasan_save_stack+0x30/0x50 mm/kasan/common.c:57  kasan_save_track+0x14/0x30 mm/kasan/common.c:78  poison_kmalloc_redzone mm/kasan/common.c:398  __kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415  kasan_kmalloc include/linux/kasan.h:263  __do_kmalloc_node mm/slub.c:5296  __kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308  kmalloc_noprof include/linux/slab.h:954  kzalloc_noprof include/linux/slab.h:1188  offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35  tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258  tcf_action_offload_add net/sched/act_api.c:293  tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547  tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101 [..] Freed by task 9391:  kasan_save_stack+0x30/0x50 mm/kasan/common.c:57  kasan_save_track+0x14/0x30 mm/kasan/common.c:78  kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584  poison_slab_object mm/kasan/common.c:253  __kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285  kasan_slab_free include/linux/kasan.h:235  slab_free_hook mm/slub.c:2689  slab_free mm/slub.c:6251  kfree+0x21f/0x6b0 mm/slub.c:6566  tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284  tcf_action_offload_add net/sched/act_api.c:293  tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547  tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101  The buggy address belongs to the object at ffff88806158de00  which belongs to the cache kmalloc-256 of size 256 The buggy address is located 64 bytes inside of  freed 256-byte region [ffff88806158de00, ffff88806158df00)  The buggy address belongs to the physical page: page: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c head: order:1 mapcount:0 entire_map ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68377","epss":0.00128,"percentile":0.02731,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09792000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-68377","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68377","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2200a00ff247f70f5dcdb4e6f14b0d48ddac5467","https://git.kernel.org/stable/c/2791a501da508b704a617b4dba29db54a65bc9f7","https://git.kernel.org/stable/c/389d03992dabb80488228e8119b9dd6d0f58e1a6","https://git.kernel.org/stable/c/531dbb5bb98e52ad26be7e90f9f8bec707c5bd0e","https://git.kernel.org/stable/c/676ad6aa7cec89a08d2a5ce3cd5959e313f29733","https://git.kernel.org/stable/c/b5931f020b681fdcb9378262d89b61cb3c7ebbf8","https://git.kernel.org/stable/c/f1f5c8a3955f8fda3f84ed883ac8daa1847e724c","https://git.kernel.org/stable/c/fed1b1ddab41a0e7a462ac690a0c8af6ff793624"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_tunnel_key: Defer dst_release to RCU callback\n\nFix a race-condition use-after-free in tunnel_key_release_params().\n\nThe function releases the metadata_dst of the old params synchronously\nvia dst_release() while deferring the params struct free with\nkfree_rcu(). A concurrent tunnel_key_act() reader on the datapath may\nstill hold the old params pointer (under rcu_read_lock_bh) and proceed\nto call dst_clone(&params->tcft_enc_metadata->dst) after the writer's\ndst_release has already pushed the dst's rcuref to RCUREF_DEAD.\n\nzdi-disclosures@trendmicro.com produced a poc which i (and Victor) verified\nthat KASAN reports:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112\nBUG: KASAN: slab-use-after-free in atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326\nBUG: KASAN: slab-use-after-free in __rcuref_put include/linux/rcuref.h:109\nBUG: KASAN: slab-use-after-free in rcuref_put include/linux/rcuref.h:173\nBUG: KASAN: slab-use-after-free in dst_release+0x5b/0x370 net/core/dst.c:168\nWrite of size 4 at addr ffff88806158de40 by task poc/9388\n\nCPU: 0 UID: 0 PID: 9388 Comm: poc Tainted: G        W           7.1.0-rc7 #7 PREEMPT(lazy)\nTainted: [W]=WARN\nHardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94\n dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378\n print_report+0x139/0x4ad mm/kasan/report.c:482\n kasan_report+0xe4/0x1d0 mm/kasan/report.c:595\n check_region_inline mm/kasan/generic.c:186\n kasan_check_range+0x125/0x200 mm/kasan/generic.c:200\n instrument_atomic_read_write include/linux/instrumented.h:112\n atomic_sub_return_release include/linux/atomic/atomic-instrumented.h:326\n __rcuref_put include/linux/rcuref.h:109\n rcuref_put include/linux/rcuref.h:173\n dst_release+0x5b/0x370 net/core/dst.c:168\n refdst_drop include/net/dst.h:272\n skb_dst_drop include/net/dst.h:284\n skb_release_head_state+0x293/0x400 net/core/skbuff.c:1163\n skb_release_all net/core/skbuff.c:1187\n[..]\nAllocated by task 9391:\n kasan_save_stack+0x30/0x50 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398\n __kasan_kmalloc+0x9a/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263\n __do_kmalloc_node mm/slub.c:5296\n __kmalloc_noprof+0x2f1/0x830 mm/slub.c:5308\n kmalloc_noprof include/linux/slab.h:954\n kzalloc_noprof include/linux/slab.h:1188\n offload_action_alloc+0x2f/0x130 net/core/flow_offload.c:35\n tcf_action_offload_add_ex+0x1ba/0x880 net/sched/act_api.c:258\n tcf_action_offload_add net/sched/act_api.c:293\n tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547\n tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101\n[..]\nFreed by task 9391:\n kasan_save_stack+0x30/0x50 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n kasan_save_free_info+0x3b/0x70 mm/kasan/generic.c:584\n poison_slab_object mm/kasan/common.c:253\n __kasan_slab_free+0x6b/0x90 mm/kasan/common.c:285\n kasan_slab_free include/linux/kasan.h:235\n slab_free_hook mm/slub.c:2689\n slab_free mm/slub.c:6251\n kfree+0x21f/0x6b0 mm/slub.c:6566\n tcf_action_offload_add_ex+0x4ad/0x880 net/sched/act_api.c:284\n tcf_action_offload_add net/sched/act_api.c:293\n tcf_action_init+0x66e/0xa20 net/sched/act_api.c:1547\n tcf_action_add+0xf6/0x5d0 net/sched/act_api.c:2101\n\nThe buggy address belongs to the object at ffff88806158de00\n which belongs to the cache kmalloc-256 of size 256\nThe buggy address is located 64 bytes inside of\n freed 256-byte region [ffff88806158de00, ffff88806158df00)\n\nThe buggy address belongs to the physical page:\npage: refcount:0 mapcount:0 mapping:0000000000000000 index:0xffff88806158d600 pfn:0x6158c\nhead: order:1 mapcount:0 entire_map\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68377","epss":0.00128,"percentile":0.02731,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68377","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68386","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68386","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf, sockmap: Reject unhashed UDP sockets on sockmap update  UDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means sk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false.  Because sockmap accepts unbound UDP sockets, a BPF program can increment a socket's refcount via lookup. If the socket is subsequently bound, the transition from unbound to bound causes bpf_sk_release() to skip the decrement of the refcount, causing a memory leak.  unreferenced object 0xffff88810bc2eb40 (size 1984):   comm \"test_progs\", pid 2451, jiffies 4295320596   hex dump (first 32 bytes):     7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00  ................     02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00  ...@............   backtrace (crc bdee079d):     kmem_cache_alloc_noprof+0x557/0x660     sk_prot_alloc+0x69/0x240     sk_alloc+0x30/0x460     inet_create+0x2ce/0xf80     __sock_create+0x25b/0x5c0     __sys_socket+0x119/0x1d0     __x64_sys_socket+0x72/0xd0     do_syscall_64+0xa1/0x5f0     entry_SYSCALL_64_after_hwframe+0x76/0x7e  Instead of special-casing for refcounted sockets, reject unhashed UDP sockets during sockmap updates, as there is no benefit to supporting those. This effectively reverts the commit under Fixes, with two exceptions:  1. sock_map_sk_state_allowed() maintains a fall-through `return true`. 2. In the spirit of commit b8b8315e39ff (\"bpf, sockmap: Remove unhash    handler for BPF sockmap usage\"), the proto::unhash BPF handler is not    reintroduced.  Historical note: this issue is related to commit 67312adc96b5 (\"bpf: reject unhashed sockets in bpf_sk_assign\").","cvss":[],"epss":[{"cve":"CVE-2026-68386","epss":0.00205,"percentile":0.10657,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10250000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68386","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68386","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/17b7ef6b86112a4e61cee1e9009a4b318e3225c5","https://git.kernel.org/stable/c/2271276ac5279d2d204be7739a1a28d4ef6cf608","https://git.kernel.org/stable/c/250474c69bc3fc48a5fc21d7c349f279caad947a","https://git.kernel.org/stable/c/66efd3368ae10d05e08fbe6425b50fdec7186ac7","https://git.kernel.org/stable/c/7ffe529e7127411806c8692fb1490f552c629dc2","https://git.kernel.org/stable/c/8692655da369961128658cf8539334b6a960ecb0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Reject unhashed UDP sockets on sockmap update\n\nUDP sockets get SOCK_RCU_FREE set when (auto-)bound. This means\nsk_is_refcounted(unbound) = true, while sk_is_refcounted(bound) = false.\n\nBecause sockmap accepts unbound UDP sockets, a BPF program can increment a\nsocket's refcount via lookup. If the socket is subsequently bound, the\ntransition from unbound to bound causes bpf_sk_release() to skip the\ndecrement of the refcount, causing a memory leak.\n\nunreferenced object 0xffff88810bc2eb40 (size 1984):\n  comm \"test_progs\", pid 2451, jiffies 4295320596\n  hex dump (first 32 bytes):\n    7f 00 00 01 7f 00 00 01 d2 04 1b b7 04 d2 00 00  ................\n    02 00 01 40 00 00 00 00 00 00 00 00 00 00 00 00  ...@............\n  backtrace (crc bdee079d):\n    kmem_cache_alloc_noprof+0x557/0x660\n    sk_prot_alloc+0x69/0x240\n    sk_alloc+0x30/0x460\n    inet_create+0x2ce/0xf80\n    __sock_create+0x25b/0x5c0\n    __sys_socket+0x119/0x1d0\n    __x64_sys_socket+0x72/0xd0\n    do_syscall_64+0xa1/0x5f0\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nInstead of special-casing for refcounted sockets, reject unhashed UDP\nsockets during sockmap updates, as there is no benefit to supporting those.\nThis effectively reverts the commit under Fixes, with two exceptions:\n\n1. sock_map_sk_state_allowed() maintains a fall-through `return true`.\n2. In the spirit of commit b8b8315e39ff (\"bpf, sockmap: Remove unhash\n   handler for BPF sockmap usage\"), the proto::unhash BPF handler is not\n   reintroduced.\n\nHistorical note: this issue is related to commit 67312adc96b5 (\"bpf: reject\nunhashed sockets in bpf_sk_assign\").","cvss":[],"epss":[{"cve":"CVE-2026-68386","epss":0.00205,"percentile":0.10657,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68386","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68388","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68388","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb/client: handle overlapping allocated ranges in fallocate  smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped hole is not zero-filled, but fallocate still returns success. A later write to that hole may therefore fail with ENOSPC.  The function queries allocated ranges so that it can preserve existing contents and write zeroes only into holes. However, the server may return a range that starts before the current fallocate offset.  For example, assume the fallocate request is [100, 400) and the only allocated range returned by the server is [0, 200):          Request:      [100, 400)         Server range: [  0, 200)  allocated          Correct:         [100, 200)    allocated data, skip         [200, 400)    hole, zero-fill          Current:         [100, 300)    skipped         [300, 400)    zero-filled afterwards  The current code adds the full server range length, 200, to the current offset 100 and moves to 300. As a result, the hole in [200, 300) is skipped without being zero-filled.  Fix this by advancing only over the part of the allocated range that overlaps the current fallocate offset.  Ignore ranges that end before the current offset and reject ranges whose end offset overflows.  This also prevents a malformed range length from causing an out-of-bounds zero-buffer read.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68388","epss":0.00514,"percentile":0.42127,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48316000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-68388","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68388","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/01719883235507b1585e4c51e320d9a7113dc698","https://git.kernel.org/stable/c/377fe3e583e46369ee1004d5cfe12271d6589a68","https://git.kernel.org/stable/c/437637f5ff3f573b2edf8571de91fb00a21eb4e6","https://git.kernel.org/stable/c/7e08ab7a061b17ac1989a225c6afb53f44a86808","https://git.kernel.org/stable/c/a4a09e5142835633fffbde68bd0a039ba4d4bf97","https://git.kernel.org/stable/c/aeb58a4eb39a7ff4d7782b4f4ada0fda5e0675d2","https://git.kernel.org/stable/c/b09ae45d85dc816987a71db9eebc54b0ae288e94","https://git.kernel.org/stable/c/f47c7277c03a636fcc3a57969f2dc09567b3c050"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: handle overlapping allocated ranges in fallocate\n\nsmb3_simple_fallocate_range() can skip holes when an allocated range\nreturned by the server starts before the current fallocate offset. The\nskipped hole is not zero-filled, but fallocate still returns success. A\nlater write to that hole may therefore fail with ENOSPC.\n\nThe function queries allocated ranges so that it can preserve existing\ncontents and write zeroes only into holes. However, the server may return\na range that starts before the current fallocate offset.\n\nFor example, assume the fallocate request is [100, 400) and the only\nallocated range returned by the server is [0, 200):\n\n        Request:      [100, 400)\n        Server range: [  0, 200)  allocated\n\n        Correct:\n        [100, 200)    allocated data, skip\n        [200, 400)    hole, zero-fill\n\n        Current:\n        [100, 300)    skipped\n        [300, 400)    zero-filled afterwards\n\nThe current code adds the full server range length, 200, to the current\noffset 100 and moves to 300. As a result, the hole in [200, 300) is\nskipped without being zero-filled.\n\nFix this by advancing only over the part of the allocated range that\noverlaps the current fallocate offset.  Ignore ranges that end before the\ncurrent offset and reject ranges whose end offset overflows.\n\nThis also prevents a malformed range length from causing an out-of-bounds\nzero-buffer read.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68388","epss":0.00514,"percentile":0.42127,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68388","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68391","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68391","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds  Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF.  Use of hci_conn in hci_sync callbacks also needs to hold refcount to avoid UAF.  Take appropriate locks for hci_conn lookups, and take refcount for hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays valid.  When accessing conn->state, ensure hdev->lock is held to avoid data race.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68391","epss":0.00129,"percentile":0.02831,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68391","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68391","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/b56f2ecafc08f372bf0529f9c4f3f429cb1702dc","https://git.kernel.org/stable/c/d5b3b484b62bb0f4542e7622789d28871626cdf0","https://git.kernel.org/stable/c/da55f570191d5d72f10c607a7043b947eb05ea46","https://git.kernel.org/stable/c/ecdcb55ea1c01dda074406f38058785a69526734","https://git.kernel.org/stable/c/f915e74b6f18293d1d69a2a3305ef321ff7c0172"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds\n\nDereferencing RCU-protected pointers outside critical sections is\ninvalid and may lead to UAF.  Use of hci_conn in hci_sync callbacks also\nneeds to hold refcount to avoid UAF.\n\nTake appropriate locks for hci_conn lookups, and take refcount for\nhci_conn pointers stored in mgmt_pending_cmd so that the pointer stays\nvalid.\n\nWhen accessing conn->state, ensure hdev->lock is held to avoid data\nrace.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68391","epss":0.00129,"percentile":0.02831,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68391","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68395","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68395","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered  sata_dwc_enable_interrupts() is called before platform_get_irq() and ata_host_activate(), leaving the SATA controller's interrupt mask enabled without a registered handler.  If a later step fails (irq request, phy init, etc.) or if the controller asserts an interrupt during probe, the irq line may fire with no handler, causing a spurious interrupt storm.  Move sata_dwc_enable_interrupts() after ata_host_activate() so that interrupts are only unmasked once the handler is registered and the core is fully initialized.","cvss":[],"epss":[{"cve":"CVE-2026-68395","epss":0.0021,"percentile":0.1127,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68395","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68395","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/23d4c50fdc0dfe3ad4f9647a3b7d486de807dcda","https://git.kernel.org/stable/c/4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0","https://git.kernel.org/stable/c/5d0797d6940b8dc894f950c52f7af0b42cb55ed0","https://git.kernel.org/stable/c/60b922442e9c208832e2699f128ef078f9f50faa","https://git.kernel.org/stable/c/8fbad29f399ba11c3b070ef5baf1c4b3e13ed838","https://git.kernel.org/stable/c/d031957a6284e03c709f95cb8fc6f8891d4432ba","https://git.kernel.org/stable/c/daa80b422ed920a3c0c45153020b0ad7af7fb5a5","https://git.kernel.org/stable/c/fbe7df5d3a3aed2456667a4825e4ff98d6df6ca4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered\n\nsata_dwc_enable_interrupts() is called before platform_get_irq() and\nata_host_activate(), leaving the SATA controller's interrupt mask\nenabled without a registered handler.  If a later step fails (irq\nrequest, phy init, etc.) or if the controller asserts an interrupt\nduring probe, the irq line may fire with no handler, causing a\nspurious interrupt storm.\n\nMove sata_dwc_enable_interrupts() after ata_host_activate() so that\ninterrupts are only unmasked once the handler is registered and the\ncore is fully initialized.","cvss":[],"epss":[{"cve":"CVE-2026-68395","epss":0.0021,"percentile":0.1127,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68395","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68396","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68396","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: core: wake eh reliably when using scsi_schedule_eh  Drivers which use the scsi_schedule_eh function to run the error handler currently risk the error handler thread never waking once all commands are timed out or inactive. There is no enforced memory order between setting the host into error recovery state and counting busy commands. This can result in a race with scsi_dec_host_busy where neither CPU sees both conditions of all commands inactive and the host error state to request waking the error handler.  To fix this, run the scsi_schedule_eh's scsi_eh_wakeup from a new work item which will use rcu to ensure scsi_schedule_eh's call to scsi_host_busy will occur after the error state is globally visible and will be seen by any current scsi_dec_host_busy callers.","cvss":[],"epss":[{"cve":"CVE-2026-68396","epss":0.002,"percentile":0.09908,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-68396","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68396","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/24d7abda6a2a19e113334accc10029f6a4b57257","https://git.kernel.org/stable/c/866efe8ae8b8b4d095501001b026e1022734be28","https://git.kernel.org/stable/c/c7a15091237205770bd9bd4d14eb1f3029d97a34","https://git.kernel.org/stable/c/dccf3b1798b70f94e958b3d00b83010399e6fb05"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: wake eh reliably when using scsi_schedule_eh\n\nDrivers which use the scsi_schedule_eh function to run the error handler\ncurrently risk the error handler thread never waking once all commands are\ntimed out or inactive. There is no enforced memory order between setting\nthe host into error recovery state and counting busy commands. This can\nresult in a race with scsi_dec_host_busy where neither CPU sees both\nconditions of all commands inactive and the host error state to request\nwaking the error handler.\n\nTo fix this, run the scsi_schedule_eh's scsi_eh_wakeup from a new work item\nwhich will use rcu to ensure scsi_schedule_eh's call to scsi_host_busy will\noccur after the error state is globally visible and will be seen by any\ncurrent scsi_dec_host_busy callers.","cvss":[],"epss":[{"cve":"CVE-2026-68396","epss":0.002,"percentile":0.09908,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68396","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68397","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68397","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/iucv: take a reference on the socket found in afiucv_hs_rcv()  afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock, drops the lock, and then passes the socket to the afiucv_hs_callback_*() handlers without holding a reference. AF_IUCV sockets are not RCU-protected and are freed synchronously by iucv_sock_kill() -> sock_put(), so a concurrent close can free the socket in the window between read_unlock() and the handler, which then dereferences freed memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).  Take a reference with sock_hold() while the socket is still on the list and release it with sock_put() once the handler has run.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68397","epss":0.00266,"percentile":0.18395,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.21679000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-68397","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68397","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1801cb20a5025a787d6853e19c38db138344b4b4","https://git.kernel.org/stable/c/4dc0e63abf8bc7ba8892e617c1fb8b204361e022","https://git.kernel.org/stable/c/4fa349156043dc119721d067329714179f501749","https://git.kernel.org/stable/c/5595ea59cdf29182cf6a270cacc1426c57b603de","https://git.kernel.org/stable/c/5739be5c19495d709d902a2912c9102ce78740d5","https://git.kernel.org/stable/c/bc6c6e546ffff8865daaeb622ef348c2d481e80f","https://git.kernel.org/stable/c/c75a950e77356e526672cba4584080c6c8b793b6","https://git.kernel.org/stable/c/e3e0679fc950191aff8f27fa78abcfc2462cff4a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: take a reference on the socket found in afiucv_hs_rcv()\n\nafiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,\ndrops the lock, and then passes the socket to the afiucv_hs_callback_*()\nhandlers without holding a reference. AF_IUCV sockets are not\nRCU-protected and are freed synchronously by iucv_sock_kill() ->\nsock_put(), so a concurrent close can free the socket in the window\nbetween read_unlock() and the handler, which then dereferences freed\nmemory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).\n\nTake a reference with sock_hold() while the socket is still on the list\nand release it with sock_put() once the handler has run.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68397","epss":0.00266,"percentile":0.18395,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68397","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68398","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68398","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF  pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:   l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv()    -> ppp_input(&po->chan)  It runs under rcu_read_lock() holding only an l2tp_session reference and takes NO reference on the internal PPP channel (struct channel, chan->ppp) that ppp_input() dereferences.  The pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel are RCU-safe.  But the internal struct channel is a separate allocation that ppp_release_channel() frees with a plain kfree():   close(data socket) -> pppol2tp_release() -> pppox_unbind_sock()    -> ppp_unregister_channel() -> ppp_release_channel() -> kfree(pch)  For a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit (no PPPIOCCONNECT, pch->ppp == NULL) and not bridged, teardown skips both ppp_disconnect_channel()'s synchronize_net() and ppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace period.  rcu_read_lock() in pppol2tp_recv() does not protect against a plain kfree(), so an in-flight ppp_input() on one CPU can dereference the channel just freed by close() on another CPU.  The bug is reachable by an unprivileged user.  Defer the channel free to an RCU callback via call_rcu() so the grace period fences any in-flight ppp_input(). The disconnect and unbridge teardown paths already fence with synchronize_net()/synchronize_rcu(); call_rcu() does the same here without stalling the close() path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68398","epss":0.00195,"percentile":0.09319,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.149175},"relatedVulnerabilities":[{"id":"CVE-2026-68398","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68398","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/06213c85d8c0994f786c093b8b2a517987943ca6","https://git.kernel.org/stable/c/110b765744b147c63882f5e9cb12931c5dc8d85f","https://git.kernel.org/stable/c/3ab32218d7182705dae5c86f13925f458072da2c","https://git.kernel.org/stable/c/4bb84e964ff0fe0a171c965362de72f9820dbce9","https://git.kernel.org/stable/c/4e47f1ac188ece11d6fdabe44166a2776cc5bd4e","https://git.kernel.org/stable/c/c9574b8a8edeb4edd3ac6472c27ef7184bdb2baa","https://git.kernel.org/stable/c/ec4215683e47424c9c4762fd3c60f552a3119142"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF\n\npppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:\n\n l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv()\n   -> ppp_input(&po->chan)\n\nIt runs under rcu_read_lock() holding only an l2tp_session reference and\ntakes NO reference on the internal PPP channel (struct channel,\nchan->ppp) that ppp_input() dereferences.\n\nThe pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel\nare RCU-safe.  But the internal struct channel is a separate allocation\nthat ppp_release_channel() frees with a plain kfree():\n\n close(data socket) -> pppol2tp_release() -> pppox_unbind_sock()\n   -> ppp_unregister_channel() -> ppp_release_channel() -> kfree(pch)\n\nFor a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit\n(no PPPIOCCONNECT, pch->ppp == NULL) and not bridged, teardown skips\nboth ppp_disconnect_channel()'s synchronize_net() and\nppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace\nperiod.  rcu_read_lock() in pppol2tp_recv() does not protect against a\nplain kfree(), so an in-flight ppp_input() on one CPU can dereference\nthe channel just freed by close() on another CPU.\n\nThe bug is reachable by an unprivileged user.\n\nDefer the channel free to an RCU callback via call_rcu() so the grace\nperiod fences any in-flight ppp_input(). The disconnect and unbridge\nteardown paths already fence with synchronize_net()/synchronize_rcu();\ncall_rcu() does the same here without stalling the close() path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68398","epss":0.00195,"percentile":0.09319,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68398","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68399","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68399","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix UAF in sock clone early bailouts  Similar to recent commit 9b51a6155d14 (\"bpf,fork: wipe ->bpf_storage before bailouts that access it\"), sk_clone() performs an initial shallow copy of the socket field ->sk_bpf_storage via sock_copy() for the cloned socket newsk.  If sk_clone() bails out early (e.g. if sk_filter_charge() fails) prior to calling bpf_sk_storage_clone(), newsk->sk_bpf_storage still points to the parent socket's BPF local storage. When newsk is subsequently freed via sk_free(), the deallocation path (__sk_destruct() -> bpf_sk_storage_free()) destroys the parent socket's BPF local storage, leading to a use-after-free (UAF) on the parent socket.  Fix this by resetting newsk->sk_bpf_storage to NULL immediately after sock_copy() in sk_clone(), and remove the now redundant initialization from bpf_sk_storage_clone().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68399","epss":0.00129,"percentile":0.02884,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68399","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68399","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/14b49b5ab29979552c219a09e569b424fbbf4a6e","https://git.kernel.org/stable/c/7cbd0c4cebe4c9f678d15e6b9ba975e1155a107f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix UAF in sock clone early bailouts\n\nSimilar to recent commit 9b51a6155d14 (\"bpf,fork: wipe ->bpf_storage\nbefore bailouts that access it\"), sk_clone() performs an initial\nshallow copy of the socket field ->sk_bpf_storage via sock_copy()\nfor the cloned socket newsk.\n\nIf sk_clone() bails out early (e.g. if sk_filter_charge() fails) prior\nto calling bpf_sk_storage_clone(), newsk->sk_bpf_storage still points\nto the parent socket's BPF local storage. When newsk is subsequently\nfreed via sk_free(), the deallocation path (__sk_destruct() ->\nbpf_sk_storage_free()) destroys the parent socket's BPF local storage,\nleading to a use-after-free (UAF) on the parent socket.\n\nFix this by resetting newsk->sk_bpf_storage to NULL immediately after\nsock_copy() in sk_clone(), and remove the now redundant initialization\nfrom bpf_sk_storage_clone().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68399","epss":0.00129,"percentile":0.02884,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68399","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68401","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()  Sashiko (locally) reports multiple out-of-bound issues in ffa_setup_and_transmit: 1) Writing ep_mem_access->reserved can write out of bounds for FFA    versions < 1.2 as ffa_emad_size_get() returns 16 bytes in that case    while reserved has an offset of 24.    Instead of zeroing fields, memset the struct to zero first based on    the FFA version.  2) Make sure there is enough size to write constituents.  While at it, convert the only sizeof() in the driver that uses a type instead of variable.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68401","epss":0.00136,"percentile":0.03392,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10404000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68401","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/27abdaf0c5c89b06694e4c3d8318e8d6a60c1d1b","https://git.kernel.org/stable/c/3383ffb7ef937317361713ffcc21921a7848511a","https://git.kernel.org/stable/c/cf5708c9d78c98214c62b1e5d049cd527a543b8e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()\n\nSashiko (locally) reports multiple out-of-bound issues in\nffa_setup_and_transmit:\n1) Writing ep_mem_access->reserved can write out of bounds for FFA\n   versions < 1.2 as ffa_emad_size_get() returns 16 bytes in that case\n   while reserved has an offset of 24.\n   Instead of zeroing fields, memset the struct to zero first based on\n   the FFA version.\n\n2) Make sure there is enough size to write constituents.\n\nWhile at it, convert the only sizeof() in the driver that uses a\ntype instead of variable.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68401","epss":0.00136,"percentile":0.03392,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68402","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68402","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: cfg80211: bound element ID read when checking non-inheritance  cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem->data[0]) to look it up in an extension non-inheritance list. It does so after testing elem->id, but without verifying that the element actually has a data octet. A zero-length extension element (WLAN_EID_EXTENSION with length 0) therefore makes it read one octet past the end of the element.  _ieee802_11_parse_elems_full() runs this check for every element of a frame once a non-inheritance context exists -- e.g. while parsing a per-STA profile of a Multi-Link element in a (re)association response, or a non-transmitted BSS profile -- so a crafted frame from an AP can trigger a one-octet slab-out-of-bounds read during element parsing:    BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited   Read of size 1 ... in net/wireless/scan.c  Return early (treat the element as inherited) when an extension element carries no data, mirroring the existing handling of empty ID lists.  The bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68402","epss":0.00268,"percentile":0.18856,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.19564},"relatedVulnerabilities":[{"id":"CVE-2026-68402","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68402","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/11ac7a5e75f5132f1778e0c60981d30dc29fb869","https://git.kernel.org/stable/c/20c308d9a57722801961f816395bf825f7bde6bc","https://git.kernel.org/stable/c/24154c172246ae3f0e69bb17c9111095685ceedc","https://git.kernel.org/stable/c/2d31ebb26a14f103c9cdc5287fb20cb2d4bde901","https://git.kernel.org/stable/c/521dd5fe6d12b0d3c275f919738dc3a07117f4a5","https://git.kernel.org/stable/c/84bd907361c56fbd5523eceb2682cb39da059bd5","https://git.kernel.org/stable/c/cb8afea4655ff004fa7feee825d5c79783525383","https://git.kernel.org/stable/c/ddf2773bcc8e49a43c561f22ec1e7924215d7947"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: bound element ID read when checking non-inheritance\n\ncfg80211_is_element_inherited() reads the first data octet of the\ncandidate element (id = elem->data[0]) to look it up in an extension\nnon-inheritance list. It does so after testing elem->id, but without\nverifying that the element actually has a data octet. A zero-length\nextension element (WLAN_EID_EXTENSION with length 0) therefore makes it\nread one octet past the end of the element.\n\n_ieee802_11_parse_elems_full() runs this check for every element of a\nframe once a non-inheritance context exists -- e.g. while parsing a\nper-STA profile of a Multi-Link element in a (re)association response,\nor a non-transmitted BSS profile -- so a crafted frame from an AP can\ntrigger a one-octet slab-out-of-bounds read during element parsing:\n\n  BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited\n  Read of size 1 ... in net/wireless/scan.c\n\nReturn early (treat the element as inherited) when an extension element\ncarries no data, mirroring the existing handling of empty ID lists.\n\nThe bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68402","epss":0.00268,"percentile":0.18856,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68402","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68403","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68403","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: brcmfmac: initialize SDIO data work before cleanup  brcmf_sdio_probe() stores the newly allocated bus in sdiodev->bus before allocating the ordered workqueue. If that allocation fails, the function jumps to fail and calls brcmf_sdio_remove().  brcmf_sdio_remove() unconditionally cancels bus->datawork. Initialize the work item before the first failure path that can reach brcmf_sdio_remove(), so the cleanup path always observes a valid work object.  This issue was found by our static analysis tool and then confirmed by manual review of the probe error path and the remove-time work drain. The problem pattern is an early setup failure that reaches a cleanup helper which cancels an embedded work item before its initializer has run.  A QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in brcmf_sdio_probe(), before INIT_WORK(&bus->datawork) is reached. The resulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports the invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in the stack.","cvss":[],"epss":[{"cve":"CVE-2026-68403","epss":0.00176,"percentile":0.07301,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68403","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68403","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2a665946e0407a05a3f81bd56a08553c446498e0","https://git.kernel.org/stable/c/5c342437ea44bb829680ca9e4f683dd5b325b219","https://git.kernel.org/stable/c/6bd21ec8549a5854dd64204a66289952917a924c","https://git.kernel.org/stable/c/860887d22890417d43ef8298f0cc4865e29b54de","https://git.kernel.org/stable/c/9a4be91e5bb032b34cb3c962f6d4f82e7ef09364","https://git.kernel.org/stable/c/c73c3fc1c7ca5a927639f0884624cb244ba791e4","https://git.kernel.org/stable/c/f50a2b9e57a751e70ae9a272875d80d39eaccd6a","https://git.kernel.org/stable/c/fb12c87ae855346321af72e57a93c146205f1090"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: initialize SDIO data work before cleanup\n\nbrcmf_sdio_probe() stores the newly allocated bus in sdiodev->bus before\nallocating the ordered workqueue. If that allocation fails, the function\njumps to fail and calls brcmf_sdio_remove().\n\nbrcmf_sdio_remove() unconditionally cancels bus->datawork. Initialize the\nwork item before the first failure path that can reach brcmf_sdio_remove(),\nso the cleanup path always observes a valid work object.\n\nThis issue was found by our static analysis tool and then confirmed by\nmanual review of the probe error path and the remove-time work drain. The\nproblem pattern is an early setup failure that reaches a cleanup helper\nwhich cancels an embedded work item before its initializer has run.\n\nA QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in\nbrcmf_sdio_probe(), before INIT_WORK(&bus->datawork) is reached. The\nresulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports\nthe invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in\nthe stack.","cvss":[],"epss":[{"cve":"CVE-2026-68403","epss":0.00176,"percentile":0.07301,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68403","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68404","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68404","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: cfg80211: use wiphy work for socket owner autodisconnect  nl80211_netlink_notify() walks the cfg80211 wireless device list when a NETLINK_GENERIC socket is released. If the socket owns a connection, the notifier queues the embedded wdev->disconnect_wk work item.  That work is a plain work_struct today. NETDEV_GOING_DOWN cancels it, but a NETLINK_URELEASE notifier that already observed conn_owner_nlportid can queue it after that cancel returns. _cfg80211_unregister_wdev() then removes the wdev from the list and waits for RCU readers, but synchronize_net() does not drain work queued by such a reader.  Make the autodisconnect work a wiphy_work instead. The callback already needs the wiphy mutex, and wiphy_work runs under that mutex. This lets teardown cancel pending autodisconnect work while holding the mutex, without a cancel_work_sync() vs. worker locking concern.  Also cancel the wiphy work after list_del_rcu() and synchronize_net(). Any NETLINK_URELEASE notifier that had already reached the wdev list has then either queued the work and it is removed, or can no longer find the wdev.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68404","epss":0.00154,"percentile":0.04837,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11780999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-68404","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68404","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0c2ed186bbe14304415476d6707b747dddcd8583","https://git.kernel.org/stable/c/6d6123fef5a4af175cc6b6b12a03dd0f3c240b79"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: use wiphy work for socket owner autodisconnect\n\nnl80211_netlink_notify() walks the cfg80211 wireless device list when a\nNETLINK_GENERIC socket is released. If the socket owns a connection, the\nnotifier queues the embedded wdev->disconnect_wk work item.\n\nThat work is a plain work_struct today. NETDEV_GOING_DOWN cancels it, but a\nNETLINK_URELEASE notifier that already observed conn_owner_nlportid can\nqueue it after that cancel returns. _cfg80211_unregister_wdev() then\nremoves the wdev from the list and waits for RCU readers, but\nsynchronize_net() does not drain work queued by such a reader.\n\nMake the autodisconnect work a wiphy_work instead. The callback already\nneeds the wiphy mutex, and wiphy_work runs under that mutex. This lets\nteardown cancel pending autodisconnect work while holding the mutex,\nwithout a cancel_work_sync() vs. worker locking concern.\n\nAlso cancel the wiphy work after list_del_rcu() and synchronize_net(). Any\nNETLINK_URELEASE notifier that had already reached the wdev list has then\neither queued the work and it is removed, or can no longer find the wdev.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68404","epss":0.00154,"percentile":0.04837,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68404","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68405","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68405","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock  ieee80211_do_stop() removes AP_VLAN packets from the parent AP ps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then calls ieee80211_free_txskb() before dropping the lock.  ieee80211_free_txskb() is not just a passive SKB release. For SKBs with TX status state it can report a dropped frame through cfg80211/nl80211, and that path can reach netlink tap transmit. This is the same reason the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs under the queue lock and frees them after IRQ state is restored.  The buggy scenario involves two paths, with each column showing the order within that path:  AP_VLAN management TX:             AP_VLAN stop: 1. attach ACK-status state         1. clear the running state 2. queue a multicast SKB on        2. take ps->bc_buf.lock with IRQs    parent ps->bc_buf                  disabled                                    3. unlink the AP_VLAN SKB                                    4. call ieee80211_free_txskb()  Unlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock, but move them to a local free queue. Drop the lock and restore IRQ state before calling ieee80211_free_txskb().  WARNING: kernel/softirq.c:430 at __local_bh_enable_ip","cvss":[],"epss":[{"cve":"CVE-2026-68405","epss":0.0022,"percentile":0.12447,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-68405","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68405","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0d2619e708e2ef02ba1c91642ea261d3f19d8f9a","https://git.kernel.org/stable/c/4b8abf43bf34791c99d99dc3be13f897adefc461","https://git.kernel.org/stable/c/659a81b62a61440b85e02c09903be861ae7679e5","https://git.kernel.org/stable/c/962f755a47d7ec3bbf6c709697d7f4c5f798441d","https://git.kernel.org/stable/c/a424985c3ef2a87ce6057a853e18d0c441a86be8","https://git.kernel.org/stable/c/aa01ef0ebbc3289154229ef58e65baf289eb9789","https://git.kernel.org/stable/c/be9dfcb0654c1f6c0fce7ba2a909683bb6f1e0ef","https://git.kernel.org/stable/c/f3858d5b1432098c1936e03d6e03dd0e33facf60"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock\n\nieee80211_do_stop() removes AP_VLAN packets from the parent AP\nps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then\ncalls ieee80211_free_txskb() before dropping the lock.\n\nieee80211_free_txskb() is not just a passive SKB release. For SKBs with\nTX status state it can report a dropped frame through cfg80211/nl80211,\nand that path can reach netlink tap transmit. This is the same reason\nthe pending queue cleanup in ieee80211_do_stop() already unlinks SKBs\nunder the queue lock and frees them after IRQ state is restored.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nAP_VLAN management TX:             AP_VLAN stop:\n1. attach ACK-status state         1. clear the running state\n2. queue a multicast SKB on        2. take ps->bc_buf.lock with IRQs\n   parent ps->bc_buf                  disabled\n                                   3. unlink the AP_VLAN SKB\n                                   4. call ieee80211_free_txskb()\n\nUnlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock,\nbut move them to a local free queue. Drop the lock and restore IRQ state\nbefore calling ieee80211_free_txskb().\n\nWARNING: kernel/softirq.c:430 at __local_bh_enable_ip","cvss":[],"epss":[{"cve":"CVE-2026-68405","epss":0.0022,"percentile":0.12447,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68405","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68406","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68406","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: cfg80211: validate PMSR FTM preamble range  PMSR FTM request parsing accepts preamble values outside the enumerated nl80211 preamble range.  Reject out-of-range values before using them in the parser capability bit test using the policy.  [drop unnecessary check]","cvss":[],"epss":[{"cve":"CVE-2026-68406","epss":0.00184,"percentile":0.08122,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.092},"relatedVulnerabilities":[{"id":"CVE-2026-68406","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68406","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2b97fa1bce7731f6a244f3d4407c61858f09b93f","https://git.kernel.org/stable/c/36230936468f0ba4930e94aef496fc229d4bb951","https://git.kernel.org/stable/c/44ea65d779e2d23b2264fea6af2d0c666a3ec9fb","https://git.kernel.org/stable/c/58320cb47df2accc7a20bb72c0150280732fa58f","https://git.kernel.org/stable/c/73ada9f23c2c7fac74474ea2a38ceb265bae17f1","https://git.kernel.org/stable/c/922d71fbaf99c1d5318151a0cb0a42ad448d07d9","https://git.kernel.org/stable/c/9b33f260db3971f572dda0b45dd28d477cf51ed1","https://git.kernel.org/stable/c/cfbda103aeae61071a122a6fc2bfe98cffbd7165"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: validate PMSR FTM preamble range\n\nPMSR FTM request parsing accepts preamble values outside the\nenumerated nl80211 preamble range.\n\nReject out-of-range values before using them in the parser capability\nbit test using the policy.\n\n[drop unnecessary check]","cvss":[],"epss":[{"cve":"CVE-2026-68406","epss":0.00184,"percentile":0.08122,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68406","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68407","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68407","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: nl80211: free RNR data on MBSSID mismatch  nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR entries than MBSSID entries.  The rejected RNR allocation has not been attached to the beacon data yet, so free it before returning the error.","cvss":[],"epss":[{"cve":"CVE-2026-68407","epss":0.00172,"percentile":0.0681,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-68407","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68407","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/07a95ec2b54774201fdf4ef7ffb0ca2ab19ed29c","https://git.kernel.org/stable/c/312c8b9d7836ef58e552619a8c19be08b04032bb","https://git.kernel.org/stable/c/4b76fc30c80b240107a7de3c7560113c9290eafc","https://git.kernel.org/stable/c/6f919f29e9b75793104709987131b8d910d7800a","https://git.kernel.org/stable/c/fa9592ef7de11f8c7042315d9bc20e91a97f679e","https://git.kernel.org/stable/c/fb052a6e2fa866384d8edc237746583ec94c15af"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: free RNR data on MBSSID mismatch\n\nnl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR\nentries than MBSSID entries.\n\nThe rejected RNR allocation has not been attached to the beacon data yet,\nso free it before returning the error.","cvss":[],"epss":[{"cve":"CVE-2026-68407","epss":0.00172,"percentile":0.0681,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68407","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68408","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68408","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock  When a netlink socket that owns a PMSR session is closed, cfg80211_release_pmsr() clears the request's nl_portid and queues pmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.  If the interface tears down concurrently, cfg80211_pmsr_wdev_down() is called under wiphy_lock and calls cancel_work_sync(&pmsr_free_wk) to wait for any running work. The work function acquires wiphy_lock via guard(wiphy) before calling process_abort.  This is a deadlock: wdev_down holds wiphy_lock and blocks inside cancel_work_sync(); pmsr_free_wk blocks trying to acquire that same wiphy_lock. Neither thread can proceed.  The same deadlock is reachable from cfg80211_leave_locked(), which calls cfg80211_pmsr_wdev_down() for all interface types under wiphy_lock.  Fix this by converting pmsr_free_wk from a plain work_struct to a wiphy_work. The wiphy_work dispatcher holds wiphy_lock when running work items, so the explicit guard(wiphy) in the work function is no longer needed. wiphy_work_cancel() can be called safely while holding wiphy_lock - since wiphy_lock prevents the work from running concurrently, wiphy_work_cancel() never blocks, eliminating the deadlock.  Remove the cancel_work_sync() for pmsr_free_wk from the NETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally just before it, already cancels any pending work under wiphy_lock via wiphy_work_cancel() inside cfg80211_pmsr_wdev_down().","cvss":[],"epss":[{"cve":"CVE-2026-68408","epss":0.00168,"percentile":0.0632,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-68408","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68408","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0a77d9fb4d5c0e01306cd406ffdee8f1fe955c0e","https://git.kernel.org/stable/c/133684982dd0c24359fcc641d19d89cc17d6e5ef","https://git.kernel.org/stable/c/21512b5f7a74fd18c996c22e6854efe57d570816","https://git.kernel.org/stable/c/2b0eab425e1f658d8fe1df7590e3b9af5959505e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock\n\nWhen a netlink socket that owns a PMSR session is closed,\ncfg80211_release_pmsr() clears the request's nl_portid and queues\npmsr_free_wk to call cfg80211_pmsr_process_abort() asynchronously.\n\nIf the interface tears down concurrently, cfg80211_pmsr_wdev_down()\nis called under wiphy_lock and calls cancel_work_sync(&pmsr_free_wk)\nto wait for any running work. The work function acquires wiphy_lock\nvia guard(wiphy) before calling process_abort.\n\nThis is a deadlock: wdev_down holds wiphy_lock and blocks inside\ncancel_work_sync(); pmsr_free_wk blocks trying to acquire that same\nwiphy_lock. Neither thread can proceed.\n\nThe same deadlock is reachable from cfg80211_leave_locked(), which\ncalls cfg80211_pmsr_wdev_down() for all interface types under\nwiphy_lock.\n\nFix this by converting pmsr_free_wk from a plain work_struct to a\nwiphy_work. The wiphy_work dispatcher holds wiphy_lock when running\nwork items, so the explicit guard(wiphy) in the work function is no\nlonger needed. wiphy_work_cancel() can be called safely while holding\nwiphy_lock - since wiphy_lock prevents the work from running\nconcurrently, wiphy_work_cancel() never blocks, eliminating the\ndeadlock.\n\nRemove the cancel_work_sync() for pmsr_free_wk from the\nNETDEV_GOING_DOWN handler. cfg80211_leave(), called unconditionally\njust before it, already cancels any pending work under wiphy_lock\nvia wiphy_work_cancel() inside cfg80211_pmsr_wdev_down().","cvss":[],"epss":[{"cve":"CVE-2026-68408","epss":0.00168,"percentile":0.0632,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68408","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68409","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68409","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: defer link RX stats percpu free to RCU  sta_remove_link() frees a removed MLO link's RX stats percpu buffer right away, but defers only the link container to RCU:  \tsta_info_free_link(&alloc->info); \tkfree_rcu(alloc, rcu_head);  The RX fast path reads link_sta under rcu_read_lock and writes the percpu stats. A reader that resolved link_sta before the removal keeps the pointer. The container stays alive from the kfree_rcu, so the read still works. But the percpu block it points to is already freed. This needs uses_rss. That is when pcpu_rx_stats exists.  The full STA teardown frees the deflink stats only after synchronize_net(). The link removal path had no such barrier. The race is hard to win in practice, but the free should still wait for RCU.  Free the link together with its data from a single RCU callback, so the percpu block is reclaimed only after readers drain.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68409","epss":0.00239,"percentile":0.14915,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19478500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-68409","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68409","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2aa1789880fa5e41049b0f6a74a4fc2fa1997610","https://git.kernel.org/stable/c/a03fceae0c65b31ce31840dac5e26684ceecb65b","https://git.kernel.org/stable/c/aa2eb62525188269cdd402a583b9a8ed94657ff0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: defer link RX stats percpu free to RCU\n\nsta_remove_link() frees a removed MLO link's RX stats percpu buffer right\naway, but defers only the link container to RCU:\n\n\tsta_info_free_link(&alloc->info);\n\tkfree_rcu(alloc, rcu_head);\n\nThe RX fast path reads link_sta under rcu_read_lock and writes the percpu\nstats. A reader that resolved link_sta before the removal keeps the\npointer. The container stays alive from the kfree_rcu, so the read still\nworks. But the percpu block it points to is already freed. This needs\nuses_rss. That is when pcpu_rx_stats exists.\n\nThe full STA teardown frees the deflink stats only after\nsynchronize_net(). The link removal path had no such barrier. The race is\nhard to win in practice, but the free should still wait for RCU.\n\nFree the link together with its data from a single RCU callback, so the\npercpu block is reclaimed only after readers drain.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68409","epss":0.00239,"percentile":0.14915,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68409","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68410","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68410","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: libertas: fix memory leak in helper_firmware_cb()  helper_firmware_cb() neglects to free the single-stage firmware image after a successful async load, leading to a memory leak in the USB firmware-download path.  Fix this memory leak by calling release_firmware() immediately after lbs_fw_loaded() returns.  The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in the current wireless tree.  An x86_64 allyesconfig build showed no new warnings. As we do not have compatible Libertas USB hardware for exercising this firmware-download path, no runtime testing was able to be performed.","cvss":[],"epss":[{"cve":"CVE-2026-68410","epss":0.0021,"percentile":0.1127,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-68410","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68410","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/63c2391deefb31e1b801b7f32bd502ca4808639b","https://git.kernel.org/stable/c/644640cde2fb216e6567de5eee780a38dbc95928","https://git.kernel.org/stable/c/6c1f54a04813676c5a2150d99331c8d21f199374","https://git.kernel.org/stable/c/6cda91bbb8dc3d22ef0323008a12dcf73a5129da","https://git.kernel.org/stable/c/7f28722b3e4e0c8d49c859fea4a9b1fa13b5ae06","https://git.kernel.org/stable/c/ce829286f4935f1eb6b5dcb64da02910ce149c76","https://git.kernel.org/stable/c/d497b7566e74920acfe283dd6b2cbf1682890796","https://git.kernel.org/stable/c/eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas: fix memory leak in helper_firmware_cb()\n\nhelper_firmware_cb() neglects to free the single-stage firmware image\nafter a successful async load, leading to a memory leak in the USB\nfirmware-download path.\n\nFix this memory leak by calling release_firmware() immediately after\nlbs_fw_loaded() returns.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nthe current wireless tree.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\ncompatible Libertas USB hardware for exercising this firmware-download\npath, no runtime testing was able to be performed.","cvss":[],"epss":[{"cve":"CVE-2026-68410","epss":0.0021,"percentile":0.1127,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68410","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68411","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68411","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211_hwsim: clamp virtio RX length before skb_put  hwsim_virtio_rx_work() passes the virtqueue used-ring length reported by the device straight to skb_put() on a fixed-size receive skb. A backend reporting a length larger than the skb tailroom drives skb_put() past the buffer end and hits skb_over_panic() -- a host-triggerable guest panic (denial of service).  Clamp the length to the skb's available room before skb_put(). A conforming device never reports more than the posted buffer size, so valid frames are unaffected; a truncated over-report then fails the length/header checks in hwsim_virtio_handle_cmd() and is dropped, so truncating rather than dropping here cannot be turned into a parsing problem.","cvss":[],"epss":[{"cve":"CVE-2026-68411","epss":0.00176,"percentile":0.07303,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68411","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68411","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/10a2b430f8f06ae14b9590b6f6faa6b588ef0654","https://git.kernel.org/stable/c/5779e4a33e1666ddfeba43e96e29c4a9e5254ff0","https://git.kernel.org/stable/c/6dc76371a9a360c29de00df5b11563102d9d675a","https://git.kernel.org/stable/c/7f9d678b870fca8eaf1d46fa915cba0b1d5b387a","https://git.kernel.org/stable/c/82c5a30a66e2a7337d99476c67d6fc1a99c4250e","https://git.kernel.org/stable/c/909573d6a9b67354fc0515952574564e7c909c62","https://git.kernel.org/stable/c/99dc05c75acc3c8cde8d89c5371f4b569de5ac62","https://git.kernel.org/stable/c/fade308845c89f784da8a6780c1e77258488f1b6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211_hwsim: clamp virtio RX length before skb_put\n\nhwsim_virtio_rx_work() passes the virtqueue used-ring length reported by\nthe device straight to skb_put() on a fixed-size receive skb. A backend\nreporting a length larger than the skb tailroom drives skb_put() past the\nbuffer end and hits skb_over_panic() -- a host-triggerable guest panic\n(denial of service).\n\nClamp the length to the skb's available room before skb_put(). A\nconforming device never reports more than the posted buffer size, so valid\nframes are unaffected; a truncated over-report then fails the\nlength/header checks in hwsim_virtio_handle_cmd() and is dropped, so\ntruncating rather than dropping here cannot be turned into a parsing\nproblem.","cvss":[],"epss":[{"cve":"CVE-2026-68411","epss":0.00176,"percentile":0.07303,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68411","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68412","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68412","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()  If the test against IEEE80211_MAX_SSID_LEN fails, then 'creq' leaks. Use the existing error handling path to fix it.","cvss":[],"epss":[{"cve":"CVE-2026-68412","epss":0.00198,"percentile":0.0966,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.099},"relatedVulnerabilities":[{"id":"CVE-2026-68412","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68412","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/99d2e850c643e2c70fa165b722a1ad28347a8b3a","https://git.kernel.org/stable/c/c6659f66d4ee4841aafae5659d2ef5e4c5c63cb6","https://git.kernel.org/stable/c/e67dc2b8d5ac4bb804000b6732768a9ae678912f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()\n\nIf the test against IEEE80211_MAX_SSID_LEN fails, then 'creq' leaks.\nUse the existing error handling path to fix it.","cvss":[],"epss":[{"cve":"CVE-2026-68412","epss":0.00198,"percentile":0.0966,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68412","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68413","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()  The memory allocated in the ipw2100_alloc_device() function is not freed in some of the error paths in ipw2100_pci_init_one(). Fix that by converting the direct return into a goto to the error path return.  The error path when pci_enable_device() fails cannot jump to fail, since at this point priv is not set, so perform error handling inline.","cvss":[],"epss":[{"cve":"CVE-2026-68413","epss":0.00196,"percentile":0.0946,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.098},"relatedVulnerabilities":[{"id":"CVE-2026-68413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68413","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0d388f62031dbabcba0f44bb91b59f10e88cac17","https://git.kernel.org/stable/c/71614326ab43e8b8f392ba865aeb6d7e327dff7d","https://git.kernel.org/stable/c/768a701362a8f77b62c14f8202ad559b7ecbb0c6","https://git.kernel.org/stable/c/7cbda50eebcd9aa00b0de382f776287cf7a36cf8","https://git.kernel.org/stable/c/836a19c654dcb1b01878a70090af016fbd0fd7e5","https://git.kernel.org/stable/c/9b080198a22fd809c4e7f6793eafab53ac2643fd","https://git.kernel.org/stable/c/f442e581a88937671a22ceb3806c186265ef6254","https://git.kernel.org/stable/c/f75b9a2a9d8334ae0f9c5e47df7b31f7aeb1fdbe"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()\n\nThe memory allocated in the ipw2100_alloc_device() function is not freed\nin some of the error paths in ipw2100_pci_init_one(). Fix that by\nconverting the direct return into a goto to the error path return.\n\nThe error path when pci_enable_device() fails cannot jump to fail, since\nat this point priv is not set, so perform error handling inline.","cvss":[],"epss":[{"cve":"CVE-2026-68413","epss":0.00196,"percentile":0.0946,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68413","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68414","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68414","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: cfg80211: cancel sched scan results work on unregister  cfg80211_sched_scan_results() can queue rdev->sched_scan_res_wk from a driver result notification while a scheduled scan request is present. The work callback recovers the containing cfg80211_registered_device and then locks the wiphy and walks the scheduled-scan request list.  wiphy_unregister() already makes the wiphy unreachable and drains rdev work items before cfg80211_dev_free() can release the object, but it does not drain sched_scan_res_wk. A queued or running result work item can therefore cross the unregister/free boundary and access freed rdev state.  The buggy scenario involves two paths, with each column showing the order within that path:  scheduled-scan result path:        unregister/free path: 1. cfg80211_sched_scan_results()   1. interface teardown stops and    queues rdev->sched_scan_res_wk.    removes the scheduled scan request. 2. cfg80211_wq starts the work     2. wiphy_unregister() drains other    item and recovers rdev.            rdev work items. 3. The worker locks rdev->wiphy    3. cfg80211_dev_free() destroys and    and walks rdev state.              frees rdev.  Cancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev work items. cancel_work_sync() removes a pending result notification and waits for an already running callback, so cfg80211_dev_free() cannot free rdev while this work item is still active.  Validation reproduced this kernel report: BUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530 Workqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211] Read of size 8 Call trace:   dump_stack_lvl+0x66/0xa0   print_report+0xce/0x630   cfg80211_sched_scan_results_wk+0x4a6/0x530   srso_alias_return_thunk+0x5/0xfbef5   __virt_addr_valid+0x224/0x430   kasan_report+0xac/0xe0   lockdep_hardirqs_on_prepare+0xea/0x1a0   process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)   lock_is_held_type+0x8f/0x100   worker_thread+0x5ad/0xfd0   __kthread_parkme+0xc6/0x200   kthread+0x31e/0x410   trace_hardirqs_on+0x1a/0x170   ret_from_fork+0x576/0x810   __switch_to+0x57e/0xe20   __switch_to_asm+0x33/0x70   ret_from_fork_asm+0x1a/0x30","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68414","epss":0.0023,"percentile":0.13753,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1725},"relatedVulnerabilities":[{"id":"CVE-2026-68414","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68414","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/308ffdf575560d7e7b8b21f1e3ca6276630f73bf","https://git.kernel.org/stable/c/3368457b4871ae8f0f88d19c9a3e6270e850ede6","https://git.kernel.org/stable/c/9293574ac208d18c11073538851fb69355beb3b5","https://git.kernel.org/stable/c/b119c70b24776c8ab2a2c0515397b3b0ad4e66cd","https://git.kernel.org/stable/c/b51b42b974461fd0f688baad85f10e2b8ab215c5","https://git.kernel.org/stable/c/c0fa1f3a4b021a5c6373169fd6c9bb4261d676a0","https://git.kernel.org/stable/c/edf0730be33696a1bd142792830d392129e495cc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: cancel sched scan results work on unregister\n\ncfg80211_sched_scan_results() can queue rdev->sched_scan_res_wk from a\ndriver result notification while a scheduled scan request is present. The\nwork callback recovers the containing cfg80211_registered_device and then\nlocks the wiphy and walks the scheduled-scan request list.\n\nwiphy_unregister() already makes the wiphy unreachable and drains rdev work\nitems before cfg80211_dev_free() can release the object, but it does not\ndrain sched_scan_res_wk. A queued or running result work item can therefore\ncross the unregister/free boundary and access freed rdev state.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nscheduled-scan result path:        unregister/free path:\n1. cfg80211_sched_scan_results()   1. interface teardown stops and\n   queues rdev->sched_scan_res_wk.    removes the scheduled scan request.\n2. cfg80211_wq starts the work     2. wiphy_unregister() drains other\n   item and recovers rdev.            rdev work items.\n3. The worker locks rdev->wiphy    3. cfg80211_dev_free() destroys and\n   and walks rdev state.              frees rdev.\n\nCancel sched_scan_res_wk in wiphy_unregister() alongside the other rdev\nwork items. cancel_work_sync() removes a pending result notification and\nwaits for an already running callback, so cfg80211_dev_free() cannot free\nrdev while this work item is still active.\n\nValidation reproduced this kernel report:\nBUG: KASAN: use-after-free in cfg80211_sched_scan_results_wk+0x4a6/0x530\nWorkqueue: cfg80211 cfg80211_sched_scan_results_wk [cfg80211]\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x630\n  cfg80211_sched_scan_results_wk+0x4a6/0x530\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x224/0x430\n  kasan_report+0xac/0xe0\n  lockdep_hardirqs_on_prepare+0xea/0x1a0\n  process_one_work+0x8d0/0x18f0 (kernel/workqueue.c:3212)\n  lock_is_held_type+0x8f/0x100\n  worker_thread+0x5ad/0xfd0\n  __kthread_parkme+0xc6/0x200\n  kthread+0x31e/0x410\n  trace_hardirqs_on+0x1a/0x170\n  ret_from_fork+0x576/0x810\n  __switch_to+0x57e/0xe20\n  __switch_to_asm+0x33/0x70\n  ret_from_fork_asm+0x1a/0x30","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":1.7,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68414","epss":0.0023,"percentile":0.13753,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68414","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68417","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68417","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/siw: publish QP after initialization  siw_create_qp() currently calls siw_qp_add() before the queues, CQ pointers, state, completion, and device list entry are ready. A QPN lookup can therefore reach a QP that is still being constructed.  Move siw_qp_add() to the end of siw_create_qp(), after QP initialization and before adding the QP to the siw device list.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68417","epss":0.0012,"percentile":0.02074,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-68417","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68417","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/36e91a58397ca8c978e38a0bf389f0c6113fa8ca","https://git.kernel.org/stable/c/3c9d128219964dcea897bf6139b88242e987be8f","https://git.kernel.org/stable/c/3ff82e3841ecab1ff38d5817c969a019d266c83c","https://git.kernel.org/stable/c/52f9fcb191143448df55fd215ff09c5207fed43e","https://git.kernel.org/stable/c/74912ad168f87d6b2b670a87987bb302d6e64aa1","https://git.kernel.org/stable/c/bb27fcc67c429d97f785c92c35a6c5adebb05d7f","https://git.kernel.org/stable/c/fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: publish QP after initialization\n\nsiw_create_qp() currently calls siw_qp_add() before the queues, CQ\npointers, state, completion, and device list entry are ready. A QPN\nlookup can therefore reach a QP that is still being constructed.\n\nMove siw_qp_add() to the end of siw_create_qp(), after QP\ninitialization and before adding the QP to the siw device list.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68417","epss":0.0012,"percentile":0.02074,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68417","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68418","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68418","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/irdma: Prevent user-triggered null deref on QP create  Previously, the user QP creation path would only attempt to populate iwqp->iwpbl if the user-provided req.user_wqe_bufs field was non-zero. The problem is that iwqp->iwpbl is unconditionally dereferenced later on in irdma_setup_virt_qp.  While there was a check for iwqp->iwpbl != NULL, this check would only occur if req.user_wqe_bufs was non-zero. The end result is that a user could send a zero user_wqe_bufs value and trigger a null ptr deref.  Fix this by unconditionally calling irdma_get_pbl and bailing if it fails, similar to the CQ and SRQ paths.","cvss":[],"epss":[{"cve":"CVE-2026-68418","epss":0.00154,"percentile":0.04903,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.077},"relatedVulnerabilities":[{"id":"CVE-2026-68418","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68418","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/728211c815f6eef28dd3df2a5b6297483185aa20","https://git.kernel.org/stable/c/b9b0889071569d43623c260074e159cd8f26adb1","https://git.kernel.org/stable/c/ec675b4cdfd378d8c9dd8c93126c024f2469bd79"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Prevent user-triggered null deref on QP create\n\nPreviously, the user QP creation path would only attempt to\npopulate iwqp->iwpbl if the user-provided req.user_wqe_bufs\nfield was non-zero. The problem is that iwqp->iwpbl is\nunconditionally dereferenced later on in irdma_setup_virt_qp.\n\nWhile there was a check for iwqp->iwpbl != NULL, this check\nwould only occur if req.user_wqe_bufs was non-zero. The end\nresult is that a user could send a zero user_wqe_bufs value\nand trigger a null ptr deref.\n\nFix this by unconditionally calling irdma_get_pbl and bailing\nif it fails, similar to the CQ and SRQ paths.","cvss":[],"epss":[{"cve":"CVE-2026-68418","epss":0.00154,"percentile":0.04903,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68418","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68422","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68422","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()  If we have an unexpected reloc_root for our root, we jump to the out label but never drop the reference we obtained for root, resulting in a leak. Add a missing btrfs_put_root() call.","cvss":[],"epss":[{"cve":"CVE-2026-68422","epss":0.00215,"percentile":0.1181,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1075},"relatedVulnerabilities":[{"id":"CVE-2026-68422","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68422","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3f586b4c92e4272fcd01bf0db0590b63acf3e85b","https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206","https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735","https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4","https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db","https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c","https://git.kernel.org/stable/c/f89df93e8aefa4c1c813f835559f2ac727f79766"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()\n\nIf we have an unexpected reloc_root for our root, we jump to the out label\nbut never drop the reference we obtained for root, resulting in a leak.\nAdd a missing btrfs_put_root() call.","cvss":[],"epss":[{"cve":"CVE-2026-68422","epss":0.00215,"percentile":0.1181,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68422","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68425","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68425","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  IB/mad: Drop unmatched RMPP responses before reassembly  Kernel-handled RMPP receive processing starts reassembly for active DATA responses before the response is matched to an outstanding send. The normal match happens later, after ib_process_rmpp_recv_wc() has either assembled a complete message or consumed the segment.  That ordering lets an unsolicited response that routes to a kernel RMPP agent by the high TID bits allocate or extend RMPP receive state before the full TID and source address are checked against a real request. A reordered burst can therefore reach the receive-side insertion path even though the response would not match any send.  For kernel-handled RMPP DATA responses, require the existing ib_find_send_mad() match before entering RMPP reassembly. The matcher already checks the full TID, management class and source address/GID against the agent wait, backlog and in-flight send lists. If there is no match, drop the response without creating RMPP state.  This leaves the RMPP window behavior unchanged and only rejects responses that have no corresponding request.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68425","epss":0.00263,"percentile":0.18131,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.19199},"relatedVulnerabilities":[{"id":"CVE-2026-68425","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68425","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/45416c87ebcece1e90f3bc5bc172d106b77c6b69","https://git.kernel.org/stable/c/6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72","https://git.kernel.org/stable/c/9634fb1f4d404f36a20ffbcb8797369db69b06bb","https://git.kernel.org/stable/c/98d2d468b4faa1fdc68c0c6c238389906ee3490c","https://git.kernel.org/stable/c/ad9c9ad3204f63a46f0f7de29687a8e512f05e29","https://git.kernel.org/stable/c/bfb9e8243fd2099d1080d09222964d988f991d9b","https://git.kernel.org/stable/c/d2e52d610b9b09694261632340b801a421e0b0c5","https://git.kernel.org/stable/c/dfa535c94406c03d3f0c869ef3ba5528e395737c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mad: Drop unmatched RMPP responses before reassembly\n\nKernel-handled RMPP receive processing starts reassembly for active\nDATA responses before the response is matched to an outstanding send.\nThe normal match happens later, after ib_process_rmpp_recv_wc() has\neither assembled a complete message or consumed the segment.\n\nThat ordering lets an unsolicited response that routes to a kernel\nRMPP agent by the high TID bits allocate or extend RMPP receive state\nbefore the full TID and source address are checked against a real\nrequest. A reordered burst can therefore reach the receive-side\ninsertion path even though the response would not match any send.\n\nFor kernel-handled RMPP DATA responses, require the existing\nib_find_send_mad() match before entering RMPP reassembly. The matcher\nalready checks the full TID, management class and source address/GID\nagainst the agent wait, backlog and in-flight send lists. If there is\nno match, drop the response without creating RMPP state.\n\nThis leaves the RMPP window behavior unchanged and only rejects\nresponses that have no corresponding request.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68425","epss":0.00263,"percentile":0.18131,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68425","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68426","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68426","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: fix stale skb->prev after async crypto steals a GSO segment  skb_gso_segment() leaves the segment list head with ->prev pointing at the last segment, an invariant validate_xmit_skb_list() relies on when it sets its tail pointer (tail = skb->prev).  When validate_xmit_xfrm() walks a GSO list and some segments are stolen by async crypto (->xmit() returns -EINPROGRESS), those segments are unlinked from the list but the head ->prev is never updated.  If the last segment is the one stolen, the returned head still has ->prev pointing at it, even though it is now owned by the crypto engine and may be freed.  validate_xmit_skb_list() later does tail->next = skb, writing through that stale pointer -- a use-after-free.  Repoint skb->prev at the last retained segment before returning.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68426","epss":0.00367,"percentile":0.29952,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.34498},"relatedVulnerabilities":[{"id":"CVE-2026-68426","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68426","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/33e1b0d25ca0d2818c635ff80e6aa0d295e08a98","https://git.kernel.org/stable/c/3f4c3919baf0944ad96580467c302bc6c7758b00","https://git.kernel.org/stable/c/bbca7cc3b2b4b10afbfee99b81d9ee78f5423046"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix stale skb->prev after async crypto steals a GSO segment\n\nskb_gso_segment() leaves the segment list head with ->prev pointing at\nthe last segment, an invariant validate_xmit_skb_list() relies on when\nit sets its tail pointer (tail = skb->prev).\n\nWhen validate_xmit_xfrm() walks a GSO list and some segments are stolen\nby async crypto (->xmit() returns -EINPROGRESS), those segments are\nunlinked from the list but the head ->prev is never updated.  If the\nlast segment is the one stolen, the returned head still has ->prev\npointing at it, even though it is now owned by the crypto engine and may\nbe freed.  validate_xmit_skb_list() later does tail->next = skb, writing\nthrough that stale pointer -- a use-after-free.\n\nRepoint skb->prev at the last retained segment before returning.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68426","epss":0.00367,"percentile":0.29952,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68426","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68427","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68427","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings  __host1x_bo_unpin() drops the last reference to the mapping and frees it, so we can't dereference mapping afterwards. The cache itself outlives the mapping, so use the cache local variable instead.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68427","epss":0.00125,"percentile":0.02544,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-68427","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68427","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/266cddf7bd0f6c79b6c0633aef742a22bf70265b","https://git.kernel.org/stable/c/5b7e5f84d3d4cea10c3764d2da274810a7934228","https://git.kernel.org/stable/c/5f4de3c717d34a24d555af581947742980778c02","https://git.kernel.org/stable/c/86a9bd8c8f422d5f3079da31e151868902fcc702","https://git.kernel.org/stable/c/abeff53233b984571b87582bb588b4b38ef4ea50","https://git.kernel.org/stable/c/b773faa32b0a98c3eb2b50d96de631681e5d1157"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings\n\n__host1x_bo_unpin() drops the last reference to the mapping and frees\nit, so we can't dereference mapping afterwards. The cache itself\noutlives the mapping, so use the cache local variable instead.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68427","epss":0.00125,"percentile":0.02544,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68427","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68428","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68428","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: x86/mmu: Fix use-after-free on vendor module reload  mmu_destroy_caches() destroys pte_list_desc_cache and mmu_page_header_cache, but leaves both pointers unchanged.  The pointers live in kvm.ko, and therefore survive when a vendor module is unloaded while kvm.ko remains loaded.  If creation of pte_list_desc_cache fails during a subsequent vendor module load, its assignment sets pte_list_desc_cache to NULL and the error path calls mmu_destroy_caches().  mmu_page_header_cache still points to the cache destroyed during the preceding vendor module unload.  Passing that stale pointer to kmem_cache_destroy() causes a slab use-after-free.  Reproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y, CONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m.  A one-shot test hook forces pte_list_desc_cache to NULL on the second invocation of kvm_mmu_vendor_module_init():    1. Load kvm.ko and kvm-intel.ko, creating both caches.   2. Unload only kvm_intel, leaving kvm.ko loaded.   3. Reload kvm_intel and force initialization through the -ENOMEM path.  KASAN reports:    BUG: KASAN: slab-use-after-free in   kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]   ...   kmem_cache_destroy+0x21/0x1d0   kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]   ...   Allocated by task 16817:   __kmem_cache_create_args+0x12c/0x3b0   __kmem_cache_create.constprop.0+0xb6/0xf0 [kvm]   kvm_mmu_vendor_module_init+0x13b/0x170 [kvm]   ...   Freed by task 16820:   kmem_cache_destroy+0x117/0x1d0   kvm_mmu_vendor_module_exit+0x21/0x30 [kvm]  Clear both pointers immediately after destroying their caches so that the stored state reflects the caches' lifetime and repeated cleanup is safe.  With the fix applied, the same injected vendor module reload fails with -ENOMEM as expected and produces no KASAN report.","cvss":[],"epss":[{"cve":"CVE-2026-68428","epss":0.00164,"percentile":0.05948,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.082},"relatedVulnerabilities":[{"id":"CVE-2026-68428","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68428","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/034b7fa1f5846d69eb51f12ce6d1c71871e83c2d","https://git.kernel.org/stable/c/32b9f89ed9e6d7a45075d64089c254a7f6e13695","https://git.kernel.org/stable/c/42272b0f239f3a89f9c26a01cc37aee06138b1b7","https://git.kernel.org/stable/c/43cfb20d62ffe49626d62beecfc32eb6f262191c","https://git.kernel.org/stable/c/52f2f7c30126037975389aa04d24c506a5177c35","https://git.kernel.org/stable/c/6f4be73880302d5642c83a0813fdfe1f5fd4b6e3","https://git.kernel.org/stable/c/940950d5cd86f250dca578279ad5ca63b4e0986b","https://git.kernel.org/stable/c/ec9daa8fd1b6f45545c9839dca55bd867fad9e13"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: Fix use-after-free on vendor module reload\n\nmmu_destroy_caches() destroys pte_list_desc_cache and\nmmu_page_header_cache, but leaves both pointers unchanged.  The pointers\nlive in kvm.ko, and therefore survive when a vendor module is unloaded\nwhile kvm.ko remains loaded.\n\nIf creation of pte_list_desc_cache fails during a subsequent vendor\nmodule load, its assignment sets pte_list_desc_cache to NULL and the\nerror path calls mmu_destroy_caches().  mmu_page_header_cache still\npoints to the cache destroyed during the preceding vendor module\nunload.  Passing that stale pointer to kmem_cache_destroy() causes a\nslab use-after-free.\n\nReproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y,\nCONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m.  A\none-shot test hook forces pte_list_desc_cache to NULL on the second\ninvocation of kvm_mmu_vendor_module_init():\n\n  1. Load kvm.ko and kvm-intel.ko, creating both caches.\n  2. Unload only kvm_intel, leaving kvm.ko loaded.\n  3. Reload kvm_intel and force initialization through the -ENOMEM path.\n\nKASAN reports:\n\n  BUG: KASAN: slab-use-after-free in\n  kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]\n  ...\n  kmem_cache_destroy+0x21/0x1d0\n  kvm_mmu_vendor_module_init+0x5b/0x170 [kvm]\n  ...\n  Allocated by task 16817:\n  __kmem_cache_create_args+0x12c/0x3b0\n  __kmem_cache_create.constprop.0+0xb6/0xf0 [kvm]\n  kvm_mmu_vendor_module_init+0x13b/0x170 [kvm]\n  ...\n  Freed by task 16820:\n  kmem_cache_destroy+0x117/0x1d0\n  kvm_mmu_vendor_module_exit+0x21/0x30 [kvm]\n\nClear both pointers immediately after destroying their caches so that\nthe stored state reflects the caches' lifetime and repeated cleanup is\nsafe.\n\nWith the fix applied, the same injected vendor module reload fails with\n-ENOMEM as expected and produces no KASAN report.","cvss":[],"epss":[{"cve":"CVE-2026-68428","epss":0.00164,"percentile":0.05948,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68428","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68430","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68430","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/gfx8: drop unecessary BUG_ON()  There's no need to crash the kernel for this case.  (cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)","cvss":[],"epss":[{"cve":"CVE-2026-68430","epss":0.00177,"percentile":0.07336,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68430","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68430","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0027afe3dc97a4964a9ea0fb5a3457de06d85f5b","https://git.kernel.org/stable/c/2404600dca5c0979485c6f2d9c62bd356a98870a","https://git.kernel.org/stable/c/26ad939b402a754b0624840dfaeebd86d7ff2a22","https://git.kernel.org/stable/c/69004f1f769f7f6e9e34f4390d98a12aa0b4ab98","https://git.kernel.org/stable/c/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5","https://git.kernel.org/stable/c/ab05af6c345bc8460052c60de657ce6d4a2386f7","https://git.kernel.org/stable/c/db85aa861b8214fa0d1d8405c01488f604a455a0","https://git.kernel.org/stable/c/f70bd5235d9efc2ee2f70293eea51888c5f2a54d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx8: drop unecessary BUG_ON()\n\nThere's no need to crash the kernel for this case.\n\n(cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)","cvss":[],"epss":[{"cve":"CVE-2026-68430","epss":0.00177,"percentile":0.07336,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68430","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68431","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68431","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate minimum PDU size for transform requests  The receive path applies the minimum SMB2 PDU size check only when ProtocolId is SMB2_PROTO_NUMBER. A packet carrying SMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated dialect does not provide transform handling.  On an SMB 2.1 connection, a short transform packet therefore reaches init_smb2_rsp_hdr(), which interprets the request as a full SMB2 header and reads beyond the request allocation. The copied fields can then be returned to the unauthenticated client.  Compression transforms are converted to ordinary SMB2 messages before protocol validation. After that conversion, validate ordinary SMB2 requests against SMB2_MIN_SUPPORTED_PDU_SIZE and require encryption transform requests to contain both a transform header and an SMB2 header. This rejects truncated requests before work allocation.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68431","epss":0.00366,"percentile":0.29919,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.33123},"relatedVulnerabilities":[{"id":"CVE-2026-68431","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68431","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/22f1aa35b87e471cc31b35b74451f46630863b12","https://git.kernel.org/stable/c/32e486b70c256d5ef4baa5a2936ade2fea50e8eb","https://git.kernel.org/stable/c/928dda88d0e13fbca381255028f65b244343a4ea","https://git.kernel.org/stable/c/b62c510f59803f82f9b4c76ead2a56833b2984c7","https://git.kernel.org/stable/c/cfc0b8e5080aec87700774e8568765eaa4b7b92b","https://git.kernel.org/stable/c/d8e5c5672724b8f3c4c099d2cf60239c996e5424","https://git.kernel.org/stable/c/d9e9753dfd43bd27c956578df7804a3c90b80fdc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate minimum PDU size for transform requests\n\nThe receive path applies the minimum SMB2 PDU size check only when\nProtocolId is SMB2_PROTO_NUMBER. A packet carrying\nSMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated\ndialect does not provide transform handling.\n\nOn an SMB 2.1 connection, a short transform packet therefore reaches\ninit_smb2_rsp_hdr(), which interprets the request as a full SMB2 header\nand reads beyond the request allocation. The copied fields can then be\nreturned to the unauthenticated client.\n\nCompression transforms are converted to ordinary SMB2 messages before\nprotocol validation. After that conversion, validate ordinary SMB2\nrequests against SMB2_MIN_SUPPORTED_PDU_SIZE and require encryption\ntransform requests to contain both a transform header and an SMB2\nheader. This rejects truncated requests before work allocation.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68431","epss":0.00366,"percentile":0.29919,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68431","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68432","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68432","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: require CAP_NET_ADMIN in the device netns for changelink  A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns vxlan->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in vxlan->net can rewrite a vxlan device whose underlay lives in vxlan->net.  vxlan_changelink() validates and applies the new configuration against vxlan->net (vxlan_config_validate(vxlan->net, ...)) and can reopen the underlay socket in that netns, so the same reasoning as the tunnel changelink series applies here.  Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the \"require CAP_NET_ADMIN in the device netns for changelink\" series.  Found by 0sec automated security-research tooling (https://0sec.ai).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68432","epss":0.0013,"percentile":0.02943,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10595000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-68432","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68432","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0aa580a8bbbed2507b4582a1f0ef581d480d06ed","https://git.kernel.org/stable/c/32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f","https://git.kernel.org/stable/c/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e","https://git.kernel.org/stable/c/730c7e5fea7f06e0cdf21c547222ec93234fd1d6","https://git.kernel.org/stable/c/7465ade989ba84adc2bfa58bad3ca25d249f0f7a","https://git.kernel.org/stable/c/b3793d7dccb192ffff29894d11824db6251acdd5","https://git.kernel.org/stable/c/b95a8743e58f7efed5ddc4cb73829b66f17feab0","https://git.kernel.org/stable/c/e8ad0d311e225939a9a6c745d6cc384c7364ec87"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns vxlan->net. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in vxlan->net can rewrite a vxlan\ndevice whose underlay lives in vxlan->net.\n\nvxlan_changelink() validates and applies the new configuration against\nvxlan->net (vxlan_config_validate(vxlan->net, ...)) and can reopen the\nunderlay socket in that netns, so the same reasoning as the tunnel\nchangelink series applies here.\n\nGate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68432","epss":0.0013,"percentile":0.02943,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68432","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68433","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68433","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: bound get_version reply decode to front len  handle_get_version_reply() uses msg->front_alloc_len as the decode boundary for MON_GET_VERSION_REPLY.  That is the size of the reused reply buffer, not the number of bytes actually received.  A truncated reply can therefore pass ceph_decode_need() and decode the second u64 from stale tail bytes left in the buffer by an earlier message, causing an uninitialized memory read.  Use msg->front.iov_len as the receive-side decode boundary, matching other libceph reply handlers and limiting decoding to the bytes that were actually read from the wire.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68433","epss":0.00291,"percentile":0.21455,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.23425499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-68433","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68433","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0d934c934ec746d53fc7e4f53239792647bbae63","https://git.kernel.org/stable/c/1307028f082756bf453e1889aee9983d30643a4b","https://git.kernel.org/stable/c/340e0386aa39da181015bee38f309018c335ce16","https://git.kernel.org/stable/c/4e7ebfaa0d14cf50e44041bfde38070d6dbc019f","https://git.kernel.org/stable/c/72a35070fcefa229b1b031aa7482ad3788e18f07","https://git.kernel.org/stable/c/d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0","https://git.kernel.org/stable/c/d60de8253c85a02d0e6194b0735e7a562981a04c","https://git.kernel.org/stable/c/f6cbf6878f3a1503c872ba8f1e69a58ee68d8b2e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: bound get_version reply decode to front len\n\nhandle_get_version_reply() uses msg->front_alloc_len as the decode\nboundary for MON_GET_VERSION_REPLY.  That is the size of the reused\nreply buffer, not the number of bytes actually received.\n\nA truncated reply can therefore pass ceph_decode_need() and decode the\nsecond u64 from stale tail bytes left in the buffer by an earlier\nmessage, causing an uninitialized memory read.\n\nUse msg->front.iov_len as the receive-side decode boundary, matching\nother libceph reply handlers and limiting decoding to the bytes that\nwere actually read from the wire.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68433","epss":0.00291,"percentile":0.21455,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68433","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68434","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68434","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms  Commit b1b4efea05a5 (\"serial: 8250_mid: Disable DMA for selected platforms\") replaced the dnv_board setup and exit callbacks with PTR_IF(false, ...), which evaluates to NULL. However, the three call sites in mid8250_probe() and mid8250_remove() unconditionally dereference these function pointers without NULL checks, causing a NULL pointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon D (ICX-D/CDF), or Snowridge (SNR) platform.  Fix this by adding the missing NULL checks before calling the setup and exit callbacks.","cvss":[],"epss":[{"cve":"CVE-2026-68434","epss":0.00177,"percentile":0.07395,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68434","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68434","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1096397c31f6bffa95e77bdd18fbca085be83e10","https://git.kernel.org/stable/c/4ea933a36a14bec19b71025cdd8407bafbd67ec1","https://git.kernel.org/stable/c/600dcd548fb2b00a69f447684f52ba45d5a3540e","https://git.kernel.org/stable/c/7fb13fd7e9a59a37cd911efff83abe19e3ee029d","https://git.kernel.org/stable/c/8cbad52ccfa6a7f089cfab34979bc6cc3bff25be","https://git.kernel.org/stable/c/b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56","https://git.kernel.org/stable/c/bdaa8871b53fe9b1730ef64dda2fcd662fd83339","https://git.kernel.org/stable/c/f85a42fb90399dedcf81c146d09c07e4548b1e8c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms\n\nCommit b1b4efea05a5 (\"serial: 8250_mid: Disable DMA for selected\nplatforms\") replaced the dnv_board setup and exit callbacks with\nPTR_IF(false, ...), which evaluates to NULL. However, the three call\nsites in mid8250_probe() and mid8250_remove() unconditionally\ndereference these function pointers without NULL checks, causing a NULL\npointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon\nD (ICX-D/CDF), or Snowridge (SNR) platform.\n\nFix this by adding the missing NULL checks before calling the setup and\nexit callbacks.","cvss":[],"epss":[{"cve":"CVE-2026-68434","epss":0.00177,"percentile":0.07395,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68434","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68435","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68435","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  LoongArch: Fix address space mismatch in kexec command line lookup  When searching the loaded segments for the \"kexec\" command line marker, the kexec_load(2) path (file_mode == 0) passes the user-space segment buffer straight to strncmp() through a bogus (char __user *) cast. This dereferences a user pointer in kernel context, which is wrong and is flagged by sparse:    arch/loongarch/kernel/machine_kexec.c:84:51: sparse: incorrect type in   argument 2 (different address spaces) @@ expected char const * @@ got   char [noderef] __user *  Here copy the marker-sized prefix of each segment into a small on-stack buffer with copy_from_user() before comparing, and skip segments that fault. The subsequent copy_from_user() that stages the full command line into the safe area is left unchanged.","cvss":[],"epss":[{"cve":"CVE-2026-68435","epss":0.00155,"percentile":0.04965,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-68435","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68435","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/485ed44db5694d8d2e5027f63ad608e705286f30","https://git.kernel.org/stable/c/7a54e0cbaad4a5a09e7cc7a4f05d181048e98ca7","https://git.kernel.org/stable/c/a94d6726ec8680a2b0c453fc782a543f68a1ea06"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Fix address space mismatch in kexec command line lookup\n\nWhen searching the loaded segments for the \"kexec\" command line marker,\nthe kexec_load(2) path (file_mode == 0) passes the user-space segment\nbuffer straight to strncmp() through a bogus (char __user *) cast. This\ndereferences a user pointer in kernel context, which is wrong and is\nflagged by sparse:\n\n  arch/loongarch/kernel/machine_kexec.c:84:51: sparse: incorrect type in\n  argument 2 (different address spaces) @@ expected char const * @@ got\n  char [noderef] __user *\n\nHere copy the marker-sized prefix of each segment into a small on-stack\nbuffer with copy_from_user() before comparing, and skip segments that\nfault. The subsequent copy_from_user() that stages the full command line\ninto the safe area is left unchanged.","cvss":[],"epss":[{"cve":"CVE-2026-68435","epss":0.00155,"percentile":0.04965,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68435","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68441","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains  When a TC filter attached to a qdisc filter chain returns TC_ACT_REDIRECT (ex: via an eBPF program calling bpf_redirect() or an act_bpf action), the redirect was silently lost i.e no qdisc classify function handled TC_ACT_REDIRECT, so the packet fell through the switch and was enqueued normally instead of being redirected.  This has been broken since bpf_redirect() was introduced for TC in commit 27b29f63058d (\"bpf: add bpf_redirect() helper\"). We got lucky for a long time because bpf_net_context was a per-CPU variable that was always available.  commit 401cb7dae813 (\"net: Reference bpf_redirect_info via task_struct on PREEMPT_RT.\") turned bpf_net_context into a task_struct member that is only set up by explicit callers. Without a caller setting it up, bpf_redirect() itself crashes with a NULL pointer dereference in bpf_net_ctx_get_ri(). However, even with bpf_net_context available, TC_ACT_REDIRECT from qdisc filter chains cannot be honored without adding skb_do_redirect() calls to every qdisc classify function, which would require changes across net/sched/. Isolate it to ebpf core where it belongs.  Instead, add a tcf_classify_qdisc() inline helper in pkt_cls.h, as a wrapper around tcf_classify() for use by qdisc classify functions and tcf_qevent_handle(). When the classify verdict is TC_ACT_REDIRECT, the wrapper converts it to TC_ACT_SHOT, dropping the packet rather than letting it continue silently. Dropping is preferred over letting the packet through because the user immediately sees packet loss. Silently passing the packet through would hide the problem and leave the user wondering why their redirect is not working.  The clsact fast path, tc_run() continues to call tcf_classify() directly and is unaffected: TC_ACT_REDIRECT is returned as-is and handled by sch_handle_egress/ingress() calling skb_do_redirect() as before.","cvss":[],"epss":[{"cve":"CVE-2026-68441","epss":0.00148,"percentile":0.04373,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.074},"relatedVulnerabilities":[{"id":"CVE-2026-68441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68441","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/c8fd74445e86f88096d2f6cf0f9e4d54d8ed1781","https://git.kernel.org/stable/c/ec48b3be2c8595dd290be883dbd4fb8b2f9f5d5e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: Handle TC_ACT_REDIRECT from qdisc filter chains\n\nWhen a TC filter attached to a qdisc filter chain returns\nTC_ACT_REDIRECT (ex: via an eBPF program calling bpf_redirect() or an\nact_bpf action), the redirect was silently lost i.e no qdisc classify\nfunction handled TC_ACT_REDIRECT, so the packet fell through the\nswitch and was enqueued normally instead of being redirected.\n\nThis has been broken since bpf_redirect() was introduced for TC in\ncommit 27b29f63058d (\"bpf: add bpf_redirect() helper\"). We got lucky\nfor a long time because bpf_net_context was a per-CPU variable that\nwas always available.\n\ncommit 401cb7dae813 (\"net: Reference bpf_redirect_info via task_struct\non PREEMPT_RT.\") turned bpf_net_context into a task_struct member that\nis only set up by explicit callers. Without a caller setting it up,\nbpf_redirect() itself crashes with a NULL pointer dereference in\nbpf_net_ctx_get_ri(). However, even with bpf_net_context available,\nTC_ACT_REDIRECT from qdisc filter chains cannot be honored without\nadding skb_do_redirect() calls to every qdisc classify function, which\nwould require changes across net/sched/. Isolate it to ebpf core where\nit belongs.\n\nInstead, add a tcf_classify_qdisc() inline helper in pkt_cls.h, as a\nwrapper around tcf_classify() for use by qdisc classify functions and\ntcf_qevent_handle(). When the classify verdict is TC_ACT_REDIRECT,\nthe wrapper converts it to TC_ACT_SHOT, dropping the packet rather\nthan letting it continue silently. Dropping is preferred over\nletting the packet through because the user immediately sees packet\nloss. Silently passing the packet through would hide the problem and\nleave the user wondering why their redirect is not working.\n\nThe clsact fast path, tc_run() continues to call tcf_classify() directly\nand is unaffected: TC_ACT_REDIRECT is returned as-is and handled by\nsch_handle_egress/ingress() calling skb_do_redirect() as before.","cvss":[],"epss":[{"cve":"CVE-2026-68441","epss":0.00148,"percentile":0.04373,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68441","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68444","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68444","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()  ffa_partition_info_get() passes uuid_str directly to uuid_parse() without a NULL check. When a caller passes NULL, uuid_parse() -> __uuid_parse() -> uuid_is_valid() dereferences the pointer, causing a kernel panic:    |  Unable to handle kernel NULL pointer dereference at virtual address   |  0000000000000040   |  pc : uuid_parse+0x40/0xac   |  lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa]  Add a NULL guard before uuid_parse() so a NULL argument returns -ENODEV instead of crashing. Callers are expected to always supply a valid partition UUID, so NULL is not a supported input.","cvss":[],"epss":[{"cve":"CVE-2026-68444","epss":0.00173,"percentile":0.06892,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-68444","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68444","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/12a42c610e4432e7708cc48d607e5903fffe0aad","https://git.kernel.org/stable/c/7201e56e52d18abf4cd0a2fee45daf9dc08b5b97","https://git.kernel.org/stable/c/7dfb020e3048411fbca91e9ad6174da9a2d3e2b3","https://git.kernel.org/stable/c/86f5ea90f73bb7154593bb96f3411e197f3d4fbe","https://git.kernel.org/stable/c/8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8","https://git.kernel.org/stable/c/996c5c19d5b5ac5b98a7b5a406b548305841c301","https://git.kernel.org/stable/c/ddf85f0c32e05baafbd9c3a44859858db90eec48"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()\n\nffa_partition_info_get() passes uuid_str directly to uuid_parse()\nwithout a NULL check. When a caller passes NULL, uuid_parse() ->\n__uuid_parse() -> uuid_is_valid() dereferences the pointer, causing\na kernel panic:\n\n  |  Unable to handle kernel NULL pointer dereference at virtual address\n  |  0000000000000040\n  |  pc : uuid_parse+0x40/0xac\n  |  lr : ffa_partition_info_get+0x1c/0x94 [arm_ffa]\n\nAdd a NULL guard before uuid_parse() so a NULL argument returns\n-ENODEV instead of crashing. Callers are expected to always supply\na valid partition UUID, so NULL is not a supported input.","cvss":[],"epss":[{"cve":"CVE-2026-68444","epss":0.00173,"percentile":0.06892,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68444","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68445","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68445","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vc4: Prevent shader BO mappings from becoming writable  vc4_gem_object_mmap() rejects a writable mapping of a validated shader BO, but leaves VM_MAYWRITE set.  Userspace can map the BO read-only and then turn it writable with mprotect().  Validated shader BOs must stay read-only: the validator checks the instructions once and the GPU trusts them afterwards.  A writable mapping lets userspace rewrite the code after validation, bypassing the validator.  Clear VM_MAYWRITE on the read-only path so the mapping cannot be upgraded, as i915 already does for its read-only objects.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68445","epss":0.00126,"percentile":0.02628,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-68445","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68445","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/019e6ad247f7fd038d2e009789f6d9bfcccb1ae7","https://git.kernel.org/stable/c/0c9e6367639548307d3f578f6943ce72c9d39087","https://git.kernel.org/stable/c/6deaa317201851c644c431b57682e54d06b35838","https://git.kernel.org/stable/c/9f0ee411fc2d76333d6087c5862ffa907cf7a175","https://git.kernel.org/stable/c/fe168ef1d232d734d9998fd74822e2e20930dfff"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Prevent shader BO mappings from becoming writable\n\nvc4_gem_object_mmap() rejects a writable mapping of a validated shader\nBO, but leaves VM_MAYWRITE set.  Userspace can map the BO read-only and\nthen turn it writable with mprotect().\n\nValidated shader BOs must stay read-only: the validator checks the\ninstructions once and the GPU trusts them afterwards.  A writable\nmapping lets userspace rewrite the code after validation, bypassing the\nvalidator.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 already does for its read-only objects.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68445","epss":0.00126,"percentile":0.02628,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68445","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68446","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vmwgfx: Validate vmw_surface_metadata::array_size  This field comes from userspace and should be validated against specific limits depending on which Shader Model (SM) is available.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68446","epss":0.0012,"percentile":0.02092,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-68446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68446","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0403cec2aff8037bc246cf9a0831eb169ddcd9df","https://git.kernel.org/stable/c/5ff94e1279176b539d451e3e754fdcbd1a8d520a","https://git.kernel.org/stable/c/6910ccaf41678f7761ba2e57d72b77d056320b4d","https://git.kernel.org/stable/c/71779fe8bf403a9b3e28dc59229fa556db32d35d","https://git.kernel.org/stable/c/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991","https://git.kernel.org/stable/c/aded8463466ede7a7fbd1bbf821756c67c83e89b","https://git.kernel.org/stable/c/b1379f0c42b88cb60b9f3757eb5d1e73ad460ed8","https://git.kernel.org/stable/c/e949adf2d42678fb391a41db277e2fcb12090566"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Validate vmw_surface_metadata::array_size\n\nThis field comes from userspace and should be validated against specific\nlimits depending on which Shader Model (SM) is available.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68446","epss":0.0012,"percentile":0.02092,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68446","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68447","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68447","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size  CRIU checkpoint copies the MQD control stack using cp_hqd_cntl_stack_size from hardware without bounding it to the allocated BO region. If the HW field is larger than the queue's control stack allocation, memcpy reads past the BO into adjacent GTT memory and can leak kernel data to userspace.  Store the page-aligned control stack BO size in mqd_manager and clamp checkpoint copies and reported checkpoint sizes to min(cp_hqd_cntl_stack_size, mm->ctl_stack_size). Apply the same bound for multi-XCC v9.4.3 checkpoint layout.  (cherry picked from commit 6c2abd0ec09e86c6323010673766f76050e28aa3)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68447","epss":0.0011,"percentile":0.01383,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0803},"relatedVulnerabilities":[{"id":"CVE-2026-68447","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68447","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/426ffae6ecc7ec77d32bf8be065c21a1b881b084","https://git.kernel.org/stable/c/a0d87beb2660a5098b2b0ecdc1e96810a9074ea9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size\n\nCRIU checkpoint copies the MQD control stack using cp_hqd_cntl_stack_size\nfrom hardware without bounding it to the allocated BO region. If the HW\nfield is larger than the queue's control stack allocation, memcpy reads\npast the BO into adjacent GTT memory and can leak kernel data to userspace.\n\nStore the page-aligned control stack BO size in mqd_manager and clamp\ncheckpoint copies and reported checkpoint sizes to\nmin(cp_hqd_cntl_stack_size, mm->ctl_stack_size). Apply the same bound\nfor multi-XCC v9.4.3 checkpoint layout.\n\n(cherry picked from commit 6c2abd0ec09e86c6323010673766f76050e28aa3)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68447","epss":0.0011,"percentile":0.01383,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68447","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68448","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68448","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ovl: check access to copy_file_range source with src mounter creds  Commit 5dae222a5ff0c (\"vfs: allow copy_file_range to copy across devices\") allowed filesystems that implement the copy_file_range() f_op to decide if they want to access cross-sb copy from/to the same fs type.  The same commit added checks to verify same sb copy for filesystems that implement ->copy_file_range() and do not support cross-sb copy at the time, namely, to ceph, fuse and nfs.  The two remaining fs which implement ->copy_file_range(), cifs and overlayfs started to support cross-sb copy from this time.  While overlayfs does support cross-sb copy when the two underlying files are on the same base fs, the copy operation on the two real files from two different overalyfs filesystems is performed with the mounter creds of the destination overlayfs and the read permission access hook for the source file was called with the wrong creds.  This could cause either deny of access to copy which would otherwise be allowed (e.g. with splice) or allow read access to file which would otherwise be denied.  Fix the latter case by explicitly verifying read access to source file with the source overlayfs mounter creds.  The former case remains a quirk of cross-sb overlayfs copy, but userspace could fall back to regular copy so no harm done.","cvss":[],"epss":[{"cve":"CVE-2026-68448","epss":0.00155,"percentile":0.04966,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-68448","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68448","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1f4a107439d2e43db176e34919933e617cb7f2c5","https://git.kernel.org/stable/c/9ec22c8113d8cf72ed7197bb61037dcad09e50d8","https://git.kernel.org/stable/c/a1e0eb8f55cfe09bb31a202a388babc411292656"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\novl: check access to copy_file_range source with src mounter creds\n\nCommit 5dae222a5ff0c (\"vfs: allow copy_file_range to copy across devices\")\nallowed filesystems that implement the copy_file_range() f_op to decide\nif they want to access cross-sb copy from/to the same fs type.\n\nThe same commit added checks to verify same sb copy for filesystems that\nimplement ->copy_file_range() and do not support cross-sb copy at the\ntime, namely, to ceph, fuse and nfs.\n\nThe two remaining fs which implement ->copy_file_range(), cifs and\noverlayfs started to support cross-sb copy from this time.\n\nWhile overlayfs does support cross-sb copy when the two underlying files\nare on the same base fs, the copy operation on the two real files from\ntwo different overalyfs filesystems is performed with the mounter\ncreds of the destination overlayfs and the read permission access hook\nfor the source file was called with the wrong creds.\n\nThis could cause either deny of access to copy which would otherwise be\nallowed (e.g. with splice) or allow read access to file which would\notherwise be denied.\n\nFix the latter case by explicitly verifying read access to source file\nwith the source overlayfs mounter creds.\n\nThe former case remains a quirk of cross-sb overlayfs copy, but\nuserspace could fall back to regular copy so no harm done.","cvss":[],"epss":[{"cve":"CVE-2026-68448","epss":0.00155,"percentile":0.04966,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68448","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68449","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68449","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning  The hand-rolled bit-scanning loop in the NCQ completion path has an infinite loop bug.  When tag_mask has only high bits set (e.g. 0x80000000), the inner while loop left-shifts tag_mask until it overflows to 0.  At that point !(0 & 1) is always true and 0 <<= 1 stays 0, causing an infinite loop in hardirq context with a spinlock held.  Replace the open-coded bit-scanning with __ffs() which correctly finds the least significant set bit and is bounded by the width of the argument.","cvss":[],"epss":[{"cve":"CVE-2026-68449","epss":0.00161,"percentile":0.05647,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-68449","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68449","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1842d45f461a78988254631893329bdf4596e954","https://git.kernel.org/stable/c/29b916d3556bd12a95be7c56ca391b8cd572f8be","https://git.kernel.org/stable/c/4c6e64cae2b2dab32ad9099faa339f6a72c0ce16","https://git.kernel.org/stable/c/8c5de0d8ab6824cfdadcbbe1be4c6c9d9f4c1f80","https://git.kernel.org/stable/c/c2130f6553f4a5cbdc259de069600117a995f197","https://git.kernel.org/stable/c/d72e8089dc332ac48293512ef0de77cbe0e04d25","https://git.kernel.org/stable/c/ea9fa4dabe476f85fe73df30a6ab61a23c22fda4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning\n\nThe hand-rolled bit-scanning loop in the NCQ completion path has an\ninfinite loop bug.  When tag_mask has only high bits set (e.g.\n0x80000000), the inner while loop left-shifts tag_mask until it\noverflows to 0.  At that point !(0 & 1) is always true and 0 <<= 1\nstays 0, causing an infinite loop in hardirq context with a spinlock\nheld.\n\nReplace the open-coded bit-scanning with __ffs() which correctly\nfinds the least significant set bit and is bounded by the width of\nthe argument.","cvss":[],"epss":[{"cve":"CVE-2026-68449","epss":0.00161,"percentile":0.05647,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68449","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68450","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: free mapping node on duplicate reloc root insert  __add_reloc_root() allocates a mapping_node before inserting it into rc->reloc_root_tree.  If rb_simple_insert() finds an existing entry, it returns the existing rb_node and leaves the newly allocated node unlinked.  The error path then returns -EEXIST without freeing the new node.  Since the node was never inserted into reloc_root_tree, the later cleanup in put_reloc_control() cannot find it either.  Free the newly allocated node before returning -EEXIST.  The callers currently assert that -EEXIST should not happen, so this is a defensive cleanup for an unexpected duplicate insert path.  If the path is ever reached, the local allocation should still be released.","cvss":[],"epss":[{"cve":"CVE-2026-68450","epss":0.00161,"percentile":0.05647,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-68450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68450","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/14a8be9428435ee17f17fae7991215c246b7fd43","https://git.kernel.org/stable/c/29d9746812d8b7c37d594f484e994fd552c3ec33","https://git.kernel.org/stable/c/6a8269b6459ed870a8156c106a0f597383907872","https://git.kernel.org/stable/c/797dc567146c7e3c4f8d9680e4fbc76e0a6d9151","https://git.kernel.org/stable/c/92bedc0455552b42ada1a1f42b0e3a8593cdfccc","https://git.kernel.org/stable/c/ae0629ff9ccb836416ada129f4edc7efea6eaaad","https://git.kernel.org/stable/c/b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: free mapping node on duplicate reloc root insert\n\n__add_reloc_root() allocates a mapping_node before inserting it into\nrc->reloc_root_tree.  If rb_simple_insert() finds an existing entry, it\nreturns the existing rb_node and leaves the newly allocated node unlinked.\n\nThe error path then returns -EEXIST without freeing the new node.  Since\nthe node was never inserted into reloc_root_tree, the later cleanup in\nput_reloc_control() cannot find it either.\n\nFree the newly allocated node before returning -EEXIST.\n\nThe callers currently assert that -EEXIST should not happen, so this is a\ndefensive cleanup for an unexpected duplicate insert path.  If the path is\never reached, the local allocation should still be released.","cvss":[],"epss":[{"cve":"CVE-2026-68450","epss":0.00161,"percentile":0.05647,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68450","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68451","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68451","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/zcrypt: Validate length for CCA ECC private key requests  cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68451","epss":0.00132,"percentile":0.03103,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10097999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-68451","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68451","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/013a4484f061a2b41f052e25c0015203287e63f1","https://git.kernel.org/stable/c/447a37a6bef11bfd3645069e380460b11386e2b9","https://git.kernel.org/stable/c/7dc306ff7c4d951582adaae65e0aee9fb4968dbe","https://git.kernel.org/stable/c/8fa3e9435a13c335efb63fb4f4e77531a0031159","https://git.kernel.org/stable/c/a9ae0f6dd45c3ccc1d69363f7aea8af179122730","https://git.kernel.org/stable/c/dd25bd9b0f36849808bd7625dcc59dd4c1aeef3e","https://git.kernel.org/stable/c/ecc3b8691c1935f9f3e4eb964ab11e40fdec17f5","https://git.kernel.org/stable/c/f0831f13c42c1261d449dcee8a035e1c6cd9fcaa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Validate length for CCA ECC private key requests\n\ncca_ecc2protkey() derives the copy length for the CPRB parameter\nblock directly from the length field in the key token. Reject the\nrequest early if the token length exceeds the available space in the\nparameter block.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68451","epss":0.00132,"percentile":0.03103,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68451","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68452","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68452","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/zcrypt: Validate length for CCA AES cipher key requests  cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68452","epss":0.00129,"percentile":0.02908,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-68452","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68452","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/06afe425d5283b9764303de47f554da5a808ce8a","https://git.kernel.org/stable/c/3859f630b674801a00bca39bc451f52288591f65","https://git.kernel.org/stable/c/406b317ea2b501f6f5eca1264293c9399a73a778","https://git.kernel.org/stable/c/4e500ecb6704d879f9c2417c2ed6faba595015ca","https://git.kernel.org/stable/c/4fc46deceda076d429ef3fab2ccf8d96629ebd23","https://git.kernel.org/stable/c/7f9e5a3dbb14a9b321a1dfa30390402c673f82dc","https://git.kernel.org/stable/c/ad93a1f1a45652478c0cf4eb029114e03af57f3b","https://git.kernel.org/stable/c/be037204e4f595e4bd2159acda146677a1dc6342"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Validate length for CCA AES cipher key requests\n\ncca_cipher2protkey() derives the copy length for the CPRB parameter\nblock directly from the length field in the key token. Reject the\nrequest early if the token length exceeds the available space in the\nparameter block.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68452","epss":0.00129,"percentile":0.02908,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68452","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68453","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68453","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/zcrypt: Fix buffer over-read in cca_cipher2protkey  Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size.  The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read.  So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of   sizeof key token struct ... key buf length","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68453","epss":0.00127,"percentile":0.02654,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09271},"relatedVulnerabilities":[{"id":"CVE-2026-68453","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68453","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/36b230835b8a008266aad22168ca52afacc8a58d","https://git.kernel.org/stable/c/3b2abee2a678607ae27975bc6833785c2002df43","https://git.kernel.org/stable/c/a57fd7fcdb63e2d5ceac78bbe825ec986062a9da"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Fix buffer over-read in cca_cipher2protkey\n\nAdd validation of both the actual key buffer size and token length\nfields in all the cca_check_sec*token() functions. Additionally check\nin cca_gencipherkey() for possible underflow with returned key size.\n\nThe CCA token structures contain user-controlled len fields that\nwere used in operations without proper validation against both the\nactual buffer size and minimum token structure size. An attacker\ncould set this field larger than the actual buffer size, leading to\nreading beyond buffer boundaries. This may result in a kernel crash or\nexposure of memory via sending this as part of a request down to the\ncrypto card. Also an attacker could have used a very small len value\nand thus enforce a buffer under-run which may produce similar effects\nas a over-read.\n\nSo now a key must\n- key buf length must be at least sizeof the token struct\n- the key len field inside the token must fit into the range of\n  sizeof key token struct ... key buf length","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68453","epss":0.00127,"percentile":0.02654,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68453","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68470","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68470","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: validate extension-frame layout before RX  Extension frames only have the extension header at the regular 802.11 header offset. The generic RX path can still reach helpers and interface dispatch code that read regular header address fields before unsupported extension subtypes are dropped.  mac80211 currently only handles S1G beacon extension frames. Drop other extension subtypes before they can reach regular-header RX processing. For S1G beacons, linearize the SKB with the management-frame path and require the fixed S1G beacon header, including optional fixed fields indicated by frame control, before generic RX dispatch.  Route S1G beacons through the station/default-link RX path without regular-header station lookup. Avoid regular-header address reads in the mac80211 RX paths that process S1G extension beacons, including accept-frame, duplicate-detection, address-copy, and MLO address-translation paths.  Also make ieee80211_get_bssid() length-safe before returning the S1G source-address pointer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68470","epss":0.00289,"percentile":0.21261,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23553500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-68470","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68470","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/57d503ce32eccfa7650065ca4c560f7e29a2e676","https://git.kernel.org/stable/c/625fc704b19cb48d7d269ad54ffffb4d3bf9c7ed"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: validate extension-frame layout before RX\n\nExtension frames only have the extension header at the regular 802.11\nheader offset. The generic RX path can still reach helpers and interface\ndispatch code that read regular header address fields before unsupported\nextension subtypes are dropped.\n\nmac80211 currently only handles S1G beacon extension frames. Drop other\nextension subtypes before they can reach regular-header RX processing.\nFor S1G beacons, linearize the SKB with the management-frame path and\nrequire the fixed S1G beacon header, including optional fixed fields\nindicated by frame control, before generic RX dispatch.\n\nRoute S1G beacons through the station/default-link RX path without\nregular-header station lookup. Avoid regular-header address reads in the\nmac80211 RX paths that process S1G extension beacons, including\naccept-frame, duplicate-detection, address-copy, and MLO\naddress-translation paths.\n\nAlso make ieee80211_get_bssid() length-safe before returning the S1G\nsource-address pointer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68470","epss":0.00289,"percentile":0.21261,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68470","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68471","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ieee80211: validate MLE common info length  ieee80211_mle_common_size() uses the first common-info octet as the common information length for all known MLE types. However, ieee80211_mle_size_ok() only validates that octet for Basic, Probe Request, and TDLS MLEs.  Reconfiguration MLEs also skipped the length octet when calculating the minimum common size, and Priority Access MLEs skipped validation of the advertised common information length.  Account for the Reconfiguration common-info length octet and validate the advertised common information length for all known MLE types. Keep unknown-type handling unchanged.  [remove now misleading comment]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68471","epss":0.00314,"percentile":0.24044,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25591},"relatedVulnerabilities":[{"id":"CVE-2026-68471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68471","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/293baeae9b2434a3e432629d7720b5603db2d77e","https://git.kernel.org/stable/c/2b1589fd9a076727a73bfb39e96622a76415ad32","https://git.kernel.org/stable/c/90576bd6921a91eb038bffbb4b9467c2dc26aa1d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ieee80211: validate MLE common info length\n\nieee80211_mle_common_size() uses the first common-info octet as the\ncommon information length for all known MLE types. However,\nieee80211_mle_size_ok() only validates that octet for Basic, Probe\nRequest, and TDLS MLEs.\n\nReconfiguration MLEs also skipped the length octet when calculating the\nminimum common size, and Priority Access MLEs skipped validation of the\nadvertised common information length.\n\nAccount for the Reconfiguration common-info length octet and validate\nthe advertised common information length for all known MLE types. Keep\nunknown-type handling unchanged.\n\n[remove now misleading comment]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68471","epss":0.00314,"percentile":0.24044,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68471","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68476","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68476","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipvs: reload ip header after head reallocation  __ip_vs_get_out_rt() calls skb_ensure_writable() which may reallocate skb->head.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68476","epss":0.00695,"percentile":0.50853,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.6533},"relatedVulnerabilities":[{"id":"CVE-2026-68476","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68476","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/3fb7edd2018bb1ad0a68157383d9b9dac33dd645","https://git.kernel.org/stable/c/4f2d1151421520d7ae16ca8d367d0ca09f5dfbd7","https://git.kernel.org/stable/c/657118cad620172dfd8f6ed5717fd75c0d1f7a5a","https://git.kernel.org/stable/c/a10f5080afbed242640f2984328de25f84557da1","https://git.kernel.org/stable/c/a2f57827bf7c695b8c72dc4511cae8e86582369d","https://git.kernel.org/stable/c/ac6ac3d35bfc0ade9d17d354c84e503a946ebdab","https://git.kernel.org/stable/c/ad1e14710b360bda087ebf9fb82460eb5ef775de","https://git.kernel.org/stable/c/e51687fc56c2e39ea6e9532925f1aabd4d529f61"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reload ip header after head reallocation\n\n__ip_vs_get_out_rt() calls skb_ensure_writable() which may\nreallocate skb->head.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-68476","epss":0.00695,"percentile":0.50853,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68476","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-68480","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-68480","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  x86/bugs: Make Safe-RET robust against interrupt injection  An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potentially leading to data leakage through speculative execution.  Fixup register state as if the Safe-RET sequence executed successfully by \"emulating\" it, in a manner of speaking, and avoid executing a RET instruction after returning from the interrupt.","cvss":[],"epss":[{"cve":"CVE-2026-68480","epss":0.00234,"percentile":0.14338,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.117},"relatedVulnerabilities":[{"id":"CVE-2026-68480","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68480","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/52db77a13be224e09eb4ba6b4252ae8ab9085c2c","https://git.kernel.org/stable/c/61649a2d61cb0dbc673f0f232f0f0c298bf50442","https://git.kernel.org/stable/c/6703dba1d14cbd6647cd1ccfa3a3fa94b64dd096","https://git.kernel.org/stable/c/7e7f81cf6f5ca3311e526308f55d7c54d3ba71f9","https://git.kernel.org/stable/c/bfe7f9993467ba431b2731437949ac1e2634e771","https://git.kernel.org/stable/c/d0208e08d64d99383e09852a76cc3038c5a4c3ab","https://git.kernel.org/stable/c/dfefa3c51370f84acb643cddf98bb42c885d0483","https://git.kernel.org/stable/c/e262f28a69ae9e0791248f93b0173c1d1f3e1d5d","https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt.","cvss":[],"epss":[{"cve":"CVE-2026-68480","epss":0.00234,"percentile":0.14338,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-68480","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72007","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72007","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pmdomain: imx: Fix i.MX8MP VC8000E power up sequence  Per errata[1]: ERR050531: VPU_NOC power down handshake may hang during VC8000E/VPUMIX power up/down cycling. Description: VC8000E reset de-assertion edge and AXI clock may have a timing issue. Workaround: Set bit2 (vc8000e_clk_en) of BLK_CLK_EN_CSR to 0 to gate off both AXI clock and VC8000E clock sent to VC8000E and AXI clock sent to VPU_NOC m_v_2 interface during VC8000E power up(VC8000E reset is de-asserted by HW)  Add a bool variable is_errata_err050531 in 'struct imx8m_blk_ctrl_domain_data' to represent whether the workaround is needed. If is_errata_err050531 is true, first clear the clk before powering up gpc, then enable the clk after powering up gpc.  [1] https://www.nxp.com/webapp/Download?colCode=IMX8MP_1P33A","cvss":[],"epss":[{"cve":"CVE-2026-72007","epss":0.002,"percentile":0.09943,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-72007","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72007","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/25e252bcf1593b420b12a7231d9dd64b885a2ae2","https://git.kernel.org/stable/c/4907f4c2d98b97e640191af5bcf2814ee1034b76","https://git.kernel.org/stable/c/4ff3960f3527189bc115a927ed3561c758f562f1","https://git.kernel.org/stable/c/87af3ebc112fb3f06753794390daf0f665f151b4","https://git.kernel.org/stable/c/c498928f85651b56a4041ea165a22037eae69580"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx: Fix i.MX8MP VC8000E power up sequence\n\nPer errata[1]:\nERR050531: VPU_NOC power down handshake may hang during VC8000E/VPUMIX\npower up/down cycling.\nDescription: VC8000E reset de-assertion edge and AXI clock may have a\ntiming issue.\nWorkaround: Set bit2 (vc8000e_clk_en) of BLK_CLK_EN_CSR to 0 to gate off\nboth AXI clock and VC8000E clock sent to VC8000E and AXI clock sent to\nVPU_NOC m_v_2 interface during VC8000E power up(VC8000E reset is\nde-asserted by HW)\n\nAdd a bool variable is_errata_err050531 in\n'struct imx8m_blk_ctrl_domain_data' to represent whether the workaround\nis needed. If is_errata_err050531 is true, first clear the clk before\npowering up gpc, then enable the clk after powering up gpc.\n\n[1] https://www.nxp.com/webapp/Download?colCode=IMX8MP_1P33A","cvss":[],"epss":[{"cve":"CVE-2026-72007","epss":0.002,"percentile":0.09943,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72007","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72009","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72009","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI  The MIPI DSI and CSI domains share control bits for clock and reset, which can lead to incorrect behavior if one domain disables the shared resource while the other is still active.  To fix the issue, introduce a shared MIPI PHY power domain to own the common resources and make DSI and CSI its subdomains. This ensures the shared bits are properly managed and not disabled while still in use.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72009","epss":0.00162,"percentile":0.05673,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12393},"relatedVulnerabilities":[{"id":"CVE-2026-72009","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72009","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4ba6d7166750d0b810c6cfc0b1df7585f513b48c","https://git.kernel.org/stable/c/4fd5b33faf092ef2d09f730a7d9e49f9e976ac67","https://git.kernel.org/stable/c/99611233f8cda833169fa6487d5dacdf189e5cb0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI\n\nThe MIPI DSI and CSI domains share control bits for clock and reset, which\ncan lead to incorrect behavior if one domain disables the shared resource\nwhile the other is still active.\n\nTo fix the issue, introduce a shared MIPI PHY power domain to own the\ncommon resources and make DSI and CSI its subdomains. This ensures the\nshared bits are properly managed and not disabled while still in use.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72009","epss":0.00162,"percentile":0.05673,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72009","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72012","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72012","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing/osnoise: Call synchronize_rcu() when unregistering  This ensures that any RCU readers traversing the instance list have finished, before releasing the reference on the tracer that the instance points to.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72012","epss":0.00164,"percentile":0.05928,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72012","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72012","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/38366140dc8ee3568c7f0191d517e117963bd580","https://git.kernel.org/stable/c/3c693635bb7b3a9b6645831a84fed2af46cdf249","https://git.kernel.org/stable/c/428cedade9b2cc8e48f00742df0cfd770e77a803","https://git.kernel.org/stable/c/dd0160a0842337f12e7694d68b184050afc6d3a4","https://git.kernel.org/stable/c/fad36954b29592ce463254179c3043697678481f","https://git.kernel.org/stable/c/fe58f457ad8d0a2bef4e053cfecca4b5cd266b1a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/osnoise: Call synchronize_rcu() when unregistering\n\nThis ensures that any RCU readers traversing the instance list\nhave finished, before releasing the reference on the tracer that\nthe instance points to.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72012","epss":0.00164,"percentile":0.05928,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72012","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72015","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72015","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list  A pseudo-locked group's RMID is freed when it is created. On unmount rmdir_all_sub() unconditionally frees all RMID of all groups, resulting in a double-free of the pseudo-locked group's RMID. The consequence of this is that the original free results in the pseudo-locked group's RMID being added to the rmid_free_lru linked list and the second free then attempts to add the same RMID entry to the rmid_free_lru again.  Do not double-free a pseudo-locked group's RMID.","cvss":[],"epss":[{"cve":"CVE-2026-72015","epss":0.00211,"percentile":0.11313,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-72015","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72015","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/52007bfdce5310e8c8a29849bfbfb188a1e50ca0","https://git.kernel.org/stable/c/52b769165f20b38092f28ce064b4b143471540a7","https://git.kernel.org/stable/c/9168176894332312c12ef052e784735dbf4ffe3f","https://git.kernel.org/stable/c/ad12e70d7dc3c94a05efc61d1e4861078e0e162b","https://git.kernel.org/stable/c/b2fe9e140aa94b2816aab7ebc692b543e418f5e3","https://git.kernel.org/stable/c/b9f089723aee892efc77c349ae47a6b452b293c4","https://git.kernel.org/stable/c/bab7dbba38ed3011972c3d9be2dcdca7575cbe32","https://git.kernel.org/stable/c/f7628eea9212e185a09df3aea603ca8580b8678d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/resctrl: Fix double-add of pseudo-locked region's RMID to free list\n\nA pseudo-locked group's RMID is freed when it is created. On unmount\nrmdir_all_sub() unconditionally frees all RMID of all groups, resulting\nin a double-free of the pseudo-locked group's RMID. The consequence of this\nis that the original free results in the pseudo-locked group's RMID being\nadded to the rmid_free_lru linked list and the second free then attempts\nto add the same RMID entry to the rmid_free_lru again.\n\nDo not double-free a pseudo-locked group's RMID.","cvss":[],"epss":[{"cve":"CVE-2026-72015","epss":0.00211,"percentile":0.11313,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72015","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72017","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72017","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: macb: drop in-flight Tx SKBs on close  The MACB driver has since forever leaked the outgoing SKBs that have not yet been marked as completed. They live in queue->tx_skb which gets freed without remorse nor checking.  macb_free_consistent() gets called in a few codepaths, but only close will trigger the added expressions. In macb_open() and macb_alloc_consistent() failure cases, queues' tx_skb just got allocated and are empty.","cvss":[],"epss":[{"cve":"CVE-2026-72017","epss":0.00206,"percentile":0.10699,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72017","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72017","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0e9797dc4ebdefe1b7f931b1f92d5e98e5dbf655","https://git.kernel.org/stable/c/109241d9880488aafd8e104832b4d4859ad57244","https://git.kernel.org/stable/c/2143fdc0ce27adbb1caaa1a97e0bfb9f3750aef4","https://git.kernel.org/stable/c/26b131b2d5b55a81ef6182769d28105a870c0eb2","https://git.kernel.org/stable/c/27f575836cfebbf872dec020428742b10650a955","https://git.kernel.org/stable/c/6124bd785073659c99385094657b77382ebce11b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: drop in-flight Tx SKBs on close\n\nThe MACB driver has since forever leaked the outgoing SKBs that\nhave not yet been marked as completed. They live in queue->tx_skb\nwhich gets freed without remorse nor checking.\n\nmacb_free_consistent() gets called in a few codepaths, but only close will\ntrigger the added expressions. In macb_open() and macb_alloc_consistent()\nfailure cases, queues' tx_skb just got allocated and are empty.","cvss":[],"epss":[{"cve":"CVE-2026-72017","epss":0.00206,"percentile":0.10699,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72017","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72023","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72023","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  octeontx2-pf: fix SQB pointer leak on init failure  otx2_init_hw_resources() initializes SQ aura and pool resources before several later setup steps. On failure, err_free_sq_ptrs only frees SQB pages, leaving the per-SQ sqb_ptrs arrays behind.  Use otx2_free_sq_res() for the SQ unwind path and let it free sqb_ptrs even when sq->sqe has not been allocated yet.  The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.  An x86_64 allyesconfig build showed no new warnings. As we do not have an OcteonTX2 PF device and the corresponding AF mailbox setup to test with, no runtime testing was able to be performed.","cvss":[],"epss":[{"cve":"CVE-2026-72023","epss":0.00211,"percentile":0.11311,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-72023","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72023","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/148d7ec0a3a98839c320e6cdd112e2e88bfb091b","https://git.kernel.org/stable/c/23d917acd9c9a9fd999688ec3fdde7aa58ab8a14","https://git.kernel.org/stable/c/2cac2eac935ed7e0a9203204e036a1f6090ebc3d","https://git.kernel.org/stable/c/42c2836f10ac0427dac9e9a923d6ee2189dec544","https://git.kernel.org/stable/c/5df30f05db96552903680a17f858d250dfd9e86e","https://git.kernel.org/stable/c/5e023fe2569e630ba23b5558ebe4bf4837af4d16","https://git.kernel.org/stable/c/62e7df6d042aeebd5efb581074e28865c04477be","https://git.kernel.org/stable/c/fca9c22633169a6c5d429a32e439121b6419e2be"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: fix SQB pointer leak on init failure\n\notx2_init_hw_resources() initializes SQ aura and pool resources before\nseveral later setup steps. On failure, err_free_sq_ptrs only frees SQB\npages, leaving the per-SQ sqb_ptrs arrays behind.\n\nUse otx2_free_sq_res() for the SQ unwind path and let it free sqb_ptrs\neven when sq->sqe has not been allocated yet.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nOcteonTX2 PF device and the corresponding AF mailbox setup to test with,\nno runtime testing was able to be performed.","cvss":[],"epss":[{"cve":"CVE-2026-72023","epss":0.00211,"percentile":0.11311,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72023","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72028","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72028","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  riscv: probes: save original sp in rethook trampoline  Reading a word from the stack in a kretprobe crashes a risc-v kernel.  $ cd /sys/kernel/tracing/ $ echo 'r n_tty_write $stack0' > dynamic_events $ echo 1 > events/kprobes/enable Unable to handle kernel paging request at virtual address 0000000200000128 ... [<ffffffff80016d16>] regs_get_kernel_stack_nth+0x26/0x38 [<ffffffff80177196>] process_fetch_insn+0x3ee/0x760 [<ffffffff80177836>] kretprobe_trace_func+0x116/0x1f0 [<ffffffff8017795a>] kretprobe_dispatcher+0x4a/0x58 [<ffffffff8013572e>] kretprobe_rethook_handler+0x5e/0x90 [<ffffffff80180838>] rethook_trampoline_handler+0x70/0x108 [<ffffffff8001ba32>] arch_rethook_trampoline_callback+0x12/0x1c [<ffffffff8001ba84>] arch_rethook_trampoline+0x48/0x94 [<ffffffff8067872a>] tty_write+0x1a/0x30  In regs_get_kernel_stack_nth, regs->sp contains an arbitrary value.  arch_rethook_trampoline saves the registers from the probed function in a struct pt_regs. sp is not saved. Instead, sp is decremented for arch_rethook_trampoline's local stack.  Fix this crash and save the original sp along with the other registers. Use a0 as a temporary register, it is overwritten anyway.  [pjw@kernel.org: added Fixes tag; cc'ed stable]","cvss":[],"epss":[{"cve":"CVE-2026-72028","epss":0.002,"percentile":0.09944,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-72028","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72028","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2faf0198168d2017cb528a79f76c560fda3b6e94","https://git.kernel.org/stable/c/5da5cf48a432e30ded8d58087854e5383a36eff1","https://git.kernel.org/stable/c/91b4d76dd07f1a1f20f73dfebb42ba04ac911a56","https://git.kernel.org/stable/c/bc7b086a45521a986a49045907f017e3e46c763e","https://git.kernel.org/stable/c/c386e1c591d72eab58ee2e69105c8cbc70928857"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: probes: save original sp in rethook trampoline\n\nReading a word from the stack in a kretprobe crashes a risc-v kernel.\n\n$ cd /sys/kernel/tracing/\n$ echo 'r n_tty_write $stack0' > dynamic_events\n$ echo 1 > events/kprobes/enable\nUnable to handle kernel paging request at virtual address 0000000200000128\n...\n[<ffffffff80016d16>] regs_get_kernel_stack_nth+0x26/0x38\n[<ffffffff80177196>] process_fetch_insn+0x3ee/0x760\n[<ffffffff80177836>] kretprobe_trace_func+0x116/0x1f0\n[<ffffffff8017795a>] kretprobe_dispatcher+0x4a/0x58\n[<ffffffff8013572e>] kretprobe_rethook_handler+0x5e/0x90\n[<ffffffff80180838>] rethook_trampoline_handler+0x70/0x108\n[<ffffffff8001ba32>] arch_rethook_trampoline_callback+0x12/0x1c\n[<ffffffff8001ba84>] arch_rethook_trampoline+0x48/0x94\n[<ffffffff8067872a>] tty_write+0x1a/0x30\n\nIn regs_get_kernel_stack_nth, regs->sp contains an arbitrary value.\n\narch_rethook_trampoline saves the registers from the probed function in a\nstruct pt_regs. sp is not saved. Instead, sp is decremented for\narch_rethook_trampoline's local stack.\n\nFix this crash and save the original sp along with the other registers.\nUse a0 as a temporary register, it is overwritten anyway.\n\n[pjw@kernel.org: added Fixes tag; cc'ed stable]","cvss":[],"epss":[{"cve":"CVE-2026-72028","epss":0.002,"percentile":0.09944,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72028","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72030","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72030","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ata: libata-core: Reject an invalid concurrent positioning ranges count  ata_dev_config_cpr() takes the number of range descriptors from buf[0] of the concurrent positioning ranges log (up to 255), which the device reports independently of the log size in the GPL directory. The count is then walked at a fixed 32-byte stride in two places with no bound: the log read here, and the INQUIRY VPD page B9h emitter, which writes one descriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device reporting a count larger than its own log overflows the read buffer (up to 7704 bytes past a 512-byte slab), and a count above 62 overflows the response buffer on the emit side.  Bound the count once, on probe, against both the log the device returned and the number of descriptors the VPD B9h response buffer can hold (ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range count with a warning; this keeps the emitter in bounds with no separate change there.","cvss":[],"epss":[{"cve":"CVE-2026-72030","epss":0.00206,"percentile":0.10698,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72030","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72030","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/01d7d321e6046f87ba270aeeffdc5260209bd91e","https://git.kernel.org/stable/c/4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4","https://git.kernel.org/stable/c/4cb4b4dd8853c4ab3057efe238b2c34277772176","https://git.kernel.org/stable/c/533a0b940f901c15e5cbbd4b5d66e871c209e8ce","https://git.kernel.org/stable/c/b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1","https://git.kernel.org/stable/c/d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-core: Reject an invalid concurrent positioning ranges count\n\nata_dev_config_cpr() takes the number of range descriptors from buf[0]\nof the concurrent positioning ranges log (up to 255), which the device\nreports independently of the log size in the GPL directory. The count is\nthen walked at a fixed 32-byte stride in two places with no bound: the\nlog read here, and the INQUIRY VPD page B9h emitter, which writes one\ndescriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device\nreporting a count larger than its own log overflows the read buffer (up\nto 7704 bytes past a 512-byte slab), and a count above 62 overflows the\nresponse buffer on the emit side.\n\nBound the count once, on probe, against both the log the device returned\nand the number of descriptors the VPD B9h response buffer can hold\n(ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range\ncount with a warning; this keeps the emitter in bounds with no separate\nchange there.","cvss":[],"epss":[{"cve":"CVE-2026-72030","epss":0.00206,"percentile":0.10698,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72030","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72035","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72035","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked  When taprio's software path peeks a non-work-conserving child qdisc, the child stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq() then takes the packet with a direct child ->dequeue() call, which ignores that stash, orphans the peeked skb and desyncs the child's qlen/backlog. With a qfq child this re-enters the child on an emptied list and dereferences NULL, panicking the kernel from softirq on ordinary egress.  Take the packet through qdisc_dequeue_peeked(), as sch_red and sch_sfb now do. The helper returns the child's stashed skb first and is a no-op when there is none, so a work-conserving child is unaffected and the gated path now consumes the skb whose length was charged to the budget.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72035","epss":0.00573,"percentile":0.45431,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.4498049999999999},"relatedVulnerabilities":[{"id":"CVE-2026-72035","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72035","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/17ab5f76f3899f67e5569722f334591f4b88b17b","https://git.kernel.org/stable/c/18d580cb00c55805633bae45e90cf22ed6b8e424","https://git.kernel.org/stable/c/2dcebbd1ad2e180fe7b98bf346ced69a872e11e6","https://git.kernel.org/stable/c/51f8af240aed903e988755af33d7491030b50ae9","https://git.kernel.org/stable/c/6ee5a7665a9080bcb05d703bf981a579436fd05e","https://git.kernel.org/stable/c/e056e1dfcddca877dd46d704e8ec9860cfc9ec44","https://git.kernel.org/stable/c/e2b7ee61989f2d39df6c2cc06f9db1aea69bdb09","https://git.kernel.org/stable/c/f60d5c12e0551012cee5c272b0bcbcc78f7bb506"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nWhen taprio's software path peeks a non-work-conserving child qdisc, the\nchild stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq()\nthen takes the packet with a direct child ->dequeue() call, which ignores\nthat stash, orphans the peeked skb and desyncs the child's qlen/backlog.\nWith a qfq child this re-enters the child on an emptied list and\ndereferences NULL, panicking the kernel from softirq on ordinary egress.\n\nTake the packet through qdisc_dequeue_peeked(), as sch_red and sch_sfb\nnow do. The helper returns the child's stashed skb first and is a no-op\nwhen there is none, so a work-conserving child is unaffected and the\ngated path now consumes the skb whose length was charged to the budget.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72035","epss":0.00573,"percentile":0.45431,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72035","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72040","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72040","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipmi: fix refcount leak in i_ipmi_request()  When a caller provides a `supplied_recv` message to i_ipmi_request(), the function increments the user's `nr_msgs` reference count. If an error occurs later, the out_err cleanup path only frees the recv_msg if the function allocated it itself (i.e., !supplied_recv). In the supplied_recv case the cleanup is skipped, leaving the reference count elevated. The caller ipmi_request_supply_msgs() does not release the supplied_recv on error, so the reference is permanently leaked.  Fix this by explicitly reverting the reference count operations when a supplied recv_msg with a valid user pointer is present in the error path: decrement nr_msgs and drop the user's kref.","cvss":[],"epss":[{"cve":"CVE-2026-72040","epss":0.00206,"percentile":0.10698,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72040","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72040","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0fd23994ec8c5436d9f0b50848deb87ed933e6b3","https://git.kernel.org/stable/c/122ca6b2af714e114c9b872a48372ace31a9ab1f","https://git.kernel.org/stable/c/9409e18ffe7378d202efe1cf69989df9f67b0369","https://git.kernel.org/stable/c/a3f3859cecacb64f18fd446271ece9a3b3f2d4de","https://git.kernel.org/stable/c/e2a3b77df6aef031455dd83ea8ed4344b7dca1f9","https://git.kernel.org/stable/c/f5c5065963024390ddad51bd455d1adc710de575"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: fix refcount leak in i_ipmi_request()\n\nWhen a caller provides a `supplied_recv` message to i_ipmi_request(),\nthe function increments the user's `nr_msgs` reference count. If an\nerror occurs later, the out_err cleanup path only frees the recv_msg\nif the function allocated it itself (i.e., !supplied_recv). In the\nsupplied_recv case the cleanup is skipped, leaving the reference count\nelevated. The caller ipmi_request_supply_msgs() does not release the\nsupplied_recv on error, so the reference is permanently leaked.\n\nFix this by explicitly reverting the reference count operations when a\nsupplied recv_msg with a valid user pointer is present in the error\npath: decrement nr_msgs and drop the user's kref.","cvss":[],"epss":[{"cve":"CVE-2026-72040","epss":0.00206,"percentile":0.10698,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72040","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72041","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72041","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  espintcp: use sk_msg_free_partial to fix partial send  sk_msg_free_partial() ensures consistency of the skmsg at every iteration, without having to manually handle uncharges and offsets. This simplifies the code, and fixes some bugs in skmsg accounting when we don't send the full contents.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72041","epss":0.00695,"percentile":0.50853,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.6533},"relatedVulnerabilities":[{"id":"CVE-2026-72041","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72041","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/007800408002d871f5699bdb944f985896730b8f","https://git.kernel.org/stable/c/14c0b42c8a2cd9b5361bbff45b52f69c62c6a286","https://git.kernel.org/stable/c/4ea8c051b4bd7feec7749a980f2f70e1782b84d7","https://git.kernel.org/stable/c/518dcb84b997dff461800b079e5f2596389f766a","https://git.kernel.org/stable/c/54d73f18f8919735f4d04d6f43374f75756c0180","https://git.kernel.org/stable/c/a338ce41bc933d8f74c39d9b3b6f1d8ca53d9714","https://git.kernel.org/stable/c/a66d45e0ce6d73cd79962d422388e61bfaf0cb50","https://git.kernel.org/stable/c/a977f78adce40b39d90d9567e7987bb110102810"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nespintcp: use sk_msg_free_partial to fix partial send\n\nsk_msg_free_partial() ensures consistency of the skmsg at every\niteration, without having to manually handle uncharges and offsets.\nThis simplifies the code, and fixes some bugs in skmsg accounting when\nwe don't send the full contents.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72041","epss":0.00695,"percentile":0.50853,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72041","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72042","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72042","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipmi: Fix user refcount underflow in event delivery  ipmi_alloc_recv_msg(user) takes the temporary user reference owned by the receive message, and ipmi_free_recv_msg() drops it again. If event delivery fails after allocating receive messages for earlier users, handle_read_event_rsp() rolls those messages back with ipmi_free_recv_msg().  That rollback path still drops user->refcount explicitly after freeing each message. The extra put can free a user that remains linked on intf->users, so later event delivery may dereference a freed user or trip refcount_t's addition-on-zero warning when ipmi_alloc_recv_msg() tries to acquire another reference.  Remove the stale explicit put and the now-dead user assignment. Keep the list_del() and ipmi_free_recv_msg() calls; they are the required rollback operations.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72042","epss":0.00162,"percentile":0.05673,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12393},"relatedVulnerabilities":[{"id":"CVE-2026-72042","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72042","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6aa9e61c46465d231e9beddf56af7effd71be682","https://git.kernel.org/stable/c/7be349d4fcc5e065295b83418a22d27a68afbdb6","https://git.kernel.org/stable/c/ddbb6e3dc9bb4743de686aa1598c31e745cee76b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: Fix user refcount underflow in event delivery\n\nipmi_alloc_recv_msg(user) takes the temporary user reference owned by the\nreceive message, and ipmi_free_recv_msg() drops it again. If event delivery\nfails after allocating receive messages for earlier users,\nhandle_read_event_rsp() rolls those messages back with\nipmi_free_recv_msg().\n\nThat rollback path still drops user->refcount explicitly after freeing each\nmessage. The extra put can free a user that remains linked on intf->users,\nso later event delivery may dereference a freed user or trip refcount_t's\naddition-on-zero warning when ipmi_alloc_recv_msg() tries to acquire\nanother reference.\n\nRemove the stale explicit put and the now-dead user assignment. Keep the\nlist_del() and ipmi_free_recv_msg() calls; they are the required rollback\noperations.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72042","epss":0.00162,"percentile":0.05673,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72042","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72045","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72045","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF  rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to read another function's LMTLINE physical base address and copy it into the caller's own LMT map table entry. The mailbox dispatcher authenticates req->hdr.pcifunc from the IRQ source, but req->base_pcifunc is a separate payload field and is not sanitized.  Reject the request with -EPERM when a VF caller's base_pcifunc is not a valid function under its own PF. is_pf_func_valid() bounds the FUNC field to the PF's configured VF count, keeping the computed index inside the caller's own slot block.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72045","epss":0.00169,"percentile":0.06455,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13773500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72045","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72045","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/04c014e49b9f53d58a8f94adece8a0af3ae1b85c","https://git.kernel.org/stable/c/54535692bec9ef464adc714108eb19e49e38b5a2","https://git.kernel.org/stable/c/59da37fee81a8d76079313348ca13c5bc90dd6ae","https://git.kernel.org/stable/c/6967dd944be2a71eddab3a2ae1a1a4dd9e5f8eed","https://git.kernel.org/stable/c/8cdcf3d2caacdee7ddd363705fb4d93b0c1a0915","https://git.kernel.org/stable/c/c73b8795b45f4ad5a95120d2e9b435ea4616e08e","https://git.kernel.org/stable/c/e9c5b03208507dd6d58b0c23a2c60b5c2f4c1b11"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF\n\nrvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct\nindex into the LMT map table to read another function's LMTLINE\nphysical base address and copy it into the caller's own LMT map table\nentry. The mailbox dispatcher authenticates req->hdr.pcifunc from the\nIRQ source, but req->base_pcifunc is a separate payload field and is\nnot sanitized.\n\nReject the request with -EPERM when a VF caller's base_pcifunc is not a\nvalid function under its own PF. is_pf_func_valid() bounds the FUNC field\nto the PF's configured VF count, keeping the computed index inside the\ncaller's own slot block.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72045","epss":0.00169,"percentile":0.06455,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72045","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72051","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72051","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink  ip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net.  Gate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72051","epss":0.00169,"percentile":0.06447,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13773500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72051","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72051","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/234cd54fc500f69db43e37de38603da617fbbeea","https://git.kernel.org/stable/c/2496fa0b7d180b3ad356b514e7ff93bb14e6140a","https://git.kernel.org/stable/c/2636d061bc237a2446a146e42dcc6563acfa7432","https://git.kernel.org/stable/c/2d53ee7daabe733deb81f51d2cc90188f8ad59a1","https://git.kernel.org/stable/c/5252db8fb604321133138c7069d6fc3fcd89cdee","https://git.kernel.org/stable/c/7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa","https://git.kernel.org/stable/c/82e53e7281c71e174f9f5877c566a623c637b406","https://git.kernel.org/stable/c/d4bcc202a3530c856e1cb183384bc9cc8fddab22"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink\n\nip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the\ntunnel link netns t->net. They differ once the device is created in or\nmoved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t->net can rewrite a tunnel that\nlives in t->net.\n\nGate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top,\nbefore any attribute is parsed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72051","epss":0.00169,"percentile":0.06447,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72051","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72057","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72057","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: act_ct: preserve tc_skb_cb across defragmentation  tcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving and restoring skb->cb. The defrag helper clears IPCB/IP6CB, which aliases the tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through act_ct therefore loses qdisc metadata such as pkt_segs and can trigger WARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled.  Save and restore the full tc_skb_cb around nf_ct_handle_fragments(), matching the pattern used by ovs_ct_handle_fragments().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72057","epss":0.00585,"percentile":0.46012,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.459225},"relatedVulnerabilities":[{"id":"CVE-2026-72057","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72057","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2400c4b05d58834b994500a9eec90a37db44187c","https://git.kernel.org/stable/c/5c3ae5f6c7c6de73ea9b6a75154fe4ed343e1bac","https://git.kernel.org/stable/c/67d6b00a54446c008f52cf70fc0c2ad0c712f85d","https://git.kernel.org/stable/c/9092e15defbe6c7bc241c306093ca9d358a578e7","https://git.kernel.org/stable/c/b3d835407846134b0d54637c0281b39bebef831d","https://git.kernel.org/stable/c/f7f45ceb855d9ba1cba594fb3f383255f7013fad","https://git.kernel.org/stable/c/fb080b6f54835d5d4d11ce3122800e6f0f6689e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: preserve tc_skb_cb across defragmentation\n\ntcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving\nand restoring skb->cb. The defrag helper clears IPCB/IP6CB, which aliases\nthe tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through\nact_ct therefore loses qdisc metadata such as pkt_segs and can trigger\nWARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled.\n\nSave and restore the full tc_skb_cb around nf_ct_handle_fragments(),\nmatching the pattern used by ovs_ct_handle_fragments().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72057","epss":0.00585,"percentile":0.46012,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72057","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72062","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72062","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: mt7621: avoid corruption of shared interrupt trigger state  The bank-shared fields like 'rising' and 'falling' are modified using non-atomic read-modify-write operations. Since every gpio chip instance represents an entire bank of 32 pins, if 'mediatek_gpio_irq_type()' is called concurrently for different IRQs on the same bank a possible overwrite of each other's configuration is possible. Thus, protect this state with 'gpio_generic_lock_irqsave' lock in the same way it is handled in irp_chip 'mediatek_gpio_irq_mask()' and 'mediatek_gpio_irq_unmask()' callbacks.","cvss":[],"epss":[{"cve":"CVE-2026-72062","epss":0.00215,"percentile":0.11851,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1075},"relatedVulnerabilities":[{"id":"CVE-2026-72062","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72062","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1781172526d1092323af443fa03f00e6de560401","https://git.kernel.org/stable/c/207d3ebf36f654a43a934addeb4d6775cb2dd667","https://git.kernel.org/stable/c/877a243006788aaa586b2d087f27c9f3628071b0","https://git.kernel.org/stable/c/a60a40c9ba30edd06d3fb4215fdf430ed968728e","https://git.kernel.org/stable/c/bddf9314a57a243dd11ed945ba11e146e331257e","https://git.kernel.org/stable/c/d3b9026ef78da3018a7d2c5a9c9d611de6d45c47"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mt7621: avoid corruption of shared interrupt trigger state\n\nThe bank-shared fields like 'rising' and 'falling' are modified using\nnon-atomic read-modify-write operations. Since every gpio chip instance\nrepresents an entire bank of 32 pins, if 'mediatek_gpio_irq_type()' is\ncalled concurrently for different IRQs on the same bank a possible overwrite\nof each other's configuration is possible. Thus, protect this state with\n'gpio_generic_lock_irqsave' lock in the same way it is handled in irp_chip\n'mediatek_gpio_irq_mask()' and 'mediatek_gpio_irq_unmask()' callbacks.","cvss":[],"epss":[{"cve":"CVE-2026-72062","epss":0.00215,"percentile":0.11851,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72062","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72063","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72063","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: tegra: do not call pinctrl for GPIO direction  tegra_gpio_direction_input() and tegra_gpio_direction_output() already program the GPIO controller direction registers directly. The additional pinctrl_gpio_direction_input/output() calls do not add a Tegra pinctrl operation, because the Tegra pinmux ops provide GPIO request/free handling but no gpio_set_direction hook.  The extra call still enters the pinctrl core and takes pctldev->mutex. Shared GPIO users can call the direction path while holding their per-line spinlock, so this otherwise redundant pinctrl direction call can sleep in an atomic context.  This was found by our static analysis tool and then confirmed by manual review of tegra_gpio_probe(), the Tegra GPIO direction callbacks and the Tegra pinctrl ops. The reviewed path has a default non-sleeping struct gpio_chip while the direction callback still enters the pinctrl mutex path.  A directed runtime validation kept the same non-sleeping chip registration and drove:    gpio_shared_proxy_direction_output()   gpiod_direction_output_raw_commit()   tegra_gpio_direction_output()   pinctrl_gpio_direction_output()  Lockdep reported a sleep-in-atomic warning with the shared GPIO spinlock held and pinctrl_get_device_gpio_range() plus tegra_gpio_direction_output() on the stack.  Do not mark the whole chip as can_sleep to paper over this: can_sleep describes whether get()/set() may sleep, and Tegra value access is MMIO. Remove the redundant pinctrl direction calls and keep pinctrl involvement in the existing request/free path.","cvss":[],"epss":[{"cve":"CVE-2026-72063","epss":0.0022,"percentile":0.12444,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-72063","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72063","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/616188becd4a208afbae1653fc5241e1748bae80","https://git.kernel.org/stable/c/628c63f96f4564fa145f602af2d41daf9532201f","https://git.kernel.org/stable/c/89904b4f1dc0f9550c3f206dcdfceed0b7ce7c49","https://git.kernel.org/stable/c/ac761e66708d51dac35c4c7f1891ea991dc788f0","https://git.kernel.org/stable/c/cd17c5a1d9f186b57e9e2949be427803b7110a5c","https://git.kernel.org/stable/c/d3b92d16e1c4debec7526b6dbb2d98d0aeed796b","https://git.kernel.org/stable/c/d3e91a95b2b0fc6336dbf3ec90d831a1654d2720","https://git.kernel.org/stable/c/e57a4845b0da60a7b9f052160878097826320954"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: tegra: do not call pinctrl for GPIO direction\n\ntegra_gpio_direction_input() and tegra_gpio_direction_output() already\nprogram the GPIO controller direction registers directly. The additional\npinctrl_gpio_direction_input/output() calls do not add a Tegra pinctrl\noperation, because the Tegra pinmux ops provide GPIO request/free\nhandling but no gpio_set_direction hook.\n\nThe extra call still enters the pinctrl core and takes pctldev->mutex.\nShared GPIO users can call the direction path while holding their\nper-line spinlock, so this otherwise redundant pinctrl direction call can\nsleep in an atomic context.\n\nThis was found by our static analysis tool and then confirmed by manual\nreview of tegra_gpio_probe(), the Tegra GPIO direction callbacks and the\nTegra pinctrl ops. The reviewed path has a default non-sleeping\nstruct gpio_chip while the direction callback still enters the pinctrl\nmutex path.\n\nA directed runtime validation kept the same non-sleeping chip registration\nand drove:\n\n  gpio_shared_proxy_direction_output()\n  gpiod_direction_output_raw_commit()\n  tegra_gpio_direction_output()\n  pinctrl_gpio_direction_output()\n\nLockdep reported a sleep-in-atomic warning with the shared GPIO spinlock\nheld and pinctrl_get_device_gpio_range() plus tegra_gpio_direction_output()\non the stack.\n\nDo not mark the whole chip as can_sleep to paper over this: can_sleep\ndescribes whether get()/set() may sleep, and Tegra value access is MMIO.\nRemove the redundant pinctrl direction calls and keep pinctrl involvement\nin the existing request/free path.","cvss":[],"epss":[{"cve":"CVE-2026-72063","epss":0.0022,"percentile":0.12444,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72063","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72065","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72065","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: mana: Validate the packet length reported by the NIC  Validate the packet length reported in the RX CQE before passing it to skb processing. The CQE is supplied by the NIC device and should not be blindly trusted.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72065","epss":0.00728,"percentile":0.52054,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.68432},"relatedVulnerabilities":[{"id":"CVE-2026-72065","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72065","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/282c5214ca4eb3799158c76782646e86d2945d1b","https://git.kernel.org/stable/c/2e276b14b6d378372bf0152df89286cbe7632fb0","https://git.kernel.org/stable/c/2e2a83b4998af4384e677d3b2ac08565274279bf","https://git.kernel.org/stable/c/6080189291d958604dcefe513a13900835ac982f","https://git.kernel.org/stable/c/6d13eaa13341a8f80aaf86f78591e1b1d393711d","https://git.kernel.org/stable/c/a631f82f89c76084ad5b2b9c043d3b391ffa56d8","https://git.kernel.org/stable/c/d2568e64d01f480200063fadd67d6938f676c66f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Validate the packet length reported by the NIC\n\nValidate the packet length reported in the RX CQE before passing it\nto skb processing. The CQE is supplied by the NIC device and should\nnot be blindly trusted.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72065","epss":0.00728,"percentile":0.52054,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72065","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72069","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72069","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()  rt_spin_unlock() releases the RCU protection before unlocking the lock. That opens the door for the following UAF scenario:   T1\t\t\t\t\tT2  spin_lock(&p->lock);\t\trcu_read_lock();  invalidate(p);\t\t\tp = rcu_dereference(ptr);  rcu_assign_pointer(ptr, NULL);\tif (!p) return;  spin_unlock(&p->lock);\t\tspin_lock(&p->lock)  \t\t\t\t   lock(&lock->lock); \t\t\t\t   rcu_read_lock();  kfree_rcu(p);\t\t\trcu_read_unlock(); \t\t\t\t.... \t\t\t\tspin_unlock(&p->lock) \t\t\t\t  rcu_read_unlock(); // Ends grace period  rcu_do_batch()    kfree(p); \t\t\t    UAF ->\t  rt_mutex_cmpxchg_release(&lock->lock...)  Regular spinlocks keep preemption disabled accross the unlock operation, which provides full RCU protection, but the RT substitution fails to resemble that. Same applies for the rwlock substitution.  Move the rcu_read_unlock() invocation past the unlock operations to match the non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but that's harmless as the caller needs to hold RCU read lock across the lock operation. The migrate_enable() call stays before the unlock operation because there is no per CPU operation in the unlock path which would require migration to be kept disabled.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72069","epss":0.00728,"percentile":0.52054,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.68432},"relatedVulnerabilities":[{"id":"CVE-2026-72069","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72069","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1f0d56d3f1e88f20f6e46109402f8c15d59bac37","https://git.kernel.org/stable/c/3cfaac77b3c32ac3940df28866de263c3f45d24c","https://git.kernel.org/stable/c/633cadbc0b8323f5cc140a285d2432089dbb534e","https://git.kernel.org/stable/c/83f9fb561c1c3917e19f95523dd933c7d30291aa","https://git.kernel.org/stable/c/89038cc87d80c77e7aa6f42a64b2573b74af339f","https://git.kernel.org/stable/c/9d1fcd64ab81200e02b7a6db5eb1da8e244e8289","https://git.kernel.org/stable/c/af28d801cd2db4cc7378554499bd4a5d84a5517e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()\n\nrt_spin_unlock() releases the RCU protection before unlocking the\nlock. That opens the door for the following UAF scenario:\n\n T1\t\t\t\t\tT2\n spin_lock(&p->lock);\t\trcu_read_lock();\n invalidate(p);\t\t\tp = rcu_dereference(ptr);\n rcu_assign_pointer(ptr, NULL);\tif (!p) return;\n spin_unlock(&p->lock);\t\tspin_lock(&p->lock)\n \t\t\t\t   lock(&lock->lock);\n\t\t\t\t   rcu_read_lock();\n kfree_rcu(p);\t\t\trcu_read_unlock();\n\t\t\t\t....\n\t\t\t\tspin_unlock(&p->lock)\n\t\t\t\t  rcu_read_unlock(); // Ends grace period\n rcu_do_batch()\n   kfree(p);\n\t\t\t    UAF ->\t  rt_mutex_cmpxchg_release(&lock->lock...)\n\nRegular spinlocks keep preemption disabled accross the unlock operation,\nwhich provides full RCU protection, but the RT substitution fails to\nresemble that. Same applies for the rwlock substitution.\n\nMove the rcu_read_unlock() invocation past the unlock operations to match\nthe non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but\nthat's harmless as the caller needs to hold RCU read lock across the lock\noperation. The migrate_enable() call stays before the unlock operation\nbecause there is no per CPU operation in the unlock path which would\nrequire migration to be kept disabled.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72069","epss":0.00728,"percentile":0.52054,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72069","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72070","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72070","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()  lbtf_free_adapter() calls timer_delete(&priv->command_timer), which does not wait for a running command_timer_fn() callback. lbtf_free_adapter() runs on the teardown path right before ieee80211_free_hw() frees priv, both in lbtf_remove_card() and in the probe error path. command_timer is armed by mod_timer() in lbtf_cmd() whenever a firmware command is sent. command_timer_fn() dereferences priv. If a command times out as the device is removed, command_timer_fn() runs concurrently with teardown and dereferences priv after it has been freed.  This is the same use-after-free that commit 03cc8f90d053 (\"wifi: libertas: fix use-after-free in lbs_free_adapter()\") fixed in the sibling libertas driver. The libertas_tf variant has the identical pattern and was left unchanged. Use timer_delete_sync() so any in-flight callback completes before priv is freed.","cvss":[],"epss":[{"cve":"CVE-2026-72070","epss":0.0022,"percentile":0.12447,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-72070","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72070","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/066b59e84f90d270cc15f0370166155aca507630","https://git.kernel.org/stable/c/2fba1d3b2f031a2c68e566a6d45cc5b7a8d6683d","https://git.kernel.org/stable/c/4714e95f5d61cb9c5c7c6c4e68b618f37bc6ffcf","https://git.kernel.org/stable/c/9392fd5de555272449d3d8c63410ea00f8ec853a","https://git.kernel.org/stable/c/aa6dcd5c8dd9ba1d7d0f60093bcda41c0d6d438d","https://git.kernel.org/stable/c/bcf7968cb97ce4312588042cf2712f04caff6d8f","https://git.kernel.org/stable/c/bd75636681588c67006279abdb9a76a708b3ce29","https://git.kernel.org/stable/c/fcff712d0e3d183843ec3916470ee6cc3455baad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: libertas_tf: fix use-after-free in lbtf_free_adapter()\n\nlbtf_free_adapter() calls timer_delete(&priv->command_timer), which does\nnot wait for a running command_timer_fn() callback. lbtf_free_adapter()\nruns on the teardown path right before ieee80211_free_hw() frees priv,\nboth in lbtf_remove_card() and in the probe error path. command_timer is\narmed by mod_timer() in lbtf_cmd() whenever a firmware command is sent.\ncommand_timer_fn() dereferences priv. If a command times out as the\ndevice is removed, command_timer_fn() runs concurrently with teardown and\ndereferences priv after it has been freed.\n\nThis is the same use-after-free that commit 03cc8f90d053 (\"wifi: libertas:\nfix use-after-free in lbs_free_adapter()\") fixed in the sibling libertas\ndriver. The libertas_tf variant has the identical pattern and was left\nunchanged. Use timer_delete_sync() so any in-flight callback completes\nbefore priv is freed.","cvss":[],"epss":[{"cve":"CVE-2026-72070","epss":0.0022,"percentile":0.12447,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72070","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72073","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72073","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mmc: vub300: fix use-after-free on probe failure  The vub300 driver lifetime-manages its controller state using vub300->kref, with vub300_delete() freeing the mmc host when the last reference is dropped. The probe error path after the inactivity timer has been armed still bypasses that lifetime rule, however, and falls through to mmc_free_host() directly if mmc_add_host() fails.  The race window is between arming the inactivity timer and reaching the probe error unwind after mmc_add_host() fails:          probe thread                     timer/workqueue         ------------                     ---------------         kref_init(&vub300->kref)         ref = 1         kref_get(&vub300->kref)          ref = 2, timer ref         add_timer(inactivity_timer)      fires after one second         |         |   race window         |<---------------------------------------------------->         |         mmc_add_host(mmc)                                          inactivity timer fires                                          vub300_queue_dead_work()                                            kref_get()          ref = 3                                            queue_work(deadwork)         mmc_add_host() fails         timer_delete_sync()         mmc_free_host(mmc)           frees vub300                                          deadwork runs                                            use-after-free  The inactivity timeout is one second, so this would require mmc_add_host() to both fail and take more than one second to do so. This is unlikely to happen in practice, but the error path is still wrong.  timer_delete_sync() only waits for the timer callback itself. It does not flush deadwork that the callback may already have queued. As a result, queued deadwork can still hold a kref while the probe error path directly frees the backing mmc host, including the vub300 storage.  Fix this by using the same lifetime mechanism as disconnect. Clear vub300->interface so that the timer callback and any queued deadwork return early and drop their references, then drop the initial probe reference and return without falling through to err_free_host.","cvss":[],"epss":[{"cve":"CVE-2026-72073","epss":0.00219,"percentile":0.12387,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1095},"relatedVulnerabilities":[{"id":"CVE-2026-72073","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72073","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/5b82af744e06cd741938c3da54fdbe564a7e52d9","https://git.kernel.org/stable/c/618cf6b139503ec18ef93ffd663396aaf99b763a","https://git.kernel.org/stable/c/a3b5f242997a3be7404112fd48784881560aea57"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: vub300: fix use-after-free on probe failure\n\nThe vub300 driver lifetime-manages its controller state using\nvub300->kref, with vub300_delete() freeing the mmc host when the last\nreference is dropped. The probe error path after the inactivity timer has\nbeen armed still bypasses that lifetime rule, however, and falls through\nto mmc_free_host() directly if mmc_add_host() fails.\n\nThe race window is between arming the inactivity timer and reaching the\nprobe error unwind after mmc_add_host() fails:\n\n        probe thread                     timer/workqueue\n        ------------                     ---------------\n        kref_init(&vub300->kref)         ref = 1\n        kref_get(&vub300->kref)          ref = 2, timer ref\n        add_timer(inactivity_timer)      fires after one second\n        |\n        |   race window\n        |<---------------------------------------------------->\n        |\n        mmc_add_host(mmc)\n                                         inactivity timer fires\n                                         vub300_queue_dead_work()\n                                           kref_get()          ref = 3\n                                           queue_work(deadwork)\n        mmc_add_host() fails\n        timer_delete_sync()\n        mmc_free_host(mmc)\n          frees vub300\n                                         deadwork runs\n                                           use-after-free\n\nThe inactivity timeout is one second, so this would require\nmmc_add_host() to both fail and take more than one second to do so. This\nis unlikely to happen in practice, but the error path is still wrong.\n\ntimer_delete_sync() only waits for the timer callback itself. It does\nnot flush deadwork that the callback may already have queued. As a\nresult, queued deadwork can still hold a kref while the probe error path\ndirectly frees the backing mmc host, including the vub300 storage.\n\nFix this by using the same lifetime mechanism as disconnect. Clear\nvub300->interface so that the timer callback and any queued deadwork\nreturn early and drop their references, then drop the initial probe\nreference and return without falling through to err_free_host.","cvss":[],"epss":[{"cve":"CVE-2026-72073","epss":0.00219,"percentile":0.12387,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72073","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72077","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72077","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: ims-pcu - fix firmware leak in async update  The firmware object was not being released if validation failed. Use __free(firmware) to ensure the firmware is always released.","cvss":[],"epss":[{"cve":"CVE-2026-72077","epss":0.0022,"percentile":0.12449,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-72077","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72077","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1f7bdfbe791aacad77db87f044e78ef60a93ae0d","https://git.kernel.org/stable/c/47a9889a9325b87698b6d6eaf3187a9af6e4773d","https://git.kernel.org/stable/c/99c428d7ef644d3e394f3072f905040c16dab18d","https://git.kernel.org/stable/c/9efba5177a51ed996b0bdc03aa677c08247d5b91","https://git.kernel.org/stable/c/a5dd47ea3904dedb1ae7a5fe0e6b44a458f0c5ec","https://git.kernel.org/stable/c/af0641337f6584ccbc7a42ce3f4803d8ff9c5a4a","https://git.kernel.org/stable/c/d48795b5cd6828d36b707e8d62fc9e5c90e004ab","https://git.kernel.org/stable/c/f4b8cd2a96b47473e912e8a134f3c59efb81f10f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix firmware leak in async update\n\nThe firmware object was not being released if validation failed.\nUse __free(firmware) to ensure the firmware is always released.","cvss":[],"epss":[{"cve":"CVE-2026-72077","epss":0.0022,"percentile":0.12449,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72077","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72096","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72096","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm-verity: make error counter atomic  The error counter \"v->corrupted_errs\" was not atomic, thus it could be subject to race conditions. The call to dm_audit_log_target(\"max-corrupted-errors\") may be skipped due to the races.","cvss":[],"epss":[{"cve":"CVE-2026-72096","epss":0.00211,"percentile":0.11305,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-72096","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72096","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/089e05b644d5aa786c21af467c80b24d691becb1","https://git.kernel.org/stable/c/3303e5c6501e3638ded8e9402d703805b00ce64e","https://git.kernel.org/stable/c/752e214b2c6f15b40b0d873a2ce27733ce0884c6","https://git.kernel.org/stable/c/8ec4d9c5a5cf4b61fc087f871465b1f79b393325","https://git.kernel.org/stable/c/a7df22c4e0e9110f0be577919d3cb9389b2aba65","https://git.kernel.org/stable/c/aab5cb8a40e82bd33d0f3ae3c73041848b18bfd2","https://git.kernel.org/stable/c/ac99781115d37d10894653b47941d9d8fc26fa64","https://git.kernel.org/stable/c/b8eddcb1bf72199451950aff9087bd76da80635d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity: make error counter atomic\n\nThe error counter \"v->corrupted_errs\" was not atomic, thus it could be\nsubject to race conditions. The call to\ndm_audit_log_target(\"max-corrupted-errors\") may be skipped due to the\nraces.","cvss":[],"epss":[{"cve":"CVE-2026-72096","epss":0.00211,"percentile":0.11305,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72096","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72098","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72098","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm-verity: fix buffer overflow in FEC calculation  There's a buffer overflow in dm-verity-fec:  if (neras && *neras <= v->fec->roots) \tfio->erasures[(*neras)++] = i;  This allows *neras to reach roots + 1 (the post-increment pushes it past roots). This value is then passed as no_eras to decode_rs8(). Inside the RS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator polynomial loop writes lambda[j] where j can reach nroots + 1 — one element past the end of lambda[] (which is sized nroots + 1, valid indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting the syndrome buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72098","epss":0.00664,"percentile":0.49633,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.62416},"relatedVulnerabilities":[{"id":"CVE-2026-72098","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72098","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/31d6e6c0ba8d5a7bd59660035a089307100c5e8e","https://git.kernel.org/stable/c/5488d3a69d205e28f74f18857b853aa12e778e66","https://git.kernel.org/stable/c/f7990c2b0f08b8841fcd2652d1d7002f5994a7a7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity: fix buffer overflow in FEC calculation\n\nThere's a buffer overflow in dm-verity-fec:\n\nif (neras && *neras <= v->fec->roots)\n\tfio->erasures[(*neras)++] = i;\n\nThis allows *neras to reach roots + 1 (the post-increment pushes it past\nroots). This value is then passed as no_eras to decode_rs8(). Inside the\nRS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator\npolynomial loop writes lambda[j] where j can reach nroots + 1 — one\nelement past the end of lambda[] (which is sized nroots + 1, valid\nindices 0..nroots). The out-of-bounds write lands on syn[0], corrupting\nthe syndrome buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72098","epss":0.00664,"percentile":0.49633,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72098","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72099","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72099","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm-integrity: don't increment hash_offset twice  hash_offset is already incremented in the loop \"for (i = 0; i < to_copy; i++, ts--)\". Do not increment it again.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72099","epss":0.00532,"percentile":0.43219,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.38836},"relatedVulnerabilities":[{"id":"CVE-2026-72099","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72099","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/39697e2759ac23e65361fe61482f8174cad8a752","https://git.kernel.org/stable/c/4f4e43337e9ef322595201cfc24def50fd624219","https://git.kernel.org/stable/c/5dfd8042635278613da3b88553e25ade2103cd58","https://git.kernel.org/stable/c/829476c06496aab018f14127c055adb164d1a750","https://git.kernel.org/stable/c/c66b1781a54984227e94b862be9328d81d81e51c","https://git.kernel.org/stable/c/cf9feed8c131e303ecf2afebe6f791be018818ad","https://git.kernel.org/stable/c/e6646f4d711d74930d39cce6fb7bfcae4cbee5fd","https://git.kernel.org/stable/c/edf025f083854f80032b73a1aad69a3c90db236f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-integrity: don't increment hash_offset twice\n\nhash_offset is already incremented in the loop \"for (i = 0; i < to_copy;\ni++, ts--)\". Do not increment it again.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72099","epss":0.00532,"percentile":0.43219,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72099","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72106","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72106","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dm-ioctl: fix a possible overflow in list_version_get_info  sizeof(tt->version) is 12 bytes, but the code writes 16 bytes into the output buffer - info->vers->version[0], info->vers->version[1], info->vers->version[2] and info->vers->next. This can cause buffer overflow.  Fix this buffer overflow by replacing \"sizeof(tt->version)\" with \"sizeof(struct dm_target_versions)\".","cvss":[],"epss":[{"cve":"CVE-2026-72106","epss":0.00216,"percentile":0.12033,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.108},"relatedVulnerabilities":[{"id":"CVE-2026-72106","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72106","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/29536a9ff146d9bbd618959857ed2e691cda1d21","https://git.kernel.org/stable/c/76c6f845dc0c614304a6e6ee619b552f97cf24b3","https://git.kernel.org/stable/c/d61c12573ed9768690fdcb2bc38846a1bcb01358","https://git.kernel.org/stable/c/df50c24c6447c18886ed126d3d81cc7e155ea8b6","https://git.kernel.org/stable/c/e0f5842c4e2a7dbefb52a2dc6711789bc6963e55"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm-ioctl: fix a possible overflow in list_version_get_info\n\nsizeof(tt->version) is 12 bytes, but the code writes 16 bytes into the\noutput buffer - info->vers->version[0], info->vers->version[1],\ninfo->vers->version[2] and info->vers->next. This can cause buffer\noverflow.\n\nFix this buffer overflow by replacing \"sizeof(tt->version)\" with\n\"sizeof(struct dm_target_versions)\".","cvss":[],"epss":[{"cve":"CVE-2026-72106","epss":0.00216,"percentile":0.12033,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72106","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72110","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72110","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf,fork: wipe ->bpf_storage before bailouts that access it  Currently, copy_process() can bail out to free_task() before p->bpf_storage has been initialized, with this call graph (shown here for the !CONFIG_MEMCG case):  copy_process   dup_task_struct     arch_dup_task_struct       [copies the entire task_struct, including ->bpf_storage member]   [RLIMIT_NPROC check fails]   delayed_free_task     free_task       bpf_task_storage_free         rcu_dereference(task->bpf_storage)         bpf_local_storage_destroy  In this case, the nascent task's ->bpf_storage member that bpf_local_storage_destroy() operates on is a plain copy of the parent's ->bpf_storage pointer, not a real initialized pointer. This leads to badness (kernel hangs, UAF).  This is reachable as long as the process calling fork() has been inserted into a task storage map.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72110","epss":0.00164,"percentile":0.05925,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72110","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72110","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/43f0005f81b8ce3be962d653cde8db9022f1e9b0","https://git.kernel.org/stable/c/7df67a4799067a59e6a2d53f8059a6be6e73e678","https://git.kernel.org/stable/c/9b51a6155d14389876916726430da30eabb1d4ed","https://git.kernel.org/stable/c/9cff220ddb65b022cc668bb652200742476e744c","https://git.kernel.org/stable/c/aff686efd38728e06daf12417a0d7ed454ce4cff","https://git.kernel.org/stable/c/c3fd6f28c7ce1142a3b23dbb840eaa4777de1d74","https://git.kernel.org/stable/c/c4f626ddf2350652ad2f79daf1f10847f3f6eabd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf,fork: wipe ->bpf_storage before bailouts that access it\n\nCurrently, copy_process() can bail out to free_task() before p->bpf_storage\nhas been initialized, with this call graph (shown here for the\n!CONFIG_MEMCG case):\n\ncopy_process\n  dup_task_struct\n    arch_dup_task_struct\n      [copies the entire task_struct, including ->bpf_storage member]\n  [RLIMIT_NPROC check fails]\n  delayed_free_task\n    free_task\n      bpf_task_storage_free\n        rcu_dereference(task->bpf_storage)\n        bpf_local_storage_destroy\n\nIn this case, the nascent task's ->bpf_storage member that\nbpf_local_storage_destroy() operates on is a plain copy of the parent's\n->bpf_storage pointer, not a real initialized pointer.\nThis leads to badness (kernel hangs, UAF).\n\nThis is reachable as long as the process calling fork() has been inserted\ninto a task storage map.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72110","epss":0.00164,"percentile":0.05925,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72110","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72113","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72113","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: bcm: add missing device refcount for CAN filter removal  sashiko-bot remarked a problem with a concurrent device unregistration in isotp.c which also is present in the bcm.c code. A former fix for raw.c commit c275a176e4b6 (\"can: raw: add missing refcount for memory leak fix\") introduced a netdevice_tracker which solves the issue for bcm.c too.  bcm_release(), bcm_delete_rx_op() and bcm_notifier() relied on dev_get_by_index(ifindex) to re-find the device for an rx_op before unregistering its filter. If a concurrent NETDEV_UNREGISTER has already unlisted the device from the ifindex table, that lookup fails and can_rx_unregister() is silently skipped, leaving a stale CAN filter pointing at the soon-to-be-freed bcm_op/socket.  Hold a netdev_hold()/netdev_put() tracked reference on op->rx_reg_dev from the moment the rx filter is registered in bcm_rx_setup() until it is unregistered in bcm_rx_unreg(), and use that reference directly in bcm_release() and bcm_delete_rx_op() instead of re-looking the device up by ifindex.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72113","epss":0.00164,"percentile":0.05925,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72113","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72113","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/04d23061bbf18d5d81022eb21e9d32e99d24468d","https://git.kernel.org/stable/c/633bda66fbf309f5de5e1ad6defe8e6b1d77a20f","https://git.kernel.org/stable/c/84aa4807816e405c1bf87114fc63e06d244281ef","https://git.kernel.org/stable/c/b024c21c9066f6957b7d4a8f2037e4b000c5e041","https://git.kernel.org/stable/c/bd5232663524e94cc5aad861dca11e3db8e2ab6f","https://git.kernel.org/stable/c/d59948293ea34b6337ce2b5febab8510de70048c","https://git.kernel.org/stable/c/dcaee869913c7210cd47ed0a8f27349d7bdcdb7b","https://git.kernel.org/stable/c/ee8b36d0faca08f35b889b6e9aa850695e5b8ba9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add missing device refcount for CAN filter removal\n\nsashiko-bot remarked a problem with a concurrent device unregistration\nin isotp.c which also is present in the bcm.c code. A former fix for raw.c\ncommit c275a176e4b6 (\"can: raw: add missing refcount for memory leak fix\")\nintroduced a netdevice_tracker which solves the issue for bcm.c too.\n\nbcm_release(), bcm_delete_rx_op() and bcm_notifier() relied on\ndev_get_by_index(ifindex) to re-find the device for an rx_op before\nunregistering its filter. If a concurrent NETDEV_UNREGISTER has already\nunlisted the device from the ifindex table, that lookup fails and\ncan_rx_unregister() is silently skipped, leaving a stale CAN filter\npointing at the soon-to-be-freed bcm_op/socket.\n\nHold a netdev_hold()/netdev_put() tracked reference on op->rx_reg_dev\nfrom the moment the rx filter is registered in bcm_rx_setup() until it\nis unregistered in bcm_rx_unreg(), and use that reference directly in\nbcm_release() and bcm_delete_rx_op() instead of re-looking the device\nup by ifindex.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72113","epss":0.00164,"percentile":0.05925,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72113","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72114","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72114","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: bcm: validate frame length in bcm_rx_setup() for RTR replies  bcm_tx_setup() validates cf->len against the CAN/CAN FD DLC limits before installing frames for TX_SETUP, but bcm_rx_setup() never did the same for the RTR-reply frame configured via RX_SETUP with RX_RTR_FRAME.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72114","epss":0.00164,"percentile":0.05925,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72114","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72114","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1b475c0c72f44622a320a4386ce9e76f85e69bc7","https://git.kernel.org/stable/c/204f2b232717bc470ddb9e1da1d27dd9c6ef0caa","https://git.kernel.org/stable/c/59bfddea64159594feb62ef11b7d7a33c8ee3783","https://git.kernel.org/stable/c/62ec41f364648be79d54d94d0d240ee326948afd","https://git.kernel.org/stable/c/7d966cdee006911d3957e1a4e72cb93c39cd8c1e","https://git.kernel.org/stable/c/cc1f9569f1c1adf74fa69d6f716a31b58a2fc6ce","https://git.kernel.org/stable/c/deb6a697cce3f021e731df543597f37a5e54caab","https://git.kernel.org/stable/c/e061624c0a86c3c26a2bf017e432fbc93ad68f3a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: validate frame length in bcm_rx_setup() for RTR replies\n\nbcm_tx_setup() validates cf->len against the CAN/CAN FD DLC limits\nbefore installing frames for TX_SETUP, but bcm_rx_setup() never did\nthe same for the RTR-reply frame configured via RX_SETUP with\nRX_RTR_FRAME.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72114","epss":0.00164,"percentile":0.05925,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72114","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72115","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72115","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: bcm: track a single source interface for ANYDEV timeout/throttle ops  An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces: bcm_rx_handler() can run concurrently for the same op on different CPUs, racing hrtimer_cancel()/ bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing spurious RX_TIMEOUT notifications and last_frames corruption. The same concurrency lets throttled multiplex frames from different interfaces clobber the single rx_ifindex/rx_stamp fields shared by the op.  Add op->if_detected to track the first interface that delivers a matching frame while a timeout/throttle timer is configured, and reject frames from any other interface for that op. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME, independent of kt_ival1/kt_ival2, since those may briefly hold a stale value from an earlier non-RTR configuration.  The claim is released in bcm_notify() on NETDEV_UNREGISTER and in bcm_rx_setup() when SETTIMER reconfigures the timer values.  A (re-)claim is only possible on CAN devices in NETREG_REGISTERED dev->reg_state to cover the release in bcm_notify() where reg_state becomes NETREG_UNREGISTERING until synchronize_net().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72115","epss":0.00295,"percentile":0.21874,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.2301},"relatedVulnerabilities":[{"id":"CVE-2026-72115","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72115","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/03dfe347c398fa41a7e30e8dc538f12568c183e6","https://git.kernel.org/stable/c/18b45251e74e35668f0dd0c470549384ae191ecf","https://git.kernel.org/stable/c/2f5976f54a04e9f18b25283036ac3136be453b17","https://git.kernel.org/stable/c/3ff8c24b421070a2db99a5cdb86edc9ff339418e","https://git.kernel.org/stable/c/57cf104da4cf450ae9c16801a3164604b801d2cc","https://git.kernel.org/stable/c/b6317022b685a430a3ae420456716e3c0c02ef4b","https://git.kernel.org/stable/c/eca8b44d51fc6ab61022258ec968e55e3073b79e","https://git.kernel.org/stable/c/f147f48837cb1426521f5b3c3b3134c71128a25d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: track a single source interface for ANYDEV timeout/throttle ops\n\nAn ANYDEV rx op (ifindex == 0) with an active RX timeout and/or\nthrottle timer has no defined semantics when matching frames arrive\nfrom several interfaces: bcm_rx_handler() can run concurrently for\nthe same op on different CPUs, racing hrtimer_cancel()/\nbcm_rx_starttimer() against bcm_rx_timeout_handler() and causing\nspurious RX_TIMEOUT notifications and last_frames corruption. The\nsame concurrency lets throttled multiplex frames from different\ninterfaces clobber the single rx_ifindex/rx_stamp fields shared by\nthe op.\n\nAdd op->if_detected to track the first interface that delivers a\nmatching frame while a timeout/throttle timer is configured, and\nreject frames from any other interface for that op. The claim is\ndecided in bcm_rx_handler() before hrtimer_cancel() touches\nop->timer, so a rejected frame can never disturb the claimed\ninterface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME,\nindependent of kt_ival1/kt_ival2, since those may briefly hold a\nstale value from an earlier non-RTR configuration.\n\nThe claim is released in bcm_notify() on NETDEV_UNREGISTER and in\nbcm_rx_setup() when SETTIMER reconfigures the timer values.\n\nA (re-)claim is only possible on CAN devices in NETREG_REGISTERED\ndev->reg_state to cover the release in bcm_notify() where reg_state\nbecomes NETREG_UNREGISTERING until synchronize_net().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72115","epss":0.00295,"percentile":0.21874,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72115","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72116","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72116","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: bcm: fix stale rx/tx ops after device removal  RX: an RX_SETUP update(!) for an existing op skipped can_rx_register() unconditionally, even when a concurrent NETDEV_UNREGISTER had already torn down its registration (op->rx_reg_dev == NULL). This silently did not re-enable frame delivery for that updated filter. bcm_rx_setup() now re-registers in that case, while leaving rx_ops with ifindex = 0 (all CAN devices) which never carry a tracked rx_reg_dev registered as-is.  TX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving tx_ops with an active cyclic transmission re-arming its hrtimer indefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer prevents the runaway timer and any injection into a later reused ifindex, since nothing else calls bcm_can_tx() for the op until an explicit TX_SETUP update re-arms it.  Unlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops, the ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup() always rejects ifindex 0, so clearing it would strand the op: neither a later TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could ever find it again, since both require an exact ifindex match.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72116","epss":0.00181,"percentile":0.07767,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13213},"relatedVulnerabilities":[{"id":"CVE-2026-72116","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72116","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3b762c0d950383ab7a002686c9136b9aa55d2d70","https://git.kernel.org/stable/c/60d8a7942f4ed2d975207aaeba1adb576707e53d","https://git.kernel.org/stable/c/6be3e1fedf03eab36a2c09d755d1171287b2014b","https://git.kernel.org/stable/c/9517d8fb0b191398d35b9b7f8c719c1cc7761cb1","https://git.kernel.org/stable/c/b31d0933509c5a35c0be5736a2ce8df0d1bf112c","https://git.kernel.org/stable/c/ca829677ffa2de5d79e06366e19ac1e4f5cc78dd","https://git.kernel.org/stable/c/d30a36066ed3abefb72ae18901f71841ba18b350","https://git.kernel.org/stable/c/f749e4564952d60e96930c09f2be99955d07c22e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix stale rx/tx ops after device removal\n\nRX: an RX_SETUP update(!) for an existing op skipped can_rx_register()\nunconditionally, even when a concurrent NETDEV_UNREGISTER had already\ntorn down its registration (op->rx_reg_dev == NULL). This silently\ndid not re-enable frame delivery for that updated filter. bcm_rx_setup()\nnow re-registers in that case, while leaving rx_ops with ifindex = 0\n(all CAN devices) which never carry a tracked rx_reg_dev registered as-is.\n\nTX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving\ntx_ops with an active cyclic transmission re-arming its hrtimer\nindefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer\nprevents the runaway timer and any injection into a later reused ifindex,\nsince nothing else calls bcm_can_tx() for the op until an explicit\nTX_SETUP update re-arms it.\n\nUnlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops,\nthe ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup()\nalways rejects ifindex 0, so clearing it would strand the op: neither a\nlater TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could\never find it again, since both require an exact ifindex match.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72116","epss":0.00181,"percentile":0.07767,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72116","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72117","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72117","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()  For an rx op subscribed on all interfaces (ifindex == 0), the same op is registered once in the shared per-netns wildcard filter list, so bcm_rx_handler() can run concurrently on different CPUs for frames arriving on different net devices.  op->rx_stamp and op->rx_ifindex were written before bcm_rx_update_lock was taken, allowing concurrent writers to race each other - including a torn store of the 64-bit rx_stamp on 32-bit platforms.  Beyond a torn store bcm_send_to_user() must report the timestamp/ifindex of the very same frame whose content it is delivering. So the assignment is placed in the same unbroken bcm_rx_update_lock section as the content comparison.  As a side effect, the RTR-request frame feature (which never reach bcm_send_to_user()) no longer updates rx_stamp/rx_ifindex, since only the notification path needs them.","cvss":[],"epss":[{"cve":"CVE-2026-72117","epss":0.00211,"percentile":0.11308,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-72117","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72117","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/136de17f38630307991c59aa7080012a99451783","https://git.kernel.org/stable/c/4b97410f4bba18d2ee2784c8e089104f387bc27c","https://git.kernel.org/stable/c/58fd6cbc8541216af1d7ed272ea7ac2b66d50fd8","https://git.kernel.org/stable/c/5f246b96ab47523ec9b8ea870b5c567a3cb1eb1c","https://git.kernel.org/stable/c/656ff69ef235699035e57d9e1ae417e62a38aa7f","https://git.kernel.org/stable/c/b64f60c468d149aca22ea56bb842b9730215aaa5","https://git.kernel.org/stable/c/c312b750bb5ac3348cfc85dab25e90937bd4d251","https://git.kernel.org/stable/c/c8a5d7cb095d3b12bd9dcf752d6ca0ff50872ac5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()\n\nFor an rx op subscribed on all interfaces (ifindex == 0), the same op\nis registered once in the shared per-netns wildcard filter list, so\nbcm_rx_handler() can run concurrently on different CPUs for frames\narriving on different net devices.\n\nop->rx_stamp and op->rx_ifindex were written before bcm_rx_update_lock was\ntaken, allowing concurrent writers to race each other - including a torn\nstore of the 64-bit rx_stamp on 32-bit platforms.\n\nBeyond a torn store bcm_send_to_user() must report the timestamp/ifindex\nof the very same frame whose content it is delivering. So the assignment\nis placed in the same unbroken bcm_rx_update_lock section as the content\ncomparison.\n\nAs a side effect, the RTR-request frame feature (which never reach\nbcm_send_to_user()) no longer updates rx_stamp/rx_ifindex, since only\nthe notification path needs them.","cvss":[],"epss":[{"cve":"CVE-2026-72117","epss":0.00211,"percentile":0.11308,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72117","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72118","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72118","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: bcm: fix CAN frame rx/tx statistics  KCSAN detected a data race within the bcm_rx_handler() when two CAN frames have been simultaneously received and processed in a single rx op by two different CPUs.  Use atomic operations with (signed) long data types to access the statistics in the hot path to fix the KCSAN complaint.  Additionally simplify the update and check of statistics overflow by using the atomic operations in separate bcm_update_[rx|tx]_stats() functions. The rx variant runs under bcm_rx_update_lock to prevent races when resetting the two rx counters; the tx variant runs under bcm_tx_lock and only needs to guard its own counter's overflow.  As the rx path resets its values already at LONG_MAX / 100, there is no conflict between the two locking domains (bcm_rx_update_lock vs. bcm_tx_lock) even for ops that use both paths.  The rx statistics update and the frames_filtered update in bcm_rx_changed() were previously performed in two separate bcm_rx_update_lock sections. For an rx op subscribed on all interfaces (ifindex == 0), bcm_rx_handler() can run concurrently on different CPUs, so a counter reset by one CPU between these two sections could leave frames_filtered larger than frames_abs on another CPU, producing a bogus (even negative) reduction percentage in procfs. Update the statistics in the same critical section as bcm_rx_changed() to close this gap, which also removes the now unneeded extra lock/unlock pair around the traffic_flags calculation.","cvss":[],"epss":[{"cve":"CVE-2026-72118","epss":0.00211,"percentile":0.11306,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-72118","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72118","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/47fca0d1620f2d4fab0677564989ef2b9c225c66","https://git.kernel.org/stable/c/640acf3566fc897065127001be875ebc5401c218","https://git.kernel.org/stable/c/8104bcdb2612fdda95169ddc3b49747b2ff98d24","https://git.kernel.org/stable/c/8b2783172d92edd650de6006ebd1c800937021ab","https://git.kernel.org/stable/c/970caff5c1a63702c80e08d920256bcb5f88ecc5","https://git.kernel.org/stable/c/df47f07cdc801a6afe05a486b5a343c3e532a93c","https://git.kernel.org/stable/c/e6c24ba95fc3f1b5e1dcd28b1c6e59ef61a9daa5","https://git.kernel.org/stable/c/fd75884eae40a7be47867cbfc9fc84a80bb8ddb4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix CAN frame rx/tx statistics\n\nKCSAN detected a data race within the bcm_rx_handler() when two CAN frames\nhave been simultaneously received and processed in a single rx op by two\ndifferent CPUs.\n\nUse atomic operations with (signed) long data types to access the\nstatistics in the hot path to fix the KCSAN complaint.\n\nAdditionally simplify the update and check of statistics overflow by\nusing the atomic operations in separate bcm_update_[rx|tx]_stats()\nfunctions. The rx variant runs under bcm_rx_update_lock to prevent\nraces when resetting the two rx counters; the tx variant runs under\nbcm_tx_lock and only needs to guard its own counter's overflow.\n\nAs the rx path resets its values already at LONG_MAX / 100, there is\nno conflict between the two locking domains (bcm_rx_update_lock vs.\nbcm_tx_lock) even for ops that use both paths.\n\nThe rx statistics update and the frames_filtered update in\nbcm_rx_changed() were previously performed in two separate\nbcm_rx_update_lock sections. For an rx op subscribed on all interfaces\n(ifindex == 0), bcm_rx_handler() can run concurrently on different\nCPUs, so a counter reset by one CPU between these two sections could\nleave frames_filtered larger than frames_abs on another CPU, producing\na bogus (even negative) reduction percentage in procfs. Update the\nstatistics in the same critical section as bcm_rx_changed() to close\nthis gap, which also removes the now unneeded extra lock/unlock pair\naround the traffic_flags calculation.","cvss":[],"epss":[{"cve":"CVE-2026-72118","epss":0.00211,"percentile":0.11306,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72118","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72119","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72119","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: bcm: extend bcm_tx_lock usage for data and timer updates  Stage new CAN frame content for an existing tx op into a kmalloc()'d buffer and validate it there, mirroring the approach already used in bcm_rx_setup(). Only copy the validated data into op->frames while holding op->bcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler() can no longer observe a partially updated or unvalidated frame.  Add a missing error path for memcpy_from_msg() when copying CAN frame data from userspace.  Also move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup() under op->bcm_tx_lock, and read kt_ival1/kt_ival2/count under the same lock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the torn 64-bit ktime_t read on 32-bit platforms.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72119","epss":0.00164,"percentile":0.05924,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72119","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72119","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc","https://git.kernel.org/stable/c/337f966c00662d81ad82cf5a4bbb150b2e32c0d4","https://git.kernel.org/stable/c/37917e432e50b7de2b64230974380132a30f7270","https://git.kernel.org/stable/c/52f06e7603780de100233713ddaf971d422e10ef","https://git.kernel.org/stable/c/63422347b4c782f429748b2a09cd3cf3b77e6abd","https://git.kernel.org/stable/c/972fd66bb08fdef1090abe43196ca8da07216d13","https://git.kernel.org/stable/c/a538b072ee074c9b41b9d9c15a6861a963e30755","https://git.kernel.org/stable/c/bd46f55dec608daa44b45dcf3328517630ad8e40"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: extend bcm_tx_lock usage for data and timer updates\n\nStage new CAN frame content for an existing tx op into a kmalloc()'d\nbuffer and validate it there, mirroring the approach already used in\nbcm_rx_setup(). Only copy the validated data into op->frames while\nholding op->bcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler()\ncan no longer observe a partially updated or unvalidated frame.\n\nAdd a missing error path for memcpy_from_msg() when copying CAN frame\ndata from userspace.\n\nAlso move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup()\nunder op->bcm_tx_lock, and read kt_ival1/kt_ival2/count under the same\nlock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the\ntorn 64-bit ktime_t read on 32-bit platforms.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72119","epss":0.00164,"percentile":0.05924,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72119","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72121","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72121","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: bcm: add locking when updating filter and timer values  KCSAN detected a simultaneous access to timer values that can be overwritten in bcm_rx_setup() when updating timer and filter content while bcm_rx_handler(), bcm_rx_timeout_handler() or bcm_rx_thr_handler() run concurrently on incoming CAN traffic.  Protect the timer (ival1/ival2/kt_ival1/kt_ival2/kt_lastmsg) and filter (nframes/flags/frames/last_frames) updates in bcm_rx_setup() with a new per-op bcm_rx_update_lock, taken with the matching scope in the RX handlers. memcpy_from_msg() is staged into a temporary buffer before the lock is taken, since it can sleep and must not run under a spinlock.  hrtimer_cancel() is always called without bcm_rx_update_lock held, since bcm_rx_timeout_handler()/bcm_rx_thr_handler() take the same lock and a running callback would otherwise deadlock against the canceller.  Also close a related race: bcm_rx_setup() cleared the RTR flag in the stored reply frame's can_id as a separate, unprotected step after the frame content was already installed, so a concurrent bcm_rx_handler() could transmit a stale reply with CAN_RTR_FLAG still set. Fold that normalization into the initial frame preparation instead (on the staged buffer for updates, directly on op->frames pre-registration for new ops), so the installed frame is always atomically self-consistent.  bcm_rx_handler()'s RX_RTR_FRAME check now takes a lock-protected snapshot of op->flags before deciding whether to call bcm_can_tx(), but does not hold the lock across that call.  Also take a lock-protected snapshot of the currframe in bcm_can_tx() to avoid partly overwrites by content updates in bcm_tx_setup(). Finally check if a TX_RESET_MULTI_IDX/SETTIMER might have reset op->currframe between the two locked sections in bcm_can_tx().  Omit calling hrtimer_forward() with zero interval in bcm_rx_thr_handler(). kt_ival2 may have been concurrently cleared by bcm_rx_setup() before it cancels this timer, so check kt_ival2 inside the bcm_rx_update_lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72121","epss":0.00345,"percentile":0.27585,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.281175},"relatedVulnerabilities":[{"id":"CVE-2026-72121","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72121","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/19b1994069dd29478ba767de1f98f14a088198dc","https://git.kernel.org/stable/c/749179c2e25b95d22499ed29096b3e02d6dfd2b4","https://git.kernel.org/stable/c/834cbca3b12e46887f7a9b35f1981a888360ea4c","https://git.kernel.org/stable/c/96994180bd7b248b0cc698afe926e23fc1bda59b","https://git.kernel.org/stable/c/a7c369e7da8203e2b5be12bbcac7b9ab2ed5b658","https://git.kernel.org/stable/c/a7eb6db1cd3f7b556a301dc1265945ad112089f7","https://git.kernel.org/stable/c/caa8704a7f3cb7806331596195385437126ecb3a","https://git.kernel.org/stable/c/fc9f5ee1b073bd233d9c604e338af4ebb42cbc33"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add locking when updating filter and timer values\n\nKCSAN detected a simultaneous access to timer values that can be\noverwritten in bcm_rx_setup() when updating timer and filter content\nwhile bcm_rx_handler(), bcm_rx_timeout_handler() or bcm_rx_thr_handler()\nrun concurrently on incoming CAN traffic.\n\nProtect the timer (ival1/ival2/kt_ival1/kt_ival2/kt_lastmsg) and filter\n(nframes/flags/frames/last_frames) updates in bcm_rx_setup() with a new\nper-op bcm_rx_update_lock, taken with the matching scope in the RX\nhandlers. memcpy_from_msg() is staged into a temporary buffer before the\nlock is taken, since it can sleep and must not run under a spinlock.\n\nhrtimer_cancel() is always called without bcm_rx_update_lock held, since\nbcm_rx_timeout_handler()/bcm_rx_thr_handler() take the same lock and a\nrunning callback would otherwise deadlock against the canceller.\n\nAlso close a related race: bcm_rx_setup() cleared the RTR flag in the\nstored reply frame's can_id as a separate, unprotected step after the\nframe content was already installed, so a concurrent bcm_rx_handler()\ncould transmit a stale reply with CAN_RTR_FLAG still set. Fold that\nnormalization into the initial frame preparation instead (on the staged\nbuffer for updates, directly on op->frames pre-registration for new\nops), so the installed frame is always atomically self-consistent.\n\nbcm_rx_handler()'s RX_RTR_FRAME check now takes a lock-protected\nsnapshot of op->flags before deciding whether to call bcm_can_tx(),\nbut does not hold the lock across that call.\n\nAlso take a lock-protected snapshot of the currframe in bcm_can_tx()\nto avoid partly overwrites by content updates in bcm_tx_setup().\nFinally check if a TX_RESET_MULTI_IDX/SETTIMER might have reset\nop->currframe between the two locked sections in bcm_can_tx().\n\nOmit calling hrtimer_forward() with zero interval in bcm_rx_thr_handler().\nkt_ival2 may have been concurrently cleared by bcm_rx_setup() before it\ncancels this timer, so check kt_ival2 inside the bcm_rx_update_lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72121","epss":0.00345,"percentile":0.27585,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72121","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72124","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72124","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: isotp: serialize TX state transitions under so->rx_lock  The TX state machine (so->tx.state) is driven from three contexts: sendmsg() claiming and progressing a transfer, the RX path consuming Flow Control/echo frames, and two hrtimers timing out a stalled transfer. Mixing a lock-free cmpxchg() claim in sendmsg() with hrtimer_cancel() calls made under so->rx_lock elsewhere left windows where a frame or timer callback could act on a state that had already moved on, corrupting an unrelated transfer.  so->rx_lock now covers the full lifecycle of a TX claim: sendmsg() takes it to check so->tx.state is ISOTP_IDLE, switch it to ISOTP_SENDING, bump so->tx_gen and drain the previous transfer's timers - all as one critical section. isotp_rcv_fc()/isotp_rcv_cf() already run under this lock via isotp_rcv(), and isotp_rcv_echo() now takes it itself, so none of them can ever observe a transfer mid-claim. This also means a transfer can no longer be handed to sendmsg()'s cleanup paths (signal or send error) while another thread is concurrently claiming or finishing it, so those paths can cancel timers and reset the state unconditionally.  isotp_release() claims the socket the same way, so a racing sendmsg() sees a consistent ISOTP_SHUTDOWN and skips arming its timer or sending.  Only the hrtimer callbacks stay outside so->rx_lock, since they run under so->rx_lock's cancellation elsewhere and taking it themselves would deadlock. so->tx_gen lets them recognize whether the transfer they timed out is still the one currently active, so they don't report an error against a transfer that has since completed or been superseded.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72124","epss":0.00354,"percentile":0.28644,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.28851000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-72124","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72124","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b05eca9589f609e2491b528dccf683168a4cda8","https://git.kernel.org/stable/c/377a8f500704da42ed86a4541ed930e9dcfdb2ea","https://git.kernel.org/stable/c/37beb16e08cae94cc05840c7274225e3b0b38ae7","https://git.kernel.org/stable/c/4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca","https://git.kernel.org/stable/c/6da8119e8dd542194103139812d1a4b7dcd1aedd","https://git.kernel.org/stable/c/a7d90e7b5e75d7406c889fe36e9a61ee364a00cb","https://git.kernel.org/stable/c/bbedeb67a9a684f2fb78c55bd3662c400526715e","https://git.kernel.org/stable/c/cf070fe33bfbd1a4c21236078fadb35dd223a157"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: serialize TX state transitions under so->rx_lock\n\nThe TX state machine (so->tx.state) is driven from three contexts:\nsendmsg() claiming and progressing a transfer, the RX path consuming\nFlow Control/echo frames, and two hrtimers timing out a stalled\ntransfer. Mixing a lock-free cmpxchg() claim in sendmsg() with\nhrtimer_cancel() calls made under so->rx_lock elsewhere left windows\nwhere a frame or timer callback could act on a state that had already\nmoved on, corrupting an unrelated transfer.\n\nso->rx_lock now covers the full lifecycle of a TX claim: sendmsg()\ntakes it to check so->tx.state is ISOTP_IDLE, switch it to\nISOTP_SENDING, bump so->tx_gen and drain the previous transfer's\ntimers - all as one critical section. isotp_rcv_fc()/isotp_rcv_cf()\nalready run under this lock via isotp_rcv(), and isotp_rcv_echo() now\ntakes it itself, so none of them can ever observe a transfer mid-claim.\nThis also means a transfer can no longer be handed to sendmsg()'s\ncleanup paths (signal or send error) while another thread is\nconcurrently claiming or finishing it, so those paths can cancel\ntimers and reset the state unconditionally.\n\nisotp_release() claims the socket the same way, so a racing sendmsg()\nsees a consistent ISOTP_SHUTDOWN and skips arming its timer or sending.\n\nOnly the hrtimer callbacks stay outside so->rx_lock, since they run\nunder so->rx_lock's cancellation elsewhere and taking it themselves\nwould deadlock. so->tx_gen lets them recognize whether the transfer\nthey timed out is still the one currently active, so they don't\nreport an error against a transfer that has since completed or been\nsuperseded.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72124","epss":0.00354,"percentile":0.28644,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72124","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72125","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72125","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER  isotp_release() looked up the bound network device via dev_get_by_index() using the stored ifindex. During device unregistration the device is unlisted from the ifindex hash before the NETDEV_UNREGISTER notifier chain runs, so a concurrent isotp_release() could find no device, skip can_rx_unregister() entirely, and still proceed to free the socket. Since isotp_release() had already removed itself from the isotp notifier list at that point, isotp_notify() would never get a chance to clean up either, leaving a stale CAN filter that keeps pointing at the freed socket.  Fix this the same way raw.c already does: hold a tracked reference to the bound net_device in the socket (so->dev/so->dev_tracker) from bind() onward instead of re-resolving it from the ifindex, and serialize bind()/release() with rtnl_lock() so that so->dev is always consistent with what the NETDEV_UNREGISTER notifier sees. so->dev stays valid regardless of ifindex-hash unlisting, and is only ever cleared by whichever of isotp_release()/isotp_notify() gets there first, so the filter is always removed exactly once.  isotp_bind() now rejects a (re)bind with -EAGAIN while so->[tx|rx].state isn't ISOTP_IDLE yet, so a timer left running by a prior NETDEV_UNREGISTER can't act on a newly bound so->ifindex. Both checks share the same lock_sock() section, so there is no window in which a concurrent isotp_notify() clearing so->bound could be missed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72125","epss":0.00164,"percentile":0.05899,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72125","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72125","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96","https://git.kernel.org/stable/c/20bab8b88baac140ca3701116e1d486c7f51e311","https://git.kernel.org/stable/c/33b9cd9245e2a4b800f99ed1cc53d64960614152","https://git.kernel.org/stable/c/43884dc7963beef2328f507f4fe680bdc173eb80","https://git.kernel.org/stable/c/7bef39ba76eb7307ed22a50329e0f5776dbeda58","https://git.kernel.org/stable/c/8e018f4335590460ebcf0c2b493ed38ba1a35204","https://git.kernel.org/stable/c/e442b62ba5a7756c17e05a77b32cdd085a2b6138","https://git.kernel.org/stable/c/f311bbb29bb06aaab69ba45a6e4b11323d20b8f9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER\n\nisotp_release() looked up the bound network device via dev_get_by_index()\nusing the stored ifindex. During device unregistration the device is\nunlisted from the ifindex hash before the NETDEV_UNREGISTER notifier\nchain runs, so a concurrent isotp_release() could find no device, skip\ncan_rx_unregister() entirely, and still proceed to free the socket.\nSince isotp_release() had already removed itself from the isotp\nnotifier list at that point, isotp_notify() would never get a chance to\nclean up either, leaving a stale CAN filter that keeps pointing at the\nfreed socket.\n\nFix this the same way raw.c already does: hold a tracked reference to\nthe bound net_device in the socket (so->dev/so->dev_tracker) from\nbind() onward instead of re-resolving it from the ifindex, and\nserialize bind()/release() with rtnl_lock() so that so->dev is always\nconsistent with what the NETDEV_UNREGISTER notifier sees. so->dev\nstays valid regardless of ifindex-hash unlisting, and is only ever\ncleared by whichever of isotp_release()/isotp_notify() gets there\nfirst, so the filter is always removed exactly once.\n\nisotp_bind() now rejects a (re)bind with -EAGAIN while so->[tx|rx].state\nisn't ISOTP_IDLE yet, so a timer left running by a prior\nNETDEV_UNREGISTER can't act on a newly bound so->ifindex. Both checks\nshare the same lock_sock() section, so there is no window in which a\nconcurrent isotp_notify() clearing so->bound could be missed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72125","epss":0.00164,"percentile":0.05899,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72125","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72130","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72130","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet-auth: reject short AUTH_RECEIVE buffers  nvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length after checking only that it is nonzero and matches the transfer length. In the SUCCESS1 and FAILURE1/default states, that lets a remote NVMe-oF initiator reach the fixed-size DH-HMAC-CHAP response builders with a kmalloc() buffer shorter than the response, so nvmet_auth_success1() and nvmet_auth_failure1() write past the allocation; both only WARN_ON the short length and then format the message anyway.  Impact: A remote NVMe-oF initiator with access to an auth-enabled target can trigger a 16-byte heap out-of-bounds write via a one-byte AUTH_RECEIVE allocation length.  Compute the minimum response length for the current DH-HMAC-CHAP step in nvmet_auth_receive_data_len() and report a zero data length when the host-supplied allocation length is shorter, so the existing zero-length check in nvmet_execute_auth_receive() rejects the command before any builder runs. The SUCCESS1 minimum is sizeof(struct nvmf_auth_dhchap_success1_data) plus the HMAC hash length, because the response hash is written into the rval[] flexible-array tail, so the minimum is state dependent rather than a flat sizeof. CHALLENGE keeps its existing variable-length guard in nvmet_auth_challenge().  This is reachable only when in-band DH-HMAC-CHAP authentication is configured on the target.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72130","epss":0.00748,"percentile":0.52724,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.7031200000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72130","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72130","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/2eaa3ad450141cfcf187bb43cb8335eb336b5f87","https://git.kernel.org/stable/c/779575bc35c687697ba69e904f2cd22e60112534","https://git.kernel.org/stable/c/80bf7b7f676e3987bbe06af3c359bd56ac91a5a9","https://git.kernel.org/stable/c/bc111698b46e43eddd8664cceaa621cd559e99a0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: reject short AUTH_RECEIVE buffers\n\nnvmet_execute_auth_receive() trusts the AUTH_RECEIVE allocation length\nafter checking only that it is nonzero and matches the transfer length.\nIn the SUCCESS1 and FAILURE1/default states, that lets a remote NVMe-oF\ninitiator reach the fixed-size DH-HMAC-CHAP response builders with a\nkmalloc() buffer shorter than the response, so nvmet_auth_success1() and\nnvmet_auth_failure1() write past the allocation; both only WARN_ON the\nshort length and then format the message anyway.\n\nImpact: A remote NVMe-oF initiator with access to an auth-enabled target\ncan trigger a 16-byte heap out-of-bounds write via a one-byte\nAUTH_RECEIVE allocation length.\n\nCompute the minimum response length for the current DH-HMAC-CHAP step in\nnvmet_auth_receive_data_len() and report a zero data length when the\nhost-supplied allocation length is shorter, so the existing zero-length\ncheck in nvmet_execute_auth_receive() rejects the command before any\nbuilder runs. The SUCCESS1 minimum is sizeof(struct\nnvmf_auth_dhchap_success1_data) plus the HMAC hash length, because the\nresponse hash is written into the rval[] flexible-array tail, so the\nminimum is state dependent rather than a flat sizeof. CHALLENGE keeps its\nexisting variable-length guard in nvmet_auth_challenge().\n\nThis is reachable only when in-band DH-HMAC-CHAP authentication is\nconfigured on the target.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72130","epss":0.00748,"percentile":0.52724,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72130","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72142","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72142","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)  SMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic (polling) path rejects it as -EPROTO. Worse, it returns without a NACK+STOP: the next receive cycle has already started, so the target keeps holding SDA and the bus stays stuck until a power cycle for this i2c controller.  Reading I2DR to obtain the count likewise arms the next byte on the count > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly and left the bus held.  Handle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so the existing last-byte handling emits STOP; the dummy byte is discarded. A count of 0 is a valid empty block read; a count above I2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus has been released.  The interrupt-driven path has the same flaw from a later commit and is fixed separately, as it carries a different Fixes: tag and stable range.","cvss":[],"epss":[{"cve":"CVE-2026-72142","epss":0.00211,"percentile":0.11303,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1055},"relatedVulnerabilities":[{"id":"CVE-2026-72142","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72142","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/016ef0f6ca4bc9bf0330ac41bd2ea349759643e3","https://git.kernel.org/stable/c/0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec","https://git.kernel.org/stable/c/38d4947431b2410850409fda016b2ac9f640a4dd","https://git.kernel.org/stable/c/60ed00d46616a9232e42ea7a3e3c0273d7cf7543","https://git.kernel.org/stable/c/6d2c973926d0612360693bc559be2ffde836151b","https://git.kernel.org/stable/c/c882e8cc68fb993700dc21fd6e754001e6297934","https://git.kernel.org/stable/c/cb2fc37857693b55909fb77dc2c87cfbc1cdc476","https://git.kernel.org/stable/c/e3e8b02d4773cfc5ad561d2e5505efde36c6927a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: fix locked bus on SMBus block-read of 0 (atomic)\n\nSMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic\n(polling) path rejects it as -EPROTO. Worse, it returns without a\nNACK+STOP: the next receive cycle has already started, so the target\nkeeps holding SDA and the bus stays stuck until a power cycle for\nthis i2c controller.\n\nReading I2DR to obtain the count likewise arms the next byte on the\ncount > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly\nand left the bus held.\n\nHandle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so\nthe existing last-byte handling emits STOP; the dummy byte is discarded.\nA count of 0 is a valid empty block read; a count above\nI2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus\nhas been released.\n\nThe interrupt-driven path has the same flaw from a later commit and is\nfixed separately, as it carries a different Fixes: tag and stable range.","cvss":[],"epss":[{"cve":"CVE-2026-72142","epss":0.00211,"percentile":0.11303,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72142","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72144","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72144","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  platform/x86: dell-laptop: fix missing cleanups in init error path  dell_init() initializes several resources after dell_setup_rfkill(), including the optional touchpad LED, keyboard backlight LED, battery hook, debugfs directory and dell-laptop notifier.  If a later LED or backlight registration fails, the error path only tears down the battery hook and rfkill resources. This leaves the notifier, debugfs directory, keyboard backlight LED and optional touchpad LED registered after dell_init() returns an error.  Add the missing cleanup calls before tearing down rfkill.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72144","epss":0.00163,"percentile":0.05855,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12469499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-72144","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72144","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1e41ca4a7fba2e680d6950e9511245255fffa46c","https://git.kernel.org/stable/c/6bd76d5421a72d2526c9be8f01f55bee960f899f","https://git.kernel.org/stable/c/6e9cab2247e5b243ae2d907ce7c948a8a9c8d61a","https://git.kernel.org/stable/c/b351e082711d12f075a36a6cd67709693689315f","https://git.kernel.org/stable/c/e4908b3bed755f73870416b971e162a8d0ef0aef"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: dell-laptop: fix missing cleanups in init error path\n\ndell_init() initializes several resources after dell_setup_rfkill(),\nincluding the optional touchpad LED, keyboard backlight LED, battery\nhook, debugfs directory and dell-laptop notifier.\n\nIf a later LED or backlight registration fails, the error path only\ntears down the battery hook and rfkill resources. This leaves the\nnotifier, debugfs directory, keyboard backlight LED and optional\ntouchpad LED registered after dell_init() returns an error.\n\nAdd the missing cleanup calls before tearing down rfkill.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72144","epss":0.00163,"percentile":0.05855,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72144","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72146","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72146","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: sh: rz-dmac: Move interrupt request after everything is set up  Once the interrupt is requested, the interrupt handler may run immediately. Since the IRQ handler can access channel->ch_base, which is initialized only after requesting the IRQ, this may lead to invalid memory access. Likewise, the IRQ thread may access uninitialized data (the ld_free, ld_queue, and ld_active lists), which may also lead to issues.  Request the interrupts only after everything is set up. To keep the error path simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72146","epss":0.0018,"percentile":0.07699,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1431},"relatedVulnerabilities":[{"id":"CVE-2026-72146","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72146","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/07ae600bd353b22f31a8f1007269744fafc7f123","https://git.kernel.org/stable/c/0e0c5b3cf374ebf3c589741751e1fbc67f53ec2f","https://git.kernel.org/stable/c/2a4d9e2234c3f817bb0ddbc8680d09ce9be84f93","https://git.kernel.org/stable/c/5b12de6229d662864ee22c11d4876652b40120f0","https://git.kernel.org/stable/c/731712403ddb39d1a76a11abf339a0615bc85de7","https://git.kernel.org/stable/c/d24d53323e817d79a4bd111bd10b34dbc96e64a8","https://git.kernel.org/stable/c/ec9f66c91bffdb69d309bae6dfb387562db7ebc8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sh: rz-dmac: Move interrupt request after everything is set up\n\nOnce the interrupt is requested, the interrupt handler may run immediately.\nSince the IRQ handler can access channel->ch_base, which is initialized\nonly after requesting the IRQ, this may lead to invalid memory access.\nLikewise, the IRQ thread may access uninitialized data (the ld_free,\nld_queue, and ld_active lists), which may also lead to issues.\n\nRequest the interrupts only after everything is set up. To keep the error\npath simpler, use dmam_alloc_coherent() instead of dma_alloc_coherent().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72146","epss":0.0018,"percentile":0.07699,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72146","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72147","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72147","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: dw-edma-pcie: Reject devices without driver data  dw_edma_pcie_probe() treats the PCI device ID driver_data as the template for the controller layout and copies it unconditionally. A device bound dynamically via sysfs can match the driver without that data, which leads to a NULL pointer dereference.  Reject such matches before enabling the device.","cvss":[],"epss":[{"cve":"CVE-2026-72147","epss":0.002,"percentile":0.0994,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-72147","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72147","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/043acb00e4edd4b9ffb9dd0e357482dcd9086486","https://git.kernel.org/stable/c/044f7b3252d4fb2143d4999eec2800c08f1001ed","https://git.kernel.org/stable/c/11d7cfe0c119691b2dafbb699bbca90258c678aa","https://git.kernel.org/stable/c/2733b5dcb5a4ba4446f7bac954b97e4501dcaa64","https://git.kernel.org/stable/c/a1042599fa8f9e313be176eb1ea1ae199f983419"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: dw-edma-pcie: Reject devices without driver data\n\ndw_edma_pcie_probe() treats the PCI device ID driver_data as the\ntemplate for the controller layout and copies it unconditionally. A\ndevice bound dynamically via sysfs can match the driver without that\ndata, which leads to a NULL pointer dereference.\n\nReject such matches before enabling the device.","cvss":[],"epss":[{"cve":"CVE-2026-72147","epss":0.002,"percentile":0.0994,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72147","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72157","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72157","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: thunderbolt: Fix frags[] overflow by bounding frame_count  tbnet_poll() assembles a multi-frame ThunderboltIP packet into one skb. The first frame goes into the skb linear area and every further frame is added as a page fragment.  \tskb_add_rx_frag(skb, skb_shinfo(skb)->nr_frags, \t\t\tpage, hdr_size, frame_size, \t\t\tTBNET_RX_PAGE_SIZE - hdr_size);  A packet of frame_count frames therefore ends up with frame_count - 1 fragments. tbnet_check_frame() only bounds the peer supplied frame_count to TBNET_RING_SIZE / 4 (64), which is far above MAX_SKB_FRAGS (17 by default). A peer that sends a packet of 19 or more small frames pushes nr_frags past MAX_SKB_FRAGS, so skb_add_rx_frag() writes past skb_shinfo()->frags[] and corrupts memory after the shared info.  Tighten the start of packet bound to MAX_SKB_FRAGS + 1 so a packet can never produce more fragments than frags[] can hold. This matches the recent skb frags overflow fixes in other receive paths, for example f0813bcd2d9d (\"net: wwan: t7xx: fix potential skb->frags overflow in RX path\") and 600dc40554dc (\"net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72157","epss":0.00345,"percentile":0.27586,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.281175},"relatedVulnerabilities":[{"id":"CVE-2026-72157","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72157","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2b3b4e5ff5a58ad32817824b0310e63908b12052","https://git.kernel.org/stable/c/55d9895f89970501fe126d1026b586b04a224c27","https://git.kernel.org/stable/c/569ba39b2d12995a29dc158e5b4de6e449278f30","https://git.kernel.org/stable/c/6262f51e09d8dc8b07599a9e4f03bd3989d13fff","https://git.kernel.org/stable/c/e27beb4536cbf1d59e2d8c2840e87d972aba906f","https://git.kernel.org/stable/c/e5824d5b841d99a2bcdd4e2c256643293bbc22c1","https://git.kernel.org/stable/c/f96b3b35c622d565eff2438993e028d280163f5c","https://git.kernel.org/stable/c/fe6b606fbf0c3beb94ccf17fcf31d8c2138264e3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Fix frags[] overflow by bounding frame_count\n\ntbnet_poll() assembles a multi-frame ThunderboltIP packet into one skb. The\nfirst frame goes into the skb linear area and every further frame is added as\na page fragment.\n\n\tskb_add_rx_frag(skb, skb_shinfo(skb)->nr_frags,\n\t\t\tpage, hdr_size, frame_size,\n\t\t\tTBNET_RX_PAGE_SIZE - hdr_size);\n\nA packet of frame_count frames therefore ends up with frame_count - 1\nfragments. tbnet_check_frame() only bounds the peer supplied frame_count to\nTBNET_RING_SIZE / 4 (64), which is far above MAX_SKB_FRAGS (17 by default). A\npeer that sends a packet of 19 or more small frames pushes nr_frags past\nMAX_SKB_FRAGS, so skb_add_rx_frag() writes past skb_shinfo()->frags[] and\ncorrupts memory after the shared info.\n\nTighten the start of packet bound to MAX_SKB_FRAGS + 1 so a packet can never\nproduce more fragments than frags[] can hold. This matches the recent skb\nfrags overflow fixes in other receive paths, for example f0813bcd2d9d (\"net:\nwwan: t7xx: fix potential skb->frags overflow in RX path\") and 600dc40554dc\n(\"net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72157","epss":0.00345,"percentile":0.27586,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72157","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72162","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72162","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec  [BUG] On-disk corruption setting l_next_free_rec to 0 in an inode's embedded extent list triggers a UBSAN panic on the next write to that file.  [CAUSE] ocfs2_sum_rightmost_rec() computes i = le16_to_cpu(el->l_next_free_rec) - 1 and accesses el->l_recs[i] without validating i. When l_next_free_rec is 0, i becomes -1; when l_next_free_rec exceeds l_count, i falls past the end of the array. Either case violates the __counted_by_le(l_count) annotation on l_recs[] and triggers UBSAN.  [FIX] Validate the inode's embedded extent list when the inode is read, in ocfs2_validate_inode_block(): l_count must be non-zero and no larger than the inode block can hold, and l_next_free_rec must not exceed l_count. A corrupt list is rejected at read time, before the b-tree code can index l_recs[] out of bounds.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72162","epss":0.00162,"percentile":0.05675,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12393},"relatedVulnerabilities":[{"id":"CVE-2026-72162","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72162","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/452a8467be8143747292218212671deeb186d2ae","https://git.kernel.org/stable/c/671889c553ea55e2da6a4f3b15f4c0fa40f2f0d1","https://git.kernel.org/stable/c/858aa4965ffa8c0d4bb5dd835ac4f1c9a1dcab85"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec\n\n[BUG]\nOn-disk corruption setting l_next_free_rec to 0 in an inode's embedded\nextent list triggers a UBSAN panic on the next write to that file.\n\n[CAUSE]\nocfs2_sum_rightmost_rec() computes\ni = le16_to_cpu(el->l_next_free_rec) - 1\nand accesses el->l_recs[i] without validating i. When l_next_free_rec\nis 0, i becomes -1; when l_next_free_rec exceeds l_count, i falls\npast the end of the array. Either case violates the\n__counted_by_le(l_count) annotation on l_recs[] and triggers UBSAN.\n\n[FIX]\nValidate the inode's embedded extent list when the inode is read, in\nocfs2_validate_inode_block(): l_count must be non-zero and no larger\nthan the inode block can hold, and l_next_free_rec must not exceed\nl_count. A corrupt list is rejected at read time, before the b-tree\ncode can index l_recs[] out of bounds.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72162","epss":0.00162,"percentile":0.05675,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72162","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72168","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72168","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mtd: maps: vmu-flash: fix fault in unaligned fixup  Use kzalloc_obj() / kzalloc_objs() to allocate the memcard structs, instead of kmalloc_obj() / kmalloc_objs() to prevent access to uninitialized data.  Fixes runtime error: Fault in unaligned fixup: 0000 [#1] at mtd_get_fact_prot_info.","cvss":[],"epss":[{"cve":"CVE-2026-72168","epss":0.002,"percentile":0.09941,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-72168","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72168","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/01928835d80829e615a492aa66c629b953ec7bef","https://git.kernel.org/stable/c/19360c25135fccb6bbafbee49a5f66baf9a311af","https://git.kernel.org/stable/c/455519f6b70f46ac6cbf41a75ac76ec5e59040f2","https://git.kernel.org/stable/c/79d1661502c6e4b6f626185cef72cf2fa78116e1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: maps: vmu-flash: fix fault in unaligned fixup\n\nUse kzalloc_obj() / kzalloc_objs() to allocate the memcard structs,\ninstead of kmalloc_obj() / kmalloc_objs() to prevent access to\nuninitialized data.\n\nFixes runtime error: Fault in unaligned fixup: 0000 [#1] at\nmtd_get_fact_prot_info.","cvss":[],"epss":[{"cve":"CVE-2026-72168","epss":0.002,"percentile":0.09941,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72168","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72170","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72170","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  9p: skip nlink update in cacheless mode to fix WARN_ON  v9fs_dec_count() unconditionally calls drop_nlink() on regular files, even when the inode's nlink is already zero. In cacheless mode the client refetches inode metadata from the server (the source of truth) on every operation, so by the time v9fs_remove() returns, the locally cached nlink may already reflect the post-unlink value:    1. Client initiates unlink, server processes it and sets nlink to 0   2. Client refetches inode metadata (nlink=0) before unlink returns   3. Client's v9fs_remove() completes successfully   4. Client calls v9fs_dec_count() which calls drop_nlink() on nlink=0  This race is easily triggered under heavy unlink workloads, such as stress-ng's unlink stressor, producing the following warning:    WARNING: fs/inode.c:417 at drop_nlink+0x4c/0xc8   Call trace:    drop_nlink+0x4c/0xc8    v9fs_remove+0x1e0/0x250 [9p]    v9fs_vfs_unlink+0x20/0x38 [9p]    vfs_unlink+0x13c/0x258    ...  In cacheless mode the server is authoritative and the inode is on its way out, so locally adjusting nlink buys nothing. Skip v9fs_dec_count() entirely when neither CACHE_META nor CACHE_LOOSE is set, which both avoids the warning and removes a class of nlink races (two concurrent unlinkers observing nlink > 0 and both calling drop_nlink()) that an nlink == 0 guard alone would only narrow rather than close.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72170","epss":0.00164,"percentile":0.05926,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72170","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72170","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4ec4ebe40c82cb4c60756732f6593055d010c59c","https://git.kernel.org/stable/c/574aa0b4799470ac814479f1138d19efe6262255","https://git.kernel.org/stable/c/6086469f7d469549bfd070348b717a6e43736200","https://git.kernel.org/stable/c/8d610017c992de705b304d3d727a6e3a86af6149","https://git.kernel.org/stable/c/8faccac11e1369adddf5d80f4a45af93f13b2e1a","https://git.kernel.org/stable/c/a5a682b016ef5b5384e28f6d652d47a8f8e73d37","https://git.kernel.org/stable/c/ab257019cb72f467b55c95384d99c94e3908b928","https://git.kernel.org/stable/c/de79c3f3643841b8659a71958df7cf2a66bfd409"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\n9p: skip nlink update in cacheless mode to fix WARN_ON\n\nv9fs_dec_count() unconditionally calls drop_nlink() on regular files,\neven when the inode's nlink is already zero. In cacheless mode the\nclient refetches inode metadata from the server (the source of truth)\non every operation, so by the time v9fs_remove() returns, the locally\ncached nlink may already reflect the post-unlink value:\n\n  1. Client initiates unlink, server processes it and sets nlink to 0\n  2. Client refetches inode metadata (nlink=0) before unlink returns\n  3. Client's v9fs_remove() completes successfully\n  4. Client calls v9fs_dec_count() which calls drop_nlink() on nlink=0\n\nThis race is easily triggered under heavy unlink workloads, such as\nstress-ng's unlink stressor, producing the following warning:\n\n  WARNING: fs/inode.c:417 at drop_nlink+0x4c/0xc8\n  Call trace:\n   drop_nlink+0x4c/0xc8\n   v9fs_remove+0x1e0/0x250 [9p]\n   v9fs_vfs_unlink+0x20/0x38 [9p]\n   vfs_unlink+0x13c/0x258\n   ...\n\nIn cacheless mode the server is authoritative and the inode is on its\nway out, so locally adjusting nlink buys nothing. Skip v9fs_dec_count()\nentirely when neither CACHE_META nor CACHE_LOOSE is set, which both\navoids the warning and removes a class of nlink races (two concurrent\nunlinkers observing nlink > 0 and both calling drop_nlink()) that an\nnlink == 0 guard alone would only narrow rather than close.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72170","epss":0.00164,"percentile":0.05926,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72170","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72172","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72172","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE  If DAX memory is hotplugged into an unoccupied subsection of an early section, section_activate() reuses the unoptimized boot memmap.  However, compound_nr_pages() still assumes that vmemmap optimization is in effect and initializes only the reduced number of struct pages.  As a result, the remaining tail struct pages are left uninitialized, which can later lead to unexpected behavior or crashes.  Fix this by treating early sections as unoptimized when calculating how many struct pages to initialize.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72172","epss":0.00164,"percentile":0.05926,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72172","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72172","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/11f2826e9ee6f24aaa774e3dcd75abbe4b3091b6","https://git.kernel.org/stable/c/511a60e71aec308b24722cffc1912bf6befb87bf","https://git.kernel.org/stable/c/b91e27bce37cab9f35de0059278ebe457ca9878b","https://git.kernel.org/stable/c/c5ef574d57e4a701485c13f26822328c91f05413","https://git.kernel.org/stable/c/cd681403a87085562499d60325b7b45d3be11217","https://git.kernel.org/stable/c/da5234df0941665f3a3f5b80f3dab94046537be0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mm_init: fix uninitialized struct pages for ZONE_DEVICE\n\nIf DAX memory is hotplugged into an unoccupied subsection of an early\nsection, section_activate() reuses the unoptimized boot memmap.  However,\ncompound_nr_pages() still assumes that vmemmap optimization is in effect\nand initializes only the reduced number of struct pages.  As a result, the\nremaining tail struct pages are left uninitialized, which can later lead\nto unexpected behavior or crashes.\n\nFix this by treating early sections as unoptimized when calculating how\nmany struct pages to initialize.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72172","epss":0.00164,"percentile":0.05926,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72172","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72191","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72191","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ntfs3: validate split-point offset in indx_insert_into_buffer  indx_insert_into_buffer() computes      used = used1 - to_copy - sp_size;     memmove(de_t, Add2Ptr(sp, sp_size), used - le32_to_cpu(hdr1->de_off));  where sp and sp_size come from hdr_find_split().  hdr_find_split() walks entries by le16_to_cpu(e->size) without validating that each step stays within hdr->used or that the size field is at least sizeof(struct NTFS_DE).  index_hdr_check(), the on-load gatekeeper, only validates header-level fields (used, total, de_off) and does not walk per-entry sizes.  A crafted NTFS image whose leaf INDEX_HDR reports used == total but contains one interior NTFS_DE with size = 0xFFF0 therefore passes validation, descends to indx_insert_into_buffer() through the ntfs_create() -> indx_insert_entry() path, and makes hdr_find_split() return an sp whose sp_size (0xFFF0) greatly exceeds the remaining bytes in the buffer.  The u32 subtraction underflows and the memmove count becomes a near-4-GiB value, producing an out-of-bounds kernel write that corrupts adjacent allocations and panics the kernel.  Reproduced on 7.0.0-rc7 with UML + KASAN via a crafted image and a single 'touch' inside the mounted directory; crash site resolves to fs/ntfs3/index.c at the memmove.  Trigger requires only local mount of an attacker-supplied filesystem image (USB, loopback, or removable media auto-mount).  Reject the split whenever the chosen sp plus its declared size already extends past hdr1->used.  This is the minimal fix; it preserves the existing hdr_find_split() contract and relies on the same out: cleanup path as the pre-existing error returns.  A prior OOB read in the very same indx_insert_into_buffer() memmove was fixed in commit b8c44949044e (\"fs/ntfs3: Fix OOB read in indx_insert_into_buffer\") by tightening hdr_find_e(), but that fix does not cover the split-point size field path addressed here: sp is returned by hdr_find_split(), not hdr_find_e(), and the underflow is driven by sp->size rather than hdr->used exceeding hdr->total.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72191","epss":0.00679,"percentile":0.50245,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.63826},"relatedVulnerabilities":[{"id":"CVE-2026-72191","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72191","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1758a564b6ebe7f4a82f23c9851d1cae15549457","https://git.kernel.org/stable/c/4c2f648139a0a86f4486170f72e24fedd4fae74e","https://git.kernel.org/stable/c/7bf74e6baf810fe325f111996496c678fc6e244f","https://git.kernel.org/stable/c/8e4ba5a38c155bb3c1c11e63cd285b178cdb099e","https://git.kernel.org/stable/c/b232eb5c9fe11ec2368e9b565db69c724c35fbd2","https://git.kernel.org/stable/c/f1df9d771df47aa40de6d70949c28720ae1e430d","https://git.kernel.org/stable/c/f3624cc069195001c88df7a291af215f2133ff2c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: validate split-point offset in indx_insert_into_buffer\n\nindx_insert_into_buffer() computes\n\n    used = used1 - to_copy - sp_size;\n    memmove(de_t, Add2Ptr(sp, sp_size), used - le32_to_cpu(hdr1->de_off));\n\nwhere sp and sp_size come from hdr_find_split().  hdr_find_split()\nwalks entries by le16_to_cpu(e->size) without validating that each\nstep stays within hdr->used or that the size field is at least\nsizeof(struct NTFS_DE).  index_hdr_check(), the on-load gatekeeper,\nonly validates header-level fields (used, total, de_off) and does\nnot walk per-entry sizes.\n\nA crafted NTFS image whose leaf INDEX_HDR reports used == total but\ncontains one interior NTFS_DE with size = 0xFFF0 therefore passes\nvalidation, descends to indx_insert_into_buffer() through the\nntfs_create() -> indx_insert_entry() path, and makes hdr_find_split()\nreturn an sp whose sp_size (0xFFF0) greatly exceeds the remaining\nbytes in the buffer.  The u32 subtraction underflows and the memmove\ncount becomes a near-4-GiB value, producing an out-of-bounds kernel\nwrite that corrupts adjacent allocations and panics the kernel.\n\nReproduced on 7.0.0-rc7 with UML + KASAN via a crafted image and a\nsingle 'touch' inside the mounted directory; crash site resolves to\nfs/ntfs3/index.c at the memmove.  Trigger requires only local mount\nof an attacker-supplied filesystem image (USB, loopback, or removable\nmedia auto-mount).\n\nReject the split whenever the chosen sp plus its declared size\nalready extends past hdr1->used.  This is the minimal fix; it\npreserves the existing hdr_find_split() contract and relies on the\nsame out: cleanup path as the pre-existing error returns.\n\nA prior OOB read in the very same indx_insert_into_buffer() memmove\nwas fixed in commit b8c44949044e (\"fs/ntfs3: Fix OOB read in\nindx_insert_into_buffer\") by tightening hdr_find_e(), but that fix\ndoes not cover the split-point size field path addressed here: sp is\nreturned by hdr_find_split(), not hdr_find_e(), and the underflow is\ndriven by sp->size rather than hdr->used exceeding hdr->total.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72191","epss":0.00679,"percentile":0.50245,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72191","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72198","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72198","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ntfs: reject non-resident records for resident-only attributes  The shared lookup-time attribute validator rejects non-resident $FILE_NAME and $VOLUME_NAME records because their formats require resident values and callers handle returned records as resident attributes. Other resident-only attribute types still pass through the generic non-resident mapping-pairs checks.  That leaves real resident/non-resident union confusion paths. Inode load looks up $STANDARD_INFORMATION and then reads data.resident.value_offset without checking a->non_resident. ntfs_inode_sync_standard_information() does the same when updating the standard information value. ntfs_write_volume_flags() also looks up $VOLUME_INFORMATION and reads data.resident.value_offset directly. $INDEX_ROOT callers in dir.c and index.c depend on the same lookup contract before consuming the resident index root value.  Reject non-resident records for all resident-only attribute types in the shared validator. Keep the existing $FILE_NAME and $VOLUME_NAME behavior, but factor it through a helper and extend it to $STANDARD_INFORMATION, $OBJECT_ID, $VOLUME_INFORMATION, $INDEX_ROOT, and $EA_INFORMATION. For $OBJECT_ID and $EA_INFORMATION this is contract hardening for resident-only formats; this patch only rejects the non-resident form and does not add new resident value validation for those types.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72198","epss":0.00162,"percentile":0.05674,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.12393},"relatedVulnerabilities":[{"id":"CVE-2026-72198","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72198","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/097cdfd0a55df5af82c9753833f39a8bfadbcfcb","https://git.kernel.org/stable/c/7ffa8f3d30236e0ab897c30bdb01224ff1fe1c89","https://git.kernel.org/stable/c/b54c9beb90e570bae17a9c18442aeeaf17165ccb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: reject non-resident records for resident-only attributes\n\nThe shared lookup-time attribute validator rejects non-resident\n$FILE_NAME and $VOLUME_NAME records because their formats require\nresident values and callers handle returned records as resident\nattributes. Other resident-only attribute types still pass through the\ngeneric non-resident mapping-pairs checks.\n\nThat leaves real resident/non-resident union confusion paths. Inode load\nlooks up $STANDARD_INFORMATION and then reads data.resident.value_offset\nwithout checking a->non_resident. ntfs_inode_sync_standard_information()\ndoes the same when updating the standard information value.\nntfs_write_volume_flags() also looks up $VOLUME_INFORMATION and reads\ndata.resident.value_offset directly. $INDEX_ROOT callers in dir.c and\nindex.c depend on the same lookup contract before consuming the resident\nindex root value.\n\nReject non-resident records for all resident-only attribute types in the\nshared validator. Keep the existing $FILE_NAME and $VOLUME_NAME behavior,\nbut factor it through a helper and extend it to\n$STANDARD_INFORMATION, $OBJECT_ID, $VOLUME_INFORMATION, $INDEX_ROOT, and\n$EA_INFORMATION. For $OBJECT_ID and $EA_INFORMATION this is contract\nhardening for resident-only formats; this patch only rejects the\nnon-resident form and does not add new resident value validation for\nthose types.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72198","epss":0.00162,"percentile":0.05674,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72198","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72200","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72200","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ntfs: detect mapping-pairs LCN accumulator overflow  The NTFS mapping-pairs parser accumulates relative LCN deltas in a signed integer.  A corrupted attribute can drive that addition past the representable range.  One corrupt runlist shape sets the accumulated LCN to S64_MAX and then adds a delta of 1 in the next mapping-pairs entry.  Signed overflow is undefined and can turn an invalid runlist into a different set of physical clusters.  Check the LCN addition for overflow before storing the next run.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72200","epss":0.00598,"percentile":0.46633,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.5621200000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72200","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72200","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/7fb64788812d137b37f6d8724e1e41c624c1e814","https://git.kernel.org/stable/c/7ffa8f3d30236e0ab897c30bdb01224ff1fe1c89","https://git.kernel.org/stable/c/ec4f061f2219e0f0c6465d56d0380bf749235a53"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: detect mapping-pairs LCN accumulator overflow\n\nThe NTFS mapping-pairs parser accumulates relative LCN deltas in a\nsigned integer.  A corrupted attribute can drive that addition past\nthe representable range.\n\nOne corrupt runlist shape sets the accumulated LCN to S64_MAX and\nthen adds a delta of 1 in the next mapping-pairs entry.\n\nSigned overflow is undefined and can turn an invalid runlist into a\ndifferent set of physical clusters.\n\nCheck the LCN addition for overflow before storing the next run.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72200","epss":0.00598,"percentile":0.46633,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72200","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72203","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72203","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ntfs: skip extent mft records in writeback to prevent deadlock  This patch fixes the ABBA deadlock between extent_lock and extent mrec_lock triggered by xfstests generic/113, that occurs since the commit 6994acf33bae (\"ntfs: use base mft_no when looking up base inode for \t\textent record\").  Path A (inode writeback):   VFS writeback     -> ntfs_write_inode()       -> __ntfs_write_inode()         -> mutex_lock(&ni->extent_lock)         -> mutex_lock(&tni->mrec_lock)  Path B (MFT folio writeback):   VFS writeback of $MFT dirty folios     -> ntfs_mft_writepages()       -> ntfs_write_mft_block()         -> ntfs_may_write_mft_record()           -> holds one extent mrec_lock from a previous iteration           -> tries to acquire another base inode extent_lock  By removing all extent_lock and extent mrec_lock acquisition from the MFT folio writeback path, the ABBA lock ordering is eliminated:  Path A: __ntfs_write_inode(): extent_lock -> mrec_lock Path B (removed): ntfs_write_mft_block(): mrec_lock -> extent_lock  Path B is always redundant for extent records because:  1. mark_mft_record_dirty(ext_ni) does NOT dirty the MFT folio.    It only sets NInoDirty(ext_ni) and marks the base VFS inode dirty    via __mark_inode_dirty(I_DIRTY_DATASYNC), which triggers Path A.    Therefore, normal extent modifications never create a situation where    the MFT folio is dirty and Path B is not scheduled.  2. The MFT folio only gets dirtied via ntfs_mft_mark_dirty() inside    ntfs_mft_record_alloc(). But all identified callers in attrib.c    (ntfs_attr_add, ntfs_attr_record_move_away,    ntfs_attr_make_non_resident, ntfs_attr_record_resize) follow through    with mark_mft_record_dirty(), which triggers Path A to write the    complete record.  3. ntfs_evict_big_inode() calls ntfs_commit_inode() before freeing extent    inodes, ensuring all dirty extents are flushed via Path A before the    base inode leaves the icache.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72203","epss":0.00576,"percentile":0.45565,"date":"2026-09-09"}],"fix":{"versions":[],"state":"wont-fix"},"advisories":[],"risk":0.432},"relatedVulnerabilities":[{"id":"CVE-2026-72203","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72203","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/76bc14c7097ff678b2b5dbfd4fa33b46897d87ce","https://git.kernel.org/stable/c/7ffa8f3d30236e0ab897c30bdb01224ff1fe1c89","https://git.kernel.org/stable/c/f831ab09d521898bf1dd99bf5adfd630ea1428e3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: skip extent mft records in writeback to prevent deadlock\n\nThis patch fixes the ABBA deadlock between extent_lock and extent\nmrec_lock triggered by xfstests generic/113, that occurs since the commit\n6994acf33bae (\"ntfs: use base mft_no when looking up base inode for\n\t\textent record\").\n\nPath A (inode writeback):\n  VFS writeback\n    -> ntfs_write_inode()\n      -> __ntfs_write_inode()\n        -> mutex_lock(&ni->extent_lock)\n        -> mutex_lock(&tni->mrec_lock)\n\nPath B (MFT folio writeback):\n  VFS writeback of $MFT dirty folios\n    -> ntfs_mft_writepages()\n      -> ntfs_write_mft_block()\n        -> ntfs_may_write_mft_record()\n          -> holds one extent mrec_lock from a previous iteration\n          -> tries to acquire another base inode extent_lock\n\nBy removing all extent_lock and extent mrec_lock acquisition from the MFT\nfolio writeback path, the ABBA lock ordering is eliminated:\n\nPath A: __ntfs_write_inode(): extent_lock -> mrec_lock\nPath B (removed): ntfs_write_mft_block(): mrec_lock -> extent_lock\n\nPath B is always redundant for extent records because:\n\n1. mark_mft_record_dirty(ext_ni) does NOT dirty the MFT folio.\n   It only sets NInoDirty(ext_ni) and marks the base VFS inode dirty\n   via __mark_inode_dirty(I_DIRTY_DATASYNC), which triggers Path A.\n   Therefore, normal extent modifications never create a situation where\n   the MFT folio is dirty and Path B is not scheduled.\n\n2. The MFT folio only gets dirtied via ntfs_mft_mark_dirty() inside\n   ntfs_mft_record_alloc(). But all identified callers in attrib.c\n   (ntfs_attr_add, ntfs_attr_record_move_away,\n   ntfs_attr_make_non_resident, ntfs_attr_record_resize) follow through\n   with mark_mft_record_dirty(), which triggers Path A to write the\n   complete record.\n\n3. ntfs_evict_big_inode() calls ntfs_commit_inode() before freeing extent\n   inodes, ensuring all dirty extents are flushed via Path A before the\n   base inode leaves the icache.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72203","epss":0.00576,"percentile":0.45565,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72203","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72213","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72213","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch  In alloc_hugetlb_folio(), a single h_cg pointer is used for both the rsvd and non-rsvd hugetlb cgroup charges.  When map_chg is set, hugetlb_cgroup_charge_cgroup_rsvd() stores the charged cgroup in h_cg, but the immediately following hugetlb_cgroup_charge_cgroup() overwrites h_cg with the non-rsvd cgroup pointer.  As a result, hugetlb_cgroup_commit_charge_rsvd() stores the wrong (non-rsvd) cgroup pointer into the folio's rsvd slot.  When the folio is later freed, free_huge_folio() unconditionally calls both hugetlb_cgroup_uncharge_folio() and hugetlb_cgroup_uncharge_folio_rsvd().  The rsvd uncharge reads back the wrong cgroup from the folio and decrements a counter that was never charged for that cgroup, causing a page_counter underflow:    page_counter underflow: -512 nr_pages=512   WARNING: mm/page_counter.c:61 at page_counter_cancel  Fix this by introducing a separate h_cg_rsvd pointer exclusively for the rsvd charge path, keeping the rsvd and non-rsvd charges fully independent through their charge, commit, and error uncharge paths.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72213","epss":0.00159,"percentile":0.05424,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11606999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-72213","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72213","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/15807d0ddde37407af72859426b654f3d1972b00","https://git.kernel.org/stable/c/1697d253f51cf5e3825a3423ff49e128a3502ab2","https://git.kernel.org/stable/c/5c32ae4a91fb5f4941328e0c1720a7fa4189c3bd","https://git.kernel.org/stable/c/b785f2bd9496facedc0a031be09cddcd1d3c84d3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch\n\nIn alloc_hugetlb_folio(), a single h_cg pointer is used for both the rsvd\nand non-rsvd hugetlb cgroup charges.  When map_chg is set,\nhugetlb_cgroup_charge_cgroup_rsvd() stores the charged cgroup in h_cg, but\nthe immediately following hugetlb_cgroup_charge_cgroup() overwrites h_cg\nwith the non-rsvd cgroup pointer.\n\nAs a result, hugetlb_cgroup_commit_charge_rsvd() stores the wrong\n(non-rsvd) cgroup pointer into the folio's rsvd slot.\n\nWhen the folio is later freed, free_huge_folio() unconditionally calls\nboth hugetlb_cgroup_uncharge_folio() and\nhugetlb_cgroup_uncharge_folio_rsvd().  The rsvd uncharge reads back the\nwrong cgroup from the folio and decrements a counter that was never\ncharged for that cgroup, causing a page_counter underflow:\n\n  page_counter underflow: -512 nr_pages=512\n  WARNING: mm/page_counter.c:61 at page_counter_cancel\n\nFix this by introducing a separate h_cg_rsvd pointer exclusively for the\nrsvd charge path, keeping the rsvd and non-rsvd charges fully independent\nthrough their charge, commit, and error uncharge paths.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72213","epss":0.00159,"percentile":0.05424,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72213","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72216","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72216","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  remoteproc: qcom: Fix leak when custom dump_segments addition fails  Free allocated minidump_region 'name' in qcom_add_minidump_segments() when failing before adding the region to 'dump_segments'. Otherwise, the 'name' is not tracked and is never freed by qcom_minidump_cleanup().  Return error when adding to 'dump_segments' fails.","cvss":[],"epss":[{"cve":"CVE-2026-72216","epss":0.00206,"percentile":0.10694,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72216","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72216","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/381c8a7a59da06293951c343857f4a2465b2c655","https://git.kernel.org/stable/c/491edca252d1256b57e805c6e3acae320b53f53e","https://git.kernel.org/stable/c/51aad3d89a2dd2bd34713785b0f2fd5177eb33b6","https://git.kernel.org/stable/c/65104d6eb43f066dcf73ca9ade6478824b17d867","https://git.kernel.org/stable/c/8bfe7e7729617e73233ab5f1a2edbeee5e75c722","https://git.kernel.org/stable/c/e5b1aaa74118e91f0c0f18b22b6f853199873db4","https://git.kernel.org/stable/c/ecf9fc18e62c58eae1ceb65dab2bccb8a724de2d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: qcom: Fix leak when custom dump_segments addition fails\n\nFree allocated minidump_region 'name' in qcom_add_minidump_segments()\nwhen failing before adding the region to 'dump_segments'. Otherwise,\nthe 'name' is not tracked and is never freed by qcom_minidump_cleanup().\n\nReturn error when adding to 'dump_segments' fails.","cvss":[],"epss":[{"cve":"CVE-2026-72216","epss":0.00206,"percentile":0.10694,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72216","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72236","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72236","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()  ev variable is userspace controlled via event->attr.config and used as an array index after bounds checking, but without speculation barriers.  Add the missing array_index_nospec() call to prevent speculative execution.","cvss":[],"epss":[{"cve":"CVE-2026-72236","epss":0.00221,"percentile":0.12648,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11050000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72236","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72236","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/27206bb57c47bdbe33bccc78fa7f7e2a719a06b9","https://git.kernel.org/stable/c/49145bce539117db4b6e9e83c0e5ef528e361050","https://git.kernel.org/stable/c/4c249b214c686f9a1c4cf4f32893b59b189e897a","https://git.kernel.org/stable/c/a21f3615c88421df81060b6ff89220fd34094c4d","https://git.kernel.org/stable/c/f79dff8c721bbb1f3fc312ea55e0551c2cc28801","https://git.kernel.org/stable/c/fa1ebae4206e6afc8caa642e9eb1bbe39a9a724f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()\n\nev variable is userspace controlled via event->attr.config and used\nas an array index after bounds checking, but without speculation\nbarriers.\n\nAdd the missing array_index_nospec() call to prevent speculative\nexecution.","cvss":[],"epss":[{"cve":"CVE-2026-72236","epss":0.00221,"percentile":0.12648,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72236","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72237","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72237","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf/x86/amd/brs: Fix kernel address leakage  A user-only branch stack can contain branches that originate from the kernel. As a result, kernel addresses are exposed to user space even when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors supporting X86_FEATURE_BRS (Zen 3 only), perf can still report entries such as SYSRET/interrupt returns for which the branch-from addresses are in the kernel.  E.g.    $ perf record -j any,u -c 4000 -e branch-brs -o - -- \\         perf bench syscall basic --loop 1000 | \\         perf script -i - -F brstack|tr ' ' '\\n'| \\         grep -E '0x[89a-f][0-9a-f]{15}'    ...   0xffffffff810001c4/0x72e2e32955eb/-/-/-/0//-   0xffffffff810001c4/0x72e2d94a9821/-/-/-/0//-   0xffffffff810001c4/0x72e2d94ffa1b/-/-/-/0//-   ...  BRS provides no hardware branch filtering, so privilege level filtering is performed entirely in software. However, amd_brs_match_plm() only validates the branch-to address against the requested privilege levels. For branches from the kernel to user space, the branch-from address is left unchecked and is leaked. Extend the software filter to also validate the branch-from address, so that any branch record whose branch-from address is in the kernel is dropped when PERF_SAMPLE_BRANCH_USER is requested.","cvss":[],"epss":[{"cve":"CVE-2026-72237","epss":0.00206,"percentile":0.10695,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72237","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72237","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/046f6244da9b68e463a849b21446b9424e531491","https://git.kernel.org/stable/c/2e706be56f418718bb3ae66c0aa94f9b61150e6d","https://git.kernel.org/stable/c/47915e855fb38b42133e31ba917d99565f862154","https://git.kernel.org/stable/c/4f949bc3913a6e3ce3b8574ac6ed1da8ec7a5ad1","https://git.kernel.org/stable/c/90843d00dbc61220b66408ea0d8775cae9e51f70","https://git.kernel.org/stable/c/ac44b4a3d6137489f8fa2e794b12e849c6b22eaa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/brs: Fix kernel address leakage\n\nA user-only branch stack can contain branches that originate from\nthe kernel. As a result, kernel addresses are exposed to user space\neven when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors\nsupporting X86_FEATURE_BRS (Zen 3 only), perf can still report entries\nsuch as SYSRET/interrupt returns for which the branch-from addresses\nare in the kernel.\n\nE.g.\n\n  $ perf record -j any,u -c 4000 -e branch-brs -o - -- \\\n        perf bench syscall basic --loop 1000 | \\\n        perf script -i - -F brstack|tr ' ' '\\n'| \\\n        grep -E '0x[89a-f][0-9a-f]{15}'\n\n  ...\n  0xffffffff810001c4/0x72e2e32955eb/-/-/-/0//-\n  0xffffffff810001c4/0x72e2d94a9821/-/-/-/0//-\n  0xffffffff810001c4/0x72e2d94ffa1b/-/-/-/0//-\n  ...\n\nBRS provides no hardware branch filtering, so privilege level\nfiltering is performed entirely in software. However, amd_brs_match_plm()\nonly validates the branch-to address against the requested privilege\nlevels. For branches from the kernel to user space, the branch-from\naddress is left unchecked and is leaked. Extend the software filter to\nalso validate the branch-from address, so that any branch record whose\nbranch-from address is in the kernel is dropped when\nPERF_SAMPLE_BRANCH_USER is requested.","cvss":[],"epss":[{"cve":"CVE-2026-72237","epss":0.00206,"percentile":0.10695,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72237","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72242","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72242","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()  selinux_sctp_bind_connect() dereferences sk->sk_socket to pass a struct socket * to selinux_socket_bind() and selinux_socket_connect_helper().  However, when the hook is invoked from the ASCONF softirq path (sctp_process_asconf), there is no file reference guaranteeing that sk->sk_socket is non-NULL.  The setsockopt callers (bindx, connectx, set_primary, sendmsg connect) hold a file reference and are not affected.  Both selinux_socket_bind() and selinux_socket_connect_helper() immediately resolve sock->sk, never using the struct socket * for anything else.  Refactor the inner logic into helpers that take a struct sock * directly so that selinux_sctp_bind_connect() never needs to touch sk->sk_socket at all.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72242","epss":0.00677,"percentile":0.50178,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.50775},"relatedVulnerabilities":[{"id":"CVE-2026-72242","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72242","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2fcaf133a8fd88b69f32ebaecad93fd302da828f","https://git.kernel.org/stable/c/37d642b37ccdc31e1947c2ebc8dc38f03d4a0ceb","https://git.kernel.org/stable/c/56acfeb10019e200ab6787d01f8d7cbe0f01526f","https://git.kernel.org/stable/c/5d4d93f9bfbc997ffbb03cd6107e8f6979dbb9b4","https://git.kernel.org/stable/c/a4bc2fb8536488b37680c0b66c59434a4b7f8c2f","https://git.kernel.org/stable/c/cc8bd47b35eca82393cbad08b1cc86f02e034439","https://git.kernel.org/stable/c/d61a80b17254be7230bc5544f8e62ddf21ab38e2","https://git.kernel.org/stable/c/e4f3b8db1b0c5e9f6374b8996d9e1888d1042b55"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: avoid sk_socket dereference in selinux_sctp_bind_connect()\n\nselinux_sctp_bind_connect() dereferences sk->sk_socket to pass a\nstruct socket * to selinux_socket_bind() and\nselinux_socket_connect_helper().  However, when the hook is invoked\nfrom the ASCONF softirq path (sctp_process_asconf), there is no file\nreference guaranteeing that sk->sk_socket is non-NULL.  The setsockopt\ncallers (bindx, connectx, set_primary, sendmsg connect) hold a file\nreference and are not affected.\n\nBoth selinux_socket_bind() and selinux_socket_connect_helper()\nimmediately resolve sock->sk, never using the struct socket * for\nanything else.  Refactor the inner logic into helpers that take a\nstruct sock * directly so that selinux_sctp_bind_connect() never needs\nto touch sk->sk_socket at all.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72242","epss":0.00677,"percentile":0.50178,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72242","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72252","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72252","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_set_pipapo: don't leak bad clone into future transaction  On memory allocation failure the cloned nft_pipapo_match can enter a bad state:  - some fields can have their lookup tables resized while others did    not  - bits might have been toggled  - scratch map can be undersized which also means m->bsize_max can be    lower than what is required  This means that the next insertion in the same batch can trigger out-of-bounds writes.  Furthermore, a failure in the first can result in the bad clone to leak into the next transaction because the abort callback is never executed in this case (the upper layer saw an error and no attempt to allocate a transactional request was made).  Record a state for the nft_pipapo_match structure: - NEW (pristine clone) - MOD (modified clone with good state) - ERR (potentially bogus content)  Then make it so that deletes and insertions fail when the clone entered ERR state.  In case the very first insert attempt results in an error, free the clone right away.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72252","epss":0.00164,"percentile":0.05928,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72252","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72252","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/02b6b0e892aea582590671796fd6eff5b93ea93f","https://git.kernel.org/stable/c/047e813324eac2ac60cddfb58bcdbd0144eadb09","https://git.kernel.org/stable/c/0ab7b1802f63ca5b288ea59acb467830b83abd6b","https://git.kernel.org/stable/c/47e65eff50691f0a5b79d325e28d83ec1da43bcf","https://git.kernel.org/stable/c/610e3b73efaec3dd81a95dcda2421ad7d9795bd0","https://git.kernel.org/stable/c/cc53703f48558896295f565cd4f5e956d21b7af4","https://git.kernel.org/stable/c/e74f9680e1b64872a51cc7b5bda1edaaa08aa51f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: don't leak bad clone into future transaction\n\nOn memory allocation failure the cloned nft_pipapo_match can enter a bad\nstate:\n - some fields can have their lookup tables resized while others did\n   not\n - bits might have been toggled\n - scratch map can be undersized which also means m->bsize_max can be\n   lower than what is required\n\nThis means that the next insertion in the same batch can trigger\nout-of-bounds writes.\n\nFurthermore, a failure in the first can result in the bad clone to\nleak into the next transaction because the abort callback is never\nexecuted in this case (the upper layer saw an error and no attempt to\nallocate a transactional request was made).\n\nRecord a state for the nft_pipapo_match structure:\n- NEW (pristine clone)\n- MOD (modified clone with good state)\n- ERR (potentially bogus content)\n\nThen make it so that deletes and insertions fail when the clone\nentered ERR state.\n\nIn case the very first insert attempt results in an error, free the\nclone right away.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72252","epss":0.00164,"percentile":0.05928,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72252","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72253","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72253","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack_sip: validate skb_dst() before accessing it  tc ingress and openvswitch do not guarantee routing information to be available. These subsystems use the conntrack helper infrastructure, and the SIP helper relies on the skb_dst() to be present if sip_external_media is set to 1 (which is disabled by default as a module parameter).  This effectively disables the sip_external_media toggle for these subsystems without resulting in a crash.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72253","epss":0.00677,"percentile":0.50178,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.50775},"relatedVulnerabilities":[{"id":"CVE-2026-72253","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72253","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/09755dc62b026076b1d47f83489eb0547c8135e0","https://git.kernel.org/stable/c/0aec339694a56e263d4b22475ff7211d40900830","https://git.kernel.org/stable/c/7866116a040b3a23fb094e7d8f7ea3d61b3ac70b","https://git.kernel.org/stable/c/b843a96252f672332837ea2ecb7c8db0acf68e20","https://git.kernel.org/stable/c/c199ed687c00841daf60e9d131976958583a8c09","https://git.kernel.org/stable/c/c5ef7228be04518d95591fc5369a9c554b19756d","https://git.kernel.org/stable/c/e5e24a365a5e024efef63cc49abb345fbd4852c5","https://git.kernel.org/stable/c/e64a48c50a1ff565a98c6a98d82b5b942868e76e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: validate skb_dst() before accessing it\n\ntc ingress and openvswitch do not guarantee routing information to be\navailable. These subsystems use the conntrack helper infrastructure, and\nthe SIP helper relies on the skb_dst() to be present if\nsip_external_media is set to 1 (which is disabled by default as a module\nparameter).\n\nThis effectively disables the sip_external_media toggle for these\nsubsystems without resulting in a crash.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72253","epss":0.00677,"percentile":0.50178,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72253","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72254","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72254","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_fib: reject fib expression on the netdev egress hook  A fib expression in a netdev egress base chain dereferences nft_in(pkt), NULL on the transmit path, causing a NULL pointer dereference at eval. nft_fib_validate() masks the hook with NF_INET_* values, but netdev hook numbers are a separate enum that aliases them (NF_NETDEV_EGRESS == NF_INET_LOCAL_IN), so an egress chain passes validation and then faults.  Add nft_fib_netdev_validate() that limits each result/flag to the netdev hook where the device it reads exists: the input-device cases (OIF, OIFNAME, ADDRTYPE with F_IIF) to ingress, the output-device case (ADDRTYPE with F_OIF) to egress, ADDRTYPE with no device flag to both. Also restrict nft_fib_validate() to NFPROTO_IPV4/IPV6/INET so its NF_INET_* masks are not applied to another family's hooks.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72254","epss":0.00595,"percentile":0.46477,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.44625000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-72254","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72254","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4fee43759b489559a491f7c95f9bfa7a1d0c7a10","https://git.kernel.org/stable/c/568931f26af4727a51e8521f72efbc78d3b82410","https://git.kernel.org/stable/c/d01c913febead04a01a5f3a6374d1f45504dc523","https://git.kernel.org/stable/c/d07955dd34ecae17d35d8c7d0a273a3fba653a8c","https://git.kernel.org/stable/c/f68305267ebda7e839b5e8f77e8d77535a3d5a0f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_fib: reject fib expression on the netdev egress hook\n\nA fib expression in a netdev egress base chain dereferences nft_in(pkt),\nNULL on the transmit path, causing a NULL pointer dereference at eval.\nnft_fib_validate() masks the hook with NF_INET_* values, but netdev hook\nnumbers are a separate enum that aliases them (NF_NETDEV_EGRESS ==\nNF_INET_LOCAL_IN), so an egress chain passes validation and then faults.\n\nAdd nft_fib_netdev_validate() that limits each result/flag to the netdev\nhook where the device it reads exists: the input-device cases (OIF,\nOIFNAME, ADDRTYPE with F_IIF) to ingress, the output-device case (ADDRTYPE\nwith F_OIF) to egress, ADDRTYPE with no device flag to both. Also restrict\nnft_fib_validate() to NFPROTO_IPV4/IPV6/INET so its NF_INET_* masks are\nnot applied to another family's hooks.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72254","epss":0.00595,"percentile":0.46477,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72254","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72260","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72260","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: mediatek: mt8192: Check runtime resume during probe  The MT8192 AFE probe enables runtime PM temporarily while reinitializing the regmap cache from hardware, but it uses pm_runtime_get_sync() without checking the return value. If runtime resume fails, probe keeps going without the device necessarily being accessible, and pm_runtime_get_sync() may leave the PM usage count incremented.  The regmap_reinit_cache() failure path also returns before dropping the temporary PM reference and before clearing pm_runtime_bypass_reg_ctl.  Use pm_runtime_resume_and_get() so resume failures do not leak a usage count, and clear the temporary bypass flag after dropping the probe PM reference on all regmap_reinit_cache() outcomes.","cvss":[],"epss":[{"cve":"CVE-2026-72260","epss":0.00216,"percentile":0.11988,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.108},"relatedVulnerabilities":[{"id":"CVE-2026-72260","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72260","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/6e2ee6eacc3ec7b339753abcf33812d27e03efe5","https://git.kernel.org/stable/c/91b20e8c9b64042056d14394c89c81fc16a1c327","https://git.kernel.org/stable/c/9339266a8a720889d0385cfd78ba6652fe7bb1a8","https://git.kernel.org/stable/c/e0f276f1918a202e9c3ac72baffd311cecb6b8db","https://git.kernel.org/stable/c/e24d5dde56a50946020b134fa8448869093db76a","https://git.kernel.org/stable/c/f6e424835cc05d215c57b6370b2c1e353dd02915","https://git.kernel.org/stable/c/faa97a1a6cab01cd3e2055deb4db4e57efc43ff2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8192: Check runtime resume during probe\n\nThe MT8192 AFE probe enables runtime PM temporarily while reinitializing\nthe regmap cache from hardware, but it uses pm_runtime_get_sync()\nwithout checking the return value. If runtime resume fails, probe keeps\ngoing without the device necessarily being accessible, and\npm_runtime_get_sync() may leave the PM usage count incremented.\n\nThe regmap_reinit_cache() failure path also returns before dropping the\ntemporary PM reference and before clearing pm_runtime_bypass_reg_ctl.\n\nUse pm_runtime_resume_and_get() so resume failures do not leak a usage\ncount, and clear the temporary bypass flag after dropping the probe PM\nreference on all regmap_reinit_cache() outcomes.","cvss":[],"epss":[{"cve":"CVE-2026-72260","epss":0.00216,"percentile":0.11988,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72260","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72262","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72262","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get  The ipc_control_data buffer is allocated as kzalloc(max_size), where max_size covers the entire struct sof_ipc_ctrl_data including its flexible array payload. However, the bounds checks in bytes_ext_put and _bytes_ext_get compared user data lengths against max_size directly, ignoring that cdata->data sits at an offset of sizeof(struct sof_ipc_ctrl_data) bytes into the allocation.  This allowed writing up to sizeof(struct sof_ipc_ctrl_data) bytes past the end of the heap buffer from unprivileged userspace via the ALSA TLV kcontrol interface, and similarly allowed over-reading adjacent heap data on the get path.  Fix all bounds checks to subtract sizeof(*cdata) from max_size so they reflect the actual space available at the cdata->data offset. Also fix the error-path restore in bytes_ext_put which wrote to cdata->data instead of cdata, causing the same overflow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72262","epss":0.00182,"percentile":0.07919,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13923},"relatedVulnerabilities":[{"id":"CVE-2026-72262","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72262","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/121577383b5cf221e86581e0f2bcca4c66f17469","https://git.kernel.org/stable/c/1adde1941bba7b0d7104b86ed819d48d81cb0ad9","https://git.kernel.org/stable/c/af4b437a463ac0482ba705434a44da06783778e6","https://git.kernel.org/stable/c/eaa67e139c9217099e2a7b717aeeb46c65de3494","https://git.kernel.org/stable/c/f4933e1d11b97b6a0951648b7c3e53850e1b33a9","https://git.kernel.org/stable/c/fd46668d538993218eea19c6925c868ac0f2630c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get\n\nThe ipc_control_data buffer is allocated as kzalloc(max_size), where\nmax_size covers the entire struct sof_ipc_ctrl_data including its\nflexible array payload. However, the bounds checks in bytes_ext_put\nand _bytes_ext_get compared user data lengths against max_size\ndirectly, ignoring that cdata->data sits at an offset of\nsizeof(struct sof_ipc_ctrl_data) bytes into the allocation.\n\nThis allowed writing up to sizeof(struct sof_ipc_ctrl_data) bytes past\nthe end of the heap buffer from unprivileged userspace via the ALSA TLV\nkcontrol interface, and similarly allowed over-reading adjacent heap\ndata on the get path.\n\nFix all bounds checks to subtract sizeof(*cdata) from max_size so they\nreflect the actual space available at the cdata->data offset. Also fix\nthe error-path restore in bytes_ext_put which wrote to cdata->data\ninstead of cdata, causing the same overflow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72262","epss":0.00182,"percentile":0.07919,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72262","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72288","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72288","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling  Hyunwoo Kim reports some really bad races should the following situation occur:  - LPI-I is pending in vcpu-B's AP list - vcpu-A writes to vcpu-B's RD to disable its LPIs - vcpu-C moves I from B to C  If the last two race nicely enough, vgic_prune_ap_list() can drop the irq and AP list locks, reacquire them, and in the interval the irq has been freed. UAF follows.  The fix is two-fold:  - Before dropping the irq and ap_list locks, take a reference on   the irq  - Do not try to handle migration of the pending bit: there is no   expectation that this state is retained, as per the architecture  With that, we're sure that the interrupt is still around, and we safely remove it from the AP list as it has no target at this stage (unless another interrupt fires, but that's another story).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72288","epss":0.00178,"percentile":0.07477,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.16287000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72288","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72288","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/7258770e5814f15e8308ebda82ac9acf6964ba8e","https://git.kernel.org/stable/c/b1a89d12d35a8256d2b170ced0b1c86851f3def2","https://git.kernel.org/stable/c/d19dca8194ebed371e624331c6be2cb73b562caf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling\n\nHyunwoo Kim reports some really bad races should the following\nsituation occur:\n\n- LPI-I is pending in vcpu-B's AP list\n- vcpu-A writes to vcpu-B's RD to disable its LPIs\n- vcpu-C moves I from B to C\n\nIf the last two race nicely enough, vgic_prune_ap_list() can drop\nthe irq and AP list locks, reacquire them, and in the interval\nthe irq has been freed. UAF follows.\n\nThe fix is two-fold:\n\n- Before dropping the irq and ap_list locks, take a reference on\n  the irq\n\n- Do not try to handle migration of the pending bit: there is no\n  expectation that this state is retained, as per the architecture\n\nWith that, we're sure that the interrupt is still around, and we\nsafely remove it from the AP list as it has no target at this\nstage (unless another interrupt fires, but that's another story).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72288","epss":0.00178,"percentile":0.07477,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72288","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72299","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72299","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: restrict socket queue dumps in enqueue tracepoints  tipc_sk_enqueue() runs with sk->sk_lock.slock held while the socket is owned by user context. The spinlock protects the backlog queue in this path, but it does not serialize against the socket owner consuming or purging sk_receive_queue.  KASAN reported:    CPU: 14 UID: 0 PID: 1050 Comm: tipc3 Not tainted 7.1.0-rc6+ #126 PREEMPT(lazy)   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014   Call Trace:     <TASK>     dump_stack_lvl+0x76/0xa0 lib/dump_stack.c:123     print_report+0xce/0x5b0 mm/kasan/report.c:482     kasan_report+0xc6/0x100 mm/kasan/report.c:597     __asan_report_load4_noabort+0x14/0x30 mm/kasan/report_generic.c:380     tipc_skb_dump+0x1327/0x16f0 net/tipc/trace.c:73     tipc_list_dump+0x208/0x2e0 net/tipc/trace.c:187     tipc_sk_dump+0xaf6/0xd60 net/tipc/socket.c:3996     trace_event_raw_event_tipc_sk_class+0x312/0x5a0 net/tipc/trace.h:188     tipc_sk_rcv+0xb1d/0x1d50 net/tipc/socket.c:2497     tipc_node_xmit+0x1c3/0x1440 net/tipc/node.c:1689     __tipc_sendmsg+0x97a/0x1440 net/tipc/socket.c:1512     tipc_sendmsg+0x52/0x80 net/tipc/socket.c:1400     sock_sendmsg+0x2f6/0x3e0 net/socket.c:825     splice_to_socket+0x7f9/0x1010 fs/splice.c:884     do_splice+0xe21/0x2330 fs/splice.c:936     __do_splice+0x153/0x260 fs/splice.c:1431     __x64_sys_splice+0x150/0x230 fs/splice.c:1616     x64_sys_call+0xeb5/0x2790 arch/x86/entry/syscall_64.c:41     do_syscall_64+0xf3/0x620 arch/x86/entry/syscall_64.c:63     entry_SYSCALL_64_after_hwframe+0x76/0x7e arch/x86/entry/entry_64.S:130   RIP: 0033:0x71624e8aafe2   Code: 08 0f 85 71 3a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00 66   RSP: 002b:0000716157ffed68 EFLAGS: 00000246 ORIG_RAX: 0000000000000113   RAX: ffffffffffffffda RBX: 0000716157fff6c0 RCX: 000071624e8aafe2   RDX: 000000000000005f RSI: 0000000000000000 RDI: 0000000000000066   RBP: 0000716157ffed90 R08: 0000000000008000 R09: 0000000000000001   R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff00   R13: 0000000000000021 R14: 0000000000000000 R15: 00007fff89799c40     </TASK>  The TIPC_DUMP_ALL tracepoints in tipc_sk_enqueue() also dump sk_receive_queue and can therefore dereference skbs that the socket owner has already dequeued or freed. Restrict these dumps to TIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held spinlock.  Keep the change limited to the enqueue path, where the unsafe queue dump is reachable while the socket is owned by user context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72299","epss":0.00745,"percentile":0.52639,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.7003},"relatedVulnerabilities":[{"id":"CVE-2026-72299","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72299","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/12876864f9de5fa6f611a30c6c17e405a773bf0a","https://git.kernel.org/stable/c/258fb15b30db4f3941ab335d5e02f744baf1da54","https://git.kernel.org/stable/c/273ff83c49b82e4267373adbe629e6ee8aeaa16c","https://git.kernel.org/stable/c/61a55fa24a5d737436018764a647fe5b6cb36371","https://git.kernel.org/stable/c/6acbbe54215d5f4251593000cff2bf51d6748713","https://git.kernel.org/stable/c/acd7df8d955480a6f6e5bb809da67b1500cc3cf4","https://git.kernel.org/stable/c/ae5d0d9ce767b20a5580bb6dc5e06f3e1b8a0fb0","https://git.kernel.org/stable/c/b9e100815f4b55e9ccaf6af9a3aba173eb13d381"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: restrict socket queue dumps in enqueue tracepoints\n\ntipc_sk_enqueue() runs with sk->sk_lock.slock held while the socket is\nowned by user context. The spinlock protects the backlog queue in this\npath, but it does not serialize against the socket owner consuming or\npurging sk_receive_queue.\n\nKASAN reported:\n\n  CPU: 14 UID: 0 PID: 1050 Comm: tipc3 Not tainted 7.1.0-rc6+ #126 PREEMPT(lazy)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n  Call Trace:\n    <TASK>\n    dump_stack_lvl+0x76/0xa0 lib/dump_stack.c:123\n    print_report+0xce/0x5b0 mm/kasan/report.c:482\n    kasan_report+0xc6/0x100 mm/kasan/report.c:597\n    __asan_report_load4_noabort+0x14/0x30 mm/kasan/report_generic.c:380\n    tipc_skb_dump+0x1327/0x16f0 net/tipc/trace.c:73\n    tipc_list_dump+0x208/0x2e0 net/tipc/trace.c:187\n    tipc_sk_dump+0xaf6/0xd60 net/tipc/socket.c:3996\n    trace_event_raw_event_tipc_sk_class+0x312/0x5a0 net/tipc/trace.h:188\n    tipc_sk_rcv+0xb1d/0x1d50 net/tipc/socket.c:2497\n    tipc_node_xmit+0x1c3/0x1440 net/tipc/node.c:1689\n    __tipc_sendmsg+0x97a/0x1440 net/tipc/socket.c:1512\n    tipc_sendmsg+0x52/0x80 net/tipc/socket.c:1400\n    sock_sendmsg+0x2f6/0x3e0 net/socket.c:825\n    splice_to_socket+0x7f9/0x1010 fs/splice.c:884\n    do_splice+0xe21/0x2330 fs/splice.c:936\n    __do_splice+0x153/0x260 fs/splice.c:1431\n    __x64_sys_splice+0x150/0x230 fs/splice.c:1616\n    x64_sys_call+0xeb5/0x2790 arch/x86/entry/syscall_64.c:41\n    do_syscall_64+0xf3/0x620 arch/x86/entry/syscall_64.c:63\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e arch/x86/entry/entry_64.S:130\n  RIP: 0033:0x71624e8aafe2\n  Code: 08 0f 85 71 3a ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 66 2e 0f 1f 84 00 00 00 00 00 66\n  RSP: 002b:0000716157ffed68 EFLAGS: 00000246 ORIG_RAX: 0000000000000113\n  RAX: ffffffffffffffda RBX: 0000716157fff6c0 RCX: 000071624e8aafe2\n  RDX: 000000000000005f RSI: 0000000000000000 RDI: 0000000000000066\n  RBP: 0000716157ffed90 R08: 0000000000008000 R09: 0000000000000001\n  R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff00\n  R13: 0000000000000021 R14: 0000000000000000 R15: 00007fff89799c40\n    </TASK>\n\nThe TIPC_DUMP_ALL tracepoints in tipc_sk_enqueue() also dump\nsk_receive_queue and can therefore dereference skbs that the socket\nowner has already dequeued or freed. Restrict these dumps to\nTIPC_DUMP_SK_BKLGQ, which matches the queue protected by the held\nspinlock.\n\nKeep the change limited to the enqueue path, where the unsafe queue dump\nis reachable while the socket is owned by user context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72299","epss":0.00745,"percentile":0.52639,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72299","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72305","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72305","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  VDUSE: avoid leaking information to userspace  The bounceing is not necessarily page aligned, so current VDUSE can leak kernel information through mapping bounce pages to userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking information to userspace.","cvss":[],"epss":[{"cve":"CVE-2026-72305","epss":0.00206,"percentile":0.107,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10300000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72305","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72305","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/00335df9da2011e095f846d645cc2e9fd2907659","https://git.kernel.org/stable/c/3ae878f262bd1445c8c31511856a99962a05fe16","https://git.kernel.org/stable/c/41e27a6aca608c9e04f091c29c420d03fafe0313","https://git.kernel.org/stable/c/5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1","https://git.kernel.org/stable/c/690fb82c4122f8c2656fa4f842275132771b68b9","https://git.kernel.org/stable/c/9c1523803445ee0348f62b77793266dd981596e0","https://git.kernel.org/stable/c/fde25641cbddd0c084e3320d08f755e7e6acfae5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nVDUSE: avoid leaking information to userspace\n\nThe bounceing is not necessarily page aligned, so current VDUSE can\nleak kernel information through mapping bounce pages to\nuserspace. Allocate bounce pages with __GFP_ZERO to avoid leaking\ninformation to userspace.","cvss":[],"epss":[{"cve":"CVE-2026-72305","epss":0.00206,"percentile":0.107,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72305","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72308","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()  When mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join() returns an error without releasing the lag reference obtained by the earlier mlxsw_sp_lag_get().  All other error paths in the function jump to the cleanup label that ends with mlxsw_sp_lag_put(), so this is a single missed release.  Fix the leak by replacing the bare 'return err' with a goto to the existing error cleanup label, which will drop the reference safely.","cvss":[],"epss":[{"cve":"CVE-2026-72308","epss":0.0022,"percentile":0.12444,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11},"relatedVulnerabilities":[{"id":"CVE-2026-72308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72308","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1cf8a1af42b1f12a30b7abd34fe4fc23b3170e7e","https://git.kernel.org/stable/c/2d8b3c3e129973a51ae924bdcf6993a76b828814","https://git.kernel.org/stable/c/3fbeaa8ecd144ad593f9fa1ab4b40a780ad3700b","https://git.kernel.org/stable/c/41c8c1d65b32beacd8d916a22457b4f6e47f45af","https://git.kernel.org/stable/c/8b3350eacd9df0597bfe36a594df7b9def0b3edf","https://git.kernel.org/stable/c/99ff5b0083eae6f774360c4ea6874604e6c9b553","https://git.kernel.org/stable/c/9bf2d6eea26a226f8ebab7baea6f2b018f914560","https://git.kernel.org/stable/c/cab468c3c03f4bcd7530ce2783a4140da14efb7b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: fix refcount leak in mlxsw_sp_port_lag_join()\n\nWhen mlxsw_sp_port_lag_index_get() fails, mlxsw_sp_port_lag_join()\nreturns an error without releasing the lag reference obtained by\nthe earlier mlxsw_sp_lag_get().  All other error paths in the\nfunction jump to the cleanup label that ends with\nmlxsw_sp_lag_put(), so this is a single missed release.\n\nFix the leak by replacing the bare 'return err' with a goto to the\nexisting error cleanup label, which will drop the reference safely.","cvss":[],"epss":[{"cve":"CVE-2026-72308","epss":0.0022,"percentile":0.12444,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72308","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72315","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72315","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix busy dentry warning on unmount after DIO  Commit c68337442f03 (\"cifs: Fix busy dentry used after unmounting\") fixed the issue in cifs where deferred close of a file led to a dentry reference count not being released in umount, by flushing deferredclose_wq in cifs_kill_sb() to solve it.  However, the cifs DIO path suffers from the same busy-dentry problem caused by a delayed dentry reference-count release:  \t[dio]\t\t\t[cifsd]\t\t\t[close + umount] netfs_unbuffered_write_iter_locked ... \t\t\t\tcifs_demultiplex_thread  netfs_unbuffered_write   cifs_issue_write   netfs_wait_for_in_progress_stream [1] \t\t\t\t... \t\t\t\t netfs_write_subrequest_terminated \t\t\t\t  netfs_subreq_clear_in_progress \t\t\t\t   netfs_wake_collector // wake [1] \t\t\t\t  netfs_put_subrequest  netfs_put_request   queue_work(system_dfl_wq, xxx) [2]  // dio write return\t\t\t\t\tcifs_close \t\t\t\t\t\t\t _cifsFileInfo_put \t\t\t\t\t\t\t  // cfile->count 2->1 \t\t\t\t\t\t\t  --cfile->count [3]  \t\t\t\t\t\t\t// umount \t\t\t\t\t\t\tcifs_kill_sb \t\t\t\t\t\t\t kill_anon_super \t\t\t\t\t\t\t  // warning triggered! \t\t\t\t\t\t\t  shrink_dcache_for_umount [4] [system_dfl_wq] [5] netfs_free_request  ...  _cifsFileInfo_put   // cfile->count 1->0   --cfile->count   queue_work(fileinfo_put_wq, xxx)  [fileinfo_put_wq] [6] cifsFileInfo_put_work  cifsFileInfo_put_final   dput  If the umount path is triggered before [5], it results warning: BUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test}  still in use (1) [unmount of cifs cifs]  The existing per-inode ictx->io_count wait in cifs_evict_inode() does not help: it lives in the inode eviction path, which runs after shrink_dcache_for_umount() has already warned about the busy dentries.  Fix it by adding a per-superblock outstanding-rreq counter that is incremented in cifs_init_request() and decremented in cifs_free_request(). In cifs_kill_sb(), before kill_anon_super(), wait for this counter to reach 0 - which guarantees that all cleanup_work for this sb have run and thus all relevant cfile puts are queued on fileinfo_put_wq or serverclose_wq. Then drain the workqueue so the dentry refs are dropped.  This is a targeted wait, not a flush of the system-wide system_dfl_wq.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72315","epss":0.00165,"percentile":0.06061,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.126225},"relatedVulnerabilities":[{"id":"CVE-2026-72315","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72315","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/75f5c412fa867efa0bf9b646bffe0d912109e84a","https://git.kernel.org/stable/c/f0eac9c3c3711f24efc2aaf12b8ec3e54a38c214"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix busy dentry warning on unmount after DIO\n\nCommit c68337442f03 (\"cifs: Fix busy dentry used after unmounting\") fixed\nthe issue in cifs where deferred close of a file led to a dentry reference\ncount not being released in umount, by flushing deferredclose_wq in\ncifs_kill_sb() to solve it.\n\nHowever, the cifs DIO path suffers from the same busy-dentry problem caused\nby a delayed dentry reference-count release:\n\n\t[dio]\t\t\t[cifsd]\t\t\t[close + umount]\nnetfs_unbuffered_write_iter_locked\n...\n\t\t\t\tcifs_demultiplex_thread\n netfs_unbuffered_write\n  cifs_issue_write\n  netfs_wait_for_in_progress_stream [1]\n\t\t\t\t...\n\t\t\t\t netfs_write_subrequest_terminated\n\t\t\t\t  netfs_subreq_clear_in_progress\n\t\t\t\t   netfs_wake_collector // wake [1]\n\t\t\t\t  netfs_put_subrequest\n netfs_put_request\n  queue_work(system_dfl_wq, xxx) [2]\n // dio write return\t\t\t\t\tcifs_close\n\t\t\t\t\t\t\t _cifsFileInfo_put\n\t\t\t\t\t\t\t  // cfile->count 2->1\n\t\t\t\t\t\t\t  --cfile->count [3]\n\n\t\t\t\t\t\t\t// umount\n\t\t\t\t\t\t\tcifs_kill_sb\n\t\t\t\t\t\t\t kill_anon_super\n\t\t\t\t\t\t\t  // warning triggered!\n\t\t\t\t\t\t\t  shrink_dcache_for_umount [4]\n[system_dfl_wq] [5]\nnetfs_free_request\n ...\n _cifsFileInfo_put\n  // cfile->count 1->0\n  --cfile->count\n  queue_work(fileinfo_put_wq, xxx)\n\n[fileinfo_put_wq] [6]\ncifsFileInfo_put_work\n cifsFileInfo_put_final\n  dput\n\nIf the umount path is triggered before [5], it results warning:\nBUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test}  still in use (1)\n[unmount of cifs cifs]\n\nThe existing per-inode ictx->io_count wait in cifs_evict_inode() does not\nhelp: it lives in the inode eviction path, which runs after\nshrink_dcache_for_umount() has already warned about the busy dentries.\n\nFix it by adding a per-superblock outstanding-rreq counter that is\nincremented in cifs_init_request() and decremented in cifs_free_request().\nIn cifs_kill_sb(), before kill_anon_super(), wait for this counter to reach\n0 - which guarantees that all cleanup_work for this sb have run and thus\nall relevant cfile puts are queued on fileinfo_put_wq or serverclose_wq.\nThen drain the workqueue so the dentry refs are dropped.\n\nThis is a targeted wait, not a flush of the system-wide system_dfl_wq.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72315","epss":0.00165,"percentile":0.06061,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72315","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72320","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72320","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_lookup: fix catchall element handling with inverted lookups  nft_lookup_eval() decides whether a lookup matched (`found`) from the direct set lookup and priv->invert before falling back to the catchall element used by interval sets (e.g. nft_set_rbtree) for the open-ended default range. Since `found` is never recomputed after `ext` is replaced by the catchall lookup, inverted lookups (NFT_LOOKUP_F_INV, \"!= @set\") can wrongly match or wrongly skip the catchall element, producing the wrong verdict. Fold the catchall lookup into `ext` before computing `found`, matching the order already used by nft_objref_map_eval().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72320","epss":0.00523,"percentile":0.42679,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.47331500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-72320","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72320","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0ab8880865f9678eb6174e72c1fc4712e44c745c","https://git.kernel.org/stable/c/238c612357b5a25f03eacf356f95034f8551f218","https://git.kernel.org/stable/c/e6107a4c74b54cb33e3bce162a63048ae5a6b198","https://git.kernel.org/stable/c/ef0c7d4b04a0e6ad175323c24bc84e11470dd79d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_lookup: fix catchall element handling with inverted lookups\n\nnft_lookup_eval() decides whether a lookup matched (`found`) from the\ndirect set lookup and priv->invert before falling back to the\ncatchall element used by interval sets (e.g. nft_set_rbtree) for the\nopen-ended default range. Since `found` is never recomputed after\n`ext` is replaced by the catchall lookup, inverted lookups\n(NFT_LOOKUP_F_INV, \"!= @set\") can wrongly match or wrongly skip the\ncatchall element, producing the wrong verdict. Fold the catchall\nlookup into `ext` before computing `found`, matching the order\nalready used by nft_objref_map_eval().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72320","epss":0.00523,"percentile":0.42679,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72320","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72321","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72321","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()  When a timer is deleted and not re-armed in igmp_mod_timer(), or stopped in igmp_stop_timer(), the code currently decrements the reference counter of the multicast list entry @im using refcount_dec(&im->refcnt).  However, both functions can be called from the RCU reader path: - igmp_mod_timer() via igmp_heard_query() -> for_each_pmc_rcu() - igmp_stop_timer() via igmp_rcv() -> igmp_heard_report()  If the group im was concurrently removed from the list by ip_mc_dec_group(), its reference count might have already been decremented to 1.  In this case, timer_delete() succeeds, and refcount_dec() decrements the refcount from 1 to 0. Since refcount_dec() does not free the object when it hits 0 (unlike ip_ma_put()), the im structure is leaked.  Fix this by using ip_ma_put(im) instead of refcount_dec(&im->refcnt), and deferring the put until after the spinlock is released.","cvss":[],"epss":[{"cve":"CVE-2026-72321","epss":0.00207,"percentile":0.10831,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1035},"relatedVulnerabilities":[{"id":"CVE-2026-72321","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72321","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3546deaa0c30a14c7cdb5dc8f2432cb428f0cd36","https://git.kernel.org/stable/c/95128dc74425ec19ed4f2077ccc651e791ff4b75","https://git.kernel.org/stable/c/f60ec3058a85447008b88b762c859d336163acb3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()\n\nWhen a timer is deleted and not re-armed in igmp_mod_timer(), or stopped\nin igmp_stop_timer(), the code currently decrements the reference counter\nof the multicast list entry @im using refcount_dec(&im->refcnt).\n\nHowever, both functions can be called from the RCU reader path:\n- igmp_mod_timer() via igmp_heard_query() -> for_each_pmc_rcu()\n- igmp_stop_timer() via igmp_rcv() -> igmp_heard_report()\n\nIf the group im was concurrently removed from the list by ip_mc_dec_group(),\nits reference count might have already been decremented to 1.\n\nIn this case, timer_delete() succeeds, and refcount_dec() decrements\nthe refcount from 1 to 0. Since refcount_dec() does not free the object\nwhen it hits 0 (unlike ip_ma_put()), the im structure is leaked.\n\nFix this by using ip_ma_put(im) instead of refcount_dec(&im->refcnt),\nand deferring the put until after the spinlock is released.","cvss":[],"epss":[{"cve":"CVE-2026-72321","epss":0.00207,"percentile":0.10831,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72321","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72323","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72323","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()  A race condition exists between device teardown (inetdev_destroy) and incoming IGMP query processing (igmp_rcv), leading to a Use-After-Free in the IGMP timer callback.  During device destruction, inetdev_destroy() drops the primary reference to in_device, which can drop its refcount to 0. The actual freeing of in_device memory is deferred via RCU (using call_rcu()).  Concurrently, igmp_rcv() runs under RCU read lock and obtains the in_device pointer. Because the memory is RCU-protected, CPU-0 can safely dereference in_device even if its refcount has hit 0.  However, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it attempts to acquire a reference using in_dev_hold(). This increments the refcount from 0 to 1, triggering a \"refcount_t: addition on 0\" warning. Since the in_device memory is still scheduled to be freed after the RCU grace period (as the free callback does not check the refcount again), the device is freed while the timer is still armed. When the timer expires, it accesses the freed memory, causing a kernel panic.  Fix this by using refcount_inc_not_zero() (via a new helper in_dev_hold_safe()) to prevent acquiring a reference if the device is already being destroyed. If the refcount is 0, we do not arm the timer.  A similar issue in IPv6 MLD is fixed in a subsequent patch.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72323","epss":0.00724,"percentile":0.51927,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.68056},"relatedVulnerabilities":[{"id":"CVE-2026-72323","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72323","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/165258303357e54b75fc19b341ae2a2b7c9e3910","https://git.kernel.org/stable/c/40a1e998cb266ed4cb529a0bb4fee2b0ba732702","https://git.kernel.org/stable/c/7265c747eec415ca3109a6a14a419f7ae433b780","https://git.kernel.org/stable/c/74b301f7f197517016befb5f5dfab01f7bc64be5","https://git.kernel.org/stable/c/75e984fe0cb9e7fbde0c8ee838c61ce8573d3ea3","https://git.kernel.org/stable/c/7b19c0f81ed1fdaec6bc522569be367199a9edf3","https://git.kernel.org/stable/c/8d4394ffa40508e0de72f464af351f6ca6a6cdc3","https://git.kernel.org/stable/c/d107b4c4f8274763b7ea5ab05d45cef78e4b81ba"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: Fix potential UAF in igmp_gq_start_timer()\n\nA race condition exists between device teardown (inetdev_destroy) and\nincoming IGMP query processing (igmp_rcv), leading to a Use-After-Free\nin the IGMP timer callback.\n\nDuring device destruction, inetdev_destroy() drops the primary reference\nto in_device, which can drop its refcount to 0. The actual freeing of\nin_device memory is deferred via RCU (using call_rcu()).\n\nConcurrently, igmp_rcv() runs under RCU read lock and obtains the\nin_device pointer. Because the memory is RCU-protected, CPU-0 can safely\ndereference in_device even if its refcount has hit 0.\n\nHowever, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it\nattempts to acquire a reference using in_dev_hold(). This increments the\nrefcount from 0 to 1, triggering a \"refcount_t: addition on 0\" warning.\nSince the in_device memory is still scheduled to be freed after the RCU\ngrace period (as the free callback does not check the refcount again),\nthe device is freed while the timer is still armed. When the timer\nexpires, it accesses the freed memory, causing a kernel panic.\n\nFix this by using refcount_inc_not_zero() (via a new helper\nin_dev_hold_safe()) to prevent acquiring a reference if the device is\nalready being destroyed. If the refcount is 0, we do not arm the timer.\n\nA similar issue in IPv6 MLD is fixed in a subsequent patch.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72323","epss":0.00724,"percentile":0.51927,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72323","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72324","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72324","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: mvebu: free generic chips on unbind  irq_alloc_domain_generic_chips() allocates generic chip data that must be freed via irq_domain_remove_generic_chips(). The devres action mvebu_gpio_remove_irq_domain() only called irq_domain_remove(), which only frees the generic chips if IRQ_DOMAIN_FLAG_DESTROY_GC is set. Call irq_domain_remove_generic_chips() explicitly before irq_domain_remove() instead.","cvss":[],"epss":[{"cve":"CVE-2026-72324","epss":0.00209,"percentile":0.11099,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1045},"relatedVulnerabilities":[{"id":"CVE-2026-72324","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72324","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3649b04f86b95243fa0c845695051455fa2ba40b","https://git.kernel.org/stable/c/3bfcce441c552133adeeb99c294d0ce8a62612ef","https://git.kernel.org/stable/c/b11c513ad943f35cf5e8007d3a56279c79b7ed4b","https://git.kernel.org/stable/c/d73e4d790db611da7439e78a6ab6cb32e7885ab8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: mvebu: free generic chips on unbind\n\nirq_alloc_domain_generic_chips() allocates generic chip data that must\nbe freed via irq_domain_remove_generic_chips(). The devres action\nmvebu_gpio_remove_irq_domain() only called irq_domain_remove(), which\nonly frees the generic chips if IRQ_DOMAIN_FLAG_DESTROY_GC is set.\nCall irq_domain_remove_generic_chips() explicitly before\nirq_domain_remove() instead.","cvss":[],"epss":[{"cve":"CVE-2026-72324","epss":0.00209,"percentile":0.11099,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72324","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72325","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72325","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf/x86/amd/core: Avoid enabling BRS from the SVM reload path  Branch Sampling (BRS) and Last Branch Record (LBR) are mutually exclusive hardware features, and users of both are tracked via cpuc->lbr_users.  When SVM is toggled on a CPU, the host perf events are reprogrammed to update the HostOnly filter bit (set when virtualization is enabled, cleared when it is disabled). On PerfMonV2-capable processors, this reprogramming is performed by calling amd_pmu_enable_all() to rewrite the event selectors. However, amd_pmu_enable_all() also calls amd_brs_enable_all(), which enables BRS whenever cpuc->lbr_users > 0. Having active LBR events satisfies this gating on processors that have LBR but not BRS. The kernel then tries to set the BRS enable bit in DebugExtnCfg (MSR 0xc000010f). Since that bit is deprecated on such hardware, the write results in a #GP:    Call Trace:    <IRQ>    amd_pmu_enable_all+0x1d/0x90    amd_pmu_disable_virt+0x62/0xb0    kvm_arch_disable_virtualization_cpu+0xa/0x40 [kvm]    hardware_disable_nolock+0x1a/0x30 [kvm]    __flush_smp_call_function_queue+0x9b/0x410    __sysvec_call_function+0x18/0xc0    sysvec_call_function+0x69/0x90    </IRQ>    <TASK>    asm_sysvec_call_function+0x16/0x20   RIP: 0010:cpuidle_enter_state+0xc4/0x450    ? cpuidle_enter_state+0xb7/0x450    cpuidle_enter+0x29/0x40    cpuidle_idle_call+0xf5/0x160    do_idle+0x7b/0xe0    cpu_startup_entry+0x26/0x30    start_secondary+0x115/0x140    secondary_startup_64_no_verify+0x194/0x19b    </TASK>  Fix this by ensuring that BRS is not enabled from the event selector reprogramming path even when cpuc->lbr_users > 0.","cvss":[],"epss":[{"cve":"CVE-2026-72325","epss":0.00209,"percentile":0.111,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1045},"relatedVulnerabilities":[{"id":"CVE-2026-72325","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72325","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/07c60dda9c059c09f83d42a3ebda2e7cc1cf3bc2","https://git.kernel.org/stable/c/46d0fd8535edce31f15e48d2de1bdee39a4850e5","https://git.kernel.org/stable/c/7cc438c99bba324a0562b1bafa747b10f7e251df","https://git.kernel.org/stable/c/e9b1a7411a667539c2f55e720bbb5f623b526a32"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/core: Avoid enabling BRS from the SVM reload path\n\nBranch Sampling (BRS) and Last Branch Record (LBR) are mutually\nexclusive hardware features, and users of both are tracked via\ncpuc->lbr_users.\n\nWhen SVM is toggled on a CPU, the host perf events are reprogrammed to\nupdate the HostOnly filter bit (set when virtualization is enabled,\ncleared when it is disabled). On PerfMonV2-capable processors, this\nreprogramming is performed by calling amd_pmu_enable_all() to rewrite\nthe event selectors. However, amd_pmu_enable_all() also calls\namd_brs_enable_all(), which enables BRS whenever cpuc->lbr_users > 0.\nHaving active LBR events satisfies this gating on processors that have\nLBR but not BRS. The kernel then tries to set the BRS enable bit in\nDebugExtnCfg (MSR 0xc000010f). Since that bit is deprecated on such\nhardware, the write results in a #GP:\n\n  Call Trace:\n   <IRQ>\n   amd_pmu_enable_all+0x1d/0x90\n   amd_pmu_disable_virt+0x62/0xb0\n   kvm_arch_disable_virtualization_cpu+0xa/0x40 [kvm]\n   hardware_disable_nolock+0x1a/0x30 [kvm]\n   __flush_smp_call_function_queue+0x9b/0x410\n   __sysvec_call_function+0x18/0xc0\n   sysvec_call_function+0x69/0x90\n   </IRQ>\n   <TASK>\n   asm_sysvec_call_function+0x16/0x20\n  RIP: 0010:cpuidle_enter_state+0xc4/0x450\n   ? cpuidle_enter_state+0xb7/0x450\n   cpuidle_enter+0x29/0x40\n   cpuidle_idle_call+0xf5/0x160\n   do_idle+0x7b/0xe0\n   cpu_startup_entry+0x26/0x30\n   start_secondary+0x115/0x140\n   secondary_startup_64_no_verify+0x194/0x19b\n   </TASK>\n\nFix this by ensuring that BRS is not enabled from the event selector\nreprogramming path even when cpuc->lbr_users > 0.","cvss":[],"epss":[{"cve":"CVE-2026-72325","epss":0.00209,"percentile":0.111,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72325","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72329","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72329","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/liquidio: drop cached VF pci_dev LUT  The PF SR-IOV enable path caches VF pci_dev pointers in dpiring_to_vfpcidev_lut[] by iterating with pci_get_device(). Those entries do not own a reference, because the iterator drops the previous device reference on each step. The cached pointer is then dereferenced later when handling OCTEON_VF_FLR_REQUEST.  Replace the cached VF mapping with runtime lookup on the mailbox DPI ring: derive the VF index from q_no, resolve the VF via exported PCI IOV helpers, validate it with the PF pointer and VF ID, then issue pcie_flr() and drop the reference with pci_dev_put(). Remove the unused VF lookup table initialization and cleanup.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72329","epss":0.0018,"percentile":0.07648,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1647},"relatedVulnerabilities":[{"id":"CVE-2026-72329","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72329","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/5c0e3ba4f500fd4314ceb42f07f16bc445156431","https://git.kernel.org/stable/c/81acef3a247fd523513a2e9f71de1c167bc0f882"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/liquidio: drop cached VF pci_dev LUT\n\nThe PF SR-IOV enable path caches VF pci_dev pointers in\ndpiring_to_vfpcidev_lut[] by iterating with pci_get_device(). Those\nentries do not own a reference, because the iterator drops the previous\ndevice reference on each step. The cached pointer is then dereferenced\nlater when handling OCTEON_VF_FLR_REQUEST.\n\nReplace the cached VF mapping with runtime lookup on the mailbox DPI\nring: derive the VF index from q_no, resolve the VF via exported PCI\nIOV helpers, validate it with the PF pointer and VF ID, then issue\npcie_flr() and drop the reference with pci_dev_put(). Remove the\nunused VF lookup table initialization and cleanup.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72329","epss":0.0018,"percentile":0.07648,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72329","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72334","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72334","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: ISO: fix malformed ISO_END/CONT handling  Core specification (Part C vol 4 sec 5.4.5) does not exclude empty ISO_CONT, ISO_END packets.  We currently reject them if they are last.  If controller sends malformed sequence      ISO_START -> rx_len = 4, ISO_CONT skb->len 4, ISO_START  that ends payload in ISO_CONT, we leak conn->rx_skb. If controller sends too long ISO_END, we panic on skb_put. If controller sends too short ISO_END we accept it.  Fix by marking unfinished ISO_START via conn->rx_skb != NULL.  Check skb->len properly before skb_put.  Combine the ISO_CONT/END code paths as they require the same initial checks. Reject too short ISO_END packets.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72334","epss":0.00341,"percentile":0.27158,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.277915},"relatedVulnerabilities":[{"id":"CVE-2026-72334","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72334","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/990e65eb9387c4ddfa7f68782b6644c2c35d489f","https://git.kernel.org/stable/c/e054c1a6ae7310d2815778fddb87da616e11c255"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: fix malformed ISO_END/CONT handling\n\nCore specification (Part C vol 4 sec 5.4.5) does not exclude empty\nISO_CONT, ISO_END packets.  We currently reject them if they are last.\n\nIf controller sends malformed sequence\n\n    ISO_START -> rx_len = 4, ISO_CONT skb->len 4, ISO_START\n\nthat ends payload in ISO_CONT, we leak conn->rx_skb. If controller sends\ntoo long ISO_END, we panic on skb_put. If controller sends too short\nISO_END we accept it.\n\nFix by marking unfinished ISO_START via conn->rx_skb != NULL.  Check\nskb->len properly before skb_put.  Combine the ISO_CONT/END code paths\nas they require the same initial checks. Reject too short ISO_END\npackets.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72334","epss":0.00341,"percentile":0.27158,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72334","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72336","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72336","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: 6lowpan: hold L2CAP conn across debugfs control  get_l2cap_conn() looks up an LE hci_conn under hdev protection, but then drops that protection before reading hcon->l2cap_data and before lowpan_control_write() later dereferences conn->hcon.  A disconnect or device close can tear down the same L2CAP connection in that window.  The buggy scenario involves two paths, with each column showing the order within that path:  6LoWPAN control write:              HCI disconnect/device close:   1. get_l2cap_conn() finds hcon      1. hci_disconn_cfm() dispatches      and hcon->l2cap_data.               the L2CAP disconnect callback.   2. get_l2cap_conn() drops hdev      2. l2cap_conn_del() clears      protection and returns conn.        hcon->l2cap_data and drops the                                          L2CAP connection reference.   3. lowpan_control_write() reads     3. hci_conn_del() removes and drops      conn->hcon.                         the HCI connection.  Take a reference to the L2CAP connection with l2cap_conn_hold_unless_zero() while hdev is still locked, and drop that reference after the debugfs command's last use of conn.  This mirrors the existing L2CAP ACL receive-side handoff and keeps the connection dereferenceable after leaving hdev protection.  Export the existing helper so the bluetooth_6lowpan module can use the same lifetime primitive.  Validation reproduced this kernel report: BUG: KASAN: slab-use-after-free in lowpan_control_write+0x374/0x520 The buggy address belongs to the object at ffff888111b9d000 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 0 bytes inside of freed 1024-byte region [ffff888111b9d000, ffff888111b9d400) Read of size 8 Call trace:   dump_stack_lvl+0x66/0xa0   print_report+0xce/0x5f0   lowpan_control_write+0x374/0x520 (net/bluetooth/6lowpan.c:1131)   srso_alias_return_thunk+0x5/0xfbef5   __virt_addr_valid+0x19f/0x330   kasan_report+0xe0/0x110   __debugfs_file_get+0xf7/0x400   full_proxy_write+0x9e/0xd0   vfs_write+0x1b0/0x810   ksys_write+0xd2/0x170   dnotify_flush+0x32/0x220   do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)   entry_SYSCALL_64_after_hwframe+0x77/0x7f Allocated by task stack:   kasan_save_stack+0x33/0x60   kasan_save_track+0x17/0x60   __kasan_kmalloc+0xaa/0xb0   l2cap_conn_add+0x45/0x520   l2cap_chan_connect+0xac6/0xd90   l2cap_sock_connect+0x216/0x350   __sys_connect+0x101/0x130   __x64_sys_connect+0x40/0x50   do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)   entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task stack:   kasan_save_stack+0x33/0x60   kasan_save_track+0x17/0x60   kasan_save_free_info+0x3b/0x60   __kasan_slab_free+0x5f/0x80   kfree+0x313/0x590   hci_conn_hash_flush+0xc0/0x140   hci_dev_close_sync+0x41a/0xb00   hci_dev_close+0x12f/0x160   hci_sock_ioctl+0x157/0x570   sock_do_ioctl+0xf7/0x210   sock_ioctl+0x32f/0x490   __x64_sys_ioctl+0xc7/0x110   do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)   entry_SYSCALL_64_after_hwframe+0x77/0x7f   kasan_record_aux_stack+0xa7/0xc0   insert_work+0x32/0x100   __queue_work+0x262/0xa60   queue_work_on+0xad/0xb0   l2cap_connect_cfm+0x4ef/0x670   hci_le_remote_feat_complete_evt+0x247/0x430   hci_event_packet+0x360/0x6f0   hci_rx_work+0x2ae/0x7a0   process_one_work+0x4fd/0xbc0   worker_thread+0x2d8/0x570   kthread+0x1ad/0x1f0   ret_from_fork+0x3c9/0x540   ret_from_fork_asm+0x1a/0x30","cvss":[],"epss":[{"cve":"CVE-2026-72336","epss":0.002,"percentile":0.09936,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-72336","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72336","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/23a83bac3356e7b211bcdcf581a31f7b536a2c24","https://git.kernel.org/stable/c/32c48c7f6cc8c7888e46a8c81622154ccafda5d2","https://git.kernel.org/stable/c/518aa9505fa10ea5662349e5d2efd8c9e32a820b","https://git.kernel.org/stable/c/ba1f1ef6522e63aa5dd29805b4390ea2ccadf05e","https://git.kernel.org/stable/c/d2a8dc1f619c9e0e4126bee795c39ebddd2ec8ff"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: 6lowpan: hold L2CAP conn across debugfs control\n\nget_l2cap_conn() looks up an LE hci_conn under hdev protection, but\nthen drops that protection before reading hcon->l2cap_data and before\nlowpan_control_write() later dereferences conn->hcon.  A disconnect or\ndevice close can tear down the same L2CAP connection in that window.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\n6LoWPAN control write:              HCI disconnect/device close:\n  1. get_l2cap_conn() finds hcon      1. hci_disconn_cfm() dispatches\n     and hcon->l2cap_data.               the L2CAP disconnect callback.\n  2. get_l2cap_conn() drops hdev      2. l2cap_conn_del() clears\n     protection and returns conn.        hcon->l2cap_data and drops the\n                                         L2CAP connection reference.\n  3. lowpan_control_write() reads     3. hci_conn_del() removes and drops\n     conn->hcon.                         the HCI connection.\n\nTake a reference to the L2CAP connection with\nl2cap_conn_hold_unless_zero() while hdev is still locked, and drop that\nreference after the debugfs command's last use of conn.  This mirrors the\nexisting L2CAP ACL receive-side handoff and keeps the connection\ndereferenceable after leaving hdev protection.  Export the existing helper\nso the bluetooth_6lowpan module can use the same lifetime primitive.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in lowpan_control_write+0x374/0x520\nThe buggy address belongs to the object at ffff888111b9d000 which belongs\nto the cache kmalloc-1k of size 1024\nThe buggy address is located 0 bytes inside of freed 1024-byte region\n[ffff888111b9d000, ffff888111b9d400)\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x66/0xa0\n  print_report+0xce/0x5f0\n  lowpan_control_write+0x374/0x520 (net/bluetooth/6lowpan.c:1131)\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x19f/0x330\n  kasan_report+0xe0/0x110\n  __debugfs_file_get+0xf7/0x400\n  full_proxy_write+0x9e/0xd0\n  vfs_write+0x1b0/0x810\n  ksys_write+0xd2/0x170\n  dnotify_flush+0x32/0x220\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\nAllocated by task stack:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x17/0x60\n  __kasan_kmalloc+0xaa/0xb0\n  l2cap_conn_add+0x45/0x520\n  l2cap_chan_connect+0xac6/0xd90\n  l2cap_sock_connect+0x216/0x350\n  __sys_connect+0x101/0x130\n  __x64_sys_connect+0x40/0x50\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\nFreed by task stack:\n  kasan_save_stack+0x33/0x60\n  kasan_save_track+0x17/0x60\n  kasan_save_free_info+0x3b/0x60\n  __kasan_slab_free+0x5f/0x80\n  kfree+0x313/0x590\n  hci_conn_hash_flush+0xc0/0x140\n  hci_dev_close_sync+0x41a/0xb00\n  hci_dev_close+0x12f/0x160\n  hci_sock_ioctl+0x157/0x570\n  sock_do_ioctl+0xf7/0x210\n  sock_ioctl+0x32f/0x490\n  __x64_sys_ioctl+0xc7/0x110\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  kasan_record_aux_stack+0xa7/0xc0\n  insert_work+0x32/0x100\n  __queue_work+0x262/0xa60\n  queue_work_on+0xad/0xb0\n  l2cap_connect_cfm+0x4ef/0x670\n  hci_le_remote_feat_complete_evt+0x247/0x430\n  hci_event_packet+0x360/0x6f0\n  hci_rx_work+0x2ae/0x7a0\n  process_one_work+0x4fd/0xbc0\n  worker_thread+0x2d8/0x570\n  kthread+0x1ad/0x1f0\n  ret_from_fork+0x3c9/0x540\n  ret_from_fork_asm+0x1a/0x30","cvss":[],"epss":[{"cve":"CVE-2026-72336","epss":0.002,"percentile":0.09936,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72336","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72337","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72337","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: 6lowpan: avoid untracked enable work  lowpan_enable_set() allocates a temporary work item and schedules do_enable_set() on system_wq, then returns to debugfs. The debugfs active operation has ended at that point, but the worker still executes module text and manipulates enable_6lowpan and listen_chan.  bt_6lowpan_exit() removes the debugfs files and immediately closes and puts listen_chan. It has no pointer to the queued work item, so it cannot cancel or flush it before tearing down the state that the worker uses.  The buggy scenario involves two paths, with each column showing the order within that path:  debugfs enable write              module exit 1. lowpan_enable_set() allocates  1. bt_6lowpan_exit() removes    set_enable work                   the debugfs file 2. schedule_work() queues         2. bt_6lowpan_exit() closes    do_enable_set()                   and puts listen_chan 3. the write operation returns    3. module teardown can continue 4. do_enable_set() later runs    against stale state  Run the enable state transition synchronously in lowpan_enable_set() instead. The simple debugfs setter can sleep, and this file already handles the 6LoWPAN control write synchronously under the same set_lock. Once the setter returns, debugfs removal covers the whole operation and exit can no longer race with an untracked work item.  Validation reproduced this kernel report: BUG: KASAN: slab-use-after-free in do_enable_set+0x113/0x2e0 Workqueue: events do_enable_set [bluetooth_6lowpan] The buggy address belongs to the object at ffff888109cb8000","cvss":[],"epss":[{"cve":"CVE-2026-72337","epss":0.00198,"percentile":0.09674,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.099},"relatedVulnerabilities":[{"id":"CVE-2026-72337","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72337","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/352a59dc1f4a41314b6f827c17e16af7ca88271a","https://git.kernel.org/stable/c/feb3fc2c38ed52003142f31e04109719b200c049"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: 6lowpan: avoid untracked enable work\n\nlowpan_enable_set() allocates a temporary work item and schedules\ndo_enable_set() on system_wq, then returns to debugfs. The debugfs active\noperation has ended at that point, but the worker still executes module\ntext and manipulates enable_6lowpan and listen_chan.\n\nbt_6lowpan_exit() removes the debugfs files and immediately closes and\nputs listen_chan. It has no pointer to the queued work item, so it cannot\ncancel or flush it before tearing down the state that the worker uses.\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\ndebugfs enable write              module exit\n1. lowpan_enable_set() allocates  1. bt_6lowpan_exit() removes\n   set_enable work                   the debugfs file\n2. schedule_work() queues         2. bt_6lowpan_exit() closes\n   do_enable_set()                   and puts listen_chan\n3. the write operation returns    3. module teardown can continue\n4. do_enable_set() later runs\n   against stale state\n\nRun the enable state transition synchronously in lowpan_enable_set()\ninstead. The simple debugfs setter can sleep, and this file already handles\nthe 6LoWPAN control write synchronously under the same set_lock. Once the\nsetter returns, debugfs removal covers the whole operation and exit can no\nlonger race with an untracked work item.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in do_enable_set+0x113/0x2e0\nWorkqueue: events do_enable_set [bluetooth_6lowpan]\nThe buggy address belongs to the object at ffff888109cb8000","cvss":[],"epss":[{"cve":"CVE-2026-72337","epss":0.00198,"percentile":0.09674,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72337","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72338","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72338","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload  There is a TOCTOU race condition in flower lockless approach between sizing a flow_rule buffer and filling it. zdi-disclosures@trendmicro.com reports: The cls_flower classifier operates with TCF_PROTO_OPS_DOIT_UNLOCKED (fl_change runs without RTNL), while RTM_NEWACTION holds RTNL, so the independent locking domains make the race reachable in practice.  KASAN confirms:   BUG: KASAN: slab-out-of-bounds in tcf_pedit_offload_act_setup+0x81b/0x930   Write of size 4 at addr ffff888001f27520 by task poc-toctou/312   The buggy address is located 0 bytes to the right of    allocated 288-byte region [ffff888001f27400, ffff888001f27520)    (cache kmalloc-512)  Note: The result is a heap OOB write attacker-controlled content into the adjacent slab object (requires CAP_NET_ADMIN).  The fix introduces reading tcfp_nkeys under act->tcfa_lock in all places using a new tcf_pedit_nkeys_locked() which replaces the old tcf_pedit_nkeys(). Additionally we close the remaining TOCTOU window between the sizing read and the fill reads by more careful accounting. Rather than silently truncating the key count, which leads to incorrect action semantics offloaded to hardware and secondary OOB writes if the remaining capacity is zero or consumed by prior actions, we enforce remaining capacity checks and return -ENOSPC if the required space exceeds the remaining capacity.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72338","epss":0.00166,"percentile":0.06178,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12699},"relatedVulnerabilities":[{"id":"CVE-2026-72338","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72338","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0d8532a5e972a5351cf4ee4a435e0d65cbba8f23","https://git.kernel.org/stable/c/27488e1a7f19757e6146edca9458ed4ffc545557","https://git.kernel.org/stable/c/6f9b23eb92a894ae1118893996943990ee0b860e","https://git.kernel.org/stable/c/8b519cbcabe836a441369fbec1a8a6518a709251","https://git.kernel.org/stable/c/8e49cd891bda447c68122d672510a604a8bb6b24"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_pedit: fix TOCTOU heap OOB write in tc offload\n\nThere is a TOCTOU race condition in flower lockless approach between sizing\na flow_rule buffer and filling it.\nzdi-disclosures@trendmicro.com reports:\nThe cls_flower classifier operates with TCF_PROTO_OPS_DOIT_UNLOCKED\n(fl_change runs without RTNL), while RTM_NEWACTION holds RTNL, so the\nindependent locking domains make the race reachable in practice.  KASAN\nconfirms:\n  BUG: KASAN: slab-out-of-bounds in tcf_pedit_offload_act_setup+0x81b/0x930\n  Write of size 4 at addr ffff888001f27520 by task poc-toctou/312\n  The buggy address is located 0 bytes to the right of\n   allocated 288-byte region [ffff888001f27400, ffff888001f27520)\n   (cache kmalloc-512)\n\nNote: The result is a heap OOB write attacker-controlled content into the\nadjacent slab object (requires CAP_NET_ADMIN).\n\nThe fix introduces reading tcfp_nkeys under act->tcfa_lock in all places\nusing a new tcf_pedit_nkeys_locked() which replaces the old tcf_pedit_nkeys().\nAdditionally we close the remaining TOCTOU window between the sizing read and\nthe fill reads by more careful accounting.\nRather than silently truncating the key count, which leads to incorrect\naction semantics offloaded to hardware and secondary OOB writes if\nthe remaining capacity is zero or consumed by prior actions, we enforce\nremaining capacity checks and return -ENOSPC if the required space exceeds\nthe remaining capacity.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72338","epss":0.00166,"percentile":0.06178,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72338","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72341","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72341","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Fix publication race for priv->channel_stats[]  mlx5e_channel_stats_alloc() publishes a new entry to priv->channel_stats[] and then increments priv->stats_nch as a publication token, but neither store carries any memory barrier:  \tpriv->channel_stats[ix] = kvzalloc_node(...); \tif (!priv->channel_stats[ix]) \t\treturn -ENOMEM; \tpriv->stats_nch++;  Concurrent readers compute the loop bound from priv->stats_nch and then dereference priv->channel_stats[i] using plain accesses, e.g.  \tfor (i = 0; i < priv->stats_nch; i++) { \t\tstruct mlx5e_channel_stats *cs = priv->channel_stats[i]; \t\t... cs->rq.packets ... \t}  On weakly-ordered architectures (ARM, PowerPC, RISC-V) the writes to channel_stats[ix] and stats_nch may become visible to other CPUs out of program order. A reader can observe stats_nch == N while still seeing channel_stats[N-1] == NULL, leading to a NULL pointer dereference in the channel_stats loop.  This has been observed in production on BlueField-3 DPUs (arm64), where ovs-vswitchd queries netdev statistics over netlink during NIC bringup, racing mlx5e_open_channel() -> mlx5e_channel_stats_alloc() on another CPU:    Unable to handle kernel NULL pointer dereference at virtual address 0x840   Hardware name: BlueField-3 DPU   pc : mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]   Call trace:    mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]    dev_get_stats+0x50/0xc0    ovs_vport_get_stats+0x38/0xac [openvswitch]    ovs_vport_cmd_fill_info+0x194/0x290 [openvswitch]    ovs_vport_cmd_get+0xbc/0x10c [openvswitch]    genl_family_rcv_msg_doit+0xd0/0x160    genl_rcv_msg+0xec/0x1f0    netlink_rcv_skb+0x64/0x130    genl_rcv+0x40/0x60    netlink_unicast+0x2fc/0x370    netlink_sendmsg+0x1dc/0x454    ...    __arm64_sys_sendmsg+0x2c/0x40  Add mlx5e_stats_nch_write() and mlx5e_stats_nch_read() helpers in en.h that wrap the smp_store_release()/smp_load_acquire() pair on stats_nch. The release/acquire pair establishes the contract:    stats_nch == N  =>  channel_stats[0..N-1] are visible and non-NULL.  Publish the stats_nch increment via mlx5e_stats_nch_write() in the writer (mlx5e_channel_stats_alloc()), and read stats_nch via mlx5e_stats_nch_read() in all readers: mlx5e RX/TX queue stats, mlx5e_get_base_stats(), ethtool channels stats, IPoIB stats, the sw_stats fold and the HV VHCA stats agent.","cvss":[],"epss":[{"cve":"CVE-2026-72341","epss":0.00207,"percentile":0.10829,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1035},"relatedVulnerabilities":[{"id":"CVE-2026-72341","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72341","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/5a799714e8ca0bce9ea40694f49914cf1adbbaa9","https://git.kernel.org/stable/c/5c7e3755abf663f033de24f917b77685e9543045","https://git.kernel.org/stable/c/815515ec68f527ca755cb1e2c1ff9148f6b3ea56"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix publication race for priv->channel_stats[]\n\nmlx5e_channel_stats_alloc() publishes a new entry to\npriv->channel_stats[] and then increments priv->stats_nch as a\npublication token, but neither store carries any memory barrier:\n\n\tpriv->channel_stats[ix] = kvzalloc_node(...);\n\tif (!priv->channel_stats[ix])\n\t\treturn -ENOMEM;\n\tpriv->stats_nch++;\n\nConcurrent readers compute the loop bound from priv->stats_nch and\nthen dereference priv->channel_stats[i] using plain accesses, e.g.\n\n\tfor (i = 0; i < priv->stats_nch; i++) {\n\t\tstruct mlx5e_channel_stats *cs = priv->channel_stats[i];\n\t\t... cs->rq.packets ...\n\t}\n\nOn weakly-ordered architectures (ARM, PowerPC, RISC-V) the writes to\nchannel_stats[ix] and stats_nch may become visible to other CPUs out\nof program order. A reader can observe stats_nch == N while still\nseeing channel_stats[N-1] == NULL, leading to a NULL pointer\ndereference in the channel_stats loop.\n\nThis has been observed in production on BlueField-3 DPUs (arm64),\nwhere ovs-vswitchd queries netdev statistics over netlink during NIC\nbringup, racing mlx5e_open_channel() -> mlx5e_channel_stats_alloc()\non another CPU:\n\n  Unable to handle kernel NULL pointer dereference at virtual address 0x840\n  Hardware name: BlueField-3 DPU\n  pc : mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]\n  Call trace:\n   mlx5e_fold_sw_stats64+0x30/0x180 [mlx5_core]\n   dev_get_stats+0x50/0xc0\n   ovs_vport_get_stats+0x38/0xac [openvswitch]\n   ovs_vport_cmd_fill_info+0x194/0x290 [openvswitch]\n   ovs_vport_cmd_get+0xbc/0x10c [openvswitch]\n   genl_family_rcv_msg_doit+0xd0/0x160\n   genl_rcv_msg+0xec/0x1f0\n   netlink_rcv_skb+0x64/0x130\n   genl_rcv+0x40/0x60\n   netlink_unicast+0x2fc/0x370\n   netlink_sendmsg+0x1dc/0x454\n   ...\n   __arm64_sys_sendmsg+0x2c/0x40\n\nAdd mlx5e_stats_nch_write() and mlx5e_stats_nch_read() helpers in en.h\nthat wrap the smp_store_release()/smp_load_acquire() pair on stats_nch.\nThe release/acquire pair establishes the contract:\n\n  stats_nch == N  =>  channel_stats[0..N-1] are visible and non-NULL.\n\nPublish the stats_nch increment via mlx5e_stats_nch_write() in the\nwriter (mlx5e_channel_stats_alloc()), and read stats_nch via\nmlx5e_stats_nch_read() in all readers: mlx5e RX/TX queue stats,\nmlx5e_get_base_stats(), ethtool channels stats, IPoIB stats, the\nsw_stats fold and the HV VHCA stats agent.","cvss":[],"epss":[{"cve":"CVE-2026-72341","epss":0.00207,"percentile":0.10829,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72341","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72369","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72369","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  minix: avoid overflow in bitmap block count calculation  minix_check_superblock() uses minix_blocks_needed() to verify that the on-disk imap and zmap block counts are large enough for the advertised inode and zone counts.  The helper currently performs DIV_ROUND_UP() in unsigned int arithmetic. A Minix v3 image can set s_ninodes or s_zones near UINT_MAX so the addition inside DIV_ROUND_UP() wraps to zero. That makes a zero imap/zmap block count look valid, after which minix_fill_super() can dereference s_imap[0] or s_zmap[0] even though no bitmap buffers were allocated.  Impact: mounting a crafted Minix v3 image whose s_ninodes or s_zones is near UINT_MAX makes minix_check_superblock() accept a zero bitmap-block count and minix_fill_super() dereference s_imap[0]/s_zmap[0], panicking the kernel.  The divisor is the bitmap capacity in bits, blocksize * 8, which is always a power of two: minix_fill_super() obtains the block size through sb_set_blocksize(), and blk_validate_block_size() rejects any size that is not a power of two. Use DIV_ROUND_UP_POW2(), which divides before adding the round-up term and so cannot overflow for a power-of-two divisor.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72369","epss":0.00175,"percentile":0.07174,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13387500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72369","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72369","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/8a29e60e2176b02e04f8737c8b32b696230eb0c5","https://git.kernel.org/stable/c/959c95340a9e19cd333b4c18935fdeecbb2f319d","https://git.kernel.org/stable/c/a11ebaab50d27d6c4c78506f84ff36452e0b901d","https://git.kernel.org/stable/c/abe3536a4bedcc43de80b6d4d7e3d57e9ba382a5","https://git.kernel.org/stable/c/fb3e566cafc38fe3ba35e6843a2d529a3748870c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nminix: avoid overflow in bitmap block count calculation\n\nminix_check_superblock() uses minix_blocks_needed() to verify that the\non-disk imap and zmap block counts are large enough for the advertised\ninode and zone counts.\n\nThe helper currently performs DIV_ROUND_UP() in unsigned int arithmetic.\nA Minix v3 image can set s_ninodes or s_zones near UINT_MAX so the\naddition inside DIV_ROUND_UP() wraps to zero. That makes a zero imap/zmap\nblock count look valid, after which minix_fill_super() can dereference\ns_imap[0] or s_zmap[0] even though no bitmap buffers were allocated.\n\nImpact: mounting a crafted Minix v3 image whose s_ninodes or s_zones is\nnear UINT_MAX makes minix_check_superblock() accept a zero bitmap-block\ncount and minix_fill_super() dereference s_imap[0]/s_zmap[0], panicking\nthe kernel.\n\nThe divisor is the bitmap capacity in bits, blocksize * 8, which is\nalways a power of two: minix_fill_super() obtains the block size through\nsb_set_blocksize(), and blk_validate_block_size() rejects any size that\nis not a power of two. Use DIV_ROUND_UP_POW2(), which divides before\nadding the round-up term and so cannot overflow for a power-of-two\ndivisor.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72369","epss":0.00175,"percentile":0.07174,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72369","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72373","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72373","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  afs: Fix missing NULL pointer check in afs_break_some_callbacks()  Fix afs_break_some_callbacks() to check to see if afs_lookup_volume_rcu() returned NULL (e.g. the specified volume is unknown).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72373","epss":0.00622,"percentile":0.47767,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.46649999999999997},"relatedVulnerabilities":[{"id":"CVE-2026-72373","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72373","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5492799ec5d27be3bd454dcaf046bc7054f637ae","https://git.kernel.org/stable/c/794a01110390c1b76f59ece773fb0fbfd89c6f5c","https://git.kernel.org/stable/c/a99a617701186dc68c7b330d35fc2253f48e2ab2","https://git.kernel.org/stable/c/e3e59ff22a0de01ed0cf3a3e25558811abc3b70a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix missing NULL pointer check in afs_break_some_callbacks()\n\nFix afs_break_some_callbacks() to check to see if afs_lookup_volume_rcu()\nreturned NULL (e.g. the specified volume is unknown).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72373","epss":0.00622,"percentile":0.47767,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72373","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72375","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72375","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  afs: Fix reinitialisation of the inode, in particular ->lock_work  It seems that initalising afs_vnode::lock_work a single time in the slab's init function isn't sufficient for work_structs.  This results in the DEBUG_OBJECTS debugging stuff producing a warning occasionally when running the generic/131 xfstest:   ODEBUG: activate not available (active state 0) object: 0000000016d8760f object type: work_struct hint: afs_lock_work+0x0/0x220  WARNING: lib/debugobjects.c:629 at debug_print_object+0x4b/0x90, CPU#3: locktest/7695  ...  CPU: 3 UID: 0 PID: 7695 Comm: locktest Tainted: G S                  7.1.0-build3+ #2771 PREEMPT  ...  RIP: 0010:debug_print_object+0x65/0x90  ...  Call Trace:   <TASK>   ? __pfx_afs_lock_work+0x10/0x10   debug_object_activate+0x122/0x170   insert_work+0x25/0x60   __queue_work+0x2e0/0x340   queue_delayed_work_on+0x48/0x70   afs_fl_release_private+0x57/0x70   locks_release_private+0x5c/0xa0   locks_free_lock+0xe/0x20   posix_lock_inode+0x55f/0x5b0   locks_lock_inode_wait+0x81/0x140   ? file_write_and_wait_range+0x50/0x70   afs_lock+0xcd/0x110   fcntl_setlk+0x10d/0x260   do_fcntl+0x24e/0x5b0   __do_sys_fcntl+0x6a/0x90   do_syscall_64+0x11e/0x310   entry_SYSCALL_64_after_hwframe+0x71/0x79  Fix this by reinitialising ->lock_work after allocating an inode.  Also, flush ->lock_work when the inode is being evicted to make sure it's not still running.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72375","epss":0.00173,"percentile":0.0692,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13234500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72375","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72375","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5597fbd1e7c161914f20315a726e54025b0fdadb","https://git.kernel.org/stable/c/63d3f283858fae097fb09ddd4ce46bb0bc1f9d01","https://git.kernel.org/stable/c/ebfd13c0367adb43d7c0a72f5cd7e004e60c6b28"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix reinitialisation of the inode, in particular ->lock_work\n\nIt seems that initalising afs_vnode::lock_work a single time in the slab's\ninit function isn't sufficient for work_structs.  This results in the\nDEBUG_OBJECTS debugging stuff producing a warning occasionally when running\nthe generic/131 xfstest:\n\n ODEBUG: activate not available (active state 0) object: 0000000016d8760f object type: work_struct hint: afs_lock_work+0x0/0x220\n WARNING: lib/debugobjects.c:629 at debug_print_object+0x4b/0x90, CPU#3: locktest/7695\n ...\n CPU: 3 UID: 0 PID: 7695 Comm: locktest Tainted: G S                  7.1.0-build3+ #2771 PREEMPT\n ...\n RIP: 0010:debug_print_object+0x65/0x90\n ...\n Call Trace:\n  <TASK>\n  ? __pfx_afs_lock_work+0x10/0x10\n  debug_object_activate+0x122/0x170\n  insert_work+0x25/0x60\n  __queue_work+0x2e0/0x340\n  queue_delayed_work_on+0x48/0x70\n  afs_fl_release_private+0x57/0x70\n  locks_release_private+0x5c/0xa0\n  locks_free_lock+0xe/0x20\n  posix_lock_inode+0x55f/0x5b0\n  locks_lock_inode_wait+0x81/0x140\n  ? file_write_and_wait_range+0x50/0x70\n  afs_lock+0xcd/0x110\n  fcntl_setlk+0x10d/0x260\n  do_fcntl+0x24e/0x5b0\n  __do_sys_fcntl+0x6a/0x90\n  do_syscall_64+0x11e/0x310\n  entry_SYSCALL_64_after_hwframe+0x71/0x79\n\nFix this by reinitialising ->lock_work after allocating an inode.\n\nAlso, flush ->lock_work when the inode is being evicted to make sure it's\nnot still running.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72375","epss":0.00173,"percentile":0.0692,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72375","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72376","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72376","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  afs: Fix misplaced inc of net->cells_outstanding  Fix net->cells_outstanding being incremented before the check for failure of idr_alloc_cyclic(), leaving the count incremented on error.","cvss":[],"epss":[{"cve":"CVE-2026-72376","epss":0.00209,"percentile":0.11101,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1045},"relatedVulnerabilities":[{"id":"CVE-2026-72376","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72376","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/5ea289ca751c47125f6a4138c93ba10c05cd28f0","https://git.kernel.org/stable/c/654a546c34f3921dd03f9ea74e60139ebffd9e20","https://git.kernel.org/stable/c/6e310f818abcef947a06584158b9e6c6cd0c98d3","https://git.kernel.org/stable/c/c9c3b615a462a4023bd148f02c564e175ed10502"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix misplaced inc of net->cells_outstanding\n\nFix net->cells_outstanding being incremented before the check for failure\nof idr_alloc_cyclic(), leaving the count incremented on error.","cvss":[],"epss":[{"cve":"CVE-2026-72376","epss":0.00209,"percentile":0.11101,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72376","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72379","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72379","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid  vfs_tmpfile() never checked that the caller's fsuid and fsgid map into the filesystem.  On an idmapped mount whose idmapping does not cover the caller's fs{u,g}id, the ->tmpfile() instance initializes the new inode through inode_init_owner(), where mapped_fsuid()/mapped_fsgid() return INVALID_UID/INVALID_GID, and the tmpfile ends up owned by (uid_t)-1.  Every other creation path already refuses this: may_o_create() (O_CREAT) and may_create_dentry() (mkdir, mknod, symlink, link) bail out with -EOVERFLOW via fsuidgid_has_mapping() precisely so that an object cannot be created with an owner the filesystem cannot represent.  An O_TMPFILE is no exception: it is created I_LINKABLE and linkat(2) can splice it into the namespace afterwards, so the same guarantee must hold.  Add the missing fsuidgid_has_mapping() check to vfs_tmpfile().  On a non-idmapped mount the caller's fs{u,g}id always map in the superblock's user namespace, so this is a no-op there and only takes effect on an idmapped mount that does not map the caller.  It applies to every filesystem that sets FS_ALLOW_IDMAP and implements ->tmpfile() (tmpfs, ext4, btrfs, xfs, f2fs, ...), and to overlayfs, whose upper-layer tmpfile creation funnels through vfs_tmpfile() via backing_tmpfile_open().","cvss":[],"epss":[{"cve":"CVE-2026-72379","epss":0.00209,"percentile":0.11101,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1045},"relatedVulnerabilities":[{"id":"CVE-2026-72379","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72379","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/47e434da476b5a8bcd1e6e52ab03c5ee7764ee78","https://git.kernel.org/stable/c/503d0568a525b168d9aa5ca046ec72fc5477df84","https://git.kernel.org/stable/c/539dce1144651f7976fa418e618b0b574bf15eeb","https://git.kernel.org/stable/c/a2038514e69371eb493083a6a897ed20fcbb8acb","https://git.kernel.org/stable/c/bac8fb0d60254846f3b56957435dcd870ae12948"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid\n\nvfs_tmpfile() never checked that the caller's fsuid and fsgid map into\nthe filesystem.  On an idmapped mount whose idmapping does not cover the\ncaller's fs{u,g}id, the ->tmpfile() instance initializes the new inode\nthrough inode_init_owner(), where mapped_fsuid()/mapped_fsgid() return\nINVALID_UID/INVALID_GID, and the tmpfile ends up owned by (uid_t)-1.\n\nEvery other creation path already refuses this: may_o_create() (O_CREAT)\nand may_create_dentry() (mkdir, mknod, symlink, link) bail out with\n-EOVERFLOW via fsuidgid_has_mapping() precisely so that an object cannot\nbe created with an owner the filesystem cannot represent.  An O_TMPFILE\nis no exception: it is created I_LINKABLE and linkat(2) can splice it\ninto the namespace afterwards, so the same guarantee must hold.\n\nAdd the missing fsuidgid_has_mapping() check to vfs_tmpfile().  On a\nnon-idmapped mount the caller's fs{u,g}id always map in the superblock's\nuser namespace, so this is a no-op there and only takes effect on an\nidmapped mount that does not map the caller.  It applies to every\nfilesystem that sets FS_ALLOW_IDMAP and implements ->tmpfile() (tmpfs,\next4, btrfs, xfs, f2fs, ...), and to overlayfs, whose upper-layer\ntmpfile creation funnels through vfs_tmpfile() via backing_tmpfile_open().","cvss":[],"epss":[{"cve":"CVE-2026-72379","epss":0.00209,"percentile":0.11101,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72379","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72380","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72380","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xen/pvcalls: bound backend response req_id before indexing rsp[]  pvcalls_front_event_handler() takes req_id directly from the backend-supplied ring response and uses it to index the fixed-size bedata->rsp[] array for a memcpy() and a store, with no range check. A malicious or buggy backend can set req_id past PVCALLS_NR_RSP_PER_RING and drive an out-of-bounds write past the bedata allocation.  req_id was also declared int while the wire field rsp->req_id is u32, so a range check on the signed value alone is insufficient: a backend req_id of 0xffffffff becomes -1, passes a >= PVCALLS_NR_RSP_PER_RING test and indexes bedata->rsp[-1]. Declare req_id as u32 so a single bound covers both ends.  A backend that sends an out-of-range req_id has violated the wire protocol, so rather than silently dropping the response, log once and stop trusting the backend: set bedata->disabled. The event handler then ignores further responses, and the request paths that wait for a response return -EIO instead of blocking forever. This mirrors the fatal-error handling xen-netback uses (xenvif_fatal_tx_err()).  The pvcalls frontend currently trusts its backend, so this is not a classic-Xen security issue, but it matters for hardening PV frontends against malicious backends (confidential and disaggregated deployments).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72380","epss":0.00289,"percentile":0.21262,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.23553500000000005},"relatedVulnerabilities":[{"id":"CVE-2026-72380","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72380","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/d1297a9e2fd6ce08678b370d41bc980ca798f809","https://git.kernel.org/stable/c/d33846c8dcc06b83b7acdeac1e8bfbb5c0c26cb2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxen/pvcalls: bound backend response req_id before indexing rsp[]\n\npvcalls_front_event_handler() takes req_id directly from the\nbackend-supplied ring response and uses it to index the fixed-size\nbedata->rsp[] array for a memcpy() and a store, with no range check. A\nmalicious or buggy backend can set req_id past PVCALLS_NR_RSP_PER_RING\nand drive an out-of-bounds write past the bedata allocation.\n\nreq_id was also declared int while the wire field rsp->req_id is u32, so\na range check on the signed value alone is insufficient: a backend\nreq_id of 0xffffffff becomes -1, passes a >= PVCALLS_NR_RSP_PER_RING\ntest and indexes bedata->rsp[-1]. Declare req_id as u32 so a single\nbound covers both ends.\n\nA backend that sends an out-of-range req_id has violated the wire\nprotocol, so rather than silently dropping the response, log once and\nstop trusting the backend: set bedata->disabled. The event handler then\nignores further responses, and the request paths that wait for a\nresponse return -EIO instead of blocking forever. This mirrors the\nfatal-error handling xen-netback uses (xenvif_fatal_tx_err()).\n\nThe pvcalls frontend currently trusts its backend, so this is not a\nclassic-Xen security issue, but it matters for hardening PV frontends\nagainst malicious backends (confidential and disaggregated deployments).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72380","epss":0.00289,"percentile":0.21262,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72380","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72382","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72382","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: reject undersized DACLs before parsing ACEs  parse_dacl() limits the attacker-controlled ACE count by comparing it with the number of minimal ACEs that fit in the DACL size. The DACL size field is 16 bits, but the expression subtracts sizeof(struct smb_acl). Because sizeof() is unsigned, a DACL size smaller than the ACL header underflows to a large size_t.  A malicious client can reach this with:  SMB2_SET_INFO (InfoType=SMB2_O_INFO_SECURITY)   -> smb2_set_info_sec()   -> set_info_sec()   -> parse_sec_desc()   -> parse_dacl()      -> init_acl_state(..., 0xffff)      -> init_acl_state(..., 0xffff)      -> kmalloc_objs(..., 0xffff)  Thus a malformed security descriptor can make num_aces pass the guard and drive large temporary ACL state and pointer-array allocations.  Reject DACLs smaller than struct smb_acl before doing the subtraction, so the ACE count check cannot be bypassed by the underflow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72382","epss":0.00589,"percentile":0.46192,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.4800350000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72382","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72382","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/15a9e9b8f7f5d7f380ae54c6f5bcbc0bdcb0f3cd","https://git.kernel.org/stable/c/16fb65ec15fe7c90f50a2115854bfd9a032d4023","https://git.kernel.org/stable/c/282847c0cf22f2e961155ac8e42f6eeab7e16049","https://git.kernel.org/stable/c/60908f7ebcd9b6cde74ad5711fab0f49c7970949","https://git.kernel.org/stable/c/d020e7f27bf65eecd3805404702f716b2b6d9e73"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: reject undersized DACLs before parsing ACEs\n\nparse_dacl() limits the attacker-controlled ACE count by comparing it\nwith the number of minimal ACEs that fit in the DACL size. The DACL size\nfield is 16 bits, but the expression subtracts sizeof(struct smb_acl).\nBecause sizeof() is unsigned, a DACL size smaller than the ACL header\nunderflows to a large size_t.\n\nA malicious client can reach this with:\n\nSMB2_SET_INFO (InfoType=SMB2_O_INFO_SECURITY)\n  -> smb2_set_info_sec()\n  -> set_info_sec()\n  -> parse_sec_desc()\n  -> parse_dacl()\n     -> init_acl_state(..., 0xffff)\n     -> init_acl_state(..., 0xffff)\n     -> kmalloc_objs(..., 0xffff)\n\nThus a malformed security descriptor can make num_aces pass the guard\nand drive large temporary ACL state and pointer-array allocations.\n\nReject DACLs smaller than struct smb_acl before doing the subtraction,\nso the ACE count check cannot be bypassed by the underflow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72382","epss":0.00589,"percentile":0.46192,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72382","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72383","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72383","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: fix addr_wq_timer race in sctp_free_addr_wq()  sctp_free_addr_wq() previously removed addr_wq_timer using timer_delete() while holding addr_wq_lock. However, timer_delete() does not guarantee that a currently running timer handler has completed.  This allows a race with sctp_addr_wq_timeout_handler(), where the handler may still run after addr_waitq has been freed, acquire addr_wq_lock, and access freed memory, leading to a use-after-free.  Fix this by calling timer_shutdown_sync() before taking addr_wq_lock.  This guarantees that any in-flight timer handler has finished and prevents the timer from being re-armed during teardown, making subsequent cleanup safe.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72383","epss":0.00157,"percentile":0.05195,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12010499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-72383","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72383","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/976c19de0f22a857ba0112f39635f8fd7a257568","https://git.kernel.org/stable/c/a8323fb2ab6cd6978f359daeed6688e0cadf32ba","https://git.kernel.org/stable/c/c3e5cac47519d77ad36b9c03a1df1536aaa0c4a1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix addr_wq_timer race in sctp_free_addr_wq()\n\nsctp_free_addr_wq() previously removed addr_wq_timer using timer_delete()\nwhile holding addr_wq_lock. However, timer_delete() does not guarantee that\na currently running timer handler has completed.\n\nThis allows a race with sctp_addr_wq_timeout_handler(), where the handler\nmay still run after addr_waitq has been freed, acquire addr_wq_lock, and\naccess freed memory, leading to a use-after-free.\n\nFix this by calling timer_shutdown_sync() before taking addr_wq_lock.  This\nguarantees that any in-flight timer handler has finished and prevents the\ntimer from being re-armed during teardown, making subsequent cleanup safe.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72383","epss":0.00157,"percentile":0.05195,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72383","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72392","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72392","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump  inet6_dump_fib() saves its progress in cb->args[1] as a positional index within the current hash chain.  Between batches, a concurrent fib6_new_table() can insert a new table at the chain head, shifting all existing entries.  The saved index then lands on a different table, causing fib6_dump_table() to set w->root to the wrong table while w->node still points into the previous one. fib6_walk_continue() dereferences w->node->parent (NULL) and panics:    BUG: kernel NULL pointer dereference, address: 0000000000000008   RIP: 0010:fib6_walk_continue+0x6e/0x170   Call Trace:    <TASK>    fib6_dump_table.isra.0+0xc5/0x240    inet6_dump_fib+0xf6/0x420    rtnl_dumpit+0x30/0xa0    netlink_dump+0x15b/0x460    netlink_recvmsg+0x1d6/0x2a0    ____sys_recvmsg+0x17a/0x190  Fix by storing tb->tb6_id in cb->args[1] instead of a positional index.  On resume, skip entries until the id matches; a concurrent head-insert can never match the saved id, so the walker always resumes on the correct table.","cvss":[],"epss":[{"cve":"CVE-2026-72392","epss":0.00216,"percentile":0.12027,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.108},"relatedVulnerabilities":[{"id":"CVE-2026-72392","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72392","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/059efb48dd746518898faaa9b965511009b59639","https://git.kernel.org/stable/c/110ccbd28c9444866fcc84ba96a2ad64fa6e95ae","https://git.kernel.org/stable/c/27210d433a8c5fe6bf7278a04bbaeb49a81d0290","https://git.kernel.org/stable/c/89f9c5fee3c64c5cabc34e65599308fd3c879cf9","https://git.kernel.org/stable/c/9facb861dc6b9b9ea9793ef5032a9a826f7a4229","https://git.kernel.org/stable/c/cb90a774a9c6c46961a44949a246fbb61f5f934c","https://git.kernel.org/stable/c/d8a01d27873e04bebd357dc87859aa756e0b28b2","https://git.kernel.org/stable/c/ee73a32dd258d4af66831ff006b771e19812b322"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump\n\ninet6_dump_fib() saves its progress in cb->args[1] as a positional\nindex within the current hash chain.  Between batches, a concurrent\nfib6_new_table() can insert a new table at the chain head, shifting\nall existing entries.  The saved index then lands on a different\ntable, causing fib6_dump_table() to set w->root to the wrong table\nwhile w->node still points into the previous one.\nfib6_walk_continue() dereferences w->node->parent (NULL) and panics:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000008\n  RIP: 0010:fib6_walk_continue+0x6e/0x170\n  Call Trace:\n   <TASK>\n   fib6_dump_table.isra.0+0xc5/0x240\n   inet6_dump_fib+0xf6/0x420\n   rtnl_dumpit+0x30/0xa0\n   netlink_dump+0x15b/0x460\n   netlink_recvmsg+0x1d6/0x2a0\n   ____sys_recvmsg+0x17a/0x190\n\nFix by storing tb->tb6_id in cb->args[1] instead of a positional\nindex.  On resume, skip entries until the id matches; a concurrent\nhead-insert can never match the saved id, so the walker always\nresumes on the correct table.","cvss":[],"epss":[{"cve":"CVE-2026-72392","epss":0.00216,"percentile":0.12027,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72392","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72397","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72397","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()  pmbus_data2reg_vid() hardcoded the VR11 encoding regardless of the vrm_version configured by the driver, while pmbus_reg2data_vid() already switched on it. Any driver that selects a non-VR11 VID mode and exposes a regulator (or hwmon vout setter) sent dangerously wrong codes to PMBUS_VOUT_COMMAND -- e.g. an nvidia195mv part asked for 200 mV got the VR11 clamp to 500 mV encoded as 0xB2, which the chip interprets as 1080 mV.  Mirror pmbus_reg2data_vid() so writes round-trip with reads.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72397","epss":0.00151,"percentile":0.0462,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11023000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72397","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72397","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5bd0d47640395f8a8c34446b62d1781b88869dfa","https://git.kernel.org/stable/c/828cd614e2af053ca5e1d6da767bbd8a1b5cabfb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()\n\npmbus_data2reg_vid() hardcoded the VR11 encoding regardless of the\nvrm_version configured by the driver, while pmbus_reg2data_vid()\nalready switched on it. Any driver that selects a non-VR11 VID mode\nand exposes a regulator (or hwmon vout setter) sent dangerously\nwrong codes to PMBUS_VOUT_COMMAND -- e.g. an nvidia195mv part asked\nfor 200 mV got the VR11 clamp to 500 mV encoded as 0xB2, which the\nchip interprets as 1080 mV.\n\nMirror pmbus_reg2data_vid() so writes round-trip with reads.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72397","epss":0.00151,"percentile":0.0462,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72397","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72398","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72398","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: add INIT verification after cookie unpacking  In SCTP handshake, the INIT chunk is initially processed by the server and embedded into the cookie carried in INIT-ACK. The client then returns this cookie via COOKIE-ECHO, where the server unpacks it and reconstructs the original INIT chunk.  When cookie authentication is enabled, the cookie contents are protected against tampering, so reusing the unpacked INIT without re-verification is safe.  However, when cookie authentication is disabled, the reconstructed INIT can no longer be trusted. In this case, the INIT must be explicitly validated after unpacking to avoid processing potentially tampered data.  Add sctp_verify_init() checks after cookie unpacking in COOKIE-ECHO processing paths (sctp_sf_do_5_1D_ce() and sctp_sf_do_5_2_4_dupcook()) when cookie_auth_enable is disabled. On failure, the new association is freed and the packet is discarded.  Also tighten cookie validation in sctp_unpack_cookie() by verifying the embedded chunk type is SCTP_CID_INIT before treating it as an INIT chunk.  Finally, update sctp_verify_init() to validate parameter bounds using the actual embedded INIT length instead of chunk->chunk_end, since the INIT stored in COOKIE-ECHO may not span the entire chunk buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72398","epss":0.00704,"percentile":0.5119,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.66176},"relatedVulnerabilities":[{"id":"CVE-2026-72398","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72398","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/062bcbf8d1f1051fdeb20b94920031b0e2cb95a2","https://git.kernel.org/stable/c/414c5447fe6a200613dd46d7fdc8454622076cb1","https://git.kernel.org/stable/c/bca3100f550281c2f2418652338bced3b35af0e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: add INIT verification after cookie unpacking\n\nIn SCTP handshake, the INIT chunk is initially processed by the server\nand embedded into the cookie carried in INIT-ACK. The client then\nreturns this cookie via COOKIE-ECHO, where the server unpacks it and\nreconstructs the original INIT chunk.\n\nWhen cookie authentication is enabled, the cookie contents are protected\nagainst tampering, so reusing the unpacked INIT without re-verification\nis safe.\n\nHowever, when cookie authentication is disabled, the reconstructed INIT\ncan no longer be trusted. In this case, the INIT must be explicitly\nvalidated after unpacking to avoid processing potentially tampered data.\n\nAdd sctp_verify_init() checks after cookie unpacking in COOKIE-ECHO\nprocessing paths (sctp_sf_do_5_1D_ce() and sctp_sf_do_5_2_4_dupcook())\nwhen cookie_auth_enable is disabled. On failure, the new association is\nfreed and the packet is discarded.\n\nAlso tighten cookie validation in sctp_unpack_cookie() by verifying the\nembedded chunk type is SCTP_CID_INIT before treating it as an INIT\nchunk.\n\nFinally, update sctp_verify_init() to validate parameter bounds using\nthe actual embedded INIT length instead of chunk->chunk_end, since the\nINIT stored in COOKIE-ECHO may not span the entire chunk buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72398","epss":0.00704,"percentile":0.5119,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72398","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72402","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72402","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Mask pseudo pointer values in verifier logs  print_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo sources when pointer leaks are not allowed, but the mask only covers BPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE.  BPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE, and BPF_PSEUDO_BTF_ID can also be resolved to kernel pointer values before the verifier log prints the instruction. Include them in the existing pointer classification so the log prints 0x0 instead of the rewritten address.","cvss":[],"epss":[{"cve":"CVE-2026-72402","epss":0.00189,"percentile":0.0868,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2026-72402","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72402","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1c53d16b174dd9e02243fc0e85089e2aa6a0d21a","https://git.kernel.org/stable/c/72a85e9464a5332fb2cd7efd26d9295275ceda2d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mask pseudo pointer values in verifier logs\n\nprint_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo\nsources when pointer leaks are not allowed, but the mask only covers\nBPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE.\n\nBPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE, and BPF_PSEUDO_BTF_ID can\nalso be resolved to kernel pointer values before the verifier log prints\nthe instruction. Include them in the existing pointer classification so\nthe log prints 0x0 instead of the rewritten address.","cvss":[],"epss":[{"cve":"CVE-2026-72402","epss":0.00189,"percentile":0.0868,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72402","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72404","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72404","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()  TIPC UDP media bearer teardown calls dst_cache_destroy() on its replicast caches before calling synchronize_net() to wait for concurrent RCU readers (transmitters) to finish:  static void cleanup_bearer(struct work_struct *work) { ... \tlist_for_each_entry_safe(rcast, tmp, &ub->rcast.list, list) { \t\tdst_cache_destroy(&rcast->dst_cache); \t\tlist_del_rcu(&rcast->list); \t\tkfree_rcu(rcast, rcu); \t} ... \tdst_cache_destroy(&ub->rcast.dst_cache); \tudp_tunnel_sock_release(ub->sk); \tsynchronize_net(); ... }  This is highly buggy because dst_cache_destroy() immediately frees the per-CPU cache memory (free_percpu()) and releases the cached dst entries without any synchronization.  If a concurrent transmitter (e.g., tipc_udp_xmit()) is running on another CPU under RCU protection, it can call dst_cache_get() concurrently, leading to: 1. Use-After-Free on the per-CPU cache pointer itself (crash). 2. \"rcuref - imbalanced put()\" warning if it attempts to release a    dst that was concurrently released by dst_cache_destroy().  Furthermore, calling kfree(ub) immediately after synchronize_net() without closing the socket first (or waiting after closing it) leaves a window where a concurrent receiver (tipc_udp_recv()) could start after synchronize_net(), access ub, and suffer a UAF when kfree(ub) runs.  To fix this, we must defer dst_cache_destroy() and kfree(ub) until after we have ensured that no more readers can see the bearer/socket and all existing readers have finished:  1. Defer rcast entry destruction (both dst_cache_destroy() and kfree())    to an RCU callback using call_rcu_hurry().    Using call_rcu_hurry() ensures the dst entries are released quickly.  2. Release the bearer socket using udp_tunnel_sock_release() (stops    new receive readers).  3. Call synchronize_net() to wait for all outstanding RCU readers    (both transmit and receive) to finish.  4. Now that it is safe, call dst_cache_destroy() on the main bearer    cache, and free ub.  Note: 3) and 4) can be changed later in net-next to also use call_rcu_hurry() and get rid of the synchronize_net() latency.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72404","epss":0.00154,"percentile":0.04854,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11780999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-72404","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72404","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1c8393eefa3cadf4ca0b61119ad1321aa32d3c8c","https://git.kernel.org/stable/c/7116764ca53ff529335d7ab7c364a69f094b23a5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()\n\nTIPC UDP media bearer teardown calls dst_cache_destroy() on its\nreplicast caches before calling synchronize_net() to wait for\nconcurrent RCU readers (transmitters) to finish:\n\nstatic void cleanup_bearer(struct work_struct *work)\n{\n...\n\tlist_for_each_entry_safe(rcast, tmp, &ub->rcast.list, list) {\n\t\tdst_cache_destroy(&rcast->dst_cache);\n\t\tlist_del_rcu(&rcast->list);\n\t\tkfree_rcu(rcast, rcu);\n\t}\n...\n\tdst_cache_destroy(&ub->rcast.dst_cache);\n\tudp_tunnel_sock_release(ub->sk);\n\tsynchronize_net();\n...\n}\n\nThis is highly buggy because dst_cache_destroy() immediately frees the\nper-CPU cache memory (free_percpu()) and releases the cached dst\nentries without any synchronization.\n\nIf a concurrent transmitter (e.g., tipc_udp_xmit()) is running on another\nCPU under RCU protection, it can call dst_cache_get() concurrently,\nleading to:\n1. Use-After-Free on the per-CPU cache pointer itself (crash).\n2. \"rcuref - imbalanced put()\" warning if it attempts to release a\n   dst that was concurrently released by dst_cache_destroy().\n\nFurthermore, calling kfree(ub) immediately after synchronize_net() without\nclosing the socket first (or waiting after closing it) leaves a window\nwhere a concurrent receiver (tipc_udp_recv()) could start after\nsynchronize_net(), access ub, and suffer a UAF when kfree(ub) runs.\n\nTo fix this, we must defer dst_cache_destroy() and kfree(ub) until after\nwe have ensured that no more readers can see the bearer/socket and all\nexisting readers have finished:\n\n1. Defer rcast entry destruction (both dst_cache_destroy() and kfree())\n   to an RCU callback using call_rcu_hurry().\n   Using call_rcu_hurry() ensures the dst entries are released quickly.\n\n2. Release the bearer socket using udp_tunnel_sock_release() (stops\n   new receive readers).\n\n3. Call synchronize_net() to wait for all outstanding RCU readers\n   (both transmit and receive) to finish.\n\n4. Now that it is safe, call dst_cache_destroy() on the main bearer\n   cache, and free ub.\n\nNote: 3) and 4) can be changed later in net-next to also use\ncall_rcu_hurry() and get rid of the synchronize_net() latency.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72404","epss":0.00154,"percentile":0.04854,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72404","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72405","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72405","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync  Yue Sun reported a use-after-free and debugobjects warning in udp_tunnel_nic_device_sync_work() during concurrent device operations.  The workqueue core clears the internal pending bit before invoking the worker. At that point, a concurrent thread can queue the work again. When the already running worker eventually clears the work_pending flag to 0, it mistakenly clears the flag for the newly queued instance. udp_tunnel_nic_unregister() then observes work_pending as 0 and frees the structure while the second work item is still active in the queue, leading to UAF.  Fix this by returning early in udp_tunnel_nic_device_sync() if work_pending is already set, preventing redundant work queueing.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72405","epss":0.00134,"percentile":0.03253,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10251000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-72405","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72405","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/54292b167466cdf42176b7b6f01da66c184deb12","https://git.kernel.org/stable/c/9075efb9b2c1d9d7a8285c937b64aa93ca0c41b7","https://git.kernel.org/stable/c/cee6688e5731c0591643521716d1a1a5c1a98bf8","https://git.kernel.org/stable/c/ecf69d4b43370c587e48d4d70289dbdb7e039d4d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync\n\nYue Sun reported a use-after-free and debugobjects warning in\nudp_tunnel_nic_device_sync_work() during concurrent device operations.\n\nThe workqueue core clears the internal pending bit before invoking the\nworker. At that point, a concurrent thread can queue the work again.\nWhen the already running worker eventually clears the work_pending flag\nto 0, it mistakenly clears the flag for the newly queued instance.\nudp_tunnel_nic_unregister() then observes work_pending as 0 and frees\nthe structure while the second work item is still active in the queue,\nleading to UAF.\n\nFix this by returning early in udp_tunnel_nic_device_sync() if\nwork_pending is already set, preventing redundant work queueing.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72405","epss":0.00134,"percentile":0.03253,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72405","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72413","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72413","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: fix err_chunk memory leaks in INIT handling  When sctp_verify_init() encounters unrecognized parameters, it allocates an err_chunk to report them. However, this chunk is leaked in several code paths:  1. In sctp_sf_do_5_1B_init(), if security_sctp_assoc_request() fails after    sctp_verify_init() has populated err_chunk, the function returns    immediately without freeing it.  2. In sctp_sf_do_unexpected_init(), the same leak occurs on the    security_sctp_assoc_request() failure path.  3. In sctp_sf_do_unexpected_init(), on the success path after copying    unrecognized parameters to the INIT-ACK, the function returns without    freeing err_chunk, unlike sctp_sf_do_5_1B_init() which properly frees    it.  Fix all three leaks by adding sctp_chunk_free(err_chunk) calls before returning in the error paths and on the success path in sctp_sf_do_unexpected_init().","cvss":[],"epss":[{"cve":"CVE-2026-72413","epss":0.00189,"percentile":0.0868,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0945},"relatedVulnerabilities":[{"id":"CVE-2026-72413","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72413","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/94f55994e19e8f0676990b9d5015b58ab6a97e00","https://git.kernel.org/stable/c/9f58a0a4d6c2ed5d341bba64f058f15d1b0c36f2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix err_chunk memory leaks in INIT handling\n\nWhen sctp_verify_init() encounters unrecognized parameters, it allocates an\nerr_chunk to report them. However, this chunk is leaked in several code\npaths:\n\n1. In sctp_sf_do_5_1B_init(), if security_sctp_assoc_request() fails after\n   sctp_verify_init() has populated err_chunk, the function returns\n   immediately without freeing it.\n\n2. In sctp_sf_do_unexpected_init(), the same leak occurs on the\n   security_sctp_assoc_request() failure path.\n\n3. In sctp_sf_do_unexpected_init(), on the success path after copying\n   unrecognized parameters to the INIT-ACK, the function returns without\n   freeing err_chunk, unlike sctp_sf_do_5_1B_init() which properly frees\n   it.\n\nFix all three leaks by adding sctp_chunk_free(err_chunk) calls before\nreturning in the error paths and on the success path in\nsctp_sf_do_unexpected_init().","cvss":[],"epss":[{"cve":"CVE-2026-72413","epss":0.00189,"percentile":0.0868,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72413","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72416","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72416","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_compat: ebtables emulation must reject non-bridge targets  xtables targets return netfilter verdicts: NF_ACCEPT, NF_DROP, and so on.  ebtables targets return incompatible verdicts: EBT_ACCEPT, EBT_DROP, ...   We cannot allow fallback to NFPROTO_UNSPEC.  ebtables doesn't permit this since 11ff7288beb2 (\"netfilter: ebtables: reject non-bridge targets\") but that commit missed the nft_compat layer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72416","epss":0.00173,"percentile":0.06877,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12802},"relatedVulnerabilities":[{"id":"CVE-2026-72416","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72416","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/33e1875d6b5b552a2e5652b40074c604199354ee","https://git.kernel.org/stable/c/9dbba7e694ec045f21ede2f892fb42b81b4e1692","https://git.kernel.org/stable/c/b3f7a84540a0d014ec42343ff5909657c1bd1994","https://git.kernel.org/stable/c/c129b0185e707dce405968e21afccd5728b2ce63","https://git.kernel.org/stable/c/efc17b9240d821c424bc5191a5c6e9384a06293e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_compat: ebtables emulation must reject non-bridge targets\n\nxtables targets return netfilter verdicts: NF_ACCEPT, NF_DROP, and so\non.  ebtables targets return incompatible verdicts: EBT_ACCEPT,\nEBT_DROP, ...   We cannot allow fallback to NFPROTO_UNSPEC.\n\nebtables doesn't permit this since\n11ff7288beb2 (\"netfilter: ebtables: reject non-bridge targets\")\nbut that commit missed the nft_compat layer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72416","epss":0.00173,"percentile":0.06877,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72416","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72420","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72420","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md/raid5: avoid R5_Overlap races while breaking stripe batches  KCSAN report a race in break_stripe_batch_list() vs. raid5_make_request() on sh->dev[i].flags (plain word write vs. atomic bit op)..  and .. one possible scenario is:  CPU1                            CPU2 break_stripe_batch_list(sh1) -> handle sh2 -> lock(sh2) -> sh2->batch_head = NULL -> unlock(sh2) -> test_and_clear_bit(R5_Overlap, sh2->dev[i].flags) -> wake_up_bit(sh2->dev[i].flags)                                 raid5_make_request()                                 -> add_all_stripe_bios(sh2)                                 -> lock(sh2)                                 -> stripe_bio_overlaps(sh2) returns true \t\t\t\t   batch_head is NULL, so new bio overlap \t\t\t\t   exist bio on sh2 -> true                                 -> set_bit(R5_Overlap, sh2->dev[i].flags)                                 -> unlock(sh2)                                 -> wait_on_bit(sh2->dev[i].flags) -> sh2->dev[i].flags = sh1->dev[i].flags & ~R5_Overlap  No wait_up_bit(), CPU2 could be wait_on_bit() forever...  Fix by : - Expand the protect zone. - Use batch_head's device flag's snaphot when no held head_sh->stripe_lock. - Move sh/head_sh->batch_head = NULL to the end of protected zone , and ,   any concurrent add_all_stripe_bios() grabs sh->stripe_lock now either: \t- see batch_head != null, and , is rejected by stripe_bio_overlaps() \t  under the lock (no R5_Overlap wait ) , or , \t- sees batch_head == NULL, only after dev[i].flags has already been \t  set and the prior R5_Overlap waiters worken.  KCSAN report: ================================================   BUG: KCSAN: data-race in break_stripe_batch_list / raid5_make_request    write (marked) to 0xffff8e89c8117548 of 8 bytes by task 4042 on cpu 0:     raid5_make_request+0xea0/0x2930     md_handle_request+0x4a2/0xa40     md_submit_bio+0x109/0x1a0     __submit_bio+0x2ec/0x390     submit_bio_noacct_nocheck+0x457/0x710     submit_bio_noacct+0x2a7/0xc20     submit_bio+0x56/0x250     blkdev_direct_IO+0x54c/0xda0     blkdev_write_iter+0x38f/0x570     aio_write+0x22b/0x490     io_submit_one+0xa51/0xf70     __x64_sys_io_submit+0xf7/0x220     x64_sys_call+0x1907/0x1c60     do_syscall_64+0x130/0x570     entry_SYSCALL_64_after_hwframe+0x76/0x7e    read to 0xffff8e89c8117548 of 8 bytes by task 4010 on cpu 5:     break_stripe_batch_list+0x249/0x480     handle_stripe_clean_event+0x720/0x9b0     handle_stripe+0x32fb/0x4500     handle_active_stripes.isra.0+0x6e0/0xa50     raid5d+0x7e0/0xba0     md_thread+0x15a/0x2d0     kthread+0x1e3/0x220     ret_from_fork+0x37a/0x410     ret_from_fork_asm+0x1a/0x30    value changed: 0x0000000000000019 -> 0x0000000000000099 --> R5_Overlap","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72420","epss":0.00445,"percentile":0.37519,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.362675},"relatedVulnerabilities":[{"id":"CVE-2026-72420","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72420","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4d919c9b770996365806b6c8d701912d52baa306","https://git.kernel.org/stable/c/55b77337bdd088c77461588e5ec094421b89911b","https://git.kernel.org/stable/c/8031b0d02bd221a5f9add4357e291fc2a527b83a","https://git.kernel.org/stable/c/d684b72dfbd320623ccaab0779aa841190488e7c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid5: avoid R5_Overlap races while breaking stripe batches\n\nKCSAN report a race in break_stripe_batch_list() vs. raid5_make_request()\non sh->dev[i].flags (plain word write vs. atomic bit op)..\n\nand .. one possible scenario is:\n\nCPU1                            CPU2\nbreak_stripe_batch_list(sh1)\n-> handle sh2\n-> lock(sh2)\n-> sh2->batch_head = NULL\n-> unlock(sh2)\n-> test_and_clear_bit(R5_Overlap, sh2->dev[i].flags)\n-> wake_up_bit(sh2->dev[i].flags)\n                                raid5_make_request()\n                                -> add_all_stripe_bios(sh2)\n                                -> lock(sh2)\n                                -> stripe_bio_overlaps(sh2) returns true\n\t\t\t\t   batch_head is NULL, so new bio overlap\n\t\t\t\t   exist bio on sh2 -> true\n                                -> set_bit(R5_Overlap, sh2->dev[i].flags)\n                                -> unlock(sh2)\n                                -> wait_on_bit(sh2->dev[i].flags)\n-> sh2->dev[i].flags = sh1->dev[i].flags & ~R5_Overlap\n\nNo wait_up_bit(), CPU2 could be wait_on_bit() forever...\n\nFix by :\n- Expand the protect zone.\n- Use batch_head's device flag's snaphot when no held head_sh->stripe_lock.\n- Move sh/head_sh->batch_head = NULL to the end of protected zone , and ,\n  any concurrent add_all_stripe_bios() grabs sh->stripe_lock now either:\n\t- see batch_head != null, and , is rejected by stripe_bio_overlaps()\n\t  under the lock (no R5_Overlap wait ) , or ,\n\t- sees batch_head == NULL, only after dev[i].flags has already been\n\t  set and the prior R5_Overlap waiters worken.\n\nKCSAN report:\n================================================\n  BUG: KCSAN: data-race in break_stripe_batch_list / raid5_make_request\n\n  write (marked) to 0xffff8e89c8117548 of 8 bytes by task 4042 on cpu 0:\n    raid5_make_request+0xea0/0x2930\n    md_handle_request+0x4a2/0xa40\n    md_submit_bio+0x109/0x1a0\n    __submit_bio+0x2ec/0x390\n    submit_bio_noacct_nocheck+0x457/0x710\n    submit_bio_noacct+0x2a7/0xc20\n    submit_bio+0x56/0x250\n    blkdev_direct_IO+0x54c/0xda0\n    blkdev_write_iter+0x38f/0x570\n    aio_write+0x22b/0x490\n    io_submit_one+0xa51/0xf70\n    __x64_sys_io_submit+0xf7/0x220\n    x64_sys_call+0x1907/0x1c60\n    do_syscall_64+0x130/0x570\n    entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n  read to 0xffff8e89c8117548 of 8 bytes by task 4010 on cpu 5:\n    break_stripe_batch_list+0x249/0x480\n    handle_stripe_clean_event+0x720/0x9b0\n    handle_stripe+0x32fb/0x4500\n    handle_active_stripes.isra.0+0x6e0/0xa50\n    raid5d+0x7e0/0xba0\n    md_thread+0x15a/0x2d0\n    kthread+0x1e3/0x220\n    ret_from_fork+0x37a/0x410\n    ret_from_fork_asm+0x1a/0x30\n\n  value changed: 0x0000000000000019 -> 0x0000000000000099 --> R5_Overlap","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72420","epss":0.00445,"percentile":0.37519,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72420","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72423","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72423","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Guard conntrack opts error writes  The conntrack lookup and allocation kfuncs take an opts pointer together with an opts__sz argument. The verifier checks only the memory range described by opts__sz, but the wrappers unconditionally write opts->error whenever the internal lookup or allocation helper returns an error.  For an invalid size smaller than the end of opts->error, that write can land outside the verifier-checked range. Keep returning NULL for invalid arguments, but only report the error through opts->error when the supplied size includes the field.  This preserves error reporting for the supported 12-byte and 16-byte layouts, and for other invalid sizes that still include opts->error.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72423","epss":0.00154,"percentile":0.04854,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12551},"relatedVulnerabilities":[{"id":"CVE-2026-72423","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72423","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6f6183a39533d727deaa5061cadae6dd9e6744d0","https://git.kernel.org/stable/c/dd74c80203842a21b2ebb9f70d1260d9aa20fa05"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard conntrack opts error writes\n\nThe conntrack lookup and allocation kfuncs take an opts pointer\ntogether with an opts__sz argument. The verifier checks only the memory\nrange described by opts__sz, but the wrappers unconditionally write\nopts->error whenever the internal lookup or allocation helper returns an\nerror.\n\nFor an invalid size smaller than the end of opts->error, that write can\nland outside the verifier-checked range. Keep returning NULL for invalid\narguments, but only report the error through opts->error when the\nsupplied size includes the field.\n\nThis preserves error reporting for the supported 12-byte and 16-byte\nlayouts, and for other invalid sizes that still include opts->error.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72423","epss":0.00154,"percentile":0.04854,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72423","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72434","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72434","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: ipset: make sure gc is properly stopped  Sashiko noticed that when destroying a set, cancel_delayed_work_sync() was called while gc calls queue_delayed_work() unconditionally which can lead not to properly shutting down the gc.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72434","epss":0.00163,"percentile":0.05856,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12469499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-72434","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72434","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/12088da6add5b003657c8506c5b0fcef835083b8","https://git.kernel.org/stable/c/4a597a87e2e2f608edb6be2c510dc826b4fdfb53","https://git.kernel.org/stable/c/c78bd5195a5998094a5866df702fbeafda60dafb","https://git.kernel.org/stable/c/c940d1b96248c3081b664ede5418078bdc7c8c07"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: make sure gc is properly stopped\n\nSashiko noticed that when destroying a set,\ncancel_delayed_work_sync() was called while gc\ncalls queue_delayed_work() unconditionally which\ncan lead not to properly shutting down the gc.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72434","epss":0.00163,"percentile":0.05856,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72434","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72438","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72438","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md/raid10: fix writes_pending and barrier reference leaks on discard failures  raid10_make_request() acquires a writes_pending reference with md_write_start() before calling raid10_handle_discard(). Several failure paths in raid10_handle_discard() complete the bio and return without releasing the corresponding reference, causing md_write_end() to be skipped.  Call md_write_end() before returning from these failure paths to keep writes_pending accounting balanced.  Additionally, discard split allocation failures can occur after wait_barrier() succeeds. Those paths return without calling allow_barrier(), leaking the associated barrier reference.  Release the barrier before returning from those paths.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72438","epss":0.00359,"percentile":0.2916,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26925},"relatedVulnerabilities":[{"id":"CVE-2026-72438","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72438","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/393d687131d8aa8c7e4de2cb494438e145d20fc2","https://git.kernel.org/stable/c/d1324b41dabd26787559efaeb430643c627c1eb0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: fix writes_pending and barrier reference leaks on discard failures\n\nraid10_make_request() acquires a writes_pending reference with\nmd_write_start() before calling raid10_handle_discard(). Several failure\npaths in raid10_handle_discard() complete the bio and return without\nreleasing the corresponding reference, causing md_write_end() to be\nskipped.\n\nCall md_write_end() before returning from these failure paths to keep\nwrites_pending accounting balanced.\n\nAdditionally, discard split allocation failures can occur after\nwait_barrier() succeeds. Those paths return without calling\nallow_barrier(), leaking the associated barrier reference.\n\nRelease the barrier before returning from those paths.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72438","epss":0.00359,"percentile":0.2916,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72438","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72439","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72439","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md/raid10: fix writes_pending leak on write request failures  raid10_make_request() acquires a writes_pending reference with md_write_start() before dispatching write requests. Several failure paths in raid10_write_request() complete the bio and return without reaching the normal write completion path, causing the corresponding md_write_end() to be skipped.  Make raid10_write_request() return a status indicating whether the write request was successfully queued. This allows raid10_make_request() to release the writes_pending reference with md_write_end() when a write request fails.","cvss":[],"epss":[{"cve":"CVE-2026-72439","epss":0.00162,"percentile":0.05766,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08099999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-72439","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72439","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/e045d6ed33f8faa3e3dd6dc33c62ec01e3ad275d","https://git.kernel.org/stable/c/f94031c94eaebe14a7c9e91720064de0c5a54a6c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: fix writes_pending leak on write request failures\n\nraid10_make_request() acquires a writes_pending reference with\nmd_write_start() before dispatching write requests. Several failure\npaths in raid10_write_request() complete the bio and return without\nreaching the normal write completion path, causing the corresponding\nmd_write_end() to be skipped.\n\nMake raid10_write_request() return a status indicating whether the write\nrequest was successfully queued. This allows raid10_make_request() to\nrelease the writes_pending reference with md_write_end() when a write\nrequest fails.","cvss":[],"epss":[{"cve":"CVE-2026-72439","epss":0.00162,"percentile":0.05766,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72439","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72440","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72440","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md/raid1: fix writes_pending and barrier reference leaks on write failures  raid1_make_request() acquires a writes_pending reference with md_write_start() before calling raid1_write_request(). Several failure paths in raid1_write_request() complete the bio and return without reaching the normal write completion path, causing the corresponding md_write_end() to be skipped.  Make raid1_write_request() return a status indicating whether the write request was successfully queued. This allows raid1_make_request() to call md_write_end() when raid1_write_request() fails.  Additionally, if wait_blocked_rdev() fails after wait_barrier() succeeds, the associated barrier reference is not released.  Call allow_barrier() before returning from that path to keep the barrier accounting balanced.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72440","epss":0.00364,"percentile":0.29677,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26571999999999996},"relatedVulnerabilities":[{"id":"CVE-2026-72440","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72440","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/8e065a1602511282fc0da2dc89445e0eb71a681c","https://git.kernel.org/stable/c/bffbbfcbd9393e315a7a4286dcd70e875265db9a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1: fix writes_pending and barrier reference leaks on write failures\n\nraid1_make_request() acquires a writes_pending reference with\nmd_write_start() before calling raid1_write_request(). Several failure\npaths in raid1_write_request() complete the bio and return without\nreaching the normal write completion path, causing the corresponding\nmd_write_end() to be skipped.\n\nMake raid1_write_request() return a status indicating whether the write\nrequest was successfully queued. This allows raid1_make_request() to\ncall md_write_end() when raid1_write_request() fails.\n\nAdditionally, if wait_blocked_rdev() fails after wait_barrier()\nsucceeds, the associated barrier reference is not released.\n\nCall allow_barrier() before returning from that path to keep the barrier\naccounting balanced.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72440","epss":0.00364,"percentile":0.29677,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72440","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72454","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72454","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()  i3c_hci_addr_to_dev() walks bus->devs.i3c, which is protected by bus.lock (rwsem).  However, it is invoked from the MIPI I3C HCI IRQ handler, which cannot take bus.lock.  This allows concurrent device addition/removal in the I3C core to modify the list while it is being traversed, potentially leading to use-after-free or crashes.  Remove the dependency on the bus device list and introduce a dedicated lookup table.  Add an ibi_devs[] array indexed by DAT entry, maintained under hci->lock.  Update the array when IBIs are enabled or disabled, so that it always reflects the set of devices allowed to generate IBIs. Also update when IBIs are freed, to cover the corner case when an IBI is freed without first being disabled (e.g. oldedev in i3c_master_add_i3c_dev_locked()).  Move i3c_hci_addr_to_dev() into core.c, reimplement it using the new array, and add a lockdep assertion to enforce that hci->lock is held by callers.  Demote a message in PIO and DMA IBI handling, from an error to a debug message, because there is a race window when the condition can arise normally.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72454","epss":0.0012,"percentile":0.02112,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-72454","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72454","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/650716f23eac488c6696babdc7805f6a6b7427ad","https://git.kernel.org/stable/c/8f851cab401c28287d536b1347d76f6e219c0db6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()\n\ni3c_hci_addr_to_dev() walks bus->devs.i3c, which is protected by\nbus.lock (rwsem).  However, it is invoked from the MIPI I3C HCI IRQ\nhandler, which cannot take bus.lock.  This allows concurrent device\naddition/removal in the I3C core to modify the list while it is being\ntraversed, potentially leading to use-after-free or crashes.\n\nRemove the dependency on the bus device list and introduce a dedicated\nlookup table.  Add an ibi_devs[] array indexed by DAT entry, maintained\nunder hci->lock.  Update the array when IBIs are enabled or disabled,\nso that it always reflects the set of devices allowed to generate IBIs.\nAlso update when IBIs are freed, to cover the corner case when an IBI is\nfreed without first being disabled (e.g. oldedev in\ni3c_master_add_i3c_dev_locked()).\n\nMove i3c_hci_addr_to_dev() into core.c, reimplement it using the new\narray, and add a lockdep assertion to enforce that hci->lock is held\nby callers.\n\nDemote a message in PIO and DMA IBI handling, from an error to a debug\nmessage, because there is a race window when the condition can arise\nnormally.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72454","epss":0.0012,"percentile":0.02112,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72454","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72469","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72469","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xprtrdma: Fix ep kref imbalance on ADDR_CHANGE  rpcrdma_cm_event_handler() falls through to the disconnected: label on RDMA_CM_EVENT_ADDR_CHANGE and calls rpcrdma_ep_put() with no matching get when the event arrives before RDMA_CM_EVENT_ESTABLISHED. The kref then underflows during connect teardown and rpcrdma_xprt_disconnect() operates on a freed ep.  Reference counts across a normal connection lifecycle:      rpcrdma_ep_create()             kref_init     ->1     rpcrdma_xprt_connect()          ep_get        ->2  (before post_recvs)     RDMA_CM_EVENT_ESTABLISHED       ep_get        ->3     RDMA_CM_EVENT_DISCONNECTED      ep_put        ->2     rpcrdma_xprt_drain()            ep_put        ->1     rpcrdma_xprt_disconnect() tail  ep_put        ->0  (ep_destroy)  The connect-time get in rpcrdma_xprt_connect(), taken just before rpcrdma_post_recvs() \"while there are outstanding Receives,\" is balanced by rpcrdma_xprt_drain. ADDR_CHANGE before ESTABLISHED has no get to consume, so its put drops the count to 1 and the drain put then frees the ep while rpcrdma_xprt_disconnect() still holds a pointer to it.  Fix by dispatching on the prior re_connect_status via xchg(): for prev == 0 (pre-ESTABLISHED) wake the connect waiter and return with no put; for prev == 1 call rpcrdma_force_disconnect() and return. The case-1 arm relies on the subsequent RDMA_CM_EVENT_DISCONNECTED event -- reliably delivered when rdma_disconnect() is called on a still-connected cm_id -- to balance the ESTABLISHED get; rpcrdma_xprt_drain() continues to balance only that connect-time get. Any other prior value means teardown is already in flight.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72469","epss":0.00317,"percentile":0.24414,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25835500000000006},"relatedVulnerabilities":[{"id":"CVE-2026-72469","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72469","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/af9b65b29af341932625c4283dc7a23cdb62688a","https://git.kernel.org/stable/c/cfd1bab66b042da7a778786685125656c695931b","https://git.kernel.org/stable/c/d0479c2b12974aa188b10d221a5770126b118b6d","https://git.kernel.org/stable/c/ffc07790539736a5d029f6a3c966b46c529f93a8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Fix ep kref imbalance on ADDR_CHANGE\n\nrpcrdma_cm_event_handler() falls through to the disconnected: label\non RDMA_CM_EVENT_ADDR_CHANGE and calls rpcrdma_ep_put() with no\nmatching get when the event arrives before RDMA_CM_EVENT_ESTABLISHED.\nThe kref then underflows during connect teardown and\nrpcrdma_xprt_disconnect() operates on a freed ep.\n\nReference counts across a normal connection lifecycle:\n\n    rpcrdma_ep_create()             kref_init     ->1\n    rpcrdma_xprt_connect()          ep_get        ->2  (before post_recvs)\n    RDMA_CM_EVENT_ESTABLISHED       ep_get        ->3\n    RDMA_CM_EVENT_DISCONNECTED      ep_put        ->2\n    rpcrdma_xprt_drain()            ep_put        ->1\n    rpcrdma_xprt_disconnect() tail  ep_put        ->0  (ep_destroy)\n\nThe connect-time get in rpcrdma_xprt_connect(), taken just before\nrpcrdma_post_recvs() \"while there are outstanding Receives,\" is\nbalanced by rpcrdma_xprt_drain. ADDR_CHANGE before ESTABLISHED has\nno get to consume, so its put drops the count to 1 and the drain\nput then frees the ep while rpcrdma_xprt_disconnect() still holds a\npointer to it.\n\nFix by dispatching on the prior re_connect_status via xchg(): for\nprev == 0 (pre-ESTABLISHED) wake the connect waiter and return with\nno put; for prev == 1 call rpcrdma_force_disconnect() and return.\nThe case-1 arm relies on the subsequent RDMA_CM_EVENT_DISCONNECTED\nevent -- reliably delivered when rdma_disconnect() is called on a\nstill-connected cm_id -- to balance the ESTABLISHED get;\nrpcrdma_xprt_drain() continues to balance only that connect-time\nget. Any other prior value means teardown is already in flight.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72469","epss":0.00317,"percentile":0.24414,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72469","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72470","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72470","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: resize log->one_page_buf when adopting on-disk page size  log_replay() allocates log->one_page_buf using the page size that was chosen from the host PAGE_SIZE:  \tlog->one_page_buf = kmalloc(log->page_size, GFP_NOFS);  Later, when a restart area is found, the log page size recorded on disk is adopted:  \tt32 = le32_to_cpu(log->rst_info.r_page->sys_page_size); \tif (log->page_size != t32) { \t\tlog->l_size = log->orig_file_size; \t\tlog->page_size = norm_file_page(t32, &log->l_size, \t\t\t\t\t\tt32 == DefaultLogPageSize); \t}  If the on-disk page size is larger than the size used for the initial allocation, log->page_size grows but one_page_buf is left at its original, smaller size. A subsequent unaligned read_log_page() then reads log->page_size bytes into the undersized scratch buffer:  \tpage_buf = page_off ? log->one_page_buf : *buffer; \terr = ntfs_read_run_nb_ra(ni->mi.sbi, &ni->file.run, page_vbo, page_buf, \t\t\t\t  log->page_size, NULL, &log->read_ahead);  overflowing the allocation. This is reachable when mounting a dirty NTFS volume whose log was formatted with a page size larger than the buffer initially allocated on the mounting host (for example a 64K-log volume mounted on a host that allocated a 4K scratch buffer).  Grow one_page_buf when the adopted on-disk page size exceeds the size used for the initial allocation. On krealloc() failure the original buffer is left intact and freed by the existing error path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72470","epss":0.00138,"percentile":0.03513,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-72470","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72470","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2097a2537d9d1c29c0e20ed0dbf717a0ccd8f374","https://git.kernel.org/stable/c/4f129fc6f756f8541e5bff45b1804cc11b1ec712","https://git.kernel.org/stable/c/5a35454179fe1041d9cd286f5d320ce0d448c12a","https://git.kernel.org/stable/c/c99444f6dfca893f6d310aae4a53c620f98f7b4f","https://git.kernel.org/stable/c/f1422df595d69b997d23a8f11e12c528ccef7fad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: resize log->one_page_buf when adopting on-disk page size\n\nlog_replay() allocates log->one_page_buf using the page size that was\nchosen from the host PAGE_SIZE:\n\n\tlog->one_page_buf = kmalloc(log->page_size, GFP_NOFS);\n\nLater, when a restart area is found, the log page size recorded on disk\nis adopted:\n\n\tt32 = le32_to_cpu(log->rst_info.r_page->sys_page_size);\n\tif (log->page_size != t32) {\n\t\tlog->l_size = log->orig_file_size;\n\t\tlog->page_size = norm_file_page(t32, &log->l_size,\n\t\t\t\t\t\tt32 == DefaultLogPageSize);\n\t}\n\nIf the on-disk page size is larger than the size used for the initial\nallocation, log->page_size grows but one_page_buf is left at its\noriginal, smaller size. A subsequent unaligned read_log_page() then\nreads log->page_size bytes into the undersized scratch buffer:\n\n\tpage_buf = page_off ? log->one_page_buf : *buffer;\n\terr = ntfs_read_run_nb_ra(ni->mi.sbi, &ni->file.run, page_vbo, page_buf,\n\t\t\t\t  log->page_size, NULL, &log->read_ahead);\n\noverflowing the allocation. This is reachable when mounting a dirty\nNTFS volume whose log was formatted with a page size larger than the\nbuffer initially allocated on the mounting host (for example a 64K-log\nvolume mounted on a host that allocated a 4K scratch buffer).\n\nGrow one_page_buf when the adopted on-disk page size exceeds the size\nused for the initial allocation. On krealloc() failure the original\nbuffer is left intact and freed by the existing error path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72470","epss":0.00138,"percentile":0.03513,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72470","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72472","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72472","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfs: use nfsi->rwsem to protect traversal of the file lock list  Lingfeng identified a bug and suggested two solutions, but both appear to have issues.  Generally, we cannot release flc_lock while iterating over the file lock list to avoid use-after-free (UAF) problems with file locks. However, functions like nfs_delegation_claim_locks and nfs4_reclaim_locks cannot adhere to this rule because recover_lock or nfs4_lock_delegation_recall may take a long time. To resolve this, NFS switches to using nfsi->rwsem for the same protection, and nfs_reclaim_locks follows this approach. Although nfs_delegation_claim_locks uses so_delegreturn_mutex instead, this is inadequate since a single inode can have multiple nfs4_state instances. Therefore, the fix is to also use nfsi->rwsem in this case.  Furthermore, after commit c69899a17ca4 (\"NFSv4: Update of VFS byte range lock must be atomic with the stateid update\"), the functions nfs4_locku_done and nfs4_lock_done also break this rule because they call locks_lock_inode_wait without holding nfsi->rwsem. Simply adding this protection could cause many deadlocks, so instead, the call to locks_lock_inode_wait is moved into _nfs4_proc_setlk. Regarding the bug fixed by commit c69899a17ca4 (\"NFSv4: Update of VFS byte range lock must be atomic with the stateid update\"), it has been resolved after commit 0460253913e5 (\"NFSv4: nfs4_do_open() is incorrectly triggering state recovery\") because all slots are drained before calling nfs4_do_reclaim, which prevents concurrent stateid changes along this path. Also, nfs_delegation_claim_locks does not cause this concurrency either since when _nfs4_proc_setlk is called with NFS_DELEGATED_STATE, no RPC is sent, so nfs4_lock_done is not called. Therefore, nfs4_lock_delegation_recall from nfs_delegation_claim_locks is the first time the stateid is set.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72472","epss":0.00644,"percentile":0.48792,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.6053600000000001},"relatedVulnerabilities":[{"id":"CVE-2026-72472","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72472","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1cda95bf2e9c0e6b63545b7565fe4a1e474322f4","https://git.kernel.org/stable/c/4837fb36219e6c08b666bc31a86841bad8526358","https://git.kernel.org/stable/c/e68035178e65e2b3aa386ce61202ff33724ae418","https://git.kernel.org/stable/c/f161ef7b0dd2f51fdb002ba4a4e9bf0ee7409218"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: use nfsi->rwsem to protect traversal of the file lock list\n\nLingfeng identified a bug and suggested two solutions, but both appear\nto have issues.\n\nGenerally, we cannot release flc_lock while iterating over the file lock\nlist to avoid use-after-free (UAF) problems with file locks. However,\nfunctions like nfs_delegation_claim_locks and nfs4_reclaim_locks cannot\nadhere to this rule because recover_lock or nfs4_lock_delegation_recall\nmay take a long time. To resolve this, NFS switches to using nfsi->rwsem\nfor the same protection, and nfs_reclaim_locks follows this approach.\nAlthough nfs_delegation_claim_locks uses so_delegreturn_mutex instead,\nthis is inadequate since a single inode can have multiple nfs4_state\ninstances. Therefore, the fix is to also use nfsi->rwsem in this case.\n\nFurthermore, after commit c69899a17ca4 (\"NFSv4: Update of VFS byte range\nlock must be atomic with the stateid update\"), the functions\nnfs4_locku_done and nfs4_lock_done also break this rule because they\ncall locks_lock_inode_wait without holding nfsi->rwsem. Simply adding\nthis protection could cause many deadlocks, so instead, the call to\nlocks_lock_inode_wait is moved into _nfs4_proc_setlk. Regarding the bug\nfixed by commit c69899a17ca4 (\"NFSv4: Update of VFS byte range\nlock must be atomic with the stateid update\"), it has been resolved\nafter commit 0460253913e5 (\"NFSv4: nfs4_do_open() is incorrectly triggering\nstate recovery\") because all slots are drained before calling\nnfs4_do_reclaim, which prevents concurrent stateid changes along this path.\nAlso, nfs_delegation_claim_locks does not cause this concurrency either\nsince when _nfs4_proc_setlk is called with NFS_DELEGATED_STATE, no RPC is\nsent, so nfs4_lock_done is not called. Therefore,\nnfs4_lock_delegation_recall from nfs_delegation_claim_locks is the first\ntime the stateid is set.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72472","epss":0.00644,"percentile":0.48792,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72472","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72488","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72488","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  soundwire: fix bug in sdw_add_element_group_count found by syzkaller  The original implementation caused an out-of-bounds memory access in the sdw_add_element_group_count for-loop when i == num.  for (i = 0; i <= num; i++) {     if (rate == group->rates[i] && lane == group->lanes[i])         ...  To fix this error, the function now checks for existing rate/lane entries in the group(a function parameter) using a for-loop before adding them.  No functional changes apart from this fix.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72488","epss":0.00162,"percentile":0.05674,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12393},"relatedVulnerabilities":[{"id":"CVE-2026-72488","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72488","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/a454f61747c97e2eadaa7a35ffc1f4b1645c6a53","https://git.kernel.org/stable/c/e483a406a23a92d5202e8d324f206e127eef48ff","https://git.kernel.org/stable/c/f772ff5a0e6758fd412803c09e03ba3bca5f5878"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsoundwire: fix bug in sdw_add_element_group_count found by syzkaller\n\nThe original implementation caused an out-of-bounds memory access\nin the sdw_add_element_group_count for-loop when i == num.\n\nfor (i = 0; i <= num; i++) {\n    if (rate == group->rates[i] && lane == group->lanes[i])\n        ...\n\nTo fix this error, the function now checks for existing rate/lane\nentries in the group(a function parameter) using a for-loop before\nadding them.\n\nNo functional changes apart from this fix.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72488","epss":0.00162,"percentile":0.05674,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72488","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72493","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72493","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: serialize netif_running() check in enqueue_to_backlog()  Syzbot reported a KASAN slab-use-after-free in fib_rules_lookup().  The root cause is a race condition where packets can escape the backlog flushing during device unregistration (e.g., during netns exit).  Commit e9e4dd3267d0 (\"net: do not process device backlog during unregistration\") introduced a lockless netif_running() check in enqueue_to_backlog() to prevent queuing packets to an unregistering device.  However, this creates a TOCTOU race window.  A lockless transmitter (like veth_xmit) can pass the check before dev_close() clears IFF_UP. If the transmitter is then delayed, flush_all_backlogs() can run and finish before the transmitter grabs the backlog lock and queues the packet. The packet then escapes the flush and triggers UAF later when processed.  Fix this by moving the netif_running() check inside the backlog lock. This serializes the check with the flush work (which also grabs the lock). We then either queue the packet before the flush runs (so it gets flushed), or check netif_running() after the flush/close completes (so it gets dropped).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.9,"exploitabilityScore":3.2,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72493","epss":0.00348,"percentile":0.28013,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.32886},"relatedVulnerabilities":[{"id":"CVE-2026-72493","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72493","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/2fface6e0bbd6314d1d9d071abf2c4d67548511c","https://git.kernel.org/stable/c/46762cefe7f4e5bffc1eb467810a7bbb02e461d7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: serialize netif_running() check in enqueue_to_backlog()\n\nSyzbot reported a KASAN slab-use-after-free in fib_rules_lookup().\n\nThe root cause is a race condition where packets can escape the backlog\nflushing during device unregistration (e.g., during netns exit).\n\nCommit e9e4dd3267d0 (\"net: do not process device backlog during unregistration\")\nintroduced a lockless netif_running() check in enqueue_to_backlog() to\nprevent queuing packets to an unregistering device.\n\nHowever, this creates a TOCTOU race window.\n\nA lockless transmitter (like veth_xmit) can pass\nthe check before dev_close() clears IFF_UP. If the transmitter is then\ndelayed, flush_all_backlogs() can run and finish before the transmitter\ngrabs the backlog lock and queues the packet. The packet then escapes\nthe flush and triggers UAF later when processed.\n\nFix this by moving the netif_running() check inside the backlog lock.\nThis serializes the check with the flush work (which also grabs the lock).\nWe then either queue the packet before the flush runs (so it gets flushed),\nor check netif_running() after the flush/close completes (so it gets dropped).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.9,"exploitabilityScore":3.2,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72493","epss":0.00348,"percentile":0.28013,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72493","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-72494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72494","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/irdma: Replace waitqueue and flag with completion  The driver previously used a waitqueue along with an explicit request_done flag, but without proper barriers around request_done.  An earlier patch by Gui-Dong Han <hanguidong02@gmail.com> attempted to fix this by adding the missing memory barriers. Rather than adding the barriers, this patch replaces the waitqueue+flag with a completion, which is designed for this exact purpose.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72494","epss":0.00407,"percentile":0.34184,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.38258000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-72494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72494","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/bde37aed0724c0139dea177f3aae8d989b6babb1","https://git.kernel.org/stable/c/d9c8c45e6d2f438a3c8e643ae78b59454fa0fadd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Replace waitqueue and flag with completion\n\nThe driver previously used a waitqueue along with an explicit\nrequest_done flag, but without proper barriers around request_done.\n\nAn earlier patch by Gui-Dong Han <hanguidong02@gmail.com> attempted\nto fix this by adding the missing memory barriers. Rather than\nadding the barriers, this patch replaces the waitqueue+flag with\na completion, which is designed for this exact purpose.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-72494","epss":0.00407,"percentile":0.34184,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-72494","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74257","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74257","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sockmap: Fix use-after-free in udp_bpf_recvmsg()  syzbot reported use-after-free of struct sk_msg in sk_msg_recvmsg(). [0]  sk_msg_recvmsg() peeks sk_msg from psock->ingress_msg under a lock, but its processing is lockless.  Thus, sk_msg_recvmsg() must be serialised by callers, otherwise multiple threads could touch the same sk_msg.  For example, TCP uses lock_sock(), and AF_UNIX uses unix_sk(sk)->iolock.  Initially, udp_bpf_recvmsg() had used lock_sock(), but the cited commit removed it.  Let's serialise sk_msg_recvmsg() with lock_sock() in udp_bpf_recvmsg().  Note that holding spin_lock_bh(&sk->sk_receive_queue.lock) is not an option due to copy_page_to_iter() in sk_msg_recvmsg().  [0]: BUG: KASAN: slab-use-after-free in sk_msg_recvmsg+0xb54/0xc30 net/core/skmsg.c:428 Read of size 4 at addr ffff88814cdcf000 by task syz.0.24/6020  CPU: 1 UID: 0 PID: 6020 Comm: syz.0.24 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 01/13/2026 Call Trace:  <TASK>  dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:378 [inline]  print_report+0xba/0x230 mm/kasan/report.c:482  kasan_report+0x117/0x150 mm/kasan/report.c:595  sk_msg_recvmsg+0xb54/0xc30 net/core/skmsg.c:428  udp_bpf_recvmsg+0x4bd/0xe00 net/ipv4/udp_bpf.c:84  inet_recvmsg+0x260/0x270 net/ipv4/af_inet.c:891  sock_recvmsg_nosec net/socket.c:1078 [inline]  sock_recvmsg+0x1a8/0x270 net/socket.c:1100  ____sys_recvmsg+0x1e6/0x4a0 net/socket.c:2812  ___sys_recvmsg+0x215/0x590 net/socket.c:2854  do_recvmmsg+0x334/0x800 net/socket.c:2949  __sys_recvmmsg net/socket.c:3023 [inline]  __do_sys_recvmmsg net/socket.c:3046 [inline]  __se_sys_recvmmsg net/socket.c:3039 [inline]  __x64_sys_recvmmsg+0x198/0x250 net/socket.c:3039  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0xe2/0xf80 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fb319f9aeb9 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fb31ad97028 EFLAGS: 00000246 ORIG_RAX: 000000000000012b RAX: ffffffffffffffda RBX: 00007fb31a216090 RCX: 00007fb319f9aeb9 RDX: 0000000000000001 RSI: 0000200000000400 RDI: 0000000000000004 RBP: 00007fb31a008c1f R08: 0000000000000000 R09: 0000000000000000 R10: 0000000040000021 R11: 0000000000000246 R12: 0000000000000000 R13: 00007fb31a216128 R14: 00007fb31a216090 R15: 00007ffe21dd0a98  </TASK>  Allocated by task 6019:  kasan_save_stack mm/kasan/common.c:57 [inline]  kasan_save_track+0x3e/0x80 mm/kasan/common.c:78  poison_kmalloc_redzone mm/kasan/common.c:398 [inline]  __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:415  kasan_kmalloc include/linux/kasan.h:263 [inline]  __kmalloc_cache_noprof+0x3d1/0x6e0 mm/slub.c:5780  kmalloc_noprof include/linux/slab.h:957 [inline]  kzalloc_noprof include/linux/slab.h:1094 [inline]  alloc_sk_msg net/core/skmsg.c:510 [inline]  sk_psock_skb_ingress_self+0x60/0x350 net/core/skmsg.c:612  sk_psock_verdict_apply net/core/skmsg.c:1038 [inline]  sk_psock_verdict_recv+0x7d9/0x8d0 net/core/skmsg.c:1236  udp_read_skb+0x73e/0x7e0 net/ipv4/udp.c:2045  sk_psock_verdict_data_ready+0x12d/0x550 net/core/skmsg.c:1257  __udp_enqueue_schedule_skb+0xc54/0x10b0 net/ipv4/udp.c:1789  __udp_queue_rcv_skb net/ipv4/udp.c:2346 [inline]  udp_queue_rcv_one_skb+0xac5/0x19c0 net/ipv4/udp.c:2475  __udp4_lib_mcast_deliver+0xc06/0xcf0 net/ipv4/udp.c:2585  __udp4_lib_rcv+0x10f6/0x2620 net/ipv4/udp.c:2724  ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207  ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241  NF_HOOK+0x336/0x3c0 include/linux/netfilter.h:318  dst_input include/net/dst.h:474 [inline]  ip_sublist_rcv_finish+0x221/0x2a0 net/ipv4/ip_input.c:584  ip_list_rcv_finish net/ipv4/ip_inp ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74257","epss":0.00124,"percentile":0.02417,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09486},"relatedVulnerabilities":[{"id":"CVE-2026-74257","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74257","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/39d44ed6904bfa9a1c6d0538672dd50c7b85520e","https://git.kernel.org/stable/c/81567d2b3f4dc4fc32f8b61433738bce2cafd4a1","https://git.kernel.org/stable/c/c010995b29c8939c6aa69e3cb26f8dbee163d156"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsockmap: Fix use-after-free in udp_bpf_recvmsg()\n\nsyzbot reported use-after-free of struct sk_msg in sk_msg_recvmsg(). [0]\n\nsk_msg_recvmsg() peeks sk_msg from psock->ingress_msg under a lock,\nbut its processing is lockless.\n\nThus, sk_msg_recvmsg() must be serialised by callers, otherwise\nmultiple threads could touch the same sk_msg.\n\nFor example, TCP uses lock_sock(), and AF_UNIX uses unix_sk(sk)->iolock.\n\nInitially, udp_bpf_recvmsg() had used lock_sock(), but the cited\ncommit removed it.\n\nLet's serialise sk_msg_recvmsg() with lock_sock() in udp_bpf_recvmsg().\n\nNote that holding spin_lock_bh(&sk->sk_receive_queue.lock) is not\nan option due to copy_page_to_iter() in sk_msg_recvmsg().\n\n[0]:\nBUG: KASAN: slab-use-after-free in sk_msg_recvmsg+0xb54/0xc30 net/core/skmsg.c:428\nRead of size 4 at addr ffff88814cdcf000 by task syz.0.24/6020\n\nCPU: 1 UID: 0 PID: 6020 Comm: syz.0.24 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Compute Engine/Google Compute Engine, BIOS Google 01/13/2026\nCall Trace:\n <TASK>\n dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xba/0x230 mm/kasan/report.c:482\n kasan_report+0x117/0x150 mm/kasan/report.c:595\n sk_msg_recvmsg+0xb54/0xc30 net/core/skmsg.c:428\n udp_bpf_recvmsg+0x4bd/0xe00 net/ipv4/udp_bpf.c:84\n inet_recvmsg+0x260/0x270 net/ipv4/af_inet.c:891\n sock_recvmsg_nosec net/socket.c:1078 [inline]\n sock_recvmsg+0x1a8/0x270 net/socket.c:1100\n ____sys_recvmsg+0x1e6/0x4a0 net/socket.c:2812\n ___sys_recvmsg+0x215/0x590 net/socket.c:2854\n do_recvmmsg+0x334/0x800 net/socket.c:2949\n __sys_recvmmsg net/socket.c:3023 [inline]\n __do_sys_recvmmsg net/socket.c:3046 [inline]\n __se_sys_recvmmsg net/socket.c:3039 [inline]\n __x64_sys_recvmmsg+0x198/0x250 net/socket.c:3039\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xe2/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fb319f9aeb9\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fb31ad97028 EFLAGS: 00000246 ORIG_RAX: 000000000000012b\nRAX: ffffffffffffffda RBX: 00007fb31a216090 RCX: 00007fb319f9aeb9\nRDX: 0000000000000001 RSI: 0000200000000400 RDI: 0000000000000004\nRBP: 00007fb31a008c1f R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000040000021 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007fb31a216128 R14: 00007fb31a216090 R15: 00007ffe21dd0a98\n </TASK>\n\nAllocated by task 6019:\n kasan_save_stack mm/kasan/common.c:57 [inline]\n kasan_save_track+0x3e/0x80 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398 [inline]\n __kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263 [inline]\n __kmalloc_cache_noprof+0x3d1/0x6e0 mm/slub.c:5780\n kmalloc_noprof include/linux/slab.h:957 [inline]\n kzalloc_noprof include/linux/slab.h:1094 [inline]\n alloc_sk_msg net/core/skmsg.c:510 [inline]\n sk_psock_skb_ingress_self+0x60/0x350 net/core/skmsg.c:612\n sk_psock_verdict_apply net/core/skmsg.c:1038 [inline]\n sk_psock_verdict_recv+0x7d9/0x8d0 net/core/skmsg.c:1236\n udp_read_skb+0x73e/0x7e0 net/ipv4/udp.c:2045\n sk_psock_verdict_data_ready+0x12d/0x550 net/core/skmsg.c:1257\n __udp_enqueue_schedule_skb+0xc54/0x10b0 net/ipv4/udp.c:1789\n __udp_queue_rcv_skb net/ipv4/udp.c:2346 [inline]\n udp_queue_rcv_one_skb+0xac5/0x19c0 net/ipv4/udp.c:2475\n __udp4_lib_mcast_deliver+0xc06/0xcf0 net/ipv4/udp.c:2585\n __udp4_lib_rcv+0x10f6/0x2620 net/ipv4/udp.c:2724\n ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207\n ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241\n NF_HOOK+0x336/0x3c0 include/linux/netfilter.h:318\n dst_input include/net/dst.h:474 [inline]\n ip_sublist_rcv_finish+0x221/0x2a0 net/ipv4/ip_input.c:584\n ip_list_rcv_finish net/ipv4/ip_inp\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74257","epss":0.00124,"percentile":0.02417,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74257","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74261","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74261","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: seq: avoid stale FIFO cells during resize  snd_seq_fifo_resize() still needs to publish the replacement pool before it waits for FIFO users. A blocking snd_seq_read() holds f->use_lock while it sleeps, so concurrent senders must be able to queue to the new pool and wake that reader instead of failing against a closing old pool.  However, snd_seq_fifo_event_in() duplicates an event before it takes f->lock, and snd_seq_read() can dequeue a cell and later call snd_seq_fifo_cell_putback() if copy_to_user() or snd_seq_expand_var_event() fails. If resize swaps f->pool and detaches oldhead in between, either path can relink an old-pool cell after the snapshot. That stale cell sits outside the drained oldhead list, keeps oldpool->counter elevated, and can leave snd_seq_pool_delete() waiting for the retired pool to drain.  Keep the existing swap-before-wait ordering in snd_seq_fifo_resize(), but reject stale cells before any FIFO relink. Revalidate event-in cells under f->lock and retry them against the published replacement pool, and free stale putback cells instead of linking them back into the FIFO.  The buggy scenario involves two paths, with each column showing the order within that path:  resize path:                    relink path: 1. Allocate newpool.             1. Take f->use_lock. 2. Swap f->pool to newpool and   2. Duplicate or dequeue an old-pool    detach oldhead.                  cell before oldpool closes. 3. Mark oldpool closing and      3. Reach a later relink point after    wait for FIFO users.             resize published newpool. 4. Free oldhead and delete       4. Relink the old-pool cell after    oldpool.                         resize detached oldhead.                                  5. Drop f->use_lock.  The reproducer reports a resize ioctl blocked in the expected pool teardown path:  signal: resize iteration=98 target_pool=4 exceeded 250ms         (elapsed=251ms) diagnostic: resize_tid=651 wchan=snd_seq_pool_done diagnostic: resize_tid=651 stack=   snd_seq_pool_done+0x5b/0x140   snd_seq_pool_delete+0x7a/0x90   snd_seq_fifo_resize+0x193/0x1e0   snd_seq_ioctl_set_client_pool+0x214/0x260   snd_seq_ioctl+0x119/0x540   __x64_sys_ioctl+0xd1/0x120   do_syscall_64+0xbb/0x2f0   entry_SYSCALL_64_after_hwframe+0x77/0x7f  A second run with larger pools hit the same target path:  signal: resize iteration=32 target_pool=64 exceeded 250ms         (elapsed=251ms) diagnostic: resize_tid=663 wchan=snd_seq_pool_done diagnostic: resize_tid=663 stack=   snd_seq_pool_done+0x5b/0x140   snd_seq_pool_delete+0x7a/0x90   snd_seq_fifo_resize+0x193/0x1e0   snd_seq_ioctl_set_client_pool+0x214/0x260   snd_seq_ioctl+0x119/0x540   __x64_sys_ioctl+0xd1/0x120   do_syscall_64+0xbb/0x2f0   entry_SYSCALL_64_after_hwframe+0x77/0x7f","cvss":[],"epss":[{"cve":"CVE-2026-74261","epss":0.00198,"percentile":0.09683,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.099},"relatedVulnerabilities":[{"id":"CVE-2026-74261","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74261","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1c4c35fb68d520241f7d9f1c356b5e2370fd8364","https://git.kernel.org/stable/c/98a965cb1e767b54b6bbd831b6cea26f521a8f51","https://git.kernel.org/stable/c/e546128291f8d688dcb931827e2efd2aa6c0734d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: avoid stale FIFO cells during resize\n\nsnd_seq_fifo_resize() still needs to publish the replacement pool\nbefore it waits for FIFO users. A blocking snd_seq_read() holds\nf->use_lock while it sleeps, so concurrent senders must be able to\nqueue to the new pool and wake that reader instead of failing against a\nclosing old pool.\n\nHowever, snd_seq_fifo_event_in() duplicates an event before it takes\nf->lock, and snd_seq_read() can dequeue a cell and later call\nsnd_seq_fifo_cell_putback() if copy_to_user() or\nsnd_seq_expand_var_event() fails. If resize swaps f->pool and detaches\noldhead in between, either path can relink an old-pool cell after the\nsnapshot. That stale cell sits outside the drained oldhead list, keeps\noldpool->counter elevated, and can leave snd_seq_pool_delete() waiting\nfor the retired pool to drain.\n\nKeep the existing swap-before-wait ordering in snd_seq_fifo_resize(),\nbut reject stale cells before any FIFO relink. Revalidate event-in cells\nunder f->lock and retry them against the published replacement pool, and\nfree stale putback cells instead of linking them back into the FIFO.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nresize path:                    relink path:\n1. Allocate newpool.             1. Take f->use_lock.\n2. Swap f->pool to newpool and   2. Duplicate or dequeue an old-pool\n   detach oldhead.                  cell before oldpool closes.\n3. Mark oldpool closing and      3. Reach a later relink point after\n   wait for FIFO users.             resize published newpool.\n4. Free oldhead and delete       4. Relink the old-pool cell after\n   oldpool.                         resize detached oldhead.\n                                 5. Drop f->use_lock.\n\nThe reproducer reports a resize ioctl blocked in the expected pool\nteardown path:\n\nsignal: resize iteration=98 target_pool=4 exceeded 250ms\n        (elapsed=251ms)\ndiagnostic: resize_tid=651 wchan=snd_seq_pool_done\ndiagnostic: resize_tid=651 stack=\n  snd_seq_pool_done+0x5b/0x140\n  snd_seq_pool_delete+0x7a/0x90\n  snd_seq_fifo_resize+0x193/0x1e0\n  snd_seq_ioctl_set_client_pool+0x214/0x260\n  snd_seq_ioctl+0x119/0x540\n  __x64_sys_ioctl+0xd1/0x120\n  do_syscall_64+0xbb/0x2f0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nA second run with larger pools hit the same target path:\n\nsignal: resize iteration=32 target_pool=64 exceeded 250ms\n        (elapsed=251ms)\ndiagnostic: resize_tid=663 wchan=snd_seq_pool_done\ndiagnostic: resize_tid=663 stack=\n  snd_seq_pool_done+0x5b/0x140\n  snd_seq_pool_delete+0x7a/0x90\n  snd_seq_fifo_resize+0x193/0x1e0\n  snd_seq_ioctl_set_client_pool+0x214/0x260\n  snd_seq_ioctl+0x119/0x540\n  __x64_sys_ioctl+0xd1/0x120\n  do_syscall_64+0xbb/0x2f0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f","cvss":[],"epss":[{"cve":"CVE-2026-74261","epss":0.00198,"percentile":0.09683,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74261","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74264","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74264","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: watchdog: fix refcount tracking races  Blamed commit converted the untracked dev_hold()/dev_put() calls in the watchdog code to use the tracked dev_hold_track()/dev_put_track() (which were later renamed/interfaced to netdev_hold() and netdev_put()).  By introducing dev->watchdog_dev_tracker to store the reference tracking information without adding synchronization between netdev_watchdog_up() and dev_watchdog(), it enabled the race condition where this pointer could be overwritten or freed concurrently, leading to the list corruption crash syzbot reported:  list_del corruption, ffff888114a18c00->next is NULL  kernel BUG at lib/list_debug.c:52 ! Oops: invalid opcode: 0000 [#1] SMP KASAN PTI CPU: 1 UID: 0 PID: 91 Comm: kworker/u8:5 Not tainted syzkaller #0 PREEMPT(lazy) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026 Workqueue: events_unbound linkwatch_event  RIP: 0010:__list_del_entry_valid_or_report.cold+0x22/0x2a lib/list_debug.c:52 Call Trace:  <TASK>   __list_del_entry_valid include/linux/list.h:132 [inline]   __list_del_entry include/linux/list.h:246 [inline]   list_move_tail include/linux/list.h:341 [inline]   ref_tracker_free+0x1a7/0x6c0 lib/ref_tracker.c:329   netdev_tracker_free include/linux/netdevice.h:4491 [inline]   netdev_put include/linux/netdevice.h:4508 [inline]   netdev_put include/linux/netdevice.h:4504 [inline]   netdev_watchdog_down net/sched/sch_generic.c:600 [inline]   dev_deactivate_many+0x28c/0xfe0 net/sched/sch_generic.c:1363   dev_deactivate+0x109/0x1d0 net/sched/sch_generic.c:1397   linkwatch_do_dev net/core/link_watch.c:184 [inline]   linkwatch_do_dev+0xd3/0x120 net/core/link_watch.c:166   __linkwatch_run_queue+0x3a5/0x810 net/core/link_watch.c:240   linkwatch_event+0x8f/0xc0 net/core/link_watch.c:314   process_one_work+0xa0e/0x1980 kernel/workqueue.c:3314   process_scheduled_works kernel/workqueue.c:3397 [inline]   worker_thread+0x5ef/0xe50 kernel/workqueue.c:3478   kthread+0x370/0x450 kernel/kthread.c:436   ret_from_fork+0x69a/0xc80 arch/x86/kernel/process.c:158   ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245  This patch has three coordinated parts:  1) Add dev->watchdog_lock and dev->watchdog_ref_held to serialize watchdog operations.  2) Remove netdev_watchdog_up() call from netif_carrier_on():    This ensures netdev_watchdog_up() is only called from process/BH context    (via linkwatch workqueue dev_activate()), allowing us to use    spin_lock_bh() for synchronization.  3) Synchronize watchdog up and watchdog timer:    Protect netdev_watchdog_up() with tx_global_lock and watchdog_lock.    Only allocate a new tracker in netdev_watchdog_up() if one is    not already present.    In dev_watchdog(), ensure we don't release the tracker if the    timer was rescheduled either by dev_watchdog() itself or concurrently    by netdev_watchdog_up().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74264","epss":0.00162,"percentile":0.05673,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.12393},"relatedVulnerabilities":[{"id":"CVE-2026-74264","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74264","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/446fe8ce699ce0a4d702f7b0fcdb50de340b9260","https://git.kernel.org/stable/c/7ce2b00ff058ec4cafc9b447e1f0a6d6f49275d9","https://git.kernel.org/stable/c/8eed5519e496b7a07f441a0f579cb228a33189f7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: watchdog: fix refcount tracking races\n\nBlamed commit converted the untracked dev_hold()/dev_put() calls\nin the watchdog code to use the tracked dev_hold_track()/dev_put_track()\n(which were later renamed/interfaced to netdev_hold() and netdev_put()).\n\nBy introducing dev->watchdog_dev_tracker to store the\nreference tracking information without adding synchronization\nbetween netdev_watchdog_up() and dev_watchdog(), it enabled the\nrace condition where this pointer could be overwritten or freed\nconcurrently, leading to the list corruption crash syzbot reported:\n\nlist_del corruption, ffff888114a18c00->next is NULL\n kernel BUG at lib/list_debug.c:52 !\nOops: invalid opcode: 0000 [#1] SMP KASAN PTI\nCPU: 1 UID: 0 PID: 91 Comm: kworker/u8:5 Not tainted syzkaller #0 PREEMPT(lazy)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026\nWorkqueue: events_unbound linkwatch_event\n RIP: 0010:__list_del_entry_valid_or_report.cold+0x22/0x2a lib/list_debug.c:52\nCall Trace:\n <TASK>\n  __list_del_entry_valid include/linux/list.h:132 [inline]\n  __list_del_entry include/linux/list.h:246 [inline]\n  list_move_tail include/linux/list.h:341 [inline]\n  ref_tracker_free+0x1a7/0x6c0 lib/ref_tracker.c:329\n  netdev_tracker_free include/linux/netdevice.h:4491 [inline]\n  netdev_put include/linux/netdevice.h:4508 [inline]\n  netdev_put include/linux/netdevice.h:4504 [inline]\n  netdev_watchdog_down net/sched/sch_generic.c:600 [inline]\n  dev_deactivate_many+0x28c/0xfe0 net/sched/sch_generic.c:1363\n  dev_deactivate+0x109/0x1d0 net/sched/sch_generic.c:1397\n  linkwatch_do_dev net/core/link_watch.c:184 [inline]\n  linkwatch_do_dev+0xd3/0x120 net/core/link_watch.c:166\n  __linkwatch_run_queue+0x3a5/0x810 net/core/link_watch.c:240\n  linkwatch_event+0x8f/0xc0 net/core/link_watch.c:314\n  process_one_work+0xa0e/0x1980 kernel/workqueue.c:3314\n  process_scheduled_works kernel/workqueue.c:3397 [inline]\n  worker_thread+0x5ef/0xe50 kernel/workqueue.c:3478\n  kthread+0x370/0x450 kernel/kthread.c:436\n  ret_from_fork+0x69a/0xc80 arch/x86/kernel/process.c:158\n  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n\nThis patch has three coordinated parts:\n\n1) Add dev->watchdog_lock and dev->watchdog_ref_held to serialize watchdog operations.\n\n2) Remove netdev_watchdog_up() call from netif_carrier_on():\n   This ensures netdev_watchdog_up() is only called from process/BH context\n   (via linkwatch workqueue dev_activate()), allowing us to use\n   spin_lock_bh() for synchronization.\n\n3) Synchronize watchdog up and watchdog timer:\n   Protect netdev_watchdog_up() with tx_global_lock and watchdog_lock.\n   Only allocate a new tracker in netdev_watchdog_up() if one is\n   not already present.\n   In dev_watchdog(), ensure we don't release the tracker if the\n   timer was rescheduled either by dev_watchdog() itself or concurrently\n   by netdev_watchdog_up().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74264","epss":0.00162,"percentile":0.05673,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74264","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74268","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74268","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tcp: clear sock_ops cb flags before force-closing a child socket  A child socket inherits the listener's bpf_sock_ops_cb_flags via sk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() / tcp_v6_syn_recv_sock(), the child is freed through put_and_exit, where inet_csk_prepare_forced_close() drops the socket lock and tcp_done() runs without it.  If BPF_SOCK_OPS_STATE_CB_FLAG was inherited, tcp_done() -> tcp_set_state() calls tcp_call_bpf(), which expects the lock and trips sock_owned_by_me():    WARNING: include/net/sock.h:1799 at tcp_set_state+0x433/0x550   RIP: 0010:tcp_set_state+0x433/0x550 include/net/sock.h:1799   Call Trace:    <IRQ>    tcp_done+0xba/0x250 net/ipv4/tcp.c:5095    tcp_v4_syn_recv_sock+0x850/0xa50 net/ipv4/tcp_ipv4.c:1787    tcp_check_req+0xf30/0x1360 net/ipv4/tcp_minisocks.c:926    tcp_v4_rcv+0x1047/0x1b50 net/ipv4/tcp_ipv4.c:2164    </IRQ>  The child is freed before it is ever established, so it should run no sock_ops callback. Clear its cb flags in inet_csk_prepare_for_destroy_sock(), the common point for the IPv4, IPv6 and chtls forced-close paths and for the MPTCP ->syn_recv_sock() failure path (dispose_child), which reaches tcp_done() on a child that was never established too.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74268","epss":0.00598,"percentile":0.46634,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.5621200000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74268","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74268","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/8874dafc9099bc49c2e5ebba030f85d276421f92","https://git.kernel.org/stable/c/990348e5bb457697c2f1f7f7b65154a3334d9d2b","https://git.kernel.org/stable/c/ce311bd2e36596f0aa2c92ca86fb3e019ac57eae"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: clear sock_ops cb flags before force-closing a child socket\n\nA child socket inherits the listener's bpf_sock_ops_cb_flags via\nsk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() /\ntcp_v6_syn_recv_sock(), the child is freed through put_and_exit, where\ninet_csk_prepare_forced_close() drops the socket lock and tcp_done() runs\nwithout it.\n\nIf BPF_SOCK_OPS_STATE_CB_FLAG was inherited, tcp_done() -> tcp_set_state()\ncalls tcp_call_bpf(), which expects the lock and trips sock_owned_by_me():\n\n  WARNING: include/net/sock.h:1799 at tcp_set_state+0x433/0x550\n  RIP: 0010:tcp_set_state+0x433/0x550 include/net/sock.h:1799\n  Call Trace:\n   <IRQ>\n   tcp_done+0xba/0x250 net/ipv4/tcp.c:5095\n   tcp_v4_syn_recv_sock+0x850/0xa50 net/ipv4/tcp_ipv4.c:1787\n   tcp_check_req+0xf30/0x1360 net/ipv4/tcp_minisocks.c:926\n   tcp_v4_rcv+0x1047/0x1b50 net/ipv4/tcp_ipv4.c:2164\n   </IRQ>\n\nThe child is freed before it is ever established, so it should run no\nsock_ops callback. Clear its cb flags in inet_csk_prepare_for_destroy_sock(),\nthe common point for the IPv4, IPv6 and chtls forced-close paths and for the\nMPTCP ->syn_recv_sock() failure path (dispose_child), which reaches tcp_done()\non a child that was never established too.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74268","epss":0.00598,"percentile":0.46634,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74268","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74269","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74269","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bnxt: fix head underflow on XDP head-grow  The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on a bnxt machine (and also crashes in NIPA).  It seems that the bug is an underflow in bnxt_rx_multi_page_skb, which builds the skb head:    napi_build_skb(data_ptr - bp->rx_offset, rxr->rx_page_size);  The problem with this expression is that in page mode, rx_offset is:    bp->rx_offset = NET_IP_ALIGN + XDP_PACKET_HEADROOM;  Which evaluates (at least on x86_64) to 258.  The test test_xdp_native_adjst_head_grow_data tests a case where the head is adjusted by -256.  When this test runs, data_ptr is shifted to frag_start + 2 (where frag_start = page_address(page) + offset).  Then, bnxt_rx_multi_page_skb is invoked and the napi_build_skb expression subtracts 258, landing at an address before frag_start. This could be either the previous fragment or the previous physical page when the offset is < 256 (e.g. if the fragment started at offset 0).  When the skb is freed, the page pool fragment reference is dropped on either the wrong page or the wrong frag of the right page. In either case, the corrupted reference count can lead to the page being prematurely recycled while still in use. Once (incorrectly) recycled, it can be handed out again and on driver teardown this would result in a double free.  The commit under fixes updated this code to handle the case where the native page size is >= 64k, but it unintentionally broke the head grow case.  To fix this, add an offset field to struct bnxt_sw_rx_bd, mirroring the existing offset field in struct bnxt_sw_rx_agg_bd. Populate it on allocation and preserve it on reuse.  In bnxt_rx_multi_page_skb, use the newly added offset field to compute the fragment start and pass that to napi_build_skb. Adjust the layout with skb_reserve.  There are two cases, the non-adjustment case and the adjustment case.  In both cases, the skb is built at page_address(page) + offset to account for the case where the native page size >= 64K and skb_reserve is called with data_ptr - (page_address(page) + offset). That difference equals bp->rx_offset when data_ptr was not moved, or bp->rx_offset + xdp_adjust when XDP adjusted the head.  Re-running the failing test with this commit applied causes the test to run successfully to completion.  The other rx_skb_func implementations don't have this issue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74269","epss":0.0038,"percentile":0.31291,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3572},"relatedVulnerabilities":[{"id":"CVE-2026-74269","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74269","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/bb72b1c6755631c74b7e0878ee55bb81c06776c0","https://git.kernel.org/stable/c/e26657fe3b85c068b01f42bb0c602f242d643ba9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt: fix head underflow on XDP head-grow\n\nThe xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on\na bnxt machine (and also crashes in NIPA).\n\nIt seems that the bug is an underflow in bnxt_rx_multi_page_skb, which\nbuilds the skb head:\n\n  napi_build_skb(data_ptr - bp->rx_offset, rxr->rx_page_size);\n\nThe problem with this expression is that in page mode, rx_offset is:\n\n  bp->rx_offset = NET_IP_ALIGN + XDP_PACKET_HEADROOM;\n\nWhich evaluates (at least on x86_64) to 258.\n\nThe test test_xdp_native_adjst_head_grow_data tests a case where the\nhead is adjusted by -256.\n\nWhen this test runs, data_ptr is shifted to frag_start + 2 (where\nfrag_start = page_address(page) + offset).\n\nThen, bnxt_rx_multi_page_skb is invoked and the napi_build_skb\nexpression subtracts 258, landing at an address before frag_start. This\ncould be either the previous fragment or the previous physical page when\nthe offset is < 256 (e.g. if the fragment started at offset 0).\n\nWhen the skb is freed, the page pool fragment reference is dropped on\neither the wrong page or the wrong frag of the right page. In either\ncase, the corrupted reference count can lead to the page being\nprematurely recycled while still in use. Once (incorrectly) recycled, it\ncan be handed out again and on driver teardown this would result in a\ndouble free.\n\nThe commit under fixes updated this code to handle the case where the\nnative page size is >= 64k, but it unintentionally broke the head grow\ncase.\n\nTo fix this, add an offset field to struct bnxt_sw_rx_bd, mirroring the\nexisting offset field in struct bnxt_sw_rx_agg_bd. Populate it on\nallocation and preserve it on reuse.\n\nIn bnxt_rx_multi_page_skb, use the newly added offset field to compute\nthe fragment start and pass that to napi_build_skb. Adjust the layout\nwith skb_reserve.\n\nThere are two cases, the non-adjustment case and the adjustment case.\n\nIn both cases, the skb is built at page_address(page) + offset to\naccount for the case where the native page size >= 64K and skb_reserve\nis called with data_ptr - (page_address(page) + offset). That\ndifference equals bp->rx_offset when data_ptr was not moved, or\nbp->rx_offset + xdp_adjust when XDP adjusted the head.\n\nRe-running the failing test with this commit applied causes the test to\nrun successfully to completion.\n\nThe other rx_skb_func implementations don't have this issue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74269","epss":0.0038,"percentile":0.31291,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74269","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74272","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74272","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  cxl/region: Resolve region deletion races  Sungwoo noticed that the sysfs trigger to delete a region may try to delete a region multiple times. It also has no exclusion relative to the kernel releasing the region via CXL root device teardown.  Instead of installing new cxl root devres actions per region, use the existing root decoder unregistration event to remove all remaining regions. An xarray of regions replaces a devres list of regions.  This handles 3 separate issues with the old approach:  1/ sysfs users racing to delete the same region: no longer possible now    that the regions_lock is held over the lookup and deletion.  2/ multiple actions triggering deletion of the same region: solved by    erasing regions while holding @regions_lock, and only proceeding on    successful erasure.  3/ userspace racing devres_release_all() to trigger the devres not found    warning: solved by sysfs unregistration not requiring a release action","cvss":[],"epss":[{"cve":"CVE-2026-74272","epss":0.00155,"percentile":0.05025,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-74272","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74272","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4dd86ca99ffcc413cbf79063fd9956ef54e0ca91","https://git.kernel.org/stable/c/be44c1c04f85d7b7ac1c597a30b443bbd346acbd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Resolve region deletion races\n\nSungwoo noticed that the sysfs trigger to delete a region may try to delete\na region multiple times. It also has no exclusion relative to the kernel\nreleasing the region via CXL root device teardown.\n\nInstead of installing new cxl root devres actions per region, use the\nexisting root decoder unregistration event to remove all remaining regions.\nAn xarray of regions replaces a devres list of regions.\n\nThis handles 3 separate issues with the old approach:\n\n1/ sysfs users racing to delete the same region: no longer possible now\n   that the regions_lock is held over the lookup and deletion.\n\n2/ multiple actions triggering deletion of the same region: solved by\n   erasing regions while holding @regions_lock, and only proceeding on\n   successful erasure.\n\n3/ userspace racing devres_release_all() to trigger the devres not found\n   warning: solved by sysfs unregistration not requiring a release action","cvss":[],"epss":[{"cve":"CVE-2026-74272","epss":0.00155,"percentile":0.05025,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74272","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74278","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74278","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: seq: Fix kernel heap address leak in bounce_error_event()  The comment above bounce_error_event() documents that user clients should receive SNDRV_SEQ_EVENT_BOUNCE with the original event embedded as variable-length data, while kernel clients should receive SNDRV_SEQ_EVENT_KERNEL_ERROR with a quoted kernel pointer.  However, the implementation unconditionally uses SNDRV_SEQ_EVENT_KERNEL_ERROR with data.quote.event set to the raw struct snd_seq_event pointer for all clients.  When a bounce error event is delivered to a USER_CLIENT via snd_seq_read(), the kernel heap address in data.quote.event is exposed to userspace through copy_to_user() in the fixed-length branch.  This is a distinct leak path from the one addressed by commit 705dd6dcbc0e (\"ALSA: seq: Clear variable event pointer on read\"), which sanitizes data.ext.ptr in the variable-length branch of snd_seq_read().  The bounce_error_event() leak uses fixed-length events that take the else branch where no sanitization occurs.  Differentiate the bounce event by client type.  For USER_CLIENT, send SNDRV_SEQ_EVENT_BOUNCE with SNDRV_SEQ_EVENT_LENGTH_VARIABLE and data.ext pointing to the original event.  The variable-length path in snd_seq_event_dup() copies the event data into chained cells, and snd_seq_expand_var_event() copies only the content -- never the pointer -- to userspace.  For KERNEL_CLIENT, keep the existing SNDRV_SEQ_EVENT_KERNEL_ERROR behavior with the quoted pointer.","cvss":[],"epss":[{"cve":"CVE-2026-74278","epss":0.00168,"percentile":0.06345,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74278","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74278","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0527a56cb327021cb73167cfddf0e49efa043500","https://git.kernel.org/stable/c/93d260ce43a81df579c98bee92b91316df9c1c57","https://git.kernel.org/stable/c/dae23c545eb5a2be3b27a82fd0f611894fb8ab69","https://git.kernel.org/stable/c/efc86691e4d8083d9e380ea95042c2cf679f65fd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix kernel heap address leak in bounce_error_event()\n\nThe comment above bounce_error_event() documents that user clients\nshould receive SNDRV_SEQ_EVENT_BOUNCE with the original event embedded\nas variable-length data, while kernel clients should receive\nSNDRV_SEQ_EVENT_KERNEL_ERROR with a quoted kernel pointer.\n\nHowever, the implementation unconditionally uses\nSNDRV_SEQ_EVENT_KERNEL_ERROR with data.quote.event set to the raw\nstruct snd_seq_event pointer for all clients.  When a bounce error\nevent is delivered to a USER_CLIENT via snd_seq_read(), the kernel\nheap address in data.quote.event is exposed to userspace through\ncopy_to_user() in the fixed-length branch.\n\nThis is a distinct leak path from the one addressed by commit\n705dd6dcbc0e (\"ALSA: seq: Clear variable event pointer on read\"),\nwhich sanitizes data.ext.ptr in the variable-length branch of\nsnd_seq_read().  The bounce_error_event() leak uses fixed-length\nevents that take the else branch where no sanitization occurs.\n\nDifferentiate the bounce event by client type.  For USER_CLIENT,\nsend SNDRV_SEQ_EVENT_BOUNCE with SNDRV_SEQ_EVENT_LENGTH_VARIABLE\nand data.ext pointing to the original event.  The variable-length\npath in snd_seq_event_dup() copies the event data into chained\ncells, and snd_seq_expand_var_event() copies only the content --\nnever the pointer -- to userspace.  For KERNEL_CLIENT, keep the\nexisting SNDRV_SEQ_EVENT_KERNEL_ERROR behavior with the quoted\npointer.","cvss":[],"epss":[{"cve":"CVE-2026-74278","epss":0.00168,"percentile":0.06345,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74278","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74289","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74289","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: fib: Don't dump dying fib_info in fib_leaf_notify().  syzbot reported use-after-free in nsim_fib4_prepare_event(). [0]  The problem is that the following functions call fib_info_hold() / refcount_inc() while dumping fib_info under RCU, which is unsafe.    * mlxsw_sp_router_fib4_event()   * rocker_router_fib_event()   * nsim_fib4_prepare_event()  refcount_inc_not_zero() must be used, but it would be too late there.  Let's guarantee the lifetime of fib_info in fib_leaf_notify().  Note that IPv6 does not need the corresponding change since fib6_table_dump() holds fib6_table.tb6_lock.  [0]: refcount_t: addition on 0; use-after-free. WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#0: kworker/u8:15/3420 Modules linked in: CPU: 0 UID: 0 PID: 3420 Comm: kworker/u8:15 Not tainted syzkaller #0 PREEMPT_{RT,(full)} Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026 Workqueue: netns cleanup_net RIP: 0010:refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25 Code: eb 66 85 db 74 3e 83 fb 01 75 4c e8 1b f1 22 fd 48 8d 3d 84 cb f1 0a 67 48 0f b9 3a eb 4a e8 08 f1 22 fd 48 8d 3d 81 cb f1 0a <67> 48 0f b9 3a eb 37 e8 f5 f0 22 fd 48 8d 3d 7e cb f1 0a 67 48 0f RSP: 0018:ffffc9000f2c7270 EFLAGS: 00010293 RAX: ffffffff84a18858 RBX: 0000000000000002 RCX: ffff888032ff9ec0 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8f9353e0 RBP: 0000000000000000 R08: ffff888032ff9ec0 R09: 0000000000000005 R10: 0000000000000100 R11: 0000000000000004 R12: ffff8880570cc000 R13: dffffc0000000000 R14: ffff88802b40563c R15: ffff8880570cc000 FS:  0000000000000000(0000) GS:ffff888126173000(0000) knlGS:0000000000000000 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fb1f4d5d000 CR3: 000000006072a000 CR4: 00000000003526f0 Call Trace:  <TASK>  __refcount_add include/linux/refcount.h:-1 [inline]  __refcount_inc include/linux/refcount.h:366 [inline]  refcount_inc include/linux/refcount.h:383 [inline]  fib_info_hold include/net/ip_fib.h:629 [inline]  nsim_fib4_prepare_event drivers/net/netdevsim/fib.c:930 [inline]  nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1000 [inline]  nsim_fib_event_nb+0x1055/0x1240 drivers/net/netdevsim/fib.c:1043  call_fib_notifier+0x45/0x80 net/core/fib_notifier.c:25  call_fib_entry_notifier net/ipv4/fib_trie.c:90 [inline]  fib_leaf_notify net/ipv4/fib_trie.c:2176 [inline]  fib_table_notify net/ipv4/fib_trie.c:2194 [inline]  fib_notify+0x36b/0x5e0 net/ipv4/fib_trie.c:2217  fib_net_dump net/core/fib_notifier.c:70 [inline]  register_fib_notifier+0x184/0x360 net/core/fib_notifier.c:108  nsim_fib_create+0x85d/0x9f0 drivers/net/netdevsim/fib.c:1596  nsim_dev_reload_create drivers/net/netdevsim/dev.c:1604 [inline]  nsim_dev_reload_up+0x374/0x7c0 drivers/net/netdevsim/dev.c:1058  devlink_reload+0x501/0x8d0 net/devlink/dev.c:475  devlink_pernet_pre_exit+0x1ff/0x420 net/devlink/core.c:558  ops_pre_exit_list net/core/net_namespace.c:161 [inline]  ops_undo_list+0x187/0x940 net/core/net_namespace.c:234  cleanup_net+0x56e/0x800 net/core/net_namespace.c:702  process_one_work kernel/workqueue.c:3314 [inline]  process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397  worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478  kthread+0x388/0x470 kernel/kthread.c:436  ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245  </TASK>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74289","epss":0.0012,"percentile":0.02112,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74289","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74289","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/06b693d2eb6651a63ad85bad8673de3b7d4edd6d","https://git.kernel.org/stable/c/676482da8d938ea72c26da0fc86af2d2ec238ab2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: Don't dump dying fib_info in fib_leaf_notify().\n\nsyzbot reported use-after-free in nsim_fib4_prepare_event(). [0]\n\nThe problem is that the following functions call fib_info_hold() /\nrefcount_inc() while dumping fib_info under RCU, which is unsafe.\n\n  * mlxsw_sp_router_fib4_event()\n  * rocker_router_fib_event()\n  * nsim_fib4_prepare_event()\n\nrefcount_inc_not_zero() must be used, but it would be too late\nthere.\n\nLet's guarantee the lifetime of fib_info in fib_leaf_notify().\n\nNote that IPv6 does not need the corresponding change since\nfib6_table_dump() holds fib6_table.tb6_lock.\n\n[0]:\nrefcount_t: addition on 0; use-after-free.\nWARNING: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#0: kworker/u8:15/3420\nModules linked in:\nCPU: 0 UID: 0 PID: 3420 Comm: kworker/u8:15 Not tainted syzkaller #0 PREEMPT_{RT,(full)}\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026\nWorkqueue: netns cleanup_net\nRIP: 0010:refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25\nCode: eb 66 85 db 74 3e 83 fb 01 75 4c e8 1b f1 22 fd 48 8d 3d 84 cb f1 0a 67 48 0f b9 3a eb 4a e8 08 f1 22 fd 48 8d 3d 81 cb f1 0a <67> 48 0f b9 3a eb 37 e8 f5 f0 22 fd 48 8d 3d 7e cb f1 0a 67 48 0f\nRSP: 0018:ffffc9000f2c7270 EFLAGS: 00010293\nRAX: ffffffff84a18858 RBX: 0000000000000002 RCX: ffff888032ff9ec0\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8f9353e0\nRBP: 0000000000000000 R08: ffff888032ff9ec0 R09: 0000000000000005\nR10: 0000000000000100 R11: 0000000000000004 R12: ffff8880570cc000\nR13: dffffc0000000000 R14: ffff88802b40563c R15: ffff8880570cc000\nFS:  0000000000000000(0000) GS:ffff888126173000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fb1f4d5d000 CR3: 000000006072a000 CR4: 00000000003526f0\nCall Trace:\n <TASK>\n __refcount_add include/linux/refcount.h:-1 [inline]\n __refcount_inc include/linux/refcount.h:366 [inline]\n refcount_inc include/linux/refcount.h:383 [inline]\n fib_info_hold include/net/ip_fib.h:629 [inline]\n nsim_fib4_prepare_event drivers/net/netdevsim/fib.c:930 [inline]\n nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1000 [inline]\n nsim_fib_event_nb+0x1055/0x1240 drivers/net/netdevsim/fib.c:1043\n call_fib_notifier+0x45/0x80 net/core/fib_notifier.c:25\n call_fib_entry_notifier net/ipv4/fib_trie.c:90 [inline]\n fib_leaf_notify net/ipv4/fib_trie.c:2176 [inline]\n fib_table_notify net/ipv4/fib_trie.c:2194 [inline]\n fib_notify+0x36b/0x5e0 net/ipv4/fib_trie.c:2217\n fib_net_dump net/core/fib_notifier.c:70 [inline]\n register_fib_notifier+0x184/0x360 net/core/fib_notifier.c:108\n nsim_fib_create+0x85d/0x9f0 drivers/net/netdevsim/fib.c:1596\n nsim_dev_reload_create drivers/net/netdevsim/dev.c:1604 [inline]\n nsim_dev_reload_up+0x374/0x7c0 drivers/net/netdevsim/dev.c:1058\n devlink_reload+0x501/0x8d0 net/devlink/dev.c:475\n devlink_pernet_pre_exit+0x1ff/0x420 net/devlink/core.c:558\n ops_pre_exit_list net/core/net_namespace.c:161 [inline]\n ops_undo_list+0x187/0x940 net/core/net_namespace.c:234\n cleanup_net+0x56e/0x800 net/core/net_namespace.c:702\n process_one_work kernel/workqueue.c:3314 [inline]\n process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397\n worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478\n kthread+0x388/0x470 kernel/kthread.c:436\n ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n </TASK>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74289","epss":0.0012,"percentile":0.02112,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74289","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74291","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74291","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: topology: Check PCM and DAI name strings before use  Topology objects store several PCM and DAI names in fixed-size UAPI arrays. Other topology parser paths validate these fields with bounded strnlen() checks before using them as C strings, but the PCM and DAI paths still pass some fixed-size arrays directly to strlen(), devm_kstrdup(), DAI lookup, and diagnostic prints.  A malformed topology blob with a non-NUL-terminated PCM, DAI, or stream capability name can therefore make the parser read past the end of the fixed-size field.  Reject unterminated PCM and DAI name fields before consuming them as C strings.","cvss":[],"epss":[{"cve":"CVE-2026-74291","epss":0.00155,"percentile":0.05024,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-74291","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74291","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/b7e44d1986d6671342c19b82192189ca5db5dab7","https://git.kernel.org/stable/c/ba37b62ed0a443b8e23f53a7477e7f2537fd34c7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: topology: Check PCM and DAI name strings before use\n\nTopology objects store several PCM and DAI names in fixed-size UAPI\narrays. Other topology parser paths validate these fields with bounded\nstrnlen() checks before using them as C strings, but the PCM and DAI\npaths still pass some fixed-size arrays directly to strlen(),\ndevm_kstrdup(), DAI lookup, and diagnostic prints.\n\nA malformed topology blob with a non-NUL-terminated PCM, DAI, or stream\ncapability name can therefore make the parser read past the end of the\nfixed-size field.\n\nReject unterminated PCM and DAI name fields before consuming them as C\nstrings.","cvss":[],"epss":[{"cve":"CVE-2026-74291","epss":0.00155,"percentile":0.05024,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74291","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74294","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74294","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: meson: aiu: Validate written enum values  The AIU HDMI and internal codec mux put callbacks use the written enum value with snd_soc_enum_item_to_val() before checking whether the value is valid for the enumeration.  Reject out-of-range values before converting the enum item, matching the validation already done by the G12A HDMI and internal codec mux controls.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74294","epss":0.00114,"percentile":0.01695,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08435999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74294","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74294","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0965892cc486ca554d72eeb62d85ccf8d0137a5a","https://git.kernel.org/stable/c/d65adf85477247be04ac86886f8edfaa047b5d4a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: meson: aiu: Validate written enum values\n\nThe AIU HDMI and internal codec mux put callbacks use the written enum\nvalue with snd_soc_enum_item_to_val() before checking whether the value is\nvalid for the enumeration.\n\nReject out-of-range values before converting the enum item, matching the\nvalidation already done by the G12A HDMI and internal codec mux controls.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74294","epss":0.00114,"percentile":0.01695,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74294","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74302","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74302","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_core: Fix UAF in hci_unregister_dev()  hci_unregister_dev() does not disable cmd_timer and ncmd_timer before the hci_dev structure is freed. If a timeout fires during device teardown, the callback dereferences freed memory (including the hdev->reset function pointer), leading to a use-after-free.  Add disable_delayed_work_sync() calls alongside the existing disable_work_sync() calls to ensure both timers are fully quiesced before teardown proceeds.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74302","epss":0.00125,"percentile":0.02517,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-74302","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74302","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/48c7ad6afcc58c2cda11fed39791708103b6a644","https://git.kernel.org/stable/c/5edcc018fa6e80b2c478454a4a8229c23d67c181","https://git.kernel.org/stable/c/672d52d9412252e61b8de8d773ccdf5a277cf540","https://git.kernel.org/stable/c/a0fd1086a57b982f8c24ae4ab165c2af39fe1735"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix UAF in hci_unregister_dev()\n\nhci_unregister_dev() does not disable cmd_timer and ncmd_timer\nbefore the hci_dev structure is freed. If a timeout fires\nduring device teardown, the callback dereferences freed memory\n(including the hdev->reset function pointer), leading to a\nuse-after-free.\n\nAdd disable_delayed_work_sync() calls alongside the existing\ndisable_work_sync() calls to ensure both timers are fully\nquiesced before teardown proceeds.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74302","epss":0.00125,"percentile":0.02517,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74302","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74307","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74307","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT  Reject the EXT4_IOC_MOVE_EXT ioctl early if the donor file does not belong to the same superblock as the original file.  Currently, this validation is performed inside ext4_move_extents() by mext_check_validity(), but only after lock_two_nondirectories() has already acquired the inode locks.  When the donor fd refers to a file on a different filesystem (e.g., overlayfs), this late validation creates a circular lock dependency:    CPU0 (overlayfs write)            CPU1 (ext4 ioctl)   ----                              ----   inode_lock(ovl_inode)                                     mnt_want_write_file(filp)                                       sb_start_write(ext4_sb)   [sb_writers]     backing_file_write_iter()       vfs_iter_write(real_file)         file_start_write(real_file)           sb_start_write(ext4_sb)   [blocked by freeze]                                     lock_two_nondirectories()                                       inode_lock(ovl_inode)     [blocked]  With a concurrent freeze operation holding sb_writers write side, this forms a deadlock cycle: CPU0 waits for freeze to complete, freeze waits for CPU1's sb_writers reader to exit, CPU1 waits for CPU0's inode lock.  Since EXT4_IOC_MOVE_EXT exchanges physical extents between two files, it fundamentally requires both files to reside on the same ext4 filesystem.  Moving the superblock check before any lock acquisition is both semantically correct and eliminates the circular dependency by ensuring that cross-filesystem donor fds are rejected before sb_writers or inode locks are taken.","cvss":[],"epss":[{"cve":"CVE-2026-74307","epss":0.00166,"percentile":0.06148,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-74307","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74307","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/74796e886ca39fcb0d3fd36ea6a39c62784ab6fb","https://git.kernel.org/stable/c/c143957520c6c9b5cd72e0de8b52b814f0c576fe","https://git.kernel.org/stable/c/fb52013cad9e9b7d3a6a14ea1bcd841e41da7c6c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate donor file superblock early in EXT4_IOC_MOVE_EXT\n\nReject the EXT4_IOC_MOVE_EXT ioctl early if the donor file does not\nbelong to the same superblock as the original file.  Currently, this\nvalidation is performed inside ext4_move_extents() by\nmext_check_validity(), but only after lock_two_nondirectories() has\nalready acquired the inode locks.  When the donor fd refers to a file\non a different filesystem (e.g., overlayfs), this late validation\ncreates a circular lock dependency:\n\n  CPU0 (overlayfs write)            CPU1 (ext4 ioctl)\n  ----                              ----\n  inode_lock(ovl_inode)\n                                    mnt_want_write_file(filp)\n                                      sb_start_write(ext4_sb)   [sb_writers]\n    backing_file_write_iter()\n      vfs_iter_write(real_file)\n        file_start_write(real_file)\n          sb_start_write(ext4_sb)   [blocked by freeze]\n                                    lock_two_nondirectories()\n                                      inode_lock(ovl_inode)     [blocked]\n\nWith a concurrent freeze operation holding sb_writers write side, this\nforms a deadlock cycle: CPU0 waits for freeze to complete, freeze waits\nfor CPU1's sb_writers reader to exit, CPU1 waits for CPU0's inode lock.\n\nSince EXT4_IOC_MOVE_EXT exchanges physical extents between two files,\nit fundamentally requires both files to reside on the same ext4\nfilesystem.  Moving the superblock check before any lock acquisition\nis both semantically correct and eliminates the circular dependency\nby ensuring that cross-filesystem donor fds are rejected before\nsb_writers or inode locks are taken.","cvss":[],"epss":[{"cve":"CVE-2026-74307","epss":0.00166,"percentile":0.06148,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74307","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74308","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74308","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: fix kernel BUG in ext4_write_inline_data_end  When the data=journal mount option is used, the ext4_journalled_write_end() function incorrectly calls ext4_write_inline_data_end() without checking if the EXT4_STATE_MAY_INLINE_DATA flag is still set on the inode.  If a previous attempt to convert the inline data to an extent failed (e.g. due to ENOSPC), the EXT4_STATE_MAY_INLINE_DATA flag is cleared, but the EXT4_INODE_INLINE_DATA flag remains set. In this scenario, the next call to ext4_write_begin() will not prepare the inline data xattr for writing, but ext4_journalled_write_end() will incorrectly attempt to write to it, triggering a BUG_ON(pos + len > EXT4_I(inode)->i_inline_size) in ext4_write_inline_data() since i_inline_size was not expanded.  Fix this by ensuring that ext4_journalled_write_end() only calls ext4_write_inline_data_end() if the EXT4_STATE_MAY_INLINE_DATA flag is set, mirroring the behavior of ext4_write_end() and ext4_da_write_end().","cvss":[],"epss":[{"cve":"CVE-2026-74308","epss":0.00168,"percentile":0.06342,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74308","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74308","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0ae42b51607240990614e0843f0d3529aaff62cc","https://git.kernel.org/stable/c/260830a9a706f5d335398236fc788ce32f220de1","https://git.kernel.org/stable/c/9808ae9fae996afa942bd963a39c9b1cdeebd0bd","https://git.kernel.org/stable/c/ad09aa45965d3fafaf9963bc78109b73c0f9ac8d","https://git.kernel.org/stable/c/f00f5c0dd55319bc33b76f72c853bda0e0a32eda"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix kernel BUG in ext4_write_inline_data_end\n\nWhen the data=journal mount option is used, the ext4_journalled_write_end()\nfunction incorrectly calls ext4_write_inline_data_end() without checking\nif the EXT4_STATE_MAY_INLINE_DATA flag is still set on the inode.\n\nIf a previous attempt to convert the inline data to an extent failed (e.g.\ndue to ENOSPC), the EXT4_STATE_MAY_INLINE_DATA flag is cleared, but\nthe EXT4_INODE_INLINE_DATA flag remains set. In this scenario, the next\ncall to ext4_write_begin() will not prepare the inline data xattr for\nwriting, but ext4_journalled_write_end() will incorrectly attempt to write\nto it, triggering a BUG_ON(pos + len > EXT4_I(inode)->i_inline_size) in\next4_write_inline_data() since i_inline_size was not expanded.\n\nFix this by ensuring that ext4_journalled_write_end() only calls\next4_write_inline_data_end() if the EXT4_STATE_MAY_INLINE_DATA flag is\nset, mirroring the behavior of ext4_write_end() and ext4_da_write_end().","cvss":[],"epss":[{"cve":"CVE-2026-74308","epss":0.00168,"percentile":0.06342,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74308","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74314","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74314","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Cancel special fields on map value recycle  Map update and delete paths currently call bpf_obj_free_fields() when a value is being replaced or recycled. That makes field destruction depend on the context of the update/delete operation. For tracing programs this can include NMI context, where referenced kptr destructors, uptr unpinning, and graph root destruction are not generally safe.  Introduce bpf_obj_cancel_fields() for the reusable-value path. It only performs NMI-safe cleanup for timer, workqueue, and task_work fields. Fields that need full destruction are left attached to the recycled value and are destroyed by the final cleanup path instead.  Switch array and hashtab update/delete/recycle paths to this cancel helper. Keep bpf_obj_free_fields() for final map destruction and for bpf_mem_alloc destructors. Preallocated hashtabs do not have allocator destructors, so teardown continues to walk the normal and extra elements and fully destroy their fields.  This deliberately relaxes the eager-free semantics of map update/delete for special fields. Programs that relied on a recycled map slot becoming empty immediately after update/delete were relying on behavior that cannot be implemented safely from every BPF execution context without offloading arbitrary destructors.  There is a chance this change breaks programs making assumptions regarding the eager freeing of fields. If so, we can relax semantics to cancellation only when irqs_disabled() is true in the future. However, theoretically, map values that get reused eagerly already have weaker guarantees as parallel users can recreate freed fields before the new element becomes visible again.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74314","epss":0.00129,"percentile":0.02867,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74314","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74314","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/9ea734e2cc0143d7429ab7dc0b20c85e5836183c","https://git.kernel.org/stable/c/a3a81d247651218e47153f2d2afd7aee236726fd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Cancel special fields on map value recycle\n\nMap update and delete paths currently call bpf_obj_free_fields() when a\nvalue is being replaced or recycled. That makes field destruction depend\non the context of the update/delete operation. For tracing programs this\ncan include NMI context, where referenced kptr destructors, uptr\nunpinning, and graph root destruction are not generally safe.\n\nIntroduce bpf_obj_cancel_fields() for the reusable-value path. It only\nperforms NMI-safe cleanup for timer, workqueue, and task_work fields.\nFields that need full destruction are left attached to the recycled value\nand are destroyed by the final cleanup path instead.\n\nSwitch array and hashtab update/delete/recycle paths to this cancel\nhelper. Keep bpf_obj_free_fields() for final map destruction and for\nbpf_mem_alloc destructors. Preallocated hashtabs do not have allocator\ndestructors, so teardown continues to walk the normal and extra elements\nand fully destroy their fields.\n\nThis deliberately relaxes the eager-free semantics of map update/delete\nfor special fields. Programs that relied on a recycled map slot becoming\nempty immediately after update/delete were relying on behavior that\ncannot be implemented safely from every BPF execution context without\noffloading arbitrary destructors.\n\nThere is a chance this change breaks programs making assumptions\nregarding the eager freeing of fields. If so, we can relax semantics to\ncancellation only when irqs_disabled() is true in the future. However,\ntheoretically, map values that get reused eagerly already have weaker\nguarantees as parallel users can recreate freed fields before the new\nelement becomes visible again.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74314","epss":0.00129,"percentile":0.02867,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74314","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74317","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74317","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ixgbe: do not configure xps for XDP queues  netif_set_xps_queue() should not be called for an XDP Tx queue, since such queues are not netdev-exposed. On systems with number of CPUs >=64, on E610 adapter, netdev is configured with maximum number queue pairs being 63 (due to MSI-X assignment), but configuring XDP results in 64 XDP queues.  So, during XDP program load, when netif_set_xps_queue() is called for the last XDP queue, we get a WARNING with a call trace and KASAN report afterwards (if enabled).  [ 2012.699800] WARNING: net/core/dev.c:2854 at __netif_set_xps_queue+0x116a/0x1e40, CPU#36: xdpsock/103668 [...] [ 2012.700029] RIP: 0010:__netif_set_xps_queue+0x116a/0x1e40 [ 2012.700035] Code: b6 34 06 48 89 f8 83 e0 07 83 c0 01 40 38 f0 7c 09 40 84 f6 0f 85 03 0a 00 00 0f b7 44 24 40 66 43 89 44 6a 18 e9 01 fb ff ff <0f> 0b e9 f2 ee ff ff 44 8b 44 24 44 45 85 c0 74 50 4d 85 e4 0f 84 [ 2012.700040] RSP: 0018:ffff8882369aeb28 EFLAGS: 00010246 [ 2012.700046] RAX: 0000000000000000 RBX: 000000000000003f RCX: 0000000000000000 [ 2012.700050] RDX: 1ffff1111da3d891 RSI: ffff888120e34250 RDI: ffff8888ed1ec488 [ 2012.700054] RBP: ffff888913281560 R08: 0000000000000000 R09: ffff8888ed1ec000 [ 2012.700058] R10: ffff8888a2e83180 R11: 0000000000000000 R12: 0000000000007fa8 [ 2012.700061] R13: 000000000000003f R14: ffff888120e34854 R15: ffff8889132817c8 [ 2012.700065] FS:  00007fc8ea9ff740(0000) GS:ffff88884cefe000(0000) knlGS:0000000000000000 [ 2012.700069] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 2012.700073] CR2: 00007f81c8000020 CR3: 00000002299f8006 CR4: 00000000007726f0 [ 2012.700077] PKRU: 55555554 [ 2012.700080] Call Trace: [ 2012.700084]  <TASK> [ 2012.700087]  ? ktime_get+0x61/0x150 [ 2012.700097]  ? usleep_range_state+0x133/0x1b0 [ 2012.700108]  ? __pfx_usleep_range_state+0x10/0x10 [ 2012.700114]  netif_set_xps_queue+0x31/0x50 [ 2012.700119]  ixgbe_configure_tx_ring+0x472/0x920 [ixgbe] [...] [ 2012.700486]  ixgbe_xdp+0x38f/0x750 [ixgbe]  [...]  [ 2012.701094] BUG: KASAN: slab-out-of-bounds in __netif_set_xps_queue+0x1ac5/0x1e40 [ 2012.701100] Write of size 4 at addr ffff88888d43cff8 by task xdpsock/103668  Skip XPS configuration for XDP Tx queues.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74317","epss":0.0012,"percentile":0.02109,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74317","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74317","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7bd4355272de34c2e90e34b72c5613736d03c32b","https://git.kernel.org/stable/c/a2a224f5e344ccb1ec3693a0735822db9214e2ca"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nixgbe: do not configure xps for XDP queues\n\nnetif_set_xps_queue() should not be called for an XDP Tx queue, since such\nqueues are not netdev-exposed. On systems with number of CPUs >=64, on E610\nadapter, netdev is configured with maximum number queue pairs being 63\n(due to MSI-X assignment), but configuring XDP results in 64 XDP queues.\n\nSo, during XDP program load, when netif_set_xps_queue() is called for the\nlast XDP queue, we get a WARNING with a call trace and KASAN report\nafterwards (if enabled).\n\n[ 2012.699800] WARNING: net/core/dev.c:2854 at __netif_set_xps_queue+0x116a/0x1e40, CPU#36: xdpsock/103668\n[...]\n[ 2012.700029] RIP: 0010:__netif_set_xps_queue+0x116a/0x1e40\n[ 2012.700035] Code: b6 34 06 48 89 f8 83 e0 07 83 c0 01 40 38 f0 7c 09 40 84 f6 0f 85 03 0a 00 00 0f b7 44 24 40 66 43 89 44 6a 18 e9 01 fb ff ff <0f> 0b e9 f2 ee ff ff 44 8b 44 24 44 45 85 c0 74 50 4d 85 e4 0f 84\n[ 2012.700040] RSP: 0018:ffff8882369aeb28 EFLAGS: 00010246\n[ 2012.700046] RAX: 0000000000000000 RBX: 000000000000003f RCX: 0000000000000000\n[ 2012.700050] RDX: 1ffff1111da3d891 RSI: ffff888120e34250 RDI: ffff8888ed1ec488\n[ 2012.700054] RBP: ffff888913281560 R08: 0000000000000000 R09: ffff8888ed1ec000\n[ 2012.700058] R10: ffff8888a2e83180 R11: 0000000000000000 R12: 0000000000007fa8\n[ 2012.700061] R13: 000000000000003f R14: ffff888120e34854 R15: ffff8889132817c8\n[ 2012.700065] FS:  00007fc8ea9ff740(0000) GS:ffff88884cefe000(0000) knlGS:0000000000000000\n[ 2012.700069] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 2012.700073] CR2: 00007f81c8000020 CR3: 00000002299f8006 CR4: 00000000007726f0\n[ 2012.700077] PKRU: 55555554\n[ 2012.700080] Call Trace:\n[ 2012.700084]  <TASK>\n[ 2012.700087]  ? ktime_get+0x61/0x150\n[ 2012.700097]  ? usleep_range_state+0x133/0x1b0\n[ 2012.700108]  ? __pfx_usleep_range_state+0x10/0x10\n[ 2012.700114]  netif_set_xps_queue+0x31/0x50\n[ 2012.700119]  ixgbe_configure_tx_ring+0x472/0x920 [ixgbe]\n[...]\n[ 2012.700486]  ixgbe_xdp+0x38f/0x750 [ixgbe]\n\n[...]\n\n[ 2012.701094] BUG: KASAN: slab-out-of-bounds in __netif_set_xps_queue+0x1ac5/0x1e40\n[ 2012.701100] Write of size 4 at addr ffff88888d43cff8 by task xdpsock/103668\n\nSkip XPS configuration for XDP Tx queues.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74317","epss":0.0012,"percentile":0.02109,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74317","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74318","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74318","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix deadlock cloning inline extent when using flushoncommit  In commit b48c980b6a7e (\"btrfs: fix deadlock between reflink and transaction commit when using flushoncommit\") a deadlock was fixed between reflinks and transaction commits when the fs is mounted with the flushoncommit option. This happened when we had to copy an inline extent's data to the destination file. However the issue was fixed only for the case where the destination offset is 0, it missed the case when the offset is greater than zero.  Fix this by ensuring we get i_size update whenever we copied an inline extent's data into the destination file.  Syzbot reported this with the following trace:     INFO: task kworker/u8:3:57 blocked for more than 143 seconds.          Not tainted syzkaller #0    \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.    task:kworker/u8:3    state:D stack:21600 pid:57    tgid:57    ppid:2      task_flags:0x4208160 flags:0x00080000    Workqueue: writeback wb_workfn (flush-btrfs-129)    Call Trace:     <TASK>     context_switch kernel/sched/core.c:5402 [inline]     __schedule+0x16f9/0x5500 kernel/sched/core.c:7204     __schedule_loop kernel/sched/core.c:7283 [inline]     schedule+0x164/0x360 kernel/sched/core.c:7298     wait_extent_bit fs/btrfs/extent-io-tree.c:905 [inline]     btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:2008     btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline]     btrfs_invalidate_folio+0x440/0xc00 fs/btrfs/inode.c:7718     extent_writepage fs/btrfs/extent_io.c:1848 [inline]     extent_write_cache_pages fs/btrfs/extent_io.c:2552 [inline]     btrfs_writepages+0x12f3/0x2410 fs/btrfs/extent_io.c:2684     do_writepages+0x32e/0x550 mm/page-writeback.c:2571     __writeback_single_inode+0x133/0x10e0 fs/fs-writeback.c:1764     writeback_sb_inodes+0x97f/0x1980 fs/fs-writeback.c:2056     wb_writeback+0x445/0xb00 fs/fs-writeback.c:2241     wb_do_writeback fs/fs-writeback.c:2388 [inline]     wb_workfn+0x3fd/0xf20 fs/fs-writeback.c:2428     process_one_work+0x98b/0x1630 kernel/workqueue.c:3318     process_scheduled_works kernel/workqueue.c:3401 [inline]     worker_thread+0xb49/0x1140 kernel/workqueue.c:3482     kthread+0x388/0x470 kernel/kthread.c:436     ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158     ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245     </TASK>    INFO: task syz.0.145:8523 blocked for more than 143 seconds.          Not tainted syzkaller #0    \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.    task:syz.0.145       state:D stack:22752 pid:8523  tgid:8522  ppid:5850   task_flags:0x400140 flags:0x00080002    Call Trace:     <TASK>     context_switch kernel/sched/core.c:5402 [inline]     __schedule+0x16f9/0x5500 kernel/sched/core.c:7204     __schedule_loop kernel/sched/core.c:7283 [inline]     schedule+0x164/0x360 kernel/sched/core.c:7298     wb_wait_for_completion+0x3e8/0x790 fs/fs-writeback.c:227     __writeback_inodes_sb_nr+0x24c/0x2d0 fs/fs-writeback.c:2847     try_to_writeback_inodes_sb+0x9a/0xc0 fs/fs-writeback.c:2895     btrfs_start_delalloc_flush fs/btrfs/transaction.c:2182 [inline]     btrfs_commit_transaction+0x813/0x2fc0 fs/btrfs/transaction.c:2371     btrfs_sync_file+0xdf4/0x1230 fs/btrfs/file.c:1822     generic_write_sync include/linux/fs.h:2663 [inline]     btrfs_do_write_iter+0x6a9/0x840 fs/btrfs/file.c:1473     new_sync_write fs/read_write.c:595 [inline]     vfs_write+0x629/0xba0 fs/read_write.c:688     ksys_write+0x156/0x270 fs/read_write.c:740     do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]     do_syscall_64+0x15f/0x560 arch/x86/entry/syscall_64.c:94     entry_SYSCALL_64_after_hwframe+0x77/0x7f    RIP: 0033:0x7f5a0bdece59    RSP: 002b:00007f5a0b446028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001    RAX: ffffffffffffffda RBX: 00007f5a0c065fa0 RCX: 00007f5a0bdece59    RDX: 000000000000029f RSI: 0000200000 ---truncated---","cvss":[],"epss":[{"cve":"CVE-2026-74318","epss":0.00168,"percentile":0.06351,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74318","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74318","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/06283034cec0fa357cbd85784ef7d3f5b2ce0790","https://git.kernel.org/stable/c/2aa37c8ef1092c6f088e23a90bffefc672831c09","https://git.kernel.org/stable/c/532085d00eb54c074bdeae648b194765239f4d11","https://git.kernel.org/stable/c/ea3452726ccb6bcaa732f43cc57bb928eca3dd59"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock cloning inline extent when using flushoncommit\n\nIn commit b48c980b6a7e (\"btrfs: fix deadlock between reflink and\ntransaction commit when using flushoncommit\") a deadlock was fixed\nbetween reflinks and transaction commits when the fs is mounted with the\nflushoncommit option. This happened when we had to copy an inline extent's\ndata to the destination file. However the issue was fixed only for the\ncase where the destination offset is 0, it missed the case when the offset\nis greater than zero.\n\nFix this by ensuring we get i_size update whenever we copied an inline\nextent's data into the destination file.\n\nSyzbot reported this with the following trace:\n\n   INFO: task kworker/u8:3:57 blocked for more than 143 seconds.\n         Not tainted syzkaller #0\n   \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n   task:kworker/u8:3    state:D stack:21600 pid:57    tgid:57    ppid:2      task_flags:0x4208160 flags:0x00080000\n   Workqueue: writeback wb_workfn (flush-btrfs-129)\n   Call Trace:\n    <TASK>\n    context_switch kernel/sched/core.c:5402 [inline]\n    __schedule+0x16f9/0x5500 kernel/sched/core.c:7204\n    __schedule_loop kernel/sched/core.c:7283 [inline]\n    schedule+0x164/0x360 kernel/sched/core.c:7298\n    wait_extent_bit fs/btrfs/extent-io-tree.c:905 [inline]\n    btrfs_lock_extent_bits+0x59c/0x700 fs/btrfs/extent-io-tree.c:2008\n    btrfs_lock_extent fs/btrfs/extent-io-tree.h:152 [inline]\n    btrfs_invalidate_folio+0x440/0xc00 fs/btrfs/inode.c:7718\n    extent_writepage fs/btrfs/extent_io.c:1848 [inline]\n    extent_write_cache_pages fs/btrfs/extent_io.c:2552 [inline]\n    btrfs_writepages+0x12f3/0x2410 fs/btrfs/extent_io.c:2684\n    do_writepages+0x32e/0x550 mm/page-writeback.c:2571\n    __writeback_single_inode+0x133/0x10e0 fs/fs-writeback.c:1764\n    writeback_sb_inodes+0x97f/0x1980 fs/fs-writeback.c:2056\n    wb_writeback+0x445/0xb00 fs/fs-writeback.c:2241\n    wb_do_writeback fs/fs-writeback.c:2388 [inline]\n    wb_workfn+0x3fd/0xf20 fs/fs-writeback.c:2428\n    process_one_work+0x98b/0x1630 kernel/workqueue.c:3318\n    process_scheduled_works kernel/workqueue.c:3401 [inline]\n    worker_thread+0xb49/0x1140 kernel/workqueue.c:3482\n    kthread+0x388/0x470 kernel/kthread.c:436\n    ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158\n    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n    </TASK>\n   INFO: task syz.0.145:8523 blocked for more than 143 seconds.\n         Not tainted syzkaller #0\n   \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n   task:syz.0.145       state:D stack:22752 pid:8523  tgid:8522  ppid:5850   task_flags:0x400140 flags:0x00080002\n   Call Trace:\n    <TASK>\n    context_switch kernel/sched/core.c:5402 [inline]\n    __schedule+0x16f9/0x5500 kernel/sched/core.c:7204\n    __schedule_loop kernel/sched/core.c:7283 [inline]\n    schedule+0x164/0x360 kernel/sched/core.c:7298\n    wb_wait_for_completion+0x3e8/0x790 fs/fs-writeback.c:227\n    __writeback_inodes_sb_nr+0x24c/0x2d0 fs/fs-writeback.c:2847\n    try_to_writeback_inodes_sb+0x9a/0xc0 fs/fs-writeback.c:2895\n    btrfs_start_delalloc_flush fs/btrfs/transaction.c:2182 [inline]\n    btrfs_commit_transaction+0x813/0x2fc0 fs/btrfs/transaction.c:2371\n    btrfs_sync_file+0xdf4/0x1230 fs/btrfs/file.c:1822\n    generic_write_sync include/linux/fs.h:2663 [inline]\n    btrfs_do_write_iter+0x6a9/0x840 fs/btrfs/file.c:1473\n    new_sync_write fs/read_write.c:595 [inline]\n    vfs_write+0x629/0xba0 fs/read_write.c:688\n    ksys_write+0x156/0x270 fs/read_write.c:740\n    do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n    do_syscall_64+0x15f/0x560 arch/x86/entry/syscall_64.c:94\n    entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   RIP: 0033:0x7f5a0bdece59\n   RSP: 002b:00007f5a0b446028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\n   RAX: ffffffffffffffda RBX: 00007f5a0c065fa0 RCX: 00007f5a0bdece59\n   RDX: 000000000000029f RSI: 0000200000\n---truncated---","cvss":[],"epss":[{"cve":"CVE-2026-74318","epss":0.00168,"percentile":0.06351,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74318","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74334","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74334","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/nldev: Fix locking when accessing mr->pd  Sashiko points out that, due to rereg_mr, the PD is actually variable and all the touches in nldev are racy.  Use mr->device instead of mr->pd->device.  Getting the PD restrack ID is more tricky. To avoid disturbing all the happy paths, add an rdma_restrack_sync() operation which is sort of like flush_workqueue() or synchronize_irq(): after it returns, all the old nldev touches to the mr are gone and everything sees the new PD. This makes it safe to reach into the PD pointer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74334","epss":0.0012,"percentile":0.02103,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74334","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74334","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1a132ee4e655288d9a0937ea5109a0d038431ae9","https://git.kernel.org/stable/c/50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/nldev: Fix locking when accessing mr->pd\n\nSashiko points out that, due to rereg_mr, the PD is actually variable and\nall the touches in nldev are racy.\n\nUse mr->device instead of mr->pd->device.\n\nGetting the PD restrack ID is more tricky. To avoid disturbing all the\nhappy paths, add an rdma_restrack_sync() operation which is sort of like\nflush_workqueue() or synchronize_irq(): after it returns, all the old\nnldev touches to the mr are gone and everything sees the new PD. This\nmakes it safe to reach into the PD pointer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74334","epss":0.0012,"percentile":0.02103,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74334","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74337","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74337","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix NMI/tracepoint re-entry deadlock on lru locks  NMI and tracepoint BPF programs can re-enter the per-CPU or global LRU lock that bpf_lru_pop_free()/push_free() already hold on the same CPU, AA-deadlocking. Lockdep reports \"inconsistent {INITIAL USE} -> {IN-NMI}\" on &l->lock (syzbot c69a0a2c816716f1e0d5) and \"possible recursive locking detected\" on &loc_l->lock (syzbot 18b26edb69b2e19f3b33).  Prior trylock and rqspinlock based fixes (see links) were nacked because compromised on reliability.  This patch converts every LRU lock site to rqspinlock_t and adds a recovery path for some failure windows to avoid node leaks.  Failure recovery:   - *_pop_free top-level: return NULL; prealloc_lru_pop() already    treats that as no-free-element (-ENOMEM).   - Cross-CPU steal: skip the victim's locked loc_l, try next CPU.   - Post-steal local lock fail: publish stolen node to lockless    per-CPU free_llist; next pop on this CPU picks it up.   - push_free fail: mark node pending_free=1. __local_list_flush(),    __local_list_pop_pending() reclaim the node from pending_list.    __bpf_lru_list_shrink_inactive() reclaims the node from inactive    list. Nodes from active list are reclaimed by __bpf_lru_list_shrink()    or after __bpf_lru_list_rotate_active() demotes it to the inactive.","cvss":[],"epss":[{"cve":"CVE-2026-74337","epss":0.00166,"percentile":0.06147,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-74337","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74337","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/440a2fdbb40608d55a7b11f2be53592a3785131d","https://git.kernel.org/stable/c/89edbdfc5d0308cef57b71359331de5c4ddbf763","https://git.kernel.org/stable/c/8b0510cc3a4a000d4ed1a56cd96231f3d3ba94c5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix NMI/tracepoint re-entry deadlock on lru locks\n\nNMI and tracepoint BPF programs can re-enter the per-CPU or global\nLRU lock that bpf_lru_pop_free()/push_free() already hold on the\nsame CPU, AA-deadlocking. Lockdep reports \"inconsistent\n{INITIAL USE} -> {IN-NMI}\" on &l->lock (syzbot c69a0a2c816716f1e0d5)\nand \"possible recursive locking detected\" on &loc_l->lock (syzbot\n18b26edb69b2e19f3b33).\n\nPrior trylock and rqspinlock based fixes (see links) were nacked\nbecause compromised on reliability.\n\nThis patch converts every LRU lock site to rqspinlock_t and adds a\nrecovery path for some failure windows to avoid node leaks.\n\nFailure recovery:\n\n - *_pop_free top-level: return NULL; prealloc_lru_pop() already\n   treats that as no-free-element (-ENOMEM).\n\n - Cross-CPU steal: skip the victim's locked loc_l, try next CPU.\n\n - Post-steal local lock fail: publish stolen node to lockless\n   per-CPU free_llist; next pop on this CPU picks it up.\n\n - push_free fail: mark node pending_free=1. __local_list_flush(),\n   __local_list_pop_pending() reclaim the node from pending_list.\n   __bpf_lru_list_shrink_inactive() reclaims the node from inactive\n   list. Nodes from active list are reclaimed by __bpf_lru_list_shrink()\n   or after __bpf_lru_list_rotate_active() demotes it to the inactive.","cvss":[],"epss":[{"cve":"CVE-2026-74337","epss":0.00166,"percentile":0.06147,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74337","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74338","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74338","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Reject sleepable BPF_LSM_CGROUP programs at load time  The cgroup shim runs under rcu_read_lock_dont_migrate(), so we should not attach any sleepable BPF programs there. Add support to the verifier to explicitly reject attempts to load sleepable BPF programs destined for LSM cgroup attachment.  Without this, we get the following splat from a BPF_LSM_CGROUP program marked BPF_F_SLEEPABLE attached to file_open when it calls bpf_get_dentry_xattr():    BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1567   in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 34317, name: load   preempt_count: 0, expected: 0   RCU nest depth: 2, expected: 0   Call Trace:    down_read+0x76/0x480    ext4_xattr_get+0x11f/0x700    __vfs_getxattr+0xf0/0x150    bpf_get_dentry_xattr+0xbb/0xf0    bpf_prog_e76a298dac9218c6_test_open+0x6a/0x85    __cgroup_bpf_run_lsm_current+0x326/0x840    bpf_trampoline_6442534646+0x62/0x14d    security_file_open+0x34/0x60    do_dentry_open+0x340/0x1260    vfs_open+0x7a/0x440    path_openat+0x1bac/0x30a0  libbpf provides a .s named section variant for every sleepable program type except lsm_cgroup, reflecting that per-cgroup LSM programs are intended to only run in a non-sleepable context.  The above splat was obtained by bypassing libbpf by using bpf(2) directly.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74338","epss":0.00128,"percentile":0.02752,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09792000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-74338","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74338","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5b038319be442c620f774e6fc9e9283deeca1c75","https://git.kernel.org/stable/c/be9eaf2bb5db4ad3de61ef739fd268fd7f135737"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject sleepable BPF_LSM_CGROUP programs at load time\n\nThe cgroup shim runs under rcu_read_lock_dont_migrate(), so we should\nnot attach any sleepable BPF programs there. Add support to the verifier\nto explicitly reject attempts to load sleepable BPF programs destined\nfor LSM cgroup attachment.\n\nWithout this, we get the following splat from a BPF_LSM_CGROUP\nprogram marked BPF_F_SLEEPABLE attached to file_open when it calls\nbpf_get_dentry_xattr():\n\n  BUG: sleeping function called from invalid context at kernel/locking/rwsem.c:1567\n  in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 34317, name: load\n  preempt_count: 0, expected: 0\n  RCU nest depth: 2, expected: 0\n  Call Trace:\n   down_read+0x76/0x480\n   ext4_xattr_get+0x11f/0x700\n   __vfs_getxattr+0xf0/0x150\n   bpf_get_dentry_xattr+0xbb/0xf0\n   bpf_prog_e76a298dac9218c6_test_open+0x6a/0x85\n   __cgroup_bpf_run_lsm_current+0x326/0x840\n   bpf_trampoline_6442534646+0x62/0x14d\n   security_file_open+0x34/0x60\n   do_dentry_open+0x340/0x1260\n   vfs_open+0x7a/0x440\n   path_openat+0x1bac/0x30a0\n\nlibbpf provides a .s named section variant for every sleepable\nprogram type except lsm_cgroup, reflecting that per-cgroup LSM programs\nare intended to only run in a non-sleepable context.\n\nThe above splat was obtained by bypassing libbpf by using bpf(2)\ndirectly.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74338","epss":0.00128,"percentile":0.02752,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74338","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74342","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74342","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  kernfs: link kn to its parent before the LSM init hook  After commit 12e9e3cd03b5 (\"simpe_xattr: use per-sb cache\"), kernfs_xattr_set() and kernfs_xattr_get() compute the cache via kernfs_root(kn) before any other check.  kernfs_root(kn) walks kn->__parent first and falls back to kn->dir.root, both of which are NULL on a freshly kmem_cache_zalloc()'d kn. kn->__parent was being set in kernfs_new_node() after __kernfs_new_node() returned, and kn->dir.root is set even later by kernfs_create_dir_ns() / kernfs_create_empty_dir().  The LSM kernfs_init_security hook is invoked from inside __kernfs_new_node(), before either field has been initialized. selinux_kernfs_init_security() ends with kernfs_xattr_set(kn, XATTR_NAME_SELINUX, ...).  kernfs_root(kn) then returns NULL, and &((struct kernfs_root *)NULL)->xa_cache evaluates to offsetof(struct kernfs_root, xa_cache) which faults:    BUG: kernel NULL pointer dereference, address: 00000000000000e0   RIP: 0010:simple_xattr_set+0x27/0x8b0   Call Trace:    kernfs_xattr_set+0x63/0xb0    selinux_kernfs_init_security+0x13b/0x270    security_kernfs_init_security+0x36/0xc0    __kernfs_new_node+0x182/0x290    kernfs_new_node+0x80/0xc0    kernfs_create_dir_ns+0x2b/0xa0    cgroup_create+0x116/0x380    cgroup_mkdir+0x7c/0x1a0  Reproduces deterministically at PID 1 (systemd) on an SELinux-enabled distro. The first cgroup mkdir under /sys/fs/cgroup with a labelled parent panics the kernel.  The LSM hook's contract is that the kn_dir argument is the parent of the new kn, so kn->__parent should already point at kn_dir when the hook runs.  Move kernfs_get(parent) and rcu_assign_pointer of kn->__parent from kernfs_new_node() into __kernfs_new_node() right before the security hook, and unwind the parent reference on the err_out4 path.  kernfs_root(kn) then takes its parent branch during the hook and returns parent->dir.root, which is the correct root.  This also closes the same-shape latent bug in kernfs_xattr_get() (which today is hidden only by kernfs_iattrs_noalloc() returning NULL on a fresh kn).","cvss":[],"epss":[{"cve":"CVE-2026-74342","epss":0.00155,"percentile":0.05026,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-74342","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74342","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/319b82e8b46edaf557436ad858e734e583f78ec9","https://git.kernel.org/stable/c/6cccc49b027c7551ffc1d2532f2ef1922661f3da"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nkernfs: link kn to its parent before the LSM init hook\n\nAfter commit 12e9e3cd03b5 (\"simpe_xattr: use per-sb cache\"),\nkernfs_xattr_set() and kernfs_xattr_get() compute the cache via\nkernfs_root(kn) before any other check.  kernfs_root(kn) walks\nkn->__parent first and falls back to kn->dir.root, both of which are\nNULL on a freshly kmem_cache_zalloc()'d kn. kn->__parent was being set\nin kernfs_new_node() after __kernfs_new_node() returned, and kn->dir.root\nis set even later by kernfs_create_dir_ns() / kernfs_create_empty_dir().\n\nThe LSM kernfs_init_security hook is invoked from inside\n__kernfs_new_node(), before either field has been initialized.\nselinux_kernfs_init_security() ends with kernfs_xattr_set(kn,\nXATTR_NAME_SELINUX, ...).  kernfs_root(kn) then returns NULL, and\n&((struct kernfs_root *)NULL)->xa_cache evaluates to\noffsetof(struct kernfs_root, xa_cache) which faults:\n\n  BUG: kernel NULL pointer dereference, address: 00000000000000e0\n  RIP: 0010:simple_xattr_set+0x27/0x8b0\n  Call Trace:\n   kernfs_xattr_set+0x63/0xb0\n   selinux_kernfs_init_security+0x13b/0x270\n   security_kernfs_init_security+0x36/0xc0\n   __kernfs_new_node+0x182/0x290\n   kernfs_new_node+0x80/0xc0\n   kernfs_create_dir_ns+0x2b/0xa0\n   cgroup_create+0x116/0x380\n   cgroup_mkdir+0x7c/0x1a0\n\nReproduces deterministically at PID 1 (systemd) on an SELinux-enabled\ndistro. The first cgroup mkdir under /sys/fs/cgroup with a labelled\nparent panics the kernel.\n\nThe LSM hook's contract is that the kn_dir argument is the parent of\nthe new kn, so kn->__parent should already point at kn_dir when the\nhook runs.  Move kernfs_get(parent) and rcu_assign_pointer of\nkn->__parent from kernfs_new_node() into __kernfs_new_node() right\nbefore the security hook, and unwind the parent reference on the\nerr_out4 path.  kernfs_root(kn) then takes its parent branch during\nthe hook and returns parent->dir.root, which is the correct root.\n\nThis also closes the same-shape latent bug in kernfs_xattr_get() (which\ntoday is hidden only by kernfs_iattrs_noalloc() returning NULL on a\nfresh kn).","cvss":[],"epss":[{"cve":"CVE-2026-74342","epss":0.00155,"percentile":0.05026,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74342","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74345","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74345","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/siw: Fix endpoint/socket association handling  Disassociating a socket from an endpoint via siw_socket_disassoc() may release the last reference on that endpoint and free it. Therefore, don't clear the endpoints socket pointer after calling that function, but within.  This fixes a:    BUG: KASAN: slab-use-after-free in siw_cm_work_handler (drivers/infiniband/sw/siw/siw_cm.c:1053 drivers/infiniband/sw/siw/siw_cm.c:1075)  which occurred after processing a malformed MPA request during connection establishment, causing the new endpoint to be closed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74345","epss":0.00444,"percentile":0.37457,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.41736000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-74345","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74345","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/b28d513393f81e2de00f82970487a9d001557e4e","https://git.kernel.org/stable/c/b6cf763eee0a932792bef64ceaca568d324192fc","https://git.kernel.org/stable/c/ea4f6f6c53577fb3f05dbd78b15e586772d49831","https://git.kernel.org/stable/c/f6183983ce1ff254d629a333739082b39d7c5eb6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix endpoint/socket association handling\n\nDisassociating a socket from an endpoint via siw_socket_disassoc() may\nrelease the last reference on that endpoint and free it. Therefore, don't\nclear the endpoints socket pointer after calling that function, but\nwithin.\n\nThis fixes a:\n\n  BUG: KASAN: slab-use-after-free in siw_cm_work_handler (drivers/infiniband/sw/siw/siw_cm.c:1053 drivers/infiniband/sw/siw/siw_cm.c:1075)\n\nwhich occurred after processing a malformed MPA request during connection\nestablishment, causing the new endpoint to be closed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74345","epss":0.00444,"percentile":0.37457,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74345","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74347","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74347","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount  Add a refcount for struct nf_ct_timeout which is used by ct extension to set the custom ct timeout policy, this tells us that the ct timeout is being used by a conntrack entry. When the last conntrack entry drops the refcount on the ct timeout, the ct timeout is released.  Remove the refcount for control plane which controls if the ruleset refers to the timeout policy. After this update, it is possible to remove the ct timeout policy from nfnetlink_cttimeout immediately. This is for simplicity not to handle two refcounts on a single object.  Remove nf_queue_nf_hook_drop(): a packet sitting in nfqueue will just hold a reference to the nf_ct_timeout object until packet is reinjected, since this is part of the ct extension, this will be released by the time the conntrack is freed.  nf_ct_untimeout() is still called to clean up in a best effort basis: the ct timeout on existing entries gets removed when the ct timeout goes away, but as long as the iptables ruleset still refers to the ct timeout through a template, new conntracks may keep attaching it and extend its lifetime until the rule is removed.  nf_ct_untimeout() is not called anymore from module removal path, this is unlikely to find timeouts give module refcount is bumped, and the new refcount already tracks the ct timeout policy use so it is released when unused.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74347","epss":0.0012,"percentile":0.02112,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74347","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74347","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7d6a9cdb8d3a51d9cfe546a09a518ab3d2671549","https://git.kernel.org/stable/c/9aeb0dcfeb460d33d61d434148b51103ab1d2013"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: cttimeout: detach dataplane timeout policy and repurpose refcount\n\nAdd a refcount for struct nf_ct_timeout which is used by ct extension to\nset the custom ct timeout policy, this tells us that the ct timeout is\nbeing used by a conntrack entry. When the last conntrack entry drops the\nrefcount on the ct timeout, the ct timeout is released.\n\nRemove the refcount for control plane which controls if the ruleset\nrefers to the timeout policy. After this update, it is possible to\nremove the ct timeout policy from nfnetlink_cttimeout immediately.\nThis is for simplicity not to handle two refcounts on a single object.\n\nRemove nf_queue_nf_hook_drop(): a packet sitting in nfqueue will just\nhold a reference to the nf_ct_timeout object until packet is reinjected,\nsince this is part of the ct extension, this will be released by the\ntime the conntrack is freed.\n\nnf_ct_untimeout() is still called to clean up in a best effort basis:\nthe ct timeout on existing entries gets removed when the ct timeout goes\naway, but as long as the iptables ruleset still refers to the ct timeout\nthrough a template, new conntracks may keep attaching it and extend its\nlifetime until the rule is removed.\n\nnf_ct_untimeout() is not called anymore from module removal path, this\nis unlikely to find timeouts give module refcount is bumped, and the new\nrefcount already tracks the ct timeout policy use so it is released when\nunused.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74347","epss":0.0012,"percentile":0.02112,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74347","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74350","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74350","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ocfs2: validate fast symlink target during inode read  ocfs2_validate_inode_block() already rejects several inconsistent self-contained dinodes before they are exposed to the rest of the filesystem.  Fast symlinks need the same treatment.  A zero-cluster symlink is treated as a fast symlink and later read through page_get_link() and ocfs2_fast_symlink_read_folio().  That path uses strnlen() on the inline payload and then copies len + 1 bytes into the folio.  If a corrupt dinode stores an i_size that does not fit the inline area or omits the terminating NUL at i_size, that copy reads past the end of the inode block buffer.  Reject zero-cluster symlink dinodes whose i_size exceeds the inline fast-symlink capacity or whose inline payload is not NUL-terminated exactly at i_size when the inode block is validated.  This keeps malformed fast symlinks from reaching the read path.  Validation reproduced this kernel report: KASAN use-after-free in ocfs2_fast_symlink_read_folio+0x12c/0x1f0 RIP: 0033:0x7f5c6d859aa7 Read of size 3905 Call trace:   dump_stack_lvl+0x66/0xa0 (?:?)   print_report+0xce/0x630 (?:?)   ocfs2_fast_symlink_read_folio+0x12c/0x1f0 (fs/ocfs2/inode.c:?)   srso_alias_return_thunk+0x5/0xfbef5 (?:?)   __virt_addr_valid+0x19f/0x330 (?:?)   kasan_report+0xe0/0x110 (?:?)   kasan_check_range+0x105/0x1b0 (?:?)   __asan_memcpy+0x23/0x60 (?:?)   filemap_read_folio+0x27/0xe0 (?:?)   filemap_read_folio+0x35/0xe0 (?:?)   do_read_cache_folio+0x138/0x230 (?:?)   __page_get_link+0x26/0x110 (?:?)   page_get_link+0x2e/0x70 (?:?)   vfs_readlink+0x15e/0x250 (?:?)   touch_atime+0x4d/0x370 (?:?)   do_readlinkat+0x186/0x200 (?:?)   do_user_addr_fault+0x65a/0x890 (?:?)   __x64_sys_readlink+0x46/0x60 (?:?)   do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)   entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74350","epss":0.0038,"percentile":0.31292,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3572},"relatedVulnerabilities":[{"id":"CVE-2026-74350","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74350","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/e234973f286ed2e8961a24561ec91594ec3e3ff8","https://git.kernel.org/stable/c/f9e2cb692b77a679b1f4cc2b7b277fa908586533"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: validate fast symlink target during inode read\n\nocfs2_validate_inode_block() already rejects several inconsistent\nself-contained dinodes before they are exposed to the rest of the\nfilesystem.  Fast symlinks need the same treatment.\n\nA zero-cluster symlink is treated as a fast symlink and later read through\npage_get_link() and ocfs2_fast_symlink_read_folio().  That path uses\nstrnlen() on the inline payload and then copies len + 1 bytes into the\nfolio.  If a corrupt dinode stores an i_size that does not fit the inline\narea or omits the terminating NUL at i_size, that copy reads past the end\nof the inode block buffer.\n\nReject zero-cluster symlink dinodes whose i_size exceeds the inline\nfast-symlink capacity or whose inline payload is not NUL-terminated\nexactly at i_size when the inode block is validated.  This keeps malformed\nfast symlinks from reaching the read path.\n\nValidation reproduced this kernel report:\nKASAN use-after-free in ocfs2_fast_symlink_read_folio+0x12c/0x1f0\nRIP: 0033:0x7f5c6d859aa7\nRead of size 3905\nCall trace:\n  dump_stack_lvl+0x66/0xa0 (?:?)\n  print_report+0xce/0x630 (?:?)\n  ocfs2_fast_symlink_read_folio+0x12c/0x1f0 (fs/ocfs2/inode.c:?)\n  srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n  __virt_addr_valid+0x19f/0x330 (?:?)\n  kasan_report+0xe0/0x110 (?:?)\n  kasan_check_range+0x105/0x1b0 (?:?)\n  __asan_memcpy+0x23/0x60 (?:?)\n  filemap_read_folio+0x27/0xe0 (?:?)\n  filemap_read_folio+0x35/0xe0 (?:?)\n  do_read_cache_folio+0x138/0x230 (?:?)\n  __page_get_link+0x26/0x110 (?:?)\n  page_get_link+0x2e/0x70 (?:?)\n  vfs_readlink+0x15e/0x250 (?:?)\n  touch_atime+0x4d/0x370 (?:?)\n  do_readlinkat+0x186/0x200 (?:?)\n  do_user_addr_fault+0x65a/0x890 (?:?)\n  __x64_sys_readlink+0x46/0x60 (?:?)\n  do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74350","epss":0.0038,"percentile":0.31292,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74350","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74356","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74356","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vhost: fix vhost_get_avail_idx for a non empty ring  vhost_get_avail_idx is supposed to report whether it has updated vq->avail_idx. Instead, it returns whether all entries have been consumed, which is usually the same. But not always - in drivers/vhost/net.c and when mergeable buffers have been enabled, the driver checks whether the combined entries are big enough to store an incoming packet. If not, the driver re-enables notifications with available entries still in the ring. The incorrect return value from vhost_get_avail_idx propagates through vhost_enable_notify and causes the host to livelock if the guest is not making progress, as vhost will immediately disable notifications and retry using the available entries.  This goes back to commit d3bb267bbdcb (\"vhost: cache avail index in vhost_enable_notify()\") which changed vhost_enable_notify() to compare the freshly read avail index against vq->last_avail_idx instead of the previously cached vq->avail_idx. Commit 7ad472397667 (\"vhost: move smp_rmb() into vhost_get_avail_idx()\") then carried over the same comparison when refactoring vhost_enable_notify() to call the unified vhost_get_avail_idx().  The obvious fix is to make vhost_get_avail_idx do what the comment says it does and report whether new entries have been added.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.4,"exploitabilityScore":2.9,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74356","epss":0.00232,"percentile":0.14104,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17284},"relatedVulnerabilities":[{"id":"CVE-2026-74356","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74356","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/09861858a68342f851f71c669ac0f69865c32151","https://git.kernel.org/stable/c/7f229d27bf27c7e589eca690d8612763a7a4801f","https://git.kernel.org/stable/c/a9326b652bc7acd748d7a1143573845c7924d847","https://git.kernel.org/stable/c/e115471008111f894c6528d9ab2ce7d0ce306f35"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost: fix vhost_get_avail_idx for a non empty ring\n\nvhost_get_avail_idx is supposed to report whether it has updated\nvq->avail_idx. Instead, it returns whether all entries have been\nconsumed, which is usually the same. But not always - in\ndrivers/vhost/net.c and when mergeable buffers have been enabled, the\ndriver checks whether the combined entries are big enough to store an\nincoming packet. If not, the driver re-enables notifications with\navailable entries still in the ring. The incorrect return value from\nvhost_get_avail_idx propagates through vhost_enable_notify and causes\nthe host to livelock if the guest is not making progress, as vhost will\nimmediately disable notifications and retry using the available entries.\n\nThis goes back to commit d3bb267bbdcb (\"vhost: cache avail index in\nvhost_enable_notify()\") which changed vhost_enable_notify() to compare\nthe freshly read avail index against vq->last_avail_idx instead of the\npreviously cached vq->avail_idx. Commit 7ad472397667 (\"vhost: move\nsmp_rmb() into vhost_get_avail_idx()\") then carried over the same\ncomparison when refactoring vhost_enable_notify() to call the unified\nvhost_get_avail_idx().\n\nThe obvious fix is to make vhost_get_avail_idx do what the comment\nsays it does and report whether new entries have been added.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.4,"exploitabilityScore":2.9,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74356","epss":0.00232,"percentile":0.14104,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74356","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74374","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74374","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  md/raid1,raid10: fix error-path detection with md_cloned_bio()  Detect the error path using md_cloned_bio() instead of relying on r1_bio in raid1 or r10_bio->read_slot in raid10, which may be NULL or -1 after splitting and resubmitting a failed bio.  As a result, the error path may not be recognized and memory allocations can incorrectly use GFP_NOIO instead of (GFP_NOIO | __GFP_HIGH), which can lead to a deadlock under memory pressure.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74374","epss":0.00344,"percentile":0.27476,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.258},"relatedVulnerabilities":[{"id":"CVE-2026-74374","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74374","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/20fb582c92fd64e5c8bd83c6176264b2794603b7","https://git.kernel.org/stable/c/811545e0926d02a6a0b1a1258bb5544777c164d4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid1,raid10: fix error-path detection with md_cloned_bio()\n\nDetect the error path using md_cloned_bio() instead of relying\non r1_bio in raid1 or r10_bio->read_slot in raid10, which may be\nNULL or -1 after splitting and resubmitting a failed bio.\n\nAs a result, the error path may not be recognized and memory\nallocations can incorrectly use GFP_NOIO instead of\n(GFP_NOIO | __GFP_HIGH), which can lead to a deadlock under\nmemory pressure.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74374","epss":0.00344,"percentile":0.27476,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74374","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74386","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74386","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet-tcp: fix page fragment cache leak in error path  In nvmet_tcp_alloc_queue(), when a connection is closed during the allocation process (e.g., nvmet_tcp_set_queue_sock() returns -ENOTCONN), the error handling jumps to out_destroy_sq and then to out_ida_remove without draining the page fragment cache.  Although nvmet_tcp_free_cmd() is called in some error paths to release individual page fragments, the underlying page cache reference held by queue->pf_cache is never released. The first allocation using pf_cache is the call to nvmet_tcp_alloc_cmd() for queue->connect, which happens after ida_alloc() returns successfully. This results in a page leak each time a connection fails during allocation, which could lead to memory exhaustion over time if connections are repeatedly opened and closed.  Fix this by calling page_frag_cache_drain() before freeing the queue structure in the out_ida_remove label.","cvss":[],"epss":[{"cve":"CVE-2026-74386","epss":0.00168,"percentile":0.06427,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74386","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74386","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4dae393956093c807212918fd91a8fc70df15338","https://git.kernel.org/stable/c/5fbe83a374f09561a0f0c1f4aa021501ffd681eb","https://git.kernel.org/stable/c/a43a9abc1ebf663f0aa56a729106f68dd9c77da6","https://git.kernel.org/stable/c/ba3209704b3cd46961e4e081af5c52a780785648"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: fix page fragment cache leak in error path\n\nIn nvmet_tcp_alloc_queue(), when a connection is closed during the\nallocation process (e.g., nvmet_tcp_set_queue_sock() returns -ENOTCONN),\nthe error handling jumps to out_destroy_sq and then to out_ida_remove\nwithout draining the page fragment cache.\n\nAlthough nvmet_tcp_free_cmd() is called in some error paths to release\nindividual page fragments, the underlying page cache reference held by\nqueue->pf_cache is never released. The first allocation using pf_cache\nis the call to nvmet_tcp_alloc_cmd() for queue->connect, which happens\nafter ida_alloc() returns successfully. This results in a page leak each\ntime a connection fails during allocation, which could lead to memory\nexhaustion over time if connections are repeatedly opened and closed.\n\nFix this by calling page_frag_cache_drain() before freeing the queue\nstructure in the out_ida_remove label.","cvss":[],"epss":[{"cve":"CVE-2026-74386","epss":0.00168,"percentile":0.06427,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74386","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74388","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74388","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data  The OSS sequencer processes the input MIDI bytes into a sequencer event to be dispatched later (in snd_seq_oss_midi_putc() called from snd_seq_oss_process_event()).  When it's a SysEx data, the event record contains data.ext.ptr pointer to the original SysEx bytes, and the referred data is copied into the pool afterwards at dispatching. The problem is that, if the sequencer port gets closed concurrently before the dispatch, the OSS sequencer core also releases the resources (in snd_seq_oss_midi_check_exit_port()), while the pending event may hold a stale pointer, eventually leading to a UAF at a later dispatch.  Fortunately, there is already a refcounting mechanism (snd_use_lock_t) for the OSS MIDI device access, and for addressing the issue above, we just need to extend the refcount until the event gets dispatched.  This patch extends snd_seq_oss_process_event() to give back the refcount object, which is in turn released after calling the sequencer dispatcher with the given event in the caller side.  According to the original report, KASAN report as below:  KASAN slab-use-after-free in snd_seq_event_dup+0x40c/0x470 RIP: 0033:0x7f2cb66a6340 Read of size 6 Call trace:   dump_stack_lvl+0x73/0xb0 (?:?)   print_report+0xd1/0x650 (?:?)   srso_alias_return_thunk+0x5/0xfbef5 (?:?)   __virt_addr_valid+0x1a7/0x340 (?:?)   kasan_complete_mode_report_info+0x64/0x200 (?:?)   kasan_report+0xf7/0x130 (?:?)   snd_seq_event_dup+0x40c/0x470 (?:?)   kasan_check_range+0x10c/0x1c0 (?:?)   __asan_memcpy+0x27/0x70 (?:?)   snd_seq_event_dup+0x9/0x470 (?:?)   snd_seq_client_enqueue_event+0x139/0x240 (?:?)   _raw_spin_unlock_irqrestore+0x4b/0x60 (?:?)   snd_seq_kernel_client_enqueue+0x102/0x120 (?:?)   snd_seq_oss_write+0x416/0x4e0 (?:?)   apparmor_file_permission+0x20/0x30 (?:?)   odev_write+0x3b/0x60 (?:?)   vfs_write+0x1ce/0x850 (?:?)   lock_release+0xc8/0x2a0 (?:?)   __kasan_check_write+0x18/0x20 (?:?)   __mutex_unlock_slowpath+0x129/0x510 (?:?)   ksys_write+0xe1/0x180 (?:?)   mutex_unlock+0x16/0x20 (?:?)   odev_ioctl+0x65/0xc0 (?:?)   __x64_sys_write+0x46/0x60 (?:?)   x64_sys_call+0x7d/0x20d0 (?:?)   do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87)   entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74388","epss":0.00124,"percentile":0.02415,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09486},"relatedVulnerabilities":[{"id":"CVE-2026-74388","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74388","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6dc781778b595be94c31395b2cb167f65145d91f","https://git.kernel.org/stable/c/7aad70cabd8f34cf11a9593fcd3f2ac3f5496943","https://git.kernel.org/stable/c/7c349b4f2a603202fb8c363bd2774a22ac2fddf3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: oss: Fix UAF at handling events with embedded SysEx data\n\nThe OSS sequencer processes the input MIDI bytes into a sequencer\nevent to be dispatched later (in snd_seq_oss_midi_putc() called from\nsnd_seq_oss_process_event()).  When it's a SysEx data, the event\nrecord contains data.ext.ptr pointer to the original SysEx bytes, and\nthe referred data is copied into the pool afterwards at dispatching.\nThe problem is that, if the sequencer port gets closed concurrently\nbefore the dispatch, the OSS sequencer core also releases the\nresources (in snd_seq_oss_midi_check_exit_port()), while the pending\nevent may hold a stale pointer, eventually leading to a UAF at a later\ndispatch.\n\nFortunately, there is already a refcounting mechanism (snd_use_lock_t)\nfor the OSS MIDI device access, and for addressing the issue above, we\njust need to extend the refcount until the event gets dispatched.\n\nThis patch extends snd_seq_oss_process_event() to give back the\nrefcount object, which is in turn released after calling the sequencer\ndispatcher with the given event in the caller side.\n\nAccording to the original report, KASAN report as below:\n\nKASAN slab-use-after-free in snd_seq_event_dup+0x40c/0x470\nRIP: 0033:0x7f2cb66a6340\nRead of size 6\nCall trace:\n  dump_stack_lvl+0x73/0xb0 (?:?)\n  print_report+0xd1/0x650 (?:?)\n  srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n  __virt_addr_valid+0x1a7/0x340 (?:?)\n  kasan_complete_mode_report_info+0x64/0x200 (?:?)\n  kasan_report+0xf7/0x130 (?:?)\n  snd_seq_event_dup+0x40c/0x470 (?:?)\n  kasan_check_range+0x10c/0x1c0 (?:?)\n  __asan_memcpy+0x27/0x70 (?:?)\n  snd_seq_event_dup+0x9/0x470 (?:?)\n  snd_seq_client_enqueue_event+0x139/0x240 (?:?)\n  _raw_spin_unlock_irqrestore+0x4b/0x60 (?:?)\n  snd_seq_kernel_client_enqueue+0x102/0x120 (?:?)\n  snd_seq_oss_write+0x416/0x4e0 (?:?)\n  apparmor_file_permission+0x20/0x30 (?:?)\n  odev_write+0x3b/0x60 (?:?)\n  vfs_write+0x1ce/0x850 (?:?)\n  lock_release+0xc8/0x2a0 (?:?)\n  __kasan_check_write+0x18/0x20 (?:?)\n  __mutex_unlock_slowpath+0x129/0x510 (?:?)\n  ksys_write+0xe1/0x180 (?:?)\n  mutex_unlock+0x16/0x20 (?:?)\n  odev_ioctl+0x65/0xc0 (?:?)\n  __x64_sys_write+0x46/0x60 (?:?)\n  x64_sys_call+0x7d/0x20d0 (?:?)\n  do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74388","epss":0.00124,"percentile":0.02415,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74388","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74389","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74389","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/hns: Fix log flood after cmd_mbox failure  hns_roce_cmd_mbox() is the command interface between driver and hardware. When hardware is abnormal, the unlimited error printings after hns_roce_cmd_mbox() failure will cause log flood and even system crash.  Replace ibdev_err() and ibdev_warn() with their ratelimited versions in the error handling path after hns_roce_cmd_mbox() (and its wrappers hns_roce_create_hw_ctx/hns_roce_destroy_hw_ctx) fails.","cvss":[],"epss":[{"cve":"CVE-2026-74389","epss":0.00168,"percentile":0.06345,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74389","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74389","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/66f44ec974ab372e4e1ee9eac4245237c94e8f68","https://git.kernel.org/stable/c/7d9fbee252f84de3e6947a40eec01481c9d8afbb","https://git.kernel.org/stable/c/bbd97d71e53e551890e4115ad9de46b5f2ac0858","https://git.kernel.org/stable/c/f3c9e84268e9fa613d40d6c138fb6969c35879b5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix log flood after cmd_mbox failure\n\nhns_roce_cmd_mbox() is the command interface between driver and\nhardware. When hardware is abnormal, the unlimited error printings\nafter hns_roce_cmd_mbox() failure will cause log flood and even\nsystem crash.\n\nReplace ibdev_err() and ibdev_warn() with their ratelimited versions\nin the error handling path after hns_roce_cmd_mbox() (and its wrappers\nhns_roce_create_hw_ctx/hns_roce_destroy_hw_ctx) fails.","cvss":[],"epss":[{"cve":"CVE-2026-74389","epss":0.00168,"percentile":0.06345,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74389","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74391","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74391","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing: Bound synthetic-field strings with seq_buf  The synthetic field helpers build a prefixed synthetic variable name and a generated hist command in fixed MAX_FILTER_STR_VAL buffers. The current code appends those strings with raw strcat(), so long key lists, field names, or saved filters can run past the end of the staging buffers.  Build both strings with seq_buf and propagate -E2BIG if either the synthetic variable name or the generated command exceeds MAX_FILTER_STR_VAL. This keeps the existing tracing-side limit while using the helper intended for bounded command construction.  [ sdr: Moved struct seq_buf *s for upside-down x-mas tree formatting ]","cvss":[],"epss":[{"cve":"CVE-2026-74391","epss":0.00168,"percentile":0.06427,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74391","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74391","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0c584c27f6649a93ec12061cc779a4bd8f7c1434","https://git.kernel.org/stable/c/88b901fdc1662b131ff908cbd017333b61e7acc8","https://git.kernel.org/stable/c/baa333b2700a7fa3529d504529c8c10060fd687c","https://git.kernel.org/stable/c/cf334620036ad2250e008c7e7bb6646a3938b7b0","https://git.kernel.org/stable/c/f07883450eb14d1cf020b55d9f3a7ec5683bcd26"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Bound synthetic-field strings with seq_buf\n\nThe synthetic field helpers build a prefixed synthetic variable name and\na generated hist command in fixed MAX_FILTER_STR_VAL buffers. The\ncurrent code appends those strings with raw strcat(), so long key lists,\nfield names, or saved filters can run past the end of the staging\nbuffers.\n\nBuild both strings with seq_buf and propagate -E2BIG if either the\nsynthetic variable name or the generated command exceeds\nMAX_FILTER_STR_VAL. This keeps the existing tracing-side limit while\nusing the helper intended for bounded command construction.\n\n[ sdr: Moved struct seq_buf *s for upside-down x-mas tree formatting ]","cvss":[],"epss":[{"cve":"CVE-2026-74391","epss":0.00168,"percentile":0.06427,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74391","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74397","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74397","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier  mlx5_ib_alloc_transport_domain() allocates a transport domain and then may fail in mlx5_ib_enable_lb(). In that case, the allocated TD is leaked.  Fix this by deallocating the TD when mlx5_ib_enable_lb() returns an error. Also return 0 explicitly in the no-loopback-capability success branch, and move dev->lb.mutex initialization to mlx5_ib_stage_init_init().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74397","epss":0.00129,"percentile":0.02882,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74397","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74397","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2c3b2667dad69d56774b79db763acb3a1bee0fc0","https://git.kernel.org/stable/c/37fc3cc0f924fd8d0f0cf87b92672dec75a32e57","https://git.kernel.org/stable/c/65e344925fa30abf50c8de8c150b397715fa2066","https://git.kernel.org/stable/c/e79389115b9d27287ff6230a9750675106ed7668","https://git.kernel.org/stable/c/f88e12c95fc19f719e06ca1e9eb20fdad68ef61a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier\n\nmlx5_ib_alloc_transport_domain() allocates a transport domain and then\nmay fail in mlx5_ib_enable_lb(). In that case, the allocated TD is leaked.\n\nFix this by deallocating the TD when mlx5_ib_enable_lb() returns an\nerror. Also return 0 explicitly in the no-loopback-capability success\nbranch, and move dev->lb.mutex initialization to mlx5_ib_stage_init_init().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74397","epss":0.00129,"percentile":0.02882,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74397","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74401","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74401","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dlm: fix add msg handle in send_queue ordered  In a benchmark scenario triggering a lot of requests that triggers a lot of DLM messages on the network it can be that the mh->seq is not ordered according the oldest seq number. This ordering is required by dlm_receive_ack as \"before(mh->seq, seq)\" will stop to check for older sequence numbers that are ordered in the tail of \"node->send_queue\".  The side effects of not having it correct ordered regarding \"before(mh->seq, seq)\" are refcounting issues and use-after free.  I only was able to reproduce this issue in a experimental DLM branch and a user space DLM benchmark that uses io_uring. After changing this I don't experienced any refcounting with the sending buffer issues anymore.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74401","epss":0.00444,"percentile":0.37458,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.41736000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-74401","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74401","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/4d45250b1d22960f86d83245be188b16e456218b","https://git.kernel.org/stable/c/6369619f1b665f12d8c99cc6ff733c64eb08b22e","https://git.kernel.org/stable/c/712714f818d83373847874ab0f8e426be79296cf","https://git.kernel.org/stable/c/ae9e534e502a0f48c12baf83608c5de0ff0eab11","https://git.kernel.org/stable/c/d2248cb70c070f8f04762872772e155b59016f17"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: fix add msg handle in send_queue ordered\n\nIn a benchmark scenario triggering a lot of requests that triggers a lot\nof DLM messages on the network it can be that the mh->seq is not ordered\naccording the oldest seq number. This ordering is required by\ndlm_receive_ack as \"before(mh->seq, seq)\" will stop to check for older\nsequence numbers that are ordered in the tail of \"node->send_queue\".\n\nThe side effects of not having it correct ordered regarding\n\"before(mh->seq, seq)\" are refcounting issues and use-after free.\n\nI only was able to reproduce this issue in a experimental DLM branch\nand a user space DLM benchmark that uses io_uring. After changing this I\ndon't experienced any refcounting with the sending buffer issues anymore.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74401","epss":0.00444,"percentile":0.37458,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74401","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74405","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74405","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  OPP: Fix race between OPP addition and lookup  A race exists between dev_pm_opp_add_dynamic() and dev_pm_opp_find_freq_exact():    CPU0 (add)                          CPU1 (lookup)   -------------------------------     ------------------------------   _opp_add()     mutex_lock()     list_add(&new_opp->node, head)     mutex_unlock()                    _opp_table_find_key()                                         mutex_lock()                                         dev_pm_opp_get(opp)                                           kref_get()                                         mutex_unlock()     kref_init(&new_opp->kref)                                       dev_pm_opp_put()                                         kref_put_mutex()  The newly added OPP is inserted into the list before its kref is initialized. A concurrent lookup can find this OPP and increment its reference count while it is still uninitialized, leading to refcount corruption and a potential premature free.  Fix this by initializing ->kref and ->opp_table before making the OPP visible via list_add(). This ensures any concurrent lookup observes a fully initialized object.  [ Viresh: Updated commit log ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74405","epss":0.00128,"percentile":0.02737,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09792000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-74405","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74405","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/46696b0b2123475d7f95909435c09808fc5ffd23","https://git.kernel.org/stable/c/bb75bd7d9ae7672034f73ce67a57e6ac89bb39e5","https://git.kernel.org/stable/c/f5e1cc9a284bff2510981643a5bca4bc4c21b81a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nOPP: Fix race between OPP addition and lookup\n\nA race exists between dev_pm_opp_add_dynamic() and\ndev_pm_opp_find_freq_exact():\n\n  CPU0 (add)                          CPU1 (lookup)\n  -------------------------------     ------------------------------\n  _opp_add()\n    mutex_lock()\n    list_add(&new_opp->node, head)\n    mutex_unlock()                    _opp_table_find_key()\n                                        mutex_lock()\n                                        dev_pm_opp_get(opp)\n                                          kref_get()\n                                        mutex_unlock()\n    kref_init(&new_opp->kref)\n                                      dev_pm_opp_put()\n                                        kref_put_mutex()\n\nThe newly added OPP is inserted into the list before its kref is\ninitialized. A concurrent lookup can find this OPP and increment its\nreference count while it is still uninitialized, leading to refcount\ncorruption and a potential premature free.\n\nFix this by initializing ->kref and ->opp_table before making the OPP\nvisible via list_add(). This ensures any concurrent lookup observes a\nfully initialized object.\n\n[ Viresh: Updated commit log ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74405","epss":0.00128,"percentile":0.02737,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74405","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74407","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74407","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath11k: cancel SSR work items during PCI shutdown  A reboot can crash the kernel if it overlaps with WLAN firmware crash recovery (SSR). The crash is a NULL pointer dereference in the MHI teardown path while freeing DMA-backed MHI contexts.  Simplified trace:   dma_free_attrs   mhi_deinit_dev_ctxt [mhi]   ath11k_pci_power_down [ath11k_pci]   ath11k_pci_shutdown [ath11k_pci]   device_shutdown   kernel_restart  On the host side, SSR is driven by the MHI RDDM callback, which queues reset_work to perform device recovery. reset_work power-cycles the device by calling ath11k_hif_power_down() followed by ath11k_hif_power_up(). The power-down phase deinitializes MHI and frees DMA resources.  Shutdown/reboot runs fully asynchronously with this RDDM-driven SSR recovery flow. As a result, the shutdown path (ath11k_pci_shutdown() -> ath11k_pci_power_down()) can race with the SSR recovery sequence.  Fix this by canceling SSR-related work items during PCI shutdown, marking the device as unregistering, and serializing the RDDM callback path that checks and queues reset_work. This ensures that no new SSR recovery work can be queued once teardown has started, and that any in-flight recovery work is fully synchronized before device power-down, preventing MHI teardown and DMA resource freeing from running more than once.  Note: This issue only affects PCI/MHI-based devices. AHB-based ath11k devices do not queue reset_work in normal SSR flows.  Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74407","epss":0.00218,"percentile":0.12257,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.17767000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-74407","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74407","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/53dd29e8aeb2a1b5f079178551836b85fc6b53df","https://git.kernel.org/stable/c/8c79aac429b583301f387374ff37c59be671df87"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: cancel SSR work items during PCI shutdown\n\nA reboot can crash the kernel if it overlaps with WLAN firmware crash\nrecovery (SSR). The crash is a NULL pointer dereference in the MHI teardown\npath while freeing DMA-backed MHI contexts.\n\nSimplified trace:\n  dma_free_attrs\n  mhi_deinit_dev_ctxt [mhi]\n  ath11k_pci_power_down [ath11k_pci]\n  ath11k_pci_shutdown [ath11k_pci]\n  device_shutdown\n  kernel_restart\n\nOn the host side, SSR is driven by the MHI RDDM callback, which queues\nreset_work to perform device recovery. reset_work power-cycles the device\nby calling ath11k_hif_power_down() followed by ath11k_hif_power_up(). The\npower-down phase deinitializes MHI and frees DMA resources.\n\nShutdown/reboot runs fully asynchronously with this RDDM-driven SSR\nrecovery flow. As a result, the shutdown path\n(ath11k_pci_shutdown() -> ath11k_pci_power_down()) can race with the SSR\nrecovery sequence.\n\nFix this by canceling SSR-related work items during PCI shutdown, marking\nthe device as unregistering, and serializing the RDDM callback path that\nchecks and queues reset_work. This ensures that no new SSR recovery work\ncan be queued once teardown has started, and that any in-flight recovery\nwork is fully synchronized before device power-down, preventing MHI\nteardown and DMA resource freeing from running more than once.\n\nNote: This issue only affects PCI/MHI-based devices. AHB-based ath11k\ndevices do not queue reset_work in normal SSR flows.\n\nTested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74407","epss":0.00218,"percentile":0.12257,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74407","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74417","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74417","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/radeon: fix integer overflow in radeon_align_pitch()  radeon_align_pitch() has the same kind of overflow issue as the old amdgpu helper: both the alignment round-up add and the final 'aligned * cpp' calculation can overflow signed int.  If that wraps, radeon_mode_dumb_create() can end up returning an invalid pitch or creating a zero-sized dumb buffer.  Fix this by using check_add_overflow() for the alignment round-up and check_mul_overflow() for the final pitch calculation, returning 0 on overflow. Also reject zero pitch and size in radeon_mode_dumb_create().  Found via AST-based call-graph analysis using sqry.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74417","epss":0.0012,"percentile":0.02044,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74417","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74417","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/415bb9893e249e46aa5159f7363a11512cf06fa9","https://git.kernel.org/stable/c/b7b44937c548c2c987fcdd129f8896741004bed6","https://git.kernel.org/stable/c/ce3b24eb3ee8f82de851535f516bf21f83e82259","https://git.kernel.org/stable/c/d9dfa176899d488e48bb7342d2c43ddd36e66318","https://git.kernel.org/stable/c/dfc7b5b5599472277e71e5bd2712740651c7c5be"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: fix integer overflow in radeon_align_pitch()\n\nradeon_align_pitch() has the same kind of overflow issue as the old\namdgpu helper: both the alignment round-up add and the final\n'aligned * cpp' calculation can overflow signed int.\n\nIf that wraps, radeon_mode_dumb_create() can end up returning an\ninvalid pitch or creating a zero-sized dumb buffer.\n\nFix this by using check_add_overflow() for the alignment round-up and\ncheck_mul_overflow() for the final pitch calculation, returning 0 on\noverflow. Also reject zero pitch and size in\nradeon_mode_dumb_create().\n\nFound via AST-based call-graph analysis using sqry.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74417","epss":0.0012,"percentile":0.02044,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74417","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74436","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74436","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: serialize kernel accept preallocation with socket teardown  rxrpc_kernel_charge_accept() reads rx->backlog without any socket/backlog synchronization and passes that raw pointer into rxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc() sets rx->backlog = NULL and frees the backlog rings, so a kernel preallocation worker can keep using a freed struct rxrpc_backlog while updating *_backlog_head/tail and array slots.  Serialize the state check and backlog lookup with the socket lock, and reject kernel preallocation once teardown has disabled listening or discarded the service backlog.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74436","epss":0.00399,"percentile":0.33349,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37505999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-74436","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74436","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0337cdba0c477f176c0459bed012109453184573","https://git.kernel.org/stable/c/11b429b84c87cb5a0152f14e7d6cb649ed363901","https://git.kernel.org/stable/c/1741378a7a83dfd8e53a9196730df709b903cd33","https://git.kernel.org/stable/c/35a967ff8b24db09ee429c39c5b5e6571639997d","https://git.kernel.org/stable/c/c20d983968f239574290cf804a58cde18ad1c559","https://git.kernel.org/stable/c/d6207326b4ca0ae1041281b6af9df53f8080669a","https://git.kernel.org/stable/c/dc175389b18c29a5303ee83169ec653adfae3e17","https://git.kernel.org/stable/c/dfa0b2bbc5e50119f89c6b5407faa5ed86dfa7c5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: serialize kernel accept preallocation with socket teardown\n\nrxrpc_kernel_charge_accept() reads rx->backlog without any\nsocket/backlog synchronization and passes that raw pointer into\nrxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()\nsets rx->backlog = NULL and frees the backlog rings, so a kernel\npreallocation worker can keep using a freed struct rxrpc_backlog\nwhile updating *_backlog_head/tail and array slots.\n\nSerialize the state check and backlog lookup with the socket lock,\nand reject kernel preallocation once teardown has disabled\nlistening or discarded the service backlog.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74436","epss":0.00399,"percentile":0.33349,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74436","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74441","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74441","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: typec: ucsi: Fix race condition and ordering in port unregistration  A synchronization issue exists during port unregistration where pending partner work items can race against workqueue destruction, leading to use-after-free conditions:    cros_ec_ucsi cros_ec_ucsi.3.auto: error -ETIMEDOUT: PPM init failed   BUG: kernel NULL pointer dereference, address: 0000000000000000   RIP: 0010:__queue_work+0x83/0x4a0   Call Trace:     <IRQ>     __cfi_delayed_work_timer_fn+0x10/0x10     run_timer_softirq+0x3b6/0xbd0     sched_clock_cpu+0xc/0x110     irq_exit_rcu+0x18d/0x330     fred_sysvec_apic_timer_interrupt+0x5e/0x80  Fix this by ensuring strict ordering and proper serialization during teardown:  1. Move ucsi_unregister_partner() to the beginning of the teardown sequence and protect it under the connector mutex lock. 2. Ensure all pending partner tasks are explicitly flushed and finished before the workqueue is destroyed. 3. Switch from mod_delayed_work() to a cancel_delayed_work() and queue_delayed_work() sequence. This guarantees that items currently marked as pending won't be scheduled an additional time, preventing a double release of resources which leads to the following crash:    Oops: general protection fault, probably for non-canonical address     0xdead000000000122: 0000 [#1] SMP NOPTI   Workqueue: cros_ec_ucsi.3.auto-con2 ucsi_poll_worker   RIP: 0010:ucsi_poll_worker+0x65/0x1e0   Call Trace:   <TASK>     process_scheduled_works+0x218/0x6d0     worker_thread+0x188/0x3f0     __cfi_worker_thread+0x10/0x10     kthread+0x226/0x2a0  To ensure these rules are applied identically across both the normal teardown and the ucsi_init() error paths, consolidate the cleanup logic into a new helper, ucsi_unregister_port().","cvss":[],"epss":[{"cve":"CVE-2026-74441","epss":0.00173,"percentile":0.06835,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74441","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74441","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/07f8aaffee705e552c1f723ac8bf7eb137ad59c2","https://git.kernel.org/stable/c/11483d80267db97fbe49f2df66385434256cc3b0","https://git.kernel.org/stable/c/3f7b3728dd9011c915cbeaea77274ebe8366550d","https://git.kernel.org/stable/c/7aa7d4bf9d3fa9a6a47b640ad103ab433b7ff261","https://git.kernel.org/stable/c/7b63c680ff605f60f056e5f2c323f1a602aee182","https://git.kernel.org/stable/c/bc7a0f721123ea260a42f1ded06dab844ba49434"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Fix race condition and ordering in port unregistration\n\nA synchronization issue exists during port unregistration where pending\npartner work items can race against workqueue destruction, leading to\nuse-after-free conditions:\n\n  cros_ec_ucsi cros_ec_ucsi.3.auto: error -ETIMEDOUT: PPM init failed\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  RIP: 0010:__queue_work+0x83/0x4a0\n  Call Trace:\n    <IRQ>\n    __cfi_delayed_work_timer_fn+0x10/0x10\n    run_timer_softirq+0x3b6/0xbd0\n    sched_clock_cpu+0xc/0x110\n    irq_exit_rcu+0x18d/0x330\n    fred_sysvec_apic_timer_interrupt+0x5e/0x80\n\nFix this by ensuring strict ordering and proper serialization during\nteardown:\n\n1. Move ucsi_unregister_partner() to the beginning of the teardown\nsequence and protect it under the connector mutex lock.\n2. Ensure all pending partner tasks are explicitly flushed and finished\nbefore the workqueue is destroyed.\n3. Switch from mod_delayed_work() to a cancel_delayed_work() and\nqueue_delayed_work() sequence. This guarantees that items currently marked\nas pending won't be scheduled an additional time, preventing a double\nrelease of resources which leads to the following crash:\n\n  Oops: general protection fault, probably for non-canonical address\n    0xdead000000000122: 0000 [#1] SMP NOPTI\n  Workqueue: cros_ec_ucsi.3.auto-con2 ucsi_poll_worker\n  RIP: 0010:ucsi_poll_worker+0x65/0x1e0\n  Call Trace:\n  <TASK>\n    process_scheduled_works+0x218/0x6d0\n    worker_thread+0x188/0x3f0\n    __cfi_worker_thread+0x10/0x10\n    kthread+0x226/0x2a0\n\nTo ensure these rules are applied identically across both the normal\nteardown and the ucsi_init() error paths, consolidate the cleanup logic\ninto a new helper, ucsi_unregister_port().","cvss":[],"epss":[{"cve":"CVE-2026-74441","epss":0.00173,"percentile":0.06835,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74441","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74443","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74443","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vmwgfx: bound DMA command body size against suffix pointer  vmw_cmd_dma() locates the DMA suffix at  \t(unsigned long) &cmd->body + header->size - sizeof(*suffix)  without checking that header->size is large enough to contain both cmd->body and the suffix.  An undersized header makes the suffix pointer underflow back into the previous command in the bounce buffer.  The verifier later writes suffix->maximumOffset, clobbering verified fields of an already-relocated earlier command -- a TOCTOU on the device-visible command stream that lets one command rewrite another's GMR id, surface id, or other authenticated fields.  Reject the command if the body is too small for the suffix to fit.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74443","epss":0.00129,"percentile":0.02902,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74443","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74443","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/036e16ada95389bdc30f41068af04c1d0872fad0","https://git.kernel.org/stable/c/7e40e6120fb232a10b543ffd994e5c6d8f3a2cc6","https://git.kernel.org/stable/c/9759da60e38d7b9db44dc92713e4e0391883d221","https://git.kernel.org/stable/c/a4a37080a5ac777b59306cfcdf854cc05d7604d4","https://git.kernel.org/stable/c/d5d7ada4e1296b00d89fe82b2ca850cc7809d6f7","https://git.kernel.org/stable/c/eb20f418933bea53375843b27b4022c1810be63b","https://git.kernel.org/stable/c/f4f1db96bfd68b81053693ba53405b6f510ac16c","https://git.kernel.org/stable/c/fcd1e56e7816b31a1050ccc67df722b20f6bb15d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: bound DMA command body size against suffix pointer\n\nvmw_cmd_dma() locates the DMA suffix at\n\n\t(unsigned long) &cmd->body + header->size - sizeof(*suffix)\n\nwithout checking that header->size is large enough to contain both\ncmd->body and the suffix.  An undersized header makes the suffix\npointer underflow back into the previous command in the bounce\nbuffer.  The verifier later writes suffix->maximumOffset, clobbering\nverified fields of an already-relocated earlier command -- a TOCTOU\non the device-visible command stream that lets one command rewrite\nanother's GMR id, surface id, or other authenticated fields.\n\nReject the command if the body is too small for the suffix to fit.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74443","epss":0.00129,"percentile":0.02902,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74443","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74444","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74444","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vmwgfx: validate DRAW_PRIMITIVES header size before division  vmw_cmd_draw() computes  \tmaxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl);  where header->size is u32 and is taken straight from the user-supplied command stream.  When header->size is less than sizeof(cmd->body) the unsigned subtraction wraps to nearly 4 GiB, producing a huge maxnum. Any user-controlled cmd->body.numVertexDecls then passes the bound and the loop dereferences decl[i] far past the end of the kernel command bounce buffer, producing an out-of-bounds read of kernel memory.  Reject undersized headers up front.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74444","epss":0.00129,"percentile":0.02894,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74444","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74444","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/112c6ff29a56f3a22db4d5af869697aa07035ad6","https://git.kernel.org/stable/c/2666cddf0dd218aa9bd1f99db688d1b532eac21a","https://git.kernel.org/stable/c/85891d174707d8bddcec7a888fb4e1d17def34f3","https://git.kernel.org/stable/c/b89ca4bba820f79dde52af15ee139fe6e8bbc314","https://git.kernel.org/stable/c/bef30317fcb4c838a37bceb2fc76256eb6b975c1","https://git.kernel.org/stable/c/c77cf8edae2bd3a1599115301cc7c98d0c78e731","https://git.kernel.org/stable/c/dc0be7662b7b0ce28cb5eea864737793ed7b9e70","https://git.kernel.org/stable/c/fc0c02f510e41650df3479f96e257acf87d8a20a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: validate DRAW_PRIMITIVES header size before division\n\nvmw_cmd_draw() computes\n\n\tmaxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl);\n\nwhere header->size is u32 and is taken straight from the user-supplied\ncommand stream.  When header->size is less than sizeof(cmd->body) the\nunsigned subtraction wraps to nearly 4 GiB, producing a huge maxnum.\nAny user-controlled cmd->body.numVertexDecls then passes the bound and\nthe loop dereferences decl[i] far past the end of the kernel command\nbounce buffer, producing an out-of-bounds read of kernel memory.\n\nReject undersized headers up front.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74444","epss":0.00129,"percentile":0.02894,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74444","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74445","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74445","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vmwgfx: reject DX_BIND_QUERY without a DX context  vmw_cmd_dx_bind_query() unconditionally dereferences sw_context->dx_ctx_node->ctx.  Userspace can trigger a NULL pointer dereference from any render-node fd by submitting an execbuf with dx_context_handle == SVGA3D_INVALID_ID and a SVGA_3D_CMD_DX_BIND_QUERY opcode in the command stream: dx_ctx_node is left NULL and the kernel oopses on the assignment.  The same NULL is then re-read in vmw_resources_reserve() via vmw_context_get_dx_query_mob().  All sibling DX handlers fail-close on a missing dx_ctx_node using VMW_GET_CTX_NODE().  Use the same pattern here, returning -EINVAL up front before any relocation state is published.","cvss":[],"epss":[{"cve":"CVE-2026-74445","epss":0.00168,"percentile":0.06348,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74445","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74445","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0634d50e8b398c25bd07c96b048e484d22688c26","https://git.kernel.org/stable/c/55ec09c9ce10b1272802c7ab6c1be2ea0dbc68db","https://git.kernel.org/stable/c/6b1eb0b63cc153e1c0cb5ab8350950119be11947","https://git.kernel.org/stable/c/7eae011829f94a76470ec76f016805f508437755","https://git.kernel.org/stable/c/e479240a1e076ba1104236331abd62400bf1d495"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: reject DX_BIND_QUERY without a DX context\n\nvmw_cmd_dx_bind_query() unconditionally dereferences\nsw_context->dx_ctx_node->ctx.  Userspace can trigger a NULL pointer\ndereference from any render-node fd by submitting an execbuf with\ndx_context_handle == SVGA3D_INVALID_ID and a SVGA_3D_CMD_DX_BIND_QUERY\nopcode in the command stream: dx_ctx_node is left NULL and the kernel\noopses on the assignment.  The same NULL is then re-read in\nvmw_resources_reserve() via vmw_context_get_dx_query_mob().\n\nAll sibling DX handlers fail-close on a missing dx_ctx_node using\nVMW_GET_CTX_NODE().  Use the same pattern here, returning -EINVAL up\nfront before any relocation state is published.","cvss":[],"epss":[{"cve":"CVE-2026-74445","epss":0.00168,"percentile":0.06348,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74445","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74446","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74446","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: hold event_mutex while checkpointing CRIU events  kfd_criu_checkpoint_events() counts the entries in p->event_idr via kfd_get_num_events(), allocates an array sized to that count, and then walks the same IDR to fill it. Neither the count nor the walk holds p->event_mutex.  The CRIU checkpoint caller holds only p->mutex. Event create and destroy (kfd_event_create()/kfd_event_destroy()) take p->event_mutex and do not take p->mutex, so a second thread in the same process can insert or remove events between the count and the walk. If an event is inserted, the walk iterates more entries than were counted and writes past the end of the ev_privs allocation; if an event is removed, the walk dereferences an entry that is being freed.  Hold p->event_mutex across the count and the walk so both observe a consistent view of p->event_idr. The lock is released before copy_to_user(), which only touches the local buffer. The caller already holds p->mutex and the create/destroy paths never take p->mutex, so the p->mutex -> p->event_mutex order is not inverted and no deadlock is introduced.  (cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74446","epss":0.00129,"percentile":0.02894,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74446","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74446","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2040b7e39027cb83bb8c7b84a4c95c2f6053c32f","https://git.kernel.org/stable/c/6a52f48157fa7fb81e0c146937fd6c8b0c1cfdbd","https://git.kernel.org/stable/c/8f7196f25b14f4290738639a50459b56a5ff2784","https://git.kernel.org/stable/c/9a7f765985f64fd4a7a58f7bc9cd80a1f4230628","https://git.kernel.org/stable/c/bed80be08c0bee47fa242a4256ac873477c815f8","https://git.kernel.org/stable/c/ff8bc5a68a9a70bdc38d61a72c7a49c56063f9d2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: hold event_mutex while checkpointing CRIU events\n\nkfd_criu_checkpoint_events() counts the entries in p->event_idr via\nkfd_get_num_events(), allocates an array sized to that count, and then\nwalks the same IDR to fill it. Neither the count nor the walk holds\np->event_mutex.\n\nThe CRIU checkpoint caller holds only p->mutex. Event create and destroy\n(kfd_event_create()/kfd_event_destroy()) take p->event_mutex and do not\ntake p->mutex, so a second thread in the same process can insert or remove\nevents between the count and the walk. If an event is inserted, the walk\niterates more entries than were counted and writes past the end of the\nev_privs allocation; if an event is removed, the walk dereferences an\nentry that is being freed.\n\nHold p->event_mutex across the count and the walk so both observe a\nconsistent view of p->event_idr. The lock is released before\ncopy_to_user(), which only touches the local buffer. The caller already\nholds p->mutex and the create/destroy paths never take p->mutex, so the\np->mutex -> p->event_mutex order is not inverted and no deadlock is\nintroduced.\n\n(cherry picked from commit ff57e223ab105795b05d3ef3f3c35a5a441bcbaa)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74446","epss":0.00129,"percentile":0.02894,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74446","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74450","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74450","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/pm: fix pptable use-after-free  amdgpu_dpm_get_pp_table() returns a pointer to a driver-owned power table after dropping adev->pm.mutex. The sysfs path then copies from that pointer. A concurrent pp_table write can replace and free the allocation during the copy, causing a use-after-free.  Change the DPM interface to copy into caller-provided storage while the mutex is held. Keep the size-only query for attribute discovery without exposing the driver-owned pointer.  (cherry picked from commit f6eed7acfd30099ef7baeb6ba45bb59daad80631)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74450","epss":0.00126,"percentile":0.02568,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74450","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74450","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3fbb3ac75000e3187f500a91a4099b24206866a1","https://git.kernel.org/stable/c/81b5af1fb0f14cace6c3b3130a05e5602a597820","https://git.kernel.org/stable/c/8c685df5c3b261c42505110965b42f9a754eb9b7","https://git.kernel.org/stable/c/9efc767335234cf7a892e46d45cd453b711421e7","https://git.kernel.org/stable/c/b628f2c6feb3a115ea72d3120a2bd94afc5163df","https://git.kernel.org/stable/c/bb493058c35c8676e48269ab6732688ea733d23c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: fix pptable use-after-free\n\namdgpu_dpm_get_pp_table() returns a pointer to a driver-owned power table\nafter dropping adev->pm.mutex. The sysfs path then copies from that pointer.\nA concurrent pp_table write can replace and free the allocation during the\ncopy, causing a use-after-free.\n\nChange the DPM interface to copy into caller-provided storage while the mutex\nis held. Keep the size-only query for attribute discovery without exposing\nthe driver-owned pointer.\n\n(cherry picked from commit f6eed7acfd30099ef7baeb6ba45bb59daad80631)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74450","epss":0.00126,"percentile":0.02568,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74450","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74453","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74453","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vc4: Zero the tile state data array before each BIN job  The binner BO is a single 16MB buffer split into 512KB slots that are handed out to jobs at submission time and recycled as jobs complete, without ever being cleared. Each slot holds the job's Tile State Data Array (TSDA) at its start, followed by the tile allocation pool.  While the tile allocation pool is only walked by the render thread through branches the binner generated during the current job, the TSDA is the PTB's own per-tile bookkeeping and is consumed by the hardware itself. Although the kernel sets the \"Auto-initialise Tile State Data Array\" flag in the tile binning mode configuration, the PTB demonstrably still acts on stale tile state left by the slot's previous user: the binner ends up creating invalid command streams with invalid primitive streams and branches, which can cause GPU hangs as observed in [1][2].  Zero the TSDA when the job's binning slot is configured. This clears 48 bytes per tile (~24KB for a 1080p frame) in the submission path, and guarantees the PTB never sees another job's tile state.  The tile count is only checked for being non-zero today, so the 8-bit fields it comes from can describe a tile state array almost six times larger than the slot it has to live in. Bound it before the slot is handed out, since such size decides how much of the slot is left for the tile alloc pool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74453","epss":0.00129,"percentile":0.02897,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74453","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74453","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0e858422df2334165293ea742da9fbb2e51f2739","https://git.kernel.org/stable/c/48a570c964d8e37d353381e4195106277e17f5cb","https://git.kernel.org/stable/c/57667eb7548faaac396c6e39f3b4444dab5b097c","https://git.kernel.org/stable/c/a75c8f365e209aa9bb927b0942a7840152d44892","https://git.kernel.org/stable/c/c5d8e8e1a8e3b4e464683c5a8a869c16a6382fea","https://git.kernel.org/stable/c/c8dea7e7c6098e383e44f21a64d0431da5480e3f","https://git.kernel.org/stable/c/d3677372e0275e139f0efd2872c5a524b5d12868","https://git.kernel.org/stable/c/f5802be65535f8818af7191159cf8c11f48ab2a2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Zero the tile state data array before each BIN job\n\nThe binner BO is a single 16MB buffer split into 512KB slots that are\nhanded out to jobs at submission time and recycled as jobs complete,\nwithout ever being cleared. Each slot holds the job's Tile State Data\nArray (TSDA) at its start, followed by the tile allocation pool.\n\nWhile the tile allocation pool is only walked by the render thread\nthrough branches the binner generated during the current job, the\nTSDA is the PTB's own per-tile bookkeeping and is consumed by the\nhardware itself. Although the kernel sets the \"Auto-initialise Tile\nState Data Array\" flag in the tile binning mode configuration, the\nPTB demonstrably still acts on stale tile state left by the slot's\nprevious user: the binner ends up creating invalid command streams\nwith invalid primitive streams and branches, which can cause GPU hangs\nas observed in [1][2].\n\nZero the TSDA when the job's binning slot is configured. This clears\n48 bytes per tile (~24KB for a 1080p frame) in the submission path, and\nguarantees the PTB never sees another job's tile state.\n\nThe tile count is only checked for being non-zero today, so the 8-bit\nfields it comes from can describe a tile state array almost six times\nlarger than the slot it has to live in. Bound it before the slot is\nhanded out, since such size decides how much of the slot is left for\nthe tile alloc pool.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74453","epss":0.00129,"percentile":0.02897,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74453","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74454","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74454","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size  vc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB binner BO, but writes the size of the whole BO to BPOS. On every binner out-of-memory event the PTB is therefore authorized to write tile lists across all the other slots (which may hold the tile state, tile alloc and overflow memory of in-flight jobs) and, for any slot but the first, past the end of the binner BO into unrelated CMA memory.  Since CMA pages are recycled into page cache and user allocations, this is arbitrary memory corruption by GPU DMA. In practice it shows up as GPU hangs with corrupted control list pointers, userspace heap corruption, a GPU that stays permanently wedged after the first hang, and occasional full system crashes, whenever a job overflows the initial binner slot.  The bug dates back to the conversion from a dedicated overflow BO (where writing the full BO size was correct) to the slotted binner BO.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74454","epss":0.00129,"percentile":0.02897,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74454","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74454","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0badb30871004d34df87be33e853536f0b69885f","https://git.kernel.org/stable/c/1e33ca7f44be64beed2735bb76b86eb65ba8c05b","https://git.kernel.org/stable/c/2f2291a119e9a8b696ae8bb36e86b75d272ceaea","https://git.kernel.org/stable/c/6395789e4739aa5177bbec0fa0f07ccc38d249b0","https://git.kernel.org/stable/c/6cd5acf6f87c073622bd61e38fe99c47365cda9c","https://git.kernel.org/stable/c/bb5656ae063f2711f56438cf2f1f5b613aea5f12"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size\n\nvc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB\nbinner BO, but writes the size of the whole BO to BPOS. On every binner\nout-of-memory event the PTB is therefore authorized to write tile lists\nacross all the other slots (which may hold the tile state, tile alloc and\noverflow memory of in-flight jobs) and, for any slot but the first, past\nthe end of the binner BO into unrelated CMA memory.\n\nSince CMA pages are recycled into page cache and user allocations, this\nis arbitrary memory corruption by GPU DMA. In practice it shows up as GPU\nhangs with corrupted control list pointers, userspace heap corruption, a\nGPU that stays permanently wedged after the first hang, and occasional\nfull system crashes, whenever a job overflows the initial binner slot.\n\nThe bug dates back to the conversion from a dedicated overflow BO (where\nwriting the full BO size was correct) to the slotted binner BO.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74454","epss":0.00129,"percentile":0.02897,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74454","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74455","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74455","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: peak_usb: validate uCAN receive record lengths  pcan_usb_fd_decode_buf() walks uCAN records packed in one USB receive buffer.  Require each record to contain the fixed header for its type, and verify CAN payload bytes before copying them into the skb.","cvss":[],"epss":[{"cve":"CVE-2026-74455","epss":0.00177,"percentile":0.07327,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74455","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74455","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2427ef427bdd78d862c7c76597bfd9eda88b81f1","https://git.kernel.org/stable/c/276d989cd2dd88e2b7ab2c96fd10c86836b12781","https://git.kernel.org/stable/c/2c8f08f3641a074da40acf05baa5a18ae2739260","https://git.kernel.org/stable/c/6067c878e38d02a3d5c43497347e143f85c9064a","https://git.kernel.org/stable/c/89c92a8052698dbbd3652a77c04d02bbd74a3275","https://git.kernel.org/stable/c/93fcab2c6968446316bbb49548848df604d6346f","https://git.kernel.org/stable/c/bf9d787b7e1ef59be19b35abca08194772deb97e","https://git.kernel.org/stable/c/d9c115948c3dd5fcc2d0245cec5eb76c098503c8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: validate uCAN receive record lengths\n\npcan_usb_fd_decode_buf() walks uCAN records packed in one USB\nreceive buffer.\n\nRequire each record to contain the fixed header for its type, and verify\nCAN payload bytes before copying them into the skb.","cvss":[],"epss":[{"cve":"CVE-2026-74455","epss":0.00177,"percentile":0.07327,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74455","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74456","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74456","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error  In peak_usb_start(), each RX URB transfer buffer is allocated with kmalloc() and the URB is flagged URB_FREE_BUFFER so that the final usb_free_urb() also frees the transfer buffer.  If usb_submit_urb() fails, the error path frees the buffer explicitly with kfree(buf) and then calls usb_free_urb(urb). Because URB_FREE_BUFFER is set, usb_free_urb() -> urb_destroy() frees the same buffer a second time, a double free of the transfer buffer.    BUG: KASAN: double-free in usb_free_urb.part.0+0x91/0xb0   Free of addr ffff8881069ccb80 by task trigger.sh/285    Call Trace:    kfree+0x113/0x3c0    usb_free_urb.part.0+0x91/0xb0  Drop the redundant kfree(buf); usb_free_urb() already releases the transfer buffer. This mirrors commit 03819abbeb11 (\"net: usb: lan78xx: Fix double free issue with interrupt buffer allocation\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74456","epss":0.00129,"percentile":0.02894,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74456","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74456","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4bb3325075138dd5346b71589a959878b564dc0b","https://git.kernel.org/stable/c/525640b93d3e5f82f4ebea4730f4e0cf799522ba","https://git.kernel.org/stable/c/5f2fa5840c34d3a558c57855781be75e03bef752","https://git.kernel.org/stable/c/914c3b8fa175acf8476ad31cf04e308638e3578e","https://git.kernel.org/stable/c/92d0de80ca2223b9c7da78020155b6cb27824cc0","https://git.kernel.org/stable/c/9b3d5a6d952c38bbcf07f903cbeadefdb56b9bc9","https://git.kernel.org/stable/c/b9088d581fff971a7eb1628f8dcc30df6cfef4dc","https://git.kernel.org/stable/c/dfb17bf04a764462000f11258a7c06aa92d1f261"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error\n\nIn peak_usb_start(), each RX URB transfer buffer is allocated with kmalloc()\nand the URB is flagged URB_FREE_BUFFER so that the final usb_free_urb() also\nfrees the transfer buffer.\n\nIf usb_submit_urb() fails, the error path frees the buffer explicitly with\nkfree(buf) and then calls usb_free_urb(urb). Because URB_FREE_BUFFER is set,\nusb_free_urb() -> urb_destroy() frees the same buffer a second time, a double\nfree of the transfer buffer.\n\n  BUG: KASAN: double-free in usb_free_urb.part.0+0x91/0xb0\n  Free of addr ffff8881069ccb80 by task trigger.sh/285\n\n  Call Trace:\n   kfree+0x113/0x3c0\n   usb_free_urb.part.0+0x91/0xb0\n\nDrop the redundant kfree(buf); usb_free_urb() already releases the transfer\nbuffer. This mirrors commit 03819abbeb11 (\"net: usb: lan78xx: Fix double free\nissue with interrupt buffer allocation\").","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74456","epss":0.00129,"percentile":0.02894,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74456","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74457","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74457","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: peak_usb: add bounds check for USB channel index  The channel control index ctrl_idx is derived from rx->len which comes directly from a device USB payload. The mask 0x0f allows values 0-15, but the array size of usb_if->dev[] is only 2. Values 2-15 cause heap out-of-bounds read, eventually causing kernel panic in the IRQ context.  Add bounds checking for ctrl_idx before the array access in both pcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error().","cvss":[],"epss":[{"cve":"CVE-2026-74457","epss":0.00177,"percentile":0.07325,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74457","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74457","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0149fdb50a30944827acf9600a2cc44de0325a7f","https://git.kernel.org/stable/c/0c9268457bd6e4058fe55b4db01b16661c2eacf5","https://git.kernel.org/stable/c/18b1a868a2cda66fb438007ba47ce5f2484db381","https://git.kernel.org/stable/c/1acab790b7cecd4e144d1d18bdfe549e282f6b0b","https://git.kernel.org/stable/c/39132f166ca8ce00ae60d8a9068e06a60943cc4b","https://git.kernel.org/stable/c/825c903ca3c98cd0cf0e3de8ab8f2604a5339b3f","https://git.kernel.org/stable/c/94fb6fe83ce152532b11b36730b30f3dc0c94217","https://git.kernel.org/stable/c/f97b7e5e1cdaae15cd95b3a360028c7929664969"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: add bounds check for USB channel index\n\nThe channel control index ctrl_idx is derived from rx->len which comes\ndirectly from a device USB payload. The mask 0x0f allows values 0-15, but\nthe array size of usb_if->dev[] is only 2. Values 2-15 cause heap\nout-of-bounds read, eventually causing kernel panic in the IRQ context.\n\nAdd bounds checking for ctrl_idx before the array access in both\npcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error().","cvss":[],"epss":[{"cve":"CVE-2026-74457","epss":0.00177,"percentile":0.07325,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74457","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74458","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74458","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents  The wait and bulk receive paths walk variable-length commands from a USB buffer. A nonzero command shorter than CMD_HEADER_LEN can still be dispatched, and the wait path copies a matching command into a fixed caller-owned struct kvaser_cmd using the device-provided length.  Reject nonzero commands that do not contain the fixed header or that extend beyond the current USB buffer item. In the wait path, also reject a matching command that exceeds the destination before copying it.","cvss":[],"epss":[{"cve":"CVE-2026-74458","epss":0.00177,"percentile":0.07325,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74458","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74458","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee","https://git.kernel.org/stable/c/185cb1fa38142a3cbf223dd8b3abb24217f330d3","https://git.kernel.org/stable/c/21f0465fd86d77794aaed8e05f833634f68d178d","https://git.kernel.org/stable/c/3d0897ec623e422695d70d80ae456f89476c5328","https://git.kernel.org/stable/c/695aea154bb2d453e6daada1510972fafd075285","https://git.kernel.org/stable/c/72f96c2942f11a0ae8663adcb3d9ee986e07d4fa","https://git.kernel.org/stable/c/c00ec53d7dec08134e97071850cc00ef000c5b77","https://git.kernel.org/stable/c/d9e91672526ffa279709b15490118aea1bdee714"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents\n\nThe wait and bulk receive paths walk variable-length commands from a\nUSB buffer. A nonzero command shorter than CMD_HEADER_LEN can still be\ndispatched, and the wait path copies a matching command into a fixed\ncaller-owned struct kvaser_cmd using the device-provided length.\n\nReject nonzero commands that do not contain the fixed header or that\nextend beyond the current USB buffer item. In the wait path, also reject\na matching command that exceeds the destination before copying it.","cvss":[],"epss":[{"cve":"CVE-2026-74458","epss":0.00177,"percentile":0.07325,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74458","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74459","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74459","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure  es58x_read_bulk_callback() resubmits the RX URB after processing a received packet. If the resubmit succeeds, the URB remains anchored and will be handled by the normal RX path or by teardown.  However, if usb_submit_urb() fails, the callback unanchors the URB and then returns directly. This skips the existing free_urb path, so the coherent transfer buffer allocated with usb_alloc_coherent() is not released.  Reuse the existing free_urb path after a resubmit failure so that the RX coherent buffer is freed before leaving the callback.","cvss":[],"epss":[{"cve":"CVE-2026-74459","epss":0.00173,"percentile":0.06834,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74459","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74459","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0ef136ba052101243ba117a1aca6f4a4c3a81142","https://git.kernel.org/stable/c/19c6c8c6cd5dd14fab5fcd744584812a57cbb78d","https://git.kernel.org/stable/c/21da1a374769751546cc131e58a4d8bd968f57b2","https://git.kernel.org/stable/c/7a0cf2b2497c757c3cb1286eddf2986abb0d387b","https://git.kernel.org/stable/c/b85e5c310382803d27adf6fe6554d4208bc8951c","https://git.kernel.org/stable/c/c311f17c261fd375ddf5755f2ebe1f022c19c5b0","https://git.kernel.org/stable/c/c7ddf119544eea2d8409e12471c3f9f36ca02e3f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure\n\nes58x_read_bulk_callback() resubmits the RX URB after processing a received\npacket. If the resubmit succeeds, the URB remains anchored and will be\nhandled by the normal RX path or by teardown.\n\nHowever, if usb_submit_urb() fails, the callback unanchors the URB and then\nreturns directly. This skips the existing free_urb path, so the coherent\ntransfer buffer allocated with usb_alloc_coherent() is not released.\n\nReuse the existing free_urb path after a resubmit failure so that the RX\ncoherent buffer is freed before leaving the callback.","cvss":[],"epss":[{"cve":"CVE-2026-74459","epss":0.00173,"percentile":0.06834,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74459","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74460","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74460","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: ems_usb: validate CPC message lengths  ems_usb_read_bulk_callback() walks CPC messages packed in one USB receive buffer.  Check that each declared message fits in the URB payload. Also require the type-specific payload to cover the fields used by the CAN, state, error and overrun handlers.","cvss":[],"epss":[{"cve":"CVE-2026-74460","epss":0.00173,"percentile":0.06834,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74460","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74460","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/02925f51377f2a42a6724f00549167499c9302e5","https://git.kernel.org/stable/c/0b23144c59c126beb4a7761a85a194ae0fe668a5","https://git.kernel.org/stable/c/0b9090717c7e2184e2c427bbcc752f295116ac1d","https://git.kernel.org/stable/c/bb3cc8da8a2967c0f8e83d148fc6870b19fa32c6","https://git.kernel.org/stable/c/ce8125566b1d0b0f16449407e014addf451804ea","https://git.kernel.org/stable/c/db5655287d78f00daf98888a520bb8da4d30126d","https://git.kernel.org/stable/c/df3ac2a672a5284441f120d486acabdd6740fc2a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: ems_usb: validate CPC message lengths\n\nems_usb_read_bulk_callback() walks CPC messages packed in one USB\nreceive buffer.\n\nCheck that each declared message fits in the URB payload. Also require the\ntype-specific payload to cover the fields used by the CAN, state, error and\noverrun handlers.","cvss":[],"epss":[{"cve":"CVE-2026-74460","epss":0.00173,"percentile":0.06834,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74460","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74461","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74461","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i2c: imx: Cancel hrtimer before clearing slave pointer  In i2c_imx_unreg_slave(), the slave pointer is set to NULL after disabling interrupts.  However, a pending interrupt might already have started the hrtimer (i2c_imx_slave_timeout) before the pointer was cleared.  If the hrtimer fires after i2c_imx->slave is set to NULL, the timer callback i2c_imx_slave_finish_op() will call i2c_imx_slave_event() with a NULL slave pointer, which results in a use-after-free / NULL pointer dereference.  Fix by canceling the hrtimer and waiting for it to complete after disabling interrupts, before clearing the slave pointer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74461","epss":0.00138,"percentile":0.03491,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10970999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74461","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74461","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/470fe15fb3bb2eba6629be301ca7e991ee3cfb7e","https://git.kernel.org/stable/c/6ac7702b6cc2b94aaed9ef2d95bfbefcdc90061f","https://git.kernel.org/stable/c/753060f2b77ff2f386addbd3ecadb95b9f90cddd","https://git.kernel.org/stable/c/a8a1f9ac3d763e721586f15479ef9140b216ddf3","https://git.kernel.org/stable/c/affd62f5719a78135b7441aa49c8cab3c3b5e838","https://git.kernel.org/stable/c/dab4762ee7f3fd0a01980d5407ba48d0261d3bff","https://git.kernel.org/stable/c/e3da77bdb4015051656bb472c295656bbea03b6f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: Cancel hrtimer before clearing slave pointer\n\nIn i2c_imx_unreg_slave(), the slave pointer is set to NULL after\ndisabling interrupts.  However, a pending interrupt might already\nhave started the hrtimer (i2c_imx_slave_timeout) before the pointer\nwas cleared.  If the hrtimer fires after i2c_imx->slave is set to\nNULL, the timer callback i2c_imx_slave_finish_op() will call\ni2c_imx_slave_event() with a NULL slave pointer, which results in a\nuse-after-free / NULL pointer dereference.\n\nFix by canceling the hrtimer and waiting for it to complete after\ndisabling interrupts, before clearing the slave pointer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74461","epss":0.00138,"percentile":0.03491,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74461","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74463","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74463","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock  Fix a severe AB/BA deadlock between the Common Clock Framework (CCF) and the I2C adapter lock, which triggers when an I2C-controlled clock generator client (like the Si5351) is registered or modified under the CCF.  During an i2c client clock (generator) frequency change, the CCF acquires its global 'prepare_lock' mutex and the driver calls i2c_transfer() to update the client's chip registers, stalling for the adapter's I2C bus lock.  Concurrently, an independent, parallel transfer on the same bus (e.g., a GPIO expander handling LEDs) can hold the I2C adapter lock. Inside this parallel transfer path, jz4780_i2c_set_speed() calls clk_get_rate() on the host controller's input clock to calculate bus timings. This call attempts to acquire the blocked CCF 'prepare_lock', creating a circular dependency that freezes the system.  The jz4780 host controller clock itself is static and never changes at runtime.  However, calling clk_get_rate() inside the active transfer path introduces an unnecessary dependency on the CCF internal locks.  Eliminate this synchronous clk_get_rate() call from the active transfer path by caching the static host peripheral clock rate once - inside the private jz4780_i2c structure during jz4780_i2c_probe(). Update jz4780_i2c_set_speed() to use this cached value, safely decoupling active I2C transactions from the CCF internal locks without any risk of stale timings.  Assisted-by web based Google AI (pinpointing the bug and writing the message).","cvss":[],"epss":[{"cve":"CVE-2026-74463","epss":0.00177,"percentile":0.07326,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74463","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74463","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/14429dc1c756c35e106f01ff09cadccb82f5531d","https://git.kernel.org/stable/c/19b783335d62e7a2367436a6e1f1b37da1878360","https://git.kernel.org/stable/c/aa1944b52d6492c48bdd17046578aa0d953546e6","https://git.kernel.org/stable/c/b6cb47e186abba85a3b08aa3023067ab82577286","https://git.kernel.org/stable/c/cc111696ef420f6bb552b2526530067977f0b406","https://git.kernel.org/stable/c/d99607c888f26e8a4e9fe9772860cef4aff86bb4","https://git.kernel.org/stable/c/deffad5bb4f8b4f09e46252f24754ddc9960b244","https://git.kernel.org/stable/c/f96a719d9f8a797105ec5cacf568ab128e33391f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock\n\nFix a severe AB/BA deadlock between the Common Clock Framework (CCF)\nand the I2C adapter lock, which triggers when an I2C-controlled clock\ngenerator client (like the Si5351) is registered or modified under the CCF.\n\nDuring an i2c client clock (generator) frequency change, the CCF acquires its global\n'prepare_lock' mutex and the driver calls i2c_transfer() to update the client's\nchip registers, stalling for the adapter's I2C bus lock.\n\nConcurrently, an independent, parallel transfer on the same bus (e.g., a GPIO\nexpander handling LEDs) can hold the I2C adapter lock. Inside this parallel\ntransfer path, jz4780_i2c_set_speed() calls clk_get_rate() on the host\ncontroller's input clock to calculate bus timings. This call attempts to acquire\nthe blocked CCF 'prepare_lock', creating a circular dependency that freezes\nthe system.\n\nThe jz4780 host controller clock itself is static and never changes at runtime.\n\nHowever, calling clk_get_rate() inside the active transfer path introduces\nan unnecessary dependency on the CCF internal locks.\n\nEliminate this synchronous clk_get_rate() call from the active transfer\npath by caching the static host peripheral clock rate once - inside the private\njz4780_i2c structure during jz4780_i2c_probe(). Update jz4780_i2c_set_speed()\nto use this cached value, safely decoupling active I2C transactions from the\nCCF internal locks without any risk of stale timings.\n\nAssisted-by web based Google AI (pinpointing the bug and writing the message).","cvss":[],"epss":[{"cve":"CVE-2026-74463","epss":0.00177,"percentile":0.07326,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74463","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74464","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74464","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: openvswitch: fix skb leak on flow key update failure during ct  ovs_ct_execute() always steals or frees the skb on failure while ovs_flow_key_update() does not.  So, if it fails and we return right away, the skb ends up leaked.  Fix that by breaking instead and letting the common error handling code at the bottom of the loop to free the skb properly.  This is a very unlikely scenario as it requires the packet to become unparseable by applying a set of actions on a previously parseable skb, but should be fixed nevertheless.  Reported by Sashiko.","cvss":[],"epss":[{"cve":"CVE-2026-74464","epss":0.00177,"percentile":0.07327,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74464","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74464","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/22e0ca88090d89c128078062186b03bb5fdc4f98","https://git.kernel.org/stable/c/393f3c72600ab6721d732a0ab245bc896c5b28fc","https://git.kernel.org/stable/c/6cc523eaee72c4e91894136cff64946ae9de2cda","https://git.kernel.org/stable/c/736e972f3f8a304158345223ac6e816166a467ce","https://git.kernel.org/stable/c/b77126b2915900f69f9fcf5d624a77c8e6d50c31","https://git.kernel.org/stable/c/bc62e843bc48f933da765ce47079fd992e535794","https://git.kernel.org/stable/c/e0ba8eaef2a0d02a7a485e6a7157e47272b65cea","https://git.kernel.org/stable/c/e84dfaac50aab45ad8c670da43e3aa1f97bd2a41"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix skb leak on flow key update failure during ct\n\novs_ct_execute() always steals or frees the skb on failure while\novs_flow_key_update() does not.  So, if it fails and we return right\naway, the skb ends up leaked.\n\nFix that by breaking instead and letting the common error handling\ncode at the bottom of the loop to free the skb properly.\n\nThis is a very unlikely scenario as it requires the packet to become\nunparseable by applying a set of actions on a previously parseable skb,\nbut should be fixed nevertheless.\n\nReported by Sashiko.","cvss":[],"epss":[{"cve":"CVE-2026-74464","epss":0.00177,"percentile":0.07327,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74464","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74465","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74465","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: openvswitch: fix potential UAF on meter attach failure  While attaching a newly created meter attach_meter() function makes the new meter visible to other CPUs but can still fail afterwards. On failure, it detaches the meter back and returns an error.  However, this is an unexpected behavior for the ovs_meter_cmd_set() that uses a plain kfree(meter) on attach failure without waiting for RCU readers to stop using it, assuming it was never visible.  This is never a problem for ovs-vswitchd as it always creates meters before creating any flows that use them.  But the UAF can be triggered with a custom application using uAPI:   BUG: KASAN: slab-use-after-free in ovs_meter_execute (net/openvswitch/meter.c:653)  Read of size 8 at addr ffff88810d152650 by task meter/2508   Call Trace:   ovs_meter_execute (net/openvswitch/meter.c:653)   do_execute_actions (net/openvswitch/actions.c:1407)   ovs_execute_actions (net/openvswitch/actions.c:1584)   ovs_packet_cmd_execute (net/openvswitch/datapath.c:703)   ...   netlink_sendmsg (af_netlink.c:1900)   Allocated by task 2519:   __kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)   ovs_meter_cmd_set (net/openvswitch/meter.c:422)   ...   netlink_sendmsg (af_netlink.c:1900)   Freed by task 2519:   kfree (mm/slub.c:2705 mm/slub.c:6405 mm/slub.c:6720)   ovs_meter_cmd_set (net/openvswitch/meter.c:479)   ...   netlink_sendmsg (af_netlink.c:1900)  Fix that by making sure attach_meter() doesn't make the meter visible until all the checks are done and the function can't fail anymore.  This also makes sure the \"hash\" value is calculated after the potential re-sizing of the table.  Reported by Trend Micro's Zero Day Initiative as ZDI-CAN-31642.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74465","epss":0.00126,"percentile":0.02564,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74465","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74465","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0310d1fa7f9debd0d89629e9f14c7975a47eaa9a","https://git.kernel.org/stable/c/431a295d93f76fbdb6a7cfce92a9e3dfee1e5d61","https://git.kernel.org/stable/c/496f3013c6ff759249abcfb2da2361c1a3e2e66d","https://git.kernel.org/stable/c/4d03e5fa3fbb1df15258a1eb3d6963f0d65659b3","https://git.kernel.org/stable/c/90623c9499627803ef3f04fa25a3199402d4fb95","https://git.kernel.org/stable/c/a58a2b0ce354df531ebc71fc870058c2feb59f6b","https://git.kernel.org/stable/c/b0de3b58dac3b02b528f72ee0397728aed11f993","https://git.kernel.org/stable/c/ddc0ef4217cc697c6ba1a295cc1ea42423ec68ac"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix potential UAF on meter attach failure\n\nWhile attaching a newly created meter attach_meter() function makes\nthe new meter visible to other CPUs but can still fail afterwards.\nOn failure, it detaches the meter back and returns an error.\n\nHowever, this is an unexpected behavior for the ovs_meter_cmd_set()\nthat uses a plain kfree(meter) on attach failure without waiting for\nRCU readers to stop using it, assuming it was never visible.\n\nThis is never a problem for ovs-vswitchd as it always creates meters\nbefore creating any flows that use them.  But the UAF can be triggered\nwith a custom application using uAPI:\n\n BUG: KASAN: slab-use-after-free in ovs_meter_execute (net/openvswitch/meter.c:653)\n Read of size 8 at addr ffff88810d152650 by task meter/2508\n\n Call Trace:\n  ovs_meter_execute (net/openvswitch/meter.c:653)\n  do_execute_actions (net/openvswitch/actions.c:1407)\n  ovs_execute_actions (net/openvswitch/actions.c:1584)\n  ovs_packet_cmd_execute (net/openvswitch/datapath.c:703)\n  ...\n  netlink_sendmsg (af_netlink.c:1900)\n\n Allocated by task 2519:\n  __kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)\n  ovs_meter_cmd_set (net/openvswitch/meter.c:422)\n  ...\n  netlink_sendmsg (af_netlink.c:1900)\n\n Freed by task 2519:\n  kfree (mm/slub.c:2705 mm/slub.c:6405 mm/slub.c:6720)\n  ovs_meter_cmd_set (net/openvswitch/meter.c:479)\n  ...\n  netlink_sendmsg (af_netlink.c:1900)\n\nFix that by making sure attach_meter() doesn't make the meter visible\nuntil all the checks are done and the function can't fail anymore.\n\nThis also makes sure the \"hash\" value is calculated after the potential\nre-sizing of the table.\n\nReported by Trend Micro's Zero Day Initiative as ZDI-CAN-31642.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74465","epss":0.00126,"percentile":0.02564,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74465","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74466","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74466","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/zcrypt: Close speculative mem read possibility  The domain value is extracted from a given CCA or EP11 ioctl struct when a CPRB is about to be sent. Thus this is a user controlled value. Under some special conditions (custom device node used, administrative load) this value is used as an array index after bounds checking, but without speculation barrier.  Add the missing array_index_nospec() call to prevent speculative execution where this domain value is used.","cvss":[],"epss":[{"cve":"CVE-2026-74466","epss":0.0017,"percentile":0.06588,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08499999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74466","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74466","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/82b62eda68abfb7a33ac40f24b8c4128c2891148","https://git.kernel.org/stable/c/e935cd525af4c6ed2e2c6404aa27ca19c7f39ddb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Close speculative mem read possibility\n\nThe domain value is extracted from a given CCA or EP11 ioctl struct\nwhen a CPRB is about to be sent. Thus this is a user controlled value.\nUnder some special conditions (custom device node used, administrative\nload) this value is used as an array index after bounds checking, but\nwithout speculation barrier.\n\nAdd the missing array_index_nospec() call to prevent speculative\nexecution where this domain value is used.","cvss":[],"epss":[{"cve":"CVE-2026-74466","epss":0.0017,"percentile":0.06588,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74466","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74467","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74467","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/qeth: Check CAP_NET_ADMIN for private ioctls  Gate the SIOCDEVPRIVATE ioctl commands SIOC_QETH_ADP_SET_SNMP_CONTROL, SIOC_QETH_GET_CARD_TYPE and SIOC_QETH_QUERY_OAT with CAP_NET_ADMIN capable check to ensure unprivileged users cannot invoke them.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74467","epss":0.00129,"percentile":0.02901,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74467","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74467","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3ea5210db058347481c93849786982f874f7be2d","https://git.kernel.org/stable/c/4e48168825818bf4a13c743582227d15f1d30d04","https://git.kernel.org/stable/c/8fb69547924bbb3d7c900a0d7d137a7234db3f5f","https://git.kernel.org/stable/c/93a0a846ec59a88e0c402878a15357a5ce430eb4","https://git.kernel.org/stable/c/b40c74262f7e1e601221cebccdbdb2b392ff9976","https://git.kernel.org/stable/c/bd63c7879eaa87f1958f7ee027813356fcd9ff11","https://git.kernel.org/stable/c/d211028bac1bd0fff0026bfa2a8328e5b78cd0e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/qeth: Check CAP_NET_ADMIN for private ioctls\n\nGate the SIOCDEVPRIVATE ioctl commands SIOC_QETH_ADP_SET_SNMP_CONTROL,\nSIOC_QETH_GET_CARD_TYPE and SIOC_QETH_QUERY_OAT with CAP_NET_ADMIN\ncapable check to ensure unprivileged users cannot invoke them.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74467","epss":0.00129,"percentile":0.02901,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74467","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74468","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74468","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: pch: use raw_spinlock_t for the register lock  pch_irq_type() is registered as the irq_chip .irq_set_type callback and takes chip->spinlock with spin_lock_irqsave().  This callback is reached from __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while the caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled. That context is not sleepable, but on PREEMPT_RT a regular spinlock_t is an rtmutex-backed sleeping lock, so acquiring it there is invalid.  This was confirmed on a PREEMPT_RT kernel with lockdep (PROVE_RAW_LOCK_NESTING and DEBUG_ATOMIC_SLEEP).  A grounded PoC mirrored pch_irq_type()'s locking and drove it through the real genirq carrier irq_set_irq_type() -> __irq_set_trigger() -> chip->irq_set_type(), i.e. the same __irq_set_trigger() edge that __setup_irq() takes for a requested IRQ.  With the original spin_lock_irqsave() edge lockdep reported an invalid wait context, immediately followed by:    BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48   in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 95, name: insmod   hardirqs last disabled at (3784): _raw_spin_lock_irqsave+0x4f/0x60    rt_spin_lock+0x3a/0x1c0    repro_irq_set_type+0x64/0xa0 [pch_repro]    __irq_set_trigger+0x69/0x140    irq_set_irq_type+0x78/0xd0  Switching the mirrored lock to raw_spinlock_t made both splats go away.  Convert the register lock to raw_spinlock_t.  The same lock also serializes the GPIO direction/value callbacks and the suspend/resume register save/restore, but all of those critical sections only perform MMIO register accesses (ioread32()/iowrite32()) and irq_set_handler_locked(); none of them contain sleepable operations. Keeping this register lock non-sleeping is therefore appropriate for the irqchip callbacks and does not change the GPIO-side locking contract.  This is the same class of issue and fix as recently addressed for other GPIO controllers, e.g. commit 286533cb14a3 (\"gpio: sch: use raw_spinlock_t in the irq startup path\") and commit 90f0109019e6 (\"gpio: eic-sprd: use raw_spinlock_t in the irq startup path\").","cvss":[],"epss":[{"cve":"CVE-2026-74468","epss":0.0018,"percentile":0.07734,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09},"relatedVulnerabilities":[{"id":"CVE-2026-74468","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74468","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/16da33cb36e663b6967112185e11d00ce8ff957c","https://git.kernel.org/stable/c/466ab0c41d5f54f71cee60619d07c4abd0ffd2cd","https://git.kernel.org/stable/c/935e6872db7faecfbe1a10b3f5d97a62fdff5ec9","https://git.kernel.org/stable/c/98f292cb6d01487d17988d9fd4e19c13e7adb156","https://git.kernel.org/stable/c/a02b8950d619123da64f69b70fe1dadef217dfe4","https://git.kernel.org/stable/c/c0a4ec89fc26e4b679b04f1002c503cb2529acdc","https://git.kernel.org/stable/c/efc76a3f5353dd33a2e2ad48200cd4a18de30a0d","https://git.kernel.org/stable/c/ff050589a21967883bb55f6dba42568f8367ad4a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: pch: use raw_spinlock_t for the register lock\n\npch_irq_type() is registered as the irq_chip .irq_set_type callback and\ntakes chip->spinlock with spin_lock_irqsave().  This callback is reached\nfrom __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while\nthe caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled.\nThat context is not sleepable, but on PREEMPT_RT a regular spinlock_t is\nan rtmutex-backed sleeping lock, so acquiring it there is invalid.\n\nThis was confirmed on a PREEMPT_RT kernel with lockdep\n(PROVE_RAW_LOCK_NESTING and DEBUG_ATOMIC_SLEEP).  A grounded PoC mirrored\npch_irq_type()'s locking and drove it through the real genirq carrier\nirq_set_irq_type() -> __irq_set_trigger() -> chip->irq_set_type(), i.e.\nthe same __irq_set_trigger() edge that __setup_irq() takes for a\nrequested IRQ.  With the original spin_lock_irqsave() edge lockdep\nreported an invalid wait context, immediately followed by:\n\n  BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48\n  in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 95, name: insmod\n  hardirqs last disabled at (3784): _raw_spin_lock_irqsave+0x4f/0x60\n   rt_spin_lock+0x3a/0x1c0\n   repro_irq_set_type+0x64/0xa0 [pch_repro]\n   __irq_set_trigger+0x69/0x140\n   irq_set_irq_type+0x78/0xd0\n\nSwitching the mirrored lock to raw_spinlock_t made both splats go away.\n\nConvert the register lock to raw_spinlock_t.  The same lock also\nserializes the GPIO direction/value callbacks and the suspend/resume\nregister save/restore, but all of those critical sections only perform\nMMIO register accesses (ioread32()/iowrite32()) and\nirq_set_handler_locked(); none of them contain sleepable operations.\nKeeping this register lock non-sleeping is therefore appropriate for the\nirqchip callbacks and does not change the GPIO-side locking contract.\n\nThis is the same class of issue and fix as recently addressed for other\nGPIO controllers, e.g. commit 286533cb14a3 (\"gpio: sch: use raw_spinlock_t\nin the irq startup path\") and commit 90f0109019e6 (\"gpio: eic-sprd: use\nraw_spinlock_t in the irq startup path\").","cvss":[],"epss":[{"cve":"CVE-2026-74468","epss":0.0018,"percentile":0.07734,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74468","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74469","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74469","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: prevent peer transport count overflow  sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero.  SCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload, then copies one sockaddr_storage for every entry in transport_addr_list. After the wrap, a diagnostic dump reserves an empty payload and writes 8 MiB of peer addresses past the skb tail.  Reject a new unique peer when transport_count has reached U16_MAX. Perform the check after the existing-peer lookup so a duplicate address continues to return its existing transport at the limit.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74469","epss":0.00469,"percentile":0.39106,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.382235},"relatedVulnerabilities":[{"id":"CVE-2026-74469","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74469","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/09e722030e8148ba4ed1e42c6b2ea57bda9f9895","https://git.kernel.org/stable/c/4ba5bf7ed50f235ea4581de8e7a0002f4ed287b0","https://git.kernel.org/stable/c/546221b86ceeba0d8fec92d46a0604bb7b62be07","https://git.kernel.org/stable/c/6201cd1d70f1670c5b31ac506e7ab2fa7b8e7f75","https://git.kernel.org/stable/c/80f48523a0fe42db2e7375dff4e38a25c117090a","https://git.kernel.org/stable/c/b453e00da1211e997b82743d28af7714c59c05c8","https://git.kernel.org/stable/c/bd0e9289e2642f6a5c54faad304ce0f41e926d22","https://git.kernel.org/stable/c/dfea32dd76f390e3155177b0038cc47b01386198"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: prevent peer transport count overflow\n\nsctp_assoc_add_peer() increments the association's 16-bit transport_count\nfor every new unique peer. Adding the 65,536th transport wraps the count to\nzero.\n\nSCTP sock_diag uses transport_count to reserve the INET_DIAG_PEERS payload,\nthen copies one sockaddr_storage for every entry in transport_addr_list.\nAfter the wrap, a diagnostic dump reserves an empty payload and writes\n8 MiB of peer addresses past the skb tail.\n\nReject a new unique peer when transport_count has reached U16_MAX. Perform\nthe check after the existing-peer lookup so a duplicate address continues\nto return its existing transport at the limit.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74469","epss":0.00469,"percentile":0.39106,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74469","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74470","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74470","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write  resp_report_zones() sizes the reply buffer from the CDB allocation length. The v3 fix rounds alloc_len up with ALIGN() before deriving the descriptor count:  \trep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - \t\t\t RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD); \tarr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);  For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to 0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which passes the !arr check, and desc = arr + 64 is then dereferenced in the loop -> out-of-bounds write / panic.  Clamp rep_max_zones to devip->nr_zones. The loop already stops at sdebug_capacity (after nr_zones zones), so a report can never hold more than nr_zones descriptors; the clamp does not change the report, it only bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device property that can never reach 0x100000000.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74470","epss":0.00129,"percentile":0.02902,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74470","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74470","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b","https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066","https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e","https://git.kernel.org/stable/c/5d3e1d006bbb543259f9e31824caadbfff6a5465","https://git.kernel.org/stable/c/7b615fc139e35c81077046df44725c532f7e2404","https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433","https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write\n\nresp_report_zones() sizes the reply buffer from the CDB allocation\nlength. The v3 fix rounds alloc_len up with ALIGN() before deriving the\ndescriptor count:\n\n\trep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -\n\t\t\t RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD);\n\tarr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);\n\nFor alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to\n0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit\nand truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which\npasses the !arr check, and desc = arr + 64 is then dereferenced in the\nloop -> out-of-bounds write / panic.\n\nClamp rep_max_zones to devip->nr_zones. The loop already stops at\nsdebug_capacity (after nr_zones zones), so a report can never hold more\nthan nr_zones descriptors; the clamp does not change the report, it only\nbounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device\nproperty that can never reach 0x100000000.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74470","epss":0.00129,"percentile":0.02902,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74470","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74471","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74471","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing: Check return value of __register_event() in trace_module_add_events()  trace_module_add_events() ignores the return value of __register_event() and unconditionally calls __add_event_to_tracers() for each event.  If __register_event() fails (for example, if event_init() fails), the trace_event_call is not added to ftrace_events list, but __add_event_to_tracers() still creates a trace_event_file pointing to it. If module loading subsequently fails and module memory is freed, tracing state retains a stale trace_event_call pointer in trace_event_file, leading to a use-after-free when tracefs or tracing subsystem operations are later executed.  Fix this by checking the return value of __register_event() and only calling __add_event_to_tracers() if event registration succeeded.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74471","epss":0.00126,"percentile":0.02561,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74471","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74471","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/000765dcdc3edf128990762790543adc4b868f6c","https://git.kernel.org/stable/c/22f954f7a8afe975e85517aff41b35defe05144b","https://git.kernel.org/stable/c/3bf965a2827c44f03294107703e7ba53fbd0a69a","https://git.kernel.org/stable/c/54b7a358f6399c1242d2fb7f4f96085af34baa5e","https://git.kernel.org/stable/c/9d6d79744f01eacaf3d5522f4fcd59939581abfd","https://git.kernel.org/stable/c/ac8719969e6c3c54e939834df812bc41f25453cf","https://git.kernel.org/stable/c/cbb5ed3be9cae70e1c12b1991009b4e12bf4a4ca","https://git.kernel.org/stable/c/d61ee2a27dfd5eb43ddc18af40168f5b9eb1cea5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Check return value of __register_event() in trace_module_add_events()\n\ntrace_module_add_events() ignores the return value of __register_event()\nand unconditionally calls __add_event_to_tracers() for each event.\n\nIf __register_event() fails (for example, if event_init() fails), the\ntrace_event_call is not added to ftrace_events list, but\n__add_event_to_tracers() still creates a trace_event_file pointing to it.\nIf module loading subsequently fails and module memory is freed, tracing\nstate retains a stale trace_event_call pointer in trace_event_file,\nleading to a use-after-free when tracefs or tracing subsystem operations\nare later executed.\n\nFix this by checking the return value of __register_event() and only\ncalling __add_event_to_tracers() if event registration succeeded.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74471","epss":0.00126,"percentile":0.02561,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74471","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74472","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74472","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()  ublk_ctrl_add_dev() memcpy()s the userspace ublksrv_ctrl_dev_info into ub->dev_info and then fixes up the fields the driver owns, but misses ->state and ->ublksrv_pid.  A device added with ->state = UBLK_S_DEV_LIVE passes the \"->state != UBLK_S_DEV_DEAD\" test that ublk_stop_dev_unlocked() uses as its proxy for \"a disk is attached\", while ->ub_disk is still NULL, so DEL_DEV right after ADD_DEV oopses in del_gendisk().  UBLK_S_DEV_QUIESCED plus UBLK_F_USER_RECOVERY dies one step earlier, in ublk_force_abort_dev().  A poisoned ->state also gets START_USER_RECOVERY and the char device read/write path onto a device that was never started, and wedges START_DEV at -EEXIST.  A poisoned ->ublksrv_pid just makes GET_DEV_INFO report an unrelated task as the ublk server.  Reset both after the memcpy(), as ublk_detach_disk() does.  Userspace only ever reads these back, so correcting them silently breaks nothing.  ADD_DEV has copied ->state in unsanitized since ublk was merged, but back then it was harmless: the gendisk was allocated during ADD_DEV, and both teardown and the START_DEV -EEXIST check keyed off disk_live() rather than ->state.  The oops became reachable once the disk allocation moved to START_DEV and those checks switched to ->state.","cvss":[],"epss":[{"cve":"CVE-2026-74472","epss":0.00173,"percentile":0.06831,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74472","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74472","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/127033b79383a3e78361d7e971588aa8849f5124","https://git.kernel.org/stable/c/205feb72e5beb3140e4e1403b6cff30cf739bab9","https://git.kernel.org/stable/c/787c944502e7e63d20a9201bada77e0dd924f458","https://git.kernel.org/stable/c/b67ce16b26ad0f14cfd6071013840aa95f823bea","https://git.kernel.org/stable/c/e65848e4ce352bac9e3465099354c8b8f845391f","https://git.kernel.org/stable/c/ee41b00858ca65b4428e99efe39a4277c1f043d2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()\n\nublk_ctrl_add_dev() memcpy()s the userspace ublksrv_ctrl_dev_info into\nub->dev_info and then fixes up the fields the driver owns, but misses\n->state and ->ublksrv_pid.\n\nA device added with ->state = UBLK_S_DEV_LIVE passes the\n\"->state != UBLK_S_DEV_DEAD\" test that ublk_stop_dev_unlocked() uses as its\nproxy for \"a disk is attached\", while ->ub_disk is still NULL, so DEL_DEV\nright after ADD_DEV oopses in del_gendisk().  UBLK_S_DEV_QUIESCED plus\nUBLK_F_USER_RECOVERY dies one step earlier, in ublk_force_abort_dev().  A\npoisoned ->state also gets START_USER_RECOVERY and the char device\nread/write path onto a device that was never started, and wedges START_DEV\nat -EEXIST.  A poisoned ->ublksrv_pid just makes GET_DEV_INFO report an\nunrelated task as the ublk server.\n\nReset both after the memcpy(), as ublk_detach_disk() does.  Userspace only\never reads these back, so correcting them silently breaks nothing.\n\nADD_DEV has copied ->state in unsanitized since ublk was merged, but back\nthen it was harmless: the gendisk was allocated during ADD_DEV, and both\nteardown and the START_DEV -EEXIST check keyed off disk_live() rather than\n->state.  The oops became reachable once the disk allocation moved to\nSTART_DEV and those checks switched to ->state.","cvss":[],"epss":[{"cve":"CVE-2026-74472","epss":0.00173,"percentile":0.06831,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74472","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74473","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74473","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: use pskb_network_may_pull() in route_shortcircuit()  route_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr)) (or ipv6hdr), which checks if bytes are available starting from skb->data.  However, in vxlan_xmit(), skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20) only checks 20 bytes from skb->data (which is 14 bytes MAC header + 6 bytes of IP header), leaving the rest of the IP header potentially un-pulled in non-linear frags. Subsequent dereferences of ip_hdr(skb)->daddr can read beyond the pulled linear buffer length.  Fix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to the length check to ensure the full network header is present in the linear buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74473","epss":0.00525,"percentile":0.42816,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.4935000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74473","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74473","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/214ba43faf106cb06cd3dd30999c5c809c868b53","https://git.kernel.org/stable/c/26bb2dd0a8839617e2c79ffbbe1923f8e4bab9fb","https://git.kernel.org/stable/c/42887be7c4cf283cce02cd0fb6411221167c8b6c","https://git.kernel.org/stable/c/4f3f96e771a20263635bb5e1307c112d613b4bbd","https://git.kernel.org/stable/c/6bd0a3a1b5744166946f0c551a6665c3b46b05e4","https://git.kernel.org/stable/c/aa0d31376d574ac858a40078431a77127bf04ee4","https://git.kernel.org/stable/c/c419af4924c1593500a40519730ed98575d04a3e","https://git.kernel.org/stable/c/ee799977d7941dbfb11049e17edd9eaf4f8820f7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use pskb_network_may_pull() in route_shortcircuit()\n\nroute_shortcircuit() currently calls pskb_may_pull(skb, sizeof(struct iphdr))\n(or ipv6hdr), which checks if bytes are available starting from skb->data.\n\nHowever, in vxlan_xmit(), skb->data points to the MAC header, so\nskb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, 20)\nonly checks 20 bytes from skb->data (which is 14 bytes MAC header + 6 bytes of\nIP header), leaving the rest of the IP header potentially un-pulled in non-linear\nfrags. Subsequent dereferences of ip_hdr(skb)->daddr can read beyond the pulled\nlinear buffer length.\n\nFix this by using pskb_network_may_pull(), which adds skb_network_offset(skb) to\nthe length check to ensure the full network header is present in the linear buffer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74473","epss":0.00525,"percentile":0.42816,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74473","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74474","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74474","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: use pskb_network_may_pull() for transmit path header pulls  In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was being called to verify the availability of network layer headers (ARP, IPv6/ND, IP/IPv6 MDB keys).  However, during transmit skb->data points to the MAC header, so skb_network_offset(skb) is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data rather than skb_network_offset(skb) + len, which can leave part of the network header in non-linear frags.  Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly account for the MAC header offset.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74474","epss":0.00457,"percentile":0.38359,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.4295800000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74474","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74474","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/6146901881f09ef063eb34ad389f63231f8486f5","https://git.kernel.org/stable/c/7076a34b6e33315dc160b4612bfea1c597495585","https://git.kernel.org/stable/c/94dee751aad627b3645d424b5d0c736d394573e9","https://git.kernel.org/stable/c/b9553558b48db54ac9273e6b98d7263ef5c1a329","https://git.kernel.org/stable/c/bb01c51950c3ff3c76acdd54b85ab38ccc2a8bb4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use pskb_network_may_pull() for transmit path header pulls\n\nIn vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was\nbeing called to verify the availability of network layer headers (ARP, IPv6/ND,\nIP/IPv6 MDB keys).\n\nHowever, during transmit skb->data points to the MAC header, so skb_network_offset(skb)\nis ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data\nrather than skb_network_offset(skb) + len, which can leave part of the network header\nin non-linear frags.\n\nReplace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly\naccount for the MAC header offset.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74474","epss":0.00457,"percentile":0.38359,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74474","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74475","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74475","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: use neigh_ha_snapshot() in route_shortcircuit()  The neighbour hardware address n->ha can be updated asynchronously by the neighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without holding the seqlock loop can lead to torn reads or reading a partially updated MAC address.  Use neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under read_seqbegin()/read_seqretry() lock protection before using it.  Note that arp_reduce() and neigh_reduce() seem to have the same issue left for future patches.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74475","epss":0.00454,"percentile":0.38165,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.4313},"relatedVulnerabilities":[{"id":"CVE-2026-74475","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74475","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/05f2987f73daa05333fd713d05546142f9f7c5f0","https://git.kernel.org/stable/c/32a9590a8d30426e3db63e6b20893e47e02576c0","https://git.kernel.org/stable/c/87210054bad82bbae6f483a742dc45722fb47a6b","https://git.kernel.org/stable/c/8eca411347e1d38964f9ed2c8d3b6ab0e7e4473d","https://git.kernel.org/stable/c/d08e8ac13f2e228cc7fc3c70b5ebe71557b624a0","https://git.kernel.org/stable/c/d0993fc053f29e15cc7c9fe2029df3882a2ab5ab","https://git.kernel.org/stable/c/ec341bb76d77b4c2948764375ee6bfeef4bb41c3","https://git.kernel.org/stable/c/ff89415d34c3ab9f5312316423122e664ed3524f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: use neigh_ha_snapshot() in route_shortcircuit()\n\nThe neighbour hardware address n->ha can be updated asynchronously by the\nneighbour subsystem, protected by n->ha_lock seqlock. Reading n->ha without\nholding the seqlock loop can lead to torn reads or reading a partially updated\nMAC address.\n\nUse neigh_ha_snapshot() in route_shortcircuit() to safely copy n->ha under\nread_seqbegin()/read_seqretry() lock protection before using it.\n\nNote that arp_reduce() and neigh_reduce() seem to have the same issue\nleft for future patches.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74475","epss":0.00454,"percentile":0.38165,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74475","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74476","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74476","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  veth: convert frag_list skbs before running XDP  A frag_list skb can reach veth with data_len set but nr_frags zero. veth_convert_skb_to_xdp_buff() only converts skbs that are shared, locked, have frags[], or do not have enough headroom. It later uses skb_is_nonlinear() to decide whether to set XDP_FLAGS_HAS_FRAGS and xdp_frags_size.  That exposes frag_list data to XDP as if it were stored in frags[], but frags[] is empty. AF_XDP copy mode can then trust the bogus XDP fragment metadata, walk an empty fragment entry, and crash in memcpy() from __xsk_rcv().  Route non-linear skbs through skb_pp_cow_data() before exposing them to XDP, and only advertise XDP frags when the resulting skb has frags[]. skb_copy_bits() already handles frag_list input, and skb_pp_cow_data() builds frags[] output with skb_add_rx_frag(), which is the representation XDP multi-buffer expects.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74476","epss":0.00491,"percentile":0.40637,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.444355},"relatedVulnerabilities":[{"id":"CVE-2026-74476","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74476","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/04958dba44dc795dc79ce2fcbc117821bbbd6542","https://git.kernel.org/stable/c/0be3632597b8349d43a7dc4244b492dc62a05998","https://git.kernel.org/stable/c/5c1c15c540fc45820ce3033c319151ec891bc10a","https://git.kernel.org/stable/c/b24ba0bbffe3e23eb2f6838881c1fabcb29fb9fb","https://git.kernel.org/stable/c/d0d6415963040c401e7a7e4e482a698ba52448cb","https://git.kernel.org/stable/c/f9c1fff857e93be709c8b52ed1a643f37bd82c66"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nveth: convert frag_list skbs before running XDP\n\nA frag_list skb can reach veth with data_len set but nr_frags zero.\nveth_convert_skb_to_xdp_buff() only converts skbs that are shared,\nlocked, have frags[], or do not have enough headroom. It later uses\nskb_is_nonlinear() to decide whether to set XDP_FLAGS_HAS_FRAGS and\nxdp_frags_size.\n\nThat exposes frag_list data to XDP as if it were stored in frags[], but\nfrags[] is empty. AF_XDP copy mode can then trust the bogus XDP fragment\nmetadata, walk an empty fragment entry, and crash in memcpy() from\n__xsk_rcv().\n\nRoute non-linear skbs through skb_pp_cow_data() before exposing them to\nXDP, and only advertise XDP frags when the resulting skb has frags[].\nskb_copy_bits() already handles frag_list input, and skb_pp_cow_data()\nbuilds frags[] output with skb_add_rx_frag(), which is the\nrepresentation XDP multi-buffer expects.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74476","epss":0.00491,"percentile":0.40637,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74476","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74478","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74478","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  um: vector: fix use-after-free in vector_mmsg_rx()  When vector_mmsg_rx() discards a packet whose overlay header fails verify_header(), it frees the skb and continues the loop:  \tif (header_check < 0) { \t\tdev_kfree_skb_irq(skb); \t\tvp->estats.rx_encaps_errors++; \t\tcontinue; \t}  The normal and short-packet paths fall through to the bottom of the loop body, which clears the consumed slot and advances the cursors:  \t(*skbuff_vector) = NULL; \tmmsg_vector++; \tskbuff_vector++;  The verify_header() < 0 path skips that via continue, so the freed skb is left in skbuff_vector[] and the cursors do not advance. The next iteration reads the same slot, gets the freed skb, and frees it again, producing a refcount underflow / use-after-free in the RX path.  Discard the slot the same way the other paths do before continuing.  Only transports whose verify_header() can return negative are affected: GRE and L2TPv3 do so on a cookie/session-id mismatch (raw/tap do not), so any peer on such a transport can trigger it without authentication.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74478","epss":0.00573,"percentile":0.4541,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.53862},"relatedVulnerabilities":[{"id":"CVE-2026-74478","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74478","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/180ff4c81faf01ec4e06082c9daa7c40518ead89","https://git.kernel.org/stable/c/4b9601595e8b6b5d18878cac0aeabc687d241111","https://git.kernel.org/stable/c/67d58ab4f2ccf7145f3da07e025735a09c79de1b","https://git.kernel.org/stable/c/7dc9781e320d664c9bdd50003c9acfddf363d1e1","https://git.kernel.org/stable/c/804b681002ead233abf49a3efd681f5468a835f9","https://git.kernel.org/stable/c/967c779c9853d2a1cc9cd8e61d300250c348f3d9","https://git.kernel.org/stable/c/a7bc015bb798c525e7a82dd14225c6aeb994274b","https://git.kernel.org/stable/c/af421e9aed3920c7ac88c24daa48606c7112feca"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\num: vector: fix use-after-free in vector_mmsg_rx()\n\nWhen vector_mmsg_rx() discards a packet whose overlay header fails\nverify_header(), it frees the skb and continues the loop:\n\n\tif (header_check < 0) {\n\t\tdev_kfree_skb_irq(skb);\n\t\tvp->estats.rx_encaps_errors++;\n\t\tcontinue;\n\t}\n\nThe normal and short-packet paths fall through to the bottom of the\nloop body, which clears the consumed slot and advances the cursors:\n\n\t(*skbuff_vector) = NULL;\n\tmmsg_vector++;\n\tskbuff_vector++;\n\nThe verify_header() < 0 path skips that via continue, so the freed skb\nis left in skbuff_vector[] and the cursors do not advance. The next\niteration reads the same slot, gets the freed skb, and frees it again,\nproducing a refcount underflow / use-after-free in the RX path.\n\nDiscard the slot the same way the other paths do before continuing.\n\nOnly transports whose verify_header() can return negative are affected:\nGRE and L2TPv3 do so on a cookie/session-id mismatch (raw/tap do not),\nso any peer on such a transport can trigger it without authentication.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74478","epss":0.00573,"percentile":0.4541,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74478","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74479","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74479","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: pktgen: fix proc entry use-after-free  pktgen_change_name() replaces pkt_dev->entry while holding t->if_lock. pktgen_remove_device() removes the same entry before _rem_dev_from_if_list() takes that lock.  This allows the following interleaving:    CPU 0 (NETDEV_CHANGENAME)       CPU 1 (kpktgend)   if_lock(t)   proc_remove(pkt_dev->entry)                                   proc_remove(pkt_dev->entry)   pkt_dev->entry = proc_create_data(...)   if_unlock(t)  The kthread can pass the stale proc_dir_entry to proc_remove() after the rename path has freed it. A reproducer with a widened race window reports:    BUG: KASAN: slab-use-after-free in proc_remove+0x78/0x80   Read of size 8 at addr ffff8881478fea70 by task kpktgend_0/67   Call Trace:    proc_remove+0x78/0x80    pktgen_remove_device.isra.0+0x11c/0x4c0    pktgen_thread_worker+0x1214/0x6bc0    kthread+0x2c6/0x3b0   Allocated by task 95:    __proc_create+0x204/0x790    proc_create_data+0x72/0xe0    pktgen_thread_write+0xd61/0x1510   Freed by task 28:    kmem_cache_free+0xcb/0x3d0    proc_free_inode+0x5b/0x80    rcu_core+0x50a/0x1850   The buggy address belongs to the object at ffff8881478fea00    which belongs to the cache proc_dir_entry of size 192  Move proc_remove() into the if_lock-protected list removal helper. Keep it before list_del_rcu() to preserve the ordering required by add_device(). The rename path must then finish replacing the entry before removal, or it observes that the device is no longer on the list.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74479","epss":0.00126,"percentile":0.02561,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74479","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74479","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4ef801b838d85c0ea5852c50667f7344ce3b6cd0","https://git.kernel.org/stable/c/577443530cb592d5782a1f79847411a9363a65c8","https://git.kernel.org/stable/c/7991c7cff8b8622cddb3d8dee07dbe74aa4cbec4","https://git.kernel.org/stable/c/817ff6efdb7f484ea547218e11e17d8e43daa3b4","https://git.kernel.org/stable/c/82ed3db9269cb61e3c15bad2f6e221efce90e1e0","https://git.kernel.org/stable/c/b006a5404470bd3eb2aa0425fc447183032047ef","https://git.kernel.org/stable/c/d1cc9797cf8f7aeb87e7ad01b748c6a960a819e4","https://git.kernel.org/stable/c/f85a58340b91f225de3299dfa782c6414098077c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: pktgen: fix proc entry use-after-free\n\npktgen_change_name() replaces pkt_dev->entry while holding t->if_lock.\npktgen_remove_device() removes the same entry before\n_rem_dev_from_if_list() takes that lock.\n\nThis allows the following interleaving:\n\n  CPU 0 (NETDEV_CHANGENAME)       CPU 1 (kpktgend)\n  if_lock(t)\n  proc_remove(pkt_dev->entry)\n                                  proc_remove(pkt_dev->entry)\n  pkt_dev->entry = proc_create_data(...)\n  if_unlock(t)\n\nThe kthread can pass the stale proc_dir_entry to proc_remove() after the\nrename path has freed it. A reproducer with a widened race window reports:\n\n  BUG: KASAN: slab-use-after-free in proc_remove+0x78/0x80\n  Read of size 8 at addr ffff8881478fea70 by task kpktgend_0/67\n  Call Trace:\n   proc_remove+0x78/0x80\n   pktgen_remove_device.isra.0+0x11c/0x4c0\n   pktgen_thread_worker+0x1214/0x6bc0\n   kthread+0x2c6/0x3b0\n  Allocated by task 95:\n   __proc_create+0x204/0x790\n   proc_create_data+0x72/0xe0\n   pktgen_thread_write+0xd61/0x1510\n  Freed by task 28:\n   kmem_cache_free+0xcb/0x3d0\n   proc_free_inode+0x5b/0x80\n   rcu_core+0x50a/0x1850\n  The buggy address belongs to the object at ffff8881478fea00\n   which belongs to the cache proc_dir_entry of size 192\n\nMove proc_remove() into the if_lock-protected list removal helper. Keep it\nbefore list_del_rcu() to preserve the ordering required by add_device().\nThe rename path must then finish replacing the entry before removal, or\nit observes that the device is no longer on the list.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74479","epss":0.00126,"percentile":0.02561,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74479","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74480","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74480","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: bridge: stop fast-leave after deleting a port group  br_multicast_leave_group() iterates mp->ports with pp = &p->next in its fast-leave path. After br_multicast_del_pg() removes p, continuing the loop advances pp through the deleted entry.  If multicast-to-unicast was enabled, the bridge can hold multiple port groups for the same port and group with different source MAC addresses. Once multicast-to-unicast is disabled, br_port_group_equal() matches those entries by port only. A fast leave can then delete one entry and continue from its stale next pointer, leaving mp->ports pointing at a deleted port group.  Fast leave only needs to remove one matching port group. Break after br_multicast_del_pg() so the loop stops before dereferencing the removed entry.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74480","epss":0.0056,"percentile":0.44758,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.5264000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74480","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74480","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0309ebbc570000ea0df11c06b69798e5860c5f6f","https://git.kernel.org/stable/c/159ad90cb929c033308bb39a2c5f8fbf393b77aa","https://git.kernel.org/stable/c/1a109cc9890d017c41d77e6c82da739579c49f0b","https://git.kernel.org/stable/c/4695430e8132420bf8de94da3eb36a6cf35fde6b","https://git.kernel.org/stable/c/482bcb85139addb4e8ac8ed10baeda3e0aad4031","https://git.kernel.org/stable/c/4c57056ca6aace2e9f94ae9298bf49ef6b0c95e4","https://git.kernel.org/stable/c/a39789f211b8a4125f0c70e05b30cf715f4f187d","https://git.kernel.org/stable/c/d6c32e2e25a9a06ba021030e26b6d602a277eb72"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: stop fast-leave after deleting a port group\n\nbr_multicast_leave_group() iterates mp->ports with pp = &p->next in\nits fast-leave path. After br_multicast_del_pg() removes p,\ncontinuing the loop advances pp through the deleted entry.\n\nIf multicast-to-unicast was enabled, the bridge can hold multiple port\ngroups for the same port and group with different source MAC\naddresses. Once multicast-to-unicast is disabled,\nbr_port_group_equal() matches those entries by port only. A fast leave\ncan then delete one entry and continue from its stale next pointer,\nleaving mp->ports pointing at a deleted port group.\n\nFast leave only needs to remove one matching port group. Break after\nbr_multicast_del_pg() so the loop stops before dereferencing the\nremoved entry.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74480","epss":0.0056,"percentile":0.44758,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74480","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74481","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74481","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/page_reporting: use system_freezable_wq to fix UAF during suspend  During PM freeze (e.g.  S3 suspend or S4 hibernation), device drivers like virtio_balloon reset their underlying virtio devices and delete their virtqueues via vdev->config->del_vqs().  However, page reporting work (page_reporting_process) was scheduled on the global system_wq.  Because system_wq lacks the WQ_FREEZABLE flag, the PM freezer skips it, leaving page_reporting_process active during suspend.  If pages are freed into the buddy allocator while suspending (for example, when core MM invokes the balloon shrinker during S4 hibernation image saving), page reporting triggers virtballoon_free_page_report() on deleted virtqueues, resulting in a Use-After-Free / General Protection Fault:      [  196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI     [  196.825967] Workqueue: events page_reporting_process     [  196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]     [  196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]     [  196.946943] page_reporting_process+0x370/0x4f0  Fix this by switching page reporting work to system_freezable_wq.  This ensures that the PM freezer pauses page_reporting_process before device drivers destroy their reporting virtqueues.  Because the reporting worker is frozen, memory reclamation/freeing (e.g.  via shrinker execution) can safely return pages to MM during freeze without triggering unfrozen reporting work on deleted virtqueues.  This aligns with the driver's existing design. The comment in virtballoon_freeze() states:     /*      * The workqueue is already frozen by the PM core before this      * function is called.      */  Testing: I have verified these fixes using Google’s virtualization infrastructure by running continuous suspend/resume iterations (40+ cycles) while churning memory using stress-ng (`stress-ng --vm 4 --vm-bytes 60% --timeout 1`) to constantly create free pages for the buddy allocator.  We also set the `page_reporting_order` parameter to 0 to make the page reporting worker highly sensitive, forcing it to pick up any 4K free pages.  This confirmed that the UAF crashes are no longer reproducible.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74481","epss":0.00132,"percentile":0.03132,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10097999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74481","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74481","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b45f6927a14914ff685fe0e6f9d11232a1e03df","https://git.kernel.org/stable/c/450f35f4d5a682a0796757e52295df58ddb63bc9","https://git.kernel.org/stable/c/992f270fd808338fbae1f498a5e325e7e2e20368","https://git.kernel.org/stable/c/a4c60046052777ca1dcc83fe3ece2a5136b301f1","https://git.kernel.org/stable/c/b11907c905fa08eda925395f0724b7a409870f65","https://git.kernel.org/stable/c/b2c094e98f8bb823b3ae475f7169fe2091c40c6d","https://git.kernel.org/stable/c/f978048326570047e8216e81a67f9c71ef2bb1b1","https://git.kernel.org/stable/c/faf439b5fa7b231120eac4f7a617e0bfd4f6f5c7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_reporting: use system_freezable_wq to fix UAF during suspend\n\nDuring PM freeze (e.g.  S3 suspend or S4 hibernation), device drivers like\nvirtio_balloon reset their underlying virtio devices and delete their\nvirtqueues via vdev->config->del_vqs().\n\nHowever, page reporting work (page_reporting_process) was scheduled on the\nglobal system_wq.  Because system_wq lacks the WQ_FREEZABLE flag, the PM\nfreezer skips it, leaving page_reporting_process active during suspend.\n\nIf pages are freed into the buddy allocator while suspending (for example,\nwhen core MM invokes the balloon shrinker during S4 hibernation image\nsaving), page reporting triggers virtballoon_free_page_report() on deleted\nvirtqueues, resulting in a Use-After-Free / General Protection Fault:\n\n    [  196.795226] general protection fault, probably for non-canonical address 0xaa1436fe70dae6df: 0000 [#1] SMP NOPTI\n    [  196.825967] Workqueue: events page_reporting_process\n    [  196.831038] RIP: 0010:virtqueue_add_split+0x233/0x4c0 [virtio_ring]\n    [  196.927073] virtballoon_free_page_report+0x3a/0xe0 [virtio_balloon]\n    [  196.946943] page_reporting_process+0x370/0x4f0\n\nFix this by switching page reporting work to system_freezable_wq.  This\nensures that the PM freezer pauses page_reporting_process before device\ndrivers destroy their reporting virtqueues.  Because the reporting worker\nis frozen, memory reclamation/freeing (e.g.  via shrinker execution) can\nsafely return pages to MM during freeze without triggering unfrozen\nreporting work on deleted virtqueues.\n\nThis aligns with the driver's existing design. The comment in\nvirtballoon_freeze() states:\n    /*\n     * The workqueue is already frozen by the PM core before this\n     * function is called.\n     */\n\nTesting:\nI have verified these fixes using Google’s virtualization infrastructure\nby running continuous suspend/resume iterations (40+ cycles) while\nchurning memory using stress-ng (`stress-ng --vm 4 --vm-bytes 60%\n--timeout 1`) to constantly create free pages for the buddy allocator.  We\nalso set the `page_reporting_order` parameter to 0 to make the page\nreporting worker highly sensitive, forcing it to pick up any 4K free\npages.  This confirmed that the UAF crashes are no longer reproducible.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74481","epss":0.00132,"percentile":0.03132,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74481","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74482","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74482","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios  __folio_split() keeps dereferencing the mapping after the split: shmem_uncharge(mapping->host) and remap_page() while the folios are still frozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the after-split folios have been unlocked and freed.  Nothing holds an inode reference across that.  The split relies on @folio -- which the beyond-EOF drop loop never removes, as it starts at folio_next(folio) -- staying locked and in the page cache to hold off eviction.  But the unlock loop unlocks @folio before i_mmap_unlock_read() runs.  If the caller's @lock_at is a tail beyond EOF, as memory_failure() passes when splitting a poisoned tail of a shmem THP that reaches past i_size during truncation, it too is gone from the page cache; so once @folio is unlocked no locked, in-cache folio pins the inode, and a concurrent final iput() can evict and RCU-free it before i_mmap_unlock_read() touches i_mmap_rwsem:    BUG: KASAN: slab-use-after-free in __up_read+0x634/0x790    i_mmap_unlock_read include/linux/fs.h:537 [inline]    __folio_split+0x732/0x1640 mm/huge_memory.c:4100    try_to_split_thp_page+0xab/0x390 mm/memory-failure.c:1675    memory_failure+0x1394/0x26e0 mm/memory-failure.c:2470    Freed by task 4601:    shmem_free_in_core_inode+0x54/0xb0 mm/shmem.c:5177    evict+0x57f/0xac0 fs/inode.c:870  Do every mapping dereference while @folio still pins the inode: drop i_mmap_rwsem right after remap_page(), before the loop that unlocks and frees the after-split folios, and clear @mapping so the exit path does not unlock it again.  shmem_uncharge() and remap_page() already run before that point, so after this nothing past the unlock loop touches the inode or the mapping.  This is now a rule the split depends on, alongside keeping @folio frozen until the page cache is updated: no inode or mapping dereference once the after-split folios start being unlocked.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74482","epss":0.00126,"percentile":0.02561,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74482","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74482","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/10065fb891651d9541e7a5a2db84c1e656ece4f9","https://git.kernel.org/stable/c/6f5c272d71845a669e4c8ee5c72b376e29a0e6e5","https://git.kernel.org/stable/c/bc2f5eabaaf60ec18da70b619a8fba1bfb7dea3a","https://git.kernel.org/stable/c/be106f7855f03d3128ed0ce70ba74b484a90b473","https://git.kernel.org/stable/c/d640efe94d86d3be893d4c19220362546a637e90","https://git.kernel.org/stable/c/e3dd774dbfd0b5bc2dbd0995221751b1234f8205","https://git.kernel.org/stable/c/e923bd21058ea02fd0dcd3549d151d143fd036e5","https://git.kernel.org/stable/c/f87c08060818ebb19bafed37c38244538da25097"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios\n\n__folio_split() keeps dereferencing the mapping after the split:\nshmem_uncharge(mapping->host) and remap_page() while the folios are still\nfrozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the\nafter-split folios have been unlocked and freed.\n\nNothing holds an inode reference across that.  The split relies on @folio\n-- which the beyond-EOF drop loop never removes, as it starts at\nfolio_next(folio) -- staying locked and in the page cache to hold off\neviction.  But the unlock loop unlocks @folio before i_mmap_unlock_read()\nruns.  If the caller's @lock_at is a tail beyond EOF, as memory_failure()\npasses when splitting a poisoned tail of a shmem THP that reaches past\ni_size during truncation, it too is gone from the page cache; so once\n@folio is unlocked no locked, in-cache folio pins the inode, and a\nconcurrent final iput() can evict and RCU-free it before\ni_mmap_unlock_read() touches i_mmap_rwsem:\n\n  BUG: KASAN: slab-use-after-free in __up_read+0x634/0x790\n   i_mmap_unlock_read include/linux/fs.h:537 [inline]\n   __folio_split+0x732/0x1640 mm/huge_memory.c:4100\n   try_to_split_thp_page+0xab/0x390 mm/memory-failure.c:1675\n   memory_failure+0x1394/0x26e0 mm/memory-failure.c:2470\n\n  Freed by task 4601:\n   shmem_free_in_core_inode+0x54/0xb0 mm/shmem.c:5177\n   evict+0x57f/0xac0 fs/inode.c:870\n\nDo every mapping dereference while @folio still pins the inode: drop\ni_mmap_rwsem right after remap_page(), before the loop that unlocks and\nfrees the after-split folios, and clear @mapping so the exit path does not\nunlock it again.  shmem_uncharge() and remap_page() already run before\nthat point, so after this nothing past the unlock loop touches the inode\nor the mapping.\n\nThis is now a rule the split depends on, alongside keeping @folio frozen\nuntil the page cache is updated: no inode or mapping dereference once the\nafter-split folios start being unlocked.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74482","epss":0.00126,"percentile":0.02561,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74482","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74485","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74485","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  binfmt_misc: reject a flag character as the field delimiter  The registration string starts with a user chosen delimiter that separates the individual fields. So that the field parsers terminate even on a truncated string create_entry() pads the buffer with that same delimiter:  \tmemset(buf + count, del, 8);  Most fields are scanned for the delimiter with strchr()/scanarg() and happily stop on the padding. The flags field is different: instead of scanning for the delimiter check_special_flags() consumes the flag characters 'P', 'O', 'C' and 'F' and stops at the first byte that is none of them, relying on the trailing delimiter to end the scan.  If the delimiter is itself a flag character the padding no longer acts as a terminator. The scan swallows all eight padding bytes and keeps reading past the end of the allocation until it hits a byte that is not a flag character. For example registering  \tPaPEPPxPPiP  with 'P' as the delimiter (name \"a\", type extension, magic \"x\", interpreter \"i\", empty flags) leaves the flag scan running off the end of the buffer. The registration is rejected in the end because the parser does not stop exactly at buf + count, but only after the out of bounds read has already happened. With an unlucky allocation layout the scan can walk into an unmapped page; under KASAN it is reported as a slab out of bounds read. binfmt_misc mounts are available to unprivileged users in a user namespace so the read is reachable without privileges.  Reject a delimiter that is one of the flag characters up front. Such a registration was always rejected anyway, only after the out of bounds read, so no valid registration string changes meaning.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74485","epss":0.00126,"percentile":0.02583,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09198},"relatedVulnerabilities":[{"id":"CVE-2026-74485","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74485","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1819f82dee766c58295ecaacdac02cdf6837d7a4","https://git.kernel.org/stable/c/1853e95c9bfe69ef1dd862b3f551e68f4a1b76cc","https://git.kernel.org/stable/c/840bb9c49c3e75fb32b593d67ab32f6b77122262","https://git.kernel.org/stable/c/8e85d50ba1117fd446bf9a250bd8a97d48384bdc","https://git.kernel.org/stable/c/96bd5d4fea2970b9b08265293ca7a10b9b27c0fd","https://git.kernel.org/stable/c/9970e094e5d60f0d66914bf9a97d1ef19107ebf5","https://git.kernel.org/stable/c/9a2d87db3898b5993b64fd258d0334e0eba9ee0d","https://git.kernel.org/stable/c/b29e3c1f375c1296362d219ff38bceddf2d2a88a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: reject a flag character as the field delimiter\n\nThe registration string starts with a user chosen delimiter that\nseparates the individual fields. So that the field parsers terminate\neven on a truncated string create_entry() pads the buffer with that\nsame delimiter:\n\n\tmemset(buf + count, del, 8);\n\nMost fields are scanned for the delimiter with strchr()/scanarg() and\nhappily stop on the padding. The flags field is different: instead of\nscanning for the delimiter check_special_flags() consumes the flag\ncharacters 'P', 'O', 'C' and 'F' and stops at the first byte that is\nnone of them, relying on the trailing delimiter to end the scan.\n\nIf the delimiter is itself a flag character the padding no longer acts\nas a terminator. The scan swallows all eight padding bytes and keeps\nreading past the end of the allocation until it hits a byte that is\nnot a flag character. For example registering\n\n\tPaPEPPxPPiP\n\nwith 'P' as the delimiter (name \"a\", type extension, magic \"x\",\ninterpreter \"i\", empty flags) leaves the flag scan running off the end\nof the buffer. The registration is rejected in the end because the\nparser does not stop exactly at buf + count, but only after the out of\nbounds read has already happened. With an unlucky allocation layout the\nscan can walk into an unmapped page; under KASAN it is reported as a\nslab out of bounds read. binfmt_misc mounts are available to\nunprivileged users in a user namespace so the read is reachable without\nprivileges.\n\nReject a delimiter that is one of the flag characters up front. Such a\nregistration was always rejected anyway, only after the out of bounds\nread, so no valid registration string changes meaning.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74485","epss":0.00126,"percentile":0.02583,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74485","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74487","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74487","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  binfmt_misc: restore write access when removing an entry  Registering an entry with the MISC_FMT_OPEN_FILE flag opens the interpreter via open_exec() which denies write access to it for as long as the entry exists. Removing the entry closes the interpreter file via filp_close() but never restores write access, leaving the inode's i_writecount permanently negative. Opening the interpreter for writing keeps failing with ETXTBSY long after the entry is gone until the inode is evicted from the inode cache.  Commit 90f601b497d7 (\"binfmt_misc: restore write access before closing files opened by open_exec()\") fixed the same imbalance in the error path of bm_register_write() but the actual removal path has been leaking the write denial since the introduction of the flag.  Restore write access in put_binfmt_handler() before closing the interpreter file.","cvss":[],"epss":[{"cve":"CVE-2026-74487","epss":0.00177,"percentile":0.07338,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74487","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74487","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/13efc628fdf641d901bdba07caa1c558e1bed046","https://git.kernel.org/stable/c/3b522487a3a9162b1b519eefde7998d103e3e07b","https://git.kernel.org/stable/c/7873f987213695e3564c8c259e6db283e4739472","https://git.kernel.org/stable/c/a50296cca2a1db9d8d21051e7d50f0cf3a4b7ec8","https://git.kernel.org/stable/c/db1856ea9196cf6e015d12199a34c0b9313c7bfa","https://git.kernel.org/stable/c/dd9ba32169e73a3c3ba595cf1de1f4c69ceafb3c","https://git.kernel.org/stable/c/f1cf67f6be0babc73afa4ee0e27bdedffeeeb095","https://git.kernel.org/stable/c/fdc1d702bf3001586221fa07e598e876a0a854c5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: restore write access when removing an entry\n\nRegistering an entry with the MISC_FMT_OPEN_FILE flag opens the\ninterpreter via open_exec() which denies write access to it for as\nlong as the entry exists. Removing the entry closes the interpreter\nfile via filp_close() but never restores write access, leaving the\ninode's i_writecount permanently negative. Opening the interpreter\nfor writing keeps failing with ETXTBSY long after the entry is gone\nuntil the inode is evicted from the inode cache.\n\nCommit 90f601b497d7 (\"binfmt_misc: restore write access before\nclosing files opened by open_exec()\") fixed the same imbalance in the\nerror path of bm_register_write() but the actual removal path has\nbeen leaking the write denial since the introduction of the flag.\n\nRestore write access in put_binfmt_handler() before closing the\ninterpreter file.","cvss":[],"epss":[{"cve":"CVE-2026-74487","epss":0.00177,"percentile":0.07338,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74487","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74488","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74488","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames  mwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with ieee80211_amsdu_to_8023s() and walks the resulting subframes. For each subframe it passes the subframe data pointer to mwifiex_process_tdls_action_frame(), but pairs it with skb->len, the length of the A-MSDU parent, instead of rx_skb->len:  \trx_skb = __skb_dequeue(&list); \trx_hdr = (struct rx_packet_hdr *)rx_skb->data; \tif (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) && \t    ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) { \t\tmwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr, \t\t\t\t\t\t  skb->len); \t}  The parent is not a valid description of that buffer, and may not be valid memory at all. ieee80211_amsdu_to_8023s() ends with  \tif (!reuse_skb) \t\tdev_kfree_skb(skb);  and it only sets reuse_skb when the parent is linear, is not a head_frag, and is being consumed as the *last* subframe. So when the parent does not qualify for reuse it has already been freed, and the read of skb->len is a use-after-free. When it is reused, skb->len is the length of the last subframe, applied to every earlier subframe, which over-states the buffer whenever an earlier subframe is shorter.  The callee cannot absorb a wrong length, because it derives its own ceiling from the value it is given. Each frame type computes  \ties_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN;  and the element walk is then bounded entirely against that ceiling,  \tfor (end = pos + ies_len; pos + 1 < end; pos += 2 + pos[1]) { \t\tu8 ie_len = pos[1];  \t\tif (pos + 2 + ie_len > end) \t\t\tbreak;  so a too-large len moves end past the end of the subframe and the walk reads and copies beyond it. The A-MSDU layout is chosen by the sender, which makes the difference between the last subframe and a shorter earlier one remotely selectable. Reaching this requires TDLS support in firmware and the TDLS ethertype on the subframe.  The other caller, mwifiex_process_rx_packet(), is correct: it passes a pointer and a length that describe the same region of the RX buffer.  Pass rx_skb->len, the length of the subframe actually being parsed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74488","epss":0.00255,"percentile":0.17067,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.20782500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-74488","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74488","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/25e5a3fe4f15e30f74eca42cbf3bcc3a3fbeda79","https://git.kernel.org/stable/c/3b02275833a0d3e6583627995d614fa99bdf364f","https://git.kernel.org/stable/c/5a21ab03829cb6d2682c127f22e2b9cd63b4393f","https://git.kernel.org/stable/c/707664027bb9307f7268eda403af7c4ccd9b8644","https://git.kernel.org/stable/c/99a948382af8a225e2d5e54a7052158cd6281cc6","https://git.kernel.org/stable/c/a1f0f7dc7eb15754e6931b433edb7beb754c996a","https://git.kernel.org/stable/c/c9dcfe6b8b71369e1d732e2ff622c3696a2f032c","https://git.kernel.org/stable/c/ece2ebb34247d573142617dfc534a9dc11ba59be"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames\n\nmwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with\nieee80211_amsdu_to_8023s() and walks the resulting subframes. For each\nsubframe it passes the subframe data pointer to\nmwifiex_process_tdls_action_frame(), but pairs it with skb->len, the\nlength of the A-MSDU parent, instead of rx_skb->len:\n\n\trx_skb = __skb_dequeue(&list);\n\trx_hdr = (struct rx_packet_hdr *)rx_skb->data;\n\tif (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) &&\n\t    ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) {\n\t\tmwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr,\n\t\t\t\t\t\t  skb->len);\n\t}\n\nThe parent is not a valid description of that buffer, and may not be\nvalid memory at all. ieee80211_amsdu_to_8023s() ends with\n\n\tif (!reuse_skb)\n\t\tdev_kfree_skb(skb);\n\nand it only sets reuse_skb when the parent is linear, is not a\nhead_frag, and is being consumed as the *last* subframe. So when the\nparent does not qualify for reuse it has already been freed, and the\nread of skb->len is a use-after-free. When it is reused, skb->len is\nthe length of the last subframe, applied to every earlier subframe,\nwhich over-states the buffer whenever an earlier subframe is shorter.\n\nThe callee cannot absorb a wrong length, because it derives its own\nceiling from the value it is given. Each frame type computes\n\n\ties_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN;\n\nand the element walk is then bounded entirely against that ceiling,\n\n\tfor (end = pos + ies_len; pos + 1 < end; pos += 2 + pos[1]) {\n\t\tu8 ie_len = pos[1];\n\n\t\tif (pos + 2 + ie_len > end)\n\t\t\tbreak;\n\nso a too-large len moves end past the end of the subframe and the walk\nreads and copies beyond it. The A-MSDU layout is chosen by the sender,\nwhich makes the difference between the last subframe and a shorter\nearlier one remotely selectable. Reaching this requires TDLS support in\nfirmware and the TDLS ethertype on the subframe.\n\nThe other caller, mwifiex_process_rx_packet(), is correct: it passes a\npointer and a length that describe the same region of the RX buffer.\n\nPass rx_skb->len, the length of the subframe actually being parsed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74488","epss":0.00255,"percentile":0.17067,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74488","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74490","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74490","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: avoid use-after-free in poll trace queue dumps  TIPC socket tracepoints dump queue state through tipc_sk_dump(). Most queue-dump callsites already serialize that walk under the socket lock or sk->sk_lock.slock, but tipc_poll() calls trace_tipc_sk_poll(..., TIPC_DUMP_ALL, ...) without holding either lock.  That lets the poll trace path reach tipc_list_dump() and backlog head/tail dumping while another context dequeues and frees an skb, leaving the trace helper dereferencing a stale queue entry.  Stop the unlocked poll trace site from requesting queue dumps. Other queue dump trace callsites keep their existing output under the locking they already provide, while poll still emits the event itself without walking live queue members from an unlocked context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74490","epss":0.00455,"percentile":0.38239,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37082500000000007},"relatedVulnerabilities":[{"id":"CVE-2026-74490","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74490","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3cd57c6b210d50fd1f7ac1720442ba5be5dc94f8","https://git.kernel.org/stable/c/5e82beba4bc1f91d0e64c9c43f2b2fa9cd1c2a7d","https://git.kernel.org/stable/c/78706367fe1b98aee0a6de27c62b7f1e3035f38d","https://git.kernel.org/stable/c/ac2f787980fdf4364cd5651a4c8128e59b8de3aa","https://git.kernel.org/stable/c/ae7fc824970888b4fdaa076819c9a6f2fcede275","https://git.kernel.org/stable/c/b4f1719dfea023220e0e6bd892b087d76b2a6a49","https://git.kernel.org/stable/c/bed792737b5f1ba773054dbe984502958bdfe6ce","https://git.kernel.org/stable/c/d7940bb6a8e7ab28f972c2875cb05783216312dc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: avoid use-after-free in poll trace queue dumps\n\nTIPC socket tracepoints dump queue state through tipc_sk_dump(). Most\nqueue-dump callsites already serialize that walk under the socket lock or\nsk->sk_lock.slock, but tipc_poll() calls trace_tipc_sk_poll(...,\nTIPC_DUMP_ALL, ...) without holding either lock.\n\nThat lets the poll trace path reach tipc_list_dump() and backlog head/tail\ndumping while another context dequeues and frees an skb, leaving the trace\nhelper dereferencing a stale queue entry.\n\nStop the unlocked poll trace site from requesting queue dumps. Other queue\ndump trace callsites keep their existing output under the locking they\nalready provide, while poll still emits the event itself without walking\nlive queue members from an unlocked context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74490","epss":0.00455,"percentile":0.38239,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74490","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74492","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74492","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: ipset: do not update comments from kernel-side hash adds  mtype_resize() copies comment pointers with memcpy(), not the comment objects themselves. During the window after an entry has been copied but before the table swap and backlog replay, the old table is still published for packet-side updates while the replacement-table entry already holds the same ip_set_comment_rcu pointer.  If xt_SET --add-set ... --exist hits that old entry in this window, mtype_add() calls ip_set_init_comment() even though packet-side adds carry no comment payload. That call frees the shared comment through the old entry, so the replacement-table entry now holds a stale pointer. When the queued add is replayed on the new table, mtype_add() calls ip_set_init_comment() again and strlen() dereferences the stale pointer.  Fix this in mtype_add() by skipping ip_set_init_comment() when ext->target marks a packet-side add. Userspace adds still update comments, while packet-side adds can no longer free comment storage shared with a resize copy.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74492","epss":0.00142,"percentile":0.03803,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11289000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-74492","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74492","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/16bfa7be2d76ca1e0aacfa363482e1bf8ab5042a","https://git.kernel.org/stable/c/4ae701848e4ba9e9713375fb7d82218cbd309da2","https://git.kernel.org/stable/c/661ff9c0cfbe07f8eed920dde9f7781491738207","https://git.kernel.org/stable/c/6f13f4d52d06986c18f12e8bffaab944dd27ceab","https://git.kernel.org/stable/c/77dbb248a5cc7a5270cd37bbb0b635bf059a872a","https://git.kernel.org/stable/c/c710e9bf38e4e71a8db85d26a0f70c0674664207","https://git.kernel.org/stable/c/f30415929be8aeb002d557c8d3f7ab2d2188003a","https://git.kernel.org/stable/c/f9d6cabff1fca010562dcdb0d22b296bdca3ba5a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: do not update comments from kernel-side hash adds\n\nmtype_resize() copies comment pointers with memcpy(), not the comment\nobjects themselves. During the window after an entry has been copied but\nbefore the table swap and backlog replay, the old table is still\npublished for packet-side updates while the replacement-table entry\nalready holds the same ip_set_comment_rcu pointer.\n\nIf xt_SET --add-set ... --exist hits that old entry in this window,\nmtype_add() calls ip_set_init_comment() even though packet-side adds\ncarry no comment payload. That call frees the shared comment through the\nold entry, so the replacement-table entry now holds a stale pointer.\nWhen the queued add is replayed on the new table, mtype_add() calls\nip_set_init_comment() again and strlen() dereferences the stale pointer.\n\nFix this in mtype_add() by skipping ip_set_init_comment() when\next->target marks a packet-side add. Userspace adds still update\ncomments, while packet-side adds can no longer free comment storage\nshared with a resize copy.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74492","epss":0.00142,"percentile":0.03803,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74492","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74493","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74493","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/smc: fix socket use-after-free during link group termination  __smc_lgr_terminate() drops conns_lock after finding a connection in lgr->conns_all, but before taking a reference on its socket. The connection is embedded in the socket, and its registration reference protects it only while the connection remains in the tree.  A concurrent close can unregister the connection and drop that reference, freeing the socket before the termination worker reaches sock_hold().  The race is reachable when close overlaps link group termination. Local stress testing reproduced the use-after-free and KASAN reported:    BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc]   Write of size 4 by task kworker/3:3   Workqueue: events smc_lgr_terminate_work [smc]   __smc_lgr_terminate.part.0 [smc]  The socket was allocated by smc_create(), freed through slab_free_after_rcu_debug(), and was followed by:    refcount_t: addition on 0; use-after-free.   __smc_lgr_terminate.part.0 [smc]  Take the socket reference while conns_lock still protects the tree entry. The unregister path then cannot drop the last reference until termination has finished using the socket.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74493","epss":0.005,"percentile":0.41182,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47000000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74493","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74493","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/281c103a8eaed59001ce952f231df1b07674215a","https://git.kernel.org/stable/c/5a42f162b857019a4c10ff687dc3bcdf51831865","https://git.kernel.org/stable/c/9fb17c95b8f0683570fca1fb2792264147af937a","https://git.kernel.org/stable/c/bea8dc14de2d56aca749d368563e6888217710a5","https://git.kernel.org/stable/c/f0541a775d04c88e90ba448e35ce0d743512822a","https://git.kernel.org/stable/c/f621d6ebeebb6374342571e4ddf45fdbc420f6cd","https://git.kernel.org/stable/c/f807a63d0d95680c34f677700da9148a07d7c78f","https://git.kernel.org/stable/c/ff44f2df57fb5560bdc75eb977867643e764a262"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix socket use-after-free during link group termination\n\n__smc_lgr_terminate() drops conns_lock after finding a connection in\nlgr->conns_all, but before taking a reference on its socket. The connection\nis embedded in the socket, and its registration reference protects it only\nwhile the connection remains in the tree.\n\nA concurrent close can unregister the connection and drop that reference,\nfreeing the socket before the termination worker reaches sock_hold().\n\nThe race is reachable when close overlaps link group termination.\nLocal stress testing reproduced the use-after-free and KASAN reported:\n\n  BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc]\n  Write of size 4 by task kworker/3:3\n  Workqueue: events smc_lgr_terminate_work [smc]\n  __smc_lgr_terminate.part.0 [smc]\n\nThe socket was allocated by smc_create(), freed through\nslab_free_after_rcu_debug(), and was followed by:\n\n  refcount_t: addition on 0; use-after-free.\n  __smc_lgr_terminate.part.0 [smc]\n\nTake the socket reference while conns_lock still protects the tree entry.\nThe unregister path then cannot drop the last reference until termination\nhas finished using the socket.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74493","epss":0.005,"percentile":0.41182,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74493","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74494","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74494","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: reject repeated SMB2 NEGOTIATE requests  Unauthenticated client can send multiple successful SMB2 NEGOTIATE requests on one connection before SESSION_SETUP. While the connection is in KSMBD_SESS_NEED_SETUP, smb2_handle_negotiate() accepts another SMB3.1.1 NEGOTIATE and overwrites conn->preauth_info with a new allocation. Only the final allocation is freed when the connection is released, leaking one object for every additional successful request.  A repeated SMB2 NEGOTIATE after a dialect has been selected is a protocol violation. MS-SMB2 section 3.3.5.4 requires the server to disconnect without replying in this case. Set the connection exiting when rejecting the request, in addition to suppressing the response.  Reject SMB2 NEGOTIATE unless the connection is new or is waiting for the SMB2 NEGOTIATE that follows an SMB1 multi-protocol negotiate. Serialize both SMB1 and SMB2 negotiation paths under conn->srv_mutex, since they update connection-wide dialect and negotiation state.  Move the locking contract to ksmbd_smb_negotiate_common(), where the state and dialect are selected, and add ksmbd_conn_new() for consistent state access.","cvss":[],"epss":[{"cve":"CVE-2026-74494","epss":0.00173,"percentile":0.06833,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74494","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74494","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0b1390cf2b6b91723b37c0909dd123f7a5eba1a7","https://git.kernel.org/stable/c/7e02cb30e8a1f5fc78cb10b220b06020e36d0bbe","https://git.kernel.org/stable/c/7fb8dbeb3f2868ae836ca12311d89aed16fc2927","https://git.kernel.org/stable/c/81e21cb7bd1479bb5238e0004a7e0110452c610b","https://git.kernel.org/stable/c/a60b5da05e318d9a364dbac38c347c7f24e625e7","https://git.kernel.org/stable/c/cb469993b3a61a72653770856d37af616d72d05f","https://git.kernel.org/stable/c/fd6a6c43f96b40a08a22ff62f08d194a49741c8a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: reject repeated SMB2 NEGOTIATE requests\n\nUnauthenticated client can send multiple successful SMB2 NEGOTIATE\nrequests on one connection before SESSION_SETUP. While the connection is\nin KSMBD_SESS_NEED_SETUP, smb2_handle_negotiate() accepts another\nSMB3.1.1 NEGOTIATE and overwrites conn->preauth_info with a new allocation.\nOnly the final allocation is freed when the connection is released, leaking\none object for every additional successful request.\n\nA repeated SMB2 NEGOTIATE after a dialect has been selected is a protocol\nviolation. MS-SMB2 section 3.3.5.4 requires the server to disconnect\nwithout replying in this case. Set the connection exiting when rejecting\nthe request, in addition to suppressing the response.\n\nReject SMB2 NEGOTIATE unless the connection is new or is waiting for the\nSMB2 NEGOTIATE that follows an SMB1 multi-protocol negotiate. Serialize\nboth SMB1 and SMB2 negotiation paths under conn->srv_mutex, since they\nupdate connection-wide dialect and negotiation state.\n\nMove the locking contract to ksmbd_smb_negotiate_common(), where the state\nand dialect are selected, and add ksmbd_conn_new() for consistent state\naccess.","cvss":[],"epss":[{"cve":"CVE-2026-74494","epss":0.00173,"percentile":0.06833,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74494","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74495","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74495","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  igbvf: Fix leak in TX DMA error cleanup  If an error is encountered while mapping TX buffers, the driver should unmap any buffers already mapped for that skb.  Because count is incremented before each frag mapping, it will always match the correct number of unmappings needed when dma_error is reached. Decrementing count before the while loop in dma_error causes an off-by-one error. If any mapping was successful before an unsuccessful mapping, exactly one DMA mapping (the head) would leak.  This bug was introduced by a 2010 fix for an endless loop in dma_error. All other affected drivers have already been fixed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74495","epss":0.00514,"percentile":0.42122,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48316000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74495","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74495","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0565052b7e2f436b7f1541f4849da96dc0aa7a0e","https://git.kernel.org/stable/c/31089f4eab42e0fc248ec80c26f9b0bad59ba4cc","https://git.kernel.org/stable/c/56726ff12cb6759ab90d6f5332c2377aeca7d249","https://git.kernel.org/stable/c/845a9cdd9b03b7b6fa8de3ee80579780350a7f65","https://git.kernel.org/stable/c/bc25d56c03e41c10bc4b40e99ca5d7b941675c04","https://git.kernel.org/stable/c/df07003b5a6c6c9fce60d765d6a3da815a74c41c","https://git.kernel.org/stable/c/e3ed89c257f6361f13df23023cd10ace830330ad","https://git.kernel.org/stable/c/e42b7225c45f57b42306b80cdd3bda202bae7293"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nigbvf: Fix leak in TX DMA error cleanup\n\nIf an error is encountered while mapping TX buffers, the driver should\nunmap any buffers already mapped for that skb.\n\nBecause count is incremented before each frag mapping, it will always\nmatch the correct number of unmappings needed when dma_error is reached.\nDecrementing count before the while loop in dma_error causes an\noff-by-one error. If any mapping was successful before an unsuccessful\nmapping, exactly one DMA mapping (the head) would leak.\n\nThis bug was introduced by a 2010 fix for an endless loop in dma_error.\nAll other affected drivers have already been fixed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74495","epss":0.00514,"percentile":0.42122,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74495","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74496","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74496","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fou: Fix use-after-free in fou_create()  fou_create() publishes struct fou through sk_user_data before adding the new FOU port to the per-netns list.  If fou_add_to_port_list() fails, the error path frees fou while it is still reachable through sk_user_data.  A concurrent receive can then dereference the freed object in fou_from_sock().  This ordering issue was previously noted in the linked discussion.  The failure is reachable when local port 0 is requested.  Each socket binds to a different ephemeral port, but fou_cfg_cmp() compares the requested port 0 and reports -EALREADY once an entry already exists.  Release the tunnel socket before freeing fou so sk_user_data is cleared first, and defer reclamation with kfree_rcu() to protect concurrent RCU readers.  This matches the lifetime handling in fou_release().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74496","epss":0.0012,"percentile":0.02106,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74496","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74496","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/a28d8903bfe76089ea4bbdbff9976965f9ef8107","https://git.kernel.org/stable/c/b14361aca6350ff7907b0e9903c7b94dc7d5d4a0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Fix use-after-free in fou_create()\n\nfou_create() publishes struct fou through sk_user_data before adding the\nnew FOU port to the per-netns list.  If fou_add_to_port_list() fails,\nthe error path frees fou while it is still reachable through\nsk_user_data.  A concurrent receive can then dereference the freed\nobject in fou_from_sock().\n\nThis ordering issue was previously noted in the linked discussion.\n\nThe failure is reachable when local port 0 is requested.  Each socket\nbinds to a different ephemeral port, but fou_cfg_cmp() compares the\nrequested port 0 and reports -EALREADY once an entry already exists.\n\nRelease the tunnel socket before freeing fou so sk_user_data is cleared\nfirst, and defer reclamation with kfree_rcu() to protect concurrent RCU\nreaders.  This matches the lifetime handling in fou_release().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74496","epss":0.0012,"percentile":0.02106,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74496","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74497","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74497","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: Clamp frame size in implicit-feedback mode  snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's stride and stores the result directly in out_packet->packet_size[i]. If a connected USB device sends an oversized sync packet, this frame count can exceed ep->maxframesize.  The un-clamped frame count then propagates to the playback endpoint queue, potentially driving packet transfers beyond the endpoint's hardware frame limits.  Cap the calculated frame count against ep->maxframesize in snd_usb_handle_sync_urb() to prevent oversized packets from entering the playback queue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74497","epss":0.00142,"percentile":0.03804,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11289000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-74497","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74497","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/09cf3dbbb4256a43feb91d2f51f274510a9ada47","https://git.kernel.org/stable/c/2d39fea6d3c19a2f5811d123114d92e3d0115fd1","https://git.kernel.org/stable/c/2db4535d6af79276a64449201c5be5feffb31c64","https://git.kernel.org/stable/c/53f0aa37eb945f3c983f61d12fc35eb33debb8a9","https://git.kernel.org/stable/c/56ac3e7c90f6b45969c3fd07a98fad760ffd6901","https://git.kernel.org/stable/c/8d7a30c50c2e58a6839634ed0acde14466d1dc61","https://git.kernel.org/stable/c/be97fea7451d758881b95af78e900dd0d58a382a","https://git.kernel.org/stable/c/cfa8d3e0e8b812c4db4d5241f62b6bdbab2bd7be"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Clamp frame size in implicit-feedback mode\n\nsnd_usb_handle_sync_urb() scales received sync packet sizes by the sender's\nstride and stores the result directly in out_packet->packet_size[i]. If a\nconnected USB device sends an oversized sync packet, this frame count can\nexceed ep->maxframesize.\n\nThe un-clamped frame count then propagates to the playback endpoint queue,\npotentially driving packet transfers beyond the endpoint's hardware frame\nlimits.\n\nCap the calculated frame count against ep->maxframesize in\nsnd_usb_handle_sync_urb() to prevent oversized packets from entering the\nplayback queue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74497","epss":0.00142,"percentile":0.03804,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74497","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74498","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74498","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set  When a USB audio endpoint requests full packet transfers via the fill_max descriptor flag, data_ep_set_params() promotes ep->curpacksize to ep->maxpacksize. However, maxsize is left at the original sample-rate derived value.  Since u->buffer_size is allocated as maxsize * packets, the resulting DMA buffer is far too small for the requested transfer length. When the USB host controller streams up to curpacksize bytes per packet, it writes past the end of the buffer via DMA, corrupting kernel heap memory.  Update maxsize to curpacksize when fill_max is set so that the allocated DMA buffer size matches the actual transfer request size.  [ changed to reassign maxsize only when ep->fill_max is set -- tiwai ]","cvss":[],"epss":[{"cve":"CVE-2026-74498","epss":0.00177,"percentile":0.0733,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74498","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74498","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/04595233e5606d452f9f47e6989fc7ae7440fd40","https://git.kernel.org/stable/c/10c24e6fddf4bdff0b6b05a47a4347b38e6960e8","https://git.kernel.org/stable/c/3852974608f53e530e27c21d0c6c7d79c17b3f5a","https://git.kernel.org/stable/c/6cbdd11f9b05b92f4aa29f09a66e19ed0e25e66c","https://git.kernel.org/stable/c/b1770f9ac35c0ffc34914d52347c65dcd5ac049b","https://git.kernel.org/stable/c/bd65b7191683bebd9923904f0558b9211b9129da","https://git.kernel.org/stable/c/d0199ae1666ff9ae2d1d568d64c3430d4c47f0e5","https://git.kernel.org/stable/c/f9b6c9576568169139ac151f7881474f384659fd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set\n\nWhen a USB audio endpoint requests full packet transfers via the fill_max\ndescriptor flag, data_ep_set_params() promotes ep->curpacksize to\nep->maxpacksize. However, maxsize is left at the original sample-rate\nderived value.\n\nSince u->buffer_size is allocated as maxsize * packets, the resulting\nDMA buffer is far too small for the requested transfer length. When the\nUSB host controller streams up to curpacksize bytes per packet, it writes\npast the end of the buffer via DMA, corrupting kernel heap memory.\n\nUpdate maxsize to curpacksize when fill_max is set so that the allocated\nDMA buffer size matches the actual transfer request size.\n\n[ changed to reassign maxsize only when ep->fill_max is set -- tiwai ]","cvss":[],"epss":[{"cve":"CVE-2026-74498","epss":0.00177,"percentile":0.0733,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74498","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74499","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74499","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()  snd_usbmidi_akai_output() computes its fill-loop bound  \tbuf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;  as a signed int, so a small device-advertised bulk-OUT max_transfer makes buf_end negative.  The loop guard then compares the u32 urb->transfer_buffer_length against that negative int: the usual arithmetic conversion turns buf_end into a large unsigned value, so the guard stays true and each iteration keeps appending SysEx framing and payload bytes past the end of the URB transfer buffer, which is only max_transfer bytes long.  A USB device that advertises a tiny bulk-OUT endpoint can therefore trigger an attacker-length- and content-controlled heap out-of-bounds write when a process writes to the created /dev/snd/midiC*D* node.  Return early when there is no room for even one SysEx, so the loop is never entered with a bound that would wrap.  The loop is the last statement of the function, so bailing out is equivalent to it not running.  Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[],"epss":[{"cve":"CVE-2026-74499","epss":0.00177,"percentile":0.07326,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74499","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74499","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/00cc659a42ac4e94ec880fae2c9bf22fce69c2e8","https://git.kernel.org/stable/c/0970274613fb463d376211450cab066d34ebfe6a","https://git.kernel.org/stable/c/29a4c29943631301e85f5e9d10f25741bd78e7ba","https://git.kernel.org/stable/c/2b7a0f330dd90dd1a7657cec0db019ee1efa4372","https://git.kernel.org/stable/c/78dfdeb8d2065524ed5928d6470bf3d3244d1009","https://git.kernel.org/stable/c/9b22a5c8310b0d55d04f5f0159b913a2fb8b444f","https://git.kernel.org/stable/c/b5305a0d0bb8e90a6fc9f88270d5f6c9b8c40081","https://git.kernel.org/stable/c/ce949d66607cfb000b8d8d84f80f35a886e72683"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()\n\nsnd_usbmidi_akai_output() computes its fill-loop bound\n\n\tbuf_end = ep->max_transfer - MAX_AKAI_SYSEX_LEN - 1;\n\nas a signed int, so a small device-advertised bulk-OUT max_transfer\nmakes buf_end negative.  The loop guard then compares the u32\nurb->transfer_buffer_length against that negative int: the usual\narithmetic conversion turns buf_end into a large unsigned value, so the\nguard stays true and each iteration keeps appending SysEx framing and\npayload bytes past the end of the URB transfer buffer, which is only\nmax_transfer bytes long.\n\nA USB device that advertises a tiny bulk-OUT endpoint can therefore\ntrigger an attacker-length- and content-controlled heap out-of-bounds\nwrite when a process writes to the created /dev/snd/midiC*D* node.\n\nReturn early when there is no room for even one SysEx, so the loop is\nnever entered with a bound that would wrap.  The loop is the last\nstatement of the function, so bailing out is equivalent to it not\nrunning.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[],"epss":[{"cve":"CVE-2026-74499","epss":0.00177,"percentile":0.07326,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74499","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74505","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74505","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: 6fire: Fix UAF at error handling during probe  Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB before freeing the resources, which may lead to a UAF.  This patch addresses it by doing the almost same cleanup procedure like the normal disconnect phase at the error path.","cvss":[],"epss":[{"cve":"CVE-2026-74505","epss":0.00177,"percentile":0.07328,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74505","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74505","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/11e2953d9f4c7c3d2af94a889c2d805c537d633f","https://git.kernel.org/stable/c/2de734dcbb210bd59983e13d36988acbcc122194","https://git.kernel.org/stable/c/49bc7741cd2761c703a292dc69245041ae8a67bd","https://git.kernel.org/stable/c/630c8d6a93cbd9b2a207f1a67ef1fd21af098b0c","https://git.kernel.org/stable/c/8b7ecb2446845fa8d1f1ce9aac6307caac50cfd5","https://git.kernel.org/stable/c/a0bb5b9d39e54888385dc399c899223299201fe6","https://git.kernel.org/stable/c/a54bf16965f896415c3337bc4fbb40fb11941d99","https://git.kernel.org/stable/c/d41bfea14ee6e063a953f6e72046088737c4e66c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: 6fire: Fix UAF at error handling during probe\n\nAlthough 6fire driver had a few fixes for dealing with the early error\nhandling during the probe phase, it forgot a pending URB before\nfreeing the resources, which may lead to a UAF.\n\nThis patch addresses it by doing the almost same cleanup procedure\nlike the normal disconnect phase at the error path.","cvss":[],"epss":[{"cve":"CVE-2026-74505","epss":0.00177,"percentile":0.07328,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74505","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74506","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74506","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  afs: Fix UAF when sending a message  In afs_make_call(), there's a race with async call reception and destruction.  If a call is dispatched that doesn't have call->write_iter set (used to specify the data content for FS.StoreData), then the first rxrpc_kernel_send_data() will not set MSG_MORE in the msghdr.  Once rxrpc_send_data() queues the last request packet, the response could come in at any time and cause the call to be completed and put.  However, afs_make_call() will look at the call again to see it ->write_iter should be handled - something it's only allowed to do if it has its own ref on the call.  Whilst this is the case for synchronous calls, it isn't true for async calls such as FS.FetchData.  There's also a potential UAF in afs_make_call() in the event that an asynchronous call is being sent, but the call fails in some way (e.g. it gets aborted from the server).  The problem there is that afs_make_call() tries to abort a call if the rxrpc send fails, but the asynchronous notification from rxrpc may have caused the afs_call to be torn down.  generic/650 plays games with randomly taking CPUs offline, and can interject a significant delay such that the call is deallocated before afs_make_call() gets to check call->write_iter - and a UAF ensues (caught by KASAN).     BUG: KASAN: slab-use-after-free in afs_make_call+0x1c90/0x2210 [kafs]    Read of size 8 at addr ffff888035e050e8 by task fsstress/1409  Fix this by making afs_make_op_call() give the op->call its own ref rather than transferring the caller's ref to it and then dropping the ref when afs_make_call() returns.  This also means that the afs_make_call() func never loses its ref on the call now.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74506","epss":0.00124,"percentile":0.02417,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09486},"relatedVulnerabilities":[{"id":"CVE-2026-74506","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74506","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4af1ec68d54b3871155914d584fb10669c41a861","https://git.kernel.org/stable/c/c0d3b81f703b2a9e37fe1347610a50cdf0078c27","https://git.kernel.org/stable/c/daaa726b14fc3026a6b328614d312b698f62f391"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix UAF when sending a message\n\nIn afs_make_call(), there's a race with async call reception and\ndestruction.  If a call is dispatched that doesn't have call->write_iter\nset (used to specify the data content for FS.StoreData), then the first\nrxrpc_kernel_send_data() will not set MSG_MORE in the msghdr.\n\nOnce rxrpc_send_data() queues the last request packet, the response could\ncome in at any time and cause the call to be completed and put.  However,\nafs_make_call() will look at the call again to see it ->write_iter should\nbe handled - something it's only allowed to do if it has its own ref on the\ncall.  Whilst this is the case for synchronous calls, it isn't true for\nasync calls such as FS.FetchData.\n\nThere's also a potential UAF in afs_make_call() in the event that an\nasynchronous call is being sent, but the call fails in some way (e.g. it\ngets aborted from the server).  The problem there is that afs_make_call()\ntries to abort a call if the rxrpc send fails, but the asynchronous\nnotification from rxrpc may have caused the afs_call to be torn down.\n\ngeneric/650 plays games with randomly taking CPUs offline, and can\ninterject a significant delay such that the call is deallocated before\nafs_make_call() gets to check call->write_iter - and a UAF ensues (caught\nby KASAN).\n\n   BUG: KASAN: slab-use-after-free in afs_make_call+0x1c90/0x2210 [kafs]\n   Read of size 8 at addr ffff888035e050e8 by task fsstress/1409\n\nFix this by making afs_make_op_call() give the op->call its own ref rather\nthan transferring the caller's ref to it and then dropping the ref when\nafs_make_call() returns.\n\nThis also means that the afs_make_call() func never loses its ref on the\ncall now.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74506","epss":0.00124,"percentile":0.02417,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74506","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74507","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74507","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: HIDP: validate numbered report payloads  When hidp_get_raw_report() waits for a numbered report, hidp_process_data() compares the expected report number with skb->data[0]. A connected HIDP peer can reply with only a DATA transaction header, leaving the skb empty after the header is removed.  KMSAN reports an uninitialized-value use in hidp_session_run(), with the value originating in __alloc_skb() through vhci_write(). The transaction header checks remove the empty-frame reports, but this report remains until the payload check is added.  The comparison can also consume a peer-controlled byte beyond the declared L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made the current code accept that byte as report ID 1 and complete HIDIOCGFEATURE with a zero-byte result. With this change the malformed response is rejected with -EIO, while a subsequent valid response still succeeds.  Require a payload byte before comparing a numbered report ID. Unnumbered reports continue to accept an empty payload.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74507","epss":0.00242,"percentile":0.1535,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.17665999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-74507","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74507","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/011bf4350d941f1995b2bd4b815ee206cacf2b8e","https://git.kernel.org/stable/c/27cc0e603355c585f1e5da8398faa4d36d498188","https://git.kernel.org/stable/c/34f53d27b81a16a02828c8fdfa4e02badc326f17","https://git.kernel.org/stable/c/689d8bb7fee96b7196b572b015b6055c6616ce0c","https://git.kernel.org/stable/c/7e7162427659b70ea17cd41b1f79e2e64c246690","https://git.kernel.org/stable/c/9c841f59e10b5d75c398a3fc6b2da448d2a2276b","https://git.kernel.org/stable/c/b7ad105d46acd828e424454815e4cd31069e047a","https://git.kernel.org/stable/c/c73beb320f5705e508bf7d385b8cc5ef8d9c8b69"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HIDP: validate numbered report payloads\n\nWhen hidp_get_raw_report() waits for a numbered report,\nhidp_process_data() compares the expected report number with skb->data[0].\nA connected HIDP peer can reply with only a DATA transaction header,\nleaving the skb empty after the header is removed.\n\nKMSAN reports an uninitialized-value use in hidp_session_run(), with the\nvalue originating in __alloc_skb() through vhci_write(). The transaction\nheader checks remove the empty-frame reports, but this report remains until\nthe payload check is added.\n\nThe comparison can also consume a peer-controlled byte beyond the declared\nL2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made\nthe current code accept that byte as report ID 1 and complete\nHIDIOCGFEATURE with a zero-byte result. With this change the malformed\nresponse is rejected with -EIO, while a subsequent valid response still\nsucceeds.\n\nRequire a payload byte before comparing a numbered report ID. Unnumbered\nreports continue to accept an empty payload.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":2.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74507","epss":0.00242,"percentile":0.1535,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74507","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74508","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74508","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: HIDP: reject frames without a transaction header  hidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0] before checking that the L2CAP SDU contains a transaction header. A connected HIDP peer can send an empty basic-mode SDU and make both paths use an uninitialized byte from skb tailroom.  KMSAN reports the use in hidp_session_run(), with the uninitialized value originating in __alloc_skb() through vhci_write(). The control path produces two reports and the interrupt path produces one.  The byte can also be controlled by a malformed lower-layer packet. If an HCI ACL packet contains an L2CAP PDU with a declared zero-length payload followed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to the declared PDU length before dispatch. The current HIDP path nevertheless consumes the extra byte as HIDP_TRANS_HID_CONTROL | HIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this change, the same packet is discarded and a subsequent feature report request succeeds.  Pull the transaction header with skb_pull_data() and discard frames that do not contain it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74508","epss":0.00262,"percentile":0.17994,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.21353000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74508","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74508","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/238c333bc4b3f245c626632e8bfa3c9dab97f51b","https://git.kernel.org/stable/c/24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8","https://git.kernel.org/stable/c/2ebf63aa557a69990b4e9ea22be224d58aabce96","https://git.kernel.org/stable/c/46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec","https://git.kernel.org/stable/c/47778d2c2087b5d192398f6fddf692d16a5431cf","https://git.kernel.org/stable/c/567a2a0a633f2ea5fdccaf3517c09f22c9d860c7","https://git.kernel.org/stable/c/854194494a6f726a60b90b76059148bf08df023d","https://git.kernel.org/stable/c/97b61241ab45bfa5b0526cb0f3978942493bc811"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HIDP: reject frames without a transaction header\n\nhidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0]\nbefore checking that the L2CAP SDU contains a transaction header. A\nconnected HIDP peer can send an empty basic-mode SDU and make both paths\nuse an uninitialized byte from skb tailroom.\n\nKMSAN reports the use in hidp_session_run(), with the uninitialized value\noriginating in __alloc_skb() through vhci_write(). The control path\nproduces two reports and the interrupt path produces one.\n\nThe byte can also be controlled by a malformed lower-layer packet. If an\nHCI ACL packet contains an L2CAP PDU with a declared zero-length payload\nfollowed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to\nthe declared PDU length before dispatch. The current HIDP path nevertheless\nconsumes the extra byte as HIDP_TRANS_HID_CONTROL |\nHIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this\nchange, the same packet is discarded and a subsequent feature report\nrequest succeeds.\n\nPull the transaction header with skb_pull_data() and discard frames that\ndo not contain it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74508","epss":0.00262,"percentile":0.17994,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74508","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74509","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74509","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_sync: Fix advertising data UAFs  hci_find_adv_instance() returns an adv_info pointer that is valid only while hdev->lock is held.  The advertising command-sync paths perform instance lookups without that lock and, in some cases, retain the pointer while waiting for a controller response.  An advertising termination event can therefore interleave as follows:    hci_cmd_sync_work                 hci_rx_work   hci_find_adv_instance()   __hci_cmd_sync_status()     wait for controller reply       hci_dev_lock()                                     hci_remove_adv_instance()                                       kfree(adv)   adv->scan_rsp_changed = false  KASAN reported:    BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300   Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88   Workqueue: hci0 hci_cmd_sync_work   Call Trace:    hci_set_ext_scan_rsp_data_sync+0x2e1/0x300    hci_schedule_adv_instance_sync+0x390/0x4c0    hci_cmd_sync_work+0x173/0x300   Allocated by task 87:    hci_add_adv_instance+0x538/0xac0    add_advertising+0x885/0x1160   Freed by task 89:    kfree+0x131/0x3c0    hci_remove_adv_instance+0x1d8/0x3b0    hci_le_ext_adv_term_evt+0x17b/0x730  Protect the instance lookup and payload construction in the extended advertising, scan response, and periodic advertising data paths.  Snapshot the advertising parameters under hdev->lock, but release the lock before waiting for the controller.  Clear advertising-data dirty bits before issuing their commands and restore them after a failure using a fresh lookup.  Likewise, update the reported transmit power through a fresh lookup after the parameter command completes.  No adv_info pointer then survives an HCI command wait.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74509","epss":0.00249,"percentile":0.16244,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.202935},"relatedVulnerabilities":[{"id":"CVE-2026-74509","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74509","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/565971488191bf54a87a417abafab6ad0de72201","https://git.kernel.org/stable/c/95cdcd8c82a501931fd3ae9b3811b0b6da167e94","https://git.kernel.org/stable/c/b16ebdbebd2d37f4cdc590bc3e9db71fe90350a3","https://git.kernel.org/stable/c/c4cec575a6d6f7c36808a3a0017b0675968bb06b","https://git.kernel.org/stable/c/cdc36db204ffd97b947d64374cf23a210dc74777","https://git.kernel.org/stable/c/eb1d8318764de7216e6dbba29a24d69f7ce51348"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Fix advertising data UAFs\n\nhci_find_adv_instance() returns an adv_info pointer that is valid only\nwhile hdev->lock is held.  The advertising command-sync paths perform\ninstance lookups without that lock and, in some cases, retain the pointer\nwhile waiting for a controller response.\n\nAn advertising termination event can therefore interleave as follows:\n\n  hci_cmd_sync_work                 hci_rx_work\n  hci_find_adv_instance()\n  __hci_cmd_sync_status()\n    wait for controller reply       hci_dev_lock()\n                                    hci_remove_adv_instance()\n                                      kfree(adv)\n  adv->scan_rsp_changed = false\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in hci_set_ext_scan_rsp_data_sync+0x2e1/0x300\n  Write of size 1 at addr ffff88810a45d21d by task kworker/u17:0/88\n  Workqueue: hci0 hci_cmd_sync_work\n  Call Trace:\n   hci_set_ext_scan_rsp_data_sync+0x2e1/0x300\n   hci_schedule_adv_instance_sync+0x390/0x4c0\n   hci_cmd_sync_work+0x173/0x300\n  Allocated by task 87:\n   hci_add_adv_instance+0x538/0xac0\n   add_advertising+0x885/0x1160\n  Freed by task 89:\n   kfree+0x131/0x3c0\n   hci_remove_adv_instance+0x1d8/0x3b0\n   hci_le_ext_adv_term_evt+0x17b/0x730\n\nProtect the instance lookup and payload construction in the extended\nadvertising, scan response, and periodic advertising data paths.  Snapshot\nthe advertising parameters under hdev->lock, but release the lock before\nwaiting for the controller.\n\nClear advertising-data dirty bits before issuing their commands and\nrestore them after a failure using a fresh lookup.  Likewise, update the\nreported transmit power through a fresh lookup after the parameter command\ncompletes.  No adv_info pointer then survives an HCI command wait.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74509","epss":0.00249,"percentile":0.16244,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74509","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74510","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74510","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: mgmt: fix UAF in pair command cancellation  The pairing completion and authentication failure callbacks look up the pending MGMT_OP_PAIR_DEVICE command by walking hdev->mgmt_pending. The lookup returned a command that was still linked on the shared pending list, without keeping mgmt_pending_lock held for the later dereference and removal.  A concurrent MGMT_OP_CANCEL_PAIR_DEVICE request can remove and free the same pending command before the callback uses it. The reverse race is also possible when cancel_pair_device() gets a command from pending_find() and a callback removes it before the cancel path dereferences it. This can lead to a use-after-free and a second list_del().  Make the pairing lookup helpers transfer ownership of the pending command by removing it from hdev->mgmt_pending while holding mgmt_pending_lock. The callbacks and cancel path then complete the command and free it directly, so racing paths cannot find or free the same command again. Take a temporary hci_conn reference in cancel_pair_device() because the command completion drops the reference stored in the pending command.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74510","epss":0.00139,"percentile":0.03634,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.106335},"relatedVulnerabilities":[{"id":"CVE-2026-74510","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74510","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/50af4280a587c9971b5388cbc438f1324e626b7b","https://git.kernel.org/stable/c/51be7280980fddc90ebe874a69c2fe8ab02bb46a","https://git.kernel.org/stable/c/7c2a152a897cd1c184b2051484d4f74d803e7f4a","https://git.kernel.org/stable/c/86ed4dd6548ccf277bc691bc912ca06e76b9d80c","https://git.kernel.org/stable/c/c569def320aa8b1fde89227e2ea96606790fd86d","https://git.kernel.org/stable/c/d0a7b48ad0921bd88effaee10bf970ab1d5d0ddd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: mgmt: fix UAF in pair command cancellation\n\nThe pairing completion and authentication failure callbacks look up the\npending MGMT_OP_PAIR_DEVICE command by walking hdev->mgmt_pending. The\nlookup returned a command that was still linked on the shared pending list,\nwithout keeping mgmt_pending_lock held for the later dereference and\nremoval.\n\nA concurrent MGMT_OP_CANCEL_PAIR_DEVICE request can remove and free the\nsame pending command before the callback uses it. The reverse race is also\npossible when cancel_pair_device() gets a command from pending_find() and a\ncallback removes it before the cancel path dereferences it. This can lead\nto a use-after-free and a second list_del().\n\nMake the pairing lookup helpers transfer ownership of the pending command\nby removing it from hdev->mgmt_pending while holding mgmt_pending_lock.\nThe callbacks and cancel path then complete the command and free it\ndirectly, so racing paths cannot find or free the same command again. Take\na temporary hci_conn reference in cancel_pair_device() because the command\ncompletion drops the reference stored in the pending command.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74510","epss":0.00139,"percentile":0.03634,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74510","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74512","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74512","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  audit: fix potential use-after-free in audit_del_rule()  `audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()` before unlinking the rule from RCU-visible filter lists and waiting for a grace period. Concurrent readers in `audit_filter()` and `audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify mark can be freed on an independent lifetime path. This creates a use-after-free window during rule deletion.  Fix this by unlinking the rule from the RCU-visible lists and invoking `synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other rule removal helpers). This ensures that all existing RCU readers have exited the critical section before any underlying resources are destroyed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74512","epss":0.00126,"percentile":0.02562,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74512","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74512","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/246df90b5f1a8a6e6abbd2f058b029558720adec","https://git.kernel.org/stable/c/3f82927b399d7a276c0c12b6ff4424b747a0c9a7","https://git.kernel.org/stable/c/45bf3df5b32e5a49953e7ceabc55f7dd85380e46","https://git.kernel.org/stable/c/5b8f46864f06d6dbacb7dcea52bc084dfd122638","https://git.kernel.org/stable/c/78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf","https://git.kernel.org/stable/c/8ae135a8962be9d4e8a131eb18eb06cdf02a47ce","https://git.kernel.org/stable/c/93616c567469510b7bba55b2674e0c4523fd7e64","https://git.kernel.org/stable/c/cae0dfed5d307b240bff71c3cf206652d1b6f215"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix potential use-after-free in audit_del_rule()\n\n`audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()`\nbefore unlinking the rule from RCU-visible filter lists and waiting for a\ngrace period. Concurrent readers in `audit_filter()` and\n`audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify\nmark can be freed on an independent lifetime path. This creates a\nuse-after-free window during rule deletion.\n\nFix this by unlinking the rule from the RCU-visible lists and invoking\n`synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other\nrule removal helpers). This ensures that all existing RCU readers have\nexited the critical section before any underlying resources are destroyed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74512","epss":0.00126,"percentile":0.02562,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74512","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74514","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74514","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: s390: pci: Fix memory accounting for pinned/unpinned pages  The account_mem() and unaccount_mem() functions call get_uid() which increments the reference count of struct user_struct on every invocation. But we don't decrement the count by calling free_uid(). It also accounted/unaccounted the pages against the current->mm. But its possible the unaccount_mem() can be called from a different process context than the one that originally pinned the pages.  Let's fix this by storing the pinning process user_struct and mm_struct when accounting for pinned pages, and subsequently free these resources when the pages are unpinned.  [borntraeger@linux.ibm.com: Fixed whitespace]","cvss":[],"epss":[{"cve":"CVE-2026-74514","epss":0.00173,"percentile":0.06829,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74514","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74514","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/36f6999ecde3976731a8bfc0b8e667da6f593069","https://git.kernel.org/stable/c/47cfd75d9df7c8f425b0d769328fe43a8a8e606e","https://git.kernel.org/stable/c/70871b121f81d08879363cb1238a4c85c5c2800c","https://git.kernel.org/stable/c/ad1c2ac7f15b224cf9ab26b593caa9bd1a4be72e","https://git.kernel.org/stable/c/dc7465a364104526c56b922c9de9dfcc08a7d5f7","https://git.kernel.org/stable/c/e3f732e086e438c52c7400bd2734bb166aa4752c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Fix memory accounting for pinned/unpinned pages\n\nThe account_mem() and unaccount_mem() functions call get_uid() which\nincrements the reference count of struct user_struct on every invocation.\nBut we don't decrement the count by calling free_uid(). It also\naccounted/unaccounted the pages against the current->mm. But its possible\nthe unaccount_mem() can be called from a different process context than the\none that originally pinned the pages.\n\nLet's fix this by storing the pinning process user_struct and mm_struct\nwhen accounting for pinned pages, and subsequently free these resources\nwhen the pages are unpinned.\n\n[borntraeger@linux.ibm.com: Fixed whitespace]","cvss":[],"epss":[{"cve":"CVE-2026-74514","epss":0.00173,"percentile":0.06829,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74514","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74515","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74515","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: s390: pci: Reject adapter interrupt forwarding if already enabled  The MPCIFC instruction doesn't allow registering adapter interrupts without first unregistering. So reject any request to enable interrupt forwarding if its already enabled for the zPCI device. This also fixes overwriting and thus leaking resources when the ioctl is called multiple times for the same device.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74515","epss":0.00129,"percentile":0.02901,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74515","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74515","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/591952b63a9f976da7d49f719f36ec826ee2a575","https://git.kernel.org/stable/c/642d2d1067f7c4d753ae0e3ba5bc98b43cfe3c70","https://git.kernel.org/stable/c/6837f0ae85fd54cf64c8a0c7c530bba2fae0a207","https://git.kernel.org/stable/c/6be1ff49ba81f96a6fa55915e6d920be43ac57cc","https://git.kernel.org/stable/c/78d9648e7e960546d5b72504a0b0358cd8bb1e9d","https://git.kernel.org/stable/c/8fa01be5a6149404adb82c0979a78f6347edd3ef"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Reject adapter interrupt forwarding if already enabled\n\nThe MPCIFC instruction doesn't allow registering adapter interrupts without\nfirst unregistering. So reject any request to enable interrupt forwarding\nif its already enabled for the zPCI device. This also fixes overwriting and\nthus leaking resources when the ioctl is called multiple times for the same\ndevice.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74515","epss":0.00129,"percentile":0.02901,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74515","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74516","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74516","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active  Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even if L2 is active and KVM is using a separate MSR bitmap to run L2.  If AVIC is fully enabled prior to running L2, and is then inhibited while L2 is active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled, but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of the host's APIC state, send arbitrary interrupts, change task priority, and ultimately trivially DoS the host.  E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with CONFIG_HYPERV=n in the host kernel as a \"safe\" PoC, yields:    Spurious interrupt (vector 0xee) on CPU#425. Acked  And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:    ------------[ cut here ]------------   WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940   CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S   U   Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER   Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026   RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]   Call Trace:    <IRQ>    sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80    </IRQ>    <TASK>    asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20   RIP: 0010:vcpu_run+0x1430/0x1e40 [kvm]    kvm_arch_vcpu_ioctl_run+0x2c1/0x600 [kvm]    kvm_vcpu_ioctl+0x580/0x6b0 [kvm]    __se_sys_ioctl+0x6d/0xb0    do_syscall_64+0x10a/0x480    entry_SYSCALL_64_after_hwframe+0x4b/0x53   RIP: 0033:0x46ff4b    </TASK>   ---[ end trace 0000000000000000 ]---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74516","epss":0.00135,"percentile":0.03277,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10597499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74516","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74516","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4ca05385b3ddbd463be17c6d69ec76fca657081d","https://git.kernel.org/stable/c/6664a5aea45318f4ec156a729949b474dd6e3159","https://git.kernel.org/stable/c/7668c58dcf465559dc7a0d2e95e9cb79cf47454b","https://git.kernel.org/stable/c/7d3aae206663c4e006b25a1c7a20a4029e67da76","https://git.kernel.org/stable/c/89f9e8398e79c49886766fc24a84c37726231104","https://git.kernel.org/stable/c/f12373625b4dc9bcc89c41872648878c73bb9272"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active\n\nAlways update x2APIC MSR intercepts for L1 when AVIC is deactivated, even\nif L2 is active and KVM is using a separate MSR bitmap to run L2.  If AVIC\nis fully enabled prior to running L2, and is then inhibited while L2 is\nactive (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,\nbut with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of\nthe host's APIC state, send arbitrary interrupts, change task priority, and\nultimately trivially DoS the host.\n\nE.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with\nCONFIG_HYPERV=n in the host kernel as a \"safe\" PoC, yields:\n\n  Spurious interrupt (vector 0xee) on CPU#425. Acked\n\nAnd hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a\nhandler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:\n\n  ------------[ cut here ]------------\n  WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940\n  CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S   U\n  Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER\n  Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026\n  RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]\n  Call Trace:\n   <IRQ>\n   sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80\n   </IRQ>\n   <TASK>\n   asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20\n  RIP: 0010:vcpu_run+0x1430/0x1e40 [kvm]\n   kvm_arch_vcpu_ioctl_run+0x2c1/0x600 [kvm]\n   kvm_vcpu_ioctl+0x580/0x6b0 [kvm]\n   __se_sys_ioctl+0x6d/0xb0\n   do_syscall_64+0x10a/0x480\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n  RIP: 0033:0x46ff4b\n   </TASK>\n  ---[ end trace 0000000000000000 ]---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74516","epss":0.00135,"percentile":0.03277,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74516","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74518","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74518","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/hugetlb: fix list corruption in allocate_file_region_entries()  allocate_file_region_entries() tops up resv->region_cache with freshly allocated file_region descriptors.  The allocation uses GFP_KERNEL, so resv->lock is dropped around it: the new entries are gathered on a stack-local list head, allocated_regions, and spliced into resv->region_cache once the lock is re-acquired.  The splice used list_splice(), which moves the entries but does not re-initialize the source head, so allocated_regions is left pointing at an entry that now lives on resv->region_cache.  The top-up runs in a while loop that re-checks the cache deficit after re-acquiring the lock.  For a shared mapping the resv_map is shared by every mapper of the hugetlbfs inode, so a concurrent region_chg()/region_add()/region_del() on the same resv_map can consume cache entries during the unlocked window and force a second iteration.  That iteration calls list_add() on the stale head and corrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check trips:    list_add corruption. next->prev should be prev (ffffc900011ff7f8),   but was ffff88814c281460. (next=ffff88814c545640).   kernel BUG at lib/list_debug.c:31!    allocate_file_region_entries+0x191/0x420    region_chg+0x267/0x300    hugetlb_reserve_pages+0x387/0xc80    hugetlbfs_file_mmap+0x2ce/0x3f0    mmap_region+0x1348/0x1a80    do_mmap+0x85e/0xb90    vm_mmap_pgoff+0x18c/0x330    ksys_mmap_pgoff+0x2a1/0x3e0    do_syscall_64+0xd7/0x420  Without CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack address into resv->region_cache, leading to later use-after-free.  This was observed as a real host panic on a dense KVM host where a QEMU guest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate SPDK/DPDK vhost-user target, generating concurrent region_* traffic on one shared resv_map.  Use list_splice_init() so the source head is re-initialized empty after each splice, making the retry loop safe.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74518","epss":0.00126,"percentile":0.02562,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74518","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74518","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/01b8569233e47693d6ff7efa96d9854c55f936fc","https://git.kernel.org/stable/c/126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df","https://git.kernel.org/stable/c/587a0accc2b4fccc5cf7baf0fe34e50efde51f9c","https://git.kernel.org/stable/c/62e1c2741a4d923d9854efd5927a6212aad7a187","https://git.kernel.org/stable/c/9c5fdffc5e1ce84403c58289ee72697051803bf7","https://git.kernel.org/stable/c/ac1bb7fd45088d0db57a22ce7729f258ebd63cf5","https://git.kernel.org/stable/c/dd9623f58ec702a07b2d67179d6fcea79c52231a","https://git.kernel.org/stable/c/f3e54f6a5e1681f83d13e8716bc92ef5ecf121d3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix list corruption in allocate_file_region_entries()\n\nallocate_file_region_entries() tops up resv->region_cache with freshly\nallocated file_region descriptors.  The allocation uses GFP_KERNEL, so\nresv->lock is dropped around it: the new entries are gathered on a\nstack-local list head, allocated_regions, and spliced into\nresv->region_cache once the lock is re-acquired.\n\nThe splice used list_splice(), which moves the entries but does not\nre-initialize the source head, so allocated_regions is left pointing at an\nentry that now lives on resv->region_cache.  The top-up runs in a while\nloop that re-checks the cache deficit after re-acquiring the lock.  For a\nshared mapping the resv_map is shared by every mapper of the hugetlbfs\ninode, so a concurrent region_chg()/region_add()/region_del() on the same\nresv_map can consume cache entries during the unlocked window and force a\nsecond iteration.  That iteration calls list_add() on the stale head and\ncorrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check\ntrips:\n\n  list_add corruption. next->prev should be prev (ffffc900011ff7f8),\n  but was ffff88814c281460. (next=ffff88814c545640).\n  kernel BUG at lib/list_debug.c:31!\n   allocate_file_region_entries+0x191/0x420\n   region_chg+0x267/0x300\n   hugetlb_reserve_pages+0x387/0xc80\n   hugetlbfs_file_mmap+0x2ce/0x3f0\n   mmap_region+0x1348/0x1a80\n   do_mmap+0x85e/0xb90\n   vm_mmap_pgoff+0x18c/0x330\n   ksys_mmap_pgoff+0x2a1/0x3e0\n   do_syscall_64+0xd7/0x420\n\nWithout CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack\naddress into resv->region_cache, leading to later use-after-free.\n\nThis was observed as a real host panic on a dense KVM host where a QEMU\nguest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate\nSPDK/DPDK vhost-user target, generating concurrent region_* traffic on one\nshared resv_map.\n\nUse list_splice_init() so the source head is re-initialized empty after\neach splice, making the retry loop safe.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74518","epss":0.00126,"percentile":0.02562,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74518","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74519","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74519","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  pinctrl: devicetree: don't free uninitialized dev_name on error path  dt_remember_or_free_map() duplicates dev_name for each map entry. If kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps entries, including entries that have not been initialized.  Some pinctrl drivers, including pinctrl-imx, allocate the map with kmalloc() and leave dev_name for the core to initialize. The untouched entries therefore contain uninitialized data which is passed to kfree_const().  Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection while binding the pinctrl-consuming device, under KASAN:    BUG: KASAN: double-free in dt_free_map+0x34/0xa4   Free of addr c425a900 by task init/1    kfree from dt_free_map+0x34/0xa4    dt_free_map from dt_remember_or_free_map+0x184/0x198    dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8    pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0  Initialize all dev_name fields to NULL before duplicating the device name, making the full-map cleanup safe after a partial failure.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74519","epss":0.00146,"percentile":0.04168,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11168999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-74519","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74519","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/015b5bcbcb622b32317642be91a7f79aa5413649","https://git.kernel.org/stable/c/1586423da2739a80871ef6240016fcb9c7339bfb","https://git.kernel.org/stable/c/321fe3584a8298386938130d138191aa35040b75","https://git.kernel.org/stable/c/929f6396baade89999ec8a1281232c101cbc727d","https://git.kernel.org/stable/c/9d00a5ac7cd3d32ae61140f4b8a62f136de84e7d","https://git.kernel.org/stable/c/ad0ad3c228b6f76fde10f32047e0ec5fbc109dc8","https://git.kernel.org/stable/c/dec5f0a8080502908dec5e35597c7ae07d533a3b","https://git.kernel.org/stable/c/e3cfb22bad363bebcfd55d909e12d499cb8c5490"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: devicetree: don't free uninitialized dev_name on error path\n\ndt_remember_or_free_map() duplicates dev_name for each map entry. If\nkstrdup_const() fails, dt_free_map() frees dev_name in all num_maps\nentries, including entries that have not been initialized.\n\nSome pinctrl drivers, including pinctrl-imx, allocate the map with\nkmalloc() and leave dev_name for the core to initialize. The untouched\nentries therefore contain uninitialized data which is passed to\nkfree_const().\n\nReproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection\nwhile binding the pinctrl-consuming device, under KASAN:\n\n  BUG: KASAN: double-free in dt_free_map+0x34/0xa4\n  Free of addr c425a900 by task init/1\n   kfree from dt_free_map+0x34/0xa4\n   dt_free_map from dt_remember_or_free_map+0x184/0x198\n   dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8\n   pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0\n\nInitialize all dev_name fields to NULL before duplicating the device\nname, making the full-map cleanup safe after a partial failure.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74519","epss":0.00146,"percentile":0.04168,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74519","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74521","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74521","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: use memcmp() to compare ClientGUIDs  ClientGUID is a fixed-size binary value and can contain embedded NUL bytes. strncmp() stops comparing at the first NUL byte, so different ClientGUID values can incorrectly be treated as equal.  Use memcmp() in SMB3 multichannel session binding and FSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE bytes.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74521","epss":0.00315,"percentile":0.24127,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.285075},"relatedVulnerabilities":[{"id":"CVE-2026-74521","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74521","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/d535363299822c5caa543787b21bd5cfa3e41949","https://git.kernel.org/stable/c/e8bb506e6ef749ac0336f3e579d8d02396b7d832"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use memcmp() to compare ClientGUIDs\n\nClientGUID is a fixed-size binary value and can contain embedded NUL\nbytes. strncmp() stops comparing at the first NUL byte, so different\nClientGUID values can incorrectly be treated as equal.\n\nUse memcmp() in SMB3 multichannel session binding and\nFSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE\nbytes.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74521","epss":0.00315,"percentile":0.24127,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74521","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74522","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74522","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free in __close_file_table_ids()  A ksmbd_file can remain alive after logical close while another session holds a temporary reference obtained through ksmbd_lookup_fd_inode(). ksmbd_close_fd() currently marks the file closed and drops the idr-owned reference, but leaves the pointer published in the closing session's idr until the final reference is dropped.  If the foreign holder performs the final ksmbd_fd_put(), __put_fd_final() supplies the foreign session's file table to __ksmbd_close_fd(). The object is then freed without being removed from its owner's idr, and the owner session later dereferences the stale pointer during file-table teardown.  Remove the volatile id from the owner's idr while ksmbd_close_fd() still holds that table's lock, and clear volatile_id before dropping the idr-owned reference. A later foreign final put then only performs physical destruction and cannot remove the object from the wrong table.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74522","epss":0.00435,"percentile":0.36684,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.354525},"relatedVulnerabilities":[{"id":"CVE-2026-74522","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74522","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0c3918c2cee62ec6c9de8d5c73ebfe6f833961ac","https://git.kernel.org/stable/c/19bfd90d5aaf63217735d81964585c5306158e5f","https://git.kernel.org/stable/c/67aaec2a1fdce3e1dde46c45b5d1ef8cf22f65cd","https://git.kernel.org/stable/c/9be4a66f019ea90bd9deca70511f4f9ffebf5c6f","https://git.kernel.org/stable/c/cffbdc86393b0235383a20c8c59bc32f16036459","https://git.kernel.org/stable/c/e7188199eff46a636f3436356f0aae039be6dd66"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in __close_file_table_ids()\n\nA ksmbd_file can remain alive after logical close while another session\nholds a temporary reference obtained through ksmbd_lookup_fd_inode().\nksmbd_close_fd() currently marks the file closed and drops the idr-owned\nreference, but leaves the pointer published in the closing session's idr\nuntil the final reference is dropped.\n\nIf the foreign holder performs the final ksmbd_fd_put(), __put_fd_final()\nsupplies the foreign session's file table to __ksmbd_close_fd(). The object\nis then freed without being removed from its owner's idr, and the owner\nsession later dereferences the stale pointer during file-table teardown.\n\nRemove the volatile id from the owner's idr while ksmbd_close_fd() still\nholds that table's lock, and clear volatile_id before dropping\nthe idr-owned reference. A later foreign final put then only performs\nphysical destruction and cannot remove the object from the wrong table.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74522","epss":0.00435,"percentile":0.36684,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74522","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74523","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74523","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  qede: sync udp_tunnel ports outside qede_lock in the recovery path  A TX timeout on a qede NIC that has VXLAN/GENEVE tunnel ports configured wedges the rtnetlink control plane of the whole machine:    NETDEV WATCHDOG: ens6f1 (qede): transmit queue 2 timed out 10226 ms   [qede_tx_timeout:586(ens6f1)]TX timeout on queue 2!   [qede_recovery_handler:2665(ens6f0)]Starting a recovery process  The recovery path deadlocks on the driver's own mutex:    qede_sp_task    rtnl_lock()    mutex_lock(&edev->qede_lock)        <- taken    qede_recovery_handler     qede_load     udp_tunnel_nic_reset_ntf      __udp_tunnel_nic_device_sync       info->sync_table == qede_udp_tunnel_sync        mutex_lock(&edev->qede_lock)    <- same task: deadlock  The mutex is not recursive, so the kworker blocks on itself with rtnl_lock held, and neither lock is ever released. Every task that calls rtnl_lock() afterwards (ip, ovs-vswitchd, lldpad, IPv6 addrconf, sshd) blocks forever while the node still answers ping. In a vmcore from an affected production node rtnl_mutex.owner decodes to the very kworker blocked at the innermost mutex_lock() above.  Re-sync the tunnel ports from qede_sp_task() after the internal lock is dropped, still under rtnl_lock as the udp_tunnel API requires. This mirrors qede_open(), which calls udp_tunnel_nic_reset_ntf() under rtnl without the internal lock.  qede_recovery_handler() now returns whether it has successfully reloaded an open device, and the caller re-syncs the ports only in that case. This keeps the old gating exactly: a device that was down or a failed recovery returns false, as those paths never reached the udp_tunnel_nic_reset_ntf() call before either.  This was the only user of the qede_lock()/qede_unlock() helpers, so remove them.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74523","epss":0.00501,"percentile":0.41266,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37575},"relatedVulnerabilities":[{"id":"CVE-2026-74523","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74523","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/19e505ee8bb9e0f0355eda9e9f614fb25fed0070","https://git.kernel.org/stable/c/451c9075d6c53f2438d110addbeeeea6fac18567","https://git.kernel.org/stable/c/4626df3f63c9185efba5750fe76ac01ab3351bae","https://git.kernel.org/stable/c/6f1ef8170d3d8ad9319aa01347945dcdf5cc4f27","https://git.kernel.org/stable/c/8e1bdf57de91247e57816482966265ada573cc74","https://git.kernel.org/stable/c/c4c1e5d6bc2b900b2328d6fff93dc8146b858d69","https://git.kernel.org/stable/c/e382a4efeeae6555b95d9ff336cf3094ee7d336b","https://git.kernel.org/stable/c/e51becb8f3377a377171ed5bf0082b96e22e6292"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nqede: sync udp_tunnel ports outside qede_lock in the recovery path\n\nA TX timeout on a qede NIC that has VXLAN/GENEVE tunnel ports\nconfigured wedges the rtnetlink control plane of the whole machine:\n\n  NETDEV WATCHDOG: ens6f1 (qede): transmit queue 2 timed out 10226 ms\n  [qede_tx_timeout:586(ens6f1)]TX timeout on queue 2!\n  [qede_recovery_handler:2665(ens6f0)]Starting a recovery process\n\nThe recovery path deadlocks on the driver's own mutex:\n\n  qede_sp_task\n   rtnl_lock()\n   mutex_lock(&edev->qede_lock)        <- taken\n   qede_recovery_handler\n    qede_load\n    udp_tunnel_nic_reset_ntf\n     __udp_tunnel_nic_device_sync\n      info->sync_table == qede_udp_tunnel_sync\n       mutex_lock(&edev->qede_lock)    <- same task: deadlock\n\nThe mutex is not recursive, so the kworker blocks on itself with\nrtnl_lock held, and neither lock is ever released. Every task that\ncalls rtnl_lock() afterwards (ip, ovs-vswitchd, lldpad, IPv6\naddrconf, sshd) blocks forever while the node still answers ping.\nIn a vmcore from an affected production node rtnl_mutex.owner\ndecodes to the very kworker blocked at the innermost mutex_lock()\nabove.\n\nRe-sync the tunnel ports from qede_sp_task() after the internal lock\nis dropped, still under rtnl_lock as the udp_tunnel API requires.\nThis mirrors qede_open(), which calls udp_tunnel_nic_reset_ntf()\nunder rtnl without the internal lock.\n\nqede_recovery_handler() now returns whether it has successfully\nreloaded an open device, and the caller re-syncs the ports only in\nthat case. This keeps the old gating exactly: a device that was down\nor a failed recovery returns false, as those paths never reached the\nudp_tunnel_nic_reset_ntf() call before either.\n\nThis was the only user of the qede_lock()/qede_unlock() helpers, so\nremove them.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74523","epss":0.00501,"percentile":0.41266,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74523","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74525","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74525","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: sxgbe: free TX rings on RX allocation failure  When RX descriptor ring allocation fails, init_dma_desc_rings() only frees the partially allocated RX rings and returns. The TX rings that were allocated earlier in the same function are leaked.  Rearrange error labels to clean up TX rings upon RX failures.","cvss":[],"epss":[{"cve":"CVE-2026-74525","epss":0.00177,"percentile":0.07329,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74525","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74525","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3563e2486dcd50a751dbcbc1de37e5186646dce6","https://git.kernel.org/stable/c/42b87cfd9666ef156637c90ff3f6f6dd9a5ad4cb","https://git.kernel.org/stable/c/923389d0370b4117bd579784442e8450f9bb89be","https://git.kernel.org/stable/c/a07a69f472fff1c6edf77ca97616381657a8444c","https://git.kernel.org/stable/c/b33644a4f6d8f127c62d7b39f24114d3d2499204","https://git.kernel.org/stable/c/c870f7e2890b9f78ac84515a9809cc5c183c975e","https://git.kernel.org/stable/c/f2e5bb9fb710553e76a3be9097b448b4e73d8c92","https://git.kernel.org/stable/c/f52de3ea462229457334c9d3c0d95a7856908664"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sxgbe: free TX rings on RX allocation failure\n\nWhen RX descriptor ring allocation fails, init_dma_desc_rings() only\nfrees the partially allocated RX rings and returns. The TX rings that\nwere allocated earlier in the same function are leaked.\n\nRearrange error labels to clean up TX rings upon RX failures.","cvss":[],"epss":[{"cve":"CVE-2026-74525","epss":0.00177,"percentile":0.07329,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74525","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74527","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74527","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  octeontx2-af: Block VFs from clobbering special CGX PKIND state  PF and VF NIX LFs that share a CGX LMAC reuse the same hardware PKIND programming. When HiGig2 or EDSA parsing is enabled, a VF NIX LF alloc must not reset the LMAC RX PKIND or default TX parse config over the PF setup.  Add cgx_get_pkind() and rvu_cgx_is_pkind_config_permitted() so VFs skip cgx_set_pkind(), rvu_npc_set_pkind(), and NIX_AF_LFX_TX_PARSE_CFG updates when the LMAC is using NPC_RX_HIGIG_PKIND or NPC_RX_EDSA_PKIND.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74527","epss":0.0012,"percentile":0.02107,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0978},"relatedVulnerabilities":[{"id":"CVE-2026-74527","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74527","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3bd438a58e910db5dc369aa25dfed1fc95f1b596","https://git.kernel.org/stable/c/d3c6b0f48f126a36955b3fb4154a59d0b3621d97"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: Block VFs from clobbering special CGX PKIND state\n\nPF and VF NIX LFs that share a CGX LMAC reuse the same hardware PKIND\nprogramming. When HiGig2 or EDSA parsing is enabled, a VF NIX LF alloc must\nnot reset the LMAC RX PKIND or default TX parse config over the PF setup.\n\nAdd cgx_get_pkind() and rvu_cgx_is_pkind_config_permitted() so VFs skip\ncgx_set_pkind(), rvu_npc_set_pkind(), and NIX_AF_LFX_TX_PARSE_CFG updates\nwhen the LMAC is using NPC_RX_HIGIG_PKIND or NPC_RX_EDSA_PKIND.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74527","epss":0.0012,"percentile":0.02107,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74527","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74536","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74536","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: ISO: fix leaking sk after socket release  iso_sock_kill() tests !sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket || sock_flag(sk, SOCK_DEAD) for early return, but this is always true since sock_orphan(sk) sets SOCK_DEAD, so the sk reference released by socket always leaks, iso_sock_destruct is never called.  The socket reference also leaks when __iso_sock_close() does not set SOCK_ZAPPED, since iso_conn_del() does not call iso_sock_kill() after zapping.  Fix by replacing SOCK_DEAD by BT_SK_KILLED flag that is not used for something else, and lock_sock to ensure iso_sock_kill() puts sk only after socket release only once. Release and iso_conn_del may run concurrently. Call iso_sock_kill() from iso_conn_del() to clean sk up after zapping.  Remove call to iso_sock_kill() from iso_sock_close(), as it's generally no-op there.","cvss":[],"epss":[{"cve":"CVE-2026-74536","epss":0.00168,"percentile":0.06351,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74536","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74536","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/96ed3c772c08e7a91c399567f412618e43231023","https://git.kernel.org/stable/c/ce57442a379212fe3fda59c9437ee8217eceb5b1","https://git.kernel.org/stable/c/e30e5ca63c8fbe3cd505fbb419bb547760cda633","https://git.kernel.org/stable/c/e76a0ae6542ae43241b2147bacf4990e7ae5316a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: fix leaking sk after socket release\n\niso_sock_kill() tests !sock_flag(sk, SOCK_ZAPPED) || sk->sk_socket ||\nsock_flag(sk, SOCK_DEAD) for early return, but this is always true since\nsock_orphan(sk) sets SOCK_DEAD, so the sk reference released by socket\nalways leaks, iso_sock_destruct is never called.\n\nThe socket reference also leaks when __iso_sock_close() does not set\nSOCK_ZAPPED, since iso_conn_del() does not call iso_sock_kill() after\nzapping.\n\nFix by replacing SOCK_DEAD by BT_SK_KILLED flag that is not used for\nsomething else, and lock_sock to ensure iso_sock_kill() puts sk only\nafter socket release only once. Release and iso_conn_del may run\nconcurrently. Call iso_sock_kill() from iso_conn_del() to clean sk up\nafter zapping.\n\nRemove call to iso_sock_kill() from iso_sock_close(), as it's generally\nno-op there.","cvss":[],"epss":[{"cve":"CVE-2026-74536","epss":0.00168,"percentile":0.06351,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74536","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74537","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74537","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: ISO: hold sk properly in iso_conn_ready  sk deref in iso_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk is currently accessed without either:      [Task 1]            [Task 2]                         iso_sock_release     iso_conn_ready       sk = conn->sk                           lock_sock(sk)                             conn->sk = NULL       lock_sock(sk)                           release_sock(sk)                           iso_sock_kill(sk)        UAF on sk deref  Fix possible UAF by holding sk refcount in iso_conn_ready().  Also recheck after lock_sock that the socket is still valid.  Adjust locking so conn->sk is cleared only under lock_sock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74537","epss":0.00239,"percentile":0.14915,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.19478500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-74537","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74537","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0d255e63fcf3f13a570d7ac11678fa1164ac015c","https://git.kernel.org/stable/c/1308d72903d792d10b82bc4ef08b8a4452308b04","https://git.kernel.org/stable/c/4e9b5e8669b3602a4e01b6d1e9539b72e42c84d5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: hold sk properly in iso_conn_ready\n\nsk deref in iso_conn_ready must be done either under conn->lock, or\nholding a refcount, to avoid concurrent close. conn->sk is currently\naccessed without either:\n\n    [Task 1]            [Task 2]\n                        iso_sock_release\n    iso_conn_ready\n      sk = conn->sk\n                          lock_sock(sk)\n                            conn->sk = NULL\n      lock_sock(sk)\n                          release_sock(sk)\n                          iso_sock_kill(sk)\n       UAF on sk deref\n\nFix possible UAF by holding sk refcount in iso_conn_ready().  Also\nrecheck after lock_sock that the socket is still valid.  Adjust locking\nso conn->sk is cleared only under lock_sock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74537","epss":0.00239,"percentile":0.14915,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74537","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74540","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74540","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp  l2cap_le_connect_rsp() obtains a channel via __l2cap_get_chan_by_ident() but neither holds a reference nor uses l2cap_chan_hold_unless_zero() before locking and operating on it. A concurrent l2cap_chan_del() triggered by a remote disconnect can free the channel between the lookup and l2cap_chan_lock(), causing a use-after-free.  The BR/EDR counterpart l2cap_connect_rsp() and the sibling handler l2cap_le_command_rej() already use l2cap_chan_hold_unless_zero() to safely hold a reference, but l2cap_le_connect_rsp() was left unprotected.  Fix by adding l2cap_chan_hold_unless_zero() after the ident lookup and l2cap_chan_put() on the exit path, consistent with other L2CAP response handlers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74540","epss":0.00255,"percentile":0.17067,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.20782500000000004},"relatedVulnerabilities":[{"id":"CVE-2026-74540","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74540","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/09f447accc2570751e7d17f0dc0788b40d3edade","https://git.kernel.org/stable/c/15d6c2367217a6a20b1abae9f38ded716bf620f1","https://git.kernel.org/stable/c/1818180fe12d6cec7a437bc59cde8efdf6b10250","https://git.kernel.org/stable/c/522b730c62c53a1981604fd73524697fd347830d","https://git.kernel.org/stable/c/58e3c5289ad230a7e24ae4b0c7b43f5ee6e32136","https://git.kernel.org/stable/c/8325eafb38c3dee5af329266393763693d17381b","https://git.kernel.org/stable/c/c4740e7f23ff9a8210198d8b4703259e21b9f69d","https://git.kernel.org/stable/c/fd4c1e301bdec60a40728ea37de531cbccda501a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp\n\nl2cap_le_connect_rsp() obtains a channel via\n__l2cap_get_chan_by_ident() but neither holds a reference nor uses\nl2cap_chan_hold_unless_zero() before locking and operating on it.\nA concurrent l2cap_chan_del() triggered by a remote disconnect can\nfree the channel between the lookup and l2cap_chan_lock(), causing\na use-after-free.\n\nThe BR/EDR counterpart l2cap_connect_rsp() and the sibling handler\nl2cap_le_command_rej() already use l2cap_chan_hold_unless_zero()\nto safely hold a reference, but l2cap_le_connect_rsp() was left\nunprotected.\n\nFix by adding l2cap_chan_hold_unless_zero() after the ident lookup\nand l2cap_chan_put() on the exit path, consistent with other L2CAP\nresponse handlers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74540","epss":0.00255,"percentile":0.17067,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74540","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74543","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74543","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()  syzbot reported a memory leak [1] in the UDP tunnel NIC offload code.  When device registration fails (e.g. in register_netdevice()), netdev core unwinds by sending a single NETDEV_UNREGISTER notification. If work was queued during NETDEV_REGISTER (utn->work_pending is set), udp_tunnel_nic_unregister() returns early:  \tif (utn->work_pending) \t\treturn;  Because failed registrations do not enter netdev_wait_allrefs_any(), no subsequent NETDEV_UNREGISTER rebroadcast will ever occur. As a result, the struct udp_tunnel_nic allocated in udp_tunnel_nic_alloc() is leaked permanently.  Fix this by removing the early return. Instead, synchronously cancel any pending work with cancel_delayed_work_sync() before freeing @utn.  To be able to call cancel_delayed_work_sync() while holding RTNL (the work also needs RTNL), switch udp_tunnel_nic_device_sync_work() to rtnl_trylock(). If RTNL is contended, requeue the work with a 1 jiffy delay (via queue_delayed_work()) to prevent high CPU contention while waiting for RTNL lock.  The utn->work_pending bookkeeping is no longer needed and is removed, as the workqueue core already tracks the pending/running state of the work.  [1] BUG: memory leak unreferenced object 0xffff888127d5f840 (size 96):   comm \"syz-executor\", pid 5806, jiffies 4294942188   backtrace (crc 99fdb6c8):     __kmalloc_noprof+0x3bf/0x550     udp_tunnel_nic_alloc net/ipv4/udp_tunnel_nic.c:756 [inline]     udp_tunnel_nic_register net/ipv4/udp_tunnel_nic.c:833 [inline]     udp_tunnel_nic_netdevice_event+0x804/0xab0 net/ipv4/udp_tunnel_nic.c:931     notifier_call_chain+0x59/0x160 kernel/notifier.c:85     call_netdevice_notifiers_info+0x7d/0xb0 net/core/dev.c:2250     register_netdevice+0xc10/0xeb0 net/core/dev.c:11478","cvss":[],"epss":[{"cve":"CVE-2026-74543","epss":0.00168,"percentile":0.06427,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74543","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74543","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/080695e6f005e2396f1207fd69d24c442cb230c6","https://git.kernel.org/stable/c/b322532a4b774db1b480a2de84125910a70739a5","https://git.kernel.org/stable/c/b712da45bd9b9835d132e9fbc0c3e43c164cb1fd","https://git.kernel.org/stable/c/f82a2ded3d7a9098267c84f14eafdb98c4550ac5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()\n\nsyzbot reported a memory leak [1] in the UDP tunnel NIC offload code.\n\nWhen device registration fails (e.g. in register_netdevice()), netdev core\nunwinds by sending a single NETDEV_UNREGISTER notification. If work was queued\nduring NETDEV_REGISTER (utn->work_pending is set), udp_tunnel_nic_unregister()\nreturns early:\n\n\tif (utn->work_pending)\n\t\treturn;\n\nBecause failed registrations do not enter netdev_wait_allrefs_any(), no\nsubsequent NETDEV_UNREGISTER rebroadcast will ever occur. As a result, the\nstruct udp_tunnel_nic allocated in udp_tunnel_nic_alloc() is leaked\npermanently.\n\nFix this by removing the early return. Instead, synchronously cancel any\npending work with cancel_delayed_work_sync() before freeing @utn.\n\nTo be able to call cancel_delayed_work_sync() while holding RTNL (the work also\nneeds RTNL), switch udp_tunnel_nic_device_sync_work() to rtnl_trylock(). If RTNL\nis contended, requeue the work with a 1 jiffy delay (via queue_delayed_work())\nto prevent high CPU contention while waiting for RTNL lock.\n\nThe utn->work_pending bookkeeping is no longer needed and is removed, as\nthe workqueue core already tracks the pending/running state of the work.\n\n[1]\nBUG: memory leak\nunreferenced object 0xffff888127d5f840 (size 96):\n  comm \"syz-executor\", pid 5806, jiffies 4294942188\n  backtrace (crc 99fdb6c8):\n    __kmalloc_noprof+0x3bf/0x550\n    udp_tunnel_nic_alloc net/ipv4/udp_tunnel_nic.c:756 [inline]\n    udp_tunnel_nic_register net/ipv4/udp_tunnel_nic.c:833 [inline]\n    udp_tunnel_nic_netdevice_event+0x804/0xab0 net/ipv4/udp_tunnel_nic.c:931\n    notifier_call_chain+0x59/0x160 kernel/notifier.c:85\n    call_netdevice_notifiers_info+0x7d/0xb0 net/core/dev.c:2250\n    register_netdevice+0xc10/0xeb0 net/core/dev.c:11478","cvss":[],"epss":[{"cve":"CVE-2026-74543","epss":0.00168,"percentile":0.06427,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74543","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74544","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74544","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds  u32_change() copies the user-provided tc_u32_sel.offshift (unsigned char, 0-255) into the kernel knode object without bounds validation. When a packet later hits u32_classify() with TC_U32_VAROFFSET set, it evaluates `ntohs(offmask & *data) >> offshift` where the left operand is a 16-bit value promoted to a 32-bit int. Any offshift >= 32 is undefined behavior per C11 6.5.7p3, triggerable by an unprivileged user via user/network namespaces.  UBSAN: shift-out-of-bounds in net/sched/cls_u32.c:236:43 shift exponent 32 is too large for 32-bit type int  Fix this by rejecting offshift >= 16 during filter creation in u32_change().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74544","epss":0.00121,"percentile":0.02171,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.092565},"relatedVulnerabilities":[{"id":"CVE-2026-74544","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74544","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/313cb9ffc4101a885d791facf4b5ea3d5e06144d","https://git.kernel.org/stable/c/aef96eead2860cbfa371e4471d4f04412213b958"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_u32: validate offshift to prevent shift-out-of-bounds\n\nu32_change() copies the user-provided tc_u32_sel.offshift (unsigned char,\n0-255) into the kernel knode object without bounds validation. When a\npacket later hits u32_classify() with TC_U32_VAROFFSET set, it evaluates\n`ntohs(offmask & *data) >> offshift` where the left operand is a 16-bit\nvalue promoted to a 32-bit int. Any offshift >= 32 is undefined behavior\nper C11 6.5.7p3, triggerable by an unprivileged user via user/network\nnamespaces.\n\nUBSAN: shift-out-of-bounds in net/sched/cls_u32.c:236:43\nshift exponent 32 is too large for 32-bit type int\n\nFix this by rejecting offshift >= 16 during filter creation in\nu32_change().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74544","epss":0.00121,"percentile":0.02171,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74544","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74546","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74546","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read  If the fan data becomes 0 between the FAN_DATA_VALID() check and the FAN_PERIOD_TO_RPM() conversion, it will result in a divide-by-zero crash due to a race with a concurrent update of the cached fan value.  Fix a TOCTOU issue by reading fan data once.","cvss":[],"epss":[{"cve":"CVE-2026-74546","epss":0.00173,"percentile":0.06833,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74546","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74546","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/009240d057e26831cc925feaba4c490209c1d0ba","https://git.kernel.org/stable/c/1b46fe9dc8f8de59310f37e6c5e5c0e05ded46c3","https://git.kernel.org/stable/c/689a2ea75434131d0af58aeb7d51fde40e858b4d","https://git.kernel.org/stable/c/76963b04b2d1c648d69949d8dd521e1ff7f40b51","https://git.kernel.org/stable/c/832069bec79cf6f903441c5769d3cdba95d0af33","https://git.kernel.org/stable/c/96ad57d31763559d376416cdf3bf5ae79bbbebec","https://git.kernel.org/stable/c/d328175045176f85c15c369bd21dc551351e7935"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read\n\nIf the fan data becomes 0 between the FAN_DATA_VALID() check and the\nFAN_PERIOD_TO_RPM() conversion, it will result in a divide-by-zero crash\ndue to a race with a concurrent update of the cached fan value.\n\nFix a TOCTOU issue by reading fan data once.","cvss":[],"epss":[{"cve":"CVE-2026-74546","epss":0.00173,"percentile":0.06833,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74546","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74547","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74547","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread  When userspace configures 'auto_update_interval' to 0 via sysfs, the background kthread executes schedule_timeout_interruptible(0), which returns immediately.  If 'num_temp_sensors' is concurrently or previously set to 0, the msleep_interruptible() delay inside adt7470_read_temperatures() also becomes 0. This combination forces the background thread into a tight, unbounded busy-loop, hogging the CPU and flooding the I2C bus with a continuous stream of transactions.  Fix this vulnerability by raising the lower limit of the clamp_val in auto_update_interval_store() from 0 to 500 milliseconds. This guarantees a reasonable minimum sleep window between sensor updates, protecting the system from intentional or accidental I2C bus denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-74547","epss":0.00177,"percentile":0.07395,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74547","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74547","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1325975a2eab265510e6036d8bf0c0068373d332","https://git.kernel.org/stable/c/1a42bd72a66205e439db1d1142442b62d393408a","https://git.kernel.org/stable/c/2c4c4d7cadd10b50b5489183bbbb9eb95f6f8344","https://git.kernel.org/stable/c/38e6b5ce5794ff09442231cc171c2be5e900bab3","https://git.kernel.org/stable/c/4dc1518f9cc57c6db99514cafeb02dd7117d5bda","https://git.kernel.org/stable/c/5ea299c3aa42a827f6a863eeead6de3525bbb17a","https://git.kernel.org/stable/c/82d65f7ef11edcea0228745440b8b4b1f222c34c","https://git.kernel.org/stable/c/cb0b7f9c43b0abbd422a7e4c2c85e91db429207c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (adt7470) Fix busy-loop and I2C flooding in update thread\n\nWhen userspace configures 'auto_update_interval' to 0 via sysfs, the\nbackground kthread executes schedule_timeout_interruptible(0), which\nreturns immediately.\n\nIf 'num_temp_sensors' is concurrently or previously set to 0, the\nmsleep_interruptible() delay inside adt7470_read_temperatures() also\nbecomes 0. This combination forces the background thread into a tight,\nunbounded busy-loop, hogging the CPU and flooding the I2C bus with a\ncontinuous stream of transactions.\n\nFix this vulnerability by raising the lower limit of the clamp_val in\nauto_update_interval_store() from 0 to 500 milliseconds. This guarantees\na reasonable minimum sleep window between sensor updates, protecting the\nsystem from intentional or accidental I2C bus denial of service.","cvss":[],"epss":[{"cve":"CVE-2026-74547","epss":0.00177,"percentile":0.07395,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74547","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74548","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  forcedeth: fix UAF of txrx_stats in nv_remove  nv_remove() frees the per-CPU txrx_stats before unregister_netdev(). Until unregister completes, ndo_get_stats64, the NAPI/xmit data path, and nv_close()/drain may still access txrx_stats, leading to a use-after-free.  Free the stats only after unregister_netdev().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74548","epss":0.00126,"percentile":0.02568,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74548","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/201e05aa531eba0dfe2ee05b4e178f6ffa12c8b1","https://git.kernel.org/stable/c/22666ba1420164753d7b0f5a841986b25ace5435","https://git.kernel.org/stable/c/7c22b4ee0bd003cecfc14ca28981cb213e201f70","https://git.kernel.org/stable/c/ae20a8a4de06a289d40b0a0633d8d573f1fcb049","https://git.kernel.org/stable/c/c9d24a205fd508b9999fcab6aca4c590490a12cf","https://git.kernel.org/stable/c/cdf864d5d3c813ae1876f2bacc1cf3ac3c66dfc9","https://git.kernel.org/stable/c/cf2dcde2284562ff87830ca0b7fa2b06e95aef1e","https://git.kernel.org/stable/c/d51ce7a63b76eda02cabfed1b0cc277b2f5c9bcc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nforcedeth: fix UAF of txrx_stats in nv_remove\n\nnv_remove() frees the per-CPU txrx_stats before unregister_netdev().\nUntil unregister completes, ndo_get_stats64, the NAPI/xmit data path,\nand nv_close()/drain may still access txrx_stats, leading to a\nuse-after-free.\n\nFree the stats only after unregister_netdev().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74548","epss":0.00126,"percentile":0.02568,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74548","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74549","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74549","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (nct6775-core) Prevent access to unsupported weight registers  Sashiko reports:  During initialization of the nct6116 chip, the driver sets data->pwm_num to 5. However, it assigns several NCT6106 register arrays (such as NCT6106_REG_WEIGHT_DUTY_STEP, NCT6106_REG_WEIGHT_TEMP_SEL, and NCT6106_REG_WEIGHT_TEMP_*) to data->REG_PWM and data->REG_WEIGHT_TEMP. These arrays only contain 3 elements.  In nct6775_update_pwm(), the driver iterates up to data->pwm_num. If data->has_pwm has bits 3 or 4 set (which is structurally possible for nct6116), the loop attempts to read elements at index 3 and 4 from these 3-element arrays. This results in a global out-of-bounds read, which can be caught by KASAN.  Furthermore, the driver uses these garbage out-of-bounds values as hardware register addresses for subsequent read and write operations. This leads to invalid hardware register access, potentially causing hardware misconfiguration or system crashes.  The underlying problem is that the chip does support up to five fan control channels, but only the first three support weight control. Fix the problem by extending the affected weight register arrays with zeroed fields. The driver uses zeroed register addresses to determine if a register is supported or not, and skips accesses for unsupported registers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74549","epss":0.0013,"percentile":0.02943,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09945},"relatedVulnerabilities":[{"id":"CVE-2026-74549","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74549","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0d11b2a10269ace29832f584d207ff3768f79dc5","https://git.kernel.org/stable/c/1b722740ac5c2b2070f9ba922f4e0f227faf0246","https://git.kernel.org/stable/c/25b528816f5d83be5236dc182692369e8c9402b0","https://git.kernel.org/stable/c/4a77f1d72c6db04cbbfab0250292ac71fdea5f0a","https://git.kernel.org/stable/c/4ad2972ef0e1bd1018ad7a72661a4636ed7daecc","https://git.kernel.org/stable/c/513d847f7a95bbdbeaaf55fb942c38992587734f","https://git.kernel.org/stable/c/689082a4cb166a7ae9729f7b12339e69fdad6c52","https://git.kernel.org/stable/c/d0b704e569ac3b8416d8e02270cdc9bf830ed395"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775-core) Prevent access to unsupported weight registers\n\nSashiko reports:\n\nDuring initialization of the nct6116 chip, the driver sets data->pwm_num\nto 5. However, it assigns several NCT6106 register arrays (such as\nNCT6106_REG_WEIGHT_DUTY_STEP, NCT6106_REG_WEIGHT_TEMP_SEL, and\nNCT6106_REG_WEIGHT_TEMP_*) to data->REG_PWM and data->REG_WEIGHT_TEMP.\nThese arrays only contain 3 elements.\n\nIn nct6775_update_pwm(), the driver iterates up to data->pwm_num. If\ndata->has_pwm has bits 3 or 4 set (which is structurally possible for\nnct6116), the loop attempts to read elements at index 3 and 4 from these\n3-element arrays. This results in a global out-of-bounds read, which can\nbe caught by KASAN.\n\nFurthermore, the driver uses these garbage out-of-bounds values as\nhardware register addresses for subsequent read and write operations. This\nleads to invalid hardware register access, potentially causing hardware\nmisconfiguration or system crashes.\n\nThe underlying problem is that the chip does support up to five fan\ncontrol channels, but only the first three support weight control.\nFix the problem by extending the affected weight register arrays with\nzeroed fields. The driver uses zeroed register addresses to determine\nif a register is supported or not, and skips accesses for unsupported\nregisters.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74549","epss":0.0013,"percentile":0.02943,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74549","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74550","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74550","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: do not send ICMP/NDISC Redirects when peer allocation fails  When inet_getpeer_v4() or inet_getpeer_v6() fails to allocate a peer entry under memory pressure or tree size caps, redirect handlers previously fell back to sending un-rate-limited ICMP/NDISC Redirect messages.  In IPv4, ip_rt_send_redirect() called icmp_send() directly when peer == NULL. In IPv6, ip6_forward() and ndisc_send_redirect() passed a NULL peer into inet_peer_xrlim_allow(), which returned true when peer == NULL.  Because ICMP/NDISC Redirects are not part of the default global rate limit mask (sysctl_icmp_ratemask), sending redirects when peer == NULL creates an un-rate-limited ICMP packet storm.  Fix this by failing closed in ip_rt_send_redirect(), ip6_forward(), and ndisc_send_redirect() when peer is NULL.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74550","epss":0.00479,"percentile":0.39833,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.35925},"relatedVulnerabilities":[{"id":"CVE-2026-74550","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74550","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/21666f7af49a90ef44d474916b8ef4402dfd74f5","https://git.kernel.org/stable/c/5ec5f00fc606a6df8434948c4552b3cb1176595d","https://git.kernel.org/stable/c/828f6670d110ff2bf44c743037b38badc315704c","https://git.kernel.org/stable/c/c0adf8b4247bcc5a145a25c1929006eb392580bb","https://git.kernel.org/stable/c/dbc3791e3b2472e1ccc08947e0f83b443470ff4f","https://git.kernel.org/stable/c/f5ecaa7ea7686fa7ecdb6affc9d3a9a42e4524b1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: do not send ICMP/NDISC Redirects when peer allocation fails\n\nWhen inet_getpeer_v4() or inet_getpeer_v6() fails to allocate a peer entry\nunder memory pressure or tree size caps, redirect handlers previously fell\nback to sending un-rate-limited ICMP/NDISC Redirect messages.\n\nIn IPv4, ip_rt_send_redirect() called icmp_send() directly when peer == NULL.\nIn IPv6, ip6_forward() and ndisc_send_redirect() passed a NULL peer into\ninet_peer_xrlim_allow(), which returned true when peer == NULL.\n\nBecause ICMP/NDISC Redirects are not part of the default global rate limit\nmask (sysctl_icmp_ratemask), sending redirects when peer == NULL creates\nan un-rate-limited ICMP packet storm.\n\nFix this by failing closed in ip_rt_send_redirect(), ip6_forward(), and\nndisc_send_redirect() when peer is NULL.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74550","epss":0.00479,"percentile":0.39833,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74550","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74551","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74551","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (nzxt-smart2) DMA-align output buffer  Sashiko reports:  When send_output_report() calls hid_hw_output_report(), the underlying USB HID core calls usb_interrupt_msg() which maps this buffer directly for DMA.  When the DMA mapping flushes or invalidates the cacheline, it will corrupt the adjacent variables (mutex, update_interval) that were modified concurrently by the CPU. This causes memory corruption due to cacheline sharing on non-coherent CPU architectures (such as ARM or MIPS). The DMA API debugging tool (CONFIG_DMA_API_DEBUG) will trigger runtime warnings for this violation.  Any operation that triggers send_output_report() (like setting a fan speed or updating the interval) causes the USB DMA mapping. On systems with non-coherent caches, this structural bug causes immediate and deterministic memory corruption.  Align the output buffer to ARCH_DMA_MINALIGN to fix the problem.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74551","epss":0.00129,"percentile":0.0289,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74551","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74551","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/080bbf42faf77e6489ab30d5114c5f8f6ccbb1b8","https://git.kernel.org/stable/c/2332d35aaf206c17acf848522817252732596676","https://git.kernel.org/stable/c/51a76bc1b8e717ee3fc0d84f15ac51490ca5f76f","https://git.kernel.org/stable/c/6a2dbce5da2d2163a5b684acf68a0e54582ff0fa","https://git.kernel.org/stable/c/70ad543ce81f368411b6c721265a3b2d7ab4fda4","https://git.kernel.org/stable/c/81a6593b1c8dfb2694cd0ce39be01212d2b8436c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nzxt-smart2) DMA-align output buffer\n\nSashiko reports:\n\nWhen send_output_report() calls hid_hw_output_report(), the underlying USB\nHID core calls usb_interrupt_msg() which maps this buffer directly for DMA.\n\nWhen the DMA mapping flushes or invalidates the cacheline, it will corrupt\nthe adjacent variables (mutex, update_interval) that were modified\nconcurrently by the CPU. This causes memory corruption due to cacheline\nsharing on non-coherent CPU architectures (such as ARM or MIPS). The DMA\nAPI debugging tool (CONFIG_DMA_API_DEBUG) will trigger runtime warnings\nfor this violation.\n\nAny operation that triggers send_output_report() (like setting a fan speed\nor updating the interval) causes the USB DMA mapping. On systems with\nnon-coherent caches, this structural bug causes immediate and deterministic\nmemory corruption.\n\nAlign the output buffer to ARCH_DMA_MINALIGN to fix the problem.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74551","epss":0.00129,"percentile":0.0289,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74551","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74552","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74552","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (lm90) Only report alarms if driver is ready  Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference.  Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.","cvss":[],"epss":[{"cve":"CVE-2026-74552","epss":0.00173,"percentile":0.06831,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74552","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74552","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/075fce376cf852db9293481edce07c181a9b1f46","https://git.kernel.org/stable/c/31ce62d36d859423dc39f9902f7c4c307b2e00e3","https://git.kernel.org/stable/c/4eed33c7db5c0c573928d28d8a2c003642c679b8","https://git.kernel.org/stable/c/70d9a71aa407044d70b50d356b6decf6659c4d56","https://git.kernel.org/stable/c/aa9429edf9fc0e90d6f4da19ea4b5495a54ab117","https://git.kernel.org/stable/c/f0b791a006512a48b6348494cb6960598fa99a58"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Only report alarms if driver is ready\n\nUserspace can read sysfs attributes before driver registration is complete,\nimmediately after devm_hwmon_device_register_with_info() has been called.\nAt that time, data->hwmon_dev is not yet initialized. This can trigger\na NULL pointer access since lm90_update_device() and with it\nlm90_update_alarms_locked() will be called. This call schedules\nreport_work and lm90_report_alarms(), which passes the still-NULL\ndata->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer\ndereference.\n\nFix the problem by only scheduling the report and alert workers\ndata->hwmon_dev is set.","cvss":[],"epss":[{"cve":"CVE-2026-74552","epss":0.00173,"percentile":0.06831,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74552","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74553","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74553","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (nct6775-core) Fix number of temperature registers for NCT6116  Unlike NCT6106, NCT6116 only has three temperature registers, and with it only three temperature source and temperature source configuration registers. The register addresses match those of NCT6106 and can be re-used.  The code used a separate array to list the temperature source registers for NCT6116, but used the size of the NCT6106 register array to set the number of registers. The NCT6106 register array provides six addresses, while the temperature source register array for NCT6116 only provides three addresses. This causes a KASAN report.  BUG: KASAN: global-out-of-bounds in nct6775_probe+0x936/0x46f0 [nct6775] Read of size 2 at addr ffffffffc19561a6 by task modprobe/954 ... Call Trace:  dump_stack+0x7d/0xa7  print_address_description.constprop.0+0x1c/0x220  ? __kasan_kmalloc.constprop.0+0xc9/0xd0  ? __kmalloc_node_track_caller+0x194/0x5b0  ? nct6775_probe+0x936/0x46f0 [nct6775]  ? nct6775_probe+0x936/0x46f0 [nct6775] ...  Fix the problem by hard-coding the number of temperature and temperature configuration registers to three for NCT6116. Drop the unnecessary NCT6116_REG_TEMP_SOURCE array and re-use NCT6106_REG_TEMP_SOURCE.","cvss":[],"epss":[{"cve":"CVE-2026-74553","epss":0.00161,"percentile":0.05647,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-74553","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74553","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/16c45bb3d3434cfb9ea264fa52090d0823240465","https://git.kernel.org/stable/c/739d7fc6b6f662c8286912157f0c4912388aa292","https://git.kernel.org/stable/c/9a87dfaa05c3c9d3a4cdb7eafc1ab4abc84f6eef","https://git.kernel.org/stable/c/a42d727dae5701deac8bb2a75effadae7d681153","https://git.kernel.org/stable/c/a7f47f5246cd6c3199e5fb2d4109cc53e766e3f0","https://git.kernel.org/stable/c/b0e8adb2ccb43009796897ced09f91636685c9d3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775-core) Fix number of temperature registers for NCT6116\n\nUnlike NCT6106, NCT6116 only has three temperature registers, and with\nit only three temperature source and temperature source configuration\nregisters. The register addresses match those of NCT6106 and can be\nre-used.\n\nThe code used a separate array to list the temperature source registers\nfor NCT6116, but used the size of the NCT6106 register array to set\nthe number of registers. The NCT6106 register array provides six addresses,\nwhile the temperature source register array for NCT6116 only provides three\naddresses. This causes a KASAN report.\n\nBUG: KASAN: global-out-of-bounds in nct6775_probe+0x936/0x46f0 [nct6775]\nRead of size 2 at addr ffffffffc19561a6 by task modprobe/954\n...\nCall Trace:\n dump_stack+0x7d/0xa7\n print_address_description.constprop.0+0x1c/0x220\n ? __kasan_kmalloc.constprop.0+0xc9/0xd0\n ? __kmalloc_node_track_caller+0x194/0x5b0\n ? nct6775_probe+0x936/0x46f0 [nct6775]\n ? nct6775_probe+0x936/0x46f0 [nct6775]\n...\n\nFix the problem by hard-coding the number of temperature and temperature\nconfiguration registers to three for NCT6116. Drop the unnecessary\nNCT6116_REG_TEMP_SOURCE array and re-use NCT6106_REG_TEMP_SOURCE.","cvss":[],"epss":[{"cve":"CVE-2026-74553","epss":0.00161,"percentile":0.05647,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74553","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74555","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74555","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race  Commit fbefe22811c3 (\"scsi: libsas: Don't always drain event workqueue for HA resume\") introduced sas_resume_ha_no_sync() to avoid a deadlock: the PHYE_RESUME_TIMEOUT handler, running on the HA event workqueue, calls sas_deform_port() -> sas_destruct_devices(), which removes SCSI devices and waits for the host to become runtime-active. But the host cannot resume until sas_resume_ha() -> sas_drain_work() returns, and the drain is blocked on that very handler.  However skipping the drain reintroduces a race: hisi_sas returns from resume before all PHY UP work and libsas discovery work finish. The controller may then autosuspend while disks are still waking up. The disks issue IO to a suspended controller, the IO fails, and the disks get disabled.  Fix the deadlock at its source by moving the PHYE_RESUME_TIMEOUT notification to after sas_drain_work(). By then the host resume is about to complete, so device removal through device_link no longer blocks on the resume and the cycle is broken.  With the deadlock gone, restore sas_resume_ha() (the draining variant) in hisi_sas and remove sas_resume_ha_no_sync().  The reorder is safe for the other libsas consumers (isci, pm8001, aic94xx, mvsas). During suspend, sas_suspend_devices() calls sas_notify_lldd_dev_gone() for each device, which sets dev->lldd_dev to NULL. When scsi_unblock_requests re-enables I/O in resume, any I/O to a timed-out phy's disk is immediately rejected by the LLDD before reaching hardware: isci returns SAS_DEVICE_UNKNOWN (mapped to DID_BAD_TARGET), and pm8001 returns SAS_PHY_DOWN (mapped to DID_NO_CONNECT). Both complete directly via scsi_done() without entering SCSI EH. This is identical in both the old and new ordering since lldd_dev_gone runs during suspend, before resume. The reorder only affects when the PHYE_RESUME_TIMEOUT handler runs (synchronized by sas_drain_work() vs. asynchronous after resume returns), not whether I/O can reach the device. aic94xx and mvsas do not register any PM ops and never reach this code path.","cvss":[],"epss":[{"cve":"CVE-2026-74555","epss":0.00161,"percentile":0.05599,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-74555","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74555","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/09357f067122e2e28ec52e27013a1660a1571618","https://git.kernel.org/stable/c/3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845","https://git.kernel.org/stable/c/9e24b47ef81d43b3fb1b14294f09991640c79fcc","https://git.kernel.org/stable/c/b9c44a14062093e9fc2d6bddc696cfceadb482d7","https://git.kernel.org/stable/c/c391b5899dd46485a5893696c12ae3e95a3a7325","https://git.kernel.org/stable/c/e50a6523a603594a6d92cdecfe11997d639410a3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race\n\nCommit fbefe22811c3 (\"scsi: libsas: Don't always drain event workqueue\nfor HA resume\") introduced sas_resume_ha_no_sync() to avoid a deadlock:\nthe PHYE_RESUME_TIMEOUT handler, running on the HA event workqueue,\ncalls sas_deform_port() -> sas_destruct_devices(), which removes SCSI\ndevices and waits for the host to become runtime-active. But the host\ncannot resume until sas_resume_ha() -> sas_drain_work() returns, and the\ndrain is blocked on that very handler.\n\nHowever skipping the drain reintroduces a race: hisi_sas returns from\nresume before all PHY UP work and libsas discovery work finish. The\ncontroller may then autosuspend while disks are still waking up. The\ndisks issue IO to a suspended controller, the IO fails, and the disks\nget disabled.\n\nFix the deadlock at its source by moving the PHYE_RESUME_TIMEOUT\nnotification to after sas_drain_work(). By then the host resume is about\nto complete, so device removal through device_link no longer blocks on\nthe resume and the cycle is broken.\n\nWith the deadlock gone, restore sas_resume_ha() (the draining variant)\nin hisi_sas and remove sas_resume_ha_no_sync().\n\nThe reorder is safe for the other libsas consumers (isci, pm8001,\naic94xx, mvsas). During suspend, sas_suspend_devices() calls\nsas_notify_lldd_dev_gone() for each device, which sets dev->lldd_dev to\nNULL. When scsi_unblock_requests re-enables I/O in resume, any I/O to a\ntimed-out phy's disk is immediately rejected by the LLDD before reaching\nhardware: isci returns SAS_DEVICE_UNKNOWN (mapped to DID_BAD_TARGET),\nand pm8001 returns SAS_PHY_DOWN (mapped to DID_NO_CONNECT). Both\ncomplete directly via scsi_done() without entering SCSI EH. This is\nidentical in both the old and new ordering since lldd_dev_gone runs\nduring suspend, before resume. The reorder only affects when the\nPHYE_RESUME_TIMEOUT handler runs (synchronized by sas_drain_work()\nvs. asynchronous after resume returns), not whether I/O can reach the\ndevice. aic94xx and mvsas do not register any PM ops and never reach\nthis code path.","cvss":[],"epss":[{"cve":"CVE-2026-74555","epss":0.00161,"percentile":0.05599,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74555","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74556","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74556","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer  iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data buffer, which is allocated for ISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes.  For the LOGIN_RSP, TEXT_RSP, REJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU whose DataSegmentLength exceeds that buffer.  The SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its data segment (sense/response data) into conn->data via iscsi_tcp_data_recv_prep(), but it does so without the same check.  The only upstream bound on in.datalen is conn->max_recv_dlength, the initiator's advertised MaxRecvDataSegmentLength, which is commonly negotiated well above 8192 (open-iscsi defaults to 262144).  A target that returns a SCSI Response with a DataSegmentLength between 8193 and max_recv_dlength therefore overflows the 8192-byte conn->data buffer.  Once the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly like those responses: bound the data segment, receive it into conn->data when present, and otherwise complete the PDU with no data.  Fold the opcode into that case group rather than duplicating the check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74556","epss":0.00399,"percentile":0.33346,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37505999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-74556","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74556","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/084af0253673425ce2ae62e3c7f74f0dd023711b","https://git.kernel.org/stable/c/72815741715bd41556dac5eeb068bf0f8af06ee7","https://git.kernel.org/stable/c/a51812842084fd390590ab8dc0431f10c73ddc56","https://git.kernel.org/stable/c/a8f94cc9f0e5759252551be3a172960c57f21f54","https://git.kernel.org/stable/c/b0aa3e8e2ab4ca92adb28a3ef41873b3363b8676","https://git.kernel.org/stable/c/c1dea15f819cded9b3faf58f8bec72323568b6e6","https://git.kernel.org/stable/c/c97b5265cc47775f77fd2a23d6bde0426997b233","https://git.kernel.org/stable/c/f1a3a51fc5dba0e99532379665069f1700da6b44"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer\n\niscsi_tcp_hdr_dissect() receives the data segment of several PDU types\ninto the fixed-size conn->data buffer, which is allocated for\nISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes.  For the LOGIN_RSP, TEXT_RSP,\nREJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU\nwhose DataSegmentLength exceeds that buffer.\n\nThe SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its\ndata segment (sense/response data) into conn->data via\niscsi_tcp_data_recv_prep(), but it does so without the same check.  The\nonly upstream bound on in.datalen is conn->max_recv_dlength, the\ninitiator's advertised MaxRecvDataSegmentLength, which is commonly\nnegotiated well above 8192 (open-iscsi defaults to 262144).  A target\nthat returns a SCSI Response with a DataSegmentLength between 8193 and\nmax_recv_dlength therefore overflows the 8192-byte conn->data buffer.\n\nOnce the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly\nlike those responses: bound the data segment, receive it into conn->data\nwhen present, and otherwise complete the PDU with no data.  Fold the\nopcode into that case group rather than duplicating the check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74556","epss":0.00399,"percentile":0.33346,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74556","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74557","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74557","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer  iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the target-supplied data segment.  The segment carries a 2-byte sense length followed by the sense bytes, so it must hold 2 + senselen bytes, but the bounds check only requires datalen >= senselen:  \tsenselen = get_unaligned_be16(data); \tif (datalen < senselen) \t\tgoto invalid_datalen; \tmemcpy(sc->sense_buffer, data + 2, \t       min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));  A target that returns a SCSI Response whose datalen equals senselen (with senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data + 2 read up to two bytes past the received data.  Those bytes are stale conn->data contents and end up in the command's sense buffer, which is returned to userspace.  Account for the 2-byte sense length prefix in the check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74557","epss":0.00329,"percentile":0.25789,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.24675},"relatedVulnerabilities":[{"id":"CVE-2026-74557","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74557","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1f07a897d43c63e6c9458bf77450defef39b5833","https://git.kernel.org/stable/c/3ef209ca0b4b68c75e9a814d90cc916026b5a6ac","https://git.kernel.org/stable/c/60499924faf4ef97e84228c20515218ef121facf","https://git.kernel.org/stable/c/7567f06abdefb1caf2d836107c4d08c5185c650e","https://git.kernel.org/stable/c/812f1ae95b22419422972748f173b0916ee4d621","https://git.kernel.org/stable/c/98b87885de4b7f605533a2860685f5689fce8e82","https://git.kernel.org/stable/c/baa04572673125e4d5bc309b4077d1cb46cc78d1","https://git.kernel.org/stable/c/fef6167e8149896cd81bea333fd51b1c91239149"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libiscsi: Fix stale-data leak into the SCSI sense buffer\n\niscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the\ntarget-supplied data segment.  The segment carries a 2-byte sense length\nfollowed by the sense bytes, so it must hold 2 + senselen bytes, but the\nbounds check only requires datalen >= senselen:\n\n\tsenselen = get_unaligned_be16(data);\n\tif (datalen < senselen)\n\t\tgoto invalid_datalen;\n\tmemcpy(sc->sense_buffer, data + 2,\n\t       min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));\n\nA target that returns a SCSI Response whose datalen equals senselen\n(with senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data +\n2 read up to two bytes past the received data.  Those bytes are stale\nconn->data contents and end up in the command's sense buffer, which is\nreturned to userspace.\n\nAccount for the 2-byte sense length prefix in the check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74557","epss":0.00329,"percentile":0.25789,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74557","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74563","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74563","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()  rds_tcp_laddr_check() looks up a scoped IPv6 interface with dev_get_by_index_rcu(), drops the RCU read-side lock, and only then passes the bare struct net_device * into ipv6_chk_addr().  dev_get_by_index_rcu() only keeps the device alive within the same RCU read-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can free the net_device; ipv6_chk_addr() then dereferences the stale pointer in __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading freed memory.  Keep the RCU read-side lock held across the ipv6_chk_addr() call instead of dropping it right after the lookup, so the device cannot be freed while it is in use.    BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)   Read of size 8 at addr ffff8880106ec000 by task exploit/153   Call Trace:    ...    kasan_report (mm/kasan/report.c:595)    __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)    ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)    rds_tcp_laddr_check (net/rds/tcp.c:370)    rds_bind (net/rds/bind.c:248)    __sys_bind (net/socket.c:1920)    __x64_sys_bind (net/socket.c:1956)    do_syscall_64 (arch/x86/entry/syscall_64.c:63)    entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74563","epss":0.00117,"percentile":0.01895,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-74563","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74563","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/76dd48886eeeb5fcf2b837d2f4c3d17eebeac9ef","https://git.kernel.org/stable/c/78f75d632f74b8de0f081a128588f7c37d0d1164","https://git.kernel.org/stable/c/8398bc477d3cb3e2b018a5aaac2bec0f69acda30","https://git.kernel.org/stable/c/b1d480fce05f857dc438080cd8c9244b84a83494","https://git.kernel.org/stable/c/ba95bce5dfe6e2ef602a87e0557225f2934ccb5c","https://git.kernel.org/stable/c/c4933624a6f416ecfcc31ab58d585da1207a0597","https://git.kernel.org/stable/c/f0d1fb05d70c8a561cd8d0473bcacafa2fc137ff","https://git.kernel.org/stable/c/f8a8977af2134a1d91e5f9773cb7d9d53278c830"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()\n\nrds_tcp_laddr_check() looks up a scoped IPv6 interface with\ndev_get_by_index_rcu(), drops the RCU read-side lock, and only then\npasses the bare struct net_device * into ipv6_chk_addr().\n\ndev_get_by_index_rcu() only keeps the device alive within the same RCU\nread-side section. After rcu_read_unlock(), a concurrent RTM_DELLINK can\nfree the net_device; ipv6_chk_addr() then dereferences the stale pointer\nin __ipv6_chk_addr_and_flags() (e.g. l3mdev_master_dev_rcu(dev)), reading\nfreed memory.\n\nKeep the RCU read-side lock held across the ipv6_chk_addr() call instead\nof dropping it right after the lookup, so the device cannot be freed\nwhile it is in use.\n\n  BUG: KASAN: slab-use-after-free in __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)\n  Read of size 8 at addr ffff8880106ec000 by task exploit/153\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   __ipv6_chk_addr_and_flags (... net/ipv6/addrconf.c:1998)\n   ipv6_chk_addr (net/ipv6/addrconf.c:2031 net/ipv6/addrconf.c:1972)\n   rds_tcp_laddr_check (net/rds/tcp.c:370)\n   rds_bind (net/rds/bind.c:248)\n   __sys_bind (net/socket.c:1920)\n   __x64_sys_bind (net/socket.c:1956)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74563","epss":0.00117,"percentile":0.01895,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74563","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74564","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74564","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH  The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the dsthash_ent structure which represents an entry in the hashtable.  There is a union area which uses a different layout to express the rate match mode.  Update .checkentry path to validate the XT_HASHLIMIT_RATE_MATCH mode flag is requested by two or more different rules that refer to the same hashtable. Otherwise, uninitialized access to the burst field in the union is possible.  Reject the use of the XT_HASHLIMIT_RATE_MATCH mode flag if set on by revision less than 3 too.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74564","epss":0.00118,"percentile":0.0192,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08614},"relatedVulnerabilities":[{"id":"CVE-2026-74564","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74564","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/06a76334243ccd875a981aa8bb46c0f931ef1e3b","https://git.kernel.org/stable/c/24683fea1f06bd3bd2707b99460e859bc6464c22","https://git.kernel.org/stable/c/305b63e1402267459fdabb183af4527f6799eebf","https://git.kernel.org/stable/c/32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0","https://git.kernel.org/stable/c/402befce5854c195058cf4bab7c78ca286068a26","https://git.kernel.org/stable/c/d186f77d18bdfb252d401ff992ca3001a6a65a0f","https://git.kernel.org/stable/c/dee686b5e7f21180538ff719867702f411c8eb5c","https://git.kernel.org/stable/c/f76ab783e7d8d33e33dd7dfa697297f70d57b0e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH\n\nThe XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the\ndsthash_ent structure which represents an entry in the hashtable.  There\nis a union area which uses a different layout to express the rate match\nmode.\n\nUpdate .checkentry path to validate the XT_HASHLIMIT_RATE_MATCH mode\nflag is requested by two or more different rules that refer to the same\nhashtable. Otherwise, uninitialized access to the burst field in the\nunion is possible.\n\nReject the use of the XT_HASHLIMIT_RATE_MATCH mode flag if set on by\nrevision less than 3 too.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74564","epss":0.00118,"percentile":0.0192,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74564","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74565","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74565","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: make nft_object rhltable per table  The nft_object rhltable is global, this allows for accessing objects that are being dismangled from lookup path by other existing netns. Given the nft_obj_destroy() releases the object inmediately, this might lead to use-after-free of these objects that are being released. Make the existing rhltable per table to address this issue to deal with with the nft_rcv_nl_event() path too.  Update nft_obj_lookup() to take the table as non-const, otherwise, compiler complains when passing the objname_ht to rhltable_lookup().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74565","epss":0.00116,"percentile":0.01829,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08874},"relatedVulnerabilities":[{"id":"CVE-2026-74565","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74565","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1948e4f85b855618b5b9a27265f98d816f4cb7cb","https://git.kernel.org/stable/c/63ba12b664a2cd3220ed43e22c717715f4cc2ae8","https://git.kernel.org/stable/c/7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af","https://git.kernel.org/stable/c/f4f699790590bd0896c48a71e9232a65198f92f0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: make nft_object rhltable per table\n\nThe nft_object rhltable is global, this allows for accessing objects\nthat are being dismangled from lookup path by other existing netns.\nGiven the nft_obj_destroy() releases the object inmediately, this might\nlead to use-after-free of these objects that are being released.\nMake the existing rhltable per table to address this issue to deal with\nwith the nft_rcv_nl_event() path too.\n\nUpdate nft_obj_lookup() to take the table as non-const, otherwise,\ncompiler complains when passing the objname_ht to rhltable_lookup().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74565","epss":0.00116,"percentile":0.01829,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74565","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74566","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74566","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  keys: make keyring key-chunk byte order agree with keyring_diff_objects()  keyring_get_key_chunk() loads description bytes into the index chunk low address first, while keyring_diff_objects() numbers the first differing bit from the low end and folds the absolute byte index into the level without removing the inline-prefix offset the level already carries. The two disagree on byte order and bit position, so the array can be told two keys first differ at a bit that does not differ in the chunk the walker uses, letting crafted descriptions collide into one node.  Load the chunk in the order keyring_diff_objects() assumes and drop the inline-prefix length when folding the byte index into the level.  This only changes the in-memory ordering used to place keys within a keyring; add, search and read of non-colliding keys are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-74566","epss":0.00165,"percentile":0.05978,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-74566","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74566","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3d9f16c0b643ceac305526b2e2fe25c2c6166926","https://git.kernel.org/stable/c/414bcf37d81ce9b3823aabc06b04c97fdcbe489b","https://git.kernel.org/stable/c/58565eef0f8d861aae92abfb7658458d661cee17","https://git.kernel.org/stable/c/7269df3e7fcfa308e6a456305162f7788747bdbd","https://git.kernel.org/stable/c/7e5397a3fed0dee7779bd084bec3c0584db3c930","https://git.kernel.org/stable/c/abe43c661efb753d5ee35ad8ace4bbb16fa9afd0","https://git.kernel.org/stable/c/bd0f976ef89dce6db458bf75bc2cf51127becc41","https://git.kernel.org/stable/c/f81920917074e3c4ad4fba06fe8c56738d010606"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: make keyring key-chunk byte order agree with keyring_diff_objects()\n\nkeyring_get_key_chunk() loads description bytes into the index chunk low\naddress first, while keyring_diff_objects() numbers the first differing\nbit from the low end and folds the absolute byte index into the level\nwithout removing the inline-prefix offset the level already carries.\nThe two disagree on byte order and bit position, so the array can be\ntold two keys first differ at a bit that does not differ in the chunk\nthe walker uses, letting crafted descriptions collide into one node.\n\nLoad the chunk in the order keyring_diff_objects() assumes and drop the\ninline-prefix length when folding the byte index into the level.  This\nonly changes the in-memory ordering used to place keys within a keyring;\nadd, search and read of non-colliding keys are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-74566","epss":0.00165,"percentile":0.05978,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74566","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74567","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74567","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  keys: fix out-of-bounds read in keyring_get_key_chunk()  For description-level chunks keyring_get_key_chunk() advances the read pointer by level * sizeof(long) past the inline prefix but only bounds-checks the prefix, so a long enough key description is read past its kmemdup(desc, desc_len + 1) allocation.  Compute the full byte offset and bounds-check the description against it before reading.  The walk only reaches a description-level chunk when two keys collide through the hash, x, type and domain_tag chunks, so this is reached from an unprivileged add_key(2) with a crafted pair of same-type keys whose index hashes collide; KASAN reports a slab-out-of-bounds read.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74567","epss":0.00117,"percentile":0.01877,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08541},"relatedVulnerabilities":[{"id":"CVE-2026-74567","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74567","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3a744838453fb9309ce5a5526d3252e211d60152","https://git.kernel.org/stable/c/4c0c26f751e50d3027eacc4d7d0fabc31f1d7e6b","https://git.kernel.org/stable/c/63918731f9ae25b5deb022f118e941e6dddfcef4","https://git.kernel.org/stable/c/79916f40d4ab1b4ae694d8c024fd179454bfe46e","https://git.kernel.org/stable/c/8dba33c1e779d0fb9a2acb31e354cf0fc0229111","https://git.kernel.org/stable/c/d1933e03e8c74a018550c31a393b79c4d95bff40","https://git.kernel.org/stable/c/e5b01998cef8d7f613200230ccaadebe5de9135c","https://git.kernel.org/stable/c/e9417d21a22ad2ec398e78fcf084b717ce92cf2f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: fix out-of-bounds read in keyring_get_key_chunk()\n\nFor description-level chunks keyring_get_key_chunk() advances the read\npointer by level * sizeof(long) past the inline prefix but only\nbounds-checks the prefix, so a long enough key description is read past\nits kmemdup(desc, desc_len + 1) allocation.  Compute the full byte\noffset and bounds-check the description against it before reading.\n\nThe walk only reaches a description-level chunk when two keys collide\nthrough the hash, x, type and domain_tag chunks, so this is reached from\nan unprivileged add_key(2) with a crafted pair of same-type keys whose\nindex hashes collide; KASAN reports a slab-out-of-bounds read.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74567","epss":0.00117,"percentile":0.01877,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74567","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74569","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74569","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()  sip_help_tcp() stores the size change of each NAT-rewritten SIP message in s16 diff and accumulates it in s16 tdiff, but a single message can grow by more than S16_MAX while the packet stays under the 65535 enlarge_skb() limit: nf_nat_sip() rewrites every matching URI, and a long Contact list expands the message by tens of kilobytes. diff then wraps, and \"datalen = datalen + diff - msglen\" yields a huge unsigned datalen, so the next iteration's ct_sip_get_header() reads past the linearized skb tail.  Widen diff, tdiff and the seq_adjust hook to s32. Both are bounded by the 65535 byte packet limit, and the seqadj core is already s32 (nf_ct_seqadj_set() takes s32), so no previously accepted input is rejected.    BUG: KASAN: use-after-free in ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)   Read of size 1 at addr ffff888010800000 by task ksoftirqd/1/25    ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)    sip_help_tcp (net/netfilter/nf_conntrack_sip.c:1694)    nf_confirm (net/netfilter/nf_conntrack_proto.c:183)    nf_hook_slow (net/netfilter/core.c:619)    ip6_output (net/ipv6/ip6_output.c:246)    ip6_forward (net/ipv6/ip6_output.c:690)    ipv6_rcv (net/ipv6/ip6_input.c:351)    __netif_receive_skb_one_core (net/core/dev.c:6212)    process_backlog (net/core/dev.c:6676)    __napi_poll (net/core/dev.c:7735)    net_rx_action (net/core/dev.c:7955)    handle_softirqs (kernel/softirq.c:622)    run_ksoftirqd (kernel/softirq.c:1076)    ...","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74569","epss":0.00388,"percentile":0.32177,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.36472000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-74569","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74569","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1b0843f9e9b9b0b9b4b70d143b67e58163c85b2c","https://git.kernel.org/stable/c/32d4abc8923b0d4046fd63ad6e4917872e44eb6d","https://git.kernel.org/stable/c/63eea41759fd682229c14e0a2205802b46d106f3","https://git.kernel.org/stable/c/c97621a110e386b2dd69e276eb699e1d3cec581d","https://git.kernel.org/stable/c/db3d0e0e5d4bc5ab4fe445b9f413d1b486508ca5","https://git.kernel.org/stable/c/ed1f9be6dc8e2e280b8725e44ccdc6e0cd38640d","https://git.kernel.org/stable/c/ef5e2c6555d2bb52dfe0e4053a8c6193f9d83b64","https://git.kernel.org/stable/c/f74554e67ccf04d1fa71069e8c9afa2717e40716"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()\n\nsip_help_tcp() stores the size change of each NAT-rewritten SIP message\nin s16 diff and accumulates it in s16 tdiff, but a single message can\ngrow by more than S16_MAX while the packet stays under the 65535\nenlarge_skb() limit: nf_nat_sip() rewrites every matching URI, and a long\nContact list expands the message by tens of kilobytes. diff then wraps,\nand \"datalen = datalen + diff - msglen\" yields a huge unsigned datalen,\nso the next iteration's ct_sip_get_header() reads past the linearized skb\ntail.\n\nWiden diff, tdiff and the seq_adjust hook to s32. Both are bounded by the\n65535 byte packet limit, and the seqadj core is already s32\n(nf_ct_seqadj_set() takes s32), so no previously accepted input is\nrejected.\n\n  BUG: KASAN: use-after-free in ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)\n  Read of size 1 at addr ffff888010800000 by task ksoftirqd/1/25\n   ct_sip_get_header (net/netfilter/nf_conntrack_sip.c:464)\n   sip_help_tcp (net/netfilter/nf_conntrack_sip.c:1694)\n   nf_confirm (net/netfilter/nf_conntrack_proto.c:183)\n   nf_hook_slow (net/netfilter/core.c:619)\n   ip6_output (net/ipv6/ip6_output.c:246)\n   ip6_forward (net/ipv6/ip6_output.c:690)\n   ipv6_rcv (net/ipv6/ip6_input.c:351)\n   __netif_receive_skb_one_core (net/core/dev.c:6212)\n   process_backlog (net/core/dev.c:6676)\n   __napi_poll (net/core/dev.c:7735)\n   net_rx_action (net/core/dev.c:7955)\n   handle_softirqs (kernel/softirq.c:622)\n   run_ksoftirqd (kernel/softirq.c:1076)\n   ...","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74569","epss":0.00388,"percentile":0.32177,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74569","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74571","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74571","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: skip global block reserve accounting for rescue mounts  [BUG] Mounting with rescue=ibadroots after corrupting the block group tree root triggers a NULL pointer dereference:    BUG: kernel NULL pointer dereference, address: 0000000000000100   RIP: 0010:btrfs_update_global_block_rsv+0x9d/0x1c0 [btrfs]   Call Trace:    fill_dummy_bgs+0xd4/0x120 [btrfs]    open_ctree+0xc6e/0x1ca0 [btrfs]    btrfs_get_tree+0x50d/0xa40 [btrfs]  The same crash occurs with a corrupted raid stripe tree root, via btrfs_read_block_groups() instead of fill_dummy_bgs().  [CAUSE] With rescue=ibadroots, btrfs_read_roots() allows the mount to continue when either root cannot be read, leaving the corresponding root pointer NULL while its on-disk feature bit remains set.  btrfs_update_global_block_rsv() then dereferences the missing root based on the feature bit alone.  [FIX] Rescue mounts are fully read-only and cannot start transactions, so the global reserve is never consumed. Under btrfs_is_full_ro(), mark the reserve as full and return before performing the accounting.  And since we need to check if the fs is mount fully RO, export fs_is_full_ro() as btrfs_is_full_ro(), and move it to fs.h.  [ Squash the fs_is_full_ro() export commit into this one. ]","cvss":[],"epss":[{"cve":"CVE-2026-74571","epss":0.00145,"percentile":0.04131,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0725},"relatedVulnerabilities":[{"id":"CVE-2026-74571","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74571","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/076349e4c8d11f6b58c4549976a513b2b4dc6df2","https://git.kernel.org/stable/c/51a0e8399858621442807a26057bcd1cd3ced046"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: skip global block reserve accounting for rescue mounts\n\n[BUG]\nMounting with rescue=ibadroots after corrupting the block group tree\nroot triggers a NULL pointer dereference:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000100\n  RIP: 0010:btrfs_update_global_block_rsv+0x9d/0x1c0 [btrfs]\n  Call Trace:\n   fill_dummy_bgs+0xd4/0x120 [btrfs]\n   open_ctree+0xc6e/0x1ca0 [btrfs]\n   btrfs_get_tree+0x50d/0xa40 [btrfs]\n\nThe same crash occurs with a corrupted raid stripe tree root, via\nbtrfs_read_block_groups() instead of fill_dummy_bgs().\n\n[CAUSE]\nWith rescue=ibadroots, btrfs_read_roots() allows the mount to continue\nwhen either root cannot be read, leaving the corresponding root pointer\nNULL while its on-disk feature bit remains set.\n\nbtrfs_update_global_block_rsv() then dereferences the missing root based\non the feature bit alone.\n\n[FIX]\nRescue mounts are fully read-only and cannot start transactions, so the\nglobal reserve is never consumed. Under btrfs_is_full_ro(), mark the\nreserve as full and return before performing the accounting.\n\nAnd since we need to check if the fs is mount fully RO, export\nfs_is_full_ro() as btrfs_is_full_ro(), and move it to fs.h.\n\n[ Squash the fs_is_full_ro() export commit into this one. ]","cvss":[],"epss":[{"cve":"CVE-2026-74571","epss":0.00145,"percentile":0.04131,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74571","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74575","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74575","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  thunderbolt: Prevent XDomain delayed work use-after-free on disconnect  tb_xdp_handle_request() runs on system_wq and queues xd->state_work via queue_delayed_work() in three request handlers: PROPERTIES_CHANGED_REQUEST, UUID_REQUEST (via start_handshake), and LINK_STATE_CHANGE_REQUEST.  Similarly, update_xdomain() queues xd->properties_changed_work when local properties change.  Concurrently, tb_xdomain_remove() calls stop_handshake() which does cancel_delayed_work_sync() on both delayed works.  Later, tb_xdomain_unregister() calls device_unregister() which eventually frees the xdomain.  Since commit 559c1e1e0134 (\"thunderbolt: Run tb_xdp_handle_request() in system workqueue\") moved the request handler off tb->wq, the handler and the remove path are no longer serialized.  If queue_delayed_work() executes after cancel_delayed_work_sync() but before the xdomain is freed, the delayed work fires on a freed object.  Add xd->removing that tb_xdomain_remove() sets under xd->lock before calling stop_handshake().  Each external queue site holds the same lock and checks removing before calling queue_delayed_work().  This provides the mutual exclusion needed: either the queue site acquires the lock first and queues work that the subsequent cancel will see, or the remove path acquires the lock first and the queue site observes removing == true and skips the queue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74575","epss":0.00238,"percentile":0.1474,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.19397000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74575","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74575","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2aa2cde2cc79a79d8ea4a15be9f4a67fc528ae91","https://git.kernel.org/stable/c/2c5d2d3c3f70cde2565d7b279b544893a2035842","https://git.kernel.org/stable/c/33c0ee18cf8665c974b00f4e0ba769fbc07efe10","https://git.kernel.org/stable/c/54a62153c765cd24239cde1f2633f2a2fd005368","https://git.kernel.org/stable/c/91b40862a02000f490b63f1d315be3ee31e83871","https://git.kernel.org/stable/c/cfbd2dba3d862c9be8c92bea2a357d9ed828a54a","https://git.kernel.org/stable/c/d4fa0d544c04dea636bf821ff5582cd7d63e2c34","https://git.kernel.org/stable/c/dc11d5118f9da6ea28487ffe055de5a0d0734125"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Prevent XDomain delayed work use-after-free on disconnect\n\ntb_xdp_handle_request() runs on system_wq and queues\nxd->state_work via queue_delayed_work() in three request handlers:\nPROPERTIES_CHANGED_REQUEST, UUID_REQUEST (via start_handshake),\nand LINK_STATE_CHANGE_REQUEST.  Similarly, update_xdomain() queues\nxd->properties_changed_work when local properties change.\n\nConcurrently, tb_xdomain_remove() calls stop_handshake() which does\ncancel_delayed_work_sync() on both delayed works.  Later,\ntb_xdomain_unregister() calls device_unregister() which eventually\nfrees the xdomain.  Since commit 559c1e1e0134 (\"thunderbolt: Run\ntb_xdp_handle_request() in system workqueue\") moved the request\nhandler off tb->wq, the handler and the remove path are no longer\nserialized.  If queue_delayed_work() executes after\ncancel_delayed_work_sync() but before the xdomain is freed, the\ndelayed work fires on a freed object.\n\nAdd xd->removing that tb_xdomain_remove() sets under xd->lock\nbefore calling stop_handshake().  Each external queue site holds\nthe same lock and checks removing before calling\nqueue_delayed_work().  This provides the mutual exclusion needed:\neither the queue site acquires the lock first and queues work that\nthe subsequent cancel will see, or the remove path acquires the\nlock first and the queue site observes removing == true and skips\nthe queue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74575","epss":0.00238,"percentile":0.1474,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74575","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74577","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74577","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: mpls: initialize rtm_tos in mpls_getroute()  mpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE request by filling a struct rtmsg allocated from an skb whose data area is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every field of the header except rtm_tos:  \tr = nlmsg_data(nlh); \tr->rtm_family\t = AF_MPLS; \tr->rtm_dst_len\t= 20; \tr->rtm_src_len\t= 0; \tr->rtm_table\t= RT_TABLE_MAIN; \tr->rtm_type\t= RTN_UNICAST; \tr->rtm_scope\t= RT_SCOPE_UNIVERSE; \tr->rtm_protocol = rt->rt_protocol; \tr->rtm_flags\t= 0;  struct rtmsg has no padding, so the one uninitialised byte rtm_tos (offset 3) is copied straight to user space on recvmsg(), leaking a byte of uninitialised heap memory. This is in contrast to mpls_dump_route(), which fills the very same header and does set rtm_tos = 0.  Initialize rtm_tos to 0, matching mpls_dump_route().  Reproduced with KMSAN by adding an MPLS route and issuing a non-RTM_F_FIB_MATCH RTM_GETROUTE for its label:    BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0    _copy_to_iter+0x36c/0x33f0    __skb_datagram_iter+0x196/0x12c0    skb_copy_datagram_iter+0x5b/0x210    netlink_recvmsg+0x37b/0xef0    ...   Uninit was created at:    __alloc_skb+0x8ca/0x10e0    mpls_getroute+0x1280/0x3a40    rtnetlink_rcv_msg+0x1138/0x15a0    ...   Byte 19 of 64 is uninitialized  (byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)","cvss":[],"epss":[{"cve":"CVE-2026-74577","epss":0.00165,"percentile":0.06046,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-74577","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74577","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1fea5ff0eb4aa7e951bb3d380248566c473aa377","https://git.kernel.org/stable/c/248718fd88b146d8bdc7610ecd1eb4cd16e0b5a1","https://git.kernel.org/stable/c/295dd295e2137e10e9a5b1891d97e0f08de76f03","https://git.kernel.org/stable/c/2dc2fffc704a4365cae1aae078ba62223aaeff93","https://git.kernel.org/stable/c/466b474a8deb0c93b5280c6d261e5eda6482eca7","https://git.kernel.org/stable/c/95651461cf77cc6590fa08c87667717e5dcfa55d","https://git.kernel.org/stable/c/a5cdd2407dd890f741f59b8367e4c6c101cce154","https://git.kernel.org/stable/c/ba56f88aab18d982f2a21f11390f4d8a8897782a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mpls: initialize rtm_tos in mpls_getroute()\n\nmpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE\nrequest by filling a struct rtmsg allocated from an skb whose data\narea is not zeroed (alloc_skb(NLMSG_GOODSIZE, ...)). It sets every\nfield of the header except rtm_tos:\n\n\tr = nlmsg_data(nlh);\n\tr->rtm_family\t = AF_MPLS;\n\tr->rtm_dst_len\t= 20;\n\tr->rtm_src_len\t= 0;\n\tr->rtm_table\t= RT_TABLE_MAIN;\n\tr->rtm_type\t= RTN_UNICAST;\n\tr->rtm_scope\t= RT_SCOPE_UNIVERSE;\n\tr->rtm_protocol = rt->rt_protocol;\n\tr->rtm_flags\t= 0;\n\nstruct rtmsg has no padding, so the one uninitialised byte rtm_tos\n(offset 3) is copied straight to user space on recvmsg(), leaking a\nbyte of uninitialised heap memory. This is in contrast to\nmpls_dump_route(), which fills the very same header and does set\nrtm_tos = 0.\n\nInitialize rtm_tos to 0, matching mpls_dump_route().\n\nReproduced with KMSAN by adding an MPLS route and issuing a\nnon-RTM_F_FIB_MATCH RTM_GETROUTE for its label:\n\n  BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x36c/0x33f0\n   _copy_to_iter+0x36c/0x33f0\n   __skb_datagram_iter+0x196/0x12c0\n   skb_copy_datagram_iter+0x5b/0x210\n   netlink_recvmsg+0x37b/0xef0\n   ...\n  Uninit was created at:\n   __alloc_skb+0x8ca/0x10e0\n   mpls_getroute+0x1280/0x3a40\n   rtnetlink_rcv_msg+0x1138/0x15a0\n   ...\n  Byte 19 of 64 is uninitialized\n\n(byte 19 = nlmsghdr(16) + rtmsg offset 3 = rtm_tos)","cvss":[],"epss":[{"cve":"CVE-2026-74577","epss":0.00165,"percentile":0.06046,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74577","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74579","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74579","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_payload: fix mask build for partial field offload  nft_payload_offload_mask() builds the offload match mask for a payload expression that covers only part of a header field.  For a partial IPv6 address match (field_len = 16, priv_len = 1) that shift is 1 << 120, which is undefined on the 32-bit int operand.  It also trims only one word, so the remaining words stay 0xffffffff (and when priv_len is a multiple of 4 the trim is skipped entirely), leaving the mask covering more bytes than the rule matches.    UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20   shift exponent 120 is too large for 32-bit type 'int'   ...  The match is byte-granular and struct nft_data is zero-initialised, so the correct mask is simply the first priv_len bytes set to 0xff. Set those bytes directly and drop the word/shift trimming; this removes the undefined shift and no longer over-masks the trailing bytes.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74579","epss":0.0012,"percentile":0.02076,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0876},"relatedVulnerabilities":[{"id":"CVE-2026-74579","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74579","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/16b553c46e347bc9de9946c4960654d5884a86de","https://git.kernel.org/stable/c/363c3a84a946d53e5e121c9f47c7c2b7d228c46b","https://git.kernel.org/stable/c/39e88f28fb32bf02bd4b525c24c842c9cff5663d","https://git.kernel.org/stable/c/3ee7b3f813b11f28cd6efdf7f24d64b5a7fd4dc7","https://git.kernel.org/stable/c/630295d5bba1d0e0f494cc459452eb0a0058c545","https://git.kernel.org/stable/c/8720df4504e0ed1781a702f65251bd47b3534d5e","https://git.kernel.org/stable/c/a375d8ace807767f29f276b681b6324c74929b1d","https://git.kernel.org/stable/c/b19b5d2e042c294e2cc1c908dc598f9d64015396"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_payload: fix mask build for partial field offload\n\nnft_payload_offload_mask() builds the offload match mask for a payload\nexpression that covers only part of a header field.  For a partial IPv6\naddress match (field_len = 16, priv_len = 1) that shift is 1 << 120, which\nis undefined on the 32-bit int operand.  It also trims only one word, so\nthe remaining words stay 0xffffffff (and when priv_len is a multiple of 4\nthe trim is skipped entirely), leaving the mask covering more bytes than\nthe rule matches.\n\n  UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20\n  shift exponent 120 is too large for 32-bit type 'int'\n  ...\n\nThe match is byte-granular and struct nft_data is zero-initialised, so the\ncorrect mask is simply the first priv_len bytes set to 0xff. Set those\nbytes directly and drop the word/shift trimming; this removes the undefined\nshift and no longer over-masks the trailing bytes.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74579","epss":0.0012,"percentile":0.02076,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74579","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74580","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74580","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vhost: reset the vring metadata cache on vring reconfiguration  vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring metadata region, and iotlb_access_ok() returns early on a cache hit, taking the hit as proof that the region has already been validated:  \tif (vhost_vq_meta_fetch(vq, addr, len, type)) \t\treturn true;  The cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on device IOTLB (re)initialisation and on vq reset, but not when VHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when VHOST_SET_VRING_NUM changes the region sizes.  With a device IOTLB attached both ioctls are accepted while the vq is live, and neither validates the addresses at ioctl time: vq_access_ok() and vq_log_used_access_ok() return true early because the addresses are GIOVAs, deferring validation to prefetch time.  Once the cache has been populated that deferred validation no longer runs -- vq_meta_prefetch() hits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps translating through the old mapping as  \tmap->addr + addr - map->start  for an address the mapping no longer covers.  vhost_copy_to_user() and vhost_copy_from_user() consume the result with __copy_to_user() and __copy_from_user(), which do not check it either, so a subsequent used ring update or descriptor fetch accesses memory outside the region the IOTLB actually maps.  Reset the metadata cache whenever the vring is reconfigured, so the new addresses are pushed back through iotlb_access_ok()'s slow path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74580","epss":0.00121,"percentile":0.02163,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09861500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74580","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74580","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/13fa6f32a56a386a82bd7451644c494beed034af","https://git.kernel.org/stable/c/5224bd37e37d36076a550d99b2aebba33939fd95","https://git.kernel.org/stable/c/54617e9119be2eb728ecdd8d977b99c99d4c498a","https://git.kernel.org/stable/c/6fa3e9b1fe856259555a7e22f3f3082e7827fd9b","https://git.kernel.org/stable/c/b70ebe0bba254e093dd5fd4c0c170941ce83eb85","https://git.kernel.org/stable/c/cf363a7a02ce132ef1f58084fdb13e1a3b7da7e7","https://git.kernel.org/stable/c/de845981da67a6b049080c87e605130b0c30adc5","https://git.kernel.org/stable/c/f1e21108e3ddfcce62f6cad4ebd7b5674543c9e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost: reset the vring metadata cache on vring reconfiguration\n\nvq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring\nmetadata region, and iotlb_access_ok() returns early on a cache hit,\ntaking the hit as proof that the region has already been validated:\n\n\tif (vhost_vq_meta_fetch(vq, addr, len, type))\n\t\treturn true;\n\nThe cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on\ndevice IOTLB (re)initialisation and on vq reset, but not when\nVHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when\nVHOST_SET_VRING_NUM changes the region sizes.\n\nWith a device IOTLB attached both ioctls are accepted while the vq is\nlive, and neither validates the addresses at ioctl time: vq_access_ok()\nand vq_log_used_access_ok() return true early because the addresses are\nGIOVAs, deferring validation to prefetch time.  Once the cache has been\npopulated that deferred validation no longer runs -- vq_meta_prefetch()\nhits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps\ntranslating through the old mapping as\n\n\tmap->addr + addr - map->start\n\nfor an address the mapping no longer covers.  vhost_copy_to_user() and\nvhost_copy_from_user() consume the result with __copy_to_user() and\n__copy_from_user(), which do not check it either, so a subsequent used\nring update or descriptor fetch accesses memory outside the region the\nIOTLB actually maps.\n\nReset the metadata cache whenever the vring is reconfigured, so the new\naddresses are pushed back through iotlb_access_ok()'s slow path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74580","epss":0.00121,"percentile":0.02163,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74580","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74581","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74581","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ipv6: clear suppressed fib6 rule result  fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info.  If no later rule supplies a replacement, fib6_rule_lookup() still sees res.rt6 and returns that stale dst to its caller. A suppressing rule can therefore leak a released route back to rt6_lookup(), and the next put hits rcuref_put_slowpath() from dst_release().  Clear res->rt6 when suppressing the route so suppressed lookups fall through to the null dst instead of reusing the released one.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74581","epss":0.00399,"percentile":0.33347,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37505999999999995},"relatedVulnerabilities":[{"id":"CVE-2026-74581","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74581","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/354db6243eca59e9d187ffbf8b7955b044ce84dc","https://git.kernel.org/stable/c/5d29b286c9de0b309e94b9ed083aa1a2f429434f","https://git.kernel.org/stable/c/6aea62e433fe1b586202a5fee8b5807ce635e1d7","https://git.kernel.org/stable/c/6d98c70fe0ba8c7708bfd5b2a5174d2086775daa","https://git.kernel.org/stable/c/90c57310e266eb94e4a80d6b15a9ca131d2e82cb","https://git.kernel.org/stable/c/9bad152c42b37499162367fe47867411e62fffa3","https://git.kernel.org/stable/c/a341c091ca0bfae377747b1b59a3bd8ebe18a937","https://git.kernel.org/stable/c/dc3ab04220667f254f4348572b2a0b3febff89fb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: clear suppressed fib6 rule result\n\nfib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),\nbut leaves res->rt6 pointing at the released rt6_info.\n\nIf no later rule supplies a replacement, fib6_rule_lookup() still sees\nres.rt6 and returns that stale dst to its caller. A suppressing rule can\ntherefore leak a released route back to rt6_lookup(), and the next put\nhits rcuref_put_slowpath() from dst_release().\n\nClear res->rt6 when suppressing the route so suppressed lookups fall\nthrough to the null dst instead of reusing the released one.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74581","epss":0.00399,"percentile":0.33347,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74581","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74582","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74582","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  packet: use consistent hard_header_len in non-ring send paths  packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding device type changes.  For SOCK_RAW, packet_snd() can save a larger value in reserve and later allocate headroom using a smaller value. Moving skb->data back by reserve then places it before skb->head, and the following copy from userspace can attempt an out-of-bounds write.  packet_sendmsg_spkt() has the same issue because it calculates its reservation and header offset from separate reads before dropping the RCU read lock to allocate the skb.  Add LL_RESERVED_SPACE_EX() for callers that already saved a header length. Read hard_header_len once in packet_snd() and use it for allocation and construction. In packet_sendmsg_spkt(), preserve the allocation-time value through the device lookup retry.  The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74582","epss":0.0012,"percentile":0.02094,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74582","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74582","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/03390aa32e669cc4ecd7d34108e2e1afc13d689d","https://git.kernel.org/stable/c/142e287b3a25cfe909215177c23243e7fc5ae2b1","https://git.kernel.org/stable/c/5bb10753d428aadfc356a2bfe9acea09c82a62ec","https://git.kernel.org/stable/c/78a47127e33c340bc6d38dcc4552a094b4f5cc77","https://git.kernel.org/stable/c/9052756290962ffb9a661bcf319e92dedaaedfed","https://git.kernel.org/stable/c/91f041451f967cd87ed722a8f43c0b767a64f1a0","https://git.kernel.org/stable/c/b06b6fce6d7deaf7238e09b48ce3b1125ff41acd","https://git.kernel.org/stable/c/bcd4df60ac9481b1ceffdfe5ec38fe51dcaae812"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npacket: use consistent hard_header_len in non-ring send paths\n\npacket_snd() reads dev->hard_header_len multiple times while allocating\nand constructing an skb. Device reconfiguration can change this value\nconcurrently, for example through bonding device type changes.\n\nFor SOCK_RAW, packet_snd() can save a larger value in reserve and later\nallocate headroom using a smaller value. Moving skb->data back by reserve\nthen places it before skb->head, and the following copy from userspace can\nattempt an out-of-bounds write.\n\npacket_sendmsg_spkt() has the same issue because it calculates its\nreservation and header offset from separate reads before dropping the RCU\nread lock to allocate the skb.\n\nAdd LL_RESERVED_SPACE_EX() for callers that already saved a header length.\nRead hard_header_len once in packet_snd() and use it for allocation and\nconstruction. In packet_sendmsg_spkt(), preserve the allocation-time value\nthrough the device lookup retry.\n\nThe separate SOCK_DGRAM consistency problem between hard_header_len and\nheader_ops->create is not addressed here.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74582","epss":0.0012,"percentile":0.02094,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74582","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74583","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: cls_route: fix fastmap use-after-free on filter  The route4 classifier maintains a 16-slot fastmap cache that stores raw struct route4_filter pointers indexed by (id, iif). The reader (route4_classify) populates this cache via route4_set_fastmap() for every classified packet that hits a filter. The writer (route4_delete, route4_change) clears the cache via route4_reset_fastmap() before RCU-deferred kfree of the filter.  This creates a UAF race:  1. Reader walks the RCU-protected bucket chain, finds filter f  2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work()  3. Reader calls route4_set_fastmap() and writes f into the cache     *after* the writer's reset, caching a pointer about to be freed  4. After the RCU grace period, kfree(f) executes  5. Next classified packet on the same (id, iif) tuple hits the stale     fastmap entry and reads f->res from freed memory  Reproduced with an mdelay(100) accelerator in route4_set_fastmap() and a concurrent add/delete stress test (provided by both zdi and Santosh). Both triggered KASAN slab-use-after-free reports in the route4 fastmap paths.  Fix: Introduce a per-filter boolean dying flag to suppress stale fastmap republishing by in-flight readers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74583","epss":0.00117,"percentile":0.0187,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.089505},"relatedVulnerabilities":[{"id":"CVE-2026-74583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74583","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0e7a8cf8895b06d07c7311f028eba16ad742b9bc","https://git.kernel.org/stable/c/47d7f7051253bdc02b1d245d87e38f16d31a74df","https://git.kernel.org/stable/c/5ec9001be6d0eb527251125632ec8fe88278897f","https://git.kernel.org/stable/c/7897198b26445b4009a057bda1986b94a99e5d5f","https://git.kernel.org/stable/c/820f083c294ad6d319c02a7d43294f2ed2565139","https://git.kernel.org/stable/c/a17f636c9330eac879822ce29f998e5abd1b72c1","https://git.kernel.org/stable/c/ae9aff87025219005a2d16b4fe83d6f24643e50d","https://git.kernel.org/stable/c/b969984b2bdc85d721ce4047cd270cd37ec705a2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_route: fix fastmap use-after-free on filter\n\nThe route4 classifier maintains a 16-slot fastmap cache that stores raw\nstruct route4_filter pointers indexed by (id, iif). The reader\n(route4_classify) populates this cache via route4_set_fastmap() for every\nclassified packet that hits a filter. The writer (route4_delete,\nroute4_change) clears the cache via route4_reset_fastmap() before\nRCU-deferred kfree of the filter.\n\nThis creates a UAF race:\n 1. Reader walks the RCU-protected bucket chain, finds filter f\n 2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work()\n 3. Reader calls route4_set_fastmap() and writes f into the cache\n    *after* the writer's reset, caching a pointer about to be freed\n 4. After the RCU grace period, kfree(f) executes\n 5. Next classified packet on the same (id, iif) tuple hits the stale\n    fastmap entry and reads f->res from freed memory\n\nReproduced with an mdelay(100) accelerator in route4_set_fastmap() and a\nconcurrent add/delete stress test (provided by both zdi and Santosh).\nBoth triggered KASAN slab-use-after-free reports in the route4 fastmap\npaths.\n\nFix:\nIntroduce a per-filter boolean dying flag to suppress stale fastmap\nrepublishing by in-flight readers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74583","epss":0.00117,"percentile":0.0187,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74583","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74585","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74585","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  thunderbolt: Bound the DROM dual link port number before indexing sw->ports  tb_drom_parse_entry_port() validates the device-supplied header->index against sw->config.max_port_number before indexing sw->ports[], but the sibling field entry->dual_link_port_nr -- a 6-bit value also read from the DROM -- indexes the same array with no such check. A malicious or malformed Thunderbolt device can set dual_link_port_nr beyond the allocated sw->ports[] (max_port_number + 1 entries), producing an out-of-bounds tb_port pointer that is stored and later dereferenced.  Reject a port entry whose dual_link_port_nr exceeds max_port_number, the same bound already applied to header->index.","cvss":[],"epss":[{"cve":"CVE-2026-74585","epss":0.00177,"percentile":0.07331,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74585","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74585","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3d3c212b70633332ab71672aa2bc6af257d2ec83","https://git.kernel.org/stable/c/40d2ffb74094cf36edbe05855566a4c58b6ce808","https://git.kernel.org/stable/c/50f0c8dd8c3390f851cfb97ca13116f9ee6469d1","https://git.kernel.org/stable/c/6c892ed9f4129ae40ef0f92e1bb31aa0b0ddc72c","https://git.kernel.org/stable/c/b98e1e28bd95b0fa33164eec1e763d26c7058b39","https://git.kernel.org/stable/c/d6764992f17b23d91ff93ce905ab53c2aa7191f0","https://git.kernel.org/stable/c/f28066057134aa9294caa597b670daf505ad9dce","https://git.kernel.org/stable/c/f32c3a9a77cfb50934a60b05d5407649af062535"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Bound the DROM dual link port number before indexing sw->ports\n\ntb_drom_parse_entry_port() validates the device-supplied header->index\nagainst sw->config.max_port_number before indexing sw->ports[], but the\nsibling field entry->dual_link_port_nr -- a 6-bit value also read from\nthe DROM -- indexes the same array with no such check. A malicious or\nmalformed Thunderbolt device can set dual_link_port_nr beyond the\nallocated sw->ports[] (max_port_number + 1 entries), producing an\nout-of-bounds tb_port pointer that is stored and later dereferenced.\n\nReject a port entry whose dual_link_port_nr exceeds max_port_number,\nthe same bound already applied to header->index.","cvss":[],"epss":[{"cve":"CVE-2026-74585","epss":0.00177,"percentile":0.07331,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74585","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74586","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74586","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: clear new_transport when removing a peer  sctp_process_asconf_param() stores a newly added peer transport in asoc->new_transport. After all parameters in the ASCONF chunk have been processed, sctp_sf_do_asconf() uses this pointer to send a HEARTBEAT to the new transport.  An authenticated ASCONF from a remote SCTP peer can add a transport and remove it again with a wildcard DEL-IP parameter in the same chunk. The wildcard deletion preserves the transport on which the ASCONF arrived, but removes the newly added transport through sctp_assoc_del_nonprimary_peers(). The removal does not clear asoc->new_transport, leaving it pointing to the removed transport.  sctp_sf_do_asconf() then creates a HEARTBEAT whose chunk->transport points to the removed transport without holding a transport reference. During local address replacement, src_out_of_asoc_ok keeps this HEARTBEAT on control_chunk_list. After the transport is freed by RCU, a successful ASCONF_ACK for the replacement address releases the queued HEARTBEAT and sctp_outq_select_transport() reads the freed transport's state.  The issue was found during a static audit of SCTP objects. With an authenticated peer, the reproducer triggered the same KASAN report in 2 of 2 unpatched runs on a KASAN-enabled netdev/main kernel:    BUG: KASAN: slab-use-after-free in sctp_outq_select_transport   Read of size 4 at addr ffff88800b9bd95c by task python3/197    Call Trace:    sctp_outq_select_transport+0x549/0x8b0 [sctp]    sctp_outq_flush+0x306/0x2c60 [sctp]    sctp_transport_immediate_rtx+0xaf/0x260 [sctp]    sctp_process_asconf_ack+0xa48/0xf70 [sctp]    Allocated by task 197:    sctp_transport_new+0x68/0x650 [sctp]    sctp_assoc_add_peer+0x258/0x12a0 [sctp]    sctp_process_asconf+0x5e9/0x1090 [sctp]    Last potentially related work creation:    __call_rcu_common.constprop.0+0x77/0xb70    sctp_assoc_del_nonprimary_peers+0x7c/0xd0 [sctp]    sctp_process_asconf+0xd9c/0x1090 [sctp]  The first invalid access was a four-byte read of transport->state at net/sctp/outqueue.c:833. The same reproducer completed the full authenticated ASCONF and local-address replacement sequence with this change without a KASAN report or oops.  Clear new_transport when its peer is removed, before it can be used to create the HEARTBEAT.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74586","epss":0.005,"percentile":0.41183,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47000000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74586","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74586","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/163847552a571bd55094291f4ffcdc1de0f14a7b","https://git.kernel.org/stable/c/291accf36febce751021888de5f15090f4875b56","https://git.kernel.org/stable/c/31efa656cf6aface26e88f038c14f22ee6ca1500","https://git.kernel.org/stable/c/3b539b317cd052236fed0350364ff1268996ba46","https://git.kernel.org/stable/c/beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3","https://git.kernel.org/stable/c/c0f973bb5118dd1b146cda3fcc8af6f6057befec","https://git.kernel.org/stable/c/ca33df36aa0143a1d04f57d2086020c12e7eddb7","https://git.kernel.org/stable/c/db9d8e3b670f841755bc2018f178472dc6064d27"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: clear new_transport when removing a peer\n\nsctp_process_asconf_param() stores a newly added peer transport in\nasoc->new_transport. After all parameters in the ASCONF chunk have been\nprocessed, sctp_sf_do_asconf() uses this pointer to send a HEARTBEAT to the\nnew transport.\n\nAn authenticated ASCONF from a remote SCTP peer can add a transport and\nremove it again with a wildcard DEL-IP parameter in the same chunk. The\nwildcard deletion preserves the transport on which the ASCONF arrived, but\nremoves the newly added transport through\nsctp_assoc_del_nonprimary_peers(). The removal does not clear\nasoc->new_transport, leaving it pointing to the removed transport.\n\nsctp_sf_do_asconf() then creates a HEARTBEAT whose chunk->transport points\nto the removed transport without holding a transport reference. During\nlocal address replacement, src_out_of_asoc_ok keeps this HEARTBEAT on\ncontrol_chunk_list. After the transport is freed by RCU, a successful\nASCONF_ACK for the replacement address releases the queued HEARTBEAT and\nsctp_outq_select_transport() reads the freed transport's state.\n\nThe issue was found during a static audit of SCTP objects. With an\nauthenticated peer, the reproducer triggered the same KASAN report in 2\nof 2 unpatched runs on a KASAN-enabled netdev/main kernel:\n\n  BUG: KASAN: slab-use-after-free in sctp_outq_select_transport\n  Read of size 4 at addr ffff88800b9bd95c by task python3/197\n\n  Call Trace:\n   sctp_outq_select_transport+0x549/0x8b0 [sctp]\n   sctp_outq_flush+0x306/0x2c60 [sctp]\n   sctp_transport_immediate_rtx+0xaf/0x260 [sctp]\n   sctp_process_asconf_ack+0xa48/0xf70 [sctp]\n\n  Allocated by task 197:\n   sctp_transport_new+0x68/0x650 [sctp]\n   sctp_assoc_add_peer+0x258/0x12a0 [sctp]\n   sctp_process_asconf+0x5e9/0x1090 [sctp]\n\n  Last potentially related work creation:\n   __call_rcu_common.constprop.0+0x77/0xb70\n   sctp_assoc_del_nonprimary_peers+0x7c/0xd0 [sctp]\n   sctp_process_asconf+0xd9c/0x1090 [sctp]\n\nThe first invalid access was a four-byte read of transport->state at\nnet/sctp/outqueue.c:833. The same reproducer completed the full\nauthenticated ASCONF and local-address replacement sequence with this\nchange without a KASAN report or oops.\n\nClear new_transport when its peer is removed, before it can be used to\ncreate the HEARTBEAT.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74586","epss":0.005,"percentile":0.41183,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74586","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74587","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74587","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: fix use-after-free of cached ASCONF chunk  addip_last_asconf caches the outstanding outbound ASCONF chunk. The normal ASCONF-ACK completion path releases the chunk and clears the pointer.  However, sctp_asconf_queue_teardown() releases the cached chunk without clearing addip_last_asconf. During peer restart handling, sctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes sctp_asconf_queue_teardown() while the association remains alive and leaves the pointer dangling.  A delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(), which accesses the stale chunk and passes it to sctp_process_asconf_ack(), causing a use-after-free and a second release.  Clearing the pointer exposes a race with T4 expiry. Peer restart handling queues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses timer_delete(), which does not wait for a callback already running on another CPU. Such a callback can reach sctp_sf_t4_timer_expire() after the purge and dereference NULL.  Clear addip_last_asconf after releasing the cached chunk, and make sctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding ASCONF remains.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74587","epss":0.005,"percentile":0.41183,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47000000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74587","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74587","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/07daf4f9750104960a1d60831b2353c0d41f35fb","https://git.kernel.org/stable/c/10459b03e2d9ee12435e96f587de4d4cacdbf435","https://git.kernel.org/stable/c/179676f0166230c80053a392303485b37c93dd33","https://git.kernel.org/stable/c/618b5c6d049896fcfabb91afc072954c92cb2693","https://git.kernel.org/stable/c/8c283e7b56adce00193837f3311b06662466fb21","https://git.kernel.org/stable/c/d949992bc3f00027a2c755e860a11950c75f6073","https://git.kernel.org/stable/c/dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d","https://git.kernel.org/stable/c/e1bb114e09372fd6e03387ced9ef566da336ed6c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix use-after-free of cached ASCONF chunk\n\naddip_last_asconf caches the outstanding outbound ASCONF chunk. The normal\nASCONF-ACK completion path releases the chunk and clears the pointer.\n\nHowever, sctp_asconf_queue_teardown() releases the cached chunk without\nclearing addip_last_asconf. During peer restart handling,\nsctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes\nsctp_asconf_queue_teardown() while the association remains alive and leaves\nthe pointer dangling.\n\nA delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(),\nwhich accesses the stale chunk and passes it to sctp_process_asconf_ack(),\ncausing a use-after-free and a second release.\n\nClearing the pointer exposes a race with T4 expiry. Peer restart handling\nqueues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses\ntimer_delete(), which does not wait for a callback already running on\nanother CPU. Such a callback can reach sctp_sf_t4_timer_expire() after\nthe purge and dereference NULL.\n\nClear addip_last_asconf after releasing the cached chunk, and make\nsctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding\nASCONF remains.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74587","epss":0.005,"percentile":0.41183,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74587","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74588","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74588","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: keep chunk->transport in step with the list it is queued on  __sctp_outq_flush_rtx() moves a gap-acked chunk onto another transport's transmitted list without updating chunk->transport:  \tif (chunk->tsn_gap_acked) { \t\tlist_move_tail(&chunk->transmitted_list, \t\t\t       &transport->transmitted); \t\tcontinue; \t}  The chunk then sits on a live transport's list while chunk->transport still names a different one.  If that transport is removed - sctp_assoc_rm_peer() from an ASCONF Delete-IP - sctp_transport_free() RCU-frees it and the chunk is left with a dangling pointer.  sctp_assoc_rm_peer() scrubs peer->transmitted and asoc->outqueue.out_chunk_list, but the chunk is on neither.  The pointer is not followed while tsn_gap_acked is set.  A SACK that reneges on the TSN clears the flag, and the next SACK reaches  \ttchunk->transport->flight_size -= sctp_data_size(tchunk);  inside the freed transport.  KASAN reports a slab-use-after-free read in sctp_check_transmitted(), freed from sctp_assoc_rm_peer().  Both the removal and the SACKs come from the association peer.  Set chunk->transport at the move.  The ordinary resend path needs nothing: it reaches its list_move_tail() only after sctp_packet_append_chunk() returned SCTP_XMIT_OK, and __sctp_packet_append_chunk() has rebound the chunk by then.  Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74588","epss":0.005,"percentile":0.41182,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47000000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74588","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74588","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1adf929121e13e0b19200bb9fef715b918d483fe","https://git.kernel.org/stable/c/2b3b5eec8b2c30ee237e3c31a6a38de9c39d804d","https://git.kernel.org/stable/c/5ccf35ef0ed6059cdf8b1f4606a6584d5b67166b","https://git.kernel.org/stable/c/6575fb17230814b48b471727c8410c0aadff9274","https://git.kernel.org/stable/c/6b9e2ea2057113f3393990ba646d2d97c719a80d","https://git.kernel.org/stable/c/874a7c2b5e184f06134fdfde27e9ce9271bafe58","https://git.kernel.org/stable/c/9f2cf069a9a72a2d6b97ca8b4c70e714aac99749","https://git.kernel.org/stable/c/e2e7c1de0e226ca1b7fea2de57a6c9bca408709b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: keep chunk->transport in step with the list it is queued on\n\n__sctp_outq_flush_rtx() moves a gap-acked chunk onto another transport's\ntransmitted list without updating chunk->transport:\n\n\tif (chunk->tsn_gap_acked) {\n\t\tlist_move_tail(&chunk->transmitted_list,\n\t\t\t       &transport->transmitted);\n\t\tcontinue;\n\t}\n\nThe chunk then sits on a live transport's list while chunk->transport still\nnames a different one.  If that transport is removed - sctp_assoc_rm_peer()\nfrom an ASCONF Delete-IP - sctp_transport_free() RCU-frees it and the chunk\nis left with a dangling pointer.  sctp_assoc_rm_peer() scrubs\npeer->transmitted and asoc->outqueue.out_chunk_list, but the chunk is on\nneither.\n\nThe pointer is not followed while tsn_gap_acked is set.  A SACK that\nreneges on the TSN clears the flag, and the next SACK reaches\n\n\ttchunk->transport->flight_size -= sctp_data_size(tchunk);\n\ninside the freed transport.  KASAN reports a slab-use-after-free read in\nsctp_check_transmitted(), freed from sctp_assoc_rm_peer().  Both the\nremoval and the SACKs come from the association peer.\n\nSet chunk->transport at the move.  The ordinary resend path needs nothing:\nit reaches its list_move_tail() only after sctp_packet_append_chunk()\nreturned SCTP_XMIT_OK, and __sctp_packet_append_chunk() has rebound the\nchunk by then.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74588","epss":0.005,"percentile":0.41182,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74588","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74589","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf, sockmap: Fix sk_redir use-after-free in send verdict  sk_psock_msg_verdict() takes a socket reference for psock->sk_redir. tcp_bpf_send_verdict() copies that pointer while holding the source socket lock, but does not take a reference for the local copy before dropping the lock around tcp_bpf_sendmsg_redir().  When apply_bytes keeps the cached verdict active, another sendmsg() on the same source socket can consume the remaining bytes and release the cached reference while the first thread still holds only the raw local pointer:    CPU 0                                  CPU 1   sk_redir = psock->sk_redir   apply_bytes remains nonzero   release_sock(sk)                                          lock_sock(sk)                                          apply_bytes reaches zero                                          psock->sk_redir = NULL                                          release_sock(sk)                                          tcp_bpf_sendmsg_redir(sk_redir)                                          sock_put(sk_redir)   tcp_bpf_sendmsg_redir(sk_redir)  The final sock_put() can free sk_redir before CPU 0 dereferences it.  KASAN reported:    BUG: KASAN: slab-use-after-free in tcp_bpf_sendmsg_redir+0xf39/0x1020   Read of size 8 at addr ffff888108537090 by task poc/87   Call Trace:    tcp_bpf_sendmsg_redir+0xf39/0x1020    tcp_bpf_sendmsg+0x977/0x1a50    __sys_sendto+0x32c/0x3a0    __x64_sys_sendto+0xdb/0x1b0   Allocated by task 85:    sk_prot_alloc+0x56/0x210    sk_clone+0x6f/0x14b0    inet_csk_clone_lock+0x24/0x740    tcp_create_openreq_child+0x25/0x2710    tcp_v4_syn_recv_sock+0x10a/0xe00   Freed by task 0:    __kasan_slab_free+0x43/0x70    slab_free_after_rcu_debug+0xa6/0x1e0    rcu_core+0x50a/0x1850   Last potentially related work creation:    __sk_destruct+0x3da/0x540    sk_psock_destroy+0x81e/0xab0    process_one_work+0x63a/0x1070  Take a temporary socket reference while the source socket lock still protects psock->sk_redir, and drop it after tcp_bpf_sendmsg_redir() returns.  This keeps each unlocked use independent of cached-verdict ownership.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74589","epss":0.00138,"percentile":0.03492,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10970999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74589","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1cec526cf0a2227395f2c2f4b671cb052ff0b00e","https://git.kernel.org/stable/c/41b7da0cb72ca5aa1e62b68dab323d0791fc6bdf","https://git.kernel.org/stable/c/4c9d9aa809c261dc0490a0e19d675f7e8e4c85bf","https://git.kernel.org/stable/c/90a19b0894ba79a699b48cf44421b36fbd566e99","https://git.kernel.org/stable/c/9b4fbc371a6ecf1b4e43b5a629015cc0830d8de3","https://git.kernel.org/stable/c/a14e4ef1d90c3418f01b3b6b8fd3a40a0a208a10","https://git.kernel.org/stable/c/a76624733730e541e4955fdecf506af2f6b20558","https://git.kernel.org/stable/c/d192cff2a37d59206dabe6ec2e60ceac6271f274"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix sk_redir use-after-free in send verdict\n\nsk_psock_msg_verdict() takes a socket reference for psock->sk_redir.\ntcp_bpf_send_verdict() copies that pointer while holding the source socket\nlock, but does not take a reference for the local copy before dropping the\nlock around tcp_bpf_sendmsg_redir().\n\nWhen apply_bytes keeps the cached verdict active, another sendmsg() on the\nsame source socket can consume the remaining bytes and release the cached\nreference while the first thread still holds only the raw local pointer:\n\n  CPU 0                                  CPU 1\n  sk_redir = psock->sk_redir\n  apply_bytes remains nonzero\n  release_sock(sk)\n                                         lock_sock(sk)\n                                         apply_bytes reaches zero\n                                         psock->sk_redir = NULL\n                                         release_sock(sk)\n                                         tcp_bpf_sendmsg_redir(sk_redir)\n                                         sock_put(sk_redir)\n  tcp_bpf_sendmsg_redir(sk_redir)\n\nThe final sock_put() can free sk_redir before CPU 0 dereferences it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in tcp_bpf_sendmsg_redir+0xf39/0x1020\n  Read of size 8 at addr ffff888108537090 by task poc/87\n  Call Trace:\n   tcp_bpf_sendmsg_redir+0xf39/0x1020\n   tcp_bpf_sendmsg+0x977/0x1a50\n   __sys_sendto+0x32c/0x3a0\n   __x64_sys_sendto+0xdb/0x1b0\n  Allocated by task 85:\n   sk_prot_alloc+0x56/0x210\n   sk_clone+0x6f/0x14b0\n   inet_csk_clone_lock+0x24/0x740\n   tcp_create_openreq_child+0x25/0x2710\n   tcp_v4_syn_recv_sock+0x10a/0xe00\n  Freed by task 0:\n   __kasan_slab_free+0x43/0x70\n   slab_free_after_rcu_debug+0xa6/0x1e0\n   rcu_core+0x50a/0x1850\n  Last potentially related work creation:\n   __sk_destruct+0x3da/0x540\n   sk_psock_destroy+0x81e/0xab0\n   process_one_work+0x63a/0x1070\n\nTake a temporary socket reference while the source socket lock still\nprotects psock->sk_redir, and drop it after tcp_bpf_sendmsg_redir()\nreturns.  This keeps each unlocked use independent of cached-verdict\nownership.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74589","epss":0.00138,"percentile":0.03492,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74589","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74592","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74592","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ima: Instantiate file_truncate and path_truncate hooks  Instantiate the file_truncate and path_truncate LSM hooks to reset the action cache flags (IMA_DONE_MASK) as soon as truncation is requested, so the file, based on policy, is re-collected, re-measured, re-audited, and re-appraised on next access.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74592","epss":0.00341,"percentile":0.27211,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.26598},"relatedVulnerabilities":[{"id":"CVE-2026-74592","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74592","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0baed1fa2184c81e4baf76f445d3faa4b738c8f7","https://git.kernel.org/stable/c/5f46705d96eb60587aa7035acfcbec977e08d620","https://git.kernel.org/stable/c/b80bed5c871a80151351342c065579405ce77145","https://git.kernel.org/stable/c/dd21c96a71e876c8df9ec546b885a2c5f47bbb05"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nima: Instantiate file_truncate and path_truncate hooks\n\nInstantiate the file_truncate and path_truncate LSM hooks to reset the\naction cache flags (IMA_DONE_MASK) as soon as truncation is requested,\nso the file, based on policy, is re-collected, re-measured, re-audited,\nand re-appraised on next access.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74592","epss":0.00341,"percentile":0.27211,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74592","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74594","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74594","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sched/psi: Shut down rtpoll_timer in psi_cgroup_free()  psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath and can race psi_trigger_destroy() taking down the last rtpoll trigger under rtpoll_trigger_lock:    psi_schedule_rtpoll_work()        psi_trigger_destroy()    rcu_read_lock();   task = rcu_dereference(rtpoll_task);                                     rcu_assign_pointer(rtpoll_task, NULL);                                     timer_delete(&rtpoll_timer);   mod_timer(&rtpoll_timer, ...);   rcu_read_unlock();                                     synchronize_rcu();                                     kthread_stop(task_to_destroy);  The group can then be freed with the re-armed timer still pending, and poll_timer_fn() runs on freed memory.  461daba06bdc (\"psi: eliminate kthread_worker from psi trigger scheduling mechanism\") deleted the timer synchronously after the synchronize_rcu(), which prevented this but raced trigger creation instead: the deletion could cancel the timer that a new trigger set armed during the grace period and, as creation also reinitialized the timer at the time, corrupt it. 8f91efd870ea (\"psi: Fix race between psi_trigger_create/destroy\") moved the initialization into group_init() and the deletion into the locked section, trading the creation races for the window above.  Neither placement in the destruction path works. A pending timer firing while the group is alive is harmless though. poll_timer_fn() just wakes the rtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's lifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it by then. timer_shutdown_sync() because the timer is never armed again.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74594","epss":0.00129,"percentile":0.02892,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74594","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74594","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1e5ca82eee59caca6988f9d6e859786aab8a5fa0","https://git.kernel.org/stable/c/310b5a537a78c358a4cd244bd767c1a517a05459","https://git.kernel.org/stable/c/4addb102154b7cf6e2310ccbe20c3c08619e520d","https://git.kernel.org/stable/c/5457025fa8ca3c0d2732109513de839e3e797190","https://git.kernel.org/stable/c/611e7821c4f83a671455658797336faecc3a5196","https://git.kernel.org/stable/c/8037c5b2b2a447df52542f4d8535895d837bdcbd","https://git.kernel.org/stable/c/806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08","https://git.kernel.org/stable/c/894a9300d7fb2e2951da92e565ae6de7ddfb0a69"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/psi: Shut down rtpoll_timer in psi_cgroup_free()\n\npsi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath\nand can race psi_trigger_destroy() taking down the last rtpoll trigger under\nrtpoll_trigger_lock:\n\n  psi_schedule_rtpoll_work()        psi_trigger_destroy()\n\n  rcu_read_lock();\n  task = rcu_dereference(rtpoll_task);\n                                    rcu_assign_pointer(rtpoll_task, NULL);\n                                    timer_delete(&rtpoll_timer);\n  mod_timer(&rtpoll_timer, ...);\n  rcu_read_unlock();\n                                    synchronize_rcu();\n                                    kthread_stop(task_to_destroy);\n\nThe group can then be freed with the re-armed timer still pending, and\npoll_timer_fn() runs on freed memory.\n\n461daba06bdc (\"psi: eliminate kthread_worker from psi trigger scheduling\nmechanism\") deleted the timer synchronously after the synchronize_rcu(),\nwhich prevented this but raced trigger creation instead: the deletion could\ncancel the timer that a new trigger set armed during the grace period and,\nas creation also reinitialized the timer at the time, corrupt it.\n8f91efd870ea (\"psi: Fix race between psi_trigger_create/destroy\") moved the\ninitialization into group_init() and the deletion into the locked section,\ntrading the creation races for the window above.\n\nNeither placement in the destruction path works. A pending timer firing\nwhile the group is alive is harmless though. poll_timer_fn() just wakes the\nrtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's\nlifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it\nby then. timer_shutdown_sync() because the timer is never armed again.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74594","epss":0.00129,"percentile":0.02892,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74594","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74595","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74595","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()  fscrypt_ioctl_set_policy() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing an encryption policy to be set, instead of the idmap of the mount the ioctl was issued on.  fscrypt is used by filesystems that support idmapped mounts (e.g. ext4, f2fs), so on such a mount this compares the caller's fsuid against the unmapped on-disk owner rather than the mapped owner: the actual owner can be wrongly denied with -EACCES and an unrelated caller wrongly allowed.  Use file_mnt_idmap(filp) instead.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74595","epss":0.00092,"percentile":0.00582,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.07038000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74595","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74595","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0baeb730044981f5ec5fb7d62a3763835ea606f6","https://git.kernel.org/stable/c/174633a468817a49bd474bcfc9067c84e54efe68","https://git.kernel.org/stable/c/33b7e810ce09955aa02f3b632455cf5e7ac990a9","https://git.kernel.org/stable/c/653e888a24c87b8bbeab44d7e558a1c1a3641088","https://git.kernel.org/stable/c/6a67c460b12315033268dce597546984fe5739e7","https://git.kernel.org/stable/c/98516ba8b817f34e86bdd7a5b7a383cff75c3ddf","https://git.kernel.org/stable/c/cf6c993c0feca7984797e634deba3c80342e199a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()\n\nfscrypt_ioctl_set_policy() calls inode_owner_or_capable() with\n&nop_mnt_idmap before allowing an encryption policy to be set, instead\nof the idmap of the mount the ioctl was issued on.\n\nfscrypt is used by filesystems that support idmapped mounts (e.g. ext4,\nf2fs), so on such a mount this compares the caller's fsuid against the\nunmapped on-disk owner rather than the mapped owner: the actual owner\ncan be wrongly denied with -EACCES and an unrelated caller wrongly\nallowed.  Use file_mnt_idmap(filp) instead.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74595","epss":0.00092,"percentile":0.00582,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74595","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74597","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74597","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ip6_tunnel: clear skb2->cb[] in ip6ip6_err()  ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the quoted inner IPv6 packet, and then passes the clone to icmpv6_send(). The clone still carries the outer packet's inet6_skb_parm in skb->cb.  If the outer packet had a Home Address Option, IP6CB(skb2)->dsthao remains non-zero after skb_pull(). icmpv6_send() later calls mip6_addr_swap(), which uses that stale dsthao offset against the quoted inner packet. A malformed inner destination-options header can then make the HAO lookup and address swap run past the end of the quoted packet and corrupt skb_shared_info.  Clear skb2->cb[] before pulling the quoted inner IPv6 packet so the reply path does not reuse metadata left by the outer IPv6 stack.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74597","epss":0.00514,"percentile":0.42124,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48316000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74597","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74597","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0dadb0620ab65949a8bc2439dd28ea3c942fe87d","https://git.kernel.org/stable/c/44fe898df302e91c5ee5acbc71ffa74e78e6c183","https://git.kernel.org/stable/c/484134e1eb07d700a73b1e4bbf3fb503e299be60","https://git.kernel.org/stable/c/4eb15c465337b18f44716c499cd6ad63eee0ad54","https://git.kernel.org/stable/c/64e41736a26f37ab6215bc2e6df125df05aceb08","https://git.kernel.org/stable/c/b6816536a2990c0db44a26130a03e40b441e829b","https://git.kernel.org/stable/c/f803c086399da277b5d0ff36a107d0f162751800","https://git.kernel.org/stable/c/fbf40faa0414b753212494ad197542002e66ed9e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: clear skb2->cb[] in ip6ip6_err()\n\nip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the\nquoted inner IPv6 packet, and then passes the clone to icmpv6_send().\nThe clone still carries the outer packet's inet6_skb_parm in skb->cb.\n\nIf the outer packet had a Home Address Option, IP6CB(skb2)->dsthao\nremains non-zero after skb_pull(). icmpv6_send() later calls\nmip6_addr_swap(), which uses that stale dsthao offset against the quoted\ninner packet. A malformed inner destination-options header can then make\nthe HAO lookup and address swap run past the end of the quoted packet\nand corrupt skb_shared_info.\n\nClear skb2->cb[] before pulling the quoted inner IPv6 packet so the\nreply path does not reuse metadata left by the outer IPv6 stack.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74597","epss":0.00514,"percentile":0.42124,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74597","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74598","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74598","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: fix Route Information option length validation  rt6_route_rcv() validates the Route Information option (RFC 4191) length against the prefix length, but both checks are off by one.  rinfo->length is the ND option length in units of 8 octets and it *includes* the 8-byte option header, so an option carrying N bytes of prefix has length == 1 + N/8.  RFC 4191 section 2.3 requires length 3 when Prefix Length is greater than 64, and 2 or 3 when it is greater than 0.  The code accepts length >= 2 and length >= 1 respectively.  ipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix, so a Router Advertisement with (prefix_len=128, length=2) or (prefix_len=64, length=1) makes the kernel read up to 8 bytes past the end of the option.  Those bytes end up in the prefix of the route that gets installed, so they are visible to userspace:    # RA with a Route Information option (prefix_len=128, length=2)   # followed by a source link-layer address option, 01 01 de ad be ef ca fe   $ ip -6 route show   2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra                      ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds  When the Route Information option is the last one in the packet, those eight bytes come from the skb tail room instead.  Reject the option lengths RFC 4191 does not allow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74598","epss":0.00425,"percentile":0.35839,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.31875000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74598","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74598","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b9e02f3bd31c888f2ccdc0ca08e546d6abe9c4d","https://git.kernel.org/stable/c/2f6f94eda12430fb41b24b44a71e2ea4e93561d7","https://git.kernel.org/stable/c/3b2231e358d26e3aec5d8040b1fb777af03c5f05","https://git.kernel.org/stable/c/7309529f257ae18e72112ef9f614edfd6df229bb","https://git.kernel.org/stable/c/7eac87396c44a312be457ef41d4c5687883be9a2","https://git.kernel.org/stable/c/d1ad8fb2ac6a1afb71dc22d9ae8efb4dda96c824","https://git.kernel.org/stable/c/da64ed1f346ba84df574d6469fa2e422b2511719","https://git.kernel.org/stable/c/ff3cb05289b8a4ef95fa7ea14c7d34818359edbb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix Route Information option length validation\n\nrt6_route_rcv() validates the Route Information option (RFC 4191) length\nagainst the prefix length, but both checks are off by one.\n\nrinfo->length is the ND option length in units of 8 octets and it\n*includes* the 8-byte option header, so an option carrying N bytes of\nprefix has length == 1 + N/8.  RFC 4191 section 2.3 requires length 3\nwhen Prefix Length is greater than 64, and 2 or 3 when it is greater\nthan 0.  The code accepts length >= 2 and length >= 1 respectively.\n\nipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix,\nso a Router Advertisement with (prefix_len=128, length=2) or\n(prefix_len=64, length=1) makes the kernel read up to 8 bytes past the\nend of the option.  Those bytes end up in the prefix of the route that\ngets installed, so they are visible to userspace:\n\n  # RA with a Route Information option (prefix_len=128, length=2)\n  # followed by a source link-layer address option, 01 01 de ad be ef ca fe\n  $ ip -6 route show\n  2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra\n                     ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds\n\nWhen the Route Information option is the last one in the packet, those\neight bytes come from the skb tail room instead.\n\nReject the option lengths RFC 4191 does not allow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74598","epss":0.00425,"percentile":0.35839,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74598","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74599","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74599","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/ptdump: always stabilise against page table freeing using init_mm  Previous commits have established the invariant that kernel page table freeing is performed while an mmap read lock on init_mm is held, which fixes races between ptdump and kernel page table freeing over init_mm.  However, x86 and arm64 can perform a ptdump over an mm other than init_mm via ptdump_walk_pgd() and since kernel memory ranges are shared across non-kernel mm's, this means that the race still exists for these cases.  Fix this by acquiring a nested mmap write lock for init_mm in ptdump_walk_pgd().  This is safe as we take this after mmap write locking the mm, and nothing acquires the init_mm lock first before locking an arbitrary mm, so no deadlock is possible.  Also update walk_page_range_debug() to assert that init_mm is write locked, add a comment explaining why and remove some redundant code, and eliminate the unnecessary and confusing invocation of walk_kernel_page_table_range().  We can safely remove the non-NULL check for walk.mm, as the mmap lock asserts would NULL pointer deref if it was (and of course no callers do this).  The first point at which ptdump can race kernel page table freeing is commit b6bdb7517c3d (\"mm/vmalloc: add interfaces to free unmapped page table\"), so we target this in the Fixes tag.","cvss":[],"epss":[{"cve":"CVE-2026-74599","epss":0.00173,"percentile":0.06831,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74599","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74599","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/27c32e5538344b13c1505a08861e04620c125d47","https://git.kernel.org/stable/c/3c0391b9a774cc0854f3152e484a9d4835b12b40","https://git.kernel.org/stable/c/4adc4c9a9a43d61fe476dfe10811f3df2e7e4106","https://git.kernel.org/stable/c/76df4edf7d61ecb711bc517ff4c20a5e85c4e9f7","https://git.kernel.org/stable/c/7f740664aec1f832953c2e6d9b8920cd6c8bcc0c","https://git.kernel.org/stable/c/b9c6d048bdfaae78d7d921b454f7de7baefaa2f0","https://git.kernel.org/stable/c/cbd9583bb6f70733d0022a66d3546a15c76ae744"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/ptdump: always stabilise against page table freeing using init_mm\n\nPrevious commits have established the invariant that kernel page table\nfreeing is performed while an mmap read lock on init_mm is held, which\nfixes races between ptdump and kernel page table freeing over init_mm.\n\nHowever, x86 and arm64 can perform a ptdump over an mm other than init_mm\nvia ptdump_walk_pgd() and since kernel memory ranges are shared across\nnon-kernel mm's, this means that the race still exists for these cases.\n\nFix this by acquiring a nested mmap write lock for init_mm in\nptdump_walk_pgd().\n\nThis is safe as we take this after mmap write locking the mm, and nothing\nacquires the init_mm lock first before locking an arbitrary mm, so no\ndeadlock is possible.\n\nAlso update walk_page_range_debug() to assert that init_mm is write\nlocked, add a comment explaining why and remove some redundant code, and\neliminate the unnecessary and confusing invocation of\nwalk_kernel_page_table_range().\n\nWe can safely remove the non-NULL check for walk.mm, as the mmap lock\nasserts would NULL pointer deref if it was (and of course no callers do\nthis).\n\nThe first point at which ptdump can race kernel page table freeing is\ncommit b6bdb7517c3d (\"mm/vmalloc: add interfaces to free unmapped page\ntable\"), so we target this in the Fixes tag.","cvss":[],"epss":[{"cve":"CVE-2026-74599","epss":0.00173,"percentile":0.06831,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74599","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74600","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74600","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/page_table_check: skip special zero mappings  page_table_check_set() and page_table_check_clear() account mappings based on PageAnon().  Shared zero-page PTEs and huge zero PMDs are special mappings, but page_table_check can still account them as file-backed pages.  An unprivileged process can populate enough zero mappings to overflow file_map_count and hit the existing BUG_ON().  The PTE path can do this with the shared zero page, and the PMD path can do the same with huge zero mappings.  Skip special zero mappings in the user page-table accounting paths.  Keep the PTE-side pte_special() check, and identify huge zero PMDs from the mapped folio instead of pmd_special().  That covers architectures where pmd_special() is a no-op without adding huge_zero_pfn checks to the generic counter helpers.","cvss":[],"epss":[{"cve":"CVE-2026-74600","epss":0.00166,"percentile":0.06159,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-74600","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74600","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/7755be923e325dc300f4b0c3e1ad7e91b28b3cb9","https://git.kernel.org/stable/c/8db4bab826ccc9ec10fa41736a48031cd338d392","https://git.kernel.org/stable/c/b726eb3c94d23e09da0e0f46b0fa09fb2b5d99cc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_table_check: skip special zero mappings\n\npage_table_check_set() and page_table_check_clear() account mappings based\non PageAnon().  Shared zero-page PTEs and huge zero PMDs are special\nmappings, but page_table_check can still account them as file-backed\npages.\n\nAn unprivileged process can populate enough zero mappings to overflow\nfile_map_count and hit the existing BUG_ON().  The PTE path can do this\nwith the shared zero page, and the PMD path can do the same with huge zero\nmappings.\n\nSkip special zero mappings in the user page-table accounting paths.  Keep\nthe PTE-side pte_special() check, and identify huge zero PMDs from the\nmapped folio instead of pmd_special().  That covers architectures where\npmd_special() is a no-op without adding huge_zero_pfn checks to the\ngeneric counter helpers.","cvss":[],"epss":[{"cve":"CVE-2026-74600","epss":0.00166,"percentile":0.06159,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74600","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74601","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74601","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ring-buffer: Use current_context for safe per-CPU buffer swap  The ring_buffer_swap_cpu() function currently checks the per-CPU committing counter to determine if a buffer is actively being written to before performing the swap. However, there exists a race window where this check can be bypassed:      ring_buffer_lock_reserve         cpu_buffer = buffer->buffers[cpu];       // cpu_buffer_a         rb_reserve_next_event             rb_start_commit // inc committing             if (unlikely(READ_ONCE(cpu_buffer->buffer) != buffer)) {...}             __rb_reserve_next                 rb_move_tail                     rb_end_commit(cpu_buffer);   // dec committing => 0                     /* interrupt hits here, successfully swaps! */                     local_inc(&cpu_buffer->committing);      ring_buffer_unlock_commit         cpu_buffer = buffer->buffers[cpu];      // cpu_buffer_b         rb_commit             rb_end_commit             RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing))                                                 // triggers warning  The committing counter can temporarily drop to 0 during a single write operation (within rb_move_tail), creating a window where swap can succeed even though the write is still in progress. This leads to inconsistent buffer state and triggers the RB_WARN_ON in rb_commit().  Replace the committing counter check with current_context checks, which are set at the entry of ring_buffer_lock_reserve() and remain valid throughout the entire write operation, providing a reliable indicator of buffer busy state during swap.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74601","epss":0.00136,"percentile":0.03338,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10404000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74601","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74601","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/22709117d9ae95e52673685f98caac7c356a8227","https://git.kernel.org/stable/c/26662bc8fced1d668fa1aa146eda085bfc67bd0b","https://git.kernel.org/stable/c/597f279b7b4a06412e3d965e98cc36e181cdbede","https://git.kernel.org/stable/c/5b926fb04cb9ef3156dcf88c69a59d3d1a1c4f9f","https://git.kernel.org/stable/c/5e6e2a18c20e88167d414f666032792e8bf19b80","https://git.kernel.org/stable/c/6b524e6b234e45c7f5f90d13b042c6f57f80105c","https://git.kernel.org/stable/c/ad7e10c7ea89af45ac1bf1814855d45da472703d","https://git.kernel.org/stable/c/f27bdc43077e4fcb5557dfc315ee8d91e741f483"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Use current_context for safe per-CPU buffer swap\n\nThe ring_buffer_swap_cpu() function currently checks the per-CPU\ncommitting counter to determine if a buffer is actively being written to\nbefore performing the swap. However, there exists a race window where\nthis check can be bypassed:\n\n    ring_buffer_lock_reserve\n        cpu_buffer = buffer->buffers[cpu];       // cpu_buffer_a\n        rb_reserve_next_event\n            rb_start_commit // inc committing\n            if (unlikely(READ_ONCE(cpu_buffer->buffer) != buffer)) {...}\n            __rb_reserve_next\n                rb_move_tail\n                    rb_end_commit(cpu_buffer);   // dec committing => 0\n                    /* interrupt hits here, successfully swaps! */\n                    local_inc(&cpu_buffer->committing);\n\n    ring_buffer_unlock_commit\n        cpu_buffer = buffer->buffers[cpu];      // cpu_buffer_b\n        rb_commit\n            rb_end_commit\n            RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing))\n                                                // triggers warning\n\nThe committing counter can temporarily drop to 0 during a single write\noperation (within rb_move_tail), creating a window where swap can\nsucceed even though the write is still in progress. This leads to\ninconsistent buffer state and triggers the RB_WARN_ON in rb_commit().\n\nReplace the committing counter check with current_context checks, which\nare set at the entry of ring_buffer_lock_reserve() and remain valid\nthroughout the entire write operation, providing a reliable indicator of\nbuffer busy state during swap.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74601","epss":0.00136,"percentile":0.03338,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74601","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74603","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74603","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ptp: ocp: Fix board ID over-read  The EEPROM board ID is a fixed 13-byte field and is not guaranteed to contain a NUL terminator. Passing it directly to devlink_info_version_fixed_put() treats it as a C string and may read beyond the field.  Format at most OCP_BOARD_ID_LEN bytes into the existing local buffer before reporting the ID. Use a precision limit because the snprintf() output size alone does not bound the source string scan.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74603","epss":0.00126,"percentile":0.02578,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09198},"relatedVulnerabilities":[{"id":"CVE-2026-74603","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74603","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3d965811be78473654e6e8cc8e4fb7b6b87aa6c1","https://git.kernel.org/stable/c/5fd91dd4a143479b0575fb1f202ec1c501e71fd5","https://git.kernel.org/stable/c/6b69f2ef10cdb018c0b127a7cab88e590bbddba4","https://git.kernel.org/stable/c/72ef3ce80078199bfad32f98d055f44ba7cd0c3d","https://git.kernel.org/stable/c/f8d7e5751267637190eff887c971d5b468106213","https://git.kernel.org/stable/c/f92558bbe78d6284fedd053900f82a70f0aa8707"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nptp: ocp: Fix board ID over-read\n\nThe EEPROM board ID is a fixed 13-byte field and is not guaranteed to\ncontain a NUL terminator. Passing it directly to\ndevlink_info_version_fixed_put() treats it as a C string and may read\nbeyond the field.\n\nFormat at most OCP_BOARD_ID_LEN bytes into the existing local buffer\nbefore reporting the ID. Use a precision limit because the snprintf()\noutput size alone does not bound the source string scan.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74603","epss":0.00126,"percentile":0.02578,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74603","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74604","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74604","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Revert \"thermal/drivers/hwmon: Cleanup coding style a bit\"  Revert commit 030a48b0f6ce (\"thermal/drivers/hwmon: Cleanup coding style a bit\") that introduced a use-after-free into the error path of thermal_add_hwmon_sysfs() by removing a valid check from it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74604","epss":0.00138,"percentile":0.03492,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10970999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74604","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74604","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2434f4765da8ccd7ef31be88b86f1bfa2e95be11","https://git.kernel.org/stable/c/6a48ee9a5bda0f8ee501f9bef159fb9f39ff519a","https://git.kernel.org/stable/c/6b446d335ba16e93a266dd77adf1ba51abc82df4","https://git.kernel.org/stable/c/8d34019d1413629a434a7e8d9f91c76d256196a0","https://git.kernel.org/stable/c/999e573212d5f1debf073c68be35e55bbfad12fc","https://git.kernel.org/stable/c/b4c01ae6dd56d9dfd96bd1b29c28afa8fa06b366","https://git.kernel.org/stable/c/ff8da20b6f47c48d46e47f93f7a59e2d56ee9107"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"thermal/drivers/hwmon: Cleanup coding style a bit\"\n\nRevert commit 030a48b0f6ce (\"thermal/drivers/hwmon: Cleanup coding style\na bit\") that introduced a use-after-free into the error path of\nthermal_add_hwmon_sysfs() by removing a valid check from it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74604","epss":0.00138,"percentile":0.03492,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74604","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74607","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74607","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: SVM: Serialize accesses to the owner and mirror list with separate lock  Interaction between KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM and KVM_CAP_VM_COPY_ENC_CONTEXT_FROM can cause two separate issues:  - in sev_migrate_from(), when the destination KVM is a mirror, the mirror   entry is moved from the source's list to the owner's mirror_vms list,   without holding the owner's lock unlike other writers of the owner's   mirror list (sev_vm_copy_enc_context_from(), sev_vm_destroy()).   A concurrent COPY or destroy can race with sev_migrate_from() and   corrupt the list.  - In sev_vm_destroy(), the *owner* is still active and could receive   concurrently a KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM that causes   sev->enc_context_owner to change.  In this case the incorrect VM   receives kvm_put_kvm().  The second issue needs particular care because the owner could disappear altogether (even though the race window is impossibly small) between reading it and locking it.  There is thus no way to perform the checks under the owner lock without putting struct kvm under SLAB_TYPESAFE_BY_RCU (which would allow kvm_get_kvm_safe() under RCU critical section).  It is much simpler to just use a global lock, since the critical sections are so small and the new lock is always a leaf lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74607","epss":0.00129,"percentile":0.02893,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74607","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74607","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1d78d33275ef2a16c6d080910b291d0a97a0e613","https://git.kernel.org/stable/c/28afde1edbd8b20058cbf4d75fb57876471ec334","https://git.kernel.org/stable/c/328ab4fabe05af004d886659f8744076e320ddce","https://git.kernel.org/stable/c/47976eaaf0a4eb46dade48b3246779090db9e3ec","https://git.kernel.org/stable/c/7943ec3a6d0e7e0a2eb4943300bce089ac3e8c3e","https://git.kernel.org/stable/c/d728baba0f20e49439fc7831bf3e4e7dee82161a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Serialize accesses to the owner and mirror list with separate lock\n\nInteraction between KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM and\nKVM_CAP_VM_COPY_ENC_CONTEXT_FROM can cause two separate issues:\n\n- in sev_migrate_from(), when the destination KVM is a mirror, the mirror\n  entry is moved from the source's list to the owner's mirror_vms list,\n  without holding the owner's lock unlike other writers of the owner's\n  mirror list (sev_vm_copy_enc_context_from(), sev_vm_destroy()).\n  A concurrent COPY or destroy can race with sev_migrate_from() and\n  corrupt the list.\n\n- In sev_vm_destroy(), the *owner* is still active and could receive\n  concurrently a KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM that causes\n  sev->enc_context_owner to change.  In this case the incorrect VM\n  receives kvm_put_kvm().\n\nThe second issue needs particular care because the owner could disappear\naltogether (even though the race window is impossibly small) between\nreading it and locking it.  There is thus no way to perform the checks\nunder the owner lock without putting struct kvm under SLAB_TYPESAFE_BY_RCU\n(which would allow kvm_get_kvm_safe() under RCU critical section).\n\nIt is much simpler to just use a global lock, since the critical\nsections are so small and the new lock is always a leaf lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74607","epss":0.00129,"percentile":0.02893,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74607","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74608","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74608","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  smb: client: Fix use-after-free in cifs_try_adding_channels()  cifs_try_adding_channels() takes a temporary reference to an interface before dropping iface_lock. If cifs_ses_add_channel() fails, it drops that reference and then increments iface->weight_fulfilled.  A concurrent interface list refresh can remove the list reference while channel creation is in progress. In that case, the failure-path kref_put() releases the last reference and frees iface. Updating weight_fulfilled afterward then accesses freed memory.  Increment weight_fulfilled before dropping the temporary reference, keeping iface alive for the final access.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74608","epss":0.00477,"percentile":0.39724,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.44838000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-74608","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74608","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1305eadc6a7d78a8d0a52eee29ddd2d9e8a27805","https://git.kernel.org/stable/c/1ffacbadc14530e55b8d86f7b917524f6a0fb891","https://git.kernel.org/stable/c/47dfac48bce7198ad4f1a388fc8c9491f878ac3b","https://git.kernel.org/stable/c/4986410316b1ae0e63c6ce418e4eb196723626e7","https://git.kernel.org/stable/c/64d7584e62ac8cdc750455c5fdc6008fc2de4f06","https://git.kernel.org/stable/c/c292d4686f717c03e5022fc4ae7c782f39a94915"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_try_adding_channels()\n\ncifs_try_adding_channels() takes a temporary reference to an interface\nbefore dropping iface_lock. If cifs_ses_add_channel() fails, it drops\nthat reference and then increments iface->weight_fulfilled.\n\nA concurrent interface list refresh can remove the list reference while\nchannel creation is in progress. In that case, the failure-path\nkref_put() releases the last reference and frees iface. Updating\nweight_fulfilled afterward then accesses freed memory.\n\nIncrement weight_fulfilled before dropping the temporary reference,\nkeeping iface alive for the final access.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74608","epss":0.00477,"percentile":0.39724,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74608","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74609","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74609","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: read le->link under the node lock in tipc_node_link_down()  tipc_node_link_down() caches the link pointer before taking n->lock:  \tstruct tipc_link *l = le->link;\t\t/* unlocked */  \tif (!l) \t\treturn; \ttipc_node_write_lock(n); \tif (!tipc_link_is_establishing(l)) {\t/* deref l */ \t... \t\ttipc_link_reset(l);\t\t/* write into l */ \tif (delete) { \t\tkfree(l); \t\tle->link = NULL;  The delete=true caller frees that very object under n->lock, so the lock does not protect the cached pointer against it:   - CPU A, delete=false: tipc_rcv() on TIPC_LINK_DOWN_EVT, or the link    supervision timer via tipc_node_timeout(), reads l unlocked and then    dereferences it under n->lock;  - CPU B, delete=true: netlink TIPC_NL_BEARER_DISABLE -> bearer_disable()    -> tipc_node_delete_links() -> tipc_node_link_down(n, bearer_id, true)    -> kfree(l).  The link is freed with plain kfree(), not kfree_rcu(), and for UDP bearers disable_media() only schedules the asynchronous cleanup_bearer() work, so its synchronize_net() runs after the links are already gone.  An in-flight CPU A that has read l therefore dereferences freed memory once B frees it: a use-after-free read in tipc_link_is_establishing(), and a use-after-free write via tipc_link_reset() on the establishing branch.  The following trace was captured on 7.2.0-rc5-00284-gaf39eb111ce6:    BUG: KASAN: slab-use-after-free in tipc_link_is_establishing (net/tipc/link.c:285)   Read of size 4 at addr ffff88802e2aa068 by task swapper/2/0    tipc_link_is_establishing (net/tipc/link.c:285)    tipc_node_link_down (net/tipc/node.c:1076)    tipc_node_timeout (net/tipc/node.c:843)   Allocated by task 9549:    tipc_link_create (net/tipc/link.c:490)    tipc_node_check_dest (net/tipc/node.c:1279)    tipc_disc_rcv (net/tipc/discover.c:252)    tipc_udp_recv (net/tipc/udp_media.c:389)   Freed by task 9549:    tipc_node_link_down (net/tipc/node.c:1084)    tipc_node_delete_links (net/tipc/node.c:1320)    bearer_disable (net/tipc/bearer.c:414)    __tipc_nl_bearer_disable (net/tipc/bearer.c:992)  Move the le->link read inside tipc_node_write_lock(), so it is serialised against the kfree() in the delete path.  A racing teardown now either has not run yet, and we see a valid link, or has already run, and we see NULL.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74609","epss":0.00126,"percentile":0.02558,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74609","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74609","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2be741ad565c610871a6a95062c12c39da7168fd","https://git.kernel.org/stable/c/47ba70891b10b2feb52462086b7fcd2ad75d3ce3","https://git.kernel.org/stable/c/5558a8312452ddb21eff22b1cbd84302ad951944","https://git.kernel.org/stable/c/69d209461c110388710e483a130caf051e4fd09a","https://git.kernel.org/stable/c/a714d62513befef37f71f4ae89bb1fe173b65f2e","https://git.kernel.org/stable/c/c3f2347a47754eac690967cfd82cb6d559817b07","https://git.kernel.org/stable/c/cba9ccb47e9fa4cc77692fb896cc5ab57a667882","https://git.kernel.org/stable/c/de017c22135f545ca4e65d1eada22887b64958eb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: read le->link under the node lock in tipc_node_link_down()\n\ntipc_node_link_down() caches the link pointer before taking n->lock:\n\n\tstruct tipc_link *l = le->link;\t\t/* unlocked */\n\n\tif (!l)\n\t\treturn;\n\ttipc_node_write_lock(n);\n\tif (!tipc_link_is_establishing(l)) {\t/* deref l */\n\t...\n\t\ttipc_link_reset(l);\t\t/* write into l */\n\tif (delete) {\n\t\tkfree(l);\n\t\tle->link = NULL;\n\nThe delete=true caller frees that very object under n->lock, so the lock\ndoes not protect the cached pointer against it:\n\n - CPU A, delete=false: tipc_rcv() on TIPC_LINK_DOWN_EVT, or the link\n   supervision timer via tipc_node_timeout(), reads l unlocked and then\n   dereferences it under n->lock;\n - CPU B, delete=true: netlink TIPC_NL_BEARER_DISABLE -> bearer_disable()\n   -> tipc_node_delete_links() -> tipc_node_link_down(n, bearer_id, true)\n   -> kfree(l).\n\nThe link is freed with plain kfree(), not kfree_rcu(), and for UDP bearers\ndisable_media() only schedules the asynchronous cleanup_bearer() work, so\nits synchronize_net() runs after the links are already gone.  An in-flight\nCPU A that has read l therefore dereferences freed memory once B frees it:\na use-after-free read in tipc_link_is_establishing(), and a use-after-free\nwrite via tipc_link_reset() on the establishing branch.\n\nThe following trace was captured on 7.2.0-rc5-00284-gaf39eb111ce6:\n\n  BUG: KASAN: slab-use-after-free in tipc_link_is_establishing (net/tipc/link.c:285)\n  Read of size 4 at addr ffff88802e2aa068 by task swapper/2/0\n   tipc_link_is_establishing (net/tipc/link.c:285)\n   tipc_node_link_down (net/tipc/node.c:1076)\n   tipc_node_timeout (net/tipc/node.c:843)\n  Allocated by task 9549:\n   tipc_link_create (net/tipc/link.c:490)\n   tipc_node_check_dest (net/tipc/node.c:1279)\n   tipc_disc_rcv (net/tipc/discover.c:252)\n   tipc_udp_recv (net/tipc/udp_media.c:389)\n  Freed by task 9549:\n   tipc_node_link_down (net/tipc/node.c:1084)\n   tipc_node_delete_links (net/tipc/node.c:1320)\n   bearer_disable (net/tipc/bearer.c:414)\n   __tipc_nl_bearer_disable (net/tipc/bearer.c:992)\n\nMove the le->link read inside tipc_node_write_lock(), so it is serialised\nagainst the kfree() in the delete path.  A racing teardown now either has\nnot run yet, and we see a valid link, or has already run, and we see NULL.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74609","epss":0.00126,"percentile":0.02558,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74609","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74611","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74611","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tls: rx: restore msg_iter before TLS 1.3 optimistic retry  tls_decrypt_sg() advances msg->msg_iter when it maps user pages for the optimistic TLS 1.3 zero-copy path. If the decrypted record turns out not to be unpadded application data, tls_decrypt_sw() retries into a kernel skb, but leaves the iterator advanced.  The subsequent copy from the skb then writes decrypted bytes again at a later point in the caller iovecs while recvmsg() reports only the post-retry length. A TLS peer can trigger this after the receiver enables TLS_RX_EXPECT_NO_PAD.  Revert the iterator by the number of bytes consumed by the optimistic mapping before retrying without zero-copy.  Add a selftest which sends a TLS 1.3 control record with TLS_RX_EXPECT_NO_PAD enabled and verifies that recvmsg() does not overwrite later iovecs beyond the returned length.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74611","epss":0.00442,"percentile":0.37273,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.41548},"relatedVulnerabilities":[{"id":"CVE-2026-74611","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74611","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1c8629651cb54f7b51db8fc0b1a9944e4a4b0f5e","https://git.kernel.org/stable/c/3c837266a734e2a22b24d2d567404a501d405835","https://git.kernel.org/stable/c/68787940274ec89f41dc91b1a68ee1a16a90735f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: rx: restore msg_iter before TLS 1.3 optimistic retry\n\ntls_decrypt_sg() advances msg->msg_iter when it maps user pages for\nthe optimistic TLS 1.3 zero-copy path. If the decrypted record turns\nout not to be unpadded application data, tls_decrypt_sw() retries into\na kernel skb, but leaves the iterator advanced.\n\nThe subsequent copy from the skb then writes decrypted bytes again at\na later point in the caller iovecs while recvmsg() reports only the\npost-retry length. A TLS peer can trigger this after the receiver\nenables TLS_RX_EXPECT_NO_PAD.\n\nRevert the iterator by the number of bytes consumed by the optimistic\nmapping before retrying without zero-copy.\n\nAdd a selftest which sends a TLS 1.3 control record with\nTLS_RX_EXPECT_NO_PAD enabled and verifies that recvmsg() does not\noverwrite later iovecs beyond the returned length.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74611","epss":0.00442,"percentile":0.37273,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74611","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74612","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74612","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  veth: fix skb length accounting after XDP frag adjustment  veth exposes non-linear skb fragments through an xdp_buff. If an XDP program adjusts the fragment area, veth_xdp_rcv_skb() copies xdp_frags_size back to skb->data_len but leaves skb->len containing the old fragment contribution.  After a fragment shrink, this makes skb_headlen() larger than the actual linear area. In the reproduced UDP receive path, __skb_datagram_iter() copied 1024 bytes past the actual linear tail to userspace, starting at struct skb_shared_info. The copied bytes included the affected skb's nr_frags, xdp_frags_size, and a kernel pointer from skb_shinfo(skb)->frags[0]. Real packet data was displaced by the same amount and truncated at the end.  Subtract the old data_len before replacing it and add the new data_len afterwards, keeping skb->len and skb->data_len synchronized.  Additionally, bpf_xdp_pull_data() can advance data_end while leaving frags present. The skb is then still non-linear, so the old __skb_put(skb, off) triggers SKB_LINEAR_ASSERT().  Use skb_set_tail_pointer() and update skb->len explicitly instead, following bpf_prog_run_generic_xdp(). Unlike __skb_put(), skb_set_tail_pointer() does not require a linear skb.  A 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by 1024 bytes from its fragment area. Before the fix, all 10 runs produced corrupted payloads. After the fix, all 10 runs matched the expected payload exactly. A forced-tailroom reproducer also exercises bpf_xdp_pull_data() with frags still present; the old code triggers SKB_LINEAR_ASSERT(), while this fix passes 10/10 runs.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74612","epss":0.00491,"percentile":0.40637,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.46645000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74612","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74612","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0c3024afabb8064b141f3cedcb1ddd6ab05ad9d5","https://git.kernel.org/stable/c/2f2a7f3f8b9f1bffc9b0488aa02b6951b2aec139","https://git.kernel.org/stable/c/3205b0652a37255dbb7ca8f3d942c8d8aa677c21","https://git.kernel.org/stable/c/41b96667d42b74bb4b137f1bb78b611a953c5943","https://git.kernel.org/stable/c/cb6379feaaff11c4e1e79c26c745ffa23182768a","https://git.kernel.org/stable/c/cdf745b7a777f87f51666e5d8f4c6fc279bcf54d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix skb length accounting after XDP frag adjustment\n\nveth exposes non-linear skb fragments through an xdp_buff. If an XDP\nprogram adjusts the fragment area, veth_xdp_rcv_skb() copies\nxdp_frags_size back to skb->data_len but leaves skb->len containing the\nold fragment contribution.\n\nAfter a fragment shrink, this makes skb_headlen() larger than the actual\nlinear area. In the reproduced UDP receive path, __skb_datagram_iter()\ncopied 1024 bytes past the actual linear tail to userspace, starting at\nstruct skb_shared_info. The copied bytes included the affected skb's\nnr_frags, xdp_frags_size, and a kernel pointer from\nskb_shinfo(skb)->frags[0]. Real packet data was displaced by the same\namount and truncated at the end.\n\nSubtract the old data_len before replacing it and add the new data_len\nafterwards, keeping skb->len and skb->data_len synchronized.\n\nAdditionally, bpf_xdp_pull_data() can advance data_end while leaving\nfrags present. The skb is then still non-linear, so the old\n__skb_put(skb, off) triggers SKB_LINEAR_ASSERT().\n\nUse skb_set_tail_pointer() and update skb->len explicitly instead,\nfollowing bpf_prog_run_generic_xdp(). Unlike __skb_put(),\nskb_set_tail_pointer() does not require a linear skb.\n\nA 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by\n1024 bytes from its fragment area. Before the fix, all 10 runs produced\ncorrupted payloads. After the fix, all 10 runs matched the expected\npayload exactly. A forced-tailroom reproducer also exercises\nbpf_xdp_pull_data() with frags still present; the old code triggers\nSKB_LINEAR_ASSERT(), while this fix passes 10/10 runs.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74612","epss":0.00491,"percentile":0.40637,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74612","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74613","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74613","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vsock/virtio: avoid refilling the RX queue after teardown  Commit b917507e5ad9 (\"vsock/virtio: stop workers during the .remove()\") made the RX worker jump to its common exit when rx_run is clear.  That exit still refills the RX queue when the buffer count is low, so work queued across virtio_vsock_vqs_del() can add buffers after the virtqueues have been deleted.  BUG: KASAN: slab-use-after-free in virtqueue_add_sgs Read of size 4 by task kworker/0:1 Workqueue: virtio_vsock virtio_transport_rx_work Call Trace:  virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)  virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)  virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)  process_one_work (kernel/workqueue.c:3314)  worker_thread (kernel/workqueue.c:3478)  kthread (kernel/kthread.c:436)  ret_from_fork (arch/x86/kernel/process.c:158)  ret_from_fork_asm (arch/x86/entry/entry_64.S:245) ... Freed by task 141:  kfree (mm/slub.c:6566)  vp_del_vq (drivers/virtio/virtio_pci_common.c:259)  vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)  virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)  virtio_device_freeze (drivers/virtio/virtio.c:658)  virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)  pci_pm_freeze (drivers/pci/pci-driver.c:1098)  device_suspend (drivers/base/power/main.c:1968) Kernel panic - not syncing: KASAN: panic_on_warn set ...  Jump to a no-refill exit when rx_run is clear, leaving the normal exit to replenish a running queue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74613","epss":0.00126,"percentile":0.02563,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74613","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74613","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171","https://git.kernel.org/stable/c/38c7763fdc533edb34dc8f4489c260e8ba2ccae9","https://git.kernel.org/stable/c/4d37e3525cc346a1421c1bdeaad5848e249fc60c","https://git.kernel.org/stable/c/9d80a04129a6c27a690cb69de3fe3f50be5aa8b9","https://git.kernel.org/stable/c/a309b74e3fc052352ab778500449cb9c3853c363","https://git.kernel.org/stable/c/a31e0ad444698d8aa7534a0f89fda543730f97a5","https://git.kernel.org/stable/c/a7658508f5fe8f1077a65e8cb9535d3426f37a2f","https://git.kernel.org/stable/c/e82a5faea2e3886dfb2a65ce092a132e7e896915"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: avoid refilling the RX queue after teardown\n\nCommit b917507e5ad9 (\"vsock/virtio: stop workers during the .remove()\")\nmade the RX worker jump to its common exit when rx_run is clear.  That\nexit still refills the RX queue when the buffer count is low, so work\nqueued across virtio_vsock_vqs_del() can add buffers after the virtqueues\nhave been deleted.\n\nBUG: KASAN: slab-use-after-free in virtqueue_add_sgs\nRead of size 4 by task kworker/0:1\nWorkqueue: virtio_vsock virtio_transport_rx_work\nCall Trace:\n virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)\n virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)\n virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)\n process_one_work (kernel/workqueue.c:3314)\n worker_thread (kernel/workqueue.c:3478)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n...\nFreed by task 141:\n kfree (mm/slub.c:6566)\n vp_del_vq (drivers/virtio/virtio_pci_common.c:259)\n vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)\n virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)\n virtio_device_freeze (drivers/virtio/virtio.c:658)\n virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)\n pci_pm_freeze (drivers/pci/pci-driver.c:1098)\n device_suspend (drivers/base/power/main.c:1968)\nKernel panic - not syncing: KASAN: panic_on_warn set ...\n\nJump to a no-refill exit when rx_run is clear, leaving the normal exit\nto replenish a running queue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74613","epss":0.00126,"percentile":0.02563,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74613","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74614","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74614","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vsock/virtio: read virtqueues under worker locks  Commit bd50c5dc182b (\"vsock/virtio: add support for device suspend/resume\") made the *_run flags transition from false to true when restore installs replacement virtqueues.  The RX, TX and event workers read their virtqueue before locking and checking the corresponding flag, so a worker delayed across freeze and restore can observe the replacement queue's running state while retaining a pointer to the deleted queue.  Read each virtqueue under its mutex after checking the run flag, keeping the pointer and state in the same queue generation.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74614","epss":0.00142,"percentile":0.03804,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11289000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-74614","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74614","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1cecb4202afdbeddcf29d59baf596ac6ab753f7f","https://git.kernel.org/stable/c/29dd10583bf9d2744cd84b862e4257c0a5699570","https://git.kernel.org/stable/c/941329ce14c5f481223a10d1d4c8b57ea7f3048a","https://git.kernel.org/stable/c/a1fb0c5b8a7c2753758aeced40971f99449dde0c","https://git.kernel.org/stable/c/bd43a7ec668be428265b3209eb43647aedcf720a","https://git.kernel.org/stable/c/eae099c764c7ebdb842eb1f638913e310bdd6513","https://git.kernel.org/stable/c/ebac8f6b1ef0e9278afe204b8692a7479988dace"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: read virtqueues under worker locks\n\nCommit bd50c5dc182b (\"vsock/virtio: add support for device\nsuspend/resume\") made the *_run flags transition from false to true when\nrestore installs replacement virtqueues.  The RX, TX and event workers\nread their virtqueue before locking and checking the corresponding flag,\nso a worker delayed across freeze and restore can observe the replacement\nqueue's running state while retaining a pointer to the deleted queue.\n\nRead each virtqueue under its mutex after checking the run flag, keeping\nthe pointer and state in the same queue generation.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74614","epss":0.00142,"percentile":0.03804,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74614","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74615","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74615","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: do not arm the ageing timer on a device that is down  vxlan_changelink() arms vxlan->age_timer whenever the requested ageing interval differs from the configured one:  \tif (conf.age_interval != vxlan->cfg.age_interval) \t\tmod_timer(&vxlan->age_timer, jiffies);  There is no netif_running() test, so the timer is armed even on a device that was never brought up.  The only synchronous cancel in the driver is the timer_delete_sync() in vxlan_stop(), which is .ndo_stop. netif_close_many() drops devices without IFF_UP before __dev_close_many() runs, so that cancel is skipped for such a device.  vxlan_setup() sets dev->needs_free_netdev = true and age_timer is a member of struct vxlan_dev, so free_netdev() releases the allocation the timer lives in while it is still queued on a timer_base. expire_timers() unlinks the entry before it loads timer->function, so the timer core writes through the freed object's list pointers:    BUG: KASAN: slab-use-after-free in __run_timers+0x208/0x654   Write of size 8 at addr ffff00001adace68 by task true/192    __asan_store8+0x84/0xac    __run_timers+0x208/0x654    run_timer_softirq+0x154/0x18c   Allocated by task 189:    alloc_netdev_mqs+0x64/0x720    rtnl_create_link+0x4ac/0x520    rtnl_newlink+0x758/0xd00   Freed by task 191:    netdev_release+0x40/0x58    netdev_run_todo+0x4a4/0x8c0    rtnl_dellink+0x200/0x4e8  The rtnl operations involved are netns-scoped, so an unprivileged user can perform them in a new user and network namespace.  Arming the timer on a down device never had an effect: vxlan_cleanup() returns early on !netif_running(), and vxlan_open() arms the timer for any non-zero interval once the device is brought up.  Add the missing test.  Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74615","epss":0.00126,"percentile":0.02558,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10269},"relatedVulnerabilities":[{"id":"CVE-2026-74615","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74615","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/26c179d47403d2f919ee914cc02c31d896b59fee","https://git.kernel.org/stable/c/46bb297ad77680e009244f067f27d51cf5b8c7cf","https://git.kernel.org/stable/c/619dd29045e439d0b0f8c6d4fec1af447a050680","https://git.kernel.org/stable/c/6b095e99b9e67ea31f0c4b00260e010898253519","https://git.kernel.org/stable/c/6b4119af544996a545cf84b16f1dbce829ba0de8","https://git.kernel.org/stable/c/9dc561f0522c35bdd66e0646a748814a138ec4ca","https://git.kernel.org/stable/c/b37971686ec59fb027fa4910ba16805e68fddb97","https://git.kernel.org/stable/c/be44d79d14d7f9ae7c8ffb7272142005341b5123"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: do not arm the ageing timer on a device that is down\n\nvxlan_changelink() arms vxlan->age_timer whenever the requested ageing\ninterval differs from the configured one:\n\n\tif (conf.age_interval != vxlan->cfg.age_interval)\n\t\tmod_timer(&vxlan->age_timer, jiffies);\n\nThere is no netif_running() test, so the timer is armed even on a device\nthat was never brought up.  The only synchronous cancel in the driver is\nthe timer_delete_sync() in vxlan_stop(), which is .ndo_stop.\nnetif_close_many() drops devices without IFF_UP before\n__dev_close_many() runs, so that cancel is skipped for such a device.\n\nvxlan_setup() sets dev->needs_free_netdev = true and age_timer is a\nmember of struct vxlan_dev, so free_netdev() releases the allocation the\ntimer lives in while it is still queued on a timer_base.\nexpire_timers() unlinks the entry before it loads timer->function, so\nthe timer core writes through the freed object's list pointers:\n\n  BUG: KASAN: slab-use-after-free in __run_timers+0x208/0x654\n  Write of size 8 at addr ffff00001adace68 by task true/192\n   __asan_store8+0x84/0xac\n   __run_timers+0x208/0x654\n   run_timer_softirq+0x154/0x18c\n  Allocated by task 189:\n   alloc_netdev_mqs+0x64/0x720\n   rtnl_create_link+0x4ac/0x520\n   rtnl_newlink+0x758/0xd00\n  Freed by task 191:\n   netdev_release+0x40/0x58\n   netdev_run_todo+0x4a4/0x8c0\n   rtnl_dellink+0x200/0x4e8\n\nThe rtnl operations involved are netns-scoped, so an unprivileged user\ncan perform them in a new user and network namespace.\n\nArming the timer on a down device never had an effect: vxlan_cleanup()\nreturns early on !netif_running(), and vxlan_open() arms the timer for\nany non-zero interval once the device is brought up.  Add the missing\ntest.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74615","epss":0.00126,"percentile":0.02558,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74615","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74616","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xdp: reject clones that overrun skb_shared_info tailroom  xdpf_clone() clones broadcast copies into a single page and sets frame_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that page like a normal XDP frame and expects the usual skb_shared_info tailroom at the end of the buffer.  The current check only rejects frames whose linear xdp_frame header, headroom, and packet data exceed PAGE_SIZE. A source frame backed by a larger allocation can still satisfy that check while extending into the clone's required shared-info area. When such a clone is converted back into an skb, build_skb_around() places skb_shared_info over live packet bytes and later writes can corrupt XDP return metadata.  Reject clones unless their linear area fits inside SKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already enforced by the XDP-to-skb conversion path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74616","epss":0.00513,"percentile":0.42033,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48222000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-74616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74616","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/58408982fa39f9758124cec169f42854d6f98f35","https://git.kernel.org/stable/c/685edea27ac68d08fe4dbd3de74b858d2ad8e830","https://git.kernel.org/stable/c/ba13763d667e008e185fedf592d53846a5b457d1","https://git.kernel.org/stable/c/e48e8edbef2eb824201495daa5234560f632b23c","https://git.kernel.org/stable/c/ef4b7c7046d29a67090de15af0da0d1ae8d1b192","https://git.kernel.org/stable/c/f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0","https://git.kernel.org/stable/c/fab820f1691a9e26d9031f18aae1e9ce09078f92"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: reject clones that overrun skb_shared_info tailroom\n\nxdpf_clone() clones broadcast copies into a single page and sets\nframe_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that\npage like a normal XDP frame and expects the usual skb_shared_info\ntailroom at the end of the buffer.\n\nThe current check only rejects frames whose linear xdp_frame header,\nheadroom, and packet data exceed PAGE_SIZE. A source frame backed by a\nlarger allocation can still satisfy that check while extending into the\nclone's required shared-info area. When such a clone is converted back\ninto an skb, build_skb_around() places skb_shared_info over live packet\nbytes and later writes can corrupt XDP return metadata.\n\nReject clones unless their linear area fits inside\nSKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already\nenforced by the XDP-to-skb conversion path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74616","epss":0.00513,"percentile":0.42033,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74616","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74620","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74620","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: act_gact, act_police: range check the fallback control action  tcf_action_check_ctrlact() range checks the primary control action:  \tif (!opcode) \t\tret = action > TC_ACT_VALUE_MAX ? -EINVAL : 0;  TC_ACT_VALUE_MAX is TC_ACT_TRAP, so kernel-internal verdicts above it cannot be set that way. But act_gact and act_police each carry a second, independent control action supplied by user space that never reaches that helper - TCA_GACT_PROB.paction and TCA_POLICE_RESULT. Both only reject TC_ACT_GOTO_CHAIN, so any other value is stored verbatim and returned verbatim from the action.  In particular user space can store TC_ACT_CONSUMED, which is TC_ACT_VALUE_MAX + 1 and is deliberately not part of the UAPI value range. That verdict tells every caller the action took ownership of the skb, so nobody frees it: sch_handle_ingress(), sch_handle_egress() and tcf_qevent_handle() all deliberately skip the free for it. The result is one leaked sk_buff plus its data buffer per packet traversing the filter, unbounded, for all traffic on the chain including kernel-generated packets.  Both are trivially deterministic. act_gact clamps tcfg_pval to >= 1, so with pval = 1 gact_determ() returns the fallback for every packet. act_police has no mandatory rate, so rate = 0 leaves tcfp_mtu = ~0 and tcf_police_mtu_check() always passes.  TC_ACT_CONSUMED was added by commit 720f22fed81b (\"net: sched: refactor reinsert action\"), after both goto-chain guards were written: commit 9469f375ab09 (\"net/sched: act_gact: disallow 'goto chain' on fallback control action\") and commit c08f5ed5d625 (\"net/sched: act_police: disallow 'goto chain' on fallback control action\"). Neither guard was widened when the new verdict appeared.  Factor the existing range test out of tcf_action_check_ctrlact() as tcf_action_valid() and apply it to both fallbacks. The helper cannot call tcf_action_check_ctrlact() directly because that also allocates a goto_chain, which is exactly what these two sites must not do.  Reproduced on v7.2-rc6: kmemleak reports one leaked 232-byte skbuff_head_cache object plus its 704-byte data buffer per packet. With this patch both configurations are rejected with -EINVAL and kmemleak reports none.","cvss":[],"epss":[{"cve":"CVE-2026-74620","epss":0.00177,"percentile":0.07338,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74620","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74620","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2e8df8c9190335475a3b64a159d3efd8cdd1cb73","https://git.kernel.org/stable/c/5344e01179baa37547ab29fd7b8614f83faa190c","https://git.kernel.org/stable/c/5f038affdacaffedf6a85a06cf59ec0a852d36a7","https://git.kernel.org/stable/c/6bcb8839aa2d686964a4154650afc4db91e1c514","https://git.kernel.org/stable/c/725efc2ab4a40affc4e285a2dc4896d103948a6c","https://git.kernel.org/stable/c/883b56ae58fe657d8497806c7059646e9ba6dbd0","https://git.kernel.org/stable/c/92f00f1d4d204a428b38e26fce3baee144b6955d","https://git.kernel.org/stable/c/efa58aeb6a99028b1fbc3ab2f31ba3a881211ad4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_gact, act_police: range check the fallback control action\n\ntcf_action_check_ctrlact() range checks the primary control action:\n\n\tif (!opcode)\n\t\tret = action > TC_ACT_VALUE_MAX ? -EINVAL : 0;\n\nTC_ACT_VALUE_MAX is TC_ACT_TRAP, so kernel-internal verdicts above it\ncannot be set that way. But act_gact and act_police each carry a second,\nindependent control action supplied by user space that never reaches that\nhelper - TCA_GACT_PROB.paction and TCA_POLICE_RESULT. Both only reject\nTC_ACT_GOTO_CHAIN, so any other value is stored verbatim and returned\nverbatim from the action.\n\nIn particular user space can store TC_ACT_CONSUMED, which is\nTC_ACT_VALUE_MAX + 1 and is deliberately not part of the UAPI value\nrange. That verdict tells every caller the action took ownership of the\nskb, so nobody frees it: sch_handle_ingress(), sch_handle_egress() and\ntcf_qevent_handle() all deliberately skip the free for it. The result is\none leaked sk_buff plus its data buffer per packet traversing the filter,\nunbounded, for all traffic on the chain including kernel-generated\npackets.\n\nBoth are trivially deterministic. act_gact clamps tcfg_pval to >= 1, so\nwith pval = 1 gact_determ() returns the fallback for every packet.\nact_police has no mandatory rate, so rate = 0 leaves tcfp_mtu = ~0 and\ntcf_police_mtu_check() always passes.\n\nTC_ACT_CONSUMED was added by commit 720f22fed81b (\"net: sched: refactor\nreinsert action\"), after both goto-chain guards were written:\ncommit 9469f375ab09 (\"net/sched: act_gact: disallow 'goto chain' on\nfallback control action\") and\ncommit c08f5ed5d625 (\"net/sched: act_police: disallow 'goto chain' on\nfallback control action\"). Neither guard was widened when the new\nverdict appeared.\n\nFactor the existing range test out of tcf_action_check_ctrlact() as\ntcf_action_valid() and apply it to both fallbacks. The helper cannot call\ntcf_action_check_ctrlact() directly because that also allocates a\ngoto_chain, which is exactly what these two sites must not do.\n\nReproduced on v7.2-rc6: kmemleak reports one leaked 232-byte\nskbuff_head_cache object plus its 704-byte data buffer per packet. With\nthis patch both configurations are rejected with -EINVAL and kmemleak\nreports none.","cvss":[],"epss":[{"cve":"CVE-2026-74620","epss":0.00177,"percentile":0.07338,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74620","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74621","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74621","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: act_ct: fix sk_buff leak when the header checks reject a packet  tcf_ct_handle_fragments() runs its header sanity checks before handing anything to the defragmentation engine:  \tif (family == NFPROTO_IPV4) \t\terr = tcf_ct_ipv4_is_fragment(skb, &frag); \telse \t\terr = tcf_ct_ipv6_is_fragment(skb, &frag); \tif (err || !frag) \t\treturn err;  tcf_ct_ipv4_is_fragment() returns -EINVAL or -ENOMEM; tcf_ct_ipv6_is_fragment() adds -EPROTO when ipv6_find_hdr() fails. None of them frees or queues the skb, so on that path the caller still owns it.  tcf_ct_act() however funnels every non-zero return into the ownership-transfer exit:  \terr = tcf_ct_handle_fragments(net, skb, family, p->zone, &defrag); \tif (err) \t\tgoto out_frag; \t... out_frag: \tif (err != -EINPROGRESS) \t\ttcf_action_inc_drop_qstats(&c->common); \treturn TC_ACT_CONSUMED;  TC_ACT_CONSUMED means the action took ownership of the skb, so no caller frees it - sch_handle_ingress(), sch_handle_egress() and tcf_qevent_handle() all deliberately skip the free for that verdict. The skb is therefore orphaned: one sk_buff plus its data buffer is leaked per malformed packet, unbounded. Note the drop counter is already incremented for these errors, so the statistics claim a drop that never happens.  Three different ownership states reach out_frag: today - the skb may be queued by the defrag engine (-EINPROGRESS), already freed by nf_ct_handle_fragments(), or still owned by us. Tell the caller which of those it is, and free the packet ourselves in the last case, which restores the TC_ACT_SHOT behaviour that predated the Fixes: commit.  Reproduced on v7.2-rc6 with a 54-byte frame carrying a 40-byte IPv6 header with nexthdr = 0 (hop-by-hop) and nothing after it, on a clsact ingress chain with \"action ct\". kmemleak reports one leaked 232-byte skbuff_head_cache object plus its 704-byte data buffer per packet; with this patch it reports none.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74621","epss":0.0049,"percentile":0.4056,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3675},"relatedVulnerabilities":[{"id":"CVE-2026-74621","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74621","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/23e97d594ddd0153020c506d5041048fbde1beb4","https://git.kernel.org/stable/c/439d3e404f9d5e515911cc8132cde198b337c19e","https://git.kernel.org/stable/c/47d99828591d0fe8be4b9c8992ff3b8e47968db9","https://git.kernel.org/stable/c/737873a59905a54ca0d2d127ef882f3f88bf4379","https://git.kernel.org/stable/c/8a7ed561671aa6a911a2de99e59ef670a4d0b1df","https://git.kernel.org/stable/c/b47bb899e04b5407c5a63fe88d4b6676586a6e84","https://git.kernel.org/stable/c/b5dbecc2016e1692fd1c2532af9c41ba729cb747"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix sk_buff leak when the header checks reject a packet\n\ntcf_ct_handle_fragments() runs its header sanity checks before handing\nanything to the defragmentation engine:\n\n\tif (family == NFPROTO_IPV4)\n\t\terr = tcf_ct_ipv4_is_fragment(skb, &frag);\n\telse\n\t\terr = tcf_ct_ipv6_is_fragment(skb, &frag);\n\tif (err || !frag)\n\t\treturn err;\n\ntcf_ct_ipv4_is_fragment() returns -EINVAL or -ENOMEM;\ntcf_ct_ipv6_is_fragment() adds -EPROTO when ipv6_find_hdr() fails. None of\nthem frees or queues the skb, so on that path the caller still owns it.\n\ntcf_ct_act() however funnels every non-zero return into the\nownership-transfer exit:\n\n\terr = tcf_ct_handle_fragments(net, skb, family, p->zone, &defrag);\n\tif (err)\n\t\tgoto out_frag;\n\t...\nout_frag:\n\tif (err != -EINPROGRESS)\n\t\ttcf_action_inc_drop_qstats(&c->common);\n\treturn TC_ACT_CONSUMED;\n\nTC_ACT_CONSUMED means the action took ownership of the skb, so no caller\nfrees it - sch_handle_ingress(), sch_handle_egress() and\ntcf_qevent_handle() all deliberately skip the free for that verdict. The\nskb is therefore orphaned: one sk_buff plus its data buffer is leaked per\nmalformed packet, unbounded. Note the drop counter is already incremented\nfor these errors, so the statistics claim a drop that never happens.\n\nThree different ownership states reach out_frag: today - the skb may be\nqueued by the defrag engine (-EINPROGRESS), already freed by\nnf_ct_handle_fragments(), or still owned by us. Tell the caller which of\nthose it is, and free the packet ourselves in the last case, which\nrestores the TC_ACT_SHOT behaviour that predated the Fixes: commit.\n\nReproduced on v7.2-rc6 with a 54-byte frame carrying a 40-byte IPv6\nheader with nexthdr = 0 (hop-by-hop) and nothing after it, on a\nclsact ingress chain with \"action ct\". kmemleak reports one leaked\n232-byte skbuff_head_cache object plus its 704-byte data buffer per\npacket; with this patch it reports none.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74621","epss":0.0049,"percentile":0.4056,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74621","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74622","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74622","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: atlantic: free RX pages of consumed but not refilled buffers  aq_ring_rx_deinit() only walks [sw_head, sw_tail), the region posted to hardware. Since the page reuse strategy was added, a cleaned RX buffer keeps its page (and its DMA mapping) in the ring for reuse, and refill is batched: aq_ring_rx_fill() returns early until AQ_CFG_RX_REFILL_THRES slots are free. Slots that were consumed but not yet reposted therefore sit in the complementary [sw_tail, sw_head) gap with a live page, and the deinit walk never visits them: up to a refill batch worth of pages and DMA mappings leak on every interface down.  Walk the whole ring instead and release whatever is still there. Also bail out if the buffer ring is already gone: a partial aq_ptp_ring_alloc() failure frees the ring but leaves aq_nic set, so aq_ptp_ring_deinit() still gets here on the unwind path.","cvss":[],"epss":[{"cve":"CVE-2026-74622","epss":0.00177,"percentile":0.07332,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74622","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74622","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/17c99dd86f169c7a3e73d6778e79ef5b1ed3ceac","https://git.kernel.org/stable/c/1e58b0bab40dcbdfc04acaba6a221d40801c3770","https://git.kernel.org/stable/c/24d87dc28ddd3771dd0e88719209811809729439","https://git.kernel.org/stable/c/30c473ea097ef0c93b064281b3e295c97d17e28b","https://git.kernel.org/stable/c/64e1346bc66b947eb80b848e4c8d9828ba50e0fe","https://git.kernel.org/stable/c/782cc40b7ade4614a8aec0b948b8cf95c69f8d4b","https://git.kernel.org/stable/c/e8e7471ef686b6c002218fee9671cc61992ae01a","https://git.kernel.org/stable/c/ff451bc4290b79c04f1c5cfa928d448f9d47ecf5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: free RX pages of consumed but not refilled buffers\n\naq_ring_rx_deinit() only walks [sw_head, sw_tail), the region posted to\nhardware. Since the page reuse strategy was added, a cleaned RX buffer\nkeeps its page (and its DMA mapping) in the ring for reuse, and refill\nis batched: aq_ring_rx_fill() returns early until AQ_CFG_RX_REFILL_THRES\nslots are free. Slots that were consumed but not yet reposted therefore\nsit in the complementary [sw_tail, sw_head) gap with a live page, and\nthe deinit walk never visits them: up to a refill batch worth of pages\nand DMA mappings leak on every interface down.\n\nWalk the whole ring instead and release whatever is still there. Also\nbail out if the buffer ring is already gone: a partial\naq_ptp_ring_alloc() failure frees the ring but leaves aq_nic set, so\naq_ptp_ring_deinit() still gets here on the unwind path.","cvss":[],"epss":[{"cve":"CVE-2026-74622","epss":0.00177,"percentile":0.07332,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74622","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74623","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74623","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: atlantic: free stranded TX buffers on ring deinit  aq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean() call, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and stops at hw_head, which no longer moves once aq_vec_stop() has stopped the hardware and NAPI. Completed descriptors beyond the budget and everything still posted in [hw_head, sw_tail) keep their skb or xdp_frame when the interface goes down: aq_vec_ring_free() then frees the buffer ring and the references are lost for good.  Today this is a silent memory leak on every interface down under TX/XDP_TX load. With the conversion of the RX path to page_pool posted for net-next it becomes much more visible: XDP_TX frames carry fragment references on the RX ring's page_pool, so a single stranded frame keeps the pool's inflight count above zero forever. page_pool_destroy() then never completes, the pool is leaked together with its pages, and \"page_pool_release_retry() stalled pool shutdown\" is warned every 60 seconds from that point on, on every ifdown, XDP detach or ring resize under XDP_TX load.  Bring back aq_ring_tx_deinit() as it was before the removal and use it for teardown again, with one extension: TX rings can hold xdp_frames nowadays, so release those too. They are returned with xdp_return_frame() since this runs in process context.","cvss":[],"epss":[{"cve":"CVE-2026-74623","epss":0.00177,"percentile":0.0733,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74623","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74623","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/307d80193b4a4a75b8dc4e0d3162be3755abbed7","https://git.kernel.org/stable/c/3447641d361dcc5511841d986ad4d849b2900d9b","https://git.kernel.org/stable/c/452636ea5410a96e02ebaaf80b21e3620b98e0dd","https://git.kernel.org/stable/c/4f1c20873f70b4b22ef86dc38dad1fda8e169bcd","https://git.kernel.org/stable/c/7a3e1481f4ee6c581bccc6bfc6c970aac5be7b0c","https://git.kernel.org/stable/c/a14ceebd13bf857bfca052bc5a6bd49e737912be","https://git.kernel.org/stable/c/b13202d401e1a20fec89b0cda733dcbaf279f79d","https://git.kernel.org/stable/c/dd633280de7fdfd60dc4fcf63d04e2ad95b43269"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: free stranded TX buffers on ring deinit\n\naq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean()\ncall, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and\nstops at hw_head, which no longer moves once aq_vec_stop() has stopped\nthe hardware and NAPI. Completed descriptors beyond the budget and\neverything still posted in [hw_head, sw_tail) keep their skb or\nxdp_frame when the interface goes down: aq_vec_ring_free() then frees\nthe buffer ring and the references are lost for good.\n\nToday this is a silent memory leak on every interface down under\nTX/XDP_TX load. With the conversion of the RX path to page_pool posted\nfor net-next it becomes much more visible: XDP_TX frames carry fragment\nreferences on the RX ring's page_pool, so a single stranded frame keeps\nthe pool's inflight count above zero forever. page_pool_destroy() then\nnever completes, the pool is leaked together with its pages, and\n\"page_pool_release_retry() stalled pool shutdown\" is warned every 60\nseconds from that point on, on every ifdown, XDP detach or ring resize\nunder XDP_TX load.\n\nBring back aq_ring_tx_deinit() as it was before the removal and use it\nfor teardown again, with one extension: TX rings can hold xdp_frames\nnowadays, so release those too. They are returned with\nxdp_return_frame() since this runs in process context.","cvss":[],"epss":[{"cve":"CVE-2026-74623","epss":0.00177,"percentile":0.0733,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74623","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74624","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74624","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack: defer invalid log until after unlock  TCP and SCTP conntrack paths can emit invalid-packet logs while ct->lock is still held.  When invalid logging is routed to nfnetlink_log and conntrack export is enabled, the log path can re-enter conntrack netlink glue and dump the same conntrack again. Protocol attribute dumping may take ct->lock, so logging while holding that lock can deadlock.  Defer the TCP invalid logs by storing only the minimal log context while ct->lock is held and emitting the log after unlocking. Also make the TCP timeout-lowering invalid path return whether a log is needed, then emit that log after unlocking.  Do the same for the SCTP invalid state-transition log that can be reached while ct->lock is held.  Add a lockdep assertion to nf_ct_l4proto_log_invalid() so future callers that log invalid conntracks while holding ct->lock are caught outside TCP and SCTP as well.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74624","epss":0.00479,"percentile":0.39832,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.35925},"relatedVulnerabilities":[{"id":"CVE-2026-74624","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74624","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0424186d570aa4d1ad17f516afb86bd9eaa4f42e","https://git.kernel.org/stable/c/2d19b95c9723001f214f7a47d67b09f46238f200","https://git.kernel.org/stable/c/63853eb20bba4e00b7cd0b8cfc19337bbaaf5037","https://git.kernel.org/stable/c/9480fcf70a5aa9d320088a01c95df0e5e6391f4a","https://git.kernel.org/stable/c/c0224327b7cbed9d3198e8dbec847281053dcd06","https://git.kernel.org/stable/c/ca97360eba4b3dc67f1804625542f4ccc774242a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack: defer invalid log until after unlock\n\nTCP and SCTP conntrack paths can emit invalid-packet logs while ct->lock\nis still held.\n\nWhen invalid logging is routed to nfnetlink_log and conntrack export is\nenabled, the log path can re-enter conntrack netlink glue and dump the\nsame conntrack again. Protocol attribute dumping may take ct->lock, so\nlogging while holding that lock can deadlock.\n\nDefer the TCP invalid logs by storing only the minimal log context while\nct->lock is held and emitting the log after unlocking. Also make the TCP\ntimeout-lowering invalid path return whether a log is needed, then emit\nthat log after unlocking.\n\nDo the same for the SCTP invalid state-transition log that can be reached\nwhile ct->lock is held.\n\nAdd a lockdep assertion to nf_ct_l4proto_log_invalid() so future callers\nthat log invalid conntracks while holding ct->lock are caught outside TCP\nand SCTP as well.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74624","epss":0.00479,"percentile":0.39832,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74624","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74625","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74625","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: bridge: release template ct on non-IP path  A bridge nftables ct zone set rule can attach a conntrack template to an skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6 EtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with IP_CT_UNTRACKED without releasing the existing template reference.  That makes the per-cpu template, and any temporary templates allocated for concurrent use, unreachable and leaks memory until the host runs out of slab.  Reset the skb conntrack state before marking the frame untracked so the existing template reference is dropped on the non-IP path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74625","epss":0.00501,"percentile":0.41264,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37575},"relatedVulnerabilities":[{"id":"CVE-2026-74625","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74625","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd","https://git.kernel.org/stable/c/6ea88401e10e04e0b3bb7a7adea54932fb60b93b","https://git.kernel.org/stable/c/7cff440d702616022769f2643168d7f9820547a0","https://git.kernel.org/stable/c/bd7b16494dacf87e9336a1dcfdada83b9e40edd6","https://git.kernel.org/stable/c/c58d34fe8b7e47bb0b350a7625023b1261342be5","https://git.kernel.org/stable/c/d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f","https://git.kernel.org/stable/c/daa6e070f8e1e7a4dddec8b64ca37663f8cda917","https://git.kernel.org/stable/c/fc90df37540627d092af770215fb4b7befe9409b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: release template ct on non-IP path\n\nA bridge nftables ct zone set rule can attach a conntrack template to\nan skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6\nEtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with\nIP_CT_UNTRACKED without releasing the existing template reference.\n\nThat makes the per-cpu template, and any temporary templates allocated\nfor concurrent use, unreachable and leaks memory until the host runs out\nof slab.\n\nReset the skb conntrack state before marking the frame untracked so the\nexisting template reference is dropped on the non-IP path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74625","epss":0.00501,"percentile":0.41264,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74625","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74626","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74626","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  NTB: ntb_netdev: Preserve RX queue depth on allocation failure  ntb_netdev_rx_handler() hands the received skb to the network stack before allocating its replacement. If the allocation fails, nothing is reposted. Every failure therefore takes one buffer out of the RX queue while the interface remains up, and enough failures eventually stall reception.  A retry path could refill the queue later, but ntb_netdev has none. Allocate the replacement first instead. If that fails, drop the packet and repost the same skb. This keeps the queue full and lets packet delivery resume as soon as memory is available again.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74626","epss":0.00501,"percentile":0.41263,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37575},"relatedVulnerabilities":[{"id":"CVE-2026-74626","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74626","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/18781cc0bfb5c7f2a51ac6d678a28f101b7c35c5","https://git.kernel.org/stable/c/272df0fbe6f3e04e22bc67fbdd9ac24586b942f4","https://git.kernel.org/stable/c/3f2a15f33f86f7bd5b920669fd40c06725d72a1e","https://git.kernel.org/stable/c/6d7f8a23c130d768c0976c2578b214353674e18f","https://git.kernel.org/stable/c/755fd7843f300d724caceabdf9bb13adc8701540","https://git.kernel.org/stable/c/a4e340971fe8ccd245d206db4d43b2a0eec240bd","https://git.kernel.org/stable/c/d2121faf133ac3bf9531b53a7e21273649a08517","https://git.kernel.org/stable/c/fcaf8ba7e56bb73319ac107a63b907d59536192c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_netdev: Preserve RX queue depth on allocation failure\n\nntb_netdev_rx_handler() hands the received skb to the network stack\nbefore allocating its replacement. If the allocation fails, nothing is\nreposted. Every failure therefore takes one buffer out of the RX queue\nwhile the interface remains up, and enough failures eventually stall\nreception.\n\nA retry path could refill the queue later, but ntb_netdev has none.\nAllocate the replacement first instead. If that fails, drop the packet\nand repost the same skb. This keeps the queue full and lets packet\ndelivery resume as soon as memory is available again.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74626","epss":0.00501,"percentile":0.41263,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74626","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74628","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74628","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/x25: fix use-after-free of the socket by its timers  The x25 timers are armed with mod_timer() and cancelled with timer_delete(), so a pending timer holds no reference on the socket and a cancel does not wait for a callback already running on another CPU.  x25_heartbeat_expiry() also rearms unconditionally, so it can reinstall sk->sk_timer after __x25_destroy_socket() has passed its cancel point. The following __sock_put() frees the socket while the timer is still queued, and the next expiry uses freed memory.  KASAN reports a slab-use-after-free on the kmalloc-2k object freed by close().  timer_delete_sync() cannot be used here: x25_heartbeat_expiry() and x25_timer_expiry() both reach the cancels from inside the timer they would wait on, through __x25_destroy_socket() and x25_disconnect().  Arm the timers with sk_reset_timer() and cancel them with sk_stop_timer() so that an armed timer owns a reference, and release it in both expiry handlers.  Rearm the heartbeat only while sk_hashed(sk) is still true, since __x25_destroy_socket() unlinks the socket before dropping it.  Arm the deferred destroy timer the same way and drop its reference in x25_destroy_timer().  Reproduced on net with KASAN, with the heartbeat period shortened so the window recurs.  With this patch the reproducer no longer triggers a report and /proc/net/x25 drains.  Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74628","epss":0.005,"percentile":0.41182,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47000000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74628","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74628","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1fc9f6d2c7c9fdb341bfe8ca449c990632299ea6","https://git.kernel.org/stable/c/2195424c3da2ef1829a63b807e3a900a90e57d85","https://git.kernel.org/stable/c/3c4919be5d910db4beebca420953858606fba7d8","https://git.kernel.org/stable/c/4bc522b33438fefc3272840ae5988771863a4f1f","https://git.kernel.org/stable/c/6b79659590f0f82a9b8efd2ffd55ec6399ebfc33","https://git.kernel.org/stable/c/ba925a2e98ce967a0e71c5bcbcf5dbd3facaf0c8","https://git.kernel.org/stable/c/e92c7e2b41d1528a830bc64c5e4e46dfa8133dda","https://git.kernel.org/stable/c/fdd9ac50b9b61ef2b2d52c5156aff788be91454d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/x25: fix use-after-free of the socket by its timers\n\nThe x25 timers are armed with mod_timer() and cancelled with\ntimer_delete(), so a pending timer holds no reference on the socket and a\ncancel does not wait for a callback already running on another CPU.\n\nx25_heartbeat_expiry() also rearms unconditionally, so it can reinstall\nsk->sk_timer after __x25_destroy_socket() has passed its cancel point.\nThe following __sock_put() frees the socket while the timer is still\nqueued, and the next expiry uses freed memory.  KASAN reports a\nslab-use-after-free on the kmalloc-2k object freed by close().\n\ntimer_delete_sync() cannot be used here: x25_heartbeat_expiry() and\nx25_timer_expiry() both reach the cancels from inside the timer they\nwould wait on, through __x25_destroy_socket() and x25_disconnect().\n\nArm the timers with sk_reset_timer() and cancel them with sk_stop_timer()\nso that an armed timer owns a reference, and release it in both expiry\nhandlers.  Rearm the heartbeat only while sk_hashed(sk) is still true,\nsince __x25_destroy_socket() unlinks the socket before dropping it.  Arm\nthe deferred destroy timer the same way and drop its reference in\nx25_destroy_timer().\n\nReproduced on net with KASAN, with the heartbeat period shortened so the\nwindow recurs.  With this patch the reproducer no longer triggers a\nreport and /proc/net/x25 drains.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74628","epss":0.005,"percentile":0.41182,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74628","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74630","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74630","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: prevent in6_dev_get() from resurrecting inet6_dev  in6_dev_get() reads dev->ip6_ptr under RCU and then unconditionally increments its refcount. Device teardown can clear the pointer and drop the last reference between these operations. The increment then resurrects an object whose RCU free has already been queued, so callers can use it after it is freed.  Use refcount_inc_not_zero() and return NULL when the object has already reached zero. RCU keeps the memory accessible through the attempted reference acquisition, and a successful increment pins the object for the caller.  An independent run on the exact unpatched 6f5156d7a31a (v7.2-rc3) kernel reproduced the invalid reference acquisition as UID 1000:    refcount_t: addition on 0; use-after-free.   ip6_mc_source+0xef4/0x17e0  It was followed by the corresponding reference underflow in ip6_mc_source(). The supplied trace from the same unpatched revision additionally shows the access after the RCU read-side section ends:    BUG: KASAN: slab-use-after-free in mutex_lock+0x76/0xe0   Write of size 8 at addr ffff888015b50240 by task poc/1219  Bug found and triaged by OpenAI Security Research and validated by Trail of Bits.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74630","epss":0.00128,"percentile":0.02794,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09792000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-74630","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74630","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0e243671bc7b8eaf00f83dd2f4367436dc0cff98","https://git.kernel.org/stable/c/145812b678de9f3b59780173be3c0d22ed60dd93","https://git.kernel.org/stable/c/14e812ab41df0cac033479da835ec9a5de633404","https://git.kernel.org/stable/c/1c206d461c680c3151daa3c89fc26eaf5bf98a7f","https://git.kernel.org/stable/c/680fbd7942185448eadb990a3d10a53eb946b702","https://git.kernel.org/stable/c/785d908f8d21c8bc78b6fb2c2932ab662bf6918a","https://git.kernel.org/stable/c/aedcfefdb5b7ed7f8a6196a3e68a25bdbe51d2f8","https://git.kernel.org/stable/c/cc5bd568f9b7683e60841b6fd02c10d64535bd6e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent in6_dev_get() from resurrecting inet6_dev\n\nin6_dev_get() reads dev->ip6_ptr under RCU and then unconditionally\nincrements its refcount. Device teardown can clear the pointer and drop\nthe last reference between these operations. The increment then\nresurrects an object whose RCU free has already been queued, so callers\ncan use it after it is freed.\n\nUse refcount_inc_not_zero() and return NULL when the object has already\nreached zero. RCU keeps the memory accessible through the attempted\nreference acquisition, and a successful increment pins the object for\nthe caller.\n\nAn independent run on the exact unpatched 6f5156d7a31a (v7.2-rc3)\nkernel reproduced the invalid reference acquisition as UID 1000:\n\n  refcount_t: addition on 0; use-after-free.\n  ip6_mc_source+0xef4/0x17e0\n\nIt was followed by the corresponding reference underflow in\nip6_mc_source(). The supplied trace from the same unpatched revision\nadditionally shows the access after the RCU read-side section ends:\n\n  BUG: KASAN: slab-use-after-free in mutex_lock+0x76/0xe0\n  Write of size 8 at addr ffff888015b50240 by task poc/1219\n\nBug found and triaged by OpenAI Security Research and\nvalidated by Trail of Bits.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74630","epss":0.00128,"percentile":0.02794,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74630","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74631","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74631","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: smc: fix splice entry lifetime imbalance in smc_rx_splice  smc_rx_splice() passes pages to splice_to_pipe() before taking the references that cover the lifetime of each splice entry. In the VM-backed RMB path, splice_to_pipe() may drop unqueued entries through smc_rx_spd_release(), while queued entries are released later via the pipe buffer callback.  The old post-splice accounting also derives the number of queued VM pages from an offset mutated while building the descriptor, and a multi-page splice pairs one sock_hold() with multiple sock_put() calls.  Take the page and socket references for every candidate entry before splice_to_pipe(), and drop the matching private state, page reference, and socket reference from smc_rx_spd_release() for entries that never get queued. This fixes a refcount imbalance that can underflow page refcounts and trigger a use-after-free.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74631","epss":0.00138,"percentile":0.03491,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10970999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74631","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74631","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/07ad246529d136d5ef441d5ab4c305d132ff3090","https://git.kernel.org/stable/c/0b7d54cedea5cb158e21925ae0c6c2f5c87ed2a0","https://git.kernel.org/stable/c/4515c78f4d9fd577270f012efeb062ea58b3682d","https://git.kernel.org/stable/c/5d9686af2976741bbd79b150d1c9e60b81e7f12e","https://git.kernel.org/stable/c/7ddc7af2ae7fc5a0c0635b245c0824c8b76de5cb","https://git.kernel.org/stable/c/af02c67ce654356c58db20a0bb2db33ace3b07a8","https://git.kernel.org/stable/c/c841789e456ec6751342fa800639ce8e82ff0e6b","https://git.kernel.org/stable/c/ca8342b5fc24c249fdb998468f6a168b457c67e5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: smc: fix splice entry lifetime imbalance in smc_rx_splice\n\nsmc_rx_splice() passes pages to splice_to_pipe() before taking the\nreferences that cover the lifetime of each splice entry. In the\nVM-backed RMB path, splice_to_pipe() may drop unqueued entries through\nsmc_rx_spd_release(), while queued entries are released later via the\npipe buffer callback.\n\nThe old post-splice accounting also derives the number of queued VM pages\nfrom an offset mutated while building the descriptor, and a multi-page\nsplice pairs one sock_hold() with multiple sock_put() calls.\n\nTake the page and socket references for every candidate entry before\nsplice_to_pipe(), and drop the matching private state, page reference,\nand socket reference from smc_rx_spd_release() for entries that never\nget queued. This fixes a refcount imbalance that can underflow page\nrefcounts and trigger a use-after-free.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74631","epss":0.00138,"percentile":0.03491,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74631","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74632","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74632","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/huge_memory: fix huge_zero_pfn race  Patch series \"mm/huge_memory: fix huge_zero_pfn race\", v2.  There is a subtle race in the reference-counted huge_zero_folio implementation.  The fast path atomic logic fails to account for the fact that the shrinker (which drops the final huge_zero_refcount pin) can overwrite huge_zero_pfn with the ~0UL sentinel value in shrink_huge_zero_folio_scan() after a racing get_huge_zero_folio() installed a valid value there.  This results in huge_zero_folio being correctly set but huge_zero_pfn being set incorrectly and thus is_huge_zero_pfn() and consequently is_huge_zero_pmd() will misidentify the huge zero folio as being an ordinary THP folio.  This can result in the huge zero folio being split and otherwise treated incorrectly.  The solution to this is very subtle as there is an atomic fast path, and thus ordering in weakly ordered architectures has to be treated very carefully.  The first commit fixes the issue by introducing a spinlock around huge_zero_[pfn, folio, refcount] write, with careful consideration paid to load/store ordering in the fast path.  It is placed first and kept as small as possible so that it can be backported on its own.  The second commit is a pure cleanup which reworks the CONFIG_PERSISTENT_HUGE_ZERO_FOLIO logic to better separate the persistent logic from the dynamically allocated one.   This patch (of 2):  If !CONFIG_PERSISTENT_HUGE_ZERO_FOLIO, the huge_zero_folio is refcounted by huge_zero_refcount and returned by mm_get_huge_zero_folio().  When the caller is done with the huge zero page, its reference count is decremented.  Only a shrinker can set the reference count to zero.  A race can unfortunately occur between a shrinker decrementing the reference count to zero and a concurrent page fault.  This is because shrink_huge_zero_folio_scan() might, if very unlucky, be preempted between setting huge_zero_refcount to zero and writing an invalid value.  During this time get_huge_zero_folio() could write to huge_zero_pfn before shrink_huge_zero_folio_scan() resumes.  In this event the huge zero folio will be persistently misidentified causing the THP code path to be entered inappropriately for the huge zero folio:                  CPU 0                                   CPU 1 =======================================|================================= shrink_huge_zero_folio_scan()          |    atomic_cmpxchg() sets refcount to 0 |    xchg() sets huge_zero_folio to NULL | get_huge_zero_folio()                  |                     |    atomic_inc_not_zero() -> zero       preempted for a long time        |    Allocate new huge zero folio                  |                     |    Write valid huge_zero_folio                  v                     |    Write valid huge_zero_pfn   Overwrite huge_zero_pfn with ~0UL   <--- Invalid overwrite!  This results in is_huge_zero_pfn() and is_huge_zero_pmd() incorrectly returning false for a huge zero page which could result in issues like the huge zero folio being incorrectly split.  Note that the issue is with huge_zero_pfn not huge_zero_folio, as get_huge_zero_folio() uses cmpxchg() gated on huge_zero_folio being NULL with a retry loop and shrink_huge_zero_folio_scan() uses xchg() to set huge_zero_folio.  Fix the issue by introducing a spinlock, huge_zero_lock, to prevent concurrent write of huge_zero_folio, huge_zero_pfn and huge_zero_refcount.  There needs to be significant care taken here to ensure correctness:  The fast path in get_huge_zero_folio() uses atomic_inc_not_zero(), which is outside of the critical section, and means huge zero allocation is gated on zero huge_zero_refcount.  The fast path doesn't use huge_zero_lock, so the critical section is irrelevant to it.  So invariants are required - huge_zero_refcount MUST:  * Only be set in the huge_zero_lock critical section to ensure   serialisation of huge_zero_pfn, huge_zero_folio and ---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74632","epss":0.00129,"percentile":0.02893,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74632","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74632","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/105d04edbec83010df5728f74d17fd9c108e7553","https://git.kernel.org/stable/c/33192a26cddea7a7e4ca66e5c3eebd36fa8be2bb","https://git.kernel.org/stable/c/6024f6d0d9b9ca5138bfc4ac6f6e4bdf616e42b3","https://git.kernel.org/stable/c/9332b080ad57650d1dc582e54517f9fc78ef89cc","https://git.kernel.org/stable/c/9c0fd1802ce06d7709f0bae4edeb085288f28764","https://git.kernel.org/stable/c/ab7e4b407c7f58d1a003134eff3841f303d5ccc2","https://git.kernel.org/stable/c/b7041ba61c5da4e0b56f9be58cfb87d7689724e4","https://git.kernel.org/stable/c/f3a874a903053c53fb53ba287ea9eacda69c68e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: fix huge_zero_pfn race\n\nPatch series \"mm/huge_memory: fix huge_zero_pfn race\", v2.\n\nThere is a subtle race in the reference-counted huge_zero_folio\nimplementation.\n\nThe fast path atomic logic fails to account for the fact that the shrinker\n(which drops the final huge_zero_refcount pin) can overwrite huge_zero_pfn\nwith the ~0UL sentinel value in shrink_huge_zero_folio_scan() after a\nracing get_huge_zero_folio() installed a valid value there.\n\nThis results in huge_zero_folio being correctly set but huge_zero_pfn\nbeing set incorrectly and thus is_huge_zero_pfn() and consequently\nis_huge_zero_pmd() will misidentify the huge zero folio as being an\nordinary THP folio.\n\nThis can result in the huge zero folio being split and otherwise treated\nincorrectly.\n\nThe solution to this is very subtle as there is an atomic fast path, and\nthus ordering in weakly ordered architectures has to be treated very\ncarefully.\n\nThe first commit fixes the issue by introducing a spinlock around\nhuge_zero_[pfn, folio, refcount] write, with careful consideration paid to\nload/store ordering in the fast path.  It is placed first and kept as\nsmall as possible so that it can be backported on its own.\n\nThe second commit is a pure cleanup which reworks the\nCONFIG_PERSISTENT_HUGE_ZERO_FOLIO logic to better separate the persistent\nlogic from the dynamically allocated one.\n\n\nThis patch (of 2):\n\nIf !CONFIG_PERSISTENT_HUGE_ZERO_FOLIO, the huge_zero_folio is refcounted\nby huge_zero_refcount and returned by mm_get_huge_zero_folio().\n\nWhen the caller is done with the huge zero page, its reference count is\ndecremented.  Only a shrinker can set the reference count to zero.\n\nA race can unfortunately occur between a shrinker decrementing the\nreference count to zero and a concurrent page fault.\n\nThis is because shrink_huge_zero_folio_scan() might, if very unlucky, be\npreempted between setting huge_zero_refcount to zero and writing an\ninvalid value.\n\nDuring this time get_huge_zero_folio() could write to huge_zero_pfn before\nshrink_huge_zero_folio_scan() resumes.\n\nIn this event the huge zero folio will be persistently misidentified\ncausing the THP code path to be entered inappropriately for the huge zero\nfolio:\n\n                CPU 0                                   CPU 1\n=======================================|=================================\nshrink_huge_zero_folio_scan()          |\n   atomic_cmpxchg() sets refcount to 0 |\n   xchg() sets huge_zero_folio to NULL | get_huge_zero_folio()\n                 |                     |    atomic_inc_not_zero() -> zero\n      preempted for a long time        |    Allocate new huge zero folio\n                 |                     |    Write valid huge_zero_folio\n                 v                     |    Write valid huge_zero_pfn\n  Overwrite huge_zero_pfn with ~0UL   <--- Invalid overwrite!\n\nThis results in is_huge_zero_pfn() and is_huge_zero_pmd() incorrectly\nreturning false for a huge zero page which could result in issues like the\nhuge zero folio being incorrectly split.\n\nNote that the issue is with huge_zero_pfn not huge_zero_folio, as\nget_huge_zero_folio() uses cmpxchg() gated on huge_zero_folio being NULL\nwith a retry loop and shrink_huge_zero_folio_scan() uses xchg() to set\nhuge_zero_folio.\n\nFix the issue by introducing a spinlock, huge_zero_lock, to prevent\nconcurrent write of huge_zero_folio, huge_zero_pfn and huge_zero_refcount.\n\nThere needs to be significant care taken here to ensure correctness:\n\nThe fast path in get_huge_zero_folio() uses atomic_inc_not_zero(), which\nis outside of the critical section, and means huge zero allocation is\ngated on zero huge_zero_refcount.\n\nThe fast path doesn't use huge_zero_lock, so the critical section is\nirrelevant to it.\n\nSo invariants are required - huge_zero_refcount MUST:\n\n* Only be set in the huge_zero_lock critical section to ensure\n  serialisation of huge_zero_pfn, huge_zero_folio and\n---truncated---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74632","epss":0.00129,"percentile":0.02893,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74632","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74635","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74635","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: bitblit: bound-check glyph index in bit_cursor()  bit_cursor() fetches the glyph under the cursor with  \tc = scr_readw(vc_pos); \tsrc = vc_font.data + ((c & charmask) * w * height);  where charmask is 0x1ff when vc_hi_font_mask is set. The screen buffer value comes directly from scr_readw() and may be larger than the current font's glyph count.  Syzkaller triggers this via vcs_write(). The Call Trace shows vcs_write() in vc_screen.c writing an arbitrary 16-bit value with writev() to /dev/vcsa, which vcs_write_buf() in vc_screen.c stores via vcs_scr_writew() without checking charcount. The stored value is later read in bit_cursor() in bitblit.c.  When the font is changed from a font with 512 glyphs to a font with 256 glyphs, the screen buffer can retain characters with the high bit set from the previous mode, which could also produce the same out-of-bounds access.    BUG: KASAN: global-out-of-bounds in soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70   Read of size 16 at addr ffff800086c57970    Call Trace:    soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70    bit_cursor+0xa90/0x1108 drivers/video/fbdev/core/bitblit.c:365    fbcon_cursor+0x344/0x498 drivers/video/fbdev/core/fbcon.c:1427    hide_cursor+0xdc/0x2d0 drivers/tty/vt/vt.c:883    update_region+0x100/0x18c drivers/tty/vt/vt.c:669    vcs_write+0x8ec/0xaf0 drivers/tty/vt/vc_screen.c:685  bit_putcs_aligned() and bit_putcs_unaligned() already clamp the glyph index to vc_font.charcount. Apply the same clamp in bit_cursor() after extracting the attribute and masking, before indexing fontdata.  The fix completes the bounds checking started in commit 18c4ef4e765a (\"fbdev: bitblit: bound-check glyph index in bit_putcs*\"), which missed the cursor path.  This change should be safe because the clamp reuses the existing contract from fbcon: charcount is maintained under console_lock in con_font_set() and fbcon_font_set(), and hi_font_mask is cleared when switching from 512 to 256 glyphs. When stale screen data with high bits remains after a font switch, or when vcs_write() stores an arbitrary value, clamping the index to 0 prevents the out-of-bounds read without changing cursor semantics — the same fallback bit_putcs uses.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74635","epss":0.00129,"percentile":0.02893,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74635","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74635","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/250159ace2dc53c1bdad267aa8da51b638748700","https://git.kernel.org/stable/c/46336f476484f36145e5117e72d7b590f47433ee","https://git.kernel.org/stable/c/94134d70abf9273b70499d97d0adc9185ef21091","https://git.kernel.org/stable/c/9ea879862e66e354e616028c31b39aa3eb6d35d8","https://git.kernel.org/stable/c/bc9db0d879c655d5dfd8add32fd60f13e65d132c","https://git.kernel.org/stable/c/bf750cfeacf4e47ac72dadc7f05839696efb8576","https://git.kernel.org/stable/c/c1e7351767dd30fc574395c82121e4c67b882da3","https://git.kernel.org/stable/c/e033cbf3975a8465f879ebd5989dc35b04423a4d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: bitblit: bound-check glyph index in bit_cursor()\n\nbit_cursor() fetches the glyph under the cursor with\n\n\tc = scr_readw(vc_pos);\n\tsrc = vc_font.data + ((c & charmask) * w * height);\n\nwhere charmask is 0x1ff when vc_hi_font_mask is set. The screen buffer\nvalue comes directly from scr_readw() and may be larger than the current\nfont's glyph count.\n\nSyzkaller triggers this via vcs_write(). The Call Trace shows\nvcs_write() in vc_screen.c writing an arbitrary 16-bit value with\nwritev() to /dev/vcsa, which vcs_write_buf() in vc_screen.c stores via\nvcs_scr_writew() without checking charcount. The stored value is later\nread in bit_cursor() in bitblit.c.\n\nWhen the font is changed from a font with 512 glyphs to a font with\n256 glyphs, the screen buffer can retain characters with the high\nbit set from the previous mode, which could also produce the same\nout-of-bounds access.\n\n  BUG: KASAN: global-out-of-bounds in soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70\n  Read of size 16 at addr ffff800086c57970\n\n  Call Trace:\n   soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70\n   bit_cursor+0xa90/0x1108 drivers/video/fbdev/core/bitblit.c:365\n   fbcon_cursor+0x344/0x498 drivers/video/fbdev/core/fbcon.c:1427\n   hide_cursor+0xdc/0x2d0 drivers/tty/vt/vt.c:883\n   update_region+0x100/0x18c drivers/tty/vt/vt.c:669\n   vcs_write+0x8ec/0xaf0 drivers/tty/vt/vc_screen.c:685\n\nbit_putcs_aligned() and bit_putcs_unaligned() already clamp the glyph\nindex to vc_font.charcount. Apply the same clamp in bit_cursor() after\nextracting the attribute and masking, before indexing fontdata.\n\nThe fix completes the bounds checking started in commit 18c4ef4e765a\n(\"fbdev: bitblit: bound-check glyph index in bit_putcs*\"), which missed\nthe cursor path.\n\nThis change should be safe because the clamp reuses the existing\ncontract from fbcon: charcount is maintained under console_lock in\ncon_font_set() and fbcon_font_set(), and hi_font_mask is cleared when\nswitching from 512 to 256 glyphs. When stale screen data with high bits\nremains after a font switch, or when vcs_write() stores an arbitrary\nvalue, clamping the index to 0 prevents the out-of-bounds read without\nchanging cursor semantics — the same fallback bit_putcs uses.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74635","epss":0.00129,"percentile":0.02893,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74635","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74636","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74636","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing: Fix race between update_event_fields and, event_define_fields  The following sequence may leads race between event_define_fields() and update_event_fields():   CPU0 (loads module A)                      CPU1 (loads module B)  ===============================            ===============================  load_module(A)                             load_module(B)    notifier_call_chain                        notifier_call_chain      trace_module_notify                        trace_module_notify        mutex_lock(&event_mutex)                   trace_event_update_all()          trace_module_add_events(A)                 down_write(&trace_event_sem)             __register_event(call_A)               __add_event_to_tracers(call_A)                 event_define_fields(call_A)                   for each f:                         list_for_each_entry(field,                     list_add(&f->link,                                    &class->fields, link)                              &class->fields)            field = class->fields->next;  Where access to the class->fields is not protected by the event_mutex in trace_event_update_all().  This produces the following panic:    Unable to handle kernel access ... at virtual address 0000000000000018    pc : update_event_fields+0xf8/0x368    Call trace:     update_event_fields+0xf8/0x368     trace_event_update_all+0x7c/0x2b4     trace_module_notify+0x4c/0x1dc     notifier_call_chain+0x84/0x168     blocking_notifier_call_chain_robust+0x64/0xd4     load_module+0x10c8/0x123c     __arm64_sys_finit_module+0x230/0x31c  Fix by taking event_mutex in trace_event_update_all() before trace_event_sem.","cvss":[],"epss":[{"cve":"CVE-2026-74636","epss":0.00173,"percentile":0.06833,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74636","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74636","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4e39f7b4d9d36508c53e89e6cbc640728df870b5","https://git.kernel.org/stable/c/a30d421468300b1e7b2f233136aeb2db8013f555","https://git.kernel.org/stable/c/c3730b8373bb5059d735509b9e6a00d7eb337d7c","https://git.kernel.org/stable/c/e5f1d301b4bdaa4206db251fdc691f623162b0a8","https://git.kernel.org/stable/c/ed49684e69f846bf50b5050651ccdb87cfd152c0","https://git.kernel.org/stable/c/f128740f39ab28d1f4ad5bdd10f3e117eec0c374","https://git.kernel.org/stable/c/fdeb190b0905a6aaed1e5d6adfb8613214748d7d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix race between update_event_fields and, event_define_fields\n\nThe following sequence may leads race between event_define_fields()\nand update_event_fields():\n\n CPU0 (loads module A)                      CPU1 (loads module B)\n ===============================            ===============================\n load_module(A)                             load_module(B)\n   notifier_call_chain                        notifier_call_chain\n     trace_module_notify                        trace_module_notify\n       mutex_lock(&event_mutex)                   trace_event_update_all()\n         trace_module_add_events(A)                 down_write(&trace_event_sem)\n            __register_event(call_A)\n              __add_event_to_tracers(call_A)\n                event_define_fields(call_A)\n                  for each f:                         list_for_each_entry(field,\n                    list_add(&f->link,                                    &class->fields, link)\n                             &class->fields)            field = class->fields->next;\n\nWhere access to the class->fields is not protected by the event_mutex in\ntrace_event_update_all().\n\nThis produces the following panic:\n   Unable to handle kernel access ... at virtual address 0000000000000018\n   pc : update_event_fields+0xf8/0x368\n   Call trace:\n    update_event_fields+0xf8/0x368\n    trace_event_update_all+0x7c/0x2b4\n    trace_module_notify+0x4c/0x1dc\n    notifier_call_chain+0x84/0x168\n    blocking_notifier_call_chain_robust+0x64/0xd4\n    load_module+0x10c8/0x123c\n    __arm64_sys_finit_module+0x230/0x31c\n\nFix by taking event_mutex in trace_event_update_all() before\ntrace_event_sem.","cvss":[],"epss":[{"cve":"CVE-2026-74636","epss":0.00173,"percentile":0.06833,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74636","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74637","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74637","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf/core: Fix group leader use-after-free after sibling detach  perf_group_detach() handles leader and sibling detach differently. When the group leader is detached, all siblings are promoted to singleton events and their group_leader pointer is reset to themselves. When a sibling is detached, it is removed from the leader's sibling_list, but its group_leader pointer is left pointing at the old leader.  That is harmless when the sibling is being closed and freed immediately, as in the DETACH_DEAD path. It is not safe when the sibling is detached but kept alive, such as during CPU hotplug with DETACH_GROUP. In that case the sibling is removed from the context, while its file descriptor can still keep it alive.  A typical failing sequence is:    - A group contains leader L and sibling S.   - CPU hot-unplug detaches S with DETACH_GROUP, removing it from     L->sibling_list but leaving S->group_leader == L.   - L is later closed and freed.   - A PERF_IOC_FLAG_GROUP ioctl on S follows S->group_leader and     dereferences the freed leader.  This was reproduced by running the perf event fuzzer, CPU hotplug, and a stress workload concurrently:    Unable to handle kernel paging request at virtual address 006b6b6b6b6b6cdb   CPU: 2 PID: 12489 Comm: perf_fuzzer 6.18.7 PREEMPT   pc : perf_ioctl+0x34c/0xc68   x20: ffffff89a3fa2c70 x8 : 6b6b6b6b6b6b6b6b   Code: 943c4a0e 340047a0 f9404a94 f9411e88 (f940b908)   Call trace:   perf_ioctl+0x34c/0xc68 (P)   __arm64_sys_ioctl+0xa0/0xf4   invoke_syscall+0x58/0xe4   el0_svc_common+0xa8/0xdc   do_el0_svc+0x1c/0x28   el0_svc+0x40/0xc0   el0t_64_sync_handler+0x68/0xdc   el0t_64_sync+0x1c4/0x1c8  The fault happened in perf_ioctl(), where perf_event_for_each() follows the stale group_leader pointer and perf_event_for_each_child() then dereferences the freed leader's context.  Fix the use-after-free by promoting the detached sibling to a singleton. Also fix __event_disable() cgroup accounting and event state change.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74637","epss":0.00126,"percentile":0.02569,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74637","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74637","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1e7abfeb23c12bf46f6457e4a3e1a1a300d50619","https://git.kernel.org/stable/c/42c5ca1f0a288a52878bd72a5595b08261057438","https://git.kernel.org/stable/c/80c6054a4c40a0ffad82acef9f9a0dee108d152a","https://git.kernel.org/stable/c/8e92e03984364d93e0d5b0acd81c95eca773f034","https://git.kernel.org/stable/c/8f867c0e8da4c2303d91adf45acb6b1820966c27","https://git.kernel.org/stable/c/a979a642402d0b1f856c7a729b4cb2d92de4cf2f","https://git.kernel.org/stable/c/b42948f9e0d1ea4dbd5742ce1dfc7688de5d4a35","https://git.kernel.org/stable/c/f8a07021679aadfb6d63b209207ccc41f26982d1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Fix group leader use-after-free after sibling detach\n\nperf_group_detach() handles leader and sibling detach differently. When the\ngroup leader is detached, all siblings are promoted to singleton events and\ntheir group_leader pointer is reset to themselves. When a sibling is\ndetached, it is removed from the leader's sibling_list, but its\ngroup_leader pointer is left pointing at the old leader.\n\nThat is harmless when the sibling is being closed and freed immediately, as\nin the DETACH_DEAD path. It is not safe when the sibling is detached but\nkept alive, such as during CPU hotplug with DETACH_GROUP. In that case the\nsibling is removed from the context, while its file descriptor can still\nkeep it alive.\n\nA typical failing sequence is:\n\n  - A group contains leader L and sibling S.\n  - CPU hot-unplug detaches S with DETACH_GROUP, removing it from\n    L->sibling_list but leaving S->group_leader == L.\n  - L is later closed and freed.\n  - A PERF_IOC_FLAG_GROUP ioctl on S follows S->group_leader and\n    dereferences the freed leader.\n\nThis was reproduced by running the perf event fuzzer, CPU hotplug, and a\nstress workload concurrently:\n\n  Unable to handle kernel paging request at virtual address 006b6b6b6b6b6cdb\n  CPU: 2 PID: 12489 Comm: perf_fuzzer 6.18.7 PREEMPT\n  pc : perf_ioctl+0x34c/0xc68\n  x20: ffffff89a3fa2c70 x8 : 6b6b6b6b6b6b6b6b\n  Code: 943c4a0e 340047a0 f9404a94 f9411e88 (f940b908)\n  Call trace:\n  perf_ioctl+0x34c/0xc68 (P)\n  __arm64_sys_ioctl+0xa0/0xf4\n  invoke_syscall+0x58/0xe4\n  el0_svc_common+0xa8/0xdc\n  do_el0_svc+0x1c/0x28\n  el0_svc+0x40/0xc0\n  el0t_64_sync_handler+0x68/0xdc\n  el0t_64_sync+0x1c4/0x1c8\n\nThe fault happened in perf_ioctl(), where perf_event_for_each() follows\nthe stale group_leader pointer and perf_event_for_each_child() then\ndereferences the freed leader's context.\n\nFix the use-after-free by promoting the detached sibling to a singleton.\nAlso fix __event_disable() cgroup accounting and event state change.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74637","epss":0.00126,"percentile":0.02569,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74637","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74638","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74638","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/v3d: Serialize the scheduler timeout handlers  V3D exposes several independent hardware queues (BIN, RENDER, TFU and CSD) but has only a single, global reset. A timeout on any one queue therefore has to stop, reset and restart the schedulers of every other queue as well. That makes concurrent timeout handlers unsafe.  `reset_lock` was never able to make them safe, as a driver-side lock can only cover the driver's &drm_sched_backend_ops.timedout_job callback. The scheduler handles the timed out job and its pending list around that callback, outside of the driver's control, so a global reset triggered by one queue can still interfere with another queue that is in the middle of handling a timeout of its own.  Consequently, if a reset happens in the CSD queue while a CL-intensive application is running, the global reset stops and restarts the CL queue's scheduler while that queue is handling a timeout of its own. As drm_sched_stop() and drm_sched_start() subtract and add the credits of every job sitting on the pending list of the scheduler they are called on, and as the CL queue's handler concurrently takes its job off that same list and puts it back, the stop and the start no longer see the same set of jobs. The CL queue is left with more credits in flight than its limit:  [  327.302739] ------------[ cut here ]------------ [  327.302744] WARNING: CPU: 2 PID: 43 at drivers/gpu/drm/scheduler/sched_main.c:102 drm_sched_run_job_work+0x238/0x4d0 [gpu_sched] [  327.302884] CPU: 2 UID: 0 PID: 43 Comm: kworker/u16:1 Not tainted 6.18.39-v8-16k+ #3 PREEMPT [  327.302889] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT) [  327.302893] Workqueue: v3d_bin drm_sched_run_job_work [gpu_sched] [  327.302984] Call trace: [  327.302987]  drm_sched_run_job_work+0x238/0x4d0 [gpu_sched] (P) [  327.302997]  process_scheduled_works+0x180/0x3d0 [  327.303010]  worker_thread+0x268/0x3e8 [  327.303016]  kthread+0x140/0x250 [  327.303022]  ret_from_fork+0x10/0x20 [  327.303031] ---[ end trace 0000000000000000 ]---  From that point on, the credit count of the CL queue is broken, causing a complete GPU hang and UI freeze.  The DRM scheduler already provides a mechanism to serialize the timeout handlers of different schedulers: an ordered workqueue passed as drm_sched_init()'s @timeout_wq parameter. By default, each scheduler queues its timeout work on the system workqueue, which runs the handlers concurrently. Give all of the queues a shared ordered workqueue instead, as recommended by the DRM scheduler documentation for hardware that has distinct queues but resets globally.","cvss":[],"epss":[{"cve":"CVE-2026-74638","epss":0.00166,"percentile":0.06153,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-74638","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74638","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4da94744707b27a3ae1197bdd7127da4505dc5b1","https://git.kernel.org/stable/c/5884851a096d8afcdf91f0e542bac193035183a6","https://git.kernel.org/stable/c/c22a45817b9c92aa0391db60e2ed467c7e6027d7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Serialize the scheduler timeout handlers\n\nV3D exposes several independent hardware queues (BIN, RENDER, TFU and\nCSD) but has only a single, global reset. A timeout on any one queue\ntherefore has to stop, reset and restart the schedulers of every other\nqueue as well. That makes concurrent timeout handlers unsafe.\n\n`reset_lock` was never able to make them safe, as a driver-side lock can\nonly cover the driver's &drm_sched_backend_ops.timedout_job callback.\nThe scheduler handles the timed out job and its pending list around that\ncallback, outside of the driver's control, so a global reset triggered\nby one queue can still interfere with another queue that is in the\nmiddle of handling a timeout of its own.\n\nConsequently, if a reset happens in the CSD queue while a CL-intensive\napplication is running, the global reset stops and restarts the CL\nqueue's scheduler while that queue is handling a timeout of its own. As\ndrm_sched_stop() and drm_sched_start() subtract and add the credits of\nevery job sitting on the pending list of the scheduler they are called\non, and as the CL queue's handler concurrently takes its job off that\nsame list and puts it back, the stop and the start no longer see the\nsame set of jobs. The CL queue is left with more credits in flight than\nits limit:\n\n[  327.302739] ------------[ cut here ]------------\n[  327.302744] WARNING: CPU: 2 PID: 43 at drivers/gpu/drm/scheduler/sched_main.c:102 drm_sched_run_job_work+0x238/0x4d0 [gpu_sched]\n[  327.302884] CPU: 2 UID: 0 PID: 43 Comm: kworker/u16:1 Not tainted 6.18.39-v8-16k+ #3 PREEMPT\n[  327.302889] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT)\n[  327.302893] Workqueue: v3d_bin drm_sched_run_job_work [gpu_sched]\n[  327.302984] Call trace:\n[  327.302987]  drm_sched_run_job_work+0x238/0x4d0 [gpu_sched] (P)\n[  327.302997]  process_scheduled_works+0x180/0x3d0\n[  327.303010]  worker_thread+0x268/0x3e8\n[  327.303016]  kthread+0x140/0x250\n[  327.303022]  ret_from_fork+0x10/0x20\n[  327.303031] ---[ end trace 0000000000000000 ]---\n\nFrom that point on, the credit count of the CL queue is broken, causing\na complete GPU hang and UI freeze.\n\nThe DRM scheduler already provides a mechanism to serialize the timeout\nhandlers of different schedulers: an ordered workqueue passed as\ndrm_sched_init()'s @timeout_wq parameter. By default, each scheduler\nqueues its timeout work on the system workqueue, which runs the handlers\nconcurrently. Give all of the queues a shared ordered workqueue instead,\nas recommended by the DRM scheduler documentation for hardware that has\ndistinct queues but resets globally.","cvss":[],"epss":[{"cve":"CVE-2026-74638","epss":0.00166,"percentile":0.06153,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74638","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74641","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74641","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: usx2y: bound the hwdep mmap fault offset  snd_us428ctls_vm_fault() turns the faulting page offset into a kernel address with no bound of any kind:  \toffset = vmf->pgoff << PAGE_SHIFT; \tvaddr = (char *)(...)->us428ctls_sharedmem + offset; \tpage = virt_to_page(vaddr); \tget_page(page); \tvmf->page = page;  \treturn 0;  snd_us428ctls_mmap() checks only the length of the mapping, never the offset, and us428ctls_sharedmem is a single page from alloc_pages_exact().  For a character device file_mmap_size_max() returns ULONG_MAX, so the mm layer imposes no ceiling either.  Every page offset above zero resolves to a struct page outside the object, and the handler installs it into the caller's address space read-write; the vma is not marked read-only.  The caller picks the page frame with a single mmap() argument and gets read-write access to a page of kernel memory it does not own; an offset that lands in an unpopulated vmemmap region oopses instead.  A process that can open the hwdep node of an attached US-X2Y reaches this after loading the FPGA image through the same node; no capability check is involved.  On 7.2.0-rc5 (arm64), mmap() with a large offset:    Unable to handle kernel paging request at virtual address fffffdffc45d5ac8   pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]   Call trace:    snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]    __do_fault    __handle_mm_fault    handle_mm_fault    el0_da  Reject any offset outside the shared region.  The pcm hwdep handler in usx2yhwdeppcm.c computes its address the same way and needs the same bound.  Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74641","epss":0.00129,"percentile":0.0289,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74641","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74641","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/10a87401fb3148c388e55df0148295b3b137da07","https://git.kernel.org/stable/c/2ca1eea3cd17930daffe9e429a7c89232036ec24","https://git.kernel.org/stable/c/34ab56ed854baa73a731cfd99af689f0b1bac444","https://git.kernel.org/stable/c/4208db2453e1ea71b8048a5b7802360cb29a53f1","https://git.kernel.org/stable/c/5bf5ccddf00b59f1e3ea7e65d76a5f5b5c21cc2e","https://git.kernel.org/stable/c/ad6fedea65c6e90eda00d716c8bf20cdc437ed10","https://git.kernel.org/stable/c/f613b4a2d87247b51a1b2b330f2e083a454125f2","https://git.kernel.org/stable/c/f75d6f61f0d9c5c1ea725104014e10d26d1e3a00"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usx2y: bound the hwdep mmap fault offset\n\nsnd_us428ctls_vm_fault() turns the faulting page offset into a kernel\naddress with no bound of any kind:\n\n\toffset = vmf->pgoff << PAGE_SHIFT;\n\tvaddr = (char *)(...)->us428ctls_sharedmem + offset;\n\tpage = virt_to_page(vaddr);\n\tget_page(page);\n\tvmf->page = page;\n\n\treturn 0;\n\nsnd_us428ctls_mmap() checks only the length of the mapping, never the\noffset, and us428ctls_sharedmem is a single page from\nalloc_pages_exact().  For a character device file_mmap_size_max()\nreturns ULONG_MAX, so the mm layer imposes no ceiling either.  Every page\noffset above zero resolves to a struct page outside the object, and the\nhandler installs it into the caller's address space read-write; the vma\nis not marked read-only.\n\nThe caller picks the page frame with a single mmap() argument and gets\nread-write access to a page of kernel memory it does not own; an offset\nthat lands in an unpopulated vmemmap region oopses instead.\n\nA process that can open the hwdep node of an attached US-X2Y reaches\nthis after loading the FPGA image through the same node; no capability\ncheck is involved.\n\nOn 7.2.0-rc5 (arm64), mmap() with a large offset:\n\n  Unable to handle kernel paging request at virtual address fffffdffc45d5ac8\n  pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]\n  Call trace:\n   snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]\n   __do_fault\n   __handle_mm_fault\n   handle_mm_fault\n   el0_da\n\nReject any offset outside the shared region.  The pcm hwdep handler in\nusx2yhwdeppcm.c computes its address the same way and needs the same\nbound.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74641","epss":0.00129,"percentile":0.0289,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74641","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74647","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74647","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  misc: fastrpc: Remove buffer from list prior to unmap operation  fastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is getting removed from the list after it is unmapped from DSP. This can create potential race conditions if multiple threads invoke unmap concurrently, where one thread may remove the entry from the list while another thread's unmap operation is still ongoing.  Fix this by removing the buffer entry from the list before calling the unmap operation. If the unmap fails, the entry is re-added to the list so that userspace can retry the unmap, or alternatively, the buffer will be cleaned up during device release when the DSP process is torn down and all DSP-side mappings are freed along with remaining buffers in the list.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74647","epss":0.00129,"percentile":0.02891,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74647","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74647","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0beaa9bd7eb10d9b5e6352ed5161f3f3bbd4c3c5","https://git.kernel.org/stable/c/1edb654b2b41baee2ab5cf418baaf6e57dfbd802","https://git.kernel.org/stable/c/4716c23c206a2f99ca54ebfdd8b5ba9dd0102240","https://git.kernel.org/stable/c/6102ceb4eab845743ee57acd3863fbd06e93c927","https://git.kernel.org/stable/c/97273624f7b356eaf8261609a75cfcb8738a165a","https://git.kernel.org/stable/c/99f8de36c84cb9b872157aa6c3578c2480cee4b8","https://git.kernel.org/stable/c/9bf22a7d950cec2d1efeca7f16bb20fcca84c36a","https://git.kernel.org/stable/c/fe70329055977fc1e8dc6291318d0dd75470795a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Remove buffer from list prior to unmap operation\n\nfastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is\ngetting removed from the list after it is unmapped from DSP. This can\ncreate potential race conditions if multiple threads invoke unmap\nconcurrently, where one thread may remove the entry from the list while\nanother thread's unmap operation is still ongoing.\n\nFix this by removing the buffer entry from the list before calling the\nunmap operation. If the unmap fails, the entry is re-added to the list\nso that userspace can retry the unmap, or alternatively, the buffer\nwill be cleaned up during device release when the DSP process is torn\ndown and all DSP-side mappings are freed along with remaining buffers\nin the list.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74647","epss":0.00129,"percentile":0.02891,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74647","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74648","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74648","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: validate monitor transmit frame lengths  rtw_cfg80211_monitor_if_xmit_entry() removes the radiotap header and then reads the 802.11 frame control field without checking that a base 802.11 header remains.  The data path also pulls the calculated 802.11, QoS and SNAP header span before confirming that the skb contains it. A truncated frame can therefore cause out-of-bounds reads or leave insufficient data for the Ethernet address writes.  Reject frames that do not contain the base 802.11 header and data frames that do not contain their complete calculated header span.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74648","epss":0.00129,"percentile":0.02891,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74648","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74648","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6829665d050983907b560173e49dcc6c11cb2730","https://git.kernel.org/stable/c/7b0f62d2986a28e5e4188366bc2f4e2868b14790","https://git.kernel.org/stable/c/7edd3adb0c80d70b4237640275c559610f438476","https://git.kernel.org/stable/c/8b3e4ed9c35d3d3b64fcc23f4a1f22b37c1865b1","https://git.kernel.org/stable/c/a3ac6d849de5f7abe14761d741bbb843ac793454","https://git.kernel.org/stable/c/bd88f6289b7e483216a9c1df15a0460ef9b02cb6","https://git.kernel.org/stable/c/c5e5d78743992e235b76d2ebe5a403d60315aa8a","https://git.kernel.org/stable/c/f03398d835f5249c49546f0eb0d0df6792b95d5f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: validate monitor transmit frame lengths\n\nrtw_cfg80211_monitor_if_xmit_entry() removes the radiotap header and\nthen reads the 802.11 frame control field without checking that a base\n802.11 header remains.\n\nThe data path also pulls the calculated 802.11, QoS and SNAP header\nspan before confirming that the skb contains it. A truncated frame can\ntherefore cause out-of-bounds reads or leave insufficient data for the\nEthernet address writes.\n\nReject frames that do not contain the base 802.11 header and data\nframes that do not contain their complete calculated header span.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74648","epss":0.00129,"percentile":0.02891,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74648","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74649","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74649","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: fix missing shared-key auth challenge length check  The WEP shared-key authentication handler uses the challenge-text element's attacker-controlled length without checking it against the fixed 128-byte chg_txt buffer.  In OnAuthClient() the length from rtw_get_ie() - up to 255 - is used to perform memcpy() into the 128-byte pmlmeinfo->chg_txt, so a malicious AP sending a malformed WLAN_EID_CHALLENGE element can overflow/underfill chg_txt by up to 127 bytes. It is reachable over the air, before association, during shared-key authentication. In the case of an overflow, the driver can write out of bounds. In the case of an underfill, the driver can echo stale buffer memory.  The challenge text is defined to be exactly 128 octets, which is already provided as the WLAN_AUTH_CHALLENGE_LEN define; require the element to be exactly that length before use.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74649","epss":0.00288,"percentile":0.21175,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.23472},"relatedVulnerabilities":[{"id":"CVE-2026-74649","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74649","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2c56ef658ac8c6bca36bc5574715e8f717207c6c","https://git.kernel.org/stable/c/39ae1033071001af9bb4573ebdbb43bbbe88f749","https://git.kernel.org/stable/c/4ba402fd47009d20e51dbfc934abb562098ea35b","https://git.kernel.org/stable/c/4d018e7d7d908bdfcb5ecfa922b1d5cb9ddb3722","https://git.kernel.org/stable/c/6235b5156b48ed5d1ce3410d8f0b2fd67d30d944","https://git.kernel.org/stable/c/87c2f073d2aaea041d531b8e579c47570b54b3b7","https://git.kernel.org/stable/c/a28a4b0592e4a37ea471bc0d308513a93133ce7e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix missing shared-key auth challenge length check\n\nThe WEP shared-key authentication handler uses the challenge-text\nelement's attacker-controlled length without checking it against the\nfixed 128-byte chg_txt buffer.\n\nIn OnAuthClient() the length from rtw_get_ie() - up to 255 - is used\nto perform memcpy() into the 128-byte pmlmeinfo->chg_txt, so a\nmalicious AP sending a malformed WLAN_EID_CHALLENGE element can\noverflow/underfill chg_txt by up to 127 bytes. It is reachable over the\nair, before association, during shared-key authentication. In the case\nof an overflow, the driver can write out of bounds. In the case of an\nunderfill, the driver can echo stale buffer memory.\n\nThe challenge text is defined to be exactly 128 octets, which is\nalready provided as the WLAN_AUTH_CHALLENGE_LEN define; require the\nelement to be exactly that length before use.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74649","epss":0.00288,"percentile":0.21175,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74649","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74650","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: fix OOB read in WMM_param_handler()  WMM_param_handler() copies a fixed-size WMM parameter element out of a received information element without checking that the element is long enough, causing an out-of-bounds read for a short WMM IE.  The handler reads sizeof(struct WMM_para_element) (18) bytes at pIE->data + 6, so it requires pIE->length to be at least 24 (WLAN_WMM_LEN), but it never validates the length. Two of its three callers reach it after matching only the WMM OUI: OnAssocRsp() in rtw_mlme_ext.c matches a 6-byte OUI, and join_cmd_hdl() matches a 4-byte OUI, before calling the handler. A vendor-specific IE carrying the WMM OUI but a length between 6 and 23, placed in an association response or in the IE blob handed to join_cmd_hdl(), passes the OUI check and then makes the memcmp() and memcpy() at pIE->data + 6 read past the end of the element. OnAssocRsp() parses a frame received from the AP, so this is reachable from a remote peer.  The remaining caller in rtw_wlan_util.c already guards the handler with \"pIE->length == WLAN_WMM_LEN\". Move the equivalent check into the handler itself so every caller is covered; the sibling IE handlers in the same parsing loop (HT_caps_handler(), HT_info_handler(), ERP_IE_handler()) likewise bound their accesses by pIE->length.","cvss":[],"epss":[{"cve":"CVE-2026-74650","epss":0.00177,"percentile":0.07328,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74650","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1158b9931207392d6dd136aa0c4be18893b50fa1","https://git.kernel.org/stable/c/2bee6f7a0f0125238951e31da2e96d06fe359043","https://git.kernel.org/stable/c/5df2fd06567df5f178c8faae0bdaefd203618d21","https://git.kernel.org/stable/c/6cdca4c8b64c15a3ab9ad7a85f482e9519eadf93","https://git.kernel.org/stable/c/ae21407350151bddfd4fea7aa39bd0643c0ca9d3","https://git.kernel.org/stable/c/ce2399717de242344880044b91a20a712644fdfb","https://git.kernel.org/stable/c/e429c6dfd5d2324cd866daaf4c29d5cfe4dea0e4","https://git.kernel.org/stable/c/e5b7610008f4e6a80c8b071aa77ddbd5e17ea472"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in WMM_param_handler()\n\nWMM_param_handler() copies a fixed-size WMM parameter element out of a\nreceived information element without checking that the element is long\nenough, causing an out-of-bounds read for a short WMM IE.\n\nThe handler reads sizeof(struct WMM_para_element) (18) bytes at\npIE->data + 6, so it requires pIE->length to be at least 24\n(WLAN_WMM_LEN), but it never validates the length. Two of its three\ncallers reach it after matching only the WMM OUI: OnAssocRsp() in\nrtw_mlme_ext.c matches a 6-byte OUI, and join_cmd_hdl() matches a\n4-byte OUI, before calling the handler. A vendor-specific IE carrying\nthe WMM OUI but a length between 6 and 23, placed in an association\nresponse or in the IE blob handed to join_cmd_hdl(), passes the OUI\ncheck and then makes the memcmp() and memcpy() at pIE->data + 6 read\npast the end of the element. OnAssocRsp() parses a frame received from\nthe AP, so this is reachable from a remote peer.\n\nThe remaining caller in rtw_wlan_util.c already guards the handler with\n\"pIE->length == WLAN_WMM_LEN\". Move the equivalent check into the\nhandler itself so every caller is covered; the sibling IE handlers in\nthe same parsing loop (HT_caps_handler(), HT_info_handler(),\nERP_IE_handler()) likewise bound their accesses by pIE->length.","cvss":[],"epss":[{"cve":"CVE-2026-74650","epss":0.00177,"percentile":0.07328,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74650","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74651","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74651","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()  rtw_get_wpa_ie() reads bytes at fixed offsets into a vendor-specific information element without checking that the element is long enough, causing an out-of-bounds read for a short trailing IE.  The function locates a vendor-specific IE (EID 221) with rtw_get_ie() and then compares a 4-byte OUI+type at pbuf + 2 and reads a 2-byte version word at pbuf + 6. Those accesses require the IE body to be at least 6 bytes, but rtw_get_ie() only guarantees that the element fits within the buffer; it does not enforce a minimum body length. A vendor-specific IE whose length byte is 0 to 5, placed at the end of the buffer, therefore makes these reads run past the end of the IE and past the end of the buffer itself.  The buffer holds information elements taken from received management frames and from the IE blob passed to rtw_cfg80211_set_wpa_ie(), which is kmemdup'd to its exact length, so the read can run off the end of the allocation.  The sibling helpers rtw_get_sec_ie(), rtw_get_wapi_ie() and rtw_get_wps_ie() in this file already reject too-short vendor-specific IEs before their OUI memcmp(); rtw_get_wpa_ie() was never brought in line with them, and needs a minimum of 6 rather than 4 bytes because of the version word. Add the missing length check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74651","epss":0.00274,"percentile":0.19616,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.21372000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-74651","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74651","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/01ab275f8f3e497a13ebbe4ded44ec0623bccde3","https://git.kernel.org/stable/c/0d19f0600fbb610c42f2a86f95c35706dc04691b","https://git.kernel.org/stable/c/1c3e23e78862493e8cf1adad02b10ffcb8b9921c","https://git.kernel.org/stable/c/42c5a0d454aa5b54fec17162d9a1f8c30f8af45a","https://git.kernel.org/stable/c/4fc459c5cd8767ca4d9bf2f7becbd562639ba4d9","https://git.kernel.org/stable/c/b45be82387bf759931acdd21ca7dfe740f16eb97","https://git.kernel.org/stable/c/c9068f82a0906b29c905e8788edb62c3208c7c8a","https://git.kernel.org/stable/c/e167a38a8a8f50f137721fef1a1fbba0f4588b5d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()\n\nrtw_get_wpa_ie() reads bytes at fixed offsets into a vendor-specific\ninformation element without checking that the element is long enough,\ncausing an out-of-bounds read for a short trailing IE.\n\nThe function locates a vendor-specific IE (EID 221) with rtw_get_ie()\nand then compares a 4-byte OUI+type at pbuf + 2 and reads a 2-byte\nversion word at pbuf + 6. Those accesses require the IE body to be at\nleast 6 bytes, but rtw_get_ie() only guarantees that the element fits\nwithin the buffer; it does not enforce a minimum body length. A\nvendor-specific IE whose length byte is 0 to 5, placed at the end of\nthe buffer, therefore makes these reads run past the end of the IE and\npast the end of the buffer itself.\n\nThe buffer holds information elements taken from received management\nframes and from the IE blob passed to rtw_cfg80211_set_wpa_ie(), which\nis kmemdup'd to its exact length, so the read can run off the end of\nthe allocation.\n\nThe sibling helpers rtw_get_sec_ie(), rtw_get_wapi_ie() and\nrtw_get_wps_ie() in this file already reject too-short vendor-specific\nIEs before their OUI memcmp(); rtw_get_wpa_ie() was never brought in\nline with them, and needs a minimum of 6 rather than 4 bytes because\nof the version word. Add the missing length check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"exploitabilityScore":2.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74651","epss":0.00274,"percentile":0.19616,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74651","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74653","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74653","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx  The NXP LPC32xx UART (PORT_LPC3220) can latch an RX character-timeout interrupt while the RX FIFO is empty: IIR reports UART_IIR_RX_TIMEOUT (0x0c) but LSR.DR is clear. A character timeout is only cleared by reading RHR, but serial8250_rx_chars() reads RHR only when LSR.DR is set, so nothing ever clears the condition. The interrupt is level-triggered and re-fires immediately, so on a single-core ARM926 the resulting interrupt storm livelocks the CPU.  It is reproducible when userspace repeatedly opens the front-panel port (ttyS1): serial8250_do_set_termios() re-enables interrupts on unlock and the handler then spins forever with iir=0xcc lsr=0x60 ier=0x05, tripping the soft-lockup detector in serial8250_handle_irq_locked().  LPC32xx has no dedicated 8250 glue driver, it's driven by the generic 8250_of. Add a hardware specific handle_irq for PORT_LPC3220, wired up in of_platform_serial_setup() the same way fsl8250_handle_irq is installed. The handler follows dw8250_handle_irq(): on an RX timeout with an empty FIFO (LSR.DR and LSR.BI clear) it does one throwaway RHR read to clear the condition, then calls serial8250_handle_irq_locked(). No real received data is ever discarded, and it is a no-op on healthy UARTs which never report a timeout with DR clear.  This is the same class of bug already worked around in other 8250 drivers; see commit 424d79183af0 (\"serial: 8250_dw: Avoid \"too much work\" from bogus rx timeout interrupt\") which reports the identical iir=0xcc/lsr=0x60. See also UART_RX_TIMEOUT_QUIRK in 8250_omap, and the note in 8250_bcm7271.","cvss":[],"epss":[{"cve":"CVE-2026-74653","epss":0.00168,"percentile":0.06352,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74653","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74653","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1423415471274abda87024967d7fe2206ceee0ea","https://git.kernel.org/stable/c/3ce24bc4d115336218e59b7e286fd3a79f4fc4c6","https://git.kernel.org/stable/c/7795e8abedc86438cae0454602cbf9038b94bf38","https://git.kernel.org/stable/c/c321dc5172c8c66e21ffbeeb7a2ebb88ae6fd4c3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx\n\nThe NXP LPC32xx UART (PORT_LPC3220) can latch an RX character-timeout\ninterrupt while the RX FIFO is empty: IIR reports UART_IIR_RX_TIMEOUT\n(0x0c) but LSR.DR is clear. A character timeout is only cleared by\nreading RHR, but serial8250_rx_chars() reads RHR only when LSR.DR is\nset, so nothing ever clears the condition. The interrupt is\nlevel-triggered and re-fires immediately, so on a single-core ARM926\nthe resulting interrupt storm livelocks the CPU.\n\nIt is reproducible when userspace repeatedly opens the front-panel port\n(ttyS1): serial8250_do_set_termios() re-enables interrupts on unlock and\nthe handler then spins forever with iir=0xcc lsr=0x60 ier=0x05, tripping\nthe soft-lockup detector in serial8250_handle_irq_locked().\n\nLPC32xx has no dedicated 8250 glue driver, it's driven by the generic\n8250_of. Add a hardware specific handle_irq for PORT_LPC3220, wired up\nin of_platform_serial_setup() the same way fsl8250_handle_irq is\ninstalled. The handler follows dw8250_handle_irq(): on an RX timeout\nwith an empty FIFO (LSR.DR and LSR.BI clear) it does one throwaway RHR\nread to clear the condition, then calls serial8250_handle_irq_locked().\nNo real received data is ever discarded, and it is a no-op on healthy\nUARTs which never report a timeout with DR clear.\n\nThis is the same class of bug already worked around in other 8250 drivers;\nsee commit 424d79183af0 (\"serial: 8250_dw: Avoid \"too much work\" from bogus rx timeout interrupt\")\nwhich reports the identical iir=0xcc/lsr=0x60. See also\nUART_RX_TIMEOUT_QUIRK in 8250_omap, and the note in 8250_bcm7271.","cvss":[],"epss":[{"cve":"CVE-2026-74653","epss":0.00168,"percentile":0.06352,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74653","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74654","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74654","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  serial: 8250_dma: Clear stale RX state on shutdown  serial8250_release_dma() terminates RX DMA and releases the channel, but leaves rx_running set.  If the port is closed while an RX transfer is active, the stale state remains while rxchan is NULL until the channel is requested again on the next open.  The DesignWare BUSY workaround added by commit a7b9ce39fbe4 (\"serial: 8250_dw: Ensure BUSY is deasserted\") calls serial8250_rx_dma_flush() from the LCR write path during startup.  This happens before serial8250_request_dma() obtains a new RX channel.  On reopen, the stale rx_running state therefore makes the flush path pass a NULL channel to dmaengine_pause(), causing a kernel Oops.  Clear rx_running after terminating RX DMA, matching the TX cleanup.  Also make the flush helper return if the DMA object or RX channel is not available so startup and teardown paths cannot pass a NULL channel to the DMAengine API.","cvss":[],"epss":[{"cve":"CVE-2026-74654","epss":0.00177,"percentile":0.07329,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74654","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74654","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/9f2444f4c0e4b06f61bae38da87c9c94c78efa86","https://git.kernel.org/stable/c/ae05d9e50b6b9f246c110b3bdc03676145c2d0d4","https://git.kernel.org/stable/c/bf4fb620e02962b2b52500a4b3d8420f351eb46a","https://git.kernel.org/stable/c/d06cfb1add4a2d5b393e9e31f49ebbd168beea49","https://git.kernel.org/stable/c/e10f06ee050a08930e2339b6fec7148fd0b2a8f6","https://git.kernel.org/stable/c/e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41","https://git.kernel.org/stable/c/e7a5d792cf64a2096e18f1d573cc3d01cba15e92","https://git.kernel.org/stable/c/e7e3cc6709caa49d1d6ce6c1f7cb305e38675cc9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_dma: Clear stale RX state on shutdown\n\nserial8250_release_dma() terminates RX DMA and releases the channel, but\nleaves rx_running set.  If the port is closed while an RX transfer is\nactive, the stale state remains while rxchan is NULL until the channel is\nrequested again on the next open.\n\nThe DesignWare BUSY workaround added by commit a7b9ce39fbe4\n(\"serial: 8250_dw: Ensure BUSY is deasserted\") calls\nserial8250_rx_dma_flush() from the LCR write path during startup.  This\nhappens before serial8250_request_dma() obtains a new RX channel.  On\nreopen, the stale rx_running state therefore makes the flush path pass a\nNULL channel to dmaengine_pause(), causing a kernel Oops.\n\nClear rx_running after terminating RX DMA, matching the TX cleanup.  Also\nmake the flush helper return if the DMA object or RX channel is not\navailable so startup and teardown paths cannot pass a NULL channel to the\nDMAengine API.","cvss":[],"epss":[{"cve":"CVE-2026-74654","epss":0.00177,"percentile":0.07329,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74654","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74656","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74656","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: fix use-after-free in fib_nhc_update_mtu()  fib_nhc_update_mtu() walks the nexthop exception table under RTNL, but RTNL does not serialize this walk with PMTU exception updates. The walk uses rcu_dereference_protected() with a constant true condition without holding fnhe_lock.  The following interleaving can therefore occur:    CPU 0                              CPU 1   fib_nhc_update_mtu()               update_or_create_fnhe()     load fnhe                          spin_lock_bh(&fnhe_lock)                                        fnhe_remove_oldest()                                          unlink fnhe                                          kfree_rcu(fnhe, rcu)     <quiescent state>     access fnhe after grace period  KASAN reported:    BUG: KASAN: slab-use-after-free in fib_nhc_update_mtu+0x3df/0x410   Read of size 8 at addr ffff888107d49000 by task poc/90   Call Trace:    fib_nhc_update_mtu+0x3df/0x410    fib_sync_mtu+0x7a/0xd0    fib_netdev_event+0x229/0x3f0    netif_set_mtu_ext+0x33a/0x570    dev_set_mtu+0x88/0x120  The same walk updates fnhe_pmtu and fnhe_mtu_locked. These fields form a pair and other writers serialize them with fnhe_lock. RCU alone prevents reclamation, but would still allow concurrent writers to leave a mixed pair.  Walk the table under RCU and acquire fnhe_lock only while updating each exception. RCU keeps the current entry alive while the short critical section serializes its paired PMTU fields. This avoids holding the global lock while scanning all 2048 buckets for every nexthop.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74656","epss":0.00126,"percentile":0.02566,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74656","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74656","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5a28a4b22dde92f9d293b94236314b8d6181dc4a","https://git.kernel.org/stable/c/63996ffc594d128ccec8fc0983f91effd2d3adc4","https://git.kernel.org/stable/c/bc5bde9ce3cc36502839dfe98e068f7303a50982","https://git.kernel.org/stable/c/dfe388da13aa784851e5ebbea90afbb099075761","https://git.kernel.org/stable/c/e00f7d2b5f2540a3415a229c982af7a25ff6362e","https://git.kernel.org/stable/c/e1e602d6b22d5cb1641c4459c487eb18bf569e0a","https://git.kernel.org/stable/c/ed503eaad62f20cdd5122d7c3078a648a99c8f16","https://git.kernel.org/stable/c/fd39e711866498ae94fcf9acf6f422a4f045b681"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fix use-after-free in fib_nhc_update_mtu()\n\nfib_nhc_update_mtu() walks the nexthop exception table under RTNL, but\nRTNL does not serialize this walk with PMTU exception updates. The walk\nuses rcu_dereference_protected() with a constant true condition without\nholding fnhe_lock.\n\nThe following interleaving can therefore occur:\n\n  CPU 0                              CPU 1\n  fib_nhc_update_mtu()               update_or_create_fnhe()\n    load fnhe                          spin_lock_bh(&fnhe_lock)\n                                       fnhe_remove_oldest()\n                                         unlink fnhe\n                                         kfree_rcu(fnhe, rcu)\n    <quiescent state>\n    access fnhe after grace period\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in fib_nhc_update_mtu+0x3df/0x410\n  Read of size 8 at addr ffff888107d49000 by task poc/90\n  Call Trace:\n   fib_nhc_update_mtu+0x3df/0x410\n   fib_sync_mtu+0x7a/0xd0\n   fib_netdev_event+0x229/0x3f0\n   netif_set_mtu_ext+0x33a/0x570\n   dev_set_mtu+0x88/0x120\n\nThe same walk updates fnhe_pmtu and fnhe_mtu_locked. These fields form a\npair and other writers serialize them with fnhe_lock. RCU alone prevents\nreclamation, but would still allow concurrent writers to leave a mixed\npair.\n\nWalk the table under RCU and acquire fnhe_lock only while updating each\nexception. RCU keeps the current entry alive while the short critical\nsection serializes its paired PMTU fields. This avoids holding the global\nlock while scanning all 2048 buckets for every nexthop.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74656","epss":0.00126,"percentile":0.02566,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74656","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74657","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74657","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops  fib_nlmsg_size() still estimates nexthop space as if every gateway is encoded as an IPv4 RTA_GATEWAY attribute. IPv4 routes can also carry an IPv6 gateway, which fib_nexthop_info() dumps as RTA_VIA.  As a result, route notifications can allocate an skb that is too small. fib_dump_info() then fails with -EMSGSIZE and rtmsg_fib() hits the WARN_ON() that marks such failures as a fib_nlmsg_size() bug. With panic_on_warn set, this becomes a kernel panic.  Mirror the actual nexthop dump layout in fib_nlmsg_size(): account for IPv6 nexthop gateways dumped as RTA_VIA, for the no-header rtnexthop layout used inside RTA_MULTIPATH, and for RTA_FLOW only when it is actually present.","cvss":[],"epss":[{"cve":"CVE-2026-74657","epss":0.00177,"percentile":0.07329,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74657","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74657","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0f0ca602941d0a81ae9514943ca06c55159c6385","https://git.kernel.org/stable/c/4a5dfbae5179f6574695012a980476254df2d295","https://git.kernel.org/stable/c/4ff9548d84945d2cbf9e4c207288063a200ea397","https://git.kernel.org/stable/c/5307a53599fa762c06e475ee4a375252074fd324","https://git.kernel.org/stable/c/57195f0ab5cfbb5ee0864e5aff15ceb48f5a5e28","https://git.kernel.org/stable/c/7f80ad373ce4a7af5367ff273cea0f16e91387f3","https://git.kernel.org/stable/c/9b22f13524fa0de0d963bbd3002df6c28bae3395","https://git.kernel.org/stable/c/a59edda6eda1252340354322d8ab318b2e9052fb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops\n\nfib_nlmsg_size() still estimates nexthop space as if every gateway is\nencoded as an IPv4 RTA_GATEWAY attribute. IPv4 routes can also carry an\nIPv6 gateway, which fib_nexthop_info() dumps as RTA_VIA.\n\nAs a result, route notifications can allocate an skb that is too small.\nfib_dump_info() then fails with -EMSGSIZE and rtmsg_fib() hits the\nWARN_ON() that marks such failures as a fib_nlmsg_size() bug. With\npanic_on_warn set, this becomes a kernel panic.\n\nMirror the actual nexthop dump layout in fib_nlmsg_size(): account for\nIPv6 nexthop gateways dumped as RTA_VIA, for the no-header rtnexthop\nlayout used inside RTA_MULTIPATH, and for RTA_FLOW only when it is\nactually present.","cvss":[],"epss":[{"cve":"CVE-2026-74657","epss":0.00177,"percentile":0.07329,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74657","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74658","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74658","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  futex: Prevent robust futex exit race some more  A robust futex unlock stores 0 over the whole futex value - wiping FUTEX_WAITERS - and wakes a single waiter. That wakeup is a one-shot notification: the protocol relies on its recipient to either acquire the futex (and eventually unlock while aware of the remaining contention) or re-arm FUTEX_WAITERS before sleeping again.  If the woken waiter is killed before it can do either, the kernel must jump in and wake the next task down the line.  This is a known complication of the futex protocol with a previous partial fix in commit ca16d5bee598 (\"futex: Prevent robust futex exit race\"). Unfortunately, that fix is insufficient.  If a third task re-acquired the futex through the uncontended fast path in the meantime, the notification is lost: robust exit processing sees that it is owned by another task and does nothing, while the new owner sees no FUTEX_WAITERS when it unlocks and wakes nobody. The remaining waiters sleep forever behind a free futex:    A owns the futex, B and C sleep in FUTEX_WAIT                                         uval == A | FUTEX_WAITERS   A robust unlock: store 0, FUTEX_WAKE(1) wakes B                                         uval == 0   D fast path acquire: cmpxchg(0 -> D)                                         uval == D, no FUTEX_WAITERS   B killed before acting on the wakeup   B exit walk, pending op: owner D != B -> no action   D unlock: no FUTEX_WAITERS -> no wake                                         C sleeps forever  This is clearly a shortcoming in the implementation, which fails to keep the FUTEX_WAITERS bit consistent.  Work around this by augmenting the robust list exit processing to also perform the extra wakeup if the futex word is owned by another thread but FUTEX_WAITERS is not set.  This does not fix the problem of a non-contended take over/release and free sequence, which has been discussed for years and has been addressed by commit 3ca9595d9fb6 (\"futex: Add support for unlocking robust futexes\") and subsequent changes, but failed to take the problem described above into account.  A more complete solution which is based on the in kernel unlock of contended robust futexes has been discussed in the context of this change and should show up in mainline sooner than later.  [ tglx: Amend change log slightly and fixup coding style ]","cvss":[],"epss":[{"cve":"CVE-2026-74658","epss":0.00177,"percentile":0.07338,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74658","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74658","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/33bfa85458105d6169ebdb697f692b8bb8025bae","https://git.kernel.org/stable/c/6d4514ca9cdf61fec4ec634cf50386f6f7e69748","https://git.kernel.org/stable/c/7b8c53263f8878bdd12c87e147ac6feca5c05211","https://git.kernel.org/stable/c/7cf710e70f9bb8ea75f759ebed09871801315992","https://git.kernel.org/stable/c/83b0f71d5a313a765754acab51d2ecc5de76e0b9","https://git.kernel.org/stable/c/925628656b73b70930972ccde421de4f758d8650","https://git.kernel.org/stable/c/a1c2b7b86a946b6b172bce44d74553da2323a36c","https://git.kernel.org/stable/c/aa5c571901c6b22b58373693a4bf889ecab11ff5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Prevent robust futex exit race some more\n\nA robust futex unlock stores 0 over the whole futex value - wiping\nFUTEX_WAITERS - and wakes a single waiter. That wakeup is a one-shot\nnotification: the protocol relies on its recipient to either acquire the\nfutex (and eventually unlock while aware of the remaining contention) or\nre-arm FUTEX_WAITERS before sleeping again.  If the woken waiter is killed\nbefore it can do either, the kernel must jump in and wake the next task\ndown the line.\n\nThis is a known complication of the futex protocol with a previous\npartial fix in commit ca16d5bee598 (\"futex: Prevent robust futex exit\nrace\"). Unfortunately, that fix is insufficient.\n\nIf a third task re-acquired the futex through the uncontended fast\npath in the meantime, the notification is lost: robust exit processing\nsees that it is owned by another task and does nothing, while the new\nowner sees no FUTEX_WAITERS when it unlocks and wakes nobody.\nThe remaining waiters sleep forever behind a free futex:\n\n  A owns the futex, B and C sleep in FUTEX_WAIT\n                                        uval == A | FUTEX_WAITERS\n  A robust unlock: store 0, FUTEX_WAKE(1) wakes B\n                                        uval == 0\n  D fast path acquire: cmpxchg(0 -> D)\n                                        uval == D, no FUTEX_WAITERS\n  B killed before acting on the wakeup\n  B exit walk, pending op: owner D != B -> no action\n  D unlock: no FUTEX_WAITERS -> no wake\n                                        C sleeps forever\n\nThis is clearly a shortcoming in the implementation, which fails to keep\nthe FUTEX_WAITERS bit consistent.\n\nWork around this by augmenting the robust list exit processing to also\nperform the extra wakeup if the futex word is owned by another thread but\nFUTEX_WAITERS is not set.\n\nThis does not fix the problem of a non-contended take over/release and free\nsequence, which has been discussed for years and has been addressed by\ncommit 3ca9595d9fb6 (\"futex: Add support for unlocking robust futexes\") and\nsubsequent changes, but failed to take the problem described above into\naccount.\n\nA more complete solution which is based on the in kernel unlock of\ncontended robust futexes has been discussed in the context of this change\nand should show up in mainline sooner than later.\n\n[ tglx: Amend change log slightly and fixup coding style ]","cvss":[],"epss":[{"cve":"CVE-2026-74658","epss":0.00177,"percentile":0.07338,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74658","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74659","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74659","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: bridge: mrp: fix uninitialised bytes on the wire  br_mrp_alloc_test_skb() builds MRP test frames on an skb from dev_alloc_skb(), which does not clear the linear data area.  On the MRA ring-role branch the sub-option TLV header is appended with  \tsub_tlv = skb_put(skb, sizeof(*sub_tlv)); \tsub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;  so sub_tlv->length is never written, and the two trailing alignment bytes are appended with a bare skb_put() that does not clear them either.  The neighbouring oui and sub_opt regions are explicitly zeroed, so three uninitialised bytes are left in every MRA MRP_Test frame that goes out.  Put the sub-option TLV header and the alignment padding in a single skb_put_zero(), which clears both.  The AUTO_MGR sub-TLV carries no payload, so the zeroed length field is already the value it should have.","cvss":[],"epss":[{"cve":"CVE-2026-74659","epss":0.00173,"percentile":0.06832,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74659","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74659","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/014c062d23c63ec77ef2cf17a0d9363c7441cc94","https://git.kernel.org/stable/c/06d58b8d2f053ced82e01efaeb6e7c82891eed58","https://git.kernel.org/stable/c/5912cf1822fbe53ae275c147868740eb384a5d3e","https://git.kernel.org/stable/c/63488dba65ef91373ef616575b32eb0eb21459f4","https://git.kernel.org/stable/c/7ebc23ff03668042e0b0e4034bb1518d36198d9e","https://git.kernel.org/stable/c/a5e385eeb2d6dbbbdebfa050e67c34734ae12693","https://git.kernel.org/stable/c/e08665218040f8e312abe40f74543186f3c2c941"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mrp: fix uninitialised bytes on the wire\n\nbr_mrp_alloc_test_skb() builds MRP test frames on an skb from\ndev_alloc_skb(), which does not clear the linear data area.  On the MRA\nring-role branch the sub-option TLV header is appended with\n\n\tsub_tlv = skb_put(skb, sizeof(*sub_tlv));\n\tsub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;\n\nso sub_tlv->length is never written, and the two trailing alignment bytes\nare appended with a bare skb_put() that does not clear them either.  The\nneighbouring oui and sub_opt regions are explicitly zeroed, so three\nuninitialised bytes are left in every MRA MRP_Test frame that goes out.\n\nPut the sub-option TLV header and the alignment padding in a single\nskb_put_zero(), which clears both.  The AUTO_MGR sub-TLV carries no\npayload, so the zeroed length field is already the value it should have.","cvss":[],"epss":[{"cve":"CVE-2026-74659","epss":0.00173,"percentile":0.06832,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74659","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74660","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74660","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: ebt_nflog: pin the NFLOG backend  nf_log_unregister() runs after the per-net teardown so its final RCU grace period also drains readers that obtained the logger from a per-net binding.  However, ebt_nflog passes an explicit ULOG log type to nf_log_packet() without holding a reference on the selected logger module, unlike the xt_NFLOG and nft_log frontends.  An ebtables nflog rule can therefore remain callable while nfnetlink_log is unloaded.  The resulting interleaving is:    CPU 0                               CPU 1   nfnetlink_log_fini()     unregister_pernet_subsys()       kfree(nfnl_log_pernet(net))                                       ebt_nflog_tg()                                         nf_log_packet()                                           nfulnl_log_packet()                                             instance_lookup_get_rcu()  The global ULOG logger is still registered at this point, so CPU 1 dereferences the per-net state after CPU 0 has freed it.  KASAN reported:    BUG: KASAN: slab-use-after-free in instance_lookup_get_rcu   Read of size 8 at addr ff110001052e6210 by task poc/92   Call Trace:    instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log]    nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log]    nf_log_packet+0x204/0x300    ebt_nflog_tg+0x351/0x550    ebt_do_table+0xedf/0x22b0   Allocated by task 90:    __kmalloc_noprof+0x186/0x470    ops_init+0x6d/0x420    register_pernet_operations+0x2f6/0x670    register_pernet_subsys+0x23/0x40   Freed by task 93:    kfree+0x131/0x3c0    ops_undo_list+0x3e3/0x700    unregister_pernet_operations+0x232/0x490    unregister_pernet_subsys+0x1c/0x30    nfnetlink_log_fini+0x34/0x450 [nfnetlink_log]  Acquire the ULOG logger module reference when an ebt_nflog rule is validated and release it when the rule is destroyed.  Request the NFLOG backend for legacy callers when needed, matching xt_NFLOG.  This prevents module teardown until all ebt_nflog rules have stopped using the logger.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74660","epss":0.00126,"percentile":0.0256,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74660","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74660","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2cac4294f184c9bc19ff82552c62b80498694c39","https://git.kernel.org/stable/c/30825970339c107bacaf7f61af90fcdb1f597ca1","https://git.kernel.org/stable/c/394d7939c6b2b9e6bea0844c89efb5913168d898","https://git.kernel.org/stable/c/3bcce49d617c593c7606083bfdb464a1761fa68d","https://git.kernel.org/stable/c/47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb","https://git.kernel.org/stable/c/6809379a860b9fccbb5435bf08343f6d081ac68d","https://git.kernel.org/stable/c/9d8a94b48b393885e7f876c8ef68ed4da5012078","https://git.kernel.org/stable/c/e2ab7e878bdbe80104c879c31fd2d82a476703b8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebt_nflog: pin the NFLOG backend\n\nnf_log_unregister() runs after the per-net teardown so its final RCU\ngrace period also drains readers that obtained the logger from a per-net\nbinding.  However, ebt_nflog passes an explicit ULOG log type to\nnf_log_packet() without holding a reference on the selected logger module,\nunlike the xt_NFLOG and nft_log frontends.\n\nAn ebtables nflog rule can therefore remain callable while nfnetlink_log\nis unloaded.  The resulting interleaving is:\n\n  CPU 0                               CPU 1\n  nfnetlink_log_fini()\n    unregister_pernet_subsys()\n      kfree(nfnl_log_pernet(net))\n                                      ebt_nflog_tg()\n                                        nf_log_packet()\n                                          nfulnl_log_packet()\n                                            instance_lookup_get_rcu()\n\nThe global ULOG logger is still registered at this point, so CPU 1\ndereferences the per-net state after CPU 0 has freed it.  KASAN reported:\n\n  BUG: KASAN: slab-use-after-free in instance_lookup_get_rcu\n  Read of size 8 at addr ff110001052e6210 by task poc/92\n  Call Trace:\n   instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log]\n   nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log]\n   nf_log_packet+0x204/0x300\n   ebt_nflog_tg+0x351/0x550\n   ebt_do_table+0xedf/0x22b0\n  Allocated by task 90:\n   __kmalloc_noprof+0x186/0x470\n   ops_init+0x6d/0x420\n   register_pernet_operations+0x2f6/0x670\n   register_pernet_subsys+0x23/0x40\n  Freed by task 93:\n   kfree+0x131/0x3c0\n   ops_undo_list+0x3e3/0x700\n   unregister_pernet_operations+0x232/0x490\n   unregister_pernet_subsys+0x1c/0x30\n   nfnetlink_log_fini+0x34/0x450 [nfnetlink_log]\n\nAcquire the ULOG logger module reference when an ebt_nflog rule is\nvalidated and release it when the rule is destroyed.  Request the NFLOG\nbackend for legacy callers when needed, matching xt_NFLOG.  This prevents\nmodule teardown until all ebt_nflog rules have stopped using the logger.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74660","epss":0.00126,"percentile":0.0256,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74660","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74662","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74662","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  inet: frags: publish queues before arming timer  inet_frag_create() arms the fragment queue timer before inserting the queue into the fqdir rhashtable. If the namespace fragment timeout is zero or negative, the timer can run before the queue is published.  The timer callback then marks the queue complete, tries to remove a node that is not in the hash table yet, and drops the anticipated hash reference. Creation can subsequently publish the completed queue without restoring that reference, leaving a stale hash node after the caller drops the remaining reference.  Publish the queue first and arm the timer while holding the queue lock. This makes timer expiry wait until the queue is visible in the hash table, so inet_frag_kill() can remove the node and balance the hash reference.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74662","epss":0.00514,"percentile":0.42126,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48316000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74662","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74662","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/08a04d7bfb9c103432561aff8a62b6872e694a6a","https://git.kernel.org/stable/c/39c6c4b267b65f00e0b0335a2ae00cbe9e3174f0","https://git.kernel.org/stable/c/4ed0681dc2c1e0538b79d2fc56190ffcb369dacd","https://git.kernel.org/stable/c/653d7ddf6cba867777a3d14c4f83ace008c5ad13","https://git.kernel.org/stable/c/928128865e43b197e30688dc1bc991592c97edcf","https://git.kernel.org/stable/c/9f904dd3e455750e5d4ec9b2f134835811b85a2f","https://git.kernel.org/stable/c/d3ffb89b2944672cf7bdd8e9ee577d2043b4a956","https://git.kernel.org/stable/c/f4e4dab62181b7fe7c011bed6fbef9fc3d48c769"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: publish queues before arming timer\n\ninet_frag_create() arms the fragment queue timer before inserting the\nqueue into the fqdir rhashtable. If the namespace fragment timeout is\nzero or negative, the timer can run before the queue is published.\n\nThe timer callback then marks the queue complete, tries to remove a node\nthat is not in the hash table yet, and drops the anticipated hash\nreference. Creation can subsequently publish the completed queue without\nrestoring that reference, leaving a stale hash node after the caller drops\nthe remaining reference.\n\nPublish the queue first and arm the timer while holding the queue lock.\nThis makes timer expiry wait until the queue is visible in the hash table,\nso inet_frag_kill() can remove the node and balance the hash reference.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74662","epss":0.00514,"percentile":0.42126,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74662","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74663","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74663","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: reject overly deep qdisc hierarchies  Deep qdisc hierarchies can lead to excessive recursion in qdisc tree walkers and exhaust the kernel stack. The existing loop check does not cover the create-and-graft path, so a hierarchy can still be extended by creating a new child qdisc below an already deep parent.  Store the hierarchy depth in struct Qdisc and update it when qdiscs are grafted. Reject new child qdiscs once the parent is already at the maximum allowed depth.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74663","epss":0.00129,"percentile":0.0289,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74663","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74663","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/08dc49df1527b09d9ea225a7265bbf6c237097bf","https://git.kernel.org/stable/c/2759acf08a3454866660edcd3ef4e64139f254a6","https://git.kernel.org/stable/c/8ca8cdb74939581339e1ae370193c0adb5a85336","https://git.kernel.org/stable/c/9f69bb9fdaa2fe64b68bb62fb84d405784bee540","https://git.kernel.org/stable/c/a4b14a4df29d36458a943f9b521ddd0f940363cc","https://git.kernel.org/stable/c/a627d36c2a94e18c8c105ae68008786dfd85592e","https://git.kernel.org/stable/c/dedd34b0f2310e28c5f6d4875cfbf4b7ed821c01","https://git.kernel.org/stable/c/e2d658c6427844cee5bc654b436ca68d680b6148"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: reject overly deep qdisc hierarchies\n\nDeep qdisc hierarchies can lead to excessive recursion in qdisc tree\nwalkers and exhaust the kernel stack. The existing loop check does not\ncover the create-and-graft path, so a hierarchy can still be extended by\ncreating a new child qdisc below an already deep parent.\n\nStore the hierarchy depth in struct Qdisc and update it when qdiscs are\ngrafted. Reject new child qdiscs once the parent is already at the maximum\nallowed depth.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74663","epss":0.00129,"percentile":0.0289,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74663","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74664","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74664","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: openvswitch: reallocate update replies for mismatched IDs  ovs_flow_cmd_new() preallocates the optional reply skb before it takes ovs_mutex and before it knows which existing flow will be updated.  That is normally fine because the skb is sized from the request flow identifier.  That identifier also becomes the inserted flow's identifier. For updates, however, a request with a UFID may miss the UFID lookup and then fall back to the flow key lookup.  That lookup can legitimately find an existing key-identified flow.  UFIDs are optional and the flow key is the primary identifier.  For echoed replies, ovs_flow_cmd_fill_info() writes the matched flow's identifier, not the request identifier used for the preallocation.  A short request UFID can therefore leave too little room for the key identifier. The fill can then fail with -EMSGSIZE and hit the BUG_ON(error < 0) in the update path.  Once the update target has been resolved, reallocate the reply skb if the matched flow needs a larger reply than the request identifier allowed.  Do this before replacing the actions so the request can still fail cleanly if the rare extra allocation fails.","cvss":[],"epss":[{"cve":"CVE-2026-74664","epss":0.00177,"percentile":0.07338,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74664","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74664","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/00f987f066e802793a37dd2167459e67cf2cf2ec","https://git.kernel.org/stable/c/20751193d83be2e9735d4faee71375691c09cd13","https://git.kernel.org/stable/c/23716dd9d8d46a5908536b73dc085e62f2b5c237","https://git.kernel.org/stable/c/5d1c224dd914579524a183a514c12b95095d12ce","https://git.kernel.org/stable/c/696a0b9435fce9cf4f1e9ba7f6afa6bee96c97fc","https://git.kernel.org/stable/c/69f40ccf85074981340847d650a9cbf9adabfbbe","https://git.kernel.org/stable/c/87d0c0040b5d4b61de51ae39132c4c46709f2f77","https://git.kernel.org/stable/c/bd8ca84d48cd9a4f6fc63df26512c55e1d339927"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: reallocate update replies for mismatched IDs\n\novs_flow_cmd_new() preallocates the optional reply skb before it takes\novs_mutex and before it knows which existing flow will be updated.\n\nThat is normally fine because the skb is sized from the request flow\nidentifier.  That identifier also becomes the inserted flow's identifier.\nFor updates, however, a request with a UFID may miss the UFID lookup and\nthen fall back to the flow key lookup.  That lookup can legitimately find\nan existing key-identified flow.  UFIDs are optional and the flow key is\nthe primary identifier.\n\nFor echoed replies, ovs_flow_cmd_fill_info() writes the matched flow's\nidentifier, not the request identifier used for the preallocation.  A short\nrequest UFID can therefore leave too little room for the key identifier.\nThe fill can then fail with -EMSGSIZE and hit the BUG_ON(error < 0) in the\nupdate path.\n\nOnce the update target has been resolved, reallocate the reply skb if the\nmatched flow needs a larger reply than the request identifier allowed.  Do\nthis before replacing the actions so the request can still fail cleanly if\nthe rare extra allocation fails.","cvss":[],"epss":[{"cve":"CVE-2026-74664","epss":0.00177,"percentile":0.07338,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74664","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74666","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74666","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  packet: synchronize pressure clearing with ring reconfiguration  packet_set_ring() updates the RX ring state under sk_receive_queue.lock, but used to publish the tpacket receive mode through po->prot_hook.func after releasing that lock. packet_poll() and packet_recvmsg() can then run the pressure clearing path after the ring has been cleared while still seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference stale or NULL ring storage.  Move the existing receive hook assignment into the same sk_receive_queue.lock section as the ring state update. Keep the assignment otherwise unchanged, including on TX ring reconfiguration, to avoid adding behavior changes that are not required for the fix.  Serialize packet_recvmsg() pressure clearing with the same queue lock only after PACKET_SOCK_PRESSURE has been observed. If the flag is clear and the socket has moved away from tpacket_rcv, packet_set_ring() has already detached the socket and waited for synchronize_net(), so no new packet input can set the flag again.  packet_poll() already holds sk_receive_queue.lock, so it uses the new unlocked helper directly.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74666","epss":0.00129,"percentile":0.02892,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74666","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74666","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1a35da325cac4d5bcad76a2aa943408a6f1d9000","https://git.kernel.org/stable/c/2c7b5eb87b2b288cdbde825f21d2b83b2f5da747","https://git.kernel.org/stable/c/8cfb2e71926a682f36c4240067d424074dd8f70f","https://git.kernel.org/stable/c/a08196c3cc105947746ec21309edfbb60275fcdb","https://git.kernel.org/stable/c/ad740b4990347521f0db260d381f9f74e7b340ba","https://git.kernel.org/stable/c/bf3c8e86bc8ad111be3f3136125e255344bcb3da","https://git.kernel.org/stable/c/cf8189b82bb93f219ab740e0346c919ad65ada62","https://git.kernel.org/stable/c/f015c9de92b731814059a343b765c60c0196225c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npacket: synchronize pressure clearing with ring reconfiguration\n\npacket_set_ring() updates the RX ring state under sk_receive_queue.lock,\nbut used to publish the tpacket receive mode through po->prot_hook.func\nafter releasing that lock. packet_poll() and packet_recvmsg() can then\nrun the pressure clearing path after the ring has been cleared while\nstill seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference\nstale or NULL ring storage.\n\nMove the existing receive hook assignment into the same\nsk_receive_queue.lock section as the ring state update. Keep the\nassignment otherwise unchanged, including on TX ring reconfiguration, to\navoid adding behavior changes that are not required for the fix.\n\nSerialize packet_recvmsg() pressure clearing with the same queue lock\nonly after PACKET_SOCK_PRESSURE has been observed. If the flag is clear\nand the socket has moved away from tpacket_rcv, packet_set_ring() has\nalready detached the socket and waited for synchronize_net(), so no new\npacket input can set the flag again.\n\npacket_poll() already holds sk_receive_queue.lock, so it uses the new\nunlocked helper directly.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74666","epss":0.00129,"percentile":0.02892,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74666","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74667","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74667","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/packet: reset the MAC header on the packet-socket transmit path  packet_parse_headers() resets the MAC header only for a SOCK_RAW frame whose socket did not bind a protocol. A protocol-bound SOCK_RAW socket, any SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave skb->mac_header unset here.  For frames sent via __dev_queue_xmit() this is harmless: it resets the MAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS path uses dev_direct_xmit(), which does not, so the frame reaches ndo_start_xmit() with the MAC header unset. A driver that reads eth_hdr(skb) on transmit then dereferences skb->head + (u16)~0, an out-of-bounds access ~64 KiB past the head -- the same class fixed for one consumer in commit f5089008f90c (\"macsec: do not read an unset MAC header in macsec_encrypt()\").  packet_parse_headers() runs only on the transmit path, where skb->data points at the start of the L2 header for every packet-socket type regardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied header and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC header unconditionally, mirroring __dev_queue_xmit(), so the frame is anchored on the bypass path too.  Found by 0sec (https://0sec.ai) using automated source analysis; verified against source and matched to the macsec KASAN report in f5089008f90c. Compile-tested.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74667","epss":0.00136,"percentile":0.03337,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10404000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74667","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74667","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1e43a1d66615f411d427f9df1f46dd049d9e3681","https://git.kernel.org/stable/c/2610ed4e86a4590234a9d70518c469751c5af231","https://git.kernel.org/stable/c/284f3e7a3f1a743fdf89e304fd1f19d5ffcff46d","https://git.kernel.org/stable/c/4057853a91fb796c4f47c7d1baf1aa085394148e","https://git.kernel.org/stable/c/971aa7d99242bbf09513e27b7a243f0b29ff23ae","https://git.kernel.org/stable/c/b47ba8fe6e1d2df8c92048de5afafd059447dc30","https://git.kernel.org/stable/c/c2707480cfbf19c7619acc9c089d17f20869821f","https://git.kernel.org/stable/c/fdd4d7d52358a58e351dd9d82530c04eba8ccd7a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: reset the MAC header on the packet-socket transmit path\n\npacket_parse_headers() resets the MAC header only for a SOCK_RAW frame\nwhose socket did not bind a protocol. A protocol-bound SOCK_RAW socket,\nany SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave\nskb->mac_header unset here.\n\nFor frames sent via __dev_queue_xmit() this is harmless: it resets the\nMAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS\npath uses dev_direct_xmit(), which does not, so the frame reaches\nndo_start_xmit() with the MAC header unset. A driver that reads\neth_hdr(skb) on transmit then dereferences skb->head + (u16)~0, an\nout-of-bounds access ~64 KiB past the head -- the same class fixed for\none consumer in commit f5089008f90c (\"macsec: do not read an unset MAC\nheader in macsec_encrypt()\").\n\npacket_parse_headers() runs only on the transmit path, where skb->data\npoints at the start of the L2 header for every packet-socket type\nregardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied\nheader and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC\nheader unconditionally, mirroring __dev_queue_xmit(), so the frame is\nanchored on the bypass path too.\n\nFound by 0sec (https://0sec.ai) using automated source analysis;\nverified against source and matched to the macsec KASAN report in\nf5089008f90c. Compile-tested.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74667","epss":0.00136,"percentile":0.03337,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74667","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74668","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74668","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  packet: use consistent hard_header_len in TX_RING send path  tpacket_snd() reads dev->hard_header_len independently for skb allocation and header construction in tpacket_fill_skb(). Concurrent netdevice reconfiguration can therefore make the reserved headroom smaller than the amount later pushed, or make copylen - hard_header_len negative.  Snapshot hard_header_len once before processing ring frames and use it for the frame limit, headroom allocation, copy length, and skb construction. Pass the snapshot to tpacket_fill_skb().  The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74668","epss":0.00129,"percentile":0.02892,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74668","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74668","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/016763e829cac37b3234eace86fd0a4c560de4a7","https://git.kernel.org/stable/c/21b5953e7494c16a42e6cd8cf110e18d13ae4a6b","https://git.kernel.org/stable/c/27e068d1b35dbec10a3cf268887c94407be4badc","https://git.kernel.org/stable/c/2a73b2c37ee3060a880b53cd24783d93fc7be5f8","https://git.kernel.org/stable/c/9c7e8ff48c377bef18c3d178748aea0575b69ede","https://git.kernel.org/stable/c/d48ea5c9c4c34dc0df621f0e39ed3a16b644621a","https://git.kernel.org/stable/c/d85d2fd54e901637c81d847811e03c662aee13cd","https://git.kernel.org/stable/c/e79f59a8527a49078cfaf8fe8fb5fcefc20c76d2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\npacket: use consistent hard_header_len in TX_RING send path\n\ntpacket_snd() reads dev->hard_header_len independently for skb\nallocation and header construction in tpacket_fill_skb(). Concurrent\nnetdevice reconfiguration can therefore make the reserved headroom\nsmaller than the amount later pushed, or make copylen - hard_header_len\nnegative.\n\nSnapshot hard_header_len once before processing ring frames and use it\nfor the frame limit, headroom allocation, copy length, and skb\nconstruction. Pass the snapshot to tpacket_fill_skb().\n\nThe separate SOCK_DGRAM consistency problem between hard_header_len and\nheader_ops->create is not addressed here.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74668","epss":0.00129,"percentile":0.02892,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74668","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74669","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74669","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipvs: clear IPv4 options after rebasing tunnel ICMP errors  ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the quoted original request before passing it to icmp_send(). However, IPCB(skb)->opt still describes the outer IPv4 header.  A timestamp option in the outer header can therefore leave an offset that points into the quoted transport header after the rebase. __ip_options_echo() treats a byte at that stale location as the option length and copies it into the fixed-size option storage on the __icmp_send() stack, causing a stack out-of-bounds write.  Clear the stale option metadata after resetting the network header. Keep the remaining control block fields, including the ingress interface used by the ICMP response path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74669","epss":0.00514,"percentile":0.42121,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48316000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74669","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74669","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/37c61b3745129cbd682c557b51345828120972e5","https://git.kernel.org/stable/c/384b4dae14277d369221d187e9b3af56c79d2e50","https://git.kernel.org/stable/c/6f46fc460e9316062bdcdf89199eb5d7a33da33b","https://git.kernel.org/stable/c/75eec935444db4af2123e0491936f6e273d7ea00","https://git.kernel.org/stable/c/79ffa99202c944467e28b13b513bf2998732edff","https://git.kernel.org/stable/c/c9413b50204738fbc429bb86bf01353c393a6c28","https://git.kernel.org/stable/c/e0ba936287dfe9783426aac27e5fd76fe35b38c9","https://git.kernel.org/stable/c/ed246dd85ebf27c1f6b7897834d40786c0ca3006"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: clear IPv4 options after rebasing tunnel ICMP errors\n\nip_vs_in_icmp() rebases an skb from the outer ICMP packet to the\nquoted original request before passing it to icmp_send(). However,\nIPCB(skb)->opt still describes the outer IPv4 header.\n\nA timestamp option in the outer header can therefore leave an offset\nthat points into the quoted transport header after the rebase.\n__ip_options_echo() treats a byte at that stale location as the option\nlength and copies it into the fixed-size option storage on the\n__icmp_send() stack, causing a stack out-of-bounds write.\n\nClear the stale option metadata after resetting the network header.\nKeep the remaining control block fields, including the ingress\ninterface used by the ICMP response path.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74669","epss":0.00514,"percentile":0.42121,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74669","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74671","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74671","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ima: fix out-of-bounds read in xattr_verify()  The digest-length check in xattr_verify() mixes int and size_t:  \tif (xattr_len - sizeof(xattr_value->type) - hash_start >= \t\t\tiint->ima_hash->length)  sizeof() yields size_t, so the usual arithmetic conversions promote the whole left-hand side to unsigned 64-bit before the subtraction runs. For a truncated xattr this underflows instead of going negative: a 1-byte IMA_XATTR_DIGEST_NG xattr (xattr_len == 1, hash_start == 1) turns \"1 - 1 - 1\" into SIZE_MAX, which is trivially >= ima_hash->length. The check then passes and the following memcmp() reads iint->ima_hash->length bytes starting past the end of the buffer vfs_getxattr_alloc() allocated for it.  Nothing upstream clamps xattr_len back into a safe range first: ima_get_hash_algo() only special-cases xattr_len < 2 to pick a default algorithm, and evm_verifyxattr() returns INTEGRITY_UNKNOWN rather than failing when no HMAC key is loaded, so a truncated security.ima value reaches the length check as-is.  Rewrite the comparison so every operand stays a signed int and no implicit conversion to size_t can occur.","cvss":[],"epss":[{"cve":"CVE-2026-74671","epss":0.00177,"percentile":0.07331,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74671","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74671","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/27f3924061592d0ef6b04e16f48754b6cb6adf27","https://git.kernel.org/stable/c/5ff232d31106f45ac87c3b64e1d35a0667777797","https://git.kernel.org/stable/c/7e515b6c9aab452a4f0734bd7208e4e780e164ca","https://git.kernel.org/stable/c/a784b4732ac7e51862b9b210c2d8b2ab9e83568c","https://git.kernel.org/stable/c/b6cb134707a2127d90a58d69dd818679cae8033c","https://git.kernel.org/stable/c/caeb105c15ea2431fa8da7ecfa242d0c68272426","https://git.kernel.org/stable/c/d823b5f4557083d1dd92096f796a78a2b1b06d10","https://git.kernel.org/stable/c/dd04114af0d451091f7b8cbd26d9e37d011e9131"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nima: fix out-of-bounds read in xattr_verify()\n\nThe digest-length check in xattr_verify() mixes int and size_t:\n\n\tif (xattr_len - sizeof(xattr_value->type) - hash_start >=\n\t\t\tiint->ima_hash->length)\n\nsizeof() yields size_t, so the usual arithmetic conversions promote\nthe whole left-hand side to unsigned 64-bit before the subtraction\nruns. For a truncated xattr this underflows instead of going negative:\na 1-byte IMA_XATTR_DIGEST_NG xattr (xattr_len == 1, hash_start == 1)\nturns \"1 - 1 - 1\" into SIZE_MAX, which is trivially >= ima_hash->length.\nThe check then passes and the following memcmp() reads\niint->ima_hash->length bytes starting past the end of the buffer\nvfs_getxattr_alloc() allocated for it.\n\nNothing upstream clamps xattr_len back into a safe range first:\nima_get_hash_algo() only special-cases xattr_len < 2 to pick a default\nalgorithm, and evm_verifyxattr() returns INTEGRITY_UNKNOWN rather than\nfailing when no HMAC key is loaded, so a truncated security.ima value\nreaches the length check as-is.\n\nRewrite the comparison so every operand stays a signed int and no\nimplicit conversion to size_t can occur.","cvss":[],"epss":[{"cve":"CVE-2026-74671","epss":0.00177,"percentile":0.07331,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74671","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74672","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74672","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF  Patch series \"mm: fix UAF caused by race between ptdump and vmap pgtable freeing\", v6.  Kernel page table walkers fall into two broad categories - those ranges where no exclusion is required via walk_kernel_page_table_range_lockless() and those where exclusion is required via walk_kernel_page_table_range() or walk_page_range_debug().  The former category is used only by arm64 arch code operating on ranges it both wholly owns and does not concurrently write.  The latter category consists of kernel page table walkers operating on ranges that are wholly owned (but which need exclusion against concurrent writers).  The lock used for exclusion is the mmap lock, and for kernel ranges this is the mmap lock on init_mm.  ptdump is a special case being both the only user of walk_page_range_debug(), and the only case in which it walks ranges it does not own.  This presents a problem, as page tables may be freed under ptdump.  And indeed there is a use-after-free bug in the kernel as a result, which this series addresses.  vmap promotes page tables to huge leaf entries where possible, freeing the lower page table when it does.  It does this with no meaningful locks held against concurrent ptdump walks.  As a result, use-after-free can currently occur.  This series addresses the issue by having the vmap huge promotion logic acquire the mmap read lock while both setting the huge page table entry and freeing the prior leaf page table.  The ptdump code already acquires the mmap write lock, so by doing so we ensure that the ptdump walker only ever observes either the huge page table entry or the existing page table entry, and nothing is freed underneath it.  A mitigation for this issue was already applied for arm64 in commit fa93b45fd397 (\"arm64: Enable vmalloc-huge with ptdump\"), which this series has to deal with carefully.  This mitigation resolves the issue by acquiring the mmap read lock on init_mm on vmap page table free if a ptdump is in progress.  However the fix in this series would cause a deadlock if we were to simply apply it for arm64 without also reverting the change.  This is because vmap may acquire the read lock before ptdump attempts to acquire the write lock, which then gets queued, and rwsem starvation rules mean that the (unacknowledged) nested mmap read lock in the arm64 code would also block, meaning the original read lock is never released and thus deadlock.  This series works around this by #ifndef CONFIG_ARM64'ing the mmap read lock in vmap logic, then partially reverting commit fa93b45fd397 (\"arm64: Enable vmalloc-huge with ptdump\"), keeping the enablement of huge vmap support, and removing the ifdeffery with the partial revert patch.  There are related issues that are also addressed in this series:  * x86 page attribute logic, specifically Change Page Attributes (CPA),   implements a feature whereby huge ranges can be collapsed into huge leaf   entries. This can similarly cause a UAF when done in parallel with a   ptdump walk, so similarly acquire the init_mm mmap lock to avoid this.  * The CPA logic allows concurrent page table manipulation and CPA   collapse, meaning the former risks accessing a page table the latter   frees. Fix this by acquiring mmap write lock on init_mm across the   whole CPA collapse operation and read lock on the page table   manipulation.  * x86 and arm64 permit walks of non-kernel mm's (both allowing efi mm   walks, and in x86's case arbitrary mm's), so we ensure kernel mappings   remain stable by locking the init_mm as well as the mm being walked.  The ordering of patches is established for both strict dependencies (the arm64 partial revert in particular has to be done after the vmap changes) and logical ones (the non-kernel mm fix only makes sense once the vmap/CPA fixes are in place).   This patch (of 3):  Currently there is a nasty ra ---truncated---","cvss":[],"epss":[{"cve":"CVE-2026-74672","epss":0.00173,"percentile":0.06833,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74672","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74672","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/26444eb71465c9934d9d418ef69c43f61185329b","https://git.kernel.org/stable/c/39c6772b56a6bbdd62794833f74232971d94d7c9","https://git.kernel.org/stable/c/3cc26c8907db0f5d1ff8043b5851ee572e9b3c98","https://git.kernel.org/stable/c/7ac8a333dd41ba5e1b4e8c6edbc48b15446c5468","https://git.kernel.org/stable/c/8d7f560f4b0482d469de962fbe4b59c37561052e","https://git.kernel.org/stable/c/c5bf8cd148cfea948cfa3db71da427294b20db0f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF\n\nPatch series \"mm: fix UAF caused by race between ptdump and vmap pgtable\nfreeing\", v6.\n\nKernel page table walkers fall into two broad categories - those ranges\nwhere no exclusion is required via walk_kernel_page_table_range_lockless()\nand those where exclusion is required via walk_kernel_page_table_range()\nor walk_page_range_debug().\n\nThe former category is used only by arm64 arch code operating on ranges it\nboth wholly owns and does not concurrently write.\n\nThe latter category consists of kernel page table walkers operating on\nranges that are wholly owned (but which need exclusion against concurrent\nwriters).\n\nThe lock used for exclusion is the mmap lock, and for kernel ranges this\nis the mmap lock on init_mm.\n\nptdump is a special case being both the only user of\nwalk_page_range_debug(), and the only case in which it walks ranges it\ndoes not own.\n\nThis presents a problem, as page tables may be freed under ptdump.  And\nindeed there is a use-after-free bug in the kernel as a result, which this\nseries addresses.\n\nvmap promotes page tables to huge leaf entries where possible, freeing the\nlower page table when it does.  It does this with no meaningful locks held\nagainst concurrent ptdump walks.\n\nAs a result, use-after-free can currently occur.  This series addresses\nthe issue by having the vmap huge promotion logic acquire the mmap read\nlock while both setting the huge page table entry and freeing the prior\nleaf page table.\n\nThe ptdump code already acquires the mmap write lock, so by doing so we\nensure that the ptdump walker only ever observes either the huge page\ntable entry or the existing page table entry, and nothing is freed\nunderneath it.\n\nA mitigation for this issue was already applied for arm64 in commit\nfa93b45fd397 (\"arm64: Enable vmalloc-huge with ptdump\"), which this series\nhas to deal with carefully.\n\nThis mitigation resolves the issue by acquiring the mmap read lock on\ninit_mm on vmap page table free if a ptdump is in progress.\n\nHowever the fix in this series would cause a deadlock if we were to simply\napply it for arm64 without also reverting the change.\n\nThis is because vmap may acquire the read lock before ptdump attempts to\nacquire the write lock, which then gets queued, and rwsem starvation rules\nmean that the (unacknowledged) nested mmap read lock in the arm64 code\nwould also block, meaning the original read lock is never released and\nthus deadlock.\n\nThis series works around this by #ifndef CONFIG_ARM64'ing the mmap read\nlock in vmap logic, then partially reverting commit fa93b45fd397 (\"arm64:\nEnable vmalloc-huge with ptdump\"), keeping the enablement of huge vmap\nsupport, and removing the ifdeffery with the partial revert patch.\n\nThere are related issues that are also addressed in this series:\n\n* x86 page attribute logic, specifically Change Page Attributes (CPA),\n  implements a feature whereby huge ranges can be collapsed into huge leaf\n  entries. This can similarly cause a UAF when done in parallel with a\n  ptdump walk, so similarly acquire the init_mm mmap lock to avoid this.\n\n* The CPA logic allows concurrent page table manipulation and CPA\n  collapse, meaning the former risks accessing a page table the latter\n  frees. Fix this by acquiring mmap write lock on init_mm across the\n  whole CPA collapse operation and read lock on the page table\n  manipulation.\n\n* x86 and arm64 permit walks of non-kernel mm's (both allowing efi mm\n  walks, and in x86's case arbitrary mm's), so we ensure kernel mappings\n  remain stable by locking the init_mm as well as the mm being walked.\n\nThe ordering of patches is established for both strict dependencies (the\narm64 partial revert in particular has to be done after the vmap changes)\nand logical ones (the non-kernel mm fix only makes sense once the vmap/CPA\nfixes are in place).\n\n\nThis patch (of 3):\n\nCurrently there is a nasty ra\n---truncated---","cvss":[],"epss":[{"cve":"CVE-2026-74672","epss":0.00173,"percentile":0.06833,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74672","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74673","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74673","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: evdev - fix information leak in evdev_pass_values()  In evdev_pass_values(), the input_event structure is allocated on the kernel stack and populated field-by-field. However, it is never fully initialized. On architectures where struct input_event contains explicit or implicit padding (such as the 32-bit __pad field on SPARC64), these padding bytes are left uninitialized.  When this event structure is subsequently passed to the client buffer and later copied to userspace, the uninitialized padding bytes leak kernel stack memory, potentially exposing sensitive information.  Similar issues exist in __evdev_queue_syn_dropped and __pass_event.  Fix this by explicitly zeroing the entire event structure with memset() before populating its fields. This ensures all padding bytes are cleared before the data crosses the security boundary.","cvss":[],"epss":[{"cve":"CVE-2026-74673","epss":0.00177,"percentile":0.0733,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74673","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74673","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/06a286b320236508d02ab2ccc9496352748652a8","https://git.kernel.org/stable/c/7d17e9454a9af3ec7aebb88b41a9deedd5b19a6b","https://git.kernel.org/stable/c/7e55ca1080f09d9f7112c7f20ac31f682c1f2374","https://git.kernel.org/stable/c/90f305f2c7a30257c683e13f4bf7c798eea992a0","https://git.kernel.org/stable/c/bd3c4108a56de34380edab670065e86283cb3029","https://git.kernel.org/stable/c/c6d5fa46c1ee25d068fc730fd377f0f54188d290","https://git.kernel.org/stable/c/d2e3839419ac4047835762c4d7712bda1101b57e","https://git.kernel.org/stable/c/e748811d9b80a3e101110ff4b3c612e5fca54d98"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - fix information leak in evdev_pass_values()\n\nIn evdev_pass_values(), the input_event structure is allocated on the\nkernel stack and populated field-by-field. However, it is never fully\ninitialized. On architectures where struct input_event contains explicit\nor implicit padding (such as the 32-bit __pad field on SPARC64), these\npadding bytes are left uninitialized.\n\nWhen this event structure is subsequently passed to the client buffer\nand later copied to userspace, the uninitialized padding bytes leak\nkernel stack memory, potentially exposing sensitive information.\n\nSimilar issues exist in __evdev_queue_syn_dropped and __pass_event.\n\nFix this by explicitly zeroing the entire event structure with memset()\nbefore populating its fields. This ensures all padding bytes are cleared\nbefore the data crosses the security boundary.","cvss":[],"epss":[{"cve":"CVE-2026-74673","epss":0.00177,"percentile":0.0733,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74673","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74675","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74675","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vt: stabilize tty reference in kbd_keycode with tty_port_tty_get  kbd_keycode() reads vc->port.tty without acquiring a tty reference, racing against con_shutdown() which clears port.tty under a different lock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference for the duration the tty pointer is needed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74675","epss":0.00129,"percentile":0.02891,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74675","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74675","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/38400673c9bfb39cfc87539e1a072087e98f4e4f","https://git.kernel.org/stable/c/38a0aa593ebc275aea6f79534d07f44e43768ce6","https://git.kernel.org/stable/c/3f6b1d3fcfc26dc3fc85262f753439df93b055b4","https://git.kernel.org/stable/c/b664592e9ba8c47c9e23408db7ba52eb9f946c8a","https://git.kernel.org/stable/c/b84fd400f80adf4d1c88fbce50ae1cf2f8119e65","https://git.kernel.org/stable/c/cab5a342f0589334046741006d8a280514f94235","https://git.kernel.org/stable/c/cc4a1a2ce0c58eafd477effb055863935260ddc1","https://git.kernel.org/stable/c/e25d47a526939ad44b75f778b8a7500562b84fc1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvt: stabilize tty reference in kbd_keycode with tty_port_tty_get\n\nkbd_keycode() reads vc->port.tty without acquiring a tty reference,\nracing against con_shutdown() which clears port.tty under a different\nlock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference\nfor the duration the tty pointer is needed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74675","epss":0.00129,"percentile":0.02891,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74675","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74676","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74676","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vt: add permission check for KDSKBMETA ioctl  KDSKBMETA modifies keyboard meta mode but lacks the !perm check that all other keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process to change meta mode on a non-controlling console without authorization.","cvss":[],"epss":[{"cve":"CVE-2026-74676","epss":0.00177,"percentile":0.07331,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74676","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74676","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1c5b67a1e2cb7d78dab321280f330b056e3bf437","https://git.kernel.org/stable/c/4671c3b79e337bbae28c2d79023dc642df012bde","https://git.kernel.org/stable/c/7bf32337a7103ccb686cbd240324bf26225ef2d6","https://git.kernel.org/stable/c/9f8cbaf4b774694dcc292e60509762483ebfd9ae","https://git.kernel.org/stable/c/a1c31e026c93e378e297a8df8328983d3013a59f","https://git.kernel.org/stable/c/a7ad0034453ba4c353f9b8f810ee2569de33d283","https://git.kernel.org/stable/c/d8ead5083b203d12b8319e7cb29cc6b8836e813f","https://git.kernel.org/stable/c/ddc4a8303347114e945b9e6e81b81d77855f7358"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvt: add permission check for KDSKBMETA ioctl\n\nKDSKBMETA modifies keyboard meta mode but lacks the !perm check that all\nother keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process\nto change meta mode on a non-controlling console without authorization.","cvss":[],"epss":[{"cve":"CVE-2026-74676","epss":0.00177,"percentile":0.07331,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74676","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74677","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74677","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: usb: ipheth: fix carrier_work UAF on disconnect  ipheth_sndbulk_callback() re-arms the carrier-check work on any non-zero URB status:  \telse \t\tschedule_delayed_work(&dev->carrier_work, 0);  Nothing ties that to the interface being up, so the work can be armed again after ipheth_close() has already drained it, and stay armed until the netdev whose private area embeds it is freed.  On unplug with a TX URB in flight, ipheth_disconnect() drains the work through unregister_netdev() -> ipheth_close() -> cancel_delayed_work_sync() and only then calls ipheth_kill_urbs(). usb_kill_urb() completes the in-flight TX URB with -ENOENT, so ipheth_sndbulk_callback() runs after the drain and re-arms carrier_work.  The same completion also re-arms the work if the interface is only brought down while a TX URB is in flight, and ipheth_carrier_check_work() then keeps re-queueing itself once a second. unregister_netdev() does not call ipheth_close() for an already-down interface, so nothing drains it on the later unplug either.  In both cases free_netdev() frees the netdev while carrier_work is still pending, and ipheth_carrier_check_work() dereferences freed memory.  Tie the work to the interface state instead of chasing the completion: disable it in ipheth_close() and enable it in ipheth_open(), so a schedule_delayed_work() from the URB completion is a no-op whenever the interface is not up. disable_delayed_work_sync() also waits for a running instance, so it fully replaces the cancel_delayed_work_sync() it takes the place of. The work starts out disabled in ipheth_probe() so the enable/disable counts balance from the first open.  Reproduced under KASAN on linux-next (next-20260731) with dummy_hcd and raw-gadget standing in for the device, driving the second path above (the interface is already down, so unregister_netdev() does not call ipheth_close()): 15 of 15 unpatched boots report a slab-use-after-free in __run_timers(), freed by ipheth_disconnect() and re-armed from ipheth_sndbulk_callback() via queue_delayed_work_on(). The same trigger on a kernel differing only by this patch reports 0 of 15, and the carrier check still functions across open/close cycles.  The reproducer needs an attached USB device that stops draining bulk OUT, plus a link down and unplug, driven as root. It is not a privilege boundary crossing and no exploit primitive was developed.  Found by 0sec (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-74677","epss":0.00168,"percentile":0.06343,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-74677","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74677","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2c7496124e94c7f9c3daa5c5b1fb563ca9d62c45","https://git.kernel.org/stable/c/48303f3ae0fa6e102f3fc7dbf1688cc179131962","https://git.kernel.org/stable/c/d07133fe1befae9a1e4c4c5e46ef0b73d2992020","https://git.kernel.org/stable/c/fde39b8a521780391fb4e5bda2c0aa4928947f12"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: ipheth: fix carrier_work UAF on disconnect\n\nipheth_sndbulk_callback() re-arms the carrier-check work on any\nnon-zero URB status:\n\n\telse\n\t\tschedule_delayed_work(&dev->carrier_work, 0);\n\nNothing ties that to the interface being up, so the work can be armed\nagain after ipheth_close() has already drained it, and stay armed\nuntil the netdev whose private area embeds it is freed.\n\nOn unplug with a TX URB in flight, ipheth_disconnect() drains the work\nthrough unregister_netdev() -> ipheth_close() ->\ncancel_delayed_work_sync() and only then calls ipheth_kill_urbs().\nusb_kill_urb() completes the in-flight TX URB with -ENOENT, so\nipheth_sndbulk_callback() runs after the drain and re-arms\ncarrier_work.\n\nThe same completion also re-arms the work if the interface is only\nbrought down while a TX URB is in flight, and\nipheth_carrier_check_work() then keeps re-queueing itself once a\nsecond. unregister_netdev() does not call ipheth_close() for an\nalready-down interface, so nothing drains it on the later unplug\neither.\n\nIn both cases free_netdev() frees the netdev while carrier_work is\nstill pending, and ipheth_carrier_check_work() dereferences freed\nmemory.\n\nTie the work to the interface state instead of chasing the completion:\ndisable it in ipheth_close() and enable it in ipheth_open(), so a\nschedule_delayed_work() from the URB completion is a no-op whenever\nthe interface is not up. disable_delayed_work_sync() also waits for a\nrunning instance, so it fully replaces the cancel_delayed_work_sync()\nit takes the place of. The work starts out disabled in ipheth_probe()\nso the enable/disable counts balance from the first open.\n\nReproduced under KASAN on linux-next (next-20260731) with dummy_hcd and\nraw-gadget standing in for the device, driving the second path above (the\ninterface is already down, so unregister_netdev() does not call\nipheth_close()): 15 of 15 unpatched boots report a slab-use-after-free in\n__run_timers(), freed by ipheth_disconnect() and re-armed from\nipheth_sndbulk_callback() via queue_delayed_work_on(). The\nsame trigger on a kernel differing only by this patch reports 0 of 15,\nand the carrier check still functions across open/close cycles.\n\nThe reproducer needs an attached USB device that stops draining bulk OUT,\nplus a link down and unplug, driven as root. It is not a privilege\nboundary crossing and no exploit primitive was developed.\n\nFound by 0sec (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-74677","epss":0.00168,"percentile":0.06343,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74677","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74678","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74678","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()  When the interface has NETIF_F_SG enabled and skb_linearize() fails in ax88179_tx_fixup(), the function returns NULL without freeing the skb.  usbnet_start_xmit() treats a NULL return from tx_fixup() as a drop (info->flags does not set FLAG_MULTI_PACKET for this driver), jumping to the \"drop\" label where it does `if (skb) dev_kfree_skb_any(skb)`. Because tx_fixup() returned NULL, the local skb variable in usbnet_start_xmit() is NULL, so the original skb is never freed — a memory leak on every TX frame whose linearization fails (i.e. under memory pressure).  Free the skb before returning, matching the error handling already used for the pskb_expand_head() failure path in the same function.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74678","epss":0.00479,"percentile":0.39831,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.35925},"relatedVulnerabilities":[{"id":"CVE-2026-74678","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74678","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1c63303659a2264bd55d9813df74cb4caeed5922","https://git.kernel.org/stable/c/1f428e30947395d9b9aacee03e25a4e6cfcad7a4","https://git.kernel.org/stable/c/2be5091fa693b9119ad25a8bb8c149d236a23ade","https://git.kernel.org/stable/c/4039cd807a5a46dc5f7618fffae926b8ad8455eb","https://git.kernel.org/stable/c/58733b1dd46bb231d9d279c132a20ee46da1b664","https://git.kernel.org/stable/c/83a765cbd7b4d11b0b9fa1bb9d941ae911a2159b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()\n\nWhen the interface has NETIF_F_SG enabled and skb_linearize() fails in\nax88179_tx_fixup(), the function returns NULL without freeing the skb.\n\nusbnet_start_xmit() treats a NULL return from tx_fixup() as a drop\n(info->flags does not set FLAG_MULTI_PACKET for this driver), jumping\nto the \"drop\" label where it does `if (skb) dev_kfree_skb_any(skb)`.\nBecause tx_fixup() returned NULL, the local skb variable in\nusbnet_start_xmit() is NULL, so the original skb is never freed — a\nmemory leak on every TX frame whose linearization fails (i.e. under\nmemory pressure).\n\nFree the skb before returning, matching the error handling already used\nfor the pskb_expand_head() failure path in the same function.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74678","epss":0.00479,"percentile":0.39831,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74678","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74679","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74679","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_ncm: Use unsigned int for ndp_index  The variable ndp_index is declared as a signed integer, but it stores the return value of get_ncm(), which is unsigned.  A malicious host can supply a large offset that overflows the signed ndp_index, making it negative. Because ndp_index is compared against unsigned bounds, this negative value bypasses sanity checks and leads to an out-of-bounds read when calculating the address of the NDP block (ntb_ptr + ndp_index).  Fix this by changing ndp_index to unsigned int to ensure consistent unsigned comparisons throughout the function.","cvss":[],"epss":[{"cve":"CVE-2026-74679","epss":0.00185,"percentile":0.08247,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0925},"relatedVulnerabilities":[{"id":"CVE-2026-74679","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74679","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/11413d7ed42174b8f5d8d0b6a25d10dc88239b21","https://git.kernel.org/stable/c/5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3","https://git.kernel.org/stable/c/6b1c8a9403a26cb0fed7a648916c74dc236da591","https://git.kernel.org/stable/c/9c8c6825a750fcd3efbe922847ca70ccd5a66857","https://git.kernel.org/stable/c/a1c0deeba4a46481543d6b09c665f758c54c3a1a","https://git.kernel.org/stable/c/d13f650a3485b58c124b3cda45597e8002c9c833","https://git.kernel.org/stable/c/d328fdc607fa1bb668ad512e1c918a120f78f337","https://git.kernel.org/stable/c/fc9e54e22845c4da29588ca0986cb7c795b5a262"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: Use unsigned int for ndp_index\n\nThe variable ndp_index is declared as a signed integer, but it stores\nthe return value of get_ncm(), which is unsigned.\n\nA malicious host can supply a large offset that overflows the signed\nndp_index, making it negative. Because ndp_index is compared against\nunsigned bounds, this negative value bypasses sanity checks and leads\nto an out-of-bounds read when calculating the address of the NDP\nblock (ntb_ptr + ndp_index).\n\nFix this by changing ndp_index to unsigned int to ensure consistent\nunsigned comparisons throughout the function.","cvss":[],"epss":[{"cve":"CVE-2026-74679","epss":0.00185,"percentile":0.08247,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74679","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74680","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74680","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()  If cxacru_cm() encounters an error while submitting or waiting for snd_urb, it aborts and returns the error without killing the already submitted rcv_urb. This leaves the rcv_urb active.  When this happens during initialization (e.g., in cxacru_atm_start()), the driver may ignore the error and proceed to call cxacru_poll_status(), which invokes cxacru_cm() again. Attempting to submit the still-active rcv_urb triggers a warning in usb_submit_urb():  cxacru 1-1:1.0: send of cm 0x84 failed (-104) ATM dev 0: cxacru_atm_start: CHIP_ADSL_LINE_START returned -104 ------------[ cut here ]------------ URB ffff88812658d200 submitted while active WARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0 drivers/usb/core/urb.c:379 ... Call Trace:  <TASK>  cxacru_cm+0x21a/0xf10 drivers/usb/atm/cxacru.c:631  cxacru_cm_get_array drivers/usb/atm/cxacru.c:722 [inline]  cxacru_poll_status+0x178/0x1110 drivers/usb/atm/cxacru.c:828  cxacru_atm_start+0x185/0x360 drivers/usb/atm/cxacru.c:814  usbatm_atm_init+0x144/0x3a0 drivers/usb/atm/usbatm.c:927  usbatm_usb_probe+0x15cb/0x1db0 drivers/usb/atm/usbatm.c:1178  cxacru_usb_probe+0x17f/0x220 drivers/usb/atm/cxacru.c:1370 ...  To fix this, ensure that rcv_urb is properly killed if cxacru_cm() aborts early. We can safely call usb_kill_urb() on rcv_urb in the error path, as it is safe to call even if the URB is not active (e.g., if it failed to submit in the first place, or if it already completed).","cvss":[],"epss":[{"cve":"CVE-2026-74680","epss":0.00177,"percentile":0.07394,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74680","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74680","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0af047703dbed8224552587ed436f14a24371b46","https://git.kernel.org/stable/c/2f73a065791d2a8e3f0bdf29248e33600359e865","https://git.kernel.org/stable/c/61093d7f1144f6a15bac505df35e5f535ade2ac1","https://git.kernel.org/stable/c/6133b461058316e3ccba7331f974d110d4c08b23","https://git.kernel.org/stable/c/645d98dbccdbfdbf0129f48822af7183492de091","https://git.kernel.org/stable/c/939b6a41f681aea52af678053072ee443068e93e","https://git.kernel.org/stable/c/993f7677949e3d72e360e86eed1f41c2511f75ed","https://git.kernel.org/stable/c/c2f811314be351d86b6ab41e9297ae80d8da6f86"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()\n\nIf cxacru_cm() encounters an error while submitting or waiting for snd_urb,\nit aborts and returns the error without killing the already submitted\nrcv_urb. This leaves the rcv_urb active.\n\nWhen this happens during initialization (e.g., in cxacru_atm_start()), the\ndriver may ignore the error and proceed to call cxacru_poll_status(), which\ninvokes cxacru_cm() again. Attempting to submit the still-active rcv_urb\ntriggers a warning in usb_submit_urb():\n\ncxacru 1-1:1.0: send of cm 0x84 failed (-104)\nATM dev 0: cxacru_atm_start: CHIP_ADSL_LINE_START returned -104\n------------[ cut here ]------------\nURB ffff88812658d200 submitted while active\nWARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0\ndrivers/usb/core/urb.c:379\n...\nCall Trace:\n <TASK>\n cxacru_cm+0x21a/0xf10 drivers/usb/atm/cxacru.c:631\n cxacru_cm_get_array drivers/usb/atm/cxacru.c:722 [inline]\n cxacru_poll_status+0x178/0x1110 drivers/usb/atm/cxacru.c:828\n cxacru_atm_start+0x185/0x360 drivers/usb/atm/cxacru.c:814\n usbatm_atm_init+0x144/0x3a0 drivers/usb/atm/usbatm.c:927\n usbatm_usb_probe+0x15cb/0x1db0 drivers/usb/atm/usbatm.c:1178\n cxacru_usb_probe+0x17f/0x220 drivers/usb/atm/cxacru.c:1370\n...\n\nTo fix this, ensure that rcv_urb is properly killed if cxacru_cm() aborts\nearly. We can safely call usb_kill_urb() on rcv_urb in the error path, as\nit is safe to call even if the URB is not active (e.g., if it failed to\nsubmit in the first place, or if it already completed).","cvss":[],"epss":[{"cve":"CVE-2026-74680","epss":0.00177,"percentile":0.07394,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74680","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74682","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74682","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: fix OOB write on Type II inbound URBs  data_ep_set_params() sizes each URB transfer buffer before it adds the Format Type II transfer delimiter:  \tu->packets = urb_packs; \tu->buffer_size = maxsize * u->packets;  \tif (fmt->fmt_type == UAC_FORMAT_TYPE_II) \t\tu->packets++; /* for transfer delimiter */ \tu->urb = usb_alloc_urb(u->packets, GFP_KERNEL);  buffer_size is computed from the pre-increment packet count and never recomputed, so for a Type II endpoint the buffer is one packet short of the packet count the URB is built with.  prepare_inbound_urb() then lays out one iso frame per packet and never consults buffer_size:  \toffs = 0; \tfor (i = 0; i < urb_ctx->packets; i++) { \t\turb->iso_frame_desc[i].offset = offs; \t\turb->iso_frame_desc[i].length = ep->curpacksize; \t\toffs += ep->curpacksize; \t}  \turb->transfer_buffer_length = offs; \turb->number_of_packets = urb_ctx->packets;  The last descriptor therefore points one packet past the end of the transfer buffer, where the host controller writes device data on every inbound transfer.  prepare_silent_urb() and prepare_playback_urb() bound their fill loops by ctx->buffer_size, so only capture is affected.  fmt_type comes from the device's audio streaming descriptors, so any device advertising a Type II capture format hits this once userspace sets hw_params on the stream.  KASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report per inbound transfer:    BUG: KASAN: slab-out-of-bounds in dummy_timer   Write of size 64 at addr ffff0000186171c0 by task cons02/166    __asan_memcpy    dummy_timer    hrtimer_run_softirq   Allocated by task 166:    usb_alloc_coherent    snd_usb_endpoint_set_params   The buggy address is located 0 bytes to the right of    allocated 64-byte region [ffff000018617180, ffff0000186171c0)  Compute buffer_size after the delimiter packet has been accounted for, and bound the fill loop by buffer_size, as prepare_silent_urb() already does on the outbound side.  This grows every Type II URB allocation by one maxsize packet.  Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[],"epss":[{"cve":"CVE-2026-74682","epss":0.00177,"percentile":0.07333,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74682","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74682","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0a235379825e1a6194e43861ee6658e5fc35686d","https://git.kernel.org/stable/c/137bf034740e5a2734794908d0aff1e0bd7cee6e","https://git.kernel.org/stable/c/6607f85242577f33d4540a0d1f4a6137f5367058","https://git.kernel.org/stable/c/69ee44e1a23be62318189dc4b37fa4ad94053269","https://git.kernel.org/stable/c/6af5f29af7711233ae68d3b25c15d67478468900","https://git.kernel.org/stable/c/ca22c94bdfc22c564ca2e11c87ba4d17ebeaaa9a","https://git.kernel.org/stable/c/d3ed4e6321bb453757044cb9e5ecb30a33f04903","https://git.kernel.org/stable/c/f1fbb50b99311b35c2e85cc70341d62082dca4b5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write on Type II inbound URBs\n\ndata_ep_set_params() sizes each URB transfer buffer before it adds the\nFormat Type II transfer delimiter:\n\n\tu->packets = urb_packs;\n\tu->buffer_size = maxsize * u->packets;\n\n\tif (fmt->fmt_type == UAC_FORMAT_TYPE_II)\n\t\tu->packets++; /* for transfer delimiter */\n\tu->urb = usb_alloc_urb(u->packets, GFP_KERNEL);\n\nbuffer_size is computed from the pre-increment packet count and never\nrecomputed, so for a Type II endpoint the buffer is one packet short of\nthe packet count the URB is built with.\n\nprepare_inbound_urb() then lays out one iso frame per packet and never\nconsults buffer_size:\n\n\toffs = 0;\n\tfor (i = 0; i < urb_ctx->packets; i++) {\n\t\turb->iso_frame_desc[i].offset = offs;\n\t\turb->iso_frame_desc[i].length = ep->curpacksize;\n\t\toffs += ep->curpacksize;\n\t}\n\n\turb->transfer_buffer_length = offs;\n\turb->number_of_packets = urb_ctx->packets;\n\nThe last descriptor therefore points one packet past the end of the\ntransfer buffer, where the host controller writes device data on every\ninbound transfer.  prepare_silent_urb() and prepare_playback_urb() bound\ntheir fill loops by ctx->buffer_size, so only capture is affected.\n\nfmt_type comes from the device's audio streaming descriptors, so any\ndevice advertising a Type II capture format hits this once userspace sets\nhw_params on the stream.\n\nKASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report\nper inbound transfer:\n\n  BUG: KASAN: slab-out-of-bounds in dummy_timer\n  Write of size 64 at addr ffff0000186171c0 by task cons02/166\n   __asan_memcpy\n   dummy_timer\n   hrtimer_run_softirq\n  Allocated by task 166:\n   usb_alloc_coherent\n   snd_usb_endpoint_set_params\n  The buggy address is located 0 bytes to the right of\n   allocated 64-byte region [ffff000018617180, ffff0000186171c0)\n\nCompute buffer_size after the delimiter packet has been accounted for,\nand bound the fill loop by buffer_size, as prepare_silent_urb() already\ndoes on the outbound side.  This grows every Type II URB allocation by\none maxsize packet.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[],"epss":[{"cve":"CVE-2026-74682","epss":0.00177,"percentile":0.07333,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74682","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74683","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74683","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: evdev - sanitize event type index when fetching event masks  The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK ioctls is used to index the static counts array in evdev_get_mask_cnt() and client evmasks array in evdev_get_mask().  While the event type is architecturally bounded by EV_CNT, speculative execution may mispredict bounds checks and perform out-of-bounds loads.  Sanitize the event type index in evdev_get_mask_cnt() branchlessly using array_index_mask_nospec(). This clamps the index to 0 for safe array access and forces the returned count to 0 speculatively when the index is out of bounds.  We do not need additional array_index_nospec() calls in evdev_get_mask() because evdev_get_mask_cnt() speculatively forces the count (and resulting xfer_size) to 0 for out-of-bounds types, preventing any speculative memory access to client evmasks array.","cvss":[],"epss":[{"cve":"CVE-2026-74683","epss":0.0019,"percentile":0.08759,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.095},"relatedVulnerabilities":[{"id":"CVE-2026-74683","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74683","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3abd29c61d2ef37c4102cf755b18be53bb9dbea6","https://git.kernel.org/stable/c/4034ef247a9dde3f56660b01f0c3280dac6b1274","https://git.kernel.org/stable/c/433913b4a92214d76e9f0c03ad9128fec943d5f8","https://git.kernel.org/stable/c/5db341189bb7ff041d570dbe36ecca7e32913927","https://git.kernel.org/stable/c/810e1883d4815f29c30d900ad7333d03cc2515d1","https://git.kernel.org/stable/c/c79b08d8fa230871a3634e34a66e591ac2d084ef","https://git.kernel.org/stable/c/f27fa9b39f925d26e034a1f382cb45523138f4ae","https://git.kernel.org/stable/c/f3fc329acad9a71b3c077237cbac20670d2358c8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - sanitize event type index when fetching event masks\n\nThe user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK\nioctls is used to index the static counts array in evdev_get_mask_cnt()\nand client evmasks array in evdev_get_mask().\n\nWhile the event type is architecturally bounded by EV_CNT, speculative\nexecution may mispredict bounds checks and perform out-of-bounds loads.\n\nSanitize the event type index in evdev_get_mask_cnt() branchlessly using\narray_index_mask_nospec(). This clamps the index to 0 for safe array\naccess and forces the returned count to 0 speculatively when the index\nis out of bounds.\n\nWe do not need additional array_index_nospec() calls in evdev_get_mask()\nbecause evdev_get_mask_cnt() speculatively forces the count (and\nresulting xfer_size) to 0 for out-of-bounds types, preventing any\nspeculative memory access to client evmasks array.","cvss":[],"epss":[{"cve":"CVE-2026-74683","epss":0.0019,"percentile":0.08759,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74683","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74684","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74684","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()  The commit 4f61f133f354 (\"net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null\") fixed a crash in tap_get_user() by assigning skb->dev before calling tun_vnet_hdr_to_skb(). This is required because virtio_net_hdr_to_skb() may invoke dev_parse_header_protocol(), which dereferences skb->dev. Without the assignment, a NULL pointer dereference can occur.  However, tap_get_user_xdp() still parses the virtio-net header before assigning skb->dev. When the vhost TX path passes an XDP buffer containing a GSO virtio-net header but the protocol is set to zero on purpose, tun_vnet_hdr_to_skb() can reach dev_parse_header_protocol() while skb->dev is still NULL, resulting in a crash.  Fix this by looking up the tap device and assigning skb->dev before calling tun_vnet_hdr_to_skb(), matching the ordering already used in tap_get_user(). Preserve the existing RCU read-side critical section across dev_queue_xmit().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.6,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74684","epss":0.00138,"percentile":0.03539,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.10073999999999998},"relatedVulnerabilities":[{"id":"CVE-2026-74684","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74684","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/15583b07fd691a844fbf7b3ad612cdc9e9a657c0","https://git.kernel.org/stable/c/164c31ee252ebd1ac8f44c2dfc5486b6d9a0379b","https://git.kernel.org/stable/c/3874892dd27d5387aa9a06f58d9060f18f351d24","https://git.kernel.org/stable/c/8b444b126cd8e4473e652f529753ed4dd1360a9c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()\n\nThe commit 4f61f133f354 (\"net: tap: NULL pointer derefence in\ndev_parse_header_protocol when skb->dev is null\") fixed a crash in\ntap_get_user() by assigning skb->dev before calling tun_vnet_hdr_to_skb().\nThis is required because virtio_net_hdr_to_skb() may invoke\ndev_parse_header_protocol(), which dereferences skb->dev. Without the\nassignment, a NULL pointer dereference can occur.\n\nHowever, tap_get_user_xdp() still parses the virtio-net header before\nassigning skb->dev. When the vhost TX path passes an XDP buffer containing\na GSO virtio-net header but the protocol is set to zero on purpose,\ntun_vnet_hdr_to_skb() can reach dev_parse_header_protocol() while skb->dev\nis still NULL, resulting in a crash.\n\nFix this by looking up the tap device and assigning skb->dev before calling\ntun_vnet_hdr_to_skb(), matching the ordering already used in\ntap_get_user(). Preserve the existing RCU read-side critical section across\ndev_queue_xmit().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.6,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74684","epss":0.00138,"percentile":0.03539,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74684","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74687","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74687","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  watchdog: at91sam9_wdt: prevent timer rearm during teardown  at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can leave the timer accessing the devm-allocated at91wdt after it has been freed.  Use timer_shutdown_sync() on both teardown paths. It waits for a running callback and rejects any attempt by the callback to rearm the timer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74687","epss":0.00127,"percentile":0.02689,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097155},"relatedVulnerabilities":[{"id":"CVE-2026-74687","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74687","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/29fe74c9aa69d78c1c6a3930f1d9fc5db71a6eed","https://git.kernel.org/stable/c/8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783","https://git.kernel.org/stable/c/b7949b0a7d998013b7ec8617a0ef5b07cca80be4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: at91sam9_wdt: prevent timer rearm during teardown\n\nat91_ping() rearms the watchdog timer from its callback. timer_delete()\nneither waits for a running callback nor prevents it from rearming the\ntimer, so probe failure or driver removal can leave the timer accessing the\ndevm-allocated at91wdt after it has been freed.\n\nUse timer_shutdown_sync() on both teardown paths. It waits for a running\ncallback and rejects any attempt by the callback to rearm the timer.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74687","epss":0.00127,"percentile":0.02689,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74687","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74688","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74688","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: clear control chunk transport if it is being removed  sctp_make_heartbeat_ack() caches the destination transport in chunk->transport without taking a reference. When src_out_of_asoc_ok is enabled, the HEARTBEAT ACK may remain queued on control_chunk_list instead of being transmitted immediately.  If the peer transport is removed while the chunk is still queued, sctp_assoc_rm_peer() drops the transport and schedules it for RCU freeing, but only clears cached transport pointers in out_chunk_list.  The queued control chunk therefore retains a dangling transport pointer.  Once an ASCONF_ACK clears the suppression and the queued control chunk is transmitted, SCTP dereferences the stale transport pointer, leading to a use-after-free.  Fix this by also clearing chunk->transport for queued control chunks in control_chunk_list when removing the transport.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74688","epss":0.005,"percentile":0.41181,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47000000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-74688","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74688","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/18d704bdd809377dfd81a3c2f42426763b5da227","https://git.kernel.org/stable/c/4d6b9cac6df5e0cfef1a66b3edd7aebdb9e4b7e7","https://git.kernel.org/stable/c/6160e756db81d6cb63e3e2952efcf6c5134be385","https://git.kernel.org/stable/c/8de65194a04d2552cd39b6c67d942d490f22d174","https://git.kernel.org/stable/c/936658ec41c28c397ef390140e02d4c91ade92f0","https://git.kernel.org/stable/c/c9158ceaf27780ef64534ad72f44ffde3f8ccc49","https://git.kernel.org/stable/c/dbb3f418a8665ffb0514e1a9520ab6a1c5d4d886","https://git.kernel.org/stable/c/fad4766a74220fe579c6fcaa10ba01c23529814f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: clear control chunk transport if it is being removed\n\nsctp_make_heartbeat_ack() caches the destination transport in\nchunk->transport without taking a reference. When src_out_of_asoc_ok is\nenabled, the HEARTBEAT ACK may remain queued on control_chunk_list instead\nof being transmitted immediately.\n\nIf the peer transport is removed while the chunk is still queued,\nsctp_assoc_rm_peer() drops the transport and schedules it for RCU freeing,\nbut only clears cached transport pointers in out_chunk_list.  The queued\ncontrol chunk therefore retains a dangling transport pointer.\n\nOnce an ASCONF_ACK clears the suppression and the queued control chunk is\ntransmitted, SCTP dereferences the stale transport pointer, leading to a\nuse-after-free.\n\nFix this by also clearing chunk->transport for queued control chunks in\ncontrol_chunk_list when removing the transport.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74688","epss":0.005,"percentile":0.41181,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74688","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74689","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74689","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/atm: fix slab-out-of-bounds read in vcc_setsockopt()  vcc_setsockopt() contained an ineffective optlen check:   if (__SO_LEVEL_MATCH(optname, level) && optlen != __SO_SIZE(optname))       return -EINVAL;  If __SO_LEVEL_MATCH(optname, level) evaluated to false (e.g. if the caller passed a mismatched level), the length check optlen != __SO_SIZE(optname) was short-circuited and bypassed. Execution then fell through to switch(optname), calling copy_from_sockptr() assuming optval contained sufficient space.  Furthermore, even if level matched, a cgroup BPF setsockopt filter could shrink optlen after entry. Because copy_from_sockptr() on kernel pointers uses memcpy(), this leads to a KASAN slab-out-of-bounds read when optlen is smaller than the expected structure size.  Fix this by using copy_safe_from_sockptr(), which unconditionally validates that optlen is at least the expected size before copying. Also change the local 'value' variable type from 'unsigned long' to 'int' so that SO_SETCLP matches its sizeof(int) ABI encoding on 64-bit systems.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74689","epss":0.00139,"percentile":0.03598,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10146999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74689","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74689","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2c5988c7349c0b64a7e0441bfc6e1dca54f7116a","https://git.kernel.org/stable/c/35f258fee9ed358c6d0f57f91c30bf029c3724af","https://git.kernel.org/stable/c/6eb6af88710977eb529b558a07294874d8c40c4d","https://git.kernel.org/stable/c/9f77c1ab382188f5b51982fab6d913443b6dc59f","https://git.kernel.org/stable/c/b3bcd5d65ac03c15787b2a5b36c718e26a689336","https://git.kernel.org/stable/c/d0c80dbb970439bd2eeb0e5effff8c16a5f4e1e3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/atm: fix slab-out-of-bounds read in vcc_setsockopt()\n\nvcc_setsockopt() contained an ineffective optlen check:\n  if (__SO_LEVEL_MATCH(optname, level) && optlen != __SO_SIZE(optname))\n      return -EINVAL;\n\nIf __SO_LEVEL_MATCH(optname, level) evaluated to false (e.g. if the caller\npassed a mismatched level), the length check optlen != __SO_SIZE(optname)\nwas short-circuited and bypassed. Execution then fell through to switch(optname),\ncalling copy_from_sockptr() assuming optval contained sufficient space.\n\nFurthermore, even if level matched, a cgroup BPF setsockopt filter could shrink\noptlen after entry. Because copy_from_sockptr() on kernel pointers uses memcpy(),\nthis leads to a KASAN slab-out-of-bounds read when optlen is smaller than the\nexpected structure size.\n\nFix this by using copy_safe_from_sockptr(), which unconditionally validates\nthat optlen is at least the expected size before copying. Also change the local\n'value' variable type from 'unsigned long' to 'int' so that SO_SETCLP matches\nits sizeof(int) ABI encoding on 64-bit systems.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":1.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74689","epss":0.00139,"percentile":0.03598,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74689","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74690","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74690","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/ism: Fix UAF of sba and ieq during ism_dev_exit()  A ism interrupt handler can be active in parallel with ism_dev_exit(), accessing freed data structures.  No new interrupts will be generated after unregister_ieq(). Drain ongoing interrupt handlers by free_irq(), before freeing ism data structures.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74690","epss":0.0014,"percentile":0.03704,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11130000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74690","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74690","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/774394d27930ec4cf4cb3eed8ab6a4d20cb2430a","https://git.kernel.org/stable/c/b1896543ce59c4258625a35cf41e23a9a1f80ea2","https://git.kernel.org/stable/c/fc3021284050ecb3bba8a7851340cedcb5037928"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/ism: Fix UAF of sba and ieq during ism_dev_exit()\n\nA ism interrupt handler can be active in parallel with ism_dev_exit(),\naccessing freed data structures.\n\nNo new interrupts will be generated after unregister_ieq(). Drain ongoing\ninterrupt handlers by free_irq(), before freeing ism data structures.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74690","epss":0.0014,"percentile":0.03704,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74690","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74691","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74691","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: thunderbolt: Tear down DMA paths before stopping the rings  tbnet_tear_down() stops both rings and frees their frame buffers before calling tb_xdomain_disable_paths().  tb_ring_stop() zeroes the ring's descriptor base and tbnet_free_buffers() unmaps and frees the pages the frames sit in, so by the time __tb_path_deactivate_hop() polls the hop's 'pending' bit, anything still in flight has nowhere to drain to.  The teardown sequence has been in this order since the driver was added. The setup path has not: commit ff7cd07f3064 (\"net: thunderbolt: Enable DMA paths only after rings are enabled\") moved the path enable to the end of tbnet_connected_work() and documented why:  \t/* Both logins successful so enable the rings, high-speed DMA \t * paths and start the network device queue. \t * \t * Note we enable the DMA paths last to make sure we have primed \t * the Rx ring before any incoming packets are allowed to \t * arrive. \t */  Teardown was never updated to match, so the rings and the paths now come down in the same order they go up instead of in reverse.  On an ASMedia ASM4242 host router the 'pending' bit then never clears: every teardown burns the full 500 ms timeout and __tb_path_deactivate_hop() returns -ETIMEDOUT.  Raising the timeout to 5 s does not help, so the hop is not slow to drain, it never drains at all.  The failure is invisible above the thunderbolt core. __tb_path_deactivate_hops() is void and only calls tb_port_warn(); tb_path_deactivate(), tb_tunnel_deactivate() and __tb_disconnect_xdomain_paths() are void as well, and tb_disconnect_xdomain_paths() ends in an unconditional \"return 0\".  So tb_xdomain_disable_paths() reports success and the netdev_warn() below it never fires.  Repeated teardowns eventually take the XDomain control channel down, after which the peer node is gone and only a power cycle brings the controller back.  Deactivating the paths first fixes it.  Measured with kretprobes on a stock v6.17 tree with no other patches applied, on a link that was up and had just carried traffic:    before: __tb_path_deactivate_hop() returns 0 for the first hop, then           -ETIMEDOUT for the second 500335 us later   after:  0 for both, 525 us apart  Alternating the two orderings ABBA over three load levels, four teardowns per arm: every teardown failed before the change (21 of 21 that ran), none failed after (0 of 24).  The before arms ran short because the link died partway through.  The same split shows up when the interface is enslaved to a bond instead of just brought down, which is how I ran into this in the first place.  Throughput and latency after the change are unchanged.  Hosts whose routers drain the hop despite the stale descriptor base see no functional difference, since the paths end up deactivated either way.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74691","epss":0.00256,"percentile":0.17261,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.20864000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-74691","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74691","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0da9a6d27155ad072dd76db8cd637feead99a0e0","https://git.kernel.org/stable/c/103a9b663ac1cacb8465aeff18f84a247154a562","https://git.kernel.org/stable/c/4dd71cb0d23d40cb58fe4261c7bd183dca66caa0","https://git.kernel.org/stable/c/68bf02b6b4ad3f748c6db71fd77b6c0402d252f4","https://git.kernel.org/stable/c/7cce39109206bc5497e0953806563644b88bfc44","https://git.kernel.org/stable/c/9a482b2b117e5fa656b6d24fc01799e8ac2d4368","https://git.kernel.org/stable/c/b5a21615f627c48dafaa6ef82a34a5b97a4352aa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Tear down DMA paths before stopping the rings\n\ntbnet_tear_down() stops both rings and frees their frame buffers before\ncalling tb_xdomain_disable_paths().  tb_ring_stop() zeroes the ring's\ndescriptor base and tbnet_free_buffers() unmaps and frees the pages the\nframes sit in, so by the time __tb_path_deactivate_hop() polls the hop's\n'pending' bit, anything still in flight has nowhere to drain to.\n\nThe teardown sequence has been in this order since the driver was added.\nThe setup path has not: commit ff7cd07f3064 (\"net: thunderbolt: Enable\nDMA paths only after rings are enabled\") moved the path enable to the end\nof tbnet_connected_work() and documented why:\n\n\t/* Both logins successful so enable the rings, high-speed DMA\n\t * paths and start the network device queue.\n\t *\n\t * Note we enable the DMA paths last to make sure we have primed\n\t * the Rx ring before any incoming packets are allowed to\n\t * arrive.\n\t */\n\nTeardown was never updated to match, so the rings and the paths now come\ndown in the same order they go up instead of in reverse.\n\nOn an ASMedia ASM4242 host router the 'pending' bit then never clears:\nevery teardown burns the full 500 ms timeout and\n__tb_path_deactivate_hop() returns -ETIMEDOUT.  Raising the timeout to\n5 s does not help, so the hop is not slow to drain, it never drains\nat all.\n\nThe failure is invisible above the thunderbolt core.\n__tb_path_deactivate_hops() is void and only calls tb_port_warn();\ntb_path_deactivate(), tb_tunnel_deactivate() and\n__tb_disconnect_xdomain_paths() are void as well, and\ntb_disconnect_xdomain_paths() ends in an unconditional \"return 0\".  So\ntb_xdomain_disable_paths() reports success and the netdev_warn() below\nit never fires.  Repeated teardowns eventually take the XDomain control\nchannel down, after which the peer node is gone and only a power cycle\nbrings the controller back.\n\nDeactivating the paths first fixes it.  Measured with kretprobes on a\nstock v6.17 tree with no other patches applied, on a link that was up\nand had just carried traffic:\n\n  before: __tb_path_deactivate_hop() returns 0 for the first hop, then\n          -ETIMEDOUT for the second 500335 us later\n  after:  0 for both, 525 us apart\n\nAlternating the two orderings ABBA over three load levels, four\nteardowns per arm: every teardown failed before the change (21 of 21\nthat ran), none failed after (0 of 24).  The before arms ran short\nbecause the link died partway through.  The same split shows up when\nthe interface is enslaved to a bond instead of just brought down, which\nis how I ran into this in the first place.  Throughput and latency after\nthe change are unchanged.\n\nHosts whose routers drain the hop despite the stale descriptor base see\nno functional difference, since the paths end up deactivated either way.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74691","epss":0.00256,"percentile":0.17261,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74691","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74692","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74692","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/smc: fix TOCTOU race between smc_listen_out() and listener close  smc_listen_out() reads lsmc->sk.sk_state without the listener lock, then acquires lock_sock_nested() only after the check passes. This opens a window where smc_close_active() can transition the listener to SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept queue, and release the lock, all between the lockless read and the delayed lock acquisition:    smc_listen_work (smc_hs_wq)          smc_close_active()   -------------------------------      -------------------------   release_sock(child)   if (sk_state == SMC_LISTEN) TRUE                                         lock_sock(listener)                                         sk_state = SMC_CLOSED                                         smc_close_cleanup_listen()                                         release_sock(listener)                                         flush_work(tcp_listen_work)   lock_sock_nested(listener)   smc_accept_enqueue(listener, child) /* child enqueued on dead listener */  smc_close_active() flushes only tcp_listen_work. Work items already dispatched onto smc_hs_wq for the CLC handshake continue running unguarded. smc_accept_enqueue() takes a sock_hold() on the child that is never released, so the child smc_sock, its clcsock, and the reference all leak. A remote peer that opens TCP connections while the server calls close() can exhaust kernel memory.  Move lock_sock_nested() to before the sk_state check so that the test and the enqueue are atomic under the listener lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74692","epss":0.0049,"percentile":0.4056,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3675},"relatedVulnerabilities":[{"id":"CVE-2026-74692","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74692","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/00f89433777236ced4771211047fb5d4cd581cea","https://git.kernel.org/stable/c/01865e1ddb126b25ac9eba5cdd7ec49e11183a64","https://git.kernel.org/stable/c/185a4caeecabc150106deda1da170b09f2ad803f","https://git.kernel.org/stable/c/53c7938d8bcfde3296ec1a347ba2a9393c1fdcfa","https://git.kernel.org/stable/c/78e5ebcd1c10ed7c8bda0a99e0abd5b62da86d67","https://git.kernel.org/stable/c/feb71634bb1abab3e8fb5cde874b27001cc1282e","https://git.kernel.org/stable/c/ff5bcd804b5bc5c64736b7d318c20e12ea9506b8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix TOCTOU race between smc_listen_out() and listener close\n\nsmc_listen_out() reads lsmc->sk.sk_state without the listener lock,\nthen acquires lock_sock_nested() only after the check passes. This\nopens a window where smc_close_active() can transition the listener\nto SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept\nqueue, and release the lock, all between the lockless read and the\ndelayed lock acquisition:\n\n  smc_listen_work (smc_hs_wq)          smc_close_active()\n  -------------------------------      -------------------------\n  release_sock(child)\n  if (sk_state == SMC_LISTEN) TRUE\n                                        lock_sock(listener)\n                                        sk_state = SMC_CLOSED\n                                        smc_close_cleanup_listen()\n                                        release_sock(listener)\n                                        flush_work(tcp_listen_work)\n  lock_sock_nested(listener)\n  smc_accept_enqueue(listener, child) /* child enqueued on dead listener */\n\nsmc_close_active() flushes only tcp_listen_work. Work items already\ndispatched onto smc_hs_wq for the CLC handshake continue running\nunguarded. smc_accept_enqueue() takes a sock_hold() on the child that\nis never released, so the child smc_sock, its clcsock, and the\nreference all leak. A remote peer that opens TCP connections while the\nserver calls close() can exhaust kernel memory.\n\nMove lock_sock_nested() to before the sk_state check so that the test\nand the enqueue are atomic under the listener lock.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74692","epss":0.0049,"percentile":0.4056,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74692","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74693","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74693","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: prestera: validate firmware header length  prestera_fw_hdr_parse() reads the firmware header before checking that the firmware image contains that header.  Reject images shorter than struct prestera_fw_header before decoding the magic and version fields.","cvss":[],"epss":[{"cve":"CVE-2026-74693","epss":0.00177,"percentile":0.07328,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74693","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74693","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0fbcceb9d19f2d1dcdf099aee590f2517cb718bb","https://git.kernel.org/stable/c/363e048a9d0a6c245cbc348c8a220170afed046a","https://git.kernel.org/stable/c/38a3afbf9fd8a2e8c47fa3ca47b425a8a9623240","https://git.kernel.org/stable/c/470ac9cce7308e60cf2dceb448749cdd006e73de","https://git.kernel.org/stable/c/6fad06bb793d7089ae05b9fcf46e11be2dfe4850","https://git.kernel.org/stable/c/7fa8a12296d8d5aa4b1c3904f0b354d81124cf29","https://git.kernel.org/stable/c/8ae344eb540af3f457179b52bc6061416752485c","https://git.kernel.org/stable/c/e0f382e8084117f0b11ffb070fe1079e38c0d7f9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: prestera: validate firmware header length\n\nprestera_fw_hdr_parse() reads the firmware header before checking\nthat the firmware image contains that header.\n\nReject images shorter than struct prestera_fw_header before decoding the\nmagic and version fields.","cvss":[],"epss":[{"cve":"CVE-2026-74693","epss":0.00177,"percentile":0.07328,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74693","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74694","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74694","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length  ncsi_send_cmd_nl() takes the number of bytes to copy from the attacker-controlled ncsi_pkt_hdr.length field of the in-band packet header, while the source buffer is the NCSI_ATTR_DATA netlink attribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr). The two length sources are never cross-checked: only nla_len() >= sizeof(struct ncsi_pkt_hdr) is enforced.  With hdr->length set larger than the attribute payload (up to 65535 against at most 2032 readable bytes), ncsi_cmd_handler_oem() copies past the end of the netlink attribute buffer with unsafe_memcpy(), leaking up to ~64KB of kernel heap memory into the transmitted NCSI command packet. The destination skb is sized by the declared payload, so the write side does not overflow - this is a pure OOB read / information leak, reachable with CAP_NET_ADMIN on systems with a registered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where NET_NCSI=y is standard).  Reject commands whose declared payload extends past the end of the data attribute.  The issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab.","cvss":[],"epss":[{"cve":"CVE-2026-74694","epss":0.00177,"percentile":0.07328,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74694","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74694","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/02226af69362758046822840fc6a497f5de33f00","https://git.kernel.org/stable/c/3a60b5af75abe8e3494ccd074fb4ae6e601a3e55","https://git.kernel.org/stable/c/43c7d0a6917751ea898ae584d00f24f5deac46d4","https://git.kernel.org/stable/c/4489b4a17892750131e4bef4bc1d3d703c8fb5ba","https://git.kernel.org/stable/c/67c72b8ef63d9d9a610546fda30b116638f39745","https://git.kernel.org/stable/c/afa58b7384913c8773d837acdb07b035690ec5d2","https://git.kernel.org/stable/c/b5231ad0b376b801ab8cf2962b182cc29deaedb3","https://git.kernel.org/stable/c/e60afa01d35f8b2671b27ca93309921427144cce"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length\n\nncsi_send_cmd_nl() takes the number of bytes to copy from the\nattacker-controlled ncsi_pkt_hdr.length field of the in-band packet\nheader, while the source buffer is the NCSI_ATTR_DATA netlink\nattribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr).\nThe two length sources are never cross-checked: only\nnla_len() >= sizeof(struct ncsi_pkt_hdr) is enforced.\n\nWith hdr->length set larger than the attribute payload (up to 65535\nagainst at most 2032 readable bytes), ncsi_cmd_handler_oem() copies\npast the end of the netlink attribute buffer with unsafe_memcpy(),\nleaking up to ~64KB of kernel heap memory into the transmitted NCSI\ncommand packet. The destination skb is sized by the declared payload,\nso the write side does not overflow - this is a pure OOB read /\ninformation leak, reachable with CAP_NET_ADMIN on systems with a\nregistered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where\nNET_NCSI=y is standard).\n\nReject commands whose declared payload extends past the end of the\ndata attribute.\n\nThe issue was found by the autokbug dynamic kernel fuzzer at Tencent\nYunding Lab.","cvss":[],"epss":[{"cve":"CVE-2026-74694","epss":0.00177,"percentile":0.07328,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74694","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74695","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74695","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()  Incoming skbs passing through netfilter flowtable offload hooks (or XFRM offload path) might already carry a ref-counted dst_entry assigned during earlier RX or routing steps.  Calling skb_dst_set_noref() when skb already holds a ref-counted dst overwrites skb->_skb_refdst, leaking the previous dst_entry reference count and triggering a DEBUG_NET_WARN_ON_ONCE assertion in skb_dst_check_unset():    WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170   WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234   WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864  Drop any existing dst_entry reference with skb_dst_drop(skb) before setting the non-referenced flowtable destination.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74695","epss":0.00426,"percentile":0.35926,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3195},"relatedVulnerabilities":[{"id":"CVE-2026-74695","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74695","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/12afa450a6a6c0cce2c42b7545a9958f62d8a00c","https://git.kernel.org/stable/c/538e67e8c7889cf5f93951f5309d1bcb41f86036","https://git.kernel.org/stable/c/8aecf0bbcc72605592134c917c222207d8f63ab0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()\n\nIncoming skbs passing through netfilter flowtable offload hooks (or XFRM\noffload path) might already carry a ref-counted dst_entry assigned during\nearlier RX or routing steps.\n\nCalling skb_dst_set_noref() when skb already holds a ref-counted dst\noverwrites skb->_skb_refdst, leaking the previous dst_entry reference\ncount and triggering a DEBUG_NET_WARN_ON_ONCE assertion in\nskb_dst_check_unset():\n\n  WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170\n  WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234\n  WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864\n\nDrop any existing dst_entry reference with skb_dst_drop(skb) before\nsetting the non-referenced flowtable destination.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74695","epss":0.00426,"percentile":0.35926,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74695","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74696","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74696","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tcp: fix TFO max_qlen accounting across reuseport migration  A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through far more pending Fast Open requests than it was configured for.  This only shows up with SO_REUSEPORT listener migration, where closing a listener hands its still-pending TFO children over to a surviving one.  fastopenq.qlen is charged in tcp_fastopen_create_child() when the child is created and uncharged in reqsk_fastopen_remove() when the handshake completes.  The uncharge follows rsk_listener of the request the child points at, and inet_reqsk_clone() has repointed the child at a new request owned by the new listener, so the ++ and the -- land on two different sockets.  The new listener's qlen drifts negative and its limit no longer binds.  Charge the new listener during migration, like reqsk_queue_migrated() already does for queue->young and queue->qlen.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74696","epss":0.0049,"percentile":0.4056,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3675},"relatedVulnerabilities":[{"id":"CVE-2026-74696","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74696","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/585fc5247d14939a561056aa2addd9b7c2b1f670","https://git.kernel.org/stable/c/6e10ee56524a26b250229ad348637825646ddb88","https://git.kernel.org/stable/c/a0ab2ba83e35159d81cec830a92e885ecf8139be","https://git.kernel.org/stable/c/a66e869cf0c90c1e47ae75f72b6482acbfc808ff","https://git.kernel.org/stable/c/b6247e0f96bd825ffb2005257f6177b5e642dee6","https://git.kernel.org/stable/c/d974618b2097453778389d385e3741629c40e0a3","https://git.kernel.org/stable/c/e98f0d80b9cccb5f828425d2004f9686e7d1ae24"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix TFO max_qlen accounting across reuseport migration\n\nA listener's TCP_FASTOPEN max_qlen stops being accurate and lets through\nfar more pending Fast Open requests than it was configured for.\n\nThis only shows up with SO_REUSEPORT listener migration, where closing a\nlistener hands its still-pending TFO children over to a surviving one.\n\nfastopenq.qlen is charged in tcp_fastopen_create_child() when the child\nis created and uncharged in reqsk_fastopen_remove() when the handshake\ncompletes.  The uncharge follows rsk_listener of the request the child\npoints at, and inet_reqsk_clone() has repointed the child at a new\nrequest owned by the new listener, so the ++ and the -- land on two\ndifferent sockets.  The new listener's qlen drifts negative and its\nlimit no longer binds.\n\nCharge the new listener during migration, like reqsk_queue_migrated()\nalready does for queue->young and queue->qlen.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74696","epss":0.0049,"percentile":0.4056,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74696","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74697","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74697","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bnxt_en: Disable EOP for TPA on all chips to prevent data corruption  EOP (End of frame padding) on the AGG ring may cause overlapping of zero padding at the end of one segment with the next segment's data. If Relaxed Ordering (RO) is enabled, the zero padding may overwrite valid data in the next segment and corrupt the data.  Older chips (P5 and older) do not automatically disable RO when EOP is enabled. On some ARM systems, data corruption was reported on 57508 (P5) chips with RO enabled.  Always disable EOP on all chips on the AGG rings when TPA is enabled to fix the data corruption.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74697","epss":0.00433,"percentile":0.36498,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.33990499999999996},"relatedVulnerabilities":[{"id":"CVE-2026-74697","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74697","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/410da4428b1f47bf9a84bdc0bcaa089d73ba2048","https://git.kernel.org/stable/c/68c181af7cd1ca9cbf29acd95911073bfd3c6397","https://git.kernel.org/stable/c/7aee22a35978b44784612c156e358e375ddf5d16","https://git.kernel.org/stable/c/aab3b5f4d8ec8598606ee011e219ef824ae25ca0","https://git.kernel.org/stable/c/b61c4911204a0a2f900e538d64ceb608f6c9614d","https://git.kernel.org/stable/c/c1962ab4645a914a91ff492735881150ddc8a79e","https://git.kernel.org/stable/c/c3faf548a00f4c17100cc9204746975fa46a73b9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Disable EOP for TPA on all chips to prevent data corruption\n\nEOP (End of frame padding) on the AGG ring may cause overlapping of\nzero padding at the end of one segment with the next segment's data.\nIf Relaxed Ordering (RO) is enabled, the zero padding may overwrite\nvalid data in the next segment and corrupt the data.  Older chips\n(P5 and older) do not automatically disable RO when EOP is enabled.\nOn some ARM systems, data corruption was reported on 57508 (P5)\nchips with RO enabled.\n\nAlways disable EOP on all chips on the AGG rings when TPA is enabled\nto fix the data corruption.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74697","epss":0.00433,"percentile":0.36498,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74697","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74700","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74700","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers  Another challenge with unlocked filters. There is a short window in tc_new_tfilter where a tcf_proto can be found and briefly referenced by a totally unrelated, unlocked classifier's request and cause a race.  Feng created a poc which created this race with two threads, one creating a u32 filter and other a flower filter in the same chain/prio:  1. Both threads enter tc_new_tfilter, both find the chain empty, both    drop filter_chain_lock 2. u32 finishes tcf_proto_create(\"u32\") first, calls    tcf_chain_tp_insert_unique() -> inserts u32_tp into the chain 3. flower finishes tcf_proto_create(\"flower\") later, calls    tcf_chain_tp_insert_unique() -> tcf_chain_tp_find() now sees u32_tp    already there, takes a reference on it, destroys flower's own tp_new    and returns u32_tp to the caller.  Flower then hits the kind mismatch check (because it requested for kind \"flower\" but tp->ops->kind is \"u32\") and goes through the errout path which calls tcf_proto_put() on u32_tp. If the u32 thread has already gone through its own errout (its change() call failed on the PoC's empty options) and dropped its create and insert refs, flower's put is the last one and drops u32_tp's refcnt to zero.  At this point tp->ops->destroy() runs in a context that never took rtnl_lock. When that happens, it might cause a UAF like the following (illustrated by the PoC):  [  +0.000710] BUG: KASAN: slab-use-after-free in u32_init (net/sched/cls_u32.c:393) [  +0.000281] Read of size 8 at addr ffff888120022f00 by task poc_feng_xue/524    Call Trace:    u32_init (net/sched/cls_u32.c:393)    tc_new_tfilter (net/sched/cls_api.c:2378)    Allocated by task 526:    u32_init (net/sched/cls_u32.c:378)    tc_new_tfilter (net/sched/cls_api.c:2378)    Freed by task 522:    kfree    u32_destroy (net/sched/cls_u32.c:662)    tcf_proto_destroy (net/sched/cls_api.c:446)    tcf_proto_put (net/sched/cls_api.c:459)    tc_new_tfilter (net/sched/cls_api.c:2459)  Fix this by having tcf_proto_destroy() take rtnl_lock around tp->ops->destroy() for locked classifiers whenever rtnl is not held.  To explain why I used a temp variable \"not_lockless\" I'd like to point to a semi-related note on rtnl_held vs TCF_PROTO_OPS_DOIT_UNLOCKED (adding here for future cleanup if deemed necessary): The rtnl_held parameter and the TCF_PROTO_OPS_DOIT_UNLOCKED flag are redundant sources of truth for whether rtnl_lock is held. Among the nine classifier destroy(..rtnl_held..) callbacks, only flower consults the rtnl_held parameter which it propagates to tc_setup_cb_destroy() and tc_setup_cb_call(). The other eight (u32, flow, bpf, cgroup, route, basic, fw, mall) ignore it entirely;-> those that call tc_setup_cb_destroy() (u32, bpf, mall) hardcode true always instead of forwarding the parameter.  A future cleanup should remove the rtnl_held parameter from the destroy callback signature entirely and have callers rely solely on their knowledge whether they are running in an unlocked context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74700","epss":0.00125,"percentile":0.02516,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-74700","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74700","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/34e77d8e3570f9df3952496ddb402833695662fd","https://git.kernel.org/stable/c/a347304b2ca1a5377d5bd2d8a72e4b4f12afe648","https://git.kernel.org/stable/c/a81f9c44d87fb59d99fce72e29e02cab3a49a1c3","https://git.kernel.org/stable/c/b648c8a56531aeabd1c14f6b5cf1891e269b3756","https://git.kernel.org/stable/c/d6222af7274f08e7a1848131dc30319993d8f377"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers\n\nAnother challenge with unlocked filters.\nThere is a short window in tc_new_tfilter where a tcf_proto can be found\nand briefly referenced by a totally unrelated, unlocked classifier's request\nand cause a race.\n\nFeng created a poc which created this race with two threads, one creating a\nu32 filter and other a flower filter in the same chain/prio:\n\n1. Both threads enter tc_new_tfilter, both find the chain empty, both\n   drop filter_chain_lock\n2. u32 finishes tcf_proto_create(\"u32\") first, calls\n   tcf_chain_tp_insert_unique() -> inserts u32_tp into the chain\n3. flower finishes tcf_proto_create(\"flower\") later, calls\n   tcf_chain_tp_insert_unique() -> tcf_chain_tp_find() now sees u32_tp\n   already there, takes a reference on it, destroys flower's own tp_new\n   and returns u32_tp to the caller.\n\nFlower then hits the kind mismatch check (because it requested for kind\n\"flower\" but tp->ops->kind is \"u32\") and goes through the errout path\nwhich calls tcf_proto_put() on u32_tp. If the u32 thread has already\ngone through its own errout (its change() call failed on the PoC's empty\noptions) and dropped its create and insert refs, flower's put is the\nlast one and drops u32_tp's refcnt to zero.\n\nAt this point tp->ops->destroy() runs in a context that never took\nrtnl_lock. When that happens, it might cause a UAF like the following\n(illustrated by the PoC):\n\n[  +0.000710] BUG: KASAN: slab-use-after-free in u32_init (net/sched/cls_u32.c:393)\n[  +0.000281] Read of size 8 at addr ffff888120022f00 by task poc_feng_xue/524\n\n  Call Trace:\n   u32_init (net/sched/cls_u32.c:393)\n   tc_new_tfilter (net/sched/cls_api.c:2378)\n\n  Allocated by task 526:\n   u32_init (net/sched/cls_u32.c:378)\n   tc_new_tfilter (net/sched/cls_api.c:2378)\n\n  Freed by task 522:\n   kfree\n   u32_destroy (net/sched/cls_u32.c:662)\n   tcf_proto_destroy (net/sched/cls_api.c:446)\n   tcf_proto_put (net/sched/cls_api.c:459)\n   tc_new_tfilter (net/sched/cls_api.c:2459)\n\nFix this by having tcf_proto_destroy() take rtnl_lock around\ntp->ops->destroy() for locked classifiers whenever rtnl is not held.\n\nTo explain why I used a temp variable \"not_lockless\" I'd like to point to a\nsemi-related note on rtnl_held vs TCF_PROTO_OPS_DOIT_UNLOCKED (adding here\nfor future cleanup if deemed necessary):\nThe rtnl_held parameter and the TCF_PROTO_OPS_DOIT_UNLOCKED flag are\nredundant sources of truth for whether rtnl_lock is held. Among the nine\nclassifier destroy(..rtnl_held..) callbacks, only flower consults the\nrtnl_held parameter which it propagates to tc_setup_cb_destroy()\nand tc_setup_cb_call(). The other eight (u32, flow, bpf, cgroup, route, basic,\nfw, mall) ignore it entirely;-> those that call tc_setup_cb_destroy()\n(u32, bpf, mall) hardcode true always instead of forwarding the parameter.\n\nA future cleanup should remove the rtnl_held parameter from the destroy callback\nsignature entirely and have callers rely solely on their knowledge whether\nthey are running in an unlocked context.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74700","epss":0.00125,"percentile":0.02516,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74700","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74701","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74701","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/openvswitch: check Ethernet header length in key_extract()  When a packet arrives on an ARPHRD_NONE device (e.g. TUN), ovs_flow_key_extract() trusts the user-provided skb->protocol field: if it is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and key_extract() is called without ensuring the skb has ETH_HLEN (14) bytes of linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes for MAC addresses and parse_ethertype() pulls 2 more, either of which triggers a kernel BUG in __skb_pull() when the linear area is too small.    kernel BUG at include/linux/skbuff.h:2848!   RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933   ovs_flow_key_extract+0x419/0xa70   ovs_vport_receive+0x222/0x390   netdev_frame_hook+0x3e0/0x630   tun_get_user+0x2d0c/0x38e0  Fixed by calling check_header() in key_extract() before accessing the Ethernet header.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74701","epss":0.0013,"percentile":0.02942,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09945},"relatedVulnerabilities":[{"id":"CVE-2026-74701","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74701","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0b60b55652ba772b173dddc63f3851e1d2dd5927","https://git.kernel.org/stable/c/81f9b09f0ea3ba9ab966dd17e9f32625a14555e9","https://git.kernel.org/stable/c/831471718f6e19aed1a330b03b53190a90e06466","https://git.kernel.org/stable/c/9b8cfbb58b85bfa7a78fac47fdc77396cd01f699","https://git.kernel.org/stable/c/a8139285c8925efe59af28a9169bb2fda91bff15","https://git.kernel.org/stable/c/cf6f8b29befb92173659bcef6a441d274947bfae","https://git.kernel.org/stable/c/d8bea341b183190ce6c055ab0e64ab78eb9a7290","https://git.kernel.org/stable/c/e85278afd4890dd190ba3c7a1b1a712b801c9fe1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/openvswitch: check Ethernet header length in key_extract()\n\nWhen a packet arrives on an ARPHRD_NONE device (e.g. TUN),\novs_flow_key_extract() trusts the user-provided skb->protocol field: if\nit is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and\nkey_extract() is called without ensuring the skb has ETH_HLEN (14) bytes\nof linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes\nfor MAC addresses and parse_ethertype() pulls 2 more, either of which\ntriggers a kernel BUG in __skb_pull() when the linear area is too small.\n\n  kernel BUG at include/linux/skbuff.h:2848!\n  RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933\n  ovs_flow_key_extract+0x419/0xa70\n  ovs_vport_receive+0x222/0x390\n  netdev_frame_hook+0x3e0/0x630\n  tun_get_user+0x2d0c/0x38e0\n\nFixed by calling check_header() in key_extract() before accessing the\nEthernet header.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74701","epss":0.0013,"percentile":0.02942,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74701","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74704","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74704","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter  The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set.  The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74704","epss":0.00443,"percentile":0.37356,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3477549999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74704","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74704","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0c4882bff34558d8d53fb04c3e96da5c327c7dc8","https://git.kernel.org/stable/c/2504a76e5c0694e14e15562730e1339f2d9f9458","https://git.kernel.org/stable/c/2a33516f9ef59ad11844d4fc152f889449b5daf3","https://git.kernel.org/stable/c/a1ae353d8355407c1bea971d1c1af5e7f242bb7d","https://git.kernel.org/stable/c/a4b52612004a5639c4bfc30ba93ba414b8326e2a","https://git.kernel.org/stable/c/ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3","https://git.kernel.org/stable/c/c1693b7844a6c06d31a565e5a494948034dfd235","https://git.kernel.org/stable/c/cd2f1d9fe8a507c2dc86ad326fe221f121c47734"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter\n\nThe sch_cake ACK filter parses packets to find the TCP header and filter\nduplicated ACKs if the flow is backlogged. The parsing code contains a\nWARN_ON(1) which can be triggered by a malformed IP header in certain\ncases. Depending on the system configuration, this leads either to\neither spamming dmesg with warnings, or a panic if panic_on_warn is set.\n\nThe code already correctly skips the offending packet in the branch that\ntriggers the warning, so the WARN_ON itself doesn't really serve any\npurpose. So just drop it altogether to avoid the inconvenient side\neffects.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":3.9,"impactScore":4.3},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74704","epss":0.00443,"percentile":0.37356,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74704","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74705","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74705","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  udp: fix potential use-after-free in tunnel segmentation  __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocates skb->head, the saved UDP header pointer is no longer valid.  Get the UDP header after the pull to avoid a potential use-after-free.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74705","epss":0.005,"percentile":0.41183,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.475},"relatedVulnerabilities":[{"id":"CVE-2026-74705","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74705","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/19d89b13a43640b2da2f277ee462d919d988cb6f","https://git.kernel.org/stable/c/1ae134c012e10384cdac420b5cc6e0615cde0b55","https://git.kernel.org/stable/c/5161e67c561c4f28a5d9335a6e859b02511de92b","https://git.kernel.org/stable/c/588d4a6795d99d080f74ef0b5f391ea8c453ae5d","https://git.kernel.org/stable/c/64d322c288577793eedd352b96ef75234ed380fe","https://git.kernel.org/stable/c/6a733a38b983d8c2e222f13968209010cf44de87","https://git.kernel.org/stable/c/b3df61bb745eb5201eac22679a2839d4ccbf3442","https://git.kernel.org/stable/c/d0f86fb36eb260abd10007b62c9dcc1028e03e61"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nudp: fix potential use-after-free in tunnel segmentation\n\n__skb_udp_tunnel_segment() gets the UDP header before ensuring the\ntunnel header is in the skb head. If the pull reallocates skb->head,\nthe saved UDP header pointer is no longer valid.\n\nGet the UDP header after the pull to avoid a potential use-after-free.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"exploitabilityScore":3.9,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74705","epss":0.005,"percentile":0.41183,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74705","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74713","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74713","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vhost_iotlb: bound map allocation in add_range  vhost_iotlb_add_range_ctx() only retires an old entry when the table has a non-zero limit, has exactly reached that limit and has VHOST_IOTLB_FLAG_RETIRE set. Non-retiring tables can keep allocating entries after reaching their configured limit.  Existing vhost devices allocate their IOTLB with max_iotlb_entries from vhost.c, which defaults to 2048 and is tunable by module parameter. Use the caller-provided limit at the allocation point instead of adding a separate default in the common IOTLB helper, and reject non-positive values in vhost paths that can report an error.  Other vhost IOTLB users should not create zero-limit tables when entries can be populated from userspace or guest-controlled requests. Add caller-side max_iotlb_entries parameters for mlx5 vDPA, VDUSE and vhost-vDPA. Reject non-positive VDUSE and vhost-vDPA values, and require at least two entries for vdpa_sim and mlx5 vDPA paths that install full-range mappings, since those mappings are split into two IOTLB entries.  Handle full-range mappings in the common helper by checking that the IOTLB can hold both split entries before inserting the first half. This avoids returning an error after leaving a half mapping behind.  When the table is full, keep the existing retire behavior for retiring tables and return -ENOSPC for non-retiring tables. Reuse the retired map node instead of freeing it and allocating a replacement, so a stream of IOTLB updates cannot keep forcing GFP_ATOMIC allocations after the table has reached its limit. If a zero-limit IOTLB still reaches the common helper, treat it as a configuration error and return -EINVAL.  I found this bug myself, though the patch was written with AI assistance.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.6,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74713","epss":0.0012,"percentile":0.02078,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0876},"relatedVulnerabilities":[{"id":"CVE-2026-74713","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74713","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1ed35ac7f3fe2b4396bdd29ac3a7f0ebc0829e94","https://git.kernel.org/stable/c/ae128dd19040ee06a4f8143c7ced4d18080d7a9a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost_iotlb: bound map allocation in add_range\n\nvhost_iotlb_add_range_ctx() only retires an old entry when the table\nhas a non-zero limit, has exactly reached that limit and has\nVHOST_IOTLB_FLAG_RETIRE set. Non-retiring tables can keep allocating\nentries after reaching their configured limit.\n\nExisting vhost devices allocate their IOTLB with max_iotlb_entries from\nvhost.c, which defaults to 2048 and is tunable by module parameter. Use\nthe caller-provided limit at the allocation point instead of adding a\nseparate default in the common IOTLB helper, and reject non-positive\nvalues in vhost paths that can report an error.\n\nOther vhost IOTLB users should not create zero-limit tables when entries\ncan be populated from userspace or guest-controlled requests. Add\ncaller-side max_iotlb_entries parameters for mlx5 vDPA, VDUSE and\nvhost-vDPA. Reject non-positive VDUSE and vhost-vDPA values, and require\nat least two entries for vdpa_sim and mlx5 vDPA paths that install\nfull-range mappings, since those mappings are split into two IOTLB\nentries.\n\nHandle full-range mappings in the common helper by checking that the\nIOTLB can hold both split entries before inserting the first half. This\navoids returning an error after leaving a half mapping behind.\n\nWhen the table is full, keep the existing retire behavior for retiring\ntables and return -ENOSPC for non-retiring tables. Reuse the retired map\nnode instead of freeing it and allocating a replacement, so a stream of\nIOTLB updates cannot keep forcing GFP_ATOMIC allocations after the table\nhas reached its limit. If a zero-limit IOTLB still reaches the common\nhelper, treat it as a configuration error and return -EINVAL.\n\nI found this bug myself, though the patch was written with AI assistance.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.6,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74713","epss":0.0012,"percentile":0.02078,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74713","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74714","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74714","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()  reqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto the ehash chain, drops the bucket lock, and only afterwards sets rsk_refcnt to 3.  Lockless readers such as __inet_lookup_established() handle this with refcount_inc_not_zero(), but bpf_iter_tcp_established_batch() uses plain sock_hold() while holding the bucket lock, on the assumption that the lock guarantees sk_refcnt > 0. That assumption does not hold for request_sock:    CPU 0                                CPU 1   -----                                -----   tcp_conn_request()    reqsk_queue_hash_req()     inet_ehash_insert(req)      spin_lock(bucket)      __sk_nulls_add_node_rcu(req)      // rsk_refcnt == 0      spin_unlock(bucket)                                        bpf_iter_tcp_established_batch()                                         spin_lock(bucket)                                         sock_hold(req)   <-- addition on 0                                         spin_unlock(bucket)     refcount_set(&req->rsk_refcnt, 3)  // clobbers saturated value  which surfaces as:    refcount_t: addition on 0; use-after-free.   WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x48/0x90, CPU#1   Call Trace:    bpf_iter_tcp_established_batch+0x14e/0x170    bpf_iter_tcp_batch+0x53/0x200    bpf_iter_tcp_seq_next+0x27/0x70    bpf_seq_read+0x107/0x410    vfs_read+0xb9/0x380  The iterator's stolen reference is lost when the publishing CPU's refcount_set() overwrites the count, leaving the socket one reference short. When the last legitimate owner drops its reference the reqsk is freed while still reachable, leading to use-after-free.  This reproduces in seconds with tcp_syncookies=0, a handful of threads doing connect()/close() to a local listener while others read an iter/tcp link in a tight loop.  Use refcount_inc_not_zero() and skip the socket on failure. A skipped socket is still part of the bucket, so keep counting it in expected. The reallocations are sized from expected, and a request sock whose refcount gets published while the lock is held across the last realloc must already have room.  A skipped socket is counted in expected but never batched, so end_sk can be short of expected on a batch that is actually complete. Decide completeness by whether the walk left any socket behind instead. The WARN after the locked realloc checks the same, replacing an end_sk == expected check that could not hold on that path since commit cdec67a489d4 (\"bpf: tcp: Make sure iter->batch always contains a full bucket snapshot\").  If every matching socket in a bucket is mid-init (refcount 0), end_sk stays 0. Advance to the next bucket rather than returning a batch entry that was never filled this round.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74714","epss":0.00126,"percentile":0.02558,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09639},"relatedVulnerabilities":[{"id":"CVE-2026-74714","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74714","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7d2b60a4bc0499f62ff8520af6309bbe170882fd","https://git.kernel.org/stable/c/97e74d3e45d653c07c2d406fc530a9bbe3df8396","https://git.kernel.org/stable/c/cc0295f89296ed351fc4b0b48fee887ba02c5d24","https://git.kernel.org/stable/c/cefcbbe20846a45f9a7dae868f7ef1000953e2df","https://git.kernel.org/stable/c/ddbe966b5d1fe212ada749bc3d0b410f1a7dea74","https://git.kernel.org/stable/c/e5fd3f514e27db1f05fbd72ba615d74941e23c51"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()\n\nreqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto\nthe ehash chain, drops the bucket lock, and only afterwards sets\nrsk_refcnt to 3.\n\nLockless readers such as __inet_lookup_established() handle this with\nrefcount_inc_not_zero(), but bpf_iter_tcp_established_batch() uses plain\nsock_hold() while holding the bucket lock, on the assumption that the\nlock guarantees sk_refcnt > 0. That assumption does not hold for\nrequest_sock:\n\n  CPU 0                                CPU 1\n  -----                                -----\n  tcp_conn_request()\n   reqsk_queue_hash_req()\n    inet_ehash_insert(req)\n     spin_lock(bucket)\n     __sk_nulls_add_node_rcu(req)      // rsk_refcnt == 0\n     spin_unlock(bucket)\n                                       bpf_iter_tcp_established_batch()\n                                        spin_lock(bucket)\n                                        sock_hold(req)   <-- addition on 0\n                                        spin_unlock(bucket)\n    refcount_set(&req->rsk_refcnt, 3)  // clobbers saturated value\n\nwhich surfaces as:\n\n  refcount_t: addition on 0; use-after-free.\n  WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x48/0x90, CPU#1\n  Call Trace:\n   bpf_iter_tcp_established_batch+0x14e/0x170\n   bpf_iter_tcp_batch+0x53/0x200\n   bpf_iter_tcp_seq_next+0x27/0x70\n   bpf_seq_read+0x107/0x410\n   vfs_read+0xb9/0x380\n\nThe iterator's stolen reference is lost when the publishing CPU's\nrefcount_set() overwrites the count, leaving the socket one reference\nshort. When the last legitimate owner drops its reference the reqsk is\nfreed while still reachable, leading to use-after-free.\n\nThis reproduces in seconds with tcp_syncookies=0, a handful of threads\ndoing connect()/close() to a local listener while others read an\niter/tcp link in a tight loop.\n\nUse refcount_inc_not_zero() and skip the socket on failure. A skipped\nsocket is still part of the bucket, so keep counting it in expected.\nThe reallocations are sized from expected, and a request sock whose\nrefcount gets published while the lock is held across the last realloc\nmust already have room.\n\nA skipped socket is counted in expected but never batched, so end_sk\ncan be short of expected on a batch that is actually complete. Decide\ncompleteness by whether the walk left any socket behind instead. The\nWARN after the locked realloc checks the same, replacing an\nend_sk == expected check that could not hold on that path since\ncommit cdec67a489d4 (\"bpf: tcp: Make sure iter->batch always\ncontains a full bucket snapshot\").\n\nIf every matching socket in a bucket is mid-init (refcount 0), end_sk\nstays 0. Advance to the next bucket rather than returning a batch entry\nthat was never filled this round.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74714","epss":0.00126,"percentile":0.02558,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74714","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74715","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74715","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix netns reference imbalance in conntrack kfuncs  The opts argument of the BPF conntrack kfuncs can point to a shared map value.  __bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read opts->netns_id separately when acquiring and releasing the network namespace reference.  The reference imbalance can occur as follows:    CPU 0                                  CPU 1   read opts->netns_id (-1)   skip get_net_ns_by_id()                                          write opts->netns_id (id)   read opts->netns_id (id)   put_net(net) /* no matching get */  The reverse transition leaks the reference.  Repeating the unmatched put can destroy a live namespace and crash later users.  The kernel reported:    Oops: general protection fault, probably for non-canonical address   KASAN: null-ptr-deref in range [0x00000000000000e8-0x00000000000000ef]   RIP: 0010:bpf_prog_test_run_xdp+0x52c/0x1700   Call Trace:    __sys_bpf+0x1662/0x50c0    __x64_sys_bpf+0x73/0xb0    do_syscall_64+0xf9/0x540    entry_SYSCALL_64_after_hwframe+0x77/0x7f   Kernel panic - not syncing: Fatal exception  Snapshot every input field of opts with READ_ONCE() before validating or using it.  The netns_id snapshot keeps the namespace get/put pair balanced, while the other snapshots keep the remaining options from changing partway through an invocation.  The individual reads can still observe an inconsistent combination during a concurrent update, but each selected field value remains stable for that invocation.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74715","epss":0.0012,"percentile":0.02107,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74715","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74715","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/e5e060eb63d10b41ab60fd955649479d99b38210","https://git.kernel.org/stable/c/fdeba03fea78407a8c52faa99177c9f7f29f90eb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix netns reference imbalance in conntrack kfuncs\n\nThe opts argument of the BPF conntrack kfuncs can point to a shared\nmap value.  __bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read\nopts->netns_id separately when acquiring and releasing the network\nnamespace reference.\n\nThe reference imbalance can occur as follows:\n\n  CPU 0                                  CPU 1\n  read opts->netns_id (-1)\n  skip get_net_ns_by_id()\n                                         write opts->netns_id (id)\n  read opts->netns_id (id)\n  put_net(net) /* no matching get */\n\nThe reverse transition leaks the reference.  Repeating the unmatched put\ncan destroy a live namespace and crash later users.\n\nThe kernel reported:\n\n  Oops: general protection fault, probably for non-canonical address\n  KASAN: null-ptr-deref in range [0x00000000000000e8-0x00000000000000ef]\n  RIP: 0010:bpf_prog_test_run_xdp+0x52c/0x1700\n  Call Trace:\n   __sys_bpf+0x1662/0x50c0\n   __x64_sys_bpf+0x73/0xb0\n   do_syscall_64+0xf9/0x540\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  Kernel panic - not syncing: Fatal exception\n\nSnapshot every input field of opts with READ_ONCE() before validating or\nusing it.  The netns_id snapshot keeps the namespace get/put pair\nbalanced, while the other snapshots keep the remaining options from\nchanging partway through an invocation.  The individual reads can still\nobserve an inconsistent combination during a concurrent update, but each\nselected field value remains stable for that invocation.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74715","epss":0.0012,"percentile":0.02107,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74715","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74717","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74717","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5: fw_tracer, return NULL on create error  Tracer creation can fail by returning either NULL or ERR_PTR. The return value is stored without a check on the device, and users treat ERR_PTR and NULL the same way. This also causes a crash in the core dump logic, which is missing the ERR_PTR check and ends up dereferencing it, as shown in the trace below.  Switch tracer creation to return NULL on failure only, so callers only need a single NULL check.    Internal error: Oops: 0000000096000006 [#1]  SMP   Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core   CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)   Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]   pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)   pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]   lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]   sp : ffff800081cf3c40   x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000   x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05   x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000   x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0   x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac   x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650   x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8   x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000   x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030   x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e   Call trace:    mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)    mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]    devlink_health_do_dump+0x9c/0x160    devlink_health_report+0x1c0/0x288    mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]    process_one_work+0x15c/0x3d8    worker_thread+0x18c/0x320    kthread+0x148/0x228    ret_from_fork+0x10/0x20   Code: b9400000 5ac00800 7a401800 540003ca (3940a260)   ---[ end trace 0000000000000000 ]---   Kernel panic - not syncing: Oops: Fatal exception   SMP: stopping secondary CPUs   Kernel Offset: disabled   CPU features: 0x000000,00078031,75fce5a1,35fffe67   Memory Limit: none   ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74717","epss":0.00501,"percentile":0.41264,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37575},"relatedVulnerabilities":[{"id":"CVE-2026-74717","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74717","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/04599570c3a18f9ae7aad36825eb46f3dcd2c4e3","https://git.kernel.org/stable/c/47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0","https://git.kernel.org/stable/c/4aafa600d93e9551c1f24e785d57cbd4adf021d5","https://git.kernel.org/stable/c/80094352bd40ba54a33731f9c22872493983ed6d","https://git.kernel.org/stable/c/9a416f000285a94c1b723877547981dec8132434","https://git.kernel.org/stable/c/af39eb111ce6b5eba9c08513b62c4868eb7e7fd5","https://git.kernel.org/stable/c/b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb","https://git.kernel.org/stable/c/ee41ea49c4ab0e4015919f52ad23ec251d3b39d3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fw_tracer, return NULL on create error\n\nTracer creation can fail by returning either NULL or ERR_PTR.\nThe return value is stored without a check on the device, and users\ntreat ERR_PTR and NULL the same way.\nThis also causes a crash in the core dump logic, which is missing the\nERR_PTR check and ends up dereferencing it, as shown in the trace below.\n\nSwitch tracer creation to return NULL on failure only, so callers only\nneed a single NULL check.\n\n  Internal error: Oops: 0000000096000006 [#1]  SMP\n  Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core\n  CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)\n  Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]\n  pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n  pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]\n  lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]\n  sp : ffff800081cf3c40\n  x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000\n  x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05\n  x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000\n  x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0\n  x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac\n  x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650\n  x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8\n  x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000\n  x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030\n  x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e\n  Call trace:\n   mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)\n   mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]\n   devlink_health_do_dump+0x9c/0x160\n   devlink_health_report+0x1c0/0x288\n   mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]\n   process_one_work+0x15c/0x3d8\n   worker_thread+0x18c/0x320\n   kthread+0x148/0x228\n   ret_from_fork+0x10/0x20\n  Code: b9400000 5ac00800 7a401800 540003ca (3940a260)\n  ---[ end trace 0000000000000000 ]---\n  Kernel panic - not syncing: Oops: Fatal exception\n  SMP: stopping secondary CPUs\n  Kernel Offset: disabled\n  CPU features: 0x000000,00078031,75fce5a1,35fffe67\n  Memory Limit: none\n  ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74717","epss":0.00501,"percentile":0.41264,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74717","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74719","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74719","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()  The SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in smc_llc_event_handler() stores an incoming qentry into the local LLC flow without first checking whether a qentry is already pending. If a malicious or buggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is active and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the pointer without freeing the previous allocation, leaking one kmalloc-96 object per spurious message.  The sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry guard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a duplicate message when qentry is already occupied falls through to break and is freed by the kfree(qentry) at the out: label, rather than silently leaking the existing allocation.  The response direction (smc_llc_rx_response()) is unaffected: it already guards with flow->qentry at the equivalent site and drops duplicate responses correctly.","cvss":[],"epss":[{"cve":"CVE-2026-74719","epss":0.00177,"percentile":0.07336,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74719","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74719","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/06734dfeaeba886aab1bf147249195b888ac3e4d","https://git.kernel.org/stable/c/10cb31b2b74cb664c6c95cf72364d7d5c483ab82","https://git.kernel.org/stable/c/976245094925bab9bc39366b2e9ab44ffcde61d0","https://git.kernel.org/stable/c/a1e980d7a9e7ee6faf4f5fd7b450413b969af26d","https://git.kernel.org/stable/c/bfc336a9fbbf09805f3dfe25c195a4db90af2846","https://git.kernel.org/stable/c/c23c409228629107203d3c3e95fff1473173f1a6","https://git.kernel.org/stable/c/e0eb87677c76b157cdf8eb7c1f19e56227165a33","https://git.kernel.org/stable/c/e384f3cba6ea709f5b2272b1770db4ce14047f78"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()\n\nThe SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in\nsmc_llc_event_handler() stores an incoming qentry into the local LLC flow\nwithout first checking whether a qentry is already pending. If a malicious or\nbuggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is\nactive and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the\npointer without freeing the previous allocation, leaking one kmalloc-96 object\nper spurious message.\n\nThe sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry\nguard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a\nduplicate message when qentry is already occupied falls through to break and is\nfreed by the kfree(qentry) at the out: label, rather than silently leaking the\nexisting allocation.\n\nThe response direction (smc_llc_rx_response()) is unaffected: it already guards\nwith flow->qentry at the equivalent site and drops duplicate responses\ncorrectly.","cvss":[],"epss":[{"cve":"CVE-2026-74719","epss":0.00177,"percentile":0.07336,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74719","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74720","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74720","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Preserve pointer state for commuted arithmetic  When scalar += pointer is handled in adjust_ptr_min_max_vals(), the destination register inherits the pointer state from the source pointer. Copying only selected fields is fragile because pointer provenance is tracked by several bpf_reg_state fields.  Use the caller's temporary offset register to preserve the scalar operand while replacing the destination with the full pointer state. This preserves the frame number for PTR_TO_STACK registers and keeps parent identity fields consistent.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74720","epss":0.00129,"percentile":0.02891,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74720","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74720","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/29c239f8dbec5ab33a61796724d189bddee6cd4b","https://git.kernel.org/stable/c/8109c25e0c41f5f19a1c2380bb49c991a877494e","https://git.kernel.org/stable/c/86b203aadc2930e0a4f9c6277b5b80ff3664c472","https://git.kernel.org/stable/c/8cb23101a3fcc7432b451ea3d0f14a90711f4acf","https://git.kernel.org/stable/c/a4c6f804b44c5c790269b25e0e61cf4e9f117c86","https://git.kernel.org/stable/c/d1959028190a7649b926f5867a58de5fe221b23c","https://git.kernel.org/stable/c/db6382ed3361bdd8129572a3423956cba1dae829","https://git.kernel.org/stable/c/eaffa1495e4fe6330aeff9f323ea3d48b01f118a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve pointer state for commuted arithmetic\n\nWhen scalar += pointer is handled in adjust_ptr_min_max_vals(), the\ndestination register inherits the pointer state from the source pointer.\nCopying only selected fields is fragile because pointer provenance is\ntracked by several bpf_reg_state fields.\n\nUse the caller's temporary offset register to preserve the scalar operand\nwhile replacing the destination with the full pointer state. This preserves\nthe frame number for PTR_TO_STACK registers and keeps parent identity\nfields consistent.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74720","epss":0.00129,"percentile":0.02891,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74720","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74722","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74722","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix memory leak in btrfs_do_encoded_write()  Local fuzzing of 6.12.94 has found the following memory leak:  Unreferenced object 0xffff888018050a80 (size 64):   comm \"syz.0.17\", pid 10297, jiffies 4294953601   hex dump (first 32 bytes):     00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00  ................     10 0a 05 18 80 88 ff ff 10 0a 05 18 80 88 ff ff  ................   backtrace (crc a8a6fc29):     kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]     slab_post_alloc_hook mm/slub.c:4152 [inline]     slab_alloc_node mm/slub.c:4197 [inline]     __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358     kmalloc_noprof include/linux/slab.h:878 [inline]     extent_changeset_alloc fs/btrfs/extent_io.h:207 [inline]     qgroup_reserve_data+0x1c5/0x7d0 fs/btrfs/qgroup.c:4305     btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355     btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746     btrfs_encoded_write fs/btrfs/file.c:1482 [inline]     btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507     btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738     btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1     vfs_ioctl fs/ioctl.c:51 [inline]     __do_sys_ioctl fs/ioctl.c:906 [inline]     __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892     do_syscall_x64 arch/x86/entry/common.c:47 [inline]     do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78     entry_SYSCALL_64_after_hwframe+0x77/0x7f  Unreferenced object 0xffff888018050a00 (size 64):   comm \"syz.0.17\", pid 10297, jiffies 4294953601   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 ff 0f 00 00 00 00 00 00  ................     90 0a 05 18 80 88 ff ff 90 0a 05 18 80 88 ff ff  ................   backtrace (crc cb5c9580):     kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]     slab_post_alloc_hook mm/slub.c:4152 [inline]     slab_alloc_node mm/slub.c:4197 [inline]     __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358     kmalloc_noprof include/linux/slab.h:878 [inline]     kzalloc_noprof include/linux/slab.h:1014 [inline]     ulist_prealloc+0x9c/0x110 fs/btrfs/ulist.c:114     extent_changeset_prealloc fs/btrfs/extent_io.h:217 [inline]     __set_extent_bit+0x16b/0x1a70 fs/btrfs/extent-io-tree.c:1086     set_record_extent_bits+0x50/0x90 fs/btrfs/extent-io-tree.c:1821     qgroup_reserve_data+0x274/0x7d0 fs/btrfs/qgroup.c:4312     btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355     btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746     btrfs_encoded_write fs/btrfs/file.c:1482 [inline]     btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507     btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738     btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1     vfs_ioctl fs/ioctl.c:51 [inline]     __do_sys_ioctl fs/ioctl.c:906 [inline]     __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892     do_syscall_x64 arch/x86/entry/common.c:47 [inline]     do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78     entry_SYSCALL_64_after_hwframe+0x77/0x7f  Fix this by freeing an extent changeset before returning from btrfs_do_encoded_write().","cvss":[],"epss":[{"cve":"CVE-2026-74722","epss":0.00173,"percentile":0.06838,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-74722","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74722","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0f0da96ccb1b9f35f4d3d4540dcaab0969d9d6b0","https://git.kernel.org/stable/c/20c0eeb4313f9f89d47b80b672b5846f9827cb31","https://git.kernel.org/stable/c/24a8f2c29aebb753ccb962fbb25bae18d7978f6e","https://git.kernel.org/stable/c/60b50ceba6243802f8d2c0a9a7c2d549a93b1d64","https://git.kernel.org/stable/c/d2a4e4e626b2f4670b69b430c357f03f53eb6632","https://git.kernel.org/stable/c/e2c7e88815edd5ecfb88e7660ab9fd42bda6bc47"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix memory leak in btrfs_do_encoded_write()\n\nLocal fuzzing of 6.12.94 has found the following memory leak:\n\nUnreferenced object 0xffff888018050a80 (size 64):\n  comm \"syz.0.17\", pid 10297, jiffies 4294953601\n  hex dump (first 32 bytes):\n    00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00  ................\n    10 0a 05 18 80 88 ff ff 10 0a 05 18 80 88 ff ff  ................\n  backtrace (crc a8a6fc29):\n    kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]\n    slab_post_alloc_hook mm/slub.c:4152 [inline]\n    slab_alloc_node mm/slub.c:4197 [inline]\n    __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358\n    kmalloc_noprof include/linux/slab.h:878 [inline]\n    extent_changeset_alloc fs/btrfs/extent_io.h:207 [inline]\n    qgroup_reserve_data+0x1c5/0x7d0 fs/btrfs/qgroup.c:4305\n    btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355\n    btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746\n    btrfs_encoded_write fs/btrfs/file.c:1482 [inline]\n    btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507\n    btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738\n    btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1\n    vfs_ioctl fs/ioctl.c:51 [inline]\n    __do_sys_ioctl fs/ioctl.c:906 [inline]\n    __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892\n    do_syscall_x64 arch/x86/entry/common.c:47 [inline]\n    do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78\n    entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUnreferenced object 0xffff888018050a00 (size 64):\n  comm \"syz.0.17\", pid 10297, jiffies 4294953601\n  hex dump (first 32 bytes):\n    00 00 00 00 00 00 00 00 ff 0f 00 00 00 00 00 00  ................\n    90 0a 05 18 80 88 ff ff 90 0a 05 18 80 88 ff ff  ................\n  backtrace (crc cb5c9580):\n    kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]\n    slab_post_alloc_hook mm/slub.c:4152 [inline]\n    slab_alloc_node mm/slub.c:4197 [inline]\n    __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358\n    kmalloc_noprof include/linux/slab.h:878 [inline]\n    kzalloc_noprof include/linux/slab.h:1014 [inline]\n    ulist_prealloc+0x9c/0x110 fs/btrfs/ulist.c:114\n    extent_changeset_prealloc fs/btrfs/extent_io.h:217 [inline]\n    __set_extent_bit+0x16b/0x1a70 fs/btrfs/extent-io-tree.c:1086\n    set_record_extent_bits+0x50/0x90 fs/btrfs/extent-io-tree.c:1821\n    qgroup_reserve_data+0x274/0x7d0 fs/btrfs/qgroup.c:4312\n    btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355\n    btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746\n    btrfs_encoded_write fs/btrfs/file.c:1482 [inline]\n    btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507\n    btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738\n    btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1\n    vfs_ioctl fs/ioctl.c:51 [inline]\n    __do_sys_ioctl fs/ioctl.c:906 [inline]\n    __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892\n    do_syscall_x64 arch/x86/entry/common.c:47 [inline]\n    do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78\n    entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFix this by freeing an extent changeset before returning from\nbtrfs_do_encoded_write().","cvss":[],"epss":[{"cve":"CVE-2026-74722","epss":0.00173,"percentile":0.06838,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74722","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74723","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74723","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: lzo: reject inline extents without valid headers  [BUG] For a crafted btrfs image, the following KASAN can be triggered when reading an inline lzo compressed file extent:    BUG: KASAN: slab-out-of-bounds in lzo_decompress+0x57d/0x700   Read of size 4 at addr ffff888006f2e644 by task btrfs_lzo_inlin/77    Call Trace:    <TASK>    dump_stack_lvl+0x5b/0x70    print_report+0xd1/0x610    kasan_report+0xe0/0x110    __asan_report_load_n_noabort+0x13/0x20    lzo_decompress+0x57d/0x700    btrfs_decompress+0x140/0x1c0    uncompress_inline+0x147/0x1b0    btrfs_get_extent+0xb23/0x10a0    btrfs_do_readpage.constprop.0+0x538/0x1ac0    btrfs_readahead+0x32f/0x5f0    read_pages+0x16f/0x850    page_cache_ra_unbounded+0x296/0x490    do_page_cache_ra+0xd9/0x130    page_cache_sync_ra+0x3ee/0x6f0    filemap_get_pages+0x306/0x15c0    filemap_read+0x329/0xd00    btrfs_file_read_iter+0x1f8/0x2b0    vfs_read+0x4ef/0x720    ksys_read+0xf8/0x1d0    __x64_sys_read+0x71/0xb0    x64_sys_call+0x1ab0/0x1b70    do_syscall_64+0x61/0x470    entry_SYSCALL_64_after_hwframe+0x4b/0x53    </TASK>  [CAUSE] For an inline lzo compressed file extent, there should always be one lzo header, recording the total length of the compressed data, followed by one segment header, recording the compressed lzo payload.  But if a crafted inline lzo compressed file extent contains only an lzo header, without the segment header or payload, lzo_decompress() will still try to read the segment header, causing a read beyond the item boundary.  Furthermore if the inline lzo compressed file extent is the first item of the leaf, it will be at the extent buffer boundary. The above out-of-boundary read will go beyond the extent buffer boundary, triggering the above KASAN report.  [FIX] Validate the total length of the inlined lzo compressed file extent, to make sure there is at least one LZO header and one segment header, and a non-zero payload.  [ Rework the commit message to remove slop ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74723","epss":0.0038,"percentile":0.31291,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3572},"relatedVulnerabilities":[{"id":"CVE-2026-74723","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74723","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0fa78ef637deb5dbe341582f88553a4bce496de0","https://git.kernel.org/stable/c/fc50b475ad27f50b4dcc98fc4c44e8802bc1b248"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: lzo: reject inline extents without valid headers\n\n[BUG]\nFor a crafted btrfs image, the following KASAN can be triggered when\nreading an inline lzo compressed file extent:\n\n  BUG: KASAN: slab-out-of-bounds in lzo_decompress+0x57d/0x700\n  Read of size 4 at addr ffff888006f2e644 by task btrfs_lzo_inlin/77\n\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x5b/0x70\n   print_report+0xd1/0x610\n   kasan_report+0xe0/0x110\n   __asan_report_load_n_noabort+0x13/0x20\n   lzo_decompress+0x57d/0x700\n   btrfs_decompress+0x140/0x1c0\n   uncompress_inline+0x147/0x1b0\n   btrfs_get_extent+0xb23/0x10a0\n   btrfs_do_readpage.constprop.0+0x538/0x1ac0\n   btrfs_readahead+0x32f/0x5f0\n   read_pages+0x16f/0x850\n   page_cache_ra_unbounded+0x296/0x490\n   do_page_cache_ra+0xd9/0x130\n   page_cache_sync_ra+0x3ee/0x6f0\n   filemap_get_pages+0x306/0x15c0\n   filemap_read+0x329/0xd00\n   btrfs_file_read_iter+0x1f8/0x2b0\n   vfs_read+0x4ef/0x720\n   ksys_read+0xf8/0x1d0\n   __x64_sys_read+0x71/0xb0\n   x64_sys_call+0x1ab0/0x1b70\n   do_syscall_64+0x61/0x470\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n   </TASK>\n\n[CAUSE]\nFor an inline lzo compressed file extent, there should always be one lzo\nheader, recording the total length of the compressed data, followed by\none segment header, recording the compressed lzo payload.\n\nBut if a crafted inline lzo compressed file extent contains only an lzo\nheader, without the segment header or payload, lzo_decompress() will\nstill try to read the segment header, causing a read beyond the item\nboundary.\n\nFurthermore if the inline lzo compressed file extent is the first item\nof the leaf, it will be at the extent buffer boundary. The above\nout-of-boundary read will go beyond the extent buffer boundary,\ntriggering the above KASAN report.\n\n[FIX]\nValidate the total length of the inlined lzo compressed file extent, to\nmake sure there is at least one LZO header and one segment header, and a\nnon-zero payload.\n\n[ Rework the commit message to remove slop ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74723","epss":0.0038,"percentile":0.31291,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74723","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74724","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74724","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipvs: avoid out-of-bounds write in ip_vs_nat_icmp  Sashiko warns that local attacker can modify the packet while it is processed by IPVS. Some places read the IP ihl field multiple times which can cause out-of-bounds access. One such place is ip_vs_nat_icmp where we can write after the validated area.  Fix it by providing ciph argument just like it is done for IPv6 and use ciph->len as offset to the embedded transport header.  Modify some IPv4 header checks by reading the ihl field only once.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74724","epss":0.00123,"percentile":0.02363,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.094095},"relatedVulnerabilities":[{"id":"CVE-2026-74724","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74724","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/243d0187ec4c3837b9b0004f18d1068e46115760","https://git.kernel.org/stable/c/3b8f79af0e98f27b932b0b416e9c52b692d31ff9","https://git.kernel.org/stable/c/3c779b258c9c3c3567af68d4f45c2f751f35bd0e","https://git.kernel.org/stable/c/646922a0379496154e8c8faca4f8e2fd9100cacc","https://git.kernel.org/stable/c/a69a4b3fff5814d079beff9a1e9d369994b2ed47","https://git.kernel.org/stable/c/be65fa324640c7a95e30b146159a2be5cc73f22e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: avoid out-of-bounds write in ip_vs_nat_icmp\n\nSashiko warns that local attacker can modify the packet\nwhile it is processed by IPVS. Some places read the\nIP ihl field multiple times which can cause out-of-bounds\naccess. One such place is ip_vs_nat_icmp where we\ncan write after the validated area.\n\nFix it by providing ciph argument just like it is done for\nIPv6 and use ciph->len as offset to the embedded transport\nheader.\n\nModify some IPv4 header checks by reading the ihl field\nonly once.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74724","epss":0.00123,"percentile":0.02363,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74724","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74725","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74725","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  enic: fix tx_hang_reset use-after-free on device removal  enic_remove() cancels the reset and change_mtu_work items but does not cancel tx_hang_reset. A TX timeout that fires while the device is being removed can schedule enic_tx_hang_reset() so that it runs after free_netdev(), resulting in a use-after-free.  cancel_work_sync() alone is not sufficient here: the still-live watchdog and notify paths can re-schedule these work items in the window between the cancel and unregister_netdev(). Use disable_work_sync(), which cancels the work and blocks any subsequent schedule_work() from requeuing it, and apply it to the reset and change_mtu_work items as well so the same requeue race is closed for all teardown work.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74725","epss":0.00125,"percentile":0.02518,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-74725","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74725","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4f3464fc6c1f26afc504fd525c574f2bc14c9d42","https://git.kernel.org/stable/c/8619865f34fb3b130b567855382a5c4aadd522b9","https://git.kernel.org/stable/c/e506e704b74748ffd0e1c92a7453ca2a959f832b","https://git.kernel.org/stable/c/ec680ea4ba1bca92a767fb7e7869758bfdd886e3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nenic: fix tx_hang_reset use-after-free on device removal\n\nenic_remove() cancels the reset and change_mtu_work items but does not\ncancel tx_hang_reset. A TX timeout that fires while the device is being\nremoved can schedule enic_tx_hang_reset() so that it runs after\nfree_netdev(), resulting in a use-after-free.\n\ncancel_work_sync() alone is not sufficient here: the still-live watchdog\nand notify paths can re-schedule these work items in the window between\nthe cancel and unregister_netdev(). Use disable_work_sync(), which\ncancels the work and blocks any subsequent schedule_work() from\nrequeuing it, and apply it to the reset and change_mtu_work items as\nwell so the same requeue race is closed for all teardown work.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74725","epss":0.00125,"percentile":0.02518,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74725","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74726","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74726","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor  bond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and takes RTNL via rtnl_trylock() before undoing the promiscuity it set on the active slave. In that window the active slave can change under RTNL (RTM_DELLINK -> __bond_release_one() -> bond_alb_handle_active_change()), which already drops the promiscuity and clears primary_is_promisc. The monitor still acts on the stale decision: if the slave was removed with no failover, curr_active_slave is now NULL and the deref faults; if it failed over, the stale dev_set_promiscuity(-1) underflows the new slave's promiscuity counter and pins it in IFF_PROMISC.    Oops: general protection fault, probably for non-canonical address ...   KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]   Workqueue: b42 bond_alb_monitor   RIP: 0010:bond_alb_monitor (drivers/net/bonding/bond_alb.c:1600)    process_one_work (kernel/workqueue.c:3322)    worker_thread (kernel/workqueue.c:3486)    kthread (kernel/kthread.c:436)    ret_from_fork (arch/x86/kernel/process.c:158)   Kernel panic - not syncing: Fatal exception  Re-check primary_is_promisc (and curr_active_slave) after taking RTNL so the monitor only undoes an increment it still owns. The other bonding monitors already re-read state under RTNL in their commit phase (bond_miimon_commit/bond_ab_arp_commit); bond_alb_monitor() was the only one acting on the pre-trylock decision.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74726","epss":0.00126,"percentile":0.02578,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09324},"relatedVulnerabilities":[{"id":"CVE-2026-74726","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74726","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/09add8d5cfa9c46828f51eaad162c36e86366b71","https://git.kernel.org/stable/c/257c4a3a34d8f51efb00f35375a0c6ce3c8f6ce2","https://git.kernel.org/stable/c/2faf75a8a06504071b4c0aea7e45a9cc49a4e187","https://git.kernel.org/stable/c/683c6ba6e58e6ed1037831ea97dd58d9c0e76b8d","https://git.kernel.org/stable/c/b82f51681a7a88c7d3c865e817a3340d42b5fa2a","https://git.kernel.org/stable/c/dccec0227ed8d9e36936d66e256b957dc2858468","https://git.kernel.org/stable/c/dd148539fb4741d01c06b7d2c8bd84b01920756c","https://git.kernel.org/stable/c/f7668762bf5fd6db9397de5c0514407489d9d815"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor\n\nbond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and\ntakes RTNL via rtnl_trylock() before undoing the promiscuity it set on the\nactive slave. In that window the active slave can change under RTNL\n(RTM_DELLINK -> __bond_release_one() -> bond_alb_handle_active_change()),\nwhich already drops the promiscuity and clears primary_is_promisc. The\nmonitor still acts on the stale decision: if the slave was removed with no\nfailover, curr_active_slave is now NULL and the deref faults; if it failed\nover, the stale dev_set_promiscuity(-1) underflows the new slave's\npromiscuity counter and pins it in IFF_PROMISC.\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  Workqueue: b42 bond_alb_monitor\n  RIP: 0010:bond_alb_monitor (drivers/net/bonding/bond_alb.c:1600)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n  Kernel panic - not syncing: Fatal exception\n\nRe-check primary_is_promisc (and curr_active_slave) after taking RTNL so\nthe monitor only undoes an increment it still owns. The other bonding\nmonitors already re-read state under RTNL in their commit phase\n(bond_miimon_commit/bond_ab_arp_commit); bond_alb_monitor() was the only\none acting on the pre-trylock decision.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74726","epss":0.00126,"percentile":0.02578,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74726","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74729","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74729","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read  put_fifo_with_discard() acts as both producer and consumer on the kfifo: it calls kfifo_skip() (advances out) and kfifo_put() (advances in) from the IRQ handler without synchronizing with snoop_file_read(), which also consumes via kfifo_to_user(). On SMP systems this concurrent access can leave (in - out) larger than the ring buffer, so __kfifo_to_user()'s clamp to (in - out) is ineffective and kfifo_copy_to_user() can attempt a copy_to_user() past the kmalloc-2k backing store:    usercopy: Kernel memory exposure attempt detected from SLUB object   'kmalloc-2k' (offset 0, size 2049)!   kernel BUG at mm/usercopy.c!   Call trace:    usercopy_abort    __check_heap_object    __check_object_size    kfifo_copy_to_user    __kfifo_to_user    snoop_file_read    vfs_read  Serialize kfifo access with a per-channel spinlock shared between the IRQ handler (producer) and the file reader (consumer).  Annotate @fifo with __guarded_by(&lock) and opt the driver into context analysis so the compiler enforces that all fifo access holds the lock.","cvss":[],"epss":[{"cve":"CVE-2026-74729","epss":0.0017,"percentile":0.06572,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08499999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74729","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74729","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/131ab677b03349a5ae48da8722ec7075b37ec66e","https://git.kernel.org/stable/c/1acef6d85bfd98bd9dfe1f08bffa397a4dda8a6f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read\n\nput_fifo_with_discard() acts as both producer and consumer on the kfifo:\nit calls kfifo_skip() (advances out) and kfifo_put() (advances in) from\nthe IRQ handler without synchronizing with snoop_file_read(), which also\nconsumes via kfifo_to_user(). On SMP systems this concurrent access can\nleave (in - out) larger than the ring buffer, so __kfifo_to_user()'s clamp\nto (in - out) is ineffective and kfifo_copy_to_user() can attempt a\ncopy_to_user() past the kmalloc-2k backing store:\n\n  usercopy: Kernel memory exposure attempt detected from SLUB object\n  'kmalloc-2k' (offset 0, size 2049)!\n  kernel BUG at mm/usercopy.c!\n  Call trace:\n   usercopy_abort\n   __check_heap_object\n   __check_object_size\n   kfifo_copy_to_user\n   __kfifo_to_user\n   snoop_file_read\n   vfs_read\n\nSerialize kfifo access with a per-channel spinlock shared between the\nIRQ handler (producer) and the file reader (consumer).  Annotate @fifo\nwith __guarded_by(&lock) and opt the driver into context analysis so the\ncompiler enforces that all fifo access holds the lock.","cvss":[],"epss":[{"cve":"CVE-2026-74729","epss":0.0017,"percentile":0.06572,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74729","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74730","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74730","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  NFS: Pin the 'struct nfs_server' during a FREE_STATEID call  Dan Aloni reports that he was able to hit a use-after-free bug if a FREE_STATEID operation gets delayed for whatever reason. Fix this by bumping the refcount of the 'struct nfs_server' object for the duration of the FREE_STATEID so it doesn't get cleaned up from underneath us while operations are still in flight.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74730","epss":0.0051,"percentile":0.41859,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47940000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-74730","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74730","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/80ed3d762628b36c9e4b22fac7c65b72ef3b13dd","https://git.kernel.org/stable/c/af62f1af182d33a0de38308c012841885d8ab92e","https://git.kernel.org/stable/c/caee6a68ffaa5016dfc01cd0b3dc1896a32e3abd","https://git.kernel.org/stable/c/cf616096a0f3a2b60f7d68b6b39674a6867ded9c","https://git.kernel.org/stable/c/d71dfffa512e71b166a889484e4c3b148a9a3af2","https://git.kernel.org/stable/c/d858ab09e787106432d4d9830bad9dfedf02f890","https://git.kernel.org/stable/c/ed1161ab6239761958b38d5667225634fc2be894","https://git.kernel.org/stable/c/ed2f92ce2fc48463c41e0e540b9a3454889e8af8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Pin the 'struct nfs_server' during a FREE_STATEID call\n\nDan Aloni reports that he was able to hit a use-after-free bug if a\nFREE_STATEID operation gets delayed for whatever reason. Fix this by\nbumping the refcount of the 'struct nfs_server' object for the duration\nof the FREE_STATEID so it doesn't get cleaned up from underneath us\nwhile operations are still in flight.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74730","epss":0.0051,"percentile":0.41859,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74730","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74732","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74732","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Check for tg ops in dce110_set_avmute  Some older DCE timing generators do not implement is_tg_enabled in their ops table. Calling it unconditionally when waiting for AV mute frames causes a NULL pointer dereference on Southern Islands dGPUs when turning the display off over HDMI.  Check that tg and the required ops exist before waiting for frames.  (cherry picked from commit 2686a0c0aaa07bec2e24131835cf27b5fd4935a5)","cvss":[],"epss":[{"cve":"CVE-2026-74732","epss":0.00183,"percentile":0.0803,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0915},"relatedVulnerabilities":[{"id":"CVE-2026-74732","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74732","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3141e3d61469bba2624a91c5e2407f110b33b29e","https://git.kernel.org/stable/c/5edbb409b0bc5001195f4b7cfca19122361211a1","https://git.kernel.org/stable/c/853c2d31408bd45dcf92d0eb1f06eb439a56cf04","https://git.kernel.org/stable/c/d089f32d34f821c8f0ef23d5fcd77bd43c1b3b92"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check for tg ops in dce110_set_avmute\n\nSome older DCE timing generators do not implement is_tg_enabled in\ntheir ops table. Calling it unconditionally when waiting for AV mute\nframes causes a NULL pointer dereference on Southern Islands dGPUs\nwhen turning the display off over HDMI.\n\nCheck that tg and the required ops exist before waiting for frames.\n\n(cherry picked from commit 2686a0c0aaa07bec2e24131835cf27b5fd4935a5)","cvss":[],"epss":[{"cve":"CVE-2026-74732","epss":0.00183,"percentile":0.0803,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74732","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74733","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74733","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock  Locking is disabled in the regmap config as this driver uses its own lock. This means that all calls to regmap functions (read or write) must hold the i2c_lock. The function pca953x_irq_bus_sync_unlock() did not do this, and it was therefore possible that multiple threads could cause an incorrect register to be read/written.  A previous patch partly fixed this, but only protected the write to the interrupt mask register, and not the read from the direction register.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74733","epss":0.00123,"percentile":0.02379,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.094095},"relatedVulnerabilities":[{"id":"CVE-2026-74733","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74733","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/9dc325327babe7f159e84cbe9380a45342da0585","https://git.kernel.org/stable/c/e6a2f5f845f50b0c4299bace5111f56d3390a090"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock\n\nLocking is disabled in the regmap config as this driver uses its own\nlock. This means that all calls to regmap functions (read or write) must\nhold the i2c_lock. The function pca953x_irq_bus_sync_unlock() did not do\nthis, and it was therefore possible that multiple threads could cause an\nincorrect register to be read/written.\n\nA previous patch partly fixed this, but only protected the write to the\ninterrupt mask register, and not the read from the direction register.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74733","epss":0.00123,"percentile":0.02379,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74733","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74735","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74735","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  l2tp: fix tunnel and session refcount leak on seq_file release  In pppol2tp_proc_open() and l2tp_dfs_seq_open(), iteration state (pd->tunnel and pd->session) is kept in seq_file private data to allow iteration across multiple read() system calls.  However, if userspace closes /proc/net/pppol2tp or /sys/kernel/debug/l2tp/tunnels before reading to end-of-file (EOF), any tunnel or session reference stored in pd->tunnel / pd->session is left un-dropped when seq_file private data is freed.  Fix this by dropping any remaining pd->tunnel and pd->session references in pppol2tp_proc_release() and l2tp_dfs_seq_release() when closing the file.","cvss":[],"epss":[{"cve":"CVE-2026-74735","epss":0.00162,"percentile":0.05747,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08099999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-74735","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74735","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/9006c116dd111d457bf5d074990210f70a4ad2c8","https://git.kernel.org/stable/c/ebe2774e956482dd3c70b8991f6f7654356339e6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: fix tunnel and session refcount leak on seq_file release\n\nIn pppol2tp_proc_open() and l2tp_dfs_seq_open(), iteration state\n(pd->tunnel and pd->session) is kept in seq_file private data to allow\niteration across multiple read() system calls.\n\nHowever, if userspace closes /proc/net/pppol2tp or /sys/kernel/debug/l2tp/tunnels\nbefore reading to end-of-file (EOF), any tunnel or session reference stored in\npd->tunnel / pd->session is left un-dropped when seq_file private data is freed.\n\nFix this by dropping any remaining pd->tunnel and pd->session references in\npppol2tp_proc_release() and l2tp_dfs_seq_release() when closing the file.","cvss":[],"epss":[{"cve":"CVE-2026-74735","epss":0.00162,"percentile":0.05747,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74735","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74737","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74737","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG  On the packet reception path, the ID of the MAC Port on which the packet was received, is embedded in the RX DMA Descriptor's metadata. The ID is extracted using the helper function cppi5_desc_get_tags_ids() which fills in the 16-bit Source Tag into the 'port_id' variable. However, it is only the lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID, while the upper 8-bits are Hardware-Reserved and carry an arbitrary value. With the existing logic, sporadic kernel crash is observed due to the subsequent driver code accessing out-of-bound memory because of an invalid port_id.  Hence, fix the port_id extraction logic to use only the lower 8-bits of the Source Tag as the MAC Port ID.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74737","epss":0.00559,"percentile":0.4468,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.52546},"relatedVulnerabilities":[{"id":"CVE-2026-74737","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74737","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/14fc40bf28390e0ebee6a072457c36b82c614100","https://git.kernel.org/stable/c/1c0e35ce761131f82062222779d8574849790892","https://git.kernel.org/stable/c/36a05d2820077bb3955acb8111e1041d39148037","https://git.kernel.org/stable/c/46a8e084a159e638ac2728e96980b65d752d65fd","https://git.kernel.org/stable/c/551688b410d3fb0dae7739724422f268cd9446d6","https://git.kernel.org/stable/c/72e4e3d7efc3b7d85f86abbe8b94f8e45074abe3","https://git.kernel.org/stable/c/914e0100df3435bd14d09f397238e891cf9b7dce","https://git.kernel.org/stable/c/9a220225efd6f58350bbb53fe70bdec08519267f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG\n\nOn the packet reception path, the ID of the MAC Port on which the packet\nwas received, is embedded in the RX DMA Descriptor's metadata. The ID is\nextracted using the helper function cppi5_desc_get_tags_ids() which fills\nin the 16-bit Source Tag into the 'port_id' variable. However, it is only\nthe lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,\nwhile the upper 8-bits are Hardware-Reserved and carry an arbitrary value.\nWith the existing logic, sporadic kernel crash is observed due to the\nsubsequent driver code accessing out-of-bound memory because of an invalid\nport_id.\n\nHence, fix the port_id extraction logic to use only the lower 8-bits of the\nSource Tag as the MAC Port ID.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74737","epss":0.00559,"percentile":0.4468,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74737","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74739","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74739","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: cls_u32: skip hash tables in u32_bind_class()  u32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode through the walker callback. u32_bind_class() unconditionally casts the passed fh to tc_u_knode and accesses &n->res, so when fh is actually a tc_u_hnode, which has no tcf_result member, this results in a slab-out-of-bounds read of res->classid in tc_cls_bind_class().  The issue can be reproduced with the following commands:      tc qdisc add dev lo root handle 1: hfsc     tc class add dev lo parent 1: classid 1:1 hfsc sc rate 1000kbit     tc filter add dev lo parent 1:1 protocol ip prio 1 u32 match u32 0 0 flowid 1:1     tc class add dev lo parent 1: classid 1:2 hfsc sc rate 2000kbit  Fix this by skipping hash tables via the TC_U32_KEY(handle) check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74739","epss":0.00138,"percentile":0.03557,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-74739","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74739","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/19d114b93c94bdef70496f26685c2a6b242f41b3","https://git.kernel.org/stable/c/31f26a95eeee926946809ac456c61a3217936a62","https://git.kernel.org/stable/c/594a064d603202b9ee21e07679d854e5c1750cc4","https://git.kernel.org/stable/c/6d3724e616faf952c3adcf8414fc21a828ef3709","https://git.kernel.org/stable/c/e71f8e9ed6f311410b14741f6012afe01869c0fa","https://git.kernel.org/stable/c/ec5f3005586a785689fd568361b0c5925cb1548b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_u32: skip hash tables in u32_bind_class()\n\nu32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode\nthrough the walker callback. u32_bind_class() unconditionally casts the\npassed fh to tc_u_knode and accesses &n->res, so when fh is actually a\ntc_u_hnode, which has no tcf_result member, this results in a\nslab-out-of-bounds read of res->classid in tc_cls_bind_class().\n\nThe issue can be reproduced with the following commands:\n\n    tc qdisc add dev lo root handle 1: hfsc\n    tc class add dev lo parent 1: classid 1:1 hfsc sc rate 1000kbit\n    tc filter add dev lo parent 1:1 protocol ip prio 1 u32 match u32 0 0 flowid 1:1\n    tc class add dev lo parent 1: classid 1:2 hfsc sc rate 2000kbit\n\nFix this by skipping hash tables via the TC_U32_KEY(handle) check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74739","epss":0.00138,"percentile":0.03557,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74739","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74740","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74740","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain  tcf_action_exec() handles TC_ACT_GOTO_CHAIN by first checking rcu_access_pointer(a->goto_chain) and then calling tcf_action_goto_chain_exec(), which does a second, independent rcu_dereference_bh(a->goto_chain) read and immediately dereferences chain->filter_chain. A concurrent tcf_action_set_ctrlact() (e.g. the gact replace path) can clear a->goto_chain between the two reads, so the second read returns NULL and tcf_action_goto_chain_exec() dereferences NULL.  Fix the race by doing a single rcu_dereference_bh() read of a->goto_chain in tcf_action_exec(), checking it once for NULL, and passing the resulting chain pointer into tcf_action_goto_chain_exec(). This turns the split check/use into a single check/use on one value.","cvss":[],"epss":[{"cve":"CVE-2026-74740","epss":0.00175,"percentile":0.07155,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08750000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74740","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74740","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1ec48b6715c29b20105e3485206602cff6c51ae5","https://git.kernel.org/stable/c/6b70886ebc428eed43a069c8944a931b5fb3f4e4","https://git.kernel.org/stable/c/91d55fd1fdb85c8371ca8793c788ea7d5192383a","https://git.kernel.org/stable/c/abceabc4408fca6a9dd52611f5d197dec9390d63","https://git.kernel.org/stable/c/f60b396ee174206fe08ebf997d16cd3801b77b22"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: fix TOCTOU NULL deref on a->goto_chain\n\ntcf_action_exec() handles TC_ACT_GOTO_CHAIN by first checking\nrcu_access_pointer(a->goto_chain) and then calling\ntcf_action_goto_chain_exec(), which does a second, independent\nrcu_dereference_bh(a->goto_chain) read and immediately dereferences\nchain->filter_chain. A concurrent tcf_action_set_ctrlact() (e.g. the gact\nreplace path) can clear a->goto_chain between the two reads, so the second\nread returns NULL and tcf_action_goto_chain_exec() dereferences NULL.\n\nFix the race by doing a single rcu_dereference_bh() read of a->goto_chain\nin tcf_action_exec(), checking it once for NULL, and passing the resulting\nchain pointer into tcf_action_goto_chain_exec(). This turns the split\ncheck/use into a single check/use on one value.","cvss":[],"epss":[{"cve":"CVE-2026-74740","epss":0.00175,"percentile":0.07155,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74740","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74743","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74743","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  macvlan: inherit needed_headroom and needed_tailroom from lowerdev  macvlan devices inherit hard_header_len from lowerdev during macvlan_init(), but leave needed_headroom and needed_tailroom set to 0.  When the underlying lowerdev requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx headroom), upper layers calculating packet headroom and tailroom fail to reserve sufficient space.  This can result in reallocation overhead, skb headroom underflows, or KASAN slab-use-after-free crashes when dev_hard_header() / macvlan_hard_header() prepends header data or when lower devices append tailroom.  Fix this by: 1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init(). 2. Propagating needed_headroom and needed_tailroom updates to attached macvlans    in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74743","epss":0.00519,"percentile":0.42421,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48786},"relatedVulnerabilities":[{"id":"CVE-2026-74743","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74743","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/28afc87bd8da0b3348bbbd834c8a89e83712cf5e","https://git.kernel.org/stable/c/8cd90e850e434577bf6774778657d26d6995e53f","https://git.kernel.org/stable/c/8f6a05dbac05725e0786701eb04778c5bdbe4eaa","https://git.kernel.org/stable/c/96fa90b74385b7f2b0d97251dd43d5ee6ca44668","https://git.kernel.org/stable/c/bc9a00fb78e32bccc39d763bfd13a450705bac5d","https://git.kernel.org/stable/c/cef51860becd9700217c81732ca1eb1ea6ed6fe1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: inherit needed_headroom and needed_tailroom from lowerdev\n\nmacvlan devices inherit hard_header_len from lowerdev during macvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying lowerdev requires extra headroom or tailroom for\nheaders/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx\nheadroom), upper layers calculating packet headroom and tailroom fail to\nreserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / macvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached macvlans\n   in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74743","epss":0.00519,"percentile":0.42421,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74743","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74744","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74744","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipvlan: inherit needed_headroom and needed_tailroom from phy_dev  ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), but leave needed_headroom and needed_tailroom set to 0.  When the underlying phy_dev (or stacked lower device) requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx headroom), upper layers calculating packet headroom and tailroom fail to reserve sufficient space.  This can result in reallocation overhead, skb headroom underflows, or KASAN slab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header() prepends header data or when lower devices append tailroom.  Fix this by: 1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init(). 2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans    in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74744","epss":0.00519,"percentile":0.42422,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48786},"relatedVulnerabilities":[{"id":"CVE-2026-74744","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74744","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/5c2ca77212eb38559b0353b8363b7a84f4b019dd","https://git.kernel.org/stable/c/5f33188457bbcc1b11ca87084037963c516ed3d9","https://git.kernel.org/stable/c/af602c4d0ee548da18e2409b4b4da1079625a372","https://git.kernel.org/stable/c/c0fbe31f6b20ade0465130685859faa5c86fda59","https://git.kernel.org/stable/c/e16e960d55a40d36bd7c2494cc005e757dc9a1ef","https://git.kernel.org/stable/c/f3c17ff65f54781cde696e16a6c577615ed735aa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: inherit needed_headroom and needed_tailroom from phy_dev\n\nipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying phy_dev (or stacked lower device) requires extra headroom\nor tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or\nveth with rx headroom), upper layers calculating packet headroom and tailroom\nfail to reserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / ipvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from phy_dev in ipvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached ipvlans\n   in ipvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74744","epss":0.00519,"percentile":0.42422,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74744","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74746","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74746","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: flowtable: publish GC-visible tuple last  nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flow_offload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC never sees a partially installed flow.  KASAN can trigger slab-use-after-free read and write reports in the flowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del, flow_offload_lookup, etc.).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74746","epss":0.00543,"percentile":0.43852,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.5104200000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74746","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74746","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0a00254585827f1695aa2700114af622ea754cfa","https://git.kernel.org/stable/c/2014ac62df9d45bb9a004a043e85df7be09ed780","https://git.kernel.org/stable/c/211ee5d998d92a7d548811939c65942d06c146e4","https://git.kernel.org/stable/c/972fdf7c4f5c282a239c88fea614b056c33dc025","https://git.kernel.org/stable/c/be345dcbddb4643a54252b954af974b16eda8f91","https://git.kernel.org/stable/c/d16b71231e65cb05daea2b45701fcf09cef041e7","https://git.kernel.org/stable/c/d37917e7bebe078f3c17e47fd6fc1c9f6e8497b2","https://git.kernel.org/stable/c/d9d3050a70efe217e73a0751e55fdae6a7092620"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: publish GC-visible tuple last\n\nnf_flow_table_iterate() only treats original-direction tuple nodes as\nowning entries. Publishing the original node first lets GC observe and\nfree a flow while flow_offload_add() is still inserting the reply node.\nPublish the reply node first and the original node last so GC never\nsees a partially installed flow.\n\nKASAN can trigger slab-use-after-free read and write reports in the\nflowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del,\nflow_offload_lookup, etc.).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74746","epss":0.00543,"percentile":0.43852,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74746","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74747","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74747","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipvs: revalidate ihl to prevent out-of-bounds access  While the outer IP header is already pulled into the skb head, we must be careful and revalidate the embedded headers after reading them from the skb frags to prevent out-of-bounds access.  One such place reported by Sashiko is ip_vs_nat_icmp() where local process can change the ihl field and after skb_ensure_writable() we can see larger value which is a problem for the ip_send_check(cih) calls.  Add check to drop the packet if the ihl field is changed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74747","epss":0.00129,"percentile":0.02884,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-74747","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74747","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/5365f012451fce2453f13a568dcb72ea534c1e4d","https://git.kernel.org/stable/c/d93660df4dd1d116f608ada4a29a80a5d6f0a6ed"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: revalidate ihl to prevent out-of-bounds access\n\nWhile the outer IP header is already pulled into the skb head,\nwe must be careful and revalidate the embedded headers after\nreading them from the skb frags to prevent out-of-bounds\naccess.\n\nOne such place reported by Sashiko is ip_vs_nat_icmp() where\nlocal process can change the ihl field and after\nskb_ensure_writable() we can see larger value which is a\nproblem for the ip_send_check(cih) calls.\n\nAdd check to drop the packet if the ihl field is changed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74747","epss":0.00129,"percentile":0.02884,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74747","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74748","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74748","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: ipset: fix refcount race between list:set GC and swap  __ip_set_put_byindex() resolved the index to a set pointer under RCU, then took ip_set_ref_lock in __ip_set_put() to decrement set->ref. ip_set_swap() holds that same lock while swapping both the ip_set_list slots and the two sets' ref counters, so it can interleave between the dereference and the lock acquisition, leaving the caller to decrement a set whose reference already moved to the other index and hit BUG_ON(set->ref == 0). list_set_gc() reaches this from timer softirq, which the nfnl mutex does not serialize against swap: an expiring list:set member calls list_set_del() -> ip_set_put_byindex() while IPSET_CMD_SWAP runs on the referenced sets.  Resolve the index and decrement under ip_set_ref_lock, as ip_set_swap() already does, keeping the refcount tied to the index rather than to a stale set pointer.    kernel BUG at net/netfilter/ipset/ip_set_core.c:685!   Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI   RIP: 0010:ip_set_put_byindex (net/netfilter/ipset/ip_set_core.c:870)   Call Trace:    <IRQ>    list_set_del (net/netfilter/ipset/ip_set_list_set.c:159)    set_cleanup_entries (net/netfilter/ipset/ip_set_list_set.c:181)    list_set_gc (net/netfilter/ipset/ip_set_list_set.c:578)    call_timer_fn (kernel/time/timer.c:1748)    __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2374)    run_timer_softirq (kernel/time/timer.c:2405)    </IRQ>   Kernel panic - not syncing: Fatal exception in interrupt","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74748","epss":0.00138,"percentile":0.03557,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10557},"relatedVulnerabilities":[{"id":"CVE-2026-74748","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74748","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0c88868271653537ed443272dd8e7d13634d214b","https://git.kernel.org/stable/c/20cb13a523f0a05cb2d0a7d72abae687683712e0","https://git.kernel.org/stable/c/24ffcb1e1688c55fd2a505f064295cd28eac546d","https://git.kernel.org/stable/c/97a01de0c6321b7210d30d0a4d60f10f561097c7","https://git.kernel.org/stable/c/b0aab9dd1a348b99d75ff52765719d0cc2050630","https://git.kernel.org/stable/c/b891e7a6bb06e0f6560e5932665ac660acd12225","https://git.kernel.org/stable/c/c21afc7c216a4d257a4f3f300e0791890bc846b9","https://git.kernel.org/stable/c/cb20da33839f28f590c99f16bafaa6151451c0e8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: fix refcount race between list:set GC and swap\n\n__ip_set_put_byindex() resolved the index to a set pointer under RCU,\nthen took ip_set_ref_lock in __ip_set_put() to decrement set->ref.\nip_set_swap() holds that same lock while swapping both the ip_set_list\nslots and the two sets' ref counters, so it can interleave between the\ndereference and the lock acquisition, leaving the caller to decrement a\nset whose reference already moved to the other index and hit\nBUG_ON(set->ref == 0). list_set_gc() reaches this from timer softirq,\nwhich the nfnl mutex does not serialize against swap: an expiring\nlist:set member calls list_set_del() -> ip_set_put_byindex() while\nIPSET_CMD_SWAP runs on the referenced sets.\n\nResolve the index and decrement under ip_set_ref_lock, as ip_set_swap()\nalready does, keeping the refcount tied to the index rather than to a\nstale set pointer.\n\n  kernel BUG at net/netfilter/ipset/ip_set_core.c:685!\n  Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n  RIP: 0010:ip_set_put_byindex (net/netfilter/ipset/ip_set_core.c:870)\n  Call Trace:\n   <IRQ>\n   list_set_del (net/netfilter/ipset/ip_set_list_set.c:159)\n   set_cleanup_entries (net/netfilter/ipset/ip_set_list_set.c:181)\n   list_set_gc (net/netfilter/ipset/ip_set_list_set.c:578)\n   call_timer_fn (kernel/time/timer.c:1748)\n   __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2374)\n   run_timer_softirq (kernel/time/timer.c:2405)\n   </IRQ>\n  Kernel panic - not syncing: Fatal exception in interrupt","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74748","epss":0.00138,"percentile":0.03557,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74748","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74752","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74752","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: validate cookie AUTH state before use  When cookie authentication is disabled, COOKIE_ECHO restores fixed-size AUTH fields directly from peer-controlled cookie bytes.  A forged RANDOM length, HMAC list, or CHUNKS list can then reach association consumers with lengths or identifiers that were never validated against the local backing arrays.  A forged RANDOM length can cause out-of-bounds reads during key-vector construction.  A forged HMAC identifier also caused a 32-byte write past a zero-length AUTH chunk, providing a primitive for a local privilege escalation chain.  Validate the cookie's RANDOM, HMACS, and CHUNKS parameters at the cookie trust boundary before copying them into the association.  Reject invalid types, malformed lengths, unsupported HMAC identifiers, HMAC lists without SHA1, and forbidden chunk ids.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74752","epss":0.00434,"percentile":0.36643,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.40796},"relatedVulnerabilities":[{"id":"CVE-2026-74752","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74752","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/3dbb44d88b1e94dd31fe43588af7437b34b44d56","https://git.kernel.org/stable/c/88619b117be1daf633ce32210570ce35a0bd1c98"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate cookie AUTH state before use\n\nWhen cookie authentication is disabled, COOKIE_ECHO restores fixed-size\nAUTH fields directly from peer-controlled cookie bytes.  A forged RANDOM\nlength, HMAC list, or CHUNKS list can then reach association consumers\nwith lengths or identifiers that were never validated against the local\nbacking arrays.\n\nA forged RANDOM length can cause out-of-bounds reads during key-vector\nconstruction.  A forged HMAC identifier also caused a 32-byte write past\na zero-length AUTH chunk, providing a primitive for a local privilege\nescalation chain.\n\nValidate the cookie's RANDOM, HMACS, and CHUNKS parameters at the cookie\ntrust boundary before copying them into the association.  Reject invalid\ntypes, malformed lengths, unsupported HMAC identifiers, HMAC lists\nwithout SHA1, and forbidden chunk ids.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-74752","epss":0.00434,"percentile":0.36643,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74752","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-74754","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74754","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: core: pair EH runtime PM get and put  shost->eh_noresume is currently consulted twice in one error handling iteration: once before scsi_autopm_get_host() and once again before scsi_autopm_put_host().  That is racy when a PM-triggered error path flips shost->eh_noresume while the SCSI EH thread is still running.  The problem flow looks like this: PM path   ufshcd_set_dev_pwr_mode()     shost->eh_noresume = 1     ufshcd_execute_start_stop  <-- trigger EH     ...     shost->eh_noresume = 0  EH path   scsi_error_handler()     if (!shost->eh_noresume)       scsi_autopm_get_host()  <-- skipped     ...     if (!shost->eh_noresume)        scsi_autopm_put_host()  <-- executed later  In that case one EH iteration can skip autoresume on entry and still drop a runtime PM reference on exit. That leaves an unmatched runtime PM put and can trigger a runtime PM usage count underflow.  Fix this by making eh_noresume a regular bool so it can be accessed with READ_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use that snapshot for both runtime PM get and put decisions.","cvss":[],"epss":[{"cve":"CVE-2026-74754","epss":0.00155,"percentile":0.04987,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-74754","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74754","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/872f486259ae0bc6b73ca4735a15d013241f73e9","https://git.kernel.org/stable/c/e83eed1bea142c8fe852fd53156845b88252ecd8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: pair EH runtime PM get and put\n\nshost->eh_noresume is currently consulted twice in one error handling\niteration: once before scsi_autopm_get_host() and once again before\nscsi_autopm_put_host().\n\nThat is racy when a PM-triggered error path flips shost->eh_noresume\nwhile the SCSI EH thread is still running.\n\nThe problem flow looks like this:\nPM path\n  ufshcd_set_dev_pwr_mode()\n    shost->eh_noresume = 1\n    ufshcd_execute_start_stop  <-- trigger EH\n    ...\n    shost->eh_noresume = 0\n\nEH path\n  scsi_error_handler()\n    if (!shost->eh_noresume)\n      scsi_autopm_get_host()  <-- skipped\n    ...\n    if (!shost->eh_noresume)\n       scsi_autopm_put_host()  <-- executed later\n\nIn that case one EH iteration can skip autoresume on entry and still\ndrop a runtime PM reference on exit. That leaves an unmatched runtime PM\nput and can trigger a runtime PM usage count underflow.\n\nFix this by making eh_noresume a regular bool so it can be accessed with\nREAD_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use\nthat snapshot for both runtime PM get and put decisions.","cvss":[],"epss":[{"cve":"CVE-2026-74754","epss":0.00155,"percentile":0.04987,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-74754","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80521","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80521","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  af_unix: Unlink scc_entry in unix_del_edge().  Kyle Zeng reported that GC could free a dead SCC partially.  The scenario is as follows:     1) Create two SCCs:         X -.   A <-> B        ^--'     2) Run the following concurrently:        2-1) send() sk-B to sk-B from sk-X       2-2) close() both A and B  At 2-1), there is a small window where unix_add_edges() publishes a new edge (B <-> B) to GC but its skb is not queued by skb_queue_tail().  If 2-2) completes before skb_queue_tail() and GC is triggered, it judges A <-> B as dead, but B is not freed because GC cannot collect the not-yet-queued skb holding the B <-> B edge.         X -.   A <-> B -. This edge is visible        ^--'         ^..'  but skb is not  This itself is not a problem since the next GC run will judge B as dead as well and free it finally.         X -.   A <.> B -.        ^--'         ^--'  However, X's SCC forces the next GC to call unix_walk_scc_fast(), and it iterates over A through B's scc_entry.  Let's unlink scc_entry before freeing the vertex in unix_del_edge().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80521","epss":0.0012,"percentile":0.02087,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80521","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80521","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/594d905195024b228c962627ae5ae7c17bd582a4","https://git.kernel.org/stable/c/e3702470ced94fad74d71e2232f022d2eb752a6d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Unlink scc_entry in unix_del_edge().\n\nKyle Zeng reported that GC could free a dead SCC partially.\n\nThe scenario is as follows:\n\n   1) Create two SCCs:\n\n       X -.   A <-> B\n       ^--'\n\n   2) Run the following concurrently:\n\n      2-1) send() sk-B to sk-B from sk-X\n      2-2) close() both A and B\n\nAt 2-1), there is a small window where unix_add_edges()\npublishes a new edge (B <-> B) to GC but its skb is not queued\nby skb_queue_tail().\n\nIf 2-2) completes before skb_queue_tail() and GC is triggered,\nit judges A <-> B as dead, but B is not freed because GC cannot\ncollect the not-yet-queued skb holding the B <-> B edge.\n\n       X -.   A <-> B -. This edge is visible\n       ^--'         ^..'  but skb is not\n\nThis itself is not a problem since the next GC run will judge\nB as dead as well and free it finally.\n\n       X -.   A <.> B -.\n       ^--'         ^--'\n\nHowever, X's SCC forces the next GC to call unix_walk_scc_fast(),\nand it iterates over A through B's scc_entry.\n\nLet's unlink scc_entry before freeing the vertex in unix_del_edge().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80521","epss":0.0012,"percentile":0.02087,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80521","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80526","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80526","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: tas2562: Validate values for volume writes  tas2562_volume_control_put() does not do any validation of the control value written by userspace, it uses it to look up a value in a fixed size array which can easily be overflowed and then writes whatever value it gets back to the device.  Add validation that we are loading a value we have in the array.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80526","epss":0.00128,"percentile":0.02815,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09792000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80526","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80526","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1f389ecd0c35e9e281036e44c121df904f3164c1","https://git.kernel.org/stable/c/20bdbb1376457ecbf418bf677fd285820d1fc011","https://git.kernel.org/stable/c/8fb41964f7e4e4207c8999af2056894caa7a252a","https://git.kernel.org/stable/c/c37a0461c0d0a70c5de4fdbd70449a7f53c12dda","https://git.kernel.org/stable/c/db488d653d896fcf9ac87e15239924c2928bbc3c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: tas2562: Validate values for volume writes\n\ntas2562_volume_control_put() does not do any validation of the control\nvalue written by userspace, it uses it to look up a value in a fixed\nsize array which can easily be overflowed and then writes whatever value\nit gets back to the device.  Add validation that we are loading a value\nwe have in the array.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80526","epss":0.00128,"percentile":0.02815,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80526","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80527","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80527","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ceph: fix hanging __ceph_get_caps() with stale mds_wanted  A reader can hang forever in __ceph_get_caps() when the client no longer holds `FILE_RD`, but local cap state still says that the capability is already wanted (via `mds_wanted`).  One way to trigger this is through MDS cap revocation.  If another client performs a conflicting operation, the MDS can revoke `FILE_RD` from the reader; the next read then has to reacquire `FILE_RD`.  If the cap update that should request `FILE_RD` never reaches the MDS after `cap->mds_wanted` was raised, the reader is left holding only non-file caps while local `mds_wanted` still includes the file read caps.  In that state, try_get_cap_refs() sees `need <= mds_wanted` and returns 0, so __ceph_get_caps() just waits on `i_cap_wq`.  If the cap update that was supposed to request `FILE_RD never reaches the MDS after `cap->mds_wanted was` raised, no further request is sent and the waiter can sleep indefinitely until unrelated cap traffic happens to wake it up.  The ordering issue is that `cap->mds_wanted` is updated in __prep_cap() before the `CEPH_MSG_CLIENT_CAPS message` is actually queued for send.  That makes one field serve two different meanings at once: what this client wants, and what the client believes the MDS already knows it wants.  A proper fix would be to split those states and track whether a cap update is actually in flight or has been observed by the MDS. However, simply moving the `cap->mds_wanted assignment` later would not be sufficient: queueing the message in the messenger does not guarantee that the MDS processed that specific wanted set, and reconnect or message loss can still invalidate that assumption. Fixing that properly would require a larger rework of the cap state machine.  To allow simpler backports to stable kernels, this patch implements a simpler workaround:  - stop waiting forever in __ceph_get_caps(); after a bounded wait,   fall back to the renew path  - make ceph_renew_caps() issue a synchronous `OPEN` request whenever   the inode still does not actually hold the wanted caps, instead of   only calling ceph_check_caps()  The extra issued-vs-wanted check in ceph_renew_caps() is necessary because the previous test only checked whether the inode still had any real caps at all.  That is not enough after revocation: the client can still hold something like `pLs` and yet be missing `FILE_RD` completely.  In that case, falling back to ceph_check_caps() is not sufficient, because it still trusts `cap->mds_wanted` and may resend nothing.  By requiring `(issued & wanted) == wanted` before taking the asynchronous path, the code only uses ceph_check_caps() when the `wanted caps` are already actually issued.  Otherwise, it sends the synchronous `OPEN` renew.  This preserves the existing asynchronous fast path when the wanted caps are already issued, avoids changing cap-state semantics, and fixes the hang by guaranteeing that a stalled waiter eventually retries through a path that does not rely on the stale `mds_wanted` state.  [ idryomov: move CEPH_GET_CAPS_WAIT_TIMEOUT from libceph.h to   mds_client.h, formatting ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80527","epss":0.00508,"percentile":0.41705,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.381},"relatedVulnerabilities":[{"id":"CVE-2026-80527","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80527","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/50958bb928bad3bdba9e5d1b7ff4bbadcf6951e6","https://git.kernel.org/stable/c/5e84bc6f67e19fdd192d8b215de728acbfc12572","https://git.kernel.org/stable/c/5fedf279a1ea369d39c8b06dd4547cdc576065d0","https://git.kernel.org/stable/c/9e55fe24c548ad3163903eb58bb002d28d32a630","https://git.kernel.org/stable/c/a3bc6b3e9ef3f5f5cb85a902a30a090c7931127c","https://git.kernel.org/stable/c/b5661524c5a45085a866864ca9b8ae2513dfd67a","https://git.kernel.org/stable/c/e05c315b4da0c16ea800ee4b2cb6c617f586d1b5","https://git.kernel.org/stable/c/fcce1b3be6d286aa80831e730289f4c062053ae6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix hanging __ceph_get_caps() with stale mds_wanted\n\nA reader can hang forever in __ceph_get_caps() when the client no\nlonger holds `FILE_RD`, but local cap state still says that the\ncapability is already wanted (via `mds_wanted`).\n\nOne way to trigger this is through MDS cap revocation.  If another\nclient performs a conflicting operation, the MDS can revoke `FILE_RD`\nfrom the reader; the next read then has to reacquire `FILE_RD`.  If\nthe cap update that should request `FILE_RD` never reaches the MDS\nafter `cap->mds_wanted` was raised, the reader is left holding only\nnon-file caps while local `mds_wanted` still includes the file read\ncaps.\n\nIn that state, try_get_cap_refs() sees `need <= mds_wanted` and\nreturns 0, so __ceph_get_caps() just waits on `i_cap_wq`.  If the cap\nupdate that was supposed to request `FILE_RD never reaches the MDS\nafter `cap->mds_wanted was` raised, no further request is sent and the\nwaiter can sleep indefinitely until unrelated cap traffic happens to\nwake it up.\n\nThe ordering issue is that `cap->mds_wanted` is updated in\n__prep_cap() before the `CEPH_MSG_CLIENT_CAPS message` is actually\nqueued for send.  That makes one field serve two different meanings at\nonce: what this client wants, and what the client believes the MDS\nalready knows it wants.\n\nA proper fix would be to split those states and track whether a cap\nupdate is actually in flight or has been observed by the MDS.\nHowever, simply moving the `cap->mds_wanted assignment` later would\nnot be sufficient: queueing the message in the messenger does not\nguarantee that the MDS processed that specific wanted set, and\nreconnect or message loss can still invalidate that assumption.\nFixing that properly would require a larger rework of the cap state\nmachine.\n\nTo allow simpler backports to stable kernels, this patch implements a\nsimpler workaround:\n\n- stop waiting forever in __ceph_get_caps(); after a bounded wait,\n  fall back to the renew path\n\n- make ceph_renew_caps() issue a synchronous `OPEN` request whenever\n  the inode still does not actually hold the wanted caps, instead of\n  only calling ceph_check_caps()\n\nThe extra issued-vs-wanted check in ceph_renew_caps() is necessary\nbecause the previous test only checked whether the inode still had any\nreal caps at all.  That is not enough after revocation: the client can\nstill hold something like `pLs` and yet be missing `FILE_RD`\ncompletely.  In that case, falling back to ceph_check_caps() is not\nsufficient, because it still trusts `cap->mds_wanted` and may resend\nnothing.  By requiring `(issued & wanted) == wanted` before taking the\nasynchronous path, the code only uses ceph_check_caps() when the\n`wanted caps` are already actually issued.  Otherwise, it sends the\nsynchronous `OPEN` renew.\n\nThis preserves the existing asynchronous fast path when the wanted\ncaps are already issued, avoids changing cap-state semantics, and\nfixes the hang by guaranteeing that a stalled waiter eventually\nretries through a path that does not rely on the stale `mds_wanted`\nstate.\n\n[ idryomov: move CEPH_GET_CAPS_WAIT_TIMEOUT from libceph.h to\n  mds_client.h, formatting ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80527","epss":0.00508,"percentile":0.41705,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80527","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80528","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80528","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ceph: avoid fs reclaim while using current->journal_info  handle_reply() stores a `ceph_mds_request` pointer in `current->journal_info` while filling the inode and dentry cache from an MDS reply.  An allocation in this section can enter direct reclaim and prune dentries from another filesystem.  If this dirties an ext4 inode, ext4 starts a JBD2 transaction.  JBD2 interprets the Ceph request in `current->journal_info` as a journal handle and dereferences the request's `r_tid` as `h_transaction`, causing a kernel crash, e.g.:   Unable to handle kernel paging request at virtual address 00000000077b4818  [...]  Internal error: Oops: 0000000096000004 [#1]  SMP  Modules linked in:  CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE  [...]  Workqueue: ceph-msgr ceph_con_workfn  pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)  pc : jbd2__journal_start+0x2c/0x208  lr : __ext4_journal_start_sb+0x100/0x178  [...]  Call trace:   jbd2__journal_start+0x2c/0x208 (P)   __ext4_journal_start_sb+0x100/0x178   ext4_dirty_inode+0x3c/0x90   __mark_inode_dirty+0x58/0x400   iput.part.0+0x2b0/0x370   iput+0x18/0x30   dentry_unlink_inode+0xc0/0x158   __dentry_kill+0x80/0x250   shrink_dentry_list+0x90/0x130   prune_dcache_sb+0x60/0x98   super_cache_scan+0xe8/0x190   do_shrink_slab+0x174/0x388   shrink_slab+0xd8/0x4c0   shrink_node+0x31c/0x908   do_try_to_free_pages+0xd0/0x508   try_to_free_pages+0x11c/0x238   __alloc_frozen_pages_noprof+0x4d0/0xdd0   __folio_alloc_noprof+0x18/0x70   __filemap_get_folio+0x248/0x440   ceph_readdir_prepopulate+0x570/0x9e8   mds_dispatch+0x1424/0x1ba0   ceph_con_process_message+0x74/0xa0   ceph_con_v1_try_read+0x3a0/0x1510   ceph_con_workfn+0x260/0x460  Enter a scoped NOFS allocation context and leave it after clearing `journal_info`.  This prevents filesystem reclaim from recursing into another filesystem while the field contains Ceph-private data.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80528","epss":0.00521,"percentile":0.42541,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48974000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-80528","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80528","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/00c12f57a87f537fa8779258fb3a03003a99963e","https://git.kernel.org/stable/c/47b745747b3aa39064724a642884f9df924ddf20","https://git.kernel.org/stable/c/4dbb2c02558e71f93510a6461d7e798b67426b49","https://git.kernel.org/stable/c/5b602344a49e039e792ce5a8923bcc61412ee134","https://git.kernel.org/stable/c/79d95b43ca090426399651ed580dd9bf2db36ab8","https://git.kernel.org/stable/c/b6a0989613072499633e761a1536428a466de7d3","https://git.kernel.org/stable/c/c8a21660c3b90864c391164eea5622e7b5b2897c","https://git.kernel.org/stable/c/ca5fa2380dd90a0adb01580fa6225025351a90f6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: avoid fs reclaim while using current->journal_info\n\nhandle_reply() stores a `ceph_mds_request` pointer in\n`current->journal_info` while filling the inode and dentry cache from\nan MDS reply.\n\nAn allocation in this section can enter direct reclaim and prune\ndentries from another filesystem.  If this dirties an ext4 inode, ext4\nstarts a JBD2 transaction.  JBD2 interprets the Ceph request in\n`current->journal_info` as a journal handle and dereferences the\nrequest's `r_tid` as `h_transaction`, causing a kernel crash, e.g.:\n\n Unable to handle kernel paging request at virtual address 00000000077b4818\n [...]\n Internal error: Oops: 0000000096000004 [#1]  SMP\n Modules linked in:\n CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE\n [...]\n Workqueue: ceph-msgr ceph_con_workfn\n pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : jbd2__journal_start+0x2c/0x208\n lr : __ext4_journal_start_sb+0x100/0x178\n [...]\n Call trace:\n  jbd2__journal_start+0x2c/0x208 (P)\n  __ext4_journal_start_sb+0x100/0x178\n  ext4_dirty_inode+0x3c/0x90\n  __mark_inode_dirty+0x58/0x400\n  iput.part.0+0x2b0/0x370\n  iput+0x18/0x30\n  dentry_unlink_inode+0xc0/0x158\n  __dentry_kill+0x80/0x250\n  shrink_dentry_list+0x90/0x130\n  prune_dcache_sb+0x60/0x98\n  super_cache_scan+0xe8/0x190\n  do_shrink_slab+0x174/0x388\n  shrink_slab+0xd8/0x4c0\n  shrink_node+0x31c/0x908\n  do_try_to_free_pages+0xd0/0x508\n  try_to_free_pages+0x11c/0x238\n  __alloc_frozen_pages_noprof+0x4d0/0xdd0\n  __folio_alloc_noprof+0x18/0x70\n  __filemap_get_folio+0x248/0x440\n  ceph_readdir_prepopulate+0x570/0x9e8\n  mds_dispatch+0x1424/0x1ba0\n  ceph_con_process_message+0x74/0xa0\n  ceph_con_v1_try_read+0x3a0/0x1510\n  ceph_con_workfn+0x260/0x460\n\nEnter a scoped NOFS allocation context and leave it after clearing\n`journal_info`.  This prevents filesystem reclaim from recursing into\nanother filesystem while the field contains Ceph-private data.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80528","epss":0.00521,"percentile":0.42541,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80528","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80529","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80529","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfs: don't swallow dquot recovery verification errors  xlog_recover_dquot_commit_pass2() validates the recovered dquot with xfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps to out_release.  But out_release unconditionally returns 0, so the corruption error is discarded: the caller xlog_recover_items_pass2() sees success, log recovery proceeds as if the dquot were valid, and the corrupt quota buffer can be written back to disk.","cvss":[],"epss":[{"cve":"CVE-2026-80529","epss":0.00172,"percentile":0.06811,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-80529","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80529","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/36a31b12540c0a0a3b77a01fda86de646f2961fb","https://git.kernel.org/stable/c/38a4dbe588bd028a07a77dc5cee62ee3ce21e87d","https://git.kernel.org/stable/c/5b756fbb60b5d26063f46a11a3c7daa7eb616d79","https://git.kernel.org/stable/c/a233b3362a3c7bf23f5143b4ef4b17ec337fcb4d","https://git.kernel.org/stable/c/e2b4a856085e9bd939bde2dee0d08b1d41babde9","https://git.kernel.org/stable/c/e506e127fcb4e2bad1045805f1740b395eea9618"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't swallow dquot recovery verification errors\n\nxlog_recover_dquot_commit_pass2() validates the recovered dquot with\nxfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps\nto out_release.  But out_release unconditionally returns 0, so the\ncorruption error is discarded: the caller xlog_recover_items_pass2()\nsees success, log recovery proceeds as if the dquot were valid, and the\ncorrupt quota buffer can be written back to disk.","cvss":[],"epss":[{"cve":"CVE-2026-80529","epss":0.00172,"percentile":0.06811,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80529","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80534","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80534","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfs: fix ilock leak on error in xfs_dq_get_next_id  xfs_dq_get_next_id() takes the quota inode ILOCK before calling xfs_iread_extents().  If xfs_iread_extents() fails, the function returns immediately without releasing the lock, leaking the quota inode ILOCK. This can leave the quota inode locked and cause subsequent quota operations to hang.  Fix this by jumping to a common unlock path on error instead of returning directly.","cvss":[],"epss":[{"cve":"CVE-2026-80534","epss":0.00176,"percentile":0.073,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80534","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80534","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0865e4fca02e418fd2423fae9a887dee87b778a1","https://git.kernel.org/stable/c/08bed2b67d2ee79d3e138c344d8dcfa4c9b26a38","https://git.kernel.org/stable/c/514a5d42d4188fc5f1499a8d654c717ebf981193","https://git.kernel.org/stable/c/63320a0f70f66f311f4bccff3af0719c2119f46c","https://git.kernel.org/stable/c/6401b99a285cd4cfb2949ba44675541b91ad7e4f","https://git.kernel.org/stable/c/e270d539b8a2e0cb8f617fee47a7b083c0088361","https://git.kernel.org/stable/c/e4c05ebd01e910bccd4f7e9517c7353982e27763","https://git.kernel.org/stable/c/ed8bfb43de71213cfdbbe833b2c2817250e18b1a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix ilock leak on error in xfs_dq_get_next_id\n\nxfs_dq_get_next_id() takes the quota inode ILOCK before calling\nxfs_iread_extents().  If xfs_iread_extents() fails, the function returns\nimmediately without releasing the lock, leaking the quota inode ILOCK.\nThis can leave the quota inode locked and cause subsequent quota\noperations to hang.\n\nFix this by jumping to a common unlock path on error instead of returning\ndirectly.","cvss":[],"epss":[{"cve":"CVE-2026-80534","epss":0.00176,"percentile":0.073,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80534","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80536","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80536","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfs: bounds-check buffer log item's dirty bitmap  xlog_recover_do_reg_buffer() replays each dirty region described by a buffer log item's bitmap into the buffer read for that item:  \tmemcpy(xfs_buf_offset(bp, (uint)bit << XFS_BLF_SHIFT), \t\titem->ri_buf[i].iov_base, \t\tnbits << XFS_BLF_SHIFT);  The destination offset (bit/nbits, from the logged dirty bitmap) and the buffer size (from the logged blf_len) are both attacker-controlled and otherwise unrelated, yet the only thing bounding the copy is an ASSERT(), which compiles away on production kernels. A crafted image logging a small blf_len together with a bitmap bit past the end of that buffer drives the memcpy() past the buffer's allocation, corrupting adjacent kernel heap during mount-time log recovery. This is reachable by anyone who can get a crafted image mounted -- the malicious-filesystem threat model XFS already guards against elsewhere.  Turn the ASSERT() into a real XFS_IS_CORRUPT() check that aborts recovery of the buffer with -EFSCORRUPTED, consistent with the validate-and-fail idiom already used in xlog_recover_do_inode_buffer() and xfs_dquot_item_recover.c. xlog_recover_do_reg_buffer() therefore becomes STATIC int and its three callers propagate the error.  Found and confirmed with KASAN on a CONFIG_XFS_DEBUG=n build: the crafted image trips a slab-out-of-bounds write before this change and fails recovery cleanly with -EFSCORRUPTED after it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80536","epss":0.00144,"percentile":0.03978,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11448000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80536","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80536","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7e32d4eebae6ca24f8a673c107fd7eca1f47afc2","https://git.kernel.org/stable/c/813f8136a2ce1fee266d02a7df73db6e8a541604","https://git.kernel.org/stable/c/acb4e26295e7f0e685815a3fd3d70bd8329cefa1","https://git.kernel.org/stable/c/b7528b42813f02724a78fce1da24d69d1bfc4d38","https://git.kernel.org/stable/c/edaf5b6bd625356893da20d69a259b34a9de2694","https://git.kernel.org/stable/c/f3859c35a4fbc1c1c58431f684f808e43696891d","https://git.kernel.org/stable/c/f7b5fa83e2c192be922121b764415fa8c7549ea1","https://git.kernel.org/stable/c/f8288214459ead7e87d26e5822f62c14a4f2ed6b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: bounds-check buffer log item's dirty bitmap\n\nxlog_recover_do_reg_buffer() replays each dirty region described by a\nbuffer log item's bitmap into the buffer read for that item:\n\n\tmemcpy(xfs_buf_offset(bp, (uint)bit << XFS_BLF_SHIFT),\n\t\titem->ri_buf[i].iov_base,\n\t\tnbits << XFS_BLF_SHIFT);\n\nThe destination offset (bit/nbits, from the logged dirty bitmap) and the\nbuffer size (from the logged blf_len) are both attacker-controlled and\notherwise unrelated, yet the only thing bounding the copy is an ASSERT(),\nwhich compiles away on production kernels. A crafted image logging a\nsmall blf_len together with a bitmap bit past the end of that buffer\ndrives the memcpy() past the buffer's allocation, corrupting adjacent\nkernel heap during mount-time log recovery. This is reachable by anyone\nwho can get a crafted image mounted -- the malicious-filesystem threat\nmodel XFS already guards against elsewhere.\n\nTurn the ASSERT() into a real XFS_IS_CORRUPT() check that aborts recovery\nof the buffer with -EFSCORRUPTED, consistent with the validate-and-fail\nidiom already used in xlog_recover_do_inode_buffer() and\nxfs_dquot_item_recover.c. xlog_recover_do_reg_buffer() therefore becomes\nSTATIC int and its three callers propagate the error.\n\nFound and confirmed with KASAN on a CONFIG_XFS_DEBUG=n build: the crafted\nimage trips a slab-out-of-bounds write before this change and fails\nrecovery cleanly with -EFSCORRUPTED after it.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80536","epss":0.00144,"percentile":0.03978,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80536","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80539","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80539","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: disallow multiple FENCE chunks in one submit  amdgpu_cs_pass1() dispatches on chunk_id once per chunk without rejecting repeated ids. p->uf_bo is a single-slot field, so a submission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs amdgpu_cs_p1_user_fence() twice, and the second run overwrites p->uf_bo with a freshly referenced BO without dropping the reference taken by the first.  amdgpu_cs_parser_fini() only unrefs the final p->uf_bo, so every FENCE chunk but the last leaks a BO reference. The leaked BO outlives handle close and process exit.  Reject duplicate FENCE chunks the same way commit fec5f8e8c6bc (\"drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit\") did for p->bo_list.  (cherry picked from commit 665b1fc2a1845206408f9a2c6da67101789edb82)","cvss":[],"epss":[{"cve":"CVE-2026-80539","epss":0.00172,"percentile":0.06811,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-80539","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80539","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/070229262ede37d17c4ea596650deb6e5eb5d106","https://git.kernel.org/stable/c/5f46322e0b84af29e10eb951ff45bd6ea40640de","https://git.kernel.org/stable/c/71aa45f7bfe46fbc6f51e7832573ff49b6005fea","https://git.kernel.org/stable/c/7e9954e7212042ec808b06181b365b14f00c6f0a","https://git.kernel.org/stable/c/931cd1d1baeae68e8eb2c23bc1f3d8934dca6241","https://git.kernel.org/stable/c/e3ee74d6dbbe409eb99546a7b0a02b2782f9021d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: disallow multiple FENCE chunks in one submit\n\namdgpu_cs_pass1() dispatches on chunk_id once per chunk without\nrejecting repeated ids. p->uf_bo is a single-slot field, so a\nsubmission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs\namdgpu_cs_p1_user_fence() twice, and the second run overwrites\np->uf_bo with a freshly referenced BO without dropping the reference\ntaken by the first.\n\namdgpu_cs_parser_fini() only unrefs the final p->uf_bo, so every FENCE\nchunk but the last leaks a BO reference. The leaked BO outlives handle\nclose and process exit.\n\nReject duplicate FENCE chunks the same way commit fec5f8e8c6bc\n(\"drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit\") did\nfor p->bo_list.\n\n(cherry picked from commit 665b1fc2a1845206408f9a2c6da67101789edb82)","cvss":[],"epss":[{"cve":"CVE-2026-80539","epss":0.00172,"percentile":0.06811,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80539","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80540","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80540","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Fix UVD decode image min size calculation  This needs to use pitch instead of width. Also reject pitch over 4096 to avoid overflow.  (cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80540","epss":0.00129,"percentile":0.0287,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80540","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80540","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/25ee120f3803ad9e416ef9f76f4c3234cc4d645b","https://git.kernel.org/stable/c/271a7da84a6262a09de549912dcf6a749d169cb6","https://git.kernel.org/stable/c/5cbd8af02b0b9c8723fa30edcf6fccab5170af8d","https://git.kernel.org/stable/c/60539d517e8439621532d8c01091ac049c596b4b","https://git.kernel.org/stable/c/b7549e3f96c78921751c4b3e69af729662130d83","https://git.kernel.org/stable/c/b8bb9ba3f101a1b0011f785a577a4a0a38371174","https://git.kernel.org/stable/c/bc7397a033ac52f6d8c9bb6510d61694b2a3fce7","https://git.kernel.org/stable/c/d058f7a6709441afe1784eecd8c0643dd84750bc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix UVD decode image min size calculation\n\nThis needs to use pitch instead of width. Also reject pitch\nover 4096 to avoid overflow.\n\n(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80540","epss":0.00129,"percentile":0.0287,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80540","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80541","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80541","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: validate GEM_CREATE domain combinations  AMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK, but did not validate domain combinations. Userspace could combine CPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making amdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and hit BUG_ON().  Allow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/ VRAM domains to be specified one at a time. Return -EINVAL for invalid combinations in amdgpu_gem_create_ioctl().  v2: Rename helper from amdgpu_gem_domain_valid() to     amdgpu_gem_are_domains_valid() (Christian)  (cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80541","epss":0.00129,"percentile":0.0287,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80541","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80541","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/220aa2589d7321fb68d2e8597862711b5f22ae0b","https://git.kernel.org/stable/c/493355096e397f9217b41c8574ed2784c7351443","https://git.kernel.org/stable/c/584e3d47736fe2e7184ef3fc16b00b41485f96c6","https://git.kernel.org/stable/c/5c73485af7ad9c3ae592db3481f370bc07705391","https://git.kernel.org/stable/c/5e9d136ad74df4edec67e502ce267597064d8f86","https://git.kernel.org/stable/c/66133fc05c3af002f45de8a71b833c026ccbfba6","https://git.kernel.org/stable/c/80f0b53860d02577709d69a312a29ca674b9297c","https://git.kernel.org/stable/c/ce5da474c3ddf7cccec5dce6aa4296297dd7caff"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: validate GEM_CREATE domain combinations\n\nAMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK,\nbut did not validate domain combinations. Userspace could combine\nCPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making\namdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and\nhit BUG_ON().\n\nAllow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/\nVRAM domains to be specified one at a time. Return -EINVAL for invalid\ncombinations in amdgpu_gem_create_ioctl().\n\nv2: Rename helper from amdgpu_gem_domain_valid() to\n    amdgpu_gem_are_domains_valid() (Christian)\n\n(cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80541","epss":0.00129,"percentile":0.0287,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80541","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80547","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80547","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Implement a crw lock  Unlike the channel_program struct, which covers synchronous I/O submissions and asynchronous interrupts, the CRW region relies exclusively on asynchronous events coming from hardware.  Implement a lock to manage the list of those payloads, to ensure they are read cohesively.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80547","epss":0.00129,"percentile":0.02871,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80547","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80547","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0edd222730a9d7ec98368aaf1d40ee2d8d862e61","https://git.kernel.org/stable/c/16b0798024c0e9117e395829ddbbe70981c79d9c","https://git.kernel.org/stable/c/3c94d4179bcc19e01b28db634c07a58b28116209","https://git.kernel.org/stable/c/49fa26b0df009dc1f420980bd71780e70615b83b","https://git.kernel.org/stable/c/7902be374cbfc11c3435e1e87bf22195bf06a558","https://git.kernel.org/stable/c/a3d60ae24183eee352c8e87a0ff94c97cd87f156","https://git.kernel.org/stable/c/c76c4ee72bfc3824f4f491f18ed0323bf2e2daf9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Implement a crw lock\n\nUnlike the channel_program struct, which covers synchronous I/O\nsubmissions and asynchronous interrupts, the CRW region relies\nexclusively on asynchronous events coming from hardware.\n\nImplement a lock to manage the list of those payloads, to ensure\nthey are read cohesively.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80547","epss":0.00129,"percentile":0.02871,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80547","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80548","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80548","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Selectively expand io_mutex  The io_mutex was defined to serialize the io_regions, but then has also sort of been associated with the I/O themselves because of the close relationship they share.  With the handful of races that are possible, the choices are either to:  A) expand the scope of io_mutex to close these remaining windows, or  B) reduce the scope of io_mutex to just io_region, and introduce a new     lock mechanism for the remaining I/O resources  This patch implements A, since B brings with it a lot more interactions that would need to be tracked and kept in a correct hierarchy. It also takes advantage of the workqueue element for cp_free() that now gets called out of fsm_notoper(), which could be invoked out of an interrupt context and thus cannot acquire a mutex itself.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80548","epss":0.00129,"percentile":0.02874,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80548","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80548","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2a5ac0c0f1f7da33929211a2e41911bf72ee35d8","https://git.kernel.org/stable/c/2ba9efdf9ebedc4e54df4b56aa3b43a65f7967cd","https://git.kernel.org/stable/c/34f4feff3e90bd09308fad0974e97113b23b812a","https://git.kernel.org/stable/c/56d7488533ceac4e986e96e15c9e487a2245bc01","https://git.kernel.org/stable/c/b6aecea4b2b246f9fbd98a5712daa1193a60818e","https://git.kernel.org/stable/c/dab6a6627b0b0cce23653e99c7b0bf8c6cfd82e0","https://git.kernel.org/stable/c/f72a51810d49411bd8cad0c2df8592320a2fe5cc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Selectively expand io_mutex\n\nThe io_mutex was defined to serialize the io_regions, but then has\nalso sort of been associated with the I/O themselves because of\nthe close relationship they share.\n\nWith the handful of races that are possible, the choices are either to:\n A) expand the scope of io_mutex to close these remaining windows, or\n B) reduce the scope of io_mutex to just io_region, and introduce a new\n    lock mechanism for the remaining I/O resources\n\nThis patch implements A, since B brings with it a lot more interactions\nthat would need to be tracked and kept in a correct hierarchy. It also\ntakes advantage of the workqueue element for cp_free() that now gets\ncalled out of fsm_notoper(), which could be invoked out of an interrupt\ncontext and thus cannot acquire a mutex itself.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80548","epss":0.00129,"percentile":0.02874,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80548","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80549","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80549","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Move cp cleanup out of not operational  The fsm_notoper() routine is called when the device has been lost, and is (by definition) no longer operational. Since this can happen asynchronously from the normal behavior of the driver, the cleanup may happen when holding other locks in the calling sequence (notably, the cio subchannel lock).  Push the cleanup of the private->cp resources to a workqueue, where it can be done out from under that lock sequence and a future patch can safely manage the locking requirements.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80549","epss":0.00134,"percentile":0.0327,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10518999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80549","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80549","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0c11f61a876ed6fcca53d442ed3f33ea8362a0f9","https://git.kernel.org/stable/c/4e3301e2a651d742c05914f6074a25b8e41bce19","https://git.kernel.org/stable/c/56100baa0eb7055b1026dfa73e696e8066ff71fd","https://git.kernel.org/stable/c/af1759d8e6e6da9ba94f30a2f92546f406899aa7","https://git.kernel.org/stable/c/c9b85aa2cf73ea645e55e2c2670e0ddebfe1589b","https://git.kernel.org/stable/c/f98a9890ca42f4223d2d4c50e0660af3e012fcb4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Move cp cleanup out of not operational\n\nThe fsm_notoper() routine is called when the device has been\nlost, and is (by definition) no longer operational. Since this\ncan happen asynchronously from the normal behavior of the\ndriver, the cleanup may happen when holding other locks\nin the calling sequence (notably, the cio subchannel lock).\n\nPush the cleanup of the private->cp resources to a workqueue,\nwhere it can be done out from under that lock sequence and\na future patch can safely manage the locking requirements.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"exploitabilityScore":1.5,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80549","epss":0.00134,"percentile":0.0327,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80549","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80550","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80550","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Fix out of bounds check on CCW array  The routine ccwchain_calc_length() counts the number of channel command words (CCWs) that are chained together in a single channel program, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs.  The loop itself is \"do..while (count < 257)\", and while the logic in is_cpa_within_range() correctly adjusts between the 0-index array of CCWs and the count of CCWs starting at 1, this means it would look at a possible 257th CCW before ending the loop and (correctly) returning an error.  Fix this by restructuring the loop to break as soon as 256 CCWs (thus indexes 0-255) are examined, without looking at memory outside the range.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L","metrics":{"baseScore":7.9,"exploitabilityScore":2.6,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80550","epss":0.00137,"percentile":0.03422,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10548999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80550","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80550","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0282fb1c4b638eecfe2cc558092c460911d8f7e2","https://git.kernel.org/stable/c/499a8a66b1598bfab97182aed15e0f1646074a3d","https://git.kernel.org/stable/c/4c2e1d359d7a2b82cdf3254e4e480af9417f99fb","https://git.kernel.org/stable/c/907adc667d902fafbdb2d740d57b55bd025dc4cd","https://git.kernel.org/stable/c/a005b7f1a491ffda61bff0fd0f6548f8986fb977","https://git.kernel.org/stable/c/af3f80ca4c8b17f20f9e588def076288fdb49e65","https://git.kernel.org/stable/c/d5d096cd9369e986d4e5153baa86b8b35c283e09","https://git.kernel.org/stable/c/f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Fix out of bounds check on CCW array\n\nThe routine ccwchain_calc_length() counts the number of channel\ncommand words (CCWs) that are chained together in a single channel\nprogram, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs.\n\nThe loop itself is \"do..while (count < 257)\", and while the logic in\nis_cpa_within_range() correctly adjusts between the 0-index array of\nCCWs and the count of CCWs starting at 1, this means it would look\nat a possible 257th CCW before ending the loop and (correctly)\nreturning an error.\n\nFix this by restructuring the loop to break as soon as 256 CCWs\n(thus indexes 0-255) are examined, without looking at memory\noutside the range.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L","metrics":{"baseScore":7.9,"exploitabilityScore":2.6,"impactScore":4.8},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80550","epss":0.00137,"percentile":0.03422,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80550","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80551","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80551","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Ensure first IDAW remains constant  The first IDAW in a list does not need to be on a 2K/4K boundary like all others, and so is read separately to accurately calculate the size of the buffer needed to read the full IDAL.  Verify that the address found in the first IDAW is unchanged between reads, to ensure a consistent set of IDAWs being worked with.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80551","epss":0.00144,"percentile":0.03977,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13176000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80551","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80551","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/08ef2a82115690d6e229615872ac1731af732497","https://git.kernel.org/stable/c/0d46c2565f173bcddcdcaf44a4f69789a20535e2","https://git.kernel.org/stable/c/460b977a4e71cc319fdadf91c193ec3beaa57263","https://git.kernel.org/stable/c/565bef268d75bf7df665bce6923a88cd0eb74592","https://git.kernel.org/stable/c/fc59e9482117ebdccd6dc7fa8082f8b980fd021e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Ensure first IDAW remains constant\n\nThe first IDAW in a list does not need to be on a 2K/4K boundary\nlike all others, and so is read separately to accurately calculate\nthe size of the buffer needed to read the full IDAL.\n\nVerify that the address found in the first IDAW is unchanged between\nreads, to ensure a consistent set of IDAWs being worked with.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80551","epss":0.00144,"percentile":0.03977,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80551","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80552","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80552","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Ensure index for read/write regions are within range  The introduction of the capability chain rightly clamped the region indexes to the range of the capabilities itself, but neglected to do so for the existing read/write regions which should also be enforced.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80552","epss":0.00129,"percentile":0.02873,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80552","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80552","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3acbedf5c0b8e0971f0de423c05cc02bbf6ddb99","https://git.kernel.org/stable/c/649badf3a2fd8929e40198603a2cb21b74c21700","https://git.kernel.org/stable/c/79ea5e0c4c8a9842ae85f45062d947b3297dfc07","https://git.kernel.org/stable/c/988d9b5be3c2c4baf9457ce8e11b477e13eb9fcf","https://git.kernel.org/stable/c/9f5f9a78fedc45bc29d6a0a64e3a3472361afae5","https://git.kernel.org/stable/c/d3b1e38404b22df5a1f93019f2bb656feaad5ae3","https://git.kernel.org/stable/c/d597fa1273802941c7801202135976fecc29672b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Ensure index for read/write regions are within range\n\nThe introduction of the capability chain rightly clamped the\nregion indexes to the range of the capabilities itself, but\nneglected to do so for the existing read/write regions which\nshould also be enforced.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80552","epss":0.00129,"percentile":0.02873,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80552","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80553","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80553","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Cancel existing workqueues  The initialization of the io_work and crw_work workqueues begs the question of whether they should be un-initialized. Add the corresponding cleanup tags in _release_dev to ensure work isn't dispatched after the private struct is free'd.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80553","epss":0.00129,"percentile":0.02873,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10513499999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80553","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80553","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7492ca2d0c5d59add01e267be9f5a6eeb8076fd7","https://git.kernel.org/stable/c/77f5e888d2e607a0b3141fb95091ad6ef1cca9a2","https://git.kernel.org/stable/c/79c60b2c61105368dcc8444eb45847e21734f7c4","https://git.kernel.org/stable/c/87d569cb35a541b31a184faf982540694d4c9a89","https://git.kernel.org/stable/c/b7ae0f7993867d009a4b554fc1d6d451c10580a0","https://git.kernel.org/stable/c/b94b28c1f0fae53b2f2d6180ae6442c9a1558f67","https://git.kernel.org/stable/c/dc47a98abe6714577a25224534dbd356051097a3","https://git.kernel.org/stable/c/e868ea8be0bc88c6982f48ecf3259d98afd884ae"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Cancel existing workqueues\n\nThe initialization of the io_work and crw_work workqueues begs the\nquestion of whether they should be un-initialized. Add the corresponding\ncleanup tags in _release_dev to ensure work isn't dispatched after\nthe private struct is free'd.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80553","epss":0.00129,"percentile":0.02873,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80553","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80554","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80554","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Limit the number of channel program segments  The processing of channel programs, and the CCWs within them, is done recursively. As such, there is an arbitrary (but not architectural) limit to the number of CCWs that can exist in a single channel program.  The vfio-ccw logic breaks these channel programs into segments whenever it encounters a Transfer-In-Channel (TIC) CCW, and the combined number of segments count towards the global limit. Impose an equivalent limit to the number of segments until such logic can be made non-recursive.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80554","epss":0.00144,"percentile":0.03977,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.13176000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80554","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80554","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/06f4d6e5a8af6c2072e8cd39dbc512c683ca7fb2","https://git.kernel.org/stable/c/15fb4559a7fdf0b8725e433a71cfd03a1313a48b","https://git.kernel.org/stable/c/4ee94790490ae8dcc97df8597f07836c8a81bbcf","https://git.kernel.org/stable/c/5405c90d6a47b3014e74ee0618a162449abbbc93","https://git.kernel.org/stable/c/a1625f66eaa1200068a0e2c05bc90e65182fc4e3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Limit the number of channel program segments\n\nThe processing of channel programs, and the CCWs within them, is done\nrecursively. As such, there is an arbitrary (but not architectural)\nlimit to the number of CCWs that can exist in a single channel program.\n\nThe vfio-ccw logic breaks these channel programs into segments whenever\nit encounters a Transfer-In-Channel (TIC) CCW, and the combined number\nof segments count towards the global limit. Impose an equivalent limit\nto the number of segments until such logic can be made non-recursive.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80554","epss":0.00144,"percentile":0.03977,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80554","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80555","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80555","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/vfio_ccw: Free all memory if cp_init() fails  The routine cp_free() is called to unpin/free any memory once an I/O is completed successfully, or if cp_prefetch() fails. But if cp_init() fails, and cp->initialized is not enabled, the same routine cannot be used to free all the memory.  An attempt to address this exists in ccwchain_handle_ccw(), where a single call to ccwchain_free() is made for the currently-processed CCW segment. But this will leak other segments (created as a result of a Transfer in Channel) that had been allocated as part of the same channel program.  Address this by performing the cleanup outside of the recursive ccwchain_handle_ccw()/ccwchain_loop_tic() logic.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.6,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80555","epss":0.0014,"percentile":0.03683,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10219999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80555","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80555","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/152fcb74a26804b70909381c6acc90595a0ae1c1","https://git.kernel.org/stable/c/17e01e342af74de12899c206dcc9ec90684703aa","https://git.kernel.org/stable/c/276bd7ed34d56c48c65c43c0b08f2ee77029b2fa","https://git.kernel.org/stable/c/32e3d364a7b8295120d37e6a6bd433d2de26f748","https://git.kernel.org/stable/c/4699b54fada156534cbb39834d47fc9374d7a1f5","https://git.kernel.org/stable/c/6a917199aaf97904f5619afe3dfdacb155b03e8c","https://git.kernel.org/stable/c/74186c2968f8f756ac3226b545b598457c910c75","https://git.kernel.org/stable/c/f9bcff265556796834122f95de16d52a8375206c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Free all memory if cp_init() fails\n\nThe routine cp_free() is called to unpin/free any memory once an I/O\nis completed successfully, or if cp_prefetch() fails. But if cp_init()\nfails, and cp->initialized is not enabled, the same routine cannot be\nused to free all the memory.\n\nAn attempt to address this exists in ccwchain_handle_ccw(), where a\nsingle call to ccwchain_free() is made for the currently-processed\nCCW segment. But this will leak other segments (created as a result\nof a Transfer in Channel) that had been allocated as part of the same\nchannel program.\n\nAddress this by performing the cleanup outside of the recursive\nccwchain_handle_ccw()/ccwchain_loop_tic() logic.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"exploitabilityScore":2.6,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80555","epss":0.0014,"percentile":0.03683,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80555","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80556","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80556","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition  In atmci_probe, &host->bh_work is bound with atmci_work_func, and atmci_interrupt, atmci_timeout_timer and atmci_dma_complete can all queue this work on system_bh_wq.  If we remove the module, atmci_remove makes cleanup and the memory allocated for host with devm_kzalloc() is released after the remove callback returns, while the work mentioned above may still be pending or running. The sequence of operations that may lead to a UAF bug is as follows:  CPU0                                      CPU1                                            | atmci_interrupt                                           | queue_work(system_bh_wq,                                           |            &host->bh_work) atmci_remove                              | atmci_cleanup_slot(...)                   | atmci_writel(host, ATMCI_IDR, ~0UL)       | timer_delete_sync(&host->timer)           | dma_release_channel(host->dma.chan)       | free_irq(platform_get_irq(pdev, 0), host) |                                           | atmci_work_func                                           | // use host // devm resources released after          | // remove returns, host is freed          |                                           | // use host (use-after-free)  Fix it by canceling the work after all the sources that can schedule it (IRQ handler, timeout timer and DMA completion callback) have been stopped, and before proceeding with the remaining cleanup in atmci_remove.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80556","epss":0.00125,"percentile":0.02507,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.095625},"relatedVulnerabilities":[{"id":"CVE-2026-80556","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80556","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/22aecf6c4721727a2f724ca0438bc7d4b609bf3f","https://git.kernel.org/stable/c/7599a73ff66d195a908f5d88b427933a9fb1c02a","https://git.kernel.org/stable/c/b5060ff2f5460795a3e9f7cdf5052aa42f96ff81","https://git.kernel.org/stable/c/c125ee35a49a0518521b52b27631eef061b8719a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition\n\nIn atmci_probe, &host->bh_work is bound with atmci_work_func, and\natmci_interrupt, atmci_timeout_timer and atmci_dma_complete can all\nqueue this work on system_bh_wq.\n\nIf we remove the module, atmci_remove makes cleanup and the memory\nallocated for host with devm_kzalloc() is released after the remove\ncallback returns, while the work mentioned above may still be pending\nor running. The sequence of operations that may lead to a UAF bug is\nas follows:\n\nCPU0                                      CPU1\n\n                                          | atmci_interrupt\n                                          | queue_work(system_bh_wq,\n                                          |            &host->bh_work)\natmci_remove                              |\natmci_cleanup_slot(...)                   |\natmci_writel(host, ATMCI_IDR, ~0UL)       |\ntimer_delete_sync(&host->timer)           |\ndma_release_channel(host->dma.chan)       |\nfree_irq(platform_get_irq(pdev, 0), host) |\n                                          | atmci_work_func\n                                          | // use host\n// devm resources released after          |\n// remove returns, host is freed          |\n                                          | // use host (use-after-free)\n\nFix it by canceling the work after all the sources that can schedule\nit (IRQ handler, timeout timer and DMA completion callback) have been\nstopped, and before proceeding with the remaining cleanup in\natmci_remove.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80556","epss":0.00125,"percentile":0.02507,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80556","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80557","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80557","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: fix OOB read in decode_watchers() via missing bounds check  ceph_start_decoding() validates that struct_len bytes remain in the buffer after the encoding header, but accepts struct_len=0 as valid: ceph_decode_need(p, end, 0, bad) always passes. When a malicious or compromised OSD sends an obj_list_watch_response_t reply with struct_len=0, ceph_start_decoding() returns success with p == end, leaving zero bytes guaranteed for subsequent reads.  The immediately following ceph_decode_32(p) in decode_watchers() has no preceding bounds check. With p == end this is a 4-byte read past the validated buffer boundary. The garbage value is then passed directly to kzalloc_objs() as the watcher count.  The sibling function decode_watcher() already uses the safe variants (ceph_decode_copy_safe, ceph_decode_64_safe, ceph_decode_skip_32) after its own ceph_start_decoding() call. decode_watchers() is the only site that uses the bare variant, confirming an oversight.  Fix by replacing ceph_decode_32(p) with ceph_decode_32_safe(p, end, *num_watchers, bad), consistent with the established pattern.  Attacker model: a malicious or compromised OSD in a multi-tenant Ceph deployment (e.g. cloud) can trigger this against any kernel client that calls CEPH_OSD_OP_LIST_WATCHERS, without any further privileges beyond OSD session establishment.  [ idryomov: trim changelog ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80557","epss":0.00521,"percentile":0.4254,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48974000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-80557","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80557","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/00ead17c7de137a692edee59f2772e6af687e8eb","https://git.kernel.org/stable/c/1c824e7c75bb4adf19553dd4ea944a5d83096be8","https://git.kernel.org/stable/c/7130d94846dadbb97b6b7f4d78a3a7bba6e3daa1","https://git.kernel.org/stable/c/85479b7d65b4ebcb07fbbe57230976793974ab4a","https://git.kernel.org/stable/c/c59219a6b62d74936963983e5815524c3de8dd79","https://git.kernel.org/stable/c/cb8246e5846dbbe34930903a90c7a90dd8e5910b","https://git.kernel.org/stable/c/eab3eeb68bfc639d74f27256f05546af5c4f787d","https://git.kernel.org/stable/c/f161be39201eb5f9b1f58fb8f90b8a9cd3931eb6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix OOB read in decode_watchers() via missing bounds check\n\nceph_start_decoding() validates that struct_len bytes remain in the\nbuffer after the encoding header, but accepts struct_len=0 as valid:\nceph_decode_need(p, end, 0, bad) always passes. When a malicious or\ncompromised OSD sends an obj_list_watch_response_t reply with\nstruct_len=0, ceph_start_decoding() returns success with p == end,\nleaving zero bytes guaranteed for subsequent reads.\n\nThe immediately following ceph_decode_32(p) in decode_watchers() has\nno preceding bounds check. With p == end this is a 4-byte read past\nthe validated buffer boundary. The garbage value is then passed\ndirectly to kzalloc_objs() as the watcher count.\n\nThe sibling function decode_watcher() already uses the safe variants\n(ceph_decode_copy_safe, ceph_decode_64_safe, ceph_decode_skip_32)\nafter its own ceph_start_decoding() call. decode_watchers() is the\nonly site that uses the bare variant, confirming an oversight.\n\nFix by replacing ceph_decode_32(p) with ceph_decode_32_safe(p, end,\n*num_watchers, bad), consistent with the established pattern.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment (e.g. cloud) can trigger this against any kernel client\nthat calls CEPH_OSD_OP_LIST_WATCHERS, without any further privileges\nbeyond OSD session establishment.\n\n[ idryomov: trim changelog ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80557","epss":0.00521,"percentile":0.4254,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80557","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80558","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80558","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: Avoid using invalid osd indices from primary_temp  A corrupted osdmap received from a Ceph monitor or OSD may contain osd indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts that don't exist, i.e., that are greater than max_osd or smaller than CEPH_HOMELESS_OSD (-1). These indices are used to create the up and acting set in ceph_pg_to_up_acting_osds(), called from calc_target(). While most of these osd indices are checked, the one from primary_temp is not. Subsequently, this may lead to calc_target() returning this (potentially invalid) index as target osd for a (linger) request. Because the osd_state, osd_weight, and osd_addr arrays only contain max_osd entries (with indices 0 to max_osd -1), this leads to out-of-bounds accesses when trying to read values from these arrays.  This patch fixes the issue by adding a check to get_temp_osds(), so that only valid osd indices from primary_temp are used, and it falls back to using the primary from pg_temp or the up set if it is invalid.  [ idryomov: changelog ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80558","epss":0.00521,"percentile":0.4254,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48974000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-80558","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80558","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1c705fe8e59c6b16f48964973fb23c8ec4735b73","https://git.kernel.org/stable/c/3660b98d1204b419f6a77e9a295f148dcf38d042","https://git.kernel.org/stable/c/4f392fec075562dc93bb0c69f37423ca2af9b48f","https://git.kernel.org/stable/c/505fc50b8ff8e687b7e3ef6866269dea27366224","https://git.kernel.org/stable/c/6799d4a916ffcb3d450d8440f9fe0f0862f768d6","https://git.kernel.org/stable/c/dfe1877d351b99eb1b1a62a3fc2d174220e88e20","https://git.kernel.org/stable/c/e009c5f0ad634c62f5c48a41f1f3c019ecf52555","https://git.kernel.org/stable/c/e2ffeec85201b2bb748e99e12539ee1b92f62796"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Avoid using invalid osd indices from primary_temp\n\nA corrupted osdmap received from a Ceph monitor or OSD may contain osd\nindices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts\nthat don't exist, i.e., that are greater than max_osd or smaller than\nCEPH_HOMELESS_OSD (-1). These indices are used to create the up and\nacting set in ceph_pg_to_up_acting_osds(), called from calc_target().\nWhile most of these osd indices are checked, the one from primary_temp\nis not. Subsequently, this may lead to calc_target() returning this\n(potentially invalid) index as target osd for a (linger) request.\nBecause the osd_state, osd_weight, and osd_addr arrays only contain\nmax_osd entries (with indices 0 to max_osd -1), this leads to\nout-of-bounds accesses when trying to read values from these arrays.\n\nThis patch fixes the issue by adding a check to get_temp_osds(), so that\nonly valid osd indices from primary_temp are used, and it falls back to\nusing the primary from pg_temp or the up set if it is invalid.\n\n[ idryomov: changelog ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80558","epss":0.00521,"percentile":0.4254,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80558","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80559","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80559","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: sur40 - fix input device registration ordering  In sur40_probe(), input_register_device() was previously called early before the V4L2 video device and vb2_queue components were fully initialized. If userspace opened the input device immediately upon registration, sur40_open() would trigger and start the sur40_poll() worker thread. This worker thread invokes sur40_process_video() and accesses the uninitialized vb2_queue structure, leading to a data race and potential system crash.  Furthermore, if V4L2 or video registration failed after input_register_device() succeeded, the error path fell through to calling input_free_device() on a successfully registered device instead of input_unregister_device(), corrupting input core state.  Move input_register_device() to the very end of sur40_probe(). This ensures the V4L2 and video queue structures are fully initialized before polling can start, and naturally resolves the error path bug since input_free_device() is now only called when input registration has not yet occurred.  To maintain strict LIFO (Last-In, First-Out) teardown ordering, also move input_unregister_device() to the very beginning of sur40_disconnect(). This guarantees that the input polling worker thread is stopped before V4L2 video components or control handlers are unregistered.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80559","epss":0.00129,"percentile":0.02871,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80559","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80559","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3e8ed76a4f3572e637653f0654cccdf617903231","https://git.kernel.org/stable/c/5c1c5227c93f18cd329dd754b4df5e0e2daece1e","https://git.kernel.org/stable/c/764b507be7b51787e1f577ca3bf0bab7efe81ff8","https://git.kernel.org/stable/c/83aa12f9f2468a4fbef027c09224dc1011850fb0","https://git.kernel.org/stable/c/9da976eb649c9e2f588a4499410e4d8af687925f","https://git.kernel.org/stable/c/beb9b0bd6e6e23f5e9e42b7ef890a50f57f1f3aa","https://git.kernel.org/stable/c/cd4ecce2fd87760c0ad9a9d28c9fc62ea1dbfd3d","https://git.kernel.org/stable/c/dab741c9da72102a37cc1020a929051b7c45f9fb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: sur40 - fix input device registration ordering\n\nIn sur40_probe(), input_register_device() was previously called early before\nthe V4L2 video device and vb2_queue components were fully initialized. If\nuserspace opened the input device immediately upon registration, sur40_open()\nwould trigger and start the sur40_poll() worker thread. This worker thread\ninvokes sur40_process_video() and accesses the uninitialized vb2_queue\nstructure, leading to a data race and potential system crash.\n\nFurthermore, if V4L2 or video registration failed after input_register_device()\nsucceeded, the error path fell through to calling input_free_device() on a\nsuccessfully registered device instead of input_unregister_device(), corrupting\ninput core state.\n\nMove input_register_device() to the very end of sur40_probe(). This ensures\nthe V4L2 and video queue structures are fully initialized before polling can\nstart, and naturally resolves the error path bug since input_free_device()\nis now only called when input registration has not yet occurred.\n\nTo maintain strict LIFO (Last-In, First-Out) teardown ordering, also move\ninput_unregister_device() to the very beginning of sur40_disconnect(). This\nguarantees that the input polling worker thread is stopped before V4L2\nvideo components or control handlers are unregistered.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80559","epss":0.00129,"percentile":0.02871,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80559","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80560","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80560","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  openrisc: signal: do not restore privileged SR bits on sigreturn  restore_sigcontext() copies the whole supervision register (SR) from the signal frame and only clears SPR_SR_SM before the value is reloaded into the hardware SR (through ESR and l.rfe) on the return to user space.  All other SR bits are left under user control.  An unprivileged task can thus return from a signal handler through a crafted sigframe that clears SPR_SR_DME.  With the data MMU disabled the CPU performs no translation or protection on data accesses, so the task gains read and write access to arbitrary physical memory, a local privilege escalation.  SPR_SR_IME, SPR_SR_SUMRA, SPR_SR_LEE, SPR_SR_EPH and the cache-enable bits are exposed the same way.  The ptrace GPR regset already refuses any change to SR for exactly this reason.  Restore only the arithmetic flag bits (F, CY, OV) from the signal frame and take every privileged control bit from the SR the kernel saved on signal entry.  Verified with qemu-system-or1k -M or1k-sim: before this change an unprivileged PoC clears SPR_SR_DME in rt_sigreturn and writes a marker to physical address 0x03000000 (beyond the kernel's mem=32M); afterwards the same PoC receives SIGSEGV and physical memory is unchanged.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80560","epss":0.00129,"percentile":0.0287,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80560","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80560","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/212fc482ddd7f9ccdd74a05eab1cac849350dcd6","https://git.kernel.org/stable/c/32ef1b30ad736519f7a207bcc2986f3d4129d972","https://git.kernel.org/stable/c/89a91b30685c0493b0fa2b47d0ab41061a63069d","https://git.kernel.org/stable/c/a88d688be8d7f03cbf927f2ab454ea9fa58d2979","https://git.kernel.org/stable/c/b4d73c3848bae9084fa8b9b2aa76d99a7d8eb17d","https://git.kernel.org/stable/c/bc2e24ba6e167ccf374a197457aa5640a802f429","https://git.kernel.org/stable/c/cd8b43a71755c516f5c1f265a103438ae9ab15be","https://git.kernel.org/stable/c/cf1b5514ddf9df098ce7e3741fc9679fd85a4ec6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nopenrisc: signal: do not restore privileged SR bits on sigreturn\n\nrestore_sigcontext() copies the whole supervision register (SR) from the\nsignal frame and only clears SPR_SR_SM before the value is reloaded into\nthe hardware SR (through ESR and l.rfe) on the return to user space.  All\nother SR bits are left under user control.\n\nAn unprivileged task can thus return from a signal handler through a\ncrafted sigframe that clears SPR_SR_DME.  With the data MMU disabled the\nCPU performs no translation or protection on data accesses, so the task\ngains read and write access to arbitrary physical memory, a local\nprivilege escalation.  SPR_SR_IME, SPR_SR_SUMRA, SPR_SR_LEE, SPR_SR_EPH\nand the cache-enable bits are exposed the same way.  The ptrace GPR regset\nalready refuses any change to SR for exactly this reason.\n\nRestore only the arithmetic flag bits (F, CY, OV) from the signal frame\nand take every privileged control bit from the SR the kernel saved on\nsignal entry.\n\nVerified with qemu-system-or1k -M or1k-sim: before this change an\nunprivileged PoC clears SPR_SR_DME in rt_sigreturn and writes a marker to\nphysical address 0x03000000 (beyond the kernel's mem=32M); afterwards the\nsame PoC receives SIGSEGV and physical memory is unchanged.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80560","epss":0.00129,"percentile":0.0287,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80560","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80561","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80561","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  libceph: fix multiple unsafe decodes in decode_locker()  decode_locker() in cls_lock_client.c contains three unsafe decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads:  1. ceph_decode_copy() at the locker_id_t name field has no preceding    bounds check. With p == end after ceph_start_decoding() accepts    struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past    the validated buffer boundary.  2. *p += sizeof(struct ceph_timespec) after the locker_info_t header    is an unchecked pointer advance. A malicious OSD can position p    past end, causing all subsequent _safe checks to pass against a    bogus boundary.  3. len = ceph_decode_32(p) has no preceding bounds check, and the    immediately following *p += len is uncapped. A malicious OSD can    send len=0xffffffff, advancing p gigabytes past end and escaping    the decode window entirely.  Fix all three by replacing bare operations with their safe variants:   ceph_decode_copy   -> ceph_decode_copy_safe   *p += sizeof(...)  -> ceph_decode_skip_n   ceph_decode_32(p)  -> ceph_decode_32_safe   *p += len          -> ceph_decode_skip_n  A new label is added to return -EINVAL on any bounds violation. -EINVAL is appropriate here: the data received from the OSD is structurally malformed, which is an invalid argument to the decode contract regardless of whether the caller or the wire is at fault.  Attacker model: a malicious or compromised OSD in a multi-tenant Ceph deployment can trigger this against any kernel client that issues the lock.get_info class method (e.g. during RBD exclusive lock acquisition) without any further privileges beyond OSD session establishment.  [ idryomov: use ceph_decode_skip_string() to skip description, trim   changelog ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80561","epss":0.00521,"percentile":0.42541,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.48974000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-80561","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80561","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1ed45c8d96498725eb54f740172f9068d8673906","https://git.kernel.org/stable/c/3c3716dc06a34e4ca7f743f5fcfa07fbc5a11070","https://git.kernel.org/stable/c/437b6551cfcc235eea1d735a874f9d421f555e17","https://git.kernel.org/stable/c/51c8d238fe7236de627ab1a1433694552a904136","https://git.kernel.org/stable/c/6265103e78f0ee7e2518de9cf938b94bee9700a0","https://git.kernel.org/stable/c/d1bba38574d095f191557d397d9633f08cd966b1","https://git.kernel.org/stable/c/dbfd83f722a78446ec18a476ef7a38e52240b50a","https://git.kernel.org/stable/c/fa4aa86fff0c56799c2e3f51a88879053285f4a9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix multiple unsafe decodes in decode_locker()\n\ndecode_locker() in cls_lock_client.c contains three unsafe decode\noperations that allow a malicious or compromised OSD to trigger\nslab-out-of-bounds reads:\n\n1. ceph_decode_copy() at the locker_id_t name field has no preceding\n   bounds check. With p == end after ceph_start_decoding() accepts\n   struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past\n   the validated buffer boundary.\n\n2. *p += sizeof(struct ceph_timespec) after the locker_info_t header\n   is an unchecked pointer advance. A malicious OSD can position p\n   past end, causing all subsequent _safe checks to pass against a\n   bogus boundary.\n\n3. len = ceph_decode_32(p) has no preceding bounds check, and the\n   immediately following *p += len is uncapped. A malicious OSD can\n   send len=0xffffffff, advancing p gigabytes past end and escaping\n   the decode window entirely.\n\nFix all three by replacing bare operations with their safe variants:\n  ceph_decode_copy   -> ceph_decode_copy_safe\n  *p += sizeof(...)  -> ceph_decode_skip_n\n  ceph_decode_32(p)  -> ceph_decode_32_safe\n  *p += len          -> ceph_decode_skip_n\n\nA new label is added to return -EINVAL on any bounds violation.\n-EINVAL is appropriate here: the data received from the OSD\nis structurally malformed, which is an invalid argument to the decode\ncontract regardless of whether the caller or the wire is at fault.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment can trigger this against any kernel client that issues the\nlock.get_info class method (e.g. during RBD exclusive lock acquisition)\nwithout any further privileges beyond OSD session establishment.\n\n[ idryomov: use ceph_decode_skip_string() to skip description, trim\n  changelog ]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80561","epss":0.00521,"percentile":0.42541,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80561","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80562","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80562","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gpio: ml-ioh: use raw_spinlock_t for the register lock  ioh_irq_type() is registered as the irq_chip .irq_set_type callback and takes chip->spinlock with spin_lock_irqsave().  This callback is reached from __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while the caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled. That context is not sleepable, but on PREEMPT_RT a regular spinlock_t is an rtmutex-backed sleeping lock, so acquiring it there is invalid. ioh_irq_enable() and ioh_irq_disable() take the same lock from the .irq_enable/.irq_disable callbacks, which are likewise invoked with desc->lock held.  Convert the register lock to raw_spinlock_t.  The same lock also serializes the GPIO direction/value callbacks and the suspend/resume register save/restore, and those critical sections only perform short sequences of MMIO register accesses (ioread32()/iowrite32()); the .irq_set_type callback additionally emits a dev_warn() on an unsupported type.  None of these are sleepable operations, so keeping this register lock non-sleeping is appropriate for the irqchip callbacks and does not change the GPIO-side locking contract.  This is the same fix as commit a02b8950d619 (\"gpio: pch: use raw_spinlock_t for the register lock\"); this driver shares the same structure as gpio-pch.","cvss":[],"epss":[{"cve":"CVE-2026-80562","epss":0.00176,"percentile":0.07302,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80562","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80562","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0559b86611c35d342dd48542ea26a9e437046bf6","https://git.kernel.org/stable/c/359e6b1168c9a62a7bd214ace476aaa2d57eebe8","https://git.kernel.org/stable/c/431b10133113537660a6090a2856b0d74d1b06de","https://git.kernel.org/stable/c/600411ea1f2443fdf5b1af9b6480f616d7aff9d0","https://git.kernel.org/stable/c/63d2230e5076c12f93d2a1d1bff2fbbf6cf32f3c","https://git.kernel.org/stable/c/84be002b40d30c56a91873b236e2d9001bbee363","https://git.kernel.org/stable/c/b6505a4cea45dd92eb753581b1ad9b524b5fcc34","https://git.kernel.org/stable/c/bc7934d0acd4fc1c7e5b7c68debdb4a991121628"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: ml-ioh: use raw_spinlock_t for the register lock\n\nioh_irq_type() is registered as the irq_chip .irq_set_type callback and\ntakes chip->spinlock with spin_lock_irqsave().  This callback is reached\nfrom __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while\nthe caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled.\nThat context is not sleepable, but on PREEMPT_RT a regular spinlock_t is\nan rtmutex-backed sleeping lock, so acquiring it there is invalid.\nioh_irq_enable() and ioh_irq_disable() take the same lock from the\n.irq_enable/.irq_disable callbacks, which are likewise invoked with\ndesc->lock held.\n\nConvert the register lock to raw_spinlock_t.  The same lock also\nserializes the GPIO direction/value callbacks and the suspend/resume\nregister save/restore, and those critical sections only perform short\nsequences of MMIO register accesses (ioread32()/iowrite32()); the\n.irq_set_type callback additionally emits a dev_warn() on an unsupported\ntype.  None of these are sleepable operations, so keeping this register\nlock non-sleeping is appropriate for the irqchip callbacks and does not\nchange the GPIO-side locking contract.\n\nThis is the same fix as commit a02b8950d619 (\"gpio: pch: use\nraw_spinlock_t for the register lock\"); this driver shares the same\nstructure as gpio-pch.","cvss":[],"epss":[{"cve":"CVE-2026-80562","epss":0.00176,"percentile":0.07302,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80562","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80565","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80565","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: qce - fix error path in devm_qce_register_algs  If ops->register_algs() fails, the error path repeatedly calls the same ops->unregister_algs() from the failed registration. Use the loop index to unregister the previously registered algorithms instead.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80565","epss":0.0012,"percentile":0.02075,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80565","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80565","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1ece8e16c085e8cd60ecbdb641269aaa53d31da4","https://git.kernel.org/stable/c/4e88b4fda48282f3fd504b4d4f5d2d4f996b76ce","https://git.kernel.org/stable/c/9c75402286409f5e1a75e4a445555c84066f89db","https://git.kernel.org/stable/c/a134e4b8102c077286818ee112b9f925db613d4c","https://git.kernel.org/stable/c/c7dc487aade12c692add3221673c9bdf32dc24f5","https://git.kernel.org/stable/c/dbca8b798caf47fb2799a26dd09c9ad66305883d","https://git.kernel.org/stable/c/de52c713d21806b93b00a6074056b57aec4f8919","https://git.kernel.org/stable/c/fef187c6194d67395182d58169dd14ba631f1b41"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qce - fix error path in devm_qce_register_algs\n\nIf ops->register_algs() fails, the error path repeatedly calls the same\nops->unregister_algs() from the failed registration. Use the loop index\nto unregister the previously registered algorithms instead.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80565","epss":0.0012,"percentile":0.02075,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80565","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80567","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80567","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue  Previously, rmi_f54_buffer_queue() waited for the worker thread to finish but ignored whether it succeeded. If the worker failed (e.g., due to a timeout or register read failure), the queue thread would silently return success, delivering stale or uninitialized memory to userspace.  Add a 'report_error' field to struct f54_data to store the worker's exit status. Check this field in rmi_f54_buffer_queue() after the worker finishes, and mark the buffer as VB2_BUF_STATE_ERROR if an error occurred.","cvss":[],"epss":[{"cve":"CVE-2026-80567","epss":0.00164,"percentile":0.05947,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.082},"relatedVulnerabilities":[{"id":"CVE-2026-80567","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80567","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2b0403fb7e28f65883cd03814b62c9aa9bc7f04d","https://git.kernel.org/stable/c/305c24ee25b6e08ac9f4c5f697e823cc638c38da","https://git.kernel.org/stable/c/6741a8c21d98088b7f2d9f4f86a706d311ce34a2","https://git.kernel.org/stable/c/70f9aad3943559af6f32cb303744f35c05ce9cf1","https://git.kernel.org/stable/c/7d33b752e0df385b285492b74699fc73b6becdfb","https://git.kernel.org/stable/c/8786d74bf50e6797b6f655eb381ef6b25451161f","https://git.kernel.org/stable/c/9bbd3682f8a3e064271547133c37fcb17668d860","https://git.kernel.org/stable/c/be56730b547737151f24357d832b04aaa93755d5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue\n\nPreviously, rmi_f54_buffer_queue() waited for the worker thread to\nfinish but ignored whether it succeeded. If the worker failed (e.g.,\ndue to a timeout or register read failure), the queue thread would\nsilently return success, delivering stale or uninitialized memory to\nuserspace.\n\nAdd a 'report_error' field to struct f54_data to store the worker's exit\nstatus. Check this field in rmi_f54_buffer_queue() after the worker\nfinishes, and mark the buffer as VB2_BUF_STATE_ERROR if an error\noccurred.","cvss":[],"epss":[{"cve":"CVE-2026-80567","epss":0.00164,"percentile":0.05947,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80567","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80568","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80568","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: synaptics-rmi4 - block s_input when F54 queue is busy  Changing the input (diagnostic report type) mid-stream changes the report size. Since V4L2 buffers are allocated based on the size at stream start, changing the input while streaming could lead to a heap buffer overflow if the new size is larger than the allocated buffers.  Prevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue is busy (streaming).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80568","epss":0.00133,"percentile":0.03158,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.101745},"relatedVulnerabilities":[{"id":"CVE-2026-80568","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80568","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac","https://git.kernel.org/stable/c/493ba8e794729649689438edba72337111303cc4","https://git.kernel.org/stable/c/7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af","https://git.kernel.org/stable/c/cae79513f9115c350561b16f36adcb47c9bfff12","https://git.kernel.org/stable/c/ddd9a53faf3b65e5920cb802cb1db6f4615bdfef","https://git.kernel.org/stable/c/fa69f93015becf3729716de2199b58540aa99672","https://git.kernel.org/stable/c/fbfd76746adc16d64be29ff113f673b70bc3f5c2","https://git.kernel.org/stable/c/ff0849705d29277fd1f6fc6596674b9308724fb2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - block s_input when F54 queue is busy\n\nChanging the input (diagnostic report type) mid-stream changes the\nreport size. Since V4L2 buffers are allocated based on the size at\nstream start, changing the input while streaming could lead to a\nheap buffer overflow if the new size is larger than the allocated\nbuffers.\n\nPrevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue\nis busy (streaming).","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80568","epss":0.00133,"percentile":0.03158,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80568","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80569","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80569","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer  rmi_f54_work() reads a diagnostics report from the device into f54->report_data, sizing the transfer with rmi_f54_get_report_size():  \treport_size = rmi_f54_get_report_size(f54); \t... \tfor (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) { \t\tint size = min(F54_REPORT_DATA_SIZE, report_size - i); \t\t... \t\trmi_read_block(.., f54->report_data + i, size); \t}  report_data is allocated once at probe from F54's own electrode counts (array3_size(f54->num_tx_electrodes, f54->num_rx_electrodes, sizeof(u16))), but rmi_f54_get_report_size() computes the size from drv_data->num_*_electrodes when those are set, i.e. from the F55 function's electrode counts. Both counts come straight from device queries (F54 and F55 each report up to 255 electrodes) and nothing constrains the F55 counts to the F54 ones.  A malicious or malfunctioning RMI4 device that reports larger F55 electrode counts than its F54 counts makes report_size exceed the allocation, so the read loop writes past report_data (and the V4L2 dequeue memcpy() then reads past it). On conforming hardware the F55 configured electrodes are a subset of the F54 physical electrodes, so report_size never exceeds the buffer and well-behaved devices are unaffected.  Record the allocation size and reject a report that does not fit, mirroring the existing zero-size check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80569","epss":0.0012,"percentile":0.02074,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80569","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80569","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/12be3c6ca9589afd6ade41a59c761866e526634d","https://git.kernel.org/stable/c/42eaf0e6f79c487f419737314cf0760f7331d368","https://git.kernel.org/stable/c/49c5adc2b7d6e43c5cf033e1c86fdb9c16ababb1","https://git.kernel.org/stable/c/6b06aab79ff166d5781ce792d91acc2e58b1770b","https://git.kernel.org/stable/c/6b3bdd44d4cd7d5e35de1d0f06d4930f3cecd403","https://git.kernel.org/stable/c/b2f596f00d27703ce09167201ba57f55be8d2f9a","https://git.kernel.org/stable/c/b3932101c9c457148038392bc977f9b31e125a86","https://git.kernel.org/stable/c/b7b9a8b1c303b62371698e396654d6724c79cb74"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F54 report size to the allocated buffer\n\nrmi_f54_work() reads a diagnostics report from the device into\nf54->report_data, sizing the transfer with rmi_f54_get_report_size():\n\n\treport_size = rmi_f54_get_report_size(f54);\n\t...\n\tfor (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) {\n\t\tint size = min(F54_REPORT_DATA_SIZE, report_size - i);\n\t\t...\n\t\trmi_read_block(.., f54->report_data + i, size);\n\t}\n\nreport_data is allocated once at probe from F54's own electrode counts\n(array3_size(f54->num_tx_electrodes, f54->num_rx_electrodes, sizeof(u16))),\nbut rmi_f54_get_report_size() computes the size from\ndrv_data->num_*_electrodes when those are set, i.e. from the F55\nfunction's electrode counts. Both counts come straight from device\nqueries (F54 and F55 each report up to 255 electrodes) and nothing\nconstrains the F55 counts to the F54 ones.\n\nA malicious or malfunctioning RMI4 device that reports larger F55\nelectrode counts than its F54 counts makes report_size exceed the\nallocation, so the read loop writes past report_data (and the V4L2\ndequeue memcpy() then reads past it). On conforming hardware the F55\nconfigured electrodes are a subset of the F54 physical electrodes, so\nreport_size never exceeds the buffer and well-behaved devices are\nunaffected.\n\nRecord the allocation size and reject a report that does not fit,\nmirroring the existing zero-size check.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80569","epss":0.0012,"percentile":0.02074,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80569","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80570","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80570","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: synaptics-rmi4 - zero report size on F54 work error  In rmi_f54_work(), if an error occurs during report request or command verification, the code jumped directly to the 'error' label, bypassing the 'abort' label where f54->report_size was normally zeroed out.  This left f54->report_size containing its previous successful payload size. If a user then altered the V4L2 format to a smaller size, and a subsequent run failed, rmi_f54_buffer_queue() would copy the stale, larger payload size into the shrunken V4L2 buffer, causing a heap buffer overflow.  Fix this by merging the 'abort' and 'error' labels into a single 'out' exit path, and ensuring that f54->report_size is always set to 0 on failure by checking for error and zeroing the local report_size first.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80570","epss":0.00134,"percentile":0.03265,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10251000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80570","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80570","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/62079c17ec07d64362bec367ee7a525b0dbf6bf9","https://git.kernel.org/stable/c/77749685e55da19b187df215b5da4080842ca5c7","https://git.kernel.org/stable/c/79521ed3cc9ea48476666ccacf45ecd6954b29a4","https://git.kernel.org/stable/c/88c8174d72900d77fbdf2f527d54b6ff2da876a8","https://git.kernel.org/stable/c/b28593a05afdd812b590e1045b5bd862a5869225","https://git.kernel.org/stable/c/c669c64ab71afa7b467c4d7e18f6a05e96b97a1f","https://git.kernel.org/stable/c/c6cfda79f26c69e97db9805808c3b44d02227b4b","https://git.kernel.org/stable/c/dc76c3c8e8ad09362b8c1561f3928288c15cba2e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - zero report size on F54 work error\n\nIn rmi_f54_work(), if an error occurs during report request or command\nverification, the code jumped directly to the 'error' label, bypassing\nthe 'abort' label where f54->report_size was normally zeroed out.\n\nThis left f54->report_size containing its previous successful payload\nsize. If a user then altered the V4L2 format to a smaller size, and a\nsubsequent run failed, rmi_f54_buffer_queue() would copy the stale,\nlarger payload size into the shrunken V4L2 buffer, causing a heap\nbuffer overflow.\n\nFix this by merging the 'abort' and 'error' labels into a single 'out'\nexit path, and ensuring that f54->report_size is always set to 0 on\nfailure by checking for error and zeroing the local report_size first.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80570","epss":0.00134,"percentile":0.03265,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80570","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80572","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80572","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: byd - synchronize timer deletion before freeing private data  byd_disconnect() uses timer_delete() before freeing the driver's private data.  This does not wait for a running byd_clear_touch() callback, which dereferences the private data and its psmouse pointer.  A callback racing with disconnect can therefore access the private data after it has been freed.  The timer can also still be re-armed by byd_process_byte() while the disconnect is in progress.  Use timer_shutdown_sync() before freeing the private data: it waits for a running callback and turns any later re-arm attempt into a no-op.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80572","epss":0.0012,"percentile":0.02076,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80572","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80572","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/28d984a66b9e14be74986167b6ad40b5e0daf19a","https://git.kernel.org/stable/c/2e509ef60ee41a2da0deb062c262bb530143fb37","https://git.kernel.org/stable/c/84b205297fa15f97510342221d8c9a0119711478","https://git.kernel.org/stable/c/8dbfd8e32a13e116790780ed0be82b5a05eb9916","https://git.kernel.org/stable/c/c83e79c0842ed29860648bcce5022ef0ba5001c6","https://git.kernel.org/stable/c/ee944a706a18322b4a2599eebe8040a2994e928f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: byd - synchronize timer deletion before freeing private data\n\nbyd_disconnect() uses timer_delete() before freeing the driver's private\ndata.  This does not wait for a running byd_clear_touch() callback, which\ndereferences the private data and its psmouse pointer.  A callback racing\nwith disconnect can therefore access the private data after it has been\nfreed.  The timer can also still be re-armed by byd_process_byte() while\nthe disconnect is in progress.\n\nUse timer_shutdown_sync() before freeing the private data: it waits for\na running callback and turns any later re-arm attempt into a no-op.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80572","epss":0.0012,"percentile":0.02076,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80572","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80573","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80573","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: iforce - validate input packet lengths  iforce_process_packet() reads fixed fields from joystick, wheel and status packets without first checking their lengths. In particular, the shared hats-and-buttons helper unconditionally reads data[6]. The status tail is a sequence of 16-bit effect addresses, but an incomplete final address is also consumed. A successful zero-length USB URB additionally reads the packet ID before the common parser is called.  Reject the zero-length USB transfer, require the seven-byte joystick and wheel prefixes and the two-byte status prefix, and consume only complete status-tail addresses.","cvss":[],"epss":[{"cve":"CVE-2026-80573","epss":0.00164,"percentile":0.05949,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.082},"relatedVulnerabilities":[{"id":"CVE-2026-80573","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80573","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0ec411167655ef3ff3e84f6af685e962aff9a75b","https://git.kernel.org/stable/c/2c083ab16e33fbff3ab8c752fbf8118ed3dd31ce","https://git.kernel.org/stable/c/5232529eaf57f08fe37484e301579a1915b93d14","https://git.kernel.org/stable/c/5751c781d3c97ab6ce0e2a966156ed882152c415","https://git.kernel.org/stable/c/609be40988898a4d75225ade0ea5c1734757dd33","https://git.kernel.org/stable/c/84e5cb517f445dadbd5f8bf4ec513540e51f9c36","https://git.kernel.org/stable/c/a64a8b6b31cd669f0449138e53cc2592d454ccf1","https://git.kernel.org/stable/c/e73d7a7d913d89141321f5f3f16343ecc200d152"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: iforce - validate input packet lengths\n\niforce_process_packet() reads fixed fields from joystick, wheel and\nstatus packets without first checking their lengths. In particular, the\nshared hats-and-buttons helper unconditionally reads data[6]. The status\ntail is a sequence of 16-bit effect addresses, but an incomplete final\naddress is also consumed. A successful zero-length USB URB additionally\nreads the packet ID before the common parser is called.\n\nReject the zero-length USB transfer, require the seven-byte joystick and\nwheel prefixes and the two-byte status prefix, and consume only complete\nstatus-tail addresses.","cvss":[],"epss":[{"cve":"CVE-2026-80573","epss":0.00164,"percentile":0.05949,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80573","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80574","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80574","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet  Make finger2 (and also finger1) unsigned, so that if the finger index in the packet is 0 then subtracting 1 creates an array index which overflows above the existing check for FOC_MAX_FINGERS, as the existing comment says it should, instead of writing to state->fingers[-1].","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80574","epss":0.00134,"percentile":0.03224,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10653000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80574","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80574","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/063b4c6a6f3fc01bca085c442000c9c100fdbd93","https://git.kernel.org/stable/c/1842e47126816e56d30c4f856f9854fd7831066c","https://git.kernel.org/stable/c/296736076b3fd078742651c719555a488624023a","https://git.kernel.org/stable/c/6f6d5fe29efdf5001bc146fc292e6592cace93eb","https://git.kernel.org/stable/c/81b07470cb2937ceb74b00be88151582a322433b","https://git.kernel.org/stable/c/83c265bfc084d77e2171d4b67362150ab38c935b","https://git.kernel.org/stable/c/bb502d79acb9ac1e0a77fa8bc7b7b4729140b11f","https://git.kernel.org/stable/c/ca92c98b806839c108995b2bbff7061515bdfb53"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: focaltech - fix array out-of-bounds in focaltech_process_rel_packet\n\nMake finger2 (and also finger1) unsigned, so that if the finger index in\nthe packet is 0 then subtracting 1 creates an array index which overflows\nabove the existing check for FOC_MAX_FINGERS, as the existing comment says\nit should, instead of writing to state->fingers[-1].","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80574","epss":0.00134,"percentile":0.03224,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80574","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80576","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80576","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: reject oversized IBs with per-ring packet limits  On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through to ib->length_dw without a limit, while ring_emit_ib() encodes length into packet fields. Oversized values can corrupt adjacent control bits and destabilize command submission.  Add a per-ring IB packet size limit helper and reject command submissions exceeding the corresponding dword limit before IB allocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE, and apply the MM fallback limit for other ring types.  (cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80576","epss":0.0012,"percentile":0.02036,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0978},"relatedVulnerabilities":[{"id":"CVE-2026-80576","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80576","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/07fe270ec07c138a70afe7a81e115a85c35c545c","https://git.kernel.org/stable/c/1474f3970d1afd303e12ff14d06808eabb371576","https://git.kernel.org/stable/c/6e164ba1057175fb8a370d8e05cbff5c57eac0c8","https://git.kernel.org/stable/c/fd37f9dd5b5ab70a46fa7bc76623c0528d602b27"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: reject oversized IBs with per-ring packet limits\n\nOn GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through\nto ib->length_dw without a limit, while ring_emit_ib() encodes length\ninto packet fields. Oversized values can corrupt adjacent control bits\nand destabilize command submission.\n\nAdd a per-ring IB packet size limit helper and reject command\nsubmissions exceeding the corresponding dword limit before IB\nallocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE,\nand apply the MM fallback limit for other ring types.\n\n(cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.1,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80576","epss":0.0012,"percentile":0.02036,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80576","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80579","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80579","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: clear fb_info->mode before deleting a videomode  fb_set_var() can delete a mode from info->modelist when userspace passes FB_ACTIVATE_INV_MODE through FBIOPUT_VSCREENINFO. The code checks that the mode being deleted is not the current info->var and that fbcon is not using it, but it does not check fb_info->mode.  fb_info->mode may still point into the modelist entry being deleted. If the entry is freed, later mode sysfs reads through show_mode() can dereference a stale pointer.  Clear fb_info->mode before calling fb_delete_videomode() when it matches the mode being removed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80579","epss":0.00112,"percentile":0.01517,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08567999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80579","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80579","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/95e647d2a5304a8fd11f1ba3c8502de700650131","https://git.kernel.org/stable/c/ce7fef961c63229b22dec415fb988899f479d61f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: clear fb_info->mode before deleting a videomode\n\nfb_set_var() can delete a mode from info->modelist when userspace\npasses FB_ACTIVATE_INV_MODE through FBIOPUT_VSCREENINFO. The code\nchecks that the mode being deleted is not the current info->var and\nthat fbcon is not using it, but it does not check fb_info->mode.\n\nfb_info->mode may still point into the modelist entry being deleted.\nIf the entry is freed, later mode sysfs reads through show_mode() can\ndereference a stale pointer.\n\nClear fb_info->mode before calling fb_delete_videomode() when it\nmatches the mode being removed.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80579","epss":0.00112,"percentile":0.01517,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80579","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80580","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80580","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: bound mode sysfs output to the sysfs buffer  mode_string() uses snprintf() which can return a value larger than the remaining buffer space. show_modes() accumulates the return value into i without checking whether i has reached PAGE_SIZE, causing the offset to advance past the sysfs buffer if the modelist is long enough.  Add a size parameter to mode_string() and use scnprintf() to return only the bytes actually written. Add an early return when offset already exceeds the buffer. In show_modes(), stop accumulating once the buffer is full.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80580","epss":0.00112,"percentile":0.01516,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08567999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80580","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80580","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/873a1aa15c313263f2e18b38cf525623cc4fabf6","https://git.kernel.org/stable/c/d15d51fb26e830af58f3f21964f1c09c239077ea"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: bound mode sysfs output to the sysfs buffer\n\nmode_string() uses snprintf() which can return a value larger than the\nremaining buffer space. show_modes() accumulates the return value into i\nwithout checking whether i has reached PAGE_SIZE, causing the offset to\nadvance past the sysfs buffer if the modelist is long enough.\n\nAdd a size parameter to mode_string() and use scnprintf() to return\nonly the bytes actually written. Add an early return when offset\nalready exceeds the buffer. In show_modes(), stop accumulating once\nthe buffer is full.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80580","epss":0.00112,"percentile":0.01516,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80580","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80583","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80583","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses  The \"DEC0 MODE\" to \"DEC7 MODE\" controls are enumerated, but tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int).  This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 (\"ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type\") and commit 0ea5eff7c606 (\"ASoC: codecs: va-macro: fix accessing array out of bounds for enum type\"), but tx-macro was missed.  On 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value sanity check catches the 4 bytes written past the enumerated item and every read of these controls fails with -EINVAL:    snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80583","epss":0.0012,"percentile":0.02075,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80583","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80583","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1ba381759e45d5d0442452cfa5c42e836191a568","https://git.kernel.org/stable/c/2ed3601e9db08fbdb071bd3d7bd8f115d6d871b0","https://git.kernel.org/stable/c/3ee3c26ceee562079596abc9bc3307dd56dab4ed","https://git.kernel.org/stable/c/48b76879f5bfc8584b99052510ac645c6ade8d2b","https://git.kernel.org/stable/c/b6baab796d11fb84c0e9444ffca91af5eab22c25","https://git.kernel.org/stable/c/dbc81b518f6936131bfd858be71cd4295136809c","https://git.kernel.org/stable/c/f84f2c81d792cf1e65571108a3bdd2c29e09e995"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses\n\nThe \"DEC0 MODE\" to \"DEC7 MODE\" controls are enumerated, but\ntx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their\nvalue through ucontrol->value.integer.value[0] (a long) instead of\nucontrol->value.enumerated.item[0] (an unsigned int).\n\nThis same pattern was fixed in the sibling drivers by\ncommit bcfe5f76cc40 (\"ASoC: codecs: rx-macro: fix accessing array\nout of bounds for enum type\") and\ncommit 0ea5eff7c606 (\"ASoC: codecs: va-macro: fix accessing array\nout of bounds for enum type\"), but tx-macro was missed.\n\nOn 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value\nsanity check catches the 4 bytes written past the enumerated item\nand every read of these controls fails with -EINVAL:\n\n  snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80583","epss":0.0012,"percentile":0.02075,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80583","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80584","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80584","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/qeth: validate user buffer length in SNMP and ARP query ioctls  qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by a user-supplied length (udata_len) without checking a lower bound, then set udata_offset to a fixed non-zero value and pass both to a reply callback. The callback bounds-checks the copy with          if ((udata_len - udata_offset) < len)  Both fields are u32, so a udata_len smaller than udata_offset makes the subtraction wrap and the check pass, and the following memcpy() writes past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from kzalloc(), which the existing NULL check does not catch.  Reject buffers smaller than udata_offset before allocating, so the callback subtraction can no longer underflow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80584","epss":0.00134,"percentile":0.03225,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10653000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80584","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80584","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3083818e67bcd656965797fbac9a3d6c1d44f78a","https://git.kernel.org/stable/c/46443eaddebd84c51940857b11787229be169dec","https://git.kernel.org/stable/c/75fb3151513d7d9f77a8f9545418279b119c06b8","https://git.kernel.org/stable/c/91935843f9396a9e45253e2c0d4337ca1371754b","https://git.kernel.org/stable/c/9d00eeb2d27f4cc817c5e408760226d43f811ec6","https://git.kernel.org/stable/c/a3083647747942ea32faf14560d6397ff3068046","https://git.kernel.org/stable/c/cc423f4105fe145b33e1d7cad34245a798358f73","https://git.kernel.org/stable/c/d141f087b1af656f055d7c5793a3e87817ba0bbe"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/qeth: validate user buffer length in SNMP and ARP query ioctls\n\nqeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by\na user-supplied length (udata_len) without checking a lower bound, then\nset udata_offset to a fixed non-zero value and pass both to a reply\ncallback. The callback bounds-checks the copy with\n\n        if ((udata_len - udata_offset) < len)\n\nBoth fields are u32, so a udata_len smaller than udata_offset makes the\nsubtraction wrap and the check pass, and the following memcpy() writes\npast the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from\nkzalloc(), which the existing NULL check does not catch.\n\nReject buffers smaller than udata_offset before allocating, so the\ncallback subtraction can no longer underflow.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80584","epss":0.00134,"percentile":0.03225,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80584","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80586","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80586","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mptcp: options: reset DSS fields in case of unexpected size  A remote peer could send a malformed DSS with a wrong size, followed by another DSS or MPC + Data. In this case, the first suboption will be ignored, but leaving some fields written, which could lead to inconsistency or access uninitialized data.  Explicitly reset the fields that could have been modified in case of unexpected size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80586","epss":0.00404,"percentile":0.33889,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37976000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-80586","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80586","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/15e35fdad7a5576bf3f1c8d688877aeb5d1b506b","https://git.kernel.org/stable/c/192878df582c51d440bf7b91a15f297f29f2b596","https://git.kernel.org/stable/c/1fade1b2ac5b1a4948e538fae7313bea57b5ac36","https://git.kernel.org/stable/c/26dac5c9ffb20812b475fdf253eb04fab99cff3b","https://git.kernel.org/stable/c/27ed642a4e7e4b5df4b8522c72c457a67e052493","https://git.kernel.org/stable/c/35772b4981f38ba8059372cde8753e8e477e98ec","https://git.kernel.org/stable/c/4e80eff5c1c893aca2ac1d202f0b256d2e52ecde","https://git.kernel.org/stable/c/b1256090816ec46011601e084be580731df58fc7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: options: reset DSS fields in case of unexpected size\n\nA remote peer could send a malformed DSS with a wrong size, followed by\nanother DSS or MPC + Data. In this case, the first suboption will be\nignored, but leaving some fields written, which could lead to\ninconsistency or access uninitialized data.\n\nExplicitly reset the fields that could have been modified in case of\nunexpected size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80586","epss":0.00404,"percentile":0.33889,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80586","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80587","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80587","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mptcp: avoid combining some incoming suboptions  Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also because in different places, the code doesn't expect some combinations to be present. That's specially true for suboptions that would be present twice, but with different attributes.  The new restrictions are the same as the ones applied on the output side, with mptcp_write_options. The same rules can be reused with a small fix: an MP_FASTCLOSE can be used with a DSS when the sender picks this option [1], which is not the case on Linux. Here are the rules:    Which options can be used together?    X: mutually exclusive   O: often used together   C: can be used together in some cases   P: could be used together but we prefer not to (optimisations)    | Opt: | MPC  | MPJ  | DSS  | ADD  |  RM  | PRIO | FAIL |  FC  |   |------|------|------|------|------|------|------|------|------|   | MPC  |------|------|------|------|------|------|------|------|   | MPJ  |  X   |------|------|------|------|------|------|------|   | DSS  |  X   |  X   |------|------|------|------|------|------|   | ADD  |  X   |  X   |  P   |------|------|------|------|------|   | RM   |  C   |  C   |  C   |  P   |------|------|------|------|   | PRIO |  X   |  C   |  C   |  C   |  C   |------|------|------|   | FAIL |  X   |  X   |  C   |  X   |  X   |  X   |------|------|   | FC   |  X   |  X   |  P   |  X   |  X   |  X   |  X   |------|   | RST  |  X   |  X   |  X   |  X   |  X   |  X   |  O   |  O   |   |------|------|------|------|------|------|------|------|------|  The only difference is with the 'P': another stack could send and ADD_ADDR with other suboptions (DSS, RM_ADDR), and this should be allowed.  A few points of attention:   - In theory, an MP_CAPABLE could be used with a RM_ADDR, but there is    no reason to add it with a SYN. Note that even with a 4th ACK, it    doesn't seem to be useful, except when IDs are known in advance via    another channel. Better not to break that.   - Now, combining both an MP_CAPABLE and an MP_JOIN will no longer    result to a reject of the two options, but only the second suboption    is ignored. That seems OK to do that for this unexpected error. At    least now all inconsistent combinations are handled the same way.    This could change later in next. This also means the explicit checks    for having both MPC + MPJ in subflow.c will now be unreachable.    That's fine, they will be removed in a follow-up patch.   - In case of conflicting combinations, the extra suboption(s) is/are    ignored: having such combinations either means the remote peer is    buggy, or is evil. The simplest action is then taken in this case:    stop processing the current suboption.   - In mp_opt->suboptions, there is also a bit reserved to the checksum,    which can be used in an MP_CAPABLE and a DSS. Each time a DSS option    can be used in parallel with another option, the checksum can be set,    so the verification is combined into a new OPTIONS_MPTCP_DSS macro.   - An MP_CAPABLE ACK can carry a Data-Level Length, and an optional    Checksum: they are the same as the ones found in a DSS, because a DSS    cannot be used in parallel to an MP_CAPABLE. Similarly, even if there    is room, a DSS cannot be used with an MP_JOIN.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80587","epss":0.00386,"percentile":0.31969,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.36284000000000005},"relatedVulnerabilities":[{"id":"CVE-2026-80587","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80587","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/099bfcbd0c16ae9b50aba2a1bea033e63f895da7","https://git.kernel.org/stable/c/0e2210af439755a2af352eea4178261dcf61742e","https://git.kernel.org/stable/c/6bab907292155513af397a12ccb488acbfc30d79","https://git.kernel.org/stable/c/a04dcc784959e4702048785d87e0d029bd2fbdcb","https://git.kernel.org/stable/c/b6ee361524641f57b2e2363f7737f20e17f67827","https://git.kernel.org/stable/c/dc1d8d3eb345c616fbe922a010fa391c72c54d52"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: avoid combining some incoming suboptions\n\nSome MPTCP suboptions are mutually exclusive according to the RFC8684,\nbut also because in different places, the code doesn't expect some\ncombinations to be present. That's specially true for suboptions that\nwould be present twice, but with different attributes.\n\nThe new restrictions are the same as the ones applied on the output\nside, with mptcp_write_options. The same rules can be reused with a\nsmall fix: an MP_FASTCLOSE can be used with a DSS when the sender picks\nthis option [1], which is not the case on Linux. Here are the rules:\n\n  Which options can be used together?\n\n  X: mutually exclusive\n  O: often used together\n  C: can be used together in some cases\n  P: could be used together but we prefer not to (optimisations)\n\n  | Opt: | MPC  | MPJ  | DSS  | ADD  |  RM  | PRIO | FAIL |  FC  |\n  |------|------|------|------|------|------|------|------|------|\n  | MPC  |------|------|------|------|------|------|------|------|\n  | MPJ  |  X   |------|------|------|------|------|------|------|\n  | DSS  |  X   |  X   |------|------|------|------|------|------|\n  | ADD  |  X   |  X   |  P   |------|------|------|------|------|\n  | RM   |  C   |  C   |  C   |  P   |------|------|------|------|\n  | PRIO |  X   |  C   |  C   |  C   |  C   |------|------|------|\n  | FAIL |  X   |  X   |  C   |  X   |  X   |  X   |------|------|\n  | FC   |  X   |  X   |  P   |  X   |  X   |  X   |  X   |------|\n  | RST  |  X   |  X   |  X   |  X   |  X   |  X   |  O   |  O   |\n  |------|------|------|------|------|------|------|------|------|\n\nThe only difference is with the 'P': another stack could send and\nADD_ADDR with other suboptions (DSS, RM_ADDR), and this should be\nallowed.\n\nA few points of attention:\n\n - In theory, an MP_CAPABLE could be used with a RM_ADDR, but there is\n   no reason to add it with a SYN. Note that even with a 4th ACK, it\n   doesn't seem to be useful, except when IDs are known in advance via\n   another channel. Better not to break that.\n\n - Now, combining both an MP_CAPABLE and an MP_JOIN will no longer\n   result to a reject of the two options, but only the second suboption\n   is ignored. That seems OK to do that for this unexpected error. At\n   least now all inconsistent combinations are handled the same way.\n   This could change later in next. This also means the explicit checks\n   for having both MPC + MPJ in subflow.c will now be unreachable.\n   That's fine, they will be removed in a follow-up patch.\n\n - In case of conflicting combinations, the extra suboption(s) is/are\n   ignored: having such combinations either means the remote peer is\n   buggy, or is evil. The simplest action is then taken in this case:\n   stop processing the current suboption.\n\n - In mp_opt->suboptions, there is also a bit reserved to the checksum,\n   which can be used in an MP_CAPABLE and a DSS. Each time a DSS option\n   can be used in parallel with another option, the checksum can be set,\n   so the verification is combined into a new OPTIONS_MPTCP_DSS macro.\n\n - An MP_CAPABLE ACK can carry a Data-Level Length, and an optional\n   Checksum: they are the same as the ones found in a DSS, because a DSS\n   cannot be used in parallel to an MP_CAPABLE. Similarly, even if there\n   is room, a DSS cannot be used with an MP_JOIN.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80587","epss":0.00386,"percentile":0.31969,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80587","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80589","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80589","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  block: stop the timeout timer when releasing a never added disk  disk_release() undoes blk_mq_init_allocated_queue() for a disk whose probe failed before add_disk(), but it only calls blk_mq_exit_queue(). Nothing there stops q->timeout, and that timer rolls forward: it stays pending until it next expires, not until the last request completes. So if the driver issued any I/O before adding the disk, the request_queue is freed while still linked into a timer wheel bucket.  Commit 6f8191fdf41d (\"block: simplify disk shutdown\") dropped the blk_cleanup_queue() call that used to stop it.  __del_gendisk() and blk_mq_destroy_queue() still do; only the probe failure path lost it.  nvme gets there because nvme_update_ns_info() submits Report Zones or FDP io-mgmt-recv on ns->queue before the disk is added, so a later failure - a concurrent reset setting NVME_CTRL_FROZEN, or device_add_disk() failing - lands in put_disk() with the timer armed:    BUG: KASAN: slab-use-after-free in detach_if_pending+0x30c/0x340   Write of size 8 at addr ffff888004d71310 by task kworker/u8:2/37    __timer_delete_sync+0x156/0x240 kernel/time/timer.c:1621    blk_sync_queue+0x22/0x40 block/blk-core.c:222    nvme_sync_queues+0x100/0x150 drivers/nvme/host/core.c:5362    nvme_reset_work+0x138/0x930 drivers/nvme/host/pci.c:3264    Allocated by task 34:    __blk_mq_alloc_disk+0x33/0x100 block/blk-mq.c:4462    nvme_alloc_ns+0x290/0x3870 drivers/nvme/host/core.c:4146    Freed by task 0:    blk_free_queue_rcu+0x3a/0x50 block/blk-core.c:254    rcu_core+0xc10/0x1730 kernel/rcu/tree.c:2857  The queue being synced there is ctrl->admin_q, only a victim sharing a timer wheel bucket with the freed queue's dangling entry; other runs tripped in enqueue_timer(), __run_timers() or blk_mq_timeout_work(). Failing nvme_alloc_ns() with a debug patch makes it deterministic: one leaked timer trips KASAN within seconds, while 1987 patched releases produced no splat.  Stop the timer and the queue work items before blk_mq_exit_queue(), like blk_mq_destroy_queue() does.  Found by FuzzNvme.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80589","epss":0.00375,"percentile":0.30823,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.3525},"relatedVulnerabilities":[{"id":"CVE-2026-80589","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80589","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1a0ae4d502062a2759f2a92d12bdeab3c64c7372","https://git.kernel.org/stable/c/26cb8ebbfaf713c82e142d08828d4d765057633b","https://git.kernel.org/stable/c/6ae7364f68e6c7af6b6df4bbb14040b89e5975d0","https://git.kernel.org/stable/c/6f06dbe5012c160e0dba418a5a9cb16c456ad46a","https://git.kernel.org/stable/c/93d620519d71dfc6ee64b5baea74f1d85d4439fb","https://git.kernel.org/stable/c/bb03b56d1d754908a37a160603be21769da423cf"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nblock: stop the timeout timer when releasing a never added disk\n\ndisk_release() undoes blk_mq_init_allocated_queue() for a disk whose\nprobe failed before add_disk(), but it only calls blk_mq_exit_queue().\nNothing there stops q->timeout, and that timer rolls forward: it stays\npending until it next expires, not until the last request completes.\nSo if the driver issued any I/O before adding the disk, the\nrequest_queue is freed while still linked into a timer wheel bucket.\n\nCommit 6f8191fdf41d (\"block: simplify disk shutdown\") dropped the\nblk_cleanup_queue() call that used to stop it.  __del_gendisk() and\nblk_mq_destroy_queue() still do; only the probe failure path lost it.\n\nnvme gets there because nvme_update_ns_info() submits Report Zones or\nFDP io-mgmt-recv on ns->queue before the disk is added, so a later\nfailure - a concurrent reset setting NVME_CTRL_FROZEN, or\ndevice_add_disk() failing - lands in put_disk() with the timer armed:\n\n  BUG: KASAN: slab-use-after-free in detach_if_pending+0x30c/0x340\n  Write of size 8 at addr ffff888004d71310 by task kworker/u8:2/37\n   __timer_delete_sync+0x156/0x240 kernel/time/timer.c:1621\n   blk_sync_queue+0x22/0x40 block/blk-core.c:222\n   nvme_sync_queues+0x100/0x150 drivers/nvme/host/core.c:5362\n   nvme_reset_work+0x138/0x930 drivers/nvme/host/pci.c:3264\n\n  Allocated by task 34:\n   __blk_mq_alloc_disk+0x33/0x100 block/blk-mq.c:4462\n   nvme_alloc_ns+0x290/0x3870 drivers/nvme/host/core.c:4146\n\n  Freed by task 0:\n   blk_free_queue_rcu+0x3a/0x50 block/blk-core.c:254\n   rcu_core+0xc10/0x1730 kernel/rcu/tree.c:2857\n\nThe queue being synced there is ctrl->admin_q, only a victim sharing a\ntimer wheel bucket with the freed queue's dangling entry; other runs\ntripped in enqueue_timer(), __run_timers() or blk_mq_timeout_work().\nFailing nvme_alloc_ns() with a debug patch makes it deterministic: one\nleaked timer trips KASAN within seconds, while 1987 patched releases\nproduced no splat.\n\nStop the timer and the queue work items before blk_mq_exit_queue(), like\nblk_mq_destroy_queue() does.\n\nFound by FuzzNvme.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80589","epss":0.00375,"percentile":0.30823,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80589","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80590","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80590","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  inet: frags: strip GSO state from fragments before reassembly  A virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark an IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off. inet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first fragment's skb as the head of the reassembled datagram, including its shinfo->gso_size/gso_type/gso_segs, and chain the remaining fragments on frag_list with whatever linear/paged layout they arrived with.  After ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the reassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and the next software segmentation point - udp_rcv_segment() on local delivery, validate_xmit_skb(), or the ip_finish_output_gso() slow path - hands it to skb_segment(). skb_segment()'s frag_list walk assumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to a tap by an unprivileged user in its own userns are enough:    kernel BUG at net/core/skbuff.c:4899!   Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI   CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2   RIP: 0010:skb_segment+0x20ca/0x48b0   Call Trace:    <TASK>    __udp_gso_segment+0x29a/0x27d0    udp4_ufo_fragment+0x458/0x6c0    inet_gso_segment+0x429/0x1340    skb_mac_gso_segment+0x233/0x4f0    __skb_gso_segment+0x308/0x660    udp_queue_rcv_skb+0x440/0xad0    udp_unicast_rcv_skb+0xc7/0x2c0    udp_rcv+0x16ce/0x2260    ip_protocol_deliver_rcu+0x197/0x2d0    ip_local_deliver+0x430/0x690    ip_rcv+0x16f/0x1f0    __netif_receive_skb_one_core+0x15e/0x1c0    __netif_receive_skb+0x1e/0x110    netif_receive_skb+0xf6/0x5c0    tun_rx_batched.isra.0+0x3ab/0x790    tun_get_user+0x17c3/0x3550    tun_chr_write_iter+0xba/0x1b0    vfs_write+0x646/0x1130    </TASK>   Kernel panic - not syncing: Fatal exception in interrupt  This runs with BH disabled, so it is a panic rather than an oops. The same is reachable with CAP_NET_RAW in a netns where a defrag point precedes a GSO point, and from a guest whose VMM forwards virtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by commit 3dcbdb134f32 (\"net: gso: Fix skb_segment splat when splitting gso_size mangled skb having linear-headed frag_list\") and by commit 9e4b7a99a03a (\"net: gso: fix panic on frag_list with mixed head alloc types\") do not cover it: page-backed heads skip them, and kmalloc heads skip them when gso_size == skb_headlen(head), which the sender controls.  An skb entering a frag queue is an IP fragment by definition and cannot legitimately carry GSO state: GRO does not merge fragments and the stack segments before it fragments, so only untrusted sources are affected. This has been reachable since commit f43798c27684 (\"tun: Allow GSO using virtio_net_hdr\"), the first path that let userspace attach GSO metadata to an IP fragment. Reset the GSO fields of every fragment as it is queued, in inet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and 6lowpan reassembly share; then neither the head nor the frag_list members of the reassembled skb carry them (the members matter too: the ip_do_fragment()/ip6_fragment() fast paths send them out as they are). The head may remain CHECKSUM_PARTIAL; that is already accepted on receive and resolved by skb_checksum_help() in ip_do_fragment()/ip6_fragment() on forward.  Tested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer above, two further IPv4 frag_list geometries that reach BUG_ON(i >= nfrags) and BUG_ON(!list_skb->head_frag), and an IPv6 fragment-header variant (udp6_ufo_fragment()) each panic the unpatched kernel; with this patch all four datagrams are delivered intact and nothing is logged.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80590","epss":0.00586,"percentile":0.46059,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47173},"relatedVulnerabilities":[{"id":"CVE-2026-80590","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80590","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/14a8f3e10fa9a5abd6cedcdaa0c0b7ea9a09f234","https://git.kernel.org/stable/c/29dda278a5ed272f2230ff4eaa23cf403107bba0","https://git.kernel.org/stable/c/3edf721bb4b99d272c336631b44e3d8ff9a4f31b","https://git.kernel.org/stable/c/69b73b74d9eb45f5560a8fe4fa406ada580e1340","https://git.kernel.org/stable/c/c49f04e8d2b94dbb8d9fd99731dd3f00589c8ace","https://git.kernel.org/stable/c/cfdbc8c2e6f9ef5d8b8e54859da03dfe682b0bee","https://git.kernel.org/stable/c/d5dc1e69fd7258ea605c9952e5d5947539159ae3","https://git.kernel.org/stable/c/da857e448322a2e871ce3ecc2900027041160d43","https://git.kernel.org/stable/c/dec2edb7aaf12a8878b3a03172ea8fc277b8eaad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: strip GSO state from fragments before reassembly\n\nA virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark\nan IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off.\ninet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first\nfragment's skb as the head of the reassembled datagram, including its\nshinfo->gso_size/gso_type/gso_segs, and chain the remaining fragments\non frag_list with whatever linear/paged layout they arrived with.\n\nAfter ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the\nreassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and\nthe next software segmentation point - udp_rcv_segment() on local\ndelivery, validate_xmit_skb(), or the ip_finish_output_gso() slow\npath - hands it to skb_segment(). skb_segment()'s frag_list walk\nassumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to\na tap by an unprivileged user in its own userns are enough:\n\n  kernel BUG at net/core/skbuff.c:4899!\n  Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n  CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2\n  RIP: 0010:skb_segment+0x20ca/0x48b0\n  Call Trace:\n   <TASK>\n   __udp_gso_segment+0x29a/0x27d0\n   udp4_ufo_fragment+0x458/0x6c0\n   inet_gso_segment+0x429/0x1340\n   skb_mac_gso_segment+0x233/0x4f0\n   __skb_gso_segment+0x308/0x660\n   udp_queue_rcv_skb+0x440/0xad0\n   udp_unicast_rcv_skb+0xc7/0x2c0\n   udp_rcv+0x16ce/0x2260\n   ip_protocol_deliver_rcu+0x197/0x2d0\n   ip_local_deliver+0x430/0x690\n   ip_rcv+0x16f/0x1f0\n   __netif_receive_skb_one_core+0x15e/0x1c0\n   __netif_receive_skb+0x1e/0x110\n   netif_receive_skb+0xf6/0x5c0\n   tun_rx_batched.isra.0+0x3ab/0x790\n   tun_get_user+0x17c3/0x3550\n   tun_chr_write_iter+0xba/0x1b0\n   vfs_write+0x646/0x1130\n   </TASK>\n  Kernel panic - not syncing: Fatal exception in interrupt\n\nThis runs with BH disabled, so it is a panic rather than an oops. The\nsame is reachable with CAP_NET_RAW in a netns where a defrag point\nprecedes a GSO point, and from a guest whose VMM forwards\nvirtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by\ncommit 3dcbdb134f32 (\"net: gso: Fix skb_segment splat when splitting\ngso_size mangled skb having linear-headed frag_list\") and by\ncommit 9e4b7a99a03a (\"net: gso: fix panic on frag_list with mixed head\nalloc types\") do not cover it: page-backed heads skip them, and kmalloc\nheads skip them when gso_size == skb_headlen(head), which the sender\ncontrols.\n\nAn skb entering a frag queue is an IP fragment by definition and\ncannot legitimately carry GSO state: GRO does not merge fragments and\nthe stack segments before it fragments, so only untrusted sources are\naffected. This has been reachable since\ncommit f43798c27684 (\"tun: Allow GSO using virtio_net_hdr\"), the first\npath that let userspace attach GSO metadata to an IP fragment. Reset\nthe GSO fields of every fragment as it is queued, in\ninet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and\n6lowpan reassembly share; then neither the head nor the frag_list\nmembers of the reassembled skb carry them (the members matter too:\nthe ip_do_fragment()/ip6_fragment() fast paths send them out as they\nare). The head may remain CHECKSUM_PARTIAL; that is already accepted\non receive and resolved by skb_checksum_help() in\nip_do_fragment()/ip6_fragment() on forward.\n\nTested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer\nabove, two further IPv4 frag_list geometries that reach\nBUG_ON(i >= nfrags) and BUG_ON(!list_skb->head_frag), and an IPv6\nfragment-header variant (udp6_ufo_fragment()) each panic the unpatched\nkernel; with this patch all four datagrams are delivered intact and\nnothing is logged.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":8.6,"exploitabilityScore":3.9,"impactScore":4},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80590","epss":0.00586,"percentile":0.46059,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80590","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80602","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80602","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf/x86/amd/lbr: Fix kernel address leakage  A user-only branch stack can contain branches that originate from the kernel. As a result, kernel addresses are exposed to user space even when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors supporting X86_FEATURE_AMD_LBR_V2, perf can still report SYSRET/ERET entries for which the branch-from addresses are in the kernel.  E.g.    $ perf record -e cycles -o - -j any,save_type,u -- \\         perf bench syscall basic --loop 1000 | \\         perf script -i - -F brstack|tr ' ' '\\n'| \\         grep -E '0x[89a-f][0-9a-f]{15}'    ...   0xffffffff81001268/0x717a90a38f1a/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH   0xffffffff81001268/0x717a90a39157/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH   0xffffffff81001268/0x717a90a2c628/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH   0xffffffff81001268/0x717a90a41b60/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH   0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH   0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH   0xffffffff81001268/0x717a8bef1c30/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH   0xffffffff81001268/0x717a8e4d3c90/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH   ...  The reason is that the hardware filter only considers the privilege level applicable to the branch target. Extend software filtering to also validate the branch-from addresses against br_sel, so that any branch record whose branch-from address is in the kernel is dropped when PERF_SAMPLE_BRANCH_USER is requested.","cvss":[],"epss":[{"cve":"CVE-2026-80602","epss":0.00168,"percentile":0.06316,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80602","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80602","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/208ecca408b1707ad86ea247d3d3e09d3606fc13","https://git.kernel.org/stable/c/2a892294b83f541115c94b0bb637f39bef187657","https://git.kernel.org/stable/c/5ab0eba9c8819506bcb72348fd701f8a9006f95e","https://git.kernel.org/stable/c/5be478c1e08981ca91b34de310d7e2638171d9d8","https://git.kernel.org/stable/c/fb3b76b5ad2ebad63dd76f8b65b624eaf638b73f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/lbr: Fix kernel address leakage\n\nA user-only branch stack can contain branches that originate from\nthe kernel. As a result, kernel addresses are exposed to user space\neven when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors\nsupporting X86_FEATURE_AMD_LBR_V2, perf can still report SYSRET/ERET\nentries for which the branch-from addresses are in the kernel.\n\nE.g.\n\n  $ perf record -e cycles -o - -j any,save_type,u -- \\\n        perf bench syscall basic --loop 1000 | \\\n        perf script -i - -F brstack|tr ' ' '\\n'| \\\n        grep -E '0x[89a-f][0-9a-f]{15}'\n\n  ...\n  0xffffffff81001268/0x717a90a38f1a/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n  0xffffffff81001268/0x717a90a39157/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n  0xffffffff81001268/0x717a90a2c628/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n  0xffffffff81001268/0x717a90a41b60/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n  0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n  0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n  0xffffffff81001268/0x717a8bef1c30/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n  0xffffffff81001268/0x717a8e4d3c90/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n  ...\n\nThe reason is that the hardware filter only considers the privilege\nlevel applicable to the branch target. Extend software filtering to\nalso validate the branch-from addresses against br_sel, so that any\nbranch record whose branch-from address is in the kernel is dropped\nwhen PERF_SAMPLE_BRANCH_USER is requested.","cvss":[],"epss":[{"cve":"CVE-2026-80602","epss":0.00168,"percentile":0.06316,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80602","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80611","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80611","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ACPI: processor_idle: Mark LPI enter functions as __cpuidle  When function tracing or Kprobes is enabled, entering an ACPI Low Power Idle (LPI) state triggers the following RCU splat:    RCU not on for: acpi_idle_lpi_enter+0x4/0xd8   WARNING: CPU: 8 PID: 0 at include/linux/trace_recursion.h:162 function_trace_call+0x1e8/0x228  The acpi_idle_lpi_enter() function is invoked within the cpuidle path after RCU has already been disabled for the current local CPU. Consequently, ftrace's function_trace_call() expects RCU to be actively watching before recording trace data, emitting a warning if it is not.  Fix this by annotating acpi_idle_lpi_enter(), the generic __weak stub, and the RISC-V implementation of acpi_processor_ffh_lpi_enter() with __cpuidle. This moves these functions into the '.cpuidle.text' section, implicitly disabling ftrace instrumentation (notrace) along this sensitive path and preventing trace-induced RCU warnings during idle entry.","cvss":[],"epss":[{"cve":"CVE-2026-80611","epss":0.00168,"percentile":0.06318,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80611","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80611","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/10f675902a5fc88ccfe34bb8aa37de50806b03b1","https://git.kernel.org/stable/c/5b6165d7ec38477e8cfa41bfa464959957953822","https://git.kernel.org/stable/c/8bbe4dd7964552f74c271c3a8d95a4331a8ab5f9","https://git.kernel.org/stable/c/956ca5d72c76504824c8eb601879da9476973e15"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: processor_idle: Mark LPI enter functions as __cpuidle\n\nWhen function tracing or Kprobes is enabled, entering an ACPI Low\nPower Idle (LPI) state triggers the following RCU splat:\n\n  RCU not on for: acpi_idle_lpi_enter+0x4/0xd8\n  WARNING: CPU: 8 PID: 0 at include/linux/trace_recursion.h:162 function_trace_call+0x1e8/0x228\n\nThe acpi_idle_lpi_enter() function is invoked within the cpuidle\npath after RCU has already been disabled for the current local CPU.\nConsequently, ftrace's function_trace_call() expects RCU to be\nactively watching before recording trace data, emitting a warning\nif it is not.\n\nFix this by annotating acpi_idle_lpi_enter(), the generic __weak\nstub, and the RISC-V implementation of acpi_processor_ffh_lpi_enter()\nwith __cpuidle. This moves these functions into the '.cpuidle.text'\nsection, implicitly disabling ftrace instrumentation (notrace) along\nthis sensitive path and preventing trace-induced RCU warnings during\nidle entry.","cvss":[],"epss":[{"cve":"CVE-2026-80611","epss":0.00168,"percentile":0.06318,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80611","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80616","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80616","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()  It's pointless to call WARN_ON() in case of an allocation failure in dev_change_net_namespace() and device_rename(), since it only leads to useless splats caused by deliberate fault injections, so avoid it.  Found by Linux Verification Center (linuxtesting.org) with Syzkaller.","cvss":[],"epss":[{"cve":"CVE-2026-80616","epss":0.00178,"percentile":0.07503,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.089},"relatedVulnerabilities":[{"id":"CVE-2026-80616","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80616","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0569f67ed6a7af838e2141da93c68e6b6013f483","https://git.kernel.org/stable/c/6fcba77571c53f656a2f109259601a7570d4c74a","https://git.kernel.org/stable/c/f4860dd988b1041d70595f2ed84de80f90cb7ebc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()\n\nIt's pointless to call WARN_ON() in case of an allocation failure in\ndev_change_net_namespace() and device_rename(), since it only leads to\nuseless splats caused by deliberate fault injections, so avoid it.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.","cvss":[],"epss":[{"cve":"CVE-2026-80616","epss":0.00178,"percentile":0.07503,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80616","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80623","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80623","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  coresight: ete: Always save state on power down  System register ETMs and ETE are unlikely to be preserved on CPU power down. The ETE DT binding also never documented \"arm,coresight-loses-context-with-cpu\" so nobody would have legitimately been able to use that binding to fix it and ACPI has no such binding at all.  Fix it by hard coding the setting for sysreg ETMs (ETE is always sysreg) or ACPI boots. Use a local variable when setting up save_state so that it's immune to concurrent probing when devices have different configurations which is an issue with modifying the global.  This fixes the following error when using Coresight with ACPI on the FVP which supports CPU PM:    coresight ete0: External agent took claim tag   WARNING: drivers/hwtracing/coresight/coresight-core.c:248 at coresight_disclaim_device_unlocked+0xe0/0xe8, CPU#0: perf/117","cvss":[],"epss":[{"cve":"CVE-2026-80623","epss":0.00166,"percentile":0.06128,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-80623","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80623","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/293dacd5b6a9f1275d92ca6c4fd874e54b2c8319","https://git.kernel.org/stable/c/2ab4645fe4206c142a5f1491e191c906279686cf","https://git.kernel.org/stable/c/65d87f28daec31903fc39fee0744f7a0059c19f2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: ete: Always save state on power down\n\nSystem register ETMs and ETE are unlikely to be preserved on CPU power\ndown. The ETE DT binding also never documented\n\"arm,coresight-loses-context-with-cpu\" so nobody would have legitimately\nbeen able to use that binding to fix it and ACPI has no such binding at\nall.\n\nFix it by hard coding the setting for sysreg ETMs (ETE is always sysreg)\nor ACPI boots. Use a local variable when setting up save_state so that\nit's immune to concurrent probing when devices have different\nconfigurations which is an issue with modifying the global.\n\nThis fixes the following error when using Coresight with ACPI on the FVP\nwhich supports CPU PM:\n\n  coresight ete0: External agent took claim tag\n  WARNING: drivers/hwtracing/coresight/coresight-core.c:248 at coresight_disclaim_device_unlocked+0xe0/0xe8, CPU#0: perf/117","cvss":[],"epss":[{"cve":"CVE-2026-80623","epss":0.00166,"percentile":0.06128,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80623","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80628","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80628","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: seq: oss: Serialize readq reset state with q->lock  snd_seq_oss_readq_clear() resets qlen, head, and tail without q->lock even though the normal reader and producer paths serialize the same ring state under that spinlock. A reset can therefore race snd_seq_oss_readq_free() or snd_seq_oss_readq_put_event() and leave stale records in the queue, drop freshly queued ones, or report the wrong readiness after wakeup. KCSAN reports a data race between snd_seq_oss_readq_clear() and snd_seq_oss_readq_free().  Take q->lock while clearing the ring and resetting input_time. Factor the enqueue logic into a caller-locked helper so snd_seq_oss_readq_put_timestamp() updates its suppression state under the same lock instead of racing the reset path.  The buggy scenario involves two paths, with each column showing the order within that path:  reset path:                      locked readq updater: 1. snd_seq_oss_reset() or        1. A reader or callback producer    release reaches                  takes q->lock on the same queue.    snd_seq_oss_readq_clear(). 2. snd_seq_oss_readq_clear()     2. The updater tests or modifies    resets qlen, head, tail,         qlen, head, and tail.    and input_time. 3. snd_seq_oss_readq_clear()     3. The updater completes its    wakes sleepers on                read-modify-write sequence.    q->midi_sleep. 4. Without q->lock, the reset    4. The resulting ring state drives    can overlap the locked           later reads and readiness.    update.  KCSAN reports:  BUG: KCSAN: data-race in snd_seq_oss_readq_clear / snd_seq_oss_readq_free  write to 0xffff8881069fe608 of 4 bytes by task 120516 on cpu 0:   snd_seq_oss_readq_free+0x6c/0x80   snd_seq_oss_read+0xcb/0x250   odev_read+0x38/0x60   vfs_read+0xff/0x600   ksys_read+0xb4/0x140   __x64_sys_read+0x46/0x60   do_syscall_64+0xbb/0x2f0   entry_SYSCALL_64_after_hwframe+0x77/0x7f  read to 0xffff8881069fe608 of 4 bytes by task 120517 on cpu 1:   snd_seq_oss_readq_clear+0x1f/0x90   snd_seq_oss_reset+0xa7/0xf0   snd_seq_oss_ioctl+0x6f6/0x7e0   odev_ioctl+0x56/0xc0   __x64_sys_ioctl+0xd1/0x120   do_syscall_64+0xbb/0x2f0   entry_SYSCALL_64_after_hwframe+0x77/0x7f  value changed: 0x00000001 -> 0x00000000","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80628","epss":0.00127,"percentile":0.02677,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.097155},"relatedVulnerabilities":[{"id":"CVE-2026-80628","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80628","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/287d506d4e0865918cec82bb1361f283a08c979b","https://git.kernel.org/stable/c/43e10709b1ba288bcbabb9b9cb6e518b2a5d8506","https://git.kernel.org/stable/c/49ce92d207820f588b0406add82f053decfbe5d9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: oss: Serialize readq reset state with q->lock\n\nsnd_seq_oss_readq_clear() resets qlen, head, and tail without\nq->lock even though the normal reader and producer paths serialize the\nsame ring state under that spinlock. A reset can therefore race\nsnd_seq_oss_readq_free() or snd_seq_oss_readq_put_event() and leave\nstale records in the queue, drop freshly queued ones, or report the\nwrong readiness after wakeup. KCSAN reports a data race between\nsnd_seq_oss_readq_clear() and snd_seq_oss_readq_free().\n\nTake q->lock while clearing the ring and resetting input_time. Factor\nthe enqueue logic into a caller-locked helper so\nsnd_seq_oss_readq_put_timestamp() updates its suppression state under\nthe same lock instead of racing the reset path.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nreset path:                      locked readq updater:\n1. snd_seq_oss_reset() or        1. A reader or callback producer\n   release reaches                  takes q->lock on the same queue.\n   snd_seq_oss_readq_clear().\n2. snd_seq_oss_readq_clear()     2. The updater tests or modifies\n   resets qlen, head, tail,         qlen, head, and tail.\n   and input_time.\n3. snd_seq_oss_readq_clear()     3. The updater completes its\n   wakes sleepers on                read-modify-write sequence.\n   q->midi_sleep.\n4. Without q->lock, the reset    4. The resulting ring state drives\n   can overlap the locked           later reads and readiness.\n   update.\n\nKCSAN reports:\n\nBUG: KCSAN: data-race in snd_seq_oss_readq_clear /\nsnd_seq_oss_readq_free\n\nwrite to 0xffff8881069fe608 of 4 bytes by task 120516 on cpu 0:\n  snd_seq_oss_readq_free+0x6c/0x80\n  snd_seq_oss_read+0xcb/0x250\n  odev_read+0x38/0x60\n  vfs_read+0xff/0x600\n  ksys_read+0xb4/0x140\n  __x64_sys_read+0x46/0x60\n  do_syscall_64+0xbb/0x2f0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nread to 0xffff8881069fe608 of 4 bytes by task 120517 on cpu 1:\n  snd_seq_oss_readq_clear+0x1f/0x90\n  snd_seq_oss_reset+0xa7/0xf0\n  snd_seq_oss_ioctl+0x6f6/0x7e0\n  odev_ioctl+0x56/0xc0\n  __x64_sys_ioctl+0xd1/0x120\n  do_syscall_64+0xbb/0x2f0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nvalue changed: 0x00000001 -> 0x00000000","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80628","epss":0.00127,"percentile":0.02677,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80628","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80629","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80629","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  octeontx2-af: npc: Fix size of entry2cntr_map  KASAN prints below splat. This is caused by allocating counter for reserved mcam entry for cpt 2nd pass entry. But mcam->entry2cntr_map is not allocated for reserved entries.  BUG: KASAN: slab-out-of-bounds in npc_map_mcam_entry_and_cntr+0xb0/0x1a0 Write of size 2 at addr ffff0001033e7ffe by task kworker/0:1/14  CPU: 0 PID: 14 Comm: kworker/0:1 Not tainted 6.1.67 #1 Hardware name: Marvell CN106XX board (DT) Workqueue: events work_for_cpu_fn Call trace:  dump_backtrace.part.0+0xe4/0xf0  show_stack+0x18/0x30  dump_stack_lvl+0x88/0xb4  print_report+0x154/0x458  kasan_report+0xb8/0x194  __asan_store2+0x7c/0xa0  npc_map_mcam_entry_and_cntr+0xb0/0x1a0  rvu_mbox_handler_npc_mcam_write_entry+0x268/0x280  npc_install_flow+0x840/0xfe0  rvu_npc_install_cpt_pass2_entry+0x138/0x190  rvu_nix_init+0x148c/0x2880  rvu_probe+0x1800/0x30b0  local_pci_probe+0x78/0xe0  work_for_cpu_fn+0x30/0x50  process_one_work+0x4cc/0x97c  worker_thread+0x360/0x630  kthread+0x1a0/0x1b0  ret_from_fork+0x10/0x20","cvss":[],"epss":[{"cve":"CVE-2026-80629","epss":0.00168,"percentile":0.06309,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80629","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80629","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1d072cc3ba4338d6b2acb85d50a3af5cf2b12a3e","https://git.kernel.org/stable/c/2477c523c6e69733d51101ae9bd2dfc0a054b13d","https://git.kernel.org/stable/c/de8e3a4004c5df9461974352e9d7ff0f8313c508","https://git.kernel.org/stable/c/f9cd6fabe0e7c7f6fc30c6c192c7ed72aba37232"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: npc: Fix size of entry2cntr_map\n\nKASAN prints below splat. This is caused by allocating counter for\nreserved mcam entry for cpt 2nd pass entry. But mcam->entry2cntr_map\nis not allocated for reserved entries.\n\nBUG: KASAN: slab-out-of-bounds in npc_map_mcam_entry_and_cntr+0xb0/0x1a0\nWrite of size 2 at addr ffff0001033e7ffe by task kworker/0:1/14\n\nCPU: 0 PID: 14 Comm: kworker/0:1 Not tainted 6.1.67 #1\nHardware name: Marvell CN106XX board (DT)\nWorkqueue: events work_for_cpu_fn\nCall trace:\n dump_backtrace.part.0+0xe4/0xf0\n show_stack+0x18/0x30\n dump_stack_lvl+0x88/0xb4\n print_report+0x154/0x458\n kasan_report+0xb8/0x194\n __asan_store2+0x7c/0xa0\n npc_map_mcam_entry_and_cntr+0xb0/0x1a0\n rvu_mbox_handler_npc_mcam_write_entry+0x268/0x280\n npc_install_flow+0x840/0xfe0\n rvu_npc_install_cpt_pass2_entry+0x138/0x190\n rvu_nix_init+0x148c/0x2880\n rvu_probe+0x1800/0x30b0\n local_pci_probe+0x78/0xe0\n work_for_cpu_fn+0x30/0x50\n process_one_work+0x4cc/0x97c\n worker_thread+0x360/0x630\n kthread+0x1a0/0x1b0\n ret_from_fork+0x10/0x20","cvss":[],"epss":[{"cve":"CVE-2026-80629","epss":0.00168,"percentile":0.06309,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80629","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80631","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80631","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: lzo: reject compressed segment that overflows the compressed input  lzo_decompress_bio() validates each on-disk segment length seg_len only against the workspace cbuf size, not against the compressed input size (compressed_len, the total folio bytes of the bio).  A crafted extent can carry a segment whose seg_len passes the cbuf check but runs past the end of the bio, so copy_compressed_segment() walks off the last folio: get_current_folio() then returns the NULL folio from bio_next_folio(), and with CONFIG_BTRFS_ASSERT disabled (default) folio_size(NULL) faults.   BUG: KASAN: null-ptr-deref in lzo_decompress_bio (fs/btrfs/lzo.c:383)  Read of size 8 at addr 0000000000000000 by task kworker/u8:1/29  Workqueue: btrfs-endio simple_end_io_work   kasan_report (mm/kasan/report.c:590)   lzo_decompress_bio (fs/btrfs/lzo.c:383)   end_bbio_compressed_read (fs/btrfs/compression.c:1065)   btrfs_bio_end_io (fs/btrfs/bio.c:135)   btrfs_check_read_bio (fs/btrfs/bio.c:180 fs/btrfs/bio.c:285)   simple_end_io_work   process_one_work   worker_thread  Reject any segment whose payload would extend beyond compressed_len before copying it, treating it as corruption like the other on-disk validation failures in this function.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80631","epss":0.00343,"percentile":0.27443,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.25725000000000003},"relatedVulnerabilities":[{"id":"CVE-2026-80631","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80631","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1641d058adfbd50cf95d54581ed5d142ee82c07f","https://git.kernel.org/stable/c/b0d27d43791b7a3057c3c4aedf9b4aa033d37c46"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: lzo: reject compressed segment that overflows the compressed input\n\nlzo_decompress_bio() validates each on-disk segment length seg_len only\nagainst the workspace cbuf size, not against the compressed input size\n(compressed_len, the total folio bytes of the bio).  A crafted extent can\ncarry a segment whose seg_len passes the cbuf check but runs past the end\nof the bio, so copy_compressed_segment() walks off the last folio:\nget_current_folio() then returns the NULL folio from bio_next_folio(), and\nwith CONFIG_BTRFS_ASSERT disabled (default) folio_size(NULL) faults.\n\n BUG: KASAN: null-ptr-deref in lzo_decompress_bio (fs/btrfs/lzo.c:383)\n Read of size 8 at addr 0000000000000000 by task kworker/u8:1/29\n Workqueue: btrfs-endio simple_end_io_work\n  kasan_report (mm/kasan/report.c:590)\n  lzo_decompress_bio (fs/btrfs/lzo.c:383)\n  end_bbio_compressed_read (fs/btrfs/compression.c:1065)\n  btrfs_bio_end_io (fs/btrfs/bio.c:135)\n  btrfs_check_read_bio (fs/btrfs/bio.c:180 fs/btrfs/bio.c:285)\n  simple_end_io_work\n  process_one_work\n  worker_thread\n\nReject any segment whose payload would extend beyond compressed_len before\ncopying it, treating it as corruption like the other on-disk validation\nfailures in this function.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80631","epss":0.00343,"percentile":0.27443,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80631","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80634","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80634","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag  The DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps inside WARN_ON_ONCE(). num_encaps is u8, so if it's already 0 the decrement still happens and wraps it to 255. The break only leaves the inner switch -- a later path entry can set info->indev back to a real device, and we end up returning with num_encaps == 255.  nft_dev_forward_path() then walks info.encap[] (size 2) up to num_encaps, which means an OOB stack read and a bogus count copied into the route descriptor.  Should only happen on a malformed bridge path stack, hence the WARN, but worth handling sanely. Move the decrement out of the WARN.  [ While at this, remove the WARN_ON_ONCE since this can only happen   with a buggy bridge path stack --pablo ].","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80634","epss":0.00379,"percentile":0.3125,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.35626},"relatedVulnerabilities":[{"id":"CVE-2026-80634","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80634","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/2f55fa28011c97d6495d5787808db10a8c2d690d","https://git.kernel.org/stable/c/e052f920773b73be49eb4d8702a9f85de7464363"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag\n\nThe DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps\ninside WARN_ON_ONCE(). num_encaps is u8, so if it's already 0 the\ndecrement still happens and wraps it to 255. The break only leaves\nthe inner switch -- a later path entry can set info->indev back to\na real device, and we end up returning with num_encaps == 255.\n\nnft_dev_forward_path() then walks info.encap[] (size 2) up to\nnum_encaps, which means an OOB stack read and a bogus count copied\ninto the route descriptor.\n\nShould only happen on a malformed bridge path stack, hence the WARN,\nbut worth handling sanely. Move the decrement out of the WARN.\n\n[ While at this, remove the WARN_ON_ONCE since this can only happen\n  with a buggy bridge path stack --pablo ].","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80634","epss":0.00379,"percentile":0.3125,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80634","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80636","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80636","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: conntrack: revert ct extension genid infrastructure  This infrastructure is not used anymore after moving ct timeout and helper to use datapath refcount to track object use.  Revert commit c56716c69ce1 (\"netfilter: extensions: introduce extension genid count\") this patch disables all ct extensions (leading to NULL) for unconfirmed conntracks, when this is only targeted at ct helper and ct timeout. There is also codebase that dereferences the ct extension without checking for NULL which could lead to crash.","cvss":[],"epss":[{"cve":"CVE-2026-80636","epss":0.00168,"percentile":0.06319,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80636","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80636","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/35e21a4dccc5c255ba59ccfbfeb4629ed21da972","https://git.kernel.org/stable/c/61eab1d0237eb513fe73e391a5926ee70092c325","https://git.kernel.org/stable/c/6bba4846f196d081bf553391d12b5a73dcc48685","https://git.kernel.org/stable/c/a052a94bcc629acaecc2ce42a4af77f8fa399757","https://git.kernel.org/stable/c/d53eecbca16f056abba274075cb15120ab062518"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: revert ct extension genid infrastructure\n\nThis infrastructure is not used anymore after moving ct timeout and\nhelper to use datapath refcount to track object use.\n\nRevert commit c56716c69ce1 (\"netfilter: extensions: introduce extension\ngenid count\") this patch disables all ct extensions (leading to NULL)\nfor unconfirmed conntracks, when this is only targeted at ct helper and\nct timeout. There is also codebase that dereferences the ct extension\nwithout checking for NULL which could lead to crash.","cvss":[],"epss":[{"cve":"CVE-2026-80636","epss":0.00168,"percentile":0.06319,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80636","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80637","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80637","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: synproxy: fix unaligned memory access in timestamp adjustment  Use get_unaligned_be32() and put_unaligned_be32() to safely read and write the timestamp fields. This prevents performance degradation due to unaligned memory access or even a crash on strict alignment architectures.  This follows the implementation of timestamp parsing in the networking stack at tcp_parse_options() and synproxy_parse_options().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80637","epss":0.00446,"percentile":0.37599,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.3345},"relatedVulnerabilities":[{"id":"CVE-2026-80637","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80637","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2b8e7aaa38002d8ee2f48d87b1f392eadd8e98c4","https://git.kernel.org/stable/c/5c9c67cf7a3d16051dfb90e98836f530964dfb8e","https://git.kernel.org/stable/c/992c20bc8a4aba220c8b95b467d049289778dad6","https://git.kernel.org/stable/c/ea3d2caa5bfacf5db5c1cad521ca5d9144edd9a7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: fix unaligned memory access in timestamp adjustment\n\nUse get_unaligned_be32() and put_unaligned_be32() to safely read and\nwrite the timestamp fields. This prevents performance degradation due to\nunaligned memory access or even a crash on strict alignment\narchitectures.\n\nThis follows the implementation of timestamp parsing in the networking\nstack at tcp_parse_options() and synproxy_parse_options().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80637","epss":0.00446,"percentile":0.37599,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80637","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80643","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80643","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  EDAC/igen6: Fix call trace due to missing release()  When unloading the igen6_edac driver, there is a call trace:    Device '(null)' does not have a release() function, it is broken and must be fixed.   See Documentation/core-api/kobject.rst.   WARNING: drivers/base/core.c:2567 at device_release+0x84/0x90, CPU#5: rmmod/127209   ...   RIP: 0010:device_release+0x84/0x90   Call Trace:    <TASK>    kobject_put+0x8c/0x220    put_device+0x17/0x30    igen6_unregister_mcis+0xa2/0xe0 [igen6_edac]    igen6_remove+0x82/0xb0 [igen6_edac]    ...  Fix the call trace by providing empty release() functions for the memory controller devices.","cvss":[],"epss":[{"cve":"CVE-2026-80643","epss":0.00166,"percentile":0.06129,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-80643","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80643","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/9a84ced0243c74aa431ec287555054c69e6167d1","https://git.kernel.org/stable/c/a341302c5126ef96bb45286224d67ef60a24281e","https://git.kernel.org/stable/c/ab1f9d466c7d83ab0d2a529e07984e53b5960dcd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/igen6: Fix call trace due to missing release()\n\nWhen unloading the igen6_edac driver, there is a call trace:\n\n  Device '(null)' does not have a release() function, it is broken and must be fixed.\n  See Documentation/core-api/kobject.rst.\n  WARNING: drivers/base/core.c:2567 at device_release+0x84/0x90, CPU#5: rmmod/127209\n  ...\n  RIP: 0010:device_release+0x84/0x90\n  Call Trace:\n   <TASK>\n   kobject_put+0x8c/0x220\n   put_device+0x17/0x30\n   igen6_unregister_mcis+0xa2/0xe0 [igen6_edac]\n   igen6_remove+0x82/0xb0 [igen6_edac]\n   ...\n\nFix the call trace by providing empty release() functions for the\nmemory controller devices.","cvss":[],"epss":[{"cve":"CVE-2026-80643","epss":0.00166,"percentile":0.06129,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80643","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80650","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80650","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  media: atomisp: gc2235: fix UAF and memory leak  gc2235_probe() handles its error paths incorrectly.  If media_entity_pads_init() fails, gc2235_remove() is called, which tears down the subdev and frees dev, but then still falls through to atomisp_register_i2c_module(). This results in use-after-free.  If atomisp_register_i2c_module() fails, the media entity and control handler are left initialized and dev is leaked.  gc2235_remove() unconditionally calls media_entity_cleanup() and v4l2_ctrl_handler_free(), but these are not initialized at every error path in gc2235_probe().  Replace gc2235_remove() calls in the probe error paths with explicit unwind labels that free only the resources initialized at each point of failure, in reverse order of initialization.","cvss":[],"epss":[{"cve":"CVE-2026-80650","epss":0.00168,"percentile":0.06315,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80650","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80650","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/628f763aee0047ff44974388d6f70f75a763026b","https://git.kernel.org/stable/c/d57e67ea48e4d095052f2b14d8dd7593621f862f","https://git.kernel.org/stable/c/f614bf0a64aa1cb7444d152a96798a6bf1d49e1f","https://git.kernel.org/stable/c/fdbb8e55578b4ab647fa58827a9dd8730d7f4add"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: atomisp: gc2235: fix UAF and memory leak\n\ngc2235_probe() handles its error paths incorrectly.\n\nIf media_entity_pads_init() fails, gc2235_remove() is called, which\ntears down the subdev and frees dev, but then still falls through to\natomisp_register_i2c_module(). This results in use-after-free.\n\nIf atomisp_register_i2c_module() fails, the media entity and control\nhandler are left initialized and dev is leaked.\n\ngc2235_remove() unconditionally calls media_entity_cleanup() and\nv4l2_ctrl_handler_free(), but these are not initialized at every\nerror path in gc2235_probe().\n\nReplace gc2235_remove() calls in the probe error paths with explicit\nunwind labels that free only the resources initialized at each point\nof failure, in reverse order of initialization.","cvss":[],"epss":[{"cve":"CVE-2026-80650","epss":0.00168,"percentile":0.06315,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80650","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80653","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80653","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  scsi: hisi_sas: Add slave_destroy interface for v3 hw  WARNING is triggered when executing link reset of remote PHY and rmmod SAS driver simultaneously. Following is the WARNING log:  WARNING: CPU: 61 PID: 21818 at drivers/base/core.c:1347 __device_links_no_driver+0xb4/0xc0  Call trace:   __device_links_no_driver+0xb4/0xc0   device_links_driver_cleanup+0xb0/0xfc   __device_release_driver+0x198/0x23c   device_release_driver+0x38/0x50   bus_remove_device+0x130/0x140   device_del+0x184/0x434   __scsi_remove_device+0x118/0x150   scsi_remove_target+0x1bc/0x240   sas_rphy_remove+0x90/0x94   sas_rphy_delete+0x24/0x3c   sas_destruct_devices+0x64/0xa0 [libsas]   sas_revalidate_domain+0xe4/0x150 [libsas]   process_one_work+0x1e0/0x46c   worker_thread+0x15c/0x464   kthread+0x160/0x170   ret_from_fork+0x10/0x20  ---[ end trace 71e059eb58f85d4a ]---  During SAS phy up, link->status is set to DL_STATE_AVAILABLE in device_links_driver_bound, then this setting influences __device_links_no_driver() before driver rmmod and caused WARNING.  Add the slave_destroy interface to make sure link is removed after flush workque.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80653","epss":0.00142,"percentile":0.0383,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.11289000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80653","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80653","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/4867dba229292e13fc19ed865ec1839661952ff9","https://git.kernel.org/stable/c/67b85a88265df19f049241d8c00571a5408f4eeb","https://git.kernel.org/stable/c/cb414aff28e18e6f5cff9f87ea31376ed8af317b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Add slave_destroy interface for v3 hw\n\nWARNING is triggered when executing link reset of remote PHY and rmmod\nSAS driver simultaneously. Following is the WARNING log:\n\nWARNING: CPU: 61 PID: 21818 at drivers/base/core.c:1347 __device_links_no_driver+0xb4/0xc0\n Call trace:\n  __device_links_no_driver+0xb4/0xc0\n  device_links_driver_cleanup+0xb0/0xfc\n  __device_release_driver+0x198/0x23c\n  device_release_driver+0x38/0x50\n  bus_remove_device+0x130/0x140\n  device_del+0x184/0x434\n  __scsi_remove_device+0x118/0x150\n  scsi_remove_target+0x1bc/0x240\n  sas_rphy_remove+0x90/0x94\n  sas_rphy_delete+0x24/0x3c\n  sas_destruct_devices+0x64/0xa0 [libsas]\n  sas_revalidate_domain+0xe4/0x150 [libsas]\n  process_one_work+0x1e0/0x46c\n  worker_thread+0x15c/0x464\n  kthread+0x160/0x170\n  ret_from_fork+0x10/0x20\n ---[ end trace 71e059eb58f85d4a ]---\n\nDuring SAS phy up, link->status is set to DL_STATE_AVAILABLE in\ndevice_links_driver_bound, then this setting influences\n__device_links_no_driver() before driver rmmod and caused WARNING.\n\nAdd the slave_destroy interface to make sure link is removed after flush\nworkque.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80653","epss":0.00142,"percentile":0.0383,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80653","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80654","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80654","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  soc: xilinx: Shutdown and free rx mailbox channel  A mbox rx channel is requested using mbox_request_channel_byname() in probe. In remove callback, the rx mailbox channel is cleaned up when the rx_chan is NULL due to incorrect condition check. The mailbox channel is not shutdown and it can receive messages even after the device removal. This leads to use after free. Also the channel resources are not freed. Fix this by checking the rx_chan correctly.","cvss":[],"epss":[{"cve":"CVE-2026-80654","epss":0.00168,"percentile":0.0632,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80654","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80654","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/a83e77d1e52c01c50096e6e97c57d34e0590d628","https://git.kernel.org/stable/c/b0f748c563921a7918c78e6a599cefd54de7d688","https://git.kernel.org/stable/c/b5d2240c2c7bc8370e7ba54a2e1fe3919f55aee5","https://git.kernel.org/stable/c/fdee7c66c0d7b6869c36b9f9a915abf29ab5b550"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: xilinx: Shutdown and free rx mailbox channel\n\nA mbox rx channel is requested using mbox_request_channel_byname() in\nprobe. In remove callback, the rx mailbox channel is cleaned up when the\nrx_chan is NULL due to incorrect condition check. The mailbox channel is\nnot shutdown and it can receive messages even after the device removal.\nThis leads to use after free. Also the channel resources are not freed.\nFix this by checking the rx_chan correctly.","cvss":[],"epss":[{"cve":"CVE-2026-80654","epss":0.00168,"percentile":0.0632,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80654","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80668","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80668","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack_expect: use conntrack GC to reap expectations  This patch replaces the timer API by GC worker approach for expectations, as it already happened in many other subsystems.  Use the existing conntrack GC worker to iterate over the local list of expectations in the master conntrack to reap expired expectations. Check IPS_HELPER_BIT to run GC for expectations, set it on for nft_ct expectation which nevers sets it. Hold the expectation spinlock while iterating over the master conntrack expectation list to synchronize with nf_ct_remove_expectations(). This also performs runtime packet path garbage collection through the expectation insertion and lookup functions while walking over one of the chains of the global expectation hashtables. Unconfirmed conntrack entries are skipped since ct->ext can be reallocated and dying are skipped since those will be gone soon. Set on IPS_HELPER_BIT if the helper ct extension is added, then the new GC worker does not need to bump the ct refcount to check if the ct->ext helper is available.  This removes the extra bump on the refcount for expectation timers, this allows to remove several nf_ct_expect_put() calls after the unlink, after this update only refcount remains at 1 while on the expectation hashes.  This patch implicitly addresses a race with the existing timer API allowing an expectation to access a stale exp->master pointer which has been already released when expectation removal loses races with an expiring timer, ie. timer_del() reporting false.  Add a new NF_CT_EXPECT_DEAD flag to reap this expectation via GC. This is needed by nf_conntrack_unexpect_related() which is called in error paths to invalidate newly created expectations that has been added into the hashes. These expectactions cannot be inmediately released as GC or nf_ct_remove_expectations() could race to make it. On expectation insert, the runtime GC reaps stale expectations before checking the expectation limit set by policy.  Set current timestamp in nf_ct_expect_alloc(), then add the expectation policy timeout (or custom timeout specified added on top of this) to specify the expectation lifetime.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80668","epss":0.00379,"percentile":0.31251,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.35626},"relatedVulnerabilities":[{"id":"CVE-2026-80668","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80668","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/7ec786f4230c2a9b2eaf97a2d45368933b49d2b2","https://git.kernel.org/stable/c/b8b09dc2bf35a00d4e0556b5d6308c7b917ebda2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_expect: use conntrack GC to reap expectations\n\nThis patch replaces the timer API by GC worker approach for\nexpectations, as it already happened in many other subsystems.\n\nUse the existing conntrack GC worker to iterate over the local list of\nexpectations in the master conntrack to reap expired expectations.\nCheck IPS_HELPER_BIT to run GC for expectations, set it on for nft_ct\nexpectation which nevers sets it. Hold the expectation spinlock while\niterating over the master conntrack expectation list to synchronize with\nnf_ct_remove_expectations(). This also performs runtime packet path\ngarbage collection through the expectation insertion and lookup\nfunctions while walking over one of the chains of the global expectation\nhashtables. Unconfirmed conntrack entries are skipped since ct->ext can\nbe reallocated and dying are skipped since those will be gone soon.\nSet on IPS_HELPER_BIT if the helper ct extension is added, then the new\nGC worker does not need to bump the ct refcount to check if the ct->ext\nhelper is available.\n\nThis removes the extra bump on the refcount for expectation timers, this\nallows to remove several nf_ct_expect_put() calls after the unlink,\nafter this update only refcount remains at 1 while on the expectation\nhashes.\n\nThis patch implicitly addresses a race with the existing timer API\nallowing an expectation to access a stale exp->master pointer which has\nbeen already released when expectation removal loses races with an\nexpiring timer, ie. timer_del() reporting false.\n\nAdd a new NF_CT_EXPECT_DEAD flag to reap this expectation via GC. This\nis needed by nf_conntrack_unexpect_related() which is called in error\npaths to invalidate newly created expectations that has been added into\nthe hashes. These expectactions cannot be inmediately released as GC or\nnf_ct_remove_expectations() could race to make it. On expectation\ninsert, the runtime GC reaps stale expectations before checking the\nexpectation limit set by policy.\n\nSet current timestamp in nf_ct_expect_alloc(), then add the expectation\npolicy timeout (or custom timeout specified added on top of this) to\nspecify the expectation lifetime.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80668","epss":0.00379,"percentile":0.31251,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80668","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80670","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80670","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf tools: Use perf_env__get_cpu_topology() in machine__resolve()  machine__resolve() accesses env->cpu[al->cpu].socket_id after checking al->cpu >= 0 and env->cpu != NULL, but without validating al->cpu against env->nr_cpus_avail.  Since al->cpu comes from the untrusted perf.data sample, a crafted file with a large CPU index causes an out-of-bounds heap read.  Use perf_env__get_cpu_topology() which validates both NULL and bounds. Also bounds-check al->cpu before the cast to struct perf_cpu (int16_t): without this, values like 65536 silently truncate to 0, bypassing the accessor's internal check and returning CPU 0's topology.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80670","epss":0.00475,"percentile":0.39609,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.42987499999999995},"relatedVulnerabilities":[{"id":"CVE-2026-80670","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80670","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/5484b43a0ec8231c36fba6ead654cb72dbba8b8f","https://git.kernel.org/stable/c/b9e8406651dcc1c19238aad11861a758683525b4","https://git.kernel.org/stable/c/eb266a14c16a93eb4db7b56a452d6be93f8bdcd4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf tools: Use perf_env__get_cpu_topology() in machine__resolve()\n\nmachine__resolve() accesses env->cpu[al->cpu].socket_id after checking\nal->cpu >= 0 and env->cpu != NULL, but without validating al->cpu\nagainst env->nr_cpus_avail.  Since al->cpu comes from the untrusted\nperf.data sample, a crafted file with a large CPU index causes an\nout-of-bounds heap read.\n\nUse perf_env__get_cpu_topology() which validates both NULL and bounds.\nAlso bounds-check al->cpu before the cast to struct perf_cpu (int16_t):\nwithout this, values like 65536 silently truncate to 0, bypassing the\naccessor's internal check and returning CPU 0's topology.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"exploitabilityScore":3.9,"impactScore":5.2},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80670","epss":0.00475,"percentile":0.39609,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80670","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80671","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80671","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  perf sched: Fix register_pid() overflow, strcpy, and BUG_ON  register_pid() has several issues when processing untrusted perf.data:  1. Integer overflow: (pid + 1) * sizeof(struct task_desc *) can wrap    to a small value on 32-bit systems when pid is large (e.g.    0x40000000), causing realloc to return a tiny buffer followed by    out-of-bounds writes in the initialization loop.  2. Heap buffer overflow: strcpy(task->comm, comm) copies the    untrusted comm string into a fixed 20-byte COMM_LEN buffer with    no length check.  3. BUG_ON on allocation failure: perf.data is untrusted input, so    allocation failures should be handled gracefully rather than    killing the process.  4. Realloc of sched->tasks assigned directly back, leaking the old    pointer on failure; nr_tasks incremented before the realloc,    leaving corrupted state on failure.  Cap pid at PID_MAX_LIMIT (4194304, matching the kernel's maximum on 64-bit), replace strcpy with strlcpy, guard against NULL comm, replace BUG_ON with NULL returns using safe realloc patterns, and add NULL checks in callers that dereference the result.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80671","epss":0.00157,"percentile":0.05169,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.143655},"relatedVulnerabilities":[{"id":"CVE-2026-80671","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80671","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/5949d339f5ec98752d56dcd4e36f619a59d513a5","https://git.kernel.org/stable/c/5ea1dcc9418c4e06ce29ed5170596f497ba86872","https://git.kernel.org/stable/c/652cea73b7b7b7c622a2be670e44e3c499c6d49f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf sched: Fix register_pid() overflow, strcpy, and BUG_ON\n\nregister_pid() has several issues when processing untrusted perf.data:\n\n1. Integer overflow: (pid + 1) * sizeof(struct task_desc *) can wrap\n   to a small value on 32-bit systems when pid is large (e.g.\n   0x40000000), causing realloc to return a tiny buffer followed by\n   out-of-bounds writes in the initialization loop.\n\n2. Heap buffer overflow: strcpy(task->comm, comm) copies the\n   untrusted comm string into a fixed 20-byte COMM_LEN buffer with\n   no length check.\n\n3. BUG_ON on allocation failure: perf.data is untrusted input, so\n   allocation failures should be handled gracefully rather than\n   killing the process.\n\n4. Realloc of sched->tasks assigned directly back, leaking the old\n   pointer on failure; nr_tasks incremented before the realloc,\n   leaving corrupted state on failure.\n\nCap pid at PID_MAX_LIMIT (4194304, matching the kernel's maximum\non 64-bit), replace strcpy with strlcpy, guard against NULL comm,\nreplace BUG_ON with NULL returns using safe realloc patterns, and\nadd NULL checks in callers that dereference the result.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80671","epss":0.00157,"percentile":0.05169,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80671","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80676","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80676","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Drivers: hv: vmbus: use generic driver_override infrastructure  When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF.  Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally.  Note that calling match() from __driver_attach() without the device lock held is intentional. [1]","cvss":[],"epss":[{"cve":"CVE-2026-80676","epss":0.00168,"percentile":0.06313,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80676","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80676","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0e2f0833556c8c5269deb457b89d538644a3b747","https://git.kernel.org/stable/c/2fb010ea7ca98cd09a6d365260b769f627e73a76","https://git.kernel.org/stable/c/331d8900121a1d74ecd45cd2db742ddcb5a0a565","https://git.kernel.org/stable/c/d1cb12ae81d2f7a58b0b1cfb51862afca98e6058"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]","cvss":[],"epss":[{"cve":"CVE-2026-80676","epss":0.00168,"percentile":0.06313,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80676","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80678","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80678","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i2c: imx: Fix slave registration race and error handling  In i2c_imx_reg_slave(), the slave pointer was assigned before pm_runtime_resume_and_get().  If pm_runtime_resume_and_get() failed, the error path returned without clearing i2c_imx->slave, leaving it non-NULL and causing all subsequent registration attempts to fail with -EBUSY.  Additionally, because this driver uses a shared IRQ, the interrupt handler i2c_imx_isr() can execute concurrently and, after acquiring slave_lock, dereference i2c_imx->slave.  The previous fix attempt added a lockless i2c_imx->slave = NULL on the error path, but that could race with the ISR under the lock and still cause a NULL pointer dereference.  Fix both issues by deferring the assignment of i2c_imx->slave and i2c_imx->last_slave_event to after a successful resume, and by performing the assignment inside the slave_lock critical section. This guarantees that the slave pointer is never left stale on the error path and is always valid when observed by the interrupt handler.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80678","epss":0.00144,"percentile":0.03977,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11448000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80678","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80678","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/12a4f0950a158d98552cbaeacc35edccd8d975fa","https://git.kernel.org/stable/c/614ca6594e301ff682999797c2216e9685558a2b","https://git.kernel.org/stable/c/754bc62f72fd64b202462367134ac8ce95b005de","https://git.kernel.org/stable/c/b9f6f4883b9ac86654e75899d0dbf8a7a96ad5d8","https://git.kernel.org/stable/c/cfdf6e13518589f911b7eace6ccb788e4ed87397","https://git.kernel.org/stable/c/d64ec362c369bbc33833f7936d5f3a706b0d5c45","https://git.kernel.org/stable/c/d6748f6802f3eebafaa16a5e5dcfbfb9b3bc173f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: Fix slave registration race and error handling\n\nIn i2c_imx_reg_slave(), the slave pointer was assigned before\npm_runtime_resume_and_get().  If pm_runtime_resume_and_get() failed,\nthe error path returned without clearing i2c_imx->slave, leaving it\nnon-NULL and causing all subsequent registration attempts to fail\nwith -EBUSY.\n\nAdditionally, because this driver uses a shared IRQ, the interrupt\nhandler i2c_imx_isr() can execute concurrently and, after acquiring\nslave_lock, dereference i2c_imx->slave.  The previous fix attempt\nadded a lockless i2c_imx->slave = NULL on the error path, but that\ncould race with the ISR under the lock and still cause a NULL pointer\ndereference.\n\nFix both issues by deferring the assignment of i2c_imx->slave and\ni2c_imx->last_slave_event to after a successful resume, and by\nperforming the assignment inside the slave_lock critical section.\nThis guarantees that the slave pointer is never left stale on the\nerror path and is always valid when observed by the interrupt handler.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80678","epss":0.00144,"percentile":0.03977,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80678","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80679","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80679","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/dasd: Fix potential NULL pointer dereference  dasd_release_space() checks the implementation of the is_ese() discipline function before calling it to determine if a given device is an ESE DASD.  The current usage of the logical AND operator will lead to a NULL pointer dereference as the function is called even if the function pointer is NULL.  Fix this by using the logical OR operator.","cvss":[],"epss":[{"cve":"CVE-2026-80679","epss":0.00176,"percentile":0.07302,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08800000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80679","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80679","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3000367a512b1283ca52230bf21f8c91dfbec45b","https://git.kernel.org/stable/c/3453a993a3f14c1684560ecf26585046976f6ac6","https://git.kernel.org/stable/c/86cdfd061509bcde84f3145f7221ba64e3e53b1f","https://git.kernel.org/stable/c/96b8e09b09539f252a5eeea6baebd93c2e3779bd","https://git.kernel.org/stable/c/9973026f572db6b67570cadc30942f3014e41079","https://git.kernel.org/stable/c/cdc7b73d0c5a9cd6360b4f8c36eae23b02097e4c","https://git.kernel.org/stable/c/dbf2ae34d2f1390a9fc1abf3dce7f809e022caae","https://git.kernel.org/stable/c/e156c70c505c6c9adce3b7be5a82025f00544709"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: Fix potential NULL pointer dereference\n\ndasd_release_space() checks the implementation of the is_ese()\ndiscipline function before calling it to determine if a given device is\nan ESE DASD.\n\nThe current usage of the logical AND operator will lead to a NULL\npointer dereference as the function is called even if the function\npointer is NULL.\n\nFix this by using the logical OR operator.","cvss":[],"epss":[{"cve":"CVE-2026-80679","epss":0.00176,"percentile":0.07302,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80679","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80680","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80680","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  i2c: amd-mp2: Unregister callback on adapter add failure  amd_mp2_register_cb() stores the platform I2C context in the MP2 PCI driver's callback table before the adapter is registered. If i2c_add_adapter() fails, probe returns and devres frees the context, but the PCI driver can still dereference the stale pointer from its IRQ and system-sleep callbacks.  Unregister the callback before returning the adapter registration error.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80680","epss":0.00129,"percentile":0.02872,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09868500000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80680","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80680","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1883a09a37fed497b9efacf736c23624a472246b","https://git.kernel.org/stable/c/2f7789b3a9628819ebf90bcba8f9da3c139f8687","https://git.kernel.org/stable/c/4786d4d70dcd1e6b7e044f2348e00f201947b69c","https://git.kernel.org/stable/c/82048795242f04275a3f49ffc66ad851b6120954","https://git.kernel.org/stable/c/8bf719659406e4a1b56d441e0c7da2085d891d96","https://git.kernel.org/stable/c/9142a3dcff0d80a3a24ce159aee19ddc869d9784","https://git.kernel.org/stable/c/b7c2c5c8868737926410b93d1223ada17625ead3","https://git.kernel.org/stable/c/cf107c5983dc70fcf932a305581a5f976d908ff1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: amd-mp2: Unregister callback on adapter add failure\n\namd_mp2_register_cb() stores the platform I2C context in the MP2 PCI\ndriver's callback table before the adapter is registered. If\ni2c_add_adapter() fails, probe returns and devres frees the context,\nbut the PCI driver can still dereference the stale pointer from its IRQ\nand system-sleep callbacks.\n\nUnregister the callback before returning the adapter registration error.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80680","epss":0.00129,"percentile":0.02872,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80680","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80681","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80681","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: re-fetch eth header after route_shortcircuit()  Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb).  Inside route_shortcircuit(), pskb_may_pull() can be called, which may reallocate skb->head.  In this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to freed memory, leading to a use-after-free when dereferencing eth->h_dest.  Fix this by updating eth = eth_hdr(skb) after calling route_shortcircuit().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80681","epss":0.00506,"percentile":0.41579,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.47564000000000006},"relatedVulnerabilities":[{"id":"CVE-2026-80681","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80681","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/1235e017aa11cf01e91b613c4c5ed6aa28934fff","https://git.kernel.org/stable/c/1395a676ec15a0a02a2a6d86602324f2d5fd41d5","https://git.kernel.org/stable/c/1511631b7cfc4152b10a0a9d04c7a0bf2ddf4585","https://git.kernel.org/stable/c/1b7f7b653e3557690047c62f03b80a24ea5a58a5","https://git.kernel.org/stable/c/2355c8c26d2aa1b4385b369e67202e47d460d555","https://git.kernel.org/stable/c/6375093eb45cd7d89f1945f939eeae3b29d79f56","https://git.kernel.org/stable/c/bf045341dfb3e767f0ff94cf240ce3c371973bd4","https://git.kernel.org/stable/c/c9dceac9e1c7c772c43c732fc0d325e72835801a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: re-fetch eth header after route_shortcircuit()\n\nBefore route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb).\n\nInside route_shortcircuit(), pskb_may_pull() can be called, which may\nreallocate skb->head.\n\nIn this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to\nfreed memory, leading to a use-after-free when dereferencing eth->h_dest.\n\nFix this by updating eth = eth_hdr(skb) after calling route_shortcircuit().","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80681","epss":0.00506,"percentile":0.41579,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80681","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80684","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80684","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: s390: pci: Fix NULL dereference on AIBV allocation failure  The airq_iv_create() can return NULL on failure, but the return value was never checked. If it fails, zdev->aibv will be NULL and fail when dereferenced in kvm_zpci_set_airq(). Add a NULL check and free the previously allocated AISB bit and zdev->aisb on failure.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80684","epss":0.00144,"percentile":0.03978,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.13176000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80684","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80684","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0a95abe964400771ad82b027d7b84a0d183cd0db","https://git.kernel.org/stable/c/8bf09b9b7d3232806df95f409581f8a9fd99a3fa","https://git.kernel.org/stable/c/96099486b63985801c9c6ef22505e9aa635b2d20","https://git.kernel.org/stable/c/d1a103dc9016c25e7423ce5841a5cc2df76d59f3","https://git.kernel.org/stable/c/df947d85e164a50a29d43a96e814f69ab1d0f7ed","https://git.kernel.org/stable/c/e137d082325bbcae780087b57501d38585e625d9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Fix NULL dereference on AIBV allocation failure\n\nThe airq_iv_create() can return NULL on failure, but the return value was\nnever checked. If it fails, zdev->aibv will be NULL and fail when\ndereferenced in kvm_zpci_set_airq(). Add a NULL check and free the\npreviously allocated AISB bit and zdev->aisb on failure.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80684","epss":0.00144,"percentile":0.03978,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80684","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80686","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80686","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE  pte_pfn() and pte_dirty() have undefined behaviour when called on a non-present PTE. In migrate_vma_collect_pmd(), these functions may be invoked on non-present entries (e.g., device-private entries), leading to potential crashes from pte_pfn() or incorrect dirty folio accounting from pte_dirty(). Fix both by guarding with pte_present() checks.","cvss":[],"epss":[{"cve":"CVE-2026-80686","epss":0.00172,"percentile":0.06807,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.086},"relatedVulnerabilities":[{"id":"CVE-2026-80686","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80686","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/26f9ca8ed42cba25d2c75daff13561cce6019395","https://git.kernel.org/stable/c/2be94d6b20789b8865b1864dae5fe458ca85e019","https://git.kernel.org/stable/c/42f30fa5481a1f90571ccdfbb20d2e25e47ae76e","https://git.kernel.org/stable/c/5b948706f11a950bc73c5304630d0a7eafc40daf","https://git.kernel.org/stable/c/63867c82d0c0c2d182016a32b1cc0103116b0ea5","https://git.kernel.org/stable/c/86d55447de3738620b9a8272ff167ce97e7f7203"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE\n\npte_pfn() and pte_dirty() have undefined behaviour when called on a\nnon-present PTE. In migrate_vma_collect_pmd(), these functions may be\ninvoked on non-present entries (e.g., device-private entries), leading\nto potential crashes from pte_pfn() or incorrect dirty folio accounting\nfrom pte_dirty(). Fix both by guarding with pte_present() checks.","cvss":[],"epss":[{"cve":"CVE-2026-80686","epss":0.00172,"percentile":0.06807,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80686","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80689","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80689","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions  mmio_trace_rw() and mmio_trace_mapping() retrieve mmio_trace_array into tr and pass it to __trace_mmiotrace_rw() and __trace_mmiotrace_map(). If these functions are invoked while mmio_trace_array is NULL (e.g. before initialization or after disabled), accessing tr->array_buffer.buffer will result in a NULL pointer dereference crash.  Fix this by adding an explicit NULL check for tr at the beginning of __trace_mmiotrace_rw() and __trace_mmiotrace_map().","cvss":[],"epss":[{"cve":"CVE-2026-80689","epss":0.00168,"percentile":0.06316,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80689","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80689","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/12b80cdbc54cf615b4717a4e8180063408091ea2","https://git.kernel.org/stable/c/60234845142fddb27db89ebc00a65178421fb3a4","https://git.kernel.org/stable/c/876014b4eeb927146430e7591cf959a7ceb8d64a","https://git.kernel.org/stable/c/a20a0010eb6485f60cd64e15ebc85a4bd388642e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions\n\nmmio_trace_rw() and mmio_trace_mapping() retrieve mmio_trace_array into\ntr and pass it to __trace_mmiotrace_rw() and __trace_mmiotrace_map().\nIf these functions are invoked while mmio_trace_array is NULL (e.g. before\ninitialization or after disabled), accessing tr->array_buffer.buffer will\nresult in a NULL pointer dereference crash.\n\nFix this by adding an explicit NULL check for tr at the beginning of\n__trace_mmiotrace_rw() and __trace_mmiotrace_map().","cvss":[],"epss":[{"cve":"CVE-2026-80689","epss":0.00168,"percentile":0.06316,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80689","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80694","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80694","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller  mtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq cookie), but mtk_poll_controller incorrectly passed the net_device *. Calling ndo_poll_controller with CONFIG_NET_POLL_CONTROLLER enabled would then crash.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80694","epss":0.00463,"percentile":0.38751,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.43521999999999994},"relatedVulnerabilities":[{"id":"CVE-2026-80694","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80694","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/276f1f180f55d56cf5992a581e20ed2b3dfa6ced","https://git.kernel.org/stable/c/3bd58ac9ca0c552651f533c1bd280dd19ae7d4e8","https://git.kernel.org/stable/c/7eb46318d53940dab63dea7130e720b67a656104","https://git.kernel.org/stable/c/e095f249e2209674f6366f6db0383a2b96e19239"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller\n\nmtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq\ncookie), but mtk_poll_controller incorrectly passed the net_device *.\nCalling ndo_poll_controller with CONFIG_NET_POLL_CONTROLLER enabled\nwould then crash.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80694","epss":0.00463,"percentile":0.38751,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80694","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80695","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80695","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  hwmon: (sht3x) Fix unaligned accesses  Sashiko reports:  In sht3x_update_client(), the 16-bit temperature and humidity values are extracted from a stack-allocated byte array using be16_to_cpup(). The pointers passed to this function are calculated as buf and buf + 3. Since the difference between the two pointers is an odd number of bytes, at least one of them is guaranteed to be at an unaligned offset.  This will trigger an alignment fault on strict-alignment architectures such as ARMv5 or SPARC, resulting in a kernel panic.  Fix the problem by using get_unaligned_be16() instead of be16_to_cpup(), and put_unaligned_be16() instead of cpu_to_be16().","cvss":[],"epss":[{"cve":"CVE-2026-80695","epss":0.00168,"percentile":0.06313,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80695","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80695","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1fb41650bc3e14d2a5ddb4bb25e96811e5afe881","https://git.kernel.org/stable/c/81529add4a2e3cca9240e0e2342973d62f88f02e","https://git.kernel.org/stable/c/c498adfd4c3e85306ccdc19b76e639bfc215f0e7","https://git.kernel.org/stable/c/f46d5ab43a572b84773015a76966f5da56fc1748"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (sht3x) Fix unaligned accesses\n\nSashiko reports:\n\nIn sht3x_update_client(), the 16-bit temperature and humidity values are\nextracted from a stack-allocated byte array using be16_to_cpup(). The\npointers passed to this function are calculated as buf and buf + 3. Since\nthe difference between the two pointers is an odd number of bytes, at\nleast one of them is guaranteed to be at an unaligned offset.\n\nThis will trigger an alignment fault on strict-alignment architectures\nsuch as ARMv5 or SPARC, resulting in a kernel panic.\n\nFix the problem by using get_unaligned_be16() instead of be16_to_cpup(),\nand put_unaligned_be16() instead of cpu_to_be16().","cvss":[],"epss":[{"cve":"CVE-2026-80695","epss":0.00168,"percentile":0.06313,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80695","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80698","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80698","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: idxd: fix double free of wq, engine, and group structs  The release callbacks for wq, engine, and group devices (idxd_conf_wq_release, idxd_conf_engine_release, idxd_conf_group_release) each call kfree() on the enclosing struct. The setup error paths and cleanup functions also call kfree() explicitly after put_device(), producing a double free whenever put_device() drops the reference count to zero and fires the release.  In the setup functions, device_initialize() is called before device_add(), so the reference count is exactly 1 at the error sites. put_device() unconditionally fires the release, which frees the struct; the subsequent explicit kfree() then operates on freed memory.  For idxd_setup_wqs(), the wq release callback also owns opcap_bmap and wqcfg. The error unwind additionally freed those fields explicitly before calling put_device(), causing further double frees on both.  Remove the redundant explicit kfree() calls from all setup error paths and cleanup functions for wq, engine, and group structs, delegating sole ownership of those allocations to the release callbacks.","cvss":[],"epss":[{"cve":"CVE-2026-80698","epss":0.00155,"percentile":0.04991,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-80698","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80698","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/c93a9f652b7373ac8ee5bfcc18a9af76959b6c6c","https://git.kernel.org/stable/c/ec2d428b2e32dd157de8f86a86dd85c5b2c8f45c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: fix double free of wq, engine, and group structs\n\nThe release callbacks for wq, engine, and group devices\n(idxd_conf_wq_release, idxd_conf_engine_release,\nidxd_conf_group_release) each call kfree() on the enclosing struct.\nThe setup error paths and cleanup functions also call kfree()\nexplicitly after put_device(), producing a double free whenever\nput_device() drops the reference count to zero and fires the release.\n\nIn the setup functions, device_initialize() is called before\ndevice_add(), so the reference count is exactly 1 at the error sites.\nput_device() unconditionally fires the release, which frees the struct;\nthe subsequent explicit kfree() then operates on freed memory.\n\nFor idxd_setup_wqs(), the wq release callback also owns opcap_bmap\nand wqcfg. The error unwind additionally freed those fields explicitly\nbefore calling put_device(), causing further double frees on both.\n\nRemove the redundant explicit kfree() calls from all setup error paths\nand cleanup functions for wq, engine, and group structs, delegating\nsole ownership of those allocations to the release callbacks.","cvss":[],"epss":[{"cve":"CVE-2026-80698","epss":0.00155,"percentile":0.04991,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80698","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80704","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80704","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: use proper context for logging  The same as the rest of the code, get_ss_info_from_atombios() uses calc_pll_cs->ctx->logger for logging. But calc_pll_cs->ctx is initialized only later in calc_pll_max_vco_construct(). Therefore, any output using DC_LOG_SYNC() leads to a NULL pointer deference in get_ss_info_from_atombios().  According to Sashiko, the very same problem exists in dce112_get_pix_clk_dividers() and dcn3_get_pix_clk_dividers() too.  To avoid accessing the NULL context, use clk_src->base.ctx->logger everywhere. That context in base is initialized earlier in dce110_clk_src_construct() and dce112_clk_src_construct(). Before get_ss_info_from_atombios() or Sashiko's get_pix_clk_dividers functions above are actually called. This is done by redefining DC_LOGGER to CTX->logger.  Before: dce110_clk_src_construct() did:  -> sets clk_src->base.ctx = ctx;  -> ss_info_from_atombios_create()    -> get_ss_info_from_atombios()   <- uses calc_pll_cs->ctx  # BOOM  -> calc_pll_max_vco_construct()    <- sets calc_pll_cs->ctx  After: dce110_clk_src_construct() does:  -> sets clk_src->base.ctx = ctx;  -> ss_info_from_atombios_create()    -> get_ss_info_from_atombios()   <- uses clk_src->base.ctx  (cherry picked from commit 6f16fcbb0c46a87e3d9685407e906573d60104b0)","cvss":[],"epss":[{"cve":"CVE-2026-80704","epss":0.00159,"percentile":0.05435,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0795},"relatedVulnerabilities":[{"id":"CVE-2026-80704","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80704","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/02647d98340738f918690ed227fdcf154db1b84a","https://git.kernel.org/stable/c/114b42507b6a23d9d24e24e4ef165233332c64d4","https://git.kernel.org/stable/c/a94e62b7c7018fcfe0251e53fa96af30f12d923a","https://git.kernel.org/stable/c/f556bc844cc4423e5ad41ae41a4c24f1cf75b978"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: use proper context for logging\n\nThe same as the rest of the code, get_ss_info_from_atombios() uses\ncalc_pll_cs->ctx->logger for logging. But calc_pll_cs->ctx is\ninitialized only later in calc_pll_max_vco_construct(). Therefore, any\noutput using DC_LOG_SYNC() leads to a NULL pointer deference in\nget_ss_info_from_atombios().\n\nAccording to Sashiko, the very same problem exists in\ndce112_get_pix_clk_dividers() and dcn3_get_pix_clk_dividers() too.\n\nTo avoid accessing the NULL context, use clk_src->base.ctx->logger\neverywhere. That context in base is initialized earlier in\ndce110_clk_src_construct() and dce112_clk_src_construct(). Before\nget_ss_info_from_atombios() or Sashiko's get_pix_clk_dividers functions\nabove are actually called. This is done by redefining DC_LOGGER to\nCTX->logger.\n\nBefore:\ndce110_clk_src_construct() did:\n -> sets clk_src->base.ctx = ctx;\n -> ss_info_from_atombios_create()\n   -> get_ss_info_from_atombios()   <- uses calc_pll_cs->ctx  # BOOM\n -> calc_pll_max_vco_construct()    <- sets calc_pll_cs->ctx\n\nAfter:\ndce110_clk_src_construct() does:\n -> sets clk_src->base.ctx = ctx;\n -> ss_info_from_atombios_create()\n   -> get_ss_info_from_atombios()   <- uses clk_src->base.ctx\n\n(cherry picked from commit 6f16fcbb0c46a87e3d9685407e906573d60104b0)","cvss":[],"epss":[{"cve":"CVE-2026-80704","epss":0.00159,"percentile":0.05435,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80704","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80706","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80706","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: softing: fw_parse(): validate firmware record spans  fw_parse() reads a fixed record header, a firmware-provided payload, and a trailing checksum without knowing the end of the firmware blob. A truncated record can therefore make those reads exceed the blob.  The same record also supplies addresses and lengths for writes into DPRAM. The generic loader uses wrap-prone mixed signed arithmetic for its bounds check, while the application loader does not bound the staging copy at all.  Pass the firmware end to the parser and validate the full source record. Use a signed wide offset for generic DPRAM records and validate the application staging span against the mapped DPRAM before copying.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80706","epss":0.0012,"percentile":0.02073,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80706","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80706","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/2ee477e541a6d5e434d6a4041c6b677ab42e1d82","https://git.kernel.org/stable/c/808ed899dcf8bdef66894fda5eb7ee4bb0eb8dc1","https://git.kernel.org/stable/c/84c850b08fc0d671c245144b619683129b55690a","https://git.kernel.org/stable/c/856d6cb04e5407523566b075841dcd6423757d1c","https://git.kernel.org/stable/c/ad331e26fd213a19fee0de18cdacd67b7ff5b478","https://git.kernel.org/stable/c/ae588e5b9cc268de1aabf30f939f0870717ca164","https://git.kernel.org/stable/c/d0eac0ea7cf493e787fd7b4a556e43ef03cb4b50","https://git.kernel.org/stable/c/f6d9a6a9512430b395a1940d7b216394fd02d30b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: softing: fw_parse(): validate firmware record spans\n\nfw_parse() reads a fixed record header, a firmware-provided payload,\nand a trailing checksum without knowing the end of the firmware blob. A\ntruncated record can therefore make those reads exceed the blob.\n\nThe same record also supplies addresses and lengths for writes into\nDPRAM. The generic loader uses wrap-prone mixed signed arithmetic for its\nbounds check, while the application loader does not bound the staging\ncopy at all.\n\nPass the firmware end to the parser and validate the full source record.\nUse a signed wide offset for generic DPRAM records and validate the\napplication staging span against the mapped DPRAM before copying.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80706","epss":0.0012,"percentile":0.02073,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80706","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80707","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80707","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer  Zero the allocated buffer in j1939_session_fresh_new() to ensure it contains no residual data.  While there is a potential performance impact if users allocate maximum sized ETP buffers, most real-world use cases are not noticeably affected since the maximum known buffer size is typically around 65K.  [mkl: add Message-ID]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80707","epss":0.00329,"percentile":0.25748,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.24675},"relatedVulnerabilities":[{"id":"CVE-2026-80707","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80707","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/038bad8e16c2e28acf31f0b527a816fb23a57269","https://git.kernel.org/stable/c/194d67e92197eb820f4c2c6605d9721333b3eba0","https://git.kernel.org/stable/c/348818277a3646d5b9fa60c9d20c00dc4bc86832","https://git.kernel.org/stable/c/8604a3b81b9d0ceaf04fee5f52e701f623a179f9","https://git.kernel.org/stable/c/bbfa49d1e287de44994955b44d19281be3195b44","https://git.kernel.org/stable/c/d5b3613c7d69d8dcb4dd6704f1f463198ce9f6cf","https://git.kernel.org/stable/c/eb96c58907922546e415e545fe9a14ea63b02719","https://git.kernel.org/stable/c/f3e120a34b336079479fa10f706f0636eaa6e751"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: transport: j1939_session_fresh_new(): initialize receive buffer\n\nZero the allocated buffer in j1939_session_fresh_new() to ensure it\ncontains no residual data.\n\nWhile there is a potential performance impact if users allocate maximum\nsized ETP buffers, most real-world use cases are not noticeably affected\nsince the maximum known buffer size is typically around 65K.\n\n[mkl: add Message-ID]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80707","epss":0.00329,"percentile":0.25748,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80707","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80708","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80708","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()  The helper function _ip_cprb_helper() uses internal buffer memory for building and processing CPRBs. After use this buffer was never scrubbed which could lead to leaving for example clear key material in memory which could be exposed via tricky reuse of this same memory.  Extend the _ip_cprb_helper() function with another parameter 'scrub' used to steer scrubbing of this buffer. So now the caller has the opportunity to decide if scrubbing is needed or not.  Extend the clear key to secure key token import process in function cca_clr2cipherkey() to tell the helper function from above to scrub the cprb buffer when the clear key value is part of the request data.  Add explicit scrubbing on return from function cca_clr2cipherkey() for the random EXOR buffer and the cprb buffer.  Overall this cleans the internal used buffer in case of clear key import to prevent sensitive data to get exposed.","cvss":[],"epss":[{"cve":"CVE-2026-80708","epss":0.00164,"percentile":0.05948,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.082},"relatedVulnerabilities":[{"id":"CVE-2026-80708","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80708","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/01476391aecef36a3b789ee844357b22fbc90665","https://git.kernel.org/stable/c/4e26d0d72bfdec311f12acfa0c6b7fbeb6a343d3","https://git.kernel.org/stable/c/7dd6e556dbfc91d3d511cfd1015d2dad42608010","https://git.kernel.org/stable/c/8e1c0def77b7450be0ed607ed0d7bae629d30020","https://git.kernel.org/stable/c/b453003ae6a869f5bdf025b5519cbb38295ae4f1","https://git.kernel.org/stable/c/be7ae07fb745d1cf575b03a178a055b0a2859364","https://git.kernel.org/stable/c/ebfbb9ac7adbb1e3556100b54a27e8a9b102feac","https://git.kernel.org/stable/c/fbb0410986e8ad214121e51a4a28c3d0a10b7644"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()\n\nThe helper function _ip_cprb_helper() uses internal buffer memory for\nbuilding and processing CPRBs. After use this buffer was never\nscrubbed which could lead to leaving for example clear key material in\nmemory which could be exposed via tricky reuse of this same memory.\n\nExtend the _ip_cprb_helper() function with another parameter 'scrub'\nused to steer scrubbing of this buffer. So now the caller has the\nopportunity to decide if scrubbing is needed or not.\n\nExtend the clear key to secure key token import process in function\ncca_clr2cipherkey() to tell the helper function from above to scrub\nthe cprb buffer when the clear key value is part of the request data.\n\nAdd explicit scrubbing on return from function cca_clr2cipherkey() for\nthe random EXOR buffer and the cprb buffer.\n\nOverall this cleans the internal used buffer in case of clear key\nimport to prevent sensitive data to get exposed.","cvss":[],"epss":[{"cve":"CVE-2026-80708","epss":0.00164,"percentile":0.05948,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80708","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80709","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80709","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs  There is a wrong upper limit check for the domain value when an EP11 CPRB is processed for sending to a crypto card. This check is only active on custom device nodes but may lead to access heap memory behind perms->adm when an administrative CPRB is sent. Add correct limit (AP_DOMAINS = 256) checking to fix this.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80709","epss":0.0012,"percentile":0.02074,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80709","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80709","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1223477ca88e2396eca440919d0ca8754df79bd5","https://git.kernel.org/stable/c/13e53d6ae1c3b2ff1be75b9ef09be26f4ec3ce15","https://git.kernel.org/stable/c/4589f742718d0256ea6dd1f5a78be6e689bdb8aa","https://git.kernel.org/stable/c/672b12940e3f1336dfed5287412a71500adf2a76","https://git.kernel.org/stable/c/983279d7f86ade73db86f886e09172dd567031b5","https://git.kernel.org/stable/c/b505dcc8307d64468b463dfad45a03bf865c637e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Fix wrong domain value verification with EP11 CPRBs\n\nThere is a wrong upper limit check for the domain value when an EP11\nCPRB is processed for sending to a crypto card. This check is only\nactive on custom device nodes but may lead to access heap memory\nbehind perms->adm when an administrative CPRB is sent.\nAdd correct limit (AP_DOMAINS = 256) checking to fix this.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80709","epss":0.0012,"percentile":0.02074,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80709","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80710","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80710","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  s390/dasd: Fix undersized format-check buffer  fmt_buffer_size in dasd_eckd_check_device_format() is declared as int, even though one of the multiplicands, sizeof(struct eckd_count), is a size_t. The expression      trkcount * rpt_max * sizeof(struct eckd_count)  is therefore correctly evaluated at 64-bit width, but the result is silently truncated when it is stored back into the 32-bit fmt_buffer_size variable. For a sufficiently large track range (start_unit/stop_unit are caller-controlled) this truncation yields a buffer size far smaller than the number of tracks actually requested. kzalloc() then succeeds with an undersized allocation, while the subsequent channel program build still operates on the untruncated track count and writes past the end of that buffer.  Compute the buffer size with check_mul_overflow() and keep it in a size_t, so that a value that no longer fits results in -EINVAL instead of a silently truncated allocation size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80710","epss":0.0012,"percentile":0.02036,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80710","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80710","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/7f40b346462f563a0d6e841a77b5163d2a882a04","https://git.kernel.org/stable/c/87f3389cd3920714c53e704778f7ca7f1cf0c39c","https://git.kernel.org/stable/c/9f88dda2f22927d22498801a92cab6a9424eaf86","https://git.kernel.org/stable/c/aca18289c86f22d3fc2f3f6ff615286e7b1702f6","https://git.kernel.org/stable/c/e16e0fc54120cee3c6f0362de95aab6792865857"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: Fix undersized format-check buffer\n\nfmt_buffer_size in dasd_eckd_check_device_format() is declared as\nint, even though one of the multiplicands, sizeof(struct eckd_count),\nis a size_t. The expression\n\n    trkcount * rpt_max * sizeof(struct eckd_count)\n\nis therefore correctly evaluated at 64-bit width, but the result is\nsilently truncated when it is stored back into the 32-bit\nfmt_buffer_size variable. For a sufficiently large track range\n(start_unit/stop_unit are caller-controlled) this truncation\nyields a buffer size far smaller than the number of tracks actually\nrequested. kzalloc() then succeeds with an undersized allocation,\nwhile the subsequent channel program build still operates on the\nuntruncated track count and writes past the end of that buffer.\n\nCompute the buffer size with check_mul_overflow() and keep it in a\nsize_t, so that a value that no longer fits results in -EINVAL\ninstead of a silently truncated allocation size.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80710","epss":0.0012,"percentile":0.02036,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80710","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80714","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80714","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipvs: do not propagate one-packet flag to synced conns  Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the destination into cp->flags.  IP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced connection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed, expiry can treat it as a one-packet connection and skip unlinking the existing conn_tab node, leaving stale hash nodes pointing at a freed struct ip_vs_conn.  Drop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced connections.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80714","epss":0.00404,"percentile":0.33889,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.37976000000000004},"relatedVulnerabilities":[{"id":"CVE-2026-80714","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80714","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/06d1d9b56ef8132fbf85006885eb43d9510b8b02","https://git.kernel.org/stable/c/300348e3ba1521b003d59825f97e24f9a6859688","https://git.kernel.org/stable/c/44af98cc7d5ef8e730488d5df1eecd5deeaa5947","https://git.kernel.org/stable/c/4649e6faeecdc2d44bfa6ccbe405eef27e55d816","https://git.kernel.org/stable/c/a63d2dbaeb50a85d4c976b15a36e6b0c7113db5b","https://git.kernel.org/stable/c/acbdc276091b308ca7794acb86e761f8203e2f59","https://git.kernel.org/stable/c/b5ee5b266f833601ac4817f6df0bc496fc376a28","https://git.kernel.org/stable/c/e7acfc990c29890c883d0d0ce3f737d003a43b44"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: do not propagate one-packet flag to synced conns\n\nSynced connections can be created before their destination exists. When\nthe destination is later added, ip_vs_bind_dest() copies connection flags\nfrom the destination into cp->flags.\n\nIP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced\nconnection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed,\nexpiry can treat it as a one-packet connection and skip unlinking the\nexisting conn_tab node, leaving stale hash nodes pointing at a freed\nstruct ip_vs_conn.\n\nDrop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced\nconnections.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80714","epss":0.00404,"percentile":0.33889,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80714","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80715","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80715","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  igc: remove napi_synchronize() in igc_down()  When an AF_XDP zero-copy application is killed abruptly, the XSK pool is torn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the full budget on every poll, so napi_complete_done() never clears NAPI_STATE_SCHED.  igc_down() calls napi_synchronize() before napi_disable(), so it spins forever waiting for that bit and the interface never goes down. Drop the napi_synchronize() and let napi_disable() do the job -- it sets NAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it ahead of igc_set_queue_napi() so the NAPI mapping is cleared only after polling has stopped, matching the recent igb fix b1e067240379.","cvss":[],"epss":[{"cve":"CVE-2026-80715","epss":0.00161,"percentile":0.05568,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-80715","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80715","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3b5aee6fcbf6b58112d40d19c8d31fa3f78ee668","https://git.kernel.org/stable/c/5ffab5b9589c50e4cfc0cf36ffd76c89422d4019","https://git.kernel.org/stable/c/605585a8d89aaeb0122e9016fdaa92376897a705","https://git.kernel.org/stable/c/9a2b637aef4e515c2179774888441d00e8a5ae95","https://git.kernel.org/stable/c/a0f16c337691813f8d8f014c01fff5a368e08898","https://git.kernel.org/stable/c/ad6e0df267dc96edb7de1fa0a2fb2a70645bff86","https://git.kernel.org/stable/c/f929a6fe5b7ae1e72d2c6d18cd69ab90dcf689d2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nigc: remove napi_synchronize() in igc_down()\n\nWhen an AF_XDP zero-copy application is killed abruptly, the XSK pool is\ntorn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the\nfull budget on every poll, so napi_complete_done() never clears\nNAPI_STATE_SCHED.\n\nigc_down() calls napi_synchronize() before napi_disable(), so it spins\nforever waiting for that bit and the interface never goes down. Drop the\nnapi_synchronize() and let napi_disable() do the job -- it sets\nNAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it\nahead of igc_set_queue_napi() so the NAPI mapping is cleared only after\npolling has stopped, matching the recent igb fix b1e067240379.","cvss":[],"epss":[{"cve":"CVE-2026-80715","epss":0.00161,"percentile":0.05568,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80715","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80716","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80716","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: pcm: wake linked drain waiters on unlink  snd_pcm_drain() on a linked stream parks an on-stack wait entry on the drained peer's runtime->sleep, and after schedule_timeout() removes it only if that peer is still found in the caller's group.  If group membership changes during the wait and the sleep ends by signal or timeout (so autoremove_wake_function() does not run), finish_wait() is skipped and snd_pcm_drain() returns with the entry still queued on that stream's sleep list; a later wake_up() then walks a freed stack frame. This is reachable by unlinking either the drained or the draining stream.  Unlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()), snd_pcm_unlink() never wakes the sleep queues.  Wake every group member under the group lock before the membership change, so a linked drainer is released and drops its entry while the streams are still grouped.  The window was opened when snd_pcm_link_rwsem stopped being held across the wait and the removal became conditional on group membership (see Fixes). The later switch to finish_wait() kept that conditional removal, so the signal/timeout case remained.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80716","epss":0.0012,"percentile":0.02074,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80716","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80716","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1c1b7e8e545ce65e40f65b55c432765e058ea98f","https://git.kernel.org/stable/c/2940cc3cf43c72126b74ee6376314c195382023a","https://git.kernel.org/stable/c/3035bb784cea3f338934f5042dd3f35225a51b2e","https://git.kernel.org/stable/c/c172e4c53321ee6429955295ea133bc3597a3ca9","https://git.kernel.org/stable/c/db09bc4ab19ce548a078240d2374792523953500","https://git.kernel.org/stable/c/e8315330e4ec09c0cac625515400e13d0ee22b81","https://git.kernel.org/stable/c/e8b784a3f4fba3ea9c4d05138ecfa784a069627f","https://git.kernel.org/stable/c/f495b6c4c8594122918552c9be2b51eb71647cd9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: wake linked drain waiters on unlink\n\nsnd_pcm_drain() on a linked stream parks an on-stack wait entry on the\ndrained peer's runtime->sleep, and after schedule_timeout() removes it\nonly if that peer is still found in the caller's group.  If group\nmembership changes during the wait and the sleep ends by signal or\ntimeout (so autoremove_wake_function() does not run), finish_wait() is\nskipped and snd_pcm_drain() returns with the entry still queued on that\nstream's sleep list; a later wake_up() then walks a freed stack frame.\nThis is reachable by unlinking either the drained or the draining stream.\n\nUnlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()),\nsnd_pcm_unlink() never wakes the sleep queues.  Wake every group member\nunder the group lock before the membership change, so a linked drainer is\nreleased and drops its entry while the streams are still grouped.\n\nThe window was opened when snd_pcm_link_rwsem stopped being held across\nthe wait and the removal became conditional on group membership (see\nFixes). The later switch to finish_wait() kept that conditional removal,\nso the signal/timeout case remained.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80716","epss":0.0012,"percentile":0.02074,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80716","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80717","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80717","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: validate Adaptation Indication parameter length  The Adaptation Layer Indication parameter contains a fixed 32-bit Adaptation Code Point after its parameter header. However, sctp_verify_param() accepts a header-only parameter because the generic parameter walker only requires the header to be present.  sctp_process_param() then reads adaptation_ind beyond the declared parameter. When the malformed parameter is last in an INIT, the read starts at the receive skb tail, and the value is copied into the state cookie returned in the INIT ACK. This may disclose four receive-buffer tail bytes.  Require the declared parameter length to match the fixed structure size and abort the association through the existing invalid parameter length path otherwise.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80717","epss":0.00329,"percentile":0.25748,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.24675},"relatedVulnerabilities":[{"id":"CVE-2026-80717","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80717","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/17b412468c7a44f66a385bda48cdc1e94e39bd6d","https://git.kernel.org/stable/c/4c92c601c061e5602db2edeea54fef74aa304027","https://git.kernel.org/stable/c/5fd7cfc708dfc988ae9920c21075e6121bc89926","https://git.kernel.org/stable/c/74b21f52c5c5a71a05c0ff70e513f4f04ff28b17","https://git.kernel.org/stable/c/7b7e4e3640d57bd8857f0052c8b0d8ed4e5e954a","https://git.kernel.org/stable/c/93942b5772e0eee4147d4799cc1b936ae12fa615","https://git.kernel.org/stable/c/bfa28cf99eb4d096c87da939f54233444d209ca5","https://git.kernel.org/stable/c/fa7861ddbe3b525b5d541c15c3953d3569e6eb0e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate Adaptation Indication parameter length\n\nThe Adaptation Layer Indication parameter contains a fixed 32-bit\nAdaptation Code Point after its parameter header. However,\nsctp_verify_param() accepts a header-only parameter because the generic\nparameter walker only requires the header to be present.\n\nsctp_process_param() then reads adaptation_ind beyond the declared\nparameter. When the malformed parameter is last in an INIT, the read\nstarts at the receive skb tail, and the value is copied into the state\ncookie returned in the INIT ACK. This may disclose four receive-buffer\ntail bytes.\n\nRequire the declared parameter length to match the fixed structure size\nand abort the association through the existing invalid parameter length\npath otherwise.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"exploitabilityScore":3.9,"impactScore":3.6},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80717","epss":0.00329,"percentile":0.25748,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80717","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80718","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80718","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()  In pcpu_create_chunk(), nr_pages is the total contiguous backing allocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated() uses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap.  Since bit N in chunk->populated means page offset N inside every unit is backed.  When nr_units > 1, the function writes beyond chunk->populated.  Fix it by using chunk->nr_pages.  It also fixes the global pcpu_nr_empty_pop_pages accounting, since pcpu_balance_free() only iterates up to chunk->nr_pages.  Commit a63d4ac4ab609 (\"percpu: make percpu-km set chunk->populated bitmap properly\") introduced the bitmap overflow issue.  Later, commit b539b87fed37f (\"percpu: implmeent pcpu_nr_empty_pop_pages and chunk->nr_populated\") added pcpu_nr_empty_pop_pages and caused the accounting issue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80718","epss":0.0012,"percentile":0.02075,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09179999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80718","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80718","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/01504da375f5b19df195cb1cb1cf1dd184318f97","https://git.kernel.org/stable/c/32134cf9211b83bed9076d0739c5906fbea4c763","https://git.kernel.org/stable/c/5c7fc39bf19abb38a996aaad77b3e3a8f48581c3","https://git.kernel.org/stable/c/5f43d2c1bea280dcdfabaf156c25e7402fb8039f","https://git.kernel.org/stable/c/6fc7da2a052f2825fff785e860e67183f5acaaba","https://git.kernel.org/stable/c/89b1b79c308818a715e75f28744b70d8940a07c9","https://git.kernel.org/stable/c/92c43ac3c2b09eb16162e8144e73c00b7c3e29d6","https://git.kernel.org/stable/c/a6940b84c8c035da465b7165fdfcfb005545724e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()\n\nIn pcpu_create_chunk(), nr_pages is the total contiguous backing\nallocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated()\nuses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap. \nSince bit N in chunk->populated means page offset N inside every unit is\nbacked.  When nr_units > 1, the function writes beyond chunk->populated. \nFix it by using chunk->nr_pages.\n\nIt also fixes the global pcpu_nr_empty_pop_pages accounting, since\npcpu_balance_free() only iterates up to chunk->nr_pages.\n\nCommit a63d4ac4ab609 (\"percpu: make percpu-km set chunk->populated bitmap\nproperly\") introduced the bitmap overflow issue.  Later, commit\nb539b87fed37f (\"percpu: implmeent pcpu_nr_empty_pop_pages and\nchunk->nr_populated\") added pcpu_nr_empty_pop_pages and caused the\naccounting issue.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80718","epss":0.0012,"percentile":0.02075,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80718","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80722","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80722","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  wifi: mac80211: validate individual TWT params before driver setup  ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it.  An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params.  The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type.  [edit commit message to not overclaim lack of validation nor  understate driver impact]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80722","epss":0.00242,"percentile":0.15321,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.19723000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80722","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80722","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0502d5077e419427d80f4d46ba95d0067f5fb916","https://git.kernel.org/stable/c/09d60d1f72e6598241490eb6c4e97245af895c09","https://git.kernel.org/stable/c/47fb04c3826e1f90271d405523043d6708b9072a","https://git.kernel.org/stable/c/92fcd0f30dc8e51f252589b082d46851d295cc1a","https://git.kernel.org/stable/c/ade9e2f0f7f4d3089600ac2af8ef0b91746f923b","https://git.kernel.org/stable/c/b558e07708d886acfcf4b0391ed7a8546e81d326","https://git.kernel.org/stable/c/ff558072d199c1d641d1561da622e67f780514de"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: validate individual TWT params before driver setup\n\nieee80211_process_rx_twt_action() only partially validates a received\nS1G TWT setup frame before queueing it.\n\nAn individual agreement can therefore reach ieee80211_s1g_rx_twt_setup()\nwith twt->length too short for the full struct ieee80211_twt_params.\n\nThe individual path passes twt to drv_add_twt_setup(). Both the tracepoint\nand the driver callback consume the complete parameters block, not merely\nreq_type. Do not pass a short individual agreement to the driver.\nBroadcast agreements remain unchanged because they are rejected locally\nafter accessing only req_type.\n\n[edit commit message to not overclaim lack of validation nor\n understate driver impact]","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"exploitabilityScore":2.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80722","epss":0.00242,"percentile":0.15321,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80722","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80725","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80725","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: gro: properly validate BIG TCP aggregation criteria  When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP (with sufficient MAC header room to insert the temporary HBH jumbo header).  However, commit b1a78b9b9886 (\"net: add support for ipv4 big tcp\") loosened the check in skb_gro_receive(), leading to several issues:  1. skb_gro_receive() checked skb_headroom(p) instead of the actual space    before the MAC header (p->mac_header). Because skb_headroom(p) includes    mac_len, crafted frames (e.g. injected via AF_PACKET) can pass the check    with p->mac_header < 8 bytes. When ipv6_gro_complete() inserts the    temporary HBH jumbo header, the memmove() starts before skb->head,    causing an out-of-bounds write and wrapping skb->mac_header. 2. It allowed non-IP protocols such as software VLAN (ETH_P_8021Q /    ETH_P_8021AD) to aggregate beyond 64KB because    p->protocol != ETH_P_IPV6 was true. 3. It checked p->encapsulation instead of NAPI_GRO_CB(skb)->encap_mark,    allowing encapsulated flows (e.g. SIT / IPv6-in-IPv4) to aggregate    beyond 64KB.  Fix skb_gro_receive() to strictly enforce: - NAPI_GRO_CB(skb)->proto == IPPROTO_TCP - Not encapsulated (!NAPI_GRO_CB(skb)->encap_mark && !p->encapsulation) - Protocol must be either ETH_P_IP or ETH_P_IPV6 - If ETH_P_IPV6, p->mac_header must be at least   sizeof(struct hop_jumbo_hdr)  Returning -E2BIG from skb_gro_receive() ensures that packets which cannot become BIG TCP are cleanly flushed at <= 64KB and delivered intact without dropping.  This issue does not exist in mainline (7.0+) because the subsystem was rewritten in commit 81be30c1f5f2 (\"net/ipv6: Drop HBH for BIG TCP on RX side\"), making this fix relevant only for older stable branches like 6.18.y.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80725","epss":0.00455,"percentile":0.38233,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.4277},"relatedVulnerabilities":[{"id":"CVE-2026-80725","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80725","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/03cb8cc2961f5f781d12e903782cb3815ed84b1c","https://git.kernel.org/stable/c/37a5dcd6837fc2afc44a7bc3ed8af4e983783d46","https://git.kernel.org/stable/c/3ce832e2bd431d0c12ba525ed73ad8fbc4191da5","https://git.kernel.org/stable/c/81be30c1f5f2bffda1f04c0efd0746af10b9643a","https://git.kernel.org/stable/c/e907bf694ed55bdfe421be99dba35751a655df25"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: properly validate BIG TCP aggregation criteria\n\nWhen GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB),\nBIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP\n(with sufficient MAC header room to insert the temporary HBH jumbo header).\n\nHowever, commit b1a78b9b9886 (\"net: add support for ipv4 big tcp\")\nloosened the check in skb_gro_receive(), leading to several issues:\n\n1. skb_gro_receive() checked skb_headroom(p) instead of the actual space\n   before the MAC header (p->mac_header). Because skb_headroom(p) includes\n   mac_len, crafted frames (e.g. injected via AF_PACKET) can pass the check\n   with p->mac_header < 8 bytes. When ipv6_gro_complete() inserts the\n   temporary HBH jumbo header, the memmove() starts before skb->head,\n   causing an out-of-bounds write and wrapping skb->mac_header.\n2. It allowed non-IP protocols such as software VLAN (ETH_P_8021Q /\n   ETH_P_8021AD) to aggregate beyond 64KB because\n   p->protocol != ETH_P_IPV6 was true.\n3. It checked p->encapsulation instead of NAPI_GRO_CB(skb)->encap_mark,\n   allowing encapsulated flows (e.g. SIT / IPv6-in-IPv4) to aggregate\n   beyond 64KB.\n\nFix skb_gro_receive() to strictly enforce:\n- NAPI_GRO_CB(skb)->proto == IPPROTO_TCP\n- Not encapsulated (!NAPI_GRO_CB(skb)->encap_mark && !p->encapsulation)\n- Protocol must be either ETH_P_IP or ETH_P_IPV6\n- If ETH_P_IPV6, p->mac_header must be at least\n  sizeof(struct hop_jumbo_hdr)\n\nReturning -E2BIG from skb_gro_receive() ensures that packets which cannot\nbecome BIG TCP are cleanly flushed at <= 64KB and delivered intact without\ndropping.\n\nThis issue does not exist in mainline (7.0+) because the subsystem was\nrewritten in commit 81be30c1f5f2 (\"net/ipv6: Drop HBH for BIG TCP on RX\nside\"), making this fix relevant only for older stable branches like\n6.18.y.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"exploitabilityScore":3.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80725","epss":0.00455,"percentile":0.38233,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80725","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80726","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80726","namespace":"debian:distro:debian:12","severity":"Critical","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page  Explicitly clear role.invalid when deriving a child shadow page's role from its parent to harden against bugs elsewhere in KVM, as violating KVM's invariant that invalid pages are NOT on the list of active MMU pages leads to use-after-free due to __kvm_mmu_prepare_zap_page() using list_add() instead of list_move() when processing an invalid shadow page, i.e. makes a bad situation far worse.  Yell loudly if the parent is invalid, as it means KVM has missed a validity check, i.e. KVM is attempting to map memory using an invalid/obsolete root, but continue on as the child is otherwise still a valid shadow page.    ==================================================================   BUG: KASAN: slab-use-after-free in __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]   Write of size 8 at addr ff11000153dd1368 by task repro/853    CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015   Call Trace:    <TASK>    dump_stack_lvl+0x4b/0x70    print_report+0x153/0x49c    kasan_report+0xbc/0xf0    __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]    mmu_alloc_root+0x141/0x320 [kvm]    kvm_mmu_load+0x612/0x20f0 [kvm]    kvm_arch_vcpu_ioctl_run+0x3dd5/0x6150 [kvm]    kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]    __x64_sys_ioctl+0x131/0x1b0    do_syscall_64+0x67/0x5f0    entry_SYSCALL_64_after_hwframe+0x4b/0x53    </TASK>    Allocated by task 853:    kasan_save_stack+0x20/0x40    kasan_save_track+0x14/0x30    __kasan_slab_alloc+0x5f/0x70    kmem_cache_alloc_noprof+0xfe/0x2e0    __kvm_mmu_topup_memory_cache+0x135/0x530 [kvm]    paging64_page_fault+0x318/0x1e30 [kvm]    kvm_mmu_do_page_fault+0x21d/0x630 [kvm]    kvm_mmu_page_fault+0x18c/0x17b0 [kvm]    kvm_arch_vcpu_ioctl_run+0x1f35/0x6150 [kvm]    kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]    __x64_sys_ioctl+0x131/0x1b0    do_syscall_64+0x67/0x5f0    entry_SYSCALL_64_after_hwframe+0x4b/0x53    Freed by task 853:    kasan_save_stack+0x20/0x40    kasan_save_track+0x14/0x30    kasan_save_free_info+0x3b/0x60    __kasan_slab_free+0x43/0x70    kmem_cache_free+0xe2/0x400    kvm_mmu_commit_zap_page.part.0+0x1e2/0x310 [kvm]    kvm_mmu_free_roots+0x283/0x560 [kvm]    kvm_arch_vcpu_ioctl_run+0x33c8/0x6150 [kvm]    kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]    __x64_sys_ioctl+0x131/0x1b0    do_syscall_64+0x67/0x5f0    entry_SYSCALL_64_after_hwframe+0x4b/0x53","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80726","epss":0.00177,"percentile":0.07398,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.16195500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80726","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80726","namespace":"nvd:cpe","severity":"Critical","urls":["https://git.kernel.org/stable/c/0af4711862c5b818204d40b21f0859ad51c230e9","https://git.kernel.org/stable/c/5ec42d57655c690234c14aece6dd3f209778c1d8","https://git.kernel.org/stable/c/66bc868a33cf1de43f22a94acd8857e0fe33393f","https://git.kernel.org/stable/c/9b7984692c18b22d6d61af3f53887fca7fddb0f1","https://git.kernel.org/stable/c/9f7760a2e962cbda0d096a27d394d14ad4d22928","https://git.kernel.org/stable/c/f33ecb89d352348ed5e625f6747ac51ede254e1b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page\n\nExplicitly clear role.invalid when deriving a child shadow page's role from\nits parent to harden against bugs elsewhere in KVM, as violating KVM's\ninvariant that invalid pages are NOT on the list of active MMU pages leads\nto use-after-free due to __kvm_mmu_prepare_zap_page() using list_add()\ninstead of list_move() when processing an invalid shadow page, i.e. makes a\nbad situation far worse.\n\nYell loudly if the parent is invalid, as it means KVM has missed a validity\ncheck, i.e. KVM is attempting to map memory using an invalid/obsolete root,\nbut continue on as the child is otherwise still a valid shadow page.\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]\n  Write of size 8 at addr ff11000153dd1368 by task repro/853\n\n  CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x4b/0x70\n   print_report+0x153/0x49c\n   kasan_report+0xbc/0xf0\n   __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm]\n   mmu_alloc_root+0x141/0x320 [kvm]\n   kvm_mmu_load+0x612/0x20f0 [kvm]\n   kvm_arch_vcpu_ioctl_run+0x3dd5/0x6150 [kvm]\n   kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]\n   __x64_sys_ioctl+0x131/0x1b0\n   do_syscall_64+0x67/0x5f0\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n   </TASK>\n\n  Allocated by task 853:\n   kasan_save_stack+0x20/0x40\n   kasan_save_track+0x14/0x30\n   __kasan_slab_alloc+0x5f/0x70\n   kmem_cache_alloc_noprof+0xfe/0x2e0\n   __kvm_mmu_topup_memory_cache+0x135/0x530 [kvm]\n   paging64_page_fault+0x318/0x1e30 [kvm]\n   kvm_mmu_do_page_fault+0x21d/0x630 [kvm]\n   kvm_mmu_page_fault+0x18c/0x17b0 [kvm]\n   kvm_arch_vcpu_ioctl_run+0x1f35/0x6150 [kvm]\n   kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]\n   __x64_sys_ioctl+0x131/0x1b0\n   do_syscall_64+0x67/0x5f0\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n  Freed by task 853:\n   kasan_save_stack+0x20/0x40\n   kasan_save_track+0x14/0x30\n   kasan_save_free_info+0x3b/0x60\n   __kasan_slab_free+0x43/0x70\n   kmem_cache_free+0xe2/0x400\n   kvm_mmu_commit_zap_page.part.0+0x1e2/0x310 [kvm]\n   kvm_mmu_free_roots+0x283/0x560 [kvm]\n   kvm_arch_vcpu_ioctl_run+0x33c8/0x6150 [kvm]\n   kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm]\n   __x64_sys_ioctl+0x131/0x1b0\n   do_syscall_64+0x67/0x5f0\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.3,"exploitabilityScore":2.6,"impactScore":6.1},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80726","epss":0.00177,"percentile":0.07398,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80726","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80728","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80728","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Revert \"drm/amdgpu: fix aperture mapping leak\"  devres teardown is LIFO. The aperture devres node was registered after the DRM device node, so devres_release_all() unmaps the aperture before the DRM device release callback fires amdgpu_device_fini_sw(). IP sw_fini callbacks (e.g. vcn_v4_0_sw_fini) write to fw_shared through a pointer derived from aper_base_kaddr, causing a kernel page fault on probe failure / rollback:    BUG: unable to handle page fault ... PMD 0   RIP: vcn_v4_0_sw_fini+0x7b/0x170 [amdgpu]   Call Trace:     amdgpu_device_fini_sw     amdgpu_driver_release_kms     devm_drm_dev_init_release     devres_release_all  This reverts commit d871e99879cb5fd1fa798b006b4888887e63a17a.  (cherry picked from commit 336e0cd576817ac64a4b394ca2b3680029f3e37f)","cvss":[],"epss":[{"cve":"CVE-2026-80728","epss":0.00168,"percentile":0.06318,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80728","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80728","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/496846a9411136eb9e86ad4f4e62d751bd1e1db5","https://git.kernel.org/stable/c/7380f1bfe9d7ed3a4ca9d99a5c4df840fff9af2a","https://git.kernel.org/stable/c/96d26143882f9cb47dcc1f3dd4e26d047e53ab9b","https://git.kernel.org/stable/c/a2e326c52c4bcecc033cd3ca2733fdbe30fbf55d","https://git.kernel.org/stable/c/b96c529cd2551b78316a4afa3237b2ed96ba03c8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"drm/amdgpu: fix aperture mapping leak\"\n\ndevres teardown is LIFO. The aperture devres node was registered after\nthe DRM device node, so devres_release_all() unmaps the aperture before\nthe DRM device release callback fires amdgpu_device_fini_sw(). IP\nsw_fini callbacks (e.g. vcn_v4_0_sw_fini) write to fw_shared through a\npointer derived from aper_base_kaddr, causing a kernel page fault on\nprobe failure / rollback:\n\n  BUG: unable to handle page fault ... PMD 0\n  RIP: vcn_v4_0_sw_fini+0x7b/0x170 [amdgpu]\n  Call Trace:\n    amdgpu_device_fini_sw\n    amdgpu_driver_release_kms\n    devm_drm_dev_init_release\n    devres_release_all\n\nThis reverts commit d871e99879cb5fd1fa798b006b4888887e63a17a.\n\n(cherry picked from commit 336e0cd576817ac64a4b394ca2b3680029f3e37f)","cvss":[],"epss":[{"cve":"CVE-2026-80728","epss":0.00168,"percentile":0.06318,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80728","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80730","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80730","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ring-buffer: Fix crash passing ERR_PTR to kthread_stop()  In test_ringbuffer()'s out_free cleanup loop, the check `!rb_threads[cpu]` only catches NULL entries and misses entries that hold an ERR_PTR.  rb_threads[] is static, so unassigned slots are NULL. But when kthread_run_on_cpu() fails for a cpu, it stores ERR_PTR(-ENOMEM) (or -EINTR) in rb_threads[cpu] before the creation loop jumps to out_free. That entry is non-NULL, so the old `!ptr` check does not break, and the cleanup proceeds to call kthread_stop() on the ERR_PTR. kthread_stop() then dereferences the bogus pointer, crashing the kernel during the late_initcall self-test.  crash logs:   BUG: kernel NULL pointer dereference, address: 000000000000001c   Oops: 0002 [#1] SMP NOPTI   CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy)   RIP: 0010:kthread_stop+0x2e/0x220   RBX: fffffffffffffff4   CR2: 000000000000001c   Call Trace:    <TASK>    test_ringbuffer+0x1ec/0x650    do_one_initcall+0x6c/0x2c0    kernel_init_freeable+0x21d/0x420    kernel_init+0x15/0x1c0    ret_from_fork+0x21b/0x320    </TASK>   Kernel panic - not syncing: Fatal exception","cvss":[],"epss":[{"cve":"CVE-2026-80730","epss":0.00205,"percentile":0.10656,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10250000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80730","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80730","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3ea2fd344d93e3cf9503739b09fd702c0d8f8f0b","https://git.kernel.org/stable/c/51d78fad30dd9ae45721224103662bdbcf210096","https://git.kernel.org/stable/c/6dd7a06894d6d3dc84319bd0b7d1a7c27df9d902","https://git.kernel.org/stable/c/8532983c312e8b875d7c9e440f8ee4674ea4b711","https://git.kernel.org/stable/c/91542863abade2fd4f2b361991f5386ad9d19c8c","https://git.kernel.org/stable/c/93e7044b548a72022208595d2c1b188bb225ce83"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix crash passing ERR_PTR to kthread_stop()\n\nIn test_ringbuffer()'s out_free cleanup loop, the check\n`!rb_threads[cpu]` only catches NULL entries and misses entries that\nhold an ERR_PTR.\n\nrb_threads[] is static, so unassigned slots are NULL. But when\nkthread_run_on_cpu() fails for a cpu, it stores ERR_PTR(-ENOMEM) (or\n-EINTR) in rb_threads[cpu] before the creation loop jumps to out_free.\nThat entry is non-NULL, so the old `!ptr` check does not break, and the\ncleanup proceeds to call kthread_stop() on the ERR_PTR. kthread_stop()\nthen dereferences the bogus pointer, crashing the kernel during the\nlate_initcall self-test.\n\ncrash logs:\n  BUG: kernel NULL pointer dereference, address: 000000000000001c\n  Oops: 0002 [#1] SMP NOPTI\n  CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy)\n  RIP: 0010:kthread_stop+0x2e/0x220\n  RBX: fffffffffffffff4\n  CR2: 000000000000001c\n  Call Trace:\n   <TASK>\n   test_ringbuffer+0x1ec/0x650\n   do_one_initcall+0x6c/0x2c0\n   kernel_init_freeable+0x21d/0x420\n   kernel_init+0x15/0x1c0\n   ret_from_fork+0x21b/0x320\n   </TASK>\n  Kernel panic - not syncing: Fatal exception","cvss":[],"epss":[{"cve":"CVE-2026-80730","epss":0.00205,"percentile":0.10656,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80730","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80731","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80731","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header  dev_validate_header() reads dev->hard_header_len directly when zero-padding short link layer headers for CAP_SYS_RAWIO holders:      if (capable(CAP_SYS_RAWIO)) {         memset(ll_header + len, 0, dev->hard_header_len - len);         return true;     }  Packet send paths call dev_validate_header() on skbs whose headroom was allocated from an earlier hard_header_len read. If the device is reconfigured so that dev->hard_header_len increases before validation, the memset writes past the reserved buffer, an out-of-bounds write.  This out-of-bounds write is masked in some SOCK_RAW paths today because the same concurrent increase can first make skb_push() exceed the reserved headroom and trigger skb_under_panic(). Remove the zero-padding branch before making those hard_header_len reads consistent, so the snapshot fixes do not turn a loud panic into a silent overwrite.  This path is only reached for variable length L2 protocols, where len < hard_header_len but len >= min_header_len. No remaining in-tree variable length L2 protocol implements header_ops->validate, and the CAP_SYS_RAWIO bypass that zero-pads and accepts short headers has no real value beyond allowing testing of intentionally malformed input.  Drop the CAP_SYS_RAWIO branch. The remaining reads of dev->hard_header_len in dev_validate_header() are comparisons only and have no memory safety impact.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80731","epss":0.0018,"percentile":0.07619,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1377},"relatedVulnerabilities":[{"id":"CVE-2026-80731","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80731","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/3b9a324e646d3657a8d9806dfbfe4f3e4066e882","https://git.kernel.org/stable/c/53fd7f912c0877647d6a1e1877f5ea8535ee0b4a","https://git.kernel.org/stable/c/74e035f07f53feca09e2352e77fccb09cad5e208","https://git.kernel.org/stable/c/8fc9816404166a90ed8d544dc52482fafffb6d9f","https://git.kernel.org/stable/c/99df6b7a713f96eda206680d100b76e15f9d9b69","https://git.kernel.org/stable/c/b0f92a5731dc82556a9ae005cc35f71ab136307b","https://git.kernel.org/stable/c/dbb30dc943a93e083f1e531bfdc6779e57de40d0","https://git.kernel.org/stable/c/fa6d98dd925e72fc028b26a0cbbff9d2f0601ff6","https://git.kernel.org/stable/c/fc902f52a02298c7432b2334c0c82a2885a1a8b6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: remove CAP_SYS_RAWIO zero-padding in dev_validate_header\n\ndev_validate_header() reads dev->hard_header_len directly when\nzero-padding short link layer headers for CAP_SYS_RAWIO holders:\n\n    if (capable(CAP_SYS_RAWIO)) {\n        memset(ll_header + len, 0, dev->hard_header_len - len);\n        return true;\n    }\n\nPacket send paths call dev_validate_header() on skbs whose headroom was\nallocated from an earlier hard_header_len read. If the device is\nreconfigured so that dev->hard_header_len increases before validation,\nthe memset writes past the reserved buffer, an out-of-bounds write.\n\nThis out-of-bounds write is masked in some SOCK_RAW paths today because\nthe same concurrent increase can first make skb_push() exceed the\nreserved headroom and trigger skb_under_panic(). Remove the zero-padding\nbranch before making those hard_header_len reads consistent, so the\nsnapshot fixes do not turn a loud panic into a silent overwrite.\n\nThis path is only reached for variable length L2 protocols, where\nlen < hard_header_len but len >= min_header_len. No remaining in-tree\nvariable length L2 protocol implements header_ops->validate, and the\nCAP_SYS_RAWIO bypass that zero-pads and accepts short headers has no\nreal value beyond allowing testing of intentionally malformed input.\n\nDrop the CAP_SYS_RAWIO branch. The remaining reads of\ndev->hard_header_len in dev_validate_header() are comparisons only and\nhave no memory safety impact.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80731","epss":0.0018,"percentile":0.07619,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80731","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80732","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80732","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ata: pata_sl82c105: fix bridge revision use-after-free  pci_get_slot() returns a referenced PCI device. Commit 44c10138fd4b (\"PCI: Change all drivers to use pci_device->revision\") replaced a configuration-space read with direct access to the cached revision field, but left that access after pci_dev_put(). The bridge may therefore be freed before its revision is read.  Read the revision before dropping the reference.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80732","epss":0.00159,"percentile":0.0542,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12163500000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80732","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80732","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1268ca9418e2217f2b60705cf4a280b689b26678","https://git.kernel.org/stable/c/56fd78c8c820f527f8003e379ab71004b2e79a44","https://git.kernel.org/stable/c/5ef87b1b4656d675440ceab32a56e69ad958d3a1","https://git.kernel.org/stable/c/7700a31039cdc6715cb6cce7e7a664ee4e945f67","https://git.kernel.org/stable/c/a626dfca96041842053cf2d1efceb436c4cd8dcf","https://git.kernel.org/stable/c/a837deeaa37cc3f0e8c4e5c096787047f272c956","https://git.kernel.org/stable/c/dc711fb137b33c12e6ca22b6a9c9b9f21d49e4de","https://git.kernel.org/stable/c/fa0dca89b4fb0909ffda7b9ab6051af33270f95e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: pata_sl82c105: fix bridge revision use-after-free\n\npci_get_slot() returns a referenced PCI device. Commit 44c10138fd4b\n(\"PCI: Change all drivers to use pci_device->revision\") replaced a\nconfiguration-space read with direct access to the cached revision field,\nbut left that access after pci_dev_put(). The bridge may therefore be freed\nbefore its revision is read.\n\nRead the revision before dropping the reference.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80732","epss":0.00159,"percentile":0.0542,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80732","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80733","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80733","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: remove WARN_ON_ONCE() from sk_mc_loop()  sk_mc_loop() can be called for sockets that are neither AF_INET nor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet socket over virtual devices such as VRF or ipvlan).  In such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls through the switch statement and triggers WARN_ON_ONCE(1).  Non-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP options, so loopback should default to true without generating a warning.","cvss":[],"epss":[{"cve":"CVE-2026-80733","epss":0.0021,"percentile":0.11274,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-80733","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80733","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0d75f2c1d0764efa756ad9c1e078d8c09ea8fc1f","https://git.kernel.org/stable/c/97133c4d42654578fab95abe47359ebe784dde18","https://git.kernel.org/stable/c/ad7dbb1d14b1b4406eca8ef9478e8de312ba0cfe","https://git.kernel.org/stable/c/ad7fa2f411cb30f63d6725f111be134064cdb718","https://git.kernel.org/stable/c/b8a39a09ae4eaae04309e1e38ed6a1101d967496","https://git.kernel.org/stable/c/c8f256dc849205ccb2bd78bd99a3497b972b44e0","https://git.kernel.org/stable/c/d2adc4e80b29e58b5162ae09f0f657a215806c8c","https://git.kernel.org/stable/c/f625c742b33dc137c209dd13d1c5f12b1c18d71c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: remove WARN_ON_ONCE() from sk_mc_loop()\n\nsk_mc_loop() can be called for sockets that are neither AF_INET\nnor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet\nsocket over virtual devices such as VRF or ipvlan).\n\nIn such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls\nthrough the switch statement and triggers WARN_ON_ONCE(1).\n\nNon-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP\noptions, so loopback should default to true without generating a warning.","cvss":[],"epss":[{"cve":"CVE-2026-80733","epss":0.0021,"percentile":0.11274,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80733","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80737","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80737","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  serial: amba-pl011: synchronize DMA teardown  dmaengine_terminate_all() does not wait for a running callback, so the TX callback can still touch the TX buffer after it is freed. The RX poll timer reads the RX buffers without the port lock.  Switch to dmaengine_terminate_sync() and delete the RX timer before freeing the buffers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80737","epss":0.00164,"percentile":0.05906,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80737","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80737","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/440915499231e9db1c361aa45bb702e8fd3b4a32","https://git.kernel.org/stable/c/44bd0ecc3444882d08ecfbc2b2418d2f463d3186","https://git.kernel.org/stable/c/5974cb66681eac367107b05924744d7e3b49d41c","https://git.kernel.org/stable/c/9f6989e477f03a4721d34bb4b09b17accd40283e","https://git.kernel.org/stable/c/a38fae9d212e2d3ed5e9ec0ef773f8c0a27fb76e","https://git.kernel.org/stable/c/c8c8e895f65fbf71ea6224e27cf8dab91b776e0d","https://git.kernel.org/stable/c/f70c9d4fba46463a5b1c7b3ee9ee3b40c90dac03","https://git.kernel.org/stable/c/fdfb46c387241b4eddd36d746793764413285913"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: amba-pl011: synchronize DMA teardown\n\ndmaengine_terminate_all() does not wait for a running callback, so the TX\ncallback can still touch the TX buffer after it is freed. The RX poll\ntimer reads the RX buffers without the port lock.\n\nSwitch to dmaengine_terminate_sync() and delete the RX timer before\nfreeing the buffers.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80737","epss":0.00164,"percentile":0.05906,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80737","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80738","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80738","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie  bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer 'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access sk->sk_protocol without validating whether 'sk' represents a full socket.  Fix this issue by checking sk->sk_state != TCP_LISTEN before inspecting sk->sk_protocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie. Since mini-sockets are never in the TCP_LISTEN state, the condition short-circuits and prevents dereferencing fullsock-specific fields.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80738","epss":0.00118,"percentile":0.01936,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.08732000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80738","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80738","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/23f682083aa3fbc0c49667818efd6979a8bc5ac2","https://git.kernel.org/stable/c/31a420a822ff92e2090bd5d65efe8e34e2d6d9b8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie\n\nbpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer\n'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access\nsk->sk_protocol without validating whether 'sk' represents a full socket.\n\nFix this issue by checking sk->sk_state != TCP_LISTEN before inspecting\nsk->sk_protocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie.\nSince mini-sockets are never in the TCP_LISTEN state, the condition\nshort-circuits and prevents dereferencing fullsock-specific fields.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"exploitabilityScore":1.9,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80738","epss":0.00118,"percentile":0.01936,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80738","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80739","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80739","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock  In case __mlx5e_add_fdb_flow() fails in lower levels, the flow is deleted via mlx5e_tc_del_flow(), and mlx5e_tc_del_flow() is acquiring ESW devcom lock without condition. In addition, in case of peer_flow, __mlx5e_add_fdb_flow() is called while holding ESW devcom comp lock. This results in an AA deadlock.  To fix this, introduce a new PEER flag that is set on flows created as peer flows (the duplicate flows on peer devices), and check it in mlx5e_tc_del_flow() before acquiring ESW devcom lock.  Lockdep splat: ============================================ WARNING: possible recursive locking detected ============================================  Possible unsafe locking scenario:        CPU0        ----   lock(&comp->lock_key#2);   lock(&comp->lock_key#2);  *** DEADLOCK *** Call Trace:  <TASK>  dump_stack_lvl+0x69/0xa0  print_deadlock_bug.cold+0xbd/0xca  __lock_acquire+0x1671/0x2ec0  lock_acquire+0x10e/0x2e0  down_read+0x95/0x430  mlx5_devcom_for_each_peer_begin+0x4e/0xe0 [mlx5_core]  mlx5e_tc_del_flow+0x11d/0xa70 [mlx5_core]  mlx5e_flow_put+0x99/0x100 [mlx5_core]  __mlx5e_add_fdb_flow+0x409/0xf00 [mlx5_core]  mlx5e_configure_flower+0x2a86/0x4100 [mlx5_core]  mlx5e_rep_setup_tc_cls_flower+0x12f/0x1b0 [mlx5_core]  mlx5e_rep_setup_tc_cb+0x153/0x750 [mlx5_core]  tc_setup_cb_add+0x1dc/0x470  fl_change+0x2f4d/0x626d [cls_flower]  tc_new_tfilter+0x79b/0x2310  rtnetlink_rcv_msg+0x778/0xad0  do_syscall_64+0x70/0x960  entry_SYSCALL_64_after_hwframe+0x4b/0x53  </TASK>","cvss":[],"epss":[{"cve":"CVE-2026-80739","epss":0.002,"percentile":0.09908,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-80739","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80739","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/585df8643081e6f616579bc52cd49ac823a57c82","https://git.kernel.org/stable/c/607adbda01053abf5f93e322fe39325da8828cb8","https://git.kernel.org/stable/c/6ddfba2ea98db21b001e0e5c472499156224650c","https://git.kernel.org/stable/c/7165fe321c61ec138850c02f030f274797761f5f","https://git.kernel.org/stable/c/ff9e7d5e3500be389ce7a0e46db3a77149830bc9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: TC, Check if flow is PEER before acquiring devcom lock\n\nIn case __mlx5e_add_fdb_flow() fails in lower levels, the flow is\ndeleted via mlx5e_tc_del_flow(), and mlx5e_tc_del_flow() is acquiring\nESW devcom lock without condition. In addition, in case of peer_flow,\n__mlx5e_add_fdb_flow() is called while holding ESW devcom comp lock.\nThis results in an AA deadlock.\n\nTo fix this, introduce a new PEER flag that is set on flows created as\npeer flows (the duplicate flows on peer devices), and check it in\nmlx5e_tc_del_flow() before acquiring ESW devcom lock.\n\nLockdep splat:\n============================================\nWARNING: possible recursive locking detected\n============================================\n Possible unsafe locking scenario:\n       CPU0\n       ----\n  lock(&comp->lock_key#2);\n  lock(&comp->lock_key#2);\n *** DEADLOCK ***\nCall Trace:\n <TASK>\n dump_stack_lvl+0x69/0xa0\n print_deadlock_bug.cold+0xbd/0xca\n __lock_acquire+0x1671/0x2ec0\n lock_acquire+0x10e/0x2e0\n down_read+0x95/0x430\n mlx5_devcom_for_each_peer_begin+0x4e/0xe0 [mlx5_core]\n mlx5e_tc_del_flow+0x11d/0xa70 [mlx5_core]\n mlx5e_flow_put+0x99/0x100 [mlx5_core]\n __mlx5e_add_fdb_flow+0x409/0xf00 [mlx5_core]\n mlx5e_configure_flower+0x2a86/0x4100 [mlx5_core]\n mlx5e_rep_setup_tc_cls_flower+0x12f/0x1b0 [mlx5_core]\n mlx5e_rep_setup_tc_cb+0x153/0x750 [mlx5_core]\n tc_setup_cb_add+0x1dc/0x470\n fl_change+0x2f4d/0x626d [cls_flower]\n tc_new_tfilter+0x79b/0x2310\n rtnetlink_rcv_msg+0x778/0xad0\n do_syscall_64+0x70/0x960\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n </TASK>","cvss":[],"epss":[{"cve":"CVE-2026-80739","epss":0.002,"percentile":0.09908,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80739","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80742","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80742","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  af_packet: Don't send zero-byte data in tpacket_snd().  syzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd():  skb_assert_len WARNING: at include/linux/skbuff.h:2753 skb_assert_len WARNING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781  Call Trace:  <TASK>  dev_queue_xmit include/linux/netdevice.h:3448 [inline]  packet_xmit+0x243/0x310 net/packet/af_packet.c:276  tpacket_snd net/packet/af_packet.c:2907 [inline]  packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134  When sending 0-byte packets via TPACKET ring buffer on devices with no hard header (e.g. dev->hard_header_len == 0), tpacket_fill_skb() populates an skb with skb->len == 0 and returns 0. tpacket_snd() then forwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to hit skb_assert_len(skb).  Similar checks exist in packet_snd() via commit dc633700f00f (\"net/af_packet: check len when min_header_len equals to 0\") and in packet_sendmsg_spkt() via commit 6a341729fb31 (\"af_packet: Don't send zero-byte data in packet_sendmsg_spkt().\").  Return -EINVAL in tpacket_fill_skb() when skb->len is zero to reject zero-length packets in tpacket_snd().","cvss":[],"epss":[{"cve":"CVE-2026-80742","epss":0.0021,"percentile":0.11272,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-80742","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80742","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1fc70b3d513bafb16b17540178870ef46e81c0bb","https://git.kernel.org/stable/c/3fa110f9e2ea96f567f2194c673c4bc327640111","https://git.kernel.org/stable/c/6bcd76c134c55c697148acb5c0194e9666abdf84","https://git.kernel.org/stable/c/7521e691c7c4f2231634c95053281ac888d1f452","https://git.kernel.org/stable/c/80a702964467b998d254f16cc61c2c9a20540c9d","https://git.kernel.org/stable/c/98c5914d6b7bd4b4675535908e57dea31f1efd6a","https://git.kernel.org/stable/c/dde212f8622f5cb36223fff1ebd6e6f2a3dc61fe","https://git.kernel.org/stable/c/f09ac5682f1bb67981fcb6ead4d3cfe439225876"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\naf_packet: Don't send zero-byte data in tpacket_snd().\n\nsyzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd():\n\nskb_assert_len\nWARNING: at include/linux/skbuff.h:2753 skb_assert_len\nWARNING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781\n\nCall Trace:\n <TASK>\n dev_queue_xmit include/linux/netdevice.h:3448 [inline]\n packet_xmit+0x243/0x310 net/packet/af_packet.c:276\n tpacket_snd net/packet/af_packet.c:2907 [inline]\n packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134\n\nWhen sending 0-byte packets via TPACKET ring buffer on devices with no\nhard header (e.g. dev->hard_header_len == 0), tpacket_fill_skb()\npopulates an skb with skb->len == 0 and returns 0. tpacket_snd() then\nforwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to\nhit skb_assert_len(skb).\n\nSimilar checks exist in packet_snd() via commit dc633700f00f\n(\"net/af_packet: check len when min_header_len equals to 0\") and in\npacket_sendmsg_spkt() via commit 6a341729fb31 (\"af_packet: Don't send\nzero-byte data in packet_sendmsg_spkt().\").\n\nReturn -EINVAL in tpacket_fill_skb() when skb->len is zero to reject\nzero-length packets in tpacket_snd().","cvss":[],"epss":[{"cve":"CVE-2026-80742","epss":0.0021,"percentile":0.11272,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80742","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80743","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80743","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers  The irq handlers take a struct device pointer and call dev_get_drvdata() to obtain the driver data.  However, the driver data is only set at the end of probe, after devm_request_irq(), so an interrupt taken in between causes the handlers to pass a NULL pointer to readl() and crash.  Pass the private data directly as the devm_request_irq() argument instead of the device pointer, matching what the handlers expect.","cvss":[],"epss":[{"cve":"CVE-2026-80743","epss":0.0021,"percentile":0.11274,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-80743","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80743","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/09e4c486348e176c083f8bee9169ae8f408cf8d1","https://git.kernel.org/stable/c/0d58a70b6dc7b65772e3ef7c43beb91882cf9ed5","https://git.kernel.org/stable/c/721cfeb0b9572084435695ae535411b921d1ea68","https://git.kernel.org/stable/c/7d857aec162fb02d10ce326aecc1ac7509c31f43","https://git.kernel.org/stable/c/a85315f2eb06adc5597a7103e1910fc7d0d35ffd","https://git.kernel.org/stable/c/b4ef887bee4d3c177adac5d1eab8b2de31b08ac3","https://git.kernel.org/stable/c/f12afefb7b01f94d6d66d397f323a9914edbf70e","https://git.kernel.org/stable/c/f51a540b14eecb8667bbe450192318271b87631e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers\n\nThe irq handlers take a struct device pointer and call\ndev_get_drvdata() to obtain the driver data.  However, the driver\ndata is only set at the end of probe, after devm_request_irq(),\nso an interrupt taken in between causes the handlers to pass a\nNULL pointer to readl() and crash.\n\nPass the private data directly as the devm_request_irq() argument\ninstead of the device pointer, matching what the handlers expect.","cvss":[],"epss":[{"cve":"CVE-2026-80743","epss":0.0021,"percentile":0.11274,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80743","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80744","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80744","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path  In nft_flow_rule_offload_abort(), WARN_ON_ONCE(err) is triggered on every error during rollback, including -ENOMEM. Memory allocation failures are expected under low-memory conditions and do not indicate a kernel bug.  Trace for example: nft_flow_offload_chain() // FLOW_BLOCK_BIND   nft_flow_block_chain()     nft_chain_offload_cmd()       nft_block_offload_cmd()         ->ndo_setup_tc()         nsim_setup_tc()           flow_block_cb_setup_simple()             flow_block_cb_alloc() // fails to -ENOMEM  The warning was reproduced on the 5.10 stable kernel under memory pressure via fault injection, but the underlying bug exists in mainline as well, as demonstrated by the ENOMEM trace above. The following splat was triggered during nf_tables transaction processing:  WARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline] WARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591 Modules linked in: CPU: 0 PID: 8567 Comm: syz-executor.0 Not tainted 5.10.260-syzkaller #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline] RIP: 0010:nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591 Call Trace:  nf_tables_commit+0x3bd/0x4bd0 net/netfilter/nf_tables_api.c:8604  nfnetlink_rcv_batch+0xb1e/0x1f20 net/netfilter/nfnetlink.c:509  nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:579 [inline]  nfnetlink_rcv+0x3b3/0x420 net/netfilter/nfnetlink.c:597  netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]  netlink_unicast+0x6cd/0xa00 net/netfilter/af_netlink.c:1340  netlink_sendmsg+0x906/0xe10 net/netfilter/af_netlink.c:1919  sock_sendmsg_nosec net/socket.c:651 [inline]  __sock_sendmsg+0x155/0x190 net/socket.c:663  ____sys_sendmsg+0x705/0x870 net/socket.c:2379  ___sys_sendmsg+0x100/0x170 net/socket.c:2433  __sys_sendmsg+0xe9/0x1c0 net/socket.c:2462  do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46  entry_SYSCALL_64_after_hwframe+0x67/0xd1  Change the condition to WARN_ON_ONCE(err && err != -ENOMEM) so that warnings are only emitted for unexpected errors. This aligns with the common kernel practice of not warning on -ENOMEM.  Found by Linux Verification Center (linuxtesting.org) with Syzkaller.","cvss":[],"epss":[{"cve":"CVE-2026-80744","epss":0.00226,"percentile":0.13308,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.11299999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80744","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80744","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/09bda4b6df222fd1819e8f188c3a6e90caf546d3","https://git.kernel.org/stable/c/17c132e18ca5d1641ddbaed8d0e6ecfd1d38fa0b","https://git.kernel.org/stable/c/2319033c4bf8bdb275a9e4e1f7af9bf8a457ad79","https://git.kernel.org/stable/c/4a923fe60939a194777bc605036ce2147ab00c9d","https://git.kernel.org/stable/c/6ee3803c22b72508c5baf1e5aecb21301b714be0","https://git.kernel.org/stable/c/7ce9851be6f2b019e96e105a9de99715aec6deb4","https://git.kernel.org/stable/c/c23620a0fa5b1d80399f894c41a9f78bc29d6235","https://git.kernel.org/stable/c/d02f592064347e0c1e0d84f24941ad338838cc48"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path\n\nIn nft_flow_rule_offload_abort(), WARN_ON_ONCE(err) is triggered on every\nerror during rollback, including -ENOMEM. Memory allocation failures are\nexpected under low-memory conditions and do not indicate a kernel bug.\n\nTrace for example:\nnft_flow_offload_chain() // FLOW_BLOCK_BIND\n  nft_flow_block_chain()\n    nft_chain_offload_cmd()\n      nft_block_offload_cmd()\n        ->ndo_setup_tc()\n        nsim_setup_tc()\n          flow_block_cb_setup_simple()\n            flow_block_cb_alloc() // fails to -ENOMEM\n\nThe warning was reproduced on the 5.10 stable kernel under memory pressure\nvia fault injection, but the underlying bug exists in mainline as well,\nas demonstrated by the ENOMEM trace above. The following splat was\ntriggered during nf_tables transaction processing:\n\nWARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline]\nWARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591\nModules linked in:\nCPU: 0 PID: 8567 Comm: syz-executor.0 Not tainted 5.10.260-syzkaller #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\nRIP: 0010:nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline]\nRIP: 0010:nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591\nCall Trace:\n nf_tables_commit+0x3bd/0x4bd0 net/netfilter/nf_tables_api.c:8604\n nfnetlink_rcv_batch+0xb1e/0x1f20 net/netfilter/nfnetlink.c:509\n nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:579 [inline]\n nfnetlink_rcv+0x3b3/0x420 net/netfilter/nfnetlink.c:597\n netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]\n netlink_unicast+0x6cd/0xa00 net/netfilter/af_netlink.c:1340\n netlink_sendmsg+0x906/0xe10 net/netfilter/af_netlink.c:1919\n sock_sendmsg_nosec net/socket.c:651 [inline]\n __sock_sendmsg+0x155/0x190 net/socket.c:663\n ____sys_sendmsg+0x705/0x870 net/socket.c:2379\n ___sys_sendmsg+0x100/0x170 net/socket.c:2433\n __sys_sendmsg+0xe9/0x1c0 net/socket.c:2462\n do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46\n entry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nChange the condition to WARN_ON_ONCE(err && err != -ENOMEM) so that\nwarnings are only emitted for unexpected errors. This aligns with the\ncommon kernel practice of not warning on -ENOMEM.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.","cvss":[],"epss":[{"cve":"CVE-2026-80744","epss":0.00226,"percentile":0.13308,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80744","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80747","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80747","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Add bounds check for CRAT subtype length  The CRAT parser validates that the subtype header fits within the image, but does not verify that the advertised subtype length fits. A malformed CRAT table with an oversized length field causes out-of-bounds reads when kfd_parse_subtype() casts the header to specific subtype structures.  Add validation that sub_type_hdr + length does not exceed the image boundary before parsing the subtype contents.  (cherry picked from commit 48e1d1e6e8798aef0312e68d8e586021b5b3cf4d)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80747","epss":0.00164,"percentile":0.05882,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1271},"relatedVulnerabilities":[{"id":"CVE-2026-80747","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80747","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/6e7566ba4739dd573c331adde1c96690f7a567bd","https://git.kernel.org/stable/c/ca91e0cc8087568e4b791648a7c01e804f48cb73"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Add bounds check for CRAT subtype length\n\nThe CRAT parser validates that the subtype header fits within the image,\nbut does not verify that the advertised subtype length fits. A malformed\nCRAT table with an oversized length field causes out-of-bounds reads when\nkfd_parse_subtype() casts the header to specific subtype structures.\n\nAdd validation that sub_type_hdr + length does not exceed the image\nboundary before parsing the subtype contents.\n\n(cherry picked from commit 48e1d1e6e8798aef0312e68d8e586021b5b3cf4d)","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":8,"exploitabilityScore":2.6,"impactScore":5.5},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80747","epss":0.00164,"percentile":0.05882,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80747","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80752","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80752","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: psxpad-spi - set driver data before use  psxpad_spi_suspend() retrieves the controller state with spi_get_drvdata(), but probe never stores it, so suspend dereferences a NULL pointer. Store it during probe.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80752","epss":0.00182,"percentile":0.07927,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.14469},"relatedVulnerabilities":[{"id":"CVE-2026-80752","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80752","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/1bba6bd6861b1e0c8ecf20cd1892f0d3877c02a2","https://git.kernel.org/stable/c/1edcb7ffee7ac4dc35cbe5bbd0e27bac3614ebe4","https://git.kernel.org/stable/c/62e25677d1440085381b047ec4984be9b6793759","https://git.kernel.org/stable/c/732f38c36059e68ba3b4b89c56911d777fd3185c","https://git.kernel.org/stable/c/86531cdfb3a03213e2569deed5195412a4e3f7ee","https://git.kernel.org/stable/c/8d622c58205adbc8af19864e277386528b671345","https://git.kernel.org/stable/c/da6b8b05db0cf43e0cc198431fa8ee9739b3b817","https://git.kernel.org/stable/c/e980066e434a9c74ff1665ed9140427e95b0ee7c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: psxpad-spi - set driver data before use\n\npsxpad_spi_suspend() retrieves the controller state with\nspi_get_drvdata(), but probe never stores it, so suspend dereferences a\nNULL pointer. Store it during probe.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"exploitabilityScore":2.6,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80752","epss":0.00182,"percentile":0.07927,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80752","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80754","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80754","namespace":"debian:distro:debian:12","severity":"High","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Input: synaptics-rmi4 - fix F55 transmitter electrode count typo  During F55 sensor detection, the transmitter (TX) electrode count was incorrectly assigned the value of the receiver (RX) electrode count due to copy-paste typos.  This incorrect value was then propagated to the driver data and used by F54 to determine the diagnostics report size. On devices with more RX than TX electrodes, this inflated the perceived TX count, leading to incorrect report size calculations and potential out-of-bounds buffer accesses.  Fix the typos by correctly assigning the TX electrode counts.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80754","epss":0.00164,"percentile":0.05903,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.12546000000000002},"relatedVulnerabilities":[{"id":"CVE-2026-80754","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80754","namespace":"nvd:cpe","severity":"High","urls":["https://git.kernel.org/stable/c/0739c65e799d4a93fe573ed23255a71fcfcc5438","https://git.kernel.org/stable/c/6058f0fea10f3caf63a435677358d1b8e9325114","https://git.kernel.org/stable/c/6484e00d6778fdf2209cd75940bc3902b276457f","https://git.kernel.org/stable/c/9759502f5cd71805923457f183ae5b9533e20c7b","https://git.kernel.org/stable/c/9b184c8337c6e12df129399007735a7fbcbbcb7b","https://git.kernel.org/stable/c/a6d9646e77da7cab2dff7043a8e9f75e23b836bc","https://git.kernel.org/stable/c/a81cafe3c3c2f8494063385a7b0ea7ff407bf19f","https://git.kernel.org/stable/c/db4e20265ebda729610ca5cf45ca9437462c3f36"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - fix F55 transmitter electrode count typo\n\nDuring F55 sensor detection, the transmitter (TX) electrode count was\nincorrectly assigned the value of the receiver (RX) electrode count\ndue to copy-paste typos.\n\nThis incorrect value was then propagated to the driver data and used\nby F54 to determine the diagnostics report size. On devices with more\nRX than TX electrodes, this inflated the perceived TX count, leading\nto incorrect report size calculations and potential out-of-bounds\nbuffer accesses.\n\nFix the typos by correctly assigning the TX electrode counts.","cvss":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","version":"3.1","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"exploitabilityScore":1.9,"impactScore":5.9},"vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-80754","epss":0.00164,"percentile":0.05903,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80754","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80755","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80755","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: reject a permission value exceeding the class permission count  perm_read() bounds a permission value by SEL_VEC_MAX but never by the nprim of the owning class or common, which is taken verbatim from the policy image.  security_get_permissions() then writes perms[value - 1] into an nprim-sized kcalloc() array, so a class declaring fewer permissions than its largest permission value drives an out-of-bounds heap write.  The top-level symbol tables are validated this way; the nested per-class permission table is not.  Reject a permission whose value exceeds nprim, which is already set when perm_read() runs.  Well-formed policies are unaffected.  [PM: tweak comment for line length]","cvss":[],"epss":[{"cve":"CVE-2026-80755","epss":0.002,"percentile":0.09907,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.1},"relatedVulnerabilities":[{"id":"CVE-2026-80755","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80755","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/6c2ab7c4549f4f2305848df834e784651dbf1676","https://git.kernel.org/stable/c/a7f3d4f22d920dc3c7d75f02ece0f7bf2c58437e","https://git.kernel.org/stable/c/d14b5d0e97fccd27974fedc03b903408872907fd","https://git.kernel.org/stable/c/dfc59a062c386d3d4415ecdab781065a645f33cc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: reject a permission value exceeding the class permission count\n\nperm_read() bounds a permission value by SEL_VEC_MAX but never by the\nnprim of the owning class or common, which is taken verbatim from the\npolicy image.  security_get_permissions() then writes perms[value - 1]\ninto an nprim-sized kcalloc() array, so a class declaring fewer\npermissions than its largest permission value drives an out-of-bounds\nheap write.  The top-level symbol tables are validated this way; the\nnested per-class permission table is not.\n\nReject a permission whose value exceeds nprim, which is already set when\nperm_read() runs.  Well-formed policies are unaffected.\n\n[PM: tweak comment for line length]","cvss":[],"epss":[{"cve":"CVE-2026-80755","epss":0.002,"percentile":0.09907,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80755","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80756","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80756","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: do not cancel a policy conversion that never started  sel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes() fails, and that helper dereferences the outgoing policy to cancel its sidtab conversion. On the first policy load there is no outgoing policy: security_load_policy() returns early for that case, before it converts anything, and state->policy is still NULL. A first load that fails while building the selinuxfs tree therefore takes a NULL dereference in selinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load.  Skip the cancel when there is no old policy, mirroring the check security_load_policy() already makes before it converts.","cvss":[],"epss":[{"cve":"CVE-2026-80756","epss":0.0021,"percentile":0.11272,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-80756","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80756","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1059789ae9f99cbbe3a78e361e9c0976beb5958b","https://git.kernel.org/stable/c/1acc317d67a755a45e32419a15d70e403fa43f0e","https://git.kernel.org/stable/c/1b4ff94ae7c580c880291519fb0e3e2bd075beef","https://git.kernel.org/stable/c/219c96de5d9b6b4af7e8576ad897b774cc3ee9a7","https://git.kernel.org/stable/c/2d29983104f06f5b0babcd5a25a0f0408272cd27","https://git.kernel.org/stable/c/a42932c6aa33d0aac683cacdf1ec7009b955ba5d","https://git.kernel.org/stable/c/a4f182f8715cb0819445f0850cd5436828f4bafc","https://git.kernel.org/stable/c/e5c0235a3c4e9eb047a16cd02323fe4ecf2f570e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: do not cancel a policy conversion that never started\n\nsel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes()\nfails, and that helper dereferences the outgoing policy to cancel its\nsidtab conversion. On the first policy load there is no outgoing policy:\nsecurity_load_policy() returns early for that case, before it converts\nanything, and state->policy is still NULL. A first load that fails while\nbuilding the selinuxfs tree therefore takes a NULL dereference in\nselinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load.\n\nSkip the cancel when there is no old policy, mirroring the check\nsecurity_load_policy() already makes before it converts.","cvss":[],"epss":[{"cve":"CVE-2026-80756","epss":0.0021,"percentile":0.11272,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80756","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80757","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80757","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: reject a class permission count below its inherited common  security_get_permissions() maps an inherited common's permissions into an array sized by the class's own permissions.nprim, but class_read() takes that nprim verbatim from the policy image and never checks that it covers the common.  A class that inherits a common of N permissions while declaring a smaller nprim is accepted, and on load the common's permissions are written past the class-sized array -- an out-of-bounds heap write.  Reject a class whose permission count is below its inherited common's. Well-formed policies, where the class count already includes the inherited permissions, are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80757","epss":0.0021,"percentile":0.11274,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.105},"relatedVulnerabilities":[{"id":"CVE-2026-80757","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80757","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1b995966c3ae5244751bdaee9bfe7e17567d4fbe","https://git.kernel.org/stable/c/2002ff745db64ac83ee1bb9ff78196d2d68bfdb3","https://git.kernel.org/stable/c/2b7ffd7921fcbfe408fb7b372e47454e45b1e6a7","https://git.kernel.org/stable/c/38d91446630a20ce8c2a981810deea81fd61a3b5","https://git.kernel.org/stable/c/638213f2e6ea52c06a25861616781338d154db35","https://git.kernel.org/stable/c/9a82dcd98b6e6e11cfd162410967951f12152528","https://git.kernel.org/stable/c/a63011c009ea79439b800a05602b880eb4adbb05","https://git.kernel.org/stable/c/acd5b09be98fd38b7392307880156fb0452a7276"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: reject a class permission count below its inherited common\n\nsecurity_get_permissions() maps an inherited common's permissions into\nan array sized by the class's own permissions.nprim, but class_read()\ntakes that nprim verbatim from the policy image and never checks that it\ncovers the common.  A class that inherits a common of N permissions while\ndeclaring a smaller nprim is accepted, and on load the common's\npermissions are written past the class-sized array -- an out-of-bounds\nheap write.\n\nReject a class whose permission count is below its inherited common's.\nWell-formed policies, where the class count already includes the\ninherited permissions, are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80757","epss":0.0021,"percentile":0.11274,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80757","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80761","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80761","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: ISO: zero the sockaddr before returning it in getname  iso_sock_getname() fills a struct sockaddr_iso in place and returns its size without clearing it first, so bytes it does not write are copied to user space from the kernel stack. The getsockname(2) and getpeername(2) paths both run through do_getsockname(), which hands getname() an uninitialized sockaddr_storage on the stack and copies back up to the number of bytes getname() returns, so the driver has to initialize every byte it accounts for.  Two ranges are left uninitialized:    - struct sockaddr_iso is 10 bytes but only 9 are written (family,     iso_bdaddr, iso_bdaddr_type), leaking the trailing pad byte on every     call.    - for a broadcast peer (BIS_LINK or PA_LINK) the returned length grows     by sizeof(struct sockaddr_iso_bc), but only bc_sid, bc_num_bis and     bc_bis are filled; bc_bdaddr and bc_bdaddr_type, the first 7 bytes of     that structure, are never written.  An unprivileged process can open a BTPROTO_ISO socket and reach the pad leak with getsockname(); the broadcast leak needs an established BIS/PA connection. l2cap and rfcomm already memset their sockaddr in getname for the same reason; do the same here.","cvss":[],"epss":[{"cve":"CVE-2026-80761","epss":0.00168,"percentile":0.06347,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80761","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80761","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/190b719b787eb4ca6c25b12fab224806f9108b06","https://git.kernel.org/stable/c/1f6d1f2611af0eb36b133a41d29ffd2cc2601615","https://git.kernel.org/stable/c/884cf2cc957da7ac178a0e6c6c69ddfec0481cc8","https://git.kernel.org/stable/c/9069be87c67f290783b332c4284e09fb89cb9ea7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: zero the sockaddr before returning it in getname\n\niso_sock_getname() fills a struct sockaddr_iso in place and returns its\nsize without clearing it first, so bytes it does not write are copied to\nuser space from the kernel stack. The getsockname(2) and getpeername(2)\npaths both run through do_getsockname(), which hands getname() an\nuninitialized sockaddr_storage on the stack and copies back up to the\nnumber of bytes getname() returns, so the driver has to initialize every\nbyte it accounts for.\n\nTwo ranges are left uninitialized:\n\n  - struct sockaddr_iso is 10 bytes but only 9 are written (family,\n    iso_bdaddr, iso_bdaddr_type), leaking the trailing pad byte on every\n    call.\n\n  - for a broadcast peer (BIS_LINK or PA_LINK) the returned length grows\n    by sizeof(struct sockaddr_iso_bc), but only bc_sid, bc_num_bis and\n    bc_bis are filled; bc_bdaddr and bc_bdaddr_type, the first 7 bytes of\n    that structure, are never written.\n\nAn unprivileged process can open a BTPROTO_ISO socket and reach the pad\nleak with getsockname(); the broadcast leak needs an established BIS/PA\nconnection. l2cap and rfcomm already memset their sockaddr in getname\nfor the same reason; do the same here.","cvss":[],"epss":[{"cve":"CVE-2026-80761","epss":0.00168,"percentile":0.06347,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80761","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80762","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80762","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_sync: Fix accept list UAF during suspend  hci_update_event_filter_sync() walks hdev->accept_list while sending a synchronous HCI command for each remote-wakeup device.  The suspend path holds hdev->req_lock, but accept-list updates are serialized by hdev->lock. Consequently, remove_device() can free the current list entry during the controller wait.  The following interleaving causes the use-after-free:    hci_update_event_filter_sync()    remove_device()   fetch accept-list entry   hci_set_event_filter_sync()     wait for controller response    hci_dev_lock()                                     list_del()                                     kfree()                                     hci_dev_unlock()   read the freed list.next  KASAN reported:    BUG: KASAN: slab-use-after-free in hci_suspend_sync+0x835/0x910   Read of size 8 at addr ffff88810bec8440 by task kworker/0:1/10   Workqueue: events vhci_suspend_work   Call Trace:    hci_suspend_sync+0x835/0x910    hci_suspend_dev+0x182/0x450    process_one_work+0x661/0x1090    worker_thread+0x45b/0xd10    Allocated by task 86:    hci_bdaddr_list_add_with_flags+0x1a8/0x400    add_device+0x381/0x820    hci_sock_sendmsg+0x1033/0x1ea0    Freed by task 91:    kfree+0x131/0x3c0    remove_device+0x429/0xb70    hci_sock_sendmsg+0x1033/0x1ea0  Snapshot the remote-wakeup addresses under hdev->lock.  Release the lock before sending HCI commands.  Clear the controller event filter before building the snapshot, and skip allocation and the second list traversal when there are no matching entries.  This preserves the original filter and scan-state updates without retaining an accept-list node across a controller wait.","cvss":[],"epss":[{"cve":"CVE-2026-80762","epss":0.00173,"percentile":0.06839,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80762","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80762","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/29c59212a507804d7616b8abf491d30b4ab8e75f","https://git.kernel.org/stable/c/87ad116ac3abc6f2ce2b5b6c488f633003581eee","https://git.kernel.org/stable/c/95bb57bc11a91caf042ad00fca85e480d3fda37f","https://git.kernel.org/stable/c/b5181516a9f5c2fdb3271cdad72a5b16c6963a44","https://git.kernel.org/stable/c/bb5f5414d1a6272a16f68684e998f4063dd19f57","https://git.kernel.org/stable/c/f57b399c4fa1501b2d5451f52d861ece86bcf3db","https://git.kernel.org/stable/c/fe93a697a7a92fa9adf78c9ff67a10db3193290c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Fix accept list UAF during suspend\n\nhci_update_event_filter_sync() walks hdev->accept_list while sending a\nsynchronous HCI command for each remote-wakeup device.  The suspend path\nholds hdev->req_lock, but accept-list updates are serialized by hdev->lock.\nConsequently, remove_device() can free the current list entry during the\ncontroller wait.\n\nThe following interleaving causes the use-after-free:\n\n  hci_update_event_filter_sync()    remove_device()\n  fetch accept-list entry\n  hci_set_event_filter_sync()\n    wait for controller response    hci_dev_lock()\n                                    list_del()\n                                    kfree()\n                                    hci_dev_unlock()\n  read the freed list.next\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in hci_suspend_sync+0x835/0x910\n  Read of size 8 at addr ffff88810bec8440 by task kworker/0:1/10\n  Workqueue: events vhci_suspend_work\n  Call Trace:\n   hci_suspend_sync+0x835/0x910\n   hci_suspend_dev+0x182/0x450\n   process_one_work+0x661/0x1090\n   worker_thread+0x45b/0xd10\n\n  Allocated by task 86:\n   hci_bdaddr_list_add_with_flags+0x1a8/0x400\n   add_device+0x381/0x820\n   hci_sock_sendmsg+0x1033/0x1ea0\n\n  Freed by task 91:\n   kfree+0x131/0x3c0\n   remove_device+0x429/0xb70\n   hci_sock_sendmsg+0x1033/0x1ea0\n\nSnapshot the remote-wakeup addresses under hdev->lock.  Release the lock\nbefore sending HCI commands.  Clear the controller event filter before\nbuilding the snapshot, and skip allocation and the second list traversal\nwhen there are no matching entries.  This preserves the original filter\nand scan-state updates without retaining an accept-list node across a\ncontroller wait.","cvss":[],"epss":[{"cve":"CVE-2026-80762","epss":0.00173,"percentile":0.06839,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80762","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80763","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80763","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_event: validate LE Set CIG Parameters response  The Command Complete dispatch validates only the fixed part of the LE Set CIG Parameters response. After that part is pulled from the skb, hci_cc_le_set_cig_params() trusts num_handles and reads each entry in the trailing handle array.  Matching num_handles against the command's num_cis does not guarantee that the response contains the advertised handles. A truncated response from a malfunctioning controller can therefore make the handler read beyond the skb data.  Validate that the remaining skb data contains all advertised handles. Include this in the existing response validation so malformed responses also follow the established CIG failure handling.","cvss":[],"epss":[{"cve":"CVE-2026-80763","epss":0.00173,"percentile":0.06838,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80763","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80763","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0acd4eeb4b225b9bebbf9ef96cc10cdd79b94899","https://git.kernel.org/stable/c/26741d178f31932c9018b36b7953e6dc391436a4","https://git.kernel.org/stable/c/6fc540e835dddb518cef3ff522b780f701cd03df","https://git.kernel.org/stable/c/9e05783d0bb96a7b853cc058a7c7de2dc4a62154","https://git.kernel.org/stable/c/a34df5c4a439cfc04565fa5be608ed1e53134f1f","https://git.kernel.org/stable/c/d83ecb7b96105d932dabaa56ccd7418c25fb7cbb","https://git.kernel.org/stable/c/e3f82e8f2a5915f533b57a065e9a045aa2ee03bc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: validate LE Set CIG Parameters response\n\nThe Command Complete dispatch validates only the fixed part of the LE Set\nCIG Parameters response. After that part is pulled from the skb,\nhci_cc_le_set_cig_params() trusts num_handles and reads each entry in the\ntrailing handle array.\n\nMatching num_handles against the command's num_cis does not guarantee\nthat the response contains the advertised handles. A truncated response\nfrom a malfunctioning controller can therefore make the handler read\nbeyond the skb data.\n\nValidate that the remaining skb data contains all advertised handles.\nInclude this in the existing response validation so malformed responses\nalso follow the established CIG failure handling.","cvss":[],"epss":[{"cve":"CVE-2026-80763","epss":0.00173,"percentile":0.06838,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80763","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80764","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80764","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_event: fix LE list UAF on reset  hci_cc_reset() clears the LE accept and resolving lists without taking hdev->lock. Other command-complete handlers serialize updates to these lists with that lock, and the debugfs readers hold it while walking them.  This permits the reset completion and a debugfs read to interleave as follows:    hci_rx_work                 debugfs reader   -----------                 --------------                               lock hdev->lock                               fetch current entry   list_del(entry)   kfree(entry)                               read entry fields  The reader then dereferences a freed list entry and may follow its stale next pointer.  KASAN reported:    BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180   Read of size 1 at addr ffff8881015dab16 by task poc/95    Call Trace:    white_list_show+0x15f/0x180    seq_read_iter+0x3ff/0x1190    seq_read+0x267/0x3d0    vfs_read+0x177/0xa20    ksys_read+0xf7/0x1c0    Allocated by task 91:    hci_bdaddr_list_add+0x1a6/0x3a0    hci_cc_le_add_to_accept_list+0xab/0x140    hci_cmd_complete_evt+0x26c/0x9a0    hci_event_packet+0x454/0xb20    hci_rx_work+0x293/0x730    Freed by task 90:    kfree+0x131/0x3c0    hci_bdaddr_list_clear+0xd8/0x160    hci_cc_reset+0x28a/0x370    hci_cmd_complete_evt+0x26c/0x9a0    hci_event_packet+0x454/0xb20    hci_rx_work+0x293/0x730  Take hdev->lock around both list clears. This matches the existing mutation and traversal locking convention.","cvss":[],"epss":[{"cve":"CVE-2026-80764","epss":0.00173,"percentile":0.06839,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80764","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80764","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0628cc9b2fa29985a7b8c774741f8a736b0f5e7c","https://git.kernel.org/stable/c/25b05e3ce31d954540e99954bcc66cbceb27ab35","https://git.kernel.org/stable/c/33af47e847fe4a28b109673affb5874015d54f5a","https://git.kernel.org/stable/c/39a3afb91be3cb465f46ce7a8e5696d9e33edf93","https://git.kernel.org/stable/c/8e68c380290b1dd64a0a512ce66d0264130c46ed","https://git.kernel.org/stable/c/b55e83a4ba31d40deae22d4e4dc8c84083e953c6","https://git.kernel.org/stable/c/d57702d4c55633c243da5a2fec37ae2ad4adb621"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: fix LE list UAF on reset\n\nhci_cc_reset() clears the LE accept and resolving lists without taking\nhdev->lock. Other command-complete handlers serialize updates to these\nlists with that lock, and the debugfs readers hold it while walking them.\n\nThis permits the reset completion and a debugfs read to interleave as\nfollows:\n\n  hci_rx_work                 debugfs reader\n  -----------                 --------------\n                              lock hdev->lock\n                              fetch current entry\n  list_del(entry)\n  kfree(entry)\n                              read entry fields\n\nThe reader then dereferences a freed list entry and may follow its stale\nnext pointer.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180\n  Read of size 1 at addr ffff8881015dab16 by task poc/95\n\n  Call Trace:\n   white_list_show+0x15f/0x180\n   seq_read_iter+0x3ff/0x1190\n   seq_read+0x267/0x3d0\n   vfs_read+0x177/0xa20\n   ksys_read+0xf7/0x1c0\n\n  Allocated by task 91:\n   hci_bdaddr_list_add+0x1a6/0x3a0\n   hci_cc_le_add_to_accept_list+0xab/0x140\n   hci_cmd_complete_evt+0x26c/0x9a0\n   hci_event_packet+0x454/0xb20\n   hci_rx_work+0x293/0x730\n\n  Freed by task 90:\n   kfree+0x131/0x3c0\n   hci_bdaddr_list_clear+0xd8/0x160\n   hci_cc_reset+0x28a/0x370\n   hci_cmd_complete_evt+0x26c/0x9a0\n   hci_event_packet+0x454/0xb20\n   hci_rx_work+0x293/0x730\n\nTake hdev->lock around both list clears. This matches the existing\nmutation and traversal locking convention.","cvss":[],"epss":[{"cve":"CVE-2026-80764","epss":0.00173,"percentile":0.06839,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80764","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80765","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80765","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: hyperv: validate initial device info bounds  The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO messages that contain a HID descriptor followed by the report descriptor bytes. mousevsc_on_receive_device_info() trusts bLength and wDescriptorLength without checking that the received packet contains both byte ranges.  A malformed host or backend message can therefore make the guest read past the received VMBus packet while copying the report descriptor. Pass the received initial-device-info size into the parser and reject descriptor lengths that exceed the packet.  Impact: A malicious Hyper-V host or backend can crash a guest by sending a short initial device-info message with an oversized HID report descriptor length.","cvss":[],"epss":[{"cve":"CVE-2026-80765","epss":0.00195,"percentile":0.09347,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80765","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80765","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2529737763cb4bcfcaf397beeea2664656c865b4","https://git.kernel.org/stable/c/334271d3812ab3197c95b4593bc6745f8d189114","https://git.kernel.org/stable/c/390d3d9c52a710fdc9de95a537747397c0c671d1","https://git.kernel.org/stable/c/608f8fd8c0f7b6268da43509447802955f210aac","https://git.kernel.org/stable/c/8614c043b11cc35ffebd35542ab4da275f8f923d","https://git.kernel.org/stable/c/934b7778aa7b7c8f6bb073d2a73ba3674885bae0","https://git.kernel.org/stable/c/c894143c508a7e063aab9f73c9e835ab40121283","https://git.kernel.org/stable/c/e0d5d3e45e142b7ef7525654aaa54d3e986002a6","https://git.kernel.org/stable/c/f84d777574b748b1a488723ca7be9d87a301a872"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hyperv: validate initial device info bounds\n\nThe Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO\nmessages that contain a HID descriptor followed by the report descriptor\nbytes. mousevsc_on_receive_device_info() trusts bLength and\nwDescriptorLength without checking that the received packet contains both\nbyte ranges.\n\nA malformed host or backend message can therefore make the guest read\npast the received VMBus packet while copying the report descriptor. Pass\nthe received initial-device-info size into the parser and reject\ndescriptor lengths that exceed the packet.\n\nImpact: A malicious Hyper-V host or backend can crash a guest by sending\na short initial device-info message with an oversized HID report\ndescriptor length.","cvss":[],"epss":[{"cve":"CVE-2026-80765","epss":0.00195,"percentile":0.09347,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80765","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80766","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80766","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: uclogic: fix use-after-free of inrange_timer on remove  uclogic_remove() cancels the pen in-range timer and then stops the device:  \ttimer_delete_sync(&drvdata->inrange_timer); \thid_hw_stop(hdev);  timer_delete_sync() only guarantees the timer is idle at that instant. uclogic_raw_event_pen() keeps delivering pen reports until hid_hw_stop() stops the transport several lines later, and every report with pen->inrange == UCLOGIC_PARAMS_PEN_INRANGE_NONE re-arms the timer:  \tmod_timer(&drvdata->inrange_timer, jiffies + msecs_to_jiffies(100));  A report landing between the timer_delete_sync() call and the transport teardown in hid_hw_stop() re-arms inrange_timer after it was cancelled. uclogic_remove() then returns and the devm drvdata is freed, while hid_hw_stop() has already freed the input device drvdata->pen_input points at, so when the timer fires ~100 ms later uclogic_inrange_timeout() dereferences freed memory -- a use-after-free in timer-softirq context.  Swapping the two calls is not a fix: stopping the device first frees drvdata->pen_input via hidinput_disconnect() while the timer may still be pending, so a timer already armed before removal fires on the freed input device in the window before timer_delete_sync() runs.  Use timer_shutdown_sync() before hid_hw_stop() instead. It cancels the timer, waits for a running callback while pen_input is still valid, and prevents any further re-arming -- a later mod_timer() from an in-flight report is silently ignored -- so the timer is provably dead before hid_hw_stop() frees the inputs. This is the ordering the timer core documents for this \"timer re-armed from another path\" teardown case.","cvss":[],"epss":[{"cve":"CVE-2026-80766","epss":0.00177,"percentile":0.07333,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80766","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80766","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/506fd50a9027340f0e9dcc587d10ccb03312dba6","https://git.kernel.org/stable/c/849e537160bbb77fe419ecc3944bfe125dcd441b","https://git.kernel.org/stable/c/9d77ac82e57ead056cf3f71d347083ed9244ad90","https://git.kernel.org/stable/c/dc5108f18f58870a8dd4203a02a47e571a2be7f0","https://git.kernel.org/stable/c/e750cdb6de009aace3c77f37fe2173f96175e8e4","https://git.kernel.org/stable/c/f13d0a00204b05e62336da0ab72ea0d87b56690c","https://git.kernel.org/stable/c/f1b3ca06380531f49f988f4721d3ed30b0d7a5d2","https://git.kernel.org/stable/c/f40243358b407aec362fe305fabfcdc94a3abd89"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: uclogic: fix use-after-free of inrange_timer on remove\n\nuclogic_remove() cancels the pen in-range timer and then stops the\ndevice:\n\n\ttimer_delete_sync(&drvdata->inrange_timer);\n\thid_hw_stop(hdev);\n\ntimer_delete_sync() only guarantees the timer is idle at that instant.\nuclogic_raw_event_pen() keeps delivering pen reports until hid_hw_stop()\nstops the transport several lines later, and every report with\npen->inrange == UCLOGIC_PARAMS_PEN_INRANGE_NONE re-arms the timer:\n\n\tmod_timer(&drvdata->inrange_timer, jiffies + msecs_to_jiffies(100));\n\nA report landing between the timer_delete_sync() call and the transport\nteardown in hid_hw_stop() re-arms inrange_timer after it was cancelled.\nuclogic_remove() then returns and the devm drvdata is freed, while\nhid_hw_stop() has already freed the input device drvdata->pen_input\npoints at, so when the timer fires ~100 ms later\nuclogic_inrange_timeout() dereferences freed memory -- a use-after-free\nin timer-softirq context.\n\nSwapping the two calls is not a fix: stopping the device first frees\ndrvdata->pen_input via hidinput_disconnect() while the timer may still\nbe pending, so a timer already armed before removal fires on the freed\ninput device in the window before timer_delete_sync() runs.\n\nUse timer_shutdown_sync() before hid_hw_stop() instead. It cancels the\ntimer, waits for a running callback while pen_input is still valid, and\nprevents any further re-arming -- a later mod_timer() from an in-flight\nreport is silently ignored -- so the timer is provably dead before\nhid_hw_stop() frees the inputs. This is the ordering the timer core\ndocuments for this \"timer re-armed from another path\" teardown case.","cvss":[],"epss":[{"cve":"CVE-2026-80766","epss":0.00177,"percentile":0.07333,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80766","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80767","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80767","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: sensor: custom: Fix use-after-free in enable_sensor  enable_sensor_store() can call set_power_report_state(), which dereferences sensor_inst->power_state and sensor_inst->report_state. These pointers refer to entries in sensor_inst->fields.  Create the field attributes before exposing the enable_sensor sysfs attribute, so enable_sensor cannot be accessed before the state it depends on has been initialized.  On remove, delete enable_sensor before freeing the field attributes, so a concurrent sysfs write cannot dereference freed memory through power_state or report_state.","cvss":[],"epss":[{"cve":"CVE-2026-80767","epss":0.00195,"percentile":0.09345,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80767","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80767","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/244a1cb638370490ed74a8adb5cc3f1212602e32","https://git.kernel.org/stable/c/2ce90cfc6646a32100feabd7110ae0352aa01167","https://git.kernel.org/stable/c/7bb79a3cf45e0805aef74457e19deb77e18cf196","https://git.kernel.org/stable/c/8406d4b69d48bc72fb6f8812a65a17a1f903440b","https://git.kernel.org/stable/c/ad8fb82b04422f49530d2aa2753cc81d1c60102c","https://git.kernel.org/stable/c/c0757f10610542d763bd0bf9bda455b78afeef0b","https://git.kernel.org/stable/c/c2be74b0272b7f8f60739e7aaf0d36c0befe7136","https://git.kernel.org/stable/c/d37ff4e3635c18af907f25712596f8ccec323751","https://git.kernel.org/stable/c/d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: sensor: custom: Fix use-after-free in enable_sensor\n\nenable_sensor_store() can call set_power_report_state(), which\ndereferences sensor_inst->power_state and sensor_inst->report_state.\nThese pointers refer to entries in sensor_inst->fields.\n\nCreate the field attributes before exposing the enable_sensor sysfs\nattribute, so enable_sensor cannot be accessed before the state it\ndepends on has been initialized.\n\nOn remove, delete enable_sensor before freeing the field attributes,\nso a concurrent sysfs write cannot dereference freed memory through\npower_state or report_state.","cvss":[],"epss":[{"cve":"CVE-2026-80767","epss":0.00195,"percentile":0.09345,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80767","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80768","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80768","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: ft260: fix stack-use-after-return write in I2C read race  ft260_i2c_read() points dev->read_buf at a caller-supplied buffer (often an on-stack variable), arms a completion and waits up to five seconds for the device to return the data. The HID input callback ft260_raw_event() runs in the input/IRQ path, independent of the dev->lock mutex held by the read path, and copies the device-supplied payload into dev->read_buf after a plain NULL check.  These two paths share read_buf, read_idx and read_len with no serialization. If the device delays its response until the read times out, ft260_i2c_read() resets the controller, clears read_buf and returns, unwinding the stack frame the buffer lived in. A response that arrives at that moment lets ft260_raw_event() pass the NULL check and then memcpy() the device-controlled payload into the now-freed stack location, a bounded but attacker-influenced stack-use-after-return write triggerable by malicious or malfunctioning hardware.  Add a dedicated spinlock that serializes every access to read_buf, read_idx and read_len. ft260_raw_event() now holds it across the NULL check, the memcpy and the index update, while the read path takes it when arming and when clearing the buffer, so the teardown can no longer slip between the check and the copy.","cvss":[],"epss":[{"cve":"CVE-2026-80768","epss":0.00177,"percentile":0.07334,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80768","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80768","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2b907001e8a83cdb71e899fd3d77ab51e2c03f10","https://git.kernel.org/stable/c/460514d46e8892189fc933a1b4433811cfa5c309","https://git.kernel.org/stable/c/5aa5a1b7cc4b4bec5497ad9ef113fdfe37b232f3","https://git.kernel.org/stable/c/77832d8f1c81d9f84b6b54807fb278586001d754","https://git.kernel.org/stable/c/90e9298f2e4336a0e1ca7eeb173403df78056164","https://git.kernel.org/stable/c/a8e1f970f9040294cfd9100c681c32af6c2aeec0","https://git.kernel.org/stable/c/bf3e39df3a397fd82967a31d17c4e02c7feab221","https://git.kernel.org/stable/c/d7ffbdc076675c84128d5b904e4d5167fe9f3a7f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: ft260: fix stack-use-after-return write in I2C read race\n\nft260_i2c_read() points dev->read_buf at a caller-supplied buffer\n(often an on-stack variable), arms a completion and waits up to five\nseconds for the device to return the data. The HID input callback\nft260_raw_event() runs in the input/IRQ path, independent of the\ndev->lock mutex held by the read path, and copies the device-supplied\npayload into dev->read_buf after a plain NULL check.\n\nThese two paths share read_buf, read_idx and read_len with no\nserialization. If the device delays its response until the read\ntimes out, ft260_i2c_read() resets the controller, clears read_buf\nand returns, unwinding the stack frame the buffer lived in. A\nresponse that arrives at that moment lets ft260_raw_event() pass the\nNULL check and then memcpy() the device-controlled payload into the\nnow-freed stack location, a bounded but attacker-influenced\nstack-use-after-return write triggerable by malicious or\nmalfunctioning hardware.\n\nAdd a dedicated spinlock that serializes every access to read_buf,\nread_idx and read_len. ft260_raw_event() now holds it across the\nNULL check, the memcpy and the index update, while the read path\ntakes it when arming and when clearing the buffer, so the teardown\ncan no longer slip between the check and the copy.","cvss":[],"epss":[{"cve":"CVE-2026-80768","epss":0.00177,"percentile":0.07334,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80768","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80770","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80770","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: nintendo: stop device IO before hid_hw_stop on probe failure  nintendo_hid_probe() calls hid_device_io_start() before joycon_init() and joycon_leds_create().  If either fails, the error path jumps to err_close which calls hid_hw_close()/hid_hw_stop() without first calling hid_device_io_stop().  hid_hw_stop() does not stop device IO, so hid_input_report() may still run and access driver data that is being torn down, resulting in a use-after-free.  Add an err_io_stop label that calls hid_device_io_stop() before hid_hw_close(), and point the two post-io_start error paths at it.","cvss":[],"epss":[{"cve":"CVE-2026-80770","epss":0.00173,"percentile":0.06836,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80770","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80770","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/03a84f9f88b42cd49752ec0259922b67e4b88598","https://git.kernel.org/stable/c/13a3edf96568a0b7aacadea07c2adec53ac8f630","https://git.kernel.org/stable/c/1f74d3bff6fe04a64e02ab3661d2e0d554565aa6","https://git.kernel.org/stable/c/2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4","https://git.kernel.org/stable/c/5efcd7bbfaaec67d137c99aa0940fa34375db27f","https://git.kernel.org/stable/c/c023443f0e6cfd257846b6515c93c1ea08026593","https://git.kernel.org/stable/c/c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: stop device IO before hid_hw_stop on probe failure\n\nnintendo_hid_probe() calls hid_device_io_start() before joycon_init()\nand joycon_leds_create().  If either fails, the error path jumps to\nerr_close which calls hid_hw_close()/hid_hw_stop() without first calling\nhid_device_io_stop().\n\nhid_hw_stop() does not stop device IO, so hid_input_report() may still\nrun and access driver data that is being torn down, resulting in a\nuse-after-free.\n\nAdd an err_io_stop label that calls hid_device_io_stop() before\nhid_hw_close(), and point the two post-io_start error paths at it.","cvss":[],"epss":[{"cve":"CVE-2026-80770","epss":0.00173,"percentile":0.06836,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80770","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80771","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80771","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: nintendo: register input device after capabilities are set  input_register_device() exposes the device to userspace immediately. In joycon_input_create() it was called before joycon_config_rumble() configures the FF_RUMBLE capability and the memless force-feedback device, so a concurrent EVIOCSFF could dereference a NULL dev->ff.  Registering early also means the initial udev event lacks button and axis information, which can make input managers ignore the device.  Move input_register_device() to the end of joycon_input_create(), after all capabilities, the IMU input device and the force-feedback callbacks have been configured.","cvss":[],"epss":[{"cve":"CVE-2026-80771","epss":0.00168,"percentile":0.06348,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80771","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80771","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/268679f501386ad46405d42c2bcf89384cb5e256","https://git.kernel.org/stable/c/27dc4b8eadac73b3c3cc526c8547d8b4ae8528be","https://git.kernel.org/stable/c/3288bec1a21d582b504344380139cdc0e88ebe4d","https://git.kernel.org/stable/c/a9fc7547f911ada09da33c5e204e5acda38e765a","https://git.kernel.org/stable/c/d723bc1fe2e72b9252234e94c11af644ec477bf7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: register input device after capabilities are set\n\ninput_register_device() exposes the device to userspace immediately.\nIn joycon_input_create() it was called before joycon_config_rumble()\nconfigures the FF_RUMBLE capability and the memless force-feedback\ndevice, so a concurrent EVIOCSFF could dereference a NULL dev->ff.\n\nRegistering early also means the initial udev event lacks button and\naxis information, which can make input managers ignore the device.\n\nMove input_register_device() to the end of joycon_input_create(), after\nall capabilities, the IMU input device and the force-feedback callbacks\nhave been configured.","cvss":[],"epss":[{"cve":"CVE-2026-80771","epss":0.00168,"percentile":0.06348,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80771","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80772","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80772","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()  joycon_ctlr_read_handler() casts an incoming HID input report to struct joycon_input_report and parses it, guarding the cast only with a 12-byte length check:  \tif (size >= 12) /* make sure it contains the input report */ \t\tjoycon_parse_report(ctlr, (struct joycon_input_report *)data);  struct joycon_input_report is 49 bytes: a 13-byte header followed by a union whose IMU arm is 36 bytes. For an IMU report joycon_parse_report() -> joycon_parse_imu_report() walks that union (struct offsets 13..48), so a report of exactly 12 bytes with data[0] == JC_INPUT_IMU_DATA passes the guard yet is read up to 37 bytes past its declared length. The over-read bytes are decoded into accelerometer/gyroscope values and forwarded to userspace through the \"(IMU)\" input device, leaking driver-internal memory. data[0] and size are fully controlled by a malicious or spoofed Joy-Con/Pro Controller.  Receive buffers are sized to the maximum report length, so this is an over-read within the allocation rather than a slab OOB, but the decoded bytes still reach userspace.  The sibling subcmd path in joycon_ctlr_handle_event() already bounds the same cast correctly:  \tif (size < sizeof(struct joycon_input_report) || \t    data[0] != JC_INPUT_SUBCMD_REPLY) \t\tbreak;  Use the same sizeof(struct joycon_input_report) bound here.","cvss":[],"epss":[{"cve":"CVE-2026-80772","epss":0.00173,"percentile":0.06836,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80772","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80772","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/27b376b945c0aac46fcdfcc950b14a85b874b557","https://git.kernel.org/stable/c/33ea29f8b6141f2d265de807e110a6435b355cb0","https://git.kernel.org/stable/c/34725ed4719da424113db8449fb5485aaf71a913","https://git.kernel.org/stable/c/51cfd1adbe7a46bb08af162abb3ab3b6820e2d15","https://git.kernel.org/stable/c/addca61f9a23c0d20a387c2040e70479f54518e1","https://git.kernel.org/stable/c/bd397c4123a4bc084913d8c7fdb40ef94e9f8172","https://git.kernel.org/stable/c/d4cabd4089adb59cf7974915737c52cc47a9bb1b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()\n\njoycon_ctlr_read_handler() casts an incoming HID input report to\nstruct joycon_input_report and parses it, guarding the cast only with a\n12-byte length check:\n\n\tif (size >= 12) /* make sure it contains the input report */\n\t\tjoycon_parse_report(ctlr, (struct joycon_input_report *)data);\n\nstruct joycon_input_report is 49 bytes: a 13-byte header followed by a\nunion whose IMU arm is 36 bytes. For an IMU report joycon_parse_report()\n-> joycon_parse_imu_report() walks that union (struct offsets 13..48),\nso a report of exactly 12 bytes with data[0] == JC_INPUT_IMU_DATA passes\nthe guard yet is read up to 37 bytes past its declared length. The\nover-read bytes are decoded into accelerometer/gyroscope values and\nforwarded to userspace through the \"(IMU)\" input device, leaking\ndriver-internal memory. data[0] and size are fully controlled by a\nmalicious or spoofed Joy-Con/Pro Controller.\n\nReceive buffers are sized to the maximum report length, so this is an\nover-read within the allocation rather than a slab OOB, but the decoded\nbytes still reach userspace.\n\nThe sibling subcmd path in joycon_ctlr_handle_event() already bounds the\nsame cast correctly:\n\n\tif (size < sizeof(struct joycon_input_report) ||\n\t    data[0] != JC_INPUT_SUBCMD_REPLY)\n\t\tbreak;\n\nUse the same sizeof(struct joycon_input_report) bound here.","cvss":[],"epss":[{"cve":"CVE-2026-80772","epss":0.00173,"percentile":0.06836,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80772","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80781","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80781","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: core: fix OOB read of field->usage in hid_set_field()  hid_set_field() hands field->usage + offset to hid_dump_input() before the guard that bounds offset:  \thid_dump_input(field->report->device, field->usage + offset, value);  \tif (offset >= field->report_count) { \t\thid_err(...); \t\treturn -1; \t}  Under CONFIG_DEBUG_FS hid_dump_input() dereferences that pointer, with buf = hid_resolv_usage(usage->hid, NULL).  The usage[] array is allocated inline with the hid_field in hid_register_field() and holds field->maxusage entries, so an offset past it reads off the end of the kvzalloc()ed allocation and into a neighbouring object.  Had the guard run first, offset < report_count <= maxusage would already have confined the pointer to the array.  A caller supplies such an offset today.  picolcd_fb_send_tile() validates only report->maxfield before issuing hid_set_field(report->field[0], 11 + i, ...) for i = 0..31, so its offsets are fixed at 11..42 and are never checked against the bound field.  When the device registers that field with fewer usages, the framebuffer deferred-io work drives the read on every tile.  KASAN reports a 4-byte slab-out-of-bounds read in hid_dump_input() below hid_set_field(), and the same boot logs \"offset (1) exceeds report_count (1)\" from the guard that runs only afterwards.  Move the hid_dump_input() call below the guard.  Because field->maxusage >= field->report_count, the guard then establishes that field->usage + offset lies inside the array before it is dereferenced, for every caller and without changing behaviour on the valid path.  Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[],"epss":[{"cve":"CVE-2026-80781","epss":0.00195,"percentile":0.09344,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80781","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80781","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/313ead1abed945544703b100a12c5a10fdf78409","https://git.kernel.org/stable/c/465544b3d6602cfbdc2305d5cbfb7f4954353b63","https://git.kernel.org/stable/c/4993e1ab85d7d3f4a40d81852170f9665483bbd8","https://git.kernel.org/stable/c/5215ea00a747eca34cb2f603cfef91fef76c2558","https://git.kernel.org/stable/c/9a1d7c5f0d82e8665715d5e47c9410c6a97e3748","https://git.kernel.org/stable/c/a13cdb19fcb223ed41bdab3bab42b98dba87e90b","https://git.kernel.org/stable/c/a38212687519f2a72f43e62dec1348a690412404","https://git.kernel.org/stable/c/c1d9c16af51cc6ff92a5a062617d3b022dd01078","https://git.kernel.org/stable/c/cbcc0e8dea499e5ca86b583372ccb1815cccc570"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: fix OOB read of field->usage in hid_set_field()\n\nhid_set_field() hands field->usage + offset to hid_dump_input() before\nthe guard that bounds offset:\n\n\thid_dump_input(field->report->device, field->usage + offset, value);\n\n\tif (offset >= field->report_count) {\n\t\thid_err(...);\n\t\treturn -1;\n\t}\n\nUnder CONFIG_DEBUG_FS hid_dump_input() dereferences that pointer, with\nbuf = hid_resolv_usage(usage->hid, NULL).  The usage[] array is\nallocated inline with the hid_field in hid_register_field() and holds\nfield->maxusage entries, so an offset past it reads off the end of the\nkvzalloc()ed allocation and into a neighbouring object.  Had the guard\nrun first, offset < report_count <= maxusage would already have confined\nthe pointer to the array.\n\nA caller supplies such an offset today.  picolcd_fb_send_tile()\nvalidates only report->maxfield before issuing\nhid_set_field(report->field[0], 11 + i, ...) for i = 0..31, so its\noffsets are fixed at 11..42 and are never checked against the bound\nfield.  When the device registers that field with fewer usages, the\nframebuffer deferred-io work drives the read on every tile.  KASAN\nreports a 4-byte slab-out-of-bounds read in hid_dump_input() below\nhid_set_field(), and the same boot logs \"offset (1) exceeds\nreport_count (1)\" from the guard that runs only afterwards.\n\nMove the hid_dump_input() call below the guard.  Because\nfield->maxusage >= field->report_count, the guard then establishes that\nfield->usage + offset lies inside the array before it is dereferenced,\nfor every caller and without changing behaviour on the valid path.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>","cvss":[],"epss":[{"cve":"CVE-2026-80781","epss":0.00195,"percentile":0.09344,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80781","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80782","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80782","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: magicmouse: do not keep a stale msc->input if no input is claimed  magicmouse_input_mapping() caches the first hid_input's input_dev in msc->input while the report descriptor is parsed, and the rest of the driver treats a non-NULL msc->input as proof that an input device was registered.  That does not hold on the hid-input error path. If hidinput_connect() fails -- for instance because input_register_device() returns an error -- it unwinds through hidinput_disconnect(), which frees every input_dev it created, including the one cached in msc->input.  The failure does not abort the probe. hid_connect() only skips the claim:  \tif ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev, \t\t\t\tconnect_mask & HID_CONNECT_HIDINPUT_FORCE)) \t\thdev->claimed |= HID_CLAIMED_INPUT;  and the \"device has no listeners\" bailout below it does not fire for this driver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad 2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore returns 0 and magicmouse_probe() continues with msc->input pointing at freed memory. Being non-NULL, it passes the \"input not registered\" check in probe and the NULL checks in ->raw_event and ->event, so the next input report dereferences freed memory.  Clear msc->input when the HID core did not claim an input device, so the existing NULL checks cover this case as well.","cvss":[],"epss":[{"cve":"CVE-2026-80782","epss":0.00195,"percentile":0.0934,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80782","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80782","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0af3b89705688af01aa06025b84fa7a1e06ba6cc","https://git.kernel.org/stable/c/0bf253e9ac994cb5329bc87b00bb4eeca9136791","https://git.kernel.org/stable/c/15b60ade825c8ce9ec560048a4ae3747e4572be3","https://git.kernel.org/stable/c/2ef16934e069d5f771e989d6ee5c3ece5042f3cd","https://git.kernel.org/stable/c/3d7a7bac4c75f25b2513505a0ac5ba909588ed2b","https://git.kernel.org/stable/c/403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14","https://git.kernel.org/stable/c/9bdf8c7bfd79f1090e61d28f969b32880fd77bb3","https://git.kernel.org/stable/c/c3597923932bb90d4fc2186aef552f6677175e4a","https://git.kernel.org/stable/c/e0c224c93d10ee38854fdf24c815108aedd3dcb3"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: do not keep a stale msc->input if no input is claimed\n\nmagicmouse_input_mapping() caches the first hid_input's input_dev in\nmsc->input while the report descriptor is parsed, and the rest of the\ndriver treats a non-NULL msc->input as proof that an input device was\nregistered.\n\nThat does not hold on the hid-input error path. If hidinput_connect()\nfails -- for instance because input_register_device() returns an error --\nit unwinds through hidinput_disconnect(), which frees every input_dev it\ncreated, including the one cached in msc->input.\n\nThe failure does not abort the probe. hid_connect() only skips the claim:\n\n\tif ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev,\n\t\t\t\tconnect_mask & HID_CONNECT_HIDINPUT_FORCE))\n\t\thdev->claimed |= HID_CLAIMED_INPUT;\n\nand the \"device has no listeners\" bailout below it does not fire for this\ndriver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad\n2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore\nreturns 0 and magicmouse_probe() continues with msc->input pointing at\nfreed memory. Being non-NULL, it passes the \"input not registered\" check\nin probe and the NULL checks in ->raw_event and ->event, so the next\ninput report dereferences freed memory.\n\nClear msc->input when the HID core did not claim an input device, so the\nexisting NULL checks cover this case as well.","cvss":[],"epss":[{"cve":"CVE-2026-80782","epss":0.00195,"percentile":0.0934,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80782","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80783","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80783","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()  magicmouse_raw_event() handles DOUBLE_REPORT_ID (0xf7) packets, which pack two touch reports into one, by splitting the packet and calling itself on each half. The only guard against runaway recursion is a \"size < 1\" check, which stops zero-sized calls but does not bound the recursion depth.  A malicious HID device that matches this driver can send a report starting with DOUBLE_REPORT_ID and filled with the sequence [0xf7, 0x00]. Each level consumes two bytes and recurses on the remainder, so an incoming report of up to HID_MAX_BUFFER_SIZE (16 KiB) drives roughly 8000 nested calls. That easily exhausts the 16 KiB kernel stack, leading to a stack overflow: a panic with CONFIG_VMAP_STACK, or memory corruption without it.  A double report only ever wraps two normal reports; it is never legitimately nested. Refuse to re-enter the DOUBLE_REPORT_ID case from a recursive call so the recursion depth is bounded to two, while all valid packets keep being parsed exactly as before.","cvss":[],"epss":[{"cve":"CVE-2026-80783","epss":0.00195,"percentile":0.09328,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80783","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80783","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/26c45abed62536aabf4033fb6d64cf72e93374e9","https://git.kernel.org/stable/c/70589b0c005db003f6d8ae4db3c4d54fed7b83e4","https://git.kernel.org/stable/c/8a10a624996f16628234306b46f0cf36707d78bd","https://git.kernel.org/stable/c/a33a596d3ad8dfe6c96a368097a028abeee16c17","https://git.kernel.org/stable/c/bec338b07beb883726b32192c8f01c601bc76fda","https://git.kernel.org/stable/c/d095de37f78c5f32a4252ef0f99b84ba76550b86","https://git.kernel.org/stable/c/d16df755b4493b6d37803c628b2c621d096796a8","https://git.kernel.org/stable/c/db8d634128d2ba88d79c0b601e983ebe14bb0519"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()\n\nmagicmouse_raw_event() handles DOUBLE_REPORT_ID (0xf7) packets, which pack\ntwo touch reports into one, by splitting the packet and calling itself on\neach half. The only guard against runaway recursion is a \"size < 1\" check,\nwhich stops zero-sized calls but does not bound the recursion depth.\n\nA malicious HID device that matches this driver can send a report starting\nwith DOUBLE_REPORT_ID and filled with the sequence [0xf7, 0x00]. Each level\nconsumes two bytes and recurses on the remainder, so an incoming report of\nup to HID_MAX_BUFFER_SIZE (16 KiB) drives roughly 8000 nested calls. That\neasily exhausts the 16 KiB kernel stack, leading to a stack overflow: a\npanic with CONFIG_VMAP_STACK, or memory corruption without it.\n\nA double report only ever wraps two normal reports; it is never\nlegitimately nested. Refuse to re-enter the DOUBLE_REPORT_ID case from a\nrecursive call so the recursion depth is bounded to two, while all valid\npackets keep being parsed exactly as before.","cvss":[],"epss":[{"cve":"CVE-2026-80783","epss":0.00195,"percentile":0.09328,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80783","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80784","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80784","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mptcp: pm: fix memory leak from alloc-during-teardown race  mptcp_pm_destroy() empties msk->pm.anno_list and msk->pm.userspace_pm_local_addr_list under msk->pm.lock during socket teardown, dropping the lock between the two.  A concurrent userspace PM genl ANNOUNCE on the same msk holds a sock reference via mptcp_token_get_sock() and, in mptcp_pm_nl_announce_doit(), calls mptcp_userspace_pm_append_new_local_addr() and mptcp_pm_announced_alloc(). Both take msk->pm.lock briefly to add to their respective lists. Because the genl handler holds a sock reference, mptcp_pm_destroy() may run on the same msk via mptcp_disconnect(), which invokes mptcp_destroy_common() without dropping the sock refcount, before the handler completes.  If the lock acquisitions interleave such that mptcp_pm_destroy() empties a list first, the later alloc adds its entry to a list head that nothing else iterates for this msk, and the entry leaks. kmemleak reports both mptcp_pm_add_addr objects (from mptcp_pm_announced_alloc()) and mptcp_pm_addr_entry objects (from mptcp_userspace_pm_append_new_local_addr()) under sustained concurrent ANNOUNCE + close load against the userspace PM.  Add an MPTCP_PM_DESTROYING bit in msk->pm.status, set by mptcp_pm_destroy() under pm.lock before the lists are emptied and checked under pm.lock by the alloc paths. Either the alloc takes pm.lock first, in which case its entry is on the list when mptcp_pm_destroy() frees it; or mptcp_pm_destroy() takes pm.lock first, in which case the later alloc observes the bit and refuses.  Found by an MPTCP protocol-flow harness extending BRF (arXiv:2305.08782).","cvss":[],"epss":[{"cve":"CVE-2026-80784","epss":0.00173,"percentile":0.0684,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80784","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80784","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/6c290915a03fc8228b473641025cf762b256dbd2","https://git.kernel.org/stable/c/9fe5eebb664ecdba88f3fde18062d94b1d1c465f","https://git.kernel.org/stable/c/b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804","https://git.kernel.org/stable/c/bb32e9a6a9a9f99eeda16c4efe443400f3e43892","https://git.kernel.org/stable/c/efc33b5102ff859bacd390a5f30112d8e0c084c0","https://git.kernel.org/stable/c/f48341830e4202db3fe884b819b2db6740f0537d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: fix memory leak from alloc-during-teardown race\n\nmptcp_pm_destroy() empties msk->pm.anno_list and\nmsk->pm.userspace_pm_local_addr_list under msk->pm.lock during socket\nteardown, dropping the lock between the two.\n\nA concurrent userspace PM genl ANNOUNCE on the same msk holds a sock\nreference via mptcp_token_get_sock() and, in\nmptcp_pm_nl_announce_doit(), calls\nmptcp_userspace_pm_append_new_local_addr() and\nmptcp_pm_announced_alloc(). Both take msk->pm.lock briefly to add to\ntheir respective lists. Because the genl handler holds a sock reference,\nmptcp_pm_destroy() may run on the same msk via mptcp_disconnect(), which\ninvokes mptcp_destroy_common() without dropping the sock refcount,\nbefore the handler completes.\n\nIf the lock acquisitions interleave such that mptcp_pm_destroy() empties\na list first, the later alloc adds its entry to a list head that nothing\nelse iterates for this msk, and the entry leaks. kmemleak reports both\nmptcp_pm_add_addr objects (from mptcp_pm_announced_alloc()) and\nmptcp_pm_addr_entry objects (from\nmptcp_userspace_pm_append_new_local_addr()) under sustained concurrent\nANNOUNCE + close load against the userspace PM.\n\nAdd an MPTCP_PM_DESTROYING bit in msk->pm.status, set by\nmptcp_pm_destroy() under pm.lock before the lists are emptied and\nchecked under pm.lock by the alloc paths. Either the alloc takes pm.lock\nfirst, in which case its entry is on the list when mptcp_pm_destroy()\nfrees it; or mptcp_pm_destroy() takes pm.lock first, in which case the\nlater alloc observes the bit and refuses.\n\nFound by an MPTCP protocol-flow harness extending BRF (arXiv:2305.08782).","cvss":[],"epss":[{"cve":"CVE-2026-80784","epss":0.00173,"percentile":0.0684,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80784","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80785","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80785","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: serialize mode sysfs access with lock_fb_info()  show_mode(), show_modes(), and store_mode() access fb_info->modelist and fb_info->mode without holding lock_fb_info(). store_modes() takes lock_fb_info() while replacing the modelist and freeing the old one.  A concurrent reader or writer can load a pointer to an old modelist entry before store_modes() frees it, then dereference freed memory or store a stale freed pointer in fb_info->mode.  Take lock_fb_info() in show_mode(), show_modes(), and store_mode() to serialize with store_modes(). In show_mode(), copy the mode to the stack and format after dropping the lock. In store_mode(), split activate() into a _locked variant to avoid double-locking, and hold the locks for the modelist walk, mode conversion, activation, and fb_info->mode assignment together.","cvss":[],"epss":[{"cve":"CVE-2026-80785","epss":0.00155,"percentile":0.05023,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-80785","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80785","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/061db6b7a910b8378f3b2df64f8c0a3ddc6e85f2","https://git.kernel.org/stable/c/26135631ed8e487bc6aef70cc41934e258d09bbe"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: serialize mode sysfs access with lock_fb_info()\n\nshow_mode(), show_modes(), and store_mode() access fb_info->modelist\nand fb_info->mode without holding lock_fb_info(). store_modes() takes\nlock_fb_info() while replacing the modelist and freeing the old one.\n\nA concurrent reader or writer can load a pointer to an old modelist\nentry before store_modes() frees it, then dereference freed memory or\nstore a stale freed pointer in fb_info->mode.\n\nTake lock_fb_info() in show_mode(), show_modes(), and store_mode() to\nserialize with store_modes(). In show_mode(), copy the mode to the\nstack and format after dropping the lock. In store_mode(), split\nactivate() into a _locked variant to avoid double-locking, and hold\nthe locks for the modelist walk, mode conversion, activation, and\nfb_info->mode assignment together.","cvss":[],"epss":[{"cve":"CVE-2026-80785","epss":0.00155,"percentile":0.05023,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80785","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80786","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80786","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: Wrap user-invoked calls to fb_set_var() in helper  Handle fbcon during display updates in fb_set_var_from_user(). Check with fbcon if the mode change is possible, update hardware state and finally update fbcon. Update all callers.  Only the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other mode-changes callers in sysfs and driver code are missing fbcon-related steps.  With the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain fbcon state themselves.","cvss":[],"epss":[{"cve":"CVE-2026-80786","epss":0.00155,"percentile":0.05023,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-80786","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80786","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/07f7e46833f71472e30da54a50dacdf48521bdd3","https://git.kernel.org/stable/c/6f611e5e5f3327cf2e2daabe6ee5acac58cc784e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Wrap user-invoked calls to fb_set_var() in helper\n\nHandle fbcon during display updates in fb_set_var_from_user(). Check\nwith fbcon if the mode change is possible, update hardware state and\nfinally update fbcon. Update all callers.\n\nOnly the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other\nmode-changes callers in sysfs and driver code are missing fbcon-related\nsteps.\n\nWith the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain\nfbcon state themselves.","cvss":[],"epss":[{"cve":"CVE-2026-80786","epss":0.00155,"percentile":0.05023,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80786","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80788","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80788","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations  When fuzzing the nvme target code, I tripped a kernel warning in nvmet_tcp_map_data() because the length passed into the allocator is controlled by the remote initiator.  A remote initiator that sends a command with an SGL claiming a huge number, can create a scatterlist and iovec allocation of over 1 million entries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER and then the page allocator will trip on a WARN_ON_ONCE_GFP() message:    WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof   Workqueue: nvmet_tcp_wq nvmet_tcp_io_work   ...   sgl_alloc_order   nvmet_tcp_map_data   nvmet_tcp_try_recv_pdu  As it's never good to trip a kernel warning remotely due to many systems having panic-on-warn enabled, let's silence it by just add GFP_NOWARN to the allocation flags.","cvss":[],"epss":[{"cve":"CVE-2026-80788","epss":0.00195,"percentile":0.09342,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80788","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80788","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/737a3b535247226f6e1a7988fd9d6e63e7d6fc71","https://git.kernel.org/stable/c/7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e","https://git.kernel.org/stable/c/7fd6da0f28932442b51658bac4ff55565ca9b377","https://git.kernel.org/stable/c/86cc450022473c4a29b43a09f3ec22a9ef566dac","https://git.kernel.org/stable/c/8d01f0d0e96485e39ad89b859ef85e1dc3020465","https://git.kernel.org/stable/c/9b770e40bc00381e5ebf53653de5776773415be3","https://git.kernel.org/stable/c/9c95f7e66c62ee6c6abedcf1c04311f430ff5833","https://git.kernel.org/stable/c/c509f20be1cabda3087810bb2d658d66b3f31f35","https://git.kernel.org/stable/c/e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations\n\nWhen fuzzing the nvme target code, I tripped a kernel warning in\nnvmet_tcp_map_data() because the length passed into the allocator is\ncontrolled by the remote initiator.\n\nA remote initiator that sends a command with an SGL claiming a huge\nnumber, can create a scatterlist and iovec allocation of over 1 million\nentries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER\nand then the page allocator will trip on a WARN_ON_ONCE_GFP() message:\n\n  WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof\n  Workqueue: nvmet_tcp_wq nvmet_tcp_io_work\n  ...\n  sgl_alloc_order\n  nvmet_tcp_map_data\n  nvmet_tcp_try_recv_pdu\n\nAs it's never good to trip a kernel warning remotely due to many systems\nhaving panic-on-warn enabled, let's silence it by just add GFP_NOWARN to\nthe allocation flags.","cvss":[],"epss":[{"cve":"CVE-2026-80788","epss":0.00195,"percentile":0.09342,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80788","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80789","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80789","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet-tcp: bound SGL data length before allocating command buffers  nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length and, for the in-capsule offset descriptor (type 0x01), checks it against port->inline_data_size before use. Any other SGL descriptor type -- including the non-inline transport SGL data-block descriptor (type (NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A, the type a real host uses for out-of-capsule writes) skips that check entirely and falls straight through to:  \tcmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt);  with len taken directly from the wire, unbounded up to 4 GiB.  nvmet_req_init() only parses the command and never inspects sgl->length, and nvmet_check_transfer_len() -- the only other place transfer_len is validated -- runs later, from req->execute(), after the allocation has already happened. For a write command the target responds with an R2T and parks the command waiting for the host to send the data; if the host (or an unauthenticated peer that simply never follows up) never does, the sgl_alloc() buffer stays resident for the life of the command. NVMe/TCP has no mandatory authentication in the default configuration, so any peer able to reach the target portal and complete a Fabrics connect can drive this with a single crafted command, repeatable across queues and connections for amplification. This is unbounded kernel memory allocation triggered by a remote, effectively unauthenticated peer.  Validate len against the same NVMET_TCP_MAXH2CDATA ceiling this file already uses to bound per-PDU H2C data, for every SGL descriptor type, before doing any allocation. This closes the gap for the non-inline descriptor while leaving the existing, tighter inline_data_size check in place for the in-capsule case.  Runtime-verified on a v6.19 KASAN stand: with this bound in place, a crafted write command carrying an oversized non-inline SGL length is rejected before sgl_alloc() runs, where the same request previously drove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that stayed resident pending an R2T the host never satisfies.","cvss":[],"epss":[{"cve":"CVE-2026-80789","epss":0.00234,"percentile":0.14278,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.117},"relatedVulnerabilities":[{"id":"CVE-2026-80789","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80789","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0952541b153e258b99d39cdb03ea6919fdeb41d0","https://git.kernel.org/stable/c/14dbe37681a6a7e346fc147bb363ec7cca3180a0","https://git.kernel.org/stable/c/25ad03d5c0e858c4b63f1e4b6d461d2af1b30b22","https://git.kernel.org/stable/c/4a3f00262a044e8e15064b1a6860968bf0500bf4","https://git.kernel.org/stable/c/6d27199ebe8cb223022150f74be13f154a964474","https://git.kernel.org/stable/c/d2acc96c528d589f5827cfb90e8e9229dd9d8cb4","https://git.kernel.org/stable/c/d895e66628f939edbb98608f6e033d3d39e6e546","https://git.kernel.org/stable/c/f63e89a0310264264923f84406dea05fe752de62","https://git.kernel.org/stable/c/f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: bound SGL data length before allocating command buffers\n\nnvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length\nand, for the in-capsule offset descriptor (type 0x01), checks it\nagainst port->inline_data_size before use. Any other SGL descriptor\ntype -- including the non-inline transport SGL data-block descriptor\n(type (NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A,\nthe type a real host uses for out-of-capsule writes) skips that check\nentirely and falls straight through to:\n\n\tcmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt);\n\nwith len taken directly from the wire, unbounded up to 4 GiB.\n\nnvmet_req_init() only parses the command and never inspects\nsgl->length, and nvmet_check_transfer_len() -- the only other place\ntransfer_len is validated -- runs later, from req->execute(), after\nthe allocation has already happened. For a write command the target\nresponds with an R2T and parks the command waiting for the host to\nsend the data; if the host (or an unauthenticated peer that simply\nnever follows up) never does, the sgl_alloc() buffer stays resident\nfor the life of the command. NVMe/TCP has no mandatory authentication\nin the default configuration, so any peer able to reach the target\nportal and complete a Fabrics connect can drive this with a single\ncrafted command, repeatable across queues and connections for\namplification. This is unbounded kernel memory allocation\ntriggered by a remote, effectively unauthenticated peer.\n\nValidate len against the same NVMET_TCP_MAXH2CDATA ceiling this file\nalready uses to bound per-PDU H2C data, for every SGL descriptor type,\nbefore doing any allocation. This closes the gap for the non-inline\ndescriptor while leaving the existing, tighter inline_data_size check\nin place for the in-capsule case.\n\nRuntime-verified on a v6.19 KASAN stand: with this bound in place, a\ncrafted write command carrying an oversized non-inline SGL length is\nrejected before sgl_alloc() runs, where the same request previously\ndrove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that\nstayed resident pending an R2T the host never satisfies.","cvss":[],"epss":[{"cve":"CVE-2026-80789","epss":0.00234,"percentile":0.14278,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80789","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80790","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80790","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet-fc: fix invalid free in LS IOD error path  nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD array. If an rqstbuf allocation or response buffer DMA mapping fails, the unwind loop decrements iod past the start of the array. The final kfree(iod) therefore frees an address before the allocated object.  This can be reproduced with nvme-fcloop and failslab by setting fail-nth to 6 before creating a target port. KASAN reports:    BUG: KASAN: invalid-free in nvmet_fc_register_targetport   Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552  Free the original allocation base stored in tgtport->iod instead. With this fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM without any KASAN report.","cvss":[],"epss":[{"cve":"CVE-2026-80790","epss":0.00195,"percentile":0.09344,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80790","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80790","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1a8f007faefe8c226ec65896589f8d59b0a8d5a5","https://git.kernel.org/stable/c/371fb1bf902adaa59be32bd7e904a5317e604fd0","https://git.kernel.org/stable/c/449e9c4f8db84ad9d9bb288029b230bcf590faa2","https://git.kernel.org/stable/c/8bce9cd08aae4283badf8ddc11fbb6f57b75a81e","https://git.kernel.org/stable/c/94334ea92f4d7535f66f86e33681efa94827eddc","https://git.kernel.org/stable/c/b189c6e408896ccc23d2e76d7738847cdebf1532","https://git.kernel.org/stable/c/ba98d6796d12258e837ece065d2ecb59d76ce4ff","https://git.kernel.org/stable/c/bb9489f0dce58da730d3479588d6710d7a2c1b45","https://git.kernel.org/stable/c/d094582cce9c08516d714e7436a8f3b9211dda90"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-fc: fix invalid free in LS IOD error path\n\nnvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD\narray. If an rqstbuf allocation or response buffer DMA mapping fails,\nthe unwind loop decrements iod past the start of the array. The final\nkfree(iod) therefore frees an address before the allocated object.\n\nThis can be reproduced with nvme-fcloop and failslab by setting\nfail-nth to 6 before creating a target port. KASAN reports:\n\n  BUG: KASAN: invalid-free in nvmet_fc_register_targetport\n  Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552\n\nFree the original allocation base stored in tgtport->iod instead. With\nthis fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM\nwithout any KASAN report.","cvss":[],"epss":[{"cve":"CVE-2026-80790","epss":0.00195,"percentile":0.09344,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80790","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80791","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80791","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nvmet-auth: zero the AUTH_RECEIVE response buffer  nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builders write only a fixed-size message into it. The full allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a remote initiator receives the bytes past the built message -- up to nearly a page of uninitialized slab -- during the pre-authentication handshake.  Allocate the buffer with kzalloc() so the unwritten tail is zeroed before it is sent; conforming responses are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80791","epss":0.00207,"percentile":0.10865,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1035},"relatedVulnerabilities":[{"id":"CVE-2026-80791","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80791","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1d6837d98bf966a041af65de5f78de7409ff83bc","https://git.kernel.org/stable/c/2dcc9226203da7275a9c29d20007da278d73d5e9","https://git.kernel.org/stable/c/3ddcfb013322aa37eaa7a0d344b73079c38dfa21","https://git.kernel.org/stable/c/447b668faa14710f611e714031e3739ac3ec3a4f","https://git.kernel.org/stable/c/8f6363c8d54dde95982f0ab45e77cf57ec0efd62","https://git.kernel.org/stable/c/b26189d28442183a8b5edb754f4a6918f77ca84e","https://git.kernel.org/stable/c/dfcf013f77709ebdb282767edc2795a37cab5b57"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: zero the AUTH_RECEIVE response buffer\n\nnvmet_execute_auth_receive() allocates the response buffer with kmalloc()\nsized by the host-supplied AUTH_RECEIVE allocation length, but the\nDH-HMAC-CHAP builders write only a fixed-size message into it. The full\nallocation length is then copied to the wire by nvmet_copy_to_sgl(), so a\nremote initiator receives the bytes past the built message -- up to nearly\na page of uninitialized slab -- during the pre-authentication handshake.\n\nAllocate the buffer with kzalloc() so the unwritten tail is zeroed before\nit is sent; conforming responses are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80791","epss":0.00207,"percentile":0.10865,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80791","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80792","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80792","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: fix use-after-free in ip6_finish_output2()  ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit().  The LWT-BPF transmit path or other encapsulation operations within lwtunnel_xmit() can reallocate the skb head, freeing the memory that daddr points to.  When lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale daddr pointer to compute the nexthop and to look up or create the neighbour entry.  This results in a use-after-free read, which can leak sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or crash the system.  Fix this by re-fetching the IPv6 header and the destination address pointer after lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop computation and neighbour lookup operate on valid memory.","cvss":[],"epss":[{"cve":"CVE-2026-80792","epss":0.00195,"percentile":0.09342,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80792","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80792","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/087ee0d914aaae929f1660c9ca878e367655ba1a","https://git.kernel.org/stable/c/3c770ac4e6f07af7c7b40c474a3efc61ffed7862","https://git.kernel.org/stable/c/3dc98e5fe82d069dd29b124ffbdb679331dfea43","https://git.kernel.org/stable/c/73a187384a8c8b983c7fea046d716b6752a1e7a3","https://git.kernel.org/stable/c/75e0a544ebe9af663ef53ca21e9e9185c51fb54a","https://git.kernel.org/stable/c/99219c82804f266189388e8bf1cf5135d10d5515","https://git.kernel.org/stable/c/c95f01b78266828a57060d754fcbfc92123a98ed","https://git.kernel.org/stable/c/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e","https://git.kernel.org/stable/c/d960881b9312e781a3429aabceb223ce6b7c882f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix use-after-free in ip6_finish_output2()\n\nip6_finish_output2() caches a pointer to the IPv6 destination\naddress (daddr) before invoking lwtunnel_xmit().  The LWT-BPF\ntransmit path or other encapsulation operations within\nlwtunnel_xmit() can reallocate the skb head, freeing the memory\nthat daddr points to.  When lwtunnel_xmit() returns\nLWTUNNEL_XMIT_CONTINUE, the function continues to use the stale\ndaddr pointer to compute the nexthop and to look up or create the\nneighbour entry.  This results in a use-after-free read, which can\nleak sensitive kernel data, pollute the neighbour table with\narbitrary values, misdirect traffic, or crash the system.\n\nFix this by re-fetching the IPv6 header and the destination\naddress pointer after lwtunnel_xmit() returns\nLWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop\ncomputation and neighbour lookup operate on valid memory.","cvss":[],"epss":[{"cve":"CVE-2026-80792","epss":0.00195,"percentile":0.09342,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80792","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80793","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80793","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv4: reject undersized MTUs in ip_do_fragment()  ip_do_fragment() subtracts the IPv4 header length from the effective MTU and passes the resulting payload MTU to ip_frag_next().  If the effective MTU is smaller than hlen + 8, ip_frag_next() rounds the fragment payload length down to zero. The fragmentation state then never makes forward progress: state->left, state->ptr and state->offset stay unchanged while ip_do_fragment() keeps allocating and transmitting header-only fragments until the softlockup detector fires.  This is reproducible with a route installed using \"mtu lock 20\", but it is also reproducible without route MTU lock, for example by forwarding a packet to a device whose MTU is 20.  Fix it in ip_do_fragment() by rejecting mtu < hlen + 8 with -EMSGSIZE, matching the existing IPv6 fragmentation check.","cvss":[],"epss":[{"cve":"CVE-2026-80793","epss":0.00195,"percentile":0.0934,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80793","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80793","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3556beb8ca86677af2aca5bfbed6f8e790fccc83","https://git.kernel.org/stable/c/36e0741833bd823866f8cb9f112f37cea1a70b60","https://git.kernel.org/stable/c/515b6816ba0c12d8415c88e5f41e6ec029e35cfa","https://git.kernel.org/stable/c/74ce7389f8f562d39015f59a00ef7ad6acd37803","https://git.kernel.org/stable/c/a716a64a4ba68cd46f2745fba2b1099fe8e0aa59","https://git.kernel.org/stable/c/b0ea911453ce7210e8200a07a94d2458bd1e6430","https://git.kernel.org/stable/c/c0726f0caf8c6b3208552949e17d23634a2f3129","https://git.kernel.org/stable/c/c8a74adccaf028223054633b532593101dfcc581","https://git.kernel.org/stable/c/d9d1a676b033acabf8e5645f730486d1f8204a3f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: reject undersized MTUs in ip_do_fragment()\n\nip_do_fragment() subtracts the IPv4 header length from the effective\nMTU and passes the resulting payload MTU to ip_frag_next().\n\nIf the effective MTU is smaller than hlen + 8, ip_frag_next() rounds\nthe fragment payload length down to zero. The fragmentation state then\nnever makes forward progress: state->left, state->ptr and state->offset\nstay unchanged while ip_do_fragment() keeps allocating and transmitting\nheader-only fragments until the softlockup detector fires.\n\nThis is reproducible with a route installed using \"mtu lock 20\", but it\nis also reproducible without route MTU lock, for example by forwarding a\npacket to a device whose MTU is 20.\n\nFix it in ip_do_fragment() by rejecting mtu < hlen + 8 with -EMSGSIZE,\nmatching the existing IPv6 fragmentation check.","cvss":[],"epss":[{"cve":"CVE-2026-80793","epss":0.00195,"percentile":0.0934,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80793","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80794","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80794","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: nci: fix uninit-value in the RF discover/activated NTF handlers  nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a notification into an on-stack struct (nci_rf_discover_ntf / nci_rf_intf_activated_ntf) that is not initialised. The RF technology-specific parameters are only extracted when rf_tech_specific_params_len is non-zero, so a notification that reports a zero length leaves the rf_tech_specific_params union uninitialised - and both handlers then pass it to nci_add_new_protocol(), which reads it:   - discover:  nci_add_new_target() -> nci_add_new_protocol();  - activated: nci_target_auto_activated() -> nci_add_new_protocol().  nci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch condition and a memcpy() length and copies nfcid1/sens_res/sel_res into ndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET.    BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0    nci_add_new_protocol+0x624/0x6c0    nci_ntf_packet+0x25b2/0x3c30    nci_rx_work+0x318/0x5d0    process_scheduled_works+0x84b/0x17a0    worker_thread+0xc10/0x11b0    kthread+0x376/0x500   Local variable ntf.i created at:    nci_ntf_packet+0xbc2/0x3c30  Zero-initialise both on-stack notifications so the union reads back as zero when no technology-specific parameters are present.","cvss":[],"epss":[{"cve":"CVE-2026-80794","epss":0.00195,"percentile":0.09341,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80794","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80794","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095","https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a","https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a","https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00","https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3","https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6","https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818","https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f","https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix uninit-value in the RF discover/activated NTF handlers\n\nnci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each\nparse a notification into an on-stack struct (nci_rf_discover_ntf /\nnci_rf_intf_activated_ntf) that is not initialised. The RF\ntechnology-specific parameters are only extracted when\nrf_tech_specific_params_len is non-zero, so a notification that reports a\nzero length leaves the rf_tech_specific_params union uninitialised - and\nboth handlers then pass it to nci_add_new_protocol(), which reads it:\n\n - discover:  nci_add_new_target() -> nci_add_new_protocol();\n - activated: nci_target_auto_activated() -> nci_add_new_protocol().\n\nnci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch\ncondition and a memcpy() length and copies nfcid1/sens_res/sel_res into\nndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET.\n\n  BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0\n   nci_add_new_protocol+0x624/0x6c0\n   nci_ntf_packet+0x25b2/0x3c30\n   nci_rx_work+0x318/0x5d0\n   process_scheduled_works+0x84b/0x17a0\n   worker_thread+0xc10/0x11b0\n   kthread+0x376/0x500\n  Local variable ntf.i created at:\n   nci_ntf_packet+0xbc2/0x3c30\n\nZero-initialise both on-stack notifications so the union reads back as\nzero when no technology-specific parameters are present.","cvss":[],"epss":[{"cve":"CVE-2026-80794","epss":0.00195,"percentile":0.09341,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80794","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80795","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80795","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: nci: fix out-of-bounds write in nci_target_auto_activated()  nci_target_auto_activated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets without first checking the array is full; unlike its sibling nci_add_new_target(), which bails out when n_targets already equals NCI_MAX_DISCOVERED_TARGETS.  ndev->n_targets is only cleared by nci_clear_target_list(), so an NFCC that repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters NCI_DISCOVERY without clearing the target list) and reports an auto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the limit. The append then writes a struct nfc_target past the end of the array (a slab out-of-bounds write), and nfc_targets_found() goes on to walk the array with the inflated count:    BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci]   Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12   Workqueue: nfc0_nci_rx_wq nci_rx_work [nci]   Call trace:    nci_add_new_protocol+0x94/0x2ac [nci]    nci_ntf_packet+0xddc/0x11a0 [nci]    nci_rx_work+0x15c/0x1e0 [nci]    process_one_work+0x2dc/0x500    worker_thread+0x240/0x460    kthread+0x1c0/0x1d0    ret_from_fork+0x10/0x20    The buggy address belongs to the cache kmalloc-2k of size 2048   The buggy address is located 1024 bytes to the right of   allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618)  Guard nci_target_auto_activated() with the same check used by nci_add_new_target().","cvss":[],"epss":[{"cve":"CVE-2026-80795","epss":0.00195,"percentile":0.09341,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80795","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80795","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2","https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7","https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa","https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec","https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951","https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032","https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd","https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e","https://git.kernel.org/stable/c/d7083f41c21b30582e91b2e6de4d54dce74f6f9c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix out-of-bounds write in nci_target_auto_activated()\n\nnci_target_auto_activated() appends a target to the fixed-size array\nndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets\nwithout first checking the array is full; unlike its sibling\nnci_add_new_target(), which bails out when n_targets already equals\nNCI_MAX_DISCOVERED_TARGETS.\n\nndev->n_targets is only cleared by nci_clear_target_list(), so an NFCC\nthat repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters\nNCI_DISCOVERY without clearing the target list) and reports an\nauto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the\nlimit. The append then writes a struct nfc_target past the end of the\narray (a slab out-of-bounds write), and nfc_targets_found() goes on to\nwalk the array with the inflated count:\n\n  BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci]\n  Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12\n  Workqueue: nfc0_nci_rx_wq nci_rx_work [nci]\n  Call trace:\n   nci_add_new_protocol+0x94/0x2ac [nci]\n   nci_ntf_packet+0xddc/0x11a0 [nci]\n   nci_rx_work+0x15c/0x1e0 [nci]\n   process_one_work+0x2dc/0x500\n   worker_thread+0x240/0x460\n   kthread+0x1c0/0x1d0\n   ret_from_fork+0x10/0x20\n\n  The buggy address belongs to the cache kmalloc-2k of size 2048\n  The buggy address is located 1024 bytes to the right of\n  allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618)\n\nGuard nci_target_auto_activated() with the same check used by\nnci_add_new_target().","cvss":[],"epss":[{"cve":"CVE-2026-80795","epss":0.00195,"percentile":0.09341,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80795","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80796","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80796","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: nci: add data_len bound checks to activation parameter extractors  nci_extract_activation_params_iso_dep() and nci_extract_activation_params_nfc_dep() read an inner length byte from the NCI RF_INTF_ACTIVATED_NTF payload and use it to memcpy() into fixed kernel buffers, but neither function receives the caller-validated activation_params_len.  A crafted NCI notification with activation_params_len=1 and an inner length byte of up to 20 (NFC-A) or 50 (NFC-B) causes memcpy() to read that many bytes past the one valid byte in the activation params region -- a slab out-of-bounds read of kernel memory adjacent to the NCI skb.  The sibling nci_extract_rf_params_*() family was given equivalent protection by commit 571dcbeb8e63 (\"net: nfc: nci: Fix parameter validation for packet data\"), but the two activation parameter extractors were not updated at that time.  Add a data_len parameter to both functions, guard against an empty region before consuming the inner length byte, decrement the remaining count after consuming it, and clamp the copy length to what is actually available.  Update both call sites to pass ntf.activation_params_len, which is already validated against the skb at ntf.c:801.","cvss":[],"epss":[{"cve":"CVE-2026-80796","epss":0.00195,"percentile":0.09346,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80796","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80796","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0428fa2c22e2ba0cff766d3b80d461e149102045","https://git.kernel.org/stable/c/04e51353cb9fa321caaeeed8331d4cd041fbaca7","https://git.kernel.org/stable/c/1168484fe2b3828bf24a46f3c42a8719fade679b","https://git.kernel.org/stable/c/9620a91f8d643b680f417a435db399a04d1e06d8","https://git.kernel.org/stable/c/9b01f5af0dc59263b59391b148bc78d83c0354a9","https://git.kernel.org/stable/c/be311c0cfeadfbe815ea22d2914a98d06e3fab0e","https://git.kernel.org/stable/c/cf9d44be50b9074a5abdc301b4a3ba3e283591df","https://git.kernel.org/stable/c/e25b44bd8b8cc666b49a3fe0ef547e64d5b1e300","https://git.kernel.org/stable/c/f5c534b53f8c424a8e7633c9b585475c4bf4ee18"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: add data_len bound checks to activation parameter extractors\n\nnci_extract_activation_params_iso_dep() and\nnci_extract_activation_params_nfc_dep() read an inner length byte from\nthe NCI RF_INTF_ACTIVATED_NTF payload and use it to memcpy() into fixed\nkernel buffers, but neither function receives the caller-validated\nactivation_params_len.  A crafted NCI notification with\nactivation_params_len=1 and an inner length byte of up to 20 (NFC-A) or\n50 (NFC-B) causes memcpy() to read that many bytes past the one valid\nbyte in the activation params region -- a slab out-of-bounds read of\nkernel memory adjacent to the NCI skb.\n\nThe sibling nci_extract_rf_params_*() family was given equivalent\nprotection by commit 571dcbeb8e63 (\"net: nfc: nci: Fix parameter\nvalidation for packet data\"), but the two activation parameter\nextractors were not updated at that time.\n\nAdd a data_len parameter to both functions, guard against an empty\nregion before consuming the inner length byte, decrement the remaining\ncount after consuming it, and clamp the copy length to what is actually\navailable.  Update both call sites to pass ntf.activation_params_len,\nwhich is already validated against the skb at ntf.c:801.","cvss":[],"epss":[{"cve":"CVE-2026-80796","epss":0.00195,"percentile":0.09346,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80796","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80797","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80797","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: pn533: purge fragmented skbs during cleanup  pn53x_common_clean() purges resp_q before freeing the common PN533 state, but it leaves fragment_skb untouched.  The fragmentation helpers queue transmit fragments there while sending large initiator or target-mode frames, and those skbs remain owned by the driver until they are sent or discarded.  If the device is removed while fragments are still queued, the common cleanup path frees the PN533 state without releasing the queued fragment skbs, leaking them.  Purge fragment_skb during cleanup alongside resp_q.","cvss":[],"epss":[{"cve":"CVE-2026-80797","epss":0.00195,"percentile":0.09346,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80797","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80797","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/130b5ad4492f8e53d0398ee3af2b0e2388504d11","https://git.kernel.org/stable/c/2f5d093194ec24d7c29b91bf7df014924e0f4ea1","https://git.kernel.org/stable/c/4a52ec2457ff8c26206fcc20fa1972cc35a678c4","https://git.kernel.org/stable/c/5718fc62198c38c2de5316020a90506f9e75e0bb","https://git.kernel.org/stable/c/9319c3c4962efc8697246b563ea31c6d47f085aa","https://git.kernel.org/stable/c/d63e85c5d5555fe6aa65155d3a09452597e163c3","https://git.kernel.org/stable/c/e169277281373818ae1cedf976aa1e99118fb77d","https://git.kernel.org/stable/c/e7ed2ea5590fbe2d3be39ee4fb0c758a12e31d0c","https://git.kernel.org/stable/c/e95beff58b38c871c557bf84e528408283c2c0ad"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: purge fragmented skbs during cleanup\n\npn53x_common_clean() purges resp_q before freeing the common PN533 state,\nbut it leaves fragment_skb untouched.  The fragmentation helpers queue\ntransmit fragments there while sending large initiator or target-mode\nframes, and those skbs remain owned by the driver until they are sent or\ndiscarded.\n\nIf the device is removed while fragments are still queued, the common\ncleanup path frees the PN533 state without releasing the queued fragment\nskbs, leaking them.\n\nPurge fragment_skb during cleanup alongside resp_q.","cvss":[],"epss":[{"cve":"CVE-2026-80797","epss":0.00195,"percentile":0.09346,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80797","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80798","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80798","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: llcp: reject PDUs shorter than the LLCP header  Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the receive path never checked that a frame is at least LLCP_HEADER_SIZE bytes before parsing it.  nfc_llcp_rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/ nfc_llcp_ssap(), which dereference pdu->data[0] and pdu->data[1], and a CONNECT or CC PDU then computes  \ttlv_array_len = skb->len - LLCP_HEADER_SIZE;  as a size_t and hands it to the TLV walk. When the frame is shorter than the header the subtraction wraps to a huge value and the walk runs far past the buffer, an out-of-bounds read.  A nearby NFC device can reach this without authentication; LLCP link activation happens automatically after NFC-DEP.  Guard the common receive choke point __nfc_llcp_recv(), shared by both the target (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, so a short skb is dropped before the rx_work worker parses it. Use pskb_may_pull() rather than a skb->len test so the two header bytes are guaranteed to sit in the skb linear area even for a non-linear skb, matching how the sibling NCI and HCI receive paths validate their headers.  Reproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on linux-next.  Found by 0sec automated security-research tooling (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-80798","epss":0.00234,"percentile":0.14279,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.117},"relatedVulnerabilities":[{"id":"CVE-2026-80798","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80798","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3793d768b40f38bb97265dd5b9a8b8655c4e1b1d","https://git.kernel.org/stable/c/95674f506c6376d6722a23144c9acd26609771ed","https://git.kernel.org/stable/c/a7b9b449f5a5132221fff6adc11a9431ab8cd914","https://git.kernel.org/stable/c/ae5f20f5842f440b72d030e3a34fe182dd8eae42","https://git.kernel.org/stable/c/d3d90243393c48146911c67fd3792b549d21d9e6","https://git.kernel.org/stable/c/e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82","https://git.kernel.org/stable/c/e969e98410051b1ef8cc318bfe0c7e3f24ec766d","https://git.kernel.org/stable/c/eab47618e282602197db287ecbd1b09d356a2515","https://git.kernel.org/stable/c/f36cffea24bf3e2cc29a00d4b51dbcadc087d810"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: reject PDUs shorter than the LLCP header\n\nEvery LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the\nreceive path never checked that a frame is at least LLCP_HEADER_SIZE bytes\nbefore parsing it.\n\nnfc_llcp_rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/\nnfc_llcp_ssap(), which dereference pdu->data[0] and pdu->data[1], and a\nCONNECT or CC PDU then computes\n\n\ttlv_array_len = skb->len - LLCP_HEADER_SIZE;\n\nas a size_t and hands it to the TLV walk. When the frame is shorter than\nthe header the subtraction wraps to a huge value and the walk runs far\npast the buffer, an out-of-bounds read.\n\nA nearby NFC device can reach this without authentication; LLCP link\nactivation happens automatically after NFC-DEP.\n\nGuard the common receive choke point __nfc_llcp_recv(), shared by both the\ntarget (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, so\na short skb is dropped before the rx_work worker parses it. Use\npskb_may_pull() rather than a skb->len test so the two header bytes are\nguaranteed to sit in the skb linear area even for a non-linear skb,\nmatching how the sibling NCI and HCI receive paths validate their headers.\n\nReproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on\nlinux-next.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-80798","epss":0.00234,"percentile":0.14279,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80798","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80799","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80799","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers  nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain three related bugs in their TLV parsing loops:  1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data    advances offset past 255 it silently wraps to zero, causing    infinite loops or double-processing of buffer data.  2. Before reading tlv[0] (type) and tlv[1] (length) there is no    check that offset+2 <= tlv_array_len. A truncated TLV causes    an OOB read of one byte past the buffer end.  3. After reading the length field, the value bytes are accessed    without checking offset+2+length <= tlv_array_len. A crafted    length=0xFF on a short buffer causes up to 255 bytes of OOB    read past the buffer end.  Both functions are reachable without authentication via nfc_llcp_set_remote_gb() which feeds remote LLCP general bytes directly into nfc_llcp_parse_gb_tlv() with no additional validation.  Fix all three issues by widening offset from u8 to u16 and adding bounds checks for both the TLV header and value field before each access.","cvss":[],"epss":[{"cve":"CVE-2026-80799","epss":0.00234,"percentile":0.14279,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.117},"relatedVulnerabilities":[{"id":"CVE-2026-80799","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80799","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1","https://git.kernel.org/stable/c/2d239590d1845a706304833d40dd6d4fec20ad88","https://git.kernel.org/stable/c/382eaa770335acf4f16a5a55524500f2bb4207df","https://git.kernel.org/stable/c/78b20c8eeacd2e44a2d8a4cb5316d3c521d90911","https://git.kernel.org/stable/c/7f6f3d087c67a4346189ef2c36481455bbc59a74","https://git.kernel.org/stable/c/875285a165fd3b402de2ab3be0deb355d6f4caf5","https://git.kernel.org/stable/c/9c47d667963542c3cf8e3007b7f10c0904d08238","https://git.kernel.org/stable/c/a209334ed929941b20810c17c3a507445b0a7c85","https://git.kernel.org/stable/c/e84cdfdc4a6c88e8b751144458f2e04e24415a28"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: fix OOB read and u8 offset wrap in TLV parsers\n\nnfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain\nthree related bugs in their TLV parsing loops:\n\n1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data\n   advances offset past 255 it silently wraps to zero, causing\n   infinite loops or double-processing of buffer data.\n\n2. Before reading tlv[0] (type) and tlv[1] (length) there is no\n   check that offset+2 <= tlv_array_len. A truncated TLV causes\n   an OOB read of one byte past the buffer end.\n\n3. After reading the length field, the value bytes are accessed\n   without checking offset+2+length <= tlv_array_len. A crafted\n   length=0xFF on a short buffer causes up to 255 bytes of OOB\n   read past the buffer end.\n\nBoth functions are reachable without authentication via\nnfc_llcp_set_remote_gb() which feeds remote LLCP general bytes\ndirectly into nfc_llcp_parse_gb_tlv() with no additional\nvalidation.\n\nFix all three issues by widening offset from u8 to u16 and adding\nbounds checks for both the TLV header and value field before each\naccess.","cvss":[],"epss":[{"cve":"CVE-2026-80799","epss":0.00234,"percentile":0.14279,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80799","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80800","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80800","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: llcp: bound the connect_sn TLV walk to the skb  Commit 27256cdb290e (\"nfc: llcp: bound SNL TLV parsing to the skb and add length checks\") fixed the unbounded TLV walk in nfc_llcp_recv_snl(), and commit d8bd2dedbde5 (\"nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers\") subsequently bounded nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv(). One sibling parser sharing the same pattern remains unbounded: nfc_llcp_connect_sn().  nfc_llcp_connect_sn() walks a TLV list, reading a two-byte header (type, length) followed by length bytes of value, without checking that the two header bytes or the declared length stay within the buffer. It returns a pointer to a service name of up to 255 bytes that may point past the end of the skb; it is subsequently consumed by memcmp() in nfc_llcp_sock_from_sn(). In addition tlv_array_len was computed as \"skb->len - LLCP_HEADER_SIZE\" in size_t, so a CONNECT/CC frame shorter than the LLCP header underflows to a huge length and the walk runs far past the buffer.  nfc_llcp_connect_sn() is reachable from nfc_llcp_recv_connect() and nfc_llcp_recv_cc(), i.e. from received CONNECT and CC PDUs. A nearby NFC device can reach this without authentication; LLCP link activation happens automatically after NFC-DEP, and the nfc_llcp_rx_skb() dispatcher applies no minimum-length guard.  Walk the TLV list by pointer, bounded by skb_tail_pointer(skb), and validate each declared length before use, matching the approach already used for nfc_llcp_recv_snl(). Starting the walk at &skb->data[LLCP_HEADER_SIZE] against the tail pointer also removes the size_t underflow for short frames.  Found by 0sec automated security-research tooling (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-80800","epss":0.00234,"percentile":0.14279,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.117},"relatedVulnerabilities":[{"id":"CVE-2026-80800","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80800","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0cfbdb0e13ab5b0765d77f96af67eb879cbc9736","https://git.kernel.org/stable/c/1964addc8dd535a05d5d3b55b4d1ac19ae31aa65","https://git.kernel.org/stable/c/22e5177ba1196a0b272a6a46c2575eb940a939c4","https://git.kernel.org/stable/c/389986fd79e4d43f971a03b512645a1bb63c982f","https://git.kernel.org/stable/c/55c68ac93e7dacc0f5f608b9c39dd4ff48cf28e8","https://git.kernel.org/stable/c/65a0ec7783b06068dda6745dd689bf4a91ee64aa","https://git.kernel.org/stable/c/b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e","https://git.kernel.org/stable/c/e18d044bab6d3d0280639098c3fe6621692cbfe2","https://git.kernel.org/stable/c/e87527b506c40db9af528714b7b1240918eb80fc"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: bound the connect_sn TLV walk to the skb\n\nCommit 27256cdb290e (\"nfc: llcp: bound SNL TLV parsing to the skb and\nadd length checks\") fixed the unbounded TLV walk in nfc_llcp_recv_snl(),\nand commit d8bd2dedbde5 (\"nfc: llcp: fix OOB read and u8 offset wrap in\nTLV parsers\") subsequently bounded nfc_llcp_parse_gb_tlv() and\nnfc_llcp_parse_connection_tlv(). One sibling parser sharing the same\npattern remains unbounded: nfc_llcp_connect_sn().\n\nnfc_llcp_connect_sn() walks a TLV list, reading a two-byte header\n(type, length) followed by length bytes of value, without checking that\nthe two header bytes or the declared length stay within the buffer. It\nreturns a pointer to a service name of up to 255 bytes that may point\npast the end of the skb; it is subsequently consumed by memcmp() in\nnfc_llcp_sock_from_sn(). In addition tlv_array_len was computed as\n\"skb->len - LLCP_HEADER_SIZE\" in size_t, so a CONNECT/CC frame shorter\nthan the LLCP header underflows to a huge length and the walk runs far\npast the buffer.\n\nnfc_llcp_connect_sn() is reachable from nfc_llcp_recv_connect() and\nnfc_llcp_recv_cc(), i.e. from received CONNECT and CC PDUs. A nearby\nNFC device can reach this without authentication; LLCP link activation\nhappens automatically after NFC-DEP, and the nfc_llcp_rx_skb()\ndispatcher applies no minimum-length guard.\n\nWalk the TLV list by pointer, bounded by skb_tail_pointer(skb), and\nvalidate each declared length before use, matching the approach already\nused for nfc_llcp_recv_snl(). Starting the walk at\n&skb->data[LLCP_HEADER_SIZE] against the tail pointer also removes the\nsize_t underflow for short frames.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-80800","epss":0.00234,"percentile":0.14279,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80800","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80801","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80801","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: microread: validate target discovery payload lengths  microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were checked only against the destination nfc_target buffers, not against the actual skb length.  Validate that each gate-specific payload contains the fixed fields and UID bytes before reading or copying them.","cvss":[],"epss":[{"cve":"CVE-2026-80801","epss":0.00195,"percentile":0.09345,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80801","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80801","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/18f02354ed229b8e4561b580812d026e7eb29c85","https://git.kernel.org/stable/c/25519469972ef57c3edb1805dabd6c5612b90211","https://git.kernel.org/stable/c/92a6f0201bb68391b5eba1b3f330af007d7323b6","https://git.kernel.org/stable/c/953963b9ac5eecbb316617d337bfaa3d731e3c5e","https://git.kernel.org/stable/c/c6de4241f2efbbab286efbb84a9c7190298b3052","https://git.kernel.org/stable/c/cb298672282421159e53ab311fe49d204c8a52da","https://git.kernel.org/stable/c/d0902a7c454326c6384c614226ab8987f3fd425d","https://git.kernel.org/stable/c/dabfa26a208e56f4d8dbf26fddc48f188bdb0649","https://git.kernel.org/stable/c/e6397fe7b8b5ef18e051f49612d40ff476c5f7d9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: microread: validate target discovery payload lengths\n\nmicroread_target_discovered() parses target discovery payloads from\nskb->data according to the HCI gate. The fixed field offsets and UID\ncopies were checked only against the destination nfc_target buffers, not\nagainst the actual skb length.\n\nValidate that each gate-specific payload contains the fixed fields and\nUID bytes before reading or copying them.","cvss":[],"epss":[{"cve":"CVE-2026-80801","epss":0.00195,"percentile":0.09345,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80801","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80802","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80802","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: fdp: bound the device-reported read length and fix an skb leak  fdp_nci_i2c_read() takes the next packet length from two device-supplied bytes and never validates it. The value is a u16 used as the i2c_master_recv() count into a 261-byte on-stack buffer: a malicious, counterfeit or malfunctioning controller (or an i2c bus interposer) can drive it far past the buffer for a stack out-of-bounds write that clobbers the canary and return address, or below the minimum frame size (directly, or by truncating the computed sum) so the header/LRC strip and the next length read run past a short receive. Reject a length outside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD], as a corrupted packet already is, and force resynchronization.  The same loop allocates one data skb per iteration and assumes a length packet followed by a data packet; a device that sends two data packets in one call leaks the first skb when the second allocation overwrites it. Free a previously allocated skb before allocating the next.","cvss":[],"epss":[{"cve":"CVE-2026-80802","epss":0.00195,"percentile":0.09339,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80802","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80802","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0d723090645b82c1cb27cfd7ebf81f0e7c96bcae","https://git.kernel.org/stable/c/1aa3fc769b0c45bd19f8dab1697084c2b3f6d706","https://git.kernel.org/stable/c/1fc32327b927a6e2cde086f82575c29880844228","https://git.kernel.org/stable/c/7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1","https://git.kernel.org/stable/c/8d2c243b79854628ff076c38748c020042f02f57","https://git.kernel.org/stable/c/d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee","https://git.kernel.org/stable/c/db7e464b350969c6ea8340de00d9796e5fd5123b","https://git.kernel.org/stable/c/e5eec121f2c3bc4c7022613bedd9121a8aa4c949","https://git.kernel.org/stable/c/fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: fdp: bound the device-reported read length and fix an skb leak\n\nfdp_nci_i2c_read() takes the next packet length from two device-supplied\nbytes and never validates it. The value is a u16 used as the\ni2c_master_recv() count into a 261-byte on-stack buffer: a malicious,\ncounterfeit or malfunctioning controller (or an i2c bus interposer) can\ndrive it far past the buffer for a stack out-of-bounds write that\nclobbers the canary and return address, or below the minimum frame size\n(directly, or by truncating the computed sum) so the header/LRC strip\nand the next length read run past a short receive. Reject a length\noutside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD], as a\ncorrupted packet already is, and force resynchronization.\n\nThe same loop allocates one data skb per iteration and assumes a length\npacket followed by a data packet; a device that sends two data packets\nin one call leaks the first skb when the second allocation overwrites\nit. Free a previously allocated skb before allocating the next.","cvss":[],"epss":[{"cve":"CVE-2026-80802","epss":0.00195,"percentile":0.09339,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80802","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80803","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80803","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: digital: clamp SENSF_RES length to the destination buffer  digital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote NFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res field without an upper-bound check. A nearby malicious NFC-F device can send an oversized SENSF_RES response to overflow the stack-local struct nfc_target.  Clamp resp->len to NFC_SENSF_RES_MAXSIZE before the copy.  Found by 0sec automated security-research tooling (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-80803","epss":0.00195,"percentile":0.09339,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80803","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80803","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/31aa28ed732f66ab83c40ef53d99791be69b85c4","https://git.kernel.org/stable/c/344a56d7c8e0f3cbaff0bcb1bcd95a1a1db24b16","https://git.kernel.org/stable/c/4e942da2869bcd646353eef706b7dd82efeb9db5","https://git.kernel.org/stable/c/6afb29751ee731e7f7a96feb8a15f91441e552ba","https://git.kernel.org/stable/c/a1ef9bddfbb3ae42b036c5aa16cf386d78db70b6","https://git.kernel.org/stable/c/a56773e649ea99b344d6bbaf90f34c8e3fadef5d","https://git.kernel.org/stable/c/af4c0606f743e009254a8d252096855335ade85d","https://git.kernel.org/stable/c/d0756a98277e383c26fead988a96c91f0781cd7f","https://git.kernel.org/stable/c/e886c63d2ca7108826076989103a1ffa8a0bb8f4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: digital: clamp SENSF_RES length to the destination buffer\n\ndigital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote\nNFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res\nfield without an upper-bound check. A nearby malicious NFC-F device can\nsend an oversized SENSF_RES response to overflow the stack-local struct\nnfc_target.\n\nClamp resp->len to NFC_SENSF_RES_MAXSIZE before the copy.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).","cvss":[],"epss":[{"cve":"CVE-2026-80803","epss":0.00195,"percentile":0.09339,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80803","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80805","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80805","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfs: validate attr entry pointer before field access  xfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen, valuelen) before checking if the entry pointer itself is within bounds. If nameidx is crafted to point near the end of the buffer, these field accesses can read out-of-bounds before the bounds check at name_end > buf_end is performed.  Add explicit bounds checks for entry pointers before accessing their fields. Use offsetof() to check that the start of the flexible array member (nameval/name) is within bounds, which ensures all preceding fields are safe to access.","cvss":[],"epss":[{"cve":"CVE-2026-80805","epss":0.00195,"percentile":0.0934,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80805","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80805","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/03a12253dd2a036545bdb0110a4e0b8dc70f8e7c","https://git.kernel.org/stable/c/0f82586741e39926542f621bafa424e237a04fa4","https://git.kernel.org/stable/c/134d82a2b5e3eba3ebf58753a1387b22f26ca1de","https://git.kernel.org/stable/c/184c1a80421a5b5ddcd262e47980ce2e67fee211","https://git.kernel.org/stable/c/98a42bb9d60d42898c3494de351a1bf508348cde","https://git.kernel.org/stable/c/9f92e749fc08b7ff3d9da190c4d1b2273745b282","https://git.kernel.org/stable/c/b7eea80be25f3334f131d52982b3131aba77b97d","https://git.kernel.org/stable/c/c35da2bac6f7cb9a9be73f188b4fcc324615c327","https://git.kernel.org/stable/c/e99120b5944a16d0bc27e52b33de78bcdaaabf5c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: validate attr entry pointer before field access\n\nxfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen,\nvaluelen) before checking if the entry pointer itself is within bounds.\nIf nameidx is crafted to point near the end of the buffer, these field\naccesses can read out-of-bounds before the bounds check at\nname_end > buf_end is performed.\n\nAdd explicit bounds checks for entry pointers before accessing their\nfields. Use offsetof() to check that the start of the flexible array\nmember (nameval/name) is within bounds, which ensures all preceding\nfields are safe to access.","cvss":[],"epss":[{"cve":"CVE-2026-80805","epss":0.00195,"percentile":0.0934,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80805","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80806","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80806","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: don't enable DAX on new encrypted files  Currently, when a new encrypted regular file is created, the call to ext4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made before EXT4_INODE_ENCRYPT is set.  As a result, it can set S_DAX if the filesystem is mounted with \"-o dax=always\".  EXT4_INODE_ENCRYPT then actually gets set a bit later in __ext4_new_inode(), when it calls fscrypt_set_context() which calls ext4_set_context().  ext4_set_context() sets EXT4_INODE_ENCRYPT and calls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too.  This was intended to clear S_DAX as well.  However, this was broken by commit 043546e46dc7 (\"fs/ext4: Only change S_DAX on inode load\").  This causes data written to the file to bypass encryption, also causing xfstests failures such as generic/548 (when \"-o dax=always\" is used).  Fix this by simplifying the flow by making __ext4_new_inode() set EXT4_INODE_ENCRYPT earlier.  This makes it take effect in ext4_set_inode_flags(inode, init=true), making S_DAX never be set.  Similarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first place on new encrypted inodes.  Then it doesn't need to be cleared.  As a result of these simplifications, ext4_set_context() no longer needs to change inode flags or state when 'handle != NULL'.  Remove that too.","cvss":[],"epss":[{"cve":"CVE-2026-80806","epss":0.00173,"percentile":0.06894,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80806","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80806","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3392391b363a63ebb531d45318a729b1c998565b","https://git.kernel.org/stable/c/458776af0061afec1014cb3cd0061e282e482e83","https://git.kernel.org/stable/c/5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c","https://git.kernel.org/stable/c/a13f61ba9b2a7a4ff1f140949ccfad23c5313757","https://git.kernel.org/stable/c/add98959b220935b243170214c787bc03044a44d","https://git.kernel.org/stable/c/da32af420d6d466e247c43ac0b829edeac7ae0ad","https://git.kernel.org/stable/c/e27bae352158c007143d5bb50f3af33a177c0a37","https://git.kernel.org/stable/c/ed1cd834da65db127f1c30ff67e78f14825a06c1","https://git.kernel.org/stable/c/f53b325068bca0b238c3e0d2eb7de9b1f2268cab"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: don't enable DAX on new encrypted files\n\nCurrently, when a new encrypted regular file is created, the call to\next4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made\nbefore EXT4_INODE_ENCRYPT is set.  As a result, it can set S_DAX if the\nfilesystem is mounted with \"-o dax=always\".\n\nEXT4_INODE_ENCRYPT then actually gets set a bit later in\n__ext4_new_inode(), when it calls fscrypt_set_context() which calls\next4_set_context().  ext4_set_context() sets EXT4_INODE_ENCRYPT and\ncalls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too.\n\nThis was intended to clear S_DAX as well.  However, this was broken by\ncommit 043546e46dc7 (\"fs/ext4: Only change S_DAX on inode load\").  This\ncauses data written to the file to bypass encryption, also causing\nxfstests failures such as generic/548 (when \"-o dax=always\" is used).\n\nFix this by simplifying the flow by making __ext4_new_inode() set\nEXT4_INODE_ENCRYPT earlier.  This makes it take effect in\next4_set_inode_flags(inode, init=true), making S_DAX never be set.\n\nSimilarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first\nplace on new encrypted inodes.  Then it doesn't need to be cleared.\n\nAs a result of these simplifications, ext4_set_context() no longer needs\nto change inode flags or state when 'handle != NULL'.  Remove that too.","cvss":[],"epss":[{"cve":"CVE-2026-80806","epss":0.00173,"percentile":0.06894,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80806","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80807","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80807","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nilfs2: reject invalid block index in GC ioctl  Syzbot reported list corruption caused by a double list_add_tail() call on bh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().  Analysis revealed that the root cause was the insertion of a page/folio with a page index of ULONG_MAX into the page cache via the GC ioctl. filemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(), repeatedly detects a dirty folio with a page index of ULONG_MAX due to index wrap-around, leading to duplicate processing of dirty buffers.  As a preparatory step, the GC ioctl loads the page/folio of the block to be moved during GC and inserts it into the page cache based on information in the nilfs_vdesc structure passed as an argument.  Normally, this does not cause issues because the user-space GC library configures the nilfs_vdesc structure properly.  However, since there is no range check on the parameters determining the page index, a request with artificially crafted parameters -- such as those generated by Syzbot -- can result in a page/folio being inserted with a page index of ULONG_MAX, triggering the above problem.  This resolves the issue by checking the ranges of 'vd_offset' and 'vd_vblocknr' in the nilfs_vdesc structure that determine the page index, thereby preventing the invalid page/folio insertions.","cvss":[],"epss":[{"cve":"CVE-2026-80807","epss":0.00201,"percentile":0.10008,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.1005},"relatedVulnerabilities":[{"id":"CVE-2026-80807","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80807","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3bd064ccc70b85f9a3d53aece29dc8473be5a226","https://git.kernel.org/stable/c/68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44","https://git.kernel.org/stable/c/898404cdf882d7b54f1132f75570984ca3214796","https://git.kernel.org/stable/c/a1735eae55448bc79c2da6593455791e886f6ed8","https://git.kernel.org/stable/c/a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1","https://git.kernel.org/stable/c/ba8a8b563a28d358c45c62a306d421434a058648","https://git.kernel.org/stable/c/e447f7edb99bd00cec63d6f3049e2e5074946f71","https://git.kernel.org/stable/c/ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1","https://git.kernel.org/stable/c/fbcfb75c20d71a5b542ad4ac3b79d10b997c8152"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject invalid block index in GC ioctl\n\nSyzbot reported list corruption caused by a double list_add_tail() call on\nbh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().\n\nAnalysis revealed that the root cause was the insertion of a page/folio\nwith a page index of ULONG_MAX into the page cache via the GC ioctl.\nfilemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(),\nrepeatedly detects a dirty folio with a page index of ULONG_MAX due to\nindex wrap-around, leading to duplicate processing of dirty buffers.\n\nAs a preparatory step, the GC ioctl loads the page/folio of the block to\nbe moved during GC and inserts it into the page cache based on information\nin the nilfs_vdesc structure passed as an argument.  Normally, this does\nnot cause issues because the user-space GC library configures the\nnilfs_vdesc structure properly.  However, since there is no range check on\nthe parameters determining the page index, a request with artificially\ncrafted parameters -- such as those generated by Syzbot -- can result in a\npage/folio being inserted with a page index of ULONG_MAX, triggering the\nabove problem.\n\nThis resolves the issue by checking the ranges of 'vd_offset' and\n'vd_vblocknr' in the nilfs_vdesc structure that determine the page index,\nthereby preventing the invalid page/folio insertions.","cvss":[],"epss":[{"cve":"CVE-2026-80807","epss":0.00201,"percentile":0.10008,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80807","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80808","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80808","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ext4: stop retrying saturated xattr cache entries  ext4_xattr_block_set() retries when a cache entry selected for reuse has a saturated reference count after taking the buffer lock. The retry returns to the mbcache lookup without making that entry ineligible, so it can select the same unusable entry indefinitely. A task spinning there can hold the parent directory's i_rwsem and leave concurrent rmdir callers blocked.  Normally a reusable entry has a reference count below EXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUSABLE_B are updated under the same buffer lock. A corrupted filesystem can violate that invariant. The syzbot reproducer reports allocator and xattr corruption before triggering this retry loop.  Check the untrusted on-disk count before incrementing it, avoiding overflow, and clear MBE_REUSABLE_B when it is already saturated. The next lookup then skips the entry that was just proven unusable. This mirrors the normal transition at EXT4_XATTR_REFCOUNT_MAX; the release path marks the entry reusable again on the exact 1024-to-1023 transition.  Using the same QEMU harness and guest parameters, current unpatched Linux hung in 6 of 8 420-second trials with the do_rmdir signature; representative NMI backtraces caught the owner spinning in ext4_xattr_block_set(). The patched kernel completed 28 of 28 trials without a hung-task report; the final twelve trials exercised the reviewed overflow-safe form of the change. syzbot's patch testing also completed without reproducing the hang.","cvss":[],"epss":[{"cve":"CVE-2026-80808","epss":0.00195,"percentile":0.0934,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80808","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80808","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/119a2f053242ed75bdd2ebc95baf3ae7db6ccacf","https://git.kernel.org/stable/c/4902a5cba21aeaf91e6b29e20e0967a5f6abdcd9","https://git.kernel.org/stable/c/54b6bd40898de7906acb2bccc9a96d1b8e6b4323","https://git.kernel.org/stable/c/55ee6533c1db7f7656fa8dd19637f3f8b8c08dc5","https://git.kernel.org/stable/c/61631352a5b405c89be579de00903b72e6888aa4","https://git.kernel.org/stable/c/8865cd664484517703df5c18a965dc3227572b87","https://git.kernel.org/stable/c/889ec86464d261f026f6c334040cfc6c58c99d58","https://git.kernel.org/stable/c/a40c45268f4358207aa9c53764fed2e05f62986a","https://git.kernel.org/stable/c/dbd4aea175ad3c46436acb251e817b4374628072"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: stop retrying saturated xattr cache entries\n\next4_xattr_block_set() retries when a cache entry selected for reuse\nhas a saturated reference count after taking the buffer lock. The retry\nreturns to the mbcache lookup without making that entry ineligible, so\nit can select the same unusable entry indefinitely. A task spinning\nthere can hold the parent directory's i_rwsem and leave concurrent\nrmdir callers blocked.\n\nNormally a reusable entry has a reference count below\nEXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUSABLE_B are\nupdated under the same buffer lock. A corrupted filesystem can violate\nthat invariant. The syzbot reproducer reports allocator and xattr\ncorruption before triggering this retry loop.\n\nCheck the untrusted on-disk count before incrementing it, avoiding\noverflow, and clear MBE_REUSABLE_B when it is already saturated. The\nnext lookup then skips the entry that was just proven unusable. This\nmirrors the normal transition at EXT4_XATTR_REFCOUNT_MAX; the release\npath marks the entry reusable again on the exact 1024-to-1023\ntransition.\n\nUsing the same QEMU harness and guest parameters, current unpatched\nLinux hung in 6 of 8 420-second trials with the do_rmdir signature;\nrepresentative NMI backtraces caught the owner spinning in\next4_xattr_block_set(). The patched kernel completed 28 of 28 trials\nwithout a hung-task report; the final twelve trials exercised the\nreviewed overflow-safe form of the change. syzbot's patch testing also\ncompleted without reproducing the hang.","cvss":[],"epss":[{"cve":"CVE-2026-80808","epss":0.00195,"percentile":0.0934,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80808","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80809","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80809","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ocfs2: fix missing metadata reservation for large xattrs  [BUG] lsetxattr() panics the kernel when setting a large xattr value on a fragmented filesystem where the file already has an external xattr block.  [CAUSE] ocfs2_calc_xattr_set_need() never reserves metadata blocks for a new xattr value's extent tree when the file already has an external xattr block. The not_found path leaves meta_add at zero, so meta_ac is NULL when ocfs2_xattr_extend_allocation() runs.  A new value root has room for a single extent record. On a fragmented filesystem, the allocator cannot satisfy the xattr value in one contiguous run, so each non-contiguous run requires its own extent record. When the value root's extent list is full and meta_ac is NULL, ocfs2_add_clusters_in_btree() returns RESTART_META, and ocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META).  [FIX] The case where no xattr block exists yet already calls ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree metadata. Add the same reservation to the case where an xattr block already exists, making the two cases consistent.  Replace the BUG_ON with a -ENOSPC return so that if RESTART_META is returned despite the reservation, the error propagates to userspace instead of panicking the kernel.","cvss":[],"epss":[{"cve":"CVE-2026-80809","epss":0.00195,"percentile":0.09342,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80809","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80809","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/04ba24bce61c917b5b3009f0db470cbb72e26a0d","https://git.kernel.org/stable/c/0cdc7dde00ec63ac714271fa8b2918d630b8da1a","https://git.kernel.org/stable/c/50f0cbec45b0f3fd7e1263d01916518dbf31eb3f","https://git.kernel.org/stable/c/6176313622e34fa3e2b66b9d0682d1e1c6b365c5","https://git.kernel.org/stable/c/6a009f1e61b11d9e23d3c5aa1dacfb010945da45","https://git.kernel.org/stable/c/743ac908282ac97ef6e73ac3a92df2cc8ecb7479","https://git.kernel.org/stable/c/a3ccb57086dd7652d5ecb826486144198a98a8e9","https://git.kernel.org/stable/c/b4663405ae29d36011cd712d243456f3f9ab700d","https://git.kernel.org/stable/c/b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix missing metadata reservation for large xattrs\n\n[BUG]\nlsetxattr() panics the kernel when setting a large xattr value on a\nfragmented filesystem where the file already has an external xattr\nblock.\n\n[CAUSE]\nocfs2_calc_xattr_set_need() never reserves metadata blocks for a new\nxattr value's extent tree when the file already has an external xattr\nblock. The not_found path leaves meta_add at zero, so meta_ac is NULL\nwhen ocfs2_xattr_extend_allocation() runs.\n\nA new value root has room for a single extent record. On a fragmented\nfilesystem, the allocator cannot satisfy the xattr value in one\ncontiguous run, so each non-contiguous run requires its own extent\nrecord. When the value root's extent list is full and meta_ac is NULL,\nocfs2_add_clusters_in_btree() returns RESTART_META, and\nocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META).\n\n[FIX]\nThe case where no xattr block exists yet already calls\nocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree\nmetadata. Add the same reservation to the case where an xattr block\nalready exists, making the two cases consistent.\n\nReplace the BUG_ON with a -ENOSPC return so that if RESTART_META is\nreturned despite the reservation, the error propagates to userspace\ninstead of panicking the kernel.","cvss":[],"epss":[{"cve":"CVE-2026-80809","epss":0.00195,"percentile":0.09342,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80809","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80812","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80812","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: dummy: Check card index validity at probe  snd_dummy_probe() blindly trusts that the given devptr->id value is within the proper card index range.  It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as \"none\", and this leads to OOB access for index[] and other parameters.  Add a sanity check for the card index and warn/correct it if it's a value out of the range.","cvss":[],"epss":[{"cve":"CVE-2026-80812","epss":0.00177,"percentile":0.07326,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80812","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80812","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/02442d5fe8ee365a084b055d4fa81a0c1abfc3fd","https://git.kernel.org/stable/c/3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec","https://git.kernel.org/stable/c/4d0892a90b57f0e89b274c3f3c51c2fa17937c88","https://git.kernel.org/stable/c/690b721b9595f9a43395fd4047a832c42b5b6078","https://git.kernel.org/stable/c/b20eb7ecbdaa3e649023fe41b177d90983ffb487","https://git.kernel.org/stable/c/b7579e86afcec932e169d10e2d603abed8dd2fdf","https://git.kernel.org/stable/c/c9f10a001c243d1f069ebb0e2f4999ad4043a254","https://git.kernel.org/stable/c/f20c2c32ec1c5c3526f29a03b487c55a5890996c"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: dummy: Check card index validity at probe\n\nsnd_dummy_probe() blindly trusts that the given devptr->id value is\nwithin the proper card index range.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.","cvss":[],"epss":[{"cve":"CVE-2026-80812","epss":0.00177,"percentile":0.07326,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80812","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80814","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80814","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  rndis_host: add overflow check in rndis_rx_fixup()  Add an overflow check to ensure that data_offset + data_len + 8 does not wrap, which would enable an OOB read of the USB data buffer.","cvss":[],"epss":[{"cve":"CVE-2026-80814","epss":0.00195,"percentile":0.09346,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80814","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80814","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/10a6b99079697c5027b25352e882bdf54fef702a","https://git.kernel.org/stable/c/2140db1232af04b92faa6c4a2a40df6371ea89ff","https://git.kernel.org/stable/c/2ded89ca77fae1da6886fe94831acfe4d6aa80b1","https://git.kernel.org/stable/c/8ca3bd404d076495ed0b274b65971c57b6fd5ac0","https://git.kernel.org/stable/c/965a251f23ff69cfb4486974d4532e9bb551c7fc","https://git.kernel.org/stable/c/be7dc3650f799a253df4edd4fe230fc9ea4be063","https://git.kernel.org/stable/c/c5398ce6db7647b7004d73a3102ccc25fb4bb596","https://git.kernel.org/stable/c/e971d956353d382ee2185d71c47b538501a43f76","https://git.kernel.org/stable/c/f8e6fde5db87f855e99b200e392467274f0eb9d7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nrndis_host: add overflow check in rndis_rx_fixup()\n\nAdd an overflow check to ensure that data_offset + data_len + 8 does not\nwrap, which would enable an OOB read of the USB data buffer.","cvss":[],"epss":[{"cve":"CVE-2026-80814","epss":0.00195,"percentile":0.09346,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80814","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80819","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80819","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept  rfcomm_sock_recvmsg() completes a deferred setup by calling rfcomm_dlc_accept() without holding any RFCOMM lock:  \tif (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) { \t\trfcomm_dlc_accept(d); \t\treturn 0; \t}  and rfcomm_dlc_accept() dereferences the session on its first line:  \tstruct sock *sk = d->session->sock->sk;  Every other path that touches d->session runs under rfcomm_mutex: rfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(), rfcomm_dlc_send_rpn(), and the RFCOMM thread through rfcomm_process_sessions(). rfcomm_connect_ind() is even documented as \"called under rfcomm_lock()\". This call site is the only one that skips it.  The RFCOMM_DEFER_SETUP bit looks like it serialises the accept against teardown, since __rfcomm_dlc_close() returns early when it wins the test_and_clear. But rfcomm_recv_disc() forces the state first:  \td->state = BT_CLOSED; \t__rfcomm_dlc_close(d, err);  and the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and BT_CONNECT2. With the state already BT_CLOSED that switch does not match, the bit is never consulted, and __rfcomm_dlc_close() falls through to rfcomm_dlc_unlink(), which sets d->session = NULL.  So a remote DISC on a deferred dlc clears the session while leaving RFCOMM_DEFER_SETUP set. The next recvmsg() then passes the test_and_clear and dereferences a NULL session. No timing window is needed: once the DISC has been processed, the dereference is unconditional.  Give rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and rfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and re-checks the session, around a __rfcomm_dlc_accept() that the two in-core callers, which already hold the mutex, keep using.  Reproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated over /dev/vhci: the peer brings up an ACL link, opens L2CAP on the RFCOMM PSM, starts a session, opens a dlc on a channel bound with BT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on the accepted socket then hits:    Oops: general protection fault   KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]   RIP: 0010:rfcomm_dlc_accept+0x54/0x350   Call Trace:     rfcomm_sock_recvmsg+0x1cd/0x230     sock_recvmsg+0x166/0x1c0     __sys_recvfrom+0x20d/0x300  0x10 is the offset of sock in struct rfcomm_session. With this patch the same run completes with recv() returning 0 and no report, and lockdep stays quiet, confirming rfcomm_mutex is still taken before lock_sock on this path as it is on the thread side.","cvss":[],"epss":[{"cve":"CVE-2026-80819","epss":0.00195,"percentile":0.09345,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80819","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80819","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/355bfd57ca4ca881c6eb03ca813b440a094b1f44","https://git.kernel.org/stable/c/362726c9c6e56eea4262109183e49868c39ccd3a","https://git.kernel.org/stable/c/43a556b2fd43f2df6dded59c2e26560a27874c24","https://git.kernel.org/stable/c/56f0aa75c7640e46397ef73bea251fcbef9150c0","https://git.kernel.org/stable/c/825b95561d7b7c393df9e7bc295451aaeadc3d18","https://git.kernel.org/stable/c/b405c2f96ae2e37375105881890f7738833b1d62","https://git.kernel.org/stable/c/d4b1a13b1eff2e80925c7368ffdeaaa50cba93df","https://git.kernel.org/stable/c/d8d686dd5662a7c4745e4515f1237a9f3b7df181","https://git.kernel.org/stable/c/eb71d5a1ea8ff2683e394b48ae3cd676037ab4c2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept\n\nrfcomm_sock_recvmsg() completes a deferred setup by calling\nrfcomm_dlc_accept() without holding any RFCOMM lock:\n\n\tif (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) {\n\t\trfcomm_dlc_accept(d);\n\t\treturn 0;\n\t}\n\nand rfcomm_dlc_accept() dereferences the session on its first line:\n\n\tstruct sock *sk = d->session->sock->sk;\n\nEvery other path that touches d->session runs under rfcomm_mutex:\nrfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(),\nrfcomm_dlc_send_rpn(), and the RFCOMM thread through\nrfcomm_process_sessions(). rfcomm_connect_ind() is even documented as\n\"called under rfcomm_lock()\". This call site is the only one that skips\nit.\n\nThe RFCOMM_DEFER_SETUP bit looks like it serialises the accept against\nteardown, since __rfcomm_dlc_close() returns early when it wins the\ntest_and_clear. But rfcomm_recv_disc() forces the state first:\n\n\td->state = BT_CLOSED;\n\t__rfcomm_dlc_close(d, err);\n\nand the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and\nBT_CONNECT2. With the state already BT_CLOSED that switch does not\nmatch, the bit is never consulted, and __rfcomm_dlc_close() falls\nthrough to rfcomm_dlc_unlink(), which sets d->session = NULL.\n\nSo a remote DISC on a deferred dlc clears the session while leaving\nRFCOMM_DEFER_SETUP set. The next recvmsg() then passes the\ntest_and_clear and dereferences a NULL session. No timing window is\nneeded: once the DISC has been processed, the dereference is\nunconditional.\n\nGive rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and\nrfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and\nre-checks the session, around a __rfcomm_dlc_accept() that the two\nin-core callers, which already hold the mutex, keep using.\n\nReproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated\nover /dev/vhci: the peer brings up an ACL link, opens L2CAP on the\nRFCOMM PSM, starts a session, opens a dlc on a channel bound with\nBT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on\nthe accepted socket then hits:\n\n  Oops: general protection fault\n  KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n  RIP: 0010:rfcomm_dlc_accept+0x54/0x350\n  Call Trace:\n    rfcomm_sock_recvmsg+0x1cd/0x230\n    sock_recvmsg+0x166/0x1c0\n    __sys_recvfrom+0x20d/0x300\n\n0x10 is the offset of sock in struct rfcomm_session. With this patch the\nsame run completes with recv() returning 0 and no report, and lockdep\nstays quiet, confirming rfcomm_mutex is still taken before lock_sock on\nthis path as it is on the thread side.","cvss":[],"epss":[{"cve":"CVE-2026-80819","epss":0.00195,"percentile":0.09345,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80819","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80820","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80820","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfs: don't livelock in scrub on a circular unlinked list  LOLLM points out that online fsck can livelock if an unlinked inode list contains a loop.  Use a bitmap to detect cycles.","cvss":[],"epss":[{"cve":"CVE-2026-80820","epss":0.00168,"percentile":0.06344,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80820","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80820","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/159d162fe80bd56573cafde5801bd5a90a3dd1ac","https://git.kernel.org/stable/c/527eaaefddb6ec5c83a06c9a1559960dd6361753","https://git.kernel.org/stable/c/56407a61a8bb85b884de802d39635abdb0ea7408","https://git.kernel.org/stable/c/599453f83458b57995290a1d31200c263e2c2691"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't livelock in scrub on a circular unlinked list\n\nLOLLM points out that online fsck can livelock if an unlinked inode list\ncontains a loop.  Use a bitmap to detect cycles.","cvss":[],"epss":[{"cve":"CVE-2026-80820","epss":0.00168,"percentile":0.06344,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80820","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80823","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80823","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  nfc: st21nfca: validate ATR_REQ length against the received frame  st21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at least ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length is at least sizeof(struct st21nfca_atr_req), but never checks that atr_req->length does not exceed the actual received length (skb->len).  st21nfca_tm_send_atr_res() then trusts the declared length:  \tgb_len = atr_req->length - sizeof(struct st21nfca_atr_req); \t... \tmemcpy(atr_res->gbi, atr_req->gbi, gb_len);  so an RF peer that sends a short frame but sets atr_req->length larger than the frame makes gb_len exceed the general bytes actually present, and the memcpy reads out of bounds past the received skb. Those bytes are placed in the ATR_RES and sent back to the peer (kernel-memory disclosure to a proximity attacker); a larger declared length is an out-of-bounds read (DoS).  Reject frames whose declared length exceeds the received length. The adjacent nfc_tm_activated() path in the same function already derives its general-bytes length from skb->len rather than the declared field.  Found by 0sec (https://0sec.ai) using automated source analysis; the missing bound is evident from source. Compile-tested.","cvss":[],"epss":[{"cve":"CVE-2026-80823","epss":0.00195,"percentile":0.09346,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80823","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80823","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0f344944c506b4f02d2b098489f7268b438c369e","https://git.kernel.org/stable/c/2c1ad291f4cdc357f9527b688c6fda9c6ffa7890","https://git.kernel.org/stable/c/304f5b414f4051d324b8c4a3ab0e79f7dc7e150e","https://git.kernel.org/stable/c/5cdcca5d62a66eda6b774110a44cba67bc1a8d1d","https://git.kernel.org/stable/c/785df00bb3ae3206674a43284eb06dac575b5c64","https://git.kernel.org/stable/c/9635507fe82949e429b3cd938876a9917125b151","https://git.kernel.org/stable/c/bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d","https://git.kernel.org/stable/c/dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa","https://git.kernel.org/stable/c/f33cecf69095c43be88567fef92b180b858f7369"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: st21nfca: validate ATR_REQ length against the received frame\n\nst21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at\nleast ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length\nis at least sizeof(struct st21nfca_atr_req), but never checks that\natr_req->length does not exceed the actual received length (skb->len).\n\nst21nfca_tm_send_atr_res() then trusts the declared length:\n\n\tgb_len = atr_req->length - sizeof(struct st21nfca_atr_req);\n\t...\n\tmemcpy(atr_res->gbi, atr_req->gbi, gb_len);\n\nso an RF peer that sends a short frame but sets atr_req->length larger\nthan the frame makes gb_len exceed the general bytes actually present,\nand the memcpy reads out of bounds past the received skb. Those bytes are\nplaced in the ATR_RES and sent back to the peer (kernel-memory disclosure\nto a proximity attacker); a larger declared length is an out-of-bounds\nread (DoS).\n\nReject frames whose declared length exceeds the received length. The\nadjacent nfc_tm_activated() path in the same function already derives its\ngeneral-bytes length from skb->len rather than the declared field.\n\nFound by 0sec (https://0sec.ai) using automated source analysis; the\nmissing bound is evident from source. Compile-tested.","cvss":[],"epss":[{"cve":"CVE-2026-80823","epss":0.00195,"percentile":0.09346,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80823","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80824","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80824","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: usbfs: fix use-after-free of usb_device in usbdev_release()  usbdev_release() drops its reference to the struct usb_device before draining the list of completed async URBs, but that drain path reads back through the same object: free_async() calls dec_usb_memory_use_count() for any URB whose buffer came from the usbfs mmap() region, and its first statement is bus_to_hcd(ps->dev->bus).  After a disconnect the usbfs reference can be the last one, in which case usb_put_dev() frees the device and the subsequent loop reads offset 80 of freed memory and uses the result as a struct usb_hcd *, which hcd_buffer_free_pages() then dereferences.  This is reachable by an unprivileged process that has read/write access to a /dev/bus/usb node: mmap() the fd, submit one URB with a buffer inside the mapping, wait for the device to be unplugged, then munmap() and close(). It reproduces on every attempt rather than being a race, because a live MAP_SHARED vma holds a reference on the struct file, so usbdev_release() cannot run until the last vma is gone and the freeing branch of dec_usb_memory_use_count() is always taken.    BUG: KASAN: slab-use-after-free in dec_usb_memory_use_count+0x3ae/0x410   Read of size 8 at addr ffff8880122ee050 by task poc/769   CPU: 1 UID: 1000 PID: 769 Comm: poc Tainted: G    B    6.12.94 #3    Call Trace:    dec_usb_memory_use_count+0x3ae/0x410    free_async+0x2aa/0x4f0    usbdev_release+0x375/0x460    __fput+0x3ea/0xb50    __x64_sys_close+0x86/0x100    Allocated by task 11:    usb_alloc_dev+0x55/0xd90    hub_event+0x2524/0x43d0    Freed by task 769:    kfree+0x121/0x360    device_release+0xd2/0x280    usb_put_dev+0x23/0x30    usbdev_release+0x2d8/0x460  Release the device reference after the drain loop instead. Nothing between the two points requires it to have been dropped.","cvss":[],"epss":[{"cve":"CVE-2026-80824","epss":0.00195,"percentile":0.09341,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80824","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80824","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0a960b88c5979f853019d4dc4957dfbeeb193440","https://git.kernel.org/stable/c/0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671","https://git.kernel.org/stable/c/47a7f98fbb5006d46d15a3a210ffdc61448a4f19","https://git.kernel.org/stable/c/5f08c45bdcfd28d1171de38c5ef29fc89a76eedc","https://git.kernel.org/stable/c/65879e0a452ca2a234b9475e0c11aff7a4343738","https://git.kernel.org/stable/c/7f0278e474c4d1c4457974ff1137cc385c944ab3","https://git.kernel.org/stable/c/96f5520fc9a5e4bbf77ac93c9d5ce502f597e6cf","https://git.kernel.org/stable/c/b3cde26a66b04f1d90ed0b675899c88b4e49d424","https://git.kernel.org/stable/c/bd4bffc621a8cb2f4d9ed9b6447415de524a3bef"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usbfs: fix use-after-free of usb_device in usbdev_release()\n\nusbdev_release() drops its reference to the struct usb_device before\ndraining the list of completed async URBs, but that drain path reads back\nthrough the same object: free_async() calls dec_usb_memory_use_count()\nfor any URB whose buffer came from the usbfs mmap() region, and its first\nstatement is bus_to_hcd(ps->dev->bus).\n\nAfter a disconnect the usbfs reference can be the last one, in which case\nusb_put_dev() frees the device and the subsequent loop reads offset 80 of\nfreed memory and uses the result as a struct usb_hcd *, which\nhcd_buffer_free_pages() then dereferences.\n\nThis is reachable by an unprivileged process that has read/write access to\na /dev/bus/usb node: mmap() the fd, submit one URB with a buffer inside the\nmapping, wait for the device to be unplugged, then munmap() and close().\nIt reproduces on every attempt rather than being a race, because a live\nMAP_SHARED vma holds a reference on the struct file, so usbdev_release()\ncannot run until the last vma is gone and the freeing branch of\ndec_usb_memory_use_count() is always taken.\n\n  BUG: KASAN: slab-use-after-free in dec_usb_memory_use_count+0x3ae/0x410\n  Read of size 8 at addr ffff8880122ee050 by task poc/769\n  CPU: 1 UID: 1000 PID: 769 Comm: poc Tainted: G    B    6.12.94 #3\n\n  Call Trace:\n   dec_usb_memory_use_count+0x3ae/0x410\n   free_async+0x2aa/0x4f0\n   usbdev_release+0x375/0x460\n   __fput+0x3ea/0xb50\n   __x64_sys_close+0x86/0x100\n\n  Allocated by task 11:\n   usb_alloc_dev+0x55/0xd90\n   hub_event+0x2524/0x43d0\n\n  Freed by task 769:\n   kfree+0x121/0x360\n   device_release+0xd2/0x280\n   usb_put_dev+0x23/0x30\n   usbdev_release+0x2d8/0x460\n\nRelease the device reference after the drain loop instead. Nothing between\nthe two points requires it to have been dropped.","cvss":[],"epss":[{"cve":"CVE-2026-80824","epss":0.00195,"percentile":0.09341,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80824","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80826","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80826","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  USB: c67x00: fix use-after-free in c67x00_add_iso_urb()  When TD creation fails for the last packet of an isochronous URB, c67x00_add_iso_urb() gives the URB back before updating the endpoint scheduling state.  c67x00_giveback_urb() frees the URB private data, and the completion callback may release the final URB reference. The following accesses to urbp->ep_data, urb->interval, and urbp->cnt can therefore use freed memory.  Update next_frame and cnt before giving back the failed final packet, making the giveback the last operation that uses the URB and its private data.","cvss":[],"epss":[{"cve":"CVE-2026-80826","epss":0.00195,"percentile":0.09343,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80826","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80826","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/62cd519ab74cac499036cd88c11692f8f0d53e14","https://git.kernel.org/stable/c/7983daa159981fac125db2457437723f38ea1472","https://git.kernel.org/stable/c/ade18b4ce78a16558f4f435aece80082f6f7b64c","https://git.kernel.org/stable/c/b1e24de475bf2d66fffc9103f3444b783527d55a","https://git.kernel.org/stable/c/b4cb8081cf80f82e48fbe9c021a8f6d0fa2ed421","https://git.kernel.org/stable/c/bb572801290e25ec1c4753d14af35777303f5d6b","https://git.kernel.org/stable/c/e4039e9bebb528dd9cd7ac72aeaec529c26c355a","https://git.kernel.org/stable/c/f24dcc61bd0ecf7639fac5bf700450b398d793a7","https://git.kernel.org/stable/c/ff172092cba7ec990ecc7b610ce703e19570b8f0"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: c67x00: fix use-after-free in c67x00_add_iso_urb()\n\nWhen TD creation fails for the last packet of an isochronous URB,\nc67x00_add_iso_urb() gives the URB back before updating the endpoint\nscheduling state.\n\nc67x00_giveback_urb() frees the URB private data, and the completion\ncallback may release the final URB reference. The following accesses to\nurbp->ep_data, urb->interval, and urbp->cnt can therefore use freed\nmemory.\n\nUpdate next_frame and cnt before giving back the failed final packet,\nmaking the giveback the last operation that uses the URB and its private\ndata.","cvss":[],"epss":[{"cve":"CVE-2026-80826","epss":0.00195,"percentile":0.09343,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80826","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80827","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80827","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  USB: serial: option: fix slab OOB read in interrupt URB callback  The interrupt URB buffer is allocated in setup_port_interrupt_in() based on the endpoint's wMaxPacketSize:      buffer_size = usb_endpoint_maxp(epd);     port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);  When a USB device declares wMaxPacketSize = 8 on its interrupt IN endpoint, the buffer is allocated from kmalloc-8 cache (exactly 8 bytes).  If the device sends a short packet (actual_length < wMaxPacketSize), the URB completes with status == 0 and the callback proceeds to read:      data[sizeof(struct usb_ctrlrequest)]  which evaluates to data[8], accessing 1 byte beyond the allocated 8-byte buffer. This results in a slab out-of-bounds read.  Fix this by adding the missing bounds check: first verify that the actual length is large enough to contain the struct usb_ctrlrequest header before accessing req_pkt->bRequestType and req_pkt->bRequest, and then verify that there is an additional byte for the modem signal state before reading data[sizeof(struct usb_ctrlrequest)] inside the conditional.  Use sizeof(*req_pkt) instead of sizeof(struct usb_ctrlrequest) for consistency.  [ johan: use dev_err(); split signals declaration and initialisation ]","cvss":[],"epss":[{"cve":"CVE-2026-80827","epss":0.00195,"percentile":0.09343,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80827","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80827","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/030e3a73d3c3aa67c44454649e984d6383cdb7d3","https://git.kernel.org/stable/c/060db7d48af1e650643c8b8319111a9ea2ce4486","https://git.kernel.org/stable/c/2ef5560387f2c0713cee975be2b24b281bd90f3e","https://git.kernel.org/stable/c/6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec","https://git.kernel.org/stable/c/885d802f544ca7bfa8f3984d94233cce715bb6b3","https://git.kernel.org/stable/c/94e5525697b9e91ddc4071129874120a50a4f342","https://git.kernel.org/stable/c/a72a13c83a652516a0e469d275b81d29a7429049","https://git.kernel.org/stable/c/d762aef4eba354066be21a5d88eb2066e282f4c9","https://git.kernel.org/stable/c/fbe60fd2abc8a5561f39719a41ad9a01b5d8e567"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: option: fix slab OOB read in interrupt URB callback\n\nThe interrupt URB buffer is allocated in setup_port_interrupt_in() based\non the endpoint's wMaxPacketSize:\n\n    buffer_size = usb_endpoint_maxp(epd);\n    port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);\n\nWhen a USB device declares wMaxPacketSize = 8 on its interrupt IN\nendpoint, the buffer is allocated from kmalloc-8 cache (exactly\n8 bytes).\n\nIf the device sends a short packet (actual_length < wMaxPacketSize),\nthe URB completes with status == 0 and the callback proceeds to read:\n\n    data[sizeof(struct usb_ctrlrequest)]\n\nwhich evaluates to data[8], accessing 1 byte beyond the allocated 8-byte\nbuffer. This results in a slab out-of-bounds read.\n\nFix this by adding the missing bounds check: first verify that the\nactual length is large enough to contain the struct usb_ctrlrequest\nheader before accessing req_pkt->bRequestType and req_pkt->bRequest,\nand then verify that there is an additional byte for the modem signal\nstate before reading data[sizeof(struct usb_ctrlrequest)] inside the\nconditional.  Use sizeof(*req_pkt) instead of sizeof(struct\nusb_ctrlrequest) for consistency.\n\n[ johan: use dev_err(); split signals declaration and initialisation ]","cvss":[],"epss":[{"cve":"CVE-2026-80827","epss":0.00195,"percentile":0.09343,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80827","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80828","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80828","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: Complete cleanup after system-resume errors  A failed system resume can leave the card unusable until reboot. usb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or snd_usb_mixer_resume() fails. The error path skips the out: block, which restores D0 and decrements chip->num_suspended_intf.  The card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in snd_power_ref_and_wait(). USB core logs an interface resume callback error. It does not retry that callback, so a later callback cannot complete the skipped cleanup.  usb_audio_suspend() increments num_suspended_intf before returning success. A system-resume callback must consume the system-suspend count even if a component resume fails. Otherwise, the stranded count skews later suspend and resume cycles.  Do not apply this cleanup to runtime-resume errors. Runtime PM can retry -EAGAIN or -EBUSY without another suspend callback. The count must continue to describe that suspended interface. Other runtime-resume errors latch runtime_error in the PM core and do not cause an immediate callback retry.  Both parts of the system-resume error path are longstanding. Commit 88a8516a2128a (\"ALSA: usbaudio: implement USB autosuspend\") introduced err_out past the D0 restore. Commit 862b2509d157c (\"ALSA: usb-audio: Fix inconsistent card PM state after resume\") later moved num_suspended_intf-- into the out: block. The error path now skips both operations.  No third-party code is needed to reach the error path. snd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the result of usb_submit_urb() for devices that have a mixer status URB. Its mixer->private_resume hook can also fail through scarlett2_init_notify(). snd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It can return -EPIPE or -EIO when the device stalls the request.  Route a component error through out: only when system_suspend is nonzero. Continue to return runtime-resume errors through err_out. Later component resume stages remain skipped. The original error still reaches USB core. A later transfer can fail if the device did not recover.  I reproduced the system-resume failure on an Audient iD14 MkI with an out-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched core left control readers in uninterruptible sleep in snd_power_ref_and_wait() until a reboot. With this patch, the same failure restored control access. A second system suspend and resume also succeeded after I disabled fault injection.","cvss":[],"epss":[{"cve":"CVE-2026-80828","epss":0.0019,"percentile":0.08756,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.095},"relatedVulnerabilities":[{"id":"CVE-2026-80828","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80828","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1739a976312e110c93a8dee66a1cdf893a1b187e","https://git.kernel.org/stable/c/3f06f3f5b16212f180764654a9398ff5f7a855c8","https://git.kernel.org/stable/c/3fa521c3c54b42e16cad8ade76551113a783752b","https://git.kernel.org/stable/c/5a625fc2284e35f33693efd9534aebaca3b005d4","https://git.kernel.org/stable/c/6c94877b6bab9185898bcad4b082ff5592558921","https://git.kernel.org/stable/c/6d3e202670b819c414076a5d07dffac8a39274ad","https://git.kernel.org/stable/c/d1f643b1c0258bd519146f7a342bbb394d413912","https://git.kernel.org/stable/c/f1c05c41d07b874635d681ae328d13ec550470c5"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Complete cleanup after system-resume errors\n\nA failed system resume can leave the card unusable until reboot.\nusb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or\nsnd_usb_mixer_resume() fails. The error path skips the out: block, which\nrestores D0 and decrements chip->num_suspended_intf.\n\nThe card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in\nsnd_power_ref_and_wait(). USB core logs an interface resume callback error.\nIt does not retry that callback, so a later callback cannot complete the\nskipped cleanup.\n\nusb_audio_suspend() increments num_suspended_intf before returning success.\nA system-resume callback must consume the system-suspend count even if a\ncomponent resume fails. Otherwise, the stranded count skews later suspend\nand resume cycles.\n\nDo not apply this cleanup to runtime-resume errors. Runtime PM can retry\n-EAGAIN or -EBUSY without another suspend callback. The count must continue\nto describe that suspended interface. Other runtime-resume errors latch\nruntime_error in the PM core and do not cause an immediate callback retry.\n\nBoth parts of the system-resume error path are longstanding. Commit\n88a8516a2128a (\"ALSA: usbaudio: implement USB autosuspend\") introduced\nerr_out past the D0 restore. Commit 862b2509d157c (\"ALSA: usb-audio: Fix\ninconsistent card PM state after resume\") later moved\nnum_suspended_intf-- into the out: block. The error path now skips both\noperations.\n\nNo third-party code is needed to reach the error path.\nsnd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the\nresult of usb_submit_urb() for devices that have a mixer status URB. Its\nmixer->private_resume hook can also fail through scarlett2_init_notify().\nsnd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It\ncan return -EPIPE or -EIO when the device stalls the request.\n\nRoute a component error through out: only when system_suspend is nonzero.\nContinue to return runtime-resume errors through err_out. Later component\nresume stages remain skipped. The original error still reaches USB core.\nA later transfer can fail if the device did not recover.\n\nI reproduced the system-resume failure on an Audient iD14 MkI with an\nout-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched\ncore left control readers in uninterruptible sleep in\nsnd_power_ref_and_wait() until a reboot. With this patch, the same failure\nrestored control access. A second system suspend and resume also succeeded\nafter I disabled fault injection.","cvss":[],"epss":[{"cve":"CVE-2026-80828","epss":0.0019,"percentile":0.08756,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80828","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80829","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80829","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()  snd_usbmidi_novation_output() lays out a two-byte header at transfer_buffer[0..1] and passes &transfer_buffer[2] together with a length of ep->max_transfer - 2 to snd_rawmidi_transmit():  \tcount = snd_rawmidi_transmit(ep->ports[0].substream, \t\t\t\t     &transfer_buffer[2], \t\t\t\t     ep->max_transfer - 2);  ep->max_transfer comes from the output endpoint's wMaxPacketSize via usb_maxpacket(). A malformed or malicious device can advertise a bulk OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this value downwards - so ep->max_transfer becomes 1 and the count argument becomes -1.  snd_rawmidi_transmit() passes the negative count on to __snd_rawmidi_transmit_peek(), where \"if (count1 > count) count1 = count\" leaves count1 negative; get_aligned_size() keeps it negative for a byte-stream substream, so the following memcpy(buffer, ..., count1) runs with a (size_t)-1 length and writes far past the transfer buffer, which was allocated with usb_alloc_coherent(ep->max_transfer).  This is the same class of bug that was fixed for snd_usbmidi_akai_output() in commit 0970274613fb (\"ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()\"); the novation output routine was left unguarded. Bail out when the endpoint cannot hold the two-byte header plus at least one payload byte.","cvss":[],"epss":[{"cve":"CVE-2026-80829","epss":0.00195,"percentile":0.09344,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80829","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80829","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1035a8f63bae28e498b0e7b5ac91d749844a7158","https://git.kernel.org/stable/c/1074c2306901b44ebcb83855583c6776e1e392ea","https://git.kernel.org/stable/c/558fc4485ecc704edfe7876d6cebae4738ff7ef8","https://git.kernel.org/stable/c/7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870","https://git.kernel.org/stable/c/7f00dbddb51f4f74325cdc7c3f6b19fb3392481a","https://git.kernel.org/stable/c/91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c","https://git.kernel.org/stable/c/94e4562fcc81badd1d467ddfb88c27e4fae974c2","https://git.kernel.org/stable/c/9c8212436631b0063cb021e9f58df438e3db84d0","https://git.kernel.org/stable/c/e9c00d7533f99aa9833c4b598f47e3b3202fdb9a"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()\n\nsnd_usbmidi_novation_output() lays out a two-byte header at\ntransfer_buffer[0..1] and passes &transfer_buffer[2] together with a\nlength of ep->max_transfer - 2 to snd_rawmidi_transmit():\n\n\tcount = snd_rawmidi_transmit(ep->ports[0].substream,\n\t\t\t\t     &transfer_buffer[2],\n\t\t\t\t     ep->max_transfer - 2);\n\nep->max_transfer comes from the output endpoint's wMaxPacketSize via\nusb_maxpacket(). A malformed or malicious device can advertise a bulk\nOUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this\nvalue downwards - so ep->max_transfer becomes 1 and the count argument\nbecomes -1.\n\nsnd_rawmidi_transmit() passes the negative count on to\n__snd_rawmidi_transmit_peek(), where \"if (count1 > count) count1 = count\"\nleaves count1 negative; get_aligned_size() keeps it negative for a\nbyte-stream substream, so the following memcpy(buffer, ..., count1) runs\nwith a (size_t)-1 length and writes far past the transfer buffer, which\nwas allocated with usb_alloc_coherent(ep->max_transfer).\n\nThis is the same class of bug that was fixed for snd_usbmidi_akai_output()\nin commit 0970274613fb (\"ALSA: usb-audio: fix OOB write in\nsnd_usbmidi_akai_output()\"); the novation output routine was left\nunguarded. Bail out when the endpoint cannot hold the two-byte header\nplus at least one payload byte.","cvss":[],"epss":[{"cve":"CVE-2026-80829","epss":0.00195,"percentile":0.09344,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80829","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80830","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80830","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: core: Add lock to usb_wakeup_notification()  Add a spin lock to usb_wakeup notification to prevent a race condition with dereferencing freed memory. This could be hit by the xHCI driver as it calls this function from an IRQ and could race with the hub_disconnect() function, which properly grabs this lock to protect the state of the device.","cvss":[],"epss":[{"cve":"CVE-2026-80830","epss":0.00195,"percentile":0.09343,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80830","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80830","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/04ab260407972e631c86f2bc576cd8e64d65b325","https://git.kernel.org/stable/c/71cfda2fdf78041a01e9d94143baa79feabbdbf6","https://git.kernel.org/stable/c/7c48aa0c1e79116b8af4b988d16ee29b427d6491","https://git.kernel.org/stable/c/960ca456faf61824b178f47967340300b24183db","https://git.kernel.org/stable/c/975ef630393c07fcbebf94f4d97043161b77a6ce","https://git.kernel.org/stable/c/a7a16167991c88016acef720927400404039d850","https://git.kernel.org/stable/c/bf2288583b4e072bdff17a233963619e4bc7a8b5","https://git.kernel.org/stable/c/d80b946804674069db7ce6657319a71cf8eeaa5a","https://git.kernel.org/stable/c/e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: Add lock to usb_wakeup_notification()\n\nAdd a spin lock to usb_wakeup notification to prevent a race condition\nwith dereferencing freed memory. This could be hit by the xHCI driver as\nit calls this function from an IRQ and could race with the\nhub_disconnect() function, which properly grabs this lock to protect the\nstate of the device.","cvss":[],"epss":[{"cve":"CVE-2026-80830","epss":0.00195,"percentile":0.09343,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80830","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80831","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80831","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: mxs-dcp - fix source scatterlist length access  mxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source scatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid and could return zero or a stale DMA length, causing encryption and decryption to process the wrong number of bytes when CONFIG_NEED_SG_DMA_LENGTH=y.  Use the original scatterlist length instead.","cvss":[],"epss":[{"cve":"CVE-2026-80831","epss":0.00165,"percentile":0.06023,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-80831","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80831","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/04201dcc88b26eac52f736e39727fc5c420b7257","https://git.kernel.org/stable/c/0e9edb108a63bbbef952dfcbc597e34ed9c1fb74","https://git.kernel.org/stable/c/1537bd55b4f842565068c54b47cd2ae1777d5f8f","https://git.kernel.org/stable/c/182f16a20d329a1c818d51dad57d9bf43d356c7c","https://git.kernel.org/stable/c/6ef9a4afb52cb102ab038cd42352c142d8505d09","https://git.kernel.org/stable/c/c5bcb084a9871e5b62afb5f48b60adfa13b5d9f8","https://git.kernel.org/stable/c/da14fae5203b72ca71ccfa9af8de9249e40d533a","https://git.kernel.org/stable/c/e72a795df521cb65b7c4705cc11078cdacfaa2f4","https://git.kernel.org/stable/c/fd0f211b27a6ec2ebd8c315683401b43adcc5511"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: mxs-dcp - fix source scatterlist length access\n\nmxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source\nscatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid\nand could return zero or a stale DMA length, causing encryption and\ndecryption to process the wrong number of bytes when\nCONFIG_NEED_SG_DMA_LENGTH=y.\n\nUse the original scatterlist length instead.","cvss":[],"epss":[{"cve":"CVE-2026-80831","epss":0.00165,"percentile":0.06023,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80831","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80832","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80832","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: qce - fix CCM AAD buffer underallocation  The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen() can be smaller than the length later programmed into the DMA scatterlist.  The allocation size is currently calculated as:    ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN  while the DMA length is set to:    ALIGN(assoclen + adata_header_len, 16)  Since ALIGN() does not distribute over addition, the allocation can be smaller than the DMA length. For example, when assoclen = 32 and adata_header_len = 2:    allocation = ALIGN(32, 16) + 6 = 38   DMA length = ALIGN(32 + 2, 16) = 48  As a result, the QCE hardware can read beyond the allocated buffer while computing the CBC-MAC over the associated data. The extra bytes are folded into the authentication tag, resulting in an incorrect tag and causing CCM self-test failures such as:    alg: aead: ccm-aes-qce encryption test failed (wrong result)   on test vector 8  Fix the allocation by adding the maximum possible AAD header length before alignment:    ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)  This guarantees that the allocated buffer is large enough for the fully padded AAD data for all supported header sizes.","cvss":[],"epss":[{"cve":"CVE-2026-80832","epss":0.00178,"percentile":0.07457,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.089},"relatedVulnerabilities":[{"id":"CVE-2026-80832","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80832","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/002f1f99aef7ea631cb687fc17bce64e4963f6aa","https://git.kernel.org/stable/c/11775b35ce9f27e73d62188d7d38aa0dc0a219aa","https://git.kernel.org/stable/c/2f65718b9c1095eef1ae9b374aa0384b1b083f3c","https://git.kernel.org/stable/c/46a84efe2dbaddde89073a3c00c694486937c34b","https://git.kernel.org/stable/c/4839f4c21f9c577eedef2919ced878a3057c7fc3","https://git.kernel.org/stable/c/7f2345f47dd189625f657cd72437179ab4170ee1","https://git.kernel.org/stable/c/c9e0f06a023107694698a7930616aeb460d91816","https://git.kernel.org/stable/c/cc56d2b0d77cfeea061e98114992ee687d5eb4dd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qce - fix CCM AAD buffer underallocation\n\nThe AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen()\ncan be smaller than the length later programmed into the DMA\nscatterlist.\n\nThe allocation size is currently calculated as:\n\n  ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN\n\nwhile the DMA length is set to:\n\n  ALIGN(assoclen + adata_header_len, 16)\n\nSince ALIGN() does not distribute over addition, the allocation\ncan be smaller than the DMA length. For example, when\nassoclen = 32 and adata_header_len = 2:\n\n  allocation = ALIGN(32, 16) + 6 = 38\n  DMA length = ALIGN(32 + 2, 16) = 48\n\nAs a result, the QCE hardware can read beyond the allocated\nbuffer while computing the CBC-MAC over the associated data.\nThe extra bytes are folded into the authentication tag,\nresulting in an incorrect tag and causing CCM self-test\nfailures such as:\n\n  alg: aead: ccm-aes-qce encryption test failed (wrong result)\n  on test vector 8\n\nFix the allocation by adding the maximum possible AAD header\nlength before alignment:\n\n  ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)\n\nThis guarantees that the allocated buffer is large enough\nfor the fully padded AAD data for all supported header sizes.","cvss":[],"epss":[{"cve":"CVE-2026-80832","epss":0.00178,"percentile":0.07457,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80832","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80833","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80833","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: sun8i-ss - Remove crypto_rng interface  Since the crypto_rng interface for hardware PRNGs is unused and is redundant with hwrng and the actual Linux RNG, it's being phased out. Most drivers for it were already removed.  Go ahead and remove the sun8i-ss support which is one of the only remaining ones.  As usual for crypto_rng, this driver was also buggy: its ->generate() function had a use-after-free vulnerability due to using wait_for_completion_interruptible_timeout() without handling shutting down the DMA operation if a signal is sent.  Also, it had a buffer overread bug in the line 'memcpy(ctx->seed, d + dlen, ctx->slen);'. There's no point in fixing these bugs separately only to remove the code anyway, so this commit is marked with Fixes and Cc stable.","cvss":[],"epss":[{"cve":"CVE-2026-80833","epss":0.00168,"percentile":0.06337,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80833","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80833","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/7c257a295e05ceb8f78aa3efecc4e9ce19c3313f","https://git.kernel.org/stable/c/8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f","https://git.kernel.org/stable/c/a78446ee6fae86ac8733f120e3ffce2e5d9384f5","https://git.kernel.org/stable/c/d29ccf9eeb67d775221e49a079caa1af83427afa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ss - Remove crypto_rng interface\n\nSince the crypto_rng interface for hardware PRNGs is unused and is\nredundant with hwrng and the actual Linux RNG, it's being phased out.\nMost drivers for it were already removed.  Go ahead and remove the\nsun8i-ss support which is one of the only remaining ones.\n\nAs usual for crypto_rng, this driver was also buggy: its ->generate()\nfunction had a use-after-free vulnerability due to using\nwait_for_completion_interruptible_timeout() without handling shutting\ndown the DMA operation if a signal is sent.  Also, it had a buffer\noverread bug in the line 'memcpy(ctx->seed, d + dlen, ctx->slen);'.\nThere's no point in fixing these bugs separately only to remove the code\nanyway, so this commit is marked with Fixes and Cc stable.","cvss":[],"epss":[{"cve":"CVE-2026-80833","epss":0.00168,"percentile":0.06337,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80833","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80834","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80834","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: sun8i-ce - Remove crypto_rng interface  Since the crypto_rng interface for hardware PRNGs is unused and is redundant with hwrng and the actual Linux RNG, it's being phased out. Most drivers for it were already removed.  Go ahead and remove the sun8i-ce support which is one of the only remaining ones.  Note that the sun8i-ce support for hwrng remains in place.  That is the interface that actually matters.  As usual for crypto_rng, this driver was also buggy: its ->generate() function had a use-after-free vulnerability due to using wait_for_completion_interruptible_timeout() without handling shutting down the DMA operation if a signal is sent.  There's no point in fixing this separately only to remove the code anyway, so this commit is marked with Fixes and Cc stable.","cvss":[],"epss":[{"cve":"CVE-2026-80834","epss":0.00168,"percentile":0.06338,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80834","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80834","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/011556f71d094da61379ae3672692cae2795304e","https://git.kernel.org/stable/c/1017f987c5f0841f00408a78f947990c9d84b346","https://git.kernel.org/stable/c/7bb9e6060710eb7b59491d9826169190297adace","https://git.kernel.org/stable/c/8e4f9110aba3127024646ef7a8999dcfcc03f516"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ce - Remove crypto_rng interface\n\nSince the crypto_rng interface for hardware PRNGs is unused and is\nredundant with hwrng and the actual Linux RNG, it's being phased out.\nMost drivers for it were already removed.  Go ahead and remove the\nsun8i-ce support which is one of the only remaining ones.\n\nNote that the sun8i-ce support for hwrng remains in place.  That is the\ninterface that actually matters.\n\nAs usual for crypto_rng, this driver was also buggy: its ->generate()\nfunction had a use-after-free vulnerability due to using\nwait_for_completion_interruptible_timeout() without handling shutting\ndown the DMA operation if a signal is sent.  There's no point in fixing\nthis separately only to remove the code anyway, so this commit is marked\nwith Fixes and Cc stable.","cvss":[],"epss":[{"cve":"CVE-2026-80834","epss":0.00168,"percentile":0.06338,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80834","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80836","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80836","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  crypto: virtio - bound the akcipher result length  virtio_crypto_dataq_akcipher_callback() sets the result length from the device-reported response length without bounding it to the destination buffer, which was allocated for the original request length. sg_copy_from_buffer() then reads that many bytes from the destination buffer; a backend reporting a larger length over-reads adjacent kernel heap into the caller's scatterlist (an out-of-bounds read).  Clamp the reported length to the originally requested destination length. A conforming device reports no more than that, so valid results are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80836","epss":0.00168,"percentile":0.06349,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80836","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80836","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1f9f877b1ef1fbd4ee95571cddf39c8002cee252","https://git.kernel.org/stable/c/3fda114a42f1510a4ec8a0b17a0cfc997952ccc2","https://git.kernel.org/stable/c/5545de5050cbc3594506d74f2c392b0716cf8bca","https://git.kernel.org/stable/c/f77a956f6a19f9463ef1527c9d0cda50dded6b92"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio - bound the akcipher result length\n\nvirtio_crypto_dataq_akcipher_callback() sets the result length from the\ndevice-reported response length without bounding it to the destination\nbuffer, which was allocated for the original request length.\nsg_copy_from_buffer() then reads that many bytes from the destination\nbuffer; a backend reporting a larger length over-reads adjacent kernel\nheap into the caller's scatterlist (an out-of-bounds read).\n\nClamp the reported length to the originally requested destination length.\nA conforming device reports no more than that, so valid results are\nunaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80836","epss":0.00168,"percentile":0.06349,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80836","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80837","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80837","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_tables: don't queue packet path object notifications  All file:line references below are against v7.2-rc4 (ac5b0e5651b1). The trace was captured on 7.2.0-rc6-kasan72rc6 (075b74841bd0), where the same lines apply.  nft_obj_notify() is exported and reached from the packet path. Its only in-tree caller is nft_quota_obj_eval() (net/netfilter/nft_quota.c:68), which notifies with GFP_ATOMIC while evaluating a rule for a transiting packet, holding no mutex.  Since commit 67cc570edaa0 (\"netfilter: nf_tables: coalesce multiple notifications into one skbuff\") that notification is no longer sent immediately. __nft_obj_notify() queues it onto nft_net->notify_list via nft_notify_enqueue() (net/netfilter/nf_tables_api.c:1211), which is a bare list_add_tail(). notify_list has no lock of its own (include/net/netfilter/nf_tables.h:1951), it is serialised by commit_mutex: the six other enqueue sites all run inside a netlink transaction, and the drain in nft_commit_notify() (net/netfilter/nf_tables_api.c:10746) does list_del() + kfree_skb() from nf_tables_commit() with commit_mutex held.  Sending packets through a chain that references a depleted quota object therefore races an unlocked list_add_tail() against list_del() + kfree_skb() on another CPU. The WRITE_ONCE(prev->next, new) in __list_add() then stores through an sk_buff that has already been freed:    BUG: KASAN: slab-use-after-free in __nft_obj_notify+0x2c5/0x2d0   Write of size 8 at addr ff110001047183c0 by task poc/76   CPU: 0 UID: 1000 PID: 76 Comm: poc Tainted: G  W  7.2.0-rc6-kasan72rc6 #4   Call Trace:    <IRQ>    __nft_obj_notify (include/linux/list.h:164 include/linux/list.h:191                      net/netfilter/nf_tables_api.c:1211                      net/netfilter/nf_tables_api.c:8743)    nft_quota_obj_eval (net/netfilter/nft_quota.c:68)    nft_do_chain_inet    nf_hook_slow    __ip_local_out    ip_push_pending_frames    udp_send_skb    udp_sendmsg    __x64_sys_sendto    Allocated by task 77:    __alloc_skb (net/core/skbuff.c:704)    __nft_obj_notify (include/net/netlink.h:1055                      net/netfilter/nf_tables_api.c:8731)    nft_quota_obj_eval (net/netfilter/nft_quota.c:68)    nft_do_chain    Freed by task 79:    nf_tables_commit (include/linux/skbuff.h:1332                      net/netfilter/nf_tables_api.c:10759                      net/netfilter/nf_tables_api.c:11185)    nfnetlink_rcv_batch (net/netfilter/nfnetlink.c:574)    netlink_unicast    netlink_sendmsg    The buggy address belongs to the cache skbuff_head_cache of size 232  Queueing from the packet path is wrong even leaving the race aside: notify_list is only drained by nft_commit_notify() from nf_tables_commit() (:11185), so a notification enqueued outside a transaction is not sent until some later netlink batch commits, if one ever does.  The gfp argument that nft_obj_notify() still takes is a leftover of the pre-67cc570edaa0 behaviour, where this path called nfnetlink_send() directly. Restore that: split the message construction out into nft_obj_notify_alloc() and let each caller decide what to do with the skb. nft_obj_notify(), the exported one reached from the packet path, sends it straight away; nf_tables_obj_notify(), which runs under commit_mutex, keeps queueing it, so transaction notifications are still coalesced.","cvss":[],"epss":[{"cve":"CVE-2026-80837","epss":0.00168,"percentile":0.06347,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80837","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80837","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/68de7f3a38acab355c24114f77bf00d3094ce4da","https://git.kernel.org/stable/c/6fa88d11983c6fe693c13ed7c5b3b75ae9f39de6","https://git.kernel.org/stable/c/7904b94768e983bcb2be34a8d6d1f3450f5b838b","https://git.kernel.org/stable/c/df86c0e84025be8b6dd572a20852698927aa666b","https://git.kernel.org/stable/c/e97e2d6d0b150fd78be573f9fdf193f204d9334e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: don't queue packet path object notifications\n\nAll file:line references below are against v7.2-rc4 (ac5b0e5651b1). The\ntrace was captured on 7.2.0-rc6-kasan72rc6 (075b74841bd0), where the same\nlines apply.\n\nnft_obj_notify() is exported and reached from the packet path. Its only\nin-tree caller is nft_quota_obj_eval() (net/netfilter/nft_quota.c:68),\nwhich notifies with GFP_ATOMIC while evaluating a rule for a transiting\npacket, holding no mutex.\n\nSince commit 67cc570edaa0 (\"netfilter: nf_tables: coalesce multiple\nnotifications into one skbuff\") that notification is no longer sent\nimmediately. __nft_obj_notify() queues it onto nft_net->notify_list via\nnft_notify_enqueue() (net/netfilter/nf_tables_api.c:1211), which is a bare\nlist_add_tail(). notify_list has no lock of its own\n(include/net/netfilter/nf_tables.h:1951), it is serialised by commit_mutex:\nthe six other enqueue sites all run inside a netlink transaction, and the\ndrain in nft_commit_notify() (net/netfilter/nf_tables_api.c:10746) does\nlist_del() + kfree_skb() from nf_tables_commit() with commit_mutex held.\n\nSending packets through a chain that references a depleted quota object\ntherefore races an unlocked list_add_tail() against list_del() +\nkfree_skb() on another CPU. The WRITE_ONCE(prev->next, new) in __list_add()\nthen stores through an sk_buff that has already been freed:\n\n  BUG: KASAN: slab-use-after-free in __nft_obj_notify+0x2c5/0x2d0\n  Write of size 8 at addr ff110001047183c0 by task poc/76\n  CPU: 0 UID: 1000 PID: 76 Comm: poc Tainted: G  W  7.2.0-rc6-kasan72rc6 #4\n  Call Trace:\n   <IRQ>\n   __nft_obj_notify (include/linux/list.h:164 include/linux/list.h:191\n                     net/netfilter/nf_tables_api.c:1211\n                     net/netfilter/nf_tables_api.c:8743)\n   nft_quota_obj_eval (net/netfilter/nft_quota.c:68)\n   nft_do_chain_inet\n   nf_hook_slow\n   __ip_local_out\n   ip_push_pending_frames\n   udp_send_skb\n   udp_sendmsg\n   __x64_sys_sendto\n\n  Allocated by task 77:\n   __alloc_skb (net/core/skbuff.c:704)\n   __nft_obj_notify (include/net/netlink.h:1055\n                     net/netfilter/nf_tables_api.c:8731)\n   nft_quota_obj_eval (net/netfilter/nft_quota.c:68)\n   nft_do_chain\n\n  Freed by task 79:\n   nf_tables_commit (include/linux/skbuff.h:1332\n                     net/netfilter/nf_tables_api.c:10759\n                     net/netfilter/nf_tables_api.c:11185)\n   nfnetlink_rcv_batch (net/netfilter/nfnetlink.c:574)\n   netlink_unicast\n   netlink_sendmsg\n\n  The buggy address belongs to the cache skbuff_head_cache of size 232\n\nQueueing from the packet path is wrong even leaving the race aside:\nnotify_list is only drained by nft_commit_notify() from nf_tables_commit()\n(:11185), so a notification enqueued outside a transaction is not sent\nuntil some later netlink batch commits, if one ever does.\n\nThe gfp argument that nft_obj_notify() still takes is a leftover of the\npre-67cc570edaa0 behaviour, where this path called nfnetlink_send()\ndirectly. Restore that: split the message construction out into\nnft_obj_notify_alloc() and let each caller decide what to do with the skb.\nnft_obj_notify(), the exported one reached from the packet path, sends it\nstraight away; nf_tables_obj_notify(), which runs under commit_mutex, keeps\nqueueing it, so transaction notifications are still coalesced.","cvss":[],"epss":[{"cve":"CVE-2026-80837","epss":0.00168,"percentile":0.06347,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80837","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80840","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80840","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: seg6: clear IPv4 control block on IPIP decapsulation  End.DX4 and End.DT4 decapsulate an IPv4 packet through decap_and_validate() and send it directly to IPv4 routing. The inner packet therefore bypasses ip_rcv_core(), which normally clears IPCB before IPv4 interprets skb->cb.  The skb instead retains IP6CB data from the outer packet. IP6CB and IPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps IPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and ts.  The sender can make the stale optlen byte nonzero with a valid outer extension-header chain. The reproducers put an eight-byte Destination Options header immediately after the 40-byte IPv6 header and before the Segment Routing Header. ipv6_destopt_rcv() records the sender-controlled Destination Options offset in both lastopt and nhoff, setting them to 40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees optlen = 40 and rr = 40.  Both tcp_v4_save_options() and __ip_options_echo() skip option copying when optlen is zero. Here optlen is 40, so the TCP SYN path allocates room for 40 bytes of option data and calls __ip_options_echo(). The stale rr value makes that function read inner packet byte 41 as the Record Route option length. The reproducers set that sender-controlled byte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte option-data area.  Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5 kernel both produced:    BUG: KASAN: slab-out-of-bounds in __ip_options_echo()   Write of size 255  The relevant End.DX4 call path is:    __ip_options_echo   tcp_v4_route_req   tcp_conn_request   tcp_v4_conn_request   tcp_rcv_state_process   tcp_v4_do_rcv   tcp_v4_rcv   ip_protocol_deliver_rcu   ip_local_deliver_finish   ip_local_deliver   input_action_end_dx4_finish   input_action_end_dx4  The relevant End.DT4 call path is:    __ip_options_echo   tcp_v4_route_req   tcp_conn_request   tcp_v4_conn_request   tcp_rcv_state_process   tcp_v4_do_rcv   tcp_v4_rcv   ip_protocol_deliver_rcu   ip_local_deliver_finish   ip_local_deliver   input_action_end_dt4  tcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so it does not appear as a separate frame.  When decap_and_validate() handles IPPROTO_IPIP, save the ingress interface from IP6CB, clear IPCB, and restore the saved value. Doing this in the common decapsulation path covers End.DX4, End.DT4, and End.DT46's IPv4 arm.  Use IP6CB(skb)->iif rather than skb->skb_iif. These actions run after l3mdev processing, which can replace skb_iif with the L3 master; IP6CB iif still records the receiving interface set at IPv6 ingress.","cvss":[],"epss":[{"cve":"CVE-2026-80840","epss":0.00205,"percentile":0.10552,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.10250000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80840","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80840","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0e3f01fe2e704e76af4385b8a1742641885a191c","https://git.kernel.org/stable/c/10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667","https://git.kernel.org/stable/c/3e4476e58343fb8f2fffced9e22d935376b17aaf","https://git.kernel.org/stable/c/44930446dde45a7a90fe1446fa38eb0e2c561646","https://git.kernel.org/stable/c/9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c","https://git.kernel.org/stable/c/bf1c1151560d11036a144d917fa4c131831342d7","https://git.kernel.org/stable/c/eb0f422487228e140f3d609b032ac61aedcab8fa","https://git.kernel.org/stable/c/f4be3b391265e24c7720fc867c50062b436acf33","https://git.kernel.org/stable/c/f52f1e75716d2ee49e013edf204ac92337c72fd8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: seg6: clear IPv4 control block on IPIP decapsulation\n\nEnd.DX4 and End.DT4 decapsulate an IPv4 packet through\ndecap_and_validate() and send it directly to IPv4 routing. The inner\npacket therefore bypasses ip_rcv_core(), which normally clears IPCB\nbefore IPv4 interprets skb->cb.\n\nThe skb instead retains IP6CB data from the outer packet. IP6CB and\nIPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps\nIPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and\nts.\n\nThe sender can make the stale optlen byte nonzero with a valid outer\nextension-header chain. The reproducers put an eight-byte Destination\nOptions header immediately after the 40-byte IPv6 header and before the\nSegment Routing Header. ipv6_destopt_rcv() records the sender-controlled\nDestination Options offset in both lastopt and nhoff, setting them to\n40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees\noptlen = 40 and rr = 40.\n\nBoth tcp_v4_save_options() and __ip_options_echo() skip option copying\nwhen optlen is zero. Here optlen is 40, so the TCP SYN path allocates\nroom for 40 bytes of option data and calls __ip_options_echo(). The\nstale rr value makes that function read inner packet byte 41 as the\nRecord Route option length. The reproducers set that sender-controlled\nbyte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte\noption-data area.\n\nSeparate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5\nkernel both produced:\n\n  BUG: KASAN: slab-out-of-bounds in __ip_options_echo()\n  Write of size 255\n\nThe relevant End.DX4 call path is:\n\n  __ip_options_echo\n  tcp_v4_route_req\n  tcp_conn_request\n  tcp_v4_conn_request\n  tcp_rcv_state_process\n  tcp_v4_do_rcv\n  tcp_v4_rcv\n  ip_protocol_deliver_rcu\n  ip_local_deliver_finish\n  ip_local_deliver\n  input_action_end_dx4_finish\n  input_action_end_dx4\n\nThe relevant End.DT4 call path is:\n\n  __ip_options_echo\n  tcp_v4_route_req\n  tcp_conn_request\n  tcp_v4_conn_request\n  tcp_rcv_state_process\n  tcp_v4_do_rcv\n  tcp_v4_rcv\n  ip_protocol_deliver_rcu\n  ip_local_deliver_finish\n  ip_local_deliver\n  input_action_end_dt4\n\ntcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so\nit does not appear as a separate frame.\n\nWhen decap_and_validate() handles IPPROTO_IPIP, save the ingress\ninterface from IP6CB, clear IPCB, and restore the saved value. Doing\nthis in the common decapsulation path covers End.DX4, End.DT4, and\nEnd.DT46's IPv4 arm.\n\nUse IP6CB(skb)->iif rather than skb->skb_iif. These actions run after\nl3mdev processing, which can replace skb_iif with the L3 master;\nIP6CB iif still records the receiving interface set at IPv6 ingress.","cvss":[],"epss":[{"cve":"CVE-2026-80840","epss":0.00205,"percentile":0.10552,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80840","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80841","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80841","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/packet: defer vmalloc TX_RING free until skbs finish  AF_PACKET TX_RING skbs keep a raw pointer to their ring frame. The skb page references preserve page-backed ring blocks after pg_vec is freed, but they do not preserve a vmalloc mapping.  tpacket_destruct_skb() currently drops the pending reference before writing the timestamp and TP_STATUS_AVAILABLE to the frame. Move the decrement after those stores. The smp_wmb() in __packet_set_status() orders the frame stores before the decrement.  Also recheck pending TX frames under pg_vec_lock before non-closing ring replacement, so a racing send cannot add a pending skb between the initial check and the ring swap.  Ring allocation can produce a mixture of page-backed and vmalloc-backed blocks. Allocate deferred-work storage during TX ring setup when the first vmalloc-backed block is encountered, and keep its pointer in the pg_vec allocation header. If allocation fails, return -ENOMEM from ring setup. On socket close, a non-NULL pointer identifies a vmalloc-backed vector without a scan. If TX skbs remain, defer the whole vector to system_long_wq.  After pg_vec is detached, a late destructor can skip the pending decrement. Use socket write-memory accounting as the deferred lifetime gate instead: an skb remains charged through its final sock_wfree(), after all ring-frame accesses. The delayed work retains a socket reference and reschedules itself until no TX skbs remain.  Move pending_refcnt release to packet_sock_destruct() so late skb destructors and deferred cleanup can safely use it after packet_release(). Page-backed teardown remains synchronous, and no lock is added to the TX completion hot path.","cvss":[],"epss":[{"cve":"CVE-2026-80841","epss":0.00166,"percentile":0.06149,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-80841","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80841","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0189dce07db2dc059ae0570e06758ec4233c6e11","https://git.kernel.org/stable/c/550d00aa58193fb649a09a9c9e338c685adad784","https://git.kernel.org/stable/c/992cc9f94ca924089a506ba9b327caa9af797529"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: defer vmalloc TX_RING free until skbs finish\n\nAF_PACKET TX_RING skbs keep a raw pointer to their ring frame. The skb\npage references preserve page-backed ring blocks after pg_vec is freed,\nbut they do not preserve a vmalloc mapping.\n\ntpacket_destruct_skb() currently drops the pending reference before\nwriting the timestamp and TP_STATUS_AVAILABLE to the frame. Move the\ndecrement after those stores. The smp_wmb() in __packet_set_status()\norders the frame stores before the decrement.\n\nAlso recheck pending TX frames under pg_vec_lock before non-closing\nring replacement, so a racing send cannot add a pending skb between\nthe initial check and the ring swap.\n\nRing allocation can produce a mixture of page-backed and vmalloc-backed\nblocks. Allocate deferred-work storage during TX ring setup when the\nfirst vmalloc-backed block is encountered, and keep its pointer in the\npg_vec allocation header. If allocation fails, return -ENOMEM from ring\nsetup. On socket close, a non-NULL pointer identifies a vmalloc-backed\nvector without a scan. If TX skbs remain, defer the whole vector to\nsystem_long_wq.\n\nAfter pg_vec is detached, a late destructor can skip the pending\ndecrement. Use socket write-memory accounting as the deferred lifetime\ngate instead: an skb remains charged through its final sock_wfree(),\nafter all ring-frame accesses. The delayed work retains a socket\nreference and reschedules itself until no TX skbs remain.\n\nMove pending_refcnt release to packet_sock_destruct() so late skb\ndestructors and deferred cleanup can safely use it after\npacket_release(). Page-backed teardown remains synchronous, and no lock\nis added to the TX completion hot path.","cvss":[],"epss":[{"cve":"CVE-2026-80841","epss":0.00166,"percentile":0.06149,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80841","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80842","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80842","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: bridge: mcast: fix use-after-free of a master VLAN's multicast context  br_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under br->multicast_lock before stopping a VLAN's multicast context.  That is the teardown handshake: lockless readers gate on the flag through br_multicast_ctx_should_use() -> br_multicast_ctx_vlan_disabled(), so once it is cleared under the lock no reader can arm the context again.  For a master VLAN the handshake never runs.  __vlan_del() clears BRIDGE_VLAN_INFO_BRENTRY before calling br_vlan_put_master(), so br_multicast_toggle_one_vlan(masterv, false) returns early on !br_vlan_is_brentry(vlan): the flag stays set and br->multicast_lock is never taken.  br_vlan_put_master() then drains the context in br_multicast_ctx_deinit() and frees the VLAN through call_rcu(), while a reader still inside rcu_read_lock() sees the context as enabled and re-arms it.  The port and port-VLAN branch of the function has no br_vlan_is_brentry() test and flips the flag under br->multicast_lock, so it is not affected.  The reader is the bridge transmit path.  For a master VLAN br_multicast_rcv() selects brmctx = &vlan->br_mcast_ctx with pmctx = NULL, so IGMP sent to the bridge device re-arms the context's timers after br_multicast_ctx_deinit() has already stopped them.    BUG: KASAN: slab-use-after-free in detach_if_pending+0x412/0x4a0   Write of size 8 at addr ffff88810ac39918 by task brmc/601    __mod_timer+0x51a/0xc50    br_multicast_host_join+0x25b/0x390    __br_multicast_add_group+0x468/0x530    br_ip4_multicast_add_group+0x1a0/0x260    br_multicast_rcv+0x2cda/0x61e0    br_dev_xmit+0x6c4/0x1540   Allocated by task 610:    br_vlan_add+0x111/0xb40    br_vlan_info+0x370/0x3e0   Freed by task 0:    kfree+0x1a7/0x4f0    rcu_core+0x7dc/0x10a0  Only test br_vlan_is_brentry() when enabling, like the br_multicast_ctx_vlan_global_disabled() test next to it.  Disabling then always clears BR_VLFLAG_MCAST_ENABLED under br->multicast_lock before br_multicast_ctx_deinit() drains the context.","cvss":[],"epss":[{"cve":"CVE-2026-80842","epss":0.00177,"percentile":0.07326,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80842","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80842","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/22226a2c3b90f15b0925f1464470d3baa6c5677e","https://git.kernel.org/stable/c/3a0ad4fcdfa0b7dba1876de14a12cb65c8b5ca50","https://git.kernel.org/stable/c/3afaaee2f972aec9059110953adb62fa3cf5c4bd","https://git.kernel.org/stable/c/3f4752996735e0628af559aa8da1d872c2fac13b","https://git.kernel.org/stable/c/50e5c6605cc9c2dd57bd2d1b3459674d19738983","https://git.kernel.org/stable/c/57f94d3f4dee8b54d63cefddf1112be4656ef9e6","https://git.kernel.org/stable/c/7c54fd8cfbcf371a5ef50db5c53fe6e85fb76686","https://git.kernel.org/stable/c/c069f29da72324697aa4b7cab5b3647a7d24a575"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mcast: fix use-after-free of a master VLAN's multicast context\n\nbr_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under\nbr->multicast_lock before stopping a VLAN's multicast context.  That is\nthe teardown handshake: lockless readers gate on the flag through\nbr_multicast_ctx_should_use() -> br_multicast_ctx_vlan_disabled(), so\nonce it is cleared under the lock no reader can arm the context again.\n\nFor a master VLAN the handshake never runs.  __vlan_del() clears\nBRIDGE_VLAN_INFO_BRENTRY before calling br_vlan_put_master(), so\nbr_multicast_toggle_one_vlan(masterv, false) returns early on\n!br_vlan_is_brentry(vlan): the flag stays set and br->multicast_lock is\nnever taken.  br_vlan_put_master() then drains the context in\nbr_multicast_ctx_deinit() and frees the VLAN through call_rcu(), while a\nreader still inside rcu_read_lock() sees the context as enabled and\nre-arms it.  The port and port-VLAN branch of the function has no\nbr_vlan_is_brentry() test and flips the flag under br->multicast_lock,\nso it is not affected.\n\nThe reader is the bridge transmit path.  For a master VLAN\nbr_multicast_rcv() selects brmctx = &vlan->br_mcast_ctx with\npmctx = NULL, so IGMP sent to the bridge device re-arms the context's\ntimers after br_multicast_ctx_deinit() has already stopped them.\n\n  BUG: KASAN: slab-use-after-free in detach_if_pending+0x412/0x4a0\n  Write of size 8 at addr ffff88810ac39918 by task brmc/601\n   __mod_timer+0x51a/0xc50\n   br_multicast_host_join+0x25b/0x390\n   __br_multicast_add_group+0x468/0x530\n   br_ip4_multicast_add_group+0x1a0/0x260\n   br_multicast_rcv+0x2cda/0x61e0\n   br_dev_xmit+0x6c4/0x1540\n  Allocated by task 610:\n   br_vlan_add+0x111/0xb40\n   br_vlan_info+0x370/0x3e0\n  Freed by task 0:\n   kfree+0x1a7/0x4f0\n   rcu_core+0x7dc/0x10a0\n\nOnly test br_vlan_is_brentry() when enabling, like the\nbr_multicast_ctx_vlan_global_disabled() test next to it.  Disabling then\nalways clears BR_VLFLAG_MCAST_ENABLED under br->multicast_lock before\nbr_multicast_ctx_deinit() drains the context.","cvss":[],"epss":[{"cve":"CVE-2026-80842","epss":0.00177,"percentile":0.07326,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80842","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80843","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80843","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: fix xfrm_state_construct() auth-trunc leak  attach_auth_trunc() can allocate x->aalg while leaving x->props.aalgo at zero when the selected auth algorithm has no sadb_alg_id. One real case is cmac(aes).  xfrm_state_construct() then treats !x->props.aalgo as \"no auth algorithm attached yet\" and calls attach_auth(). That overwrites x->aalg and loses the first allocation. Any later failure or teardown only frees the replacement pointer.  Check whether x->aalg is already attached instead of inferring that state from x->props.aalgo.","cvss":[],"epss":[{"cve":"CVE-2026-80843","epss":0.00195,"percentile":0.09341,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80843","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80843","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/37426395cb90ef217beec8407a14bd82153793d3","https://git.kernel.org/stable/c/71d42da01740ec6557837bebec0bc48cfc3b4c39","https://git.kernel.org/stable/c/958ae9f261319e1cdc44879886bcda2263258cca","https://git.kernel.org/stable/c/ba0c110c205855b3f1e3130d8c0fdb484d704c8c","https://git.kernel.org/stable/c/be19d20e53a239572bb2a28efcc1cd2b069b1ef9","https://git.kernel.org/stable/c/c12cbf56320fb633484ee0ca1fb7d68d6b64b213","https://git.kernel.org/stable/c/c8837bbe792257af547fd1c0252553ce13148795","https://git.kernel.org/stable/c/cf67361e78dca488d6e4df8396a53e6745a3a80e","https://git.kernel.org/stable/c/fb7f3e74789a3c89647f4eb768f6dfaf4a751e72"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix xfrm_state_construct() auth-trunc leak\n\nattach_auth_trunc() can allocate x->aalg while leaving\nx->props.aalgo at zero when the selected auth algorithm has no\nsadb_alg_id. One real case is cmac(aes).\n\nxfrm_state_construct() then treats !x->props.aalgo as \"no auth\nalgorithm attached yet\" and calls attach_auth(). That overwrites\nx->aalg and loses the first allocation. Any later failure or teardown\nonly frees the replacement pointer.\n\nCheck whether x->aalg is already attached instead of inferring that\nstate from x->props.aalgo.","cvss":[],"epss":[{"cve":"CVE-2026-80843","epss":0.00195,"percentile":0.09341,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80843","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80844","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80844","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: ah6: validate routing header segments_left  AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field.  That assumption does not hold for raw IPv6 HDRINCL packets. A packet with hdrlen equal to 2 describes one address, but can carry an arbitrary segments_left value. With segments_left equal to 255, the function moves its address pointer 4,064 bytes backwards and passes a 4,064-byte length to memmove(), resulting in an out-of-bounds access.  Validate the invariant locally before modifying the routing header or performing any address-pointer arithmetic, and propagate malformed-header errors to the existing AH6 input and output error paths.","cvss":[],"epss":[{"cve":"CVE-2026-80844","epss":0.00195,"percentile":0.09347,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80844","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80844","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0bf11081ad3753938a2b48723ce6298dbac743a1","https://git.kernel.org/stable/c/1516e31ac458a738be485620579d8f7fb2700fcb","https://git.kernel.org/stable/c/1b7e066eabcc7d6d8f476c34739b45932f2f4c31","https://git.kernel.org/stable/c/2dc650956e4e163b879b3fb1027f9557abc5c985","https://git.kernel.org/stable/c/46640c814f25f096b0b0045ca50e1b7030cd8a30","https://git.kernel.org/stable/c/48b0e36cf54358276ee7aa897034c973097d2bc9","https://git.kernel.org/stable/c/6733ae71268a27d598cfb3f3339a3c950b9b656d","https://git.kernel.org/stable/c/7bad4bda74dc4713f398d3b7624ff05478e3a568","https://git.kernel.org/stable/c/f00df8500e5a36ba70d336fd34bd2152ea074e5f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: ah6: validate routing header segments_left\n\nAH6 rearranges routing-header addresses before computing or verifying the\nICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than\nthe number of addresses described by the routing header's hdrlen field.\n\nThat assumption does not hold for raw IPv6 HDRINCL packets. A packet with\nhdrlen equal to 2 describes one address, but can carry an arbitrary\nsegments_left value. With segments_left equal to 255, the function moves\nits address pointer 4,064 bytes backwards and passes a 4,064-byte length to\nmemmove(), resulting in an out-of-bounds access.\n\nValidate the invariant locally before modifying the routing header or\nperforming any address-pointer arithmetic, and propagate malformed-header\nerrors to the existing AH6 input and output error paths.","cvss":[],"epss":[{"cve":"CVE-2026-80844","epss":0.00195,"percentile":0.09347,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80844","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80846","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80846","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: drop ESP-in-TCP packets with no ingress device  ESP-in-TCP receives records through the TCP strparser. handle_esp() restores skb->dev from the saved skb_iif before passing the packet into the XFRM input path.  Queued TCP data can be processed after the original ingress device has been removed, for example during veth or net namespace teardown. In that case dev_get_by_index_rcu() returns NULL. The XFRM IPv4 and IPv6 input paths both expect skb->dev to be valid while building the route lookup, so queued ESP-in-TCP data can dereference a NULL device.  Drop the packet if the saved ingress device can no longer be resolved. Such a packet can no longer be routed through the normal XFRM receive path, and this preserves the existing behaviour for packets whose ingress device still exists.","cvss":[],"epss":[{"cve":"CVE-2026-80846","epss":0.00195,"percentile":0.09347,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80846","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80846","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/239d0f71af09dc2029fd4d730cb24b8c83aaa43a","https://git.kernel.org/stable/c/2dd1609cadff46c4b20ce53b91ab9cce1380456a","https://git.kernel.org/stable/c/328e40aa774b446969c69b654c52a051a95af8a1","https://git.kernel.org/stable/c/6af5cdb03819a5ce6e945992635c6c5e91045367","https://git.kernel.org/stable/c/7911e0236616487b89db6bd3ba3f408abd10eb23","https://git.kernel.org/stable/c/943d95233b8b4a88994e244fcf466f8c403d63f1","https://git.kernel.org/stable/c/c296d25efbc840be24de83f56d43bc47e714ace9","https://git.kernel.org/stable/c/e1d7c5ac1c246ce5775f604515de0a59fbf2116e","https://git.kernel.org/stable/c/f00235f9d12301183d61f75fbe4105506f3e5140"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: drop ESP-in-TCP packets with no ingress device\n\nESP-in-TCP receives records through the TCP strparser. handle_esp()\nrestores skb->dev from the saved skb_iif before passing the packet into\nthe XFRM input path.\n\nQueued TCP data can be processed after the original ingress device has\nbeen removed, for example during veth or net namespace teardown. In that\ncase dev_get_by_index_rcu() returns NULL. The XFRM IPv4 and IPv6 input\npaths both expect skb->dev to be valid while building the route lookup,\nso queued ESP-in-TCP data can dereference a NULL device.\n\nDrop the packet if the saved ingress device can no longer be resolved.\nSuch a packet can no longer be routed through the normal XFRM receive\npath, and this preserves the existing behaviour for packets whose ingress\ndevice still exists.","cvss":[],"epss":[{"cve":"CVE-2026-80846","epss":0.00195,"percentile":0.09347,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80846","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80847","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80847","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tcp: clamp route advmss to TCP_MIN_MSS  tcp_select_initial_window() assumes that callers never pass an MSS smaller than 1, but route-derived advmss values can violate that assumption.  A too-small explicit RTAX_ADVMSS is one way to get there, but it is not the only one. The same divide-by-zero can also be reached through the \"default advmss\" path when RTAX_ADVMSS is left at 0 and the effective advmss is later driven down by route MTU and min_adv_mss.  Introduce a tcp_dst_advmss() helper that clamps route advmss to TCP_MIN_MSS before TCP consumes it, and use it in the TCP paths that derive advmss from dst metrics. This keeps the effective MSS from dropping to zero before tcp_select_initial_window() rounds the receive window.","cvss":[],"epss":[{"cve":"CVE-2026-80847","epss":0.00166,"percentile":0.06153,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.083},"relatedVulnerabilities":[{"id":"CVE-2026-80847","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80847","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/31cf2349361902769dc323e4dbf4b449795ec288","https://git.kernel.org/stable/c/6b8c20bf61924dfc38fefb145c9f7406d73fae53","https://git.kernel.org/stable/c/870a9e42ecc6fe1b8c25d87af043cb0d9c178fe1"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: clamp route advmss to TCP_MIN_MSS\n\ntcp_select_initial_window() assumes that callers never pass an MSS\nsmaller than 1, but route-derived advmss values can violate that\nassumption.\n\nA too-small explicit RTAX_ADVMSS is one way to get there, but it is not\nthe only one. The same divide-by-zero can also be reached through the\n\"default advmss\" path when RTAX_ADVMSS is left at 0 and the effective\nadvmss is later driven down by route MTU and min_adv_mss.\n\nIntroduce a tcp_dst_advmss() helper that clamps route advmss to\nTCP_MIN_MSS before TCP consumes it, and use it in the TCP paths that\nderive advmss from dst metrics. This keeps the effective MSS from\ndropping to zero before tcp_select_initial_window() rounds the receive\nwindow.","cvss":[],"epss":[{"cve":"CVE-2026-80847","epss":0.00166,"percentile":0.06153,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80847","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80848","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80848","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  xfrm: espintcp: fix UAF during close  ZDI reported and analyzed a race condition during close for espintcp sockets:      espintcp_close() frees emsg->skb via kfree_skb() without holding     any socket lock. Concurrently, the xfrm_trans_reinject work queue     invokes esp_output_tcp_finish() -> espintcp_push_skb() ->     espintcp_push_msgs() -> skb_send_sock_locked(), which reads the     same skb as a data source.  Fix this by adding a synchronize_rcu() call after resetting sk_prot, since esp_output_tcp_finish() runs under RCU and won't use a socket with sk_prot == &tcp_prot.  Simply taking the socket lock in espintcp_close() could lead to leaks, if esp_output_tcp_finish() re-adds an skb in the slot we just freed. After this, the existing barrier() is no longer needed.","cvss":[],"epss":[{"cve":"CVE-2026-80848","epss":0.00195,"percentile":0.09343,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.09749999999999999},"relatedVulnerabilities":[{"id":"CVE-2026-80848","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80848","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/24efebecf415ba264adba0f0491cec436463a14f","https://git.kernel.org/stable/c/29121c5e6591da527e8e36ddac7120dc527f574d","https://git.kernel.org/stable/c/4b31a875693c480c611519faca46216514e3e052","https://git.kernel.org/stable/c/4bc0dfa28dca6fc0084203732695968049c44072","https://git.kernel.org/stable/c/54b41ad14da9a981131ab6e4d3f79321a503ea5d","https://git.kernel.org/stable/c/deb232e884877bf10b4ce2580909eedec986c284","https://git.kernel.org/stable/c/eb3bbf29c723fe75c0eb92be14f0ec92971fe272","https://git.kernel.org/stable/c/ed5d9102190c45fc70121c036b0626b740040b75","https://git.kernel.org/stable/c/ff8dd7a932f34409a56e1b91a1219340f17457e9"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: espintcp: fix UAF during close\n\nZDI reported and analyzed a race condition during close for espintcp\nsockets:\n\n    espintcp_close() frees emsg->skb via kfree_skb() without holding\n    any socket lock. Concurrently, the xfrm_trans_reinject work queue\n    invokes esp_output_tcp_finish() -> espintcp_push_skb() ->\n    espintcp_push_msgs() -> skb_send_sock_locked(), which reads the\n    same skb as a data source.\n\nFix this by adding a synchronize_rcu() call after resetting sk_prot,\nsince esp_output_tcp_finish() runs under RCU and won't use a socket\nwith sk_prot == &tcp_prot.  Simply taking the socket lock in\nespintcp_close() could lead to leaks, if esp_output_tcp_finish()\nre-adds an skb in the slot we just freed. After this, the existing\nbarrier() is no longer needed.","cvss":[],"epss":[{"cve":"CVE-2026-80848","epss":0.00195,"percentile":0.09343,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80848","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80851","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80851","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  gtp: serialize PDP context updates  PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP network device is being unregistered. The latter is serialized by RTNL, but the generic-netlink delete path only holds RCU.  Running both paths concurrently can therefore make both paths delete the same PDP context. The issue was found through static analysis and reproduced on a KASAN-enabled kernel by a simple two-thread program racing GTP_CMD_DELPDP against RTM_DELLINK:    Oops: general protection fault, probably for non-canonical address   KASAN: maybe wild-memory-access in range          [0xdead000000000120-0xdead000000000127]   RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]   RBP: dead000000000122  The second deletion dereferenced the poisoned hlist pprev pointer.  Serialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a shared mutex. Keep the mutex held until the final use of a PDP context in the NEWPDP path, and keep the RCU read-side section around the complete PDP context use in the DELPDP path.","cvss":[],"epss":[{"cve":"CVE-2026-80851","epss":0.00168,"percentile":0.06352,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.084},"relatedVulnerabilities":[{"id":"CVE-2026-80851","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80851","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1e995498d29784a06a2b2899370a1926cfc8410d","https://git.kernel.org/stable/c/3d950e98f74af9611925a5226edced02155f6ed1","https://git.kernel.org/stable/c/498386b6d402737db1e2eeed4c385acbf0ef9e34","https://git.kernel.org/stable/c/5f77ddb2756340c1b05381674ca025d52998005e","https://git.kernel.org/stable/c/6df4f05bc2991467939d7d80b6f7e121559cc3df"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: serialize PDP context updates\n\nPDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP\nnetwork device is being unregistered. The latter is serialized by RTNL,\nbut the generic-netlink delete path only holds RCU.\n\nRunning both paths concurrently can therefore make both paths delete the\nsame PDP context. The issue was found through static analysis and\nreproduced on a KASAN-enabled kernel by a simple two-thread program\nracing GTP_CMD_DELPDP against RTM_DELLINK:\n\n  Oops: general protection fault, probably for non-canonical address\n  KASAN: maybe wild-memory-access in range\n         [0xdead000000000120-0xdead000000000127]\n  RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]\n  RBP: dead000000000122\n\nThe second deletion dereferenced the poisoned hlist pprev pointer.\n\nSerialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a\nshared mutex. Keep the mutex held until the final use of a PDP context in\nthe NEWPDP path, and keep the RCU read-side section around the complete\nPDP context use in the DELPDP path.","cvss":[],"epss":[{"cve":"CVE-2026-80851","epss":0.00168,"percentile":0.06352,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80851","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80852","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80852","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tls: device: fix out-of-bounds write in tls_append_frag()  Found with syzkaller and a local syzbot instance running on top of a netdevsim TLS offload emulation; tls_device.c is otherwise only reachable on a machine with a NIC that implements the offload.  tls_push_data() only checks whether the open record still has room for another frag at the bottom of its loop, and the MSG_MORE early break skips that check.  The record survives to the next syscall with the frag count it already had, and tls_append_frag() does not check either, so with TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds a non-coalescing pipe page and num_frags walks off the end of tls_record_info.frags[MAX_SKB_FRAGS].  Once the record is pushed, tls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and the sg_set_page() writes land on the destruct_work that follows it, which the workqueue then calls.  The byte limit is fine because copy drops to 0 and the loop falls through to the same check; the frag count has no such feedback.  Push the record rather than keep a full one open, which is what a plain TCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and new_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw already sets full_record when the sk_msg ring fills up, MSG_MORE or not.    BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269)   Write of size 8 at addr ffff8881104d1530 by task tls_oob/450    CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT   Call Trace:    <TASK>    dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)    print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)    kasan_report (mm/kasan/report.c:595)    tls_append_frag (net/tls/tls_device.c:269)    tls_push_data (net/tls/tls_device.c:518)    tls_device_sendmsg (net/tls/tls_device.c:583)    inet_sendmsg (net/ipv4/af_inet.c:865)    sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813)    splice_to_socket (fs/splice.c:884)    do_splice (fs/splice.c:936 fs/splice.c:1349)    __do_splice (fs/splice.c:1431)    __x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616)    do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)    entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)    </TASK>  and, once the record is pushed:    UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24   index 18 is out of range for type 'skb_frag_t [17]'   UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41   index 18 is out of range for type 'scatterlist [17]'   UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39   index 18 is out of range for type 'scatterlist [17]'   UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38   index 26 is out of range for type 'scatterlist [17]'    kernel tried to execute NX-protected page - exploit attempt? (uid: 0)   BUG: unable to handle page fault for address: ffffea000411a680   #PF: supervisor instruction fetch in kernel mode   #PF: error_code(0x0011) - permissions violation   Oops: Oops: 0011 [#1] SMP KASAN PTI   Workqueue: ktls_device_destruct 0xffffea000411a680   RIP: 0010:0xffffea000411a680   Call Trace:    <TASK>    worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)    kthread (kernel/kthread.c:436)    ret_from_fork (arch/x86/kernel/process.c:158)    ret_from_fork_asm (arch/x86/entry/entry_64.S:245)    </TASK>","cvss":[],"epss":[{"cve":"CVE-2026-80852","epss":0.00161,"percentile":0.05599,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-80852","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80852","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/03ced5da6120965d80ed56dbb7d78fa5c9128906","https://git.kernel.org/stable/c/7e1208c135618358da5d7d6664874dc6e53c62fc","https://git.kernel.org/stable/c/a832d7cb09da2a8e4e9734b4be14d3e76169d805","https://git.kernel.org/stable/c/b17cf742eaad70ae29ac558cefb3aa9bbeea03d4","https://git.kernel.org/stable/c/b7f10d4ff987bda038df90052cd4a1434a7412d4","https://git.kernel.org/stable/c/cd7e875b89597f3498917af764758391338d1802","https://git.kernel.org/stable/c/fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: device: fix out-of-bounds write in tls_append_frag()\n\nFound with syzkaller and a local syzbot instance running on top of a\nnetdevsim TLS offload emulation; tls_device.c is otherwise only reachable\non a machine with a NIC that implements the offload.\n\ntls_push_data() only checks whether the open record still has room for\nanother frag at the bottom of its loop, and the MSG_MORE early break\nskips that check.  The record survives to the next syscall with the frag\ncount it already had, and tls_append_frag() does not check either, so\nwith TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds\na non-coalescing pipe page and num_frags walks off the end of\ntls_record_info.frags[MAX_SKB_FRAGS].  Once the record is pushed,\ntls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and\nthe sg_set_page() writes land on the destruct_work that follows it, which\nthe workqueue then calls.\n\nThe byte limit is fine because copy drops to 0 and the loop falls through\nto the same check; the frag count has no such feedback.\n\nPush the record rather than keep a full one open, which is what a plain\nTCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and\nnew_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw\nalready sets full_record when the sk_msg ring fills up, MSG_MORE or not.\n\n  BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269)\n  Write of size 8 at addr ffff8881104d1530 by task tls_oob/450\n\n  CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT\n  Call Trace:\n   <TASK>\n   dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n   print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n   kasan_report (mm/kasan/report.c:595)\n   tls_append_frag (net/tls/tls_device.c:269)\n   tls_push_data (net/tls/tls_device.c:518)\n   tls_device_sendmsg (net/tls/tls_device.c:583)\n   inet_sendmsg (net/ipv4/af_inet.c:865)\n   sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813)\n   splice_to_socket (fs/splice.c:884)\n   do_splice (fs/splice.c:936 fs/splice.c:1349)\n   __do_splice (fs/splice.c:1431)\n   __x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n   </TASK>\n\nand, once the record is pushed:\n\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24\n  index 18 is out of range for type 'skb_frag_t [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41\n  index 18 is out of range for type 'scatterlist [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39\n  index 18 is out of range for type 'scatterlist [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38\n  index 26 is out of range for type 'scatterlist [17]'\n\n  kernel tried to execute NX-protected page - exploit attempt? (uid: 0)\n  BUG: unable to handle page fault for address: ffffea000411a680\n  #PF: supervisor instruction fetch in kernel mode\n  #PF: error_code(0x0011) - permissions violation\n  Oops: Oops: 0011 [#1] SMP KASAN PTI\n  Workqueue: ktls_device_destruct 0xffffea000411a680\n  RIP: 0010:0xffffea000411a680\n  Call Trace:\n   <TASK>\n   worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n   </TASK>","cvss":[],"epss":[{"cve":"CVE-2026-80852","epss":0.00161,"percentile":0.05599,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80852","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80854","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80854","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_tcm: keep port count until LUN teardown completes  tcm_usbg_drop_nexus() permits session removal once tpg_port_count reaches zero. However, usbg_port_unlink() currently decrements that count from the fabric_pre_unlink() callback, before core_dev_del_lun() waits for active se_lun references to drain.  If removal of the last LUN races a nexus removal, the latter can observe a zero port count and call target_remove_session(). This frees sess_cmd_map while an in-flight struct usbg_cmd, including its work item, can still be accessed.  Overlapping the last-LUN unlink with nexus removal reproduces this lifetime violation as a DEBUG_OBJECTS \"free active\" warning for usbg_cmd_work, followed by a target-core BUG/Oops.  The generic target-core unlink path has no callback after core_dev_del_lun() completes. Add an optional fabric_post_unlink() callback and use it for the f_tcm port count. The count now remains nonzero until core_dev_del_lun() has finished draining active LUN references, preventing nexus removal from freeing the session during command completion.","cvss":[],"epss":[{"cve":"CVE-2026-80854","epss":0.00182,"percentile":0.07876,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.091},"relatedVulnerabilities":[{"id":"CVE-2026-80854","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80854","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/178f59a0bccd3f66cdfa5184310f31a58b7257c4","https://git.kernel.org/stable/c/2efbfd42441d3ef8137aff2d59e9835e1d5ae780","https://git.kernel.org/stable/c/85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95","https://git.kernel.org/stable/c/ad6f0375d2e93a1d8c015463e5e92dfcb26e311b","https://git.kernel.org/stable/c/bbd6aa311a9f4dd17822c7557451458d3d2e980b","https://git.kernel.org/stable/c/c1f359d9a5efed458946063de65ddbeaacc4f165","https://git.kernel.org/stable/c/c39d0916da47d94909391876c9e5bd429ea7b1b9","https://git.kernel.org/stable/c/c494c5562ca69b61a82f566e3b87a445d2c28929","https://git.kernel.org/stable/c/eaa96a8458f54d6cf0954242ab8b1df2a6fccafa"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: keep port count until LUN teardown completes\n\ntcm_usbg_drop_nexus() permits session removal once tpg_port_count\nreaches zero. However, usbg_port_unlink() currently decrements that\ncount from the fabric_pre_unlink() callback, before core_dev_del_lun()\nwaits for active se_lun references to drain.\n\nIf removal of the last LUN races a nexus removal, the latter can observe\na zero port count and call target_remove_session(). This frees\nsess_cmd_map while an in-flight struct usbg_cmd, including its work item,\ncan still be accessed.\n\nOverlapping the last-LUN unlink with nexus removal reproduces this\nlifetime violation as a DEBUG_OBJECTS \"free active\" warning for\nusbg_cmd_work, followed by a target-core BUG/Oops.\n\nThe generic target-core unlink path has no callback after\ncore_dev_del_lun() completes. Add an optional fabric_post_unlink()\ncallback and use it for the f_tcm port count. The count now remains\nnonzero until core_dev_del_lun() has finished draining active LUN\nreferences, preventing nexus removal from freeing the session during\ncommand completion.","cvss":[],"epss":[{"cve":"CVE-2026-80854","epss":0.00182,"percentile":0.07876,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80854","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80855","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80855","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fuse: fix invalidate lock leak on open O_TRUNC DAX failure  fuse_open() takes filemap_invalidate_lock() for a DAX truncate (dax_truncate = true) and releases it before the out_inode_unlock label.  But when fuse_dax_break_layouts() fails, the goto out_inode_unlock skips the unlock and leaks the rwsem, so any later fault or truncate on the file stalls on the stale lock.  fuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal interrupts the wait for busy DAX pages to drain:    open(\"file\", O_RDWR | O_TRUNC)   └─ fuse_open()      ├─ filemap_invalidate_lock()        # dax_truncate      └─ fuse_dax_break_layouts()         └─ dax_break_layout()            └─ wait_page_idle()           # TASK_INTERRUPTIBLE               └─ fuse_wait_dax_page()    # unlock, schedule, re-lock                  └─ signal → -ERESTARTSYS      goto out_inode_unlock               # <- lock leaked  Fix this by moving filemap_invalidate_unlock() below the label so that all error paths release the lock, and rename the label to out_unlock as it now covers more than just the inode lock.","cvss":[],"epss":[{"cve":"CVE-2026-80855","epss":0.00165,"percentile":0.05978,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-80855","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80855","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1b04d80a27d317064cce2307472f5bef9975bc50","https://git.kernel.org/stable/c/1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da","https://git.kernel.org/stable/c/7288c279ddbd654a06c82118c1a3f5570c1807f0","https://git.kernel.org/stable/c/776e85fda752f9a15e0f82dec42ecacd12a9bd94","https://git.kernel.org/stable/c/a61524da59a2f5ac9c8de23ff98b30da769ab144","https://git.kernel.org/stable/c/a927f1867e61b78f39f9da0bbba3c98c2ca151fe","https://git.kernel.org/stable/c/dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010","https://git.kernel.org/stable/c/e981474d7bf1457da12404e169ea147d2c8ecea7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on open O_TRUNC DAX failure\n\nfuse_open() takes filemap_invalidate_lock() for a DAX truncate\n(dax_truncate = true) and releases it before the out_inode_unlock\nlabel.  But when fuse_dax_break_layouts() fails, the goto\nout_inode_unlock skips the unlock and leaks the rwsem, so any later\nfault or truncate on the file stalls on the stale lock.\n\nfuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal\ninterrupts the wait for busy DAX pages to drain:\n\n  open(\"file\", O_RDWR | O_TRUNC)\n  └─ fuse_open()\n     ├─ filemap_invalidate_lock()        # dax_truncate\n     └─ fuse_dax_break_layouts()\n        └─ dax_break_layout()\n           └─ wait_page_idle()           # TASK_INTERRUPTIBLE\n              └─ fuse_wait_dax_page()    # unlock, schedule, re-lock\n                 └─ signal → -ERESTARTSYS\n     goto out_inode_unlock               # <- lock leaked\n\nFix this by moving filemap_invalidate_unlock() below the label so\nthat all error paths release the lock, and rename the label to\nout_unlock as it now covers more than just the inode lock.","cvss":[],"epss":[{"cve":"CVE-2026-80855","epss":0.00165,"percentile":0.05978,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80855","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80856","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80856","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  fuse: fix invalidate lock leak on setattr writeback failure  fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate (fault_blocked = true) and releases it at the out:/error: labels.  But when a writeback flush is also needed, a write_inode_now() failure returns directly and leaks the lock, so any later fault or truncate on the file stalls on the stale rwsem.  For example, truncate(2) on a setuid file reaches fuse_do_setattr() with both ATTR_SIZE and ATTR_MODE set:    truncate(2)   └─ do_truncate()      ├─ dentry_needs_remove_privs()         # S_ISUID      └─ notify_change()                     # KILL_SUID -> ATTR_MODE         └─ fuse_setattr()                   # no killpriv:            │                                #   ia_valid |= ATTR_MODE            └─ fuse_do_setattr()               ├─ filemap_invalidate_lock()  # IS_DAX && is_truncate               └─ write_inode_now()          # is_wb && ATTR_MODE                  └─ if (err)                # e.g. daemon -> -EIO                     return err              # <- lock leaked  Fix this by adding an unlock label that releases the lock before returning the error, and use it for the fuse_dax_break_layouts() failure path as well.","cvss":[],"epss":[{"cve":"CVE-2026-80856","epss":0.00165,"percentile":0.05978,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-80856","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80856","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/03cfeeb135428fa83f0791d3f8f94d9298cae695","https://git.kernel.org/stable/c/1758730d9eaa3c06cf415c3446d9f6eed9ed3eed","https://git.kernel.org/stable/c/8f14906ce9103ab8f2f1ebda45935a0d61b9d763","https://git.kernel.org/stable/c/92588d187ba4697a322e7aefe5d9e538a87d1cd2","https://git.kernel.org/stable/c/9afeca0d569c9fc89d758fe7a9339d1e8afb1546","https://git.kernel.org/stable/c/dd278d954c0e96a9cbd3cc491e07b8267d25f8d5","https://git.kernel.org/stable/c/e8457ebfd77a46e8d1210e8888ea914ad064558e","https://git.kernel.org/stable/c/ea9fea370b8de4ffd72e0ef89550415c15637787"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on setattr writeback failure\n\nfuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate\n(fault_blocked = true) and releases it at the out:/error: labels.  But\nwhen a writeback flush is also needed, a write_inode_now() failure\nreturns directly and leaks the lock, so any later fault or truncate on\nthe file stalls on the stale rwsem.\n\nFor example, truncate(2) on a setuid file reaches fuse_do_setattr()\nwith both ATTR_SIZE and ATTR_MODE set:\n\n  truncate(2)\n  └─ do_truncate()\n     ├─ dentry_needs_remove_privs()         # S_ISUID\n     └─ notify_change()                     # KILL_SUID -> ATTR_MODE\n        └─ fuse_setattr()                   # no killpriv:\n           │                                #   ia_valid |= ATTR_MODE\n           └─ fuse_do_setattr()\n              ├─ filemap_invalidate_lock()  # IS_DAX && is_truncate\n              └─ write_inode_now()          # is_wb && ATTR_MODE\n                 └─ if (err)                # e.g. daemon -> -EIO\n                    return err              # <- lock leaked\n\nFix this by adding an unlock label that releases the lock before\nreturning the error, and use it for the fuse_dax_break_layouts()\nfailure path as well.","cvss":[],"epss":[{"cve":"CVE-2026-80856","epss":0.00165,"percentile":0.05978,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80856","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80861","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80861","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  usb: xhci: bail out of setup if the controller is inaccessible  xhci_gen_setup() locates the operational registers using the capability length read from the very first register:  \txhci->op_regs = hcd->regs + \t\tHC_LENGTH(readl(&xhci->cap_regs->hc_capbase));  If the controller is dead or has dropped off the bus, that read returns ~0, HC_LENGTH() truncates it to 0xff, and op_regs ends up 0xff bytes past the page-aligned MMIO base, i.e. unaligned. The first access through it, xhci_halt() -> xhci_handshake() reading op_regs->status, is then an unaligned readl() on device memory. arm64 faults on unaligned device accesses, so instead of xhci_handshake() catching the all-ones value and returning -ENODEV, setup oopses:    xhci-pci-renesas 0005:08:00.0: Unable to change power state from D3cold to D0, device inaccessible   xhci-pci-renesas 0005:08:00.0: xHCI Host Controller   xhci-pci-renesas 0005:08:00.0: new USB bus registered, assigned bus number 1   Unable to handle kernel paging request at virtual address ffff80030a770103     ESR = 0x0000000096000021     FSC = 0x21: alignment fault   Internal error: Oops: 0000000096000021 [#1]  SMP   pc : xhci_halt [xhci_hcd]   Call trace:    xhci_halt    xhci_gen_setup    xhci_pci_setup    usb_add_hcd    usb_hcd_pci_probe    xhci_pci_common_probe    xhci_pci_renesas_probe  This was hit with a Renesas uPD720201 that failed to power up (\"Unable to change power state from D3cold to D0, device inaccessible\") yet still reached the HCD probe path.  Read the capability register once, and if it reads back the all-ones value (as xhci_handshake() and xhci_reset() already test for), abort setup with -ENODEV before op_regs is derived from it. Reading it once also avoids re-reading a register that may change under a concurrent hot-removal.","cvss":[],"epss":[{"cve":"CVE-2026-80861","epss":0.00155,"percentile":0.04925,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-80861","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80861","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0b31744f70c5e06cce5fb660e02d057a3b9e0e37","https://git.kernel.org/stable/c/78203d5b54a40f0e36196ebf31c9c7a380fc8811","https://git.kernel.org/stable/c/bf84c6b0264947794fa783c324a6d874ca6657d8"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: bail out of setup if the controller is inaccessible\n\nxhci_gen_setup() locates the operational registers using the capability\nlength read from the very first register:\n\n\txhci->op_regs = hcd->regs +\n\t\tHC_LENGTH(readl(&xhci->cap_regs->hc_capbase));\n\nIf the controller is dead or has dropped off the bus, that read returns\n~0, HC_LENGTH() truncates it to 0xff, and op_regs ends up 0xff bytes\npast the page-aligned MMIO base, i.e. unaligned. The first access\nthrough it, xhci_halt() -> xhci_handshake() reading op_regs->status, is\nthen an unaligned readl() on device memory. arm64 faults on unaligned\ndevice accesses, so instead of xhci_handshake() catching the all-ones\nvalue and returning -ENODEV, setup oopses:\n\n  xhci-pci-renesas 0005:08:00.0: Unable to change power state from D3cold to D0, device inaccessible\n  xhci-pci-renesas 0005:08:00.0: xHCI Host Controller\n  xhci-pci-renesas 0005:08:00.0: new USB bus registered, assigned bus number 1\n  Unable to handle kernel paging request at virtual address ffff80030a770103\n    ESR = 0x0000000096000021\n    FSC = 0x21: alignment fault\n  Internal error: Oops: 0000000096000021 [#1]  SMP\n  pc : xhci_halt [xhci_hcd]\n  Call trace:\n   xhci_halt\n   xhci_gen_setup\n   xhci_pci_setup\n   usb_add_hcd\n   usb_hcd_pci_probe\n   xhci_pci_common_probe\n   xhci_pci_renesas_probe\n\nThis was hit with a Renesas uPD720201 that failed to power up (\"Unable\nto change power state from D3cold to D0, device inaccessible\") yet still\nreached the HCD probe path.\n\nRead the capability register once, and if it reads back the all-ones\nvalue (as xhci_handshake() and xhci_reset() already test for), abort\nsetup with -ENODEV before op_regs is derived from it. Reading it once\nalso avoids re-reading a register that may change under a concurrent\nhot-removal.","cvss":[],"epss":[{"cve":"CVE-2026-80861","epss":0.00155,"percentile":0.04925,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80861","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80863","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80863","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Fix OOB in free_rd_atomic_resources()  free_rd_atomic_resources() iterates using qp->attr.max_dest_rd_atomic. Updating max_dest_rd_atomic before freeing the old array can make the free path walk past the old allocation and trigger a slab out-of-bounds write catched by KASAN: ================================================================== BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline] BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline] BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline] BUG: KASAN: slab-out-of-bounds in rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712 Write of size 4 at addr ffff88802b8dddb8 by task syz.3.451/11063  CPU: 0 UID: 0 PID: 11063 Comm: syz.3.451 Not tainted 7.1.0 #2 PREEMPT(full) Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace:  <TASK>  __dump_stack lib/dump_stack.c:94 [inline]  dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:378 [inline]  print_report+0xf7/0x600 mm/kasan/report.c:482  kasan_report+0xe4/0x120 mm/kasan/report.c:595  free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]  free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]  free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]  rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712  rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623  ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625  _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915  modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932  ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958  ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_main.c:680  vfs_write+0x2aa/0x1070 fs/read_write.c:686  ksys_write+0x1f8/0x250 fs/read_write.c:740  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fefc75a70cd Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fefc8495018 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 RAX: ffffffffffffffda RBX: 00007fefc7835fa0 RCX: 00007fefc75a70cd RDX: 0000000000000078 RSI: 0000200000000240 RDI: 0000000000000007 RBP: 00007fefc764f10f R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007fefc7836038 R14: 00007fefc7835fa0 R15: 00007ffcf0586aa0  </TASK>  Allocated by task 11063:  kasan_save_stack+0x33/0x60 mm/kasan/common.c:57  kasan_save_track+0x14/0x30 mm/kasan/common.c:78  poison_kmalloc_redzone mm/kasan/common.c:398 [inline]  __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415  kasan_kmalloc include/linux/kasan.h:263 [inline]  __do_kmalloc_node mm/slub.c:5296 [inline]  __kmalloc_noprof+0x32a/0x850 mm/slub.c:5308  kmalloc_noprof include/linux/slab.h:954 [inline]  kzalloc_noprof include/linux/slab.h:1188 [inline]  alloc_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:155 [inline]  rxe_qp_from_attr+0x3f8/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:714  rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623  ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625  _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915  modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932  ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958  ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_ma ---truncated---","cvss":[],"epss":[{"cve":"CVE-2026-80863","epss":0.00182,"percentile":0.07876,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.091},"relatedVulnerabilities":[{"id":"CVE-2026-80863","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80863","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/142c8165b7974b40fa62c393653edb5c00b8b5fe","https://git.kernel.org/stable/c/30b90b55201902b2b8edcdbe2315ccd4c7547002","https://git.kernel.org/stable/c/4e5f753e8c280278c09f68fe728abf846e2bdfc1","https://git.kernel.org/stable/c/9b7d66ea88ae9395e42766b94a5c717b158b940a","https://git.kernel.org/stable/c/bc6e943794515d2a8417b02597a27bd377468d04","https://git.kernel.org/stable/c/bdf5deccfbf9f556a08d1d2ef52e9e48f969e53e","https://git.kernel.org/stable/c/d219e7a8eed3802970c3e4d243d79c70ef0a31bf","https://git.kernel.org/stable/c/de329533792a373186d79dca1ca120f8fa0afd05","https://git.kernel.org/stable/c/f5e6580a3a16a83c743ad5a7c16922854a0d8b71"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix OOB in free_rd_atomic_resources()\n\nfree_rd_atomic_resources() iterates using qp->attr.max_dest_rd_atomic.\nUpdating max_dest_rd_atomic before freeing the old array can make the\nfree path walk past the old allocation and trigger a slab out-of-bounds\nwrite catched by KASAN:\n==================================================================\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]\nBUG: KASAN: slab-out-of-bounds in rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712\nWrite of size 4 at addr ffff88802b8dddb8 by task syz.3.451/11063\n\nCPU: 0 UID: 0 PID: 11063 Comm: syz.3.451 Not tainted 7.1.0 #2 PREEMPT(full)\nHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xf7/0x600 mm/kasan/report.c:482\n kasan_report+0xe4/0x120 mm/kasan/report.c:595\n free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]\n free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]\n free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]\n rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712\n rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623\n ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625\n _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915\n modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932\n ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958\n ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_main.c:680\n vfs_write+0x2aa/0x1070 fs/read_write.c:686\n ksys_write+0x1f8/0x250 fs/read_write.c:740\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fefc75a70cd\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fefc8495018 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00007fefc7835fa0 RCX: 00007fefc75a70cd\nRDX: 0000000000000078 RSI: 0000200000000240 RDI: 0000000000000007\nRBP: 00007fefc764f10f R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007fefc7836038 R14: 00007fefc7835fa0 R15: 00007ffcf0586aa0\n </TASK>\n\nAllocated by task 11063:\n kasan_save_stack+0x33/0x60 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398 [inline]\n __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263 [inline]\n __do_kmalloc_node mm/slub.c:5296 [inline]\n __kmalloc_noprof+0x32a/0x850 mm/slub.c:5308\n kmalloc_noprof include/linux/slab.h:954 [inline]\n kzalloc_noprof include/linux/slab.h:1188 [inline]\n alloc_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:155 [inline]\n rxe_qp_from_attr+0x3f8/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:714\n rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623\n ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625\n _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915\n modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932\n ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958\n ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_ma\n---truncated---","cvss":[],"epss":[{"cve":"CVE-2026-80863","epss":0.00182,"percentile":0.07876,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80863","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80864","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80864","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp  rxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the IB_QP_STATE path, so it holds no state_lock and runs while the responder task rxe_receiver() (recv_task on rxe_wq) is live. A modify_qp() setting only that attribute calls free_rd_atomic_resources() then alloc_rd_atomic_resources(), swapping qp->resp.resources[] while rxe_prepare_res()/find_resource() walk it; free_rd_atomic_resources() also leaves the cached pointer qp->resp.res dangling. A local unprivileged user can race the free/realloc into a use-after-free in rxe_receiver() (local DoS).  Drain recv_task around the swap with rxe_disable_task()/rxe_enable_task(), as rxe_qp_reset() already does when tearing this array down, re-enabling only after alloc_rd_atomic_resources() succeeds so the responder never resumes against a NULL qp->resp.resources on the ENOMEM path. Also clear qp->resp.res in free_rd_atomic_resources(), like the rxe_resp.c completion paths.  Reproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone.","cvss":[],"epss":[{"cve":"CVE-2026-80864","epss":0.00156,"percentile":0.05132,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.078},"relatedVulnerabilities":[{"id":"CVE-2026-80864","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80864","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0136b528b753c5a56e4d997ef20b86bb6750b8fb","https://git.kernel.org/stable/c/60dfd47929cd1e7070daa810d40ce538d888410d","https://git.kernel.org/stable/c/6f7014237405e7f032b5c53a82d9eccf6161c291","https://git.kernel.org/stable/c/d4cd32eb8bd2b0ffbdc7b1f3d82ce6a371f8f844","https://git.kernel.org/stable/c/ffa4f0be69656be1755090f02db38d49816585c6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp\n\nrxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the\nIB_QP_STATE path, so it holds no state_lock and runs while the responder\ntask rxe_receiver() (recv_task on rxe_wq) is live. A modify_qp() setting\nonly that attribute calls free_rd_atomic_resources() then\nalloc_rd_atomic_resources(), swapping qp->resp.resources[] while\nrxe_prepare_res()/find_resource() walk it; free_rd_atomic_resources()\nalso leaves the cached pointer qp->resp.res dangling. A local\nunprivileged user can race the free/realloc into a use-after-free in\nrxe_receiver() (local DoS).\n\nDrain recv_task around the swap with rxe_disable_task()/rxe_enable_task(),\nas rxe_qp_reset() already does when tearing this array down, re-enabling\nonly after alloc_rd_atomic_resources() succeeds so the responder never\nresumes against a NULL qp->resp.resources on the ENOMEM path. Also clear\nqp->resp.res in free_rd_atomic_resources(), like the rxe_resp.c\ncompletion paths.\n\nReproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone.","cvss":[],"epss":[{"cve":"CVE-2026-80864","epss":0.00156,"percentile":0.05132,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80864","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80866","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80866","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  tipc: avoid busy looping in tipc_exit_net()  Blamed commit introduced a busy-wait loop in tipc_exit_net() to wait for pending UDP bearer cleanup works to complete:         while (atomic_read(&tn->wq_count))                cond_resched();  This loop can busy-wait for a long time if cond_resched() is a NOP. This typically happens if the netns exit is executed by a high priority task, or under kernels configured without preemption (CONFIG_PREEMPT_NONE). In such cases, it wastes CPU cycles and can lead to soft lockups.  Fix this by replacing the busy loop with wait_var_event(), allowing the thread to sleep properly until the work queue count reaches zero.  Accordingly, update cleanup_bearer() to use atomic_dec_and_test() and wake_up_var() to wake up the waiter when the count drops to zero.  This uses the global wait queue hash table, avoiding the need to bloat struct tipc_net with a wait_queue_head_t. The atomic_dec_and_test() provides the necessary memory barrier to ensure the wakeup is not missed.","cvss":[],"epss":[{"cve":"CVE-2026-80866","epss":0.00145,"percentile":0.0409,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0725},"relatedVulnerabilities":[{"id":"CVE-2026-80866","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80866","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/522d1d950b9e3b68190a6de7534827c8dccedb73","https://git.kernel.org/stable/c/c1481c94e74c955e0448ddf46b8615a44d840c1e"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: avoid busy looping in tipc_exit_net()\n\nBlamed commit introduced a busy-wait loop in tipc_exit_net()\nto wait for pending UDP bearer cleanup works to complete:\n\n       while (atomic_read(&tn->wq_count))\n               cond_resched();\n\nThis loop can busy-wait for a long time if cond_resched() is a NOP. This\ntypically happens if the netns exit is executed by a high priority task,\nor under kernels configured without preemption (CONFIG_PREEMPT_NONE). In\nsuch cases, it wastes CPU cycles and can lead to soft lockups.\n\nFix this by replacing the busy loop with wait_var_event(), allowing the\nthread to sleep properly until the work queue count reaches zero.\n\nAccordingly, update cleanup_bearer() to use atomic_dec_and_test() and\nwake_up_var() to wake up the waiter when the count drops to zero.\n\nThis uses the global wait queue hash table, avoiding the need to bloat\nstruct tipc_net with a wait_queue_head_t. The atomic_dec_and_test()\nprovides the necessary memory barrier to ensure the wakeup is not missed.","cvss":[],"epss":[{"cve":"CVE-2026-80866","epss":0.00145,"percentile":0.0409,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80866","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80883","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80883","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered  The host1x_client_register() function is called just prior to register map initialization loop, making the device available to userspace. This may result in userspace attempting to submits a job before the register map is initialized. Address this by moving register initialization before host1x client registration.","cvss":[],"epss":[{"cve":"CVE-2026-80883","epss":0.00157,"percentile":0.0518,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0785},"relatedVulnerabilities":[{"id":"CVE-2026-80883","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80883","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3055292b8eed69553b389a609197a241df47e68e","https://git.kernel.org/stable/c/40a2a91da02c434938f0ba53877984820800b5f0","https://git.kernel.org/stable/c/5db37fd7710e74bc4df48bddab8f571d0bfc6769","https://git.kernel.org/stable/c/6e22d5ad61cfa38aa53fab86a530113aff6a3619","https://git.kernel.org/stable/c/c4ef5ba1131346159e31f4ef858525cf377380a6"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered\n\nThe host1x_client_register() function is called just prior to register map\ninitialization loop, making the device available to userspace. This may\nresult in userspace attempting to submits a job before the register map is\ninitialized. Address this by moving register initialization before host1x\nclient registration.","cvss":[],"epss":[{"cve":"CVE-2026-80883","epss":0.00157,"percentile":0.0518,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80883","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80884","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80884","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ntb: Store original DMA address for future release  The DMA API requires that dma_free_attrs receive the exact dma_handle originally returned by the allocation function. Do not modify it.","cvss":[],"epss":[{"cve":"CVE-2026-80884","epss":0.00158,"percentile":0.05316,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.079},"relatedVulnerabilities":[{"id":"CVE-2026-80884","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80884","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/10662aafce4acd52278c942d0a5b3993594017b9","https://git.kernel.org/stable/c/da6d997ac556479c112554ab5d95cbd04683eb11"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nntb: Store original DMA address for future release\n\nThe DMA API requires that dma_free_attrs receive the exact dma_handle\noriginally returned by the allocation function. Do not modify it.","cvss":[],"epss":[{"cve":"CVE-2026-80884","epss":0.00158,"percentile":0.05316,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80884","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80888","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80888","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/vmwgfx: drop dma_buf reference on foreign-fd prime import  ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's dma_buf->ops do not match the ttm_object_device's ops, but does so without releasing the reference acquired by dma_buf_get().  Any unprivileged renderD client passing a non-vmwgfx prime fd through the DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per call and indefinitely pins the foreign exporter's GEM resources.  Funnel the error path through the existing dma_buf_put() so the reference is always dropped.","cvss":[],"epss":[{"cve":"CVE-2026-80888","epss":0.00173,"percentile":0.06891,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80888","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80888","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/4df39eb99bb47d1f24d1952c23b21b10988356bf","https://git.kernel.org/stable/c/619c3cfa88e09603a13d918f754808db2dda7057","https://git.kernel.org/stable/c/a1e972fa94c3a8069e022c67b9d97c7aa7b05293","https://git.kernel.org/stable/c/a8434b145b1e467940334c58c00af241e9494c5f","https://git.kernel.org/stable/c/c1c22fca0a0896a452a7cb92422d67babd65b4be","https://git.kernel.org/stable/c/f739416dc555fa205a785e5135d73fa39b26f35d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: drop dma_buf reference on foreign-fd prime import\n\nttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's\ndma_buf->ops do not match the ttm_object_device's ops, but does so\nwithout releasing the reference acquired by dma_buf_get().  Any\nunprivileged renderD client passing a non-vmwgfx prime fd through the\nDRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per\ncall and indefinitely pins the foreign exporter's GEM resources.\n\nFunnel the error path through the existing dma_buf_put() so the\nreference is always dropped.","cvss":[],"epss":[{"cve":"CVE-2026-80888","epss":0.00173,"percentile":0.06891,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80888","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80890","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80890","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  sctp: reject stale cookies with mismatched verification tags  sctp_unpack_cookie() skips cookie expiration checks whenever an association already exists.  This is broader than the exception in RFC 9260 Section 5.2.4.  For an existing association, Section 5.2.4 permits an expired State Cookie only when both Verification Tags in the cookie match the current association.  Otherwise, the packet SHOULD be discarded and a Stale Cookie ERROR MUST be sent.  The broad check lets an expired Action A restart cookie reach sctp_sf_do_dupcook_a().  In a runtime test with the default 60 second cookie lifetime, replaying such a cookie after 65 seconds returned a COOKIE-ACK and restarted the association.  Check cookie expiration unless both Verification Tags match.  This preserves the Action D exception for a lost COOKIE ACK while rejecting expired cookies in all other cases.","cvss":[],"epss":[{"cve":"CVE-2026-80890","epss":0.00177,"percentile":0.07395,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.08850000000000001},"relatedVulnerabilities":[{"id":"CVE-2026-80890","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80890","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/35c279113498d19a8734e2aae67b951b9b20f634","https://git.kernel.org/stable/c/61baa5020b0afb41bfd97f8f6ce5e336c4a4546e","https://git.kernel.org/stable/c/817cffdbdbdf50e1f2b016599d1897de3ca54964","https://git.kernel.org/stable/c/9d8da8e0a9bce4a340af60dd0446bc7eb8d07587","https://git.kernel.org/stable/c/a0d1693923f41d6f49083aa2446686aed09d1d79","https://git.kernel.org/stable/c/c151daba0ceb1fb068a215b07de89fb1eb5f87bc","https://git.kernel.org/stable/c/c68557a49e960dbcdede22c7a9b488603078b8b4","https://git.kernel.org/stable/c/f6e3cc296372accad4ee57405195021231ef4bcb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: reject stale cookies with mismatched verification tags\n\nsctp_unpack_cookie() skips cookie expiration checks whenever an\nassociation already exists.  This is broader than the exception in\nRFC 9260 Section 5.2.4.\n\nFor an existing association, Section 5.2.4 permits an expired State\nCookie only when both Verification Tags in the cookie match the current\nassociation.  Otherwise, the packet SHOULD be discarded and a Stale\nCookie ERROR MUST be sent.\n\nThe broad check lets an expired Action A restart cookie reach\nsctp_sf_do_dupcook_a().  In a runtime test with the default 60 second\ncookie lifetime, replaying such a cookie after 65 seconds returned a\nCOOKIE-ACK and restarted the association.\n\nCheck cookie expiration unless both Verification Tags match.  This\npreserves the Action D exception for a lost COOKIE ACK while rejecting\nexpired cookies in all other cases.","cvss":[],"epss":[{"cve":"CVE-2026-80890","epss":0.00177,"percentile":0.07395,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80890","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80891","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80891","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  KVM: s390: pci: Validate AIBV and AISB before pinning guest pages  The AIBV holds one bit per MSI-X vector for a given function. The size of the bit vector is derived from the NOI and the AIBVO. If the size of the AIBV exceeds a single page boundary, then reject the request as we cannot safely pin the guest AIBV.  Similarly reject the request if the AISB address is not 8-byte aligned as the architecture requires doubleword alignment for the summary bit address. Since the AISBO can address up to 64 bits, the size of the AISB can only be 8 bytes for the function. This also ensures the AISB doesn't exceed a single page boundary.","cvss":[],"epss":[{"cve":"CVE-2026-80891","epss":0.00173,"percentile":0.06891,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80891","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80891","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/15df7700dd99f8a37f5c6ed2dcf1e33009cdba47","https://git.kernel.org/stable/c/3a1c64220ede4ac9ef9a3e76f008ff60a34f4c48","https://git.kernel.org/stable/c/868d32ac72cba21c5c6d8a66a814b7c25a3a5c01","https://git.kernel.org/stable/c/b878ba7e28144c9a857bc847d31f3c45413450ac","https://git.kernel.org/stable/c/f00ef8efd41440129ccd88f4a1ebebf8d61d297f","https://git.kernel.org/stable/c/fbfe683f8b1ae7e40b56bdd6daf5bd671bc3a528"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Validate AIBV and AISB before pinning guest pages\n\nThe AIBV holds one bit per MSI-X vector for a given function. The size of\nthe bit vector is derived from the NOI and the AIBVO. If the size of the\nAIBV exceeds a single page boundary, then reject the request as we cannot\nsafely pin the guest AIBV.\n\nSimilarly reject the request if the AISB address is not 8-byte aligned as\nthe architecture requires doubleword alignment for the summary bit address.\nSince the AISBO can address up to 64 bits, the size of the AISB can only be\n8 bytes for the function. This also ensures the AISB doesn't exceed a\nsingle page boundary.","cvss":[],"epss":[{"cve":"CVE-2026-80891","epss":0.00173,"percentile":0.06891,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80891","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80892","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80892","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  erofs: cap LZMA stream pool size  fs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream pool from num_possible_cpus() when the lzma_streams module parameter is unset, then z_erofs_load_lzma_config() preallocates one image-supplied dictionary per stream, accepting dictionaries up to 8 MiB.  On high-CPU systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed decoder state until the erofs module is unloaded.  Impact: An EROFS image mounted by the system can pin up to 8 MiB of vmalloc memory per LZMA stream, either as intended or unexpectedly.  Bound the default stream count by a new CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the worst-case default preallocation is 128 MiB if the number of CPUs is no less than 16 while preserving the existing per-image dictionary limit. An explicit lzma_streams module parameter is still honoured as-is, so administrators who deliberately size the pool are not affected.","cvss":[],"epss":[{"cve":"CVE-2026-80892","epss":0.00173,"percentile":0.0684,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80892","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80892","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0c676903cb2a61992ded8e7907609cc6b0f11744","https://git.kernel.org/stable/c/5aaa06dfc10f8398c8807453dbec738ea9af10e4","https://git.kernel.org/stable/c/682cb3ece37fc5141e73bc726ccf4adb833e5189","https://git.kernel.org/stable/c/c9b47e6b23114e939b17f818471c7a46e59006e7","https://git.kernel.org/stable/c/e52da169b8c0d19bb2d803f2a07fe0e5a00462d6","https://git.kernel.org/stable/c/e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: cap LZMA stream pool size\n\nfs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream\npool from num_possible_cpus() when the lzma_streams module parameter is\nunset, then z_erofs_load_lzma_config() preallocates one image-supplied\ndictionary per stream, accepting dictionaries up to 8 MiB.  On high-CPU\nsystems, a small EROFS image can pin hundreds of MiB of vmalloc-backed\ndecoder state until the erofs module is unloaded.\n\nImpact: An EROFS image mounted by the system can pin up to 8 MiB of\nvmalloc memory per LZMA stream, either as intended or unexpectedly.\n\nBound the default stream count by a new\nCONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the\nworst-case default preallocation is 128 MiB if the number of CPUs is no\nless than 16 while preserving the existing per-image dictionary limit.\nAn explicit lzma_streams module parameter is still honoured as-is, so\nadministrators who deliberately size the pool are not affected.","cvss":[],"epss":[{"cve":"CVE-2026-80892","epss":0.00173,"percentile":0.0684,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80892","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80893","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80893","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()  copy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison entries with huge_pte_clear_uffd_wp(), which operates on the present-PTE bit position.  Swap entries keep the uffd-wp state elsewhere -- the migration branch reads and sets it with pte_swp_uffd_wp() and pte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap payload.  On x86-64 it lands in the inverted swap offset, where a naturally-aligned hugetlb PFN always has the affected bit set, so the clear advances the encoded PFN by two pages.  No userfaultfd needs to be involved: the clear is guarded only by the child VMA not being uffd-wp registered, so a plain fork() with an in-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts the entry copied into the child.  Instrumenting the clear and forking after MADV_HWPOISON on a 2MB anon hugetlb page shows:    offset before=120e00   offset after =120e02  The fallout is mostly latent: rmap walks match migration entries by folio range and remove_migration_pte() rebuilds the PTE from the folio, so a within-folio PFN skew heals once migration completes.  But any path that re-encodes the corrupted offset -- e.g.  hugetlb_change_protection() rewriting a writable migration entry via make_readable_migration_entry(swp_offset(entry)) -- propagates it.  Migration entries legitimately carry uffd-wp, so clear it with pte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and move_huge_pte().  A hwpoison entry, on the other hand, never carries the uffd-wp bit: it is installed fresh by make_hwpoison_entry() (try_to_unmap_one() does not preserve uffd-wp on the hwpoison path) and hugetlb_change_protection() leaves hwpoison entries untouched.  There was nothing to clear there, only the corruption, so drop the clear entirely.","cvss":[],"epss":[{"cve":"CVE-2026-80893","epss":0.00173,"percentile":0.06832,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0865},"relatedVulnerabilities":[{"id":"CVE-2026-80893","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80893","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2b9a07002c2f296aa6a9c591213933d3492e3089","https://git.kernel.org/stable/c/2fa11c60c9c06bafc19cf4d9efdaa36a38079e87","https://git.kernel.org/stable/c/69cb5825d9988c7944bc9f1dc08cb233655405a7","https://git.kernel.org/stable/c/83abe2fd5b3aeb3123b5408a5a91709c5538fb23","https://git.kernel.org/stable/c/8b0de7005b148738d79d6c45594d566489948a68","https://git.kernel.org/stable/c/f1b1311c0352873137768bac5a126e491271a747"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()\n\ncopy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison\nentries with huge_pte_clear_uffd_wp(), which operates on the present-PTE\nbit position.  Swap entries keep the uffd-wp state elsewhere -- the\nmigration branch reads and sets it with pte_swp_uffd_wp() and\npte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap\npayload.  On x86-64 it lands in the inverted swap offset, where a\nnaturally-aligned hugetlb PFN always has the affected bit set, so the\nclear advances the encoded PFN by two pages.\n\nNo userfaultfd needs to be involved: the clear is guarded only by the\nchild VMA not being uffd-wp registered, so a plain fork() with an\nin-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts\nthe entry copied into the child.  Instrumenting the clear and forking\nafter MADV_HWPOISON on a 2MB anon hugetlb page shows:\n\n  offset before=120e00\n  offset after =120e02\n\nThe fallout is mostly latent: rmap walks match migration entries by folio\nrange and remove_migration_pte() rebuilds the PTE from the folio, so a\nwithin-folio PFN skew heals once migration completes.  But any path that\nre-encodes the corrupted offset -- e.g.  hugetlb_change_protection()\nrewriting a writable migration entry via\nmake_readable_migration_entry(swp_offset(entry)) -- propagates it.\n\nMigration entries legitimately carry uffd-wp, so clear it with\npte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and\nmove_huge_pte().\n\nA hwpoison entry, on the other hand, never carries the uffd-wp bit: it is\ninstalled fresh by make_hwpoison_entry() (try_to_unmap_one() does not\npreserve uffd-wp on the hwpoison path) and hugetlb_change_protection()\nleaves hwpoison entries untouched.  There was nothing to clear there, only\nthe corruption, so drop the clear entirely.","cvss":[],"epss":[{"cve":"CVE-2026-80893","epss":0.00173,"percentile":0.06832,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80893","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80901","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80901","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ipvs: fix the checksum validations  ip_vs_in_icmp_v6() is missing checksum validation for ICMPv6 packets from clients. In fact, as for TCP/UDP we should validate the checksum for ICMP packets only when we mangle the packets on MASQ or on reply for tunnel.  Also, Sashiko points out that handle_response_icmp() being common for IPv4 and IPv6 is missing the pseudo-header calculation while validating ICMPv6 messages from real servers which is a problem if checksum is not validated by the hardware.  Fix the problems by creating ip_vs_checksum_common_check() helper and use it for TCP/UDP/ICMP both for IPv4 and IPv6. Rely on the nf_checksum() for validating the ICMP messages but use it also for TCP and UDP.  Use correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP.  IPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum validation on LOCAL_OUT (local clients or local real servers) and on FORWARD (traffic from servers on LAN). Do it only on LOCAL_IN, in case nf_checksum() is not called on PRE_ROUTING.  Also, ip_vs_checksum_complete() can be marked static.","cvss":[],"epss":[{"cve":"CVE-2026-80901","epss":0.00161,"percentile":0.056,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-80901","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80901","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/00eb23829fd08df1b5e057cb6b625996a70e7e65","https://git.kernel.org/stable/c/5558a85add073215b298f3e044ff9a6d86d714ae","https://git.kernel.org/stable/c/9cbe2c0fdb71904ee929b1851cdc1c73341a03c0","https://git.kernel.org/stable/c/b3869d9b54e76dff64118dee4c8fd9302fcd5171","https://git.kernel.org/stable/c/d418d73acf8be62744dc47359dfdde8c2148845d","https://git.kernel.org/stable/c/e876b75b9020a97bbdc79721e7fc749024891c65"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: fix the checksum validations\n\nip_vs_in_icmp_v6() is missing checksum validation for ICMPv6\npackets from clients. In fact, as for TCP/UDP we should\nvalidate the checksum for ICMP packets only when we\nmangle the packets on MASQ or on reply for tunnel.\n\nAlso, Sashiko points out that handle_response_icmp() being\ncommon for IPv4 and IPv6 is missing the pseudo-header\ncalculation while validating ICMPv6 messages from real\nservers which is a problem if checksum is not validated\nby the hardware.\n\nFix the problems by creating ip_vs_checksum_common_check()\nhelper and use it for TCP/UDP/ICMP both for IPv4 and IPv6.\nRely on the nf_checksum() for validating the ICMP messages\nbut use it also for TCP and UDP.\n\nUse correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP.\n\nIPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum\nvalidation on LOCAL_OUT (local clients or local real\nservers) and on FORWARD (traffic from servers on LAN).\nDo it only on LOCAL_IN, in case nf_checksum() is not\ncalled on PRE_ROUTING.\n\nAlso, ip_vs_checksum_complete() can be marked static.","cvss":[],"epss":[{"cve":"CVE-2026-80901","epss":0.00161,"percentile":0.056,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80901","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80902","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80902","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA  When terminating DMA transfers, active descriptors are not properly reclaimed. Only cyclic descriptors were handled, leaving non-cyclic descriptors and their LLI chains to be permanently leaked.  Fix by using vchan_terminate_vdesc() which handles both cyclic and non-cyclic descriptors by adding them to desc_terminated queue for proper cleanup.  Add pchan->desc != pchan->done check to prevent double-adding completed descriptors, which would corrupt the list.","cvss":[],"epss":[{"cve":"CVE-2026-80902","epss":0.00165,"percentile":0.0598,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-80902","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80902","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/004a7a02982bed0a727a4ac7be400f00f353e7a2","https://git.kernel.org/stable/c/1ccc5c059d067c5358682ad5352e7d7e9239ed9b","https://git.kernel.org/stable/c/27806fe7b9701af0963dcd510e30e7d0cc314c43","https://git.kernel.org/stable/c/9086b488f2737d5dcee86852b83f2059f1cdfabf","https://git.kernel.org/stable/c/ab1150115e68a46b687eb38c1ab92782018c9f2c","https://git.kernel.org/stable/c/b150f603083cc8b72b0cbf13ec3e91f85b4390a0","https://git.kernel.org/stable/c/bb87440561eb72b47a2b848b5373b86433b247e6","https://git.kernel.org/stable/c/d4ba6aa65fcd797152d3aebd428a7b2da49cd5eb"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA\n\nWhen terminating DMA transfers, active descriptors are not properly\nreclaimed. Only cyclic descriptors were handled, leaving non-cyclic\ndescriptors and their LLI chains to be permanently leaked.\n\nFix by using vchan_terminate_vdesc() which handles both cyclic and\nnon-cyclic descriptors by adding them to desc_terminated queue for\nproper cleanup.\n\nAdd pchan->desc != pchan->done check to prevent double-adding completed\ndescriptors, which would corrupt the list.","cvss":[],"epss":[{"cve":"CVE-2026-80902","epss":0.00165,"percentile":0.0598,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80902","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80904","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80904","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net/tls: Fail tls_sw_splice_read() after a failed async decrypt  When an async decrypt fails, tls_decrypt_done() records the error in ctx->async_wait.err and calls tls_err_abort(), which stores it in sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read async_wait.err once they hold the reader lock and fail the call: a record that did not authenticate breaks the connection.  tls_sw_splice_read() has no such check, and sk_err does not stand in for one. tls_rx_rec_wait() tests sk_err only inside the loop it skips whenever a record is already parsed, and the first reader to reach sock_error() clears it, while async_wait.err persists. A splice therefore keeps delivering records on a connection that recvmsg() and read_sock() refuse to read.  Read async_wait.err in tls_sw_splice_read() as the other two readers do.","cvss":[],"epss":[{"cve":"CVE-2026-80904","epss":0.00161,"percentile":0.05599,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-80904","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80904","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/06c2a53604fa1dc4820063828d7dadb3675b7af8","https://git.kernel.org/stable/c/18ae1e95f20867106a28820c208a9cec99dda861","https://git.kernel.org/stable/c/4b177911eb9f799e9841c2f87c75b08cb112757a","https://git.kernel.org/stable/c/82d9269f01ebfd835b6256aa17016a974cbbc647","https://git.kernel.org/stable/c/976df67f463db1fddaf2a32fb04f57ad2891a23d","https://git.kernel.org/stable/c/a808aadff634c7a408b2ab84d5919e9a741fdb5b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tls: Fail tls_sw_splice_read() after a failed async decrypt\n\nWhen an async decrypt fails, tls_decrypt_done() records the error in\nctx->async_wait.err and calls tls_err_abort(), which stores it in\nsk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read\nasync_wait.err once they hold the reader lock and fail the call: a\nrecord that did not authenticate breaks the connection.\n\ntls_sw_splice_read() has no such check, and sk_err does not stand in\nfor one. tls_rx_rec_wait() tests sk_err only inside the loop it\nskips whenever a record is already parsed, and the first reader to\nreach sock_error() clears it, while async_wait.err persists. A\nsplice therefore keeps delivering records on a connection that\nrecvmsg() and read_sock() refuse to read.\n\nRead async_wait.err in tls_sw_splice_read() as the other two readers\ndo.","cvss":[],"epss":[{"cve":"CVE-2026-80904","epss":0.00161,"percentile":0.05599,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80904","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80905","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80905","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: tap: fix wrong transport_header when sending VLAN-tagged frame  In tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g. ETH_P_8021Q), skb_set_network_header() is called first to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still set to ETH_P_8021Q, while nhoff (derived from skb_network_offset()) already points past the VLAN tag to the inner protocol header.  In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector hits case ETH_P_8021Q, it reads a struct vlan_hdr at the current nhoff via __skb_header_pointer(), but that offset contains the inner protocol header (e.g. an IP header). The bytes are misinterpreted as a VLAN header, yielding a garbage encapsulated EtherType that matches no known protocol. The dissector returns false, so skb_probe_transport_header() never calls skb_set_transport_header(), leaving transport_header at its uninitialized sentinel value (~0U).  Move skb_set_network_header() to after skb_probe_transport_header(). At the time skb_probe_transport_header() is called, network_header still points to the VLAN header (offset ETH_HLEN), so nhoff is correct and the flow dissector can parse the VLAN header, extract the inner EtherType, and advance nhoff to the inner protocol header, allowing transport_header to be set correctly.","cvss":[],"epss":[{"cve":"CVE-2026-80905","epss":0.00155,"percentile":0.04925,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.0775},"relatedVulnerabilities":[{"id":"CVE-2026-80905","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80905","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/5ffaa5d7f56ab24a8e23cf131eadfef31a3bbc4b","https://git.kernel.org/stable/c/88b79ac89ecc04d7f2613f7e1c0b46f0c4ddb2f3","https://git.kernel.org/stable/c/cbb35cbe8db268fefe34c23df15348cf99025298"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tap: fix wrong transport_header when sending VLAN-tagged frame\n\nIn tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g.\nETH_P_8021Q), skb_set_network_header() is called first to advance\nnetwork_header past the VLAN tag to the inner protocol header.\nskb_probe_transport_header() is then called with skb->protocol still\nset to ETH_P_8021Q, while nhoff (derived from skb_network_offset())\nalready points past the VLAN tag to the inner protocol header.\n\nIn __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff\npoints past the VLAN tag. When the dissector hits case ETH_P_8021Q, it\nreads a struct vlan_hdr at the current nhoff via __skb_header_pointer(),\nbut that offset contains the inner protocol header (e.g. an IP header).\nThe bytes are misinterpreted as a VLAN header, yielding a garbage\nencapsulated EtherType that matches no known protocol. The dissector\nreturns false, so skb_probe_transport_header() never calls\nskb_set_transport_header(), leaving transport_header at its uninitialized\nsentinel value (~0U).\n\nMove skb_set_network_header() to after skb_probe_transport_header(). At\nthe time skb_probe_transport_header() is called, network_header still\npoints to the VLAN header (offset ETH_HLEN), so nhoff is correct and the\nflow dissector can parse the VLAN header, extract the inner EtherType,\nand advance nhoff to the inner protocol header, allowing transport_header\nto be set correctly.","cvss":[],"epss":[{"cve":"CVE-2026-80905","epss":0.00155,"percentile":0.04925,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80905","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80906","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80906","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  net: packet: fix wrong transport_header when sending VLAN-tagged frame  In packet_parse_headers(), when processing a VLAN-tagged frame, skb_set_network_header() is called to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still set to the outer VLAN EtherType (e.g. ETH_P_8021Q), while nhoff (derived from skb_network_offset()) already points past the VLAN tag to the inner protocol header.  In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector hits case ETH_P_8021Q, it reads a struct vlan_hdr at nhoff via __skb_header_pointer(), but that offset contains the inner protocol header (e.g. an IP header). The bytes are misinterpreted as a VLAN header, yielding a garbage encapsulated EtherType that matches no known protocol. The dissector returns false, so skb_probe_transport_header() never calls skb_set_transport_header(), leaving transport_header at its uninitialized sentinel value (~0U).  Move skb_probe_transport_header() to before skb_set_network_header(). At the time skb_probe_transport_header() is called, network_header still points to the VLAN header, so nhoff correctly points to the VLAN header. The flow dissector can then parse the VLAN header, extract the inner EtherType, and advance nhoff to the inner protocol header, allowing transport_header to be set correctly.","cvss":[],"epss":[{"cve":"CVE-2026-80906","epss":0.00165,"percentile":0.05979,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-80906","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80906","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/01fdecc0480d916c799dbee584833a4a37e94d06","https://git.kernel.org/stable/c/5479eb9b355f44745d7ccfe112386bd4f96eceea","https://git.kernel.org/stable/c/6386a6ffa2efba2965ed8e4fa303582c0b76a215","https://git.kernel.org/stable/c/6971cf319263d6a1b4096f9248aca9e57d77a1eb","https://git.kernel.org/stable/c/a4b82de96d465ddb44bc931145c0fa80c4fe9c9c","https://git.kernel.org/stable/c/e451e20adb869a983a21dda158625f024142e61f","https://git.kernel.org/stable/c/f9297abbcaba760b7a7b9d63b839f607f738013e","https://git.kernel.org/stable/c/fa86bc52ea8ba981f74f851fd61e2a3d3bc0feac"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: packet: fix wrong transport_header when sending VLAN-tagged frame\n\nIn packet_parse_headers(), when processing a VLAN-tagged frame,\nskb_set_network_header() is called to advance network_header past the\nVLAN tag to the inner protocol header. skb_probe_transport_header() is\nthen called with skb->protocol still set to the outer VLAN EtherType\n(e.g. ETH_P_8021Q), while nhoff (derived from skb_network_offset())\nalready points past the VLAN tag to the inner protocol header.\n\nIn __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff\npoints past the VLAN tag. When the dissector hits case ETH_P_8021Q, it\nreads a struct vlan_hdr at nhoff via __skb_header_pointer(), but that\noffset contains the inner protocol header (e.g. an IP header). The bytes\nare misinterpreted as a VLAN header, yielding a garbage encapsulated\nEtherType that matches no known protocol. The dissector returns false,\nso skb_probe_transport_header() never calls skb_set_transport_header(),\nleaving transport_header at its uninitialized sentinel value (~0U).\n\nMove skb_probe_transport_header() to before skb_set_network_header(). At\nthe time skb_probe_transport_header() is called, network_header still\npoints to the VLAN header, so nhoff correctly points to the VLAN header.\nThe flow dissector can then parse the VLAN header, extract the inner\nEtherType, and advance nhoff to the inner protocol header, allowing\ntransport_header to be set correctly.","cvss":[],"epss":[{"cve":"CVE-2026-80906","epss":0.00165,"percentile":0.05979,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80906","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80907","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80907","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Fix UVD dpb min size calculation for H264  This should use actual number of references from the decode message, instead of maximum derived from level.  (cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)","cvss":[],"epss":[{"cve":"CVE-2026-80907","epss":0.00156,"percentile":0.05133,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.078},"relatedVulnerabilities":[{"id":"CVE-2026-80907","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80907","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/21a8084cd76223a13493237e04d45f5226d7cee6","https://git.kernel.org/stable/c/33f4ef585368fe93523dca1e5440e006f6e5146e","https://git.kernel.org/stable/c/38914cb2c6afb5fe00241ea3438e655822196378","https://git.kernel.org/stable/c/fa96c24485942e277483cc70d9551d9e0111d7c5","https://git.kernel.org/stable/c/ff4361816b6ba4bd29b548b17d993056a1ae2502"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix UVD dpb min size calculation for H264\n\nThis should use actual number of references from the decode\nmessage, instead of maximum derived from level.\n\n(cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)","cvss":[],"epss":[{"cve":"CVE-2026-80907","epss":0.00156,"percentile":0.05133,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80907","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80908","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80908","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Reject UVD message with dimensions above 4096  Fixes potential overflow in DPB size calculations.  (cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)","cvss":[],"epss":[{"cve":"CVE-2026-80908","epss":0.00165,"percentile":0.05981,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-80908","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80908","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/17fbb996c05f2190e0fa20927ca0b9804d481b02","https://git.kernel.org/stable/c/339deb76ee4859ea973e435c9a9a4a4fefc29338","https://git.kernel.org/stable/c/382bef781ff441ce8055bdada57b8c291dc0fd30","https://git.kernel.org/stable/c/8435d41afcf2bc31ecee213ef651c12bd1a16d38","https://git.kernel.org/stable/c/8bae80eaed00e7ae28412a3cdf590f4beca72294","https://git.kernel.org/stable/c/8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08","https://git.kernel.org/stable/c/9adc5e25f31d7ee7dfc18814499b6e3a6d402904","https://git.kernel.org/stable/c/f7af372d3b892b95dd3cd1c6acf29daa39ba076d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with dimensions above 4096\n\nFixes potential overflow in DPB size calculations.\n\n(cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)","cvss":[],"epss":[{"cve":"CVE-2026-80908","epss":0.00165,"percentile":0.05981,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80908","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80909","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80909","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Reject UVD message with invalid number of h265 refs  Same change as for h264, avoids overflow later when calculating min dpb size.  (cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)","cvss":[],"epss":[{"cve":"CVE-2026-80909","epss":0.00165,"percentile":0.0598,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-80909","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80909","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/0acdf1a575f59bd46717d5c487d84575af5bee8f","https://git.kernel.org/stable/c/1facad2a78c1a8aeecc36eb4d560c7f1e10ce198","https://git.kernel.org/stable/c/2abcdc5f738574e7fcdd9417575dffb877fdc26f","https://git.kernel.org/stable/c/499907e5d46e575e96967c0230a0a6af980a17ab","https://git.kernel.org/stable/c/9fca434208f1f9ab977feac62df8ebb1cc7ce893","https://git.kernel.org/stable/c/a930c54cb67200de8bc0de87480d09ece7dcd85d","https://git.kernel.org/stable/c/cbf1c84bf5cac2b3742ea3d2085fa713424465cc","https://git.kernel.org/stable/c/e304c3e0d9ce251887be1f274aa0ed52219d5fd7"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with invalid number of h265 refs\n\nSame change as for h264, avoids overflow later when calculating\nmin dpb size.\n\n(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)","cvss":[],"epss":[{"cve":"CVE-2026-80909","epss":0.00165,"percentile":0.0598,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80909","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80910","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80910","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses  EAR SPKR PA Gain\" and the four \"WSA RX* Mux\" controls are enumerated, but their get and put callbacks access the value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int).  This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 (\"ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type\") and commit 0ea5eff7c606 (\"ASoC: codecs: va-macro: fix accessing array out of bounds for enum type\"), but wsa-macro was missed.  On 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value sanity check and every read of these controls fails with -EINVAL.","cvss":[],"epss":[{"cve":"CVE-2026-80910","epss":0.00161,"percentile":0.056,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0805},"relatedVulnerabilities":[{"id":"CVE-2026-80910","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80910","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/2fe7a89b2b5b73be35c1e493d0246314ba54e427","https://git.kernel.org/stable/c/4bcac4bf304a3ec746192e49a669c236aaf27dbf","https://git.kernel.org/stable/c/524aa7b9954b0a43dd13f71ecbbac52a151c326d","https://git.kernel.org/stable/c/56f24311fd5607588a47e44675195a9efb200f29","https://git.kernel.org/stable/c/7bcdde412e6c744f6135e02b12a735e2e37b639f","https://git.kernel.org/stable/c/891129df5de79cd533ae335c6eab24df2ff2b0fd","https://git.kernel.org/stable/c/bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses\n\nEAR SPKR PA Gain\" and the four \"WSA RX* Mux\" controls are enumerated,\nbut their get and put callbacks access the value through\nucontrol->value.integer.value[0] (a long) instead of\nucontrol->value.enumerated.item[0] (an unsigned int).\n\nThis same pattern was fixed in the sibling drivers by\ncommit bcfe5f76cc40 (\"ASoC: codecs: rx-macro: fix accessing array\nout of bounds for enum type\") and\ncommit 0ea5eff7c606 (\"ASoC: codecs: va-macro: fix accessing array\nout of bounds for enum type\"), but wsa-macro was missed.\n\nOn 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value\nsanity check and every read of these controls fails with -EINVAL.","cvss":[],"epss":[{"cve":"CVE-2026-80910","epss":0.00161,"percentile":0.056,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80910","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80912","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80912","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: reject an unclaimed class value in security_get_classes()  security_get_classes() sizes an array by p_classes.nprim and fills it at value - 1, so a class value the policy never defines leaves a NULL. sel_make_classes() passes every entry to sel_make_dir(), reaching the same d_alloc_name() dereference as the permission array. The class symbol table is allowed to be sparse (policydb_class_isvalid() exists to absorb that), but this getter builds its own array straight from the hash table and has no such predicate.  Fail the lookup when a value went unclaimed instead of handing out the NULL. Conforming policies define every class they declare and are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80912","epss":0.00156,"percentile":0.05133,"date":"2026-09-09"}],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0.078},"relatedVulnerabilities":[{"id":"CVE-2026-80912","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80912","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/099869e9343a5f8c22b58497f074b34f63cbf856","https://git.kernel.org/stable/c/22b05fec62c0fe9864cfceb52f7d0f3a34d9b1dd","https://git.kernel.org/stable/c/841aea4d5a25e16273d04cd07a74142b4687e03b","https://git.kernel.org/stable/c/d8a10899ea3c84b80de72ca8ee9039e9a5156c9a","https://git.kernel.org/stable/c/e0285bb152211c00900136b66d4b420c14a59094"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: reject an unclaimed class value in security_get_classes()\n\nsecurity_get_classes() sizes an array by p_classes.nprim and fills it at\nvalue - 1, so a class value the policy never defines leaves a NULL.\nsel_make_classes() passes every entry to sel_make_dir(), reaching the same\nd_alloc_name() dereference as the permission array. The class symbol table\nis allowed to be sparse (policydb_class_isvalid() exists to absorb that),\nbut this getter builds its own array straight from the hash table and has\nno such predicate.\n\nFail the lookup when a value went unclaimed instead of handing out the\nNULL. Conforming policies define every class they declare and are\nunaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80912","epss":0.00156,"percentile":0.05133,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80912","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80913","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80913","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"description":"In the Linux kernel, the following vulnerability has been resolved:  selinux: require every boolean value to be defined  p_bools.nprim comes from the policy image independently of how many booleans follow it, and cond_index_bool() fills bool_val_to_struct[] at value - 1, so a count larger than the values present leaves NULL entries. Every user of that array then walks it by index and dereferences each entry: cond_evaluate_expr() on the access-vector path, security_get_bools() and security_get_bool_value() behind selinuxfs, and security_set_bools(). A sparse class value is absorbed by policydb_class_isvalid() and its siblings; booleans have no such predicate, and no consumer that could use one.  Reject a boolean value that no boolean defines, once, where the array is built. Conforming policies define every boolean they declare and are unaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80913","epss":0.00165,"percentile":0.05977,"date":"2026-09-09"}],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-09","kind":"first-observed"}]},"advisories":[],"risk":0.0825},"relatedVulnerabilities":[{"id":"CVE-2026-80913","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80913","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/3161daa3f1e3ca68f8b2b8fa01720b5a8dcc6b40","https://git.kernel.org/stable/c/3938c8494d3c5d84a53fd7d1966ae9dde46cb5f8","https://git.kernel.org/stable/c/42a7107f99d86a7524c37f108047dfa3db096ab5","https://git.kernel.org/stable/c/4d0ece18e648bd4362704fd087249ac697f2b7fb","https://git.kernel.org/stable/c/4dfb997c60f7951011d3dcbee926e3a7f80d8a76","https://git.kernel.org/stable/c/740012aebdb8311332bf66e2aabf453ba73c2c45","https://git.kernel.org/stable/c/a93d37a09b863810653f93d371fb197457d59deb","https://git.kernel.org/stable/c/ed901e88aa3fb3d5d7b0b52c2ee3073209df9bec"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: require every boolean value to be defined\n\np_bools.nprim comes from the policy image independently of how many\nbooleans follow it, and cond_index_bool() fills bool_val_to_struct[] at\nvalue - 1, so a count larger than the values present leaves NULL entries.\nEvery user of that array then walks it by index and dereferences each\nentry: cond_evaluate_expr() on the access-vector path,\nsecurity_get_bools() and security_get_bool_value() behind selinuxfs, and\nsecurity_set_bools(). A sparse class value is absorbed by\npolicydb_class_isvalid() and its siblings; booleans have no such\npredicate, and no consumer that could use one.\n\nReject a boolean value that no boolean defines, once, where the array is\nbuilt. Conforming policies define every boolean they declare and are\nunaffected.","cvss":[],"epss":[{"cve":"CVE-2026-80913","epss":0.00165,"percentile":0.05977,"date":"2026-09-09"}]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80913","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80914","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80914","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80914","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80914","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/03288b7447c9e572f8ab82fc29cfb4ca719ab210","https://git.kernel.org/stable/c/2387cd06a2c0b416f05028b02bba1089f54c28d9","https://git.kernel.org/stable/c/49fd7116f76b860b230843700fb7423ab5331e1f","https://git.kernel.org/stable/c/560bef609fa5992745929e8d7d458b9d88dd2830"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready\n\niso_conn_ready() looks up the BIS listener socket with iso_get_sock(),\nwhich takes a reference, and then, without re-checking its state,\ncreates a child socket from it:\n\n    parent = iso_get_sock(hdev, ...);\n    if (!parent)\n        return;\n\n    lock_sock(parent);\n    sk = iso_sock_alloc(sock_net(parent), NULL, BTPROTO_ISO, ...);\n    ...\n    iso_chan_add(conn, sk, parent);\n    ...\n    release_sock(parent);\n    sock_put(parent);\n\nIf the listener socket is closed concurrently, between iso_get_sock()\nand lock_sock(), the reference taken by iso_get_sock() may be the last\none: the close path drops the link-list reference, and once\niso_conn_ready() drops its own reference at the end of the function the\nsocket is freed.  The child socket, however, is already linked to the\nfreed parent, and a later disconnect of the child runs iso_chan_del()\n-> bt_accept_unlink(), which dereferences the dangling parent pointer\ninto the freed accept queue (a use-after-free).  The same dangling\npointer is also dereferenced through parent->***() in\niso_chan_del().\n\nFix it the same way the connected (non-BIS) path was fixed in commit\n0d255e63fcf3 (\"Bluetooth: ISO: hold sk properly in iso_conn_ready\"):\nafter taking the socket lock, re-check that the parent is still a\nlistening, alive socket, and bail out otherwise.","cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80914","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80916","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80916","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-10","kind":"first-observed"}]},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80916","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80916","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/18799e858b407bf355383c9dd6c06477aa437134","https://git.kernel.org/stable/c/22670d1552fe155822b2abf91f920925f7d067b4","https://git.kernel.org/stable/c/2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c","https://git.kernel.org/stable/c/5dc59fc959b2b5742985d7ef24bccd1868217dc2","https://git.kernel.org/stable/c/8ed3ddf23d39bf5338406bd9f8863d44748cf6ce","https://git.kernel.org/stable/c/a2fb8222cde23b0001812ed3acb7c0ea36dd94e2","https://git.kernel.org/stable/c/e11f5b48c82703242a3be7a7ae4b4940b4cb4610","https://git.kernel.org/stable/c/ef7048d8a614c5f5a9b20513a5428101a744514e","https://git.kernel.org/stable/c/f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nkcov: fix data corruption and race conditions on PREEMPT_RT\n\nsyzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the\ntemporary storage used for saving/restoring remote KCOV state is currently\nallocated as the per-CPU area.\n\nOn PREEMPT_RT kernels, softirq handlers run as preemptible task threads\n(e.g., ksoftirqd). If a softirq context preempts a task running a remote\nKCOV session, it safely saves the task's state into the per-CPU area.\nHowever, if that softirq thread is subsequently preempted by a higher-\npriority softirq thread on the same CPU, the second softirq will overwrite\nthe same per-CPU area, permanently destroying the original task's KCOV\nstate.\n\nFix this data corruption by moving the temporary storage from the per-CPU\narea to the per-thread area. Since each softirq thread now owns its own\ntask context, nested softirq preemption no longer causes data overwrites.\n\nNote that while the temporary storage is now on a per-thread basis, the\nper-CPU kcov_percpu_data.lock must be retained, for we need to ensure that\nkcov_remote_start() and kcov_remote_stop() operate atomically without\nracing against asynchronous interrupts that manipulate the current task's\nKCOV state.\n\nIt is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init()\nhas already called panic() before returning NULL, for there will be no\nOOM-killable userspace processes when __init function of built-in module\nruns. But this patch also fixes crashing the kernel when vmalloc_node()\nin kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL\nbut kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in\n\n  (1) doing vmalloc() in kcov_remote_start() despite !in_task() context\n\n  (2) out-of-array-bounds access if (1) succeeded but\n      kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE\n\n  (3) always leak memory allocated by (1), eventually killing all\n      OOM-killable userspace processes\n\nproblems.","cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80916","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80917","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80917","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-10","kind":"first-observed"}]},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80917","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80917","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/008cb88edb41f3c7c8e0ed763ff9f26719830984","https://git.kernel.org/stable/c/0916948026f623844acd08888f7cbedbf1c48d6b","https://git.kernel.org/stable/c/0c55707bd5d0d7670704cfd0dda933809b052f67","https://git.kernel.org/stable/c/5e52eb0290f66ba0732956dcb1e365b5ca3c5108","https://git.kernel.org/stable/c/74456843f18ba7f3045974d7e8b88ab993152b8c","https://git.kernel.org/stable/c/8d08713ec83a18526d1ed1fd5f0d2b901d103a10","https://git.kernel.org/stable/c/a199293f3038db8d31d47aa60f1e18272cd82354","https://git.kernel.org/stable/c/baf9b0383ff770fdff123d3a832f3a99641d96dd"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems\n\nOn 32-bit systems the config space is too large to ioremap in one go, so\npci_ecam_create() maps each bus segment separately and relies on the\n->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in\ncfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for\nevery config access.\n\nThe generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus\nand ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c\ndo not. As a result, on a 32-bit host using \"pci-host-cam-generic\" the\nper-bus mapping is never set up and the first config read dereferences a\nNULL base, crashing during bus enumeration:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000800\n Oops [#1]\n CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43\n Hardware name: Digilent Nexys-Video-A7 RV32 (DT)\n epc : pci_generic_config_read+0x40/0xb0\n  ra : pci_generic_config_read+0x2c/0xb0\n [<c038db9c>] pci_generic_config_read+0x40/0xb0\n [<c038da04>] pci_bus_read_config_dword+0x50/0xb0\n [<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec\n [<c039245c>] pci_scan_single_device+0xa4/0x11c\n [<c0392570>] pci_scan_slot+0x9c/0x23c\n [<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4\n [<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8\n [<c0393e54>] pci_host_probe+0x20/0xc8\n [<c03bc6f4>] pci_host_common_probe+0x144/0x1e4\n\nFix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks.\nSince pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c,\nmove the CAM ops definition there as pci_generic_cam_ops (mirroring\npci_generic_ecam_ops) and export it for pci-host-generic.c to reference.\n\n[mani: removed timestamp from log]","cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80917","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80918","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80918","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-10","kind":"first-observed"}]},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80918","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80918","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/1fa1591efd417e39e5e164bebea8ca7a3837c469","https://git.kernel.org/stable/c/28abce951343fcec26e397610868efa4e1395c3f","https://git.kernel.org/stable/c/634f498ea5d5e8e01f8d9414d4f45eeaf9ee1996","https://git.kernel.org/stable/c/abec577de5fc16cd5caae42f97cdcd0983c06d66","https://git.kernel.org/stable/c/aec2c2ec87d4ec1f098979f68cd81b29f031c8cb","https://git.kernel.org/stable/c/bed7fe3a936b6bdd84671385951397ca673cf6e7","https://git.kernel.org/stable/c/dd8035dec26e98204d6e4a6e0cee5c4d329b3d7e","https://git.kernel.org/stable/c/e542edada3f79387c0ac2a528cebf01f4ef47df8","https://git.kernel.org/stable/c/e60159f5ea60254a5c3de4ea4f2f939f0171031b"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: fix number/pointer type confusion on long items\n\nWhen fetch_item() is called by hid_scan_report() on an item with\nHID_ITEM_TAG_LONG, it stores a pointer to the item data in\nitem->data.longdata instead of storing a value directly in\nitem->data.{u8/u16/u32}.\n\nWhen item_udata() or item_sdata() encounters such an item, it incorrectly\nassumes that the item is in short format, and therefore returns the lower\npart of a kernel pointer reinterpreted as a number.\n\nWhen a HID device is connected whose descriptor contains a\nHID_GLOBAL_ITEM_TAG_REPORT_SIZE encoded in long format with size=4, this\ncauses the lower half of a kernel pointer to be printed into dmesg as a\nnumber, like this:\n\n    hid (null): invalid report_size 107953555\n\nTo fix it, let item_udata() and item_sdata() verify that the item is in\nshort format.\n\nNote that this bug only affects hid_scan_report(), while the main parsing\npass hid_parse_collections() will always bail out when encountering a long\nitem.\n\nSidenote: There are currently no users of data.longdata; maybe we should\njust remove any parsing of long-format descriptors as a follow-up.","cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80918","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80920","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80920","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80920","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80920","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/40b6ccf68731809ceb85c6e9f0f8f2ed61c7aa5a","https://git.kernel.org/stable/c/b6bb334b0e9348887e3e55e1f494b0c3b8fbf59f","https://git.kernel.org/stable/c/cd305ee3633a45fcf5f3a5d83f99f3cb77d87b6e","https://git.kernel.org/stable/c/e22f4494cc9487d326e5e3067f33dea7c1e442b2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: defer eventfd signaling when queued from a wakeup handler\n\nio_req_local_work_add() signals the CQ ring eventfd inline when it is the\none to push the first entry onto ->work_list. For DEFER_TASKRUN rings that\nadd is frequently done from a waitqueue wakeup handler, where an\narbitrary waitqueue lock is held.\n\neventfd_signal_mask() only refuses to recurse when current->in_eventfd\nis set, but that bit is set by eventfd_signal_mask() itself. If the wake\nchain starts somewhere else, signal goes out inline and can feed back\ninto epoll.\n\nAdd IOU_F_TWQ_IN_WAKE, set it on the task_work add done from the three\nwaitqueue callbacks, and use it to force io_eventfd_signal() down the\nexisting call_rcu_hurry() deferral instead of signaling inline.","cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80920","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80921","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80921","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-10","kind":"first-observed"}]},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80921","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80921","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/087c19cc60a8caa1a08e1e434c8be2caf6c27733","https://git.kernel.org/stable/c/29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6","https://git.kernel.org/stable/c/34d5b5b646c91cfb9338d7a12c955a70ffb8c66b","https://git.kernel.org/stable/c/59d51550b5cb916bda037673a721a404b3b47a0d","https://git.kernel.org/stable/c/7d23489f51109e3ebba5b5db8c5f0185af7b7fdf","https://git.kernel.org/stable/c/935eeba276012916c76243e5cbb843efd8fdb75d","https://git.kernel.org/stable/c/d110b3297f11ef227098b8a82ade2d5f123b7d2f","https://git.kernel.org/stable/c/d4bcd2df6d0d2af916b4fe1a533958778ea7c45b","https://git.kernel.org/stable/c/f6079dca67eccb5eabef9f72437948c66dc5131f"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: vsie: zero stale crypto bits\n\nWhen shadowing crypto access bits from a format0 apcb (crycb 0 or 1),\nthe bits 64..255 are unchanged from whatever is in the vsie page in the\ncrycb and thus in the apcb. This gives a nested guest potential access\nto a device no longer available. Zero out the remaining bits.","cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80921","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80923","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80923","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":["6.1.187-1"],"state":"fixed","available":[{"version":"6.1.187-1","date":"2026-09-10","kind":"first-observed"}]},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80923","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80923","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/01b7bc0938061f2fd46e0094f6483d8c6c02f7d3","https://git.kernel.org/stable/c/0d0faf3cc44c4d86fc6faf5cea972c0fbe00b922","https://git.kernel.org/stable/c/0e469b94fbba8eb03666da41dd1082b793c50c1a","https://git.kernel.org/stable/c/33ed35ca629477f57e0dd1d77d6df96cf5a9eb55","https://git.kernel.org/stable/c/43635ff6401ca0e0ed21875379eeded921321525","https://git.kernel.org/stable/c/943f976c93e70563b132f5585ff68b08c89641a2","https://git.kernel.org/stable/c/a916fa66a43e10f63198b6ce978badffc678821a","https://git.kernel.org/stable/c/eaca2814f32b9872a332326324b9e83e01f156d2"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: dbgtty: Fix unregister on tty_register_driver() failure\n\nIf tty_register_driver() fails, it drops the reference, but fails to set\nthe global dbc_tty_driver to NULL, causing the unregister to be called\nagain when module exits.\n\nOn module unload dbc_tty_exit() only gates its cleanup on the driver\npointer being non-NULL, so it operates on the already-freed driver:\n\n    module_init(xhci_hcd_init)\n      xhci_hcd_init()\n        xhci_dbc_init()                       [return value ignored]\n          dbc_tty_init()\n            tty_register_driver() fails\n              tty_driver_kref_put()           -> driver freed\n              (dbc_tty_driver left dangling)\n    ...\n    module_exit(xhci_hcd_fini)\n      xhci_hcd_fini()\n        xhci_dbc_exit()\n          dbc_tty_exit()\n            if (dbc_tty_driver)               -> true (dangling)\n              tty_unregister_driver()         -> use-after-free","cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80923","versionConstraint":"< 6.1.187-1 (deb)"},"fix":{"suggestedVersion":"6.1.187-1"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]},{"vulnerability":{"id":"CVE-2026-80925","dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80925","namespace":"debian:distro:debian:12","severity":"Unknown","urls":[],"cvss":[],"fix":{"versions":[],"state":"not-fixed"},"advisories":[],"risk":0},"relatedVulnerabilities":[{"id":"CVE-2026-80925","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80925","namespace":"nvd:cpe","severity":"Unknown","urls":["https://git.kernel.org/stable/c/447cbe95ebb95392b5d8f6a01c0556826919ce23","https://git.kernel.org/stable/c/a29f3b884ba50217e6f50414f568073221e2bb07"],"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvlan: fix skb_under_panic and races when toggling HW VLAN offload\n\nToggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or\nNETIF_F_HW_VLAN_STAG_TX) on a lower device invokes vlan_transfer_features(),\nwhich dynamically changed vlandev->hard_header_len.\n\nThis causes two issues:\n1. Lockless TX paths (e.g. packet_snd in af_packet.c, ip6_finish_output2)\n   read dev->hard_header_len without holding RTNL lock. Mutating\n   hard_header_len dynamically under RTNL creates a data race where upper\n   layers reserve insufficient headroom based on a stale hard_header_len,\n   resulting in skb_under_panic when vlan_dev_hard_header() is called.\n2. In addition, vlan_transfer_features() updated hard_header_len without\n   updating header_ops, causing a mismatch between allocated headroom\n   and header creation.\n\nAlways setting dev->hard_header_len = real_dev->hard_header_len and\ndev->needed_headroom = real_dev->needed_headroom + VLAN_HLEN unconditionally\nensures:\n- dev->hard_header_len remains 100% static and immutable at real_dev->hard_header_len,\n  eliminating all dynamic runtime updates and data races on hard_header_len.\n- Upper layers allocating skbs via LL_RESERVED_SPACE() will always reserve\n  sufficient headroom for software VLAN tag insertion (real_dev->hard_header_len +\n  real_dev->needed_headroom + VLAN_HLEN).\n- vlandev inherits real_dev->needed_tailroom so underlying trailer/padding/ICV\n  requirements are honored.\n- AF_PACKET SOCK_RAW network header offsets remain correctly aligned at\n  real_dev->hard_header_len.\n- vlan_header_ops is used unconditionally.\n\nNote to stable teams: Make sure to backport these commits:\n\ne16e960d55a4 (\"ipvlan: inherit needed_headroom and needed_tailroom from phy_dev\")\ncef51860becd (\"macvlan: inherit needed_headroom and needed_tailroom from lowerdev\")","cvss":[]}],"matchDetails":[{"type":"exact-indirect-match","matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"linux","version":"6.1.180-1"},"namespace":"debian:distro:debian:12"},"found":{"vulnerabilityID":"CVE-2026-80925","versionConstraint":"none (unknown)"}}],"artifact":{"id":"2b3ee8a4318509d3","name":"linux-libc-dev","version":"6.1.180-1","type":"deb","locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/linux-libc-dev/copyright","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/usr/share/doc/linux-libc-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","layerID":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","accessPath":"/var/lib/dpkg/info/linux-libc-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"language":"","licenses":["BSD-2-clause","CRYPTOGAMS","GPL-2","GPL-2+-or-X11","LGPL-2.1","Unicode-data","Xen-interface"],"cpes":["cpe:2.3:a:linux-libc-dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc-dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc_dev:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux-libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux_libc:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux-libc-dev:6.1.180-1:*:*:*:*:*:*:*","cpe:2.3:a:linux:linux_libc_dev:6.1.180-1:*:*:*:*:*:*:*"],"purl":"pkg:deb/debian/linux-libc-dev@6.1.180-1?arch=amd64&distro=debian-12.15&upstream=linux","upstreams":[{"name":"linux"}]},"appliedIgnoreRules":[{"namespace":"","package":{"name":"linux-libc-dev","language":"","type":"deb","upstream-name":"linux"},"match-type":"exact-indirect-match"}]}],"source":{"type":"image","target":{"userInput":"/work/acb/my-devsecops/images/zap-stable-amd64.tar","imageID":"sha256:6175579a46d477338e4b641dd9c3428936f30c3719809e2f4d36f58e60c4ddb7","manifestDigest":"sha256:4084d8fcdd5ed4ab85c39608bf1d1e2a40abcd1b5bb2bb580f9c483c1b243074","mediaType":"application/vnd.docker.distribution.manifest.v2+json","tags":["localhost/devsecops/zap:20260909"],"imageSize":2399673201,"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:66462cc862fe2053b9863fefa3866e07bb5dfb06f6b3ce3177cc096e4021aabe","size":74822940},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:5bc5025d406e110f09df4be1a0a3bf33d26cb09930a632d379efc6b59414b35b","size":1585651513},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:fe8089058c94f258d01622d874af7230097c5f461e77528c2370064a911f0387","size":158779068},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:f805cd11ec202e59f10847286c03c66d2d3dd422c429ce2c1eeafeb9de3797df","size":9847},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:1bc8afe96b01e8ffabf9181e902c85c9d9d9f1069844666686d508ca31cda7f5","size":659},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:4bc13aaf2851f2fb571123a070ee19c8e17ee59ee2684871efbd7f5a65607aa9","size":0},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef","size":0},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:98a80e7989feee3b5627a2cd8ff540a47e93998194f95a460c746603247bfe69","size":0},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:9204caafeef8d11d4d3f33f4d8011a7ee63405c8bf8d2fba764a08c1dd5accc1","size":536348993},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:4bc3103ed06a7cd48d18cca2adab792a5cbcb44a1f444e27878af911da55cd7a","size":43917854},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:ad5206cdaf5cf267a0c7dda5a8e372096ec100ced3acb64d129ecbfe439f9e75","size":114653},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:4c9c9901512ede5d22c37d57215e23f22dcda91b6a9d92468ed63aa28d47bbb3","size":1811},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:b5484b50331ead49baf00e66b6e555279df533cf4a334f421ba0c4700f0f44d6","size":127},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:e1860ee3ef1e4c424196b8651bbf7d9b5fd8c1605acef31eb1875ffa896e6d4c","size":4807},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:0465997d731650442647422badbb1e016fb34e98b023709e14d3f71a924d50b3","size":4807},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:1914ba4149fca86a337ca4de4aae9daaa4a758ac5914e684ee27df17b21a6ae9","size":7799},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:2128195dab6c9bdbc304bc1182e5c7c5c49b8ae756f5a0aa7c0e68f590ed5c35","size":39},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:2f00e47b70ef647dbdbe8df72649e185ac912ca4f6ec2c393b76e49bae98115c","size":182},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:654a5aeebb11096cc7fdd49e84a5a2a8488fc8a5c3212359953f9d584bffe3e4","size":57},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","digest":"sha256:5931495998f4941ccd8ea551f588dfcb2b2136290f7f37f3992860a646729ce5","size":8045}],"manifest":"eyJzY2hlbWFWZXJzaW9uIjoyLCJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmRpc3RyaWJ1dGlvbi5tYW5pZmVzdC52Mitqc29uIiwiY29uZmlnIjp7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuY29udGFpbmVyLmltYWdlLnYxK2pzb24iLCJzaXplIjo5NzQ2LCJkaWdlc3QiOiJzaGEyNTY6NjE3NTU3OWE0NmQ0NzczMzhlNGI2NDFkZDljMzQyODkzNmYzMGMzNzE5ODA5ZTJmNGQzNmY1OGU2MGM0ZGRiNyJ9LCJsYXllcnMiOlt7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjo3Nzg5NTY4MCwiZGlnZXN0Ijoic2hhMjU2OjY2NDYyY2M4NjJmZTIwNTNiOTg2M2ZlZmEzODY2ZTA3YmI1ZGZiMDZmNmIzY2UzMTc3Y2MwOTZlNDAyMWFhYmUifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoxNjA0MzQzODA4LCJkaWdlc3QiOiJzaGEyNTY6NWJjNTAyNWQ0MDZlMTEwZjA5ZGY0YmUxYTBhM2JmMzNkMjZjYjA5OTMwYTYzMmQzNzllZmM2YjU5NDE0YjM1YiJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjE2NzM4NDA2NCwiZGlnZXN0Ijoic2hhMjU2OmZlODA4OTA1OGM5NGYyNThkMDE2MjJkODc0YWY3MjMwMDk3YzVmNDYxZTc3NTI4YzIzNzAwNjRhOTExZjAzODcifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoyNDU3NiwiZGlnZXN0Ijoic2hhMjU2OmY4MDVjZDExZWMyMDJlNTlmMTA4NDcyODZjMDNjNjZkMmQzZGQ0MjJjNDI5Y2UyYzFlZWFmZWI5ZGUzNzk3ZGYifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjozMDcyLCJkaWdlc3QiOiJzaGEyNTY6MWJjOGFmZTk2YjAxZThmZmFiZjkxODFlOTAyYzg1YzlkOWQ5ZjEwNjk4NDQ2NjY2ODZkNTA4Y2EzMWNkYTdmNSJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjE1MzYsImRpZ2VzdCI6InNoYTI1Njo0YmMxM2FhZjI4NTFmMmZiNTcxMTIzYTA3MGVlMTljOGUxN2VlNTllZTI2ODQ4NzFlZmJkN2Y1YTY1NjA3YWE5In0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6MTAyNCwiZGlnZXN0Ijoic2hhMjU2OjVmNzBiZjE4YTA4NjAwNzAxNmU5NDhiMDRhZWQzYjgyMTAzYTM2YmVhNDE3NTViNmNkZGZhZjEwYWNlM2M2ZWYifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoyNTYwLCJkaWdlc3QiOiJzaGEyNTY6OThhODBlNzk4OWZlZWUzYjU2MjdhMmNkOGZmNTQwYTQ3ZTkzOTk4MTk0Zjk1YTQ2MGM3NDY2MDMyNDdiZmU2OSJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjUzNjUyNzM2MCwiZGlnZXN0Ijoic2hhMjU2OjkyMDRjYWFmZWVmOGQxMWQ0ZDNmMzNmNGQ4MDExYTdlZTYzNDA1YzhiZjhkMmZiYTc2NGEwOGMxZGQ1YWNjYzEifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjo0Mzk1MzE1MiwiZGlnZXN0Ijoic2hhMjU2OjRiYzMxMDNlZDA2YTdjZDQ4ZDE4Y2NhMmFkYWI3OTJhNWNiY2I0NGExZjQ0NGUyNzg3OGFmOTExZGE1NWNkN2EifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjoxMjEzNDQsImRpZ2VzdCI6InNoYTI1NjphZDUyMDZjZGFmNWNmMjY3YTBjN2RkYTVhOGUzNzIwOTZlYzEwMGNlZDNhY2I2NGQxMjllY2JmZTQzOWY5ZTc1In0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6NDYwOCwiZGlnZXN0Ijoic2hhMjU2OjRjOWM5OTAxNTEyZWRlNWQyMmMzN2Q1NzIxNWUyM2YyMmRjZGE5MWI2YTlkOTI0NjhlZDYzYWEyOGQ0N2JiYjMifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjozMDcyLCJkaWdlc3QiOiJzaGEyNTY6YjU0ODRiNTAzMzFlYWQ0OWJhZjAwZTY2YjZlNTU1Mjc5ZGY1MzNjZjRhMzM0ZjQyMWJhMGM0NzAwZjBmNDRkNiJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjE3OTIwLCJkaWdlc3QiOiJzaGEyNTY6ZTE4NjBlZTNlZjFlNGM0MjQxOTZiODY1MWJiZjdkOWI1ZmQ4YzE2MDVhY2VmMzFlYjE4NzVmZmE4OTZlNmQ0YyJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjE3NDA4LCJkaWdlc3QiOiJzaGEyNTY6MDQ2NTk5N2Q3MzE2NTA0NDI2NDc0MjJiYWRiYjFlMDE2ZmIzNGU5OGIwMjM3MDllMTRkM2Y3MWE5MjRkNTBiMyJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjEzMzEyLCJkaWdlc3QiOiJzaGEyNTY6MTkxNGJhNDE0OWZjYTg2YTMzN2NhNGRlNGFhZTlkYWFhNGE3NThhYzU5MTRlNjg0ZWUyN2RmMTdiMjFhNmFlOSJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjMwNzIsImRpZ2VzdCI6InNoYTI1NjoyMTI4MTk1ZGFiNmM5YmRiYzMwNGJjMTE4MmU1YzdjNWM0OWI4YWU3NTZmNWEwYWE3YzBlNjhmNTkwZWQ1YzM1In0seyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZG9ja2VyLmltYWdlLnJvb3Rmcy5kaWZmLnRhci5nemlwIiwic2l6ZSI6NTYzMiwiZGlnZXN0Ijoic2hhMjU2OjJmMDBlNDdiNzBlZjY0N2RiZGJlOGRmNzI2NDllMTg1YWM5MTJjYTRmNmVjMmMzOTNiNzZlNDliYWU5ODExNWMifSx7Im1lZGlhVHlwZSI6ImFwcGxpY2F0aW9uL3ZuZC5kb2NrZXIuaW1hZ2Uucm9vdGZzLmRpZmYudGFyLmd6aXAiLCJzaXplIjo0NjA4LCJkaWdlc3QiOiJzaGEyNTY6NjU0YTVhZWViYjExMDk2Y2M3ZmRkNDllODRhNWEyYTg0ODhmYzhhNWMzMjEyMzU5OTUzZjlkNTg0YmZmZTNlNCJ9LHsibWVkaWFUeXBlIjoiYXBwbGljYXRpb24vdm5kLmRvY2tlci5pbWFnZS5yb290ZnMuZGlmZi50YXIuZ3ppcCIsInNpemUiOjk3MjgsImRpZ2VzdCI6InNoYTI1Njo1OTMxNDk1OTk4ZjQ5NDFjY2Q4ZWE1NTFmNTg4ZGZjYjJiMjEzNjI5MGY3ZjM3ZjM5OTI4NjBhNjQ2NzI5Y2U1In1dfQ==","config":"eyJhcmNoaXRlY3R1cmUiOiJhbWQ2NCIsImNvbmZpZyI6eyJVc2VyIjoiemFwIiwiRW52IjpbIlBBVEg9L3Vzci9saWIvanZtL2phdmEtMTctb3Blbmpkay1hbWQ2NC9iaW46L3phcC86L3Vzci9sb2NhbC9zYmluOi91c3IvbG9jYWwvYmluOi91c3Ivc2JpbjovdXNyL2Jpbjovc2JpbjovYmluIiwiSkFWQV9IT01FPS91c3IvbGliL2p2bS9qYXZhLTE3LW9wZW5qZGstYW1kNjQiLCJaQVBfUEFUSD0vemFwL3phcC5zaCIsIlpBUF9QT1JUPTgwODAiLCJJU19DT05UQUlORVJJWkVEPXRydWUiLCJIT01FPS9ob21lL3phcC8iLCJMQ19BTEw9Qy5VVEYtOCIsIkxBTkc9Qy5VVEYtOCJdLCJDbWQiOlsiYmFzaCJdLCJXb3JraW5nRGlyIjoiL3phcCIsIkxhYmVscyI6eyJtYWludGFpbmVyIjoicHNpaW5vbkBnbWFpbC5jb20iLCJydW4uY3Jhc2hvdmVycmlkZS5hdXRob3IiOiJTaW1vbiBCZW5uZXR0cyBcdTAwM2Nwc2lpbm9uQGdtYWlsLmNvbVx1MDAzZSIsInJ1bi5jcmFzaG92ZXJyaWRlLmJyYW5jaCI6Im1haW4iLCJydW4uY3Jhc2hvdmVycmlkZS5jb21taXQtaWQiOiIyNjY1ZDk3MmY2ZDU4N2JhNDc3M2E5NTA1M2FjMzlhZjNmZGY4ZGY5IiwicnVuLmNyYXNob3ZlcnJpZGUuY29tbWl0dGVyIjoiR2l0SHViIFx1MDAzY25vcmVwbHlAZ2l0aHViLmNvbVx1MDAzZSIsInJ1bi5jcmFzaG92ZXJyaWRlLmRhdGUtYXV0aG9yZWQiOiIyMDI2LTA4LTA2VDA5OjMwOjUzLjAwMCswMTowMCIsInJ1bi5jcmFzaG92ZXJyaWRlLmRhdGUtY29tbWl0dGVkIjoiMjAyNi0wOC0wNlQwOTozMDo1My4wMDArMDE6MDAiLCJydW4uY3Jhc2hvdmVycmlkZS5vcmlnaW4tdXJpIjoiaHR0cHM6Ly9naXRodWIuY29tL3phcHJveHkvemFwcm94eSJ9LCJIZWFsdGhjaGVjayI6eyJUZXN0IjpbIkNNRC1TSEVMTCIsImN1cmwgLS1zaWxlbnQgLS1vdXRwdXQgL2Rldi9udWxsIC0tZmFpbCBodHRwOi8vbG9jYWxob3N0OiRaQVBfUE9SVC8gfHwgZXhpdCAxIl19fSwiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NTQuMDgwOTUxOThaIiwiaGlzdG9yeSI6W3siY3JlYXRlZCI6IjIwMjYtMDgtMDNUMDA6MDA6MDBaIiwiY3JlYXRlZF9ieSI6IiMgZGViaWFuLnNoIC0tYXJjaCAnYW1kNjQnIG91dC8gJ2Jvb2t3b3JtJyAnQDE3ODU3MTUyMDAnIiwiY29tbWVudCI6ImRlYnVlcnJlb3R5cGUgMC4xNyJ9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NDMuNjM2NDYzNDQ4WiIsImNyZWF0ZWRfYnkiOiJMQUJFTCBtYWludGFpbmVyPXBzaWlub25AZ21haWwuY29tIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo0My42MzY0NjM0NDhaIiwiY3JlYXRlZF9ieSI6IkFSRyBERUJJQU5fRlJPTlRFTkQ9bm9uaW50ZXJhY3RpdmUiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU4OjQzLjYzNjQ2MzQ0OFoiLCJjcmVhdGVkX2J5IjoiUlVOIHwxIERFQklBTl9GUk9OVEVORD1ub25pbnRlcmFjdGl2ZSAvYmluL3NoIC1jIGFwdC1nZXQgdXBkYXRlIFx1MDAyNlx1MDAyNiBhcHQtZ2V0IGluc3RhbGwgLXEgLXkgLS1maXgtbWlzc2luZyBcdG1ha2UgXHRhdXRvbWFrZSBcdGF1dG9jb25mIFx0Z2NjIGcrKyBcdG9wZW5qZGstMTctamRrIFx0d2dldCBcdGN1cmwgXHR4bWxzdGFybGV0IFx0dW56aXAgXHRqcSBcdGdpdCBcdG9wZW5ib3ggXHR4dGVybSBcdG5ldC10b29scyBcdHB5dGhvbjMtcGlwIFx0cHl0aG9uLWlzLXB5dGhvbjMgXHRmaXJlZm94LWVzciBcdHh2ZmIgXHR4MTF2bmMgXHUwMDI2XHUwMDI2IFx0cm0gLXJmIC92YXIvbGliL2FwdC9saXN0cy8qICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NDkuNjE2NDg2MjkxWiIsImNyZWF0ZWRfYnkiOiJSVU4gfDEgREVCSUFOX0ZST05URU5EPW5vbmludGVyYWN0aXZlIC9iaW4vc2ggLWMgcGlwMyBpbnN0YWxsIFx0LS1icmVhay1zeXN0ZW0tcGFja2FnZXMgXHQtLW5vLWNhY2hlLWRpciBcdC0tdXBncmFkZSBcdGF3c2NsaSBcdHBpcCBcdHphcHJveHkgXHRweXlhbWwgXHR1cmxsaWIzICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NDkuOTUxODQ4ODc5WiIsImNyZWF0ZWRfYnkiOiJSVU4gfDEgREVCSUFOX0ZST05URU5EPW5vbmludGVyYWN0aXZlIC9iaW4vc2ggLWMgdXNlcmFkZCAtdSAxMDAwIC1kIC9ob21lL3phcCAtbSAtcyAvYmluL2Jhc2ggemFwICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NTAuMDcyNDU3MTQ3WiIsImNyZWF0ZWRfYnkiOiJSVU4gfDEgREVCSUFOX0ZST05URU5EPW5vbmludGVyYWN0aXZlIC9iaW4vc2ggLWMgZWNobyB6YXA6emFwIHwgY2hwYXNzd2QgIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC4xMjkwMzM4MTFaIiwiY3JlYXRlZF9ieSI6IlJVTiB8MSBERUJJQU5fRlJPTlRFTkQ9bm9uaW50ZXJhY3RpdmUgL2Jpbi9zaCAtYyBta2RpciAvemFwIFx1MDAyNlx1MDAyNiBjaG93biB6YXA6emFwIC96YXAgIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC4xMzc4MTQ1NjdaIiwiY3JlYXRlZF9ieSI6IldPUktESVIgL3phcCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC4xMzc4MTQ1NjdaIiwiY3JlYXRlZF9ieSI6IlVTRVIgemFwIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC4xOTAzNzM3NTdaIiwiY3JlYXRlZF9ieSI6IlJVTiB8MSBERUJJQU5fRlJPTlRFTkQ9bm9uaW50ZXJhY3RpdmUgL2Jpbi9zaCAtYyBta2RpciAvaG9tZS96YXAvLnZuYyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU4OjUxLjIxMzE2ODk1N1oiLCJjcmVhdGVkX2J5IjoiQ09QWSAtLWNob3duPTEwMDA6MTAwMCAvemFwIC4gIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC42ODE2NDczOTJaIiwiY3JlYXRlZF9ieSI6IkNPUFkgLS1jaG93bj0xMDAwOjEwMDAgL3phcC93ZWJzd2luZyAvemFwL3dlYnN3aW5nICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NTAuNjgxNjQ3MzkyWiIsImNyZWF0ZWRfYnkiOiJBUkcgVEFSR0VUQVJDSD1hbWQ2NCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NTAuNjgxNjQ3MzkyWiIsImNyZWF0ZWRfYnkiOiJFTlYgSkFWQV9IT01FPS91c3IvbGliL2p2bS9qYXZhLTE3LW9wZW5qZGstYW1kNjQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU4OjUwLjY4MTY0NzM5MloiLCJjcmVhdGVkX2J5IjoiRU5WIFBBVEg9L3Vzci9saWIvanZtL2phdmEtMTctb3Blbmpkay1hbWQ2NC9iaW46L3phcC86L3Vzci9sb2NhbC9zYmluOi91c3IvbG9jYWwvYmluOi91c3Ivc2JpbjovdXNyL2Jpbjovc2JpbjovYmluIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC42ODE2NDczOTJaIiwiY3JlYXRlZF9ieSI6IkVOViBaQVBfUEFUSD0vemFwL3phcC5zaCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NTAuNjgxNjQ3MzkyWiIsImNyZWF0ZWRfYnkiOiJFTlYgWkFQX1BPUlQ9ODA4MCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NTAuNjgxNjQ3MzkyWiIsImNyZWF0ZWRfYnkiOiJFTlYgSVNfQ09OVEFJTkVSSVpFRD10cnVlIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC42ODE2NDczOTJaIiwiY3JlYXRlZF9ieSI6IkVOViBIT01FPS9ob21lL3phcC8iLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU4OjUwLjY4MTY0NzM5MloiLCJjcmVhdGVkX2J5IjoiRU5WIExDX0FMTD1DLlVURi04IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC42ODE2NDczOTJaIiwiY3JlYXRlZF9ieSI6IkVOViBMQU5HPUMuVVRGLTgiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU3OjI2Ljg3NzIzNTg4N1oiLCJjcmVhdGVkX2J5IjoiQ09QWSAtLWNob3duPTEwMDA6MTAwMCB6YXAqIENIQU5HRUxPRy5tZCAvemFwLyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU3OjI2Ljg1NzI4MTQ3WiIsImNyZWF0ZWRfYnkiOiJDT1BZIC0tY2hvd249MTAwMDoxMDAwIHdlYnN3aW5nLmNvbmZpZyAvemFwL3dlYnN3aW5nLyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU3OjI2Ljg2ODk4MDI0WiIsImNyZWF0ZWRfYnkiOiJDT1BZIC0tY2hvd249MTAwMDoxMDAwIHdlYnN3aW5nLnByb3BlcnRpZXMgL3phcC93ZWJzd2luZy8gIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1NzoyNi44NjQyNjQwMVoiLCJjcmVhdGVkX2J5IjoiQ09QWSAtLWNob3duPTEwMDA6MTAwMCBwb2xpY2llcyAvaG9tZS96YXAvLlpBUC9wb2xpY2llcy8gIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1NzoyNi44Nzg0NTI2MDRaIiwiY3JlYXRlZF9ieSI6IkNPUFkgLS1jaG93bj0xMDAwOjEwMDAgcG9saWNpZXMgL3Jvb3QvLlpBUC9wb2xpY2llcy8gIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1MC42NTcxNjMzMzdaIiwiY3JlYXRlZF9ieSI6IkNPUFkgLS1jaG93bj0xMDAwOjEwMDAgL2h0dHBzZW5kZXItc2NyaXB0cy8gL2hvbWUvemFwLy5aQVBfRC9zY3JpcHRzL3NjcmlwdHMvaHR0cHNlbmRlci8gIyBidWlsZGtpdCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIn0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1NzoyNi44Nzk1NDk2MDNaIiwiY3JlYXRlZF9ieSI6IkNPUFkgLS1jaG93bj0xMDAwOjEwMDAgLnhpbml0cmMgL2hvbWUvemFwLyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU3OjI2Ljg3NjQ1NDExNloiLCJjcmVhdGVkX2J5IjoiQ09QWSAtLWNob3duPTEwMDA6MTAwMCBmaXJlZm94IC9ob21lL3phcC8ubW96aWxsYS9maXJlZm94LyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU4OjU0LjA3MjUzMjI4MloiLCJjcmVhdGVkX2J5IjoiUlVOIHwyIERFQklBTl9GUk9OVEVORD1ub25pbnRlcmFjdGl2ZSBUQVJHRVRBUkNIPWFtZDY0IC9iaW4vc2ggLWMgZWNobyBcInphcDJkb2NrZXItc3RhYmxlXCIgXHUwMDNlIC96YXAvY29udGFpbmVyIFx1MDAyNlx1MDAyNiAgICAgY2htb2QgYSt4IC9ob21lL3phcC8ueGluaXRyYyAjIGJ1aWxka2l0IiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAifSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU4OjU0LjA3MjUzMjI4MloiLCJjcmVhdGVkX2J5IjoiSEVBTFRIQ0hFQ0sge1Rlc3Q6W0NNRC1TSEVMTCBjdXJsIC0tc2lsZW50IC0tb3V0cHV0IC9kZXYvbnVsbCAtLWZhaWwgaHR0cDovL2xvY2FsaG9zdDokWkFQX1BPUlQvIHx8IGV4aXQgMV0gSW50ZXJ2YWw6MHMgVGltZW91dDowcyBTdGFydFBlcmlvZDowcyBTdGFydEludGVydmFsOjBzIFJldHJpZXM6MH0iLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU4OjU0LjA3MjUzMjI4MloiLCJjcmVhdGVkX2J5IjoiTEFCRUwgcnVuLmNyYXNob3ZlcnJpZGUuY29tbWl0LWlkPTI2NjVkOTcyZjZkNTg3YmE0NzczYTk1MDUzYWMzOWFmM2ZkZjhkZjkiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCIsImVtcHR5X2xheWVyIjp0cnVlfSx7ImNyZWF0ZWQiOiIyMDI2LTA4LTA3VDE0OjU4OjU0LjA3MjUzMjI4MloiLCJjcmVhdGVkX2J5IjoiTEFCRUwgcnVuLmNyYXNob3ZlcnJpZGUuYXV0aG9yPVNpbW9uIEJlbm5ldHRzIFx1MDAzY3BzaWlub25AZ21haWwuY29tXHUwMDNlIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1NC4wNzI1MzIyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIHJ1bi5jcmFzaG92ZXJyaWRlLmNvbW1pdHRlcj1HaXRIdWIgXHUwMDNjbm9yZXBseUBnaXRodWIuY29tXHUwMDNlIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1NC4wNzI1MzIyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIHJ1bi5jcmFzaG92ZXJyaWRlLmJyYW5jaD1tYWluIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1NC4wNzI1MzIyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIHJ1bi5jcmFzaG92ZXJyaWRlLm9yaWdpbi11cmk9aHR0cHM6Ly9naXRodWIuY29tL3phcHJveHkvemFwcm94eSIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NTQuMDcyNTMyMjgyWiIsImNyZWF0ZWRfYnkiOiJMQUJFTCBydW4uY3Jhc2hvdmVycmlkZS5kYXRlLWF1dGhvcmVkPTIwMjYtMDgtMDZUMDk6MzA6NTMuMDAwKzAxOjAwIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1NC4wNzI1MzIyODJaIiwiY3JlYXRlZF9ieSI6IkxBQkVMIHJ1bi5jcmFzaG92ZXJyaWRlLmRhdGUtY29tbWl0dGVkPTIwMjYtMDgtMDZUMDk6MzA6NTMuMDAwKzAxOjAwIiwiY29tbWVudCI6ImJ1aWxka2l0LmRvY2tlcmZpbGUudjAiLCJlbXB0eV9sYXllciI6dHJ1ZX0seyJjcmVhdGVkIjoiMjAyNi0wOC0wN1QxNDo1ODo1NC4wNzI1MzIyODJaIiwiY3JlYXRlZF9ieSI6IkFSRyBUQVJHRVRQTEFURk9STT1saW51eC9hbWQ2NCIsImNvbW1lbnQiOiJidWlsZGtpdC5kb2NrZXJmaWxlLnYwIiwiZW1wdHlfbGF5ZXIiOnRydWV9LHsiY3JlYXRlZCI6IjIwMjYtMDgtMDdUMTQ6NTg6NTQuMDgwOTUxOThaIiwiY3JlYXRlZF9ieSI6IkNPUFkgL2xpbnV4L2FtZDY0IC9jaGFsay5qc29uICMgYnVpbGRraXQiLCJjb21tZW50IjoiYnVpbGRraXQuZG9ja2VyZmlsZS52MCJ9XSwib3MiOiJsaW51eCIsInJvb3RmcyI6eyJ0eXBlIjoibGF5ZXJzIiwiZGlmZl9pZHMiOlsic2hhMjU2OjY2NDYyY2M4NjJmZTIwNTNiOTg2M2ZlZmEzODY2ZTA3YmI1ZGZiMDZmNmIzY2UzMTc3Y2MwOTZlNDAyMWFhYmUiLCJzaGEyNTY6NWJjNTAyNWQ0MDZlMTEwZjA5ZGY0YmUxYTBhM2JmMzNkMjZjYjA5OTMwYTYzMmQzNzllZmM2YjU5NDE0YjM1YiIsInNoYTI1NjpmZTgwODkwNThjOTRmMjU4ZDAxNjIyZDg3NGFmNzIzMDA5N2M1ZjQ2MWU3NzUyOGMyMzcwMDY0YTkxMWYwMzg3Iiwic2hhMjU2OmY4MDVjZDExZWMyMDJlNTlmMTA4NDcyODZjMDNjNjZkMmQzZGQ0MjJjNDI5Y2UyYzFlZWFmZWI5ZGUzNzk3ZGYiLCJzaGEyNTY6MWJjOGFmZTk2YjAxZThmZmFiZjkxODFlOTAyYzg1YzlkOWQ5ZjEwNjk4NDQ2NjY2ODZkNTA4Y2EzMWNkYTdmNSIsInNoYTI1Njo0YmMxM2FhZjI4NTFmMmZiNTcxMTIzYTA3MGVlMTljOGUxN2VlNTllZTI2ODQ4NzFlZmJkN2Y1YTY1NjA3YWE5Iiwic2hhMjU2OjVmNzBiZjE4YTA4NjAwNzAxNmU5NDhiMDRhZWQzYjgyMTAzYTM2YmVhNDE3NTViNmNkZGZhZjEwYWNlM2M2ZWYiLCJzaGEyNTY6OThhODBlNzk4OWZlZWUzYjU2MjdhMmNkOGZmNTQwYTQ3ZTkzOTk4MTk0Zjk1YTQ2MGM3NDY2MDMyNDdiZmU2OSIsInNoYTI1Njo5MjA0Y2FhZmVlZjhkMTFkNGQzZjMzZjRkODAxMWE3ZWU2MzQwNWM4YmY4ZDJmYmE3NjRhMDhjMWRkNWFjY2MxIiwic2hhMjU2OjRiYzMxMDNlZDA2YTdjZDQ4ZDE4Y2NhMmFkYWI3OTJhNWNiY2I0NGExZjQ0NGUyNzg3OGFmOTExZGE1NWNkN2EiLCJzaGEyNTY6YWQ1MjA2Y2RhZjVjZjI2N2EwYzdkZGE1YThlMzcyMDk2ZWMxMDBjZWQzYWNiNjRkMTI5ZWNiZmU0MzlmOWU3NSIsInNoYTI1Njo0YzljOTkwMTUxMmVkZTVkMjJjMzdkNTcyMTVlMjNmMjJkY2RhOTFiNmE5ZDkyNDY4ZWQ2M2FhMjhkNDdiYmIzIiwic2hhMjU2OmI1NDg0YjUwMzMxZWFkNDliYWYwMGU2NmI2ZTU1NTI3OWRmNTMzY2Y0YTMzNGY0MjFiYTBjNDcwMGYwZjQ0ZDYiLCJzaGEyNTY6ZTE4NjBlZTNlZjFlNGM0MjQxOTZiODY1MWJiZjdkOWI1ZmQ4YzE2MDVhY2VmMzFlYjE4NzVmZmE4OTZlNmQ0YyIsInNoYTI1NjowNDY1OTk3ZDczMTY1MDQ0MjY0NzQyMmJhZGJiMWUwMTZmYjM0ZTk4YjAyMzcwOWUxNGQzZjcxYTkyNGQ1MGIzIiwic2hhMjU2OjE5MTRiYTQxNDlmY2E4NmEzMzdjYTRkZTRhYWU5ZGFhYTRhNzU4YWM1OTE0ZTY4NGVlMjdkZjE3YjIxYTZhZTkiLCJzaGEyNTY6MjEyODE5NWRhYjZjOWJkYmMzMDRiYzExODJlNWM3YzVjNDliOGFlNzU2ZjVhMGFhN2MwZTY4ZjU5MGVkNWMzNSIsInNoYTI1NjoyZjAwZTQ3YjcwZWY2NDdkYmRiZThkZjcyNjQ5ZTE4NWFjOTEyY2E0ZjZlYzJjMzkzYjc2ZTQ5YmFlOTgxMTVjIiwic2hhMjU2OjY1NGE1YWVlYmIxMTA5NmNjN2ZkZDQ5ZTg0YTVhMmE4NDg4ZmM4YTVjMzIxMjM1OTk1M2Y5ZDU4NGJmZmUzZTQiLCJzaGEyNTY6NTkzMTQ5NTk5OGY0OTQxY2NkOGVhNTUxZjU4OGRmY2IyYjIxMzYyOTBmN2YzN2YzOTkyODYwYTY0NjcyOWNlNSJdfX0=","repoDigests":[],"architecture":"","os":"","labels":{"maintainer":"psiinon@gmail.com","run.crashoverride.author":"Simon Bennetts <psiinon@gmail.com>","run.crashoverride.branch":"main","run.crashoverride.commit-id":"2665d972f6d587ba4773a95053ac39af3fdf8df9","run.crashoverride.committer":"GitHub <noreply@github.com>","run.crashoverride.date-authored":"2026-08-06T09:30:53.000+01:00","run.crashoverride.date-committed":"2026-08-06T09:30:53.000+01:00","run.crashoverride.origin-uri":"https://github.com/zaproxy/zaproxy"}}},"distro":{"name":"debian","version":"12.15","idLike":[]},"descriptor":{"name":"grype","version":"0.118.0","configuration":{"output":["json"],"file":"/work/acb/devsecops-local-test/grype-image/grype.json","pretty":false,"distro":"","add-cpes-if-none":false,"output-template-file":"","check-for-app-update":false,"only-fixed":false,"only-notfixed":false,"ignore-wontfix":"","platform":"","search":{"scope":"squashed","unindexed-archives":false,"indexed-archives":true},"ignore":[{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"kernel-headers","version":"","language":"","type":"rpm","location":"","upstream-name":"kernel"},"vex-status":"","vex-justification":"","match-type":"exact-indirect-match"},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"linux(-.*)?-headers-.*","version":"","language":"","type":"deb","location":"","upstream-name":"linux.*"},"vex-status":"","vex-justification":"","match-type":"exact-indirect-match"},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"linux-libc-dev","version":"","language":"","type":"deb","location":"","upstream-name":"linux"},"vex-status":"","vex-justification":"","match-type":"exact-indirect-match"},{"vulnerability":"","include-aliases":false,"reason":"","namespace":"","fix-state":"","package":{"name":"linux-kbuild-.*","version":"","language":"","type":"deb","location":"","upstream-name":"linux.*"},"vex-status":"","vex-justification":"","match-type":"exact-indirect-match"}],"exclude":[],"externalSources":{"enable":false,"maven":{"searchUpstreamBySha1":true,"baseUrl":"https://search.maven.org/solrsearch/select","rateLimit":300000000}},"match":{"java":{"using-cpes":false},"jvm":{"using-cpes":true},"dotnet":{"using-cpes":false},"golang":{"using-cpes":false,"always-use-cpe-for-stdlib":false,"allow-main-module-pseudo-version-comparison":false},"javascript":{"using-cpes":false},"python":{"using-cpes":false},"ruby":{"using-cpes":false},"rust":{"using-cpes":false},"hex":{"using-cpes":false},"stock":{"using-cpes":true},"dpkg":{"using-cpes":false,"missing-epoch-strategy":"zero","use-cpes-for-eol":false},"rpm":{"using-cpes":false,"missing-epoch-strategy":"auto","use-cpes-for-eol":false}},"fail-on-severity":"high","registry":{"insecure-skip-tls-verify":false,"insecure-use-http":false,"ca-cert":""},"show-suppressed":false,"by-cve":false,"SortBy":{"sort-by":"risk"},"name":"","default-image-pull-source":"","from":null,"vex-documents":[],"vex-add":[],"match-upstream-kernel-headers":false,"fix-channel":{"redhat-eus":{"apply":"auto","versions":">= 8.0"},"ubuntu-esm":{"apply":"auto","versions":""}},"timestamp":true,"alerts":{"enable-eol-distro-warnings":true},"db":{"cache-dir":"/work/acb/my-devsecops/cache/grype","update-url":"https://grype.anchore.io/databases","ca-cert":"","auto-update":false,"validate-by-hash-on-start":true,"validate-age":true,"max-allowed-built-age":604800000000000,"require-update-check":false,"update-available-timeout":30000000000,"update-download-timeout":300000000000,"max-update-check-frequency":7200000000000},"exp":{},"dev":{"db":{"debug":false}}},"db":{"status":{"schemaVersion":"v6.1.9","from":"https://grype.anchore.io/databases/v6/vulnerability-db_v6.1.9_2026-09-10T00:31:01Z_1789021824.tar.zst?checksum=sha256%3Ace7ae6d4f7fb81029fc3bd1891b6b441f96bac4e278519743e4768eebd805e69","built":"2026-09-10T06:30:24Z","path":"/work/acb/my-devsecops/cache/grype/6/vulnerability.db","valid":true},"providers":{"alma":{"captured":"2026-09-10T00:32:11Z","input":"xxh64:1807e105692cb88f"},"alpine":{"captured":"2026-09-10T00:31:51Z","input":"xxh64:09d59dafdef78079"},"amazon":{"captured":"2026-09-10T00:31:41Z","input":"xxh64:4117fe07be3c267a"},"arch":{"captured":"2026-09-10T00:31:36Z","input":"xxh64:c00aebe2828c161c"},"bitnami":{"captured":"2026-09-10T00:31:32Z","input":"xxh64:951c2d306a8b1b69"},"chainguard":{"captured":"2026-09-10T00:31:37Z","input":"xxh64:27e03c57f3d9dcbf"},"chainguard-libraries":{"captured":"2026-09-10T00:31:20Z","input":"xxh64:ef94aab8ce5da4c8"},"debian":{"captured":"2026-09-10T00:31:20Z","input":"xxh64:204642a2b850cb27"},"echo":{"captured":"2026-09-10T00:31:08Z","input":"xxh64:ff78d875989e7db4"},"eol":{"captured":"2026-09-10T00:31:10Z","input":"xxh64:dfbfc9c07c312bda"},"epss":{"captured":"2026-09-10T00:31:06Z","input":"xxh64:40d2df386998cfd9"},"fedora":{"captured":"2026-09-10T00:31:16Z","input":"xxh64:25ae652358dbadfd"},"github":{"captured":"2026-09-10T00:31:26Z","input":"xxh64:457b969106884a39"},"govulndb":{"captured":"2026-09-10T00:31:03Z","input":"xxh64:cd35c449ef8579fd"},"hummingbird":{"captured":"2026-09-10T00:33:21Z","input":"xxh64:7a731a5257f54a62"},"kev":{"captured":"2026-09-10T00:31:41Z","input":"xxh64:cf42b0fc13505f0e"},"mariner":{"captured":"2026-09-10T00:31:09Z","input":"xxh64:13e7b5eb73888863"},"minimos":{"captured":"2026-09-10T00:31:10Z","input":"xxh64:2bdfa73053c0a427"},"nvd":{"captured":"2026-09-10T00:32:03Z","input":"xxh64:940aa3847da19e49"},"oracle":{"captured":"2026-09-10T00:31:11Z","input":"xxh64:b2d09e8869a1f381"},"photon":{"captured":"2026-09-10T00:31:26Z","input":"xxh64:d040c89077557ee2"},"rhel":{"captured":"2026-09-10T00:32:18Z","input":"xxh64:064c5e2b32fd5d02"},"secureos":{"captured":"2026-09-10T00:31:01Z","input":"xxh64:d15a676bfc167e23"},"sles":{"captured":"2026-09-10T00:31:42Z","input":"xxh64:8cd4754292a46849"},"ubuntu":{"captured":"2026-09-10T00:33:18Z","input":"xxh64:a95743d0b61aae64"},"wolfi":{"captured":"2026-09-10T00:31:13Z","input":"xxh64:2c86b25c0167c4ae"}}},"timestamp":"2026-09-11T03:43:39.188946852+02:00"}}
